1200KM / simulation
T1037.005 Startup Items — Attack Simulation
Adversaries may use startup items automatically executed at boot initialization to establish persistence. Startup items execute during the final phase of the boot process and contain shell scripts or other executable files along with configuration information used by the system to determine the execution order for all startup items. This is technically a deprecated technology (superseded by Launch Daemon), and thus the appropriate folder,…
Technique description
Adversaries may use startup items automatically executed at boot initialization to establish persistence. Startup items execute during the final phase of the boot process and contain shell scripts or other executable files along with configuration information used by the system to determine the execution order for all startup items. This is technically a deprecated technology (superseded by Launch Daemon), and thus the appropriate folder,…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Add launch script to launch agent
Procedure 10cf5bec-49dd-4ebf-8077-8f47e420096f; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Add file to Local Library StartupItems
Procedure 134627c3-75db-410e-bff8-7a920075f198; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Add launch script to launch daemon
Procedure fc369906-90c7-4a15-86fd-d37da624dde6; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.