Esc
Emond - T1546.014
(ATT&CK® Technique)
Definition
Adversaries may gain persistence and elevate privileges by executing malicious content triggered by the Event Monitor Daemon (emond). Emond is a Launch Daemon that accepts events from various services, runs them through a simple rules engine, and takes action. The emond binary at /sbin/emond will load any rules from the /etc/emond.d/rules/ directory and take action once an explicitly defined event takes place.
D3FEND Inferred Relationships
Browse the D3FEND knowledge graph by clicking on the nodes below.