Boot or Logon Initialization Scripts T1037

Tactics: Persistence, Privilege Escalation

Adversaries may use scripts automatically executed at boot or logon initialization to establish persistence. Initialization scripts can be used to perform administrative functions, which may often execute other programs or send information to an internal logging server. These scripts can vary based on operating system and whether applied locally or remotely.

Events covered

13 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 52 rules share fields, values, and exclusions.

Fields filtered most (37 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType29eq 17, in 12exec, creation, exec_event, start, connection_attempted
host.os.type21eq 21
event.type20eq 17, ne 2, in 1start, deletion, change, info, process_started
TargetFilename16starts_with 6, wildcard 6, in 4, ends_with 2, contains 1/etc/rc.local, /etc/update-motd.d/, */.config/autostart/*, */etc/init.d/*, */etc/rc.d/*
process_name13in 8, eq 7, starts_with 2, wildcard 2, is_not_null 1bash, csh, awk, .*, at
process.args9eq 6, in 4, wildcard 4, contains 3, starts_with 2, ends_with 1*/bin/*sh*, *import*pty*spawn*, *import*subprocess*call*, -c, * /dev/shm/*
parent_process_name8eq 6, in 3, starts_with 1, wildcard 1socat, *.bin, *.lua, *.pl, Cursor
Image7wildcard 3, eq 2, is_not_null 2, starts_with 2, ends_with 1, is_null 1./, /boot/, /boot/*, /dev/shm/, /dev/shm/*
ParentImage7starts_with 4, ends_with 1, is_not_null 1, wildcard 1/etc/update-motd.d/, ., /dev/shm/*, /etc/init.d/, /etc/profile.d/*
CommandLine6contains 3, wildcard 3, eq 1, regex_match 1* nc *, * nc.traditional *, * ncat *, * setsid *, *#!/*
EventID4eq 3, in 14104, 4688, 5136, 5145, ModifyInstanceAttribute
data_stream.dataset4eq 4azure.activitylogs, fim.event, system.syslog
event.outcome4eq 4success
event_action4eq 2, in 2created, modified
file.name4eq 3, in 2.bash_logout, .bash_aliases, .bash_login, .bash_profile, .bashrc

Top indicator values (911 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
151078
EventTypeeq
exec
10576
EventTypeeq
creation
358
EventTypeeq
connection_attempted
273
process_namein
bash
6202
process_namein
csh
6159
process_namein
sh
6197
process_namein
zsh
6196
process_namein
dash
5170
process_namein
fish
5163
process_namein
ksh
5163
process_namein
tcsh
5156
EventTypein
exec
5201
EventTypein
start
5163
EventTypein
creation
434
EventTypein
exec_event
4149
EventTypein
file_create_event
29
EventTypein
microsoft.compute/virtualmachines/extensions/write
22
EventTypein
microsoft.compute/virtualmachinescalesets/extensions/write
22
EventTypein
open
27
EventTypein
rename
227
event.outcomeeq
success
4369
Imagewildcard
/etc/cron.*/*
39
ParentImagestarts_with
/etc/update-motd.d/
33
process.argseq
-c
3107
CommandLinewildcard
*disown*
210
CommandLinewildcard
*xxd *
212
Imagestarts_with
./
226
Imagestarts_with
/boot/
228
Imagestarts_with
/dev/shm/
253

Exclusions (558 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
Imagein
/usr/bin/yum
5
Imagein
/bin/autossl_check
4
Imagein
/bin/chef-client
4
Imagein
/bin/dnf
4
Imagein
/bin/dnf-automatic
4
Imagein
/bin/dockerd
4
Imagein
/bin/dpkg
4
Imagein
/bin/dpkg-divert
4
Imagein
/bin/microdnf
4
Imagein
/bin/pacman
4
Imagein
/bin/pamac-daemon
4
Imagein
/bin/podman
4
Imagein
/bin/puppet
4
Imagein
/bin/rpm
4
Imagein
/bin/snapd
4

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 4 rules

Elastic 36 rules

Splunk 10 rules

YARA-L 1 rule

Panther 1 rule