Compliance Node Overview
MITRE ATT&CK T1059.005 (Visual Basic) is an Enterprise Execution sub-technique of T1059 (Command and Scripting Interpreter). Adversaries may abuse Visual Basic (VB) for execution. VB is a programming language created by Microsoft with interoperability with many Windows technologies such as Component Object Model and the Native API through the Windows API. Although tagged as legacy with no planned future evolutions, VB is integrated and supported in the .NET Framework and cross-platform .NET Core. Derivative languages based on VB have also been created, such as Visual Basic for Applications (VBA) and VBScript. Affected platforms: Windows, macOS, Linux. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1049 Antivirus/Antimalware, M1038 Execution Prevention, M1040 Behavior Prevention on Endpoint, M1021 Restrict Web-Based Content. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, AC-17, CA-07, CM-02, CM-05.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1059/005/
SHA-256 integrity: 85d783696d78215c5123ad07d5a0d4e61528f20342eaf18ad9913c23385d31d4
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1059.005: Visual Basic (https://attack.mitre.org/techniques/T1059/005/)
- MITRE ATT&CK Tactic TA0002: Execution (https://attack.mitre.org/tactics/TA0002/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access