T1546.002sub-technique of T1546 Event Triggered Execution

Screensaver

Windowsnothing on this site yetT1546.002 on attack.mitre.org

Adversaries may establish persistence by executing malicious content triggered by user inactivity. Screensavers are programs that execute after a configurable time of user inactivity and consist of Portable Executable (PE) files with a.scr file extension.

MITRE ATT&CK 19.2, retrieved 2026-09-12

If this is happening now

2

Checklists and playbooks to open while the alert is still live.

Playbook for this stage

Cloud account compromise

Impossible travel, an unrecognised inbox rule, or a reported invoice-fraud attempt.

how MITRE says to see it

Detect Screensaver-Based Persistence via Registry and Execution Chains

  • Unusual screensaver (.scr) executions correlated with recent registry modifications to HKCU\Control Panel\Desktop values such as SCRNSAVE.exe, ScreenSaveTimeout, and ScreenSaveActive. Detection focuses on PE image paths not consistent with known legitimate screensavers and triggered after user inactivity timeout.

what reduces it

  • M1038 Execution Prevention. Block.scr files from being executed from non-standard locations.
  • M1042 Disable or Remove Feature or Program. Use Group Policy to disable screensavers if they are unnecessary.

the rest of T1546

The description, detection analytics and mitigations are reproduced from MITRE ATT&CK, version 19.2, under its terms of use. The checklists, hunts, labs and everything else linked here are this site’s.