Skip to main content

Autostart

IDDescriptionSignificance / Prevalence
BH12240Deletes scheduled tasks and jobs.
BH12346Executes script on startup.
BH12601Tampers with autorun locations.
BH12602Tampers with autorun registry keys.
BH12718Tampers with remote scheduled tasks and jobs.
BH12719Tampers with scheduled tasks and jobs.
BH12720Tampers with scheduled tasks.
BH12784Tampers with Windows Store Application Prelaunch settings.
BH12878Enables a systemd service.
BH12903Accesses an XDG autostart file.
BH20102Uses a Nishang command that uses Alternate Data Streams and Windows Registry to achieve persistence.
BH20148Uses a Nishang command to make execution of a PowerShell script from disk or URL reboot persistent using WMI permanent event consumer.
BH20167Uses PowerSploit/Empire command to add persistence capabilities to a script.
BH20172Uses PowerSploit/Empire command to configure elevated persistence options for the Add-Persistence function.
BH20173Uses PowerSploit/Empire command to configure user-level persistence options for the Add-Persistence function.