ATT&CKMatrixPersistence

Persistence

TA0003

Tactic.View on attack.mitre.org

About this tactic

The adversary is trying to maintain their foothold.

Persistence consists of techniques that adversaries use to keep access to systems across restarts, changed credentials, and other interruptions that could cut off their access. Techniques used for persistence include any access, action, or configuration changes that let them maintain their foothold on systems, such as replacing or hijacking legitimate code or adding startup code.

Techniques22

IDNameSub-techniquesExamples
T1037Boot or Logon Initialization Scripts522
T1053Scheduled Task/Job5216
T1078Valid Accounts4149
T1098Account Manipulation745
T1112Modify Registry0173
T1133External Remote Services043
T1136Create Account349
T1137Office Application Startup616
T1176Software Extensions29
T1197BITS Jobs013
T1205Traffic Signaling233
T1505Server Software Component676
T1525Implant Internal Image00
T1542Pre-OS Boot514
T1543Create or Modify System Process5198
T1546Event Triggered Execution1881
T1547Boot or Logon Autostart Execution14333
T1554Compromise Host Software Binary024
T1556Modify Authentication Process925
T1653Power Settings03
T1668Exclusive Control00
T1671Cloud Application Integration01

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.