LiveActive security incident?Get immediate response
MITRE ATT&CK® Mitigation

M1051: Update Software

Software updates ensure systems are protected against known vulnerabilities by applying patches and upgrades provided by vendors. Regular updates reduce the attack surface and prevent adversaries from exploiting known security gaps. This includes patching operating systems, applications, drivers, and firmware. This mitigation can be implemented through the following measures:

Regular Operating System Updates

- Implementation: Apply the latest Windows security updates monthly using WSUS (Windows Server Update Services) or a similar patch management solution. Configure systems to check for updates automatically and schedule reboots during maintenance windows. - Use Case: Prevents exploitation of OS vulnerabilities such as privilege escalation or remote code execution.

Application Patching

- Implementation: Monitor Apache's update release notes for security patches addressing vulnerabilities. Schedule updates for off-peak hours to avoid downtime while maintaining security compliance. - Use Case: Prevents exploitation of web application vulnerabilities, such as those leading to unauthorized access or data breaches.

Firmware Updates

- Implementation: Regularly check the vendor’s website for firmware updates addressing vulnerabilities. Plan for update deployment during scheduled maintenance to minimize business disruption. - Use Case: Protects against vulnerabilities that adversaries could exploit to gain access to network devices or inject malicious traffic.

Emergency Patch Deployment

- Implementation: Use the emergency patch deployment feature of the organization's patch management tool to apply updates to all affected Exchange servers within 24 hours. - Use Case: Reduces the risk of exploitation by rapidly addressing critical vulnerabilities.

Centralized Patch Management

- Implementation: Implement a centralized patch management system, such as SCCM or ManageEngine, to automate and track patch deployment across all environments. Generate regular compliance reports to ensure all systems are updated. - Use Case: Streamlines patching processes and ensures no critical systems are missed.

*Tools for Implementation*

Patch Management Tools:

- WSUS: Manage and deploy Microsoft updates across the organization. - ManageEngine Patch Manager Plus: Automate patch deployment for OS and third-party apps. - Ansible: Automate updates across multiple platforms, including Linux and Windows.

Vulnerability Scanning Tools:

- OpenVAS: Open-source vulnerability scanning to identify missing patches.

EnterpriseM1051MitigationObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Update Software is a foundational risk-reduction control: it reduces exposure to known vulnerabilities in operating systems, applications, drivers, and firmware before those weaknesses can be used for initial access, privilege escalation, lateral movement, persistence, credential access, stealth, or impact. For leaders, the practical question is not “do we patch?” but whether critical assets, public-facing systems, client software, firmware, and centralized deployment tools are updated quickly enough and with evidence that stands up during incidents or audits.

Executive priority

Prioritize this as a business continuity and resilience control. The ATT&CK relationships show update management applies to high-consequence scenarios including exploitation of public-facing applications, client-side exploitation, remote-service exploitation, privilege escalation, software supply chain compromise, Office and extension-based persistence, credential-related exploitation, and firmware-level impact or persistence. Executives should ask for measurable patch compliance, emergency patch capability, maintenance-window governance, and visibility into systems that are often missed: firmware, network devices, SaaS/cloud-connected management tooling, development dependencies, browsers/extensions, and deployment platforms.

Technical view

For SOC, IR, vulnerability management, and detection engineering teams, M1051 is primarily a prevention and assurance activity rather than a detection analytic; MITRE provides no official detection text for this mitigation. Validate that patch status, vulnerability scan results, asset inventory, software/firmware versions, and deployment-tool logs can be joined to the techniques this mitigation addresses, especially T1190, T1203, T1210, T1068, T1212, T1542, T1495, T1195, and T1072. Because centralized patch and software deployment systems are also related to adversary abuse, teams should treat them as privileged infrastructure: monitor change activity, administrative use, update failures, emergency deployments, and unusual command or package distribution behavior.

Likely telemetry

  • Asset inventory covering operating systems, applications, drivers, firmware, public-facing services, client applications, network devices, and cloud/SaaS-connected management components where applicable
  • Patch management records from centralized tooling, including deployment status, failures, deferrals, reboot requirements, emergency patch actions, and compliance reports
  • Vulnerability scanner findings identifying missing patches or vulnerable versions
  • Software and firmware version data from endpoints, servers, network devices, and managed platforms
  • Change-management and maintenance-window records showing when updates were approved, deployed, rolled back, or delayed

Detection direction

  • Do not treat this mitigation as a standalone detection. Validate whether security operations can prove which assets are missing vendor updates and whether those gaps overlap with exposed services, privileged systems, identity components, development tooling, or firmware-bearing devices.
  • Tune vulnerability and patch reporting around exploit-relevant exposure: public-facing applications, remote services, client applications, privilege escalation paths, credential-access surfaces, and firmware/pre-OS components reflected in the related ATT&CK techniques.
  • Correlate update failures and long-lived exceptions with incident findings. A recurring blind spot is that patch dashboards show endpoint compliance while excluding firmware, third-party applications, browser/IDE extensions, network devices, containers, IaaS assets, or SaaS-connected deployment systems.
  • Monitor centralized software deployment tools for administrative changes and unusual distribution behavior because the relationship context includes adversary use of software deployment tools for execution and lateral movement.
  • Account for false confidence from scheduled patch cycles: monthly operating system updates may not address emergency fixes, application patches, firmware updates, or supply chain/dependency risks without separate processes and evidence.

Mitigation priorities

  • Maintain a complete and current asset and software inventory before measuring patch compliance; unknown systems cannot be reliably updated.
  • Use centralized patch management to automate, track, and report deployment across operating systems, applications, drivers, and firmware where supported.
  • Define risk-based service levels for routine and emergency updates, including the ability to deploy critical fixes rapidly to affected systems such as public-facing servers or other high-risk assets.
  • Schedule reboots and maintenance windows to reduce operational disruption while preventing indefinite deferral of security updates.
  • Include application release-note monitoring, vulnerability scanning, and compliance reporting so missing patches are identified and remediated rather than only recorded.
Additional notes and limits

The supplied ATT&CK object is a mitigation, not a technique, and its official description emphasizes vendor patches, upgrades, centralized patch management, vulnerability scanning, firmware updates, and emergency patch deployment. The relationship set is broad, making this control relevant across initial access, execution, privilege escalation, persistence, credential access, lateral movement, stealth, and impact. The strongest defensive value comes from turning update management into measurable coverage: what is in scope, what is missing, how fast critical updates deploy, and whether exceptions are visible to SOC, IR, vulnerability management, and audit stakeholders.

MITRE does not provide official detection guidance for M1051, and the mitigation itself has no specified platforms or tactics. Platform relevance is inferred only from the related ATT&CK techniques and should be confirmed against the local environment. This take does not assert active exploitation, specific vendor exposure, or guaranteed detection coverage; organizations need local asset, vulnerability, patch, and incident data to prioritize action.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Update Software

Software updates ensure systems are protected against known vulnerabilities by applying patches and upgrades provided by vendors. Regular updates reduce the attack surface and prevent adversaries from exploiting known security gaps. This includes patching operating systems, applications, drivers, and firmware. This mitigation can be implemented through the following measures:

Regular Operating System Updates

- Implementation: Apply the latest Windows security updates monthly using WSUS (Windows Server Update Services) or a similar patch management solution. Configure systems to check for updates automatically and schedule reboots during maintenance windows. - Use Case: Prevents exploitation of OS vulnerabilities such as privilege escalation or remote code execution.

Application Patching

- Implementation: Monitor Apache's update release notes for security patches addressing vulnerabilities. Schedule updates for off-peak hours to avoid downtime while maintaining security compliance. - Use Case: Prevents exploitation of web application vulnerabilities, such as those leading to unauthorized access or data breaches.

Firmware Updates

- Implementation: Regularly check the vendor’s website for firmware updates addressing vulnerabilities. Plan for update deployment during scheduled maintenance to minimize business disruption. - Use Case: Protects against vulnerabilities that adversaries could exploit to gain access to network devices or inject malicious traffic.

Emergency Patch Deployment

- Implementation: Use the emergency patch deployment feature of the organization's patch management tool to apply updates to all affected Exchange servers within 24 hours. - Use Case: Reduces the risk of exploitation by rapidly addressing critical vulnerabilities.

Centralized Patch Management

- Implementation: Implement a centralized patch management system, such as SCCM or ManageEngine, to automate and track patch deployment across all environments. Generate regular compliance reports to ensure all systems are updated. - Use Case: Streamlines patching processes and ensures no critical systems are missed.

*Tools for Implementation*

Patch Management Tools:

- WSUS: Manage and deploy Microsoft updates across the organization. - ManageEngine Patch Manager Plus: Automate patch deployment for OS and third-party apps. - Ansible: Automate updates across multiple platforms, including Linux and Windows.

Vulnerability Scanning Tools:

- OpenVAS: Open-source vulnerability scanning to identify missing patches.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

42 rows
DomainIDNameRelationship / procedure
EnterpriseT1550.002Pass the HashSub-technique

Apply patch KB2871997 to Windows 7 and higher systems to limit the default access of accounts in the local administrator group.[1]

EnterpriseT1686.002Network Device FirewallSub-technique

Ensure the network firewall is up to date with security patches.

EnterpriseT1552Unsecured Credentials

Apply patch KB2962486 which prevents credentials from being stored in GPPs.[2][3]

EnterpriseT1176.002IDE ExtensionsSub-technique

Ensure operating systems and IDEs are using the most current version.

EnterpriseT1548.002Bypass User Account ControlSub-technique

Consider updating Windows to the latest version and patch level to utilize the latest protective measures against UAC bypass.[4]

EnterpriseT1602.001SNMP (MIB Dump)Sub-technique

Keep system images and software updated and migrate to SNMPv3.[5]

EnterpriseT1068Exploitation for Privilege Escalation

Update software regularly by employing patch management for internal enterprise endpoints and servers.

EnterpriseT1555.005Password ManagersSub-technique

Regularly update web browsers, password managers, and all related software to the latest versions. Keeping software up-to-date reduces the risk of vulnerabilities being exploited by attackers to extract stored credentials or session cookies.

EnterpriseT1495Firmware Corruption

Patch the BIOS and other firmware as necessary to prevent successful use of known vulnerabilities.

EnterpriseT1110.001Password GuessingSub-technique

Upgrade management services to the latest supported and compatible version. Specifically, any version providing increased password complexity or policy enforcement preventing default or weak passwords.

EnterpriseT1555Credentials from Password Stores

Perform regular software updates to mitigate exploitation risk.

EnterpriseT1611Escape to Host

Ensure that hosts are kept up-to-date with security patches.

EnterpriseT1072Software Deployment Tools

Patch deployment systems regularly to prevent potential remote access through Exploitation for Privilege Escalation.

EnterpriseT1137.004Outlook Home PageSub-technique

For the Outlook methods, blocking macros may be ineffective as the Visual Basic engine used for these features is separate from the macro scripting engine.[6] Microsoft has released patches to try to address each issue. Ensure KB3191938 which blocks Outlook Visual Basic and displays a malicious code warning, KB4011091 which disables custom forms by default, and KB4011162 which removes the legacy Home Page feature, are applied to systems.[7]

EnterpriseT1542Pre-OS Boot

Patch the BIOS and EFI as necessary.

EnterpriseT1542.001System FirmwareSub-technique

Patch the BIOS and EFI as necessary.

EnterpriseT1212Exploitation for Credential Access

Update software regularly by employing patch management for internal enterprise endpoints and servers.

EnterpriseT1602Data from Configuration Repository

Keep system images and software updated and migrate to SNMPv3.[5]

EnterpriseT1189Drive-by Compromise

Ensuring that all browsers and plugins are kept updated can help prevent the exploit phase of this technique. Use modern browsers with security features turned on.[8]

EnterpriseT1548Abuse Elevation Control Mechanism

Perform regular software updates to mitigate exploitation risk.

EnterpriseT1211Exploitation for Stealth

Update software regularly by employing patch management for internal enterprise endpoints and servers.

EnterpriseT1574Hijack Execution Flow

Update software regularly to include patches that fix DLL side-loading vulnerabilities.

EnterpriseT1176.001Browser ExtensionsSub-technique

Ensure operating systems and browsers are using the most current version.

EnterpriseT1137Office Application Startup

For the Outlook methods, blocking macros may be ineffective as the Visual Basic engine used for these features is separate from the macro scripting engine.[6] Microsoft has released patches to try to address each issue. Ensure KB3191938 which blocks Outlook Visual Basic and displays a malicious code warning, KB4011091 which disables custom forms by default, and KB4011162 which removes the legacy Home Page feature, are applied to systems.[7]

EnterpriseT1195.001Compromise Software Dependencies and Development ToolsSub-technique

A patch management process should be implemented to check unused dependencies, unmaintained and/or previously vulnerable dependencies, unnecessary features, components, files, and documentation.

EnterpriseT1552.006Group Policy PreferencesSub-technique

Apply patch KB2962486 which prevents credentials from being stored in GPPs.[2][3]

EnterpriseT1137.005Outlook RulesSub-technique

For the Outlook methods, blocking macros may be ineffective as the Visual Basic engine used for these features is separate from the macro scripting engine.[6] Microsoft has released patches to try to address each issue. Ensure KB3191938 which blocks Outlook Visual Basic and displays a malicious code warning, KB4011091 which disables custom forms by default, and KB4011162 which removes the legacy Home Page feature, are applied to systems.[7]

EnterpriseT1195Supply Chain Compromise

A patch management process should be implemented to check unused dependencies, unmaintained and/or previously vulnerable dependencies, unnecessary features, components, files, and documentation.

EnterpriseT1539Steal Web Session Cookie

Regularly update web browsers, password managers, and all related software to the latest versions. Keeping software up-to-date reduces the risk of vulnerabilities being exploited by attackers to extract stored credentials or session cookies.

EnterpriseT1555.003Credentials from Web BrowsersSub-technique

Regularly update web browsers, password managers, and all related software to the latest versions. Keeping software up-to-date reduces the risk of vulnerabilities being exploited by attackers to extract stored credentials or session cookies.

EnterpriseT1602.002Network Device Configuration DumpSub-technique

Keep system images and software updated and migrate to SNMPv3.[5]

EnterpriseT1546.010AppInit DLLsSub-technique

Upgrade to Windows 8 or later and enable secure boot.

EnterpriseT1574.001DLLSub-technique

Update software regularly to include patches that fix DLL side-loading vulnerabilities.

EnterpriseT1176Software Extensions

Ensure operating systems and software are using the most current version.

EnterpriseT1203Exploitation for Client Execution

Perform regular software updates to mitigate exploitation risk. Keeping software up-to-date with the latest security patches helps prevent adversaries from exploiting known vulnerabilities in client software, reducing the risk of successful attacks.

EnterpriseT1542.002Component FirmwareSub-technique

Perform regular firmware updates to mitigate risks of exploitation and/or abuse.

EnterpriseT1137.003Outlook FormsSub-technique

For the Outlook methods, blocking macros may be ineffective as the Visual Basic engine used for these features is separate from the macro scripting engine.[6] Microsoft has released patches to try to address each issue. Ensure KB3191938 which blocks Outlook Visual Basic and displays a malicious code warning, KB4011091 which disables custom forms by default, and KB4011162 which removes the legacy Home Page feature, are applied to systems.[7]

EnterpriseT1190Exploit Public-Facing Application

Update software regularly by employing patch management for externally exposed applications.

EnterpriseT1195.002Compromise Software Supply ChainSub-technique

A patch management process should be implemented to check unused applications, unmaintained and/or previously vulnerable software, unnecessary features, components, files, and documentation.

EnterpriseT1210Exploitation of Remote Services

Update software regularly by employing patch management for internal enterprise endpoints and servers.

EnterpriseT1546.011Application ShimmingSub-technique

Microsoft released an optional patch update - KB3045645 - that will remove the "auto-elevate" flag within the sdbinst.exe. This will prevent use of application shimming to bypass UAC.

EnterpriseT1546Event Triggered Execution

Perform regular software updates to mitigate exploitation risk.

Relationship explorer

All related ATT&CK context

mitigates · TechniqueT1550.002: Pass the HashEnterprisemitigates · TechniqueT1686.002: Network Device FirewallEnterprisemitigates · TechniqueT1552: Unsecured CredentialsEnterprisemitigates · TechniqueT1176.002: IDE ExtensionsEnterprisemitigates · TechniqueT1548.002: Bypass User Account ControlEnterprisemitigates · TechniqueT1602.001: SNMP (MIB Dump)Enterprisemitigates · TechniqueT1068: Exploitation for Privilege EscalationEnterprisemitigates · TechniqueT1555.005: Password ManagersEnterprisemitigates · TechniqueT1495: Firmware CorruptionEnterprisemitigates · TechniqueT1110.001: Password GuessingEnterprisemitigates · TechniqueT1555: Credentials from Password StoresEnterprisemitigates · TechniqueT1611: Escape to HostEnterprisemitigates · TechniqueT1072: Software Deployment ToolsEnterprisemitigates · TechniqueT1137.004: Outlook Home PageEnterprisemitigates · TechniqueT1542: Pre-OS BootEnterprisemitigates · TechniqueT1542.001: System FirmwareEnterprisemitigates · TechniqueT1212: Exploitation for Credential AccessEnterprisemitigates · TechniqueT1602: Data from Configuration RepositoryEnterprisemitigates · TechniqueT1189: Drive-by CompromiseEnterprisemitigates · TechniqueT1548: Abuse Elevation Control MechanismEnterprisemitigates · TechniqueT1211: Exploitation for StealthEnterprisemitigates · TechniqueT1574: Hijack Execution FlowEnterprisemitigates · TechniqueT1176.001: Browser ExtensionsEnterprisemitigates · TechniqueT1137: Office Application StartupEnterprise
Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
beaa77555ca1adf2...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundlebeaa77555ca1…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    NSA Spotting

    National Security Agency/Central Security Service Information Assurance Directorate. (2015, August 7). Spotting the Adversary with Windows Event Log Monitoring. Retrieved September 6, 2018.

    Open source URL
  2. [2]
    ADSecurity Finding Passwords in SYSVOL

    Sean Metcalf. (2015, December 28). Finding Passwords in SYSVOL & Exploiting Group Policy Preferences. Retrieved February 17, 2020.

    Open source URL
  3. [3]
    MS14-025

    Microsoft. (2014, May 13). MS14-025: Vulnerability in Group Policy Preferences could allow elevation of privilege. Retrieved February 17, 2020.

    Open source URL
  4. [4]
    Github UACMe

    UACME Project. (2016, June 16). UACMe. Retrieved July 26, 2016.

    Open source URL
  5. [5]
    Cisco Blog Legacy Device Attacks

    Omar Santos. (2020, October 19). Attackers Continue to Target Legacy Devices. Retrieved October 20, 2020.

    Open source URL
  6. [6]
    SensePost Outlook Forms

    Stalmans, E. (2017, April 28). Outlook Forms and Shells. Retrieved February 4, 2019.

    Open source URL
  7. [7]
    SensePost Outlook Home Page

    Stalmans, E. (2017, October 11). Outlook Home Page – Another Ruler Vector. Retrieved February 4, 2019.

    Open source URL
  8. [8]
    Browser-updates

    Dusty Miller. (2023, October 17). Are You Sure Your Browser is Up to Date? The Current Landscape of Fake Browser Updates . Retrieved February 13, 2024.

    Open source URL
  9. [9]
    mitre-attackM1051
    Open source URL
  10. [10]
    mitre-attackM1051
    Open source URL
  11. [11]
    mitre-attackM1051
    Open source URL
  12. [12]
    NSA Spotting

    National Security Agency/Central Security Service Information Assurance Directorate. (2015, August 7). Spotting the Adversary with Windows Event Log Monitoring. Retrieved September 6, 2018.

    Open source URL
  13. [13]
    ADSecurity Finding Passwords in SYSVOL

    Sean Metcalf. (2015, December 28). Finding Passwords in SYSVOL & Exploiting Group Policy Preferences. Retrieved February 17, 2020.

    Open source URL
  14. [14]
    MS14-025

    Microsoft. (2014, May 13). MS14-025: Vulnerability in Group Policy Preferences could allow elevation of privilege. Retrieved February 17, 2020.

    Open source URL
  15. [15]
    Github UACMe

    UACME Project. (2016, June 16). UACMe. Retrieved July 26, 2016.

    Open source URL
  16. [16]
    Cisco Blog Legacy Device Attacks

    Omar Santos. (2020, October 19). Attackers Continue to Target Legacy Devices. Retrieved October 20, 2020.

    Open source URL
  17. [17]
    SensePost Outlook Forms

    Stalmans, E. (2017, April 28). Outlook Forms and Shells. Retrieved February 4, 2019.

    Open source URL
  18. [18]
    SensePost Outlook Home Page

    Stalmans, E. (2017, October 11). Outlook Home Page – Another Ruler Vector. Retrieved February 4, 2019.

    Open source URL
  19. [19]
    Cisco Blog Legacy Device Attacks

    Omar Santos. (2020, October 19). Attackers Continue to Target Legacy Devices. Retrieved October 20, 2020.

    Open source URL
  20. [20]
    Cisco Blog Legacy Device Attacks

    Omar Santos. (2020, October 19). Attackers Continue to Target Legacy Devices. Retrieved October 20, 2020.

    Open source URL
  21. [21]
    Browser-updates

    Dusty Miller. (2023, October 17). Are You Sure Your Browser is Up to Date? The Current Landscape of Fake Browser Updates . Retrieved February 13, 2024.

    Open source URL
  22. [22]
    SensePost Outlook Forms

    Stalmans, E. (2017, April 28). Outlook Forms and Shells. Retrieved February 4, 2019.

    Open source URL
  23. [23]
    SensePost Outlook Forms

    Stalmans, E. (2017, April 28). Outlook Forms and Shells. Retrieved February 4, 2019.

    Open source URL
  24. [24]
    SensePost Outlook Home Page

    Stalmans, E. (2017, October 11). Outlook Home Page – Another Ruler Vector. Retrieved February 4, 2019.

    Open source URL
  25. [25]
    SensePost Outlook Home Page

    Stalmans, E. (2017, October 11). Outlook Home Page – Another Ruler Vector. Retrieved February 4, 2019.

    Open source URL
  26. [26]
    ADSecurity Finding Passwords in SYSVOL

    Sean Metcalf. (2015, December 28). Finding Passwords in SYSVOL & Exploiting Group Policy Preferences. Retrieved February 17, 2020.

    Open source URL
  27. [27]
    ADSecurity Finding Passwords in SYSVOL

    Sean Metcalf. (2015, December 28). Finding Passwords in SYSVOL & Exploiting Group Policy Preferences. Retrieved February 17, 2020.

    Open source URL
  28. [28]
    MS14-025

    Microsoft. (2014, May 13). MS14-025: Vulnerability in Group Policy Preferences could allow elevation of privilege. Retrieved February 17, 2020.

    Open source URL
  29. [29]
    MS14-025

    Microsoft. (2014, May 13). MS14-025: Vulnerability in Group Policy Preferences could allow elevation of privilege. Retrieved February 17, 2020.

    Open source URL
  30. [30]
    SensePost Outlook Forms

    Stalmans, E. (2017, April 28). Outlook Forms and Shells. Retrieved February 4, 2019.

    Open source URL
  31. [31]
    SensePost Outlook Forms

    Stalmans, E. (2017, April 28). Outlook Forms and Shells. Retrieved February 4, 2019.

    Open source URL
  32. [32]
    SensePost Outlook Home Page

    Stalmans, E. (2017, October 11). Outlook Home Page – Another Ruler Vector. Retrieved February 4, 2019.

    Open source URL
  33. [33]
    SensePost Outlook Home Page

    Stalmans, E. (2017, October 11). Outlook Home Page – Another Ruler Vector. Retrieved February 4, 2019.

    Open source URL
  34. [34]
    Cisco Blog Legacy Device Attacks

    Omar Santos. (2020, October 19). Attackers Continue to Target Legacy Devices. Retrieved October 20, 2020.

    Open source URL
  35. [35]
    Cisco Blog Legacy Device Attacks

    Omar Santos. (2020, October 19). Attackers Continue to Target Legacy Devices. Retrieved October 20, 2020.

    Open source URL
  36. [36]
    SensePost Outlook Forms

    Stalmans, E. (2017, April 28). Outlook Forms and Shells. Retrieved February 4, 2019.

    Open source URL
  37. [37]
    SensePost Outlook Forms

    Stalmans, E. (2017, April 28). Outlook Forms and Shells. Retrieved February 4, 2019.

    Open source URL
  38. [38]
    SensePost Outlook Home Page

    Stalmans, E. (2017, October 11). Outlook Home Page – Another Ruler Vector. Retrieved February 4, 2019.

    Open source URL
  39. [39]
    SensePost Outlook Home Page

    Stalmans, E. (2017, October 11). Outlook Home Page – Another Ruler Vector. Retrieved February 4, 2019.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.