Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Persistence/ T1547

T1547Boot or Logon Autostart Execution

T1547 — Boot or Logon Autostart Execution is a MITRE ATT&CK technique in the Persistence tactic. Clankerusecase tracks 4 detection use cases covering it and 3 threat-intel articles citing it.

PersistencePrivilege Escalation
View on the matrix → Filter Detection Library MITRE official spec ↗
4Use cases
3Articles
14Sub-techniques
2Tactics

Sub-techniques (14)

Use cases covering this technique (4)

Windows Unsigned MS DLL Side-Loading ESCU actions · hunting P [LLM] macOS LaunchAgent Persistence — com.user.kitty-monitor.plist (Nx Console Compromise) Bespoke install · alerting DSΣPDDCS [LLM] Mini Shai-Hulud persistence to ~/.claude/hooks and .vscode/tasks.json by node/npm/bun Bespoke install · alerting DSΣPDD [LLM] Malicious '.github/workflows/discussion.yaml' workflow file created by npm/node Bespoke install · alerting DSΣPDDCS

Articles citing this technique (3)