T1499.004 — Application or System Exploitation
T1499.004: Application or System Exploitation
MITRE ATT&CK® Enterprise technique
| Tactics | Impact |
| Platforms | Windows, IaaS, Linux, macOS |
| Permissions required | — |
| Version | 1.3 |
| Parent technique | T1499 |
Description
Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users. (Citation: Sucuri BIND9 August 2015) Some systems may automatically restart critical applications and services when crashes occur, but they can likely be re-exploited to cause a persistent denial of service (DoS) condition.
Adversaries may exploit known or zero-day vulnerabilities to crash applications and/or systems, which may also lead to dependent applications and/or systems to be in a DoS condition. Crashed or restarted applications or systems may also have other effects such as Data Destruction, Firmware Corruption, Service Stop etc. which may further cause a DoS condition and deny availability to critical information, applications and/or systems.
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1499/004
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/