Meta tags:
Headings (most frequently used words):
server, software, component, mitigations, detection, strategy, references, sub, techniques,
Text of the page (most frequently used words):
t1505 (15), and (12), software (12), all (11), the (10), att (10), #server (10), enterprise (8), that (7), component (7), components (6), techniques (6), ics (5), mobile (5), none (5), services (5), for (5), may (5), adversaries (5), mitre (4), detection (4), retrieved (4), malicious (4), abuse (4), version (4), are (3), use (3), cti (3), data (3), mitigations (3), defenses (3), sub (3), web (3), july (3), 2022 (3), day (3), plugins (3), accounts (3), systems (3), application (3), boot (3), 2026 (2), corporation (2), policy (2), domains (2), resources (2), reference (2), campaigns (2), groups (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), objects (2), prevent (2), shell (2), 2021 (2), windows (2), system (2), disabling (2), php (2), june (2), esxi (2), vsphere (2), persistent (2), scripts (2), nginx (2), execute (2), open (2), network (2), extensible (2), modules (2), apache (2), installation (2), iis (2), sql (2), establish (2), strategy (2), analytic (2), description (2), name (2), user (2), can (2), add (2), account (2), management (2), consider (2), critical (2), registry (2), permissions (2), allow (2), have (2), servers (2), developers (2), integrity (2), persistence (2), october (2), 006 (2), 005 (2), 004 (2), 003 (2), 002 (2), 001 (2), features (2), applications (2), install (2), extend (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, terms, contact, reset, filters, nsa, asd, 2020, april, detect, malware, microsoft, 2018, february, fundamentals, march, kondratiev, dangerous, functions, adair, lancaster, volexity, threat, research, driftingcloud, zero, sophos, firewall, exploitation, insidious, breach, references, interface, extensions, embed, an1510, webserver, node, applescript, sockets, an1509, tomcat, load, rogue, initiate, bash, connect, spawn, reverse, shells, an1508, later, command, line, interpreters, outbound, connections, an1507, det0547, enforce, principle, least, privilege, limiting, privileges, only, authorized, modify, m1018, using, group, configure, block, modifications, service, other, parameters, restrict, m1024, not, administrator, these, used, operations, expose, them, potential, unprivileged, privileged, m1026, from, when, possible, disable, remove, feature, program, m1042, ensure, binaries, signed, correct, code, signing, m1045, enabling, secure, allows, validation, drivers, during, initial, m1046, regularly, check, target, verify, identify, unexpected, changes, been, made, audit, m1047, mitigation, live, permalink, 2025, last, modified, 2019, created, linux, devices, macos, platforms, tactic, legitimate, development, access, include, write, functionality, main, bundles, terminal, dll, transport, agent, stored, procedures, home, join, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, with, tools, advisory, council, learn, more, about, get, started, detections, technique,
Text of the page (random words):
server software component technique t1505 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise server software component server software component sub techniques 6 id name t1505 001 sql stored procedures t1505 002 transport agent t1505 003 web shell t1505 004 iis components t1505 005 terminal services dll t1505 006 vsphere installation bundles adversaries may abuse legitimate extensible development features of servers to establish persistent access to systems enterprise server applications may include features that allow developers to write and install software or scripts to extend the functionality of the main application adversaries may install malicious components to extend and abuse server applications 1 id t1505 sub techniques t1505 001 t1505 002 t1505 003 t1505 004 t1505 005 t1505 006 ⓘ tactic persistence ⓘ platforms esxi linux network devices windows macos version 1 5 created 28 june 2019 last modified 24 october 2025 version permalink live version mitigations id mitigation description m1047 audit regularly check component software on critical services that adversaries may target for persistence to verify the integrity of the systems and identify if unexpected changes have been made m1046 boot integrity enabling secure boot allows validation of software and drivers during initial system boot m1045 code signing ensure all application component binaries are signed by the correct application developers m1042 disable or remove feature or program consider disabling software components from servers when possible to prevent abuse by adversaries 2 m1026 privileged account management do not allow administrator accounts that have permissions to add component software on these services to be used for day to day operations that may expose them to potential adversaries on unprivileged systems m1024 restrict registry permissions consider using group policy to configure and block modifications to service and other critical server parameters in the registry 3 m1018 user account management enforce the principle of least privilege by limiting privileges of user accounts so only authorized accounts can modify and or add server software components 4 detection strategy id name analytic id analytic description det0547 detection strategy for t1505 server software component an1507 installation of malicious iis apache sql server modules that later execute command line interpreters or establish outbound connections an1508 abuse of extensible server modules e g apache nginx tomcat to load rogue plugins that initiate bash connect to c2 or spawn reverse shells an1509 malicious use of webserver plugins e g for nginx php node js that execute applescript or open network sockets an1510 use of esxi web interface plugins or vsphere extensions to embed persistent malicious scripts or services references adair s lancaster t volexity threat research 2022 june 15 driftingcloud zero day sophos firewall exploitation and an insidious breach retrieved july 1 2022 kondratiev a n d disabling dangerous php functions retrieved july 26 2021 microsoft 2018 february 17 windows system services fundamentals retrieved march 28 2022 nsa and asd 2020 april 3 detect and prevent web shell malware retrieved july 23 2021 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
|