Compliance Node Overview
MITRE CAPEC-579 (Replace Winlogon Helper DLL) is a detailed-level attack pattern in the MITRE Common Attack Pattern Enumeration and Classification. Winlogon is a part of Windows that performs logon actions. In Windows systems prior to Windows Vista, a registry key can be modified that causes Winlogon to load a DLL on startup. Adversaries may take advantage of this feature to load adversarial code at startup. Likelihood of attack: Unknown. Maps to weaknesses CWE-15. Relates to MITRE ATT&CK T1547.004.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://capec.mitre.org/data/definitions/579.html
SHA-256 integrity: 0f42ee55c822034c330767defa4a07e9176ed0ec81f134b895f8ab9cebd18fdd
Primary Citations — 9 traced to source
- MITRE CAPEC-579: Replace Winlogon Helper DLL (https://capec.mitre.org/data/definitions/579.html)
- CWE-15: underlying weakness (http://cwe.mitre.org/data/definitions/15.html)
+ 7 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.