Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Privilege Escalation/ T1546

T1546Event Triggered Execution

T1546 — Event Triggered Execution is a MITRE ATT&CK technique in the Privilege Escalation tactic. Clankerusecase tracks 42 detection use cases covering it and 32 threat-intel articles citing it.

Privilege EscalationPersistence
View on the matrix → Filter Detection Library MITRE official spec ↗
42Use cases
32Articles
18Sub-techniques
2Tactics

Sub-techniques (18)

Use cases covering this technique (42)

[WEEKLY] npm/node-gyp Install-Hook Spawn Chained to Outbound Egress Internal install · alerting DSΣPDDCS [WEEKLY] Package install lifecycle hook spawns interpreter that reads developer credential stores Internal install · alerting DSPCS Windows AD AdminSDHolder ACL Modified ESCU actions · alerting P Windows Compatibility Telemetry Suspicious Child Process ESCU actions · alerting P Windows Compatibility Telemetry Tampering Through Registry ESCU actions · alerting P [LLM] Git server-side hook file written (hooks/post-index-change) - CVE-2026-60004 persistence Bespoke install · alerting DSΣPCS [LLM] Linux core_pattern overwritten to memfd/pipe handler (CVE-2026-53264 privesc payoff) Bespoke install · alerting DSΣPDDCS [LLM] mrmustard persistence artifacts: mmcompat.pth and .tf_cache/hw_probe.pyc Bespoke install · alerting DSΣPCS [LLM] Shai-Hulud worm artifacts written on GitHub Actions runner (shai-hulud-workflow.yml / bundle.js) Bespoke install · hunting DSΣPCS [LLM] Malicious .pth file dropped into site-packages by pip/python Bespoke install · hunting DSΣPDDCS [LLM] Miasma infectHost persistence in AI coding assistant configs Bespoke install · hunting DSΣPDDCS [LLM] Shai-Hulud/Miasma malicious GitHub Actions workflow file written to .github/workflows Bespoke install · alerting DSΣPDDCS [LLM] Miasma/Hades auto-exec editor & AI-tool config files dropped in project tree Bespoke install · hunting DSΣPDDCS [LLM] Hades PyPI startup hook: malicious -setup.pth dropped in site-packages Bespoke install · hunting DSΣPDDCS [LLM] Malicious AI coding-agent hook configs written to repo (.claude/.gemini/.cursor/.vscode) Bespoke install · alerting DSΣPDDCS [LLM] node.exe spawned by Code/Cursor/Claude/Gemini executing .github/setup.js Bespoke exploit · alerting DSΣPDDCS [LLM] Miasma GitHub Actions workflow injection for persistence by node payload Bespoke install · hunting DSΣPDDCS [LLM] Shai-Hulud npm worm: malicious GitHub Actions workflow file dropped (.github/workflows/shai-hulud.yaml) Bespoke install · alerting DSΣPDDCS [LLM] Kitty cat.py Python Backdoor File Drop / Execution (Nx Console Compromise) Bespoke install · alerting DSΣPDDCS [LLM] npm preinstall hook spawns node index.js under @redhat-cloud-services package path Bespoke install · alerting DSΣPDDCS [LLM] Shai-Hulud worm GitHub Action workflow file dropped under .github/workflows Bespoke install · alerting DSΣPDDCS [LLM] Compromised laravel-lang Composer package: helpers.php in vendor tree Bespoke delivery · hunting DSΣPDDCS [LLM] Mini Shai-Hulud persistence hooks written into .vscode/ and .claude/ configs Bespoke install · hunting DSΣPDDCS [LLM] Mini Shai-Hulud Claude Code SessionStart hook injection via npm install Bespoke install · alerting DSΣPDDCS [LLM] VS Code tasks.json folderOpen persistence written by npm install chain Bespoke install · hunting DSΣPDDCS [LLM] Mini Shai-Hulud Linux daemon persistence: kitty/cat.py and systemd user service Bespoke install · alerting DSΣPDDCS [LLM] Mini Shai-Hulud router_init.js dropped at npm package root in node_modules Bespoke install · alerting DSΣPDDCS [LLM] Bun spawned with tanstack_runner.js via npm prepare lifecycle (Mini Shai-Hulud) Bespoke install · alerting DSΣPDD [LLM] Mini Shai-Hulud persistence to ~/.claude/hooks and .vscode/tasks.json by node/npm/bun Bespoke install · alerting DSΣPDD [LLM] Shai-Hulud AI coding-agent persistence: .claude/settings.json + .vscode/tasks.json drops Bespoke install · alerting DSPDD [LLM] Malicious elementary.pth dropped in Python site-packages Bespoke install · alerting DSΣPDDCS [LLM] Mini Shai-Hulud post-compromise persistence artifacts in .claude/, .vscode/, .github/workflows/ Bespoke actions · alerting DSΣPDD [LLM] TeamPCP sysmon.py systemd-user persistence on developer host Bespoke install · alerting DSΣPDD [LLM] Force-install of IDE extension via cmd.exe with --install-extension flag spawned by node host Bespoke install · alerting DSΣPDD [LLM] litellm_init.pth Python autoload persistence drop Bespoke install · alerting DSΣPDDCS [LLM] Malicious litellm_init.pth dropped to site-packages by pip (litellm==1.82.8 install artifact) Bespoke install · alerting DSΣPDDCS [LLM] npm postinstall hook spawning node init.js or child.js (React Native attack pattern) Bespoke install · alerting DSΣPDDCS [LLM] Secondary payload install: 'npm install -g openclaw' postinstall hook execution Bespoke install · alerting DSΣPDDCS [LLM] npm/yarn/pnpm/bun lifecycle hook spawning shell or network LOLBin Bespoke install · hunting DSΣPDDCS [LLM] Shai-Hulud persistence artifact: shai-hulud-workflow.yml file dropped on disk Bespoke install · alerting DSΣPDDCS [LLM] cups-browsed writing new PPD or config under /etc/cups or /var/cache/cups Bespoke install · hunting DSΣPDDCS [LLM] npm/yarn/pnpm planting or overwriting a binary in a system bin directory Bespoke install · hunting DSΣPCS

Articles citing this technique (32)