{"id":"T1505","name":"Server Software Component","url":"https://attack.mitre.org/techniques/T1505","tactics":["persistence"],"platforms":["Windows","Linux","macOS","Network Devices","ESXi"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0547","stix_id":"x-mitre-detection-strategy--27b606f9-dde4-456c-8d90-51289313994f","name":"Detection Strategy for T1505 - Server Software Component","url":"https://attack.mitre.org/detectionstrategies/DET0547","analytics":[{"id":"AN1507","stix_id":"x-mitre-analytic--ea250997-091b-4c5e-8827-a41f03e34caf","name":"Analytic 1507","description":"Installation of malicious IIS/Apache/SQL server modules that later execute command-line interpreters or establish outbound connections.","url":"https://attack.mitre.org/detectionstrategies/DET0547#AN1507","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4698","data_component":"DC0001","data_component_name":"Scheduled Job Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Application","channel":"Unusual DLL/plugin registration for IIS/SQL/Apache or unexpected error logs","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"wineventlog-application"}],"mutable_elements":[{"field":"TimeWindow","description":"Time delta between module install and process execution (e.g., persistence delay)."},{"field":"ParentProcessName","description":"Custom server wrapper processes or renamed webserver processes may require tuning."}],"live":true,"detection_strategies":["DET0547"],"techniques":["T1505"]},{"id":"AN1508","stix_id":"x-mitre-analytic--65f89c21-d42a-4028-9865-122ea1079a77","name":"Analytic 1508","description":"Abuse of extensible server modules (e.g., Apache, Nginx, Tomcat) to load rogue plugins that initiate bash, connect to C2, or spawn reverse shells.","url":"https://attack.mitre.org/detectionstrategies/DET0547#AN1508","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"},{"name":"linux:syslog","channel":"Module registration or stacktrace logs indicating segmentation faults or unknown module errors","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"linux-syslog"},{"name":"NSM:Flow","channel":"Outbound connections from web server binaries (apache2, nginx, php-fpm) to unknown external IPs","data_component":"DC0078","data_component_name":"Network Traffic Flow","log_source_slug":"nsm-flow"}],"mutable_elements":[{"field":"ServerBinaryPath","description":"Alternate install paths like /opt/httpd or user-compiled binaries"},{"field":"OutboundPortRange","description":"Tunable to match expected versus suspicious outbound traffic patterns"}],"live":true,"detection_strategies":["DET0547"],"techniques":["T1505"]},{"id":"AN1509","stix_id":"x-mitre-analytic--d5af4c93-632c-41c3-a101-6e9e534d7d01","name":"Analytic 1509","description":"Malicious use of webserver plugins (e.g., for nginx, PHP, Node.js) that execute AppleScript or open network sockets.","url":"https://attack.mitre.org/detectionstrategies/DET0547#AN1509","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Script interpreter invoked by nginx/apache worker process","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"Web server process initiating outbound TCP connections not tied to normal server traffic","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"ParentBinaryPath","description":"If homebrew or manually compiled nginx/httpd used, baseline accordingly."}],"live":true,"detection_strategies":["DET0547"],"techniques":["T1505"]},{"id":"AN1510","stix_id":"x-mitre-analytic--55b8622a-795b-41d8-9b11-5576a0fb8f0f","name":"Analytic 1510","description":"Use of ESXi web interface plugins or vSphere extensions to embed persistent malicious scripts or services.","url":"https://attack.mitre.org/detectionstrategies/DET0547#AN1510","platforms":["ESXi"],"log_source_references":[{"name":"esxi:hostd","channel":"New extension/module install with unknown vendor ID","data_component":"DC0038","data_component_name":"Application Log Content","log_source_slug":"esxi-hostd"},{"name":"esxi:vmkernel","channel":"Unexpected restarts of management agents or shell access","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"esxi-vmkernel"}],"mutable_elements":[{"field":"PluginVendorName","description":"Whitelist known vendor plug-in names for extension correlation"},{"field":"AccessVector","description":"Limit exposure of plugin installation via HTTPS or SSH"}],"live":true,"detection_strategies":["DET0547"],"techniques":["T1505"]}],"live":true,"version":"1.0","techniques":["T1505"]}],"sigma_rules":[{"id":"671ffc77-50a7-464f-9e3d-9ea2b493b26b","title":"Cisco Modify Configuration","author":"Austin Clark","status":"test","level":"medium","date":"2019-08-12","modified":"2025-04-28","description":"Modifications to a config that will serve an adversary's impacts or persistence","references":[],"logsource":{"product":"cisco","service":"aaa"},"tags":["attack.privilege-escalation","attack.execution","attack.persistence","attack.impact","attack.t1490","attack.t1505","attack.t1565.002","attack.t1053"],"path":"rules/network/cisco/aaa/cisco_cli_modify_config.yml","techniques":["T1490","T1505","T1565.002","T1053"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2025-49706","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2022-29303","state":"mapped","mapping_types":["exploitation_technique"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}