Skip to main content

Trigger Malicious Code

CCC.Monitor.TH07

If a malicious actor is able to create new triggers, they would be able to use valid metric data to trigger malicious actions and re-compromise a newly replaced container or compute instance.

Related Capabilities

IDTitleDescription
CCC.Monitor.CP01Metric collectionGathering numerical (quantitative) data points about the performance, health, or behaviour of systems, applications or infrastructure.
CCC.Monitor.CP10TriggeringAutomatically initiating actions like alerts, notifications or automated workflows based on pre-defined conditions being met.
CCC.Monitor.CP11Integration with Third-Party ToolsMonitoring tools are able to integrate with a number of downstream systems in order to send notifications and alerts, raise tickets and create incident reports.

External Mappings

FrameworkIDRelationshipRemarks
MITRE-ATT&CKT1546relates-toEvent Triggered Execution