What MITRE ATT&CK T1021.005: VNC (Enterprise Tactic TA0008 - Lateral Movement) requires
MITRE ATT&CK T1021.005 (VNC) is an Enterprise Lateral Movement sub-technique of T1021 (Remote Services). Adversaries may use Valid Accounts to remotely control machines using Virtual Network Computing (VNC). VNC is a platform-independent desktop sharing system that uses the RFB ("remote framebuffer") protocol to enable users to remotely control another computer's display by relaying the screen, mouse, and keyboard inputs over the network. VNC differs from Remote Desktop Protocol as VNC is screen-sharing software rather than resource-sharing software. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1037 Filter Network Traffic, M1047 Audit, M1033 Limit Software Installation. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, AC-07, AC-17, AC-20.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1021/005/
SHA-256 integrity: b45e77e02d79cece9da35e3ed15148fb888c9e3257b3c6c1811dc8b4f24848b2
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1021.005: VNC (https://attack.mitre.org/techniques/T1021/005/)
- MITRE ATT&CK Tactic TA0008: Lateral Movement (https://attack.mitre.org/tactics/TA0008/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access