Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Persistence/ T1547.014

T1547.014Active Setup

T1547.014 — Active Setup is a MITRE ATT&CK technique in the Persistence tactic. Clankerusecase tracks 3 detection use cases covering it and 1 threat-intel article citing it.

PersistencePrivilege Escalation
View on the matrix → Filter Detection Library MITRE official spec ↗
3Use cases
1Articles
0Sub-techniques
2Tactics

Use cases covering this technique (3)

Active Setup Registry Autostart ESCU actions · alerting P Windows Audit Policy Auditing Option Modified - Registry ESCU actions · hunting P [LLM] termsrv.dll patched (multi-RDP enabling) - takeown + binary write + TermService restart Bespoke install · alerting DSΣPDDCS

Articles citing this technique (1)