TA0003ATT&CK 14.1
TA0003Persistence
Description
The adversary is trying to maintain their foothold.
Persistence consists of techniques that adversaries use to keep access to systems across restarts, changed credentials, and other interruptions that could cut off their access. Techniques used for persistence include any access, action, or configuration changes that let them maintain their foothold on systems, such as replacing or hijacking legitimate code or adding startup code.
Techniques in this tactic· 21
T1037
Boot or Logon Initialization Scripts
T1053
Scheduled Task/Job
T1078
Valid Accounts
T1098
Account Manipulation
T1133
External Remote Services
T1136
Create Account
T1137
Office Application Startup
T1176
Browser Extensions
T1197
BITS Jobs
T1205
Traffic Signaling
T1504
PowerShell Profile
T1505
Server Software Component
T1519
Emond
T1525
Implant Internal Image
T1542
Pre-OS Boot
T1543
Create or Modify System Process
T1546
Event Triggered Execution
T1547
Boot or Logon Autostart Execution
T1554
Compromise Client Software Binary
T1556
Modify Authentication Process
T1574
Hijack Execution Flow
Sub-techniques in this tactic· 98
T1037.001T1037.002T1037.003T1037.004T1037.005T1053.001T1053.002T1053.003T1053.004T1053.005T1053.006T1053.007T1078.001T1078.002T1078.003T1078.004T1098.001T1098.002T1098.003T1098.004T1098.005T1098.006T1136.001T1136.002T1136.003T1137.001T1137.002T1137.003T1137.004T1137.005T1137.006T1205.001T1205.002T1505.001T1505.002T1505.003T1505.004T1505.005T1542.001T1542.002+58 more
References
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.