What MITRE ATT&CK T1546.009: AppCert DLLs (Enterprise Tactic TA0004 - Privilege Escalation / TA0003 - Persistence) requires
MITRE ATT&CK T1546.009 (AppCert DLLs) is an Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppCert DLLs loaded into processes. Dynamic-link libraries (DLLs) that are specified in the AppCertDLLs Registry key under HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Session Manager\ are loaded into every process that calls the ubiquitously used application programming interface (API) functions CreateProcess, CreateProcessAsUser, CreateProcessWithLoginW, CreateProcessWithTokenW, or WinExec. Affected platforms: Windows. MITRE-documented mitigations include M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-06, CM-02, CM-03, CM-06, CM-07, IA-09.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1546/009/
SHA-256 integrity: c0b70fd6488f781a6aec13c90c3d9e074bb5ccd0a85c00190583e7e11f8d5598
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1546.009: AppCert DLLs (https://attack.mitre.org/techniques/T1546/009/)
- MITRE ATT&CK Tactic TA0004: Privilege Escalation (https://attack.mitre.org/tactics/TA0004/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access