What MITRE ATT&CK T1055.004: Asynchronous Procedure Call (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation) requires
MITRE ATT&CK T1055.004 (Asynchronous Procedure Call) is an Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into processes via the asynchronous procedure call (APC) queue in order to evade process-based defenses as well as possibly elevate privileges. APC injection is a method of executing arbitrary code in the address space of a separate live process. APC injection is commonly performed by attaching malicious code to the APC Queue of a process's thread. Queued APC functions are executed when the thread enters an alterable state. Affected platforms: Windows. MITRE-documented mitigations include M1040 Behavior Prevention on Endpoint. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, CM-05, CM-06, IA-02, SC-07.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1055/004/
SHA-256 integrity: aee146458a34ab343adae406cb3b4c211292abbf55fc0035d62720259926f16e
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1055.004: Asynchronous Procedure Call (https://attack.mitre.org/techniques/T1055/004/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.