Umbra Wiki technique technique/T1499.004
Back to wiki

T1499.004 — Application or System Exploitation

provenance: imported · ATT&CK: T1499.004

T1499.004: Application or System Exploitation

MITRE ATT&CK® Enterprise technique

Tactics Impact
Platforms Windows, IaaS, Linux, macOS
Permissions required
Version 1.3
Parent technique T1499

Description

Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users. (Citation: Sucuri BIND9 August 2015) Some systems may automatically restart critical applications and services when crashes occur, but they can likely be re-exploited to cause a persistent denial of service (DoS) condition.

Adversaries may exploit known or zero-day vulnerabilities to crash applications and/or systems, which may also lead to dependent applications and/or systems to be in a DoS condition. Crashed or restarted applications or systems may also have other effects such as Data Destruction, Firmware Corruption, Service Stop etc. which may further cause a DoS condition and deny availability to critical information, applications and/or systems.

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1499/004
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/