Skip to content
← LibraryTechnique entry
T1547Persistence

Boot or Logon Autostart Execution

Run code automatically at boot or logon.

§ Where this technique fits

T1547 is catalogued under the Persistence tactic of the offensive-security kill-chain. It appears in 5 approved dossiers in the registry, typically at step 5 on average.

Authoritative reference: attack.mitre.org/techniques/T1547/.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    SecureBoot Bypass
    FW-SECUREBOOT-BYPASS · Defense Evasion
    seen 1×
  2. 02
    Valid Accounts
    T1078 · Initial Access
    seen 1×