Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

MITRE ATT&CK T1553.005: Mark-of-the-Web Bypass (Enterprise Tactic TA0005 - Defense Evasion)

MITRE ATT&CK T1553.005 (Mark-of-the-Web Bypass) is an Enterprise Defense Evasion sub-technique of T1553 (Subvert Trust Controls). Adversaries may abuse…

What MITRE ATT&CK T1553.005: Mark-of-the-Web Bypass (Enterprise Tactic TA0005 - Defense Evasion) requires

MITRE ATT&CK T1553.005 (Mark-of-the-Web Bypass) is an Enterprise Defense Evasion sub-technique of T1553 (Subvert Trust Controls). Adversaries may abuse specific file formats to subvert Mark-of-the-Web (MOTW) controls. In Windows, when files are downloaded from the Internet, they are tagged with a hidden NTFS Alternate Data Stream (ADS) named Zone.Identifier with a specific value known as the MOTW. Files that are tagged with MOTW are protected and cannot perform certain actions. For example, starting in MS Office 10, if a MS Office file has the MOTW, it will open in Protected View. Affected platforms: Windows. MITRE-documented mitigations include M1042 Disable or Remove Feature or Program, M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-06, CM-02, CM-03, CM-05, CM-06, CM-07.

Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:

Primary source: https://attack.mitre.org/techniques/T1553/005/

SHA-256 integrity: 4e30654838ef337febfc0d0818fbb2ae02586fe2842a0dbd46361de15fcadace

Primary Citations — 7 traced to source

  • MITRE ATT&CK Technique T1553.005: Mark-of-the-Web Bypass (https://attack.mitre.org/techniques/T1553/005/)
  • MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)

+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.