Skip to content

by technique

MITRE ATT&CK techniques

108 techniques and sub-techniques used by the 8 profiled groups, grouped by tactic. Techniques shared by several groups are good candidates for detection priorities.

Most shared techniques

Used by three or more of the profiled groups.

  1. T1059.001 Command and Scripting Interpreter: PowerShell 8 groups
  2. T1566.001 Phishing: Spearphishing Attachment 7 groups
  3. T1053.005 Scheduled Task/Job: Scheduled Task 6 groups
  4. T1190 Exploit Public-Facing Application 6 groups
  5. T1003.001 OS Credential Dumping: LSASS Memory 5 groups
  6. T1566.002 Phishing: Spearphishing Link 5 groups
  7. T1047 Windows Management Instrumentation 4 groups
  8. T1059.005 Command and Scripting Interpreter: Visual Basic 4 groups
  9. T1102.002 Web Service: Bidirectional Communication 4 groups
  10. T1133 External Remote Services 4 groups

Reconnaissance

Resource Development

Initial Access

Execution

Persistence

Privilege Escalation

Stealth

Defense Impairment

Credential Access

Discovery

Lateral Movement

Collection

Command and Control

Exfiltration

Impact