Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/M1047
MITRE ATT&CK Mitigation

M1047: Audit

ShareXLinkedInRedditHN

Auditing is the process of recording activity and systematically reviewing and analyzing the activity and system configurations. The primary purpose of auditing is to detect anomalies and identify potential threats or weaknesses in the environment. Proper auditing configurations can also help to meet compliance requirements. The process of auditing encompasses regular analysis of user behaviors and system logs in support of proactive security measures. Auditing is applicable to all systems used within an organization, from the front door of a building to accessing a file on a fileserver. It is considered more critical for regulated industries such as, healthcare, finance and government where compliance requirements demand stringent tracking of user and system activates.This mitigation can be implemented through the following measures: System Audit: - Use Case: Regularly assess system configurations to ensure compliance with organizational security policies. - Implementation: Use tools to scan for deviations from established benchmarks. Permission Audits: - Use Case: Review file and folder permissions to minimize the risk of unauthorized access or privilege escalation. - Implementation: Run access reviews to identify users or groups with excessive permissions. Software Audits: - Use Case: Identify outdated, unsupported, or insecure software that could serve as an attack vector. - Implementation: Use inventory and vulnerability scanning tools to detect outdated versions and recommend secure alternatives. Configuration Audits: - Use Case: Evaluate system and network configurations to ensure secure settings (e.g., disabled SMBv1, enabled MFA). - Implementation: Implement automated configuration scanning tools like SCAP (Security Content Automation Protocol) to identify non-compliant systems. Network Audits: - Use Case: Examine network traffic, firewall rules, and endpoint communications to identify unauthorized or insecure connections. - Implementation: Utilize tools such as Wireshark, or Zeek to monitor and log suspicious network behavior.

▪Techniques addressed (110)

T1484Domain or Tenant Policy ModificationT1059.006PythonT1036MasqueradingT1482Domain Trust DiscoveryT1053.003CronT1574.005Executable Installer File Permissions WeaknessT1505.005Terminal Services DLLT1686.001Cloud FirewallT1176.001Browser ExtensionsT1505Server Software ComponentT1542Pre-OS BootT1566PhishingT1484.001Group Policy ModificationT1539Steal Web Session CookieT1505.001SQL Stored ProceduresT1564.006Run Virtual InstanceT1686Disable or Modify System FirewallT1686.002Network Device FirewallT1574.009Path Interception by Unquoted PathT1685.001Disable or Modify Windows Event LogT1021.001Remote Desktop ProtocolT1564.008Email Hiding RulesT1548.002Bypass User Account ControlT1558.004AS-REP RoastingT1027.011Fileless StorageT1053.002AtT1543.003Windows ServiceT1671Cloud Application IntegrationT1550Use Alternate Authentication MaterialT1552.006Group Policy PreferencesT1685Disable or Modify ToolsT1528Steal Application Access TokenT1574Hijack Execution FlowT1610Deploy ContainerT1606.001Web CookiesT1213.001ConfluenceT1213.005Messaging ApplicationsT1566.002Spearphishing LinkT1546.006LC_LOAD_DYLIB AdditionT1564Hide ArtifactsT1543Create or Modify System ProcessT1558.005Ccache FilesT1213.002SharepointT1556.008Network Provider DLLT1563.002RDP HijackingT1021Remote ServicesT1578.001Create SnapshotT1021.005VNCT1176.002IDE ExtensionsT1552.008Chat MessagesT1566.001Spearphishing AttachmentT1070.008Clear Mailbox DataT1059.011LuaT1550.001Application Access TokenT1684Social EngineeringT1606.002SAML TokensT1095Non-Application Layer ProtocolT1087.004Cloud AccountT1556.006Multi-Factor AuthenticationT1578Modify Cloud Compute InfrastructureT1560.001Archive via UtilityT1548Abuse Elevation Control MechanismT1036.012Browser FingerprintT1213.003Code RepositoriesT1685.004Disable or Modify Linux Audit System LogT1578.005Modify Cloud Compute ConfigurationsT1566.003Spearphishing via ServiceT1552.002Credentials in RegistryT1053Scheduled Task/JobT1574.010Services File Permissions WeaknessT1560Archive Collected DataT1027Obfuscated Files or InformationT1505.004IIS ComponentsT1176Software ExtensionsT1213.004Customer Relationship Management SoftwareT1556.007Hybrid IdentityT1552Unsecured CredentialsT1578.002Create Cloud InstanceT1574.008Path Interception by Search Order HijackingT1542.004ROMMONkitT1053.005Scheduled TaskT1574.001DLLT1204.003Malicious ImageT1578.003Delete Cloud InstanceT1612Build Image on HostT1505.002Transport AgentT1059Command and Scripting InterpreterT1653Power SettingsT1666Modify Cloud Resource HierarchyT1574.007Path Interception by PATH Environment VariableT1036.010Masquerade Account NameT1114.003Email Forwarding RuleT1649Steal or Forge Authentication CertificatesT1114Email CollectionT1606Forge Web CredentialsT1552.001Credentials In FilesT1548.006TCC ManipulationT1530Data from Cloud StorageT1543.004Launch DaemonT1593Search Open Websites/DomainsT1213Data from Information RepositoriesT1552.004Private KeysT1542.005TFTP BootT1556Modify Authentication ProcessT1558Steal or Forge Kerberos TicketsT1686.003Windows Host FirewallT1525Implant Internal ImageT1213.006DatabasesT1505.006vSphere Installation BundlesT1593.003Code Repositories

▪Reference

M1047on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.