Compliance Node Overview
MITRE ATT&CK T1547.007 (Re-opened Applications) is an Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may modify plist files to automatically run an application when a user logs in. When a user logs out or restarts via the macOS Graphical User Interface (GUI), a prompt is provided to the user with a checkbox to "Reopen windows when logging back in". When selected, all applications currently open are added to a property list file named com.apple.loginwindow.[UUID].plist within the ~/Library/Preferences/ByHost directory. Affected platforms: macOS. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1017 User Training. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-03, AC-16, CM-02, CM-03, CM-05, CM-06, CM-07, CM-08.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1547/007/
SHA-256 integrity: 5345bf0dd1e9a1e86c68345a5092b53cd2c4b59d37a0bb2d11c67ce3246f9016
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1547.007: Re-opened Applications (https://attack.mitre.org/techniques/T1547/007/)
- MITRE ATT&CK Tactic TA0003: Persistence (https://attack.mitre.org/tactics/TA0003/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access