Compliance Node Overview
MITRE ATT&CK T1021 covers adversary use of valid accounts to log into remote services for lateral movement. Sub-techniques cover Remote Desktop Protocol (T1021.001), SMB/Windows Admin Shares (T1021.002), Distributed Component Object Model (T1021.003), SSH (T1021.004), VNC (T1021.005), Windows Remote Management (T1021.006), Cloud Services (T1021.007), and Direct Cloud VM Connections (T1021.008). RDP abuse remains the #1 vector for ransomware operators. Compliance obligations include MFA on all remote services, jump-host architectures, and audit logging required under PCI DSS Req 8.3.6 and NIS2 Article 21.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1021/
SHA-256 integrity: 6a5550068dbf8c90188febe942f4fa26a828497fc7019189a33415eb4d8dd27b
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1021: Remote Services (https://attack.mitre.org/techniques/T1021/) with 8 sub-techniques
- NIST SP 800-53 Rev 5: AC-17 (Remote Access), IA-2 (MFA)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.