Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Persistence/ T1554

T1554Compromise Host Software Binary

T1554 — Compromise Host Software Binary is a MITRE ATT&CK technique in the Persistence tactic. Clankerusecase tracks 19 detection use cases covering it and 13 threat-intel articles citing it.

Persistence
View on the matrix → Filter Detection Library MITRE official spec ↗
19Use cases
13Articles
0Sub-techniques
1Tactic

Use cases covering this technique (19)

Kubernetes admission webhook configuration modified Internal install · alerting DD Circle CI Disable Security Job ESCU actions · hunting P Circle CI Disable Security Step ESCU actions · hunting P GitHub Workflow File Creation or Modification ESCU actions · hunting P Shai-Hulud Workflow File Creation or Modification ESCU actions · alerting P [LLM] Node.js modifying developer-tool modules for RAT self-reload persistence Bespoke install · alerting DSΣPDDCS [LLM] Pheditor source tampering: modification of pheditor.php (hash rewrite / backdoor persistence) Bespoke install · alerting DSΣPDDCS [LLM] Miasma infectHost persistence in AI coding assistant configs Bespoke install · hunting DSΣPDDCS [LLM] Megalodon backdoor workflow file (SysDiag.yml / Optimize-Build.yml) written to .github/workflows/ Bespoke install · alerting DSΣPDDCS [LLM] Mini Shai-Hulud persistence hooks written into .vscode/ and .claude/ configs Bespoke install · hunting DSΣPDDCS [LLM] Shai-Hulud AI coding-agent persistence: .claude/settings.json + .vscode/tasks.json drops Bespoke install · alerting DSPDD [LLM] Mini Shai-Hulud post-compromise persistence artifacts in .claude/, .vscode/, .github/workflows/ Bespoke actions · alerting DSΣPDD [LLM] GitHub Actions workflow file referencing compromised xygeni/xygeni-action@v5 or backdoored commit 4bf1d4e Bespoke delivery · alerting DSΣPDDCS [LLM] tj-actions/changed-files compromise: malicious commit SHA 0e58ed86... referenced on host (CVE-2025-30066) Bespoke install · hunting DSPDD [LLM] Vulnerable xz / liblzma 5.6.0 or 5.6.1 in software inventory (CVE-2024-3094) Bespoke delivery · alerting DSP [LLM] sshd loads compromised liblzma.so.5.6.0 / 5.6.1 (CVE-2024-3094 runtime trigger) Bespoke install · alerting DSΣPDDCS [LLM] Discord client tampering via index.js overwrite in discord_desktop_core (Discord Injector) Bespoke install · alerting DSΣPDDCS [LLM] Node.js web process overwriting application .js service file (GraphQL path-traversal file write) Bespoke exploit · hunting DSΣPCS [LLM] Build-time injection into vendored @zxing ReedSolomonDecoder.js (Copay wallet stealer payload) Bespoke install · alerting DSΣPDDCS

Articles citing this technique (13)