TA0003 Persistence

The adversary is trying to maintain their foothold. Persistence consists of techniques that adversaries use to keep access to systems across restarts, changed credentials, and other interruptions that could cut off their access. Techniques used for persistence include any access, action, or configuration changes that let them maintain their foothold on systems, such as replacing or hijacking legitimate code or adding startup code.

View in MITRE ATT&CK®

ATT&CK Techniques

Technique ID Technique Name Number of Mappings Number of Subtechniques
T1037 Boot or Logon Initialization Scripts 20 5
T1543 Create or Modify System Process 56 5
T1133 External Remote Services 87 0
T1547 Boot or Logon Autostart Execution 20 14
T1137 Office Application Startup 26 6
T1053 Scheduled Task/Job 32 5
T1176 Browser Extensions 20 0
T1205 Traffic Signaling 19 2
T1525 Implant Internal Image 41 0
T1542 Pre-OS Boot 39 5
T1554 Compromise Host Software Binary 25 0
T1098 Account Manipulation 69 7
T1574 Hijack Execution Flow 51 13
T1078 Valid Accounts 144 4
T1546 Event Triggered Execution 32 17
T1197 BITS Jobs 23 0
T1505 Server Software Component 40 5
T1136 Create Account 51 3
T1653 Power Settings 6 0
T1556 Modify Authentication Process 53 9