Tactic.View on attack.mitre.org
The adversary is trying to maintain their foothold.
Persistence consists of techniques that adversaries use to keep access to systems across restarts, changed credentials, and other interruptions that could cut off their access. Techniques used for persistence include any access, action, or configuration changes that let them maintain their foothold on systems, such as replacing or hijacking legitimate code or adding startup code.
| ID | Name | Sub-techniques | Examples |
|---|---|---|---|
| T1037 | Boot or Logon Initialization Scripts | 5 | 22 |
| T1053 | Scheduled Task/Job | 5 | 216 |
| T1078 | Valid Accounts | 4 | 149 |
| T1098 | Account Manipulation | 7 | 45 |
| T1112 | Modify Registry | 0 | 173 |
| T1133 | External Remote Services | 0 | 43 |
| T1136 | Create Account | 3 | 49 |
| T1137 | Office Application Startup | 6 | 16 |
| T1176 | Software Extensions | 2 | 9 |
| T1197 | BITS Jobs | 0 | 13 |
| T1205 | Traffic Signaling | 2 | 33 |
| T1505 | Server Software Component | 6 | 76 |
| T1525 | Implant Internal Image | 0 | 0 |
| T1542 | Pre-OS Boot | 5 | 14 |
| T1543 | Create or Modify System Process | 5 | 198 |
| T1546 | Event Triggered Execution | 18 | 81 |
| T1547 | Boot or Logon Autostart Execution | 14 | 333 |
| T1554 | Compromise Host Software Binary | 0 | 24 |
| T1556 | Modify Authentication Process | 9 | 25 |
| T1653 | Power Settings | 0 | 3 |
| T1668 | Exclusive Control | 0 | 0 |
| T1671 | Cloud Application Integration | 0 | 1 |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.