What MITRE ATT&CK T1546.005: Trap (Enterprise Tactic TA0004 - Privilege Escalation / TA0003 - Persistence) requires
MITRE ATT&CK T1546.005 (Trap) is an Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence by executing malicious content triggered by an interrupt signal. The trap command allows programs and shells to specify commands that will be executed upon receiving interrupt signals. A common situation is a script allowing for graceful termination and handling of common keyboard interrupts like ctrl+c and ctrl+d. Adversaries can use this to register code to be executed when the shell encounters specific interrupts as a persistence mechanism. Affected platforms: macOS, Linux. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-06, CM-02, CM-03, CM-06, IA-09, SI-02.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1546/005/
SHA-256 integrity: 5cd1335406d0215e0e460ce51c7cb6ec066bea6aa58a6198b2c8d17b37e6a33f
Primary Citations — 6 traced to source
- MITRE ATT&CK Technique T1546.005: Trap (https://attack.mitre.org/techniques/T1546/005/)
- MITRE ATT&CK Tactic TA0004: Privilege Escalation (https://attack.mitre.org/tactics/TA0004/)
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-t1546-005-trap.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-t1546-005-trap.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-t1546-005-trap
- Back to registry: Browse all 10,085 compliance nodes