Loading the archive…
Loading the archive…
500 techniques · MITRE ATT&CK
| ID | Name | Tactics |
|---|---|---|
| T1001 | Data Obfuscation | command-and-control |
| T1001.001 | Junk Data · sub | command-and-control |
| T1001.002 | Steganography · sub | command-and-control |
| T1001.003 | Protocol or Service Impersonation · sub | command-and-control |
| T1003 | OS Credential Dumping | credential-access |
| T1003.001 | LSASS Memory · sub | credential-access |
| T1003.002 | Security Account Manager · sub | credential-access |
| T1003.003 | NTDS · sub | credential-access |
| T1003.004 | LSA Secrets · sub | credential-access |
| T1003.005 | Cached Domain Credentials · sub | credential-access |
| T1003.006 | DCSync · sub | credential-access |
| T1003.007 | Proc Filesystem · sub | credential-access |
| T1003.008 | /etc/passwd and /etc/shadow · sub | credential-access |
| T1005 | Data from Local System | collection |
| T1006 | Direct Volume Access | stealth |
| T1007 | System Service Discovery | discovery |
| T1008 | Fallback Channels | command-and-control |
| T1010 | Application Window Discovery | discovery |
| T1011 | Exfiltration Over Other Network Medium | exfiltration |
| T1011.001 | Exfiltration Over Bluetooth · sub | exfiltration |
| T1012 | Query Registry | discovery |
| T1014 | Rootkit | stealth |
| T1016 | System Network Configuration Discovery | discovery |
| T1016.001 | Internet Connection Discovery · sub | discovery |
| T1016.002 | Wi-Fi Discovery · sub | discovery |
| T1018 | Remote System Discovery | discovery |
| T1020 | Automated Exfiltration | exfiltration |
| T1020.001 | Traffic Duplication · sub | exfiltration |
| T1021 | Remote Services | lateral-movement |
| T1021.001 | Remote Desktop Protocol · sub | lateral-movement |
| T1021.002 | SMB/Windows Admin Shares · sub | lateral-movement |
| T1021.003 | Distributed Component Object Model · sub | lateral-movement |
| T1021.004 | SSH · sub | lateral-movement |
| T1021.005 | VNC · sub | lateral-movement |
| T1021.006 | Windows Remote Management · sub | lateral-movement |
| T1021.007 | Cloud Services · sub | lateral-movement |
| T1021.008 | Direct Cloud VM Connections · sub | lateral-movement |
| T1025 | Data from Removable Media | collection |
| T1027 | Obfuscated Files or Information | stealth |
| T1027.001 | Binary Padding · sub | stealth |
| T1027.002 | Software Packing · sub | stealth |
| T1027.003 | Steganography · sub | stealth |
| T1027.004 | Compile After Delivery · sub | stealth |
| T1027.005 | Indicator Removal from Tools · sub | stealth |
| T1027.006 | HTML Smuggling · sub | stealth |
| T1027.007 | Dynamic API Resolution · sub | stealth |
| T1027.008 | Stripped Payloads · sub | stealth |
| T1027.009 | Embedded Payloads · sub | stealth |
| T1027.010 | Command Obfuscation · sub | stealth |
| T1027.011 | Fileless Storage · sub | stealth |
| T1027.012 | LNK Icon Smuggling · sub | stealth |
| T1027.013 | Encrypted/Encoded File · sub | stealth |
| T1027.014 | Polymorphic Code · sub | stealth |
| T1027.015 | Compression · sub | stealth |
| T1027.016 | Junk Code Insertion · sub | stealth |
| T1027.017 | SVG Smuggling · sub | stealth |
| T1027.018 | Invisible Unicode · sub | stealth |
| T1029 | Scheduled Transfer | exfiltration |
| T1030 | Data Transfer Size Limits | exfiltration |
| T1033 | System Owner/User Discovery | discovery |
| T1036 | Masquerading | stealth |
| T1036.001 | Invalid Code Signature · sub | stealth |
| T1036.002 | Right-to-Left Override · sub | stealth |
| T1036.003 | Rename Legitimate Utilities · sub | stealth |
| T1036.004 | Masquerade Task or Service · sub | stealth |
| T1036.005 | Match Legitimate Resource Name or Location · sub | stealth |
| T1036.006 | Space after Filename · sub | stealth |
| T1036.007 | Double File Extension · sub | stealth |
| T1036.008 | Masquerade File Type · sub | stealth |
| T1036.009 | Break Process Trees · sub | stealth |
| T1036.010 | Masquerade Account Name · sub | stealth |
| T1036.011 | Overwrite Process Arguments · sub | stealth |
| T1036.012 | Browser Fingerprint · sub | stealth |
| T1037 | Boot or Logon Initialization Scripts | persistence, privilege-escalation |
| T1037.001 | Logon Script (Windows) · sub | persistence, privilege-escalation |
| T1037.002 | Login Hook · sub | persistence, privilege-escalation |
| T1037.003 | Network Logon Script · sub | persistence, privilege-escalation |
| T1037.004 | RC Scripts · sub | persistence, privilege-escalation |
| T1037.005 | Startup Items · sub | persistence, privilege-escalation |
| T1039 | Data from Network Shared Drive | collection |
| T1040 | Network Sniffing | credential-access, discovery |
| T1041 | Exfiltration Over C2 Channel | exfiltration |
| T1046 | Network Service Discovery | discovery |
| T1047 | Windows Management Instrumentation | execution |
| T1048 | Exfiltration Over Alternative Protocol | exfiltration |
| T1048.001 | Exfiltration Over Symmetric Encrypted Non-C2 Protocol · sub | exfiltration |
| T1048.002 | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol · sub | exfiltration |
| T1048.003 | Exfiltration Over Unencrypted Non-C2 Protocol · sub | exfiltration |
| T1049 | System Network Connections Discovery | discovery |
| T1052 | Exfiltration Over Physical Medium | exfiltration |
| T1052.001 | Exfiltration over USB · sub | exfiltration |
| T1053 | Scheduled Task/Job | execution, persistence, privilege-escalation |
| T1053.002 | At · sub | execution, persistence, privilege-escalation |
| T1053.003 | Cron · sub | execution, persistence, privilege-escalation |
| T1053.005 | Scheduled Task · sub | execution, persistence, privilege-escalation |
| T1053.006 | Systemd Timers · sub | execution, persistence, privilege-escalation |
| T1053.007 | Container Orchestration Job · sub | execution, persistence, privilege-escalation |
| T1055 | Process Injection | stealth, privilege-escalation |
| T1055.001 | Dynamic-link Library Injection · sub | stealth, privilege-escalation |
| T1055.002 | Portable Executable Injection · sub | stealth, privilege-escalation |
| T1055.003 | Thread Execution Hijacking · sub | stealth, privilege-escalation |
| T1055.004 | Asynchronous Procedure Call · sub | stealth, privilege-escalation |
| T1055.005 | Thread Local Storage · sub | stealth, privilege-escalation |
| T1055.008 | Ptrace System Calls · sub | stealth, privilege-escalation |
| T1055.009 | Proc Memory · sub | stealth, privilege-escalation |
| T1055.011 | Extra Window Memory Injection · sub | stealth, privilege-escalation |
| T1055.012 | Process Hollowing · sub | stealth, privilege-escalation |
| T1055.013 | Process Doppelgänging · sub | stealth, privilege-escalation |
| T1055.014 | VDSO Hijacking · sub | stealth, privilege-escalation |
| T1055.015 | ListPlanting · sub | stealth, privilege-escalation |
| T1056 | Input Capture | collection, credential-access |
| T1056.001 | Keylogging · sub | collection, credential-access |
| T1056.002 | GUI Input Capture · sub | collection, credential-access |
| T1056.003 | Web Portal Capture · sub | collection, credential-access |
| T1056.004 | Credential API Hooking · sub | collection, credential-access |
| T1057 | Process Discovery | discovery |
| T1059 | Command and Scripting Interpreter | execution |
| T1059.001 | PowerShell · sub | execution |
| T1059.002 | AppleScript · sub | execution |
| T1059.003 | Windows Command Shell · sub | execution |
| T1059.004 | Unix Shell · sub | execution |
| T1059.005 | Visual Basic · sub | execution |
| T1059.006 | Python · sub | execution |
| T1059.007 | JavaScript · sub | execution |
| T1059.008 | Network Device CLI · sub | execution |
| T1059.009 | Cloud API · sub | execution |
| T1059.010 | AutoHotKey & AutoIT · sub | execution |
| T1059.011 | Lua · sub | execution |
| T1059.012 | Hypervisor CLI · sub | execution |
| T1059.013 | Container CLI/API · sub | execution |
| T1068 | Exploitation for Privilege Escalation | privilege-escalation |
| T1069 | Permission Groups Discovery | discovery |
| T1069.001 | Local Groups · sub | discovery |
| T1069.002 | Domain Groups · sub | discovery |
| T1069.003 | Cloud Groups · sub | discovery |
| T1070 | Indicator Removal | stealth |
| T1070.003 | Clear Command History · sub | stealth |
| T1070.004 | File Deletion · sub | stealth |
| T1070.005 | Network Share Connection Removal · sub | stealth |
| T1070.006 | Timestomp · sub | stealth |
| T1070.007 | Clear Network Connection History and Configurations · sub | stealth |
| T1070.008 | Clear Mailbox Data · sub | stealth |
| T1070.009 | Clear Persistence · sub | stealth |
| T1070.010 | Relocate Malware · sub | stealth |
| T1071 | Application Layer Protocol | command-and-control |
| T1071.001 | Web Protocols · sub | command-and-control |
| T1071.002 | File Transfer Protocols · sub | command-and-control |
| T1071.003 | Mail Protocols · sub | command-and-control |
| T1071.004 | DNS · sub | command-and-control |
| T1071.005 | Publish/Subscribe Protocols · sub | command-and-control |
| T1072 | Software Deployment Tools | execution, lateral-movement |
| T1074 | Data Staged | collection |
| T1074.001 | Local Data Staging · sub | collection |
| T1074.002 | Remote Data Staging · sub | collection |
| T1078 | Valid Accounts | stealth, persistence, privilege-escalation, initial-access |
| T1078.001 | Default Accounts · sub | stealth, persistence, privilege-escalation, initial-access |
| T1078.002 | Domain Accounts · sub | stealth, persistence, privilege-escalation, initial-access |
| T1078.003 | Local Accounts · sub | stealth, persistence, privilege-escalation, initial-access |
| T1078.004 | Cloud Accounts · sub | stealth, persistence, privilege-escalation, initial-access |
| T1080 | Taint Shared Content | lateral-movement |
| T1082 | System Information Discovery | discovery |
| T1083 | File and Directory Discovery | discovery |
| T1087 | Account Discovery | discovery |
| T1087.001 | Local Account · sub | discovery |
| T1087.002 | Domain Account · sub | discovery |
| T1087.003 | Email Account · sub | discovery |
| T1087.004 | Cloud Account · sub | discovery |
| T1090 | Proxy | command-and-control |
| T1090.001 | Internal Proxy · sub | command-and-control |
| T1090.002 | External Proxy · sub | command-and-control |
| T1090.003 | Multi-hop Proxy · sub | command-and-control |
| T1090.004 | Domain Fronting · sub | command-and-control |
| T1091 | Replication Through Removable Media | lateral-movement, initial-access |
| T1092 | Communication Through Removable Media | command-and-control |
| T1095 | Non-Application Layer Protocol | command-and-control |
| T1098 | Account Manipulation | persistence, privilege-escalation |
| T1098.001 | Additional Cloud Credentials · sub | persistence, privilege-escalation |
| T1098.002 | Additional Email Delegate Permissions · sub | persistence, privilege-escalation |
| T1098.003 | Additional Cloud Roles · sub | persistence, privilege-escalation |
| T1098.004 | SSH Authorized Keys · sub | persistence, privilege-escalation |
| T1098.005 | Device Registration · sub | persistence, privilege-escalation |
| T1098.006 | Additional Container Cluster Roles · sub | persistence, privilege-escalation |
| T1098.007 | Additional Local or Domain Groups · sub | persistence, privilege-escalation |
| T1102 | Web Service | command-and-control |
| T1102.001 | Dead Drop Resolver · sub | command-and-control |
| T1102.002 | Bidirectional Communication · sub | command-and-control |
| T1102.003 | One-Way Communication · sub | command-and-control |
| T1104 | Multi-Stage Channels | command-and-control |
| T1105 | Ingress Tool Transfer | command-and-control |
| T1106 | Native API | execution |
| T1110 | Brute Force | credential-access |
| T1110.001 | Password Guessing · sub | credential-access |
| T1110.002 | Password Cracking · sub | credential-access |
| T1110.003 | Password Spraying · sub | credential-access |
| T1110.004 | Credential Stuffing · sub | credential-access |
| T1111 | Multi-Factor Authentication Interception | credential-access |
| T1112 | Modify Registry | defense-impairment, persistence |
| T1113 | Screen Capture | collection |
| T1114 | Email Collection | collection |
| T1114.001 | Local Email Collection · sub | collection |
| T1114.002 | Remote Email Collection · sub | collection |
| T1114.003 | Email Forwarding Rule · sub | collection |
| T1115 | Clipboard Data | collection |
| T1119 | Automated Collection | collection |
| T1120 | Peripheral Device Discovery | discovery |
| T1123 | Audio Capture | collection |
| T1124 | System Time Discovery | discovery |
| T1125 | Video Capture | collection |
| T1127 | Trusted Developer Utilities Proxy Execution | stealth, execution |
| T1127.001 | MSBuild · sub | stealth, execution |
| T1127.002 | ClickOnce · sub | stealth, execution |
| T1127.003 | JamPlus · sub | stealth, execution |
| T1129 | Shared Modules | execution |
| T1132 | Data Encoding | command-and-control |
| T1132.001 | Standard Encoding · sub | command-and-control |
| T1132.002 | Non-Standard Encoding · sub | command-and-control |
| T1133 | External Remote Services | persistence, initial-access |
| T1134 | Access Token Manipulation | stealth, privilege-escalation |
| T1134.001 | Token Impersonation/Theft · sub | stealth, privilege-escalation |
| T1134.002 | Create Process with Token · sub | stealth, privilege-escalation |
| T1134.003 | Make and Impersonate Token · sub | stealth, privilege-escalation |
| T1134.004 | Parent PID Spoofing · sub | stealth, privilege-escalation |
| T1134.005 | SID-History Injection · sub | stealth, privilege-escalation |
| T1135 | Network Share Discovery | discovery |
| T1136 | Create Account | persistence |
| T1136.001 | Local Account · sub | persistence |
| T1136.002 | Domain Account · sub | persistence |
| T1136.003 | Cloud Account · sub | persistence |
| T1137 | Office Application Startup | persistence |
| T1137.001 | Office Template Macros · sub | persistence |
| T1137.002 | Office Test · sub | persistence |
| T1137.003 | Outlook Forms · sub | persistence |
| T1137.004 | Outlook Home Page · sub | persistence |
| T1137.005 | Outlook Rules · sub | persistence |
| T1137.006 | Add-ins · sub | persistence |
| T1140 | Deobfuscate/Decode Files or Information | stealth |
| T1176 | Software Extensions | persistence |
| T1176.001 | Browser Extensions · sub | persistence |
| T1176.002 | IDE Extensions · sub | persistence |
| T1185 | Browser Session Hijacking | collection |
| T1187 | Forced Authentication | credential-access |
| T1189 | Drive-by Compromise | initial-access |
| T1190 | Exploit Public-Facing Application | initial-access |
| T1195 | Supply Chain Compromise | initial-access |
| T1195.001 | Compromise Software Dependencies and Development Tools · sub | initial-access |
| T1195.002 | Compromise Software Supply Chain · sub | initial-access |
| T1195.003 | Compromise Hardware Supply Chain · sub | initial-access |
| T1197 | BITS Jobs | stealth, persistence, execution |
| T1199 | Trusted Relationship | initial-access |
| T1200 | Hardware Additions | initial-access |
| T1201 | Password Policy Discovery | discovery |
| T1202 | Indirect Command Execution | stealth |
| T1203 | Exploitation for Client Execution | execution |
| T1204 | User Execution | execution |
| T1204.001 | Malicious Link · sub | execution |
| T1204.002 | Malicious File · sub | execution |
| T1204.003 | Malicious Image · sub | execution |
| T1204.004 | Malicious Copy and Paste · sub | execution |
| T1204.005 | Malicious Library · sub | execution |
| T1205 | Traffic Signaling | stealth, persistence, command-and-control |
| T1205.001 | Port Knocking · sub | stealth, persistence, command-and-control |
| T1205.002 | Socket Filters · sub | stealth, persistence, command-and-control |
| T1207 | Rogue Domain Controller | defense-impairment |
| T1210 | Exploitation of Remote Services | lateral-movement |
| T1211 | Exploitation for Stealth | stealth |
| T1212 | Exploitation for Credential Access | credential-access |
| T1213 | Data from Information Repositories | collection |
| T1213.001 | Confluence · sub | collection |
| T1213.002 | Sharepoint · sub | collection |
| T1213.003 | Code Repositories · sub | collection |
| T1213.004 | Customer Relationship Management Software · sub | collection |
| T1213.005 | Messaging Applications · sub | collection |
| T1213.006 | Databases · sub | collection |
| T1216 | System Script Proxy Execution | stealth |
| T1216.001 | PubPrn · sub | stealth |
| T1216.002 | SyncAppvPublishingServer · sub | stealth |
| T1217 | Browser Information Discovery | discovery |
| T1218 | System Binary Proxy Execution | stealth |
| T1218.001 | Compiled HTML File · sub | stealth |
| T1218.002 | Control Panel · sub | stealth |
| T1218.003 | CMSTP · sub | stealth |
| T1218.004 | InstallUtil · sub | stealth |
| T1218.005 | Mshta · sub | stealth |
| T1218.007 | Msiexec · sub | stealth |
| T1218.008 | Odbcconf · sub | stealth |
| T1218.009 | Regsvcs/Regasm · sub | stealth |
| T1218.010 | Regsvr32 · sub | stealth |
| T1218.011 | Rundll32 · sub | stealth |
| T1218.012 | Verclsid · sub | stealth |
| T1218.013 | Mavinject · sub | stealth |
| T1218.014 | MMC · sub | stealth |
| T1218.015 | Electron Applications · sub | stealth |
| T1219 | Remote Access Tools | command-and-control |
| T1219.001 | IDE Tunneling · sub | command-and-control |
| T1219.002 | Remote Desktop Software · sub | command-and-control |
| T1219.003 | Remote Access Hardware · sub | command-and-control |
| T1220 | XSL Script Processing | stealth |
| T1221 | Template Injection | stealth |
| T1222 | File and Directory Permissions Modification | defense-impairment |
| T1222.001 | Windows Permissions · sub | defense-impairment |
| T1222.002 | Linux and Mac Permissions · sub | defense-impairment |
| T1480 | Execution Guardrails | stealth |
| T1480.001 | Environmental Keying · sub | stealth |
| T1480.002 | Mutual Exclusion · sub | stealth |
| T1482 | Domain Trust Discovery | discovery |
| T1484 | Domain or Tenant Policy Modification | defense-impairment, privilege-escalation |
| T1484.001 | Group Policy Modification · sub | defense-impairment, privilege-escalation |
| T1484.002 | Trust Modification · sub | defense-impairment, privilege-escalation |
| T1485 | Data Destruction | impact |
| T1485.001 | Lifecycle-Triggered Deletion · sub | impact |
| T1486 | Data Encrypted for Impact | impact |
| T1489 | Service Stop | impact |
| T1490 | Inhibit System Recovery | impact |
| T1491 | Defacement | impact |
| T1491.001 | Internal Defacement · sub | impact |
| T1491.002 | External Defacement · sub | impact |
| T1495 | Firmware Corruption | impact |
| T1496 | Resource Hijacking | impact |
| T1496.001 | Compute Hijacking · sub | impact |
| T1496.002 | Bandwidth Hijacking · sub | impact |
| T1496.003 | SMS Pumping · sub | impact |
| T1496.004 | Cloud Service Hijacking · sub | impact |
| T1497 | Virtualization/Sandbox Evasion | stealth, discovery |
| T1497.001 | System Checks · sub | stealth, discovery |
| T1497.002 | User Activity Based Checks · sub | stealth, discovery |
| T1497.003 | Time Based Checks · sub | stealth, discovery |
| T1498 | Network Denial of Service | impact |
| T1498.001 | Direct Network Flood · sub | impact |
| T1498.002 | Reflection Amplification · sub | impact |
| T1499 | Endpoint Denial of Service | impact |
| T1499.001 | OS Exhaustion Flood · sub | impact |
| T1499.002 | Service Exhaustion Flood · sub | impact |
| T1499.003 | Application Exhaustion Flood · sub | impact |
| T1499.004 | Application or System Exploitation · sub | impact |
| T1505 | Server Software Component | persistence |
| T1505.001 | SQL Stored Procedures · sub | persistence |
| T1505.002 | Transport Agent · sub | persistence |
| T1505.003 | Web Shell · sub | persistence |
| T1505.004 | IIS Components · sub | persistence |
| T1505.005 | Terminal Services DLL · sub | persistence |
| T1505.006 | vSphere Installation Bundles · sub | persistence |
| T1518 | Software Discovery | discovery |
| T1518.001 | Security Software Discovery · sub | discovery |
| T1518.002 | Backup Software Discovery · sub | discovery |
| T1525 | Implant Internal Image | persistence |
| T1526 | Cloud Service Discovery | discovery |
| T1528 | Steal Application Access Token | credential-access |
| T1529 | System Shutdown/Reboot | impact |
| T1530 | Data from Cloud Storage | collection |
| T1531 | Account Access Removal | impact |
| T1534 | Internal Spearphishing | lateral-movement |
| T1535 | Unused/Unsupported Cloud Regions | stealth |
| T1537 | Transfer Data to Cloud Account | exfiltration |
| T1538 | Cloud Service Dashboard | discovery |
| T1539 | Steal Web Session Cookie | credential-access |
| T1542 | Pre-OS Boot | stealth, persistence |
| T1542.001 | System Firmware · sub | stealth, persistence |
| T1542.002 | Component Firmware · sub | stealth, persistence |
| T1542.003 | Bootkit · sub | stealth, persistence |
| T1542.004 | ROMMONkit · sub | stealth, persistence |
| T1542.005 | TFTP Boot · sub | stealth, persistence |
| T1543 | Create or Modify System Process | persistence, privilege-escalation |
| T1543.001 | Launch Agent · sub | persistence, privilege-escalation |
| T1543.002 | Systemd Service · sub | persistence, privilege-escalation |
| T1543.003 | Windows Service · sub | persistence, privilege-escalation |
| T1543.004 | Launch Daemon · sub | persistence, privilege-escalation |
| T1543.005 | Container Service · sub | persistence, privilege-escalation |
| T1546 | Event Triggered Execution | privilege-escalation, persistence |
| T1546.001 | Change Default File Association · sub | privilege-escalation, persistence |
| T1546.002 | Screensaver · sub | privilege-escalation, persistence |
| T1546.003 | Windows Management Instrumentation Event Subscription · sub | privilege-escalation, persistence |
| T1546.004 | Unix Shell Configuration Modification · sub | privilege-escalation, persistence |
| T1546.005 | Trap · sub | privilege-escalation, persistence |
| T1546.006 | LC_LOAD_DYLIB Addition · sub | privilege-escalation, persistence |
| T1546.007 | Netsh Helper DLL · sub | privilege-escalation, persistence |
| T1546.008 | Accessibility Features · sub | privilege-escalation, persistence |
| T1546.009 | AppCert DLLs · sub | privilege-escalation, persistence |
| T1546.010 | AppInit DLLs · sub | privilege-escalation, persistence |
| T1546.011 | Application Shimming · sub | privilege-escalation, persistence |
| T1546.012 | Image File Execution Options Injection · sub | privilege-escalation, persistence |
| T1546.013 | PowerShell Profile · sub | privilege-escalation, persistence |
| T1546.014 | Emond · sub | privilege-escalation, persistence |
| T1546.015 | Component Object Model Hijacking · sub | privilege-escalation, persistence |
| T1546.016 | Installer Packages · sub | privilege-escalation, persistence |
| T1546.017 | Udev Rules · sub | persistence, privilege-escalation |
| T1546.018 | Python Startup Hooks · sub | persistence, privilege-escalation |
| T1547 | Boot or Logon Autostart Execution | persistence, privilege-escalation |
| T1547.001 | Registry Run Keys / Startup Folder · sub | persistence, privilege-escalation |
| T1547.002 | Authentication Package · sub | persistence, privilege-escalation |
| T1547.003 | Time Providers · sub | persistence, privilege-escalation |
| T1547.004 | Winlogon Helper DLL · sub | persistence, privilege-escalation |
| T1547.005 | Security Support Provider · sub | persistence, privilege-escalation |
| T1547.006 | Kernel Modules and Extensions · sub | persistence, privilege-escalation |
| T1547.007 | Re-opened Applications · sub | persistence, privilege-escalation |
| T1547.008 | LSASS Driver · sub | persistence, privilege-escalation |
| T1547.009 | Shortcut Modification · sub | persistence, privilege-escalation |
| T1547.010 | Port Monitors · sub | persistence, privilege-escalation |
| T1547.012 | Print Processors · sub | persistence, privilege-escalation |
| T1547.013 | XDG Autostart Entries · sub | persistence, privilege-escalation |
| T1547.014 | Active Setup · sub | persistence, privilege-escalation |
| T1547.015 | Login Items · sub | persistence, privilege-escalation |
| T1548 | Abuse Elevation Control Mechanism | privilege-escalation |
| T1548.001 | Setuid and Setgid · sub | privilege-escalation |
| T1548.002 | Bypass User Account Control · sub | privilege-escalation |
| T1548.003 | Sudo and Sudo Caching · sub | privilege-escalation |
| T1548.004 | Elevated Execution with Prompt · sub | privilege-escalation |
| T1548.005 | Temporary Elevated Cloud Access · sub | privilege-escalation |
| T1548.006 | TCC Manipulation · sub | privilege-escalation |
| T1550 | Use Alternate Authentication Material | lateral-movement |
| T1550.001 | Application Access Token · sub | lateral-movement |
| T1550.002 | Pass the Hash · sub | lateral-movement |
| T1550.003 | Pass the Ticket · sub | lateral-movement |
| T1550.004 | Web Session Cookie · sub | lateral-movement |
| T1552 | Unsecured Credentials | credential-access |
| T1552.001 | Credentials In Files · sub | credential-access |
| T1552.002 | Credentials in Registry · sub | credential-access |
| T1552.003 | Shell History · sub | credential-access |
| T1552.004 | Private Keys · sub | credential-access |
| T1552.005 | Cloud Instance Metadata API · sub | credential-access |
| T1552.006 | Group Policy Preferences · sub | credential-access |
| T1552.007 | Container API · sub | credential-access |
| T1552.008 | Chat Messages · sub | credential-access |
| T1553 | Subvert Trust Controls | defense-impairment |
| T1553.001 | Gatekeeper Bypass · sub | defense-impairment |
| T1553.002 | Code Signing · sub | defense-impairment |
| T1553.003 | SIP and Trust Provider Hijacking · sub | defense-impairment |
| T1553.004 | Install Root Certificate · sub | defense-impairment |
| T1553.005 | Mark-of-the-Web Bypass · sub | defense-impairment |
| T1553.006 | Code Signing Policy Modification · sub | defense-impairment |
| T1554 | Compromise Host Software Binary | persistence |
| T1555 | Credentials from Password Stores | credential-access |
| T1555.001 | Keychain · sub | credential-access |
| T1555.002 | Securityd Memory · sub | credential-access |
| T1555.003 | Credentials from Web Browsers · sub | credential-access |
| T1555.004 | Windows Credential Manager · sub | credential-access |
| T1555.005 | Password Managers · sub | credential-access |
| T1555.006 | Cloud Secrets Management Stores · sub | credential-access |
| T1556 | Modify Authentication Process | defense-impairment, persistence, credential-access |
| T1556.001 | Domain Controller Authentication · sub | defense-impairment, persistence, credential-access |
| T1556.002 | Password Filter DLL · sub | defense-impairment, persistence, credential-access |
| T1556.003 | Pluggable Authentication Modules · sub | defense-impairment, persistence, credential-access |
| T1556.004 | Network Device Authentication · sub | defense-impairment, persistence, credential-access |
| T1556.005 | Reversible Encryption · sub | defense-impairment, persistence, credential-access |
| T1556.006 | Multi-Factor Authentication · sub | defense-impairment, persistence, credential-access |
| T1556.007 | Hybrid Identity · sub | defense-impairment, persistence, credential-access |
| T1556.008 | Network Provider DLL · sub | defense-impairment, persistence, credential-access |
| T1556.009 | Conditional Access Policies · sub | defense-impairment, persistence, credential-access |
| T1557 | Adversary-in-the-Middle | credential-access, collection |
| T1557.001 | Name Resolution Poisoning and SMB Relay · sub | credential-access, collection |
| T1557.002 | ARP Cache Poisoning · sub | credential-access, collection |
| T1557.003 | DHCP Spoofing · sub | credential-access, collection |
| T1557.004 | Evil Twin · sub | credential-access, collection |
| T1558 | Steal or Forge Kerberos Tickets | credential-access |
| T1558.001 | Golden Ticket · sub | credential-access |
| T1558.002 | Silver Ticket · sub | credential-access |
| T1558.003 | Kerberoasting · sub | credential-access |
| T1558.004 | AS-REP Roasting · sub | credential-access |
| T1558.005 | Ccache Files · sub | credential-access |
| T1559 | Inter-Process Communication | execution |
| T1559.001 | Component Object Model · sub | execution |
| T1559.002 | Dynamic Data Exchange · sub | execution |
| T1559.003 | XPC Services · sub | execution |
| T1560 | Archive Collected Data | collection |
| T1560.001 | Archive via Utility · sub | collection |
| T1560.002 | Archive via Library · sub | collection |
| T1560.003 | Archive via Custom Method · sub | collection |
| T1561 | Disk Wipe | impact |
| T1561.001 | Disk Content Wipe · sub | impact |
| T1561.002 | Disk Structure Wipe · sub | impact |
| T1563 | Remote Service Session Hijacking | lateral-movement |
| T1563.001 | SSH Hijacking · sub | lateral-movement |
| T1563.002 | RDP Hijacking · sub | lateral-movement |
| T1564 | Hide Artifacts | stealth |
| T1564.001 | Hidden Files and Directories · sub | stealth |
| T1564.002 | Hidden Users · sub | stealth |
| T1564.003 | Hidden Window · sub | stealth |
| T1564.004 | NTFS File Attributes · sub | stealth |
| T1564.005 | Hidden File System · sub | stealth |
| T1564.006 | Run Virtual Instance · sub | stealth |
| T1564.007 | VBA Stomping · sub | stealth |
| T1564.008 | Email Hiding Rules · sub | stealth |
| T1564.009 | Resource Forking · sub | stealth |
| T1564.010 | Process Argument Spoofing · sub | stealth |
| T1564.011 | Ignore Process Interrupts · sub | stealth |
| T1564.012 | File/Path Exclusions · sub | stealth |
| T1564.013 | Bind Mounts · sub | stealth |
| T1564.014 | Extended Attributes · sub | stealth |
| T1565 | Data Manipulation | impact |
| T1565.001 | Stored Data Manipulation · sub | impact |
| T1565.002 | Transmitted Data Manipulation · sub | impact |
| T1565.003 | Runtime Data Manipulation · sub | impact |
| T1566 | Phishing | initial-access |
| T1566.001 | Spearphishing Attachment · sub | initial-access |
| T1566.002 | Spearphishing Link · sub | initial-access |
| T1566.003 | Spearphishing via Service · sub | initial-access |
| T1566.004 | Spearphishing Voice · sub | initial-access |
| T1567 | Exfiltration Over Web Service | exfiltration |
| T1567.001 | Exfiltration to Code Repository · sub | exfiltration |
| T1567.002 | Exfiltration to Cloud Storage · sub | exfiltration |
| T1567.003 | Exfiltration to Text Storage Sites · sub | exfiltration |