// MITRE ATT&CK

T1547.015 · Login Items

🎯 Persistence macOS Sub-technique

Sub-technique of T1547 · Boot or Logon Autostart Execution.

Adversaries may add login items to execute upon user login to gain persistence or escalate privileges. Login items are applications, documents, folders, or server connections that are automatically launched when a user logs in.(Citation: Open Login Items Apple) Login items can be added via a shared ...

How to detect & mitigate it

Detecting Login Items starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.