Adversaries may directly interact with the native OS application programming interface (API) to access system functions. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes. (Citation: The MITRE Corporation May 2017) These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations. Functionality provided by native APIs are often also exposed to user-mode applications via interfaces and libraries. For example, functions such as memcpy and direct operations on memory registers can be used to modify user and system memory space.

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is related to Safety Controller
is related to Switch
is related to Control Server
is related to Jump Host
is related to Distributed Control System (DCS) Controller
is related to Data Gateway
is related to Human-Machine Interface (HMI)
is related to Application Server
is related to Remote Terminal Unit (RTU)
is related to Intelligent Electronic Device (IED)
is related to Programmable Automation Controller (PAC)
is related to Firewall
is related to Workstation
is related to Field I/O
is related to Programmable Logic Controller (PLC)
is related to Data Historian
is related to Virtual Private Network (VPN) Server
is blocked by Execution Prevention
is blocked by Detection of Native API
Impressum Deutsch Englisch