LiveActive security incident?Get immediate response
MITRE ATT&CK® Mitigation

M1047: Audit

Auditing is the process of recording activity and systematically reviewing and analyzing the activity and system configurations. The primary purpose of auditing is to detect anomalies and identify potential threats or weaknesses in the environment. Proper auditing configurations can also help to meet compliance requirements. The process of auditing encompasses regular analysis of user behaviors and system logs in support of proactive security measures.

Auditing is applicable to all systems used within an organization, from the front door of a building to accessing a file on a fileserver. It is considered more critical for regulated industries such as, healthcare, finance and government where compliance requirements demand stringent tracking of user and system activates.This mitigation can be implemented through the following measures:

System Audit:

- Use Case: Regularly assess system configurations to ensure compliance with organizational security policies. - Implementation: Use tools to scan for deviations from established benchmarks.

Permission Audits:

- Use Case: Review file and folder permissions to minimize the risk of unauthorized access or privilege escalation. - Implementation: Run access reviews to identify users or groups with excessive permissions.

Software Audits:

- Use Case: Identify outdated, unsupported, or insecure software that could serve as an attack vector. - Implementation: Use inventory and vulnerability scanning tools to detect outdated versions and recommend secure alternatives.

Configuration Audits:

- Use Case: Evaluate system and network configurations to ensure secure settings (e.g., disabled SMBv1, enabled MFA). - Implementation: Implement automated configuration scanning tools like SCAP (Security Content Automation Protocol) to identify non-compliant systems.

Network Audits:

- Use Case: Examine network traffic, firewall rules, and endpoint communications to identify unauthorized or insecure connections. - Implementation: Utilize tools such as Wireshark, or Zeek to monitor and log suspicious network behavior.

EnterpriseM1047MitigationObject v1.3Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Audit is a broad but business-critical mitigation: it turns system, identity, software, configuration, network, email, cloud, and even physical access activity into reviewable evidence. Its value is not that logging exists, but that the organization can systematically find weak configurations, excessive permissions, outdated software, suspicious remote access, unauthorized forwarding rules, unexpected scheduled jobs, and other conditions that make incidents harder to contain or prove.

Executive priority

Leaders should treat auditing as a resilience and accountability control, not only a compliance checkbox. MITRE explicitly ties auditing to anomaly detection, weakness identification, and compliance requirements, with higher importance in regulated sectors such as healthcare, finance, and government. Priority questions include: which business-critical systems are actually audited, who reviews the results, how quickly exceptions are corrected, and whether audit evidence would support incident response, access reviews, vulnerability prioritization, and regulatory reporting.

Technical view

For SOC, detection engineering, IR, and control owners, validate that audit scope covers the ATT&CK relationship context: remote services and RDP/VNC lateral movement, scheduled task and cron persistence, command and scripting execution, obfuscated or masqueraded artifacts, cloud account discovery, mailbox changes and forwarding rules, software/browser/IDE extensions, insecure images, and unusual network communications. Because the MITRE object has no official detection text and no specific platform field, teams should map audit requirements to their own Windows, Linux, macOS, cloud/IaaS, identity provider, Office/SaaS, container, ESXi, network device, and physical-access environments where applicable from the related techniques and the official description.

Likely telemetry

  • System configuration and benchmark scan results, including deviations from approved baselines
  • Permission and access review records for files, folders, groups, privileged roles, and cloud or identity accounts
  • Software inventory, version, support status, and vulnerability scan results
  • Configuration audit evidence for security settings such as MFA enablement and disabled insecure services such as SMBv1 where applicable
  • Remote access and remote service logs, including RDP, SSH, VNC, and other service authentication records

Detection direction

  • First confirm audit coverage, retention, and review ownership before writing detections; missing or unreviewed logs are the main blind spot for this mitigation.
  • Tune audits around changes and deviations: new or modified remote access paths, excessive permissions, new accounts with lookalike names, new scheduled jobs, new forwarding rules, unsupported software, and configuration drift from approved baselines.
  • Correlate identity, endpoint, cloud, email, and network evidence for related behaviors such as valid-account remote services, mailbox collection, command execution, and persistence through scheduled jobs or extensions.
  • Account for false positives from administrators, support tools, automation, software updates, and legitimate remote work; require baselines and documented exceptions so audits do not become noise.
  • For compliance readiness, preserve evidence of both audit execution and remediation decisions, not just raw logs or scanner output.

Mitigation priorities

  • Define audit scope around critical assets, regulated systems, privileged identities, remote access services, email platforms, cloud resources, and high-risk network paths.
  • Establish secure configuration and permission baselines, then automate scanning for drift where practical.
  • Perform recurring access and permission audits to identify excessive rights and reduce privilege-escalation and unauthorized-access risk.
  • Maintain software and image inventories to find outdated, unsupported, insecure, or unapproved components.
  • Review network traffic, firewall rules, and endpoint communications for unauthorized or insecure connections.
Additional notes and limits

This is a course-of-action object, so the value is in governance and validation rather than a single detection analytic. The relationship context shows auditing supports mitigation across lateral movement, execution, persistence, stealth, discovery, command-and-control, and collection behaviors. Glexia would use this to assess whether audit practices produce actionable evidence for SOC operations, incident response, identity governance, cloud security, vulnerability management, and compliance programs.

MITRE provides no official detection field for M1047 and no platform list on the mitigation itself. Platform and tactic relevance is inferred only from the supplied related ATT&CK techniques. Local asset inventory, logging architecture, regulatory obligations, and business-critical process mapping are required to determine actual coverage and priority.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Audit

Auditing is the process of recording activity and systematically reviewing and analyzing the activity and system configurations. The primary purpose of auditing is to detect anomalies and identify potential threats or weaknesses in the environment. Proper auditing configurations can also help to meet compliance requirements. The process of auditing encompasses regular analysis of user behaviors and system logs in support of proactive security measures.

Auditing is applicable to all systems used within an organization, from the front door of a building to accessing a file on a fileserver. It is considered more critical for regulated industries such as, healthcare, finance and government where compliance requirements demand stringent tracking of user and system activates.This mitigation can be implemented through the following measures:

System Audit:

- Use Case: Regularly assess system configurations to ensure compliance with organizational security policies. - Implementation: Use tools to scan for deviations from established benchmarks.

Permission Audits:

- Use Case: Review file and folder permissions to minimize the risk of unauthorized access or privilege escalation. - Implementation: Run access reviews to identify users or groups with excessive permissions.

Software Audits:

- Use Case: Identify outdated, unsupported, or insecure software that could serve as an attack vector. - Implementation: Use inventory and vulnerability scanning tools to detect outdated versions and recommend secure alternatives.

Configuration Audits:

- Use Case: Evaluate system and network configurations to ensure secure settings (e.g., disabled SMBv1, enabled MFA). - Implementation: Implement automated configuration scanning tools like SCAP (Security Content Automation Protocol) to identify non-compliant systems.

Network Audits:

- Use Case: Examine network traffic, firewall rules, and endpoint communications to identify unauthorized or insecure connections. - Implementation: Utilize tools such as Wireshark, or Zeek to monitor and log suspicious network behavior.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.3
Created
Modified
Raw hash
7c9d679627ea7b69...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.