Compliance Node Overview
MITRE ATT&CK T1562.011 (Spoof Security Alerting) is an Enterprise Defense Evasion sub-technique of T1562 (Impair Defenses). Adversaries may spoof security alerting from tools, presenting false evidence to impair defenders' awareness of malicious activity. Messages produced by defensive tools contain information about potential security events as well as the functioning status of security software and the system. Security reporting messages are important for monitoring the normal operation of a system and identifying important events that can signal a security incident. Affected platforms: Windows, macOS, Linux. MITRE-documented mitigations include M1038 Execution Prevention. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-05, AC-06, CA-07, CM-02, CM-05, CM-06.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/versions/v16/techniques/T1562/011/
SHA-256 integrity: bc8a8b45b5c386c0d8df4bea589eb1c6c35c30fb0e304eca119b0633b85e6acf
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1562.011: Spoof Security Alerting (https://attack.mitre.org/versions/v16/techniques/T1562/011/)
- MITRE ATT&CK Tactic TA0005: Defense Evasion (https://attack.mitre.org/tactics/TA0005/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access