What MITRE ATT&CK T1547: Boot or Logon Autostart Execution (Enterprise Tactic TA0003 - Persistence) requires
MITRE ATT&CK T1547 covers adversary configuration of system settings to execute malicious code automatically at boot or user logon, providing persistence. The technique has 14 sub-techniques including Registry Run Keys (T1547.001), Authentication Packages (T1547.002), Time Providers (T1547.003), Winlogon Helper DLL (T1547.004), Security Support Provider (T1547.005), and Kernel Modules (T1547.006). Persistence mechanisms are critical to detect because they enable adversaries to survive reboots and credential changes. Compliance obligations include system integrity monitoring (NIST 800-53 SI-7, ISO A.8.9) and continuous configuration baseline enforcement.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1547/
SHA-256 integrity: d0aa5425a73a8dd0fdbb2ff6eeffa93d83ddaf989aefe72326a0a977b7f0f026
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1547: Boot or Logon Autostart Execution (https://attack.mitre.org/techniques/T1547/) with 14 sub-techniques
- NIST SP 800-53 Rev 5: SI-7 (Software Integrity), CM-6 (Configuration Settings), CM-7 (Least Functionality)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-t1547-boot-logon-autostart-execution.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-t1547-boot-logon-autostart-execution.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-t1547-boot-logon-autostart-execution
- Back to registry: Browse all 10,085 compliance nodes