Applied Cybernetics Group
T1505 — Server Software Component
- Technique
T1505- Tactics
- Persistence
- MISP citations
- 0
- KEV CVEs mapped
- 2
- Community rules
- 1
- thrunt rules
- 0
- Upstream
- https://attack.mitre.org/techniques/T1505
MITRE description
Adversaries may abuse legitimate extensible development features of servers to establish persistent access to systems. Enterprise server applications may include features that allow developers to write and install software or scripts to extend the functionality of the main application. Adversaries may install malicious components to extend and abuse server applications.(Citation: volexity_0day_sophos_FW)
KEV CVEs mapped to this technique
Per MITRE CTID's hand-curated KEV→ATT&CK mappings — these are the actively-exploited vulnerabilities behind this technique's KEV signal.
Detection coverage
SigmaHQ community rules
- Cisco Modify Configuration (core)