1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1547 Boot or Logon Autostart Execution — Detection Rules

Detection workspace for T1547 Boot or Logon Autostart Execution: 7 Sigma sources, 0 Atlas concepts and 1 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

No exact concept selected.

Anomaly models

ATT&CK analytic guidance

DET0274 Boot or Logon Autostart Execution Detection Strategy

AN0764 Analytic 0764

Correlation of registry key modification for Run/RunOnce with abnormal parent-child process relationships and outlier execution at user logon or system startup

AN0765 Analytic 0765

Correlates creation/modification of systemd service files or /etc/init.d scripts with outlier process behavior during boot

AN0766 Analytic 0766

Observes creation or modification of LaunchAgent/LaunchDaemon property list files combined with anomalous plist payload execution after user logon

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1547 simulation workspace

No reviewed association in this snapshot.

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Connected anomaly research

Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.

Telemetry contracts · Maintained query examples · Validation and blind spots

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.