T1037.001 Logon Script (Windows) — ATT&CK Technique
Adversaries may use Windows logon scripts automatically executed at logon initialization to establish persistence. Windows allows logon scripts to be run whenever a specific user or group of users log into a system. This is done via adding a path to a script to the HKCU\Environment\UserInitMprLogonScript Registry key. Adversaries may use these scripts to maintain persistence on a single system. Depending on the access configuration of the logon scripts, either local credentials or an administrator account may be necessary.
Detection coverage (4)
- Potential Persistence Via Logon Scripts - CommandLine high
- Uncommon Userinit Child Process high
- Potential Persistence Via Logon Scripts - Registry medium
- Logon Script Event Trigger Execution