ATT&CK · T1037.001 · sub-technique
Logon Script (Windows)
Tactics: persistence, privilege-escalation
About
Adversaries may use Windows logon scripts automatically executed at logon initialization to establish persistence. Windows allows logon scripts to be run whenever a specific user or group of users log into a system. This is done via adding a path to a script to the <code>HKCU\Environment\UserInitMprLogonScript</code> Registry key. Adversaries may use these scripts to maintain persistence on a single system. Depending on the access configuration of the logon scripts, either local credentials or an administrator account may be necessary.
Used by actors
2 known groups
Software
4 malware/tools implement this
Corpus indicators tagged with this technique
64 indicators in the corpus carry T1037.001.
Showing the top 30 by severity of 64.