LiveActive security incident?Get immediate response
MITRE ATT&CK® Mitigation

M1042: Disable or Remove Feature or Program

Disable or remove unnecessary and potentially vulnerable software, features, or services to reduce the attack surface and prevent abuse by adversaries. This involves identifying software or features that are no longer needed or that could be exploited and ensuring they are either removed or properly disabled. This mitigation can be implemented through the following measures:

Remove Legacy Software:

- Use Case: Disable or remove older versions of software that no longer receive updates or security patches (e.g., legacy Java, Adobe Flash). - Implementation: A company removes Flash Player from all employee systems after it has reached its end-of-life date.

Disable Unused Features:

- Use Case: Turn off unnecessary operating system features like SMBv1, Telnet, or RDP if they are not required. - Implementation: Disable SMBv1 in a Windows environment to mitigate vulnerabilities like EternalBlue.

Control Applications Installed by Users:

- Use Case: Prevent users from installing unauthorized software via group policies or other management tools. - Implementation: Block user installations of unauthorized file-sharing applications (e.g., BitTorrent clients) in an enterprise environment.

Remove Unnecessary Services:

- Use Case: Identify and disable unnecessary default services running on endpoints, servers, or network devices. - Implementation: Disable unused administrative shares (e.g., C$, ADMIN$) on workstations.

Restrict Add-ons and Plugins:

- Use Case: Remove or disable browser plugins and add-ons that are not needed for business purposes. - Implementation: Disable Java and ActiveX plugins in web browsers to prevent drive-by attacks.

EnterpriseM1042MitigationObject v1.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Disabling or removing unnecessary software, features, services, plugins, and legacy components is a basic but high-value attack-surface reduction control. For leaders, the decision value is not “turn things off” in the abstract; it is whether the organization can prove that exposed remote access paths, scripting engines, removable media functions, browser plugins, and unsupported software are needed, governed, and monitored. This mitigation matters because many related ATT&CK techniques depend on features that are commonly installed by default or left enabled after business need has changed.

Executive priority

Prioritize this as a resilience and governance control: every unused service or end-of-life component creates avoidable exposure, complicates incident response, and weakens audit evidence. Executives should ask whether the organization has an authoritative inventory, a business-justification process for enabled remote access and scripting capabilities, and a repeatable exception process. This is especially relevant to lateral movement via remote services, exfiltration through Bluetooth/USB/other media, abuse of command and scripting interpreters, account and cloud credential persistence paths, and legacy or user-installed software risk.

Technical view

SOC, IR, and detection engineering teams should validate this mitigation against the related techniques it is mapped to: Remote Services including RDP, SSH, VNC, WinRM, DCOM, and direct cloud VM connections; Network Service Discovery; Command and Scripting Interpreter use including PowerShell, Visual Basic, and JavaScript; removable media and Bluetooth-based exfiltration or command-and-control; account manipulation including added cloud credentials, SSH authorized keys, and email forwarding rules; and trusted developer utility proxy execution. Because ATT&CK provides no detection text for this mitigation, teams should focus on evidence of control state: what is installed, what is enabled, what is reachable, who can change it, and where exceptions exist.

Likely telemetry

  • Endpoint software and feature inventory, including legacy and end-of-life applications
  • Service configuration and startup state for remote access and administrative services
  • Network exposure data showing listening services and reachable management interfaces
  • Authentication and session logs for RDP, SSH, VNC, WinRM, DCOM, and cloud VM access where present
  • Cloud and identity audit logs for added credentials, service principals, keys, mailbox permissions, and forwarding rules

Detection direction

  • Validate that discovery alerts for newly enabled services are tied to asset criticality and approved baseline state, not only port activity.
  • Tune remote-service monitoring around unauthorized enablement, unexpected exposure, and use by accounts without a documented business need.
  • Correlate removable media, Bluetooth, and alternate network interface activity with data movement and host sensitivity where such telemetry exists.
  • For scripting engines and developer utilities, distinguish approved administrative or development use from unexpected execution on systems where those features should be disabled or restricted.
  • For identity and cloud-related relationships, monitor for configuration drift such as new credentials, SSH authorized keys, mailbox delegation, and forwarding rules rather than relying only on login alerts.

Mitigation priorities

  • Start with inventory: identify unsupported software, unnecessary services, browser plugins, add-ons, user-installed applications, remote access features, scripting engines, and removable-media capabilities.
  • Remove end-of-life or unsupported software first, because it cannot be reliably remediated through patching alone.
  • Disable unused remote services and administrative interfaces, including examples supplied by ATT&CK such as SMBv1, Telnet, RDP where not required, and unnecessary default services or administrative shares.
  • Control user-installed applications through managed policy and approval workflows to reduce ungoverned software exposure.
  • Restrict or disable browser plugins and add-ons that lack a business purpose, including legacy plugin technologies identified by ATT&CK such as Java and ActiveX.
Additional notes and limits

This mitigation is broad and control-oriented, so its value depends on asset inventory quality, configuration management, and exception discipline. The relationship context shows relevance across execution, lateral movement, discovery, command-and-control, collection, persistence, privilege escalation, and exfiltration behaviors. For Glexia services, this is a practical bridge between vulnerability management, identity/cloud hardening, managed detection, incident response readiness, and compliance evidence.

The official ATT&CK object does not specify platforms, tactics, or detection guidance for the mitigation itself. Platform and tactic context comes only from the supplied relationships to techniques. Local business requirements are required before disabling features, because some remote services, interpreters, plugins, or removable-media workflows may be operationally necessary.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Disable or Remove Feature or Program

Disable or remove unnecessary and potentially vulnerable software, features, or services to reduce the attack surface and prevent abuse by adversaries. This involves identifying software or features that are no longer needed or that could be exploited and ensuring they are either removed or properly disabled. This mitigation can be implemented through the following measures:

Remove Legacy Software:

- Use Case: Disable or remove older versions of software that no longer receive updates or security patches (e.g., legacy Java, Adobe Flash). - Implementation: A company removes Flash Player from all employee systems after it has reached its end-of-life date.

Disable Unused Features:

- Use Case: Turn off unnecessary operating system features like SMBv1, Telnet, or RDP if they are not required. - Implementation: Disable SMBv1 in a Windows environment to mitigate vulnerabilities like EternalBlue.

Control Applications Installed by Users:

- Use Case: Prevent users from installing unauthorized software via group policies or other management tools. - Implementation: Block user installations of unauthorized file-sharing applications (e.g., BitTorrent clients) in an enterprise environment.

Remove Unnecessary Services:

- Use Case: Identify and disable unnecessary default services running on endpoints, servers, or network devices. - Implementation: Disable unused administrative shares (e.g., C$, ADMIN$) on workstations.

Restrict Add-ons and Plugins:

- Use Case: Remove or disable browser plugins and add-ons that are not needed for business purposes. - Implementation: Disable Java and ActiveX plugins in web browsers to prevent drive-by attacks.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

71 rows
DomainIDNameRelationship / procedure
EnterpriseT1547.007Re-opened ApplicationsSub-technique

This feature can be disabled entirely with the following terminal command: defaults write -g ApplePersistence -bool no.

EnterpriseT1021.004SSHSub-technique

Disable the SSH daemon on systems that do not require it, especially ESXi servers. For macOS, ensure Remote Login is disabled under Sharing Preferences.[1]

EnterpriseT1671Cloud Application Integration

Do not allow users to add new application integrations into a SaaS environment. In Entra ID environments, consider enforcing the “Do not allow user consent” option.[2]

EnterpriseT1021.005VNCSub-technique

Uninstall any VNC server software where not required.

EnterpriseT1210Exploitation of Remote Services

Minimize available services to only those that are necessary.

EnterpriseT1059.005Visual BasicSub-technique

Turn off or restrict access to unneeded VB components.

EnterpriseT1595.003Wordlist ScanningSub-technique

Remove or disable access to any systems, resources, and infrastructure that are not explicitly required to be available externally.

EnterpriseT1021.006Windows Remote ManagementSub-technique

Disable the WinRM service.

EnterpriseT1559Inter-Process Communication

Registry keys specific to Microsoft Office feature control security can be set to disable automatic DDE/OLE execution. [3][4][5] Microsoft also created, and enabled by default, Registry keys to completely disable DDE execution in Word and Excel.[6]

EnterpriseT1564.006Run Virtual InstanceSub-technique

Disable native virtualization technologies such as Hyper-V if not necessary within a given environment. Consider also disabling Windows Sandbox if it is not needed to test or debug applications.

EnterpriseT1557.001Name Resolution Poisoning and SMB RelaySub-technique

Disable LLMNR, mDNS, and NetBIOS in local computer security settings or by group policy if they are not needed within an environment. [7]

EnterpriseT1046Network Service Discovery

Ensure that unnecessary ports and services are closed to prevent risk of discovery and potential exploitation.

EnterpriseT1218.015Electron ApplicationsSub-technique

Remove or deny access to unnecessary and potentially vulnerable software and features to prevent abuse by adversaries. Many native binaries may not be necessary within a given environment: for example, consider disabling the Node.js integration in all renderers that display remote content to protect users by limiting adversaries’ power to plant malicious JavaScript within Electron applications.[8]

EnterpriseT1127.002ClickOnceSub-technique

Disable ClickOnce installations from the internet using the following registry key: `\HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\Security\TrustManager\PromptingLevel — Internet:Disabled`[9][10]

ClickOnce may not be necessary within an environment and should be disabled if not being used.

EnterpriseT1649Steal or Forge Authentication Certificates

Consider disabling old/dangerous authentication protocols (e.g. NTLM), as well as unnecessary certificate features, such as potentially vulnerable AD CS web and other enrollment server roles.[11]

EnterpriseT1114.003Email Forwarding RuleSub-technique

Consider disabling external email forwarding.[12]

EnterpriseT1557Adversary-in-the-Middle

Disable legacy network protocols that may be used to intercept network traffic if applicable, especially those that are not needed within an environment.

EnterpriseT1011Exfiltration Over Other Network Medium

Disable WiFi connection, modem, cellular data connection, Bluetooth, or another radio frequency (RF) channel in local computer security settings or by group policy if it is not needed within an environment.

EnterpriseT1098Account Manipulation

Remove unnecessary and potentially abusable authentication and authorization mechanisms where possible.

EnterpriseT1685Disable or Modify Tools

Consider removing previous versions of tools that are unnecessary to the environment when possible.

EnterpriseT1052.001Exfiltration over USBSub-technique

Disable Autorun if it is unnecessary. [13] Disallow or restrict removable media at an organizational policy level if they are not required for business operations. [14]

EnterpriseT1553.005Mark-of-the-Web BypassSub-technique

Consider disabling auto-mounting of disk image files (i.e., .iso, .img, .vhd, and .vhdx). This can be achieved by modifying the Registry values related to the Windows Explorer file associations in order to disable the automatic Explorer "Mount and Burn" dialog for these file extensions. Note: this will not deactivate the mount functionality itself.[15]

EnterpriseT1505Server Software Component

Consider disabling software components from servers when possible to prevent abuse by adversaries.[16]

EnterpriseT1127.003JamPlusSub-technique

JamPlus may not be necessary within a given environment and should be removed if not used.

EnterpriseT1059.001PowerShellSub-technique

It may be possible to remove PowerShell from systems when not needed, but a review should be performed to assess the impact to an environment, since it could be in use for many legitimate purposes and administrative functions.

Disable/restrict the WinRM Service to help prevent uses of PowerShell for remote execution.

EnterpriseT1218.008OdbcconfSub-technique

Odbcconf.exe may not be necessary within a given environment.

EnterpriseT1091Replication Through Removable Media

Disable Autorun if it is unnecessary. [13] Disallow or restrict removable media at an organizational policy level if it is not required for business operations. [14]

EnterpriseT1137Office Application Startup

Follow Office macro security best practices suitable for your environment. Disable Office VBA macros from executing.

Disable Office add-ins. If they are required, follow best practices for securing them by requiring them to be signed and disabling user notification for allowing add-ins. For some add-ins types (WLL, VBA) additional mitigation is likely required as disabling add-ins in the Office Trust Center does not disable WLL nor does it prevent VBA code from executing. [17]

EnterpriseT1546.002ScreensaverSub-technique

Use Group Policy to disable screensavers if they are unnecessary.[18]

EnterpriseT1059Command and Scripting Interpreter

Disable or remove any unnecessary or unused shells or interpreters.

EnterpriseT1021.003Distributed Component Object ModelSub-technique

Consider disabling DCOM through Dcomcnfg.exe.[19]

EnterpriseT1021.001Remote Desktop ProtocolSub-technique

Disable the RDP service if it is unnecessary.

EnterpriseT1555.004Windows Credential ManagerSub-technique

Consider enabling the “Network access: Do not allow storage of passwords and credentials for network authentication” setting that will prevent network credentials from being stored by the Credential Manager.[20]

EnterpriseT1092Communication Through Removable Media

Disable Autoruns if it is unnecessary.[13]

EnterpriseT1563.002RDP HijackingSub-technique

Disable the RDP service if it is unnecessary.

EnterpriseT1218.013MavinjectSub-technique

Consider removing mavinject.exe if Microsoft App-V is not used within a given environment.

EnterpriseT1563Remote Service Session Hijacking

Disable the remote service (ex: SSH, RDP, etc.) if it is unnecessary.

EnterpriseT1098.004SSH Authorized KeysSub-technique

Disable SSH if it is not necessary on a host or restrict SSH access for specific users/groups using /etc/ssh/sshd_config. Setting the `PermitRootLogin` directive to `no` will prevent the root user from logging in via SSH.[21]

EnterpriseT1557.002ARP Cache PoisoningSub-technique

Consider disabling updating the ARP cache on gratuitous ARP replies.

EnterpriseT1219.002Remote Desktop SoftwareSub-technique

Consider disabling unnecessary remote connection functionality, including both unapproved software installations and specific features built into supported applications.

EnterpriseT1218.012VerclsidSub-technique

Consider removing verclsid.exe if it is not necessary within a given environment.

EnterpriseT1218.005MshtaSub-technique

Mshta.exe may not be necessary within a given environment since its functionality is tied to older versions of Internet Explorer that have reached end of life.

EnterpriseT1563.001SSH HijackingSub-technique

Ensure that agent forwarding is disabled on systems that do not explicitly require this feature to prevent misuse. [22]

EnterpriseT1133External Remote Services

Disable or block remotely available services that may be unnecessary.

EnterpriseT1218.007MsiexecSub-technique

Consider disabling the AlwaysInstallElevated policy to prevent elevated execution of Windows Installer packages.[23]

EnterpriseT1564.007VBA StompingSub-technique

Turn off or restrict access to unneeded VB components.[24]

EnterpriseT1059.007JavaScriptSub-technique

Turn off or restrict access to unneeded scripting components.

EnterpriseT1609Container Administration Command

Remove unnecessary tools and software from containers.

EnterpriseT1218.004InstallUtilSub-technique

InstallUtil may not be necessary within a given environment.

EnterpriseT1127.001MSBuildSub-technique

MSBuild.exe may not be necessary within an environment and should be removed if not being used.

EnterpriseT1011.001Exfiltration Over BluetoothSub-technique

Disable Bluetooth in local computer security settings or by group policy if it is not needed within an environment.

EnterpriseT1218.014MMCSub-technique

MMC may not be necessary within a given environment since it is primarily used by system administrators, not regular users or clients.

EnterpriseT1552.005Cloud Instance Metadata APISub-technique

Disable unnecessary metadata services and restrict or disable insecure versions of metadata services that are in use to prevent adversary access.[25]

EnterpriseT1546.014EmondSub-technique

Consider disabling emond by removing the Launch Daemon plist file.

EnterpriseT1021Remote Services

If remote services, such as the ability to make direct connections to cloud virtual machines, are not required, disable these connection types where feasible. On ESXi servers, consider enabling lockdown mode, which disables direct access to an ESXi host and requires that the host be managed remotely using vCenter.[26][27]

EnterpriseT1021.008Direct Cloud VM ConnectionsSub-technique

If direct virtual machine connections are not required for administrative use, disable these connection types where feasible.

EnterpriseT1137.001Office Template MacrosSub-technique

Follow Office macro security best practices suitable for your environment. Disable Office VBA macros from executing.

Disable Office add-ins. If they are required, follow best practices for securing them by requiring them to be signed and disabling user notification for allowing add-ins. For some add-ins types (WLL, VBA) additional mitigation is likely required as disabling add-ins in the Office Trust Center does not disable WLL nor does it prevent VBA code from executing. [17]

EnterpriseT1505.003Web ShellSub-technique

Consider disabling functions from web technologies such as PHP’s `evaI()` that may be abused for web shells.[16]

EnterpriseT1205Traffic Signaling

Disable Wake-on-LAN if it is not needed within an environment.

EnterpriseT1218System Binary Proxy Execution

Many native binaries may not be necessary within a given environment.

EnterpriseT1052Exfiltration Over Physical Medium

Disable Autorun if it is unnecessary. [13] Disallow or restrict removable media at an organizational policy level if they are not required for business operations. [14]

EnterpriseT1218.009Regsvcs/RegasmSub-technique

Regsvcs and Regasm may not be necessary within a given environment.

EnterpriseT1221Template Injection

Consider disabling Microsoft Office macros/active content to prevent the execution of malicious payloads in documents [28], though this setting may not mitigate the Forced Authentication use for this technique.

EnterpriseT1559.002Dynamic Data ExchangeSub-technique

Registry keys specific to Microsoft Office feature control security can be set to disable automatic DDE/OLE execution. [3][4][5] Microsoft also created, and enabled by default, Registry keys to completely disable DDE execution in Word and Excel.[6]

EnterpriseT1689Downgrade Attack

Consider removing previous versions of tools that are unnecessary to the environment when possible.

EnterpriseT1098.002Additional Email Delegate PermissionsSub-technique

If email delegation is not required, disable it. In Google Workspace this can be accomplished through the Google Admin console.[29]

EnterpriseT1127Trusted Developer Utilities Proxy Execution

Specific developer utilities may not be necessary within a given environment and should be removed if not used.

EnterpriseT1611Escape to Host

Remove unnecessary tools and software from containers.

EnterpriseT1219Remote Access Tools

Consider disabling unnecessary remote connection functionality, including both unapproved software installations and specific features built into supported applications.

EnterpriseT1098.001Additional Cloud CredentialsSub-technique

Remove unnecessary and potentially abusable authentication mechanisms where possible. For example, in Entra ID environments, disable the app password feature unless explicitly required.

EnterpriseT1218.003CMSTPSub-technique

CMSTP.exe may not be necessary within a given environment (unless using it for VPN connection installation).

Relationship explorer

All related ATT&CK context

mitigates · TechniqueT1547.007: Re-opened ApplicationsEnterprisemitigates · TechniqueT1021.004: SSHEnterprisemitigates · TechniqueT1671: Cloud Application IntegrationEnterprisemitigates · TechniqueT1021.005: VNCEnterprisemitigates · TechniqueT1210: Exploitation of Remote ServicesEnterprisemitigates · TechniqueT1059.005: Visual BasicEnterprisemitigates · TechniqueT1595.003: Wordlist ScanningEnterprisemitigates · TechniqueT1021.006: Windows Remote ManagementEnterprisemitigates · TechniqueT1559: Inter-Process CommunicationEnterprisemitigates · TechniqueT1564.006: Run Virtual InstanceEnterprisemitigates · TechniqueT1557.001: Name Resolution Poisoning and SMB RelayEnterprisemitigates · TechniqueT1046: Network Service DiscoveryEnterprisemitigates · TechniqueT1218.015: Electron ApplicationsEnterprisemitigates · TechniqueT1127.002: ClickOnceEnterprisemitigates · TechniqueT1649: Steal or Forge Authentication CertificatesEnterprisemitigates · TechniqueT1114.003: Email Forwarding RuleEnterprisemitigates · TechniqueT1557: Adversary-in-the-MiddleEnterprisemitigates · TechniqueT1011: Exfiltration Over Other Network MediumEnterprisemitigates · TechniqueT1098: Account ManipulationEnterprisemitigates · TechniqueT1685: Disable or Modify ToolsEnterprisemitigates · TechniqueT1052.001: Exfiltration over USBEnterprisemitigates · TechniqueT1553.005: Mark-of-the-Web BypassEnterprisemitigates · TechniqueT1505: Server Software ComponentEnterprisemitigates · TechniqueT1127.003: JamPlusEnterprise
Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.2
Created
Modified
Raw hash
2716083433cfdb09...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.2Current bundle2716083433cf…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Apple Unified Log Analysis Remote Login and Screen Sharing

    Sarah Edwards. (2020, April 30). Analysis of Apple Unified Logs: Quarantine Edition [Entry 6] – Working From Home? Remote Logins. Retrieved August 19, 2021.

    Open source URL
  2. [2]
    Microsoft Entra Configure OAuth Consent

    Microsoft Entra. (2024, September 16). Configure how users consent to applications. Retrieved March 20, 2025.

    Open source URL
  3. [3]
    Microsoft DDE Advisory Nov 2017

    Microsoft. (2017, November 8). Microsoft Security Advisory 4053440 - Securely opening Microsoft Office documents that contain Dynamic Data Exchange (DDE) fields. Retrieved November 21, 2017.

    Open source URL
  4. [4]
    BleepingComputer DDE Disabled in Word Dec 2017

    Cimpanu, C. (2017, December 15). Microsoft Disables DDE Feature in Word to Prevent Further Malware Attacks. Retrieved December 19, 2017.

    Open source URL
  5. [5]
    GitHub Disable DDEAUTO Oct 2017

    Dormann, W. (2017, October 20). Disable DDEAUTO for Outlook, Word, OneNote, and Excel versions 2010, 2013, 2016. Retrieved February 3, 2018.

    Open source URL
  6. [6]
    Microsoft ADV170021 Dec 2017

    Microsoft. (2017, December 12). ADV170021 - Microsoft Office Defense in Depth Update. Retrieved February 3, 2018.

    Open source URL
  7. [7]
    ADSecurity Windows Secure Baseline

    Metcalf, S. (2016, October 21). Securing Windows Workstations: Developing a Secure Baseline. Retrieved November 17, 2017.

    Open source URL
  8. [8]
    Electron Security 2

    Stack Overflow. (n.d.). Why do I see an "Electron Security Warning" after updating my Electron project to the latest version?. Retrieved March 7, 2024.

    Open source URL
  9. [9]
    NetSPI ClickOnce

    Ryan Gandrud. (2015, March 23). All You Need Is One – A ClickOnce Love Story. Retrieved September 9, 2024.

    Open source URL
  10. [10]
    Microsoft Learn ClickOnce Config

    Microsoft. (2023, August 4). Configure the ClickOnce trust prompt behavior. Retrieved September 9, 2024.

    Open source URL
  11. [11]
    SpecterOps Certified Pre Owned

    Schroeder, W. & Christensen, L. (2021, June 22). Certified Pre-Owned - Abusing Active Directory Certificate Services. Retrieved August 2, 2022.

    Open source URL
  12. [12]
    Microsoft BEC Campaign

    Carr, N., Sellmer, S. (2021, June 14). Behind the scenes of business email compromise: Using cross-domain threat data to disrupt a large BEC campaign. Retrieved June 15, 2021.

    Open source URL
  13. [13]
    Microsoft Disable Autorun

    Microsoft. (n.d.). How to disable the Autorun functionality in Windows. Retrieved April 20, 2016.

    Open source URL
  14. [14]
    TechNet Removable Media Control

    Microsoft. (2007, August 31). https://technet.microsoft.com/en-us/library/cc771759(v=ws.10).aspx. Retrieved April 20, 2016.

    Open source URL
  15. [15]
    GitHub MOTW

    wdormann. (2019, August 29). Disable Windows Explorer file associations for Disc Image Mount. Retrieved April 16, 2022.

    Open source URL
  16. [16]
    ITSyndicate Disabling PHP functions

    Kondratiev, A. (n.d.). Disabling dangerous PHP functions. Retrieved July 26, 2021.

    Open source URL
  17. [17]
    MRWLabs Office Persistence Add-ins

    Knowles, W. (2017, April 21). Add-In Opportunities for Office Persistence. Retrieved November 17, 2024.

    Open source URL
  18. [18]
    TechNet Screensaver GP

    Microsoft. (n.d.). Customizing the Desktop. Retrieved December 5, 2017.

    Open source URL
  19. [19]
    Microsoft Disable DCOM

    Microsoft. (n.d.). Enable or Disable DCOM. Retrieved November 22, 2017.

    Open source URL
  20. [20]
    Microsoft Network access Credential Manager

    Microsoft. (2016, August 31). Network access: Do not allow storage of passwords and credentials for network authentication. Retrieved November 23, 2020.

    Open source URL
  21. [21]
    Broadcom ESXi SSH

    Broadcom. (2024, December 12). Allowing SSH access to VMware vSphere ESXi/ESX hosts with public/private key authentication. Retrieved March 26, 2025.

    Open source URL
  22. [22]
    Symantec SSH and ssh-agent

    Hatch, B. (2004, November 22). SSH and ssh-agent. Retrieved January 8, 2018.

    Open source URL
  23. [23]
    Microsoft AlwaysInstallElevated 2018

    Microsoft. (2018, May 31). AlwaysInstallElevated. Retrieved December 14, 2020.

    Open source URL
  24. [24]
    Microsoft Disable VBA Jan 2020

    Microsoft. (2020, January 23). How to turn off Visual Basic for Applications when you deploy Office. Retrieved September 17, 2020.

    Open source URL
  25. [25]
    Amazon AWS IMDS V2

    MacCarthaigh, C. (2019, November 19). Add defense in depth against open firewalls, reverse proxies, and SSRF vulnerabilities with enhancements to the EC2 Instance Metadata Service. Retrieved October 14, 2020.

    Open source URL
  26. [26]
    Google Cloud Threat Intelligence ESXi Hardening 2023

    Alex Marvi, Greg Blaum, and Ron Craft. (2023, June 28). Detection, Containment, and Hardening Opportunities for Privileged Guest Operations, Anomalous Behavior, and VMCI Backdoors on Compromised VMware Hosts. Retrieved March 26, 2025.

    Open source URL
  27. [27]
    Broadcom ESXi Lockdown Mode

    Broadcom. (2025, February 12). Enabling or disabling Lockdown mode on an ESXi host. Retrieved March 27, 2025.

    Open source URL
  28. [28]
    Microsoft Disable Macros

    Microsoft. (n.d.). Enable or disable macros in Office files. Retrieved September 13, 2018.

    Open source URL
  29. [29]
    Gmail Delegation

    Google. (n.d.). Turn Gmail delegation on or off. Retrieved April 1, 2022.

    Open source URL
  30. [30]
    mitre-attackM1042
    Open source URL
  31. [31]
    mitre-attackM1042
    Open source URL
  32. [32]
    mitre-attackM1042
    Open source URL
  33. [33]
    Apple Unified Log Analysis Remote Login and Screen Sharing

    Sarah Edwards. (2020, April 30). Analysis of Apple Unified Logs: Quarantine Edition [Entry 6] – Working From Home? Remote Logins. Retrieved August 19, 2021.

    Open source URL
  34. [34]
    Microsoft Entra Configure OAuth Consent

    Microsoft Entra. (2024, September 16). Configure how users consent to applications. Retrieved March 20, 2025.

    Open source URL
  35. [35]
    BleepingComputer DDE Disabled in Word Dec 2017

    Cimpanu, C. (2017, December 15). Microsoft Disables DDE Feature in Word to Prevent Further Malware Attacks. Retrieved December 19, 2017.

    Open source URL
  36. [36]
    GitHub Disable DDEAUTO Oct 2017

    Dormann, W. (2017, October 20). Disable DDEAUTO for Outlook, Word, OneNote, and Excel versions 2010, 2013, 2016. Retrieved February 3, 2018.

    Open source URL
  37. [37]
    Microsoft ADV170021 Dec 2017

    Microsoft. (2017, December 12). ADV170021 - Microsoft Office Defense in Depth Update. Retrieved February 3, 2018.

    Open source URL
  38. [38]
    Microsoft DDE Advisory Nov 2017

    Microsoft. (2017, November 8). Microsoft Security Advisory 4053440 - Securely opening Microsoft Office documents that contain Dynamic Data Exchange (DDE) fields. Retrieved November 21, 2017.

    Open source URL
  39. [39]
    ADSecurity Windows Secure Baseline

    Metcalf, S. (2016, October 21). Securing Windows Workstations: Developing a Secure Baseline. Retrieved November 17, 2017.

    Open source URL
  40. [40]
    Electron Security 2

    Stack Overflow. (n.d.). Why do I see an "Electron Security Warning" after updating my Electron project to the latest version?. Retrieved March 7, 2024.

    Open source URL
  41. [41]
    Microsoft Learn ClickOnce Config

    Microsoft. (2023, August 4). Configure the ClickOnce trust prompt behavior. Retrieved September 9, 2024.

    Open source URL
  42. [42]
    NetSPI ClickOnce

    Ryan Gandrud. (2015, March 23). All You Need Is One – A ClickOnce Love Story. Retrieved September 9, 2024.

    Open source URL
  43. [43]
    SpecterOps Certified Pre Owned

    Schroeder, W. & Christensen, L. (2021, June 22). Certified Pre-Owned - Abusing Active Directory Certificate Services. Retrieved August 2, 2022.

    Open source URL
  44. [44]
    Microsoft BEC Campaign

    Carr, N., Sellmer, S. (2021, June 14). Behind the scenes of business email compromise: Using cross-domain threat data to disrupt a large BEC campaign. Retrieved June 15, 2021.

    Open source URL
  45. [45]
    Microsoft Disable Autorun

    Microsoft. (n.d.). How to disable the Autorun functionality in Windows. Retrieved April 20, 2016.

    Open source URL
  46. [46]
    TechNet Removable Media Control

    Microsoft. (2007, August 31). https://technet.microsoft.com/en-us/library/cc771759(v=ws.10).aspx. Retrieved April 20, 2016.

    Open source URL
  47. [47]
    GitHub MOTW

    wdormann. (2019, August 29). Disable Windows Explorer file associations for Disc Image Mount. Retrieved April 16, 2022.

    Open source URL
  48. [48]
    ITSyndicate Disabling PHP functions

    Kondratiev, A. (n.d.). Disabling dangerous PHP functions. Retrieved July 26, 2021.

    Open source URL
  49. [49]
    Microsoft Disable Autorun

    Microsoft. (n.d.). How to disable the Autorun functionality in Windows. Retrieved April 20, 2016.

    Open source URL
  50. [50]
    Microsoft Disable Autorun

    Microsoft. (n.d.). How to disable the Autorun functionality in Windows. Retrieved April 20, 2016.

    Open source URL
  51. [51]
    TechNet Removable Media Control

    Microsoft. (2007, August 31). https://technet.microsoft.com/en-us/library/cc771759(v=ws.10).aspx. Retrieved April 20, 2016.

    Open source URL
  52. [52]
    TechNet Removable Media Control

    Microsoft. (2007, August 31). https://technet.microsoft.com/en-us/library/cc771759(v=ws.10).aspx. Retrieved April 20, 2016.

    Open source URL
  53. [53]
    MRWLabs Office Persistence Add-ins

    Knowles, W. (2017, April 21). Add-In Opportunities for Office Persistence. Retrieved November 17, 2024.

    Open source URL
  54. [54]
    TechNet Screensaver GP

    Microsoft. (n.d.). Customizing the Desktop. Retrieved December 5, 2017.

    Open source URL
  55. [55]
    Microsoft Disable DCOM

    Microsoft. (n.d.). Enable or Disable DCOM. Retrieved November 22, 2017.

    Open source URL
  56. [56]
    Microsoft Network access Credential Manager

    Microsoft. (2016, August 31). Network access: Do not allow storage of passwords and credentials for network authentication. Retrieved November 23, 2020.

    Open source URL
  57. [57]
    Microsoft Disable Autorun

    Microsoft. (n.d.). How to disable the Autorun functionality in Windows. Retrieved April 20, 2016.

    Open source URL
  58. [58]
    Microsoft Disable Autorun

    Microsoft. (n.d.). How to disable the Autorun functionality in Windows. Retrieved April 20, 2016.

    Open source URL
  59. [59]
    Broadcom ESXi SSH

    Broadcom. (2024, December 12). Allowing SSH access to VMware vSphere ESXi/ESX hosts with public/private key authentication. Retrieved March 26, 2025.

    Open source URL
  60. [60]
    Symantec SSH and ssh-agent

    Hatch, B. (2004, November 22). SSH and ssh-agent. Retrieved January 8, 2018.

    Open source URL
  61. [61]
    Microsoft AlwaysInstallElevated 2018

    Microsoft. (2018, May 31). AlwaysInstallElevated. Retrieved December 14, 2020.

    Open source URL
  62. [62]
    Microsoft Disable VBA Jan 2020

    Microsoft. (2020, January 23). How to turn off Visual Basic for Applications when you deploy Office. Retrieved September 17, 2020.

    Open source URL
  63. [63]
    Amazon AWS IMDS V2

    MacCarthaigh, C. (2019, November 19). Add defense in depth against open firewalls, reverse proxies, and SSRF vulnerabilities with enhancements to the EC2 Instance Metadata Service. Retrieved October 14, 2020.

    Open source URL
  64. [64]
    Broadcom ESXi Lockdown Mode

    Broadcom. (2025, February 12). Enabling or disabling Lockdown mode on an ESXi host. Retrieved March 27, 2025.

    Open source URL
  65. [65]
    Google Cloud Threat Intelligence ESXi Hardening 2023

    Alex Marvi, Greg Blaum, and Ron Craft. (2023, June 28). Detection, Containment, and Hardening Opportunities for Privileged Guest Operations, Anomalous Behavior, and VMCI Backdoors on Compromised VMware Hosts. Retrieved March 26, 2025.

    Open source URL
  66. [66]
    MRWLabs Office Persistence Add-ins

    Knowles, W. (2017, April 21). Add-In Opportunities for Office Persistence. Retrieved November 17, 2024.

    Open source URL
  67. [67]
    MRWLabs Office Persistence Add-ins

    Knowles, W. (2017, April 21). Add-In Opportunities for Office Persistence. Retrieved November 17, 2024.

    Open source URL
  68. [68]
    ITSyndicate Disabling PHP functions

    Kondratiev, A. (n.d.). Disabling dangerous PHP functions. Retrieved July 26, 2021.

    Open source URL
  69. [69]
    ITSyndicate Disabling PHP functions

    Kondratiev, A. (n.d.). Disabling dangerous PHP functions. Retrieved July 26, 2021.

    Open source URL
  70. [70]
    Microsoft Disable Autorun

    Microsoft. (n.d.). How to disable the Autorun functionality in Windows. Retrieved April 20, 2016.

    Open source URL
  71. [71]
    Microsoft Disable Autorun

    Microsoft. (n.d.). How to disable the Autorun functionality in Windows. Retrieved April 20, 2016.

    Open source URL
  72. [72]
    TechNet Removable Media Control

    Microsoft. (2007, August 31). https://technet.microsoft.com/en-us/library/cc771759(v=ws.10).aspx. Retrieved April 20, 2016.

    Open source URL
  73. [73]
    TechNet Removable Media Control

    Microsoft. (2007, August 31). https://technet.microsoft.com/en-us/library/cc771759(v=ws.10).aspx. Retrieved April 20, 2016.

    Open source URL
  74. [74]
    Microsoft Disable Macros

    Microsoft. (n.d.). Enable or disable macros in Office files. Retrieved September 13, 2018.

    Open source URL
  75. [75]
    BleepingComputer DDE Disabled in Word Dec 2017

    Cimpanu, C. (2017, December 15). Microsoft Disables DDE Feature in Word to Prevent Further Malware Attacks. Retrieved December 19, 2017.

    Open source URL
  76. [76]
    GitHub Disable DDEAUTO Oct 2017

    Dormann, W. (2017, October 20). Disable DDEAUTO for Outlook, Word, OneNote, and Excel versions 2010, 2013, 2016. Retrieved February 3, 2018.

    Open source URL
  77. [77]
    Microsoft ADV170021 Dec 2017

    Microsoft. (2017, December 12). ADV170021 - Microsoft Office Defense in Depth Update. Retrieved February 3, 2018.

    Open source URL
  78. [78]
    Microsoft DDE Advisory Nov 2017

    Microsoft. (2017, November 8). Microsoft Security Advisory 4053440 - Securely opening Microsoft Office documents that contain Dynamic Data Exchange (DDE) fields. Retrieved November 21, 2017.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.