+Disable or Remove Feature or Program

Disable or Remove Feature or Program

Disable or remove unnecessary and potentially vulnerable software, features, or services to reduce the attack surface and prevent abuse by adversaries. This involves identifying software or features that are no longer needed or that could be exploited and ensuring they are either removed or properly disabled. This mitigation can be implemented through the following measures: Remove Legacy Software: - Use Case: Disable or remove older versions of software that no longer receive updates or security patches (e.g., legacy Java, Adobe Flash). - Implementation: A company removes Flash Player from all employee systems after it has reached its end-of-life date. Disable Unused Features: - Use Case: Turn off unnecessary operating system features like SMBv1, Telnet, or RDP if they are not required. - Implementation: Disable SMBv1 in a Windows environment to mitigate vulnerabilities like EternalBlue. Control Applications Installed by Users: - Use Case: Prevent users from installing unauthorized software via group policies or other management tools. - Implementation: Block user installations of unauthorized file-sharing applications (e.g., BitTorrent clients) in an enterprise environment. Remove Unnecessary Services: - Use Case: Identify and disable unnecessary default services running on endpoints, servers, or network devices. - Implementation: Disable unused administrative shares (e.g., C$, ADMIN$) on workstations. Restrict Add-ons and Plugins: - Use Case: Remove or disable browser plugins and add-ons that are not needed for business purposes. - Implementation: Disable Java and ActiveX plugins in web browsers to prevent drive-by attacks.

1. Übersicht

Bezeichnung Standard

1.1 Referenzen

1.2 Identifizierte Anforderungen

1.3 Related Regulations

2. Identifizierte Anforderungen

Anforderungen
Source Anforderung

3. Related Regulations

Regulations
Source Regulierung

Linked Issues

Issuelinks
Linktyp Issue
is related to Mitigations
blocks Re-opened Applications
blocks SSH
blocks Cloud Application Integration
blocks VNC
blocks Exploitation of Remote Services
blocks Visual Basic
blocks Wordlist Scanning
blocks Windows Remote Management
blocks Inter-Process Communication
blocks Run Virtual Instance
blocks Name Resolution Poisoning and SMB Relay
blocks Network Service Discovery
blocks Electron Applications
blocks ClickOnce
blocks Steal or Forge Authentication Certificates
blocks Email Forwarding Rule
blocks Adversary-in-the-Middle
blocks Exfiltration Over Other Network Medium
blocks Account Manipulation
blocks Disable or Modify Tools
blocks Exfiltration over USB
blocks Mark-of-the-Web Bypass
blocks Server Software Component
blocks JamPlus
blocks PowerShell
blocks Odbcconf
blocks Replication Through Removable Media
blocks Office Application Startup
blocks Screensaver
blocks Command and Scripting Interpreter
blocks Distributed Component Object Model
blocks Remote Desktop Protocol
blocks Windows Credential Manager
blocks Communication Through Removable Media
blocks RDP Hijacking
blocks Mavinject
blocks Remote Service Session Hijacking
blocks SSH Authorized Keys
blocks ARP Cache Poisoning
blocks Remote Desktop Software
blocks Verclsid
blocks Mshta
blocks SSH Hijacking
blocks External Remote Services
blocks Msiexec
blocks VBA Stomping
blocks JavaScript
blocks Container Administration Command
blocks InstallUtil
blocks MSBuild
blocks Exfiltration Over Bluetooth
blocks MMC
blocks Cloud Instance Metadata API
blocks Emond
blocks Remote Services
blocks Direct Cloud VM Connections
blocks Office Template Macros
blocks Web Shell
blocks Traffic Signaling
blocks System Binary Proxy Execution
blocks Exfiltration Over Physical Medium
blocks Regsvcs/Regasm
blocks Template Injection
blocks Dynamic Data Exchange
blocks Downgrade Attack
blocks Additional Email Delegate Permissions
blocks Trusted Developer Utilities Proxy Execution
blocks Escape to Host
blocks Remote Access Tools
blocks Additional Cloud Credentials
blocks CMSTP
  • MITREATTACK -

    © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. https://attack.mitre.org/

    Terms of Use

    LICENSE

    The MITRE Corporation (MITRE) hereby grants you a non-exclusive, royalty-free license to use ATT&CK® for research, development, and commercial purposes. Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

    "© 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation."

    DISCLAIMERS

    MITRE does not claim ATT&CK enumerates all possibilities for the types of actions and behaviors documented as part of its adversary model and framework of techniques. Using the information contained within ATT&CK to address or cover full categories of techniques will not guarantee full defensive coverage as there may be undisclosed techniques or variations on existing techniques not documented by ATT&CK.

    ALL DOCUMENTS AND THE INFORMATION CONTAINED THEREIN ARE PROVIDED ON AN "AS IS" BASIS AND THE CONTRIBUTOR, THE ORGANIZATION HE/SHE REPRESENTS OR IS SPONSORED BY (IF ANY), THE MITRE CORPORATION, ITS BOARD OF TRUSTEES, OFFICERS, AGENTS, AND EMPLOYEES, DISCLAIM ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTY THAT THE USE OF THE INFORMATION THEREIN WILL NOT INFRINGE ANY RIGHTS OR ANY IMPLIED WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE.

    See our FAQ for more information on how to use and represent the ATT&CK name.

Impressum Deutsch Englisch