Compliance Node Overview
MITRE ATT&CK T1546.016 (Installer Packages) is an Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence and elevate privileges by using an installer to trigger the execution of malicious content. Installer packages are OS specific and contain the resources an operating system needs to install applications on a system. Installer packages can include scripts that run prior to installation as well as after installation is complete. Installer scripts may inherit elevated permissions when executed. Affected platforms: Linux, macOS, Windows. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-06, CA-07, CM-02, CM-03, CM-05, CM-06.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1546/016/
SHA-256 integrity: d707a3f00ecaac8101c6d92442b1c6e96a678ad65b6d228f303fe5f29873596b
Primary Citations — 6 traced to source
- MITRE ATT&CK Technique T1546.016: Installer Packages (https://attack.mitre.org/techniques/T1546/016/)
- MITRE ATT&CK Tactic TA0004: Privilege Escalation (https://attack.mitre.org/tactics/TA0004/)
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.