Insider Threat Matrix™Insider Threat Matrix™
  • ID: PR046.003
  • Created: 22nd July 2026
  • Updated: 22nd July 2026
  • Platforms: MacOSWindowsLinux
  • MITRE ATT&CK®: T1547T1547.015T1547.014T1547.013T1547.009T1547.001
  • Contributor: The ITM Team

Startup or Logon Modification

The subject modifies startup folders, Registry autorun locations, XDG autostart entries, login items, shortcuts, or equivalent configurations so that unauthorized code executes during system startup or account logon.