Compliance Node Overview
MITRE ATT&CK T1037.004 (RC Scripts) is an Enterprise Persistence and Privilege Escalation sub-technique of T1037 (Boot or Logon Initialization Scripts). Adversaries may establish persistence by modifying RC scripts which are executed during a Unix-like system's startup. These files allow system administrators to map and start custom services at startup for different run levels. RC scripts require root privileges to modify. Adversaries can establish persistence by adding a malicious binary path or shell commands to rc.local, rc.common, and other RC scripts specific to the Unix-like distribution. Affected platforms: macOS, Linux, Network. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-03, AC-17, CA-07, CM-02, CM-06, CM-07, SI-03, SI-04.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1037/004/
SHA-256 integrity: a1589a641d5e09392cefff464f42ee9883f2cc6e05a25697377cb9e81d4e1f2d
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1037.004: RC Scripts (https://attack.mitre.org/techniques/T1037/004/)
- MITRE ATT&CK Tactic TA0003: Persistence (https://attack.mitre.org/tactics/TA0003/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access