Skip to content
COOEY

◄ SIGNAL FUSION

ATT&CK MATRIX

Reference · MITRE

The full MITRE ATT&CK Enterprise kill chain — every tactic column and technique cell, collected fresh from MITRE's public STIX. Cell intensity = how many tracked threat groups use the technique; = cited in advisories we collect. Click a technique for detail; filter by group to see one actor's playbook.

MATRIX_DOMAIN ENTERPRISE MOBILE ICS ⇩ EXPORT_JSON
TECHNIQUE · T1543.001 — Launch Agent
persistenceprivilege escalation macOS SUB-TECHNIQUE of T1543 MITRE page ↗

Adversaries may create or modify launch agents to repeatedly execute malicious payloads as part of persistence. When a user logs in, a per-user launchd process is started which loads the parameters for each launch-on-demand user agent from the property list (.plist) file found in <code>/System/Library/LaunchAgents</code>, <code>/Library/LaunchAgents</code>, and <code>~/Library/LaunchAgents</code>.(Citation: AppleDocs Launch Agent Daemons)(Citation: OSX Keydnap malware) (Citation: Antiquated Mac Malware) Property list files use the <code>Label</code>, <code>ProgramArguments </code>, and <code>RunAtLoad</code> keys to identify the Launch Agent's name, executable location, and execution time.(C…

Threat groups using it · 1
Reconnaissance
TA0043 · 12
Resource Development
TA0042 · 9
Initial Access
TA0001 · 11
Execution
TA0002 · 20
Persistence
TA0003 · 22
Privilege Escalation
TA0004 · 13
Stealth
TA0005 · 30
Defense Impairment
TA0112 · 18
Credential Access
TA0006 · 17
Discovery
TA0007 · 34
Lateral Movement
TA0008 · 9
Collection
TA0009 · 17
Command and Control
TA0011 · 18
Exfiltration
TA0010 · 9
Impact
TA0040 · 15
Heat · group adoption: ≤ median > median top quartile top decile ◆ n = cited in n of our collected advisories Source: MITRE ATT&CK Enterprise · attack-stix-data · group adoption = STIX “uses” edges