Attacker techniques (ATT&CK)
697 pages, showing 501–600, ordered by identifier.
- T1567.004 — Exfiltration Over Webhook Adversaries may exfiltrate data to a webhook endpoint rather than over their primary command and control channel....
- T1568 — Dynamic Resolution Adversaries may dynamically establish connections to command and control infrastructure to evade common detections...
- T1568.001 — Fast Flux DNS Adversaries may use Fast Flux DNS to hide a command and control channel behind an array of rapidly changing IP...
- T1568.002 — Domain Generation Algorithms Adversaries may make use of Domain Generation Algorithms (DGAs) to dynamically identify a destination domain for...
- T1568.003 — DNS Calculation Adversaries may perform calculations on addresses returned in DNS results to determine which port and IP address to...
- T1569 — System Services Adversaries may abuse system services or daemons to execute commands or programs. Adversaries can execute malicious...
- T1569.001 — Launchctl Adversaries may abuse launchctl to execute commands or programs. Launchctl interfaces with launchd, the service...
- T1569.002 — Service Execution Adversaries may abuse the Windows service control manager to execute malicious commands or payloads. The Windows...
- T1569.003 — Systemctl Adversaries may abuse systemctl to execute commands or programs. Systemctl is the primary interface for systemd, the...
- T1570 — Lateral Tool Transfer Adversaries may transfer tools or other files between systems in a compromised environment. Once brought into the...
- T1571 — Non-Standard Port Adversaries may communicate using a protocol and port pairing that are typically not associated. For example, HTTPS...
- T1572 — Protocol Tunneling Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid...
- T1573 — Encrypted Channel Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any...
- T1573.001 — Symmetric Cryptography Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than...
- T1573.002 — Asymmetric Cryptography Adversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic rather than...
- T1574 — Hijack Execution Flow Adversaries may execute their own malicious payloads by hijacking the way operating systems run programs. Hijacking...
- T1574.001 — DLL Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and...
- T1574.004 — Dylib Hijacking Adversaries may execute their own payloads by placing a malicious dynamic library (dylib) with an expected name in a...
- T1574.005 — Executable Installer File Permissions Weakness Adversaries may execute their own malicious payloads by hijacking the binaries used by an installer. These processes...
- T1574.006 — Dynamic Linker Hijacking Adversaries may execute their own malicious payloads by hijacking environment variables the dynamic linker uses to...
- T1574.007 — Path Interception by PATH Environment Variable Adversaries may execute their own malicious payloads by hijacking environment variables used to load libraries. The...
- T1574.008 — Path Interception by Search Order Hijacking Adversaries may execute their own malicious payloads by hijacking the search order used to load other programs....
- T1574.009 — Path Interception by Unquoted Path Adversaries may execute their own malicious payloads by hijacking vulnerable file path references. Adversaries can...
- T1574.010 — Services File Permissions Weakness Adversaries may execute their own malicious payloads by hijacking the binaries used by services. Adversaries may use...
- T1574.011 — Services Registry Permissions Weakness Adversaries may execute their own malicious payloads by hijacking the Registry entries used by services. Flaws in...
- T1574.012 — COR_PROFILER Adversaries may leverage the CORPROFILER environment variable to hijack the execution flow of programs that load the...
- T1574.013 — KernelCallbackTable Adversaries may abuse the <code>KernelCallbackTable</code> of a process to hijack its execution flow in order to run...
- T1574.014 — AppDomainManager Adversaries may execute their own malicious payloads by hijacking how the .NET AppDomainManager loads assemblies....
- T1578 — Modify Cloud Compute Infrastructure An adversary may attempt to modify a cloud account's compute service infrastructure to evade defenses. A...
- T1578.001 — Create Snapshot An adversary may create a snapshot or data backup within a cloud account to evade defenses. A snapshot is a...
- T1578.002 — Create Cloud Instance An adversary may create a new instance or virtual machine (VM) within the compute service of a cloud account to...
- T1578.003 — Delete Cloud Instance An adversary may delete a cloud instance after they have performed malicious activities in an attempt to evade...
- T1578.004 — Revert Cloud Instance An adversary may revert changes made to a cloud instance after they have performed malicious activities in attempt...
- T1578.005 — Modify Cloud Compute Configurations Adversaries may modify settings that directly affect the size, locations, and resources available to cloud compute...
- T1580 — Cloud Infrastructure Discovery An adversary may attempt to discover infrastructure and resources that are available within an...
- T1583 — Acquire Infrastructure Adversaries may buy, lease, rent, or obtain infrastructure that can be used during targeting. A wide variety of...
- T1583.001 — Domains Adversaries may acquire domains that can be used during targeting. Domain names are the human readable names used to...
- T1583.002 — DNS Server Adversaries may set up their own Domain Name System (DNS) servers that can be used during targeting. During...
- T1583.003 — Virtual Private Server Adversaries may rent Virtual Private Servers (VPSs) that can be used during targeting. There exist a variety of...
- T1583.004 — Server Adversaries may buy, lease, rent, or obtain physical servers that can be used during targeting. Use of servers...
- T1583.005 — Botnet Adversaries may buy, lease, or rent a network of compromised systems that can be used during targeting. A botnet is...
- T1583.006 — Web Services Adversaries may register for web services that can be used during targeting. A variety of popular websites exist for...
- T1583.007 — Serverless Adversaries may purchase and configure serverless cloud infrastructure, such as Cloudflare Workers, AWS Lambda...
- T1583.008 — Malvertising Adversaries may purchase online advertisements that can be abused to distribute malware to victims. Ads can be...
- T1584 — Compromise Infrastructure Adversaries may compromise third-party infrastructure that can be used during targeting. Infrastructure solutions...
- T1584.001 — Domains Adversaries may hijack domains and/or subdomains that can be used during targeting. Domain registration hijacking is...
- T1584.002 — DNS Server Adversaries may compromise third-party DNS servers that can be used during targeting. During post-compromise...
- T1584.003 — Virtual Private Server Adversaries may compromise third-party Virtual Private Servers (VPSs) that can be used during targeting. There exist...
- T1584.004 — Server Adversaries may compromise third-party servers that can be used during targeting. Use of servers allows an adversary...
- T1584.005 — Botnet Adversaries may compromise numerous third-party systems to form a botnet that can be used during targeting. A botnet...
- T1584.006 — Web Services Adversaries may compromise access to third-party web services that can be used during targeting. A variety of...
- T1584.007 — Serverless Adversaries may compromise serverless cloud infrastructure, such as Cloudflare Workers, AWS Lambda functions, or...
- T1584.008 — Network Devices Adversaries may compromise third-party network devices that can be used during targeting. Network devices, such as...
- T1585 — Establish Accounts Adversaries may create and cultivate accounts with services that can be used during targeting. Adversaries can...
- T1585.001 — Social Media Accounts Adversaries may create and cultivate social media accounts that can be used during targeting. Adversaries can create...
- T1585.002 — Email Accounts Adversaries may create email accounts that can be used during targeting. Adversaries can use accounts created with...
- T1585.003 — Cloud Accounts Adversaries may create accounts with cloud providers that can be used during targeting. Adversaries can use cloud...
- T1586 — Compromise Accounts Adversaries may compromise accounts with services that can be used during targeting. For operations incorporating...
- T1586.001 — Social Media Accounts Adversaries may compromise social media accounts that can be used during targeting. For operations incorporating...
- T1586.002 — Email Accounts Adversaries may compromise email accounts that can be used during targeting. Adversaries can use compromised email...
- T1586.003 — Cloud Accounts Adversaries may compromise cloud accounts that can be used during targeting. Adversaries can use compromised cloud...
- T1587 — Develop Capabilities Adversaries may build capabilities that can be used during targeting. Rather than purchasing, freely downloading, or...
- T1587.001 — Malware Adversaries may develop malware and malware components that can be used during targeting. Building malicious...
- T1587.002 — Code Signing Certificates Adversaries may create self-signed code signing certificates that can be used during targeting. Code signing is the...
- T1587.003 — Digital Certificates Adversaries may create self-signed SSL/TLS certificates that can be used during targeting. SSL/TLS certificates are...
- T1587.004 — Exploits Adversaries may develop exploits that can be used during targeting. An exploit takes advantage of a bug or...
- T1588 — Obtain Capabilities Adversaries may buy and/or steal capabilities that can be used during targeting. Rather than developing their own...
- T1588.001 — Malware Adversaries may buy, steal, or download malware that can be used during targeting. Malicious software can include...
- T1588.002 — Tool Adversaries may buy, steal, or download software tools that can be used during targeting. Tools can be open or...
- T1588.003 — Code Signing Certificates Adversaries may buy and/or steal code signing certificates that can be used during targeting. Code signing is the...
- T1588.004 — Digital Certificates Adversaries may buy and/or steal SSL/TLS certificates that can be used during targeting. SSL/TLS certificates are...
- T1588.005 — Exploits Adversaries may buy, steal, or download exploits that can be used during targeting. An exploit takes advantage of a...
- T1588.006 — Vulnerabilities Adversaries may acquire information about vulnerabilities that can be used during targeting. A vulnerability is a...
- T1588.007 — Artificial Intelligence Adversaries may obtain access to generative artificial intelligence tools, such as large language models (LLMs), to...
- T1589 — Gather Victim Identity Information Adversaries may gather information about the victim's identity that can be used during targeting. Information about...
- T1589.001 — Credentials Adversaries may gather credentials that can be used during targeting. Account credentials gathered by adversaries...
- T1589.002 — Email Addresses Adversaries may gather email addresses that can be used during targeting. Even if internal instances exist,...
- T1589.003 — Employee Names Adversaries may gather employee names that can be used during targeting. Employee names be used to derive email...
- T1590 — Gather Victim Network Information Adversaries may gather information about the victim's networks that can be used during targeting. Information about...
- T1590.001 — Domain Properties Adversaries may gather information about the victim's network domain(s) that can be used during targeting....
- T1590.002 — DNS Adversaries may gather information about the victim's DNS that can be used during targeting. DNS information may...
- T1590.003 — Network Trust Dependencies Adversaries may gather information about the victim's network trust dependencies that can be used during targeting....
- T1590.004 — Network Topology Adversaries may gather information about the victim's network topology that can be used during targeting....
- T1590.005 — IP Addresses Adversaries may gather the victim's IP addresses that can be used during targeting. Public IP addresses may be...
- T1590.006 — Network Security Appliances Adversaries may gather information about the victim's network security appliances that can be used during targeting....
- T1591 — Gather Victim Org Information Adversaries may gather information about the victim's organization that can be used during targeting. Information...
- T1591.001 — Determine Physical Locations Adversaries may gather the victim's physical location(s) that can be used during targeting. Information about...
- T1591.002 — Business Relationships Adversaries may gather information about the victim's business relationships that can be used during targeting....
- T1591.003 — Identify Business Tempo Adversaries may gather information about the victim's business tempo that can be used during targeting. Information...
- T1591.004 — Identify Roles Adversaries may gather information about identities and roles within the victim organization that can be used during...
- T1592 — Gather Victim Host Information Adversaries may gather information about the victim's hosts that can be used during targeting. Information about...
- T1592.001 — Hardware Adversaries may gather information about the victim's host hardware that can be used during targeting. Information...
- T1592.002 — Software Adversaries may gather information about the victim's host software that can be used during targeting. Information...
- T1592.003 — Firmware Adversaries may gather information about the victim's host firmware that can be used during targeting. Information...
- T1592.004 — Client Configurations Adversaries may gather information about the victim's client configurations that can be used during targeting....
- T1593 — Search Open Websites/Domains Adversaries may search freely available websites and/or domains for information about victims that can be used...
- T1593.001 — Social Media Adversaries may search social media for information about victims that can be used during targeting. Social media...
- T1593.002 — Search Engines Adversaries may use search engines to collect information about victims that can be used during targeting. Search...
- T1593.003 — Code Repositories Adversaries may search public code repositories for information about victims that can be used during targeting....
- T1594 — Search Victim-Owned Websites Adversaries may search websites owned by the victim for information that can be used during targeting. Victim-owned...
Browse by topic
Every page in the corpus, grouped. Search finds one page; this shows what else is here.