1200KM / detection
T1037.004 RC Scripts — Detection Rules
Detection workspace for T1037.004 RC Scripts: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0237 Detection Strategy for Boot or Logon Initialization Scripts: RC Scripts
AN0658 Analytic 0658
Detection of modified or newly created /etc/rc.local or /etc/init.d scripts followed by suspicious execution during system startup.
AN0659 Analytic 0659
Detection of edits or additions to /etc/rc.common, /Library/StartupItems, or /System/Library/StartupItems and associated script execution during login or reboot.
AN0660 Analytic 0660
Detection of changes to /etc/rc.local.d/local.sh or rc.local during post-boot script execution with abnormal commands or additions.
AN0661 Analytic 0661
Detection of modified boot-time configuration scripts that persist malicious CLI commands across reboots.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1037.004 simulation workspace
- Command Execution · DC0064
- File Creation · DC0039
- File Modification · DC0061
- Process Creation · DC0032
- Script Execution · DC0029
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.