Packt SecPro

Packt SecPro

Understanding MITRE ATT&CK T1547

Boot or Logon Autostart Execution

Austin Miller's avatar
Austin Miller
Apr 04, 2025
∙ Paid
2
1
Share

MITRE ATT&CK technique T1547, known as Boot or Logon Autostart Execution, refers to a tactic used by attackers to maintain persistence on a compromised system. This technique exploits mechanisms that allow programs to start automatically when a computer boots up or when a user logs in. Attackers leverage this method to ensure their malware or unauthoriz…

Keep reading with a 7-day free trial

Subscribe to Packt SecPro to keep reading this post and get 7 days of free access to the full post archives.

Already a paid subscriber? Sign in
© 2025 Packt Publishing Ltd.
Privacy ∙ Terms ∙ Collection notice
Start writingGet the app
Substack is the home for great culture