Compliance Node Overview
MITRE ATT&CK T1547.004 (Winlogon Helper DLL) is an Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may abuse features of Winlogon to execute DLLs and/or executables when a user logs in. Winlogon.exe is a Windows component responsible for actions at logon/logoff as well as the secure attention sequence (SAS) triggered by Ctrl-Alt-Delete. Registry entries in HKLM\Software[\\Wow6432Node\\]\Microsoft\Windows NT\CurrentVersion\Winlogon\ and HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\ are used to manage additional helper programs and functionalities that support Winlogon. Affected platforms: Windows. MITRE-documented mitigations include M1038 Execution Prevention, M1018 User Account Management. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, AC-17, CM-05, CM-07, IA-02.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1547/004/
SHA-256 integrity: a81bcb1795a889f8519388061327cb73ae08fdb64b6ea7330b32d9bd3f9222e1
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1547.004: Winlogon Helper DLL (https://attack.mitre.org/techniques/T1547/004/)
- MITRE ATT&CK Tactic TA0003: Persistence (https://attack.mitre.org/tactics/TA0003/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.