Compliance Node Overview
MITRE ATT&CK T1199 (Trusted Relationship) is an Enterprise Initial Access technique. Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be protected or receives less scrutiny than standard mechanisms of gaining access to a network. Organizations often grant elevated access to second or third-party external providers in order to allow them to manage internal systems as well as cloud-based environments. Affected platforms: Windows, SaaS, IaaS, Linux, macOS, Identity Provider, Office Suite. MITRE-documented mitigations include M1032 Multi-factor Authentication, M1018 User Account Management, M1030 Network Segmentation. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-03, AC-04, AC-06, AC-08, CM-06, CM-07, SC-07, SC-46.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1199/
SHA-256 integrity: 4aa10729af47e1cec3c444a4662a9f010c5e0292cfa3277a4d8503b9ef013612
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1199: Trusted Relationship (https://attack.mitre.org/techniques/T1199/)
- MITRE ATT&CK Tactic TA0001: Initial Access (https://attack.mitre.org/tactics/TA0001/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access