// MITRE ATT&CK
T1546 · Event Triggered Execution
Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events. Various operating systems have means to monitor and subscribe to events such as logons or other user activity such as running specific applications/binaries. Cloud...
¿Cómo detectarlo y mitigarlo?
La detección de Event Triggered Execution parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.
Sub-técnicas (18)
T1546.001
Change Default File Association T1546.002
Screensaver T1546.003
Windows Management Instrumentation Event Subscription T1546.004
Unix Shell Configuration Modification T1546.005
Trap T1546.006
LC_LOAD_DYLIB Addition T1546.007
Netsh Helper DLL T1546.008
Accessibility Features T1546.009
AppCert DLLs T1546.010
AppInit DLLs T1546.011
Application Shimming T1546.012
Image File Execution Options Injection T1546.013
PowerShell Profile T1546.014
Emond T1546.015
Component Object Model Hijacking T1546.016
Installer Packages T1546.017
Udev Rules T1546.018
Python Startup Hooks
Change Default File Association T1546.002
Screensaver T1546.003
Windows Management Instrumentation Event Subscription T1546.004
Unix Shell Configuration Modification T1546.005
Trap T1546.006
LC_LOAD_DYLIB Addition T1546.007
Netsh Helper DLL T1546.008
Accessibility Features T1546.009
AppCert DLLs T1546.010
AppInit DLLs T1546.011
Application Shimming T1546.012
Image File Execution Options Injection T1546.013
PowerShell Profile T1546.014
Emond T1546.015
Component Object Model Hijacking T1546.016
Installer Packages T1546.017
Udev Rules T1546.018
Python Startup Hooks
Técnicas relacionadas
T1546.013
PowerShell Profile T1546.006
LC_LOAD_DYLIB Addition T1548.002
Bypass User Account Control T1548.003
Sudo and Sudo Caching T1546.011
Application Shimming T1611
Escape to Host T1546.005
Trap T1548
Abuse Elevation Control Mechanism
PowerShell Profile T1546.006
LC_LOAD_DYLIB Addition T1548.002
Bypass User Account Control T1548.003
Sudo and Sudo Caching T1546.011
Application Shimming T1611
Escape to Host T1546.005
Trap T1548
Abuse Elevation Control Mechanism
Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.