What MITRE CAPEC-564: Run Software at Logon (Detailed Attack Pattern) requires
MITRE CAPEC-564 (Run Software at Logon) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Operating system allows logon scripts to be run whenever a specific user or users logon to a system. If adversaries can access these scripts, they may insert additional code into the logon script. This code can allow them to maintain persistence or move laterally within an enclave because it is executed every time the affected user or users logon to a computer. Likelihood of attack: Unknown. Maps to weaknesses CWE-284. Relates to MITRE ATT&CK T1037, T1543.001, T1543.004.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/564.html
SHA-256 integrity: 6879921e705c3f8ae2c9a3b074272ffc5226fcc2b1e1d96cdd6467c2a8479a06
Primary Citations — 10 traced to source
- MITRE CAPEC-564: Run Software at Logon (https://capec.mitre.org/data/definitions/564.html)
- CWE-284: underlying weakness (http://cwe.mitre.org/data/definitions/284.html)
+ 8 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-capec-capec-564-run-software-at-logon.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-capec-capec-564-run-software-at-logon.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-capec-capec-564-run-software-at-logon
- Back to registry: Browse all 10,085 compliance nodes