FORENSIA

ATT&CK · T1037.001 · sub-technique

Logon Script (Windows)

Tactics: persistence, privilege-escalation

About

Adversaries may use Windows logon scripts automatically executed at logon initialization to establish persistence. Windows allows logon scripts to be run whenever a specific user or group of users log into a system. This is done via adding a path to a script to the <code>HKCU\Environment\UserInitMprLogonScript</code> Registry key. Adversaries may use these scripts to maintain persistence on a single system. Depending on the access configuration of the logon scripts, either local credentials or an administrator account may be necessary.

Used by actors

2 known groups

Software

4 malware/tools implement this

JHUHUGITZebrocyAttorKGH_SPY

Corpus indicators tagged with this technique

64 indicators in the corpus carry T1037.001.

IndicatorTypeFamilySevSrc
2cd88d5280a61714836f5f07a16df190911c5b952af2998dbbcda910b3b1c494hashphishing804
afd5f1ed45a9867daf3bc64152cef460a06b164c8183e490db39146d4749a82chashphishing804
37e065585c573ecc082aacbfd31564ebhashphishing803
b032d4ec4e24714f59e853da9b6e63794aacdbcbhashphishing803
1fc515870c681bf3e1b7947e2248bbcfe9918db2978117e91134de20bd42fd6ahashphishing803
00d979bdb1b29b2859f2120580f101f40e8e13de0b3b7bc29675e2c31098a03chashphishing803
01b43dad62e56164771db696827a30aehashphishing804
34e20e58b54e241596dfb2b87451b42f6bbaea95hashphishing803
609c3fc64a67630a7b206a6880c893a8hashphishing803
6b22df0de0a40ff372973639c8a1974cfb75084b8e3b85f9ab9038e0acce43c0hashphishing803
31f27fdc14505e0cebe360579e1ba0326762cbe0948e50b5f920da51fdef1b51hashphishing803
1d09357b6a096fdc35cd5c873eed15665d6b3c879d20c8cf01e6bca0005512cfhashphishing804
afd1818d136a5cad592fbd81122e2c0a1aaae4b2hashphishing803
d24216d0b82747e9406a696da76960183926145f9621947e34a772137f5e22a6hashphishing803
d2c637235d62ad766f961f9b8563f6a0e6db2ec0a343470385991b4df826afbchashphishing803
d79246b49a00169993de60779cbcec17cae9da21hashphishing803
deb10789274bf903060d700b3472fdf094a14763hashphishing804
e47d2c9f62adbffff5353e21e212d98de869c81dhashphishing803
e6c69f14d7b0dabff5c67e54cf87aba2hashphishing803
fa9d1f3e719d9284af8af075b1cef9cchashphishing803
fb3630822b70bacb56aa4cec29b5a0e3e9acb3920809e70310a4003385a6d34ahashphishing804
7d4fb94f6b4623690daea67ed52e97705cb102f443988ff605f2a9c4898244dchashphishing803
6ee4050ac0c5192961c9f34568ca68fdhashphishing803
ced6b0f4441085bb9c54a32da9ab4ba14c6e21daf6e34fd61d54923f87baacd0hashphishing803
af98e97cd49229845123a1063b8c386cc9b2f441hashphishing803
0743154262c5ccf24794168ee331feeefc6539386715307ee44d5d9b6b321077hashphishing803
f2357e70f359803d42298d016c7e1631e9fba6c7e01e5df1eb8fb9ff7eb3df4ehashphishing803
3578e1588846a805ee806fa6151b5801d0acb88879a93d378300e2ee7665736ehashphishing803
eca5c297008e7c07a5c6fc9070c03121d702ef093b4a8e508b712040d87fed36hashphishing803
ae8cded2822c56dd85f52bba09d9285cb2db3e6317227530b848ea143afb067chashphishing803

Showing the top 30 by severity of 64.