Preparation
Account Creation
Account Discovery
AI-Assisted Capability Development
Archive Data
Authorization Token Staging
Boot Order Manipulation
CCTV Enumeration
Circumventing Security Controls
- Bypassing Network Segmentation
- Downgrading Microsoft Information Protection (MIP) labels
- Impairing a Security Agent
- Impairing an Anti-Virus Solution
- Modifying a Cloud-Based Firewall
- Modifying a Host-Based Firewall
- Modifying a Network-Based Firewall
- Unauthorized Manipulation of Anti-Virus Exclusions
- Uninstalling a Security Agent
- Uninstalling an Anti-Virus Solution
Credential Collection
Data Deobfuscation
Data Obfuscation
Data Staging
Delegated Preparation via Artificial Intelligence Agents
Device Mounting
Email Collection
External Media Formatting
File Download
File Exploration
Hardware-Based Remote Access (IP-KVM)
Impersonation
Increase Privileges
IT Ticketing System Exploration
Joiner
Media Capture via External Device
Mover
Network Scanning
Observational Information Gathering
On-Screen Data Collection
Oversight Circumvention and Control Degradation
Persistent Access via Bots
Physical Disk Removal
Physical Exploration
Physical Item Smuggling
Private / Incognito Browsing
Read Windows Registry
Remote Desktop (RDP)
Security Software Enumeration
Social Engineering (Outbound)
Software Installation
- Installation of Dark Web-Capable Browsers
- Installing Browser Extensions
- Installing Browsers
- Installing Cloud Storage Applications
- Installing FTP Clients
- Installing Messenger Applications
- Installing Note-Taking Applications
- Installing RDP Clients
- Installing Screen Sharing Software
- Installing SSH Clients
- Installing Virtual Machines
- Installing VPN Applications
Software or Access Request
Suspicious Web Browsing
System Persistence
Testing Ability to Print
Testing Security Controls
Unauthorized Hardware Introduction
VPN Usage
- ID: PR046
- Created: 22nd July 2026
- Updated: 22nd July 2026
- Platforms: MacOSLinuxWindows
- MITRE ATT&CK®: TA0003
- Contributor: The ITM Team
System Persistence
The subject modifies a system, application, or operating environment to preserve unauthorized access, execution, or control beyond the initial activity. The persistence mechanism is intended to remain available following events that would ordinarily interrupt the subject’s access, including system restart, user logoff, application termination, credential changes, or the subject’s departure from the organization.
System persistence may be established through the creation or modification of scheduled tasks, cron jobs, system services, startup items, Registry autorun locations, login scripts, systemd units, Windows Management Instrumentation event subscriptions, SSH authorized keys, web shells, application extensions, or other automatically executed components. The subject may create a new persistence mechanism or alter an existing legitimate component so that unauthorized code, commands, or remote-access functionality is invoked without requiring repeated manual action.
This behavior is preparatory where the subject establishes the mechanism before an intended infringement, allowing access or execution to continue at a later time or under conditions in which the subject’s normal account is unavailable. Persistence may support subsequent unauthorized access, data collection, sabotage, surveillance, or execution by another party.
Subsections (10)
| ID | Name | Description |
|---|---|---|
| PR046.010 | Boot or Firmware Modification | The subject modifies a bootloader, boot image, boot partition, firmware component, Unified Extensible Firmware Interface configuration, or network-device boot mechanism to preserve unauthorized execution or control. |
| PR046.004 | Event-Triggered Execution | The subject creates or modifies an event subscription, event handler, system hook, or equivalent trigger that executes unauthorized commands or code when specified conditions are met. |
| PR046.007 | Office Application Startup | The subject creates or modifies an Office template, macro, add-in, Outlook rule, form, home page, or related startup configuration so that unauthorized functionality executes through a Microsoft Office application. |
| PR046.001 | Scheduled Execution | The subject creates or modifies a scheduled task, cron job, system timer, or equivalent mechanism to execute unauthorized commands or code automatically at a future time or recurring interval. |
| PR046.009 | Server Software Component Modification | The subject installs or modifies an extensible server component, stored procedure, transport agent, server module, service library, or virtualization package to preserve unauthorized execution or access.
This Sub-section excludes web shells, which are represented separately under PR046.006 – Web Shell Deployment. |
| PR046.002 | Service or Daemon Creation | The subject creates or modifies a system service, daemon, launch agent, or equivalent background component to execute unauthorized functionality automatically or continuously. |
| PR046.008 | Software Extension Installation | The subject installs, sideloads, replaces, or modifies a software extension so that unauthorized functionality executes through a browser, integrated development environment, or other supported host application. |
| PR046.005 | SSH Authorized Key Modification | The subject adds, replaces, or modifies a Secure Shell (SSH) authorized key or related trust configuration to preserve unauthorized remote access to a system, virtual machine, hypervisor, or network device. |
| PR046.003 | Startup or Logon Modification | The subject modifies startup folders, Registry autorun locations, XDG autostart entries, login items, shortcuts, or equivalent configurations so that unauthorized code executes during system startup or account logon. |
| PR046.006 | Web Shell Deployment | The subject places or modifies a server-side script, application file, or web component that permits unauthorized remote command execution through a web server or hosted application. |
Preventions (9)
Detections (11)
MITRE ATT&CK® Mapping (1)
ATT&CK Enterprise Matrix Version 19.1