Attacker techniques (ATT&CK)
697 pages, showing 301–400, ordered by identifier.
- T1222.002 — Linux and Mac Permissions Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access...
- T1480 — Execution Guardrails Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and...
- T1480.001 — Environmental Keying Adversaries may environmentally key payloads or other features of malware to evade defenses and constraint execution...
- T1480.002 — Mutual Exclusion Adversaries may constrain execution or actions based on the presence of a mutex associated with malware. A mutex is...
- T1482 — Domain Trust Discovery Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral...
- T1484 — Domain or Tenant Policy Modification Adversaries may modify the configuration settings of a domain or identity tenant to evade defenses and/or escalate...
- T1484.001 — Group Policy Modification Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a...
- T1484.002 — Trust Modification Adversaries may add new domain trusts, modify the properties of existing domain trusts, or otherwise change the...
- T1485 — Data Destruction Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt...
- T1485.001 — Lifecycle-Triggered Deletion Adversaries may modify the lifecycle policies of a cloud storage bucket to destroy all objects stored within.
- T1486 — Data Encrypted for Impact Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability...
- T1489 — Service Stop Adversaries may stop or disable services on a system to render those services unavailable to legitimate users....
- T1490 — Inhibit System Recovery Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted...
- T1491 — Defacement Adversaries may modify visual content available internally or externally to an enterprise network, thus affecting...
- T1491.001 — Internal Defacement An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus...
- T1491.002 — External Defacement An adversary may deface systems external to an organization in an attempt to deliver messaging, intimidate, or...
- T1495 — Firmware Corruption Adversaries may overwrite or corrupt the flash memory contents of system BIOS or other firmware in devices attached...
- T1496 — Resource Hijacking Adversaries may leverage the resources of co-opted systems to complete resource-intensive tasks, which may impact...
- T1496.001 — Compute Hijacking Adversaries may leverage the compute resources of co-opted systems to complete resource-intensive tasks, which may...
- T1496.002 — Bandwidth Hijacking Adversaries may leverage the network bandwidth resources of co-opted systems to complete resource-intensive tasks,...
- T1496.003 — SMS Pumping Adversaries may leverage messaging services for SMS pumping, which may impact system and/or hosted service...
- T1496.004 — Cloud Service Hijacking Adversaries may leverage compromised software-as-a-service (SaaS) applications to complete resource-intensive tasks,...
- T1497 — Virtualization/Sandbox Evasion Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include...
- T1497.001 — System Checks Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may...
- T1497.002 — User Activity Based Checks Adversaries may employ various user activity checks to detect and avoid virtualization and analysis environments....
- T1497.003 — Time Based Checks Adversaries may employ various time-based methods to detect virtualization and analysis environments, particularly...
- T1498 — Network Denial of Service Adversaries may perform Network Denial of Service (DoS) attacks to degrade or block the availability of targeted...
- T1498.001 — Direct Network Flood Adversaries may attempt to cause a denial of service (DoS) by directly sending a high-volume of network traffic to a...
- T1498.002 — Reflection Amplification Adversaries may attempt to cause a denial of service (DoS) by reflecting a high-volume of network traffic to a...
- T1499 — Endpoint Denial of Service Adversaries may perform Endpoint Denial of Service (DoS) attacks to degrade or block the availability of services to...
- T1499.001 — OS Exhaustion Flood Adversaries may launch a denial of service (DoS) attack targeting an endpoint's operating system (OS). A system's OS...
- T1499.002 — Service Exhaustion Flood Adversaries may target the different network services provided by systems to conduct a denial of service (DoS)....
- T1499.003 — Application Exhaustion Flood Adversaries may target resource intensive features of applications to cause a denial of service (DoS), denying...
- T1499.004 — Application or System Exploitation Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny...
- T1505 — Server Software Component Adversaries may abuse legitimate extensible development features of servers to establish persistent access to...
- T1505.001 — SQL Stored Procedures Adversaries may abuse SQL stored procedures to establish persistent access to systems. SQL Stored Procedures are...
- T1505.002 — Transport Agent Adversaries may abuse Microsoft transport agents to establish persistent access to systems. Microsoft Exchange...
- T1505.003 — Web Shell Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web...
- T1505.004 — IIS Components Adversaries may install malicious components that run on Internet Information Services (IIS) web servers to...
- T1505.005 — Terminal Services DLL Adversaries may abuse components of Terminal Services to enable persistent access to systems. Microsoft Terminal...
- T1505.006 — vSphere Installation Bundles Adversaries may abuse vSphere Installation Bundles (VIBs) to establish persistent access to ESXi hypervisors. VIBs...
- T1518 — Software Discovery Adversaries may attempt to get a listing of software and software versions that are installed on a system or in a...
- T1518.001 — Security Software Discovery Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are...
- T1518.002 — Backup Software Discovery Adversaries may attempt to get a listing of backup software or configurations that are installed on a system....
- T1525 — Implant Internal Image Adversaries may implant cloud or container images with malicious code to establish persistence after gaining access...
- T1526 — Cloud Service Discovery An adversary may attempt to enumerate the cloud services running on a system after gaining access. These methods can...
- T1528 — Steal Application Access Token Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.
- T1529 — System Shutdown/Reboot Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems....
- T1530 — Data from Cloud Storage Adversaries may access data from cloud storage.
- T1531 — Account Access Removal Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by...
- T1534 — Internal Spearphishing After they already have access to accounts or systems within the environment, adversaries may use internal...
- T1535 — Unused/Unsupported Cloud Regions Adversaries may create cloud instances in unused geographic service regions in order to evade detection. Access is...
- T1537 — Transfer Data to Cloud Account Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of...
- T1538 — Cloud Service Dashboard An adversary may use a cloud service dashboard GUI with stolen credentials to gain useful information from an...
- T1539 — Steal Web Session Cookie An adversary may steal web application or service session cookies and use them to gain access to web applications or...
- T1542 — Pre-OS Boot Adversaries may abuse Pre-OS Boot mechanisms as a way to establish persistence on a system. During the booting...
- T1542.001 — System Firmware Adversaries may modify system firmware to persist on systems.The BIOS (Basic Input/Output System) and The Unified...
- T1542.002 — Component Firmware Adversaries may modify component firmware to persist on systems. Some adversaries may employ sophisticated means to...
- T1542.003 — Bootkit Adversaries may use bootkits to persist on systems. A bootkit is a malware variant that modifies the boot sectors of...
- T1542.004 — ROMMONkit Adversaries may abuse the ROM Monitor (ROMMON) by loading an unauthorized firmware with adversary code to provide...
- T1542.005 — TFTP Boot Adversaries may abuse netbooting to load an unauthorized network device operating system from a Trivial File...
- T1543 — Create or Modify System Process Adversaries may create or modify system-level processes to repeatedly execute malicious payloads as part of...
- T1543.001 — Launch Agent Adversaries may create or modify launch agents to repeatedly execute malicious payloads as part of persistence. When...
- T1543.002 — Systemd Service Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence....
- T1543.003 — Windows Service Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence....
- T1543.004 — Launch Daemon Adversaries may create or modify Launch Daemons to execute malicious payloads as part of persistence. Launch Daemons...
- T1543.005 — Container Service Adversaries may create or modify container or container cluster management tools that run as daemons, agents, or...
- T1546 — Event Triggered Execution Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based...
- T1546.001 — Change Default File Association Adversaries may establish persistence by executing malicious content triggered by a file type association. When a...
- T1546.002 — Screensaver Adversaries may establish persistence by executing malicious content triggered by user inactivity. Screensavers are...
- T1546.003 — Windows Management Instrumentation Event Subscription Adversaries may establish persistence and elevate privileges by executing malicious content triggered by a Windows...
- T1546.004 — Unix Shell Configuration Modification Adversaries may establish persistence through executing malicious commands triggered by a user’s shell. User Unix...
- T1546.005 — Trap Adversaries may establish persistence by executing malicious content triggered by an interrupt signal. The...
- T1546.006 — LC_LOAD_DYLIB Addition Adversaries may establish persistence by executing malicious content triggered by the execution of tainted binaries....
- T1546.007 — Netsh Helper DLL Adversaries may establish persistence by executing malicious content triggered by Netsh Helper DLLs. Netsh.exe (also...
- T1546.008 — Accessibility Features Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by...
- T1546.009 — AppCert DLLs Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppCert...
- T1546.010 — AppInit DLLs Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppInit...
- T1546.011 — Application Shimming Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by...
- T1546.012 — Image File Execution Options Injection Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by Image...
- T1546.013 — PowerShell Profile Adversaries may gain persistence and elevate privileges by executing malicious content triggered by PowerShell...
- T1546.014 — Emond Adversaries may gain persistence and elevate privileges by executing malicious content triggered by the Event...
- T1546.015 — Component Object Model Hijacking Adversaries may establish persistence by executing malicious content triggered by hijacked references to Component...
- T1546.016 — Installer Packages Adversaries may establish persistence and elevate privileges by using an installer to trigger the execution of...
- T1546.017 — Udev Rules Adversaries may maintain persistence through executing malicious content triggered using udev rules. Udev is the...
- T1546.018 — Python Startup Hooks Adversaries may achieve persistence by leveraging Python’s startup mechanisms, including path configuration (.pth)...
- T1547 — Boot or Logon Autostart Execution Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain...
- T1547.001 — Registry Run Keys / Startup Folder Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run...
- T1547.002 — Authentication Package Adversaries may abuse authentication packages to execute DLLs when the system boots. Windows authentication package...
- T1547.003 — Time Providers Adversaries may abuse time providers to execute DLLs when the system boots. The Windows Time service (W32Time)...
- T1547.004 — Winlogon Helper DLL Adversaries may abuse features of Winlogon to execute DLLs and/or executables when a user logs in. Winlogon.exe is a...
- T1547.005 — Security Support Provider Adversaries may abuse security support providers (SSPs) to execute DLLs when the system boots. Windows SSP DLLs are...
- T1547.006 — Kernel Modules and Extensions Adversaries may modify the kernel to automatically execute programs on system boot. Loadable Kernel Modules (LKMs)...
- T1547.007 — Re-opened Applications Adversaries may modify plist files to automatically run an application when a user logs in. When a user logs out or...
- T1547.008 — LSASS Driver Adversaries may modify or add LSASS drivers to obtain persistence on compromised systems. The Windows security...
- T1547.009 — Shortcut Modification Adversaries may create or modify shortcuts that can execute a program during system boot or user login. Shortcuts or...
- T1547.010 — Port Monitors Adversaries may use port monitors to run an adversary supplied DLL during system boot for persistence or privilege...
- T1547.012 — Print Processors Adversaries may abuse print processors to run malicious DLLs during system boot for persistence and/or privilege...
- T1547.013 — XDG Autostart Entries Adversaries may add or modify XDG Autostart Entries to execute malicious programs or commands when a user’s desktop...
- T1547.014 — Active Setup Adversaries may achieve persistence by adding a Registry key to the Active Setup of the local machine. Active Setup...
Browse by topic
Every page in the corpus, grouped. Search finds one page; this shows what else is here.