Threadlinqs IntelligenceStart free

ATT&CK techniquePersistencePrivilege Escalation

T1546 Event Triggered Execution

PersistencePrivilege EscalationEnterprise

As of 2026-10-05, T1546 (Event Triggered Execution) appears in 145 tracked threats, first reported 2026-02-02 and most recently 2026-09-26, with linked actors including TeamPCP, Contagious Interview, APT28; it most often appears alongside T1027 (Obfuscated Files or Information).

Tracked threats
14555 critical, 80 high, 9 medium
First seen
2026-02-02
Last seen
2026-09-26
Threat actors
41In the threats using it
Detection rules
135Blue tier and above

Data as of:

Activity timeline

T1546 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 33 reports, and 145 of the 145 threats were reported in the twelve months to 2026-09.

How adversaries use it

T1546 Event Triggered Execution is catalogued by MITRE ATT&CK under the Persistence and Privilege Escalation tactics in the Enterprise matrix. Threadlinqs maps 145 of 2623 tracked threats (5.5%) to it; by severity that is 55 critical, 80 high, 9 medium.

Threats that use T1546 most often also use T1027 Obfuscated Files or Information (100 threats), T1059 Command and Scripting Interpreter (98 threats), T1005 Data from Local System (95 threats), T1082 System Information Discovery (88 threats), T1036 Masquerading (86 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

41 tracked threat actors appear in the threats that use T1546; the most frequent are TeamPCP (20), Contagious Interview (8), APT28 (6), BlueDelta (6), Forest Blizzard (6).

Mitigations

MITRE ATT&CK lists 2 mitigations for T1546.

Data sources

Telemetry that can reveal T1546, per MITRE ATT&CK.

  • Cloud Service — Cloud Service Modification
  • Command — Command Execution
  • File — File Creation, File Metadata, File Modification
  • Module — Module Load
  • Process — Process Creation
  • WMI — WMI Creation
  • Windows Registry — Windows Registry Key Modification

Threat actors using it

Tracked threats

The 30 most recent of 145 tracked threats that use T1546.

Detection coverage

Threadlinqs maintains 135 detection rules mapped to T1546 (SPL 51, KQL 44, Sigma 38, other 2). Rule content is available to Blue tier accounts and above; this page shows counts only.

135 detection rules (SPL/KQL/Sigma) · Blue and above. Compare plans

Sub-techniques

  • T1546.001 Change Default File Association — 4 tracked threats
  • T1546.002 Screensaver — 1 tracked threat
  • T1546.003 Windows Management Instrumentation Event Subscription — 8 tracked threats
  • T1546.004 Unix Shell Configuration Modification — 28 tracked threats
  • T1546.005 Trap — 0 tracked threats
  • T1546.006 LC_LOAD_DYLIB Addition — 0 tracked threats
  • T1546.007 Netsh Helper DLL — 0 tracked threats
  • T1546.008 Accessibility Features — 1 tracked threat
  • T1546.009 AppCert DLLs — 0 tracked threats
  • T1546.010 AppInit DLLs — 0 tracked threats
  • T1546.011 Application Shimming — 1 tracked threat
  • T1546.012 Image File Execution Options Injection — 1 tracked threat
  • T1546.013 PowerShell Profile — 2 tracked threats
  • T1546.014 Emond — 1 tracked threat
  • T1546.015 Component Object Model Hijacking — 15 tracked threats
  • T1546.016 Installer Packages — 5 tracked threats
  • T1546.017 Udev Rules — 1 tracked threat
  • T1546.018 Python Startup Hooks — 1 tracked threat