Fortitude
Security intelligence
Synthetic demo
Synthetic demonstration No customer data is shown. Organizations, observations, reports, and Fortitude-proposed patterns are fictional. 30-day view

Network intelligence

Threat intelligence

Investigate behaviors across customer telemetry and anonymized reports, grounded in ATT&CK, crosswalked to OWASP, and extended with emerging patterns.

Analyst view As of 2026-07-26 · 18:40:00 UTC
Contributing organizations 24 of 24 in the demo cohort
Observed ATT&CK techniques 12 30-day assessed window
Emerging patterns 3 Fortitude proposals awaiting review
Validated visibility 68% of required demo telemetry

Executive brief

What changed and why it matters

Derived from displayed synthetic metrics

Identity-led social engineering is moving into trusted workflows

Observed activity rose 28% across the synthetic network, led by cloud-account abuse and attacks that inherit a legitimate user or agent's authority. Three proposed patterns deserve analyst review; none are attributed to an actor.

  1. 1

    Prioritize controls around authorized tool actions and cloud session changes.

  2. 2

    Validate the identity and collaboration telemetry required for the top five patterns.

  3. 3

    Brief workflow owners on callback-channel and approval-context changes.

Network pulse

Assessed observations

+28%
Bounded observations Unique-organization contribution caps applied

Investigate now

Priority signals

Confidence, prevalence, and severity stay separate so analysts can challenge each claim.

6 ranked signals
Pattern Severity Confidence Frameworks Affected orgs Change Last seen Open detail
Fortitude proposed Indirect Prompt Injection to Authorized Tool Action FORT-0001 · Execution Critical 88% assessment ATT&CK LLM01 · LLM06 +2 7 17 observations +42% 18 min ago
MITRE ATT&CK® Phishing: Spearphishing Link T1566.002 · Initial Access High 94% assessment ATT&CK No direct OWASP 14 31 observations +18% 42 min ago
MITRE ATT&CK® Valid Accounts: Cloud Accounts T1078.004 · Initial Access High 91% assessment ATT&CK A07 12 22 observations +29% 1h ago
Fortitude proposed MCP Tool-Schema Poisoning FORT-0002 · Stealth High 76% assessment ATT&CK LLM03 · ASI04 +3 5 9 observations +100% 3h ago
MITRE ATT&CK® Social Engineering: Impersonation T1684.001 · Stealth Medium 89% assessment ATT&CK No direct OWASP 11 18 observations +23% 4h ago
Fortitude proposed Cross-Agent Authority Relay FORT-0003 · Privilege Escalation Medium 68% assessment ATT&CK ASI03 · A01 +2 5 6 observations +100% 7h ago

Landscape

Enterprise ATT&CK matrix

One metric per color scale. Switch modes to avoid conflating prevalence with defensive coverage.

TA0043

Reconnaissance

5 orgs
TA0042

Resource Development

Insufficient data
TA0001

Initial Access

14 orgs
TA0002

Execution

11 orgs
TA0003

Persistence

7 orgs
TA0004

Privilege Escalation

Insufficient data
TA0005

Stealth

8 orgs
TA0112

Defense Impairment

5 orgs
TA0006

Credential Access

12 orgs
TA0007

Discovery

6 orgs
TA0008

Lateral Movement

5 orgs
TA0009

Collection

7 orgs
TA0011

Command and Control

5 orgs
TA0010

Exfiltration

Insufficient data
TA0040

Impact

5 orgs
Unique affected organizations · minimum 5 Lower Moderate Higher Suppressed

Fortitude research

Emerging patterns

Proposed behaviors can graduate through analyst review without mutating or impersonating ATT&CK.

Synthetic proposed pattern — not part of MITRE ATT&CK.
Fortitude proposed Execution · Analyst review
FORT-0001

Indirect Prompt Injection to Authorized Tool Action

Attacker-controlled retrieved content causes an enterprise AI agent to invoke an authorized tool outside the user's intent.

Confidence
88%
Affected orgs
7
First seen
2026-06-18
Fortitude proposed Stealth · Candidate
FORT-0002

MCP Tool-Schema Poisoning

A compromised tool provider alters descriptions or schemas to capture sensitive arguments or conceal side effects.

Confidence
76%
Affected orgs
5
First seen
2026-07-03
Fortitude proposed Privilege Escalation · Candidate
FORT-0003

Cross-Agent Authority Relay

A low-privilege agent induces a more privileged downstream agent to act without preserving request origin or constraints.

Confidence
68%
Affected orgs
5
First seen
2026-07-11
Reference catalog Explore MITRE ATT&CK Enterprise v19.1 15 tactics · 697 techniques and sub-techniques
697 results
Technique Tactic Platforms Object version
Abuse Elevation Control Mechanism T1548 STIX ID attack-pattern--67720091-eee3-4d2d-ae16-8264567f6f5b Privilege Escalation IaaS, Identity Provider, Linux, macOS, Office Suite, Windows 2.0
Abuse Elevation Control Mechanism: Bypass User Account Control T1548.002 · sub-technique of T1548 STIX ID attack-pattern--120d5519-3098-4e1c-9191-2aa61232f073 Privilege Escalation Windows 3.0
Abuse Elevation Control Mechanism: Elevated Execution with Prompt T1548.004 · sub-technique of T1548 STIX ID attack-pattern--b84903f0-c7d5-435d-a69e-de47cc3578c0 Privilege Escalation macOS 2.0
Abuse Elevation Control Mechanism: Setuid and Setgid T1548.001 · sub-technique of T1548 STIX ID attack-pattern--6831414d-bb70-42b7-8030-d4e06b2660c9 Privilege Escalation Linux, macOS 2.0
Abuse Elevation Control Mechanism: Sudo and Sudo Caching T1548.003 · sub-technique of T1548 STIX ID attack-pattern--1365fe3b-0f50-455d-b4da-266ce31c23b0 Privilege Escalation Linux, macOS 2.0
Abuse Elevation Control Mechanism: TCC Manipulation T1548.006 · sub-technique of T1548 STIX ID attack-pattern--e8a0a025-3601-4755-abfb-8d08283329fb Privilege Escalation macOS 2.0
Abuse Elevation Control Mechanism: Temporary Elevated Cloud Access T1548.005 · sub-technique of T1548 STIX ID attack-pattern--6fa224c7-5091-4595-bf15-3fc9fe2f2c7c Privilege Escalation IaaS, Identity Provider, Office Suite 2.0
Access Token Manipulation T1134 STIX ID attack-pattern--dcaa092b-7de9-4a21-977f-7fcb77e89c48 Privilege Escalation, Stealth Windows 3.0
Access Token Manipulation: Create Process with Token T1134.002 · sub-technique of T1134 STIX ID attack-pattern--677569f9-a8b0-459e-ab24-7f18091fa7bf Privilege Escalation, Stealth Windows 2.0
Access Token Manipulation: Make and Impersonate Token T1134.003 · sub-technique of T1134 STIX ID attack-pattern--8cdeb020-e31e-4f88-a582-f53dcfbda819 Privilege Escalation, Stealth Windows 2.0
Access Token Manipulation: Parent PID Spoofing T1134.004 · sub-technique of T1134 STIX ID attack-pattern--93591901-3172-4e94-abf8-6034ab26f44a Privilege Escalation, Stealth Windows 2.0
Access Token Manipulation: SID-History Injection T1134.005 · sub-technique of T1134 STIX ID attack-pattern--b7dc639b-24cd-482d-a7f1-8897eda21023 Privilege Escalation, Stealth Windows 2.0
Access Token Manipulation: Token Impersonation/Theft T1134.001 · sub-technique of T1134 STIX ID attack-pattern--86850eff-2729-40c3-b85e-c4af26da4a2d Privilege Escalation, Stealth Windows 2.0
Account Access Removal T1531 STIX ID attack-pattern--b24e2a20-3b3d-4bf0-823b-1ed765398fb0 Impact ESXi, IaaS, Linux, macOS, Office Suite, SaaS, Windows 1.5
Account Discovery T1087 STIX ID attack-pattern--72b74d71-8169-42aa-92e0-e7b04b9f5a08 Discovery ESXi, IaaS, Identity Provider, Linux, macOS, Office Suite, SaaS, Windows 2.6
Account Discovery: Cloud Account T1087.004 · sub-technique of T1087 STIX ID attack-pattern--8f104855-e5b7-4077-b1f5-bc3103b41abe Discovery IaaS, Identity Provider, Office Suite, SaaS 1.3
Account Discovery: Domain Account T1087.002 · sub-technique of T1087 STIX ID attack-pattern--21875073-b0ee-49e3-9077-1e2a885359af Discovery Linux, macOS, Windows 1.2
Account Discovery: Email Account T1087.003 · sub-technique of T1087 STIX ID attack-pattern--4bc31b94-045b-4752-8920-aebaebdb6470 Discovery Office Suite, Windows 1.2
Account Discovery: Local Account T1087.001 · sub-technique of T1087 STIX ID attack-pattern--25659dd6-ea12-45c4-97e6-381e3e4b593e Discovery ESXi, Linux, macOS, Windows 1.5
Account Manipulation T1098 STIX ID attack-pattern--a10641f4-87b4-45a3-a906-92a149cb2c27 Persistence, Privilege Escalation Containers, ESXi, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows 2.8
Account Manipulation: Additional Cloud Credentials T1098.001 · sub-technique of T1098 STIX ID attack-pattern--8a2f40cf-8325-47f9-96e4-b1ca4c7389bd Persistence, Privilege Escalation IaaS, Identity Provider, SaaS 2.8
Account Manipulation: Additional Cloud Roles T1098.003 · sub-technique of T1098 STIX ID attack-pattern--2dbbdcd5-92cf-44c0-aea2-fe24783a6bc3 Persistence, Privilege Escalation IaaS, Identity Provider, Office Suite, SaaS 2.5
Account Manipulation: Additional Container Cluster Roles T1098.006 · sub-technique of T1098 STIX ID attack-pattern--35d30338-5bfa-41b0-a170-ec06dfd75f64 Persistence, Privilege Escalation Containers 1.0
Account Manipulation: Additional Email Delegate Permissions T1098.002 · sub-technique of T1098 STIX ID attack-pattern--e74de37c-a829-446c-937d-56a44f0e9306 Persistence, Privilege Escalation Office Suite, Windows 2.2
Account Manipulation: Additional Local or Domain Groups T1098.007 · sub-technique of T1098 STIX ID attack-pattern--3e6831b2-bf4c-4ae6-b328-2e7c6633b291 Persistence, Privilege Escalation Linux, macOS, Windows 1.1
Account Manipulation: Device Registration T1098.005 · sub-technique of T1098 STIX ID attack-pattern--7decb26c-715c-40cf-b7e0-026f7d7cc215 Persistence, Privilege Escalation Identity Provider, Windows 1.4
Account Manipulation: SSH Authorized Keys T1098.004 · sub-technique of T1098 STIX ID attack-pattern--6b57dc31-b814-4a03-8706-28bc20d739c4 Persistence, Privilege Escalation ESXi, IaaS, Linux, macOS, Network Devices 1.4
Acquire Access T1650 STIX ID attack-pattern--d21bb61f-08ad-4dc1-b001-81ca6cb79954 Resource Development PRE 1.0
Acquire Infrastructure T1583 STIX ID attack-pattern--0458aab9-ad42-4eac-9e22-706a95bafee2 Resource Development PRE 1.5
Acquire Infrastructure: Botnet T1583.005 · sub-technique of T1583 STIX ID attack-pattern--31225cd3-cd46-4575-b287-c2c14011c074 Resource Development PRE 1.2
Acquire Infrastructure: DNS Server T1583.002 · sub-technique of T1583 STIX ID attack-pattern--197ef1b9-e764-46c3-b96c-23f77985dc81 Resource Development PRE 1.0
Acquire Infrastructure: Domains T1583.001 · sub-technique of T1583 STIX ID attack-pattern--40f5caa0-4cb7-4117-89fc-d421bb493df3 Resource Development PRE 1.4
Acquire Infrastructure: Malvertising T1583.008 · sub-technique of T1583 STIX ID attack-pattern--155207c0-7f53-4f13-a06b-0a9907ef5096 Resource Development PRE 1.0
Acquire Infrastructure: Server T1583.004 · sub-technique of T1583 STIX ID attack-pattern--60c4b628-4807-4b0b-bbf5-fdac8643c337 Resource Development PRE 1.3
Acquire Infrastructure: Serverless T1583.007 · sub-technique of T1583 STIX ID attack-pattern--04a5a8ab-3bc8-4c83-95c9-55274a89786d Resource Development PRE 1.1
Acquire Infrastructure: Virtual Private Server T1583.003 · sub-technique of T1583 STIX ID attack-pattern--79da0971-3147-4af6-a4f5-e8cd447cd795 Resource Development PRE 1.1
Acquire Infrastructure: Web Services T1583.006 · sub-technique of T1583 STIX ID attack-pattern--88d31120-5bc7-4ce3-a9c0-7cf147be8e54 Resource Development PRE 1.3
Active Scanning T1595 STIX ID attack-pattern--67073dde-d720-45ae-83da-b12d5e73ca3b Reconnaissance PRE 1.0
Active Scanning: Scanning IP Blocks T1595.001 · sub-technique of T1595 STIX ID attack-pattern--db8f5003-3b20-48f0-9b76-123e44208120 Reconnaissance PRE 1.1
Active Scanning: Vulnerability Scanning T1595.002 · sub-technique of T1595 STIX ID attack-pattern--5502c4e9-24ef-4d5f-8ee9-9e906c2f82c4 Reconnaissance PRE 1.0
Active Scanning: Wordlist Scanning T1595.003 · sub-technique of T1595 STIX ID attack-pattern--bed04f7d-e48a-4e76-bd0f-4c57fe31fc46 Reconnaissance PRE 1.0
Adversary-in-the-Middle T1557 STIX ID attack-pattern--035bb001-ab69-4a0b-9f6c-2de8b09e1b9d Collection, Credential Access Linux, macOS, Network Devices, Windows 2.5
Adversary-in-the-Middle: ARP Cache Poisoning T1557.002 · sub-technique of T1557 STIX ID attack-pattern--cabe189c-a0e3-4965-a473-dcff00f17213 Collection, Credential Access Linux, macOS, Windows 1.1
Adversary-in-the-Middle: DHCP Spoofing T1557.003 · sub-technique of T1557 STIX ID attack-pattern--59ff91cd-1430-4075-8563-e6f15f4f9ff5 Collection, Credential Access Linux, macOS, Windows 1.1
Adversary-in-the-Middle: Evil Twin T1557.004 · sub-technique of T1557 STIX ID attack-pattern--48b836c6-e4ca-435a-82a3-29c03e5b492e Collection, Credential Access Network Devices 1.1
Adversary-in-the-Middle: Name Resolution Poisoning and SMB Relay T1557.001 · sub-technique of T1557 STIX ID attack-pattern--650c784b-7504-4df7-ab2c-4ea882384d1e Collection, Credential Access Windows 2.0
Application Layer Protocol T1071 STIX ID attack-pattern--355be19c-ffc9-46d5-8d50-d6a036c675b6 Command and Control ESXi, Linux, macOS, Network Devices, Windows 2.4
Application Layer Protocol: DNS T1071.004 · sub-technique of T1071 STIX ID attack-pattern--1996eef1-ced3-4d7f-bf94-33298cabbf72 Command and Control ESXi, Linux, macOS, Network Devices, Windows 1.4
Application Layer Protocol: File Transfer Protocols T1071.002 · sub-technique of T1071 STIX ID attack-pattern--9a60a291-8960-4387-8a4a-2ab5c18bb50b Command and Control ESXi, Linux, macOS, Network Devices, Windows 1.4
Application Layer Protocol: Mail Protocols T1071.003 · sub-technique of T1071 STIX ID attack-pattern--54b4c251-1f0e-4eba-ba6b-dbc7a6f6f06b Command and Control Linux, macOS, Network Devices, Windows 1.2
Application Layer Protocol: Publish/Subscribe Protocols T1071.005 · sub-technique of T1071 STIX ID attack-pattern--241f9ea8-f6ae-4f38-92f5-cef5b7e539dd Command and Control Linux, macOS, Network Devices, Windows 1.1
Application Layer Protocol: Web Protocols T1071.001 · sub-technique of T1071 STIX ID attack-pattern--df8b2a25-8bdf-4856-953c-a04372b1c161 Command and Control ESXi, Linux, macOS, Network Devices, Windows 1.5
Application Window Discovery T1010 STIX ID attack-pattern--4ae4f953-fe58-4cc8-a327-33257e30a830 Discovery Linux, macOS, Windows 1.3
Archive Collected Data T1560 STIX ID attack-pattern--53ac20cd-aca3-406e-9aa0-9fc7fdc60a5a Collection Linux, macOS, Windows 1.0
Archive Collected Data: Archive via Custom Method T1560.003 · sub-technique of T1560 STIX ID attack-pattern--143c0cbb-a297-4142-9624-87ffc778980b Collection Linux, macOS, Windows 1.0
Archive Collected Data: Archive via Library T1560.002 · sub-technique of T1560 STIX ID attack-pattern--41868330-6ee2-4d0f-b743-9f2294c3c9b6 Collection Linux, macOS, Windows 1.0
Archive Collected Data: Archive via Utility T1560.001 · sub-technique of T1560 STIX ID attack-pattern--00f90846-cbd1-4fc5-9233-df5c2bf2a662 Collection Linux, macOS, Windows 1.3
Audio Capture T1123 STIX ID attack-pattern--1035cdf2-3e5f-446f-a7a7-e8f6d7925967 Collection Linux, macOS, Windows 1.0
Automated Collection T1119 STIX ID attack-pattern--30208d3e-0d6b-43c8-883e-44462a514619 Collection IaaS, Linux, macOS, Office Suite, SaaS, Windows 1.4
Automated Exfiltration T1020 STIX ID attack-pattern--774a3188-6ba9-4dc4-879d-d54ee48a5ce9 Exfiltration Linux, macOS, Network Devices, Windows 1.3
Automated Exfiltration: Traffic Duplication T1020.001 · sub-technique of T1020 STIX ID attack-pattern--7c46b364-8496-4234-8a56-f7e6727e21e1 Exfiltration IaaS, Network Devices 1.4
BITS Jobs T1197 STIX ID attack-pattern--c8e87b83-edbb-48d4-9295-4974897525b7 Execution, Persistence, Stealth Windows 2.0
Boot or Logon Autostart Execution T1547 STIX ID attack-pattern--1ecb2399-e8ba-4f6b-8ba7-5c27d49405cf Persistence, Privilege Escalation Linux, macOS, Network Devices, Windows 1.3
Boot or Logon Autostart Execution: Active Setup T1547.014 · sub-technique of T1547 STIX ID attack-pattern--22522668-ddf6-470b-a027-9d6866679f67 Persistence, Privilege Escalation Windows 1.1
Boot or Logon Autostart Execution: Authentication Package T1547.002 · sub-technique of T1547 STIX ID attack-pattern--b8cfed42-6a8a-4989-ad72-541af74475ec Persistence, Privilege Escalation Windows 1.1
Boot or Logon Autostart Execution: Kernel Modules and Extensions T1547.006 · sub-technique of T1547 STIX ID attack-pattern--a1b52199-c8c5-438a-9ded-656f1d0888c6 Persistence, Privilege Escalation Linux, macOS 1.4
Boot or Logon Autostart Execution: LSASS Driver T1547.008 · sub-technique of T1547 STIX ID attack-pattern--f0589bc3-a6ae-425a-a3d5-5659bfee07f4 Persistence, Privilege Escalation Windows 1.1
Boot or Logon Autostart Execution: Login Items T1547.015 · sub-technique of T1547 STIX ID attack-pattern--84601337-6a55-4ad7-9c35-79e0d1ea2ab3 Persistence, Privilege Escalation macOS 1.1
Boot or Logon Autostart Execution: Port Monitors T1547.010 · sub-technique of T1547 STIX ID attack-pattern--43881e51-ac74-445b-b4c6-f9f9e9bf23fe Persistence, Privilege Escalation Windows 1.3
Boot or Logon Autostart Execution: Print Processors T1547.012 · sub-technique of T1547 STIX ID attack-pattern--2de47683-f398-448f-b947-9abcc3e32fad Persistence, Privilege Escalation Windows 1.2
Boot or Logon Autostart Execution: Re-opened Applications T1547.007 · sub-technique of T1547 STIX ID attack-pattern--e5cc9e7a-e61a-46a1-b869-55fb6eab058e Persistence, Privilege Escalation macOS 1.2
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder T1547.001 · sub-technique of T1547 STIX ID attack-pattern--9efb1ea7-c37b-4595-9640-b7680cd84279 Persistence, Privilege Escalation Windows 2.1
Boot or Logon Autostart Execution: Security Support Provider T1547.005 · sub-technique of T1547 STIX ID attack-pattern--5095a853-299c-4876-abd7-ac0050fb5462 Persistence, Privilege Escalation Windows 1.1
Boot or Logon Autostart Execution: Shortcut Modification T1547.009 · sub-technique of T1547 STIX ID attack-pattern--4ab929c6-ee2d-4fb5-aab4-b14be2ed7179 Persistence, Privilege Escalation Windows 1.3
Boot or Logon Autostart Execution: Time Providers T1547.003 · sub-technique of T1547 STIX ID attack-pattern--61afc315-860c-4364-825d-0d62b2e91edc Persistence, Privilege Escalation Windows 1.2
Boot or Logon Autostart Execution: Winlogon Helper DLL T1547.004 · sub-technique of T1547 STIX ID attack-pattern--6836813e-8ec8-4375-b459-abb388cb1a35 Persistence, Privilege Escalation Windows 1.3
Boot or Logon Autostart Execution: XDG Autostart Entries T1547.013 · sub-technique of T1547 STIX ID attack-pattern--e0232cb0-ded5-4c2e-9dc7-2893142a5c11 Persistence, Privilege Escalation Linux 1.2
Boot or Logon Initialization Scripts T1037 STIX ID attack-pattern--03259939-0b57-482f-8eb5-87c0e0d54334 Persistence, Privilege Escalation ESXi, Linux, macOS, Network Devices, Windows 2.4
Boot or Logon Initialization Scripts: Login Hook T1037.002 · sub-technique of T1037 STIX ID attack-pattern--43ba2b05-cf72-4b6c-8243-03a4aba41ee0 Persistence, Privilege Escalation macOS 2.0
Boot or Logon Initialization Scripts: Logon Script (Windows) T1037.001 · sub-technique of T1037 STIX ID attack-pattern--eb125d40-0b2d-41ac-a71a-3229241c2cd3 Persistence, Privilege Escalation Windows 1.0
Boot or Logon Initialization Scripts: Network Logon Script T1037.003 · sub-technique of T1037 STIX ID attack-pattern--c63a348e-ffc2-486a-b9d9-d7f11ec54d99 Persistence, Privilege Escalation Windows 1.0
Boot or Logon Initialization Scripts: RC Scripts T1037.004 · sub-technique of T1037 STIX ID attack-pattern--dca670cf-eeec-438f-8185-fd959d9ef211 Persistence, Privilege Escalation ESXi, Linux, macOS, Network Devices 2.2
Boot or Logon Initialization Scripts: Startup Items T1037.005 · sub-technique of T1037 STIX ID attack-pattern--c0dfe7b0-b873-4618-9ff8-53e31f70907f Persistence, Privilege Escalation macOS 1.1
Browser Information Discovery T1217 STIX ID attack-pattern--5e4a2073-9643-44cb-a0b5-e7f4048446c7 Discovery Linux, macOS, Windows 2.0
Browser Session Hijacking T1185 STIX ID attack-pattern--544b0346-29ad-41e1-a808-501bb4193f47 Collection Windows 2.1
Brute Force T1110 STIX ID attack-pattern--a93494bb-4b80-4ea1-8695-3236a49916fd Credential Access Containers, ESXi, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows 2.8
Brute Force: Credential Stuffing T1110.004 · sub-technique of T1110 STIX ID attack-pattern--b2d03cea-aec1-45ca-9744-9ee583c1e1cc Credential Access Containers, ESXi, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows 1.7
Brute Force: Password Cracking T1110.002 · sub-technique of T1110 STIX ID attack-pattern--1d24cdee-9ea2-4189-b08e-af110bf2435d Credential Access Identity Provider, Linux, macOS, Network Devices, Office Suite, Windows 1.4
Brute Force: Password Guessing T1110.001 · sub-technique of T1110 STIX ID attack-pattern--09c4c11e-4fa1-4f8c-8dad-3cf8e69ad119 Credential Access Containers, ESXi, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows 1.7
Brute Force: Password Spraying T1110.003 · sub-technique of T1110 STIX ID attack-pattern--692074ae-bb62-4a5e-a735-02cb6bde458c Credential Access Containers, ESXi, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows 1.8
Build Image on Host T1612 STIX ID attack-pattern--800f9819-7007-4540-a520-40e655876800 Stealth Containers 2.0
Clipboard Data T1115 STIX ID attack-pattern--30973a08-aed9-4edf-8604-9084ce1b5c4f Collection Linux, macOS, Windows 1.2
Cloud Administration Command T1651 STIX ID attack-pattern--d94b3ae9-8059-4989-8e9f-ea0f601f80a7 Execution IaaS 2.1
Cloud Application Integration T1671 STIX ID attack-pattern--c31aebd6-c9b5-420f-ba2a-5853bbf897fa Persistence Office Suite, SaaS 1.0
Cloud Infrastructure Discovery T1580 STIX ID attack-pattern--57a3d31a-d04f-4663-b2da-7df8ec3f8c9d Discovery IaaS 1.3
Cloud Service Dashboard T1538 STIX ID attack-pattern--e49920b0-6c54-40c1-9571-73723653205f Discovery IaaS, Identity Provider, Office Suite, SaaS 1.5
Cloud Service Discovery T1526 STIX ID attack-pattern--e24fcba8-2557-4442-a139-1ee2f2e784db Discovery IaaS, Identity Provider, Office Suite, SaaS 1.4
Cloud Storage Object Discovery T1619 STIX ID attack-pattern--8565825b-21c8-4518-b75e-cbc4c717a156 Discovery IaaS 1.0
Command and Scripting Interpreter T1059 STIX ID attack-pattern--7385dfaf-6886-4229-9ecd-6fd678040830 Execution Containers, ESXi, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows 2.7
Command and Scripting Interpreter: AppleScript T1059.002 · sub-technique of T1059 STIX ID attack-pattern--37b11151-1776-4f8f-b328-30939fbf2ceb Execution macOS 1.3
Command and Scripting Interpreter: AutoHotKey & AutoIT T1059.010 · sub-technique of T1059 STIX ID attack-pattern--3a32740a-11b0-4bcf-b0a9-3abd0f6d3cd5 Execution Windows 1.1
Command and Scripting Interpreter: Cloud API T1059.009 · sub-technique of T1059 STIX ID attack-pattern--55bb4471-ff1f-43b4-88c1-c9384ec47abf Execution IaaS, Identity Provider, Office Suite, SaaS 1.2
Command and Scripting Interpreter: Container CLI/API T1059.013 · sub-technique of T1059 STIX ID attack-pattern--c283d88f-8c23-4318-9da5-3d50cecad756 Execution Containers 1.0
Command and Scripting Interpreter: Hypervisor CLI T1059.012 · sub-technique of T1059 STIX ID attack-pattern--d2d642da-61ff-4211-b4df-7923c9ca220c Execution ESXi 1.0
Command and Scripting Interpreter: JavaScript T1059.007 · sub-technique of T1059 STIX ID attack-pattern--0f4a0c76-ab2d-4cb0-85d3-3f0efb8cba0d Execution Linux, macOS, Windows 2.2
Command and Scripting Interpreter: Lua T1059.011 · sub-technique of T1059 STIX ID attack-pattern--afddee82-3385-4682-ad90-eeced33f2d07 Execution Linux, macOS, Network Devices, Windows 1.1
Command and Scripting Interpreter: Network Device CLI T1059.008 · sub-technique of T1059 STIX ID attack-pattern--818302b2-d640-477b-bf88-873120ce85c4 Execution Network Devices 1.2
Command and Scripting Interpreter: PowerShell T1059.001 · sub-technique of T1059 STIX ID attack-pattern--970a3432-3237-47ad-bcca-7d8cbb217736 Execution Windows 1.5
Command and Scripting Interpreter: Python T1059.006 · sub-technique of T1059 STIX ID attack-pattern--cc3502b5-30cc-4473-ad48-42d51a6ef6d1 Execution ESXi, Linux, macOS, Windows 1.1
Command and Scripting Interpreter: Unix Shell T1059.004 · sub-technique of T1059 STIX ID attack-pattern--a9d4b653-6915-42af-98b2-5758c4ceee56 Execution ESXi, Linux, macOS, Network Devices 1.4
Command and Scripting Interpreter: Visual Basic T1059.005 · sub-technique of T1059 STIX ID attack-pattern--dfd7cc1d-e1d8-4394-a198-97c4cab8aa67 Execution Linux, macOS, Windows 1.5
Command and Scripting Interpreter: Windows Command Shell T1059.003 · sub-technique of T1059 STIX ID attack-pattern--d1fcf083-a721-4223-aedf-bf8960798d62 Execution Windows 1.5
Communication Through Removable Media T1092 STIX ID attack-pattern--64196062-5210-42c3-9a02-563a0d1797ef Command and Control Linux, macOS, Windows 1.0
Compromise Accounts T1586 STIX ID attack-pattern--81033c3b-16a4-46e4-8fed-9b030dd03c4a Resource Development PRE 1.2
Compromise Accounts: Cloud Accounts T1586.003 · sub-technique of T1586 STIX ID attack-pattern--3d52e51e-f6db-4719-813c-48002a99f43a Resource Development PRE 1.1
Compromise Accounts: Email Accounts T1586.002 · sub-technique of T1586 STIX ID attack-pattern--3dc8c101-d4db-4f4d-8150-1b5a76ca5f1b Resource Development PRE 1.1
Compromise Accounts: Social Media Accounts T1586.001 · sub-technique of T1586 STIX ID attack-pattern--274770e0-2612-4ccf-a678-ef8e7bad365d Resource Development PRE 1.1
Compromise Host Software Binary T1554 STIX ID attack-pattern--960c3c86-1480-4d72-b4e0-8c242e84a5c5 Persistence ESXi, Linux, macOS, Windows 2.2
Compromise Infrastructure T1584 STIX ID attack-pattern--7e3beebd-8bfe-4e7b-a892-e44ab06a75f9 Resource Development PRE 1.6
Compromise Infrastructure: Botnet T1584.005 · sub-technique of T1584 STIX ID attack-pattern--810d8072-afb6-4a56-9ee7-86379ac4a6f3 Resource Development PRE 1.0
Compromise Infrastructure: DNS Server T1584.002 · sub-technique of T1584 STIX ID attack-pattern--c2f59d25-87fe-44aa-8f83-e8e59d077bf5 Resource Development PRE 1.3
Compromise Infrastructure: Domains T1584.001 · sub-technique of T1584 STIX ID attack-pattern--f9cc4d06-775f-4ee1-b401-4e2cc0da30ba Resource Development PRE 1.4
Compromise Infrastructure: Network Devices T1584.008 · sub-technique of T1584 STIX ID attack-pattern--149b477f-f364-4824-b1b5-aa1d56115869 Resource Development PRE 1.1
Compromise Infrastructure: Server T1584.004 · sub-technique of T1584 STIX ID attack-pattern--e196b5c5-8118-4a1c-ab8a-936586ce3db5 Resource Development PRE 1.2
Compromise Infrastructure: Serverless T1584.007 · sub-technique of T1584 STIX ID attack-pattern--df1bc34d-1634-4c93-b89e-8120994fce77 Resource Development PRE 1.1
Compromise Infrastructure: Virtual Private Server T1584.003 · sub-technique of T1584 STIX ID attack-pattern--39cc9f64-cf74-4a48-a4d8-fe98c54a02e0 Resource Development PRE 1.1
Compromise Infrastructure: Web Services T1584.006 · sub-technique of T1584 STIX ID attack-pattern--ae797531-3219-49a4-bccf-324ad7a4c7b2 Resource Development PRE 1.2
Container Administration Command T1609 STIX ID attack-pattern--7b50a1d3-4ca7-45d1-989d-a6503f04bfe1 Execution Containers 1.3
Container and Resource Discovery T1613 STIX ID attack-pattern--0470e792-32f8-46b0-a351-652bc35e9336 Discovery Containers 1.1
Content Injection T1659 STIX ID attack-pattern--43c9bc06-715b-42db-972f-52d25c09a20c Command and Control, Initial Access Linux, macOS, Windows 1.0
Create Account T1136 STIX ID attack-pattern--e01be9c5-e763-4caf-aeb7-000b416aef67 Persistence Containers, ESXi, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows 2.6
Create Account: Cloud Account T1136.003 · sub-technique of T1136 STIX ID attack-pattern--a009cb25-4801-4116-9105-80a91cf15c1b Persistence IaaS, Identity Provider, Office Suite, SaaS 1.6
Create Account: Domain Account T1136.002 · sub-technique of T1136 STIX ID attack-pattern--7610cada-1499-41a4-b3dd-46467b68d177 Persistence Linux, macOS, Windows 1.1
Create Account: Local Account T1136.001 · sub-technique of T1136 STIX ID attack-pattern--635cbe30-392d-4e27-978e-66774357c762 Persistence Containers, ESXi, Linux, macOS, Network Devices, Windows 1.5
Create or Modify System Process T1543 STIX ID attack-pattern--106c0cf6-bf73-4601-9aa8-0945c2715ec5 Persistence, Privilege Escalation Containers, Linux, macOS, Windows 1.2
Create or Modify System Process: Container Service T1543.005 · sub-technique of T1543 STIX ID attack-pattern--b0e54bf7-835e-4f44-bd8e-62f431b9b76a Persistence, Privilege Escalation Containers 1.0
Create or Modify System Process: Launch Agent T1543.001 · sub-technique of T1543 STIX ID attack-pattern--d10cbd34-42e3-45c0-84d2-535a09849584 Persistence, Privilege Escalation macOS 1.5
Create or Modify System Process: Launch Daemon T1543.004 · sub-technique of T1543 STIX ID attack-pattern--573ad264-1371-4ae0-8482-d2673b719dba Persistence, Privilege Escalation macOS 1.3
Create or Modify System Process: Systemd Service T1543.002 · sub-technique of T1543 STIX ID attack-pattern--dfefe2ed-4389-4318-8762-f0272b350a1b Persistence, Privilege Escalation Linux 1.6
Create or Modify System Process: Windows Service T1543.003 · sub-technique of T1543 STIX ID attack-pattern--2959d63f-73fd-46a1-abd2-109d7dcede32 Persistence, Privilege Escalation Windows 1.6
Credentials from Password Stores T1555 STIX ID attack-pattern--3fc9b85a-2862-4363-a64d-d692e3ffbee0 Credential Access IaaS, Linux, macOS, Windows 1.2
Credentials from Password Stores: Cloud Secrets Management Stores T1555.006 · sub-technique of T1555 STIX ID attack-pattern--cfb525cc-5494-401d-a82b-2539ca46a561 Credential Access IaaS 1.0
Credentials from Password Stores: Credentials from Web Browsers T1555.003 · sub-technique of T1555 STIX ID attack-pattern--58a3e6aa-4453-4cc8-a51f-4befe80b31a8 Credential Access Linux, macOS, Windows 1.2
Credentials from Password Stores: Keychain T1555.001 · sub-technique of T1555 STIX ID attack-pattern--1eaebf46-e361-4437-bc23-d5d65a3b92e3 Credential Access macOS 1.1
Credentials from Password Stores: Password Managers T1555.005 · sub-technique of T1555 STIX ID attack-pattern--315f51f0-6b03-4c1e-bfb2-84740afb8e21 Credential Access Linux, macOS, Windows 1.1
Credentials from Password Stores: Securityd Memory T1555.002 · sub-technique of T1555 STIX ID attack-pattern--1a80d097-54df-41d8-9d33-34e755ec5e72 Credential Access Linux, macOS 1.2
Credentials from Password Stores: Windows Credential Manager T1555.004 · sub-technique of T1555 STIX ID attack-pattern--d336b553-5da9-46ca-98a8-0b23f49fb447 Credential Access Windows 1.1
Data Destruction T1485 STIX ID attack-pattern--d45a3d09-b3cf-48f4-9f0f-f521ee5cb05c Impact Containers, ESXi, IaaS, Linux, macOS, Windows 1.4
Data Destruction: Lifecycle-Triggered Deletion T1485.001 · sub-technique of T1485 STIX ID attack-pattern--1001e0d6-ee09-4dfc-aa90-e9320ffc8fe4 Impact IaaS 1.1
Data Encoding T1132 STIX ID attack-pattern--cc7b8c4e-9be0-47ca-b0bb-83915ec3ee2f Command and Control ESXi, Linux, macOS, Windows 1.3
Data Encoding: Non-Standard Encoding T1132.002 · sub-technique of T1132 STIX ID attack-pattern--d467bc38-284b-4a00-96ac-125f447799fc Command and Control ESXi, Linux, macOS, Windows 1.1
Data Encoding: Standard Encoding T1132.001 · sub-technique of T1132 STIX ID attack-pattern--04fd5427-79c7-44ea-ae13-11b24778ff1c Command and Control ESXi, Linux, macOS, Windows 1.1
Data Encrypted for Impact T1486 STIX ID attack-pattern--b80d107d-fa0d-4b60-9684-b0433e8bdba0 Impact ESXi, IaaS, Linux, macOS, Windows 1.5
Data Manipulation T1565 STIX ID attack-pattern--ac9e6b22-11bf-45d7-9181-c1cb08360931 Impact Linux, macOS, Windows 1.1
Data Manipulation: Runtime Data Manipulation T1565.003 · sub-technique of T1565 STIX ID attack-pattern--32ad5c86-2bcf-47d8-8fdc-d7f3d79a7490 Impact Linux, macOS, Windows 1.2
Data Manipulation: Stored Data Manipulation T1565.001 · sub-technique of T1565 STIX ID attack-pattern--1cfcb312-b8d7-47a4-b560-4b16cc677292 Impact Linux, macOS, Windows 1.1
Data Manipulation: Transmitted Data Manipulation T1565.002 · sub-technique of T1565 STIX ID attack-pattern--d0613359-5781-4fd2-b5be-c269270be1f6 Impact Linux, macOS, Windows 1.1
Data Obfuscation T1001 STIX ID attack-pattern--ad255bfe-a9e6-4b52-a258-8d3462abe842 Command and Control ESXi, Linux, macOS, Windows 1.2
Data Obfuscation: Junk Data T1001.001 · sub-technique of T1001 STIX ID attack-pattern--f7c0689c-4dbd-489b-81be-7cb7c7079ade Command and Control ESXi, Linux, macOS, Windows 1.1
Data Obfuscation: Protocol or Service Impersonation T1001.003 · sub-technique of T1001 STIX ID attack-pattern--c325b232-d5bc-4dde-a3ec-71f3db9e8adc Command and Control ESXi, Linux, macOS, Windows 2.1
Data Obfuscation: Steganography T1001.002 · sub-technique of T1001 STIX ID attack-pattern--eec23884-3fa1-4d8a-ac50-6f104d51e235 Command and Control ESXi, Linux, macOS, Windows 1.1
Data Staged T1074 STIX ID attack-pattern--7dd95ff6-712e-4056-9626-312ea4ab4c5e Collection ESXi, IaaS, Linux, macOS, Windows 1.5
Data Staged: Local Data Staging T1074.001 · sub-technique of T1074 STIX ID attack-pattern--1c34f7aa-9341-4a48-bfab-af22e51aca6c Collection ESXi, Linux, macOS, Windows 1.2
Data Staged: Remote Data Staging T1074.002 · sub-technique of T1074 STIX ID attack-pattern--359b00ad-9425-420b-bba5-6de8d600cbc0 Collection ESXi, IaaS, Linux, macOS, Windows 1.2
Data Transfer Size Limits T1030 STIX ID attack-pattern--c3888c54-775d-4b2f-b759-75a2ececcbfd Exfiltration ESXi, Linux, macOS, Windows 1.1
Data from Cloud Storage T1530 STIX ID attack-pattern--3298ce88-1628-43b1-87d9-0b5336b193d7 Collection IaaS, Office Suite, SaaS 2.2
Data from Configuration Repository T1602 STIX ID attack-pattern--0ad7bc5c-235a-4048-944b-3b286676cb74 Collection Network Devices 1.1
Data from Configuration Repository: Network Device Configuration Dump T1602.002 · sub-technique of T1602 STIX ID attack-pattern--52759bf1-fe12-4052-ace6-c5b0cf7dd7fd Collection Network Devices 1.1
Data from Configuration Repository: SNMP (MIB Dump) T1602.001 · sub-technique of T1602 STIX ID attack-pattern--ee7ff928-801c-4f34-8a99-3df965e581a5 Collection Network Devices 1.1
Data from Information Repositories T1213 STIX ID attack-pattern--d28ef391-8ed4-45dc-bc4a-2f43abf54416 Collection IaaS, Linux, macOS, Office Suite, SaaS, Windows 3.4
Data from Information Repositories: Code Repositories T1213.003 · sub-technique of T1213 STIX ID attack-pattern--cff94884-3b1c-4987-a70b-6d5643c621c3 Collection SaaS 1.2
Data from Information Repositories: Confluence T1213.001 · sub-technique of T1213 STIX ID attack-pattern--7ad38ef1-381a-406d-872a-38b136eb5ecc Collection SaaS 1.1
Data from Information Repositories: Customer Relationship Management Software T1213.004 · sub-technique of T1213 STIX ID attack-pattern--bbfbb096-6561-4d7d-aa2c-a5ee8e44c696 Collection SaaS 1.0
Data from Information Repositories: Databases T1213.006 · sub-technique of T1213 STIX ID attack-pattern--248d3fe1-7fe1-4d71-91c7-8bb7ef35cad3 Collection IaaS, Linux, macOS, SaaS, Windows 1.0
Data from Information Repositories: Messaging Applications T1213.005 · sub-technique of T1213 STIX ID attack-pattern--fb75213f-cfb0-40bf-a02f-3bad93d6601e Collection Office Suite, SaaS 1.0
Data from Information Repositories: Sharepoint T1213.002 · sub-technique of T1213 STIX ID attack-pattern--0c4b4fda-9062-47da-98b9-ceae2dcf052a Collection Office Suite, Windows 1.1
Data from Local System T1005 STIX ID attack-pattern--3c4a2599-71ee-4405-ba1e-0e28414b4bc5 Collection ESXi, Linux, macOS, Network Devices, Windows 1.8
Data from Network Shared Drive T1039 STIX ID attack-pattern--ae676644-d2d2-41b7-af7e-9bed1b55898c Collection Linux, macOS, Windows 1.5
Data from Removable Media T1025 STIX ID attack-pattern--1b7ba276-eedc-4951-a762-0ceea2c030ec Collection Linux, macOS, Windows 1.3
Debugger Evasion T1622 STIX ID attack-pattern--e4dc8c01-417f-458d-9ee0-bb0617c1b391 Discovery, Stealth Linux, macOS, Windows 2.0
Defacement T1491 STIX ID attack-pattern--5909f20f-3c39-4795-be06-ef1ea40d350b Impact ESXi, IaaS, Linux, macOS, Windows 1.4
Defacement: External Defacement T1491.002 · sub-technique of T1491 STIX ID attack-pattern--0cfe31a7-81fc-472c-bc45-e2808d1066a3 Impact IaaS, Linux, macOS, Windows 1.2
Defacement: Internal Defacement T1491.001 · sub-technique of T1491 STIX ID attack-pattern--8c41090b-aa47-4331-986b-8c9a51a91103 Impact ESXi, Linux, macOS, Windows 1.2
Delay Execution T1678 STIX ID attack-pattern--a1df809c-7d0e-459f-8fe5-25474bab770b Stealth Linux, macOS, Windows 2.0
Deobfuscate/Decode Files or Information T1140 STIX ID attack-pattern--3ccef7ae-cb5e-48f6-8302-897105fbf55c Stealth ESXi, Linux, macOS, Windows 2.0
Deploy Container T1610 STIX ID attack-pattern--56e0d8b8-3e25-49dd-9050-3aa252f5aa92 Execution Containers 2.0
Develop Capabilities T1587 STIX ID attack-pattern--edadea33-549c-4ed1-9783-8f5a5853cbdf Resource Development PRE 1.1
Develop Capabilities: Code Signing Certificates T1587.002 · sub-technique of T1587 STIX ID attack-pattern--34b3f738-bd64-40e5-a112-29b0542bc8bf Resource Development PRE 1.1
Develop Capabilities: Digital Certificates T1587.003 · sub-technique of T1587 STIX ID attack-pattern--1cec9319-743b-4840-bb65-431547bce82a Resource Development PRE 1.2
Develop Capabilities: Exploits T1587.004 · sub-technique of T1587 STIX ID attack-pattern--bbc3cba7-84ae-410d-b18b-16750731dfa2 Resource Development PRE 1.0
Develop Capabilities: Malware T1587.001 · sub-technique of T1587 STIX ID attack-pattern--212306d8-efa4-44c9-8c2d-ed3d2e224aa0 Resource Development PRE 1.3
Device Driver Discovery T1652 STIX ID attack-pattern--215d9700-5881-48b8-8265-6449dbb7195d Discovery Linux, macOS, Windows 1.0
Direct Volume Access T1006 STIX ID attack-pattern--0c8ab3eb-df48-4b9c-ace7-beacaac81cc5 Stealth Network Devices, Windows 3.0
Disable or Modify System Firewall T1686 STIX ID attack-pattern--eec096b8-c207-43df-b6c1-11523861e452 Defense Impairment ESXi, Linux, macOS, Network Devices, Windows 1.0
Disable or Modify System Firewall: Cloud Firewall T1686.001 · sub-technique of T1686 STIX ID attack-pattern--ee474564-64be-4b83-a958-53f238f49b01 Defense Impairment IaaS 1.0
Disable or Modify System Firewall: Network Device Firewall T1686.002 · sub-technique of T1686 STIX ID attack-pattern--a29aa77c-a88d-4f19-bab9-7751941b2e2d Defense Impairment Network Devices 1.0
Disable or Modify System Firewall: Windows Host Firewall T1686.003 · sub-technique of T1686 STIX ID attack-pattern--291ede6c-1473-454c-b614-5ac5ea63c987 Defense Impairment Windows 1.0
Disable or Modify Tools T1685 STIX ID attack-pattern--bbde9781-60aa-4b8a-a911-895b0c1b3872 Defense Impairment Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows 1.0
Disable or Modify Tools: Clear Linux or Mac System Logs T1685.006 · sub-technique of T1685 STIX ID attack-pattern--5e29d64d-2b14-4f92-875e-4c9c498e213c Defense Impairment Linux, macOS 1.0
Disable or Modify Tools: Clear Windows Event Logs T1685.005 · sub-technique of T1685 STIX ID attack-pattern--75b9a4d2-d4e2-4ca1-9aab-1badd9e05fd0 Defense Impairment Windows 1.0
Disable or Modify Tools: Disable or Modify Cloud Log T1685.002 · sub-technique of T1685 STIX ID attack-pattern--34ff60a3-a3f8-42e4-bed0-af9a2cb563d7 Defense Impairment IaaS, Identity Provider, Office Suite, SaaS 1.0
Disable or Modify Tools: Disable or Modify Linux Audit System Log T1685.004 · sub-technique of T1685 STIX ID attack-pattern--23d69d00-80c4-42ff-9dac-dbd0459dad75 Defense Impairment Linux 1.0
Disable or Modify Tools: Disable or Modify Windows Event Log T1685.001 · sub-technique of T1685 STIX ID attack-pattern--1411e6b8-80a6-4465-9909-54eaa9c67ce0 Defense Impairment Windows 1.0
Disable or Modify Tools: Modify or Spoof Tool UI T1685.003 · sub-technique of T1685 STIX ID attack-pattern--0ff4bd68-aebb-4039-9e00-9f92c705edf4 Defense Impairment Linux, macOS, Windows 1.0
Disk Wipe T1561 STIX ID attack-pattern--1988cc35-ced8-4dad-b2d1-7628488fa967 Impact Linux, macOS, Network Devices, Windows 1.2
Disk Wipe: Disk Content Wipe T1561.001 · sub-technique of T1561 STIX ID attack-pattern--fb640c43-aa6b-431e-a961-a279010424ac Impact Linux, macOS, Network Devices, Windows 1.2
Disk Wipe: Disk Structure Wipe T1561.002 · sub-technique of T1561 STIX ID attack-pattern--0af0ca99-357d-4ba1-805f-674fdfb7bef9 Impact Linux, macOS, Network Devices, Windows 1.2
Domain Trust Discovery T1482 STIX ID attack-pattern--767dbf9e-df3f-45cb-8998-4903ab5f80c0 Discovery Windows 1.2
Domain or Tenant Policy Modification T1484 STIX ID attack-pattern--ebb42bbe-62d7-47d7-a55f-3b08b61d792d Defense Impairment, Privilege Escalation Identity Provider, Windows 4.0
Domain or Tenant Policy Modification: Group Policy Modification T1484.001 · sub-technique of T1484 STIX ID attack-pattern--5d2be8b9-d24c-4e98-83bf-2f5f79477163 Defense Impairment, Privilege Escalation Windows 2.0
Domain or Tenant Policy Modification: Trust Modification T1484.002 · sub-technique of T1484 STIX ID attack-pattern--24769ab5-14bd-4f4e-a752-cfb185da53ee Defense Impairment, Privilege Escalation Identity Provider, Windows 3.0
Downgrade Attack T1689 STIX ID attack-pattern--30904c16-39f9-41c6-b01a-500eb8878442 Defense Impairment Linux, macOS, Windows 1.0
Drive-by Compromise T1189 STIX ID attack-pattern--d742a578-d70e-4d0e-96a6-02a9c30204e6 Initial Access Identity Provider, Linux, macOS, Windows 1.7
Dynamic Resolution T1568 STIX ID attack-pattern--7bd9c723-2f78-4309-82c5-47cad406572b Command and Control ESXi, Linux, macOS, Windows 1.1
Dynamic Resolution: DNS Calculation T1568.003 · sub-technique of T1568 STIX ID attack-pattern--83a766f8-1501-4b3a-a2de-2e2849e8dfc1 Command and Control ESXi, Linux, macOS, Windows 1.1
Dynamic Resolution: Domain Generation Algorithms T1568.002 · sub-technique of T1568 STIX ID attack-pattern--118f61a5-eb3e-4fb6-931f-2096647f4ecd Command and Control ESXi, Linux, macOS, Windows 1.2
Dynamic Resolution: Fast Flux DNS T1568.001 · sub-technique of T1568 STIX ID attack-pattern--29ba5a15-3b7b-4732-b817-65ea8f6468e6 Command and Control ESXi, Linux, macOS, Windows 1.1
ESXi Administration Command T1675 STIX ID attack-pattern--31e5011f-090e-45be-9bb6-17a1c5e8219b Execution ESXi 1.0
Email Bombing T1667 STIX ID attack-pattern--bed81616-3dde-4685-be6e-ba9820f9a7ed Impact Linux, macOS, Office Suite, Windows 1.0
Email Collection T1114 STIX ID attack-pattern--1608f3e1-598a-42f4-a01a-2e252e81728f Collection Linux, macOS, Office Suite, Windows 2.6
Email Collection: Email Forwarding Rule T1114.003 · sub-technique of T1114 STIX ID attack-pattern--7d77a07d-02fe-4e88-8bd9-e9c008c01bf0 Collection Linux, macOS, Office Suite, Windows 1.4
Email Collection: Local Email Collection T1114.001 · sub-technique of T1114 STIX ID attack-pattern--1e9eb839-294b-48cc-b0d3-c45555a2a004 Collection Windows 1.1
Email Collection: Remote Email Collection T1114.002 · sub-technique of T1114 STIX ID attack-pattern--b4694861-542c-48ea-9eb1-10d356e7140a Collection Office Suite, Windows 1.3
Encrypted Channel T1573 STIX ID attack-pattern--b8902400-e6c5-4ba2-95aa-2d35b442b118 Command and Control ESXi, Linux, macOS, Network Devices, Windows 1.2
Encrypted Channel: Asymmetric Cryptography T1573.002 · sub-technique of T1573 STIX ID attack-pattern--bf176076-b789-408e-8cba-7275e81c0ada Command and Control ESXi, Linux, macOS, Network Devices, Windows 1.2
Encrypted Channel: Symmetric Cryptography T1573.001 · sub-technique of T1573 STIX ID attack-pattern--24bfaeba-cb0d-4525-b3dc-507c77ecec41 Command and Control ESXi, Linux, macOS, Network Devices, Windows 1.2
Endpoint Denial of Service T1499 STIX ID attack-pattern--c675646d-e204-4aa8-978d-e3d6d65885c4 Impact Containers, IaaS, Linux, macOS, Windows 1.2
Endpoint Denial of Service: Application Exhaustion Flood T1499.003 · sub-technique of T1499 STIX ID attack-pattern--18cffc21-3260-437e-80e4-4ab8bf2ba5e9 Impact IaaS, Linux, macOS, Windows 1.3
Endpoint Denial of Service: Application or System Exploitation T1499.004 · sub-technique of T1499 STIX ID attack-pattern--2bee5ffb-7a7a-4119-b1f2-158151b19ac0 Impact IaaS, Linux, macOS, Windows 1.3
Endpoint Denial of Service: OS Exhaustion Flood T1499.001 · sub-technique of T1499 STIX ID attack-pattern--0df05477-c572-4ed6-88a9-47c581f548f7 Impact Linux, macOS, Windows 1.2
Endpoint Denial of Service: Service Exhaustion Flood T1499.002 · sub-technique of T1499 STIX ID attack-pattern--38eb0c22-6caf-46ce-8869-5964bd735858 Impact IaaS, Linux, macOS, Windows 1.4
Escape to Host T1611 STIX ID attack-pattern--4a5b7ade-8bb5-4853-84ed-23f262002665 Privilege Escalation Containers, ESXi, Linux, Windows 1.6
Establish Accounts T1585 STIX ID attack-pattern--cdfc5f0a-9bb9-4352-b896-553cfa2d8fd8 Resource Development PRE 1.3
Establish Accounts: Cloud Accounts T1585.003 · sub-technique of T1585 STIX ID attack-pattern--926d8cfd-1d0d-4da2-ab49-3ca10ec3f3b5 Resource Development PRE 1.1
Establish Accounts: Email Accounts T1585.002 · sub-technique of T1585 STIX ID attack-pattern--65013dd2-bc61-43e3-afb5-a14c4fa7437a Resource Development PRE 1.1
Establish Accounts: Social Media Accounts T1585.001 · sub-technique of T1585 STIX ID attack-pattern--b1ccd744-3f78-4a0e-9bb2-2002057f7928 Resource Development PRE 1.1
Event Triggered Execution T1546 STIX ID attack-pattern--b6301b64-ef57-4cce-bb0b-77026f14a8db Persistence, Privilege Escalation IaaS, Linux, macOS, Office Suite, SaaS, Windows 1.4
Event Triggered Execution: Accessibility Features T1546.008 · sub-technique of T1546 STIX ID attack-pattern--70e52b04-2a0c-4cea-9d18-7149f1df9dc5 Persistence, Privilege Escalation Windows 1.2
Event Triggered Execution: AppCert DLLs T1546.009 · sub-technique of T1546 STIX ID attack-pattern--7d57b371-10c2-45e5-b3cc-83a8fb380e4c Persistence, Privilege Escalation Windows 1.1
Event Triggered Execution: AppInit DLLs T1546.010 · sub-technique of T1546 STIX ID attack-pattern--cc89ecbd-3d33-4a41-bcca-001e702d18fd Persistence, Privilege Escalation Windows 1.2
Event Triggered Execution: Application Shimming T1546.011 · sub-technique of T1546 STIX ID attack-pattern--42fe883a-21ea-4cfb-b94a-78b6476dcc83 Persistence, Privilege Escalation Windows 1.1
Event Triggered Execution: Change Default File Association T1546.001 · sub-technique of T1546 STIX ID attack-pattern--98034fef-d9fb-4667-8dc4-2eab6231724c Persistence, Privilege Escalation Windows 1.1
Event Triggered Execution: Component Object Model Hijacking T1546.015 · sub-technique of T1546 STIX ID attack-pattern--bc0f5e80-91c0-4e04-9fbb-e4e332c85dae Persistence, Privilege Escalation Windows 1.3
Event Triggered Execution: Emond T1546.014 · sub-technique of T1546 STIX ID attack-pattern--9c45eaa3-8604-4780-8988-b5074dbb9ecd Persistence, Privilege Escalation macOS 1.1
Event Triggered Execution: Image File Execution Options Injection T1546.012 · sub-technique of T1546 STIX ID attack-pattern--6d4a7fb3-5a24-42be-ae61-6728a2b581f6 Persistence, Privilege Escalation Windows 1.2
Event Triggered Execution: Installer Packages T1546.016 · sub-technique of T1546 STIX ID attack-pattern--da051493-ae9c-4b1b-9760-c009c46c9b56 Persistence, Privilege Escalation Linux, macOS, Windows 1.2
Event Triggered Execution: LC_LOAD_DYLIB Addition T1546.006 · sub-technique of T1546 STIX ID attack-pattern--10ff21b9-5a01-4268-a1b5-3b55015f1847 Persistence, Privilege Escalation macOS 1.1
Event Triggered Execution: Netsh Helper DLL T1546.007 · sub-technique of T1546 STIX ID attack-pattern--f63fe421-b1d1-45c0-b8a7-02cd16ff2bed Persistence, Privilege Escalation Windows 1.1
Event Triggered Execution: PowerShell Profile T1546.013 · sub-technique of T1546 STIX ID attack-pattern--0f2c410d-d740-4ed9-abb1-b8f4a7faf6c3 Persistence, Privilege Escalation Windows 1.2
Event Triggered Execution: Python Startup Hooks T1546.018 · sub-technique of T1546 STIX ID attack-pattern--c5087385-9b7c-4488-9923-d9e370bf08df Persistence, Privilege Escalation Linux, macOS, Windows 1.0
Event Triggered Execution: Screensaver T1546.002 · sub-technique of T1546 STIX ID attack-pattern--ce4b7013-640e-48a9-b501-d0025a95f4bf Persistence, Privilege Escalation Windows 1.3
Event Triggered Execution: Trap T1546.005 · sub-technique of T1546 STIX ID attack-pattern--63220765-d418-44de-8fae-694b3912317d Persistence, Privilege Escalation Linux, macOS 1.1
Event Triggered Execution: Udev Rules T1546.017 · sub-technique of T1546 STIX ID attack-pattern--f4c3f644-ab33-433d-8648-75cc03a95792 Persistence, Privilege Escalation Linux 1.0
Event Triggered Execution: Unix Shell Configuration Modification T1546.004 · sub-technique of T1546 STIX ID attack-pattern--b63a34e8-0a61-4c97-a23b-bf8a2ed812e2 Persistence, Privilege Escalation Linux, macOS 2.2
Event Triggered Execution: Windows Management Instrumentation Event Subscription T1546.003 · sub-technique of T1546 STIX ID attack-pattern--910906dd-8c0a-475a-9cc1-5e029e2fad58 Persistence, Privilege Escalation Windows 1.5
Exclusive Control T1668 STIX ID attack-pattern--dff263cc-328e-42b4-afbc-1fee8b6a8913 Persistence Linux, macOS, Windows 1.0
Execution Guardrails T1480 STIX ID attack-pattern--853c4192-4311-43e1-bfbb-b11b14911852 Stealth ESXi, Linux, macOS, Windows 2.0
Execution Guardrails: Environmental Keying T1480.001 · sub-technique of T1480 STIX ID attack-pattern--f244b8dd-af6c-4391-a497-fc03627ce995 Stealth Linux, macOS, Windows 2.0
Execution Guardrails: Mutual Exclusion T1480.002 · sub-technique of T1480 STIX ID attack-pattern--49fca0d2-685d-41eb-8bd4-05451cc3a742 Stealth Linux, macOS, Windows 2.0
Exfiltration Over Alternative Protocol T1048 STIX ID attack-pattern--a19e86f8-1c0a-4fea-8407-23b73d615776 Exfiltration ESXi, IaaS, Linux, macOS, Network Devices, Office Suite, SaaS, Windows 1.6
Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol T1048.002 · sub-technique of T1048 STIX ID attack-pattern--8e350c1d-ac79-4b5c-bd4e-7476d7e84ec5 Exfiltration ESXi, Linux, macOS, Windows 1.2
Exfiltration Over Alternative Protocol: Exfiltration Over Symmetric Encrypted Non-C2 Protocol T1048.001 · sub-technique of T1048 STIX ID attack-pattern--79a4052e-1a89-4b09-aea6-51f1d11fe19c Exfiltration ESXi, Linux, macOS, Windows 1.1
Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol T1048.003 · sub-technique of T1048 STIX ID attack-pattern--fb8d023d-45be-47e9-bc51-f56bcae6435b Exfiltration ESXi, Linux, macOS, Network Devices, Windows 2.2
Exfiltration Over C2 Channel T1041 STIX ID attack-pattern--92d7da27-2d91-488e-a00c-059dc162766d Exfiltration ESXi, Linux, macOS, Windows 2.3
Exfiltration Over Other Network Medium T1011 STIX ID attack-pattern--51ea26b1-ff1e-4faa-b1a0-1114cd298c87 Exfiltration Linux, macOS, Windows 1.2
Exfiltration Over Other Network Medium: Exfiltration Over Bluetooth T1011.001 · sub-technique of T1011 STIX ID attack-pattern--613d08bc-e8f4-4791-80b0-c8b974340dfd Exfiltration Linux, macOS, Windows 1.2
Exfiltration Over Physical Medium T1052 STIX ID attack-pattern--e6415f09-df0e-48de-9aba-928c902b7549 Exfiltration Linux, macOS, Windows 1.3
Exfiltration Over Physical Medium: Exfiltration over USB T1052.001 · sub-technique of T1052 STIX ID attack-pattern--a3e1e6c5-9c74-4fc0-a16c-a9d228c17829 Exfiltration Linux, macOS, Windows 1.2
Exfiltration Over Web Service T1567 STIX ID attack-pattern--40597f16-0963-4249-bf4c-ac93b7fb9807 Exfiltration ESXi, Linux, macOS, Office Suite, SaaS, Windows 1.5
Exfiltration Over Web Service: Exfiltration Over Webhook T1567.004 · sub-technique of T1567 STIX ID attack-pattern--43f2776f-b4bd-4118-94b8-fee47e69676d Exfiltration ESXi, Linux, macOS, Office Suite, SaaS, Windows 1.2
Exfiltration Over Web Service: Exfiltration to Cloud Storage T1567.002 · sub-technique of T1567 STIX ID attack-pattern--bf1b6176-597c-4600-bfcd-ac989670f96b Exfiltration ESXi, Linux, macOS, Windows 1.3
Exfiltration Over Web Service: Exfiltration to Code Repository T1567.001 · sub-technique of T1567 STIX ID attack-pattern--86a96bf6-cf8b-411c-aaeb-8959944d64f7 Exfiltration ESXi, Linux, macOS, Windows 1.2
Exfiltration Over Web Service: Exfiltration to Text Storage Sites T1567.003 · sub-technique of T1567 STIX ID attack-pattern--ba04e672-da86-4e69-aa15-0eca5db25f43 Exfiltration ESXi, Linux, macOS, Windows 1.1
Exploit Public-Facing Application T1190 STIX ID attack-pattern--3f886f2a-874f-4333-b794-aa6075009b1c Initial Access Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows 2.8
Exploitation for Client Execution T1203 STIX ID attack-pattern--be2dcee9-a7a7-4e38-afd6-21b31ecc3d63 Execution Linux, macOS, Windows 1.5
Exploitation for Credential Access T1212 STIX ID attack-pattern--9c306d8d-cde7-4b4c-b6e8-d0bb16caca36 Credential Access Identity Provider, Linux, macOS, Windows 1.6
Exploitation for Defense Impairment T1687 STIX ID attack-pattern--01c9b54f-c04e-41ba-b0c3-cfe784b3a463 Defense Impairment IaaS, Linux, macOS, SaaS, Windows 1.0
Exploitation for Privilege Escalation T1068 STIX ID attack-pattern--b21c3b2d-02e6-45b1-980b-e69051040839 Privilege Escalation Containers, Linux, macOS, Windows 1.6
Exploitation for Stealth T1211 STIX ID attack-pattern--fe926152-f431-4baf-956c-4ad3cb0bf23b Stealth IaaS, Linux, macOS, SaaS, Windows 2.0
Exploitation of Remote Services T1210 STIX ID attack-pattern--9db0cf3a-a3c9-4012-8268-123b9db6fd82 Lateral Movement ESXi, Linux, macOS, Windows 1.2
External Remote Services T1133 STIX ID attack-pattern--10d51417-ee35-4589-b1ff-b6df1c334e8d Initial Access, Persistence Containers, Linux, macOS, Windows 2.5
Fallback Channels T1008 STIX ID attack-pattern--f24faf46-3b26-4dbb-98f2-63460498e433 Command and Control ESXi, Linux, macOS, Windows 1.1
File and Directory Discovery T1083 STIX ID attack-pattern--7bc57495-ea59-4380-be31-a64af124ef18 Discovery ESXi, Linux, macOS, Network Devices, Windows 1.7
File and Directory Permissions Modification T1222 STIX ID attack-pattern--65917ae0-b854-4139-83fe-bf2441cf0196 Defense Impairment ESXi, Linux, macOS, Windows 3.0
File and Directory Permissions Modification: Linux and Mac Permissions T1222.002 · sub-technique of T1222 STIX ID attack-pattern--09b130a2-a77e-4af0-a361-f46f9aad1345 Defense Impairment Linux, macOS 2.0
File and Directory Permissions Modification: Windows Permissions T1222.001 · sub-technique of T1222 STIX ID attack-pattern--34e793de-0274-4982-9c1a-246ed1c19dee Defense Impairment Windows 2.0
Financial Theft T1657 STIX ID attack-pattern--851e071f-208d-4c79-adc6-5974c85c78f3 Impact Linux, macOS, Office Suite, SaaS, Windows 1.2
Firmware Corruption T1495 STIX ID attack-pattern--f5bb433e-bdf6-4781-84bc-35e97e43be89 Impact Linux, macOS, Network Devices, Windows 1.3
Forced Authentication T1187 STIX ID attack-pattern--b77cf5f3-6060-475d-bd60-40ccbf28fdc2 Credential Access Windows 1.4
Forge Web Credentials T1606 STIX ID attack-pattern--94cb00a4-b295-4d06-aa2b-5653b9c1be9c Credential Access IaaS, Identity Provider, Linux, macOS, Office Suite, SaaS, Windows 1.5
Forge Web Credentials: SAML Tokens T1606.002 · sub-technique of T1606 STIX ID attack-pattern--1f9c2bae-b441-4f66-a8af-b65946ee72f2 Credential Access IaaS, Identity Provider, Office Suite, SaaS, Windows 1.4
Forge Web Credentials: Web Cookies T1606.001 · sub-technique of T1606 STIX ID attack-pattern--861b8fd2-57f3-4ee1-ab5d-c19c3b8c7a4a Credential Access IaaS, Linux, macOS, SaaS, Windows 1.1
Gather Victim Host Information T1592 STIX ID attack-pattern--09312b1a-c3c6-4b45-9844-3ccc78e5d82f Reconnaissance PRE 1.2
Gather Victim Host Information: Client Configurations T1592.004 · sub-technique of T1592 STIX ID attack-pattern--774ad5bb-2366-4c13-a8a9-65e50b292e7c Reconnaissance PRE 1.1
Gather Victim Host Information: Firmware T1592.003 · sub-technique of T1592 STIX ID attack-pattern--b85f6ce5-81e8-4f36-aff2-3df9d02a9c9d Reconnaissance PRE 1.0
Gather Victim Host Information: Hardware T1592.001 · sub-technique of T1592 STIX ID attack-pattern--24286c33-d4a4-4419-85c2-1d094a896c26 Reconnaissance PRE 1.1
Gather Victim Host Information: Software T1592.002 · sub-technique of T1592 STIX ID attack-pattern--baf60e1a-afe5-4d31-830f-1b1ba2351884 Reconnaissance PRE 1.2
Gather Victim Identity Information T1589 STIX ID attack-pattern--5282dd9a-d26d-4e16-88b7-7c0f4553daf4 Reconnaissance PRE 1.3
Gather Victim Identity Information: Credentials T1589.001 · sub-technique of T1589 STIX ID attack-pattern--bc76d0a4-db11-4551-9ac4-01a469cfb161 Reconnaissance PRE 1.2
Gather Victim Identity Information: Email Addresses T1589.002 · sub-technique of T1589 STIX ID attack-pattern--69f897fd-12a9-4c89-ad6a-46d2f3c38262 Reconnaissance PRE 1.3
Gather Victim Identity Information: Employee Names T1589.003 · sub-technique of T1589 STIX ID attack-pattern--76551c52-b111-4884-bc47-ff3e728f0156 Reconnaissance PRE 1.0
Gather Victim Network Information T1590 STIX ID attack-pattern--9d48cab2-7929-4812-ad22-f536665f0109 Reconnaissance PRE 1.0
Gather Victim Network Information: DNS T1590.002 · sub-technique of T1590 STIX ID attack-pattern--0ff59227-8aa8-4c09-bf1f-925605bd07ea Reconnaissance PRE 1.2
Gather Victim Network Information: Domain Properties T1590.001 · sub-technique of T1590 STIX ID attack-pattern--e3b168bd-fcd7-439e-9382-2e6c2f63514d Reconnaissance PRE 1.1
Gather Victim Network Information: IP Addresses T1590.005 · sub-technique of T1590 STIX ID attack-pattern--0dda99f0-4701-48ca-9774-8504922e92d3 Reconnaissance PRE 1.0
Gather Victim Network Information: Network Security Appliances T1590.006 · sub-technique of T1590 STIX ID attack-pattern--6c2957f9-502a-478c-b1dd-d626c0659413 Reconnaissance PRE 1.0
Gather Victim Network Information: Network Topology T1590.004 · sub-technique of T1590 STIX ID attack-pattern--34ab90a3-05f6-4259-8f21-621081fdaba5 Reconnaissance PRE 1.0
Gather Victim Network Information: Network Trust Dependencies T1590.003 · sub-technique of T1590 STIX ID attack-pattern--36aa137f-5166-41f8-b2f0-a4cfa1b4133e Reconnaissance PRE 1.0
Gather Victim Org Information T1591 STIX ID attack-pattern--937e4772-8441-4e4a-8bf0-8d447d667e23 Reconnaissance PRE 1.1
Gather Victim Org Information: Business Relationships T1591.002 · sub-technique of T1591 STIX ID attack-pattern--6ee2dc99-91ad-4534-a7d8-a649358c331f Reconnaissance PRE 1.0
Gather Victim Org Information: Determine Physical Locations T1591.001 · sub-technique of T1591 STIX ID attack-pattern--ed730f20-0e44-48b9-85f8-0e2adeb76867 Reconnaissance PRE 1.1
Gather Victim Org Information: Identify Business Tempo T1591.003 · sub-technique of T1591 STIX ID attack-pattern--2339cf19-8f1e-48f7-8a91-0262ba547b6f Reconnaissance PRE 1.0
Gather Victim Org Information: Identify Roles T1591.004 · sub-technique of T1591 STIX ID attack-pattern--cc723aff-ec88-40e3-a224-5af9fd983cc4 Reconnaissance PRE 1.0
Generate Content T1683 STIX ID attack-pattern--b512fb8a-18dd-4bfc-bbad-acbaaeb7dde3 Resource Development PRE 1.0
Generate Content: Audio-Visual Content T1683.002 · sub-technique of T1683 STIX ID attack-pattern--8f452cb4-cbf4-4522-8b11-448787be95c4 Resource Development PRE 1.0
Generate Content: Written Content T1683.001 · sub-technique of T1683 STIX ID attack-pattern--6a6f9892-c46a-46db-b331-c09a99200fcf Resource Development PRE 1.0
Group Policy Discovery T1615 STIX ID attack-pattern--1b20efbf-8063-4fc3-a07d-b575318a301b Discovery Windows 1.1
Hardware Additions T1200 STIX ID attack-pattern--d40239b3-05ff-46d8-9bdd-b46d13463ef9 Initial Access Linux, macOS, Windows 1.7
Hide Artifacts T1564 STIX ID attack-pattern--22905430-4901-4c2a-84f6-98243cb173f8 Stealth ESXi, Linux, macOS, Office Suite, Windows 2.0
Hide Artifacts: Bind Mounts T1564.013 · sub-technique of T1564 STIX ID attack-pattern--5bd41255-a224-4425-a2e2-e9d293eafe1c Stealth Linux 2.0
Hide Artifacts: Email Hiding Rules T1564.008 · sub-technique of T1564 STIX ID attack-pattern--0cf55441-b176-4332-89e7-2c4c7799d0ff Stealth Linux, macOS, Office Suite, Windows 2.0
Hide Artifacts: Extended Attributes T1564.014 · sub-technique of T1564 STIX ID attack-pattern--762e6f29-a62f-4d96-91ed-d0073181431f Stealth Linux, macOS 2.0
Hide Artifacts: File/Path Exclusions T1564.012 · sub-technique of T1564 STIX ID attack-pattern--09b008a9-b4eb-462a-a751-a0eb58050cd9 Stealth Linux, macOS, Windows 2.0
Hide Artifacts: Hidden File System T1564.005 · sub-technique of T1564 STIX ID attack-pattern--dfebc3b7-d19d-450b-81c7-6dafe4184c04 Stealth Linux, macOS, Windows 2.0
Hide Artifacts: Hidden Files and Directories T1564.001 · sub-technique of T1564 STIX ID attack-pattern--ec8fc7e2-b356-455c-8db5-2e37be158e7d Stealth Linux, macOS, Windows 2.0
Hide Artifacts: Hidden Users T1564.002 · sub-technique of T1564 STIX ID attack-pattern--8c4aef43-48d5-49aa-b2af-c0cd58d30c3d Stealth Linux, macOS, Windows 2.0
Hide Artifacts: Hidden Window T1564.003 · sub-technique of T1564 STIX ID attack-pattern--cbb66055-0325-4111-aca0-40547b6ad5b0 Stealth Linux, macOS, Windows 2.0
Hide Artifacts: Ignore Process Interrupts T1564.011 · sub-technique of T1564 STIX ID attack-pattern--4a2975db-414e-4c0c-bd92-775987514b4b Stealth Linux, macOS, Windows 2.0
Hide Artifacts: NTFS File Attributes T1564.004 · sub-technique of T1564 STIX ID attack-pattern--f2857333-11d4-45bf-b064-2c28d8525be5 Stealth Windows 2.0
Hide Artifacts: Process Argument Spoofing T1564.010 · sub-technique of T1564 STIX ID attack-pattern--ffe59ad3-ad9b-4b9f-b74f-5beb3c309dc1 Stealth Windows 2.0
Hide Artifacts: Resource Forking T1564.009 · sub-technique of T1564 STIX ID attack-pattern--b22e5153-ac28-4cc6-865c-2054e36285cb Stealth macOS 2.0
Hide Artifacts: Run Virtual Instance T1564.006 · sub-technique of T1564 STIX ID attack-pattern--b5327dd1-6bf9-4785-a199-25bcbd1f4a9d Stealth ESXi, Linux, macOS, Windows 2.0
Hide Artifacts: VBA Stomping T1564.007 · sub-technique of T1564 STIX ID attack-pattern--c898c4b5-bf36-4e6e-a4ad-5b8c4c13e35b Stealth Linux, macOS, Windows 2.0
Hide Infrastructure T1665 STIX ID attack-pattern--eb897572-8979-4242-a089-56f294f4c91d Command and Control ESXi, Linux, macOS, Network Devices, Windows 1.2
Hijack Execution Flow T1574 STIX ID attack-pattern--aedfca76-3b30-4866-b2aa-0f1d7fd1e4b6 Execution, Stealth Linux, macOS, Windows 2.0
Hijack Execution Flow: AppDomainManager T1574.014 · sub-technique of T1574 STIX ID attack-pattern--356662f7-e315-4759-86c9-6214e2a50ff8 Execution, Stealth Windows 2.0
Hijack Execution Flow: COR_PROFILER T1574.012 · sub-technique of T1574 STIX ID attack-pattern--ffeb0780-356e-4261-b036-cfb6bd234335 Execution, Stealth Windows 2.0
Hijack Execution Flow: DLL T1574.001 · sub-technique of T1574 STIX ID attack-pattern--2fee9321-3e71-4cf4-af24-d4d40d355b34 Execution, Stealth Windows 3.0
Hijack Execution Flow: Dylib Hijacking T1574.004 · sub-technique of T1574 STIX ID attack-pattern--fc742192-19e3-466c-9eb5-964a97b29490 Execution, Stealth macOS 3.0
Hijack Execution Flow: Dynamic Linker Hijacking T1574.006 · sub-technique of T1574 STIX ID attack-pattern--633a100c-b2c9-41bf-9be5-905c1b16c825 Execution, Stealth Linux, macOS 3.0
Hijack Execution Flow: Executable Installer File Permissions Weakness T1574.005 · sub-technique of T1574 STIX ID attack-pattern--70d81154-b187-45f9-8ec5-295d01255979 Execution, Stealth Windows 2.0
Hijack Execution Flow: KernelCallbackTable T1574.013 · sub-technique of T1574 STIX ID attack-pattern--a4657bc9-d22f-47d2-a7b7-dd6ec33f3dde Execution, Stealth Windows 2.0
Hijack Execution Flow: Path Interception by PATH Environment Variable T1574.007 · sub-technique of T1574 STIX ID attack-pattern--0c2d00da-7742-49e7-9928-4514e5075d32 Execution, Stealth Linux, macOS, Windows 2.0
Hijack Execution Flow: Path Interception by Search Order Hijacking T1574.008 · sub-technique of T1574 STIX ID attack-pattern--58af3705-8740-4c68-9329-ec015a7013c2 Execution, Stealth Windows 2.0
Hijack Execution Flow: Path Interception by Unquoted Path T1574.009 · sub-technique of T1574 STIX ID attack-pattern--bf96a5a3-3bce-43b7-8597-88545984c07b Execution, Stealth Windows 2.0
Hijack Execution Flow: Services File Permissions Weakness T1574.010 · sub-technique of T1574 STIX ID attack-pattern--9e8b28c9-35fe-48ac-a14d-e6cc032dcbcd Execution, Stealth Windows 2.0
Hijack Execution Flow: Services Registry Permissions Weakness T1574.011 · sub-technique of T1574 STIX ID attack-pattern--17cc750b-e95b-4d7d-9dde-49e0de24148c Execution, Stealth Windows 2.0
Implant Internal Image T1525 STIX ID attack-pattern--4fd8a28b-4b3a-4cd6-a8cf-85ba5f824a7f Persistence Containers, IaaS 2.2
Indicator Removal T1070 STIX ID attack-pattern--799ace7f-e227-4411-baa0-8868704f2a69 Stealth Containers, ESXi, Linux, macOS, Network Devices, Office Suite, Windows 3.0
Indicator Removal: Clear Command History T1070.003 · sub-technique of T1070 STIX ID attack-pattern--3aef9463-9a7a-43ba-8957-a867e07c1e6a Stealth ESXi, Linux, macOS, Network Devices, Windows 2.0
Indicator Removal: Clear Mailbox Data T1070.008 · sub-technique of T1070 STIX ID attack-pattern--438c967d-3996-4870-bfc2-3954752a1927 Stealth Linux, macOS, Office Suite, Windows 2.0
Indicator Removal: Clear Network Connection History and Configurations T1070.007 · sub-technique of T1070 STIX ID attack-pattern--3975dbb5-0e1e-4f5b-bae1-cf2ab84b46dc Stealth Linux, macOS, Network Devices, Windows 2.0
Indicator Removal: Clear Persistence T1070.009 · sub-technique of T1070 STIX ID attack-pattern--d2c4e5ea-dbdf-4113-805a-b1e2a337fb33 Stealth ESXi, Linux, macOS, Windows 2.0
Indicator Removal: File Deletion T1070.004 · sub-technique of T1070 STIX ID attack-pattern--d63a3fb8-9452-4e9d-a60a-54be68d5998c Stealth ESXi, Linux, macOS, Windows 2.0
Indicator Removal: Network Share Connection Removal T1070.005 · sub-technique of T1070 STIX ID attack-pattern--a750a9f6-0bde-4bb3-9aae-1e2786e9780c Stealth Windows 2.0
Indicator Removal: Relocate Malware T1070.010 · sub-technique of T1070 STIX ID attack-pattern--cc36eeae-2209-4e63-89d3-c97e19edf280 Stealth Linux, macOS, Network Devices, Windows 2.0
Indicator Removal: Timestomp T1070.006 · sub-technique of T1070 STIX ID attack-pattern--47f2d673-ca62-47e9-929b-1b0be9657611 Stealth ESXi, Linux, macOS, Windows 2.0
Indirect Command Execution T1202 STIX ID attack-pattern--3b0e52ce-517a-4614-a523-1bd5deef6c5e Stealth Windows 2.0
Ingress Tool Transfer T1105 STIX ID attack-pattern--e6919abc-99f9-4c6c-95a5-14761e7b2add Command and Control ESXi, Linux, macOS, Network Devices, Windows 2.6
Inhibit System Recovery T1490 STIX ID attack-pattern--f5d8eed6-48a9-4cdf-a3d7-d1ffa99c3d2a Impact Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows 1.6
Input Capture T1056 STIX ID attack-pattern--bb5a00de-e086-4859-a231-fa793f6797e2 Collection, Credential Access Linux, macOS, Network Devices, Windows 1.4
Input Capture: Credential API Hooking T1056.004 · sub-technique of T1056 STIX ID attack-pattern--f5946b5e-9408-485f-a7f7-b5efc88909b6 Collection, Credential Access Linux, macOS, Windows 1.2
Input Capture: GUI Input Capture T1056.002 · sub-technique of T1056 STIX ID attack-pattern--a2029942-0a85-4947-b23c-ca434698171d Collection, Credential Access Linux, macOS, Windows 1.3
Input Capture: Keylogging T1056.001 · sub-technique of T1056 STIX ID attack-pattern--09a60ea3-a8d1-4ae5-976e-5783248b72a4 Collection, Credential Access Linux, macOS, Network Devices, Windows 1.3
Input Capture: Web Portal Capture T1056.003 · sub-technique of T1056 STIX ID attack-pattern--69e5226d-05dc-4f15-95d7-44f5ed78d06e Collection, Credential Access Linux, macOS, Windows 1.1
Input Injection T1674 STIX ID attack-pattern--63e3d25c-d57d-407d-8e6a-2cecd71f90be Execution Linux, macOS, Windows 1.0
Inter-Process Communication T1559 STIX ID attack-pattern--acd0ba37-7ba9-4cc5-ac61-796586cd856d Execution Linux, macOS, Windows 1.4
Inter-Process Communication: Component Object Model T1559.001 · sub-technique of T1559 STIX ID attack-pattern--2f6b4ed7-fef1-44ba-bcb8-1b4beb610b64 Execution Windows 1.2
Inter-Process Communication: Dynamic Data Exchange T1559.002 · sub-technique of T1559 STIX ID attack-pattern--232a7e42-cd6e-4902-8fe9-2960f529dd4d Execution Windows 1.4
Inter-Process Communication: XPC Services T1559.003 · sub-technique of T1559 STIX ID attack-pattern--8252f135-ed26-4ce1-ae61-f26e94429a19 Execution macOS 1.1
Internal Spearphishing T1534 STIX ID attack-pattern--9e7452df-5144-4b6e-b04a-b66dd4016747 Lateral Movement Linux, macOS, Office Suite, SaaS, Windows 1.4
Lateral Tool Transfer T1570 STIX ID attack-pattern--bf90d72c-c00b-45e3-b3aa-68560560d4c5 Lateral Movement ESXi, Linux, macOS, Windows 1.4
Local Storage Discovery T1680 STIX ID attack-pattern--f2514ae4-4e9b-4f26-a5ba-c4ae85fe93c3 Discovery ESXi, IaaS, Linux, macOS, Windows 1.0
Log Enumeration T1654 STIX ID attack-pattern--866d0d6d-02c6-42bd-aa2f-02907fdc0969 Discovery ESXi, IaaS, Linux, macOS, Windows 1.2
Masquerading T1036 STIX ID attack-pattern--42e8de7b-37b2-4258-905a-6897815e58e0 Stealth Containers, ESXi, Linux, macOS, Windows 2.0
Masquerading: Break Process Trees T1036.009 · sub-technique of T1036 STIX ID attack-pattern--34a80bc4-80f2-46e6-94ff-f3265a4b657c Stealth Linux, macOS 2.0
Masquerading: Browser Fingerprint T1036.012 · sub-technique of T1036 STIX ID attack-pattern--afac5dbc-4383-4fb6-9ba6-45b25d49e530 Stealth Linux, macOS, Windows 2.0
Masquerading: Double File Extension T1036.007 · sub-technique of T1036 STIX ID attack-pattern--11f29a39-0942-4d62-92b6-fe236cf3066e Stealth Windows 2.0
Masquerading: Invalid Code Signature T1036.001 · sub-technique of T1036 STIX ID attack-pattern--b4b7458f-81f2-4d38-84be-1c5ba0167a52 Stealth macOS, Windows 2.0
Masquerading: Masquerade Account Name T1036.010 · sub-technique of T1036 STIX ID attack-pattern--d349c66e-18e1-4d8b-a2d7-65af7cbd2ba0 Stealth Containers, IaaS, Identity Provider, Linux, macOS, Office Suite, SaaS, Windows 2.0
Masquerading: Masquerade File Type T1036.008 · sub-technique of T1036 STIX ID attack-pattern--208884f1-7b83-4473-ac22-4e1cf6c41471 Stealth Linux, macOS, Windows 2.0
Masquerading: Masquerade Task or Service T1036.004 · sub-technique of T1036 STIX ID attack-pattern--7bdca9d5-d500-4d7d-8c52-5fd47baf4c0c Stealth Linux, macOS, Windows 2.0
Masquerading: Match Legitimate Resource Name or Location T1036.005 · sub-technique of T1036 STIX ID attack-pattern--1c4e5d32-1fe9-4116-9d9d-59e3925bd6a2 Stealth Containers, ESXi, Linux, macOS, Windows 3.0
Masquerading: Overwrite Process Arguments T1036.011 · sub-technique of T1036 STIX ID attack-pattern--514dc7b3-0b80-4382-80a9-2e2d294f5019 Stealth Linux 2.0
Masquerading: Rename Legitimate Utilities T1036.003 · sub-technique of T1036 STIX ID attack-pattern--bd5b58a4-a52d-4a29-bc0d-3f1d3968eb6b Stealth Linux, macOS, Windows 3.0
Masquerading: Right-to-Left Override T1036.002 · sub-technique of T1036 STIX ID attack-pattern--77eae145-55db-4519-8ae5-77b0c7215d69 Stealth Linux, macOS, Windows 2.0
Masquerading: Space after Filename T1036.006 · sub-technique of T1036 STIX ID attack-pattern--e51137a5-1cdc-499e-911a-abaedaa5ac86 Stealth Linux, macOS 2.0
Modify Authentication Process T1556 STIX ID attack-pattern--f4c1826f-a322-41cd-9557-562100848c84 Credential Access, Defense Impairment, Persistence IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows 3.0
Modify Authentication Process: Conditional Access Policies T1556.009 · sub-technique of T1556 STIX ID attack-pattern--ceaeb6d8-95ee-4da2-9d42-dc6aa6ca43ae Credential Access, Defense Impairment, Persistence IaaS, Identity Provider 2.0
Modify Authentication Process: Domain Controller Authentication T1556.001 · sub-technique of T1556 STIX ID attack-pattern--d4b96d2c-1032-4b22-9235-2b5b649d0605 Credential Access, Defense Impairment, Persistence Windows 3.0
Modify Authentication Process: Hybrid Identity T1556.007 · sub-technique of T1556 STIX ID attack-pattern--54ca26f3-c172-4231-93e5-ccebcac2161f Credential Access, Defense Impairment, Persistence IaaS, Identity Provider, Office Suite, SaaS, Windows 2.0
Modify Authentication Process: Multi-Factor Authentication T1556.006 · sub-technique of T1556 STIX ID attack-pattern--b4409cd8-0da9-46e1-a401-a241afd4d1cc Credential Access, Defense Impairment, Persistence IaaS, Identity Provider, Linux, macOS, Office Suite, SaaS, Windows 2.0
Modify Authentication Process: Network Device Authentication T1556.004 · sub-technique of T1556 STIX ID attack-pattern--fa44a152-ac48-441e-a524-dd7b04b8adcd Credential Access, Defense Impairment, Persistence Network Devices 3.0
Modify Authentication Process: Network Provider DLL T1556.008 · sub-technique of T1556 STIX ID attack-pattern--90c4a591-d02d-490b-92aa-619d9701ac04 Credential Access, Defense Impairment, Persistence Windows 2.0
Modify Authentication Process: Password Filter DLL T1556.002 · sub-technique of T1556 STIX ID attack-pattern--3731fbcd-0e43-47ae-ae6c-d15e510f0d42 Credential Access, Defense Impairment, Persistence Windows 3.0
Modify Authentication Process: Pluggable Authentication Modules T1556.003 · sub-technique of T1556 STIX ID attack-pattern--06c00069-771a-4d57-8ef5-d3718c1a8771 Credential Access, Defense Impairment, Persistence Linux, macOS 3.0
Modify Authentication Process: Reversible Encryption T1556.005 · sub-technique of T1556 STIX ID attack-pattern--d50955c2-272d-4ac8-95da-10c29dda1c48 Credential Access, Defense Impairment, Persistence Windows 2.0
Modify Cloud Compute Infrastructure T1578 STIX ID attack-pattern--144e007b-e638-431d-a894-45d90c54ab90 Defense Impairment IaaS 2.0
Modify Cloud Compute Infrastructure: Create Cloud Instance T1578.002 · sub-technique of T1578 STIX ID attack-pattern--cf1c2504-433f-4c4e-a1f8-91de45a0318c Defense Impairment IaaS 2.0
Modify Cloud Compute Infrastructure: Create Snapshot T1578.001 · sub-technique of T1578 STIX ID attack-pattern--ed2e45f9-d338-4eb2-8ce5-3a2e03323bc1 Defense Impairment IaaS 2.0
Modify Cloud Compute Infrastructure: Delete Cloud Instance T1578.003 · sub-technique of T1578 STIX ID attack-pattern--70857657-bd0b-4695-ad3e-b13f92cac1b4 Defense Impairment IaaS 2.0
Modify Cloud Compute Infrastructure: Modify Cloud Compute Configurations T1578.005 · sub-technique of T1578 STIX ID attack-pattern--ca00366b-83a1-4c7b-a0ce-8ff950a7c87f Defense Impairment IaaS 3.0
Modify Cloud Compute Infrastructure: Revert Cloud Instance T1578.004 · sub-technique of T1578 STIX ID attack-pattern--0708ae90-d0eb-4938-9a76-d0fc94f6eec1 Defense Impairment IaaS 2.0
Modify Cloud Resource Hierarchy T1666 STIX ID attack-pattern--0ce73446-8722-4086-9d43-514f1d0f669e Defense Impairment IaaS 2.0
Modify Registry T1112 STIX ID attack-pattern--57340c81-c025-4189-8fa0-fc7ede51bae4 Defense Impairment, Persistence Windows 3.0
Modify System Image T1601 STIX ID attack-pattern--ae7f3575-0a5e-427e-991b-fe03ad44c754 Defense Impairment Network Devices 2.0
Modify System Image: Downgrade System Image T1601.002 · sub-technique of T1601 STIX ID attack-pattern--fc74ba38-dc98-461f-8611-b3dbf9978e3d Defense Impairment Network Devices 2.0
Modify System Image: Patch System Image T1601.001 · sub-technique of T1601 STIX ID attack-pattern--d245808a-7086-4310-984a-a84aaaa43f8f Defense Impairment Network Devices 2.0
Multi-Factor Authentication Interception T1111 STIX ID attack-pattern--dd43c543-bb85-4a6f-aa6e-160d90d06a49 Credential Access Linux, macOS, Windows 2.1
Multi-Factor Authentication Request Generation T1621 STIX ID attack-pattern--954a1639-f2d6-407d-aef3-4917622ca493 Credential Access IaaS, Identity Provider, Linux, macOS, Office Suite, SaaS, Windows 1.2
Multi-Stage Channels T1104 STIX ID attack-pattern--84e02621-8fdf-470f-bd58-993bb6a89d91 Command and Control ESXi, Linux, macOS, Windows 1.1
Native API T1106 STIX ID attack-pattern--391d824f-0ef1-47a0-b0ee-c59a75e27670 Execution Linux, macOS, Windows 2.3
Network Boundary Bridging T1599 STIX ID attack-pattern--b8017880-4b1e-42de-ad10-ae7ac6705166 Defense Impairment Network Devices 2.0
Network Boundary Bridging: Network Address Translation Traversal T1599.001 · sub-technique of T1599 STIX ID attack-pattern--4ffc1794-ec3b-45be-9e52-42dbcb2af2de Defense Impairment Network Devices 2.0
Network Denial of Service T1498 STIX ID attack-pattern--d74c4a7e-ffbf-432f-9365-7ebf1f787cab Impact Containers, IaaS, Linux, macOS, Windows 1.2
Network Denial of Service: Direct Network Flood T1498.001 · sub-technique of T1498 STIX ID attack-pattern--0bda01d5-4c1d-4062-8ee2-6872334383c3 Impact IaaS, Linux, macOS, Windows 1.4
Network Denial of Service: Reflection Amplification T1498.002 · sub-technique of T1498 STIX ID attack-pattern--36b2a1d7-e09e-49bf-b45e-477076c2ec01 Impact IaaS, Linux, macOS, Windows 1.4
Network Service Discovery T1046 STIX ID attack-pattern--e3a12395-188d-4051-9a16-ea8e14d07b88 Discovery Containers, IaaS, Linux, macOS, Network Devices, Windows 3.2
Network Share Discovery T1135 STIX ID attack-pattern--3489cfc5-640f-4bb3-a103-9137b97de79f Discovery Linux, macOS, Windows 3.2
Network Sniffing T1040 STIX ID attack-pattern--3257eb21-f9a7-4430-8de1-d8b6e288f529 Credential Access, Discovery IaaS, Linux, macOS, Network Devices, Windows 1.7
Non-Application Layer Protocol T1095 STIX ID attack-pattern--c21d5a77-d422-4a69-acd7-2c53c1faa34b Command and Control ESXi, Linux, macOS, Network Devices, Windows 2.4
Non-Standard Port T1571 STIX ID attack-pattern--b18eae87-b469-4e14-b454-b171b416bc18 Command and Control ESXi, Linux, macOS, Windows 1.3
OS Credential Dumping T1003 STIX ID attack-pattern--0a3ead4e-6d47-4ccb-854c-a6a4f9d96b22 Credential Access Linux, macOS, Windows 2.2
OS Credential Dumping: /etc/passwd and /etc/shadow T1003.008 · sub-technique of T1003 STIX ID attack-pattern--d0b4fcdb-d67d-4ed2-99ce-788b12f8c0f4 Credential Access Linux 1.2
OS Credential Dumping: Cached Domain Credentials T1003.005 · sub-technique of T1003 STIX ID attack-pattern--6add2ab5-2711-4e9d-87c8-7a0be8531530 Credential Access Linux, Windows 1.1
OS Credential Dumping: DCSync T1003.006 · sub-technique of T1003 STIX ID attack-pattern--f303a39a-6255-4b89-aecc-18c4d8ca7163 Credential Access Windows 1.1
OS Credential Dumping: LSA Secrets T1003.004 · sub-technique of T1003 STIX ID attack-pattern--1ecfdab8-7d59-4c98-95d4-dc41970f57fc Credential Access Windows 1.1
OS Credential Dumping: LSASS Memory T1003.001 · sub-technique of T1003 STIX ID attack-pattern--65f2d882-3f41-4d48-8a06-29af77ec9f90 Credential Access Windows 1.5
OS Credential Dumping: NTDS T1003.003 · sub-technique of T1003 STIX ID attack-pattern--edf91964-b26e-4b4a-9600-ccacd7d7df24 Credential Access Windows 1.3
OS Credential Dumping: Proc Filesystem T1003.007 · sub-technique of T1003 STIX ID attack-pattern--3120b9fa-23b8-4500-ae73-09494f607b7d Credential Access Linux 1.2
OS Credential Dumping: Security Account Manager T1003.002 · sub-technique of T1003 STIX ID attack-pattern--1644e709-12d2-41e5-a60f-3470991f5011 Credential Access Windows 1.1
Obfuscated Files or Information T1027 STIX ID attack-pattern--b3d682b6-98f2-4fb0-aa3b-b4df007ca70a Stealth ESXi, Linux, macOS, Network Devices, Windows 2.0
Obfuscated Files or Information: Binary Padding T1027.001 · sub-technique of T1027 STIX ID attack-pattern--5bfccc3f-2326-4112-86cc-c1ece9d8a2b5 Stealth Linux, macOS, Windows 2.0
Obfuscated Files or Information: Command Obfuscation T1027.010 · sub-technique of T1027 STIX ID attack-pattern--d511a6f6-4a33-41d5-bc95-c343875d1377 Stealth Linux, macOS, Windows 2.0
Obfuscated Files or Information: Compile After Delivery T1027.004 · sub-technique of T1027 STIX ID attack-pattern--c726e0a2-a57a-4b7b-a973-d0f013246617 Stealth Linux, macOS, Windows 2.0
Obfuscated Files or Information: Compression T1027.015 · sub-technique of T1027 STIX ID attack-pattern--fbd91bfc-75c2-4f0c-8116-3b4e722906b3 Stealth Linux, macOS, Windows 2.0
Obfuscated Files or Information: Dynamic API Resolution T1027.007 · sub-technique of T1027 STIX ID attack-pattern--ea4c2f9c-9df1-477c-8c42-6da1118f2ac4 Stealth Windows 2.0
Obfuscated Files or Information: Embedded Payloads T1027.009 · sub-technique of T1027 STIX ID attack-pattern--0533ab23-3f7d-463f-9bd8-634d27e4dee1 Stealth Linux, macOS, Windows 2.0
Obfuscated Files or Information: Encrypted/Encoded File T1027.013 · sub-technique of T1027 STIX ID attack-pattern--0d91b3c0-5e50-47c3-949a-2a796f04d144 Stealth Linux, macOS, Windows 2.0
Obfuscated Files or Information: Fileless Storage T1027.011 · sub-technique of T1027 STIX ID attack-pattern--02c5abff-30bf-4703-ab92-1f6072fae939 Stealth Linux, Windows 3.0
Obfuscated Files or Information: HTML Smuggling T1027.006 · sub-technique of T1027 STIX ID attack-pattern--d4dc46e3-5ba5-45b9-8204-010867cacfcb Stealth Linux, macOS, Windows 2.0
Obfuscated Files or Information: Indicator Removal from Tools T1027.005 · sub-technique of T1027 STIX ID attack-pattern--b0533c6e-8fea-4788-874f-b799cacc4b92 Stealth Linux, macOS, Windows 2.0
Obfuscated Files or Information: Invisible Unicode T1027.018 · sub-technique of T1027 STIX ID attack-pattern--e9b75bb0-b5ec-42c8-b728-f4f424d9c39e Stealth Linux, macOS, Windows 1.0
Obfuscated Files or Information: Junk Code Insertion T1027.016 · sub-technique of T1027 STIX ID attack-pattern--671cd17f-a765-48fd-adc4-dad1941b1ae3 Stealth Linux, macOS, Windows 2.0
Obfuscated Files or Information: LNK Icon Smuggling T1027.012 · sub-technique of T1027 STIX ID attack-pattern--887274fc-2d63-4bdc-82f3-fae56d1d5fdc Stealth Windows 2.0
Obfuscated Files or Information: Polymorphic Code T1027.014 · sub-technique of T1027 STIX ID attack-pattern--b577dfc1-0177-4522-8d5a-782127c8592b Stealth Linux, macOS, Windows 2.0
Obfuscated Files or Information: SVG Smuggling T1027.017 · sub-technique of T1027 STIX ID attack-pattern--78b9e70d-1605-459c-b23d-e3a25036968c Stealth Linux, macOS, Windows 2.0
Obfuscated Files or Information: Software Packing T1027.002 · sub-technique of T1027 STIX ID attack-pattern--deb98323-e13f-4b0c-8d94-175379069062 Stealth Linux, macOS, Windows 2.0
Obfuscated Files or Information: Steganography T1027.003 · sub-technique of T1027 STIX ID attack-pattern--c2e147a9-d1a8-4074-811a-d8789202d916 Stealth Linux, macOS, Windows 2.0
Obfuscated Files or Information: Stripped Payloads T1027.008 · sub-technique of T1027 STIX ID attack-pattern--2f41939b-54c3-41d6-8f8b-35f1ec18ed97 Stealth Linux, macOS, Network Devices, Windows 2.0
Obtain Capabilities T1588 STIX ID attack-pattern--ce0687a0-e692-4b77-964a-0784a8e54ff1 Resource Development PRE 1.1
Obtain Capabilities: Artificial Intelligence T1588.007 · sub-technique of T1588 STIX ID attack-pattern--0cc222f5-c3ff-48e6-9f52-3314baf9d37e Resource Development PRE 1.1
Obtain Capabilities: Code Signing Certificates T1588.003 · sub-technique of T1588 STIX ID attack-pattern--e7cbc1de-1f79-48ee-abfd-da1241c65a15 Resource Development PRE 1.1
Obtain Capabilities: Digital Certificates T1588.004 · sub-technique of T1588 STIX ID attack-pattern--19401639-28d0-4c3c-adcc-bc2ba22f6421 Resource Development PRE 1.2
Obtain Capabilities: Exploits T1588.005 · sub-technique of T1588 STIX ID attack-pattern--f4b843c1-7e92-4701-8fed-ce82f8be2636 Resource Development PRE 1.0
Obtain Capabilities: Malware T1588.001 · sub-technique of T1588 STIX ID attack-pattern--7807d3a4-a885-4639-a786-c1ed41484970 Resource Development PRE 1.1
Obtain Capabilities: Tool T1588.002 · sub-technique of T1588 STIX ID attack-pattern--a2fdce72-04b2-409a-ac10-cc1695f4fce0 Resource Development PRE 1.2
Obtain Capabilities: Vulnerabilities T1588.006 · sub-technique of T1588 STIX ID attack-pattern--2b5aa86b-a0df-4382-848d-30abea443327 Resource Development PRE 1.0
Office Application Startup T1137 STIX ID attack-pattern--2c4d4e92-0ccf-4a97-b54c-86d662988a53 Persistence Office Suite, Windows 1.4
Office Application Startup: Add-ins T1137.006 · sub-technique of T1137 STIX ID attack-pattern--34f1d81d-fe88-4f97-bd3b-a3164536255d Persistence Office Suite, Windows 1.2
Office Application Startup: Office Template Macros T1137.001 · sub-technique of T1137 STIX ID attack-pattern--79a47ad0-fc3b-4821-9f01-a026b1ddba21 Persistence Office Suite, Windows 1.2
Office Application Startup: Office Test T1137.002 · sub-technique of T1137 STIX ID attack-pattern--ed7efd4d-ce28-4a19-a8e6-c58011eb2c7a Persistence Office Suite, Windows 1.3
Office Application Startup: Outlook Forms T1137.003 · sub-technique of T1137 STIX ID attack-pattern--a9e2cea0-c805-4bf8-9e31-f5f0513a3634 Persistence Office Suite, Windows 1.2
Office Application Startup: Outlook Home Page T1137.004 · sub-technique of T1137 STIX ID attack-pattern--bf147104-abf9-4221-95d1-e81585859441 Persistence Office Suite, Windows 1.2
Office Application Startup: Outlook Rules T1137.005 · sub-technique of T1137 STIX ID attack-pattern--3d1b9d7e-3921-4d25-845a-7d9f15c0da44 Persistence Office Suite, Windows 1.2
Password Policy Discovery T1201 STIX ID attack-pattern--b6075259-dba3-44e9-87c7-e954f37ec0d5 Discovery IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows 1.7
Peripheral Device Discovery T1120 STIX ID attack-pattern--348f1eef-964b-4eb6-bb53-69b3dcb0c643 Discovery Linux, macOS, Windows 1.4
Permission Groups Discovery T1069 STIX ID attack-pattern--15dbf668-795c-41e6-8219-f0447c0e64ce Discovery Containers, IaaS, Identity Provider, Linux, macOS, Office Suite, SaaS, Windows 2.6
Permission Groups Discovery: Cloud Groups T1069.003 · sub-technique of T1069 STIX ID attack-pattern--16e94db9-b5b1-4cd0-b851-f38fbd0a70f2 Discovery IaaS, Identity Provider, Office Suite, SaaS 1.5
Permission Groups Discovery: Domain Groups T1069.002 · sub-technique of T1069 STIX ID attack-pattern--2aed01ad-3df3-4410-a8cb-11ea4ded587c Discovery Linux, macOS, Windows 1.2
Permission Groups Discovery: Local Groups T1069.001 · sub-technique of T1069 STIX ID attack-pattern--a01bf75f-00b2-4568-a58f-565ff9bf202b Discovery Linux, macOS, Windows 1.2
Phishing T1566 STIX ID attack-pattern--a62a8db3-f23a-4d8f-afd6-9dbc77e7813b Initial Access Identity Provider, Linux, macOS, Office Suite, SaaS, Windows 2.7
Phishing for Information T1598 STIX ID attack-pattern--cca0ccb6-a068-4574-a722-b1556f86833a Reconnaissance PRE 1.4
Phishing for Information: Spearphishing Attachment T1598.002 · sub-technique of T1598 STIX ID attack-pattern--8982a661-d84c-48c0-b4ec-1db29c6cf3bc Reconnaissance PRE 1.2
Phishing for Information: Spearphishing Link T1598.003 · sub-technique of T1598 STIX ID attack-pattern--2d3f5b3c-54ca-4f4d-bb1f-849346d31230 Reconnaissance PRE 1.7
Phishing for Information: Spearphishing Service T1598.001 · sub-technique of T1598 STIX ID attack-pattern--f870408c-b1cd-49c7-a5c7-0ef0fc496cc6 Reconnaissance PRE 1.0
Phishing for Information: Spearphishing Voice T1598.004 · sub-technique of T1598 STIX ID attack-pattern--6a5d222a-a7e0-4656-b110-782c33098289 Reconnaissance PRE 1.0
Phishing: Spearphishing Attachment T1566.001 · sub-technique of T1566 STIX ID attack-pattern--2e34237d-8574-43f6-aace-ae2915de8597 Initial Access Linux, macOS, Windows 2.2
Phishing: Spearphishing Link T1566.002 · sub-technique of T1566 STIX ID attack-pattern--2b742742-28c3-4e1b-bab7-8350d6300fa7 Initial Access Identity Provider, Linux, macOS, Office Suite, SaaS, Windows 2.8
Phishing: Spearphishing Voice T1566.004 · sub-technique of T1566 STIX ID attack-pattern--bb5e59c4-abe7-40c7-8196-e373cb1e5974 Initial Access Identity Provider, Linux, macOS, Windows 1.2
Phishing: Spearphishing via Service T1566.003 · sub-technique of T1566 STIX ID attack-pattern--f6ad61ee-65f3-4bd0-a3f5-2f0accb36317 Initial Access Linux, macOS, Windows 2.0
Plist File Modification T1647 STIX ID attack-pattern--7d20fff9-8751-404e-badd-ccd71bda0236 Defense Impairment macOS 2.0
Poisoned Pipeline Execution T1677 STIX ID attack-pattern--7655ac3b-dfde-49c5-a967-242856174434 Execution SaaS 1.0
Power Settings T1653 STIX ID attack-pattern--ea071aa0-8f17-416f-ab0d-2bab7e79003d Persistence Linux, macOS, Network Devices, Windows 1.1
Pre-OS Boot T1542 STIX ID attack-pattern--7f0ca133-88c4-40c6-a62f-b3083a7fbc2e Persistence, Stealth Linux, macOS, Network Devices, Windows 2.0
Pre-OS Boot: Bootkit T1542.003 · sub-technique of T1542 STIX ID attack-pattern--1b7b1806-7746-41a1-a35d-e48dae25ddba Persistence, Stealth Linux, Windows 2.0
Pre-OS Boot: Component Firmware T1542.002 · sub-technique of T1542 STIX ID attack-pattern--791481f8-e96a-41be-b089-a088763083d4 Persistence, Stealth Linux, macOS, Windows 2.0
Pre-OS Boot: ROMMONkit T1542.004 · sub-technique of T1542 STIX ID attack-pattern--a6557c75-798f-42e4-be70-ab4502e0a3bc Persistence, Stealth Network Devices 2.0
Pre-OS Boot: System Firmware T1542.001 · sub-technique of T1542 STIX ID attack-pattern--16ab6452-c3c1-497c-a47d-206018ca1ada Persistence, Stealth Network Devices, Windows 2.0
Pre-OS Boot: TFTP Boot T1542.005 · sub-technique of T1542 STIX ID attack-pattern--28abec6c-4443-4b03-8206-07f2e264a6b4 Persistence, Stealth Network Devices 2.0
Prevent Command History Logging T1690 STIX ID attack-pattern--b831f51c-d22f-4724-bbab-60d056bd1150 Defense Impairment ESXi, Linux, macOS, Network Devices, Windows 1.0
Process Discovery T1057 STIX ID attack-pattern--8f4a33ec-8b1f-4b80-a2f6-642b2e479580 Discovery ESXi, Linux, macOS, Network Devices, Windows 1.6
Process Injection T1055 STIX ID attack-pattern--43e7dc91-05b2-474c-b9ac-2ed4fe101f4d Privilege Escalation, Stealth Linux, macOS, Windows 2.0
Process Injection: Asynchronous Procedure Call T1055.004 · sub-technique of T1055 STIX ID attack-pattern--7c0f17c9-1af6-4628-9cbd-9e45482dd605 Privilege Escalation, Stealth Windows 2.0
Process Injection: Dynamic-link Library Injection T1055.001 · sub-technique of T1055 STIX ID attack-pattern--f4599aa0-4f85-4a32-80ea-fc39dc965945 Privilege Escalation, Stealth Windows 2.0
Process Injection: Extra Window Memory Injection T1055.011 · sub-technique of T1055 STIX ID attack-pattern--0042a9f5-f053-4769-b3ef-9ad018dfa298 Privilege Escalation, Stealth Windows 2.0
Process Injection: ListPlanting T1055.015 · sub-technique of T1055 STIX ID attack-pattern--eb2cb5cb-ae87-4de0-8c35-da2a17aafb99 Privilege Escalation, Stealth Windows 2.0
Process Injection: Portable Executable Injection T1055.002 · sub-technique of T1055 STIX ID attack-pattern--806a49c4-970d-43f9-9acc-ac0ee11e6662 Privilege Escalation, Stealth Windows 2.0
Process Injection: Proc Memory T1055.009 · sub-technique of T1055 STIX ID attack-pattern--d201d4cc-214d-4a74-a1ba-b3fa09fd4591 Privilege Escalation, Stealth Linux 2.0
Process Injection: Process Doppelgänging T1055.013 · sub-technique of T1055 STIX ID attack-pattern--7007935a-a8a7-4c0b-bd98-4e85be8ed197 Privilege Escalation, Stealth Windows 2.0
Process Injection: Process Hollowing T1055.012 · sub-technique of T1055 STIX ID attack-pattern--b200542e-e877-4395-875b-cf1a44537ca4 Privilege Escalation, Stealth Windows 2.0
Process Injection: Ptrace System Calls T1055.008 · sub-technique of T1055 STIX ID attack-pattern--ea016b56-ae0e-47fe-967a-cc0ad51af67f Privilege Escalation, Stealth Linux 2.0
Process Injection: Thread Execution Hijacking T1055.003 · sub-technique of T1055 STIX ID attack-pattern--41d9846c-f6af-4302-a654-24bba2729bc6 Privilege Escalation, Stealth Windows 2.0
Process Injection: Thread Local Storage T1055.005 · sub-technique of T1055 STIX ID attack-pattern--e49ee9d2-0d98-44ef-85e5-5d3100065744 Privilege Escalation, Stealth Windows 2.0
Process Injection: VDSO Hijacking T1055.014 · sub-technique of T1055 STIX ID attack-pattern--98be40f2-c86b-4ade-b6fc-4964932040e5 Privilege Escalation, Stealth Linux 2.0
Protocol Tunneling T1572 STIX ID attack-pattern--4fe28b27-b13c-453e-a386-c2ef362a573b Command and Control ESXi, Linux, macOS, Windows 1.1
Proxy T1090 STIX ID attack-pattern--731f4f55-b6d0-41d1-a7a9-072a66389aea Command and Control ESXi, Linux, macOS, Network Devices, Windows 3.2
Proxy: Domain Fronting T1090.004 · sub-technique of T1090 STIX ID attack-pattern--ca9d3402-ada3-484d-876a-d717bd6e05f2 Command and Control ESXi, Linux, macOS, Windows 1.2
Proxy: External Proxy T1090.002 · sub-technique of T1090 STIX ID attack-pattern--69b8fd78-40e8-4600-ae4d-662c9d7afdb3 Command and Control ESXi, Linux, macOS, Network Devices, Windows 1.3
Proxy: Internal Proxy T1090.001 · sub-technique of T1090 STIX ID attack-pattern--f6dacc85-b37d-458e-b58d-74fc4bbf5755 Command and Control ESXi, Linux, macOS, Network Devices, Windows 1.2
Proxy: Multi-hop Proxy T1090.003 · sub-technique of T1090 STIX ID attack-pattern--a782ebe2-daba-42c7-bc82-e8e9d923162d Command and Control ESXi, Linux, macOS, Network Devices, Windows 2.4
Query Public AI Services T1682 STIX ID attack-pattern--143122a8-fcda-4dd7-aded-5b9387d9c2d6 Reconnaissance PRE 1.0
Query Registry T1012 STIX ID attack-pattern--c32f7008-9fea-41f7-8366-5eb9b74bd896 Discovery Windows 1.3
Reflective Code Loading T1620 STIX ID attack-pattern--4933e63b-9b77-476e-ab29-761bc5b7d15a Stealth Linux, macOS, Windows 2.0
Remote Access Tools T1219 STIX ID attack-pattern--4061e78c-1284-44b4-9116-73e4ac3912f7 Command and Control Linux, macOS, Windows 3.0
Remote Access Tools: IDE Tunneling T1219.001 · sub-technique of T1219 STIX ID attack-pattern--77e29a47-e263-4f11-8692-e5012f44dbac Command and Control Linux, macOS, Windows 1.0
Remote Access Tools: Remote Access Hardware T1219.003 · sub-technique of T1219 STIX ID attack-pattern--a9fb6b3f-4a3c-4703-a4f1-f55f83d1e017 Command and Control Linux, macOS, Windows 1.0
Remote Access Tools: Remote Desktop Software T1219.002 · sub-technique of T1219 STIX ID attack-pattern--d4287702-e2f7-4946-bdfa-2c7f5aaa5032 Command and Control Linux, macOS, Windows 1.0
Remote Service Session Hijacking T1563 STIX ID attack-pattern--5b0ad6f8-6a16-4966-a4ef-d09ea6e2a9f5 Lateral Movement Linux, macOS, Windows 1.1
Remote Service Session Hijacking: RDP Hijacking T1563.002 · sub-technique of T1563 STIX ID attack-pattern--e0033c16-a07e-48aa-8204-7c3ca669998c Lateral Movement Windows 1.1
Remote Service Session Hijacking: SSH Hijacking T1563.001 · sub-technique of T1563 STIX ID attack-pattern--4d2a5b3e-340d-4600-9123-309dd63c9bf8 Lateral Movement Linux, macOS 1.1
Remote Services T1021 STIX ID attack-pattern--54a649ff-439a-41a4-9856-8d144a2551ba Lateral Movement ESXi, IaaS, Linux, macOS, Windows 1.6
Remote Services: Cloud Services T1021.007 · sub-technique of T1021 STIX ID attack-pattern--8861073d-d1b8-4941-82ce-dce621d398f0 Lateral Movement IaaS, Identity Provider, Office Suite, SaaS 1.1
Remote Services: Direct Cloud VM Connections T1021.008 · sub-technique of T1021 STIX ID attack-pattern--45241b9e-9bbc-4826-a2cc-78855e51ca09 Lateral Movement IaaS 1.0
Remote Services: Distributed Component Object Model T1021.003 · sub-technique of T1021 STIX ID attack-pattern--68a0c5ed-bee2-4513-830d-5b0d650139bd Lateral Movement Windows 1.3
Remote Services: Remote Desktop Protocol T1021.001 · sub-technique of T1021 STIX ID attack-pattern--eb062747-2193-45de-8fa2-e62549c37ddf Lateral Movement Windows 1.4
Remote Services: SMB/Windows Admin Shares T1021.002 · sub-technique of T1021 STIX ID attack-pattern--4f9ca633-15c5-463c-9724-bdcd54fde541 Lateral Movement Windows 1.3
Remote Services: SSH T1021.004 · sub-technique of T1021 STIX ID attack-pattern--2db31dcd-54da-405d-acef-b9129b816ed6 Lateral Movement ESXi, Linux, macOS 1.3
Remote Services: VNC T1021.005 · sub-technique of T1021 STIX ID attack-pattern--01327cde-66c4-4123-bf34-5f258d59457b Lateral Movement Linux, macOS, Windows 1.2
Remote Services: Windows Remote Management T1021.006 · sub-technique of T1021 STIX ID attack-pattern--60d0c01d-e2bf-49dd-a453-f8a9c9fa6f65 Lateral Movement Windows 1.2
Remote System Discovery T1018 STIX ID attack-pattern--e358d692-23c0-4a31-9eb6-ecc13a8d7735 Discovery ESXi, Linux, macOS, Network Devices, Windows 3.6
Replication Through Removable Media T1091 STIX ID attack-pattern--3b744087-9945-4a6f-91e8-9dbceda417a4 Initial Access, Lateral Movement Windows 1.3
Resource Hijacking T1496 STIX ID attack-pattern--cd25c1b4-935c-4f0e-ba8d-552f28bc4783 Impact Containers, IaaS, Linux, macOS, SaaS, Windows 2.0
Resource Hijacking: Bandwidth Hijacking T1496.002 · sub-technique of T1496 STIX ID attack-pattern--718cb208-6446-4572-a2f0-9c799c60091e Impact Containers, IaaS, Linux, macOS, Windows 1.0
Resource Hijacking: Cloud Service Hijacking T1496.004 · sub-technique of T1496 STIX ID attack-pattern--924d273c-be0d-4d8d-af58-2dddb15ef1e2 Impact SaaS 1.0
Resource Hijacking: Compute Hijacking T1496.001 · sub-technique of T1496 STIX ID attack-pattern--a718a0c8-5768-41a1-9958-a1cc3f995e99 Impact Containers, IaaS, Linux, macOS, Windows 1.0
Resource Hijacking: SMS Pumping T1496.003 · sub-technique of T1496 STIX ID attack-pattern--130d4494-b2d6-4040-bcea-6e59f05222fe Impact SaaS 1.0
Rogue Domain Controller T1207 STIX ID attack-pattern--564998d8-ab3e-4123-93fb-eccaa6b9714a Defense Impairment Windows 3.0
Rootkit T1014 STIX ID attack-pattern--0f20e3cb-245b-4a61-8a91-2d93f7cb0e9b Stealth Linux, macOS, Windows 2.0
Safe Mode Boot T1688 STIX ID attack-pattern--c7660f19-f8c5-4ae3-a5e5-24381c270376 Defense Impairment Windows 1.0
Scheduled Task/Job T1053 STIX ID attack-pattern--35dd844a-b219-4e2b-a6bb-efa9a75995a9 Execution, Persistence, Privilege Escalation Containers, ESXi, Linux, macOS, Network Devices, Windows 2.5
Scheduled Task/Job: At T1053.002 · sub-technique of T1053 STIX ID attack-pattern--f3d95a1f-bba2-44ce-9af7-37866cd63fd0 Execution, Persistence, Privilege Escalation Linux, macOS, Windows 2.4
Scheduled Task/Job: Container Orchestration Job T1053.007 · sub-technique of T1053 STIX ID attack-pattern--1126cab1-c700-412f-a510-61f4937bb096 Execution, Persistence, Privilege Escalation Containers 1.4
Scheduled Task/Job: Cron T1053.003 · sub-technique of T1053 STIX ID attack-pattern--2acf44aa-542f-4366-b4eb-55ef5747759c Execution, Persistence, Privilege Escalation ESXi, Linux, macOS 1.3
Scheduled Task/Job: Scheduled Task T1053.005 · sub-technique of T1053 STIX ID attack-pattern--005a06c6-14bf-4118-afa0-ebcd8aebb0c9 Execution, Persistence, Privilege Escalation Windows 1.8
Scheduled Task/Job: Systemd Timers T1053.006 · sub-technique of T1053 STIX ID attack-pattern--a542bac9-7bc1-4da7-9a09-96f69e23cc21 Execution, Persistence, Privilege Escalation Linux 1.3
Scheduled Transfer T1029 STIX ID attack-pattern--4eeaf8a9-c86b-4954-a663-9555fb406466 Exfiltration Linux, macOS, Windows 1.1
Screen Capture T1113 STIX ID attack-pattern--0259baeb-9f63-4c69-bf10-eb038c390688 Collection Linux, macOS, Windows 1.1
Search Closed Sources T1597 STIX ID attack-pattern--a51eb150-93b1-484b-a503-e51453b127a4 Reconnaissance PRE 1.1
Search Closed Sources: Purchase Technical Data T1597.002 · sub-technique of T1597 STIX ID attack-pattern--0a241b6c-7bb2-48f9-98f7-128145b4d27f Reconnaissance PRE 1.0
Search Closed Sources: Threat Intel Vendors T1597.001 · sub-technique of T1597 STIX ID attack-pattern--51e54974-a541-4fb6-a61b-0518e4c6de41 Reconnaissance PRE 2.0
Search Open Technical Databases T1596 STIX ID attack-pattern--55fc4df0-b42c-479a-b860-7a6761bcaad0 Reconnaissance PRE 1.0
Search Open Technical Databases: CDNs T1596.004 · sub-technique of T1596 STIX ID attack-pattern--91177e6d-b616-4a03-ba4b-f3b32f7dda75 Reconnaissance PRE 1.0
Search Open Technical Databases: DNS/Passive DNS T1596.001 · sub-technique of T1596 STIX ID attack-pattern--17fd695c-b88c-455a-a3d1-43b6cb728532 Reconnaissance PRE 1.0
Search Open Technical Databases: Digital Certificates T1596.003 · sub-technique of T1596 STIX ID attack-pattern--0979abf9-4e26-43ec-9b6e-54efc4e70fca Reconnaissance PRE 1.0
Search Open Technical Databases: Scan Databases T1596.005 · sub-technique of T1596 STIX ID attack-pattern--ec4be82f-940c-4dcb-87fe-2bbdd17c692f Reconnaissance PRE 1.0
Search Open Technical Databases: WHOIS T1596.002 · sub-technique of T1596 STIX ID attack-pattern--166de1c6-2814-4fe5-8438-4e80f76b169f Reconnaissance PRE 1.0
Search Open Websites/Domains T1593 STIX ID attack-pattern--a0e6614a-7740-4b24-bd65-f1bde09fc365 Reconnaissance PRE 1.1
Search Open Websites/Domains: Code Repositories T1593.003 · sub-technique of T1593 STIX ID attack-pattern--70910fbd-58dc-4c1c-8c48-814d11fcd022 Reconnaissance PRE 1.0
Search Open Websites/Domains: Search Engines T1593.002 · sub-technique of T1593 STIX ID attack-pattern--6e561441-8431-4773-a9b8-ccf28ef6a968 Reconnaissance PRE 1.0
Search Open Websites/Domains: Social Media T1593.001 · sub-technique of T1593 STIX ID attack-pattern--bbe5b322-e2af-4a5e-9625-a4e62bf84ed3 Reconnaissance PRE 1.0
Search Threat Vendor Data T1681 STIX ID attack-pattern--63b24abc-5702-4745-b1e4-ac70b20a43f2 Reconnaissance PRE 1.0
Search Victim-Owned Websites T1594 STIX ID attack-pattern--16cdd21f-da65-4e4f-bc04-dd7d198c7b26 Reconnaissance PRE 1.1
Selective Exclusion T1679 STIX ID attack-pattern--9b00925a-7c4b-4e53-bfc8-9a6a806fde03 Stealth Windows 2.0
Server Software Component T1505 STIX ID attack-pattern--d456de47-a16f-4e46-8980-e67478a12dcb Persistence ESXi, Linux, macOS, Network Devices, Windows 1.5
Server Software Component: IIS Components T1505.004 · sub-technique of T1505 STIX ID attack-pattern--b46a801b-fd98-491c-a25a-bca25d6e3001 Persistence Windows 1.1
Server Software Component: SQL Stored Procedures T1505.001 · sub-technique of T1505 STIX ID attack-pattern--f9e9365a-9ca2-4d9c-8e7c-050d73d1101a Persistence Linux, Windows 1.1
Server Software Component: Terminal Services DLL T1505.005 · sub-technique of T1505 STIX ID attack-pattern--379809f6-2fac-42c1-bd2e-e9dee70b27f8 Persistence Windows 1.0
Server Software Component: Transport Agent T1505.002 · sub-technique of T1505 STIX ID attack-pattern--35187df2-31ed-43b6-a1f5-2f1d3d58d3f1 Persistence Linux, Windows 1.1
Server Software Component: Web Shell T1505.003 · sub-technique of T1505 STIX ID attack-pattern--5d0d3609-d06d-49e1-b9c9-b544e0c618cb Persistence Linux, macOS, Network Devices, Windows 1.5
Server Software Component: vSphere Installation Bundles T1505.006 · sub-technique of T1505 STIX ID attack-pattern--f8ba7d61-11c5-4130-bafd-7c3ff5fbf4b5 Persistence ESXi 1.0
Serverless Execution T1648 STIX ID attack-pattern--e848506b-8484-4410-8017-3d235a52f5b3 Execution IaaS, Office Suite, SaaS 1.2
Service Stop T1489 STIX ID attack-pattern--20fb2507-d71c-455d-9b6d-6104461cf26b Impact ESXi, IaaS, Linux, macOS, Windows 1.4
Shared Modules T1129 STIX ID attack-pattern--0a5231ec-41af-4a35-83d0-6bdf11f28c65 Execution Linux, macOS, Windows 2.3
Social Engineering T1684 STIX ID attack-pattern--41e4d77a-6275-4976-9e35-785985598519 Stealth Linux, macOS, Office Suite, SaaS, Windows 1.0
Social Engineering: Email Spoofing T1684.002 · sub-technique of T1684 STIX ID attack-pattern--fcf5bccf-be7a-48ff-b7a7-8d6019279301 Stealth Linux, macOS, Office Suite, Windows 1.0
Social Engineering: Impersonation T1684.001 · sub-technique of T1684 STIX ID attack-pattern--cd92d2b8-ce43-4666-9472-f1b4b9f4f8be Stealth Linux, macOS, Office Suite, SaaS, Windows 1.0
Software Deployment Tools T1072 STIX ID attack-pattern--92a78814-b191-47ca-909c-1ccfe3777414 Execution, Lateral Movement Linux, macOS, Network Devices, SaaS, Windows 3.2
Software Discovery T1518 STIX ID attack-pattern--e3b6daca-e963-4a69-aee6-ed4fd653ad58 Discovery ESXi, IaaS, Linux, macOS, Windows 1.5
Software Discovery: Backup Software Discovery T1518.002 · sub-technique of T1518 STIX ID attack-pattern--4a6cfdae-1417-40c7-a84e-f59d21c58266 Discovery Linux, macOS, Windows 1.0
Software Discovery: Security Software Discovery T1518.001 · sub-technique of T1518 STIX ID attack-pattern--cba37adb-d6fb-4610-b069-dd04c0643384 Discovery IaaS, Linux, macOS, Windows 1.5
Software Extensions T1176 STIX ID attack-pattern--389735f1-f21c-4208-b8f0-f8031e7169b8 Persistence Linux, macOS, Windows 2.0
Software Extensions: Browser Extensions T1176.001 · sub-technique of T1176 STIX ID attack-pattern--278716b1-61ce-4a74-8d17-891d0c494101 Persistence Linux, macOS, Windows 1.1
Software Extensions: IDE Extensions T1176.002 · sub-technique of T1176 STIX ID attack-pattern--66b34be7-6915-4b83-8d5a-b0f0592b5e41 Persistence Linux, macOS, Windows 1.0
Stage Capabilities T1608 STIX ID attack-pattern--84771bc3-f6a0-403e-b144-01af70e5fda0 Resource Development PRE 1.2
Stage Capabilities: Drive-by Target T1608.004 · sub-technique of T1608 STIX ID attack-pattern--31fe0ba2-62fd-4fd9-9293-4043d84f7fe9 Resource Development PRE 1.3
Stage Capabilities: Install Digital Certificate T1608.003 · sub-technique of T1608 STIX ID attack-pattern--c071d8c1-3b3a-4f22-9407-ca4e96921069 Resource Development PRE 1.1
Stage Capabilities: Link Target T1608.005 · sub-technique of T1608 STIX ID attack-pattern--84ae8255-b4f4-4237-b5c5-e717405a9701 Resource Development PRE 1.4
Stage Capabilities: SEO Poisoning T1608.006 · sub-technique of T1608 STIX ID attack-pattern--e5d550f3-2202-4634-85f2-4a200a1d49b3 Resource Development PRE 1.1
Stage Capabilities: Upload Malware T1608.001 · sub-technique of T1608 STIX ID attack-pattern--3ee16395-03f0-4690-a32e-69ce9ada0f9e Resource Development PRE 1.3
Stage Capabilities: Upload Tool T1608.002 · sub-technique of T1608 STIX ID attack-pattern--506f6f49-7045-4156-9007-7474cb44ad6d Resource Development PRE 1.2
Steal Application Access Token T1528 STIX ID attack-pattern--890c9858-598c-401d-a4d5-c67ebcdd703a Credential Access Containers, IaaS, Identity Provider, Office Suite, SaaS 1.5
Steal Web Session Cookie T1539 STIX ID attack-pattern--10ffac09-e42d-4f56-ab20-db94c67d76ff Credential Access Linux, macOS, Office Suite, SaaS, Windows 1.5
Steal or Forge Authentication Certificates T1649 STIX ID attack-pattern--7de1f7ac-5d0c-4c9c-8873-627202205331 Credential Access Identity Provider, Linux, macOS, Windows 1.2
Steal or Forge Kerberos Tickets T1558 STIX ID attack-pattern--3fc01293-ef5e-41c6-86ce-61f10706b64a Credential Access Linux, macOS, Windows 1.7
Steal or Forge Kerberos Tickets: AS-REP Roasting T1558.004 · sub-technique of T1558 STIX ID attack-pattern--3986e7fd-a8e9-4ecb-bfc6-55920855912b Credential Access Windows 1.2
Steal or Forge Kerberos Tickets: Ccache Files T1558.005 · sub-technique of T1558 STIX ID attack-pattern--394220d9-8efc-4252-9040-664f7b115be6 Credential Access Linux, macOS 1.0
Steal or Forge Kerberos Tickets: Golden Ticket T1558.001 · sub-technique of T1558 STIX ID attack-pattern--768dce68-8d0d-477a-b01d-0eea98b963a1 Credential Access Windows 1.2
Steal or Forge Kerberos Tickets: Kerberoasting T1558.003 · sub-technique of T1558 STIX ID attack-pattern--f2877f7f-9a4c-4251-879f-1224e3006bee Credential Access Windows 1.3
Steal or Forge Kerberos Tickets: Silver Ticket T1558.002 · sub-technique of T1558 STIX ID attack-pattern--d273434a-448e-4598-8e14-607f4a0d5e27 Credential Access Windows 1.1
Subvert Trust Controls T1553 STIX ID attack-pattern--b83e166d-13d7-4b52-8677-dff90c548fd7 Defense Impairment Linux, macOS, Windows 2.0
Subvert Trust Controls: Code Signing T1553.002 · sub-technique of T1553 STIX ID attack-pattern--32901740-b42c-4fdd-bc02-345b5dc57082 Defense Impairment macOS, Windows 2.0
Subvert Trust Controls: Code Signing Policy Modification T1553.006 · sub-technique of T1553 STIX ID attack-pattern--565275d5-fcc3-4b66-b4e7-928e4cac6b8c Defense Impairment macOS, Windows 2.0
Subvert Trust Controls: Gatekeeper Bypass T1553.001 · sub-technique of T1553 STIX ID attack-pattern--31a0a2ac-c67c-4a7e-b9ed-6a96477d4e8e Defense Impairment macOS 2.0
Subvert Trust Controls: Install Root Certificate T1553.004 · sub-technique of T1553 STIX ID attack-pattern--c615231b-f253-4f58-9d47-d5b4cbdb6839 Defense Impairment Linux, macOS, Windows 2.0
Subvert Trust Controls: Mark-of-the-Web Bypass T1553.005 · sub-technique of T1553 STIX ID attack-pattern--7e7c2fba-7cca-486c-9582-4c1bb2851961 Defense Impairment Windows 2.0
Subvert Trust Controls: SIP and Trust Provider Hijacking T1553.003 · sub-technique of T1553 STIX ID attack-pattern--543fceb5-cb92-40cb-aacf-6913d4db58bc Defense Impairment Windows 2.0
Supply Chain Compromise T1195 STIX ID attack-pattern--3f18edba-28f4-4bb9-82c3-8aa60dcac5f7 Initial Access Linux, macOS, SaaS, Windows 1.7
Supply Chain Compromise: Compromise Hardware Supply Chain T1195.003 · sub-technique of T1195 STIX ID attack-pattern--39131305-9282-45e4-ac3b-591d2d4fc3ef Initial Access Linux, macOS, Windows 1.1
Supply Chain Compromise: Compromise Software Dependencies and Development Tools T1195.001 · sub-technique of T1195 STIX ID attack-pattern--191cc6af-1bb2-4344-ab5f-28e496638720 Initial Access Linux, macOS, Windows 1.3
Supply Chain Compromise: Compromise Software Supply Chain T1195.002 · sub-technique of T1195 STIX ID attack-pattern--bd369cd9-abb8-41ce-b5bb-fff23ee86c00 Initial Access Linux, macOS, Windows 1.1
System Binary Proxy Execution T1218 STIX ID attack-pattern--457c7820-d331-465a-915e-42f85500ccc4 Stealth Linux, macOS, Windows 4.0
System Binary Proxy Execution: CMSTP T1218.003 · sub-technique of T1218 STIX ID attack-pattern--4cbc6a62-9e34-4f94-8a19-5c1a11392a49 Stealth Windows 3.0
System Binary Proxy Execution: Compiled HTML File T1218.001 · sub-technique of T1218 STIX ID attack-pattern--a6937325-9321-4e2e-bb2b-3ed2d40b2a9d Stealth Windows 3.0
System Binary Proxy Execution: Control Panel T1218.002 · sub-technique of T1218 STIX ID attack-pattern--4ff5d6a8-c062-4c68-a778-36fc5edd564f Stealth Windows 3.0
System Binary Proxy Execution: Electron Applications T1218.015 · sub-technique of T1218 STIX ID attack-pattern--561ae9aa-c28a-4144-9eec-e7027a14c8c3 Stealth Linux, macOS, Windows 2.0
System Binary Proxy Execution: InstallUtil T1218.004 · sub-technique of T1218 STIX ID attack-pattern--2cd950a6-16c4-404a-aa01-044322395107 Stealth Windows 3.0
System Binary Proxy Execution: MMC T1218.014 · sub-technique of T1218 STIX ID attack-pattern--ffbcfdb0-de22-4106-9ed3-fc23c8a01407 Stealth Windows 3.0
System Binary Proxy Execution: Mavinject T1218.013 · sub-technique of T1218 STIX ID attack-pattern--1bae753e-8e52-4055-a66d-2ead90303ca9 Stealth Windows 3.0
System Binary Proxy Execution: Mshta T1218.005 · sub-technique of T1218 STIX ID attack-pattern--840a987a-99bd-4a80-a5c9-0cb2baa6cade Stealth Windows 3.0
System Binary Proxy Execution: Msiexec T1218.007 · sub-technique of T1218 STIX ID attack-pattern--365be77f-fc0e-42ee-bac8-4faf806d9336 Stealth Windows 3.0
System Binary Proxy Execution: Odbcconf T1218.008 · sub-technique of T1218 STIX ID attack-pattern--6e3bd510-6b33-41a4-af80-2d80f3ee0071 Stealth Windows 3.0
System Binary Proxy Execution: Regsvcs/Regasm T1218.009 · sub-technique of T1218 STIX ID attack-pattern--c48a67ee-b657-45c1-91bf-6cdbe27205f8 Stealth Windows 3.0
System Binary Proxy Execution: Regsvr32 T1218.010 · sub-technique of T1218 STIX ID attack-pattern--b97f1d35-4249-4486-a6b5-ee60ccf24fab Stealth Windows 3.0
System Binary Proxy Execution: Rundll32 T1218.011 · sub-technique of T1218 STIX ID attack-pattern--045d0922-2310-4e60-b5e4-3302302cb3c5 Stealth Windows 3.0
System Binary Proxy Execution: Verclsid T1218.012 · sub-technique of T1218 STIX ID attack-pattern--808e6329-ca91-4b87-ac2d-8eadc5f8f327 Stealth Windows 3.0
System Information Discovery T1082 STIX ID attack-pattern--354a7f88-63fb-41b5-a801-ce3b377b36f1 Discovery ESXi, IaaS, Linux, macOS, Network Devices, Windows 3.0
System Location Discovery T1614 STIX ID attack-pattern--c877e33f-1df6-40d6-b1e7-ce70f16f4979 Discovery IaaS, Linux, macOS, Windows 1.1
System Location Discovery: System Language Discovery T1614.001 · sub-technique of T1614 STIX ID attack-pattern--c1b68a96-3c48-49ea-a6c0-9b27359f9c19 Discovery Linux, macOS, Windows 1.1
System Network Configuration Discovery T1016 STIX ID attack-pattern--707399d6-ab3e-4963-9315-d9d3818cd6a0 Discovery ESXi, Linux, macOS, Network Devices, Windows 1.7
System Network Configuration Discovery: Internet Connection Discovery T1016.001 · sub-technique of T1016 STIX ID attack-pattern--132d5b37-aac5-4378-a8dc-3127b18a73dc Discovery ESXi, Linux, macOS, Windows 1.2
System Network Configuration Discovery: Wi-Fi Discovery T1016.002 · sub-technique of T1016 STIX ID attack-pattern--494ab9f0-36e0-4b06-b10d-57285b040a06 Discovery Linux, macOS, Windows 1.1
System Network Connections Discovery T1049 STIX ID attack-pattern--7e150503-88e7-4861-866b-ff1ac82c4475 Discovery ESXi, IaaS, Linux, macOS, Network Devices, Windows 2.5
System Owner/User Discovery T1033 STIX ID attack-pattern--03d7999c-1f4c-42cc-8373-e7690d318104 Discovery Linux, macOS, Network Devices, Windows 1.6
System Script Proxy Execution T1216 STIX ID attack-pattern--f6fe9070-7a65-49ea-ae72-76292f42cebe Stealth Windows 3.0
System Script Proxy Execution: PubPrn T1216.001 · sub-technique of T1216 STIX ID attack-pattern--09cd431f-eaf4-4d2a-acaf-2a7acfe7ed58 Stealth Windows 3.0
System Script Proxy Execution: SyncAppvPublishingServer T1216.002 · sub-technique of T1216 STIX ID attack-pattern--e6f19759-dde3-47fc-99cc-d9f5fa4ade60 Stealth Windows 2.0
System Service Discovery T1007 STIX ID attack-pattern--322bad5a-1c49-4d23-ab79-76d641794afa Discovery Linux, macOS, Windows 1.6
System Services T1569 STIX ID attack-pattern--d157f9d2-d09a-4efa-bb2a-64963f94e253 Execution Linux, macOS, Windows 1.4
System Services: Launchctl T1569.001 · sub-technique of T1569 STIX ID attack-pattern--810aa4ad-61c9-49cb-993f-daa06199421d Execution macOS 1.3
System Services: Service Execution T1569.002 · sub-technique of T1569 STIX ID attack-pattern--f1951e8a-500e-4a26-8803-76d95c4554b4 Execution Windows 1.3
System Services: Systemctl T1569.003 · sub-technique of T1569 STIX ID attack-pattern--4b46767d-4a61-4f30-995e-c19a75c2e536 Execution Linux 1.0
System Shutdown/Reboot T1529 STIX ID attack-pattern--ff73aa03-0090-4464-83ac-f89e233c02bc Impact ESXi, Linux, macOS, Network Devices, Windows 1.5
System Time Discovery T1124 STIX ID attack-pattern--f3c544dc-673c-4ef3-accb-53229f1ae077 Discovery ESXi, Linux, macOS, Network Devices, Windows 1.5
Taint Shared Content T1080 STIX ID attack-pattern--246fd3c7-f5e3-466d-8787-4c13d9e3b61c Lateral Movement Linux, macOS, Office Suite, SaaS, Windows 1.6
Template Injection T1221 STIX ID attack-pattern--dc31fe1e-d722-49da-8f5f-92c7b5aff534 Stealth Windows 2.0
Traffic Signaling T1205 STIX ID attack-pattern--451a9977-d255-43c9-b431-66de80130c8c Command and Control, Persistence, Stealth Linux, macOS, Network Devices, Windows 3.0
Traffic Signaling: Port Knocking T1205.001 · sub-technique of T1205 STIX ID attack-pattern--8868cb5b-d575-4a60-acb2-07d37389a2fd Command and Control, Persistence, Stealth Linux, macOS, Network Devices, Windows 2.0
Traffic Signaling: Socket Filters T1205.002 · sub-technique of T1205 STIX ID attack-pattern--005cc321-08ce-4d17-b1ea-cb5275926520 Command and Control, Persistence, Stealth Linux, macOS, Windows 2.0
Transfer Data to Cloud Account T1537 STIX ID attack-pattern--d4bdbdea-eaec-4071-b4f9-5105e12ea4b6 Exfiltration IaaS, Office Suite, SaaS 1.5
Trusted Developer Utilities Proxy Execution T1127 STIX ID attack-pattern--ff25900d-76d5-449b-a351-8824e62fc81b Execution, Stealth Windows 2.0
Trusted Developer Utilities Proxy Execution: ClickOnce T1127.002 · sub-technique of T1127 STIX ID attack-pattern--cc279e50-df85-4c8e-be80-6dc2eda8849c Execution, Stealth Windows 2.0
Trusted Developer Utilities Proxy Execution: JamPlus T1127.003 · sub-technique of T1127 STIX ID attack-pattern--7d356151-a69d-404e-896b-71618952702a Execution, Stealth Windows 2.0
Trusted Developer Utilities Proxy Execution: MSBuild T1127.001 · sub-technique of T1127 STIX ID attack-pattern--c92e3d68-2349-49e4-a341-7edca2deff96 Execution, Stealth Windows 2.0
Trusted Relationship T1199 STIX ID attack-pattern--9fa07bef-9c81-421e-a8e5-ad4366c5a925 Initial Access IaaS, Identity Provider, Linux, macOS, Office Suite, SaaS, Windows 2.4
Unsecured Credentials T1552 STIX ID attack-pattern--435dfb86-2697-4867-85b5-2fef496c0517 Credential Access Containers, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows 1.5
Unsecured Credentials: Chat Messages T1552.008 · sub-technique of T1552 STIX ID attack-pattern--9664ad0e-789e-40ac-82e2-d7b17fbe8fb3 Credential Access Office Suite, SaaS 1.1
Unsecured Credentials: Cloud Instance Metadata API T1552.005 · sub-technique of T1552 STIX ID attack-pattern--19bf235b-8620-4997-b5b4-94e0659ed7c3 Credential Access IaaS 1.4
Unsecured Credentials: Container API T1552.007 · sub-technique of T1552 STIX ID attack-pattern--f8ef3a62-3f44-40a4-abca-761ab235c436 Credential Access Containers 1.2
Unsecured Credentials: Credentials In Files T1552.001 · sub-technique of T1552 STIX ID attack-pattern--837f9164-50af-4ac0-8219-379d8a74cefc Credential Access Containers, IaaS, Linux, macOS, Windows 1.3
Unsecured Credentials: Credentials in Registry T1552.002 · sub-technique of T1552 STIX ID attack-pattern--341e222a-a6e3-4f6f-b69c-831d792b1580 Credential Access Windows 1.2
Unsecured Credentials: Group Policy Preferences T1552.006 · sub-technique of T1552 STIX ID attack-pattern--8d7bd4f5-3a89-4453-9c82-2c8894d5655e Credential Access Windows 1.1
Unsecured Credentials: Private Keys T1552.004 · sub-technique of T1552 STIX ID attack-pattern--60b508a1-6a5e-46b1-821a-9f7b78752abf Credential Access Linux, macOS, Network Devices, Windows 1.3
Unsecured Credentials: Shell History T1552.003 · sub-technique of T1552 STIX ID attack-pattern--8187bd2a-866f-4457-9009-86b0ddedffa3 Credential Access Linux, macOS, Windows 2.0
Unused/Unsupported Cloud Regions T1535 STIX ID attack-pattern--59bd0dec-f8b2-4b9a-9141-37a1e6899761 Stealth IaaS 2.0
Use Alternate Authentication Material T1550 STIX ID attack-pattern--51a14c76-dd3b-440b-9c20-2bf91d25a814 Lateral Movement Containers, IaaS, Identity Provider, Linux, Office Suite, SaaS, Windows 2.0
Use Alternate Authentication Material: Application Access Token T1550.001 · sub-technique of T1550 STIX ID attack-pattern--f005e783-57d4-4837-88ad-dbe7faee1c51 Lateral Movement Containers, IaaS, Identity Provider, Office Suite, SaaS 2.0
Use Alternate Authentication Material: Pass the Hash T1550.002 · sub-technique of T1550 STIX ID attack-pattern--e624264c-033a-424d-9fd7-fc9c3bbdb03e Lateral Movement Windows 2.0
Use Alternate Authentication Material: Pass the Ticket T1550.003 · sub-technique of T1550 STIX ID attack-pattern--7b211ac6-c815-4189-93a9-ab415deca926 Lateral Movement Windows 2.0
Use Alternate Authentication Material: Web Session Cookie T1550.004 · sub-technique of T1550 STIX ID attack-pattern--c3c8c916-2f3c-4e71-94b2-240bdfc996f0 Lateral Movement IaaS, Office Suite, SaaS 2.0
User Execution T1204 STIX ID attack-pattern--8c32eb4d-805f-4fc5-bf60-c4d476c131b5 Execution Containers, IaaS, Linux, macOS, Windows 1.8
User Execution: Malicious Copy and Paste T1204.004 · sub-technique of T1204 STIX ID attack-pattern--e261a979-f354-41a8-963e-6cadac27c4bf Execution Linux, macOS, Windows 1.1
User Execution: Malicious File T1204.002 · sub-technique of T1204 STIX ID attack-pattern--232b7f21-adf9-4b42-b936-b9d6f7df856e Execution Linux, macOS, Windows 1.6
User Execution: Malicious Image T1204.003 · sub-technique of T1204 STIX ID attack-pattern--b0c74ef9-c61e-4986-88cb-78da98a355ec Execution Containers, IaaS 1.2
User Execution: Malicious Library T1204.005 · sub-technique of T1204 STIX ID attack-pattern--73b24a10-6bf4-4af1-a81e-67b8bcb6c4e6 Execution Linux, macOS, Windows 1.0
User Execution: Malicious Link T1204.001 · sub-technique of T1204 STIX ID attack-pattern--ef67e13e-5598-4adc-bdb2-998225874fa9 Execution Linux, macOS, Windows 1.2
Valid Accounts T1078 STIX ID attack-pattern--b17a1a56-e99c-403c-8948-561df0cffe81 Initial Access, Persistence, Privilege Escalation, Stealth Containers, ESXi, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows 3.0
Valid Accounts: Cloud Accounts T1078.004 · sub-technique of T1078 STIX ID attack-pattern--f232fa7a-025c-4d43-abc7-318e81a73d65 Initial Access, Persistence, Privilege Escalation, Stealth IaaS, Identity Provider, Office Suite, SaaS 2.0
Valid Accounts: Default Accounts T1078.001 · sub-technique of T1078 STIX ID attack-pattern--6151cbea-819b-455a-9fa6-99a1cc58797d Initial Access, Persistence, Privilege Escalation, Stealth Containers, ESXi, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows 2.0
Valid Accounts: Domain Accounts T1078.002 · sub-technique of T1078 STIX ID attack-pattern--c3d4bdd9-2cfe-4a80-9d0c-07a29ecdce8f Initial Access, Persistence, Privilege Escalation, Stealth ESXi, Linux, macOS, Windows 2.0
Valid Accounts: Local Accounts T1078.003 · sub-technique of T1078 STIX ID attack-pattern--fdc47f44-dd32-4b99-af5f-209f556f63c2 Initial Access, Persistence, Privilege Escalation, Stealth Containers, ESXi, Linux, macOS, Network Devices, Windows 2.0
Video Capture T1125 STIX ID attack-pattern--6faf650d-bf31-4eb4-802d-1000cf38efaf Collection Linux, macOS, Windows 1.2
Virtual Machine Discovery T1673 STIX ID attack-pattern--6bc7f9aa-b91f-4b23-84b8-5e756eba68eb Discovery ESXi, Linux, macOS, Windows 1.0
Virtualization/Sandbox Evasion T1497 STIX ID attack-pattern--82caa33e-d11a-433a-94ea-9b5a5fbef81d Discovery, Stealth Linux, macOS, Windows 2.0
Virtualization/Sandbox Evasion: System Checks T1497.001 · sub-technique of T1497 STIX ID attack-pattern--29be378d-262d-4e99-b00d-852d573628e6 Discovery, Stealth Linux, macOS, Windows 3.0
Virtualization/Sandbox Evasion: Time Based Checks T1497.003 · sub-technique of T1497 STIX ID attack-pattern--4bed873f-0b7d-41d4-b93a-b6905d1f90b0 Discovery, Stealth Linux, macOS, Windows 3.0
Virtualization/Sandbox Evasion: User Activity Based Checks T1497.002 · sub-technique of T1497 STIX ID attack-pattern--91541e7e-b969-40c6-bbd8-1b5352ec2938 Discovery, Stealth Linux, macOS, Windows 2.0
Weaken Encryption T1600 STIX ID attack-pattern--1f9012ef-1e10-4e48-915e-e03563435fe8 Defense Impairment Network Devices 2.0
Weaken Encryption: Disable Crypto Hardware T1600.002 · sub-technique of T1600 STIX ID attack-pattern--7efba77e-3bc4-4ca5-8292-d8201dcd64b5 Defense Impairment Network Devices 2.0
Weaken Encryption: Reduce Key Space T1600.001 · sub-technique of T1600 STIX ID attack-pattern--3a40f208-a9c1-4efa-a598-4003c3681fb8 Defense Impairment Network Devices 2.0
Web Service T1102 STIX ID attack-pattern--830c9528-df21-472c-8c14-a036bf17d665 Command and Control ESXi, Linux, macOS, Windows 1.3
Web Service: Bidirectional Communication T1102.002 · sub-technique of T1102 STIX ID attack-pattern--be055942-6e63-49d7-9fa1-9cb7d8a8f3f4 Command and Control ESXi, Linux, macOS, Windows 1.1
Web Service: Dead Drop Resolver T1102.001 · sub-technique of T1102 STIX ID attack-pattern--f7827069-0bf2-4764-af4f-23fae0d181b7 Command and Control ESXi, Linux, macOS, Windows 1.1
Web Service: One-Way Communication T1102.003 · sub-technique of T1102 STIX ID attack-pattern--9c99724c-a483-4d60-ad9d-7f004e42e8e8 Command and Control ESXi, Linux, macOS, Windows 1.1
Wi-Fi Networks T1669 STIX ID attack-pattern--fde016f6-211a-41c8-a4ab-301f1e419c62 Initial Access Linux, macOS, Network Devices, Windows 1.0
Windows Management Instrumentation T1047 STIX ID attack-pattern--01a5a209-b94c-450b-b7f9-946497d91055 Execution Windows 1.6
XSL Script Processing T1220 STIX ID attack-pattern--ebbe170d-aa74-4946-8511-9921243415a3 Stealth Windows 2.0

Privacy floor

Cross-customer cells require 5 contributors Suppressed results display “Insufficient data,” never zero. No people, hostnames, raw content, or exact timestamps cross tenant boundaries.

Reference data

Based in part on MITRE ATT&CK® v19.1 STIX 2.1 projection · snapshot retrieved 2026-07-27T03:45:00Z · no MITRE endorsement implied. Official dataset License

Cross-framework context

Versioned OWASP risks, related—not equivalent Fortitude-authored crosswalks may be primary, supporting, conditional, or explicitly unmapped. No OWASP endorsement implied. OWASP Top 10 2025 OWASP Top 10 for LLM Applications 2025 OWASP Top 10 for Agentic Applications 2026 OWASP MCP Top 10 2025 · Beta Sources retrieved 2026-07-26 · OWASP terms
Source

Assessment confidence
Prevalence
Reports
Leading cohort

Evidence funnel

Framework mappings

MITRE ATT&CK

OWASP related risks

Recommended next step