{"id":"T1547.013","name":"XDG Autostart Entries","url":"https://attack.mitre.org/techniques/T1547/013","tactics":["persistence","privilege-escalation"],"platforms":["Linux"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0390","stix_id":"x-mitre-detection-strategy--c265ea42-9c5a-41f0-9627-d7ac0063ec98","name":"Linux Detection Strategy for T1547.013 - XDG Autostart Entries","url":"https://attack.mitre.org/detectionstrategies/DET0390","analytics":[{"id":"AN1096","stix_id":"x-mitre-analytic--7bd7f602-0f85-4e96-bd40-ae4a6f490b32","name":"Analytic 1096","description":"Correlation of file creation/modification of `.desktop` files within XDG autostart directories, followed by execution of processes at user login initiated by the desktop environment. Malicious entries typically include suspicious Exec paths or anomalous names and are not associated with installed packages.","url":"https://attack.mitre.org/detectionstrategies/DET0390#AN1096","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"creat","data_component":"DC0039","data_component_name":"File Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"open","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-syscall"},{"name":"auditd:EXECVE","channel":"Process execution via .desktop Exec path from /etc/xdg/autostart or ~/.config/autostart","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-execve"},{"name":"linux:osquery","channel":"Write or modify .desktop file in XDG autostart path","data_component":"DC0059","data_component_name":"File Metadata","log_source_slug":"linux-osquery"},{"name":"linux:auth","channel":"User login event followed by unexpected process tree","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"linux-auth"}],"mutable_elements":[{"field":"ExecCommandPattern","description":"Regex or allowlist of expected Exec paths within .desktop files. Deviations may be suspicious."},{"field":"AutostartDirectory","description":"May vary by user config (e.g., $XDG_CONFIG_HOME). Must enumerate actual values per system."},{"field":"TimeWindow","description":"Correlate file creation/mod + exec within login window (e.g., 0–5 min of user logon)."},{"field":"UserContext","description":"Should filter to non-system users, as XDG persistence typically targets interactive sessions."},{"field":"PackageOriginBaseline","description":"Compare .desktop entries to known package sources (e.g., `dpkg -S`). Unexpected origins may be suspicious."}],"live":true,"detection_strategies":["DET0390"],"techniques":["T1547.013"]}],"live":true,"version":"1.0","techniques":["T1547.013"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}