What MITRE ATT&CK T1127.002: ClickOnce (Enterprise Tactic TA0005 - Defense Evasion) requires
MITRE ATT&CK T1127.002 (ClickOnce) is an Enterprise Defense Evasion sub-technique of T1127 (Trusted Developer Utilities Proxy Execution). Adversaries may use ClickOnce applications (.appref-ms and .application files) to proxy execution of code through a trusted Windows utility. ClickOnce is a deployment that enables a user to create self-updating Windows-based .NET applications (i.e, .XBAP, .EXE, or .DLL) that install and run from a file share or web page with minimal user interaction. The application launches as a child process of DFSVC.EXE, which is responsible for installing, launching, and updating the application. Affected platforms: Windows. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1021 Restrict Web-Based Content, M1045 Code Signing. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-17, CM-02, CM-06, CM-07, CM-08, RA-05, SC-18, SI-04.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1127/002/
SHA-256 integrity: 521188efc5859328e40ef09b2e4d26dacd37f72639f53699411f9455488a79fa
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1127.002: ClickOnce (https://attack.mitre.org/techniques/T1127/002/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-t1127-002-clickonce.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-t1127-002-clickonce.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-t1127-002-clickonce
- Back to registry: Browse all 10,085 compliance nodes