Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

MITRE ATT&CK T1484: Domain or Tenant Policy Modification (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation)

MITRE ATT&CK T1484 (Domain or Tenant Policy Modification) is an Enterprise Defense Evasion and Privilege Escalation technique. Adversaries may modify the…

What MITRE ATT&CK T1484: Domain or Tenant Policy Modification (Enterprise Tactic TA0005 - Defense Evasion / TA0004 - Privilege Escalation) requires

MITRE ATT&CK T1484 (Domain or Tenant Policy Modification) is an Enterprise Defense Evasion and Privilege Escalation technique. Adversaries may modify the configuration settings of a domain or identity tenant to evade defenses and/or escalate privileges in centrally managed environments. Such services provide a centralized means of managing identity resources such as devices and accounts, and often include configuration settings that may apply between domains or tenants such as trust relationships, identity syncing, or identity federation. ATT&CK documents 2 sub-techniques: T1484.001 Group Policy Modification; T1484.002 Trust Modification. Affected platforms: Windows, Identity Provider. MITRE-documented mitigations include M1047 Audit, M1026 Privileged Account Management, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, CM-02, CM-05, CM-06.

Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:

Primary source: https://attack.mitre.org/techniques/T1484/

SHA-256 integrity: 7cf9cc31d78e0d4ff2fe8a4ebc94de2d6d265b7f8f4df67b0a699748a4f04f48

Primary Citations — 7 traced to source

  • MITRE ATT&CK Technique T1484: Domain or Tenant Policy Modification (https://attack.mitre.org/techniques/T1484/) with 2 sub-techniques
  • MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)

+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.