T1547

Boot or Logon Autostart Execution

Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence.

ATT&CK / Persistence

The Emotet malware creates registry run keys to ensure it executes every time the user logs in, maintaining persistence even after reboots.

Defense strategies

  • Monitor registry run keys
  • Restrict modification of startup locations
  • Application whitelisting
  • Regular system audits

Detection methods

  • Monitor registry modifications
  • Track startup folder changes
  • Correlate with new file creation
  • Baseline normal autostart entries

T1547 on MITRE ATT&CK ↗