Skip to content
Every technique
T1505Detection written

Server Software Component

PersistenceWindows, Linux, macOS, Network Devices, ESXi

Where this stands

One published detection covers this technique. Every one is unverified — no rule on Siemphony has been executed against real telemetry.

What the technique is

Adversaries may abuse legitimate extensible development features of servers to establish persistent access to systems. Enterprise server applications may include features that allow developers to write and install software or scripts to extend the functionality of the main application. Adversaries may install malicious components to extend and abuse server applications.

Read it on attack.mitre.org

What MITRE says you would watch

  • AN1507

    Installation of malicious IIS/Apache/SQL server modules that later execute command-line interpreters or establish outbound connections.

  • AN1508

    Abuse of extensible server modules (e.g., Apache, Nginx, Tomcat) to load rogue plugins that initiate bash, connect to C2, or spawn reverse shells.

  • AN1509

    Malicious use of webserver plugins (e.g., for nginx, PHP, Node.js) that execute AppleScript or open network sockets.

Technique names and descriptions © MITRE ATT&CK®, CC BY 4.0. Not endorsed by MITRE.