Compliance Node Overview
MITRE ATT&CK T1221 (Template Injection) is an Enterprise Defense Evasion technique. Adversaries may create or modify references in user document templates to conceal malicious code or force authentication attempts. For example, Microsoft's Office Open XML (OOXML) specification defines an XML-based format for Office documents (.docx, xlsx, .pptx) to replace older binary formats (.doc, .xls, .ppt). OOXML files are packed together ZIP archives compromised of various XML files, referred to as parts, containing properties that collectively define how a document is rendered. Affected platforms: Windows. MITRE-documented mitigations include M1049 Antivirus/Antimalware, M1031 Network Intrusion Prevention, M1017 User Training, M1042 Disable or Remove Feature or Program. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls CA-07, CM-02, CM-06, CM-07, CM-08, RA-05, SC-07, SC-44.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1221/
SHA-256 integrity: ce8662b82d23d5072ca6f76375892ec33152b97f69f13777f12e159a9559e390
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1221: Template Injection (https://attack.mitre.org/techniques/T1221/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access