1200KM / simulation
T1546 Event Triggered Execution — Attack Simulation
Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events. Various operating systems have means to monitor and subscribe to events such as logons or other user activity such as running specific applications/binaries. Cloud environments may also support various functions and services that monitor and can be invoked in response to specific cloud events. Adversaries may…
Technique description
Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events. Various operating systems have means to monitor and subscribe to events such as logons or other user activity such as running specific applications/binaries. Cloud environments may also support various functions and services that monitor and can be invoked in response to specific cloud events. Adversaries may…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Adding custom debugger for Windows Error Reporting
Procedure 17d1a3cc-3373-495a-857a-e5dd005fb302; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Load custom DLL on mstsc execution
Procedure 2db7852e-5a32-4ec7-937f-f4e027881700; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- HKCU - Persistence using CommandProcessor AutoRun key (Without Elevation)
Procedure 36b8dbf9-59b1-4e9b-a3bb-36e80563ef01; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Persistence via ErrorHandler.cmd script execution
Procedure 547a4736-dd1c-4b48-b4fe-e916190bb2e7; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- HKLM - Persistence using CommandProcessor AutoRun key (With Elevation)
Procedure a574dafe-a903-4cce-9701-14040f4f3532; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Persistence with Custom AutodialDLL
Procedure aca9ae16-7425-4b6d-8c30-cad306fdbd5b; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- WMI Invoke-CimMethod Start Process
Procedure adae83d3-0df6-45e7-b2c3-575f91584577; elevation required; cleanup not declared. Not executed or individually validated.
- Persistence using automatic execution of custom DLL during RDP session
Procedure b7fc4c3f-fe6e-479a-ba27-ef91b88536e3; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Persistence using STARTUP-PATH in MS-WORD
Procedure f0027655-25ef-47b0-acaf-3d83d106156c; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.