Esc
Create or Modify System Process - T1543
(ATT&CK® Technique)
Definition
Adversaries may create or modify system-level processes to repeatedly execute malicious payloads as part of persistence. When operating systems boot up, they can start processes that perform background system functions. On Windows and Linux, these system processes are referred to as services. On macOS, launchd processes known as Launch Daemon and Launch Agent are run to finish system initialization and load user specific parameters.
D3FEND Inferred Relationships
Browse the D3FEND knowledge graph by clicking on the nodes below.