1200KM / simulation
T1546.004 Unix Shell Configuration Modification — Attack Simulation
Adversaries may establish persistence through executing malicious commands triggered by a user’s shell. User Unix Shells execute several configuration scripts at different points throughout the session based on events. For example, when a user opens a command-line interface or remotely logs in (such as via SSH) a login shell is initiated. The login shell executes scripts from the system (/etc) and the user’s home directory (~/) to configure the…
Technique description
Adversaries may establish persistence through executing malicious commands triggered by a user’s shell. User Unix Shells execute several configuration scripts at different points throughout the session based on events. For example, when a user opens a command-line interface or remotely logs in (such as via SSH) a login shell is initiated. The login shell executes scripts from the system (/etc) and the user’s home directory (~/) to configure the…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Add command to .bashrc
Procedure 0a898315-4cfa-4007-bafe-33a4646d115f; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Create/Append to .bash_logout
Procedure 37ad2f24-7c53-4a50-92da-427a4ad13f58; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Add command to .shrc
Procedure 41502021-591a-4649-8b6e-83c9192aff53; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Append to the system shell profile
Procedure 694b3cc8-6a78-4d35-9e74-0123d009e94b; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- System shell profile scripts
Procedure 8fe2ccfd-f079-4c03-b1a9-bd9b362b67d4; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Add command to .bash_profile
Procedure 94500ae1-7e31-47e3-886b-c328da46872f; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Append commands user shell profile
Procedure bbdb06bc-bab6-4f5b-8232-ba3fbed51d77; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.