T1546: T1546
Essential information
- MITRE technique ID
T1546- Confidence
- 100/100
- Revoked
- No
- Published
- 22/01/2020 22:04
- Modified
- 27/03/2026 01:11
- Author / Source
- The MITRE Corporation
Aliases
Event Triggered Execution
Platforms
windows macos linux IaaS Office Suite SaaS
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | persistence |
| mitre-attack | privilege-escalation |
Marking (TLP)
TLP:GREEN Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (29)
-
RomCom usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Trigona usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
DONOT usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
KNOTWEED usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
APT 28 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[menuPass](https://attack.mitre.org/groups/G0045) is a threat group that has been active since at least 2006. Individual members of [menuPass](https://attack.mitre.org/groups/G0045) are known to have acted in association with the Chinese Ministry…
First seen 01/01/1970 · Last seen 16/11/5138 · -
CL0P usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Activity usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Glupteba usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Blackwood usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Goldoon usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Calypso usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Malware (73)
-
Win.Dropper.Scar uses
-
macOS.Bkdr.Activator uses
-
Space Pirates uses
-
NSIS uses
-
MostereRAT usesFamily
-
Winnti uses
-
SectopRAT usesFamily
-
Infostealer usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
HyperBro uses
-
Redline usesFamily
-
NOOPDOOR usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Mirai usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Reports (18)
-
Threat landscape — insurance relatedConfidence 100 199 MITREs 11 APTs
-
18 MITREs 1 Malware 2 Observables
-
23 CVEs 20 MITREs 2 Malwares 26 Observables 1 APT
-
15 MITREs 3 Malwares 71 Observables 1 APT
-
12 MITREs 1 Malware 12 Observables 1 APT
-
12 MITREs 1 Malware 12 Observables 1 APT
-
10 MITREs 3 Malwares
-
9 MITREs 5 Observables 1 APT
-
23 MITREs 1 Malware 15 Observables
-
19 MITREs 4 Malwares 1 APT
-
20 MITREs 3 Malwares 1 APT
-
14 MITREs 1 Malware
Vulnerabilities (CVE) (67)
Microsoft Windows Update Medic Service contains an unspecified vulnerability that allows for privilege escalation.
- Published
- 03/11/2021
- Modified
- 20/12/2025
D-Link DIR-645 Wired/Wireless Router allows remote attackers to execute arbitrary commands via a GetDeviceSettings action to the HNAP interface.
- Attack vector
- Adjacent
- Complexity
- LOW
- Published
- 23/02/2015
- Modified
- 22/04/2026
- Published
- 20/12/2025
- Modified
- 21/12/2025
- Published
- 20/12/2025
- Modified
- 21/12/2025
Microsoft Enhanced Cryptographic Provider contains an unspecified vulnerability that allows for privilege escalation.
- Published
- 03/11/2021
- Modified
- 20/12/2025
Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of …
- Published
- 03/11/2021
- Modified
- 20/12/2025
Jenkins 2.470 and earlier, LTS 2.452.3 and earlier allows agent processes to read arbitrary files from the Jenkins controller file system by …
- Attack vector
- NETWORK
- Published
- 07/08/2024
- Modified
- 21/12/2025
A command injection issue in TRENDnet TEW-411BRPplus v.2.07_eu that allows a local attacker to execute arbitrary code via the data1 parameter in …
- Attack vector
- NETWORK
- Published
- 25/01/2024
- Modified
- 21/12/2025
The web service on Nexxt Amp300 ARN02304U8 42.103.1.5095 and 80.103.2.5045 devices allows remote OS command execution by placing &telnetd in the JSON …
- Attack vector
- NETWORK
- Published
- 06/01/2023
- Modified
- 21/12/2025
Command Execution vulnerability in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via …
- Attack vector
- NETWORK
- Published
- 14/09/2023
- Modified
- 21/12/2025
The Four-Faith router models F3x24 and F3x36 are affected by an operating system (OS) command injection vulnerability. At least firmware version 2.0 …
- Attack vector
- NETWORK
- Published
- 27/12/2024
- Modified
- 21/12/2025
A vulnerability was determined in Linksys E1700 1.0.0.4.003. This vulnerability affects the function systemCommand of the file /goform/systemCommand. Executing manipulation of the …
- Attack vector
- Network
- Complexity
- Low
- Published
- 27/08/2025
- Modified
- 29/04/2026
Attack patterns (MITRE) (5)
-
PowerShell Profile subtechnique-of
-
Python Startup Hooks subtechnique-of
-
Trap subtechnique-of
-
Windows Management Instrumentation Event Subscription subtechnique-ofT1546.003 MITRE
-
Unix Shell Configuration Modification subtechnique-ofT1546.004 MITRE
Tool (1)
-
Pacu usesThe MITRE Corporation Confidence 100
Pacu is an open-source AWS exploitation framework. The tool is written in Python and publicly available on GitHub.(Citation: GitHub Pacu)
Course Of Action (1)
-
Update Software mitigates