Compliance Node Overview
MITRE ATT&CK T1037.002 (Login Hook) is an Enterprise Persistence and Privilege Escalation sub-technique of T1037 (Boot or Logon Initialization Scripts). Adversaries may use a Login Hook to establish persistence executed upon user logon. A login hook is a plist file that points to a specific script to execute with root privileges upon user logon. The plist file is located in the /Library/Preferences/com.apple.loginwindow.plist file and can be modified using the defaults command-line utility. This behavior is the same for logout hooks where a script can be executed upon user logout. All hooks require administrator permissions to modify or create hooks. Affected platforms: macOS. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-03, AC-17, CA-07, CM-02, CM-06, CM-07, SI-03, SI-04.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1037/002/
SHA-256 integrity: ce62a43daa7171b13b239c300b7ce64c37ba17e6a786119f10abf814edb60581
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1037.002: Login Hook (https://attack.mitre.org/techniques/T1037/002/)
- MITRE ATT&CK Tactic TA0003: Persistence (https://attack.mitre.org/tactics/TA0003/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.