Attacker techniques (ATT&CK)
697 pages, showing 401–500, ordered by identifier.
- T1547.015 — Login Items Adversaries may add login items to execute upon user login to gain persistence or escalate privileges. Login items...
- T1548 — Abuse Elevation Control Mechanism Adversaries may circumvent mechanisms designed to control privilege elevation to gain higher-level permissions. Most...
- T1548.001 — Setuid and Setgid An adversary may abuse configurations where an application has the setuid or setgid bits set in order to get code...
- T1548.002 — Bypass User Account Control Adversaries may bypass UAC mechanisms to elevate process privileges on system. Windows User Account Control (UAC)...
- T1548.003 — Sudo and Sudo Caching Adversaries may perform sudo caching and/or use the sudoers file to elevate privileges. Adversaries may do this to...
- T1548.004 — Elevated Execution with Prompt Adversaries may leverage the <code>AuthorizationExecuteWithPrivileges</code> API to escalate privileges by prompting...
- T1548.005 — Temporary Elevated Cloud Access Adversaries may abuse permission configurations that allow them to gain temporarily elevated access to cloud...
- T1548.006 — TCC Manipulation Adversaries can manipulate or abuse the Transparency, Consent, & Control (TCC) service or database to grant...
- T1550 — Use Alternate Authentication Material Adversaries may use alternate authentication material, such as password hashes, Kerberos tickets, and application...
- T1550.001 — Application Access Token Adversaries may use stolen application access tokens to bypass the typical authentication process and access...
- T1550.002 — Pass the Hash Adversaries may “pass the hash” using stolen password hashes to move laterally within an environment, bypassing...
- T1550.003 — Pass the Ticket Adversaries may “pass the ticket” using stolen Kerberos tickets to move laterally within an environment, bypassing...
- T1550.004 — Web Session Cookie Adversaries can use stolen session cookies to authenticate to web applications and services. This technique bypasses...
- T1552 — Unsecured Credentials Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can...
- T1552.001 — Credentials In Files Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials....
- T1552.002 — Credentials in Registry Adversaries may search the Registry on compromised systems for insecurely stored credentials. The Windows Registry...
- T1552.003 — Shell History Adversaries may search the command history on compromised systems for insecurely stored credentials.
- T1552.004 — Private Keys Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials....
- T1552.005 — Cloud Instance Metadata API Adversaries may attempt to access the Cloud Instance Metadata API to collect credentials and other sensitive data.
- T1552.006 — Group Policy Preferences Adversaries may attempt to find unsecured credentials in Group Policy Preferences (GPP). GPP are tools that allow...
- T1552.007 — Container API Adversaries may gather credentials via APIs within a containers environment. APIs in these environments, such as the...
- T1552.008 — Chat Messages Adversaries may directly collect unsecured credentials stored or passed through user communication services....
- T1553 — Subvert Trust Controls Adversaries may undermine security controls that will either warn users of untrusted activity or prevent execution...
- T1553.001 — Gatekeeper Bypass Adversaries may modify file attributes and subvert Gatekeeper functionality to evade user prompts and execute...
- T1553.002 — Code Signing Adversaries may create, acquire, or steal code signing materials to sign their malware or tools. Code signing...
- T1553.003 — SIP and Trust Provider Hijacking Adversaries may tamper with SIP and trust provider components to mislead the operating system and application...
- T1553.004 — Install Root Certificate Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary...
- T1553.005 — Mark-of-the-Web Bypass Adversaries may abuse specific file formats to subvert Mark-of-the-Web (MOTW) controls. In Windows, when files are...
- T1553.006 — Code Signing Policy Modification Adversaries may modify code signing policies to enable execution of unsigned or self-signed code. Code signing...
- T1554 — Compromise Host Software Binary Adversaries may modify host software binaries to establish persistent access to systems. Software...
- T1555 — Credentials from Password Stores Adversaries may search for common password storage locations to obtain user credentials. Passwords are stored in...
- T1555.001 — Keychain Adversaries may acquire credentials from Keychain. Keychain (or Keychain Services) is the macOS credential...
- T1555.002 — Securityd Memory An adversary with root access may gather credentials by reading securityd’s memory. securityd is a service/daemon...
- T1555.003 — Credentials from Web Browsers Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers...
- T1555.004 — Windows Credential Manager Adversaries may acquire credentials from the Windows Credential Manager. The Credential Manager stores credentials...
- T1555.005 — Password Managers Adversaries may acquire user credentials from third-party password managers. Password managers are applications...
- T1555.006 — Cloud Secrets Management Stores Adversaries may acquire credentials from cloud-native secret management solutions such as AWS Secrets Manager, GCP...
- T1556 — Modify Authentication Process Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise...
- T1556.001 — Domain Controller Authentication Adversaries may patch the authentication process on a domain controller to bypass the typical authentication...
- T1556.002 — Password Filter DLL Adversaries may register malicious password filter dynamic link libraries (DLLs) into the authentication process to...
- T1556.003 — Pluggable Authentication Modules Adversaries may modify pluggable authentication modules (PAM) to access user credentials or enable otherwise...
- T1556.004 — Network Device Authentication Adversaries may use Patch System Image to hard code a password in the operating system, thus bypassing of native...
- T1556.005 — Reversible Encryption An adversary may abuse Active Directory authentication encryption properties to gain access to credentials on...
- T1556.006 — Multi-Factor Authentication Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to...
- T1556.007 — Hybrid Identity Adversaries may patch, modify, or otherwise backdoor cloud authentication processes that are tied to on-premises...
- T1556.008 — Network Provider DLL Adversaries may register malicious network provider dynamic link libraries (DLLs) to capture cleartext user...
- T1556.009 — Conditional Access Policies Adversaries may disable or modify conditional access policies to enable persistent access to compromised accounts....
- T1557 — Adversary-in-the-Middle Adversaries may attempt to position themselves between two or more networked devices using an...
- T1557.001 — Name Resolution Poisoning and SMB Relay By responding to LLMNR/NBT-NS/mDNS network traffic, adversaries may spoof an authoritative source for name...
- T1557.002 — ARP Cache Poisoning Adversaries may poison Address Resolution Protocol (ARP) caches to position themselves between the communication of...
- T1557.003 — DHCP Spoofing Adversaries may redirect network traffic to adversary-owned systems by spoofing Dynamic Host Configuration Protocol...
- T1557.004 — Evil Twin Adversaries may host seemingly genuine Wi-Fi access points to deceive users into connecting to malicious networks as...
- T1558 — Steal or Forge Kerberos Tickets Adversaries may attempt to subvert Kerberos authentication by stealing or forging Kerberos tickets to enable Pass...
- T1558.001 — Golden Ticket Adversaries who have the KRBTGT account password hash may forge Kerberos ticket-granting tickets (TGT), also known...
- T1558.002 — Silver Ticket Adversaries who have the password hash of a target service account (e.g. SharePoint, MSSQL) may forge Kerberos...
- T1558.003 — Kerberoasting Adversaries may abuse a valid Kerberos ticket-granting ticket (TGT) or sniff network traffic to obtain a...
- T1558.004 — AS-REP Roasting Adversaries may reveal credentials of accounts that have disabled Kerberos preauthentication by Password Cracking...
- T1558.005 — Ccache Files Adversaries may attempt to steal Kerberos tickets stored in credential cache files (or ccache). These files are used...
- T1559 — Inter-Process Communication Adversaries may abuse inter-process communication (IPC) mechanisms for local code or command execution. IPC is...
- T1559.001 — Component Object Model Adversaries may use the Windows Component Object Model (COM) for local code execution. COM is an inter-process...
- T1559.002 — Dynamic Data Exchange Adversaries may use Windows Dynamic Data Exchange (DDE) to execute arbitrary commands. DDE is a client-server...
- T1559.003 — XPC Services Adversaries can provide malicious content to an XPC service daemon for local code execution. macOS uses XPC services...
- T1560 — Archive Collected Data An adversary may compress and/or encrypt data that is collected prior to exfiltration. Compressing the data can help...
- T1560.001 — Archive via Utility Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration. Many utilities...
- T1560.002 — Archive via Library An adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party libraries. Many...
- T1560.003 — Archive via Custom Method An adversary may compress or encrypt data that is collected prior to exfiltration using a custom method. Adversaries...
- T1561 — Disk Wipe Adversaries may wipe or corrupt raw disk data on specific systems or in large numbers in a network to interrupt...
- T1561.001 — Disk Content Wipe Adversaries may erase the contents of storage devices on specific systems or in large numbers in a network to...
- T1561.002 — Disk Structure Wipe Adversaries may corrupt or wipe the disk data structures on a hard drive necessary to boot a system; targeting...
- T1563 — Remote Service Session Hijacking Adversaries may take control of preexisting sessions with remote services to move laterally in an environment. Users...
- T1563.001 — SSH Hijacking Adversaries may hijack a legitimate user's SSH session to move laterally within an environment. Secure Shell (SSH)...
- T1563.002 — RDP Hijacking Adversaries may hijack a legitimate user’s remote desktop session to move laterally within an environment. Remote...
- T1564 — Hide Artifacts Adversaries may attempt to hide artifacts associated with their behaviors to evade detection. Operating systems may...
- T1564.001 — Hidden Files and Directories Adversaries may set files and directories to be hidden to evade detection mechanisms. To prevent normal users from...
- T1564.002 — Hidden Users Adversaries may use hidden users to hide the presence of user accounts they create or modify. Administrators may...
- T1564.003 — Hidden Window Adversaries may use hidden windows to conceal malicious activity from the plain sight of users. In some cases,...
- T1564.004 — NTFS File Attributes Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection. Every New...
- T1564.005 — Hidden File System Adversaries may use a hidden file system to conceal malicious activity from users and security tools. File systems...
- T1564.006 — Run Virtual Instance Adversaries may carry out malicious operations using a virtual instance to avoid detection. A wide variety of...
- T1564.007 — VBA Stomping Adversaries may hide malicious Visual Basic for Applications (VBA) payloads embedded within MS Office documents by...
- T1564.008 — Email Hiding Rules Adversaries may use email rules to hide inbound emails in a compromised user's mailbox. Many email clients allow...
- T1564.009 — Resource Forking Adversaries may abuse resource forks to hide malicious code or executables to evade detection and bypass security...
- T1564.010 — Process Argument Spoofing Adversaries may attempt to hide process command-line arguments by overwriting process memory. Process command-line...
- T1564.011 — Ignore Process Interrupts Adversaries may evade defensive mechanisms by executing commands that hide from process interrupt signals. Many...
- T1564.012 — File/Path Exclusions Adversaries may attempt to hide their file-based artifacts by writing them to specific folders or file names...
- T1564.013 — Bind Mounts Adversaries may abuse bind mounts on file structures to hide their activity and artifacts from native utilities. A...
- T1564.014 — Extended Attributes Adversaries may abuse extended attributes (xattrs) on macOS and Linux to hide their malicious data in order to evade...
- T1565 — Data Manipulation Adversaries may insert, delete, or manipulate data in order to influence external outcomes or hide activity, thus...
- T1565.001 — Stored Data Manipulation Adversaries may insert, delete, or manipulate data at rest in order to influence external outcomes or hide activity,...
- T1565.002 — Transmitted Data Manipulation Adversaries may alter data en route to storage or other systems in order to manipulate external outcomes or hide...
- T1565.003 — Runtime Data Manipulation Adversaries may modify systems in order to manipulate the data as it is accessed and displayed to an end user, thus...
- T1566 — Phishing Adversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically...
- T1566.001 — Spearphishing Attachment Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim...
- T1566.002 — Spearphishing Link Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems....
- T1566.003 — Spearphishing via Service Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems....
- T1566.004 — Spearphishing Voice Adversaries may use voice communications to ultimately gain access to victim systems. Spearphishing voice is a...
- T1567 — Exfiltration Over Web Service Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary...
- T1567.001 — Exfiltration to Code Repository Adversaries may exfiltrate data to a code repository rather than over their primary command and control channel....
- T1567.002 — Exfiltration to Cloud Storage Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control...
- T1567.003 — Exfiltration to Text Storage Sites Adversaries may exfiltrate data to text storage sites instead of their primary command and control channel. Text...
Browse by topic
Every page in the corpus, grouped. Search finds one page; this shows what else is here.