T1547
Boot or Logon Autostart Execution
Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence.
ATT&CK / Persistence
The Emotet malware creates registry run keys to ensure it executes every time the user logs in, maintaining persistence even after reboots.
Defense strategies
- Monitor registry run keys
- Restrict modification of startup locations
- Application whitelisting
- Regular system audits
Detection methods
- Monitor registry modifications
- Track startup folder changes
- Correlate with new file creation
- Baseline normal autostart entries
D3FEND mappings
4