Attacker techniques (ATT&CK)
697 pages, showing 201–300, ordered by identifier.
- T1114.002 — Remote Email Collection Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information....
- T1114.003 — Email Forwarding Rule Adversaries may setup email forwarding rules to collect sensitive information. Adversaries may abuse email...
- T1115 — Clipboard Data Adversaries may collect data stored in the clipboard from users copying information within or between applications.
- T1119 — Automated Collection Once established within a system or network, an adversary may use automated techniques for collecting internal data....
- T1120 — Peripheral Device Discovery Adversaries may attempt to gather information about attached peripheral devices and components connected to a...
- T1123 — Audio Capture An adversary can leverage a computer's peripheral devices (e.g., microphones and webcams) or applications (e.g.,...
- T1124 — System Time Discovery An adversary may gather the system time and/or time zone settings from a local or remote system. The system time is...
- T1125 — Video Capture An adversary can leverage a computer's peripheral devices (e.g., integrated cameras or webcams) or applications...
- T1127 — Trusted Developer Utilities Proxy Execution Adversaries may take advantage of trusted developer utilities to proxy execution of malicious payloads. There are...
- T1127.001 — MSBuild Adversaries may use MSBuild to proxy execution of code through a trusted Windows utility. MSBuild.exe (Microsoft...
- T1127.002 — ClickOnce Adversaries may use ClickOnce applications (.appref-ms and .application files) to proxy execution of code through a...
- T1127.003 — JamPlus Adversaries may use JamPlus to proxy the execution of a malicious script. JamPlus is a build utility tool for code...
- T1129 — Shared Modules Adversaries may execute malicious payloads via loading shared modules. Shared modules are executable files that are...
- T1132 — Data Encoding Adversaries may encode data to make the content of command and control traffic more difficult to detect. Command and...
- T1132.001 — Standard Encoding Adversaries may encode data with a standard data encoding system to make the content of command and control traffic...
- T1132.002 — Non-Standard Encoding Adversaries may encode data with a non-standard data encoding system to make the content of command and control...
- T1133 — External Remote Services Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote...
- T1134 — Access Token Manipulation Adversaries may modify access tokens to operate under a different user or system security context to perform actions...
- T1134.001 — Token Impersonation/Theft Adversaries may duplicate then impersonate another user's existing token to escalate privileges and bypass access...
- T1134.002 — Create Process with Token Adversaries may create a new process with an existing token to escalate privileges and bypass access controls....
- T1134.003 — Make and Impersonate Token Adversaries may make new tokens and impersonate users to escalate privileges and bypass access controls. For...
- T1134.004 — Parent PID Spoofing Adversaries may spoof the parent process identifier (PPID) of a new process to evade process-monitoring defenses or...
- T1134.005 — SID-History Injection Adversaries may use SID-History Injection to escalate privileges and bypass access controls. The Windows security...
- T1135 — Network Share Discovery Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of...
- T1136 — Create Account Adversaries may create an account to maintain access to victim systems. With a sufficient level of access, creating...
- T1136.001 — Local Account Adversaries may create a local account to maintain access to victim systems. Local accounts are those configured by...
- T1136.002 — Domain Account Adversaries may create a domain account to maintain access to victim systems. Domain accounts are those managed by...
- T1136.003 — Cloud Account Adversaries may create a cloud account to maintain access to victim systems. With a sufficient level of access, such...
- T1137 — Office Application Startup Adversaries may leverage Microsoft Office-based applications for persistence between startups. Microsoft Office is a...
- T1137.001 — Office Template Macros Adversaries may abuse Microsoft Office templates to obtain persistence on a compromised system. Microsoft Office...
- T1137.002 — Office Test Adversaries may abuse the Microsoft Office 'Office Test' Registry key to obtain persistence on a compromised system....
- T1137.003 — Outlook Forms Adversaries may abuse Microsoft Outlook forms to obtain persistence on a compromised system. Outlook forms are used...
- T1137.004 — Outlook Home Page Adversaries may abuse Microsoft Outlook's Home Page feature to obtain persistence on a compromised system. Outlook...
- T1137.005 — Outlook Rules Adversaries may abuse Microsoft Outlook rules to obtain persistence on a compromised system. Outlook rules allow a...
- T1137.006 — Add-ins Adversaries may abuse Microsoft Office add-ins to obtain persistence on a compromised system. Office add-ins can be...
- T1140 — Deobfuscate/Decode Files or Information Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. They may...
- T1176 — Software Extensions Adversaries may abuse software extensions to establish persistent access to victim systems. Software extensions are...
- T1176.001 — Browser Extensions Adversaries may abuse internet browser extensions to establish persistent access to victim systems. Browser...
- T1176.002 — IDE Extensions Adversaries may abuse an integrated development environment (IDE) extension to establish persistent access to victim...
- T1185 — Browser Session Hijacking Adversaries may take advantage of security vulnerabilities and inherent functionality in browser software to change...
- T1187 — Forced Authentication Adversaries may gather credential material by invoking or forcing a user to automatically provide authentication...
- T1189 — Drive-by Compromise Adversaries may gain access to a system through a user visiting a website over the normal course of browsing....
- T1190 — Exploit Public-Facing Application Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network....
- T1195 — Supply Chain Compromise Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the...
- T1195.001 — Compromise Software Dependencies and Development Tools Adversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the...
- T1195.002 — Compromise Software Supply Chain Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or...
- T1195.003 — Compromise Hardware Supply Chain Adversaries may manipulate hardware components in products prior to receipt by a final consumer for the purpose of...
- T1197 — BITS Jobs Adversaries may abuse BITS jobs to persistently execute code and perform various background tasks. Windows...
- T1199 — Trusted Relationship Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through...
- T1200 — Hardware Additions Adversaries may physically introduce computer accessories, networking hardware, or other computing devices into a...
- T1201 — Password Policy Discovery Adversaries may attempt to access detailed information about the password policy used within an enterprise network...
- T1202 — Indirect Command Execution Adversaries may abuse utilities that allow for command execution to bypass security restrictions that limit the use...
- T1203 — Exploitation for Client Execution Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist...
- T1204 — User Execution An adversary may rely upon specific actions by a user in order to gain execution. Users may be subjected to social...
- T1204.001 — Malicious Link An adversary may rely upon a user clicking a malicious link in order to gain execution. Users may be subjected to...
- T1204.002 — Malicious File An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to...
- T1204.003 — Malicious Image Adversaries may rely on a user running a malicious image to facilitate execution. Amazon Web Services (AWS) Amazon...
- T1204.004 — Malicious Copy and Paste An adversary may rely upon a user copying and pasting code in order to gain execution. Users may be subjected to...
- T1204.005 — Malicious Library Adversaries may rely on a user installing a malicious library to facilitate execution. Threat actors may Upload...
- T1205 — Traffic Signaling Adversaries may use traffic signaling to hide open ports or other malicious functionality used for persistence or...
- T1205.001 — Port Knocking Adversaries may use port knocking to hide open ports used for persistence or command and control. To enable a port,...
- T1205.002 — Socket Filters Adversaries may attach filters to a network socket to monitor then activate backdoors used for persistence or...
- T1207 — Rogue Domain Controller Adversaries may register a rogue Domain Controller to enable manipulation of Active Directory data. DCShadow may be...
- T1210 — Exploitation of Remote Services Adversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network....
- T1211 — Exploitation for Stealth Adversaries may exploit vulnerabilities to evade detection by hiding activity, suppressing logging, or operating...
- T1212 — Exploitation for Credential Access Adversaries may exploit software vulnerabilities in an attempt to collect credentials. Exploitation of a software...
- T1213 — Data from Information Repositories Adversaries may leverage information repositories to mine valuable information. Information repositories are tools...
- T1213.001 — Confluence Adversaries may leverage Confluence repositories to mine valuable information. Often found in development...
- T1213.002 — Sharepoint Adversaries may leverage the SharePoint repository as a source to mine valuable information. SharePoint will often...
- T1213.003 — Code Repositories Adversaries may leverage code repositories to collect valuable information. Code repositories are tools/services...
- T1213.004 — Customer Relationship Management Software Adversaries may leverage Customer Relationship Management (CRM) software to mine valuable information. CRM software...
- T1213.005 — Messaging Applications Adversaries may leverage chat and messaging applications, such as Microsoft Teams, Google Chat, and Slack, to mine...
- T1213.006 — Databases Adversaries may leverage databases to mine valuable information. These databases may be hosted on-premises or in the...
- T1216 — System Script Proxy Execution Adversaries may use trusted scripts, often signed with certificates, to proxy the execution of malicious files....
- T1216.001 — PubPrn Adversaries may use PubPrn to proxy execution of malicious remote files. PubPrn.vbs is a Visual Basic script that...
- T1216.002 — SyncAppvPublishingServer Adversaries may abuse SyncAppvPublishingServer.vbs to proxy execution of malicious PowerShell commands....
- T1217 — Browser Information Discovery Adversaries may enumerate information about browsers to learn more about compromised environments. Data saved by...
- T1218 — System Binary Proxy Execution Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with...
- T1218.001 — Compiled HTML File Adversaries may abuse Compiled HTML files (.chm) to conceal malicious code. CHM files are commonly distributed as...
- T1218.002 — Control Panel Adversaries may abuse control.exe to proxy execution of malicious payloads. The Windows Control Panel process binary...
- T1218.003 — CMSTP Adversaries may abuse CMSTP to proxy execution of malicious code. The Microsoft Connection Manager Profile Installer...
- T1218.004 — InstallUtil Adversaries may use InstallUtil to proxy execution of code through a trusted Windows utility. InstallUtil is a...
- T1218.005 — Mshta Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and Javascript or VBScript through a...
- T1218.007 — Msiexec Adversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility...
- T1218.008 — Odbcconf Adversaries may abuse odbcconf.exe to proxy execution of malicious payloads. Odbcconf.exe is a Windows utility that...
- T1218.009 — Regsvcs/Regasm Adversaries may abuse Regsvcs and Regasm to proxy execution of code through a trusted Windows utility. Regsvcs and...
- T1218.010 — Regsvr32 Adversaries may abuse Regsvr32.exe to proxy execution of malicious code. Regsvr32.exe is a command-line program used...
- T1218.011 — Rundll32 Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly...
- T1218.012 — Verclsid Adversaries may abuse verclsid.exe to proxy execution of malicious code. Verclsid.exe is known as the Extension...
- T1218.013 — Mavinject Adversaries may abuse mavinject.exe to proxy execution of malicious code. Mavinject.exe is the Microsoft Application...
- T1218.014 — MMC Adversaries may abuse mmc.exe to proxy execution of malicious .msc files. Microsoft Management Console (MMC) is a...
- T1218.015 — Electron Applications Adversaries may abuse components of the Electron framework to execute malicious code. The Electron framework hosts...
- T1219 — Remote Access Tools An adversary may use legitimate remote access tools to establish an interactive command and control channel within a...
- T1219.001 — IDE Tunneling Adversaries may abuse Integrated Development Environment (IDE) software with remote development features to...
- T1219.002 — Remote Desktop Software An adversary may use legitimate desktop support software to establish an interactive command and control channel to...
- T1219.003 — Remote Access Hardware An adversary may use legitimate remote access hardware to establish an interactive command and control channel to...
- T1220 — XSL Script Processing Adversaries may bypass application control and obscure execution of code by embedding scripts inside XSL files....
- T1221 — Template Injection Adversaries may create or modify references in user document templates to conceal malicious code or force...
- T1222 — File and Directory Permissions Modification Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access...
- T1222.001 — Windows Permissions Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access...
Browse by topic
Every page in the corpus, grouped. Search finds one page; this shows what else is here.