Techniques › T1505
T1505 Server Software Component
persistence — Windows, Linux, macOS, Network Devices, ESXi · attack.mitre.org · JSON
1
MITRE detection strategy
4
analytics
1
Sigma rules tagged attack.t1505
2
KEV CVEs mapped here
<p>Adversaries may abuse legitimate extensible development features of servers to establish persistent access to systems. Enterprise server applications may include features that allow developers to write and install software or scripts to extend the functionality of the main application. Adversaries may install malicious components to extend and abuse server applications.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
| CVE | Vendor / product | Mapping type | State | Added |
|---|---|---|---|---|
| CVE-2025-49706 | Microsoft SharePoint | primary impact | Mapped | 2025-07-22 |
| CVE-2022-29303 | SolarView Compact | exploitation technique | Mapped | 2023-07-13 |
Detection strategy · ATT&CK Enterprise v19.2
- DET0547 Detection Strategy for T1505 - Server Software Component v1.0
AN1507 WindowsInstallation of malicious IIS/Apache/SQL server modules that later execute command-line interpreters or establish outbound connections.WinEventLog:Application
Unusual DLL/plugin registration for IIS/SQL/Apache or unexpected error logs→ DC0038 Application Log ContentTunable:TimeWindowParentProcessNameAN1508 LinuxAbuse of extensible server modules (e.g., Apache, Nginx, Tomcat) to load rogue plugins that initiate bash, connect to C2, or spawn reverse shells.linux:syslogModule registration or stacktrace logs indicating segmentation faults or unknown module errors→ DC0038 Application Log ContentNSM:FlowOutbound connections from web server binaries (apache2, nginx, php-fpm) to unknown external IPs→ DC0078 Network Traffic FlowTunable:ServerBinaryPathOutboundPortRangeAN1509 macOSMalicious use of webserver plugins (e.g., for nginx, PHP, Node.js) that execute AppleScript or open network sockets.macos:unifiedlogScript interpreter invoked by nginx/apache worker process→ DC0032 Process Creationmacos:unifiedlogWeb server process initiating outbound TCP connections not tied to normal server traffic→ DC0085 Network Traffic ContentTunable:ParentBinaryPathAN1510 ESXiUse of ESXi web interface plugins or vSphere extensions to embed persistent malicious scripts or services.Tunable:PluginVendorNameAccessVector
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1505
Author: Austin Clark
· 2019-08-12 (modified 2025-04-28) · logsource: product=cisco service=aaa · 671ffc77-50a7-464f-9e3d-9ea2b493b26b
Modifications to a config that will serve an adversary's impacts or persistence