Compliance Node Overview
MITRE ATT&CK T1204.003 (Malicious Image) is an Enterprise Execution sub-technique of T1204 (User Execution). Adversaries may rely on a user running a malicious image to facilitate execution. Amazon Web Services (AWS) Amazon Machine Images (AMIs), Google Cloud Platform (GCP) Images, and Azure Images as well as popular container runtimes such as Docker can be backdoored. Affected platforms: IaaS, Containers. MITRE-documented mitigations include M1045 Code Signing, M1031 Network Intrusion Prevention, M1017 User Training, M1047 Audit. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-04, CA-07, CM-02, CM-06, CM-07, RA-05, SC-07, SC-44.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1204/003/
SHA-256 integrity: d9967cfcc8e973f436d2100f808fdcf262565de9eb71f6fc983ec869d3ffbca1
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1204.003: Malicious Image (https://attack.mitre.org/techniques/T1204/003/)
- MITRE ATT&CK Tactic TA0002: Execution (https://attack.mitre.org/tactics/TA0002/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access