MITRE ATT&CK Techniques
709 techniques (enterprise-attack).
- T1001: Data Obfuscation (command-and-control)
- T1001.001: Junk Data (command-and-control)
- T1001.002: Steganography (command-and-control)
- T1001.003: Protocol or Service Impersonation (command-and-control)
- T1003: OS Credential Dumping (credential-access)
- T1003.001: LSASS Memory (credential-access)
- T1003.002: Security Account Manager (credential-access)
- T1003.003: NTDS (credential-access)
- T1003.004: LSA Secrets (credential-access)
- T1003.005: Cached Domain Credentials (credential-access)
- T1003.006: DCSync (credential-access)
- T1003.007: Proc Filesystem (credential-access)
- T1003.008: /etc/passwd and /etc/shadow (credential-access)
- T1005: Data from Local System (collection)
- T1006: Direct Volume Access (stealth)
- T1007: System Service Discovery (discovery)
- T1008: Fallback Channels (command-and-control)
- T1010: Application Window Discovery (discovery)
- T1011: Exfiltration Over Other Network Medium (exfiltration)
- T1011.001: Exfiltration Over Bluetooth (exfiltration)
- T1012: Query Registry (discovery)
- T1014: Rootkit (stealth)
- T1016: System Network Configuration Discovery (discovery)
- T1016.001: Internet Connection Discovery (discovery)
- T1016.002: Wi-Fi Discovery (discovery)
- T1018: Remote System Discovery (discovery)
- T1020: Automated Exfiltration (exfiltration)
- T1020.001: Traffic Duplication (exfiltration)
- T1021: Remote Services (lateral-movement)
- T1021.001: Remote Desktop Protocol (lateral-movement)
- T1021.002: SMB/Windows Admin Shares (lateral-movement)
- T1021.003: Distributed Component Object Model (lateral-movement)
- T1021.004: SSH (lateral-movement)
- T1021.005: VNC (lateral-movement)
- T1021.006: Windows Remote Management (lateral-movement)
- T1021.007: Cloud Services (lateral-movement)
- T1021.008: Direct Cloud VM Connections (lateral-movement)
- T1025: Data from Removable Media (collection)
- T1026: Multiband Communication (command-and-control)
- T1027: Obfuscated Files or Information (stealth)
- T1027.001: Binary Padding (stealth)
- T1027.002: Software Packing (stealth)
- T1027.003: Steganography (stealth)
- T1027.004: Compile After Delivery (stealth)
- T1027.005: Indicator Removal from Tools (stealth)
- T1027.006: HTML Smuggling (stealth)
- T1027.007: Dynamic API Resolution (stealth)
- T1027.008: Stripped Payloads (stealth)
- T1027.009: Embedded Payloads (stealth)
- T1027.010: Command Obfuscation (stealth)
- T1027.011: Fileless Storage (stealth)
- T1027.012: LNK Icon Smuggling (stealth)
- T1027.013: Encrypted/Encoded File (stealth)
- T1027.014: Polymorphic Code (stealth)
- T1027.015: Compression (stealth)
- T1027.016: Junk Code Insertion (stealth)
- T1027.017: SVG Smuggling (stealth)
- T1027.018: Invisible Unicode (stealth)
- T1029: Scheduled Transfer (exfiltration)
- T1030: Data Transfer Size Limits (exfiltration)
- T1033: System Owner/User Discovery (discovery)
- T1034: Path Interception (persistence)
- T1036: Masquerading (stealth)
- T1036.001: Invalid Code Signature (stealth)
- T1036.002: Right-to-Left Override (stealth)
- T1036.003: Rename Legitimate Utilities (stealth)
- T1036.004: Masquerade Task or Service (stealth)
- T1036.005: Match Legitimate Resource Name or Location (stealth)
- T1036.006: Space after Filename (stealth)
- T1036.007: Double File Extension (stealth)
- T1036.008: Masquerade File Type (stealth)
- T1036.009: Break Process Trees (stealth)
- T1036.010: Masquerade Account Name (stealth)
- T1036.011: Overwrite Process Arguments (stealth)
- T1036.012: Browser Fingerprint (stealth)
- T1037: Boot or Logon Initialization Scripts (persistence)
- T1037.001: Logon Script (Windows) (persistence)
- T1037.002: Login Hook (persistence)
- T1037.003: Network Logon Script (persistence)
- T1037.004: RC Scripts (persistence)
- T1037.005: Startup Items (persistence)
- T1039: Data from Network Shared Drive (collection)
- T1040: Network Sniffing (credential-access)
- T1041: Exfiltration Over C2 Channel (exfiltration)
- T1043: Commonly Used Port (command-and-control)
- T1046: Network Service Discovery (discovery)
- T1047: Windows Management Instrumentation (execution)
- T1048: Exfiltration Over Alternative Protocol (exfiltration)
- T1048.001: Exfiltration Over Symmetric Encrypted Non-C2 Protocol (exfiltration)
- T1048.002: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol (exfiltration)
- T1048.003: Exfiltration Over Unencrypted Non-C2 Protocol (exfiltration)
- T1049: System Network Connections Discovery (discovery)
- T1051: Shared Webroot (lateral-movement)
- T1052: Exfiltration Over Physical Medium (exfiltration)
- T1052.001: Exfiltration over USB (exfiltration)
- T1053: Scheduled Task/Job (execution)
- T1053.002: At (execution)
- T1053.003: Cron (execution)
- T1053.004: Launchd (execution)
- T1053.005: Scheduled Task (execution)
- T1053.006: Systemd Timers (execution)
- T1053.007: Container Orchestration Job (execution)
- T1055: Process Injection (stealth)
- T1055.001: Dynamic-link Library Injection (stealth)
- T1055.002: Portable Executable Injection (stealth)
- T1055.003: Thread Execution Hijacking (stealth)
- T1055.004: Asynchronous Procedure Call (stealth)
- T1055.005: Thread Local Storage (stealth)
- T1055.008: Ptrace System Calls (stealth)
- T1055.009: Proc Memory (stealth)
- T1055.011: Extra Window Memory Injection (stealth)
- T1055.012: Process Hollowing (stealth)
- T1055.013: Process Doppelgänging (stealth)
- T1055.014: VDSO Hijacking (stealth)
- T1055.015: ListPlanting (stealth)
- T1056: Input Capture (collection)
- T1056.001: Keylogging (collection)
- T1056.002: GUI Input Capture (collection)
- T1056.003: Web Portal Capture (collection)
- T1056.004: Credential API Hooking (collection)
- T1057: Process Discovery (discovery)
- T1059: Command and Scripting Interpreter (execution)
- T1059.001: PowerShell (execution)
- T1059.002: AppleScript (execution)
- T1059.003: Windows Command Shell (execution)
- T1059.004: Unix Shell (execution)
- T1059.005: Visual Basic (execution)
- T1059.006: Python (execution)
- T1059.007: JavaScript (execution)
- T1059.008: Network Device CLI (execution)
- T1059.009: Cloud API (execution)
- T1059.010: AutoHotKey & AutoIT (execution)
- T1059.011: Lua (execution)
- T1059.012: Hypervisor CLI (execution)
- T1059.013: Container CLI/API (execution)
- T1061: Graphical User Interface (execution)
- T1062: Hypervisor (persistence)
- T1064: Scripting (stealth)
- T1068: Exploitation for Privilege Escalation (privilege-escalation)
- T1069: Permission Groups Discovery (discovery)
- T1069.001: Local Groups (discovery)
- T1069.002: Domain Groups (discovery)
- T1069.003: Cloud Groups (discovery)
- T1070: Indicator Removal (stealth)
- T1070.003: Clear Command History (stealth)
- T1070.004: File Deletion (stealth)
- T1070.005: Network Share Connection Removal (stealth)
- T1070.006: Timestomp (stealth)
- T1070.007: Clear Network Connection History and Configurations (stealth)
- T1070.008: Clear Mailbox Data (stealth)
- T1070.009: Clear Persistence (stealth)
- T1070.010: Relocate Malware (stealth)
- T1071: Application Layer Protocol (command-and-control)
- T1071.001: Web Protocols (command-and-control)
- T1071.002: File Transfer Protocols (command-and-control)
- T1071.003: Mail Protocols (command-and-control)
- T1071.004: DNS (command-and-control)
- T1071.005: Publish/Subscribe Protocols (command-and-control)
- T1072: Software Deployment Tools (execution)
- T1074: Data Staged (collection)
- T1074.001: Local Data Staging (collection)
- T1074.002: Remote Data Staging (collection)
- T1078: Valid Accounts (stealth)
- T1078.001: Default Accounts (stealth)
- T1078.002: Domain Accounts (stealth)
- T1078.003: Local Accounts (stealth)
- T1078.004: Cloud Accounts (stealth)
- T1080: Taint Shared Content (lateral-movement)
- T1082: System Information Discovery (discovery)
- T1083: File and Directory Discovery (discovery)
- T1087: Account Discovery (discovery)
- T1087.001: Local Account (discovery)
- T1087.002: Domain Account (discovery)
- T1087.003: Email Account (discovery)
- T1087.004: Cloud Account (discovery)
- T1090: Proxy (command-and-control)
- T1090.001: Internal Proxy (command-and-control)
- T1090.002: External Proxy (command-and-control)
- T1090.003: Multi-hop Proxy (command-and-control)
- T1090.004: Domain Fronting (command-and-control)
- T1091: Replication Through Removable Media (lateral-movement)
- T1092: Communication Through Removable Media (command-and-control)
- T1095: Non-Application Layer Protocol (command-and-control)
- T1098: Account Manipulation (persistence)
- T1098.001: Additional Cloud Credentials (persistence)
- T1098.002: Additional Email Delegate Permissions (persistence)
- T1098.003: Additional Cloud Roles (persistence)
- T1098.004: SSH Authorized Keys (persistence)
- T1098.005: Device Registration (persistence)
- T1098.006: Additional Container Cluster Roles (persistence)
- T1098.007: Additional Local or Domain Groups (persistence)
- T1102: Web Service (command-and-control)
- T1102.001: Dead Drop Resolver (command-and-control)
- T1102.002: Bidirectional Communication (command-and-control)
- T1102.003: One-Way Communication (command-and-control)
- T1104: Multi-Stage Channels (command-and-control)
- T1105: Ingress Tool Transfer (command-and-control)
- T1106: Native API (execution)
- T1108: Redundant Access (stealth)
- T1110: Brute Force (credential-access)
- T1110.001: Password Guessing (credential-access)
- T1110.002: Password Cracking (credential-access)
- T1110.003: Password Spraying (credential-access)
- T1110.004: Credential Stuffing (credential-access)
- T1111: Multi-Factor Authentication Interception (credential-access)
- T1112: Modify Registry (defense-impairment)
- T1113: Screen Capture (collection)
- T1114: Email Collection (collection)
- T1114.001: Local Email Collection (collection)
- T1114.002: Remote Email Collection (collection)
- T1114.003: Email Forwarding Rule (collection)
- T1115: Clipboard Data (collection)
- T1119: Automated Collection (collection)
- T1120: Peripheral Device Discovery (discovery)
- T1123: Audio Capture (collection)
- T1124: System Time Discovery (discovery)
- T1125: Video Capture (collection)
- T1127: Trusted Developer Utilities Proxy Execution (stealth)
- T1127.001: MSBuild (stealth)
- T1127.002: ClickOnce (stealth)
- T1127.003: JamPlus (stealth)
- T1129: Shared Modules (execution)
- T1132: Data Encoding (command-and-control)
- T1132.001: Standard Encoding (command-and-control)
- T1132.002: Non-Standard Encoding (command-and-control)
- T1133: External Remote Services (persistence)
- T1134: Access Token Manipulation (stealth)
- T1134.001: Token Impersonation/Theft (stealth)
- T1134.002: Create Process with Token (stealth)
- T1134.003: Make and Impersonate Token (stealth)
- T1134.004: Parent PID Spoofing (stealth)
- T1134.005: SID-History Injection (stealth)
- T1135: Network Share Discovery (discovery)
- T1136: Create Account (persistence)
- T1136.001: Local Account (persistence)
- T1136.002: Domain Account (persistence)
- T1136.003: Cloud Account (persistence)
- T1137: Office Application Startup (persistence)
- T1137.001: Office Template Macros (persistence)
- T1137.002: Office Test (persistence)
- T1137.003: Outlook Forms (persistence)
- T1137.004: Outlook Home Page (persistence)
- T1137.005: Outlook Rules (persistence)
- T1137.006: Add-ins (persistence)
- T1140: Deobfuscate/Decode Files or Information (stealth)
- T1149: LC_MAIN Hijacking (stealth)
- T1153: Source (execution)
- T1175: Component Object Model and Distributed COM (lateral-movement)
- T1176: Software Extensions (persistence)
- T1176.001: Browser Extensions (persistence)
- T1176.002: IDE Extensions (persistence)
- T1185: Browser Session Hijacking (collection)
- T1187: Forced Authentication (credential-access)
- T1189: Drive-by Compromise (initial-access)
- T1190: Exploit Public-Facing Application (initial-access)
- T1195: Supply Chain Compromise (initial-access)
- T1195.001: Compromise Software Dependencies and Development Tools (initial-access)
- T1195.002: Compromise Software Supply Chain (initial-access)
- T1195.003: Compromise Hardware Supply Chain (initial-access)
- T1197: BITS Jobs (stealth)
- T1199: Trusted Relationship (initial-access)
- T1200: Hardware Additions (initial-access)
- T1201: Password Policy Discovery (discovery)
- T1202: Indirect Command Execution (stealth)
- T1203: Exploitation for Client Execution (execution)
- T1204: User Execution (execution)
- T1204.001: Malicious Link (execution)
- T1204.002: Malicious File (execution)
- T1204.003: Malicious Image (execution)
- T1204.004: Malicious Copy and Paste (execution)
- T1204.005: Malicious Library (execution)
- T1205: Traffic Signaling (stealth)
- T1205.001: Port Knocking (stealth)
- T1205.002: Socket Filters (stealth)
- T1207: Rogue Domain Controller (defense-impairment)
- T1210: Exploitation of Remote Services (lateral-movement)
- T1211: Exploitation for Stealth (stealth)
- T1212: Exploitation for Credential Access (credential-access)
- T1213: Data from Information Repositories (collection)
- T1213.001: Confluence (collection)
- T1213.002: Sharepoint (collection)
- T1213.003: Code Repositories (collection)
- T1213.004: Customer Relationship Management Software (collection)
- T1213.005: Messaging Applications (collection)
- T1213.006: Databases (collection)
- T1216: System Script Proxy Execution (stealth)
- T1216.001: PubPrn (stealth)
- T1216.002: SyncAppvPublishingServer (stealth)
- T1217: Browser Information Discovery (discovery)
- T1218: System Binary Proxy Execution (stealth)
- T1218.001: Compiled HTML File (stealth)
- T1218.002: Control Panel (stealth)
- T1218.003: CMSTP (stealth)
- T1218.004: InstallUtil (stealth)
- T1218.005: Mshta (stealth)
- T1218.007: Msiexec (stealth)
- T1218.008: Odbcconf (stealth)
- T1218.009: Regsvcs/Regasm (stealth)
- T1218.010: Regsvr32 (stealth)
- T1218.011: Rundll32 (stealth)
- T1218.012: Verclsid (stealth)
- T1218.013: Mavinject (stealth)
- T1218.014: MMC (stealth)
- T1218.015: Electron Applications (stealth)
- T1219: Remote Access Tools (command-and-control)
- T1219.001: IDE Tunneling (command-and-control)
- T1219.002: Remote Desktop Software (command-and-control)
- T1219.003: Remote Access Hardware (command-and-control)
- T1220: XSL Script Processing (stealth)
- T1221: Template Injection (stealth)
- T1222: File and Directory Permissions Modification (defense-impairment)
- T1222.001: Windows Permissions (defense-impairment)
- T1222.002: Linux and Mac Permissions (defense-impairment)
- T1480: Execution Guardrails (stealth)
- T1480.001: Environmental Keying (stealth)
- T1480.002: Mutual Exclusion (stealth)
- T1482: Domain Trust Discovery (discovery)
- T1484: Domain or Tenant Policy Modification (defense-impairment)
- T1484.001: Group Policy Modification (defense-impairment)
- T1484.002: Trust Modification (defense-impairment)
- T1485: Data Destruction (impact)
- T1485.001: Lifecycle-Triggered Deletion (impact)
- T1486: Data Encrypted for Impact (impact)
- T1489: Service Stop (impact)
- T1490: Inhibit System Recovery (impact)
- T1491: Defacement (impact)
- T1491.001: Internal Defacement (impact)
- T1491.002: External Defacement (impact)
- T1495: Firmware Corruption (impact)
- T1496: Resource Hijacking (impact)
- T1496.001: Compute Hijacking (impact)
- T1496.002: Bandwidth Hijacking (impact)
- T1496.003: SMS Pumping (impact)
- T1496.004: Cloud Service Hijacking (impact)
- T1497: Virtualization/Sandbox Evasion (stealth)
- T1497.001: System Checks (stealth)
- T1497.002: User Activity Based Checks (stealth)
- T1497.003: Time Based Checks (stealth)
- T1498: Network Denial of Service (impact)
- T1498.001: Direct Network Flood (impact)
- T1498.002: Reflection Amplification (impact)
- T1499: Endpoint Denial of Service (impact)
- T1499.001: OS Exhaustion Flood (impact)
- T1499.002: Service Exhaustion Flood (impact)
- T1499.003: Application Exhaustion Flood (impact)
- T1499.004: Application or System Exploitation (impact)
- T1505: Server Software Component (persistence)
- T1505.001: SQL Stored Procedures (persistence)
- T1505.002: Transport Agent (persistence)
- T1505.003: Web Shell (persistence)
- T1505.004: IIS Components (persistence)
- T1505.005: Terminal Services DLL (persistence)
- T1505.006: vSphere Installation Bundles (persistence)
- T1518: Software Discovery (discovery)
- T1518.001: Security Software Discovery (discovery)
- T1518.002: Backup Software Discovery (discovery)
- T1525: Implant Internal Image (persistence)
- T1526: Cloud Service Discovery (discovery)
- T1528: Steal Application Access Token (credential-access)
- T1529: System Shutdown/Reboot (impact)
- T1530: Data from Cloud Storage (collection)
- T1531: Account Access Removal (impact)
- T1534: Internal Spearphishing (lateral-movement)
- T1535: Unused/Unsupported Cloud Regions (stealth)
- T1537: Transfer Data to Cloud Account (exfiltration)
- T1538: Cloud Service Dashboard (discovery)
- T1539: Steal Web Session Cookie (credential-access)
- T1542: Pre-OS Boot (stealth)
- T1542.001: System Firmware (stealth)
- T1542.002: Component Firmware (stealth)
- T1542.003: Bootkit (stealth)
- T1542.004: ROMMONkit (stealth)
- T1542.005: TFTP Boot (stealth)
- T1543: Create or Modify System Process (persistence)
- T1543.001: Launch Agent (persistence)
- T1543.002: Systemd Service (persistence)
- T1543.003: Windows Service (persistence)
- T1543.004: Launch Daemon (persistence)
- T1543.005: Container Service (persistence)
- T1546: Event Triggered Execution (privilege-escalation)
- T1546.001: Change Default File Association (privilege-escalation)
- T1546.002: Screensaver (privilege-escalation)
- T1546.003: Windows Management Instrumentation Event Subscription (privilege-escalation)
- T1546.004: Unix Shell Configuration Modification (privilege-escalation)
- T1546.005: Trap (privilege-escalation)
- T1546.006: LC_LOAD_DYLIB Addition (privilege-escalation)
- T1546.007: Netsh Helper DLL (privilege-escalation)
- T1546.008: Accessibility Features (privilege-escalation)
- T1546.009: AppCert DLLs (privilege-escalation)
- T1546.010: AppInit DLLs (privilege-escalation)
- T1546.011: Application Shimming (privilege-escalation)
- T1546.012: Image File Execution Options Injection (privilege-escalation)
- T1546.013: PowerShell Profile (privilege-escalation)
- T1546.014: Emond (privilege-escalation)
- T1546.015: Component Object Model Hijacking (privilege-escalation)
- T1546.016: Installer Packages (privilege-escalation)
- T1546.017: Udev Rules (persistence)
- T1546.018: Python Startup Hooks (persistence)
- T1547: Boot or Logon Autostart Execution (persistence)
- T1547.001: Registry Run Keys / Startup Folder (persistence)
- T1547.002: Authentication Package (persistence)
- T1547.003: Time Providers (persistence)
- T1547.004: Winlogon Helper DLL (persistence)
- T1547.005: Security Support Provider (persistence)
- T1547.006: Kernel Modules and Extensions (persistence)
- T1547.007: Re-opened Applications (persistence)
- T1547.008: LSASS Driver (persistence)
- T1547.009: Shortcut Modification (persistence)
- T1547.010: Port Monitors (persistence)
- T1547.012: Print Processors (persistence)
- T1547.013: XDG Autostart Entries (persistence)
- T1547.014: Active Setup (persistence)
- T1547.015: Login Items (persistence)
- T1548: Abuse Elevation Control Mechanism (privilege-escalation)
- T1548.001: Setuid and Setgid (privilege-escalation)
- T1548.002: Bypass User Account Control (privilege-escalation)
- T1548.003: Sudo and Sudo Caching (privilege-escalation)
- T1548.004: Elevated Execution with Prompt (privilege-escalation)
- T1548.005: Temporary Elevated Cloud Access (privilege-escalation)
- T1548.006: TCC Manipulation (privilege-escalation)
- T1550: Use Alternate Authentication Material (lateral-movement)
- T1550.001: Application Access Token (lateral-movement)
- T1550.002: Pass the Hash (lateral-movement)
- T1550.003: Pass the Ticket (lateral-movement)
- T1550.004: Web Session Cookie (lateral-movement)
- T1552: Unsecured Credentials (credential-access)
- T1552.001: Credentials In Files (credential-access)
- T1552.002: Credentials in Registry (credential-access)
- T1552.003: Shell History (credential-access)
- T1552.004: Private Keys (credential-access)
- T1552.005: Cloud Instance Metadata API (credential-access)
- T1552.006: Group Policy Preferences (credential-access)
- T1552.007: Container API (credential-access)
- T1552.008: Chat Messages (credential-access)
- T1553: Subvert Trust Controls (defense-impairment)
- T1553.001: Gatekeeper Bypass (defense-impairment)
- T1553.002: Code Signing (defense-impairment)
- T1553.003: SIP and Trust Provider Hijacking (defense-impairment)
- T1553.004: Install Root Certificate (defense-impairment)
- T1553.005: Mark-of-the-Web Bypass (defense-impairment)
- T1553.006: Code Signing Policy Modification (defense-impairment)
- T1554: Compromise Host Software Binary (persistence)
- T1555: Credentials from Password Stores (credential-access)
- T1555.001: Keychain (credential-access)
- T1555.002: Securityd Memory (credential-access)
- T1555.003: Credentials from Web Browsers (credential-access)
- T1555.004: Windows Credential Manager (credential-access)
- T1555.005: Password Managers (credential-access)
- T1555.006: Cloud Secrets Management Stores (credential-access)
- T1556: Modify Authentication Process (defense-impairment)
- T1556.001: Domain Controller Authentication (defense-impairment)
- T1556.002: Password Filter DLL (defense-impairment)
- T1556.003: Pluggable Authentication Modules (defense-impairment)
- T1556.004: Network Device Authentication (defense-impairment)
- T1556.005: Reversible Encryption (defense-impairment)
- T1556.006: Multi-Factor Authentication (defense-impairment)
- T1556.007: Hybrid Identity (defense-impairment)
- T1556.008: Network Provider DLL (defense-impairment)
- T1556.009: Conditional Access Policies (defense-impairment)
- T1557: Adversary-in-the-Middle (credential-access)
- T1557.001: Name Resolution Poisoning and SMB Relay (credential-access)
- T1557.002: ARP Cache Poisoning (credential-access)
- T1557.003: DHCP Spoofing (credential-access)
- T1557.004: Evil Twin (credential-access)
- T1558: Steal or Forge Kerberos Tickets (credential-access)
- T1558.001: Golden Ticket (credential-access)
- T1558.002: Silver Ticket (credential-access)
- T1558.003: Kerberoasting (credential-access)
- T1558.004: AS-REP Roasting (credential-access)
- T1558.005: Ccache Files (credential-access)
- T1559: Inter-Process Communication (execution)
- T1559.001: Component Object Model (execution)
- T1559.002: Dynamic Data Exchange (execution)
- T1559.003: XPC Services (execution)
- T1560: Archive Collected Data (collection)
- T1560.001: Archive via Utility (collection)
- T1560.002: Archive via Library (collection)
- T1560.003: Archive via Custom Method (collection)
- T1561: Disk Wipe (impact)
- T1561.001: Disk Content Wipe (impact)
- T1561.002: Disk Structure Wipe (impact)
- T1563: Remote Service Session Hijacking (lateral-movement)
- T1563.001: SSH Hijacking (lateral-movement)
- T1563.002: RDP Hijacking (lateral-movement)
- T1564: Hide Artifacts (stealth)
- T1564.001: Hidden Files and Directories (stealth)
- T1564.002: Hidden Users (stealth)
- T1564.003: Hidden Window (stealth)
- T1564.004: NTFS File Attributes (stealth)
- T1564.005: Hidden File System (stealth)
- T1564.006: Run Virtual Instance (stealth)
- T1564.007: VBA Stomping (stealth)
- T1564.008: Email Hiding Rules (stealth)
- T1564.009: Resource Forking (stealth)
- T1564.010: Process Argument Spoofing (stealth)
- T1564.011: Ignore Process Interrupts (stealth)
- T1564.012: File/Path Exclusions (stealth)
- T1564.013: Bind Mounts (stealth)
- T1564.014: Extended Attributes (stealth)
- T1565: Data Manipulation (impact)
- T1565.001: Stored Data Manipulation (impact)
- T1565.002: Transmitted Data Manipulation (impact)
- T1565.003: Runtime Data Manipulation (impact)
- T1566: Phishing (initial-access)
- T1566.001: Spearphishing Attachment (initial-access)
- T1566.002: Spearphishing Link (initial-access)
- T1566.003: Spearphishing via Service (initial-access)
- T1566.004: Spearphishing Voice (initial-access)
- T1567: Exfiltration Over Web Service (exfiltration)
- T1567.001: Exfiltration to Code Repository (exfiltration)
- T1567.002: Exfiltration to Cloud Storage (exfiltration)
- T1567.003: Exfiltration to Text Storage Sites (exfiltration)
- T1567.004: Exfiltration Over Webhook (exfiltration)
- T1568: Dynamic Resolution (command-and-control)
- T1568.001: Fast Flux DNS (command-and-control)
- T1568.002: Domain Generation Algorithms (command-and-control)
- T1568.003: DNS Calculation (command-and-control)
- T1569: System Services (execution)
- T1569.001: Launchctl (execution)
- T1569.002: Service Execution (execution)
- T1569.003: Systemctl (execution)
- T1570: Lateral Tool Transfer (lateral-movement)
- T1571: Non-Standard Port (command-and-control)
- T1572: Protocol Tunneling (command-and-control)
- T1573: Encrypted Channel (command-and-control)
- T1573.001: Symmetric Cryptography (command-and-control)
- T1573.002: Asymmetric Cryptography (command-and-control)
- T1574: Hijack Execution Flow (stealth)
- T1574.001: DLL (stealth)
- T1574.004: Dylib Hijacking (stealth)
- T1574.005: Executable Installer File Permissions Weakness (stealth)
- T1574.006: Dynamic Linker Hijacking (stealth)
- T1574.007: Path Interception by PATH Environment Variable (stealth)
- T1574.008: Path Interception by Search Order Hijacking (stealth)
- T1574.009: Path Interception by Unquoted Path (stealth)
- T1574.010: Services File Permissions Weakness (stealth)
- T1574.011: Services Registry Permissions Weakness (stealth)
- T1574.012: COR_PROFILER (stealth)
- T1574.013: KernelCallbackTable (stealth)
- T1574.014: AppDomainManager (stealth)
- T1578: Modify Cloud Compute Infrastructure (defense-impairment)
- T1578.001: Create Snapshot (defense-impairment)
- T1578.002: Create Cloud Instance (defense-impairment)
- T1578.003: Delete Cloud Instance (defense-impairment)
- T1578.004: Revert Cloud Instance (defense-impairment)
- T1578.005: Modify Cloud Compute Configurations (defense-impairment)
- T1580: Cloud Infrastructure Discovery (discovery)
- T1583: Acquire Infrastructure (resource-development)
- T1583.001: Domains (resource-development)
- T1583.002: DNS Server (resource-development)
- T1583.003: Virtual Private Server (resource-development)
- T1583.004: Server (resource-development)
- T1583.005: Botnet (resource-development)
- T1583.006: Web Services (resource-development)
- T1583.007: Serverless (resource-development)
- T1583.008: Malvertising (resource-development)
- T1584: Compromise Infrastructure (resource-development)
- T1584.001: Domains (resource-development)
- T1584.002: DNS Server (resource-development)
- T1584.003: Virtual Private Server (resource-development)
- T1584.004: Server (resource-development)
- T1584.005: Botnet (resource-development)
- T1584.006: Web Services (resource-development)
- T1584.007: Serverless (resource-development)
- T1584.008: Network Devices (resource-development)
- T1585: Establish Accounts (resource-development)
- T1585.001: Social Media Accounts (resource-development)
- T1585.002: Email Accounts (resource-development)
- T1585.003: Cloud Accounts (resource-development)
- T1586: Compromise Accounts (resource-development)
- T1586.001: Social Media Accounts (resource-development)
- T1586.002: Email Accounts (resource-development)
- T1586.003: Cloud Accounts (resource-development)
- T1587: Develop Capabilities (resource-development)
- T1587.001: Malware (resource-development)
- T1587.002: Code Signing Certificates (resource-development)
- T1587.003: Digital Certificates (resource-development)
- T1587.004: Exploits (resource-development)
- T1588: Obtain Capabilities (resource-development)
- T1588.001: Malware (resource-development)
- T1588.002: Tool (resource-development)
- T1588.003: Code Signing Certificates (resource-development)
- T1588.004: Digital Certificates (resource-development)
- T1588.005: Exploits (resource-development)
- T1588.006: Vulnerabilities (resource-development)
- T1588.007: Artificial Intelligence (resource-development)
- T1589: Gather Victim Identity Information (reconnaissance)
- T1589.001: Credentials (reconnaissance)
- T1589.002: Email Addresses (reconnaissance)
- T1589.003: Employee Names (reconnaissance)
- T1590: Gather Victim Network Information (reconnaissance)
- T1590.001: Domain Properties (reconnaissance)
- T1590.002: DNS (reconnaissance)
- T1590.003: Network Trust Dependencies (reconnaissance)
- T1590.004: Network Topology (reconnaissance)
- T1590.005: IP Addresses (reconnaissance)
- T1590.006: Network Security Appliances (reconnaissance)
- T1591: Gather Victim Org Information (reconnaissance)
- T1591.001: Determine Physical Locations (reconnaissance)
- T1591.002: Business Relationships (reconnaissance)
- T1591.003: Identify Business Tempo (reconnaissance)
- T1591.004: Identify Roles (reconnaissance)
- T1592: Gather Victim Host Information (reconnaissance)
- T1592.001: Hardware (reconnaissance)
- T1592.002: Software (reconnaissance)
- T1592.003: Firmware (reconnaissance)
- T1592.004: Client Configurations (reconnaissance)
- T1593: Search Open Websites/Domains (reconnaissance)
- T1593.001: Social Media (reconnaissance)
- T1593.002: Search Engines (reconnaissance)
- T1593.003: Code Repositories (reconnaissance)
- T1594: Search Victim-Owned Websites (reconnaissance)
- T1595: Active Scanning (reconnaissance)
- T1595.001: Scanning IP Blocks (reconnaissance)
- T1595.002: Vulnerability Scanning (reconnaissance)
- T1595.003: Wordlist Scanning (reconnaissance)
- T1596: Search Open Technical Databases (reconnaissance)
- T1596.001: DNS/Passive DNS (reconnaissance)
- T1596.002: WHOIS (reconnaissance)
- T1596.003: Digital Certificates (reconnaissance)
- T1596.004: CDNs (reconnaissance)
- T1596.005: Scan Databases (reconnaissance)
- T1597: Search Closed Sources (reconnaissance)
- T1597.001: Threat Intel Vendors (reconnaissance)
- T1597.002: Purchase Technical Data (reconnaissance)
- T1598: Phishing for Information (reconnaissance)
- T1598.001: Spearphishing Service (reconnaissance)
- T1598.002: Spearphishing Attachment (reconnaissance)
- T1598.003: Spearphishing Link (reconnaissance)
- T1598.004: Spearphishing Voice (reconnaissance)
- T1599: Network Boundary Bridging (defense-impairment)
- T1599.001: Network Address Translation Traversal (defense-impairment)
- T1600: Weaken Encryption (defense-impairment)
- T1600.001: Reduce Key Space (defense-impairment)
- T1600.002: Disable Crypto Hardware (defense-impairment)
- T1601: Modify System Image (defense-impairment)
- T1601.001: Patch System Image (defense-impairment)
- T1601.002: Downgrade System Image (defense-impairment)
- T1602: Data from Configuration Repository (collection)
- T1602.001: SNMP (MIB Dump) (collection)
- T1602.002: Network Device Configuration Dump (collection)
- T1606: Forge Web Credentials (credential-access)
- T1606.001: Web Cookies (credential-access)
- T1606.002: SAML Tokens (credential-access)
- T1608: Stage Capabilities (resource-development)
- T1608.001: Upload Malware (resource-development)
- T1608.002: Upload Tool (resource-development)
- T1608.003: Install Digital Certificate (resource-development)
- T1608.004: Drive-by Target (resource-development)
- T1608.005: Link Target (resource-development)
- T1608.006: SEO Poisoning (resource-development)
- T1609: Container Administration Command (execution)
- T1610: Deploy Container (execution)
- T1611: Escape to Host (privilege-escalation)
- T1612: Build Image on Host (stealth)
- T1613: Container and Resource Discovery (discovery)
- T1614: System Location Discovery (discovery)
- T1614.001: System Language Discovery (discovery)
- T1615: Group Policy Discovery (discovery)
- T1619: Cloud Storage Object Discovery (discovery)
- T1620: Reflective Code Loading (stealth)
- T1621: Multi-Factor Authentication Request Generation (credential-access)
- T1622: Debugger Evasion (stealth)
- T1647: Plist File Modification (defense-impairment)
- T1648: Serverless Execution (execution)
- T1649: Steal or Forge Authentication Certificates (credential-access)
- T1650: Acquire Access (resource-development)
- T1651: Cloud Administration Command (execution)
- T1652: Device Driver Discovery (discovery)
- T1653: Power Settings (persistence)
- T1654: Log Enumeration (discovery)
- T1657: Financial Theft (impact)
- T1659: Content Injection (initial-access)
- T1665: Hide Infrastructure (command-and-control)
- T1666: Modify Cloud Resource Hierarchy (defense-impairment)
- T1667: Email Bombing (impact)
- T1668: Exclusive Control (persistence)
- T1669: Wi-Fi Networks (initial-access)
- T1671: Cloud Application Integration (persistence)
- T1673: Virtual Machine Discovery (discovery)
- T1674: Input Injection (execution)
- T1675: ESXi Administration Command (execution)
- T1677: Poisoned Pipeline Execution (execution)
- T1678: Delay Execution (stealth)
- T1679: Selective Exclusion (stealth)
- T1680: Local Storage Discovery (discovery)
- T1681: Search Threat Vendor Data (reconnaissance)
- T1682: Query Public AI Services (reconnaissance)
- T1683: Generate Content (resource-development)
- T1683.001: Written Content (resource-development)
- T1683.002: Audio-Visual Content (resource-development)
- T1684: Social Engineering (stealth)
- T1684.001: Impersonation (stealth)
- T1684.002: Email Spoofing (stealth)
- T1685: Disable or Modify Tools (defense-impairment)
- T1685.001: Disable or Modify Windows Event Log (defense-impairment)
- T1685.002: Disable or Modify Cloud Log (defense-impairment)
- T1685.003: Modify or Spoof Tool UI (defense-impairment)
- T1685.004: Disable or Modify Linux Audit System Log (defense-impairment)
- T1685.005: Clear Windows Event Logs (defense-impairment)
- T1685.006: Clear Linux or Mac System Logs (defense-impairment)
- T1686: Disable or Modify System Firewall (defense-impairment)
- T1686.001: Cloud Firewall (defense-impairment)
- T1686.002: Network Device Firewall (defense-impairment)
- T1686.003: Windows Host Firewall (defense-impairment)
- T1687: Exploitation for Defense Impairment (defense-impairment)
- T1688: Safe Mode Boot (defense-impairment)
- T1689: Downgrade Attack (defense-impairment)
- T1690: Prevent Command History Logging (defense-impairment)