1200KM / simulation
T1546.008 Accessibility Features — Attack Simulation
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by accessibility features. Windows contains accessibility features that may be launched with a key combination before a user has logged in (ex: when the user is on the Windows logon screen). An adversary can modify the way these programs are launched to get a command prompt or backdoor without logging in to the system. Two common…
Technique description
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by accessibility features. Windows contains accessibility features that may be launched with a key combination before a user has logged in (ex: when the user is on the Windows logon screen). An adversary can modify the way these programs are launched to get a command prompt or backdoor without logging in to the system. Two common…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Replace utilman.exe (Ease of Access Binary) with cmd.exe
Procedure 1db380da-3422-481d-a3c8-6d5770dba580; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Replace Narrator.exe (Narrator binary) with cmd.exe
Procedure 2002f5ea-cd13-4c82-bf73-e46722e5dc5e; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Replace AtBroker.exe (App Switcher binary) with cmd.exe
Procedure 210be7ea-d841-40ec-b3e1-ff610bb62744; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Attaches Command Prompt as a Debugger to a List of Target Processes
Procedure 3309f53e-b22b-4eb6-8fd2-a6cf58b355a9; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Atbroker.exe (AT) Executes Arbitrary Command via Registry Key
Procedure 444ff124-4c83-4e28-8df6-6efd3ece6bd4; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Create Symbolic Link From osk.exe to cmd.exe
Procedure 51ef369c-5e87-4f33-88cd-6d61be63edf2; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Replace Magnify.exe (Magnifier binary) with cmd.exe
Procedure 5e4fa70d-c789-470e-85e1-6992b92bb321; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Auto-start application on user logon
Procedure 7125eba8-7b30-426b-9147-781d152be6fb; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Replace DisplaySwitch.exe (Display Switcher binary) with cmd.exe
Procedure 825ba8ca-71cc-436b-b1dd-ea0d5e109086; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Replace binary of sticky keys
Procedure 934e90cf-29ca-48b3-863c-411737ad44e3; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.