T1211: Exploitation for Defense Evasion
Essential information
- MITRE technique ID
T1211- Confidence
- 100/100
- Revoked
- No
- Published
- 18/04/2018 19:59
- Modified
- 27/03/2026 01:12
- Author / Source
- The MITRE Corporation
Aliases
T1211
Platforms
windows macos linux IaaS SaaS
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | defense-evasion |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (13)
-
Velvet Ant usesThe MITRE Corporation Confidence 100
[Velvet Ant](https://attack.mitre.org/groups/G1047) is a threat actor operating since at least 2021. [Velvet Ant](https://attack.mitre.org/groups/G1047) is associated with complex persistence mechanisms, the targeting of network devices and appliances during operations,…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Cuba usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Earth Longzhi usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
LilacSquid usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
CrazyHunter usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
DeadLock usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
ToddyCat usesThe MITRE Corporation Confidence 100
[ToddyCat](https://attack.mitre.org/groups/G1022) is a sophisticated threat group that has been active since at least 2020 using custom loaders and malware in multi-stage infection chains against government and military targets…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Kimsuky and Andariel usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[APT28](https://attack.mitre.org/groups/G0007) is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.(Citation: NSA/FBI Drovorub…
First seen 01/01/1970 · Last seen 16/11/5138 · -
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[BlackByte](https://attack.mitre.org/groups/G1043) is a ransomware threat actor operating since at least 2021. [BlackByte](https://attack.mitre.org/groups/G1043) is associated with several versions of ransomware also labeled [BlackByte Ransomware](https://attack.mitre.org/software/S1180). [BlackByte](https://attack.mitre.org/groups/G1043) ransomware operations initially used…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Aoqin Dragon usesThe MITRE Corporation Confidence 100
[Aoqin Dragon](https://attack.mitre.org/groups/G1007) is a suspected Chinese cyber espionage threat group that has been active since at least 2013. [Aoqin Dragon](https://attack.mitre.org/groups/G1007) has primarily targeted government, education, and telecommunication organizations…
First seen 01/01/1970 · Last seen 16/11/5138 ·
Malware (46)
-
Fidel uses
-
COLDDRAW uses
-
Bughatch uses
-
QuackBot usesFamily
-
DeadLock usesFamily
-
SSHDoor usesFamily
-
TCESB usesFamily
-
Beep uses
-
EDRKillShifter usesFamily
-
SmallTiger usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
NekoStealer usesFamily
-
Cobalt Strike usesFamily
Reports (12)
-
1 CVE 15 MITREs 1 Malware 5 Observables 1 APT
-
1 CVE 6 MITREs 1 Malware 2 Observables 1 APT
-
9 MITREs 6 Observables
-
1 CVE 12 MITREs 1 Malware 2 Observables 1 APT
-
21 MITREs 2 Malwares 4 Observables 1 APT
-
8 MITREs 2 Malwares 2 Observables
-
15 MITREs 2 Malwares 64 Observables 1 APT
-
20 MITREs 1 Malware 9 Observables 1 APT
-
11 MITREs 1 Observable
-
6 MITREs 1 Malware 6 Observables
-
20 MITREs 6 Malwares 19 Observables 1 APT
-
13 MITREs 2 Malwares 10 Observables
Vulnerabilities (CVE) (8)
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via …
- Attack vector
- Network
- Published
- 20/05/2024
- Modified
- 29/05/2026
An issue in the BdApiUtil driver of Baidu Antivirus v5.2.3.116083 allows attackers to terminate arbitrary process via executing a BYOVD (Bring Your …
- Attack vector
- NETWORK
- Published
- 11/02/2025
- Modified
- 21/12/2025
Veeam Backup & Replication Cloud Connect component contains a missing authentication for critical function vulnerability that allows an unauthenticated user operating within …
- Attack vector
- Network
- Published
- 22/08/2023
- Modified
- 27/05/2026
The Empowerment theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.2 via deserialization of …
- Published
- 01/10/2024
- Modified
- 04/10/2024
Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a …
- Attack vector
- Local
- Published
- 03/11/2021
- Modified
- 27/05/2026
The driver in Micro-Star MSI Afterburner 4.6.2.15658 (aka RTCore64.sys and RTCore32.sys) allows any authenticated user to read and write to arbitrary memory, …
- Attack vector
- LOCAL
- Published
- 11/09/2019
- Modified
- 20/12/2025
Howyar UEFI Application "Reloader" (32-bit and 64-bit) is vulnerable to execution of unsigned software in a hardcoded path.
- Attack vector
- LOCAL
- Published
- 14/01/2025
- Modified
- 21/12/2025
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, …
- Attack vector
- Network
- Published
- 05/12/2025
- Modified
- 29/05/2026
Course Of Action (4)
-
Threat Intelligence Program mitigates
-
Application Isolation and Sandboxing mitigates
-
Exploit Protection mitigates
-
Update Software mitigates