kevmap

Techniques › T1037

T1037 Boot or Logon Initialization Scripts

persistence · privilege escalation — ESXi, Linux, macOS, Network Devices, Windows · attack.mitre.org · JSON

1
MITRE detection strategy
5
analytics
0
Sigma rules tagged attack.t1037
3
KEV CVEs mapped here
<p>Adversaries may use scripts automatically executed at boot or logon initialization to establish persistence. Initialization scripts can be used to perform administrative functions, which may often execute other programs or send information to an internal logging server. These scripts can vary based on operating system and whether applied locally or remotely.</p><p>Adversaries may use these scripts to maintain persistence on a single system. Depending on the access configuration of the logon scripts, either local credentials or an administrator account may be necessary.</p><p>An adversary may also be able to escalate their privileges since some boot or logon initialization scripts run with higher privileges.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

CVEVendor / productMapping typeStateAdded
CVE-2024-20359Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) secondary impact Mapped2024-04-24
CVE-2024-20353Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) secondary impact Mapped2024-04-24
CVE-2022-41328Fortinet FortiOS primary impact Mapped2023-03-14

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1037

No Sigma rule carries this tag. MITRE publishes a detection strategy above, so the behaviour is specified; what is missing is public detection content. 3 actively exploited CVEs map here.

Sub-techniques

IDNameSigma rulesKEV CVEs
T1037.001Logon Script (Windows)30
T1037.002Login Hook00
T1037.003Network Logon Script00
T1037.004RC Scripts00
T1037.005Startup Items10