Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Adversaries may use network logon scripts automatically executed at logon initialization to establish persistence.
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 21% | 0% |
| case-03 | ✗→✓ | ▲ Improved | 48% | 0% |
| case-04 | ✓→✓ | = Same ✓ | 56% | 0% |
| case-05 | ✓→✓ | = Same ✓ | -30% | 0% |
| case-06 | ✓→✓ | = Same ✓ | 0% | 0% |
> Sub-technique of: T1037
Adversaries may use network logon scripts automatically executed at logon initialization to establish persistence. Network logon scripts can be assigned using Active Directory or Group Policy Objects. These logon scripts run with the privileges of the user they are assigned to. Depending on the systems within the network, initializing one of these scripts could apply to more than one or potentially all systems.
Adversaries may use these scripts to maintain persistence on a network. Depending on the access configuration of the logon scripts, either local credentials or an administrator account may be necessary.
Platforms: Windows
> Note: No Atomic Red Team tests available for this technique. See Atomic Red Team GitHub for updates.
Restrict write access to logon scripts to specific administrators.
| Finding | Severity | Impact | | ----------------------------------------- | -------- | ----------- | | Network Logon Script technique applicable | High | Persistence |
| CWE ID | Title | | ------- | ----------------------------- | | CWE-276 | Incorrect Default Permissions |
Other measured skills in the registry, with their headline benchmark lift.