Compliance Node Overview
MITRE ATT&CK T1106 covers adversary direct invocation of operating system APIs to execute code, bypassing higher-level interpreters and detection mechanisms that rely on parent-process telemetry. Common implementations include direct syscalls in Windows (ntdll.dll) and unhooked execution to evade EDR userland hooks. The technique is favoured by sophisticated threat actors (APT29, FIN7) for stealth. Compliance obligations include kernel-level EDR coverage (NIST 800-53 SI-3, ISO A.8.7), application allowlisting that operates at the kernel level (e.g., WDAC), and behavioural detection that does not rely solely on userland hooks per the NIS2 Article 21 implementation framework.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1106/
SHA-256 integrity: 162214f41aa0c0650a254a605e19d813a5fdd55edcc36a2f49b07395194af3d4
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1106: Native API (https://attack.mitre.org/techniques/T1106/) - covers direct OS API invocation including ntdll.dll syscalls
- NIST SP 800-53 Rev 5: SI-3 (Malicious Code Protection), SI-7 (Software, Firmware, and Information Integrity)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.