kevmap

Techniques › T1505

T1505 Server Software Component

persistence — Windows, Linux, macOS, Network Devices, ESXi · attack.mitre.org · JSON

1
MITRE detection strategy
4
analytics
1
Sigma rules tagged attack.t1505
2
KEV CVEs mapped here
<p>Adversaries may abuse legitimate extensible development features of servers to establish persistent access to systems. Enterprise server applications may include features that allow developers to write and install software or scripts to extend the functionality of the main application. Adversaries may install malicious components to extend and abuse server applications.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

CVEVendor / productMapping typeStateAdded
CVE-2025-49706Microsoft SharePoint primary impact Mapped2025-07-22
CVE-2022-29303SolarView Compact exploitation technique Mapped2023-07-13

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1505

Author: Austin Clark · 2019-08-12 (modified 2025-04-28) · logsource: product=cisco service=aaa · 671ffc77-50a7-464f-9e3d-9ea2b493b26b
Modifications to a config that will serve an adversary's impacts or persistence

Sub-techniques

IDNameSigma rulesKEV CVEs
T1505.001SQL Stored Procedures20
T1505.002Transport Agent30
T1505.003Web Shell3526
T1505.004IIS Components50
T1505.005Terminal Services DLL10
T1505.006vSphere Installation Bundles00