Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1106
MITRE ATT&CK Technique

T1106: Native API

ShareXLinkedInRedditHN

Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes.(Citation: NT API Windows)(Citation: Linux Kernel API) These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations. Adversaries may abuse these OS API functions as a means of executing behaviors. Similar to [Command and Scripting Interpreter](https://attack.mitre.org/techniques/T1059), the native API and its hierarchy of interfaces provide mechanisms to interact with and utilize various components of a victimized system. Native API functions (such as <code>NtCreateProcess</code>) may be directed invoked via system calls / syscalls, but these features are also often exposed to user-mode applications via interfaces and libraries.(Citation: OutFlank System Calls)(Citation: CyberBit System Calls)(Citation: MDSec System Calls) For example, functions such as the Windows API <code>CreateProcess()</code> or GNU <code>fork()</code> will allow programs and scripts to start other processes.(Citation: Microsoft CreateProcess)(Citation: GNU Fork) This may allow API callers to execute a binary, run a CLI command, load modules, etc. as thousands of similar API functions exist for various system operations.(Citation: Microsoft Win32)(Citation: LIBC)(Citation: GLIBC) Higher level software frameworks, such as Microsoft .NET and macOS Cocoa, are also available to interact with native APIs. These frameworks typically provide language wrappers/abstractions to API functionalities and are designed for ease-of-use/portability of code.(Citation: Microsoft NET)(Citation: Apple Core Services)(Citation: MACOS Cocoa)(Citation: macOS Foundation) Adversaries may use assembly to directly or in-directly invoke syscalls in an attempt to subvert defensive sensors and detection signatures such as user mode API-hooks.(Citation: Redops Syscalls) Adversaries may also attempt to tamper with sensors and defensive tools associated with API monitoring, such as unhooking monitored functions via [Disable or Modify Tools](https://attack.mitre.org/techniques/T1685).

Tactics
Execution
Platforms
Linux, macOS, Windows

▪Mitigations (2)

M1038Execution Prevention

Prevent the execution of unauthorized or malicious code on systems by implementing application control, script blocking, and other execution prevention mechanisms. This ensures that only trusted and authorized code is executed, reducing the risk of malware and unauthorized actions. This mitigation can be implemented through the following measures: Application Control: - Use Case: Use tools like AppLocker or Windows Defender Application Control (WDAC) to create whitelists of authorized applications and block unauthorized ones. On Linux, use tools like SELinux or AppArmor to define mandatory access control policies for application execution. - Implementation: Allow only digitally signed or pre-approved applications to execute on servers and endpoints. (e.g., `New-AppLockerPolicy -PolicyType Enforced -FilePath "C:\Policies\AppLocker.xml"`) Script Blocking: - Use Case: Use script control mechanisms to block unauthorized execution of scripts, such as PowerShell or JavaScript. Web Browsers: Use browser extensions or settings to block JavaScript execution from untrusted sources. - Implementation: Configure PowerShell to enforce Constrained Language Mode for non-administrator users. (e.g., `Set-ExecutionPolicy AllSigned`) Executable Blocking: - Use Case: Prevent execution of binaries from suspicious locations, such as `%TEMP%` or `%APPDATA%` directories. - Implementation: Block execution of `.exe`, `.bat`, or `.ps1` files from user-writable directories. Dynamic Analysis Prevention: - Use Case: Use behavior-based execution prevention tools to identify and block malicious activity in real time. - Implemenation: Employ EDR solutions that analyze runtime behavior and block suspicious code execution.

▪Used by groups (20)

G0010TurlaG0032Lazarus GroupG0034Sandworm Team

▪Software using this technique (203)

S0011TaidoormalwareS0013PlugXmalware

▪Reference

T1106on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.

M1040
Behavior Prevention on Endpoint

Behavior Prevention on Endpoint refers to the use of technologies and strategies to detect and block potentially malicious activities by analyzing the behavior of processes, files, API calls, and other endpoint events. Rather than relying solely on known signatures, this approach leverages heuristics, machine learning, and real-time monitoring to identify anomalous patterns indicative of an attack. This mitigation can be implemented through the following measures: Suspicious Process Behavior: - Implementation: Use Endpoint Detection and Response (EDR) tools to monitor and block processes exhibiting unusual behavior, such as privilege escalation attempts. - Use Case: An attacker uses a known vulnerability to spawn a privileged process from a user-level application. The endpoint tool detects the abnormal parent-child process relationship and blocks the action. Unauthorized File Access: - Implementation: Leverage Data Loss Prevention (DLP) or endpoint tools to block processes attempting to access sensitive files without proper authorization. - Use Case: A process tries to read or modify a sensitive file located in a restricted directory, such as /etc/shadow on Linux or the SAM registry hive on Windows. The endpoint tool identifies this anomalous behavior and prevents it. Abnormal API Calls: - Implementation: Implement runtime analysis tools to monitor API calls and block those associated with malicious activities. - Use Case: A process dynamically injects itself into another process to hijack its execution. The endpoint detects the abnormal use of APIs like `OpenProcess` and `WriteProcessMemory` and terminates the offending process. Exploit Prevention: - Implementation: Use behavioral exploit prevention tools to detect and block exploits attempting to gain unauthorized access. - Use Case: A buffer overflow exploit is launched against a vulnerable application. The endpoint detects the anomalous memory write operation and halts the process.

G0045menuPass
G0047Gamaredon Group
G0067APT37
G0078Gorgon Group
G0081Tropic Trooper
G0082APT38
G0090WIRTE
G0091Silence
G0092TA505
G0094Kimsuky
G0098BlackTech
G0114Chimera
G0126Higaisa
G0129Mustang Panda
G1008SideCopy
G1022ToddyCat
G1051Medusa Group
S0022Uroburosmalware
S0032gh0st RATmalware
S0045ADVSTORESHELLmalware
S0083Misdatmalware
S0084Mis-Typemalware
S0085S-Typemalware
S0126ComRATmalware
S0128BADNEWSmalware
S0141Winnti for Windowsmalware
S0147Pteranodonmalware
S0148RTMmalware
S0154Cobalt Strikemalware
S0161XAgentOSXmalware
S0180Volgmermalware
S0198NETWIREmalware
S0234Bandookmalware
S0239Bankshotmalware
S0240ROKRATmalware
S0242SynAckmalware
S0256Mosquitomalware
S0259InnaputRATmalware
S0260InvisiMolemalware
S0266TrickBotmalware
S0268Bisonalmalware
S0354Denismalware
S0356KONNImalware
S0363Empiretool
S0367Emotetmalware
S0384Dridexmalware
S0385njRATmalware
S0386Ursnifmalware
S0391HAWKBALLmalware
S0395LightNeuronmalware
S0396EvilBunnymalware
S0398HyperBromalware
S0412ZxShellmalware
S0416RDFSNIFFERmalware
S0431HotCroissantmalware
S0434Imminent Monitortool
S0435PLEADmalware
S0438Attormalware
S0444ShimRatmalware
S0445ShimRatReportertool
S0446Ryukmalware
S0447Lokibotmalware
S0448Rising Sunmalware
S0449Mazemalware
S0453Ponymalware
S0455Metamorfomalware
S0456Aria-bodymalware
S0457Netwalkermalware
S0458Ramsaymalware
S0466WindTailmalware
S0470BBKmalware
S0471build_downermalware
S0475BackConfigmalware
S0477Goopymalware
S0483IcedIDmalware
S0484Carberpmalware
S0493GoldenSpymalware
S0496REvilmalware
S0499Hancitormalware
S0501PipeMonmalware
S0512FatDukemalware
S0517Pillowmintmalware
S0518PolyglotDukemalware
S0521BloodHoundtool
S0531Grandoreiromalware
S0534Bazarmalware
S0537HyperStackmalware
S0554Egregormalware
S0561GuLoadermalware
S0562SUNSPOTmalware
S0569Explosivemalware
S0570BitPaymermalware
S0574BendyBearmalware
S0575Contimalware
S0576MegaCortexmalware
S0579Waterbearmalware
S0595ThiefQuestmalware
S0603Stuxnetmalware
S0606Bad Rabbitmalware
S0607KillDiskmalware
S0610SideTwistmalware
S0611Clopmalware
S0612WastedLockermalware
S0614CostaBricksmalware
S0615SombRATmalware
S0622AppleSeedmalware
S0623Siloscapemalware
S0625Cubamalware
S0627SodaMastermalware
S0629RainyDaymalware
S0630Nebulaemalware
S0631Chaesmalware
S0632GrimAgentmalware
S0638Babukmalware
S0640Avaddonmalware
S0650QakBotmalware
S0651BoxCaonmalware
S0652MarkiRATmalware
S0653xCaonmalware
S0659Diavolmalware
S0661FoggyWebmalware
S0662RCSessionmalware
S0663SysUpdatemalware
S0666Gelsemiummalware
S0667Chrommmemalware
S0668TinyTurlamalware
S0669KOCTOPUSmalware
S0670WarzoneRATmalware
S0678Torismamalware
S0680LitePowermalware
S0681Lizarmalware
S0687Cyclops Blinkmalware
S0688Meteormalware
S0689WhisperGatemalware
S0692SILENTTRINITYtool
S0693CaddyWipermalware
S0694DRATzarusmalware
S0695Donuttool
S0696Flagpromalware
S0697HermeticWipermalware
S0698HermeticWizardmalware
S1013ZxxZmalware
S1015Milanmalware
S1016MacMamalware
S1018Saint Botmalware
S1020Kevinmalware
S1025Amadeymalware
S1033DCSrvmalware
S1034StrifeWatermalware
S1039Bumblebeemalware
S1044FunnyDreammalware
S1050PcSharetool
S1052DEADEYEmalware
S1053AvosLockermalware
S1058Prestigemalware
S1059metaMainmalware
S1060Mafaldamalware
S1063Brute Ratel C4tool
S1064SVCReadymalware
S1065Woody RATmalware
S1066DarkTortillamalware
S1070Black Bastamalware
S1073Royalmalware
S1076QUIETCANARYmalware
S1078RotaJakiromalware
S1081BADHATCHmalware
S1085Sardonicmalware
S1087AsyncRATtool
S1089SharpDiscomalware
S1090NightClubmalware
S1099Samuraimalware
S1100Ninjamalware
S1111DarkGatemalware
S1122Mispadumalware
S1129Akiramalware
S1139INC Ransomwaremalware
S1145Pikabotmalware
S1149CHIMNEYSWEEPmalware
S1151ZeroClearemalware
S1152IMAPLoadermalware
S1160Latrodectusmalware
S1169Mangomalware
S1170ODAgentmalware
S1172OilBoostermalware
S1179Exbytemalware
S1180BlackByte Ransomwaremalware
S1190Kapekamalware
S1200StealBitmalware
S1202LockBit 3.0malware
S1207XLoadermalware
S1210Sagerunexmalware
S1226BOOKWORMmalware
S1227StarProxymalware
S1228PUBLOADmalware
S1229Havocmalware
S1232SplatDroppermalware
S1233PAKLOGmalware
S1234SplatCloakmalware
S1236CLAIMLOADERmalware
S1237CANONSTAGERmalware
S1239TONESHELLmalware
S1242Qilinmalware
S1244Medusa Ransomwaremalware
S1247Embargomalware
S9001SystemBCmalware
S9007HTTPTroymalware
S9012TRAILBLAZEmalware
S9016Caminhomalware
S9018HeartCryptmalware
S9020LODEINFOmalware
S9021DOWNIISSAmalware
S9025NOOPLDRmalware
S9027ANELLDRmalware
S9032MuddyVipermalware
S9033Foodermalware
S9036LP-Notesmalware
S9037RustyWatermalware
S9038DynoWipermalware