Attacker techniques (ATT&CK)
697 pages, showing 601–697, ordered by identifier.
- T1595 — Active Scanning Adversaries may execute active reconnaissance scans to gather information that can be used during targeting. Active...
- T1595.001 — Scanning IP Blocks Adversaries may scan victim IP blocks to gather information that can be used during targeting. Public IP addresses...
- T1595.002 — Vulnerability Scanning Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically...
- T1595.003 — Wordlist Scanning Adversaries may iteratively probe infrastructure using brute-forcing and crawling techniques. While this technique...
- T1596 — Search Open Technical Databases Adversaries may search freely available technical databases for information about victims that can be used during...
- T1596.001 — DNS/Passive DNS Adversaries may search DNS data for information about victims that can be used during targeting. DNS information may...
- T1596.002 — WHOIS Adversaries may search public WHOIS data for information about victims that can be used during targeting. WHOIS data...
- T1596.003 — Digital Certificates Adversaries may search public digital certificate data for information about victims that can be used during...
- T1596.004 — CDNs Adversaries may search content delivery network (CDN) data about victims that can be used during targeting. CDNs...
- T1596.005 — Scan Databases Adversaries may search within public scan databases for information about victims that can be used during targeting....
- T1597 — Search Closed Sources Adversaries may search and gather information about victims from closed (e.g., paid, private, or otherwise not...
- T1597.001 — Threat Intel Vendors Adversaries may search private data from threat intelligence vendors for information that can be used during...
- T1597.002 — Purchase Technical Data Adversaries may purchase technical information about victims that can be used during targeting. Information about...
- T1598 — Phishing for Information Adversaries may send phishing messages to elicit sensitive information that can be used during targeting. Phishing...
- T1598.001 — Spearphishing Service Adversaries may send spearphishing messages via third-party services to elicit sensitive information that can be...
- T1598.002 — Spearphishing Attachment Adversaries may send spearphishing messages with a malicious attachment to elicit sensitive information that can be...
- T1598.003 — Spearphishing Link Adversaries may send spearphishing messages with a malicious link to elicit sensitive information that can be used...
- T1598.004 — Spearphishing Voice Adversaries may use voice communications to elicit sensitive information that can be used during targeting....
- T1599 — Network Boundary Bridging Adversaries may bridge network boundaries by compromising perimeter network devices or internal devices responsible...
- T1599.001 — Network Address Translation Traversal Adversaries may bridge network boundaries by modifying a network device’s Network Address Translation (NAT)...
- T1600 — Weaken Encryption Adversaries may compromise a network device’s encryption capability in order to bypass encryption that would...
- T1600.001 — Reduce Key Space Adversaries may reduce the level of effort required to decrypt data transmitted over the network by reducing the...
- T1600.002 — Disable Crypto Hardware Adversaries disable a network device’s dedicated hardware encryption, which may enable them to leverage weaknesses...
- T1601 — Modify System Image Adversaries may make changes to the operating system of embedded network devices to weaken defenses and provide new...
- T1601.001 — Patch System Image Adversaries may modify the operating system of a network device to introduce new capabilities or weaken existing defenses.
- T1601.002 — Downgrade System Image Adversaries may install an older version of the operating system of a network device to weaken security. Older...
- T1602 — Data from Configuration Repository Adversaries may collect data related to managed devices from configuration repositories. Configuration repositories...
- T1602.001 — SNMP (MIB Dump) Adversaries may target the Management Information Base (MIB) to collect and/or mine valuable information in a...
- T1602.002 — Network Device Configuration Dump Adversaries may access network configuration files to collect sensitive data about the device and the network. The...
- T1606 — Forge Web Credentials Adversaries may forge credential materials that can be used to gain access to web applications or Internet services....
- T1606.001 — Web Cookies Adversaries may forge web cookies that can be used to gain access to web applications or Internet services. Web...
- T1606.002 — SAML Tokens An adversary may forge SAML tokens with any permissions claims and lifetimes if they possess a valid SAML...
- T1608 — Stage Capabilities Adversaries may upload, install, or otherwise set up capabilities that can be used during targeting. To support...
- T1608.001 — Upload Malware Adversaries may upload malware to third-party or adversary controlled infrastructure to make it accessible during...
- T1608.002 — Upload Tool Adversaries may upload tools to third-party or adversary controlled infrastructure to make it accessible during...
- T1608.003 — Install Digital Certificate Adversaries may install SSL/TLS certificates that can be used during targeting. SSL/TLS certificates are files that...
- T1608.004 — Drive-by Target Adversaries may prepare an operational environment to infect systems that visit a website over the normal course of...
- T1608.005 — Link Target Adversaries may put in place resources that are referenced by a link that can be used during targeting. An adversary...
- T1608.006 — SEO Poisoning Adversaries may poison mechanisms that influence search engine optimization (SEO) to further lure staged...
- T1609 — Container Administration Command Adversaries may abuse a container administration service to execute commands within a container. A container...
- T1610 — Deploy Container Adversaries may deploy a container into an environment to facilitate execution or evade defenses. In some cases,...
- T1611 — Escape to Host Adversaries may break out of a container or virtualized environment to gain access to the underlying host. This can...
- T1612 — Build Image on Host Adversaries may build a container image directly on a host to bypass defenses that monitor for the retrieval of...
- T1613 — Container and Resource Discovery Adversaries may attempt to discover containers and other resources that are available within a containers...
- T1614 — System Location Discovery Adversaries may gather information in an attempt to calculate the geographical location of a victim host....
- T1614.001 — System Language Discovery Adversaries may attempt to gather information about the system language of a victim in order to infer the...
- T1615 — Group Policy Discovery Adversaries may gather information on Group Policy settings to identify paths for privilege escalation, security...
- T1619 — Cloud Storage Object Discovery Adversaries may enumerate objects in cloud storage infrastructure. Adversaries may use this information during...
- T1620 — Reflective Code Loading Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads....
- T1621 — Multi-Factor Authentication Request Generation Adversaries may attempt to bypass multi-factor authentication (MFA) mechanisms and gain access to accounts by...
- T1622 — Debugger Evasion Adversaries may employ various means to detect and avoid debuggers. Debuggers are typically used by defenders to...
- T1647 — Plist File Modification Adversaries may modify property list files (plist files) to enable other malicious activity, while also potentially...
- T1648 — Serverless Execution Adversaries may abuse serverless computing, integration, and automation services to execute arbitrary code in cloud...
- T1649 — Steal or Forge Authentication Certificates Adversaries may steal or forge certificates used for authentication to access remote systems or resources. Digital...
- T1650 — Acquire Access Adversaries may purchase or otherwise acquire an existing access to a target system or network. A variety of online...
- T1651 — Cloud Administration Command Adversaries may abuse cloud management services to execute commands within virtual machines. Resources such as AWS...
- T1652 — Device Driver Discovery Adversaries may attempt to enumerate local device drivers on a victim host. Information about device drivers may...
- T1653 — Power Settings Adversaries may impair a system's ability to hibernate, reboot, or shut down in order to extend access to infected...
- T1654 — Log Enumeration Adversaries may enumerate system and service logs to find useful data. These logs may highlight various types of...
- T1657 — Financial Theft Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or...
- T1659 — Content Injection Adversaries may gain access and continuously communicate with victims by injecting malicious content into systems...
- T1665 — Hide Infrastructure Adversaries may manipulate network traffic in order to hide and evade detection of their C2 infrastructure. This can...
- T1666 — Modify Cloud Resource Hierarchy Adversaries may attempt to modify hierarchical structures in infrastructure-as-a-service (IaaS) environments in...
- T1667 — Email Bombing Adversaries may flood targeted email addresses with an overwhelming volume of messages. This may bury legitimate...
- T1668 — Exclusive Control Adversaries who successfully compromise a system may attempt to maintain persistence by “closing the door” behind...
- T1669 — Wi-Fi Networks Adversaries may gain initial access to target systems by connecting to wireless networks. They may accomplish this...
- T1671 — Cloud Application Integration Adversaries may achieve persistence by leveraging OAuth application integrations in a software-as-a-service...
- T1673 — Virtual Machine Discovery An adversary may attempt to enumerate running virtual machines (VMs) after gaining access to a host or hypervisor....
- T1674 — Input Injection Adversaries may simulate keystrokes on a victim’s computer by various means to perform any type of action on behalf...
- T1675 — ESXi Administration Command Adversaries may abuse ESXi administration services to execute commands on guest machines hosted within an ESXi...
- T1677 — Poisoned Pipeline Execution Adversaries may manipulate continuous integration / continuous development (CI/CD) processes by injecting malicious...
- T1678 — Delay Execution Adversaries may employ various time-based methods to evade detection and analysis. These techniques often exploit...
- T1679 — Selective Exclusion Adversaries may intentionally exclude certain files, folders, directories, file types, or system components from...
- T1680 — Local Storage Discovery Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and...
- T1681 — Search Threat Vendor Data Threat actors may seek information/indicators from closed or open threat intelligence sources gathered about their...
- T1682 — Query Public AI Services Adversaries may query publicly accessible artificial intelligence (AI) services, such as large language models...
- T1683 — Generate Content Adversaries may create or generate content to support targeting and operations. This content may be used to...
- T1683.001 — Written Content Adversaries may create or tailor written materials to support targeting and malicious operations. Content may...
- T1683.002 — Audio-Visual Content Adversaries may create or manipulate audio, image, and video content to support targeting and malicious operations....
- T1684 — Social Engineering Adversaries may use social engineering techniques to influence users to take actions that result in unauthorized...
- T1684.001 — Impersonation Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing...
- T1684.002 — Email Spoofing Adversaries may fake, or spoof, a sender’s identity by modifying the value of relevant email headers in order to...
- T1685 — Disable or Modify Tools Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and...
- T1685.001 — Disable or Modify Windows Event Log Adversaries may disable or modify the Windows Event Log to limit data that can be leveraged for detections and...
- T1685.002 — Disable or Modify Cloud Log An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on...
- T1685.003 — Modify or Spoof Tool UI Adversaries may spoof or manipulate security tool user interfaces (UIs) to falsely indicate tools are functioning...
- T1685.004 — Disable or Modify Linux Audit System Log Adversaries may disable or modify the Linux Audit system to hide malicious activity and avoid detection. Linux...
- T1685.005 — Clear Windows Event Logs Adversaries may clear Windows Event Logs to hide the activity of an intrusion. Windows Event Logs are a record of a...
- T1685.006 — Clear Linux or Mac System Logs Adversaries may clear system logs to hide evidence of an intrusion. macOS and Linux both keep track of system or...
- T1686 — Disable or Modify System Firewall Adversaries may disable or modify host-based or network firewalls to impair defensive mechanisms and enable further...
- T1686.001 — Cloud Firewall Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to...
- T1686.002 — Network Device Firewall Adversaries may disable network device-based firewall mechanisms entirely or add, delete, or modify particular rules...
- T1686.003 — Windows Host Firewall Adversaries may disable or modify the Windows host firewall to bypass controls limiting network usage. This can...
- T1687 — Exploitation for Defense Impairment Adversaries may exploit vulnerabilities in security software, infrastructure, or defensive components to degrade,...
- T1688 — Safe Mode Boot Adversaries may abuse Windows safe mode to disable endpoint defenses. Safe mode starts up the Windows operating...
- T1689 — Downgrade Attack Adversaries may downgrade or use a version of system features that may be outdated, vulnerable, and/or does not...
- T1690 — Prevent Command History Logging Adversaries may impair command history logging to hide commands they run on a compromised system. Various command...
Browse by topic
Every page in the corpus, grouped. Search finds one page; this shows what else is here.