LiveActive security incident?Get immediate response
MITRE ATT&CK® Mitigation

M1042: Disable or Remove Feature or Program

Disable or remove unnecessary and potentially vulnerable software, features, or services to reduce the attack surface and prevent abuse by adversaries. This involves identifying software or features that are no longer needed or that could be exploited and ensuring they are either removed or properly disabled. This mitigation can be implemented through the following measures:

Remove Legacy Software:

- Use Case: Disable or remove older versions of software that no longer receive updates or security patches (e.g., legacy Java, Adobe Flash). - Implementation: A company removes Flash Player from all employee systems after it has reached its end-of-life date.

Disable Unused Features:

- Use Case: Turn off unnecessary operating system features like SMBv1, Telnet, or RDP if they are not required. - Implementation: Disable SMBv1 in a Windows environment to mitigate vulnerabilities like EternalBlue.

Control Applications Installed by Users:

- Use Case: Prevent users from installing unauthorized software via group policies or other management tools. - Implementation: Block user installations of unauthorized file-sharing applications (e.g., BitTorrent clients) in an enterprise environment.

Remove Unnecessary Services:

- Use Case: Identify and disable unnecessary default services running on endpoints, servers, or network devices. - Implementation: Disable unused administrative shares (e.g., C$, ADMIN$) on workstations.

Restrict Add-ons and Plugins:

- Use Case: Remove or disable browser plugins and add-ons that are not needed for business purposes. - Implementation: Disable Java and ActiveX plugins in web browsers to prevent drive-by attacks.

EnterpriseM1042MitigationObject v1.2Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Disabling or removing unnecessary software, features, services, plugins, and legacy components is a basic but high-value attack-surface reduction control. For leaders, the decision value is not “turn things off” in the abstract; it is whether the organization can prove that exposed remote access paths, scripting engines, removable media functions, browser plugins, and unsupported software are needed, governed, and monitored. This mitigation matters because many related ATT&CK techniques depend on features that are commonly installed by default or left enabled after business need has changed.

Executive priority

Prioritize this as a resilience and governance control: every unused service or end-of-life component creates avoidable exposure, complicates incident response, and weakens audit evidence. Executives should ask whether the organization has an authoritative inventory, a business-justification process for enabled remote access and scripting capabilities, and a repeatable exception process. This is especially relevant to lateral movement via remote services, exfiltration through Bluetooth/USB/other media, abuse of command and scripting interpreters, account and cloud credential persistence paths, and legacy or user-installed software risk.

Technical view

SOC, IR, and detection engineering teams should validate this mitigation against the related techniques it is mapped to: Remote Services including RDP, SSH, VNC, WinRM, DCOM, and direct cloud VM connections; Network Service Discovery; Command and Scripting Interpreter use including PowerShell, Visual Basic, and JavaScript; removable media and Bluetooth-based exfiltration or command-and-control; account manipulation including added cloud credentials, SSH authorized keys, and email forwarding rules; and trusted developer utility proxy execution. Because ATT&CK provides no detection text for this mitigation, teams should focus on evidence of control state: what is installed, what is enabled, what is reachable, who can change it, and where exceptions exist.

Likely telemetry

  • Endpoint software and feature inventory, including legacy and end-of-life applications
  • Service configuration and startup state for remote access and administrative services
  • Network exposure data showing listening services and reachable management interfaces
  • Authentication and session logs for RDP, SSH, VNC, WinRM, DCOM, and cloud VM access where present
  • Cloud and identity audit logs for added credentials, service principals, keys, mailbox permissions, and forwarding rules

Detection direction

  • Validate that discovery alerts for newly enabled services are tied to asset criticality and approved baseline state, not only port activity.
  • Tune remote-service monitoring around unauthorized enablement, unexpected exposure, and use by accounts without a documented business need.
  • Correlate removable media, Bluetooth, and alternate network interface activity with data movement and host sensitivity where such telemetry exists.
  • For scripting engines and developer utilities, distinguish approved administrative or development use from unexpected execution on systems where those features should be disabled or restricted.
  • For identity and cloud-related relationships, monitor for configuration drift such as new credentials, SSH authorized keys, mailbox delegation, and forwarding rules rather than relying only on login alerts.

Mitigation priorities

  • Start with inventory: identify unsupported software, unnecessary services, browser plugins, add-ons, user-installed applications, remote access features, scripting engines, and removable-media capabilities.
  • Remove end-of-life or unsupported software first, because it cannot be reliably remediated through patching alone.
  • Disable unused remote services and administrative interfaces, including examples supplied by ATT&CK such as SMBv1, Telnet, RDP where not required, and unnecessary default services or administrative shares.
  • Control user-installed applications through managed policy and approval workflows to reduce ungoverned software exposure.
  • Restrict or disable browser plugins and add-ons that lack a business purpose, including legacy plugin technologies identified by ATT&CK such as Java and ActiveX.
Additional notes and limits

This mitigation is broad and control-oriented, so its value depends on asset inventory quality, configuration management, and exception discipline. The relationship context shows relevance across execution, lateral movement, discovery, command-and-control, collection, persistence, privilege escalation, and exfiltration behaviors. For Glexia services, this is a practical bridge between vulnerability management, identity/cloud hardening, managed detection, incident response readiness, and compliance evidence.

The official ATT&CK object does not specify platforms, tactics, or detection guidance for the mitigation itself. Platform and tactic context comes only from the supplied relationships to techniques. Local business requirements are required before disabling features, because some remote services, interpreters, plugins, or removable-media workflows may be operationally necessary.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Disable or Remove Feature or Program

Disable or remove unnecessary and potentially vulnerable software, features, or services to reduce the attack surface and prevent abuse by adversaries. This involves identifying software or features that are no longer needed or that could be exploited and ensuring they are either removed or properly disabled. This mitigation can be implemented through the following measures:

Remove Legacy Software:

- Use Case: Disable or remove older versions of software that no longer receive updates or security patches (e.g., legacy Java, Adobe Flash). - Implementation: A company removes Flash Player from all employee systems after it has reached its end-of-life date.

Disable Unused Features:

- Use Case: Turn off unnecessary operating system features like SMBv1, Telnet, or RDP if they are not required. - Implementation: Disable SMBv1 in a Windows environment to mitigate vulnerabilities like EternalBlue.

Control Applications Installed by Users:

- Use Case: Prevent users from installing unauthorized software via group policies or other management tools. - Implementation: Block user installations of unauthorized file-sharing applications (e.g., BitTorrent clients) in an enterprise environment.

Remove Unnecessary Services:

- Use Case: Identify and disable unnecessary default services running on endpoints, servers, or network devices. - Implementation: Disable unused administrative shares (e.g., C$, ADMIN$) on workstations.

Restrict Add-ons and Plugins:

- Use Case: Remove or disable browser plugins and add-ons that are not needed for business purposes. - Implementation: Disable Java and ActiveX plugins in web browsers to prevent drive-by attacks.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.2
Created
Modified
Raw hash
2716083433cfdb09...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.