TA0003ATT&CK 14.1

TA0003Persistence

Description

The adversary is trying to maintain their foothold. Persistence consists of techniques that adversaries use to keep access to systems across restarts, changed credentials, and other interruptions that could cut off their access. Techniques used for persistence include any access, action, or configuration changes that let them maintain their foothold on systems, such as replacing or hijacking legitimate code or adding startup code.

Techniques in this tactic· 21

T1037
Boot or Logon Initialization Scripts
T1053
Scheduled Task/Job
T1078
Valid Accounts
T1098
Account Manipulation
T1133
External Remote Services
T1136
Create Account
T1137
Office Application Startup
T1176
Browser Extensions
T1197
BITS Jobs
T1205
Traffic Signaling
T1504
PowerShell Profile
T1505
Server Software Component
T1519
Emond
T1525
Implant Internal Image
T1542
Pre-OS Boot
T1543
Create or Modify System Process
T1546
Event Triggered Execution
T1547
Boot or Logon Autostart Execution
T1554
Compromise Client Software Binary
T1556
Modify Authentication Process
T1574
Hijack Execution Flow

Sub-techniques in this tactic· 98

T1037.001T1037.002T1037.003T1037.004T1037.005T1053.001T1053.002T1053.003T1053.004T1053.005T1053.006T1053.007T1078.001T1078.002T1078.003T1078.004T1098.001T1098.002T1098.003T1098.004T1098.005T1098.006T1136.001T1136.002T1136.003T1137.001T1137.002T1137.003T1137.004T1137.005T1137.006T1205.001T1205.002T1505.001T1505.002T1505.003T1505.004T1505.005T1542.001T1542.002+58 more

References

  1. https://attack.mitre.org/tactics/TA0003

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Technique
Boot or Logon Initialization Scripts
Tactic
Privilege Escalation
Sub-technique
Clear Persistence
Technique
Boot or Logon Autostart Execution
Tactic
Command and Control
Tactic
Defense Evasion
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, Founder at SQUR.