Compliance Node Overview
MITRE ATT&CK T1505.004 (IIS Components) is an Enterprise Persistence sub-technique of T1505 (Server Software Component). Adversaries may install malicious components that run on Internet Information Services (IIS) web servers to establish persistence. IIS provides several mechanisms to extend the functionality of the web servers. For example, Internet Server Application Programming Interface (ISAPI) extensions and filters can be installed to examine and/or modify incoming and outgoing IIS web requests. Affected platforms: Windows. MITRE-documented mitigations include M1026 Privileged Account Management, M1038 Execution Prevention, M1047 Audit, M1045 Code Signing. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, AC-16, AC-17, CM-02.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1505/004/
SHA-256 integrity: a4db08f37d85cbb8fa01dc605d078aa867ca16a33344f769fa6808eb42ce4eb5
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1505.004: IIS Components (https://attack.mitre.org/techniques/T1505/004/)
- MITRE ATT&CK Tactic TA0003: Persistence (https://attack.mitre.org/tactics/TA0003/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access