If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/techniques/T1480/002 - Execution Guardrails: Mutual E.

site address: attack.mitre.org/techniques/T1480/002 redirected to: attack.mitre.org/techniques/T1480/002

site title: Execution Guardrails: Mutual Exclusion, Sub-technique T1480.002 - Enterprise MITRE ATT&CK®

Our opinion (on Saturday 29 August 2026 9:30:21 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

execution, guardrails, mutual, exclusion, procedure, examples, mitigations, detection, strategy, references, other, sub, techniques, of,

Text of the page (most frequently used words):
the (39), mutex (30), retrieved (27), and (16), 2024 (15), 2025 (15), september (15), malware (13), #execution (13), has (11), att (10), all (10), running (10), name (9), 2026 (8), process (8), may (8), using (8), enterprise (7), new (7), only (7), instance (7), can (7), kimsuky (6), october (6), 2022 (6), march (6), file (6), lock (6), guardrails (6), value (6), ensure (6), one (6), corporation (5), ics (5), mobile (5), none (5), detection (5), techniques (5), with (5), 2021 (5), from (5), april (5), ransomware (5), for (5), embargo (5), created (5), system (5), prevent (5), hard (5), coded (5), create (5), t1480 (5), mitre (4), sub (4), february (4), 2023 (4), spawnchimera (4), access (4), august (4), backdoor (4), its (4), creates (4), itself (4), version (4), mutual (4), exclusion (4), are (3), cti (3), data (3), mitigations (3), defenses (3), objects (3), troll (3), stealer (3), january (3), team (3), sunspot (3), strelastealer (3), revil (3), qilin (3), variant (3), purecrypter (3), lockbit (3), july (3), hiddenface (3), grimagent (3), used (3), gazer (3), black (3), basta (3), bpfdoor (3), linux (3), mutexes (3), resource (3), conditional (3), based (3), description (3), not (3), compromised (3), duplicate (3), avoid (3), that (3), victim (3), function (3), other (3), host (3), utilized (3), powershell (3), hardcoded (3), nec (3), 002 (3), acquire (3), synchronize (3), 2015 (2), use (2), domains (2), resources (2), reference (2), campaigns (2), software (2), groups (2), components (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), intelligence (2), analysis (2), december (2), vulnerability (2), secureworks (2), june (2), targets (2), mustang (2), panda (2), espionage (2), 2017 (2), second (2), rust (2), golo (2), muhr (2), joshua (2), chung (2), hive0154 (2), vilkomir (2), preisman (2), lenny (2), zeltser (2), names (2), likely (2), uses (2), flock (2), tmp (2), already (2), open (2), predictable (2), path (2), followed (2), behavior (2), adversary (2), named (2), createmutexw (2), code (2), reinfection (2), platforms (2), analytic (2), should (2), tools (2), subsequent (2), malicious (2), toneshell (2), fixed (2), strncpy (2), which (2), when (2), attempts (2), default (2), poisonivy (2), leveraged (2), plugx (2), check (2), more (2), whether (2), pid (2), script (2), time (2), last (2), generated (2), will (2), claimloader (2), exits (2), fails (2), presence (2), apt38 (2), india (2), technique (2), creating (2), given (2), multiple (2), associated (2), adversaries (2), ckcon (2), person (2), tickets (2), faq (2), registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, contact, reset, filters, jiho, kim, sebin, lee, s2w, disguised, korean, company, signed, valid, certificate, distribute, english, ver, crowdstrike, implant, build, fortgale, yuma, masubuchi, chimera, spawning, ivanti, connect, secure, 2019, sodinokibi, halcyon, rise, boasts, enhanced, encryption, defense, evasion, dumont, technical, fully, functional, loader, distributing, remote, trojans, information, stealers, fireeye, 2014, poison, ivy, assessing, damage, extracting, counter, threat, unit, research, bronze, president, government, officials, alexandre, cote, cyr, hodur, old, tricks, korplug, fbi, stopransomware, varadharajan, krishnasamy, aditya, sood, reconnaissance, control, operational, blueprint, apt, cyber, alexndru, cristian, bardas, dprk, playbook, httptroy, lazarus, blindingcan, breitenbacher, unmasking, priego, brothers, grim, reversing, tale, ryuk, eset, gazing, turla, stage, jan, holman, tomas, zvara, rock, cyble, revolution, steps, targeting, philippines, pakistan, taiwan, suspected, campaign, aka, shifts, focus, tibetan, community, deploy, pubload, beating, seongsu, park, bluenoroff, introduces, methods, bypassing, motw, how, generates, evade, shaul, eliran, nissan, evolves, stealthy, sniffing, ups, game, joakim, kennedy, avigayil, mechtinger, redxor, operated, chinese, nation, state, actor, 2012, looking, discovery, indicators, compromise, microsoft, references, user, mode, application, nsdistributedlock, gain, exclusive, guard, logic, alters, locked, an0374, acquired, via, lockf, lock123, early, exit, divergent, an0373, apis, termination, alternate, indicating, avoiding, an0372, across, det0132, strategy, mitigated, preventative, controls, because, protect, unintended, being, targeted, efforts, focused, preventing, earlier, chain, activity, identifying, mitigate, m1055, mitigation, during, installation, s1196, s1239, 12d61a41, 4b74, 7610, a4d8, 3028d2f56395, s0562, variants, include, values, s1183, buffer, overflow, cve, 0282, hooking, limiting, size, 256, actors, leveraging, exploit, converted, hexadecimal, verifies, added, triggered, first, byte, source, copied, matches, 0x04050203, s9024, instances, s0496, s1242, contains, global, s9019, either, custom, s0012, infection, s0013, containing, hash, than, machineguid, s1202, detect, actively, store, currently, into, txt, saved, locally, temp, directory, queried, prior, duplication, g0094, s9023, bytes, binary, compute, invalid, generic, mymutex, s0632, 531511fa, 190d, 5d85, 8a4a, 279f2f592cc7, s0168, loadupongunsbringyourfriends, also, intothefloodagainsameoldtrip, s1247, single, s1236, executed, runtime, specified, resulting, makeshift, var, run, initd, s1161, before, executing, dsajdhas, s1070, g0082, procedure, examples, live, permalink, modified, manikantan, srinivasan, nagahama, hiroki, japan, pooja, natarajan, contributors, windows, macos, stealth, tactic, dynamically, algorithm, environments, instead, attempt, able, continues, execute, while, local, exist, within, allowing, threads, activities, processes, unique, particular, verify, been, constrain, actions, locking, mechanism, thread, environmental, keying, 001, home, join, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, advisory, council, learn, about, get, started, detections,


Text of the page (random words):
execution guardrails mutual exclusion sub technique t1480 002 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise execution guardrails mutual exclusion execution guardrails mutual exclusion other sub techniques of execution guardrails 2 id name t1480 001 environmental keying t1480 002 mutual exclusion adversaries may constrain execution or actions based on the presence of a mutex associated with malware a mutex is a locking mechanism used to synchronize access to a resource only one thread or process can acquire a mutex at a given time 1 while local mutexes only exist within a given process allowing multiple threads to synchronize access to a resource system mutexes can be used to synchronize the activities of multiple processes 1 by creating a unique system mutex associated with a particular malware adversaries can verify whether or not a system has already been compromised 2 in linux environments malware may instead attempt to acquire a lock on a mutex file if the malware is able to acquire the lock it continues to execute if it fails it exits to avoid creating a second instance of itself 3 4 mutex names may be hard coded or dynamically generated using a predictable algorithm 5 id t1480 002 sub technique of t1480 ⓘ tactic stealth ⓘ platforms linux windows macos contributors manikantan srinivasan nec corporation india nagahama hiroki nec corporation japan pooja natarajan nec corporation india version 2 0 created 19 september 2024 last modified 12 may 2026 version permalink live version procedure examples id name description g0082 apt38 apt38 has created a mutex to avoid duplicate execution 6 s1070 black basta black basta will check for the presence of a hard coded mutex dsajdhas 0 before executing 7 s1161 bpfdoor when executed bpfdoor attempts to create and lock a runtime file var run initd lock and exits if it fails using the specified file resulting in a makeshift mutex 4 s1236 claimloader claimloader has created hardcoded mutex to ensure only a single instance of the malware is running 8 9 s1247 embargo embargo has utilized a hardcoded mutex name of loadupongunsbringyourfriends using the createmutexw function 10 embargo has also utilized a hardcoded mutex name of intothefloodagainsameoldtrip 11 s0168 gazer gazer creates a mutex using the hard coded value 531511fa 190d 5d85 8a4a 279f2f592cc7 to ensure that only one instance of itself is running 12 s0632 grimagent grimagent uses the last 64 bytes of the binary to compute a mutex name if the generated name is invalid it will default to the generic mymutex 13 s9023 hiddenface hiddenface can create a mutex to ensure only one instance is running at a time 14 g0094 kimsuky kimsuky has utilized a mutex to detect whether its malware is actively running on the victim host 15 16 kimsuky has leveraged powershell to store the process id pid of the currently running malicious powershell script into a file named pid txt which is saved locally on the victim host in the temp directory and is queried prior to execution of subsequent powershell script to prevent duplication 16 s1202 lockbit 3 0 lockbit 3 0 can create and check for a mutex containing a hash of the machineguid value at execution to prevent running more than one instance 17 s0013 plugx plugx has leveraged a mutex in its infection process 18 19 s0012 poisonivy poisonivy creates a mutex using either a custom or default value 20 s9019 purecrypter purecrypter code contains a global mutex 21 s1242 qilin qilin can create a mutex to ensure only one instance is running 22 s0496 revil revil attempts to create a mutex using a hard coded value to ensure that no other instances of itself are running on the host 23 s9024 spawnchimera spawnchimera has fixed a buffer overflow vulnerability cve 2025 0282 by hooking the strncpy function and limiting the size to 256 to prevent other actors from leveraging the exploit 24 spawnchimera has converted its process name to hexadecimal and verifies an added value which is triggered when the first byte of the source copied to the fixed strncpy function matches 0x04050203 24 s1183 strelastealer strelastealer variants include the use of mutex values based on the victim system name to prevent reinfection 25 s0562 sunspot sunspot creates a mutex using the hard coded value 12d61a41 4b74 7610 a4d8 3028d2f56395 to ensure that only one instance of itself is running 26 s1239 toneshell toneshell has created a mutex to avoid duplicate execution 9 s1196 troll stealer troll stealer creates a mutex during installation to prevent duplicate execution 27 mitigations id mitigation description m1055 do not mitigate execution guardrails likely should not be mitigated with preventative controls because it may protect unintended targets from being compromised if targeted efforts should be focused on preventing adversary tools from running earlier in the chain of activity and on identifying subsequent malicious behavior if compromised detection strategy id name analytic id analytic description det0132 detection of mutex based execution guardrails across platforms an0372 adversary created named mutex using system apis e g createmutexw followed by conditional process termination or alternate code path indicating malware avoiding reinfection an0373 file lock acquired via open flock or lockf on predictable path e g tmp lock123 followed by conditional early exit or divergent process behavior an0374 user mode application uses flock or nsdistributedlock to gain exclusive access to a resource file e g tmp guard lock conditional logic alters execution if already locked references microsoft 2022 march 11 mutexes retrieved september 19 2024 lenny zeltser 2012 july 24 looking at mutex objects for malware discovery indicators of compromise retrieved september 19 2024 joakim kennedy and avigayil mechtinger 2021 march 10 new linux backdoor redxor likely operated by chinese nation state actor retrieved september 19 2024 shaul vilkomir preisman and eliran nissan 2023 may 10 bpfdoor malware evolves stealthy sniffing backdoor ups its game retrieved september 19 2024 lenny zeltser 2015 march 9 how malware generates mutex names to evade detection retrieved september 19 2024 seongsu park 2022 december 27 bluenoroff introduces new methods bypassing motw retrieved february 6 2024 vilkomir preisman s 2022 august 18 beating black basta ransomware retrieved march 8 2023 golo muhr joshua chung 2025 june 23 hive0154 aka mustang panda shifts focus on tibetan community to deploy pubload backdoor retrieved august 4 2025 golo muhr joshua chung 2025 may 15 hive0154 targeting us philippines pakistan and taiwan in suspected espionage campaign retrieved august 4 2025 cyble 2024 may 24 the rust revolution new embargo ransomware steps in retrieved october 19 2025 jan holman tomas zvara 2024 october 23 embargo ransomware rock n rust retrieved october 19 2025 eset 2017 august gazing at gazer turla s new second stage backdoor retrieved september 14 2017 priego a 2021 july the brothers grim the reversing tale of grimagent malware used by ryuk retrieved september 19 2024 breitenbacher d 2024 unmasking hiddenface retrieved april 17 2026 alexndru cristian bardas 2025 october 30 dprk s playbook kimsuky s httptroy and lazarus s new blindingcan variant retrieved april 8 2026 varadharajan krishnasamy aditya k sood 2025 july 29 from reconnaissance to control the operational blueprint of kimsuky apt for cyber espionage retrieved april 18 2026 fbi et al 2023 march 16 stopransomware lockbit 3 0 retrieved february 5 2025 alexandre cote cyr 2022 march 23 mustang panda s hodur old tricks new korplug variant retrieved september 9 2025 secureworks counter threat unit research team 2022 september 8 bronze president targets government officials retrieved september 9 2025 fireeye 2014 poison ivy assessing damage and extracting intelligence retrieved september 19 2024 dumont r 2022 june 13 technical analysis of purecrypter a fully functional loader distributing remote access trojans and information stealers retrieved april 16 2026 halcyon rise team 2024 october 24 new qilin b ransomware variant boasts enhanced encryption and defense evasion retrieved september 26 2025 secureworks 2019 september 24 revil sodinokibi ransomware retrieved 2021 04 12 yuma masubuchi 2025 february 20 spawnchimera malware the chimera spawning from ivanti connect secure vulnerability retrieved april 17 2026 fortgale 2023 september 18 strelastealer malware analysis retrieved december 31 2024 crowdstrike intelligence team 2021 january 11 sunspot an implant in the build process retrieved january 11 2021 jiho kim sebin lee s2w 2024 february 7 kimsuky disguised as a korean company signed with a valid certificate to distribute troll stealer english ver retrieved january 17 2025 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 67 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-65 66-67


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
x-origin-cache HIT
Location htt????/attack.mitre.org/techniques/T1480/002
X-GitHub-Request-Id 9AAC:3C0852:FD0DDE:FFD4B4:6A92A6AC
x-github-edge-region fra
Accept-Ranges bytes
Age 0
Date Sat, 29 Aug 2026 09:30:21 GMT
Via 1.1 varnish
X-Served-By cache-rtm-ehrd2290030-RTM
X-Cache MISS
X-Cache-Hits 0
X-Timer S1787995821.001792,VS0,VE92
Vary Accept-Encoding
X-Fastly-Request-ID 2f89b8b9729afdf1a2c03d99b11323253f6914e2
HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/techniques/T1480/002/
access-control-allow-origin *
expires Sat, 29 Aug 2026 09:40:21 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id B67C:3C0852:FD0E0C:FFD4DF:6A92A6AD
x-github-edge-region fra
accept-ranges bytes
age 0
date Sat, 29 Aug 2026 09:30:21 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290037-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787995821.121346,VS0,VE102
vary Accept-Encoding
x-fastly-request-id 1d2c7782b5c88d9a333be6af9e600f4321048fbe
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:18 GMT
access-control-allow-origin *
etag W/ 6a75ea92-133cb
expires Sat, 29 Aug 2026 09:40:21 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id 0E4A:13584E:10379ED:1064139:6A92A6AC
x-github-edge-region fra
accept-ranges bytes
age 0
date Sat, 29 Aug 2026 09:30:21 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290037-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787995821.231599,VS0,VE107
vary Accept-Encoding
x-fastly-request-id b8816350e3a3fd3e60123652fe3e212b60652954
content-length 12933

Meta Tags

title="Execution Guardrails: Mutual Exclusion, Sub-technique T1480.002 - Enterprise | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size12933
load time (s)0.821732
redirect count2
speed download15752
server IP 185.199.111.153
* all occurrences of the string "http://" have been changed to "htt???/"