Adversaries may exploit vulnerabilities to evade detection by hiding activity, suppressing logging, or operating within trusted or unmonitored components. Adversaries may exploit a system or application vulnerability to avoid detection while maintaining access within an environment. Exploitation occurs when an adversary leverages a programming flaw to execute code in a manner that minimizes visibility or blends in with legitimate activity. Rather than directly disabling defenses, adversaries may use exploitation to circumvent monitoring and logging mechanisms. This can include abusing vulnerabilities in logging pipelines, security tools, or cloud infrastructure to evade audit trails, suppress alerts, or operate without generating telemetry. Adversaries may identify these opportunities through prior reconnaissance or by performing discovery of security controls after initial access. In some cases, vulnerabilities in SaaS or public cloud environments may be exploited to evade logging, obscure activity, or deploy infrastructure that remains hidden from standard monitoring tools.(Citation: Bypassing CloudTrail in AWS Service Catalog)(Citation: GhostToken GCP flaw)

Linked Issues

Issuelinks
Linktyp Issue
is related to Techniques
is blocked by Exploit Protection
is blocked by Update Software
is blocked by Threat Intelligence Program
is blocked by Application Isolation and Sandboxing
is blocked by Detection Strategy for Exploitation for Stealth
is blocked by Asset Inventories
is blocked by Security, Compliance & Resilience Controls Oversight
is blocked by Secure Baseline Configurations
is blocked by Continuous Monitoring
is blocked by Malicious Code Protection (Anti-Malware)
is blocked by Endpoint File Integrity Monitoring (FIM)
is blocked by Mobile Code
is blocked by Least Privilege
is blocked by Boundary Protection
is blocked by Data Flow Enforcement – Access Control Lists (ACLs)
is blocked by Application Partitioning
is blocked by Process Isolation
is blocked by Security Function Isolation
is blocked by Honeypots
is blocked by Honeyclients
is blocked by Heterogeneity
is blocked by Concealment & Misdirection
is blocked by Threat Intelligence Feeds
is blocked by Threat Hunting
is blocked by Software & Firmware Patching
is blocked by Vulnerability Scanning
Impressum Deutsch Englisch