Compliance Node Overview
MITRE ATT&CK T1127.003 (JamPlus) is an Enterprise Stealth, Execution technique. Adversaries may use `JamPlus` to proxy the execution of a malicious script. `JamPlus` is a build utility tool for code and data build systems. It works with several popular compilers and can be used for generating workspaces in code editors such as Visual Studio. Adversaries may abuse the `JamPlus` build utility to execute malicious scripts via a `.jam` file, which describes the build process and required dependencies. Because the malicious script is executed from a reputable developer tool, it may subvert application control security systems such as Smart App Control. Affected platforms: Windows. Sub-technique of ATT&CK T1127. ATT&CK-mapped mitigations: M1038 Execution Prevention, M1042 Disable or Remove Feature or Program.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1127/003/
SHA-256 integrity: bde5a458e9cfd4cfc3ef13ff421ab9f9972ab4abd7498ad0e622ac1af8026e94
Primary Citations — 6 traced to source
- MITRE ATT&CK Technique T1127.003: JamPlus (https://attack.mitre.org/techniques/T1127/003/)
- MITRE ATT&CK Tactic TA0005: Stealth (https://attack.mitre.org/tactics/TA0005/)
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.