- Home
- Techniques
by technique
MITRE ATT&CK techniques
108 techniques and sub-techniques used by the 8 profiled groups, grouped by tactic. Techniques shared by several groups are good candidates for detection priorities.
Most shared techniques
Used by three or more of the profiled groups.
- T1059.001 Command and Scripting Interpreter: PowerShell 8 groups
- T1566.001 Phishing: Spearphishing Attachment 7 groups
- T1053.005 Scheduled Task/Job: Scheduled Task 6 groups
- T1190 Exploit Public-Facing Application 6 groups
- T1003.001 OS Credential Dumping: LSASS Memory 5 groups
- T1566.002 Phishing: Spearphishing Link 5 groups
- T1047 Windows Management Instrumentation 4 groups
- T1059.005 Command and Scripting Interpreter: Visual Basic 4 groups
- T1102.002 Web Service: Bidirectional Communication 4 groups
- T1133 External Remote Services 4 groups
Reconnaissance
Resource Development
- T1583.001
Acquire Infrastructure: Domains
- T1583.006
Acquire Infrastructure: Web Services
- T1585.001
Establish Accounts: Social Media Accounts
- T1585.002
Establish Accounts: Email Accounts
- T1586.002
Compromise Accounts: Email Accounts
- T1587.001
Develop Capabilities: Malware
- T1588.001
Obtain Capabilities: Malware
- T1588.002
Obtain Capabilities: Tool
Initial Access
- T1566.001
Phishing: Spearphishing Attachment
- T1190
Exploit Public-Facing Application
- T1566.002
Phishing: Spearphishing Link
- T1133
External Remote Services
- T1195.002
Supply Chain Compromise: Compromise Software Supply Chain
- T1078.004
Valid Accounts: Cloud Accounts
- T1566.003
Phishing: Spearphishing via Service
- T1078
Valid Accounts
- T1078.002
Valid Accounts: Domain Accounts
- T1199
Trusted Relationship
- T1669
Wi-Fi Networks
Execution
- T1059.001
Command and Scripting Interpreter: PowerShell
- T1053.005
Scheduled Task/Job: Scheduled Task
- T1047
Windows Management Instrumentation
- T1059.005
Command and Scripting Interpreter: Visual Basic
- T1204.002
User Execution: Malicious File
- T1574.001
Hijack Execution Flow: DLL
- T1204.004
User Execution: Malicious Copy and Paste
- T1059.007
Command and Scripting Interpreter: JavaScript
- T1203
Exploitation for Client Execution
- T1204.001
User Execution: Malicious Link
Persistence
- T1547.001
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
- T1505.003
Server Software Component: Web Shell
- T1098.001
Account Manipulation: Additional Cloud Credentials
- T1098.002
Account Manipulation: Additional Email Delegate Permissions
- T1137.002
Office Application Startup: Office Test
- T1176.001
Software Extensions: Browser Extensions
- T1542.003
Pre-OS Boot: Bootkit
- T1543.002
Create or Modify System Process: Systemd Service
- T1543.003
Create or Modify System Process: Windows Service
- T1546.003
Event Triggered Execution: Windows Management Instrumentation Event Subscription
- T1556.007
Modify Authentication Process: Hybrid Identity
Privilege Escalation
- T1055.012
Process Injection: Process Hollowing
- T1068
Exploitation for Privilege Escalation
- T1484.001
Domain or Tenant Policy Modification: Group Policy Modification
- T1484.002
Domain or Tenant Policy Modification: Trust Modification
- T1548.002
Abuse Elevation Control Mechanism: Bypass User Account Control
Stealth
- T1070.004
Indicator Removal: File Deletion
- T1027.003
Obfuscated Files or Information: Steganography
- T1027.006
Obfuscated Files or Information: HTML Smuggling
- T1027.010
Obfuscated Files or Information: Command Obfuscation
- T1027.013
Obfuscated Files or Information: Encrypted/Encoded File
- T1036.004
Masquerading: Masquerade Task or Service
- T1036.007
Masquerading: Double File Extension
- T1218.005
System Binary Proxy Execution: Mshta
- T1218.011
System Binary Proxy Execution: Rundll32
- T1221
Template Injection
- T1480
Execution Guardrails
- T1684.001
Social Engineering: Impersonation
Defense Impairment
- T1553.002
Subvert Trust Controls: Code Signing
Credential Access
- T1003.001
OS Credential Dumping: LSASS Memory
- T1110.003
Brute Force: Password Spraying
- T1003.003
OS Credential Dumping: NTDS
- T1539
Steal Web Session Cookie
- T1555.003
Credentials from Password Stores: Credentials from Web Browsers
- T1003.006
OS Credential Dumping: DCSync
- T1040
Network Sniffing
- T1056.001
Input Capture: Keylogging
- T1557.004
Adversary-in-the-Middle: Evil Twin
- T1558.003
Steal or Forge Kerberos Tickets: Kerberoasting
- T1606.002
Forge Web Credentials: SAML Tokens
- T1621
Multi-Factor Authentication Request Generation
Discovery
Lateral Movement
Collection
Command and Control
- T1102.002
Web Service: Bidirectional Communication
- T1071.001
Application Layer Protocol: Web Protocols
- T1105
Ingress Tool Transfer
- T1219.002
Remote Access Tools: Remote Desktop Software
- T1090
Proxy
- T1090.002
Proxy: External Proxy
- T1090.003
Proxy: Multi-hop Proxy
- T1090.004
Proxy: Domain Fronting
- T1102.001
Web Service: Dead Drop Resolver
- T1219
Remote Access Tools
- T1568
Dynamic Resolution
- T1571
Non-Standard Port
- T1572
Protocol Tunneling
- T1665
Hide Infrastructure