LiveActive security incident?Get immediate response
MITRE ATT&CK® Mitigation

M1051: Update Software

Software updates ensure systems are protected against known vulnerabilities by applying patches and upgrades provided by vendors. Regular updates reduce the attack surface and prevent adversaries from exploiting known security gaps. This includes patching operating systems, applications, drivers, and firmware. This mitigation can be implemented through the following measures:

Regular Operating System Updates

- Implementation: Apply the latest Windows security updates monthly using WSUS (Windows Server Update Services) or a similar patch management solution. Configure systems to check for updates automatically and schedule reboots during maintenance windows. - Use Case: Prevents exploitation of OS vulnerabilities such as privilege escalation or remote code execution.

Application Patching

- Implementation: Monitor Apache's update release notes for security patches addressing vulnerabilities. Schedule updates for off-peak hours to avoid downtime while maintaining security compliance. - Use Case: Prevents exploitation of web application vulnerabilities, such as those leading to unauthorized access or data breaches.

Firmware Updates

- Implementation: Regularly check the vendor’s website for firmware updates addressing vulnerabilities. Plan for update deployment during scheduled maintenance to minimize business disruption. - Use Case: Protects against vulnerabilities that adversaries could exploit to gain access to network devices or inject malicious traffic.

Emergency Patch Deployment

- Implementation: Use the emergency patch deployment feature of the organization's patch management tool to apply updates to all affected Exchange servers within 24 hours. - Use Case: Reduces the risk of exploitation by rapidly addressing critical vulnerabilities.

Centralized Patch Management

- Implementation: Implement a centralized patch management system, such as SCCM or ManageEngine, to automate and track patch deployment across all environments. Generate regular compliance reports to ensure all systems are updated. - Use Case: Streamlines patching processes and ensures no critical systems are missed.

*Tools for Implementation*

Patch Management Tools:

- WSUS: Manage and deploy Microsoft updates across the organization. - ManageEngine Patch Manager Plus: Automate patch deployment for OS and third-party apps. - Ansible: Automate updates across multiple platforms, including Linux and Windows.

Vulnerability Scanning Tools:

- OpenVAS: Open-source vulnerability scanning to identify missing patches.

EnterpriseM1051MitigationObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Update Software is a foundational risk-reduction control: it reduces exposure to known vulnerabilities in operating systems, applications, drivers, and firmware before those weaknesses can be used for initial access, privilege escalation, lateral movement, persistence, credential access, stealth, or impact. For leaders, the practical question is not “do we patch?” but whether critical assets, public-facing systems, client software, firmware, and centralized deployment tools are updated quickly enough and with evidence that stands up during incidents or audits.

Executive priority

Prioritize this as a business continuity and resilience control. The ATT&CK relationships show update management applies to high-consequence scenarios including exploitation of public-facing applications, client-side exploitation, remote-service exploitation, privilege escalation, software supply chain compromise, Office and extension-based persistence, credential-related exploitation, and firmware-level impact or persistence. Executives should ask for measurable patch compliance, emergency patch capability, maintenance-window governance, and visibility into systems that are often missed: firmware, network devices, SaaS/cloud-connected management tooling, development dependencies, browsers/extensions, and deployment platforms.

Technical view

For SOC, IR, vulnerability management, and detection engineering teams, M1051 is primarily a prevention and assurance activity rather than a detection analytic; MITRE provides no official detection text for this mitigation. Validate that patch status, vulnerability scan results, asset inventory, software/firmware versions, and deployment-tool logs can be joined to the techniques this mitigation addresses, especially T1190, T1203, T1210, T1068, T1212, T1542, T1495, T1195, and T1072. Because centralized patch and software deployment systems are also related to adversary abuse, teams should treat them as privileged infrastructure: monitor change activity, administrative use, update failures, emergency deployments, and unusual command or package distribution behavior.

Likely telemetry

  • Asset inventory covering operating systems, applications, drivers, firmware, public-facing services, client applications, network devices, and cloud/SaaS-connected management components where applicable
  • Patch management records from centralized tooling, including deployment status, failures, deferrals, reboot requirements, emergency patch actions, and compliance reports
  • Vulnerability scanner findings identifying missing patches or vulnerable versions
  • Software and firmware version data from endpoints, servers, network devices, and managed platforms
  • Change-management and maintenance-window records showing when updates were approved, deployed, rolled back, or delayed

Detection direction

  • Do not treat this mitigation as a standalone detection. Validate whether security operations can prove which assets are missing vendor updates and whether those gaps overlap with exposed services, privileged systems, identity components, development tooling, or firmware-bearing devices.
  • Tune vulnerability and patch reporting around exploit-relevant exposure: public-facing applications, remote services, client applications, privilege escalation paths, credential-access surfaces, and firmware/pre-OS components reflected in the related ATT&CK techniques.
  • Correlate update failures and long-lived exceptions with incident findings. A recurring blind spot is that patch dashboards show endpoint compliance while excluding firmware, third-party applications, browser/IDE extensions, network devices, containers, IaaS assets, or SaaS-connected deployment systems.
  • Monitor centralized software deployment tools for administrative changes and unusual distribution behavior because the relationship context includes adversary use of software deployment tools for execution and lateral movement.
  • Account for false confidence from scheduled patch cycles: monthly operating system updates may not address emergency fixes, application patches, firmware updates, or supply chain/dependency risks without separate processes and evidence.

Mitigation priorities

  • Maintain a complete and current asset and software inventory before measuring patch compliance; unknown systems cannot be reliably updated.
  • Use centralized patch management to automate, track, and report deployment across operating systems, applications, drivers, and firmware where supported.
  • Define risk-based service levels for routine and emergency updates, including the ability to deploy critical fixes rapidly to affected systems such as public-facing servers or other high-risk assets.
  • Schedule reboots and maintenance windows to reduce operational disruption while preventing indefinite deferral of security updates.
  • Include application release-note monitoring, vulnerability scanning, and compliance reporting so missing patches are identified and remediated rather than only recorded.
Additional notes and limits

The supplied ATT&CK object is a mitigation, not a technique, and its official description emphasizes vendor patches, upgrades, centralized patch management, vulnerability scanning, firmware updates, and emergency patch deployment. The relationship set is broad, making this control relevant across initial access, execution, privilege escalation, persistence, credential access, lateral movement, stealth, and impact. The strongest defensive value comes from turning update management into measurable coverage: what is in scope, what is missing, how fast critical updates deploy, and whether exceptions are visible to SOC, IR, vulnerability management, and audit stakeholders.

MITRE does not provide official detection guidance for M1051, and the mitigation itself has no specified platforms or tactics. Platform relevance is inferred only from the related ATT&CK techniques and should be confirmed against the local environment. This take does not assert active exploitation, specific vendor exposure, or guaranteed detection coverage; organizations need local asset, vulnerability, patch, and incident data to prioritize action.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Update Software

Software updates ensure systems are protected against known vulnerabilities by applying patches and upgrades provided by vendors. Regular updates reduce the attack surface and prevent adversaries from exploiting known security gaps. This includes patching operating systems, applications, drivers, and firmware. This mitigation can be implemented through the following measures:

Regular Operating System Updates

- Implementation: Apply the latest Windows security updates monthly using WSUS (Windows Server Update Services) or a similar patch management solution. Configure systems to check for updates automatically and schedule reboots during maintenance windows. - Use Case: Prevents exploitation of OS vulnerabilities such as privilege escalation or remote code execution.

Application Patching

- Implementation: Monitor Apache's update release notes for security patches addressing vulnerabilities. Schedule updates for off-peak hours to avoid downtime while maintaining security compliance. - Use Case: Prevents exploitation of web application vulnerabilities, such as those leading to unauthorized access or data breaches.

Firmware Updates

- Implementation: Regularly check the vendor’s website for firmware updates addressing vulnerabilities. Plan for update deployment during scheduled maintenance to minimize business disruption. - Use Case: Protects against vulnerabilities that adversaries could exploit to gain access to network devices or inject malicious traffic.

Emergency Patch Deployment

- Implementation: Use the emergency patch deployment feature of the organization's patch management tool to apply updates to all affected Exchange servers within 24 hours. - Use Case: Reduces the risk of exploitation by rapidly addressing critical vulnerabilities.

Centralized Patch Management

- Implementation: Implement a centralized patch management system, such as SCCM or ManageEngine, to automate and track patch deployment across all environments. Generate regular compliance reports to ensure all systems are updated. - Use Case: Streamlines patching processes and ensures no critical systems are missed.

*Tools for Implementation*

Patch Management Tools:

- WSUS: Manage and deploy Microsoft updates across the organization. - ManageEngine Patch Manager Plus: Automate patch deployment for OS and third-party apps. - Ansible: Automate updates across multiple platforms, including Linux and Windows.

Vulnerability Scanning Tools:

- OpenVAS: Open-source vulnerability scanning to identify missing patches.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
beaa77555ca1adf2...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.