#T1037.001 Logon Script (Windows)
Technique
- Tactics: Persistence, Privilege Escalation
- Description:
Adversaries may use Windows logon scripts automatically executed at logon initialization to establish persistence. Windows allows logon scripts to be run whenever a specific user or group of users log into a system.(Citation: TechNet Logon Scripts) This is done via adding a path to a script to the <code>HKCU\Environment\UserInitMprLogonScript</code> Registry key.(Citation: Hexacorn Logon Scripts)
Adversaries may use these scripts to maintain persistence on a single system. Depending on the access configuration of the logon scripts, either local credentials or an administrator account may be necessary.
- First Seen: 비상계엄 테마 APT 공격과 Kimsuky 그룹 연관성 분석 • 2025-03-04
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days