For the complete documentation index, see llms.txt. This page is also available as Markdown.

Uncommon login item persistency was registered or modified

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

Detector Tags

Generic Persistence Analytics

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Boot or Logon Autostart Execution (T1547), Boot or Logon Autostart Execution: Login Items (T1547.015)

Severity

Informational

Description

An uncommon login item persistence mechanism was registered/modified on the system.

Attacker's Goals

Establish persistent access to the compromised host by registering malicious code.

Investigative actions

  • Analyze the persistency item and determine whether it performs any malicious or suspicious actions.

  • Analyze the registered process and determine whether it performs any malicious or suspicious actions.

  • Check the events generated by the process for potential malicious behavior.

Variations

Uncommon login item persistency was registered or modified by a security testing tool

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003)

ATT&CK Technique

Boot or Logon Autostart Execution (T1547), Boot or Logon Autostart Execution: Login Items (T1547.015)

Severity

High

Description

An uncommon login item persistence mechanism was registered/modified on the system by a security testing tool.

Attacker's Goals

Establish persistent access to the compromised host by registering malicious code.

Investigative actions

  • Analyze the persistency item and determine whether it performs any malicious or suspicious actions.

  • Analyze the registered process and determine whether it performs any malicious or suspicious actions.

  • Check the events generated by the process for potential malicious behavior.

Uncommon login item persistency was registered or modified while using osascript

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003), Execution (TA0002)

ATT&CK Technique

Boot or Logon Autostart Execution (T1547), Boot or Logon Autostart Execution: Login Items (T1547.015), Command and Scripting Interpreter (T1059)

Severity

Low

Description

An uncommon login item persistence mechanism was registered/modified on the system while using osascript for persistency registration or as a persistency triggered execution.

Attacker's Goals

Establish persistent access to the compromised host by registering malicious code.

Investigative actions

  • Analyze the persistency item and determine whether it performs any malicious or suspicious actions.

  • Analyze the registered process and determine whether it performs any malicious or suspicious actions.

  • Check the events generated by the process for potential malicious behavior.

Uncommon login item persistency was registered or modified by an invalidly signed actor process

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003), Stealth (TA0005)

ATT&CK Technique

Boot or Logon Autostart Execution (T1547), Boot or Logon Autostart Execution: Login Items (T1547.015), Masquerading: Masquerade Task or Service (T1036.004)

Severity

Low

Description

An uncommon login item persistence mechanism was registered/modified on the system by an invalidly signed actor process.

Attacker's Goals

Establish persistent access to the compromised host by registering malicious code.

Investigative actions

  • Analyze the persistency item and determine whether it performs any malicious or suspicious actions.

  • Analyze the registered process and determine whether it performs any malicious or suspicious actions.

  • Check the events generated by the process for potential malicious behavior.

Uncommon login item persistency was registered or modified by an invalidly signed causality process

Synopsis

Field
Value

ATT&CK Tactic

Persistence (TA0003), Stealth (TA0005)

ATT&CK Technique

Boot or Logon Autostart Execution (T1547), Boot or Logon Autostart Execution: Login Items (T1547.015), Masquerading: Masquerade Task or Service (T1036.004)

Severity

Low

Description

An uncommon login item persistence mechanism was registered/modified on the system by an invalidly signed causality process.

Attacker's Goals

Establish persistent access to the compromised host by registering malicious code.

Investigative actions

  • Analyze the persistency item and determine whether it performs any malicious or suspicious actions.

  • Analyze the registered process and determine whether it performs any malicious or suspicious actions.

  • Check the events generated by the process for potential malicious behavior.

Was this helpful?