Sub-technique of T1546 Event Triggered Execution.View on attack.mitre.org
Adversaries may establish persistence by executing malicious content triggered by user inactivity. Screensavers are programs that execute after a configurable time of user inactivity and consist of Portable Executable (PE) files with a .scr file extension. The Windows screensaver application scrnsave.scr is located in C:\Windows\System32\, and C:\Windows\sysWOW64\ on 64-bit Windows systems, along with screensavers included with base Windows installations.
The following screensaver settings are stored in the Registry (HKCU\Control Panel\Desktop\) and could be manipulated to achieve persistence:
* SCRNSAVE.exe - set to malicious PE path
* ScreenSaveActive - set to '1' to enable the screensaver
* ScreenSaverIsSecure - set to '0' to not require a password to unlock
* ScreenSaveTimeout - sets user inactivity timeout before screensaver is executed
Adversaries can use screensaver settings to maintain persistence by setting the screensaver to run malware after a certain timeframe of user inactivity.
Rules on DetectionCode tagged with T1546.002.
| Rule | Level | Log source |
|---|---|---|
| Path To Screensaver Binary Modified | medium | windows / registry_event |
| Suspicious ScreenSave Change by Reg.exe | medium | windows / process_creation |
| Suspicious Screensaver Binary File Creation | medium | windows / file_event |
| Writing Local Admin Share | medium | windows / file_event |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Screensaver Event Trigger Execution | TTP | NULL | Sysmon EventID 13 |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.