What MITRE ATT&CK T1484: Domain or Tenant Policy Modification (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation) requires
MITRE ATT&CK T1484 (Domain or Tenant Policy Modification) is an Enterprise Defense Evasion and Privilege Escalation technique. Adversaries may modify the configuration settings of a domain or identity tenant to evade defenses and/or escalate privileges in centrally managed environments. Such services provide a centralized means of managing identity resources such as devices and accounts, and often include configuration settings that may apply between domains or tenants such as trust relationships, identity syncing, or identity federation. ATT&CK documents 2 sub-techniques: T1484.001 Group Policy Modification; T1484.002 Trust Modification. Affected platforms: Windows, Identity Provider. MITRE-documented mitigations include M1047 Audit, M1026 Privileged Account Management, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, CM-02, CM-05, CM-06.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1484/
SHA-256 integrity: 7cf9cc31d78e0d4ff2fe8a4ebc94de2d6d265b7f8f4df67b0a699748a4f04f48
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1484: Domain or Tenant Policy Modification (https://attack.mitre.org/techniques/T1484/) with 2 sub-techniques
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-t1484-domain-or-tenant-policy-modification.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-t1484-domain-or-tenant-policy-modification.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-t1484-domain-or-tenant-policy-modification
- Back to registry: Browse all 10,085 compliance nodes