MITRE ATT&CK Β· Enterprise Matrix
MITRE ATT&CK techniques, mirrored here
697 techniques and sub-techniques, mirrored from MITRE's own published data.
Every page here is generated straight from MITRE's own STIX data, so it stays accurate without hand-editing -- and so a Grafana dashboard's ATT&CK technique click-throughs always land here on easysiem.com, even for an install with no general internet route to attack.mitre.org itself.
Initial Access
- T1078 β Valid Accounts
- T1078.001 β Default Accounts
- T1078.002 β Domain Accounts
- T1078.003 β Local Accounts
- T1078.004 β Cloud Accounts
- T1091 β Replication Through Removable Media
- T1133 β External Remote Services
- T1189 β Drive-by Compromise
- T1190 β Exploit Public-Facing Application
- T1195 β Supply Chain Compromise
- T1195.001 β Compromise Software Dependencies and Development Tools
- T1195.002 β Compromise Software Supply Chain
- T1195.003 β Compromise Hardware Supply Chain
- T1199 β Trusted Relationship
- T1200 β Hardware Additions
- T1566 β Phishing
- T1566.001 β Spearphishing Attachment
- T1566.002 β Spearphishing Link
- T1566.003 β Spearphishing via Service
- T1566.004 β Spearphishing Voice
- T1659 β Content Injection
- T1669 β Wi-Fi Networks
Execution
- T1047 β Windows Management Instrumentation
- T1053 β Scheduled Task/Job
- T1053.002 β At
- T1053.003 β Cron
- T1053.005 β Scheduled Task
- T1053.006 β Systemd Timers
- T1053.007 β Container Orchestration Job
- T1059 β Command and Scripting Interpreter
- T1059.001 β PowerShell
- T1059.002 β AppleScript
- T1059.003 β Windows Command Shell
- T1059.004 β Unix Shell
- T1059.005 β Visual Basic
- T1059.006 β Python
- T1059.007 β JavaScript
- T1059.008 β Network Device CLI
- T1059.009 β Cloud API
- T1059.010 β AutoHotKey & AutoIT
- T1059.011 β Lua
- T1059.012 β Hypervisor CLI
- T1059.013 β Container CLI/API
- T1072 β Software Deployment Tools
- T1106 β Native API
- T1127 β Trusted Developer Utilities Proxy Execution
- T1127.001 β MSBuild
- T1127.002 β ClickOnce
- T1127.003 β JamPlus
- T1129 β Shared Modules
- T1197 β BITS Jobs
- T1203 β Exploitation for Client Execution
- T1204 β User Execution
- T1204.001 β Malicious Link
- T1204.002 β Malicious File
- T1204.003 β Malicious Image
- T1204.004 β Malicious Copy and Paste
- T1204.005 β Malicious Library
- T1559 β Inter-Process Communication
- T1559.001 β Component Object Model
- T1559.002 β Dynamic Data Exchange
- T1559.003 β XPC Services
- T1569 β System Services
- T1569.001 β Launchctl
- T1569.002 β Service Execution
- T1569.003 β Systemctl
- T1574 β Hijack Execution Flow
- T1574.001 β DLL
- T1574.004 β Dylib Hijacking
- T1574.005 β Executable Installer File Permissions Weakness
- T1574.006 β Dynamic Linker Hijacking
- T1574.007 β Path Interception by PATH Environment Variable
- T1574.008 β Path Interception by Search Order Hijacking
- T1574.009 β Path Interception by Unquoted Path
- T1574.010 β Services File Permissions Weakness
- T1574.011 β Services Registry Permissions Weakness
- T1574.012 β COR_PROFILER
- T1574.013 β KernelCallbackTable
- T1574.014 β AppDomainManager
- T1609 β Container Administration Command
- T1610 β Deploy Container
- T1648 β Serverless Execution
- T1651 β Cloud Administration Command
- T1674 β Input Injection
- T1675 β ESXi Administration Command
- T1677 β Poisoned Pipeline Execution
Persistence
- T1037 β Boot or Logon Initialization Scripts
- T1037.001 β Logon Script (Windows)
- T1037.002 β Login Hook
- T1037.003 β Network Logon Script
- T1037.004 β RC Scripts
- T1037.005 β Startup Items
- T1053 β Scheduled Task/Job
- T1053.002 β At
- T1053.003 β Cron
- T1053.005 β Scheduled Task
- T1053.006 β Systemd Timers
- T1053.007 β Container Orchestration Job
- T1078 β Valid Accounts
- T1078.001 β Default Accounts
- T1078.002 β Domain Accounts
- T1078.003 β Local Accounts
- T1078.004 β Cloud Accounts
- T1098 β Account Manipulation
- T1098.001 β Additional Cloud Credentials
- T1098.002 β Additional Email Delegate Permissions
- T1098.003 β Additional Cloud Roles
- T1098.004 β SSH Authorized Keys
- T1098.005 β Device Registration
- T1098.006 β Additional Container Cluster Roles
- T1098.007 β Additional Local or Domain Groups
- T1112 β Modify Registry
- T1133 β External Remote Services
- T1136 β Create Account
- T1136.001 β Local Account
- T1136.002 β Domain Account
- T1136.003 β Cloud Account
- T1137 β Office Application Startup
- T1137.001 β Office Template Macros
- T1137.002 β Office Test
- T1137.003 β Outlook Forms
- T1137.004 β Outlook Home Page
- T1137.005 β Outlook Rules
- T1137.006 β Add-ins
- T1176 β Software Extensions
- T1176.001 β Browser Extensions
- T1176.002 β IDE Extensions
- T1197 β BITS Jobs
- T1205 β Traffic Signaling
- T1205.001 β Port Knocking
- T1205.002 β Socket Filters
- T1505 β Server Software Component
- T1505.001 β SQL Stored Procedures
- T1505.002 β Transport Agent
- T1505.003 β Web Shell
- T1505.004 β IIS Components
- T1505.005 β Terminal Services DLL
- T1505.006 β vSphere Installation Bundles
- T1525 β Implant Internal Image
- T1542 β Pre-OS Boot
- T1542.001 β System Firmware
- T1542.002 β Component Firmware
- T1542.003 β Bootkit
- T1542.004 β ROMMONkit
- T1542.005 β TFTP Boot
- T1543 β Create or Modify System Process
- T1543.001 β Launch Agent
- T1543.002 β Systemd Service
- T1543.003 β Windows Service
- T1543.004 β Launch Daemon
- T1543.005 β Container Service
- T1546 β Event Triggered Execution
- T1546.001 β Change Default File Association
- T1546.002 β Screensaver
- T1546.003 β Windows Management Instrumentation Event Subscription
- T1546.004 β Unix Shell Configuration Modification
- T1546.005 β Trap
- T1546.006 β LC_LOAD_DYLIB Addition
- T1546.007 β Netsh Helper DLL
- T1546.008 β Accessibility Features
- T1546.009 β AppCert DLLs
- T1546.010 β AppInit DLLs
- T1546.011 β Application Shimming
- T1546.012 β Image File Execution Options Injection
- T1546.013 β PowerShell Profile
- T1546.014 β Emond
- T1546.015 β Component Object Model Hijacking
- T1546.016 β Installer Packages
- T1546.017 β Udev Rules
- T1546.018 β Python Startup Hooks
- T1547 β Boot or Logon Autostart Execution
- T1547.001 β Registry Run Keys / Startup Folder
- T1547.002 β Authentication Package
- T1547.003 β Time Providers
- T1547.004 β Winlogon Helper DLL
- T1547.005 β Security Support Provider
- T1547.006 β Kernel Modules and Extensions
- T1547.007 β Re-opened Applications
- T1547.008 β LSASS Driver
- T1547.009 β Shortcut Modification
- T1547.010 β Port Monitors
- T1547.012 β Print Processors
- T1547.013 β XDG Autostart Entries
- T1547.014 β Active Setup
- T1547.015 β Login Items
- T1554 β Compromise Host Software Binary
- T1556 β Modify Authentication Process
- T1556.001 β Domain Controller Authentication
- T1556.002 β Password Filter DLL
- T1556.003 β Pluggable Authentication Modules
- T1556.004 β Network Device Authentication
- T1556.005 β Reversible Encryption
- T1556.006 β Multi-Factor Authentication
- T1556.007 β Hybrid Identity
- T1556.008 β Network Provider DLL
- T1556.009 β Conditional Access Policies
- T1653 β Power Settings
- T1668 β Exclusive Control
- T1671 β Cloud Application Integration
Privilege Escalation
- T1037 β Boot or Logon Initialization Scripts
- T1037.001 β Logon Script (Windows)
- T1037.002 β Login Hook
- T1037.003 β Network Logon Script
- T1037.004 β RC Scripts
- T1037.005 β Startup Items
- T1053 β Scheduled Task/Job
- T1053.002 β At
- T1053.003 β Cron
- T1053.005 β Scheduled Task
- T1053.006 β Systemd Timers
- T1053.007 β Container Orchestration Job
- T1055 β Process Injection
- T1055.001 β Dynamic-link Library Injection
- T1055.002 β Portable Executable Injection
- T1055.003 β Thread Execution Hijacking
- T1055.004 β Asynchronous Procedure Call
- T1055.005 β Thread Local Storage
- T1055.008 β Ptrace System Calls
- T1055.009 β Proc Memory
- T1055.011 β Extra Window Memory Injection
- T1055.012 β Process Hollowing
- T1055.013 β Process DoppelgΓ€nging
- T1055.014 β VDSO Hijacking
- T1055.015 β ListPlanting
- T1068 β Exploitation for Privilege Escalation
- T1078 β Valid Accounts
- T1078.001 β Default Accounts
- T1078.002 β Domain Accounts
- T1078.003 β Local Accounts
- T1078.004 β Cloud Accounts
- T1098 β Account Manipulation
- T1098.001 β Additional Cloud Credentials
- T1098.002 β Additional Email Delegate Permissions
- T1098.003 β Additional Cloud Roles
- T1098.004 β SSH Authorized Keys
- T1098.005 β Device Registration
- T1098.006 β Additional Container Cluster Roles
- T1098.007 β Additional Local or Domain Groups
- T1134 β Access Token Manipulation
- T1134.001 β Token Impersonation/Theft
- T1134.002 β Create Process with Token
- T1134.003 β Make and Impersonate Token
- T1134.004 β Parent PID Spoofing
- T1134.005 β SID-History Injection
- T1484 β Domain or Tenant Policy Modification
- T1484.001 β Group Policy Modification
- T1484.002 β Trust Modification
- T1543 β Create or Modify System Process
- T1543.001 β Launch Agent
- T1543.002 β Systemd Service
- T1543.003 β Windows Service
- T1543.004 β Launch Daemon
- T1543.005 β Container Service
- T1546 β Event Triggered Execution
- T1546.001 β Change Default File Association
- T1546.002 β Screensaver
- T1546.003 β Windows Management Instrumentation Event Subscription
- T1546.004 β Unix Shell Configuration Modification
- T1546.005 β Trap
- T1546.006 β LC_LOAD_DYLIB Addition
- T1546.007 β Netsh Helper DLL
- T1546.008 β Accessibility Features
- T1546.009 β AppCert DLLs
- T1546.010 β AppInit DLLs
- T1546.011 β Application Shimming
- T1546.012 β Image File Execution Options Injection
- T1546.013 β PowerShell Profile
- T1546.014 β Emond
- T1546.015 β Component Object Model Hijacking
- T1546.016 β Installer Packages
- T1546.017 β Udev Rules
- T1546.018 β Python Startup Hooks
- T1547 β Boot or Logon Autostart Execution
- T1547.001 β Registry Run Keys / Startup Folder
- T1547.002 β Authentication Package
- T1547.003 β Time Providers
- T1547.004 β Winlogon Helper DLL
- T1547.005 β Security Support Provider
- T1547.006 β Kernel Modules and Extensions
- T1547.007 β Re-opened Applications
- T1547.008 β LSASS Driver
- T1547.009 β Shortcut Modification
- T1547.010 β Port Monitors
- T1547.012 β Print Processors
- T1547.013 β XDG Autostart Entries
- T1547.014 β Active Setup
- T1547.015 β Login Items
- T1548 β Abuse Elevation Control Mechanism
- T1548.001 β Setuid and Setgid
- T1548.002 β Bypass User Account Control
- T1548.003 β Sudo and Sudo Caching
- T1548.004 β Elevated Execution with Prompt
- T1548.005 β Temporary Elevated Cloud Access
- T1548.006 β TCC Manipulation
- T1611 β Escape to Host
Stealth
- T1006 β Direct Volume Access
- T1014 β Rootkit
- T1027 β Obfuscated Files or Information
- T1027.001 β Binary Padding
- T1027.002 β Software Packing
- T1027.003 β Steganography
- T1027.004 β Compile After Delivery
- T1027.005 β Indicator Removal from Tools
- T1027.006 β HTML Smuggling
- T1027.007 β Dynamic API Resolution
- T1027.008 β Stripped Payloads
- T1027.009 β Embedded Payloads
- T1027.010 β Command Obfuscation
- T1027.011 β Fileless Storage
- T1027.012 β LNK Icon Smuggling
- T1027.013 β Encrypted/Encoded File
- T1027.014 β Polymorphic Code
- T1027.015 β Compression
- T1027.016 β Junk Code Insertion
- T1027.017 β SVG Smuggling
- T1027.018 β Invisible Unicode
- T1036 β Masquerading
- T1036.001 β Invalid Code Signature
- T1036.002 β Right-to-Left Override
- T1036.003 β Rename Legitimate Utilities
- T1036.004 β Masquerade Task or Service
- T1036.005 β Match Legitimate Resource Name or Location
- T1036.006 β Space after Filename
- T1036.007 β Double File Extension
- T1036.008 β Masquerade File Type
- T1036.009 β Break Process Trees
- T1036.010 β Masquerade Account Name
- T1036.011 β Overwrite Process Arguments
- T1036.012 β Browser Fingerprint
- T1055 β Process Injection
- T1055.001 β Dynamic-link Library Injection
- T1055.002 β Portable Executable Injection
- T1055.003 β Thread Execution Hijacking
- T1055.004 β Asynchronous Procedure Call
- T1055.005 β Thread Local Storage
- T1055.008 β Ptrace System Calls
- T1055.009 β Proc Memory
- T1055.011 β Extra Window Memory Injection
- T1055.012 β Process Hollowing
- T1055.013 β Process DoppelgΓ€nging
- T1055.014 β VDSO Hijacking
- T1055.015 β ListPlanting
- T1070 β Indicator Removal
- T1070.003 β Clear Command History
- T1070.004 β File Deletion
- T1070.005 β Network Share Connection Removal
- T1070.006 β Timestomp
- T1070.007 β Clear Network Connection History and Configurations
- T1070.008 β Clear Mailbox Data
- T1070.009 β Clear Persistence
- T1070.010 β Relocate Malware
- T1078 β Valid Accounts
- T1078.001 β Default Accounts
- T1078.002 β Domain Accounts
- T1078.003 β Local Accounts
- T1078.004 β Cloud Accounts
- T1127 β Trusted Developer Utilities Proxy Execution
- T1127.001 β MSBuild
- T1127.002 β ClickOnce
- T1127.003 β JamPlus
- T1134 β Access Token Manipulation
- T1134.001 β Token Impersonation/Theft
- T1134.002 β Create Process with Token
- T1134.003 β Make and Impersonate Token
- T1134.004 β Parent PID Spoofing
- T1134.005 β SID-History Injection
- T1140 β Deobfuscate/Decode Files or Information
- T1197 β BITS Jobs
- T1202 β Indirect Command Execution
- T1205 β Traffic Signaling
- T1205.001 β Port Knocking
- T1205.002 β Socket Filters
- T1211 β Exploitation for Stealth
- T1216 β System Script Proxy Execution
- T1216.001 β PubPrn
- T1216.002 β SyncAppvPublishingServer
- T1218 β System Binary Proxy Execution
- T1218.001 β Compiled HTML File
- T1218.002 β Control Panel
- T1218.003 β CMSTP
- T1218.004 β InstallUtil
- T1218.005 β Mshta
- T1218.007 β Msiexec
- T1218.008 β Odbcconf
- T1218.009 β Regsvcs/Regasm
- T1218.010 β Regsvr32
- T1218.011 β Rundll32
- T1218.012 β Verclsid
- T1218.013 β Mavinject
- T1218.014 β MMC
- T1218.015 β Electron Applications
- T1220 β XSL Script Processing
- T1221 β Template Injection
- T1480 β Execution Guardrails
- T1480.001 β Environmental Keying
- T1480.002 β Mutual Exclusion
- T1497 β Virtualization/Sandbox Evasion
- T1497.001 β System Checks
- T1497.002 β User Activity Based Checks
- T1497.003 β Time Based Checks
- T1535 β Unused/Unsupported Cloud Regions
- T1542 β Pre-OS Boot
- T1542.001 β System Firmware
- T1542.002 β Component Firmware
- T1542.003 β Bootkit
- T1542.004 β ROMMONkit
- T1542.005 β TFTP Boot
- T1564 β Hide Artifacts
- T1564.001 β Hidden Files and Directories
- T1564.002 β Hidden Users
- T1564.003 β Hidden Window
- T1564.004 β NTFS File Attributes
- T1564.005 β Hidden File System
- T1564.006 β Run Virtual Instance
- T1564.007 β VBA Stomping
- T1564.008 β Email Hiding Rules
- T1564.009 β Resource Forking
- T1564.010 β Process Argument Spoofing
- T1564.011 β Ignore Process Interrupts
- T1564.012 β File/Path Exclusions
- T1564.013 β Bind Mounts
- T1564.014 β Extended Attributes
- T1574 β Hijack Execution Flow
- T1574.001 β DLL
- T1574.004 β Dylib Hijacking
- T1574.005 β Executable Installer File Permissions Weakness
- T1574.006 β Dynamic Linker Hijacking
- T1574.007 β Path Interception by PATH Environment Variable
- T1574.008 β Path Interception by Search Order Hijacking
- T1574.009 β Path Interception by Unquoted Path
- T1574.010 β Services File Permissions Weakness
- T1574.011 β Services Registry Permissions Weakness
- T1574.012 β COR_PROFILER
- T1574.013 β KernelCallbackTable
- T1574.014 β AppDomainManager
- T1612 β Build Image on Host
- T1620 β Reflective Code Loading
- T1622 β Debugger Evasion
- T1678 β Delay Execution
- T1679 β Selective Exclusion
- T1684 β Social Engineering
- T1684.001 β Impersonation
- T1684.002 β Email Spoofing
Credential Access
- T1003 β OS Credential Dumping
- T1003.001 β LSASS Memory
- T1003.002 β Security Account Manager
- T1003.003 β NTDS
- T1003.004 β LSA Secrets
- T1003.005 β Cached Domain Credentials
- T1003.006 β DCSync
- T1003.007 β Proc Filesystem
- T1003.008 β /etc/passwd and /etc/shadow
- T1040 β Network Sniffing
- T1056 β Input Capture
- T1056.001 β Keylogging
- T1056.002 β GUI Input Capture
- T1056.003 β Web Portal Capture
- T1056.004 β Credential API Hooking
- T1110 β Brute Force
- T1110.001 β Password Guessing
- T1110.002 β Password Cracking
- T1110.003 β Password Spraying
- T1110.004 β Credential Stuffing
- T1111 β Multi-Factor Authentication Interception
- T1187 β Forced Authentication
- T1212 β Exploitation for Credential Access
- T1528 β Steal Application Access Token
- T1539 β Steal Web Session Cookie
- T1552 β Unsecured Credentials
- T1552.001 β Credentials In Files
- T1552.002 β Credentials in Registry
- T1552.003 β Shell History
- T1552.004 β Private Keys
- T1552.005 β Cloud Instance Metadata API
- T1552.006 β Group Policy Preferences
- T1552.007 β Container API
- T1552.008 β Chat Messages
- T1555 β Credentials from Password Stores
- T1555.001 β Keychain
- T1555.002 β Securityd Memory
- T1555.003 β Credentials from Web Browsers
- T1555.004 β Windows Credential Manager
- T1555.005 β Password Managers
- T1555.006 β Cloud Secrets Management Stores
- T1556 β Modify Authentication Process
- T1556.001 β Domain Controller Authentication
- T1556.002 β Password Filter DLL
- T1556.003 β Pluggable Authentication Modules
- T1556.004 β Network Device Authentication
- T1556.005 β Reversible Encryption
- T1556.006 β Multi-Factor Authentication
- T1556.007 β Hybrid Identity
- T1556.008 β Network Provider DLL
- T1556.009 β Conditional Access Policies
- T1557 β Adversary-in-the-Middle
- T1557.001 β Name Resolution Poisoning and SMB Relay
- T1557.002 β ARP Cache Poisoning
- T1557.003 β DHCP Spoofing
- T1557.004 β Evil Twin
- T1558 β Steal or Forge Kerberos Tickets
- T1558.001 β Golden Ticket
- T1558.002 β Silver Ticket
- T1558.003 β Kerberoasting
- T1558.004 β AS-REP Roasting
- T1558.005 β Ccache Files
- T1606 β Forge Web Credentials
- T1606.001 β Web Cookies
- T1606.002 β SAML Tokens
- T1621 β Multi-Factor Authentication Request Generation
- T1649 β Steal or Forge Authentication Certificates
Discovery
- T1007 β System Service Discovery
- T1010 β Application Window Discovery
- T1012 β Query Registry
- T1016 β System Network Configuration Discovery
- T1016.001 β Internet Connection Discovery
- T1016.002 β Wi-Fi Discovery
- T1018 β Remote System Discovery
- T1033 β System Owner/User Discovery
- T1040 β Network Sniffing
- T1046 β Network Service Discovery
- T1049 β System Network Connections Discovery
- T1057 β Process Discovery
- T1069 β Permission Groups Discovery
- T1069.001 β Local Groups
- T1069.002 β Domain Groups
- T1069.003 β Cloud Groups
- T1082 β System Information Discovery
- T1083 β File and Directory Discovery
- T1087 β Account Discovery
- T1087.001 β Local Account
- T1087.002 β Domain Account
- T1087.003 β Email Account
- T1087.004 β Cloud Account
- T1120 β Peripheral Device Discovery
- T1124 β System Time Discovery
- T1135 β Network Share Discovery
- T1201 β Password Policy Discovery
- T1217 β Browser Information Discovery
- T1482 β Domain Trust Discovery
- T1497 β Virtualization/Sandbox Evasion
- T1497.001 β System Checks
- T1497.002 β User Activity Based Checks
- T1497.003 β Time Based Checks
- T1518 β Software Discovery
- T1518.001 β Security Software Discovery
- T1518.002 β Backup Software Discovery
- T1526 β Cloud Service Discovery
- T1538 β Cloud Service Dashboard
- T1580 β Cloud Infrastructure Discovery
- T1613 β Container and Resource Discovery
- T1614 β System Location Discovery
- T1614.001 β System Language Discovery
- T1615 β Group Policy Discovery
- T1619 β Cloud Storage Object Discovery
- T1622 β Debugger Evasion
- T1652 β Device Driver Discovery
- T1654 β Log Enumeration
- T1673 β Virtual Machine Discovery
- T1680 β Local Storage Discovery
Lateral Movement
- T1021 β Remote Services
- T1021.001 β Remote Desktop Protocol
- T1021.002 β SMB/Windows Admin Shares
- T1021.003 β Distributed Component Object Model
- T1021.004 β SSH
- T1021.005 β VNC
- T1021.006 β Windows Remote Management
- T1021.007 β Cloud Services
- T1021.008 β Direct Cloud VM Connections
- T1072 β Software Deployment Tools
- T1080 β Taint Shared Content
- T1091 β Replication Through Removable Media
- T1210 β Exploitation of Remote Services
- T1534 β Internal Spearphishing
- T1550 β Use Alternate Authentication Material
- T1550.001 β Application Access Token
- T1550.002 β Pass the Hash
- T1550.003 β Pass the Ticket
- T1550.004 β Web Session Cookie
- T1563 β Remote Service Session Hijacking
- T1563.001 β SSH Hijacking
- T1563.002 β RDP Hijacking
- T1570 β Lateral Tool Transfer
Collection
- T1005 β Data from Local System
- T1025 β Data from Removable Media
- T1039 β Data from Network Shared Drive
- T1056 β Input Capture
- T1056.001 β Keylogging
- T1056.002 β GUI Input Capture
- T1056.003 β Web Portal Capture
- T1056.004 β Credential API Hooking
- T1074 β Data Staged
- T1074.001 β Local Data Staging
- T1074.002 β Remote Data Staging
- T1113 β Screen Capture
- T1114 β Email Collection
- T1114.001 β Local Email Collection
- T1114.002 β Remote Email Collection
- T1114.003 β Email Forwarding Rule
- T1115 β Clipboard Data
- T1119 β Automated Collection
- T1123 β Audio Capture
- T1125 β Video Capture
- T1185 β Browser Session Hijacking
- T1213 β Data from Information Repositories
- T1213.001 β Confluence
- T1213.002 β Sharepoint
- T1213.003 β Code Repositories
- T1213.004 β Customer Relationship Management Software
- T1213.005 β Messaging Applications
- T1213.006 β Databases
- T1530 β Data from Cloud Storage
- T1557 β Adversary-in-the-Middle
- T1557.001 β Name Resolution Poisoning and SMB Relay
- T1557.002 β ARP Cache Poisoning
- T1557.003 β DHCP Spoofing
- T1557.004 β Evil Twin
- T1560 β Archive Collected Data
- T1560.001 β Archive via Utility
- T1560.002 β Archive via Library
- T1560.003 β Archive via Custom Method
- T1602 β Data from Configuration Repository
- T1602.001 β SNMP (MIB Dump)
- T1602.002 β Network Device Configuration Dump
Exfiltration
- T1011 β Exfiltration Over Other Network Medium
- T1011.001 β Exfiltration Over Bluetooth
- T1020 β Automated Exfiltration
- T1020.001 β Traffic Duplication
- T1029 β Scheduled Transfer
- T1030 β Data Transfer Size Limits
- T1041 β Exfiltration Over C2 Channel
- T1048 β Exfiltration Over Alternative Protocol
- T1048.001 β Exfiltration Over Symmetric Encrypted Non-C2 Protocol
- T1048.002 β Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
- T1048.003 β Exfiltration Over Unencrypted Non-C2 Protocol
- T1052 β Exfiltration Over Physical Medium
- T1052.001 β Exfiltration over USB
- T1537 β Transfer Data to Cloud Account
- T1567 β Exfiltration Over Web Service
- T1567.001 β Exfiltration to Code Repository
- T1567.002 β Exfiltration to Cloud Storage
- T1567.003 β Exfiltration to Text Storage Sites
- T1567.004 β Exfiltration Over Webhook
Command and Control
- T1001 β Data Obfuscation
- T1001.001 β Junk Data
- T1001.002 β Steganography
- T1001.003 β Protocol or Service Impersonation
- T1008 β Fallback Channels
- T1071 β Application Layer Protocol
- T1071.001 β Web Protocols
- T1071.002 β File Transfer Protocols
- T1071.003 β Mail Protocols
- T1071.004 β DNS
- T1071.005 β Publish/Subscribe Protocols
- T1090 β Proxy
- T1090.001 β Internal Proxy
- T1090.002 β External Proxy
- T1090.003 β Multi-hop Proxy
- T1090.004 β Domain Fronting
- T1092 β Communication Through Removable Media
- T1095 β Non-Application Layer Protocol
- T1102 β Web Service
- T1102.001 β Dead Drop Resolver
- T1102.002 β Bidirectional Communication
- T1102.003 β One-Way Communication
- T1104 β Multi-Stage Channels
- T1105 β Ingress Tool Transfer
- T1132 β Data Encoding
- T1132.001 β Standard Encoding
- T1132.002 β Non-Standard Encoding
- T1205 β Traffic Signaling
- T1205.001 β Port Knocking
- T1205.002 β Socket Filters
- T1219 β Remote Access Tools
- T1219.001 β IDE Tunneling
- T1219.002 β Remote Desktop Software
- T1219.003 β Remote Access Hardware
- T1568 β Dynamic Resolution
- T1568.001 β Fast Flux DNS
- T1568.002 β Domain Generation Algorithms
- T1568.003 β DNS Calculation
- T1571 β Non-Standard Port
- T1572 β Protocol Tunneling
- T1573 β Encrypted Channel
- T1573.001 β Symmetric Cryptography
- T1573.002 β Asymmetric Cryptography
- T1659 β Content Injection
- T1665 β Hide Infrastructure
Impact
- T1485 β Data Destruction
- T1485.001 β Lifecycle-Triggered Deletion
- T1486 β Data Encrypted for Impact
- T1489 β Service Stop
- T1490 β Inhibit System Recovery
- T1491 β Defacement
- T1491.001 β Internal Defacement
- T1491.002 β External Defacement
- T1495 β Firmware Corruption
- T1496 β Resource Hijacking
- T1496.001 β Compute Hijacking
- T1496.002 β Bandwidth Hijacking
- T1496.003 β SMS Pumping
- T1496.004 β Cloud Service Hijacking
- T1498 β Network Denial of Service
- T1498.001 β Direct Network Flood
- T1498.002 β Reflection Amplification
- T1499 β Endpoint Denial of Service
- T1499.001 β OS Exhaustion Flood
- T1499.002 β Service Exhaustion Flood
- T1499.003 β Application Exhaustion Flood
- T1499.004 β Application or System Exploitation
- T1529 β System Shutdown/Reboot
- T1531 β Account Access Removal
- T1561 β Disk Wipe
- T1561.001 β Disk Content Wipe
- T1561.002 β Disk Structure Wipe
- T1565 β Data Manipulation
- T1565.001 β Stored Data Manipulation
- T1565.002 β Transmitted Data Manipulation
- T1565.003 β Runtime Data Manipulation
- T1657 β Financial Theft
- T1667 β Email Bombing
Resource Development
- T1583 β Acquire Infrastructure
- T1583.001 β Domains
- T1583.002 β DNS Server
- T1583.003 β Virtual Private Server
- T1583.004 β Server
- T1583.005 β Botnet
- T1583.006 β Web Services
- T1583.007 β Serverless
- T1583.008 β Malvertising
- T1584 β Compromise Infrastructure
- T1584.001 β Domains
- T1584.002 β DNS Server
- T1584.003 β Virtual Private Server
- T1584.004 β Server
- T1584.005 β Botnet
- T1584.006 β Web Services
- T1584.007 β Serverless
- T1584.008 β Network Devices
- T1585 β Establish Accounts
- T1585.001 β Social Media Accounts
- T1585.002 β Email Accounts
- T1585.003 β Cloud Accounts
- T1586 β Compromise Accounts
- T1586.001 β Social Media Accounts
- T1586.002 β Email Accounts
- T1586.003 β Cloud Accounts
- T1587 β Develop Capabilities
- T1587.001 β Malware
- T1587.002 β Code Signing Certificates
- T1587.003 β Digital Certificates
- T1587.004 β Exploits
- T1588 β Obtain Capabilities
- T1588.001 β Malware
- T1588.002 β Tool
- T1588.003 β Code Signing Certificates
- T1588.004 β Digital Certificates
- T1588.005 β Exploits
- T1588.006 β Vulnerabilities
- T1588.007 β Artificial Intelligence
- T1608 β Stage Capabilities
- T1608.001 β Upload Malware
- T1608.002 β Upload Tool
- T1608.003 β Install Digital Certificate
- T1608.004 β Drive-by Target
- T1608.005 β Link Target
- T1608.006 β SEO Poisoning
- T1650 β Acquire Access
- T1683 β Generate Content
- T1683.001 β Written Content
- T1683.002 β Audio-Visual Content
Reconnaissance
- T1589 β Gather Victim Identity Information
- T1589.001 β Credentials
- T1589.002 β Email Addresses
- T1589.003 β Employee Names
- T1590 β Gather Victim Network Information
- T1590.001 β Domain Properties
- T1590.002 β DNS
- T1590.003 β Network Trust Dependencies
- T1590.004 β Network Topology
- T1590.005 β IP Addresses
- T1590.006 β Network Security Appliances
- T1591 β Gather Victim Org Information
- T1591.001 β Determine Physical Locations
- T1591.002 β Business Relationships
- T1591.003 β Identify Business Tempo
- T1591.004 β Identify Roles
- T1592 β Gather Victim Host Information
- T1592.001 β Hardware
- T1592.002 β Software
- T1592.003 β Firmware
- T1592.004 β Client Configurations
- T1593 β Search Open Websites/Domains
- T1593.001 β Social Media
- T1593.002 β Search Engines
- T1593.003 β Code Repositories
- T1594 β Search Victim-Owned Websites
- T1595 β Active Scanning
- T1595.001 β Scanning IP Blocks
- T1595.002 β Vulnerability Scanning
- T1595.003 β Wordlist Scanning
- T1596 β Search Open Technical Databases
- T1596.001 β DNS/Passive DNS
- T1596.002 β WHOIS
- T1596.003 β Digital Certificates
- T1596.004 β CDNs
- T1596.005 β Scan Databases
- T1597 β Search Closed Sources
- T1597.001 β Threat Intel Vendors
- T1597.002 β Purchase Technical Data
- T1598 β Phishing for Information
- T1598.001 β Spearphishing Service
- T1598.002 β Spearphishing Attachment
- T1598.003 β Spearphishing Link
- T1598.004 β Spearphishing Voice
- T1681 β Search Threat Vendor Data
- T1682 β Query Public AI Services
Defense Impairment
- T1112 β Modify Registry
- T1207 β Rogue Domain Controller
- T1222 β File and Directory Permissions Modification
- T1222.001 β Windows Permissions
- T1222.002 β Linux and Mac Permissions
- T1484 β Domain or Tenant Policy Modification
- T1484.001 β Group Policy Modification
- T1484.002 β Trust Modification
- T1553 β Subvert Trust Controls
- T1553.001 β Gatekeeper Bypass
- T1553.002 β Code Signing
- T1553.003 β SIP and Trust Provider Hijacking
- T1553.004 β Install Root Certificate
- T1553.005 β Mark-of-the-Web Bypass
- T1553.006 β Code Signing Policy Modification
- T1556 β Modify Authentication Process
- T1556.001 β Domain Controller Authentication
- T1556.002 β Password Filter DLL
- T1556.003 β Pluggable Authentication Modules
- T1556.004 β Network Device Authentication
- T1556.005 β Reversible Encryption
- T1556.006 β Multi-Factor Authentication
- T1556.007 β Hybrid Identity
- T1556.008 β Network Provider DLL
- T1556.009 β Conditional Access Policies
- T1578 β Modify Cloud Compute Infrastructure
- T1578.001 β Create Snapshot
- T1578.002 β Create Cloud Instance
- T1578.003 β Delete Cloud Instance
- T1578.004 β Revert Cloud Instance
- T1578.005 β Modify Cloud Compute Configurations
- T1599 β Network Boundary Bridging
- T1599.001 β Network Address Translation Traversal
- T1600 β Weaken Encryption
- T1600.001 β Reduce Key Space
- T1600.002 β Disable Crypto Hardware
- T1601 β Modify System Image
- T1601.001 β Patch System Image
- T1601.002 β Downgrade System Image
- T1647 β Plist File Modification
- T1666 β Modify Cloud Resource Hierarchy
- T1685 β Disable or Modify Tools
- T1685.001 β Disable or Modify Windows Event Log
- T1685.002 β Disable or Modify Cloud Log
- T1685.003 β Modify or Spoof Tool UI
- T1685.004 β Disable or Modify Linux Audit System Log
- T1685.005 β Clear Windows Event Logs
- T1685.006 β Clear Linux or Mac System Logs
- T1686 β Disable or Modify System Firewall
- T1686.001 β Cloud Firewall
- T1686.002 β Network Device Firewall
- T1686.003 β Windows Host Firewall
- T1687 β Exploitation for Defense Impairment
- T1688 β Safe Mode Boot
- T1689 β Downgrade Attack
- T1690 β Prevent Command History Logging