If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/techniques/T1505 - Server Software Component, Tec.

site address: attack.mitre.org/techniques/T1505 redirected to: attack.mitre.org/techniques/T1505

site title: Server Software Component, Technique T1505 - Enterprise MITRE ATT&CK®

Our opinion (on Sunday 16 August 2026 20:07:17 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

server, software, component, mitigations, detection, strategy, references, sub, techniques,

Text of the page (most frequently used words):
t1505 (15), and (12), software (12), all (11), the (10), att (10), #server (10), enterprise (8), that (7), component (7), components (6), techniques (6), ics (5), mobile (5), none (5), services (5), for (5), may (5), adversaries (5), mitre (4), detection (4), retrieved (4), malicious (4), abuse (4), version (4), are (3), use (3), cti (3), data (3), mitigations (3), defenses (3), sub (3), web (3), july (3), 2022 (3), day (3), plugins (3), accounts (3), systems (3), application (3), boot (3), 2026 (2), corporation (2), policy (2), domains (2), resources (2), reference (2), campaigns (2), groups (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), objects (2), prevent (2), shell (2), 2021 (2), windows (2), system (2), disabling (2), php (2), june (2), esxi (2), vsphere (2), persistent (2), scripts (2), nginx (2), execute (2), open (2), network (2), extensible (2), modules (2), apache (2), installation (2), iis (2), sql (2), establish (2), strategy (2), analytic (2), description (2), name (2), user (2), can (2), add (2), account (2), management (2), consider (2), critical (2), registry (2), permissions (2), allow (2), have (2), servers (2), developers (2), integrity (2), persistence (2), october (2), 006 (2), 005 (2), 004 (2), 003 (2), 002 (2), 001 (2), features (2), applications (2), install (2), extend (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, terms, contact, reset, filters, nsa, asd, 2020, april, detect, malware, microsoft, 2018, february, fundamentals, march, kondratiev, dangerous, functions, adair, lancaster, volexity, threat, research, driftingcloud, zero, sophos, firewall, exploitation, insidious, breach, references, interface, extensions, embed, an1510, webserver, node, applescript, sockets, an1509, tomcat, load, rogue, initiate, bash, connect, spawn, reverse, shells, an1508, later, command, line, interpreters, outbound, connections, an1507, det0547, enforce, principle, least, privilege, limiting, privileges, only, authorized, modify, m1018, using, group, configure, block, modifications, service, other, parameters, restrict, m1024, not, administrator, these, used, operations, expose, them, potential, unprivileged, privileged, m1026, from, when, possible, disable, remove, feature, program, m1042, ensure, binaries, signed, correct, code, signing, m1045, enabling, secure, allows, validation, drivers, during, initial, m1046, regularly, check, target, verify, identify, unexpected, changes, been, made, audit, m1047, mitigation, live, permalink, 2025, last, modified, 2019, created, linux, devices, macos, platforms, tactic, legitimate, development, access, include, write, functionality, main, bundles, terminal, dll, transport, agent, stored, procedures, home, join, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, with, tools, advisory, council, learn, more, about, get, started, detections, technique,


Text of the page (random words):
server software component technique t1505 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise server software component server software component sub techniques 6 id name t1505 001 sql stored procedures t1505 002 transport agent t1505 003 web shell t1505 004 iis components t1505 005 terminal services dll t1505 006 vsphere installation bundles adversaries may abuse legitimate extensible development features of servers to establish persistent access to systems enterprise server applications may include features that allow developers to write and install software or scripts to extend the functionality of the main application adversaries may install malicious components to extend and abuse server applications 1 id t1505 sub techniques t1505 001 t1505 002 t1505 003 t1505 004 t1505 005 t1505 006 ⓘ tactic persistence ⓘ platforms esxi linux network devices windows macos version 1 5 created 28 june 2019 last modified 24 october 2025 version permalink live version mitigations id mitigation description m1047 audit regularly check component software on critical services that adversaries may target for persistence to verify the integrity of the systems and identify if unexpected changes have been made m1046 boot integrity enabling secure boot allows validation of software and drivers during initial system boot m1045 code signing ensure all application component binaries are signed by the correct application developers m1042 disable or remove feature or program consider disabling software components from servers when possible to prevent abuse by adversaries 2 m1026 privileged account management do not allow administrator accounts that have permissions to add component software on these services to be used for day to day operations that may expose them to potential adversaries on unprivileged systems m1024 restrict registry permissions consider using group policy to configure and block modifications to service and other critical server parameters in the registry 3 m1018 user account management enforce the principle of least privilege by limiting privileges of user accounts so only authorized accounts can modify and or add server software components 4 detection strategy id name analytic id analytic description det0547 detection strategy for t1505 server software component an1507 installation of malicious iis apache sql server modules that later execute command line interpreters or establish outbound connections an1508 abuse of extensible server modules e g apache nginx tomcat to load rogue plugins that initiate bash connect to c2 or spawn reverse shells an1509 malicious use of webserver plugins e g for nginx php node js that execute applescript or open network sockets an1510 use of esxi web interface plugins or vsphere extensions to embed persistent malicious scripts or services references adair s lancaster t volexity threat research 2022 june 15 driftingcloud zero day sophos firewall exploitation and an insidious breach retrieved july 1 2022 kondratiev a n d disabling dangerous php functions retrieved july 26 2021 microsoft 2018 february 17 windows system services fundamentals retrieved march 28 2022 nsa and asd 2020 april 3 detect and prevent web shell malware retrieved july 23 2021 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 63 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-60 61-63


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/attack.mitre.org/techniques/T1505
X-GitHub-Request-Id A416:123EB8:7885E62:7935916:6A821874
x-github-edge-region fra
Accept-Ranges bytes
Age 0
Date Sun, 16 Aug 2026 20:07:16 GMT
Via 1.1 varnish
X-Served-By cache-rtm-ehrd2290033-RTM
X-Cache MISS
X-Cache-Hits 0
X-Timer S1786910837.786818,VS0,VE100
Vary Accept-Encoding
X-Fastly-Request-ID cea80da3f317a6d3cd8176c9ff0eba0fff21fd81
HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/techniques/T1505/
access-control-allow-origin *
expires Sun, 16 Aug 2026 20:17:16 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id 2B96:F43F3:7782C2D:7832717:6A821874
x-github-edge-region fra
accept-ranges bytes
age 0
date Sun, 16 Aug 2026 20:07:17 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290045-RTM
x-cache MISS
x-cache-hits 0
x-timer S1786910837.926600,VS0,VE106
vary Accept-Encoding
x-fastly-request-id 7c807d11adcceb11230de81fc65f6d2126319529
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:19 GMT
access-control-allow-origin *
etag W/ 6a75ea93-b8d2
expires Sun, 16 Aug 2026 20:17:17 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id 579C:190D74:76DCAAB:778C302:6A821874
x-github-edge-region fra
accept-ranges bytes
date Sun, 16 Aug 2026 20:07:17 GMT
via 1.1 varnish
age 0
x-served-by cache-rtm-ehrd2290045-RTM
x-cache MISS
x-cache-hits 0
x-timer S1786910837.045529,VS0,VE111
vary Accept-Encoding
x-fastly-request-id e1da3c80d2c6da1e9ab72670f92ae64b58752cf7
content-length 7809

Meta Tags

title="Server Software Component, Technique T1505 - Enterprise | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size7809
load time (s)0.395645
redirect count2
speed download19769
server IP 185.199.111.153
* all occurrences of the string "http://" have been changed to "htt???/"