T1546Event Triggered Execution
T1546 — Event Triggered Execution is a MITRE ATT&CK technique in the Privilege Escalation tactic. Clankerusecase tracks 42 detection use cases covering it and 32 threat-intel articles citing it.
Privilege EscalationPersistence
42Use cases
32Articles
18Sub-techniques
2Tactics
Sub-techniques (18)
T1546.008 · Accessibility FeaturesT1546.009 · AppCert DLLsT1546.010 · AppInit DLLsT1546.011 · Application ShimmingT1546.001 · Change Default File AssociationT1546.015 · Component Object Model HijackingT1546.014 · EmondT1546.012 · Image File Execution Options InjectionT1546.016 · Installer PackagesT1546.006 · LC_LOAD_DYLIB AdditionT1546.007 · Netsh Helper DLLT1546.013 · PowerShell ProfileT1546.018 · Python Startup HooksT1546.002 · ScreensaverT1546.005 · TrapT1546.017 · Udev RulesT1546.004 · Unix Shell Configuration ModificationT1546.003 · Windows Management Instrumentation Event Subscription
Use cases covering this technique (42)
[WEEKLY] npm/node-gyp Install-Hook Spawn Chained to Outbound Egress [WEEKLY] Package install lifecycle hook spawns interpreter that reads developer credential stores Windows AD AdminSDHolder ACL Modified Windows Compatibility Telemetry Suspicious Child Process Windows Compatibility Telemetry Tampering Through Registry [LLM] Git server-side hook file written (hooks/post-index-change) - CVE-2026-60004 persistence [LLM] Linux core_pattern overwritten to memfd/pipe handler (CVE-2026-53264 privesc payoff) [LLM] mrmustard persistence artifacts: mmcompat.pth and .tf_cache/hw_probe.pyc [LLM] Shai-Hulud worm artifacts written on GitHub Actions runner (shai-hulud-workflow.yml / bundle.js) [LLM] Malicious .pth file dropped into site-packages by pip/python [LLM] Miasma infectHost persistence in AI coding assistant configs [LLM] Shai-Hulud/Miasma malicious GitHub Actions workflow file written to .github/workflows [LLM] Miasma/Hades auto-exec editor & AI-tool config files dropped in project tree [LLM] Hades PyPI startup hook: malicious -setup.pth dropped in site-packages [LLM] Malicious AI coding-agent hook configs written to repo (.claude/.gemini/.cursor/.vscode) [LLM] node.exe spawned by Code/Cursor/Claude/Gemini executing .github/setup.js [LLM] Miasma GitHub Actions workflow injection for persistence by node payload [LLM] Shai-Hulud npm worm: malicious GitHub Actions workflow file dropped (.github/workflows/shai-hulud.yaml) [LLM] Kitty cat.py Python Backdoor File Drop / Execution (Nx Console Compromise) [LLM] npm preinstall hook spawns node index.js under @redhat-cloud-services package path [LLM] Shai-Hulud worm GitHub Action workflow file dropped under .github/workflows [LLM] Compromised laravel-lang Composer package: helpers.php in vendor tree [LLM] Mini Shai-Hulud persistence hooks written into .vscode/ and .claude/ configs [LLM] Mini Shai-Hulud Claude Code SessionStart hook injection via npm install [LLM] VS Code tasks.json folderOpen persistence written by npm install chain [LLM] Mini Shai-Hulud Linux daemon persistence: kitty/cat.py and systemd user service [LLM] Mini Shai-Hulud router_init.js dropped at npm package root in node_modules [LLM] Bun spawned with tanstack_runner.js via npm prepare lifecycle (Mini Shai-Hulud) [LLM] Mini Shai-Hulud persistence to ~/.claude/hooks and .vscode/tasks.json by node/npm/bun [LLM] Shai-Hulud AI coding-agent persistence: .claude/settings.json + .vscode/tasks.json drops [LLM] Malicious elementary.pth dropped in Python site-packages [LLM] Mini Shai-Hulud post-compromise persistence artifacts in .claude/, .vscode/, .github/workflows/ [LLM] TeamPCP sysmon.py systemd-user persistence on developer host [LLM] Force-install of IDE extension via cmd.exe with --install-extension flag spawned by node host [LLM] litellm_init.pth Python autoload persistence drop [LLM] Malicious litellm_init.pth dropped to site-packages by pip (litellm==1.82.8 install artifact) [LLM] npm postinstall hook spawning node init.js or child.js (React Native attack pattern) [LLM] Secondary payload install: 'npm install -g openclaw' postinstall hook execution [LLM] npm/yarn/pnpm/bun lifecycle hook spawning shell or network LOLBin [LLM] Shai-Hulud persistence artifact: shai-hulud-workflow.yml file dropped on disk [LLM] cups-browsed writing new PPD or config under /etc/cups or /var/cache/cups [LLM] npm/yarn/pnpm planting or overwriting a binary in a system bin directoryArticles citing this technique (32)
high Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspicious Files art-317
high Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp art-362
crit Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack art-440