Compliance Node Overview
MITRE ATT&CK T1689 (Downgrade Attack) is an Enterprise Defense Impairment technique. Adversaries may downgrade or use a version of system features that may be outdated, vulnerable, and/or does not support updated security controls. Downgrade attacks typically take advantage of a system’s backward compatibility to force it into less secure modes of operation. Adversaries may downgrade and use various less-secure versions of features of a system, such as Command and Scripting Interpreter or even network protocols that can be abused to enable Adversary-in-the-Middle or Network Sniffing. For example, PowerShell versions 5+ includes Script Block Logging (SBL), which can record executed script content. However, adversaries may attempt to execute a previous version of PowerShell that does not support SBL with the intent to impair defenses while running malicious scripts that may ... Affected platforms: macOS, Windows, Linux. ATT&CK-mapped mitigations: M1054 Software Configuration, M1042 Disable or Remove Feature or Program.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1689/
SHA-256 integrity: c9b9468d35cddf324420b9b86200888dff7b9bae884f2758d58ab00e146d3982
Primary Citations — 6 traced to source
- MITRE ATT&CK Technique T1689: Downgrade Attack (https://attack.mitre.org/techniques/T1689/)
- MITRE ATT&CK Tactic TA0112: Defense Impairment (https://attack.mitre.org/tactics/TA0112/)
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.