Esc
Restore Configuration
Artifact Relationships:
This defensive technique is related to specific artifacts. Click the artifact node for more information.
Related Offensive Techniques:
These mappings are inferred, experimental, and will improve as the
knowledge graph grows.
These offensive techniques are determined related because of the way this defensive technique,, .
Discovery
Cloud Service Discovery
Cloud Service Dashboard
Group Policy Discovery
Software Discovery
System Location Discovery
Stealth
Impair Defenses
Hijack Execution Flow
Access Token Manipulation
Hide Artifacts
System Binary Proxy Execution
Persistence
Boot or Logon Autostart Execution
Modify Authentication Process
Boot or Logon Initialization Scripts
Office Application Startup
Event Triggered Execution
Privilege Escalation
Boot or Logon Autostart Execution
Abuse Elevation Control Mechanism
Access Token Manipulation
Domain or Tenant Policy Modification
Boot or Logon Initialization Scripts
Event Triggered Execution
Credential Access
Modify Authentication Process
Unsecured Credentials
Defense Impairment
Modify Authentication Process
File and Directory Permissions Modification
Modify Cloud Compute Infrastructure
Modify Cloud Resource Hierarchy
Domain or Tenant Policy Modification
Subvert Trust Controls
Impact
Inhibit System Recovery
References
All
Guideline
The following references were used to develop the Restore Configuration knowledge-base article.
(Note: the consideration of references does not imply specific functionality exists in an offering.)
Cybersecurity Incident & Vulnerability Response Playbooks
Reference Type: Guideline Organization: Cybersecurity and Infrastructure Security Agency Author: Cybersecurity and Infrastructure Security Agency