Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/M1042
MITRE ATT&CK Mitigation

M1042: Disable or Remove Feature or Program

ShareXLinkedInRedditHN

Disable or remove unnecessary and potentially vulnerable software, features, or services to reduce the attack surface and prevent abuse by adversaries. This involves identifying software or features that are no longer needed or that could be exploited and ensuring they are either removed or properly disabled. This mitigation can be implemented through the following measures: Remove Legacy Software: - Use Case: Disable or remove older versions of software that no longer receive updates or security patches (e.g., legacy Java, Adobe Flash). - Implementation: A company removes Flash Player from all employee systems after it has reached its end-of-life date. Disable Unused Features: - Use Case: Turn off unnecessary operating system features like SMBv1, Telnet, or RDP if they are not required. - Implementation: Disable SMBv1 in a Windows environment to mitigate vulnerabilities like EternalBlue. Control Applications Installed by Users: - Use Case: Prevent users from installing unauthorized software via group policies or other management tools. - Implementation: Block user installations of unauthorized file-sharing applications (e.g., BitTorrent clients) in an enterprise environment. Remove Unnecessary Services: - Use Case: Identify and disable unnecessary default services running on endpoints, servers, or network devices. - Implementation: Disable unused administrative shares (e.g., C$, ADMIN$) on workstations. Restrict Add-ons and Plugins: - Use Case: Remove or disable browser plugins and add-ons that are not needed for business purposes. - Implementation: Disable Java and ActiveX plugins in web browsers to prevent drive-by attacks.

▪Techniques addressed (71)

T1547.007Re-opened ApplicationsT1021.004SSHT1671Cloud Application IntegrationT1021.005VNCT1210Exploitation of Remote ServicesT1059.005Visual BasicT1595.003Wordlist ScanningT1021.006Windows Remote ManagementT1559Inter-Process CommunicationT1564.006Run Virtual InstanceT1557.001Name Resolution Poisoning and SMB RelayT1046Network Service DiscoveryT1218.015Electron ApplicationsT1127.002ClickOnceT1649Steal or Forge Authentication CertificatesT1114.003Email Forwarding RuleT1557Adversary-in-the-MiddleT1011Exfiltration Over Other Network MediumT1098Account ManipulationT1685Disable or Modify ToolsT1052.001Exfiltration over USBT1553.005Mark-of-the-Web BypassT1505Server Software ComponentT1127.003JamPlusT1059.001PowerShellT1218.008OdbcconfT1091Replication Through Removable MediaT1137Office Application StartupT1546.002ScreensaverT1059Command and Scripting InterpreterT1021.003Distributed Component Object ModelT1021.001Remote Desktop ProtocolT1555.004Windows Credential ManagerT1092Communication Through Removable MediaT1563.002RDP HijackingT1218.013MavinjectT1563Remote Service Session HijackingT1098.004SSH Authorized KeysT1557.002ARP Cache PoisoningT1219.002Remote Desktop SoftwareT1218.012VerclsidT1218.005MshtaT1563.001SSH HijackingT1133External Remote ServicesT1218.007MsiexecT1564.007VBA StompingT1059.007JavaScriptT1609Container Administration CommandT1218.004InstallUtilT1127.001MSBuildT1011.001Exfiltration Over BluetoothT1218.014MMCT1552.005Cloud Instance Metadata APIT1546.014EmondT1021Remote ServicesT1021.008Direct Cloud VM ConnectionsT1137.001Office Template MacrosT1505.003Web ShellT1205Traffic SignalingT1218System Binary Proxy ExecutionT1052Exfiltration Over Physical MediumT1218.009Regsvcs/RegasmT1221Template InjectionT1559.002Dynamic Data ExchangeT1689Downgrade AttackT1098.002Additional Email Delegate PermissionsT1127Trusted Developer Utilities Proxy ExecutionT1611Escape to HostT1219Remote Access ToolsT1098.001Additional Cloud CredentialsT1218.003CMSTP

▪Reference

M1042on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.