Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Privilege Escalation/ T1546.004

T1546.004Unix Shell Configuration Modification

T1546.004 — Unix Shell Configuration Modification is a MITRE ATT&CK technique in the Privilege Escalation tactic. Clankerusecase tracks 7 detection use cases covering it and 3 threat-intel articles citing it.

Privilege EscalationPersistence
View on the matrix → Filter Detection Library MITRE official spec ↗
7Use cases
3Articles
0Sub-techniques
2Tactics

Use cases covering this technique (7)

[WEEKLY] Web-Facing Service Process Writes to RCE/Persistence Paths (Path-Traversal File-Write) Internal install · alerting DSΣPDDCS Linux Auditd Unix Shell Configuration Modification ESCU actions · alerting P Linux File Creation In Profile Directory ESCU actions · hunting P Linux Possible Append Command To Profile Config File ESCU actions · hunting P [LLM] Recurring cron/shell-rc execution of .tf_cache/hw_probe.pyc payload Bespoke install · alerting DSΣPDDCS [LLM] Atomic Arch persistence: systemd unit, cron or shell-rc written by AUR build / JS runtime Bespoke install · hunting DSΣPCS [LLM] Shell rc files (.bashrc/.zshrc) modified by package-install process — s1ngularity persistence/shutdown Bespoke install · hunting DSΣPCS

Articles citing this technique (3)