What MITRE ATT&CK T1547.013: XDG Autostart Entries (Enterprise Tactic TA0003 - Persistence / TA0004 - Privilege Escalation) requires
MITRE ATT&CK T1547.013 (XDG Autostart Entries) is an Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may add or modify XDG Autostart Entries to execute malicious programs or commands when a user's desktop environment is loaded at login. XDG Autostart entries are available for any XDG-compliant Linux system. XDG Autostart entries use Desktop Entry files (.desktop) to configure the user's desktop environment upon user login. Affected platforms: Linux. MITRE-documented mitigations include M1022 Restrict File and Directory Permissions, M1018 User Account Management, M1033 Limit Software Installation. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, AC-17, CA-07, CM-02, CM-03.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1547/013/
SHA-256 integrity: 71495940e1be6febbe1d37637e66f504d0506793225922ad85069dfc7f253e1e
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1547.013: XDG Autostart Entries (https://attack.mitre.org/techniques/T1547/013/)
- MITRE ATT&CK Tactic TA0003: Persistence (https://attack.mitre.org/tactics/TA0003/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-t1547-013-xdg-autostart-entries.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-t1547-013-xdg-autostart-entries.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-t1547-013-xdg-autostart-entries
- Back to registry: Browse all 10,085 compliance nodes