Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/M1038
MITRE ATT&CK Mitigation

M1038: Execution Prevention

ShareXLinkedInRedditHN

Prevent the execution of unauthorized or malicious code on systems by implementing application control, script blocking, and other execution prevention mechanisms. This ensures that only trusted and authorized code is executed, reducing the risk of malware and unauthorized actions. This mitigation can be implemented through the following measures: Application Control: - Use Case: Use tools like AppLocker or Windows Defender Application Control (WDAC) to create whitelists of authorized applications and block unauthorized ones. On Linux, use tools like SELinux or AppArmor to define mandatory access control policies for application execution. - Implementation: Allow only digitally signed or pre-approved applications to execute on servers and endpoints. (e.g., `New-AppLockerPolicy -PolicyType Enforced -FilePath "C:\Policies\AppLocker.xml"`) Script Blocking: - Use Case: Use script control mechanisms to block unauthorized execution of scripts, such as PowerShell or JavaScript. Web Browsers: Use browser extensions or settings to block JavaScript execution from untrusted sources. - Implementation: Configure PowerShell to enforce Constrained Language Mode for non-administrator users. (e.g., `Set-ExecutionPolicy AllSigned`) Executable Blocking: - Use Case: Prevent execution of binaries from suspicious locations, such as `%TEMP%` or `%APPDATA%` directories. - Implementation: Block execution of `.exe`, `.bat`, or `.ps1` files from user-writable directories. Dynamic Analysis Prevention: - Use Case: Use behavior-based execution prevention tools to identify and block malicious activity in real time. - Implemenation: Employ EDR solutions that analyze runtime behavior and block suspicious code execution.

▪Techniques addressed (79)

T1219.001IDE TunnelingT1216.002SyncAppvPublishingServerT1553.003SIP and Trust Provider HijackingT1059.010AutoHotKey & AutoITT1036.005Match Legitimate Resource Name or LocationT1574.008Path Interception by Search Order HijackingT1574.006Dynamic Linker HijackingT1546.002ScreensaverT1564.003Hidden WindowT1553Subvert Trust ControlsT1176.002IDE ExtensionsT1218.005MshtaT1059.005Visual BasicT1218.004InstallUtilT1204User ExecutionT1574.001DLLT1204.004Malicious Copy and PasteT1129Shared ModulesT1218.009Regsvcs/RegasmT1548Abuse Elevation Control MechanismT1548.004Elevated Execution with PromptT1611Escape to HostT1216.001PubPrnT1547.009Shortcut ModificationT1218.012VerclsidT1106Native APIT1127.003JamPlusT1218.015Electron ApplicationsT1219Remote Access ToolsT1216System Script Proxy ExecutionT1047Windows Management InstrumentationT1674Input InjectionT1059.007JavaScriptT1204.002Malicious FileT1546.010AppInit DLLsT1059.004Unix ShellT1574Hijack Execution FlowT1505.004IIS ComponentsT1547.004Winlogon Helper DLLT1059.002AppleScriptT1553.001Gatekeeper BypassT1036.008Masquerade File TypeT1218.008OdbcconfT1685Disable or Modify ToolsT1059Command and Scripting InterpreterT1574.007Path Interception by PATH Environment VariableT1127Trusted Developer Utilities Proxy ExecutionT1490Inhibit System RecoveryT1059.008Network Device CLIT1218System Binary Proxy ExecutionT1218.002Control PanelT1059.003Windows Command ShellT1546.006LC_LOAD_DYLIB AdditionT1220XSL Script ProcessingT1080Taint Shared ContentT1059.009Cloud APIT1547.006Kernel Modules and ExtensionsT1574.009Path Interception by Unquoted PathT1059.006PythonT1059.013Container CLI/APIT1059.011LuaT1127.001MSBuildT1574.012COR_PROFILERT1546.008Accessibility FeaturesT1546.009AppCert DLLsT1176Software ExtensionsT1068Exploitation for Privilege EscalationT1176.001Browser ExtensionsT1553.005Mark-of-the-Web BypassT1218.003CMSTPT1219.002Remote Desktop SoftwareT1036MasqueradingT1218.014MMCT1218.001Compiled HTML FileT1218.013MavinjectT1564.006Run Virtual InstanceT1609Container Administration CommandT1685.003Modify or Spoof Tool UIT1059.001PowerShell

▪Reference

M1038on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.