Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Persistence/ T1547

T1547Boot or Logon Autostart Execution

T1547 — Boot or Logon Autostart Execution is a MITRE ATT&CK technique in the Persistence tactic. Clankerusecase tracks 7 detection use cases covering it and 6 threat-intel articles citing it.

PersistencePrivilege Escalation
View on the matrix → Filter Detection Library MITRE official spec ↗
7Use cases
6Articles
14Sub-techniques
2Tactics

Sub-techniques (14)

Use cases covering this technique (7)

Windows Unsigned MS DLL Side-Loading ESCU actions · hunting P [LLM] eBPF program load or pinned object created from non-system parent on Arch host Bespoke install · hunting DSΣPDDCS [LLM] Atomic Arch rootkit — eBPF program load by AUR-build-chain descendant Bespoke install · hunting DSPDD [LLM] macOS LaunchAgent Persistence — com.user.kitty-monitor.plist (Nx Console Compromise) Bespoke install · alerting DSΣPDDCS [LLM] handler.lua dropped outside Algernon's configured web root (CVE-2026-45721 backdoor stage) Bespoke install · alerting DSΣPDDCS [LLM] Mini Shai-Hulud persistence to ~/.claude/hooks and .vscode/tasks.json by node/npm/bun Bespoke install · alerting DSΣPDD [LLM] Malicious '.github/workflows/discussion.yaml' workflow file created by npm/node Bespoke install · alerting DSΣPDDCS

Articles citing this technique (6)