// MITRE ATT&CK
T1505 · Server Software Component
Adversaries may abuse legitimate extensible development features of servers to establish persistent access to systems. Enterprise server applications may include features that allow developers to write and install software or scripts to extend the functionality of the main application. Adversaries m...
¿Cómo detectarlo y mitigarlo?
La detección de Server Software Component parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.
Sub-técnicas (6)
T1505.001
SQL Stored Procedures T1505.002
Transport Agent T1505.003
Web Shell T1505.004
IIS Components T1505.005
Terminal Services DLL T1505.006
vSphere Installation Bundles
SQL Stored Procedures T1505.002
Transport Agent T1505.003
Web Shell T1505.004
IIS Components T1505.005
Terminal Services DLL T1505.006
vSphere Installation Bundles
Técnicas relacionadas
T1037
Boot or Logon Initialization Scripts T1543
Create or Modify System Process T1133
External Remote Services T1547
Boot or Logon Autostart Execution T1547.014
Active Setup T1176.001
Browser Extensions T1543.003
Windows Service T1137
Office Application Startup
Boot or Logon Initialization Scripts T1543
Create or Modify System Process T1133
External Remote Services T1547
Boot or Logon Autostart Execution T1547.014
Active Setup T1176.001
Browser Extensions T1543.003
Windows Service T1137
Office Application Startup
Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.