Compliance Node Overview
MITRE ATT&CK T1220 (XSL Script Processing) is an Enterprise Defense Evasion technique. Adversaries may bypass application control and obscure execution of code by embedding scripts inside XSL files. Extensible Stylesheet Language (XSL) files are commonly used to describe the processing and rendering of data within XML files. To support complex operations, the XSL standard includes support for embedded scripting in various languages. Adversaries may abuse this functionality to execute arbitrary files while potentially bypassing application control. Affected platforms: Windows. MITRE-documented mitigations include M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CM-02, CM-06, CM-07, SI-04, SI-07, SI-10.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1220/
SHA-256 integrity: dd83f94a17e7fc13bc2a443c2fa360f722bf9e6b7e937d9478b9dee5d6b606ea
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1220: XSL Script Processing (https://attack.mitre.org/techniques/T1220/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.