What MITRE ATT&CK T1546.011: Application Shimming (Enterprise Tactic TA0004 - Privilege Escalation / TA0003 - Persistence) requires
MITRE ATT&CK T1546.011 (Application Shimming) is an Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims. The Microsoft Windows Application Compatibility Infrastructure/Framework (Application Shim) was created to allow for backward compatibility of software as the operating system codebase changes over time. Affected platforms: Windows. MITRE-documented mitigations include M1052 User Account Control, M1051 Update Software. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-06, CM-02, CM-03, CM-06, IA-09, SI-02.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1546/011/
SHA-256 integrity: 7120e0b3597c0825fa917238813882534657f8edeca70be5c882d62711eb659f
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1546.011: Application Shimming (https://attack.mitre.org/techniques/T1546/011/)
- MITRE ATT&CK Tactic TA0004: Privilege Escalation (https://attack.mitre.org/tactics/TA0004/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-t1546-011-application-shimming.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-t1546-011-application-shimming.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-t1546-011-application-shimming
- Back to registry: Browse all 10,085 compliance nodes