ABOUT
Overview
Use Cases
Mapping Methodology
Scoring Rubric
Related Projects
ATT&CK OBJECTS
Matrix
Tactics
Techniques
MAPPING FRAMEWORKS
About Mappings
Amazon Web Services (AWS)
Azure
CSA Cloud Controls Matrix (CCM)
CRI Profile
Known Exploited Vulnerabilities
Google Cloud Platform (GCP)
Intel vPro
NIST 800-53
M365
VERIS
You're currently viewing ATT&CK Version 9.0 Enterprise and VERIS 1.3.5.
Change versions here.
Home
Mapping Frameworks
VERIS Home
Backdoor (enable remote access). Child of 'RAT' when combined with 'Trojan'
VERIS
action.malware.variety.Backdoor
Mappings
ATT&CK Version
9.0
ATT&CK Domain
Enterprise
VERIS
1.3.5
Change Versions
Capability ID
Capability Description
Mapping Type
ATT&CK ID
ATT&CK Name
action.malware.variety.Backdoor
Backdoor (enable remote access). Child of 'RAT' when combined with 'Trojan'
related-to
T1505.001
Server Software Component: SQL Stored Procedures
action.malware.variety.Backdoor
Backdoor (enable remote access). Child of 'RAT' when combined with 'Trojan'
related-to
T1505.002
Server Software Component: Transport Agent
action.malware.variety.Backdoor
Backdoor (enable remote access). Child of 'RAT' when combined with 'Trojan'
related-to
T1543
Create or Modify System Process
action.malware.variety.Backdoor
Backdoor (enable remote access). Child of 'RAT' when combined with 'Trojan'
related-to
T1547
Boot or Logon Autostart Execution
action.malware.variety.Backdoor
Backdoor (enable remote access). Child of 'RAT' when combined with 'Trojan'
related-to
T1133
External Remote Services
action.malware.variety.Backdoor
Backdoor (enable remote access). Child of 'RAT' when combined with 'Trojan'
related-to
T1505
Server Software Component
action.malware.variety.Backdoor
Backdoor (enable remote access). Child of 'RAT' when combined with 'Trojan'
related-to
T1505.003
Server Software Component: Web Shell
action.malware.variety.Backdoor
Backdoor (enable remote access). Child of 'RAT' when combined with 'Trojan'
related-to
T1525
Implant Container Image
action.malware.variety.Backdoor
Backdoor (enable remote access). Child of 'RAT' when combined with 'Trojan'
related-to
T1546
Event Triggered Execution
action.malware.variety.Backdoor
Backdoor (enable remote access). Child of 'RAT' when combined with 'Trojan'
related-to
T1574
Hijack Execution Flow
action.malware.variety.Backdoor
Backdoor (enable remote access). Child of 'RAT' when combined with 'Trojan'
related-to
T1037
Boot or Logon Initialization Script
action.malware.variety.Backdoor
Backdoor (enable remote access). Child of 'RAT' when combined with 'Trojan'
related-to
T1098
Account Manipulation
action.malware.variety.Backdoor
Backdoor (enable remote access). Child of 'RAT' when combined with 'Trojan'
related-to
T1554
Compromise Client Software Binary
action.malware.variety.Backdoor
Backdoor (enable remote access). Child of 'RAT' when combined with 'Trojan'
related-to
T1205.001
Traffic Signaling: Port Knocking