Activity timeline
T1505 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 118 reports, and 264 of the 265 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1505 Server Software Component is catalogued by MITRE ATT&CK under the Persistence tactic in the Enterprise matrix. Threadlinqs maps 265 of 2623 tracked threats (10.1%) to it; by severity that is 163 critical, 86 high, 13 medium, 1 low.
Threats that use T1505 most often also use T1190 Exploit Public-Facing Application (221 threats), T1059 Command and Scripting Interpreter (210 threats), T1005 Data from Local System (165 threats), T1071 Application Layer Protocol (163 threats), T1082 System Information Discovery (145 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
77 tracked threat actors appear in the threats that use T1505; the most frequent are Storm-2603 (7), UNC5221 (5), Cl0p (4), MuddyWater (4), UTA0178 (4).
Mitigations
MITRE ATT&CK lists 7 mitigations for T1505.
Data sources
Telemetry that can reveal T1505, per MITRE ATT&CK.
- Application Log — Application Log Content
- Command — Command Execution
- File — File Creation, File Modification
- Network Traffic — Network Traffic Content, Network Traffic Flow
- Process — Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 265 tracked threats that use T1505.
- Fortinet FortiMail critical path traversal flaw CVE-2026-104286 (FG-IR-26-175) exploited in zero-day attackscritical
- CISA Adds Actively Exploited WSO2 API Manager and Adobe Commerce Flaws to KEV Catalog, Warns on SharePoint…critical
- Check Point Patches Actively Exploited Zero-Day Path Traversal in Management Server (CVE-2026-93616)critical
- BigCommerce Merchant Storefronts Compromised via Stolen Ribon App Credentials, Malicious Script Injectionmedium
- Brevo Supply-Chain Attack: Stolen Cloudflare API Key Deploys Malicious Edge Worker, Backdoors 100,000+…critical
- Dell ObjectScale Critical Deserialization Flaw (CVE-2026-70416, CVSS 10.0) Enables Unauthenticated RCEcritical
- Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880…critical
- September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days…critical
- Ivanti September 2026 Patch Batch: 10 CVEs Across EPMM, Neurons for ITSM, and Sentry (CVE-2026-12744/12745…critical
- Telerik UI for ASP.NET AJAX — Padding Oracle Chained to Unauthenticated Deserialization RCE…high
- Chinese-Speaking Operator "Nie" Uses SecFlow AI Orchestration Framework (Claude, Qwen, DeepSeek) and GLUTTON…high
- Hundreds of WordPress Sites Hijacked via Malicious Plugins to Deploy Amatera Stealer through EtherHiding and…high
- SDLC Supply Chain Attacks: ChainDrop npm Worm and Developer Pipeline Targetinghigh
- CISA KEV: Active Exploitation of TrueConf Server Vulnerabilities (CVE-2026-72529, CVE-2026-72530) by Head…critical
- Hackers Target Zimbra Servers in Active Exploitation Campaign via CVE-2026-73570 SNMP Command Injectioncritical
- CVE-2026-19490 — Critical Authentication Bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) with…critical
- Critical Elementor Pro unauthenticated file upload vulnerability leads to RCE on WordPress sites…critical
- BdThemes WordPress Plugin Supply-Chain Attack Poisons API to Create Rogue Adminsmedium
- Greatness PhaaS — AiTM phishing platform targeting Microsoft 365 and multi-platform credentials via spoofed…high
- Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Importscritical
- August 2026 Patch Roundup: 11 Critical/High CVEs in Veeam VSPC (CVE-2026-58073, CVSS 9.5), HashiCorp…critical
- AI-Enhanced Phishing and Adversary-in-the-Middle (AiTM) Phishing-as-a-Service Ecosystem — 2025-2026 Threat…high
- CVE-2026-58048 — cPanel & WHM Database Privilege Escalation via Database Rename (SQL Mode Loss)critical
- CVE-2026-16812 — Critical Unauthenticated OS Command Injection in Arista VeloCloud Orchestrator Actively…critical
- Adobe Campaign Classic Critical Incorrect Authorization Flaw Enables Unauthenticated Remote Code Execution…critical
- Multiple Vulnerabilities in PHP (GovCERT.HK A26-07-52): Phar Symlink DoS, Bundled-libgd GIF Memory…high
- CVE-2026-59726 (RufRoot): Unauthenticated RCE in Ruflo MCP Bridge Poisons AI Agent Memorycritical
- CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEVcritical
- CVE-2026-66066 "KindaRails2Shell": Critical Ruby on Rails Active Storage Flaw Allows Unauthenticated…critical
- Fastjson2 AutoType Whitelist Bypass Leads to Unauthenticated Remote Code Execution (Fastjson2 <= 2.0.62)critical
Detection coverage
Threadlinqs maintains 125 detection rules mapped to T1505 (SPL 36, KQL 39, Sigma 50). Rule content is available to Blue tier accounts and above; this page shows counts only.
Sub-techniques
- T1505.001 SQL Stored Procedures — 2 tracked threats
- T1505.002 Transport Agent — 3 tracked threats
- T1505.003 Web Shell — 170 tracked threats
- T1505.004 IIS Components — 4 tracked threats
- T1505.005 Terminal Services DLL — 2 tracked threats
- T1505.006 vSphere Installation Bundles — 0 tracked threats