Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

MITRE ATT&CK T1546.004: Unix Shell Configuration Modification (Enterprise Tactic TA0004 - Privilege Escalation / TA0003 - Persistence)

MITRE ATT&CK T1546.004 (Unix Shell Configuration Modification) is an Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event…

What MITRE ATT&CK T1546.004: Unix Shell Configuration Modification (Enterprise Tactic TA0004 - Privilege Escalation / TA0003 - Persistence) requires

MITRE ATT&CK T1546.004 (Unix Shell Configuration Modification) is an Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence through executing malicious commands triggered by a user's shell. User Unix Shells execute several configuration scripts at different points throughout the session based on events. For example, when a user opens a command-line interface or remotely logs in (such as via SSH) a login shell is initiated. The login shell executes scripts from the system (/etc) and the user's home directory (~/) to configure the environment. Affected platforms: Linux, macOS. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-06, CA-07, CM-02, CM-03, CM-06, IA-09.

Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:

Primary source: https://attack.mitre.org/techniques/T1546/004/

SHA-256 integrity: d5a27d7c3abd11f38fbe08d99e3479bc3f01628185f81bab97c45e82916be46c

Primary Citations — 7 traced to source

  • MITRE ATT&CK Technique T1546.004: Unix Shell Configuration Modification (https://attack.mitre.org/techniques/T1546/004/)
  • MITRE ATT&CK Tactic TA0004: Privilege Escalation (https://attack.mitre.org/tactics/TA0004/)

+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.