M1013Application Developer Guidance
Reducing application-layer vulnerabilities at the source through secure development practices.
Loading…
Establishing persistence
Techniques in this tactic (6)
Reducing application-layer vulnerabilities at the source through secure development practices.
Advanced audit policy + command-line auditing + Sysmon + directory access auditing: the telemetry that detection requires.
Block common attack behaviors using Defender ASR rules and Office macro restrictions.
Allowlisting that permits only approved applications/scripts to run; blocks unknown code execution by default.
Multi-factor authentication that stops the vast majority of password-based attacks; enforced in Entra via Conditional Access.
Keep the number and use of privileged accounts to a minimum: Domain Admins hygiene, LAPS, JIT/PIM.
Closing the exploitation surface by timely patching of known vulnerabilities; eliminates one of the most common origins of breaches.
Account lifecycle management: proper creation, assignment with least privilege, timely disabling, and periodic access reviews.
Blocking LOLBin/malware attacks by allowing only approved code, libraries, and scripts to execute.