If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/techniques/T1553/005 - Subvert Trust Controls: Mark-o.

site address: attack.mitre.org/techniques/T1553/005 redirected to: attack.mitre.org/techniques/T1553/005

site title: Subvert Trust Controls: Mark-of-the-Web Bypass, Sub-technique T1553.005 - Enterprise MITRE ATT&CK®

Our opinion (on Thursday 27 August 2026 0:33:03 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

subvert, trust, controls, of, mark, the, web, bypass, procedure, examples, mitigations, detection, strategy, references, other, sub, techniques,

Text of the page (most frequently used words):
the (35), files (21), and (20), motw (14), file (12), retrieved (11), web (11), att (10), all (10), february (10), mark (10), container (9), with (9), t1553 (9), #bypass (8), are (7), enterprise (7), 2021 (7), iso (7), vhd (6), windows (6), 2022 (6), not (6), has (6), may (6), ics (5), mobile (5), none (5), data (5), techniques (5), 2020 (5), that (5), will (5), subvert (5), controls (5), trust (5), mitre (4), sub (4), explorer (4), for (4), image (4), ta505 (4), from (4), zone (4), identifier (4), name (4), disk (4), version (4), tagged (4), 2026 (3), use (3), cti (3), detection (3), mitigations (3), defenses (3), 2019 (3), vhdx (3), august (3), disable (3), mount (3), qakbot (3), december (3), security (3), internet (3), execution (3), smartscreen (3), protected (3), description (3), consider (3), 005 (3), ntfs (3), known (3), corporation (2), policy (2), domains (2), resources (2), reference (2), campaigns (2), software (2), groups (2), components (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), objects (2), march (2), associations (2), october (2), via (2), 2024 (2), threat (2), financial (2), deliver (2), beek (2), stream (2), mounting (2), archive (2), but (2), contained (2), view (2), analytic (2), extensions (2), this (2), can (2), order (2), feature (2), used (2), deploy (2), malicious (2), measures (2), apt38 (2), apt29 (2), modified (2), ads (2), amadey (2), technique (2), adversaries (2), abuse (2), formats (2), downloaded (2), within (2), after (2), extracted (2), mounted (2), run (2), specific (2), office (2), open (2), executables (2), code (2), signing (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, terms, contact, reset, filters, dormann, september, dangers, wdormann, disc, april, trend, micro, variety, servhelper, flawedammyy, kenefick, black, basta, ransomware, gang, infiltrates, networks, brute, ratel, cobalt, strike, 2023, seongsu, park, bluenoroff, introduces, new, methods, bypassing, eset, report, institute, profiling, group, continues, attack, sector, july, kennedy, zebra, gopher, clothing, russian, apt, uses, covid, lures, zebrocy, hegt, red, team, perspective, investigating, cybercriminals, november, microsoft, references, detects, extraction, zip, originated, whose, lack, tagging, correlates, creation, metadata, subsequent, unsigned, untrusted, binaries, launched, outside, an0712, detect, det0257, strategy, blocking, types, email, gateways, unregistering, prevention, m1038, disabling, auto, img, achieved, modifying, registry, values, related, automatic, burn, dialog, these, note, deactivate, functionality, itself, remove, program, m1042, mitigation, lnk, g0092, been, packaged, s0650, malware, g0082, embedded, images, html, evade, g0016, area, zero, s1025, procedure, examples, live, permalink, last, created, christiaan, christiaanbeek, contributors, platforms, defense, impairment, tactic, such, compressed, arj, gzip, payloads, marked, inherit, many, support, alternative, streams, them, treated, local, without, protections, when, they, hidden, alternate, named, value, cannot, perform, certain, actions, example, starting, processed, defender, compares, allowlist, well, trusted, prevent, warn, user, modification, 006, install, root, certificate, 004, sip, provider, hijacking, 003, 002, gatekeeper, 001, other, home, join, mclean, hotel, location, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, tools, advisory, council, learn, more, about, get, started, detections,


Text of the page (random words):
subvert trust controls mark of the web bypass sub technique t1553 005 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise subvert trust controls mark of the web bypass subvert trust controls mark of the web bypass other sub techniques of subvert trust controls 6 id name t1553 001 gatekeeper bypass t1553 002 code signing t1553 003 sip and trust provider hijacking t1553 004 install root certificate t1553 005 mark of the web bypass t1553 006 code signing policy modification adversaries may abuse specific file formats to subvert mark of the web motw controls in windows when files are downloaded from the internet they are tagged with a hidden ntfs alternate data stream ads named zone identifier with a specific value known as the motw 1 files that are tagged with motw are protected and cannot perform certain actions for example starting in ms office 10 if a ms office file has the motw it will open in protected view executables tagged with the motw will be processed by windows defender smartscreen that compares files with an allowlist of well known executables if the file is not known trusted smartscreen will prevent the execution and warn the user not to run it 2 3 4 adversaries may abuse container files such as compressed archive arj gzip and or disk image iso vhd file formats to deliver malicious payloads that may not be tagged with motw container files downloaded from the internet will be marked with motw but the files within may not inherit the motw after the container files are extracted and or mounted motw is a ntfs feature and many container files do not support ntfs alternative data streams after a container file is extracted and or mounted the files contained within them may be treated as local files on disk and run without protections 2 3 id t1553 005 sub technique of t1553 ⓘ tactic defense impairment ⓘ platforms windows contributors christiaan beek christiaanbeek version 2 0 created 22 february 2021 last modified 12 may 2026 version permalink live version procedure examples id name description s1025 amadey amadey has modified the zone identifier in the ads area to zero 5 g0016 apt29 apt29 has embedded iso images and vhdx files in html to evade mark of the web 6 g0082 apt38 apt38 has used iso and vhd files to deploy malware and to bypass mark of the web motw security measures 7 s0650 qakbot qakbot has been packaged in iso files in order to bypass mark of the web motw security measures 8 g0092 ta505 ta505 has used iso files to deploy malicious lnk files 9 mitigations id mitigation description m1042 disable or remove feature or program consider disabling auto mounting of disk image files i e iso img vhd and vhdx this can be achieved by modifying the registry values related to the windows explorer file associations in order to disable the automatic explorer mount and burn dialog for these file extensions note this will not deactivate the mount functionality itself 10 m1038 execution prevention consider blocking container file types at web and or email gateways consider unregistering container file extensions in windows file explorer 11 detection strategy id name analytic id analytic description det0257 detect mark of the web motw bypass via container and disk image files an0712 detects extraction or mounting of container archive files e g iso vhd zip that originated from the internet but whose contained files lack zone identifier motw tagging correlates file creation metadata with subsequent execution of unsigned or untrusted binaries launched outside smartscreen or protected view references microsoft 2020 august 31 zone identifier stream name retrieved february 22 2021 beek c 2020 december 3 investigating the use of vhd files by cybercriminals retrieved november 17 2024 hegt s 2020 march 30 mark of the web from a red team s perspective retrieved february 22 2021 kennedy j 2020 december 9 a zebra in gopher s clothing russian apt uses covid 19 lures to deliver zebrocy retrieved february 22 2021 financial security institute 2020 february 28 profiling of ta505 threat group that continues to attack the financial sector retrieved july 14 2022 eset 2022 february threat report t3 2021 retrieved february 10 2022 seongsu park 2022 december 27 bluenoroff introduces new methods bypassing motw retrieved february 6 2024 kenefick i et al 2022 october 12 black basta ransomware gang infiltrates networks via qakbot brute ratel and cobalt strike retrieved february 6 2023 trend micro 2019 august 27 ta505 variety in use of servhelper and flawedammyy retrieved february 22 2021 wdormann 2019 august 29 disable windows explorer file associations for disc image mount retrieved april 16 2022 dormann w 2019 september 4 the dangers of vhd and vhdx files retrieved march 16 2021 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 57 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-57


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


The site also has 1 references to other resources (not html/xhtml )

 www.welivesecurity.com/wp-content/uplo___.pdf  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/attack.mitre.org/techniques/T1553/005
X-GitHub-Request-Id 0D58:22168F:9E5BA:A7DF8:6A8F85BF
x-github-edge-region uksouth
Accept-Ranges bytes
Age 0
Date Thu, 27 Aug 2026 00:33:03 GMT
Via 1.1 varnish
X-Served-By cache-lcy-egml8630050-LCY
X-Cache MISS
X-Cache-Hits 0
X-Timer S1787790783.125459,VS0,VE81
Vary Accept-Encoding
X-Fastly-Request-ID 8d37a2394cd78621721a2ffed680265dd89ce472
HTTP/2 301
server GitHub.com
content-type text/html
location htt????/attack.mitre.org/techniques/T1553/005/
access-control-allow-origin *
expires Thu, 27 Aug 2026 00:43:03 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id B7C0:390388:A173F:AAF7D:6A8F85BB
x-github-edge-region uksouth
accept-ranges bytes
age 0
date Thu, 27 Aug 2026 00:33:03 GMT
via 1.1 varnish
x-served-by cache-lcy-egml8630056-LCY
x-cache MISS
x-cache-hits 0
x-timer S1787790783.234124,VS0,VE84
vary Accept-Encoding
x-fastly-request-id 5c9f89bbd0fc9daeac8a55a31a9f6e727498ff68
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:21 GMT
access-control-allow-origin *
etag W/ 6a75ea95-d936
expires Thu, 27 Aug 2026 00:43:03 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id 3096:2CC5E7:A1196:AA9F5:6A8F85BF
x-github-edge-region uksouth
accept-ranges bytes
age 0
date Thu, 27 Aug 2026 00:33:03 GMT
via 1.1 varnish
x-served-by cache-lcy-egml8630056-LCY
x-cache MISS
x-cache-hits 0
x-timer S1787790783.326658,VS0,VE88
vary Accept-Encoding
x-fastly-request-id cfe48782f32e82997c1bc3b9b706d4f6fe8376e5
content-length 9279

Meta Tags

title="Subvert Trust Controls: Mark-of-the-Web Bypass, Sub-technique T1553.005 - Enterprise | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size9279
load time (s)0.571677
redirect count2
speed download16250
server IP 185.199.108.153
* all occurrences of the string "http://" have been changed to "htt???/"