Login Items (T1547.015)

View on ATT&CK

In Playbook

Associated Tactics

  • Persistence
  • Privilege Escalation

Persistence (TA0003)

The adversary is trying to maintain their foothold. Persistence consists of techniques that adversaries use to keep access to systems across restarts, changed credentials, and other interruptions that could cut off their access. Techniques used for persistence include any access, action, or configuration changes that let them maintain their foothold on systems, such as replacing or hijacking legitimate code or adding startup code.

View on ATT&CK

Procedure Examples

Description Source(s)
Apple. (n.d.). Open items automatically when you log in on Mac. Retrieved October 1, 2021. Open Login Items Apple
Apple. (2016, September 13). Adding Login Items. Retrieved July 11, 2017. Adding Login Items
Tim Schroeder. (2013, April 21). SMLoginItemSetEnabled Demystified. Retrieved October 5, 2021. SMLoginItemSetEnabled Schroeder 2013
Apple. (n.d.). Launch Services. Retrieved October 5, 2021. Launch Services Apple Developer
hoakley. (2018, May 22). Running at startup: when to use a Login Item or a LaunchAgent/LaunchDaemon. Retrieved October 5, 2021. ELC Running at startup
Apple. (n.d.). Login Items AE. Retrieved October 4, 2021. Login Items AE
hoakley. (2021, September 16). How to run an app or tool at startup. Retrieved October 5, 2021. Startup Items Eclectic
fluffybunny. (2019, July 9). OSX.Dok Analysis. Retrieved October 4, 2021. hexed osx.dok analysis 2019
kaloprominat. (2013, July 30). macos: manage add list remove login items apple script. Retrieved October 5, 2021. Add List Remove Login Items Apple Script
Patrick Wardle. (n.d.). Mac Malware of 2017. Retrieved September 21, 2018. objsee mac malware 2017
Ofer Caspi. (2017, May 4). OSX Malware is Catching Up, and it wants to Read Your HTTPS Traffic. Retrieved October 5, 2021. CheckPoint Dok
Patrick Wardle. (2019, June 20). Burned by Fire(fox). Retrieved October 1, 2021. objsee netwire backdoor 2019
Patrick Wardle. (2018, July 23). Block Blocking Login Items. Retrieved October 1, 2021. objsee block blocking login items
Stokes, Phil. (2019, June 17). HOW MALWARE PERSISTS ON MACOS. Retrieved September 10, 2019. sentinelone macos persist Jun 2019
Apple. (2018, June 4). Launch Services Keys. Retrieved October 5, 2021. Launch Service Keys Developer Apple