Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0237 — Detection Strategy for Boot or Logon Initialization Scripts: RC Scripts
DET0237

Detection Strategy for Boot or Logon Initialization Scripts: RC Scripts

4 analytic(s) · 1 technique(s) detected

Analytics

4
AN0658 Analytic 0658
Linux

Detection of modified or newly created /etc/rc.local or /etc/init.d scripts followed by suspicious execution during system startup.

auditd:SYSCALL execve linux:syslog boot logs
[script_path] Specific path of init script (e.g., /etc/rc.local, /etc/init.d/*) may vary by distribution
[user_context] Root vs. non-root modification context depending on configuration
[time_window] Tuning window for script creation or modification relative to system boot
AN0659 Analytic 0659
macOS

Detection of edits or additions to /etc/rc.common, /Library/StartupItems, or /System/Library/StartupItems and associated script execution during login or reboot.

macos:unifiedlog process events fs:fsusage file activity
[script_name] Name of script or LaunchDaemon plist is tunable across environments
[event_interval] Time window between modification and reboot/login
[file_permission] Permissions on modified RC files can vary between systems
AN0660 Analytic 0660
ESXi

Detection of changes to /etc/rc.local.d/local.sh or rc.local during post-boot script execution with abnormal commands or additions.

esxi:syslog boot logs esxi:shell admin command usage
[script_section] Tunable script section edited by adversary (beginning, end, inline)
[command_type] Nature of embedded command or payload affects detection scope
[execution_trigger] Boot vs. manual script re-invocation
AN0661 Analytic 0661
Network Devices

Detection of modified boot-time configuration scripts that persist malicious CLI commands across reboots.

networkdevice:syslog startup-config networkdevice:syslog system boot logs
[firmware_family] Device type or OS determines specific init script location
[config_line_pattern] Regex or pattern matching approach to detect suspicious CLI
[reboot_time_window] Time window between config change and first boot post-modification

Detected Techniques

1

Persistence (1)

Details

MITRE ID
DET0237
STIX ID
x-mitre-detection-strategy--be6a466c-40c6-4611-9b68-7cfcbcb35fb0
Analytics
4
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.