What MITRE ATT&CK T1218.014: MMC (Enterprise Tactic TA0005 - Defense Evasion) requires
MITRE ATT&CK T1218.014 (MMC) is an Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may abuse mmc.exe to proxy execution of malicious .msc files. Microsoft Management Console (MMC) is a binary that may be signed by Microsoft and is used in several ways in either its GUI or in a command prompt. MMC can be used to create, open, and save custom consoles that contain administrative tools created by Microsoft, called snap-ins. These snap-ins may be used to manage Windows systems locally or remotely. MMC can also be used to open Microsoft created .msc files to manage system configuration. Affected platforms: Windows. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, CA-07, CM-02, CM-05.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1218/014/
SHA-256 integrity: 6ca7d1345dcf987446e487333cf1e5145f006f33305b9015438d7e337b73e7d8
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1218.014: MMC (https://attack.mitre.org/techniques/T1218/014/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access