Network intelligence
Threat intelligence
Investigate behaviors across customer telemetry and anonymized reports, grounded in ATT&CK, crosswalked to OWASP, and extended with emerging patterns.
Executive brief
What changed and why it matters
Identity-led social engineering is moving into trusted workflows
Observed activity rose 28% across the synthetic network, led by cloud-account abuse and attacks that inherit a legitimate user or agent's authority. Three proposed patterns deserve analyst review; none are attributed to an actor.
-
1
Prioritize controls around authorized tool actions and cloud session changes.
-
2
Validate the identity and collaboration telemetry required for the top five patterns.
-
3
Brief workflow owners on callback-channel and approval-context changes.
Network pulse
Assessed observations
Investigate now
Priority signals
Confidence, prevalence, and severity stay separate so analysts can challenge each claim.
| Pattern | Severity | Confidence | Frameworks | Affected orgs | Change | Last seen | Open detail |
|---|---|---|---|---|---|---|---|
| Fortitude proposed Indirect Prompt Injection to Authorized Tool Action FORT-0001 · Execution | Critical | 88% assessment | ATT&CK LLM01 · LLM06 +2 | 7 17 observations | +42% | 18 min ago | |
| MITRE ATT&CK® Phishing: Spearphishing Link T1566.002 · Initial Access | High | 94% assessment | ATT&CK No direct OWASP | 14 31 observations | +18% | 42 min ago | |
| MITRE ATT&CK® Valid Accounts: Cloud Accounts T1078.004 · Initial Access | High | 91% assessment | ATT&CK A07 | 12 22 observations | +29% | 1h ago | |
| Fortitude proposed MCP Tool-Schema Poisoning FORT-0002 · Stealth | High | 76% assessment | ATT&CK LLM03 · ASI04 +3 | 5 9 observations | +100% | 3h ago | |
| MITRE ATT&CK® Social Engineering: Impersonation T1684.001 · Stealth | Medium | 89% assessment | ATT&CK No direct OWASP | 11 18 observations | +23% | 4h ago | |
| Fortitude proposed Cross-Agent Authority Relay FORT-0003 · Privilege Escalation | Medium | 68% assessment | ATT&CK ASI03 · A01 +2 | 5 6 observations | +100% | 7h ago |
Landscape
Enterprise ATT&CK matrix
One metric per color scale. Switch modes to avoid conflating prevalence with defensive coverage.
Reconnaissance
5 orgsResource Development
Insufficient dataInitial Access
14 orgsExecution
11 orgsPersistence
7 orgsPrivilege Escalation
Insufficient dataStealth
8 orgsDefense Impairment
5 orgsCredential Access
12 orgsDiscovery
6 orgsLateral Movement
5 orgsCollection
7 orgsCommand and Control
5 orgsExfiltration
Insufficient dataImpact
5 orgsFortitude research
Emerging patterns
Proposed behaviors can graduate through analyst review without mutating or impersonating ATT&CK.
Indirect Prompt Injection to Authorized Tool Action
Attacker-controlled retrieved content causes an enterprise AI agent to invoke an authorized tool outside the user's intent.
- Confidence
- 88%
- Affected orgs
- 7
- First seen
- 2026-06-18
MCP Tool-Schema Poisoning
A compromised tool provider alters descriptions or schemas to capture sensitive arguments or conceal side effects.
- Confidence
- 76%
- Affected orgs
- 5
- First seen
- 2026-07-03
Cross-Agent Authority Relay
A low-privilege agent induces a more privileged downstream agent to act without preserving request origin or constraints.
- Confidence
- 68%
- Affected orgs
- 5
- First seen
- 2026-07-11
Reference catalog Explore MITRE ATT&CK Enterprise v19.1 15 tactics · 697 techniques and sub-techniques
| Technique | Tactic | Platforms | Object version |
|---|---|---|---|
| Abuse Elevation Control Mechanism T1548 STIX ID attack-pattern--67720091-eee3-4d2d-ae16-8264567f6f5b | Privilege Escalation | IaaS, Identity Provider, Linux, macOS, Office Suite, Windows | 2.0 |
| Abuse Elevation Control Mechanism: Bypass User Account Control T1548.002 · sub-technique of T1548 STIX ID attack-pattern--120d5519-3098-4e1c-9191-2aa61232f073 | Privilege Escalation | Windows | 3.0 |
| Abuse Elevation Control Mechanism: Elevated Execution with Prompt T1548.004 · sub-technique of T1548 STIX ID attack-pattern--b84903f0-c7d5-435d-a69e-de47cc3578c0 | Privilege Escalation | macOS | 2.0 |
| Abuse Elevation Control Mechanism: Setuid and Setgid T1548.001 · sub-technique of T1548 STIX ID attack-pattern--6831414d-bb70-42b7-8030-d4e06b2660c9 | Privilege Escalation | Linux, macOS | 2.0 |
| Abuse Elevation Control Mechanism: Sudo and Sudo Caching T1548.003 · sub-technique of T1548 STIX ID attack-pattern--1365fe3b-0f50-455d-b4da-266ce31c23b0 | Privilege Escalation | Linux, macOS | 2.0 |
| Abuse Elevation Control Mechanism: TCC Manipulation T1548.006 · sub-technique of T1548 STIX ID attack-pattern--e8a0a025-3601-4755-abfb-8d08283329fb | Privilege Escalation | macOS | 2.0 |
| Abuse Elevation Control Mechanism: Temporary Elevated Cloud Access T1548.005 · sub-technique of T1548 STIX ID attack-pattern--6fa224c7-5091-4595-bf15-3fc9fe2f2c7c | Privilege Escalation | IaaS, Identity Provider, Office Suite | 2.0 |
| Access Token Manipulation T1134 STIX ID attack-pattern--dcaa092b-7de9-4a21-977f-7fcb77e89c48 | Privilege Escalation, Stealth | Windows | 3.0 |
| Access Token Manipulation: Create Process with Token T1134.002 · sub-technique of T1134 STIX ID attack-pattern--677569f9-a8b0-459e-ab24-7f18091fa7bf | Privilege Escalation, Stealth | Windows | 2.0 |
| Access Token Manipulation: Make and Impersonate Token T1134.003 · sub-technique of T1134 STIX ID attack-pattern--8cdeb020-e31e-4f88-a582-f53dcfbda819 | Privilege Escalation, Stealth | Windows | 2.0 |
| Access Token Manipulation: Parent PID Spoofing T1134.004 · sub-technique of T1134 STIX ID attack-pattern--93591901-3172-4e94-abf8-6034ab26f44a | Privilege Escalation, Stealth | Windows | 2.0 |
| Access Token Manipulation: SID-History Injection T1134.005 · sub-technique of T1134 STIX ID attack-pattern--b7dc639b-24cd-482d-a7f1-8897eda21023 | Privilege Escalation, Stealth | Windows | 2.0 |
| Access Token Manipulation: Token Impersonation/Theft T1134.001 · sub-technique of T1134 STIX ID attack-pattern--86850eff-2729-40c3-b85e-c4af26da4a2d | Privilege Escalation, Stealth | Windows | 2.0 |
| Account Access Removal T1531 STIX ID attack-pattern--b24e2a20-3b3d-4bf0-823b-1ed765398fb0 | Impact | ESXi, IaaS, Linux, macOS, Office Suite, SaaS, Windows | 1.5 |
| Account Discovery T1087 STIX ID attack-pattern--72b74d71-8169-42aa-92e0-e7b04b9f5a08 | Discovery | ESXi, IaaS, Identity Provider, Linux, macOS, Office Suite, SaaS, Windows | 2.6 |
| Account Discovery: Cloud Account T1087.004 · sub-technique of T1087 STIX ID attack-pattern--8f104855-e5b7-4077-b1f5-bc3103b41abe | Discovery | IaaS, Identity Provider, Office Suite, SaaS | 1.3 |
| Account Discovery: Domain Account T1087.002 · sub-technique of T1087 STIX ID attack-pattern--21875073-b0ee-49e3-9077-1e2a885359af | Discovery | Linux, macOS, Windows | 1.2 |
| Account Discovery: Email Account T1087.003 · sub-technique of T1087 STIX ID attack-pattern--4bc31b94-045b-4752-8920-aebaebdb6470 | Discovery | Office Suite, Windows | 1.2 |
| Account Discovery: Local Account T1087.001 · sub-technique of T1087 STIX ID attack-pattern--25659dd6-ea12-45c4-97e6-381e3e4b593e | Discovery | ESXi, Linux, macOS, Windows | 1.5 |
| Account Manipulation T1098 STIX ID attack-pattern--a10641f4-87b4-45a3-a906-92a149cb2c27 | Persistence, Privilege Escalation | Containers, ESXi, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows | 2.8 |
| Account Manipulation: Additional Cloud Credentials T1098.001 · sub-technique of T1098 STIX ID attack-pattern--8a2f40cf-8325-47f9-96e4-b1ca4c7389bd | Persistence, Privilege Escalation | IaaS, Identity Provider, SaaS | 2.8 |
| Account Manipulation: Additional Cloud Roles T1098.003 · sub-technique of T1098 STIX ID attack-pattern--2dbbdcd5-92cf-44c0-aea2-fe24783a6bc3 | Persistence, Privilege Escalation | IaaS, Identity Provider, Office Suite, SaaS | 2.5 |
| Account Manipulation: Additional Container Cluster Roles T1098.006 · sub-technique of T1098 STIX ID attack-pattern--35d30338-5bfa-41b0-a170-ec06dfd75f64 | Persistence, Privilege Escalation | Containers | 1.0 |
| Account Manipulation: Additional Email Delegate Permissions T1098.002 · sub-technique of T1098 STIX ID attack-pattern--e74de37c-a829-446c-937d-56a44f0e9306 | Persistence, Privilege Escalation | Office Suite, Windows | 2.2 |
| Account Manipulation: Additional Local or Domain Groups T1098.007 · sub-technique of T1098 STIX ID attack-pattern--3e6831b2-bf4c-4ae6-b328-2e7c6633b291 | Persistence, Privilege Escalation | Linux, macOS, Windows | 1.1 |
| Account Manipulation: Device Registration T1098.005 · sub-technique of T1098 STIX ID attack-pattern--7decb26c-715c-40cf-b7e0-026f7d7cc215 | Persistence, Privilege Escalation | Identity Provider, Windows | 1.4 |
| Account Manipulation: SSH Authorized Keys T1098.004 · sub-technique of T1098 STIX ID attack-pattern--6b57dc31-b814-4a03-8706-28bc20d739c4 | Persistence, Privilege Escalation | ESXi, IaaS, Linux, macOS, Network Devices | 1.4 |
| Acquire Access T1650 STIX ID attack-pattern--d21bb61f-08ad-4dc1-b001-81ca6cb79954 | Resource Development | PRE | 1.0 |
| Acquire Infrastructure T1583 STIX ID attack-pattern--0458aab9-ad42-4eac-9e22-706a95bafee2 | Resource Development | PRE | 1.5 |
| Acquire Infrastructure: Botnet T1583.005 · sub-technique of T1583 STIX ID attack-pattern--31225cd3-cd46-4575-b287-c2c14011c074 | Resource Development | PRE | 1.2 |
| Acquire Infrastructure: DNS Server T1583.002 · sub-technique of T1583 STIX ID attack-pattern--197ef1b9-e764-46c3-b96c-23f77985dc81 | Resource Development | PRE | 1.0 |
| Acquire Infrastructure: Domains T1583.001 · sub-technique of T1583 STIX ID attack-pattern--40f5caa0-4cb7-4117-89fc-d421bb493df3 | Resource Development | PRE | 1.4 |
| Acquire Infrastructure: Malvertising T1583.008 · sub-technique of T1583 STIX ID attack-pattern--155207c0-7f53-4f13-a06b-0a9907ef5096 | Resource Development | PRE | 1.0 |
| Acquire Infrastructure: Server T1583.004 · sub-technique of T1583 STIX ID attack-pattern--60c4b628-4807-4b0b-bbf5-fdac8643c337 | Resource Development | PRE | 1.3 |
| Acquire Infrastructure: Serverless T1583.007 · sub-technique of T1583 STIX ID attack-pattern--04a5a8ab-3bc8-4c83-95c9-55274a89786d | Resource Development | PRE | 1.1 |
| Acquire Infrastructure: Virtual Private Server T1583.003 · sub-technique of T1583 STIX ID attack-pattern--79da0971-3147-4af6-a4f5-e8cd447cd795 | Resource Development | PRE | 1.1 |
| Acquire Infrastructure: Web Services T1583.006 · sub-technique of T1583 STIX ID attack-pattern--88d31120-5bc7-4ce3-a9c0-7cf147be8e54 | Resource Development | PRE | 1.3 |
| Active Scanning T1595 STIX ID attack-pattern--67073dde-d720-45ae-83da-b12d5e73ca3b | Reconnaissance | PRE | 1.0 |
| Active Scanning: Scanning IP Blocks T1595.001 · sub-technique of T1595 STIX ID attack-pattern--db8f5003-3b20-48f0-9b76-123e44208120 | Reconnaissance | PRE | 1.1 |
| Active Scanning: Vulnerability Scanning T1595.002 · sub-technique of T1595 STIX ID attack-pattern--5502c4e9-24ef-4d5f-8ee9-9e906c2f82c4 | Reconnaissance | PRE | 1.0 |
| Active Scanning: Wordlist Scanning T1595.003 · sub-technique of T1595 STIX ID attack-pattern--bed04f7d-e48a-4e76-bd0f-4c57fe31fc46 | Reconnaissance | PRE | 1.0 |
| Adversary-in-the-Middle T1557 STIX ID attack-pattern--035bb001-ab69-4a0b-9f6c-2de8b09e1b9d | Collection, Credential Access | Linux, macOS, Network Devices, Windows | 2.5 |
| Adversary-in-the-Middle: ARP Cache Poisoning T1557.002 · sub-technique of T1557 STIX ID attack-pattern--cabe189c-a0e3-4965-a473-dcff00f17213 | Collection, Credential Access | Linux, macOS, Windows | 1.1 |
| Adversary-in-the-Middle: DHCP Spoofing T1557.003 · sub-technique of T1557 STIX ID attack-pattern--59ff91cd-1430-4075-8563-e6f15f4f9ff5 | Collection, Credential Access | Linux, macOS, Windows | 1.1 |
| Adversary-in-the-Middle: Evil Twin T1557.004 · sub-technique of T1557 STIX ID attack-pattern--48b836c6-e4ca-435a-82a3-29c03e5b492e | Collection, Credential Access | Network Devices | 1.1 |
| Adversary-in-the-Middle: Name Resolution Poisoning and SMB Relay T1557.001 · sub-technique of T1557 STIX ID attack-pattern--650c784b-7504-4df7-ab2c-4ea882384d1e | Collection, Credential Access | Windows | 2.0 |
| Application Layer Protocol T1071 STIX ID attack-pattern--355be19c-ffc9-46d5-8d50-d6a036c675b6 | Command and Control | ESXi, Linux, macOS, Network Devices, Windows | 2.4 |
| Application Layer Protocol: DNS T1071.004 · sub-technique of T1071 STIX ID attack-pattern--1996eef1-ced3-4d7f-bf94-33298cabbf72 | Command and Control | ESXi, Linux, macOS, Network Devices, Windows | 1.4 |
| Application Layer Protocol: File Transfer Protocols T1071.002 · sub-technique of T1071 STIX ID attack-pattern--9a60a291-8960-4387-8a4a-2ab5c18bb50b | Command and Control | ESXi, Linux, macOS, Network Devices, Windows | 1.4 |
| Application Layer Protocol: Mail Protocols T1071.003 · sub-technique of T1071 STIX ID attack-pattern--54b4c251-1f0e-4eba-ba6b-dbc7a6f6f06b | Command and Control | Linux, macOS, Network Devices, Windows | 1.2 |
| Application Layer Protocol: Publish/Subscribe Protocols T1071.005 · sub-technique of T1071 STIX ID attack-pattern--241f9ea8-f6ae-4f38-92f5-cef5b7e539dd | Command and Control | Linux, macOS, Network Devices, Windows | 1.1 |
| Application Layer Protocol: Web Protocols T1071.001 · sub-technique of T1071 STIX ID attack-pattern--df8b2a25-8bdf-4856-953c-a04372b1c161 | Command and Control | ESXi, Linux, macOS, Network Devices, Windows | 1.5 |
| Application Window Discovery T1010 STIX ID attack-pattern--4ae4f953-fe58-4cc8-a327-33257e30a830 | Discovery | Linux, macOS, Windows | 1.3 |
| Archive Collected Data T1560 STIX ID attack-pattern--53ac20cd-aca3-406e-9aa0-9fc7fdc60a5a | Collection | Linux, macOS, Windows | 1.0 |
| Archive Collected Data: Archive via Custom Method T1560.003 · sub-technique of T1560 STIX ID attack-pattern--143c0cbb-a297-4142-9624-87ffc778980b | Collection | Linux, macOS, Windows | 1.0 |
| Archive Collected Data: Archive via Library T1560.002 · sub-technique of T1560 STIX ID attack-pattern--41868330-6ee2-4d0f-b743-9f2294c3c9b6 | Collection | Linux, macOS, Windows | 1.0 |
| Archive Collected Data: Archive via Utility T1560.001 · sub-technique of T1560 STIX ID attack-pattern--00f90846-cbd1-4fc5-9233-df5c2bf2a662 | Collection | Linux, macOS, Windows | 1.3 |
| Audio Capture T1123 STIX ID attack-pattern--1035cdf2-3e5f-446f-a7a7-e8f6d7925967 | Collection | Linux, macOS, Windows | 1.0 |
| Automated Collection T1119 STIX ID attack-pattern--30208d3e-0d6b-43c8-883e-44462a514619 | Collection | IaaS, Linux, macOS, Office Suite, SaaS, Windows | 1.4 |
| Automated Exfiltration T1020 STIX ID attack-pattern--774a3188-6ba9-4dc4-879d-d54ee48a5ce9 | Exfiltration | Linux, macOS, Network Devices, Windows | 1.3 |
| Automated Exfiltration: Traffic Duplication T1020.001 · sub-technique of T1020 STIX ID attack-pattern--7c46b364-8496-4234-8a56-f7e6727e21e1 | Exfiltration | IaaS, Network Devices | 1.4 |
| BITS Jobs T1197 STIX ID attack-pattern--c8e87b83-edbb-48d4-9295-4974897525b7 | Execution, Persistence, Stealth | Windows | 2.0 |
| Boot or Logon Autostart Execution T1547 STIX ID attack-pattern--1ecb2399-e8ba-4f6b-8ba7-5c27d49405cf | Persistence, Privilege Escalation | Linux, macOS, Network Devices, Windows | 1.3 |
| Boot or Logon Autostart Execution: Active Setup T1547.014 · sub-technique of T1547 STIX ID attack-pattern--22522668-ddf6-470b-a027-9d6866679f67 | Persistence, Privilege Escalation | Windows | 1.1 |
| Boot or Logon Autostart Execution: Authentication Package T1547.002 · sub-technique of T1547 STIX ID attack-pattern--b8cfed42-6a8a-4989-ad72-541af74475ec | Persistence, Privilege Escalation | Windows | 1.1 |
| Boot or Logon Autostart Execution: Kernel Modules and Extensions T1547.006 · sub-technique of T1547 STIX ID attack-pattern--a1b52199-c8c5-438a-9ded-656f1d0888c6 | Persistence, Privilege Escalation | Linux, macOS | 1.4 |
| Boot or Logon Autostart Execution: LSASS Driver T1547.008 · sub-technique of T1547 STIX ID attack-pattern--f0589bc3-a6ae-425a-a3d5-5659bfee07f4 | Persistence, Privilege Escalation | Windows | 1.1 |
| Boot or Logon Autostart Execution: Login Items T1547.015 · sub-technique of T1547 STIX ID attack-pattern--84601337-6a55-4ad7-9c35-79e0d1ea2ab3 | Persistence, Privilege Escalation | macOS | 1.1 |
| Boot or Logon Autostart Execution: Port Monitors T1547.010 · sub-technique of T1547 STIX ID attack-pattern--43881e51-ac74-445b-b4c6-f9f9e9bf23fe | Persistence, Privilege Escalation | Windows | 1.3 |
| Boot or Logon Autostart Execution: Print Processors T1547.012 · sub-technique of T1547 STIX ID attack-pattern--2de47683-f398-448f-b947-9abcc3e32fad | Persistence, Privilege Escalation | Windows | 1.2 |
| Boot or Logon Autostart Execution: Re-opened Applications T1547.007 · sub-technique of T1547 STIX ID attack-pattern--e5cc9e7a-e61a-46a1-b869-55fb6eab058e | Persistence, Privilege Escalation | macOS | 1.2 |
| Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder T1547.001 · sub-technique of T1547 STIX ID attack-pattern--9efb1ea7-c37b-4595-9640-b7680cd84279 | Persistence, Privilege Escalation | Windows | 2.1 |
| Boot or Logon Autostart Execution: Security Support Provider T1547.005 · sub-technique of T1547 STIX ID attack-pattern--5095a853-299c-4876-abd7-ac0050fb5462 | Persistence, Privilege Escalation | Windows | 1.1 |
| Boot or Logon Autostart Execution: Shortcut Modification T1547.009 · sub-technique of T1547 STIX ID attack-pattern--4ab929c6-ee2d-4fb5-aab4-b14be2ed7179 | Persistence, Privilege Escalation | Windows | 1.3 |
| Boot or Logon Autostart Execution: Time Providers T1547.003 · sub-technique of T1547 STIX ID attack-pattern--61afc315-860c-4364-825d-0d62b2e91edc | Persistence, Privilege Escalation | Windows | 1.2 |
| Boot or Logon Autostart Execution: Winlogon Helper DLL T1547.004 · sub-technique of T1547 STIX ID attack-pattern--6836813e-8ec8-4375-b459-abb388cb1a35 | Persistence, Privilege Escalation | Windows | 1.3 |
| Boot or Logon Autostart Execution: XDG Autostart Entries T1547.013 · sub-technique of T1547 STIX ID attack-pattern--e0232cb0-ded5-4c2e-9dc7-2893142a5c11 | Persistence, Privilege Escalation | Linux | 1.2 |
| Boot or Logon Initialization Scripts T1037 STIX ID attack-pattern--03259939-0b57-482f-8eb5-87c0e0d54334 | Persistence, Privilege Escalation | ESXi, Linux, macOS, Network Devices, Windows | 2.4 |
| Boot or Logon Initialization Scripts: Login Hook T1037.002 · sub-technique of T1037 STIX ID attack-pattern--43ba2b05-cf72-4b6c-8243-03a4aba41ee0 | Persistence, Privilege Escalation | macOS | 2.0 |
| Boot or Logon Initialization Scripts: Logon Script (Windows) T1037.001 · sub-technique of T1037 STIX ID attack-pattern--eb125d40-0b2d-41ac-a71a-3229241c2cd3 | Persistence, Privilege Escalation | Windows | 1.0 |
| Boot or Logon Initialization Scripts: Network Logon Script T1037.003 · sub-technique of T1037 STIX ID attack-pattern--c63a348e-ffc2-486a-b9d9-d7f11ec54d99 | Persistence, Privilege Escalation | Windows | 1.0 |
| Boot or Logon Initialization Scripts: RC Scripts T1037.004 · sub-technique of T1037 STIX ID attack-pattern--dca670cf-eeec-438f-8185-fd959d9ef211 | Persistence, Privilege Escalation | ESXi, Linux, macOS, Network Devices | 2.2 |
| Boot or Logon Initialization Scripts: Startup Items T1037.005 · sub-technique of T1037 STIX ID attack-pattern--c0dfe7b0-b873-4618-9ff8-53e31f70907f | Persistence, Privilege Escalation | macOS | 1.1 |
| Browser Information Discovery T1217 STIX ID attack-pattern--5e4a2073-9643-44cb-a0b5-e7f4048446c7 | Discovery | Linux, macOS, Windows | 2.0 |
| Browser Session Hijacking T1185 STIX ID attack-pattern--544b0346-29ad-41e1-a808-501bb4193f47 | Collection | Windows | 2.1 |
| Brute Force T1110 STIX ID attack-pattern--a93494bb-4b80-4ea1-8695-3236a49916fd | Credential Access | Containers, ESXi, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows | 2.8 |
| Brute Force: Credential Stuffing T1110.004 · sub-technique of T1110 STIX ID attack-pattern--b2d03cea-aec1-45ca-9744-9ee583c1e1cc | Credential Access | Containers, ESXi, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows | 1.7 |
| Brute Force: Password Cracking T1110.002 · sub-technique of T1110 STIX ID attack-pattern--1d24cdee-9ea2-4189-b08e-af110bf2435d | Credential Access | Identity Provider, Linux, macOS, Network Devices, Office Suite, Windows | 1.4 |
| Brute Force: Password Guessing T1110.001 · sub-technique of T1110 STIX ID attack-pattern--09c4c11e-4fa1-4f8c-8dad-3cf8e69ad119 | Credential Access | Containers, ESXi, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows | 1.7 |
| Brute Force: Password Spraying T1110.003 · sub-technique of T1110 STIX ID attack-pattern--692074ae-bb62-4a5e-a735-02cb6bde458c | Credential Access | Containers, ESXi, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows | 1.8 |
| Build Image on Host T1612 STIX ID attack-pattern--800f9819-7007-4540-a520-40e655876800 | Stealth | Containers | 2.0 |
| Clipboard Data T1115 STIX ID attack-pattern--30973a08-aed9-4edf-8604-9084ce1b5c4f | Collection | Linux, macOS, Windows | 1.2 |
| Cloud Administration Command T1651 STIX ID attack-pattern--d94b3ae9-8059-4989-8e9f-ea0f601f80a7 | Execution | IaaS | 2.1 |
| Cloud Application Integration T1671 STIX ID attack-pattern--c31aebd6-c9b5-420f-ba2a-5853bbf897fa | Persistence | Office Suite, SaaS | 1.0 |
| Cloud Infrastructure Discovery T1580 STIX ID attack-pattern--57a3d31a-d04f-4663-b2da-7df8ec3f8c9d | Discovery | IaaS | 1.3 |
| Cloud Service Dashboard T1538 STIX ID attack-pattern--e49920b0-6c54-40c1-9571-73723653205f | Discovery | IaaS, Identity Provider, Office Suite, SaaS | 1.5 |
| Cloud Service Discovery T1526 STIX ID attack-pattern--e24fcba8-2557-4442-a139-1ee2f2e784db | Discovery | IaaS, Identity Provider, Office Suite, SaaS | 1.4 |
| Cloud Storage Object Discovery T1619 STIX ID attack-pattern--8565825b-21c8-4518-b75e-cbc4c717a156 | Discovery | IaaS | 1.0 |
| Command and Scripting Interpreter T1059 STIX ID attack-pattern--7385dfaf-6886-4229-9ecd-6fd678040830 | Execution | Containers, ESXi, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows | 2.7 |
| Command and Scripting Interpreter: AppleScript T1059.002 · sub-technique of T1059 STIX ID attack-pattern--37b11151-1776-4f8f-b328-30939fbf2ceb | Execution | macOS | 1.3 |
| Command and Scripting Interpreter: AutoHotKey & AutoIT T1059.010 · sub-technique of T1059 STIX ID attack-pattern--3a32740a-11b0-4bcf-b0a9-3abd0f6d3cd5 | Execution | Windows | 1.1 |
| Command and Scripting Interpreter: Cloud API T1059.009 · sub-technique of T1059 STIX ID attack-pattern--55bb4471-ff1f-43b4-88c1-c9384ec47abf | Execution | IaaS, Identity Provider, Office Suite, SaaS | 1.2 |
| Command and Scripting Interpreter: Container CLI/API T1059.013 · sub-technique of T1059 STIX ID attack-pattern--c283d88f-8c23-4318-9da5-3d50cecad756 | Execution | Containers | 1.0 |
| Command and Scripting Interpreter: Hypervisor CLI T1059.012 · sub-technique of T1059 STIX ID attack-pattern--d2d642da-61ff-4211-b4df-7923c9ca220c | Execution | ESXi | 1.0 |
| Command and Scripting Interpreter: JavaScript T1059.007 · sub-technique of T1059 STIX ID attack-pattern--0f4a0c76-ab2d-4cb0-85d3-3f0efb8cba0d | Execution | Linux, macOS, Windows | 2.2 |
| Command and Scripting Interpreter: Lua T1059.011 · sub-technique of T1059 STIX ID attack-pattern--afddee82-3385-4682-ad90-eeced33f2d07 | Execution | Linux, macOS, Network Devices, Windows | 1.1 |
| Command and Scripting Interpreter: Network Device CLI T1059.008 · sub-technique of T1059 STIX ID attack-pattern--818302b2-d640-477b-bf88-873120ce85c4 | Execution | Network Devices | 1.2 |
| Command and Scripting Interpreter: PowerShell T1059.001 · sub-technique of T1059 STIX ID attack-pattern--970a3432-3237-47ad-bcca-7d8cbb217736 | Execution | Windows | 1.5 |
| Command and Scripting Interpreter: Python T1059.006 · sub-technique of T1059 STIX ID attack-pattern--cc3502b5-30cc-4473-ad48-42d51a6ef6d1 | Execution | ESXi, Linux, macOS, Windows | 1.1 |
| Command and Scripting Interpreter: Unix Shell T1059.004 · sub-technique of T1059 STIX ID attack-pattern--a9d4b653-6915-42af-98b2-5758c4ceee56 | Execution | ESXi, Linux, macOS, Network Devices | 1.4 |
| Command and Scripting Interpreter: Visual Basic T1059.005 · sub-technique of T1059 STIX ID attack-pattern--dfd7cc1d-e1d8-4394-a198-97c4cab8aa67 | Execution | Linux, macOS, Windows | 1.5 |
| Command and Scripting Interpreter: Windows Command Shell T1059.003 · sub-technique of T1059 STIX ID attack-pattern--d1fcf083-a721-4223-aedf-bf8960798d62 | Execution | Windows | 1.5 |
| Communication Through Removable Media T1092 STIX ID attack-pattern--64196062-5210-42c3-9a02-563a0d1797ef | Command and Control | Linux, macOS, Windows | 1.0 |
| Compromise Accounts T1586 STIX ID attack-pattern--81033c3b-16a4-46e4-8fed-9b030dd03c4a | Resource Development | PRE | 1.2 |
| Compromise Accounts: Cloud Accounts T1586.003 · sub-technique of T1586 STIX ID attack-pattern--3d52e51e-f6db-4719-813c-48002a99f43a | Resource Development | PRE | 1.1 |
| Compromise Accounts: Email Accounts T1586.002 · sub-technique of T1586 STIX ID attack-pattern--3dc8c101-d4db-4f4d-8150-1b5a76ca5f1b | Resource Development | PRE | 1.1 |
| Compromise Accounts: Social Media Accounts T1586.001 · sub-technique of T1586 STIX ID attack-pattern--274770e0-2612-4ccf-a678-ef8e7bad365d | Resource Development | PRE | 1.1 |
| Compromise Host Software Binary T1554 STIX ID attack-pattern--960c3c86-1480-4d72-b4e0-8c242e84a5c5 | Persistence | ESXi, Linux, macOS, Windows | 2.2 |
| Compromise Infrastructure T1584 STIX ID attack-pattern--7e3beebd-8bfe-4e7b-a892-e44ab06a75f9 | Resource Development | PRE | 1.6 |
| Compromise Infrastructure: Botnet T1584.005 · sub-technique of T1584 STIX ID attack-pattern--810d8072-afb6-4a56-9ee7-86379ac4a6f3 | Resource Development | PRE | 1.0 |
| Compromise Infrastructure: DNS Server T1584.002 · sub-technique of T1584 STIX ID attack-pattern--c2f59d25-87fe-44aa-8f83-e8e59d077bf5 | Resource Development | PRE | 1.3 |
| Compromise Infrastructure: Domains T1584.001 · sub-technique of T1584 STIX ID attack-pattern--f9cc4d06-775f-4ee1-b401-4e2cc0da30ba | Resource Development | PRE | 1.4 |
| Compromise Infrastructure: Network Devices T1584.008 · sub-technique of T1584 STIX ID attack-pattern--149b477f-f364-4824-b1b5-aa1d56115869 | Resource Development | PRE | 1.1 |
| Compromise Infrastructure: Server T1584.004 · sub-technique of T1584 STIX ID attack-pattern--e196b5c5-8118-4a1c-ab8a-936586ce3db5 | Resource Development | PRE | 1.2 |
| Compromise Infrastructure: Serverless T1584.007 · sub-technique of T1584 STIX ID attack-pattern--df1bc34d-1634-4c93-b89e-8120994fce77 | Resource Development | PRE | 1.1 |
| Compromise Infrastructure: Virtual Private Server T1584.003 · sub-technique of T1584 STIX ID attack-pattern--39cc9f64-cf74-4a48-a4d8-fe98c54a02e0 | Resource Development | PRE | 1.1 |
| Compromise Infrastructure: Web Services T1584.006 · sub-technique of T1584 STIX ID attack-pattern--ae797531-3219-49a4-bccf-324ad7a4c7b2 | Resource Development | PRE | 1.2 |
| Container Administration Command T1609 STIX ID attack-pattern--7b50a1d3-4ca7-45d1-989d-a6503f04bfe1 | Execution | Containers | 1.3 |
| Container and Resource Discovery T1613 STIX ID attack-pattern--0470e792-32f8-46b0-a351-652bc35e9336 | Discovery | Containers | 1.1 |
| Content Injection T1659 STIX ID attack-pattern--43c9bc06-715b-42db-972f-52d25c09a20c | Command and Control, Initial Access | Linux, macOS, Windows | 1.0 |
| Create Account T1136 STIX ID attack-pattern--e01be9c5-e763-4caf-aeb7-000b416aef67 | Persistence | Containers, ESXi, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows | 2.6 |
| Create Account: Cloud Account T1136.003 · sub-technique of T1136 STIX ID attack-pattern--a009cb25-4801-4116-9105-80a91cf15c1b | Persistence | IaaS, Identity Provider, Office Suite, SaaS | 1.6 |
| Create Account: Domain Account T1136.002 · sub-technique of T1136 STIX ID attack-pattern--7610cada-1499-41a4-b3dd-46467b68d177 | Persistence | Linux, macOS, Windows | 1.1 |
| Create Account: Local Account T1136.001 · sub-technique of T1136 STIX ID attack-pattern--635cbe30-392d-4e27-978e-66774357c762 | Persistence | Containers, ESXi, Linux, macOS, Network Devices, Windows | 1.5 |
| Create or Modify System Process T1543 STIX ID attack-pattern--106c0cf6-bf73-4601-9aa8-0945c2715ec5 | Persistence, Privilege Escalation | Containers, Linux, macOS, Windows | 1.2 |
| Create or Modify System Process: Container Service T1543.005 · sub-technique of T1543 STIX ID attack-pattern--b0e54bf7-835e-4f44-bd8e-62f431b9b76a | Persistence, Privilege Escalation | Containers | 1.0 |
| Create or Modify System Process: Launch Agent T1543.001 · sub-technique of T1543 STIX ID attack-pattern--d10cbd34-42e3-45c0-84d2-535a09849584 | Persistence, Privilege Escalation | macOS | 1.5 |
| Create or Modify System Process: Launch Daemon T1543.004 · sub-technique of T1543 STIX ID attack-pattern--573ad264-1371-4ae0-8482-d2673b719dba | Persistence, Privilege Escalation | macOS | 1.3 |
| Create or Modify System Process: Systemd Service T1543.002 · sub-technique of T1543 STIX ID attack-pattern--dfefe2ed-4389-4318-8762-f0272b350a1b | Persistence, Privilege Escalation | Linux | 1.6 |
| Create or Modify System Process: Windows Service T1543.003 · sub-technique of T1543 STIX ID attack-pattern--2959d63f-73fd-46a1-abd2-109d7dcede32 | Persistence, Privilege Escalation | Windows | 1.6 |
| Credentials from Password Stores T1555 STIX ID attack-pattern--3fc9b85a-2862-4363-a64d-d692e3ffbee0 | Credential Access | IaaS, Linux, macOS, Windows | 1.2 |
| Credentials from Password Stores: Cloud Secrets Management Stores T1555.006 · sub-technique of T1555 STIX ID attack-pattern--cfb525cc-5494-401d-a82b-2539ca46a561 | Credential Access | IaaS | 1.0 |
| Credentials from Password Stores: Credentials from Web Browsers T1555.003 · sub-technique of T1555 STIX ID attack-pattern--58a3e6aa-4453-4cc8-a51f-4befe80b31a8 | Credential Access | Linux, macOS, Windows | 1.2 |
| Credentials from Password Stores: Keychain T1555.001 · sub-technique of T1555 STIX ID attack-pattern--1eaebf46-e361-4437-bc23-d5d65a3b92e3 | Credential Access | macOS | 1.1 |
| Credentials from Password Stores: Password Managers T1555.005 · sub-technique of T1555 STIX ID attack-pattern--315f51f0-6b03-4c1e-bfb2-84740afb8e21 | Credential Access | Linux, macOS, Windows | 1.1 |
| Credentials from Password Stores: Securityd Memory T1555.002 · sub-technique of T1555 STIX ID attack-pattern--1a80d097-54df-41d8-9d33-34e755ec5e72 | Credential Access | Linux, macOS | 1.2 |
| Credentials from Password Stores: Windows Credential Manager T1555.004 · sub-technique of T1555 STIX ID attack-pattern--d336b553-5da9-46ca-98a8-0b23f49fb447 | Credential Access | Windows | 1.1 |
| Data Destruction T1485 STIX ID attack-pattern--d45a3d09-b3cf-48f4-9f0f-f521ee5cb05c | Impact | Containers, ESXi, IaaS, Linux, macOS, Windows | 1.4 |
| Data Destruction: Lifecycle-Triggered Deletion T1485.001 · sub-technique of T1485 STIX ID attack-pattern--1001e0d6-ee09-4dfc-aa90-e9320ffc8fe4 | Impact | IaaS | 1.1 |
| Data Encoding T1132 STIX ID attack-pattern--cc7b8c4e-9be0-47ca-b0bb-83915ec3ee2f | Command and Control | ESXi, Linux, macOS, Windows | 1.3 |
| Data Encoding: Non-Standard Encoding T1132.002 · sub-technique of T1132 STIX ID attack-pattern--d467bc38-284b-4a00-96ac-125f447799fc | Command and Control | ESXi, Linux, macOS, Windows | 1.1 |
| Data Encoding: Standard Encoding T1132.001 · sub-technique of T1132 STIX ID attack-pattern--04fd5427-79c7-44ea-ae13-11b24778ff1c | Command and Control | ESXi, Linux, macOS, Windows | 1.1 |
| Data Encrypted for Impact T1486 STIX ID attack-pattern--b80d107d-fa0d-4b60-9684-b0433e8bdba0 | Impact | ESXi, IaaS, Linux, macOS, Windows | 1.5 |
| Data Manipulation T1565 STIX ID attack-pattern--ac9e6b22-11bf-45d7-9181-c1cb08360931 | Impact | Linux, macOS, Windows | 1.1 |
| Data Manipulation: Runtime Data Manipulation T1565.003 · sub-technique of T1565 STIX ID attack-pattern--32ad5c86-2bcf-47d8-8fdc-d7f3d79a7490 | Impact | Linux, macOS, Windows | 1.2 |
| Data Manipulation: Stored Data Manipulation T1565.001 · sub-technique of T1565 STIX ID attack-pattern--1cfcb312-b8d7-47a4-b560-4b16cc677292 | Impact | Linux, macOS, Windows | 1.1 |
| Data Manipulation: Transmitted Data Manipulation T1565.002 · sub-technique of T1565 STIX ID attack-pattern--d0613359-5781-4fd2-b5be-c269270be1f6 | Impact | Linux, macOS, Windows | 1.1 |
| Data Obfuscation T1001 STIX ID attack-pattern--ad255bfe-a9e6-4b52-a258-8d3462abe842 | Command and Control | ESXi, Linux, macOS, Windows | 1.2 |
| Data Obfuscation: Junk Data T1001.001 · sub-technique of T1001 STIX ID attack-pattern--f7c0689c-4dbd-489b-81be-7cb7c7079ade | Command and Control | ESXi, Linux, macOS, Windows | 1.1 |
| Data Obfuscation: Protocol or Service Impersonation T1001.003 · sub-technique of T1001 STIX ID attack-pattern--c325b232-d5bc-4dde-a3ec-71f3db9e8adc | Command and Control | ESXi, Linux, macOS, Windows | 2.1 |
| Data Obfuscation: Steganography T1001.002 · sub-technique of T1001 STIX ID attack-pattern--eec23884-3fa1-4d8a-ac50-6f104d51e235 | Command and Control | ESXi, Linux, macOS, Windows | 1.1 |
| Data Staged T1074 STIX ID attack-pattern--7dd95ff6-712e-4056-9626-312ea4ab4c5e | Collection | ESXi, IaaS, Linux, macOS, Windows | 1.5 |
| Data Staged: Local Data Staging T1074.001 · sub-technique of T1074 STIX ID attack-pattern--1c34f7aa-9341-4a48-bfab-af22e51aca6c | Collection | ESXi, Linux, macOS, Windows | 1.2 |
| Data Staged: Remote Data Staging T1074.002 · sub-technique of T1074 STIX ID attack-pattern--359b00ad-9425-420b-bba5-6de8d600cbc0 | Collection | ESXi, IaaS, Linux, macOS, Windows | 1.2 |
| Data Transfer Size Limits T1030 STIX ID attack-pattern--c3888c54-775d-4b2f-b759-75a2ececcbfd | Exfiltration | ESXi, Linux, macOS, Windows | 1.1 |
| Data from Cloud Storage T1530 STIX ID attack-pattern--3298ce88-1628-43b1-87d9-0b5336b193d7 | Collection | IaaS, Office Suite, SaaS | 2.2 |
| Data from Configuration Repository T1602 STIX ID attack-pattern--0ad7bc5c-235a-4048-944b-3b286676cb74 | Collection | Network Devices | 1.1 |
| Data from Configuration Repository: Network Device Configuration Dump T1602.002 · sub-technique of T1602 STIX ID attack-pattern--52759bf1-fe12-4052-ace6-c5b0cf7dd7fd | Collection | Network Devices | 1.1 |
| Data from Configuration Repository: SNMP (MIB Dump) T1602.001 · sub-technique of T1602 STIX ID attack-pattern--ee7ff928-801c-4f34-8a99-3df965e581a5 | Collection | Network Devices | 1.1 |
| Data from Information Repositories T1213 STIX ID attack-pattern--d28ef391-8ed4-45dc-bc4a-2f43abf54416 | Collection | IaaS, Linux, macOS, Office Suite, SaaS, Windows | 3.4 |
| Data from Information Repositories: Code Repositories T1213.003 · sub-technique of T1213 STIX ID attack-pattern--cff94884-3b1c-4987-a70b-6d5643c621c3 | Collection | SaaS | 1.2 |
| Data from Information Repositories: Confluence T1213.001 · sub-technique of T1213 STIX ID attack-pattern--7ad38ef1-381a-406d-872a-38b136eb5ecc | Collection | SaaS | 1.1 |
| Data from Information Repositories: Customer Relationship Management Software T1213.004 · sub-technique of T1213 STIX ID attack-pattern--bbfbb096-6561-4d7d-aa2c-a5ee8e44c696 | Collection | SaaS | 1.0 |
| Data from Information Repositories: Databases T1213.006 · sub-technique of T1213 STIX ID attack-pattern--248d3fe1-7fe1-4d71-91c7-8bb7ef35cad3 | Collection | IaaS, Linux, macOS, SaaS, Windows | 1.0 |
| Data from Information Repositories: Messaging Applications T1213.005 · sub-technique of T1213 STIX ID attack-pattern--fb75213f-cfb0-40bf-a02f-3bad93d6601e | Collection | Office Suite, SaaS | 1.0 |
| Data from Information Repositories: Sharepoint T1213.002 · sub-technique of T1213 STIX ID attack-pattern--0c4b4fda-9062-47da-98b9-ceae2dcf052a | Collection | Office Suite, Windows | 1.1 |
| Data from Local System T1005 STIX ID attack-pattern--3c4a2599-71ee-4405-ba1e-0e28414b4bc5 | Collection | ESXi, Linux, macOS, Network Devices, Windows | 1.8 |
| Data from Network Shared Drive T1039 STIX ID attack-pattern--ae676644-d2d2-41b7-af7e-9bed1b55898c | Collection | Linux, macOS, Windows | 1.5 |
| Data from Removable Media T1025 STIX ID attack-pattern--1b7ba276-eedc-4951-a762-0ceea2c030ec | Collection | Linux, macOS, Windows | 1.3 |
| Debugger Evasion T1622 STIX ID attack-pattern--e4dc8c01-417f-458d-9ee0-bb0617c1b391 | Discovery, Stealth | Linux, macOS, Windows | 2.0 |
| Defacement T1491 STIX ID attack-pattern--5909f20f-3c39-4795-be06-ef1ea40d350b | Impact | ESXi, IaaS, Linux, macOS, Windows | 1.4 |
| Defacement: External Defacement T1491.002 · sub-technique of T1491 STIX ID attack-pattern--0cfe31a7-81fc-472c-bc45-e2808d1066a3 | Impact | IaaS, Linux, macOS, Windows | 1.2 |
| Defacement: Internal Defacement T1491.001 · sub-technique of T1491 STIX ID attack-pattern--8c41090b-aa47-4331-986b-8c9a51a91103 | Impact | ESXi, Linux, macOS, Windows | 1.2 |
| Delay Execution T1678 STIX ID attack-pattern--a1df809c-7d0e-459f-8fe5-25474bab770b | Stealth | Linux, macOS, Windows | 2.0 |
| Deobfuscate/Decode Files or Information T1140 STIX ID attack-pattern--3ccef7ae-cb5e-48f6-8302-897105fbf55c | Stealth | ESXi, Linux, macOS, Windows | 2.0 |
| Deploy Container T1610 STIX ID attack-pattern--56e0d8b8-3e25-49dd-9050-3aa252f5aa92 | Execution | Containers | 2.0 |
| Develop Capabilities T1587 STIX ID attack-pattern--edadea33-549c-4ed1-9783-8f5a5853cbdf | Resource Development | PRE | 1.1 |
| Develop Capabilities: Code Signing Certificates T1587.002 · sub-technique of T1587 STIX ID attack-pattern--34b3f738-bd64-40e5-a112-29b0542bc8bf | Resource Development | PRE | 1.1 |
| Develop Capabilities: Digital Certificates T1587.003 · sub-technique of T1587 STIX ID attack-pattern--1cec9319-743b-4840-bb65-431547bce82a | Resource Development | PRE | 1.2 |
| Develop Capabilities: Exploits T1587.004 · sub-technique of T1587 STIX ID attack-pattern--bbc3cba7-84ae-410d-b18b-16750731dfa2 | Resource Development | PRE | 1.0 |
| Develop Capabilities: Malware T1587.001 · sub-technique of T1587 STIX ID attack-pattern--212306d8-efa4-44c9-8c2d-ed3d2e224aa0 | Resource Development | PRE | 1.3 |
| Device Driver Discovery T1652 STIX ID attack-pattern--215d9700-5881-48b8-8265-6449dbb7195d | Discovery | Linux, macOS, Windows | 1.0 |
| Direct Volume Access T1006 STIX ID attack-pattern--0c8ab3eb-df48-4b9c-ace7-beacaac81cc5 | Stealth | Network Devices, Windows | 3.0 |
| Disable or Modify System Firewall T1686 STIX ID attack-pattern--eec096b8-c207-43df-b6c1-11523861e452 | Defense Impairment | ESXi, Linux, macOS, Network Devices, Windows | 1.0 |
| Disable or Modify System Firewall: Cloud Firewall T1686.001 · sub-technique of T1686 STIX ID attack-pattern--ee474564-64be-4b83-a958-53f238f49b01 | Defense Impairment | IaaS | 1.0 |
| Disable or Modify System Firewall: Network Device Firewall T1686.002 · sub-technique of T1686 STIX ID attack-pattern--a29aa77c-a88d-4f19-bab9-7751941b2e2d | Defense Impairment | Network Devices | 1.0 |
| Disable or Modify System Firewall: Windows Host Firewall T1686.003 · sub-technique of T1686 STIX ID attack-pattern--291ede6c-1473-454c-b614-5ac5ea63c987 | Defense Impairment | Windows | 1.0 |
| Disable or Modify Tools T1685 STIX ID attack-pattern--bbde9781-60aa-4b8a-a911-895b0c1b3872 | Defense Impairment | Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows | 1.0 |
| Disable or Modify Tools: Clear Linux or Mac System Logs T1685.006 · sub-technique of T1685 STIX ID attack-pattern--5e29d64d-2b14-4f92-875e-4c9c498e213c | Defense Impairment | Linux, macOS | 1.0 |
| Disable or Modify Tools: Clear Windows Event Logs T1685.005 · sub-technique of T1685 STIX ID attack-pattern--75b9a4d2-d4e2-4ca1-9aab-1badd9e05fd0 | Defense Impairment | Windows | 1.0 |
| Disable or Modify Tools: Disable or Modify Cloud Log T1685.002 · sub-technique of T1685 STIX ID attack-pattern--34ff60a3-a3f8-42e4-bed0-af9a2cb563d7 | Defense Impairment | IaaS, Identity Provider, Office Suite, SaaS | 1.0 |
| Disable or Modify Tools: Disable or Modify Linux Audit System Log T1685.004 · sub-technique of T1685 STIX ID attack-pattern--23d69d00-80c4-42ff-9dac-dbd0459dad75 | Defense Impairment | Linux | 1.0 |
| Disable or Modify Tools: Disable or Modify Windows Event Log T1685.001 · sub-technique of T1685 STIX ID attack-pattern--1411e6b8-80a6-4465-9909-54eaa9c67ce0 | Defense Impairment | Windows | 1.0 |
| Disable or Modify Tools: Modify or Spoof Tool UI T1685.003 · sub-technique of T1685 STIX ID attack-pattern--0ff4bd68-aebb-4039-9e00-9f92c705edf4 | Defense Impairment | Linux, macOS, Windows | 1.0 |
| Disk Wipe T1561 STIX ID attack-pattern--1988cc35-ced8-4dad-b2d1-7628488fa967 | Impact | Linux, macOS, Network Devices, Windows | 1.2 |
| Disk Wipe: Disk Content Wipe T1561.001 · sub-technique of T1561 STIX ID attack-pattern--fb640c43-aa6b-431e-a961-a279010424ac | Impact | Linux, macOS, Network Devices, Windows | 1.2 |
| Disk Wipe: Disk Structure Wipe T1561.002 · sub-technique of T1561 STIX ID attack-pattern--0af0ca99-357d-4ba1-805f-674fdfb7bef9 | Impact | Linux, macOS, Network Devices, Windows | 1.2 |
| Domain Trust Discovery T1482 STIX ID attack-pattern--767dbf9e-df3f-45cb-8998-4903ab5f80c0 | Discovery | Windows | 1.2 |
| Domain or Tenant Policy Modification T1484 STIX ID attack-pattern--ebb42bbe-62d7-47d7-a55f-3b08b61d792d | Defense Impairment, Privilege Escalation | Identity Provider, Windows | 4.0 |
| Domain or Tenant Policy Modification: Group Policy Modification T1484.001 · sub-technique of T1484 STIX ID attack-pattern--5d2be8b9-d24c-4e98-83bf-2f5f79477163 | Defense Impairment, Privilege Escalation | Windows | 2.0 |
| Domain or Tenant Policy Modification: Trust Modification T1484.002 · sub-technique of T1484 STIX ID attack-pattern--24769ab5-14bd-4f4e-a752-cfb185da53ee | Defense Impairment, Privilege Escalation | Identity Provider, Windows | 3.0 |
| Downgrade Attack T1689 STIX ID attack-pattern--30904c16-39f9-41c6-b01a-500eb8878442 | Defense Impairment | Linux, macOS, Windows | 1.0 |
| Drive-by Compromise T1189 STIX ID attack-pattern--d742a578-d70e-4d0e-96a6-02a9c30204e6 | Initial Access | Identity Provider, Linux, macOS, Windows | 1.7 |
| Dynamic Resolution T1568 STIX ID attack-pattern--7bd9c723-2f78-4309-82c5-47cad406572b | Command and Control | ESXi, Linux, macOS, Windows | 1.1 |
| Dynamic Resolution: DNS Calculation T1568.003 · sub-technique of T1568 STIX ID attack-pattern--83a766f8-1501-4b3a-a2de-2e2849e8dfc1 | Command and Control | ESXi, Linux, macOS, Windows | 1.1 |
| Dynamic Resolution: Domain Generation Algorithms T1568.002 · sub-technique of T1568 STIX ID attack-pattern--118f61a5-eb3e-4fb6-931f-2096647f4ecd | Command and Control | ESXi, Linux, macOS, Windows | 1.2 |
| Dynamic Resolution: Fast Flux DNS T1568.001 · sub-technique of T1568 STIX ID attack-pattern--29ba5a15-3b7b-4732-b817-65ea8f6468e6 | Command and Control | ESXi, Linux, macOS, Windows | 1.1 |
| ESXi Administration Command T1675 STIX ID attack-pattern--31e5011f-090e-45be-9bb6-17a1c5e8219b | Execution | ESXi | 1.0 |
| Email Bombing T1667 STIX ID attack-pattern--bed81616-3dde-4685-be6e-ba9820f9a7ed | Impact | Linux, macOS, Office Suite, Windows | 1.0 |
| Email Collection T1114 STIX ID attack-pattern--1608f3e1-598a-42f4-a01a-2e252e81728f | Collection | Linux, macOS, Office Suite, Windows | 2.6 |
| Email Collection: Email Forwarding Rule T1114.003 · sub-technique of T1114 STIX ID attack-pattern--7d77a07d-02fe-4e88-8bd9-e9c008c01bf0 | Collection | Linux, macOS, Office Suite, Windows | 1.4 |
| Email Collection: Local Email Collection T1114.001 · sub-technique of T1114 STIX ID attack-pattern--1e9eb839-294b-48cc-b0d3-c45555a2a004 | Collection | Windows | 1.1 |
| Email Collection: Remote Email Collection T1114.002 · sub-technique of T1114 STIX ID attack-pattern--b4694861-542c-48ea-9eb1-10d356e7140a | Collection | Office Suite, Windows | 1.3 |
| Encrypted Channel T1573 STIX ID attack-pattern--b8902400-e6c5-4ba2-95aa-2d35b442b118 | Command and Control | ESXi, Linux, macOS, Network Devices, Windows | 1.2 |
| Encrypted Channel: Asymmetric Cryptography T1573.002 · sub-technique of T1573 STIX ID attack-pattern--bf176076-b789-408e-8cba-7275e81c0ada | Command and Control | ESXi, Linux, macOS, Network Devices, Windows | 1.2 |
| Encrypted Channel: Symmetric Cryptography T1573.001 · sub-technique of T1573 STIX ID attack-pattern--24bfaeba-cb0d-4525-b3dc-507c77ecec41 | Command and Control | ESXi, Linux, macOS, Network Devices, Windows | 1.2 |
| Endpoint Denial of Service T1499 STIX ID attack-pattern--c675646d-e204-4aa8-978d-e3d6d65885c4 | Impact | Containers, IaaS, Linux, macOS, Windows | 1.2 |
| Endpoint Denial of Service: Application Exhaustion Flood T1499.003 · sub-technique of T1499 STIX ID attack-pattern--18cffc21-3260-437e-80e4-4ab8bf2ba5e9 | Impact | IaaS, Linux, macOS, Windows | 1.3 |
| Endpoint Denial of Service: Application or System Exploitation T1499.004 · sub-technique of T1499 STIX ID attack-pattern--2bee5ffb-7a7a-4119-b1f2-158151b19ac0 | Impact | IaaS, Linux, macOS, Windows | 1.3 |
| Endpoint Denial of Service: OS Exhaustion Flood T1499.001 · sub-technique of T1499 STIX ID attack-pattern--0df05477-c572-4ed6-88a9-47c581f548f7 | Impact | Linux, macOS, Windows | 1.2 |
| Endpoint Denial of Service: Service Exhaustion Flood T1499.002 · sub-technique of T1499 STIX ID attack-pattern--38eb0c22-6caf-46ce-8869-5964bd735858 | Impact | IaaS, Linux, macOS, Windows | 1.4 |
| Escape to Host T1611 STIX ID attack-pattern--4a5b7ade-8bb5-4853-84ed-23f262002665 | Privilege Escalation | Containers, ESXi, Linux, Windows | 1.6 |
| Establish Accounts T1585 STIX ID attack-pattern--cdfc5f0a-9bb9-4352-b896-553cfa2d8fd8 | Resource Development | PRE | 1.3 |
| Establish Accounts: Cloud Accounts T1585.003 · sub-technique of T1585 STIX ID attack-pattern--926d8cfd-1d0d-4da2-ab49-3ca10ec3f3b5 | Resource Development | PRE | 1.1 |
| Establish Accounts: Email Accounts T1585.002 · sub-technique of T1585 STIX ID attack-pattern--65013dd2-bc61-43e3-afb5-a14c4fa7437a | Resource Development | PRE | 1.1 |
| Establish Accounts: Social Media Accounts T1585.001 · sub-technique of T1585 STIX ID attack-pattern--b1ccd744-3f78-4a0e-9bb2-2002057f7928 | Resource Development | PRE | 1.1 |
| Event Triggered Execution T1546 STIX ID attack-pattern--b6301b64-ef57-4cce-bb0b-77026f14a8db | Persistence, Privilege Escalation | IaaS, Linux, macOS, Office Suite, SaaS, Windows | 1.4 |
| Event Triggered Execution: Accessibility Features T1546.008 · sub-technique of T1546 STIX ID attack-pattern--70e52b04-2a0c-4cea-9d18-7149f1df9dc5 | Persistence, Privilege Escalation | Windows | 1.2 |
| Event Triggered Execution: AppCert DLLs T1546.009 · sub-technique of T1546 STIX ID attack-pattern--7d57b371-10c2-45e5-b3cc-83a8fb380e4c | Persistence, Privilege Escalation | Windows | 1.1 |
| Event Triggered Execution: AppInit DLLs T1546.010 · sub-technique of T1546 STIX ID attack-pattern--cc89ecbd-3d33-4a41-bcca-001e702d18fd | Persistence, Privilege Escalation | Windows | 1.2 |
| Event Triggered Execution: Application Shimming T1546.011 · sub-technique of T1546 STIX ID attack-pattern--42fe883a-21ea-4cfb-b94a-78b6476dcc83 | Persistence, Privilege Escalation | Windows | 1.1 |
| Event Triggered Execution: Change Default File Association T1546.001 · sub-technique of T1546 STIX ID attack-pattern--98034fef-d9fb-4667-8dc4-2eab6231724c | Persistence, Privilege Escalation | Windows | 1.1 |
| Event Triggered Execution: Component Object Model Hijacking T1546.015 · sub-technique of T1546 STIX ID attack-pattern--bc0f5e80-91c0-4e04-9fbb-e4e332c85dae | Persistence, Privilege Escalation | Windows | 1.3 |
| Event Triggered Execution: Emond T1546.014 · sub-technique of T1546 STIX ID attack-pattern--9c45eaa3-8604-4780-8988-b5074dbb9ecd | Persistence, Privilege Escalation | macOS | 1.1 |
| Event Triggered Execution: Image File Execution Options Injection T1546.012 · sub-technique of T1546 STIX ID attack-pattern--6d4a7fb3-5a24-42be-ae61-6728a2b581f6 | Persistence, Privilege Escalation | Windows | 1.2 |
| Event Triggered Execution: Installer Packages T1546.016 · sub-technique of T1546 STIX ID attack-pattern--da051493-ae9c-4b1b-9760-c009c46c9b56 | Persistence, Privilege Escalation | Linux, macOS, Windows | 1.2 |
| Event Triggered Execution: LC_LOAD_DYLIB Addition T1546.006 · sub-technique of T1546 STIX ID attack-pattern--10ff21b9-5a01-4268-a1b5-3b55015f1847 | Persistence, Privilege Escalation | macOS | 1.1 |
| Event Triggered Execution: Netsh Helper DLL T1546.007 · sub-technique of T1546 STIX ID attack-pattern--f63fe421-b1d1-45c0-b8a7-02cd16ff2bed | Persistence, Privilege Escalation | Windows | 1.1 |
| Event Triggered Execution: PowerShell Profile T1546.013 · sub-technique of T1546 STIX ID attack-pattern--0f2c410d-d740-4ed9-abb1-b8f4a7faf6c3 | Persistence, Privilege Escalation | Windows | 1.2 |
| Event Triggered Execution: Python Startup Hooks T1546.018 · sub-technique of T1546 STIX ID attack-pattern--c5087385-9b7c-4488-9923-d9e370bf08df | Persistence, Privilege Escalation | Linux, macOS, Windows | 1.0 |
| Event Triggered Execution: Screensaver T1546.002 · sub-technique of T1546 STIX ID attack-pattern--ce4b7013-640e-48a9-b501-d0025a95f4bf | Persistence, Privilege Escalation | Windows | 1.3 |
| Event Triggered Execution: Trap T1546.005 · sub-technique of T1546 STIX ID attack-pattern--63220765-d418-44de-8fae-694b3912317d | Persistence, Privilege Escalation | Linux, macOS | 1.1 |
| Event Triggered Execution: Udev Rules T1546.017 · sub-technique of T1546 STIX ID attack-pattern--f4c3f644-ab33-433d-8648-75cc03a95792 | Persistence, Privilege Escalation | Linux | 1.0 |
| Event Triggered Execution: Unix Shell Configuration Modification T1546.004 · sub-technique of T1546 STIX ID attack-pattern--b63a34e8-0a61-4c97-a23b-bf8a2ed812e2 | Persistence, Privilege Escalation | Linux, macOS | 2.2 |
| Event Triggered Execution: Windows Management Instrumentation Event Subscription T1546.003 · sub-technique of T1546 STIX ID attack-pattern--910906dd-8c0a-475a-9cc1-5e029e2fad58 | Persistence, Privilege Escalation | Windows | 1.5 |
| Exclusive Control T1668 STIX ID attack-pattern--dff263cc-328e-42b4-afbc-1fee8b6a8913 | Persistence | Linux, macOS, Windows | 1.0 |
| Execution Guardrails T1480 STIX ID attack-pattern--853c4192-4311-43e1-bfbb-b11b14911852 | Stealth | ESXi, Linux, macOS, Windows | 2.0 |
| Execution Guardrails: Environmental Keying T1480.001 · sub-technique of T1480 STIX ID attack-pattern--f244b8dd-af6c-4391-a497-fc03627ce995 | Stealth | Linux, macOS, Windows | 2.0 |
| Execution Guardrails: Mutual Exclusion T1480.002 · sub-technique of T1480 STIX ID attack-pattern--49fca0d2-685d-41eb-8bd4-05451cc3a742 | Stealth | Linux, macOS, Windows | 2.0 |
| Exfiltration Over Alternative Protocol T1048 STIX ID attack-pattern--a19e86f8-1c0a-4fea-8407-23b73d615776 | Exfiltration | ESXi, IaaS, Linux, macOS, Network Devices, Office Suite, SaaS, Windows | 1.6 |
| Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol T1048.002 · sub-technique of T1048 STIX ID attack-pattern--8e350c1d-ac79-4b5c-bd4e-7476d7e84ec5 | Exfiltration | ESXi, Linux, macOS, Windows | 1.2 |
| Exfiltration Over Alternative Protocol: Exfiltration Over Symmetric Encrypted Non-C2 Protocol T1048.001 · sub-technique of T1048 STIX ID attack-pattern--79a4052e-1a89-4b09-aea6-51f1d11fe19c | Exfiltration | ESXi, Linux, macOS, Windows | 1.1 |
| Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol T1048.003 · sub-technique of T1048 STIX ID attack-pattern--fb8d023d-45be-47e9-bc51-f56bcae6435b | Exfiltration | ESXi, Linux, macOS, Network Devices, Windows | 2.2 |
| Exfiltration Over C2 Channel T1041 STIX ID attack-pattern--92d7da27-2d91-488e-a00c-059dc162766d | Exfiltration | ESXi, Linux, macOS, Windows | 2.3 |
| Exfiltration Over Other Network Medium T1011 STIX ID attack-pattern--51ea26b1-ff1e-4faa-b1a0-1114cd298c87 | Exfiltration | Linux, macOS, Windows | 1.2 |
| Exfiltration Over Other Network Medium: Exfiltration Over Bluetooth T1011.001 · sub-technique of T1011 STIX ID attack-pattern--613d08bc-e8f4-4791-80b0-c8b974340dfd | Exfiltration | Linux, macOS, Windows | 1.2 |
| Exfiltration Over Physical Medium T1052 STIX ID attack-pattern--e6415f09-df0e-48de-9aba-928c902b7549 | Exfiltration | Linux, macOS, Windows | 1.3 |
| Exfiltration Over Physical Medium: Exfiltration over USB T1052.001 · sub-technique of T1052 STIX ID attack-pattern--a3e1e6c5-9c74-4fc0-a16c-a9d228c17829 | Exfiltration | Linux, macOS, Windows | 1.2 |
| Exfiltration Over Web Service T1567 STIX ID attack-pattern--40597f16-0963-4249-bf4c-ac93b7fb9807 | Exfiltration | ESXi, Linux, macOS, Office Suite, SaaS, Windows | 1.5 |
| Exfiltration Over Web Service: Exfiltration Over Webhook T1567.004 · sub-technique of T1567 STIX ID attack-pattern--43f2776f-b4bd-4118-94b8-fee47e69676d | Exfiltration | ESXi, Linux, macOS, Office Suite, SaaS, Windows | 1.2 |
| Exfiltration Over Web Service: Exfiltration to Cloud Storage T1567.002 · sub-technique of T1567 STIX ID attack-pattern--bf1b6176-597c-4600-bfcd-ac989670f96b | Exfiltration | ESXi, Linux, macOS, Windows | 1.3 |
| Exfiltration Over Web Service: Exfiltration to Code Repository T1567.001 · sub-technique of T1567 STIX ID attack-pattern--86a96bf6-cf8b-411c-aaeb-8959944d64f7 | Exfiltration | ESXi, Linux, macOS, Windows | 1.2 |
| Exfiltration Over Web Service: Exfiltration to Text Storage Sites T1567.003 · sub-technique of T1567 STIX ID attack-pattern--ba04e672-da86-4e69-aa15-0eca5db25f43 | Exfiltration | ESXi, Linux, macOS, Windows | 1.1 |
| Exploit Public-Facing Application T1190 STIX ID attack-pattern--3f886f2a-874f-4333-b794-aa6075009b1c | Initial Access | Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows | 2.8 |
| Exploitation for Client Execution T1203 STIX ID attack-pattern--be2dcee9-a7a7-4e38-afd6-21b31ecc3d63 | Execution | Linux, macOS, Windows | 1.5 |
| Exploitation for Credential Access T1212 STIX ID attack-pattern--9c306d8d-cde7-4b4c-b6e8-d0bb16caca36 | Credential Access | Identity Provider, Linux, macOS, Windows | 1.6 |
| Exploitation for Defense Impairment T1687 STIX ID attack-pattern--01c9b54f-c04e-41ba-b0c3-cfe784b3a463 | Defense Impairment | IaaS, Linux, macOS, SaaS, Windows | 1.0 |
| Exploitation for Privilege Escalation T1068 STIX ID attack-pattern--b21c3b2d-02e6-45b1-980b-e69051040839 | Privilege Escalation | Containers, Linux, macOS, Windows | 1.6 |
| Exploitation for Stealth T1211 STIX ID attack-pattern--fe926152-f431-4baf-956c-4ad3cb0bf23b | Stealth | IaaS, Linux, macOS, SaaS, Windows | 2.0 |
| Exploitation of Remote Services T1210 STIX ID attack-pattern--9db0cf3a-a3c9-4012-8268-123b9db6fd82 | Lateral Movement | ESXi, Linux, macOS, Windows | 1.2 |
| External Remote Services T1133 STIX ID attack-pattern--10d51417-ee35-4589-b1ff-b6df1c334e8d | Initial Access, Persistence | Containers, Linux, macOS, Windows | 2.5 |
| Fallback Channels T1008 STIX ID attack-pattern--f24faf46-3b26-4dbb-98f2-63460498e433 | Command and Control | ESXi, Linux, macOS, Windows | 1.1 |
| File and Directory Discovery T1083 STIX ID attack-pattern--7bc57495-ea59-4380-be31-a64af124ef18 | Discovery | ESXi, Linux, macOS, Network Devices, Windows | 1.7 |
| File and Directory Permissions Modification T1222 STIX ID attack-pattern--65917ae0-b854-4139-83fe-bf2441cf0196 | Defense Impairment | ESXi, Linux, macOS, Windows | 3.0 |
| File and Directory Permissions Modification: Linux and Mac Permissions T1222.002 · sub-technique of T1222 STIX ID attack-pattern--09b130a2-a77e-4af0-a361-f46f9aad1345 | Defense Impairment | Linux, macOS | 2.0 |
| File and Directory Permissions Modification: Windows Permissions T1222.001 · sub-technique of T1222 STIX ID attack-pattern--34e793de-0274-4982-9c1a-246ed1c19dee | Defense Impairment | Windows | 2.0 |
| Financial Theft T1657 STIX ID attack-pattern--851e071f-208d-4c79-adc6-5974c85c78f3 | Impact | Linux, macOS, Office Suite, SaaS, Windows | 1.2 |
| Firmware Corruption T1495 STIX ID attack-pattern--f5bb433e-bdf6-4781-84bc-35e97e43be89 | Impact | Linux, macOS, Network Devices, Windows | 1.3 |
| Forced Authentication T1187 STIX ID attack-pattern--b77cf5f3-6060-475d-bd60-40ccbf28fdc2 | Credential Access | Windows | 1.4 |
| Forge Web Credentials T1606 STIX ID attack-pattern--94cb00a4-b295-4d06-aa2b-5653b9c1be9c | Credential Access | IaaS, Identity Provider, Linux, macOS, Office Suite, SaaS, Windows | 1.5 |
| Forge Web Credentials: SAML Tokens T1606.002 · sub-technique of T1606 STIX ID attack-pattern--1f9c2bae-b441-4f66-a8af-b65946ee72f2 | Credential Access | IaaS, Identity Provider, Office Suite, SaaS, Windows | 1.4 |
| Forge Web Credentials: Web Cookies T1606.001 · sub-technique of T1606 STIX ID attack-pattern--861b8fd2-57f3-4ee1-ab5d-c19c3b8c7a4a | Credential Access | IaaS, Linux, macOS, SaaS, Windows | 1.1 |
| Gather Victim Host Information T1592 STIX ID attack-pattern--09312b1a-c3c6-4b45-9844-3ccc78e5d82f | Reconnaissance | PRE | 1.2 |
| Gather Victim Host Information: Client Configurations T1592.004 · sub-technique of T1592 STIX ID attack-pattern--774ad5bb-2366-4c13-a8a9-65e50b292e7c | Reconnaissance | PRE | 1.1 |
| Gather Victim Host Information: Firmware T1592.003 · sub-technique of T1592 STIX ID attack-pattern--b85f6ce5-81e8-4f36-aff2-3df9d02a9c9d | Reconnaissance | PRE | 1.0 |
| Gather Victim Host Information: Hardware T1592.001 · sub-technique of T1592 STIX ID attack-pattern--24286c33-d4a4-4419-85c2-1d094a896c26 | Reconnaissance | PRE | 1.1 |
| Gather Victim Host Information: Software T1592.002 · sub-technique of T1592 STIX ID attack-pattern--baf60e1a-afe5-4d31-830f-1b1ba2351884 | Reconnaissance | PRE | 1.2 |
| Gather Victim Identity Information T1589 STIX ID attack-pattern--5282dd9a-d26d-4e16-88b7-7c0f4553daf4 | Reconnaissance | PRE | 1.3 |
| Gather Victim Identity Information: Credentials T1589.001 · sub-technique of T1589 STIX ID attack-pattern--bc76d0a4-db11-4551-9ac4-01a469cfb161 | Reconnaissance | PRE | 1.2 |
| Gather Victim Identity Information: Email Addresses T1589.002 · sub-technique of T1589 STIX ID attack-pattern--69f897fd-12a9-4c89-ad6a-46d2f3c38262 | Reconnaissance | PRE | 1.3 |
| Gather Victim Identity Information: Employee Names T1589.003 · sub-technique of T1589 STIX ID attack-pattern--76551c52-b111-4884-bc47-ff3e728f0156 | Reconnaissance | PRE | 1.0 |
| Gather Victim Network Information T1590 STIX ID attack-pattern--9d48cab2-7929-4812-ad22-f536665f0109 | Reconnaissance | PRE | 1.0 |
| Gather Victim Network Information: DNS T1590.002 · sub-technique of T1590 STIX ID attack-pattern--0ff59227-8aa8-4c09-bf1f-925605bd07ea | Reconnaissance | PRE | 1.2 |
| Gather Victim Network Information: Domain Properties T1590.001 · sub-technique of T1590 STIX ID attack-pattern--e3b168bd-fcd7-439e-9382-2e6c2f63514d | Reconnaissance | PRE | 1.1 |
| Gather Victim Network Information: IP Addresses T1590.005 · sub-technique of T1590 STIX ID attack-pattern--0dda99f0-4701-48ca-9774-8504922e92d3 | Reconnaissance | PRE | 1.0 |
| Gather Victim Network Information: Network Security Appliances T1590.006 · sub-technique of T1590 STIX ID attack-pattern--6c2957f9-502a-478c-b1dd-d626c0659413 | Reconnaissance | PRE | 1.0 |
| Gather Victim Network Information: Network Topology T1590.004 · sub-technique of T1590 STIX ID attack-pattern--34ab90a3-05f6-4259-8f21-621081fdaba5 | Reconnaissance | PRE | 1.0 |
| Gather Victim Network Information: Network Trust Dependencies T1590.003 · sub-technique of T1590 STIX ID attack-pattern--36aa137f-5166-41f8-b2f0-a4cfa1b4133e | Reconnaissance | PRE | 1.0 |
| Gather Victim Org Information T1591 STIX ID attack-pattern--937e4772-8441-4e4a-8bf0-8d447d667e23 | Reconnaissance | PRE | 1.1 |
| Gather Victim Org Information: Business Relationships T1591.002 · sub-technique of T1591 STIX ID attack-pattern--6ee2dc99-91ad-4534-a7d8-a649358c331f | Reconnaissance | PRE | 1.0 |
| Gather Victim Org Information: Determine Physical Locations T1591.001 · sub-technique of T1591 STIX ID attack-pattern--ed730f20-0e44-48b9-85f8-0e2adeb76867 | Reconnaissance | PRE | 1.1 |
| Gather Victim Org Information: Identify Business Tempo T1591.003 · sub-technique of T1591 STIX ID attack-pattern--2339cf19-8f1e-48f7-8a91-0262ba547b6f | Reconnaissance | PRE | 1.0 |
| Gather Victim Org Information: Identify Roles T1591.004 · sub-technique of T1591 STIX ID attack-pattern--cc723aff-ec88-40e3-a224-5af9fd983cc4 | Reconnaissance | PRE | 1.0 |
| Generate Content T1683 STIX ID attack-pattern--b512fb8a-18dd-4bfc-bbad-acbaaeb7dde3 | Resource Development | PRE | 1.0 |
| Generate Content: Audio-Visual Content T1683.002 · sub-technique of T1683 STIX ID attack-pattern--8f452cb4-cbf4-4522-8b11-448787be95c4 | Resource Development | PRE | 1.0 |
| Generate Content: Written Content T1683.001 · sub-technique of T1683 STIX ID attack-pattern--6a6f9892-c46a-46db-b331-c09a99200fcf | Resource Development | PRE | 1.0 |
| Group Policy Discovery T1615 STIX ID attack-pattern--1b20efbf-8063-4fc3-a07d-b575318a301b | Discovery | Windows | 1.1 |
| Hardware Additions T1200 STIX ID attack-pattern--d40239b3-05ff-46d8-9bdd-b46d13463ef9 | Initial Access | Linux, macOS, Windows | 1.7 |
| Hide Artifacts T1564 STIX ID attack-pattern--22905430-4901-4c2a-84f6-98243cb173f8 | Stealth | ESXi, Linux, macOS, Office Suite, Windows | 2.0 |
| Hide Artifacts: Bind Mounts T1564.013 · sub-technique of T1564 STIX ID attack-pattern--5bd41255-a224-4425-a2e2-e9d293eafe1c | Stealth | Linux | 2.0 |
| Hide Artifacts: Email Hiding Rules T1564.008 · sub-technique of T1564 STIX ID attack-pattern--0cf55441-b176-4332-89e7-2c4c7799d0ff | Stealth | Linux, macOS, Office Suite, Windows | 2.0 |
| Hide Artifacts: Extended Attributes T1564.014 · sub-technique of T1564 STIX ID attack-pattern--762e6f29-a62f-4d96-91ed-d0073181431f | Stealth | Linux, macOS | 2.0 |
| Hide Artifacts: File/Path Exclusions T1564.012 · sub-technique of T1564 STIX ID attack-pattern--09b008a9-b4eb-462a-a751-a0eb58050cd9 | Stealth | Linux, macOS, Windows | 2.0 |
| Hide Artifacts: Hidden File System T1564.005 · sub-technique of T1564 STIX ID attack-pattern--dfebc3b7-d19d-450b-81c7-6dafe4184c04 | Stealth | Linux, macOS, Windows | 2.0 |
| Hide Artifacts: Hidden Files and Directories T1564.001 · sub-technique of T1564 STIX ID attack-pattern--ec8fc7e2-b356-455c-8db5-2e37be158e7d | Stealth | Linux, macOS, Windows | 2.0 |
| Hide Artifacts: Hidden Users T1564.002 · sub-technique of T1564 STIX ID attack-pattern--8c4aef43-48d5-49aa-b2af-c0cd58d30c3d | Stealth | Linux, macOS, Windows | 2.0 |
| Hide Artifacts: Hidden Window T1564.003 · sub-technique of T1564 STIX ID attack-pattern--cbb66055-0325-4111-aca0-40547b6ad5b0 | Stealth | Linux, macOS, Windows | 2.0 |
| Hide Artifacts: Ignore Process Interrupts T1564.011 · sub-technique of T1564 STIX ID attack-pattern--4a2975db-414e-4c0c-bd92-775987514b4b | Stealth | Linux, macOS, Windows | 2.0 |
| Hide Artifacts: NTFS File Attributes T1564.004 · sub-technique of T1564 STIX ID attack-pattern--f2857333-11d4-45bf-b064-2c28d8525be5 | Stealth | Windows | 2.0 |
| Hide Artifacts: Process Argument Spoofing T1564.010 · sub-technique of T1564 STIX ID attack-pattern--ffe59ad3-ad9b-4b9f-b74f-5beb3c309dc1 | Stealth | Windows | 2.0 |
| Hide Artifacts: Resource Forking T1564.009 · sub-technique of T1564 STIX ID attack-pattern--b22e5153-ac28-4cc6-865c-2054e36285cb | Stealth | macOS | 2.0 |
| Hide Artifacts: Run Virtual Instance T1564.006 · sub-technique of T1564 STIX ID attack-pattern--b5327dd1-6bf9-4785-a199-25bcbd1f4a9d | Stealth | ESXi, Linux, macOS, Windows | 2.0 |
| Hide Artifacts: VBA Stomping T1564.007 · sub-technique of T1564 STIX ID attack-pattern--c898c4b5-bf36-4e6e-a4ad-5b8c4c13e35b | Stealth | Linux, macOS, Windows | 2.0 |
| Hide Infrastructure T1665 STIX ID attack-pattern--eb897572-8979-4242-a089-56f294f4c91d | Command and Control | ESXi, Linux, macOS, Network Devices, Windows | 1.2 |
| Hijack Execution Flow T1574 STIX ID attack-pattern--aedfca76-3b30-4866-b2aa-0f1d7fd1e4b6 | Execution, Stealth | Linux, macOS, Windows | 2.0 |
| Hijack Execution Flow: AppDomainManager T1574.014 · sub-technique of T1574 STIX ID attack-pattern--356662f7-e315-4759-86c9-6214e2a50ff8 | Execution, Stealth | Windows | 2.0 |
| Hijack Execution Flow: COR_PROFILER T1574.012 · sub-technique of T1574 STIX ID attack-pattern--ffeb0780-356e-4261-b036-cfb6bd234335 | Execution, Stealth | Windows | 2.0 |
| Hijack Execution Flow: DLL T1574.001 · sub-technique of T1574 STIX ID attack-pattern--2fee9321-3e71-4cf4-af24-d4d40d355b34 | Execution, Stealth | Windows | 3.0 |
| Hijack Execution Flow: Dylib Hijacking T1574.004 · sub-technique of T1574 STIX ID attack-pattern--fc742192-19e3-466c-9eb5-964a97b29490 | Execution, Stealth | macOS | 3.0 |
| Hijack Execution Flow: Dynamic Linker Hijacking T1574.006 · sub-technique of T1574 STIX ID attack-pattern--633a100c-b2c9-41bf-9be5-905c1b16c825 | Execution, Stealth | Linux, macOS | 3.0 |
| Hijack Execution Flow: Executable Installer File Permissions Weakness T1574.005 · sub-technique of T1574 STIX ID attack-pattern--70d81154-b187-45f9-8ec5-295d01255979 | Execution, Stealth | Windows | 2.0 |
| Hijack Execution Flow: KernelCallbackTable T1574.013 · sub-technique of T1574 STIX ID attack-pattern--a4657bc9-d22f-47d2-a7b7-dd6ec33f3dde | Execution, Stealth | Windows | 2.0 |
| Hijack Execution Flow: Path Interception by PATH Environment Variable T1574.007 · sub-technique of T1574 STIX ID attack-pattern--0c2d00da-7742-49e7-9928-4514e5075d32 | Execution, Stealth | Linux, macOS, Windows | 2.0 |
| Hijack Execution Flow: Path Interception by Search Order Hijacking T1574.008 · sub-technique of T1574 STIX ID attack-pattern--58af3705-8740-4c68-9329-ec015a7013c2 | Execution, Stealth | Windows | 2.0 |
| Hijack Execution Flow: Path Interception by Unquoted Path T1574.009 · sub-technique of T1574 STIX ID attack-pattern--bf96a5a3-3bce-43b7-8597-88545984c07b | Execution, Stealth | Windows | 2.0 |
| Hijack Execution Flow: Services File Permissions Weakness T1574.010 · sub-technique of T1574 STIX ID attack-pattern--9e8b28c9-35fe-48ac-a14d-e6cc032dcbcd | Execution, Stealth | Windows | 2.0 |
| Hijack Execution Flow: Services Registry Permissions Weakness T1574.011 · sub-technique of T1574 STIX ID attack-pattern--17cc750b-e95b-4d7d-9dde-49e0de24148c | Execution, Stealth | Windows | 2.0 |
| Implant Internal Image T1525 STIX ID attack-pattern--4fd8a28b-4b3a-4cd6-a8cf-85ba5f824a7f | Persistence | Containers, IaaS | 2.2 |
| Indicator Removal T1070 STIX ID attack-pattern--799ace7f-e227-4411-baa0-8868704f2a69 | Stealth | Containers, ESXi, Linux, macOS, Network Devices, Office Suite, Windows | 3.0 |
| Indicator Removal: Clear Command History T1070.003 · sub-technique of T1070 STIX ID attack-pattern--3aef9463-9a7a-43ba-8957-a867e07c1e6a | Stealth | ESXi, Linux, macOS, Network Devices, Windows | 2.0 |
| Indicator Removal: Clear Mailbox Data T1070.008 · sub-technique of T1070 STIX ID attack-pattern--438c967d-3996-4870-bfc2-3954752a1927 | Stealth | Linux, macOS, Office Suite, Windows | 2.0 |
| Indicator Removal: Clear Network Connection History and Configurations T1070.007 · sub-technique of T1070 STIX ID attack-pattern--3975dbb5-0e1e-4f5b-bae1-cf2ab84b46dc | Stealth | Linux, macOS, Network Devices, Windows | 2.0 |
| Indicator Removal: Clear Persistence T1070.009 · sub-technique of T1070 STIX ID attack-pattern--d2c4e5ea-dbdf-4113-805a-b1e2a337fb33 | Stealth | ESXi, Linux, macOS, Windows | 2.0 |
| Indicator Removal: File Deletion T1070.004 · sub-technique of T1070 STIX ID attack-pattern--d63a3fb8-9452-4e9d-a60a-54be68d5998c | Stealth | ESXi, Linux, macOS, Windows | 2.0 |
| Indicator Removal: Network Share Connection Removal T1070.005 · sub-technique of T1070 STIX ID attack-pattern--a750a9f6-0bde-4bb3-9aae-1e2786e9780c | Stealth | Windows | 2.0 |
| Indicator Removal: Relocate Malware T1070.010 · sub-technique of T1070 STIX ID attack-pattern--cc36eeae-2209-4e63-89d3-c97e19edf280 | Stealth | Linux, macOS, Network Devices, Windows | 2.0 |
| Indicator Removal: Timestomp T1070.006 · sub-technique of T1070 STIX ID attack-pattern--47f2d673-ca62-47e9-929b-1b0be9657611 | Stealth | ESXi, Linux, macOS, Windows | 2.0 |
| Indirect Command Execution T1202 STIX ID attack-pattern--3b0e52ce-517a-4614-a523-1bd5deef6c5e | Stealth | Windows | 2.0 |
| Ingress Tool Transfer T1105 STIX ID attack-pattern--e6919abc-99f9-4c6c-95a5-14761e7b2add | Command and Control | ESXi, Linux, macOS, Network Devices, Windows | 2.6 |
| Inhibit System Recovery T1490 STIX ID attack-pattern--f5d8eed6-48a9-4cdf-a3d7-d1ffa99c3d2a | Impact | Containers, ESXi, IaaS, Linux, macOS, Network Devices, Windows | 1.6 |
| Input Capture T1056 STIX ID attack-pattern--bb5a00de-e086-4859-a231-fa793f6797e2 | Collection, Credential Access | Linux, macOS, Network Devices, Windows | 1.4 |
| Input Capture: Credential API Hooking T1056.004 · sub-technique of T1056 STIX ID attack-pattern--f5946b5e-9408-485f-a7f7-b5efc88909b6 | Collection, Credential Access | Linux, macOS, Windows | 1.2 |
| Input Capture: GUI Input Capture T1056.002 · sub-technique of T1056 STIX ID attack-pattern--a2029942-0a85-4947-b23c-ca434698171d | Collection, Credential Access | Linux, macOS, Windows | 1.3 |
| Input Capture: Keylogging T1056.001 · sub-technique of T1056 STIX ID attack-pattern--09a60ea3-a8d1-4ae5-976e-5783248b72a4 | Collection, Credential Access | Linux, macOS, Network Devices, Windows | 1.3 |
| Input Capture: Web Portal Capture T1056.003 · sub-technique of T1056 STIX ID attack-pattern--69e5226d-05dc-4f15-95d7-44f5ed78d06e | Collection, Credential Access | Linux, macOS, Windows | 1.1 |
| Input Injection T1674 STIX ID attack-pattern--63e3d25c-d57d-407d-8e6a-2cecd71f90be | Execution | Linux, macOS, Windows | 1.0 |
| Inter-Process Communication T1559 STIX ID attack-pattern--acd0ba37-7ba9-4cc5-ac61-796586cd856d | Execution | Linux, macOS, Windows | 1.4 |
| Inter-Process Communication: Component Object Model T1559.001 · sub-technique of T1559 STIX ID attack-pattern--2f6b4ed7-fef1-44ba-bcb8-1b4beb610b64 | Execution | Windows | 1.2 |
| Inter-Process Communication: Dynamic Data Exchange T1559.002 · sub-technique of T1559 STIX ID attack-pattern--232a7e42-cd6e-4902-8fe9-2960f529dd4d | Execution | Windows | 1.4 |
| Inter-Process Communication: XPC Services T1559.003 · sub-technique of T1559 STIX ID attack-pattern--8252f135-ed26-4ce1-ae61-f26e94429a19 | Execution | macOS | 1.1 |
| Internal Spearphishing T1534 STIX ID attack-pattern--9e7452df-5144-4b6e-b04a-b66dd4016747 | Lateral Movement | Linux, macOS, Office Suite, SaaS, Windows | 1.4 |
| Lateral Tool Transfer T1570 STIX ID attack-pattern--bf90d72c-c00b-45e3-b3aa-68560560d4c5 | Lateral Movement | ESXi, Linux, macOS, Windows | 1.4 |
| Local Storage Discovery T1680 STIX ID attack-pattern--f2514ae4-4e9b-4f26-a5ba-c4ae85fe93c3 | Discovery | ESXi, IaaS, Linux, macOS, Windows | 1.0 |
| Log Enumeration T1654 STIX ID attack-pattern--866d0d6d-02c6-42bd-aa2f-02907fdc0969 | Discovery | ESXi, IaaS, Linux, macOS, Windows | 1.2 |
| Masquerading T1036 STIX ID attack-pattern--42e8de7b-37b2-4258-905a-6897815e58e0 | Stealth | Containers, ESXi, Linux, macOS, Windows | 2.0 |
| Masquerading: Break Process Trees T1036.009 · sub-technique of T1036 STIX ID attack-pattern--34a80bc4-80f2-46e6-94ff-f3265a4b657c | Stealth | Linux, macOS | 2.0 |
| Masquerading: Browser Fingerprint T1036.012 · sub-technique of T1036 STIX ID attack-pattern--afac5dbc-4383-4fb6-9ba6-45b25d49e530 | Stealth | Linux, macOS, Windows | 2.0 |
| Masquerading: Double File Extension T1036.007 · sub-technique of T1036 STIX ID attack-pattern--11f29a39-0942-4d62-92b6-fe236cf3066e | Stealth | Windows | 2.0 |
| Masquerading: Invalid Code Signature T1036.001 · sub-technique of T1036 STIX ID attack-pattern--b4b7458f-81f2-4d38-84be-1c5ba0167a52 | Stealth | macOS, Windows | 2.0 |
| Masquerading: Masquerade Account Name T1036.010 · sub-technique of T1036 STIX ID attack-pattern--d349c66e-18e1-4d8b-a2d7-65af7cbd2ba0 | Stealth | Containers, IaaS, Identity Provider, Linux, macOS, Office Suite, SaaS, Windows | 2.0 |
| Masquerading: Masquerade File Type T1036.008 · sub-technique of T1036 STIX ID attack-pattern--208884f1-7b83-4473-ac22-4e1cf6c41471 | Stealth | Linux, macOS, Windows | 2.0 |
| Masquerading: Masquerade Task or Service T1036.004 · sub-technique of T1036 STIX ID attack-pattern--7bdca9d5-d500-4d7d-8c52-5fd47baf4c0c | Stealth | Linux, macOS, Windows | 2.0 |
| Masquerading: Match Legitimate Resource Name or Location T1036.005 · sub-technique of T1036 STIX ID attack-pattern--1c4e5d32-1fe9-4116-9d9d-59e3925bd6a2 | Stealth | Containers, ESXi, Linux, macOS, Windows | 3.0 |
| Masquerading: Overwrite Process Arguments T1036.011 · sub-technique of T1036 STIX ID attack-pattern--514dc7b3-0b80-4382-80a9-2e2d294f5019 | Stealth | Linux | 2.0 |
| Masquerading: Rename Legitimate Utilities T1036.003 · sub-technique of T1036 STIX ID attack-pattern--bd5b58a4-a52d-4a29-bc0d-3f1d3968eb6b | Stealth | Linux, macOS, Windows | 3.0 |
| Masquerading: Right-to-Left Override T1036.002 · sub-technique of T1036 STIX ID attack-pattern--77eae145-55db-4519-8ae5-77b0c7215d69 | Stealth | Linux, macOS, Windows | 2.0 |
| Masquerading: Space after Filename T1036.006 · sub-technique of T1036 STIX ID attack-pattern--e51137a5-1cdc-499e-911a-abaedaa5ac86 | Stealth | Linux, macOS | 2.0 |
| Modify Authentication Process T1556 STIX ID attack-pattern--f4c1826f-a322-41cd-9557-562100848c84 | Credential Access, Defense Impairment, Persistence | IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows | 3.0 |
| Modify Authentication Process: Conditional Access Policies T1556.009 · sub-technique of T1556 STIX ID attack-pattern--ceaeb6d8-95ee-4da2-9d42-dc6aa6ca43ae | Credential Access, Defense Impairment, Persistence | IaaS, Identity Provider | 2.0 |
| Modify Authentication Process: Domain Controller Authentication T1556.001 · sub-technique of T1556 STIX ID attack-pattern--d4b96d2c-1032-4b22-9235-2b5b649d0605 | Credential Access, Defense Impairment, Persistence | Windows | 3.0 |
| Modify Authentication Process: Hybrid Identity T1556.007 · sub-technique of T1556 STIX ID attack-pattern--54ca26f3-c172-4231-93e5-ccebcac2161f | Credential Access, Defense Impairment, Persistence | IaaS, Identity Provider, Office Suite, SaaS, Windows | 2.0 |
| Modify Authentication Process: Multi-Factor Authentication T1556.006 · sub-technique of T1556 STIX ID attack-pattern--b4409cd8-0da9-46e1-a401-a241afd4d1cc | Credential Access, Defense Impairment, Persistence | IaaS, Identity Provider, Linux, macOS, Office Suite, SaaS, Windows | 2.0 |
| Modify Authentication Process: Network Device Authentication T1556.004 · sub-technique of T1556 STIX ID attack-pattern--fa44a152-ac48-441e-a524-dd7b04b8adcd | Credential Access, Defense Impairment, Persistence | Network Devices | 3.0 |
| Modify Authentication Process: Network Provider DLL T1556.008 · sub-technique of T1556 STIX ID attack-pattern--90c4a591-d02d-490b-92aa-619d9701ac04 | Credential Access, Defense Impairment, Persistence | Windows | 2.0 |
| Modify Authentication Process: Password Filter DLL T1556.002 · sub-technique of T1556 STIX ID attack-pattern--3731fbcd-0e43-47ae-ae6c-d15e510f0d42 | Credential Access, Defense Impairment, Persistence | Windows | 3.0 |
| Modify Authentication Process: Pluggable Authentication Modules T1556.003 · sub-technique of T1556 STIX ID attack-pattern--06c00069-771a-4d57-8ef5-d3718c1a8771 | Credential Access, Defense Impairment, Persistence | Linux, macOS | 3.0 |
| Modify Authentication Process: Reversible Encryption T1556.005 · sub-technique of T1556 STIX ID attack-pattern--d50955c2-272d-4ac8-95da-10c29dda1c48 | Credential Access, Defense Impairment, Persistence | Windows | 2.0 |
| Modify Cloud Compute Infrastructure T1578 STIX ID attack-pattern--144e007b-e638-431d-a894-45d90c54ab90 | Defense Impairment | IaaS | 2.0 |
| Modify Cloud Compute Infrastructure: Create Cloud Instance T1578.002 · sub-technique of T1578 STIX ID attack-pattern--cf1c2504-433f-4c4e-a1f8-91de45a0318c | Defense Impairment | IaaS | 2.0 |
| Modify Cloud Compute Infrastructure: Create Snapshot T1578.001 · sub-technique of T1578 STIX ID attack-pattern--ed2e45f9-d338-4eb2-8ce5-3a2e03323bc1 | Defense Impairment | IaaS | 2.0 |
| Modify Cloud Compute Infrastructure: Delete Cloud Instance T1578.003 · sub-technique of T1578 STIX ID attack-pattern--70857657-bd0b-4695-ad3e-b13f92cac1b4 | Defense Impairment | IaaS | 2.0 |
| Modify Cloud Compute Infrastructure: Modify Cloud Compute Configurations T1578.005 · sub-technique of T1578 STIX ID attack-pattern--ca00366b-83a1-4c7b-a0ce-8ff950a7c87f | Defense Impairment | IaaS | 3.0 |
| Modify Cloud Compute Infrastructure: Revert Cloud Instance T1578.004 · sub-technique of T1578 STIX ID attack-pattern--0708ae90-d0eb-4938-9a76-d0fc94f6eec1 | Defense Impairment | IaaS | 2.0 |
| Modify Cloud Resource Hierarchy T1666 STIX ID attack-pattern--0ce73446-8722-4086-9d43-514f1d0f669e | Defense Impairment | IaaS | 2.0 |
| Modify Registry T1112 STIX ID attack-pattern--57340c81-c025-4189-8fa0-fc7ede51bae4 | Defense Impairment, Persistence | Windows | 3.0 |
| Modify System Image T1601 STIX ID attack-pattern--ae7f3575-0a5e-427e-991b-fe03ad44c754 | Defense Impairment | Network Devices | 2.0 |
| Modify System Image: Downgrade System Image T1601.002 · sub-technique of T1601 STIX ID attack-pattern--fc74ba38-dc98-461f-8611-b3dbf9978e3d | Defense Impairment | Network Devices | 2.0 |
| Modify System Image: Patch System Image T1601.001 · sub-technique of T1601 STIX ID attack-pattern--d245808a-7086-4310-984a-a84aaaa43f8f | Defense Impairment | Network Devices | 2.0 |
| Multi-Factor Authentication Interception T1111 STIX ID attack-pattern--dd43c543-bb85-4a6f-aa6e-160d90d06a49 | Credential Access | Linux, macOS, Windows | 2.1 |
| Multi-Factor Authentication Request Generation T1621 STIX ID attack-pattern--954a1639-f2d6-407d-aef3-4917622ca493 | Credential Access | IaaS, Identity Provider, Linux, macOS, Office Suite, SaaS, Windows | 1.2 |
| Multi-Stage Channels T1104 STIX ID attack-pattern--84e02621-8fdf-470f-bd58-993bb6a89d91 | Command and Control | ESXi, Linux, macOS, Windows | 1.1 |
| Native API T1106 STIX ID attack-pattern--391d824f-0ef1-47a0-b0ee-c59a75e27670 | Execution | Linux, macOS, Windows | 2.3 |
| Network Boundary Bridging T1599 STIX ID attack-pattern--b8017880-4b1e-42de-ad10-ae7ac6705166 | Defense Impairment | Network Devices | 2.0 |
| Network Boundary Bridging: Network Address Translation Traversal T1599.001 · sub-technique of T1599 STIX ID attack-pattern--4ffc1794-ec3b-45be-9e52-42dbcb2af2de | Defense Impairment | Network Devices | 2.0 |
| Network Denial of Service T1498 STIX ID attack-pattern--d74c4a7e-ffbf-432f-9365-7ebf1f787cab | Impact | Containers, IaaS, Linux, macOS, Windows | 1.2 |
| Network Denial of Service: Direct Network Flood T1498.001 · sub-technique of T1498 STIX ID attack-pattern--0bda01d5-4c1d-4062-8ee2-6872334383c3 | Impact | IaaS, Linux, macOS, Windows | 1.4 |
| Network Denial of Service: Reflection Amplification T1498.002 · sub-technique of T1498 STIX ID attack-pattern--36b2a1d7-e09e-49bf-b45e-477076c2ec01 | Impact | IaaS, Linux, macOS, Windows | 1.4 |
| Network Service Discovery T1046 STIX ID attack-pattern--e3a12395-188d-4051-9a16-ea8e14d07b88 | Discovery | Containers, IaaS, Linux, macOS, Network Devices, Windows | 3.2 |
| Network Share Discovery T1135 STIX ID attack-pattern--3489cfc5-640f-4bb3-a103-9137b97de79f | Discovery | Linux, macOS, Windows | 3.2 |
| Network Sniffing T1040 STIX ID attack-pattern--3257eb21-f9a7-4430-8de1-d8b6e288f529 | Credential Access, Discovery | IaaS, Linux, macOS, Network Devices, Windows | 1.7 |
| Non-Application Layer Protocol T1095 STIX ID attack-pattern--c21d5a77-d422-4a69-acd7-2c53c1faa34b | Command and Control | ESXi, Linux, macOS, Network Devices, Windows | 2.4 |
| Non-Standard Port T1571 STIX ID attack-pattern--b18eae87-b469-4e14-b454-b171b416bc18 | Command and Control | ESXi, Linux, macOS, Windows | 1.3 |
| OS Credential Dumping T1003 STIX ID attack-pattern--0a3ead4e-6d47-4ccb-854c-a6a4f9d96b22 | Credential Access | Linux, macOS, Windows | 2.2 |
| OS Credential Dumping: /etc/passwd and /etc/shadow T1003.008 · sub-technique of T1003 STIX ID attack-pattern--d0b4fcdb-d67d-4ed2-99ce-788b12f8c0f4 | Credential Access | Linux | 1.2 |
| OS Credential Dumping: Cached Domain Credentials T1003.005 · sub-technique of T1003 STIX ID attack-pattern--6add2ab5-2711-4e9d-87c8-7a0be8531530 | Credential Access | Linux, Windows | 1.1 |
| OS Credential Dumping: DCSync T1003.006 · sub-technique of T1003 STIX ID attack-pattern--f303a39a-6255-4b89-aecc-18c4d8ca7163 | Credential Access | Windows | 1.1 |
| OS Credential Dumping: LSA Secrets T1003.004 · sub-technique of T1003 STIX ID attack-pattern--1ecfdab8-7d59-4c98-95d4-dc41970f57fc | Credential Access | Windows | 1.1 |
| OS Credential Dumping: LSASS Memory T1003.001 · sub-technique of T1003 STIX ID attack-pattern--65f2d882-3f41-4d48-8a06-29af77ec9f90 | Credential Access | Windows | 1.5 |
| OS Credential Dumping: NTDS T1003.003 · sub-technique of T1003 STIX ID attack-pattern--edf91964-b26e-4b4a-9600-ccacd7d7df24 | Credential Access | Windows | 1.3 |
| OS Credential Dumping: Proc Filesystem T1003.007 · sub-technique of T1003 STIX ID attack-pattern--3120b9fa-23b8-4500-ae73-09494f607b7d | Credential Access | Linux | 1.2 |
| OS Credential Dumping: Security Account Manager T1003.002 · sub-technique of T1003 STIX ID attack-pattern--1644e709-12d2-41e5-a60f-3470991f5011 | Credential Access | Windows | 1.1 |
| Obfuscated Files or Information T1027 STIX ID attack-pattern--b3d682b6-98f2-4fb0-aa3b-b4df007ca70a | Stealth | ESXi, Linux, macOS, Network Devices, Windows | 2.0 |
| Obfuscated Files or Information: Binary Padding T1027.001 · sub-technique of T1027 STIX ID attack-pattern--5bfccc3f-2326-4112-86cc-c1ece9d8a2b5 | Stealth | Linux, macOS, Windows | 2.0 |
| Obfuscated Files or Information: Command Obfuscation T1027.010 · sub-technique of T1027 STIX ID attack-pattern--d511a6f6-4a33-41d5-bc95-c343875d1377 | Stealth | Linux, macOS, Windows | 2.0 |
| Obfuscated Files or Information: Compile After Delivery T1027.004 · sub-technique of T1027 STIX ID attack-pattern--c726e0a2-a57a-4b7b-a973-d0f013246617 | Stealth | Linux, macOS, Windows | 2.0 |
| Obfuscated Files or Information: Compression T1027.015 · sub-technique of T1027 STIX ID attack-pattern--fbd91bfc-75c2-4f0c-8116-3b4e722906b3 | Stealth | Linux, macOS, Windows | 2.0 |
| Obfuscated Files or Information: Dynamic API Resolution T1027.007 · sub-technique of T1027 STIX ID attack-pattern--ea4c2f9c-9df1-477c-8c42-6da1118f2ac4 | Stealth | Windows | 2.0 |
| Obfuscated Files or Information: Embedded Payloads T1027.009 · sub-technique of T1027 STIX ID attack-pattern--0533ab23-3f7d-463f-9bd8-634d27e4dee1 | Stealth | Linux, macOS, Windows | 2.0 |
| Obfuscated Files or Information: Encrypted/Encoded File T1027.013 · sub-technique of T1027 STIX ID attack-pattern--0d91b3c0-5e50-47c3-949a-2a796f04d144 | Stealth | Linux, macOS, Windows | 2.0 |
| Obfuscated Files or Information: Fileless Storage T1027.011 · sub-technique of T1027 STIX ID attack-pattern--02c5abff-30bf-4703-ab92-1f6072fae939 | Stealth | Linux, Windows | 3.0 |
| Obfuscated Files or Information: HTML Smuggling T1027.006 · sub-technique of T1027 STIX ID attack-pattern--d4dc46e3-5ba5-45b9-8204-010867cacfcb | Stealth | Linux, macOS, Windows | 2.0 |
| Obfuscated Files or Information: Indicator Removal from Tools T1027.005 · sub-technique of T1027 STIX ID attack-pattern--b0533c6e-8fea-4788-874f-b799cacc4b92 | Stealth | Linux, macOS, Windows | 2.0 |
| Obfuscated Files or Information: Invisible Unicode T1027.018 · sub-technique of T1027 STIX ID attack-pattern--e9b75bb0-b5ec-42c8-b728-f4f424d9c39e | Stealth | Linux, macOS, Windows | 1.0 |
| Obfuscated Files or Information: Junk Code Insertion T1027.016 · sub-technique of T1027 STIX ID attack-pattern--671cd17f-a765-48fd-adc4-dad1941b1ae3 | Stealth | Linux, macOS, Windows | 2.0 |
| Obfuscated Files or Information: LNK Icon Smuggling T1027.012 · sub-technique of T1027 STIX ID attack-pattern--887274fc-2d63-4bdc-82f3-fae56d1d5fdc | Stealth | Windows | 2.0 |
| Obfuscated Files or Information: Polymorphic Code T1027.014 · sub-technique of T1027 STIX ID attack-pattern--b577dfc1-0177-4522-8d5a-782127c8592b | Stealth | Linux, macOS, Windows | 2.0 |
| Obfuscated Files or Information: SVG Smuggling T1027.017 · sub-technique of T1027 STIX ID attack-pattern--78b9e70d-1605-459c-b23d-e3a25036968c | Stealth | Linux, macOS, Windows | 2.0 |
| Obfuscated Files or Information: Software Packing T1027.002 · sub-technique of T1027 STIX ID attack-pattern--deb98323-e13f-4b0c-8d94-175379069062 | Stealth | Linux, macOS, Windows | 2.0 |
| Obfuscated Files or Information: Steganography T1027.003 · sub-technique of T1027 STIX ID attack-pattern--c2e147a9-d1a8-4074-811a-d8789202d916 | Stealth | Linux, macOS, Windows | 2.0 |
| Obfuscated Files or Information: Stripped Payloads T1027.008 · sub-technique of T1027 STIX ID attack-pattern--2f41939b-54c3-41d6-8f8b-35f1ec18ed97 | Stealth | Linux, macOS, Network Devices, Windows | 2.0 |
| Obtain Capabilities T1588 STIX ID attack-pattern--ce0687a0-e692-4b77-964a-0784a8e54ff1 | Resource Development | PRE | 1.1 |
| Obtain Capabilities: Artificial Intelligence T1588.007 · sub-technique of T1588 STIX ID attack-pattern--0cc222f5-c3ff-48e6-9f52-3314baf9d37e | Resource Development | PRE | 1.1 |
| Obtain Capabilities: Code Signing Certificates T1588.003 · sub-technique of T1588 STIX ID attack-pattern--e7cbc1de-1f79-48ee-abfd-da1241c65a15 | Resource Development | PRE | 1.1 |
| Obtain Capabilities: Digital Certificates T1588.004 · sub-technique of T1588 STIX ID attack-pattern--19401639-28d0-4c3c-adcc-bc2ba22f6421 | Resource Development | PRE | 1.2 |
| Obtain Capabilities: Exploits T1588.005 · sub-technique of T1588 STIX ID attack-pattern--f4b843c1-7e92-4701-8fed-ce82f8be2636 | Resource Development | PRE | 1.0 |
| Obtain Capabilities: Malware T1588.001 · sub-technique of T1588 STIX ID attack-pattern--7807d3a4-a885-4639-a786-c1ed41484970 | Resource Development | PRE | 1.1 |
| Obtain Capabilities: Tool T1588.002 · sub-technique of T1588 STIX ID attack-pattern--a2fdce72-04b2-409a-ac10-cc1695f4fce0 | Resource Development | PRE | 1.2 |
| Obtain Capabilities: Vulnerabilities T1588.006 · sub-technique of T1588 STIX ID attack-pattern--2b5aa86b-a0df-4382-848d-30abea443327 | Resource Development | PRE | 1.0 |
| Office Application Startup T1137 STIX ID attack-pattern--2c4d4e92-0ccf-4a97-b54c-86d662988a53 | Persistence | Office Suite, Windows | 1.4 |
| Office Application Startup: Add-ins T1137.006 · sub-technique of T1137 STIX ID attack-pattern--34f1d81d-fe88-4f97-bd3b-a3164536255d | Persistence | Office Suite, Windows | 1.2 |
| Office Application Startup: Office Template Macros T1137.001 · sub-technique of T1137 STIX ID attack-pattern--79a47ad0-fc3b-4821-9f01-a026b1ddba21 | Persistence | Office Suite, Windows | 1.2 |
| Office Application Startup: Office Test T1137.002 · sub-technique of T1137 STIX ID attack-pattern--ed7efd4d-ce28-4a19-a8e6-c58011eb2c7a | Persistence | Office Suite, Windows | 1.3 |
| Office Application Startup: Outlook Forms T1137.003 · sub-technique of T1137 STIX ID attack-pattern--a9e2cea0-c805-4bf8-9e31-f5f0513a3634 | Persistence | Office Suite, Windows | 1.2 |
| Office Application Startup: Outlook Home Page T1137.004 · sub-technique of T1137 STIX ID attack-pattern--bf147104-abf9-4221-95d1-e81585859441 | Persistence | Office Suite, Windows | 1.2 |
| Office Application Startup: Outlook Rules T1137.005 · sub-technique of T1137 STIX ID attack-pattern--3d1b9d7e-3921-4d25-845a-7d9f15c0da44 | Persistence | Office Suite, Windows | 1.2 |
| Password Policy Discovery T1201 STIX ID attack-pattern--b6075259-dba3-44e9-87c7-e954f37ec0d5 | Discovery | IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows | 1.7 |
| Peripheral Device Discovery T1120 STIX ID attack-pattern--348f1eef-964b-4eb6-bb53-69b3dcb0c643 | Discovery | Linux, macOS, Windows | 1.4 |
| Permission Groups Discovery T1069 STIX ID attack-pattern--15dbf668-795c-41e6-8219-f0447c0e64ce | Discovery | Containers, IaaS, Identity Provider, Linux, macOS, Office Suite, SaaS, Windows | 2.6 |
| Permission Groups Discovery: Cloud Groups T1069.003 · sub-technique of T1069 STIX ID attack-pattern--16e94db9-b5b1-4cd0-b851-f38fbd0a70f2 | Discovery | IaaS, Identity Provider, Office Suite, SaaS | 1.5 |
| Permission Groups Discovery: Domain Groups T1069.002 · sub-technique of T1069 STIX ID attack-pattern--2aed01ad-3df3-4410-a8cb-11ea4ded587c | Discovery | Linux, macOS, Windows | 1.2 |
| Permission Groups Discovery: Local Groups T1069.001 · sub-technique of T1069 STIX ID attack-pattern--a01bf75f-00b2-4568-a58f-565ff9bf202b | Discovery | Linux, macOS, Windows | 1.2 |
| Phishing T1566 STIX ID attack-pattern--a62a8db3-f23a-4d8f-afd6-9dbc77e7813b | Initial Access | Identity Provider, Linux, macOS, Office Suite, SaaS, Windows | 2.7 |
| Phishing for Information T1598 STIX ID attack-pattern--cca0ccb6-a068-4574-a722-b1556f86833a | Reconnaissance | PRE | 1.4 |
| Phishing for Information: Spearphishing Attachment T1598.002 · sub-technique of T1598 STIX ID attack-pattern--8982a661-d84c-48c0-b4ec-1db29c6cf3bc | Reconnaissance | PRE | 1.2 |
| Phishing for Information: Spearphishing Link T1598.003 · sub-technique of T1598 STIX ID attack-pattern--2d3f5b3c-54ca-4f4d-bb1f-849346d31230 | Reconnaissance | PRE | 1.7 |
| Phishing for Information: Spearphishing Service T1598.001 · sub-technique of T1598 STIX ID attack-pattern--f870408c-b1cd-49c7-a5c7-0ef0fc496cc6 | Reconnaissance | PRE | 1.0 |
| Phishing for Information: Spearphishing Voice T1598.004 · sub-technique of T1598 STIX ID attack-pattern--6a5d222a-a7e0-4656-b110-782c33098289 | Reconnaissance | PRE | 1.0 |
| Phishing: Spearphishing Attachment T1566.001 · sub-technique of T1566 STIX ID attack-pattern--2e34237d-8574-43f6-aace-ae2915de8597 | Initial Access | Linux, macOS, Windows | 2.2 |
| Phishing: Spearphishing Link T1566.002 · sub-technique of T1566 STIX ID attack-pattern--2b742742-28c3-4e1b-bab7-8350d6300fa7 | Initial Access | Identity Provider, Linux, macOS, Office Suite, SaaS, Windows | 2.8 |
| Phishing: Spearphishing Voice T1566.004 · sub-technique of T1566 STIX ID attack-pattern--bb5e59c4-abe7-40c7-8196-e373cb1e5974 | Initial Access | Identity Provider, Linux, macOS, Windows | 1.2 |
| Phishing: Spearphishing via Service T1566.003 · sub-technique of T1566 STIX ID attack-pattern--f6ad61ee-65f3-4bd0-a3f5-2f0accb36317 | Initial Access | Linux, macOS, Windows | 2.0 |
| Plist File Modification T1647 STIX ID attack-pattern--7d20fff9-8751-404e-badd-ccd71bda0236 | Defense Impairment | macOS | 2.0 |
| Poisoned Pipeline Execution T1677 STIX ID attack-pattern--7655ac3b-dfde-49c5-a967-242856174434 | Execution | SaaS | 1.0 |
| Power Settings T1653 STIX ID attack-pattern--ea071aa0-8f17-416f-ab0d-2bab7e79003d | Persistence | Linux, macOS, Network Devices, Windows | 1.1 |
| Pre-OS Boot T1542 STIX ID attack-pattern--7f0ca133-88c4-40c6-a62f-b3083a7fbc2e | Persistence, Stealth | Linux, macOS, Network Devices, Windows | 2.0 |
| Pre-OS Boot: Bootkit T1542.003 · sub-technique of T1542 STIX ID attack-pattern--1b7b1806-7746-41a1-a35d-e48dae25ddba | Persistence, Stealth | Linux, Windows | 2.0 |
| Pre-OS Boot: Component Firmware T1542.002 · sub-technique of T1542 STIX ID attack-pattern--791481f8-e96a-41be-b089-a088763083d4 | Persistence, Stealth | Linux, macOS, Windows | 2.0 |
| Pre-OS Boot: ROMMONkit T1542.004 · sub-technique of T1542 STIX ID attack-pattern--a6557c75-798f-42e4-be70-ab4502e0a3bc | Persistence, Stealth | Network Devices | 2.0 |
| Pre-OS Boot: System Firmware T1542.001 · sub-technique of T1542 STIX ID attack-pattern--16ab6452-c3c1-497c-a47d-206018ca1ada | Persistence, Stealth | Network Devices, Windows | 2.0 |
| Pre-OS Boot: TFTP Boot T1542.005 · sub-technique of T1542 STIX ID attack-pattern--28abec6c-4443-4b03-8206-07f2e264a6b4 | Persistence, Stealth | Network Devices | 2.0 |
| Prevent Command History Logging T1690 STIX ID attack-pattern--b831f51c-d22f-4724-bbab-60d056bd1150 | Defense Impairment | ESXi, Linux, macOS, Network Devices, Windows | 1.0 |
| Process Discovery T1057 STIX ID attack-pattern--8f4a33ec-8b1f-4b80-a2f6-642b2e479580 | Discovery | ESXi, Linux, macOS, Network Devices, Windows | 1.6 |
| Process Injection T1055 STIX ID attack-pattern--43e7dc91-05b2-474c-b9ac-2ed4fe101f4d | Privilege Escalation, Stealth | Linux, macOS, Windows | 2.0 |
| Process Injection: Asynchronous Procedure Call T1055.004 · sub-technique of T1055 STIX ID attack-pattern--7c0f17c9-1af6-4628-9cbd-9e45482dd605 | Privilege Escalation, Stealth | Windows | 2.0 |
| Process Injection: Dynamic-link Library Injection T1055.001 · sub-technique of T1055 STIX ID attack-pattern--f4599aa0-4f85-4a32-80ea-fc39dc965945 | Privilege Escalation, Stealth | Windows | 2.0 |
| Process Injection: Extra Window Memory Injection T1055.011 · sub-technique of T1055 STIX ID attack-pattern--0042a9f5-f053-4769-b3ef-9ad018dfa298 | Privilege Escalation, Stealth | Windows | 2.0 |
| Process Injection: ListPlanting T1055.015 · sub-technique of T1055 STIX ID attack-pattern--eb2cb5cb-ae87-4de0-8c35-da2a17aafb99 | Privilege Escalation, Stealth | Windows | 2.0 |
| Process Injection: Portable Executable Injection T1055.002 · sub-technique of T1055 STIX ID attack-pattern--806a49c4-970d-43f9-9acc-ac0ee11e6662 | Privilege Escalation, Stealth | Windows | 2.0 |
| Process Injection: Proc Memory T1055.009 · sub-technique of T1055 STIX ID attack-pattern--d201d4cc-214d-4a74-a1ba-b3fa09fd4591 | Privilege Escalation, Stealth | Linux | 2.0 |
| Process Injection: Process Doppelgänging T1055.013 · sub-technique of T1055 STIX ID attack-pattern--7007935a-a8a7-4c0b-bd98-4e85be8ed197 | Privilege Escalation, Stealth | Windows | 2.0 |
| Process Injection: Process Hollowing T1055.012 · sub-technique of T1055 STIX ID attack-pattern--b200542e-e877-4395-875b-cf1a44537ca4 | Privilege Escalation, Stealth | Windows | 2.0 |
| Process Injection: Ptrace System Calls T1055.008 · sub-technique of T1055 STIX ID attack-pattern--ea016b56-ae0e-47fe-967a-cc0ad51af67f | Privilege Escalation, Stealth | Linux | 2.0 |
| Process Injection: Thread Execution Hijacking T1055.003 · sub-technique of T1055 STIX ID attack-pattern--41d9846c-f6af-4302-a654-24bba2729bc6 | Privilege Escalation, Stealth | Windows | 2.0 |
| Process Injection: Thread Local Storage T1055.005 · sub-technique of T1055 STIX ID attack-pattern--e49ee9d2-0d98-44ef-85e5-5d3100065744 | Privilege Escalation, Stealth | Windows | 2.0 |
| Process Injection: VDSO Hijacking T1055.014 · sub-technique of T1055 STIX ID attack-pattern--98be40f2-c86b-4ade-b6fc-4964932040e5 | Privilege Escalation, Stealth | Linux | 2.0 |
| Protocol Tunneling T1572 STIX ID attack-pattern--4fe28b27-b13c-453e-a386-c2ef362a573b | Command and Control | ESXi, Linux, macOS, Windows | 1.1 |
| Proxy T1090 STIX ID attack-pattern--731f4f55-b6d0-41d1-a7a9-072a66389aea | Command and Control | ESXi, Linux, macOS, Network Devices, Windows | 3.2 |
| Proxy: Domain Fronting T1090.004 · sub-technique of T1090 STIX ID attack-pattern--ca9d3402-ada3-484d-876a-d717bd6e05f2 | Command and Control | ESXi, Linux, macOS, Windows | 1.2 |
| Proxy: External Proxy T1090.002 · sub-technique of T1090 STIX ID attack-pattern--69b8fd78-40e8-4600-ae4d-662c9d7afdb3 | Command and Control | ESXi, Linux, macOS, Network Devices, Windows | 1.3 |
| Proxy: Internal Proxy T1090.001 · sub-technique of T1090 STIX ID attack-pattern--f6dacc85-b37d-458e-b58d-74fc4bbf5755 | Command and Control | ESXi, Linux, macOS, Network Devices, Windows | 1.2 |
| Proxy: Multi-hop Proxy T1090.003 · sub-technique of T1090 STIX ID attack-pattern--a782ebe2-daba-42c7-bc82-e8e9d923162d | Command and Control | ESXi, Linux, macOS, Network Devices, Windows | 2.4 |
| Query Public AI Services T1682 STIX ID attack-pattern--143122a8-fcda-4dd7-aded-5b9387d9c2d6 | Reconnaissance | PRE | 1.0 |
| Query Registry T1012 STIX ID attack-pattern--c32f7008-9fea-41f7-8366-5eb9b74bd896 | Discovery | Windows | 1.3 |
| Reflective Code Loading T1620 STIX ID attack-pattern--4933e63b-9b77-476e-ab29-761bc5b7d15a | Stealth | Linux, macOS, Windows | 2.0 |
| Remote Access Tools T1219 STIX ID attack-pattern--4061e78c-1284-44b4-9116-73e4ac3912f7 | Command and Control | Linux, macOS, Windows | 3.0 |
| Remote Access Tools: IDE Tunneling T1219.001 · sub-technique of T1219 STIX ID attack-pattern--77e29a47-e263-4f11-8692-e5012f44dbac | Command and Control | Linux, macOS, Windows | 1.0 |
| Remote Access Tools: Remote Access Hardware T1219.003 · sub-technique of T1219 STIX ID attack-pattern--a9fb6b3f-4a3c-4703-a4f1-f55f83d1e017 | Command and Control | Linux, macOS, Windows | 1.0 |
| Remote Access Tools: Remote Desktop Software T1219.002 · sub-technique of T1219 STIX ID attack-pattern--d4287702-e2f7-4946-bdfa-2c7f5aaa5032 | Command and Control | Linux, macOS, Windows | 1.0 |
| Remote Service Session Hijacking T1563 STIX ID attack-pattern--5b0ad6f8-6a16-4966-a4ef-d09ea6e2a9f5 | Lateral Movement | Linux, macOS, Windows | 1.1 |
| Remote Service Session Hijacking: RDP Hijacking T1563.002 · sub-technique of T1563 STIX ID attack-pattern--e0033c16-a07e-48aa-8204-7c3ca669998c | Lateral Movement | Windows | 1.1 |
| Remote Service Session Hijacking: SSH Hijacking T1563.001 · sub-technique of T1563 STIX ID attack-pattern--4d2a5b3e-340d-4600-9123-309dd63c9bf8 | Lateral Movement | Linux, macOS | 1.1 |
| Remote Services T1021 STIX ID attack-pattern--54a649ff-439a-41a4-9856-8d144a2551ba | Lateral Movement | ESXi, IaaS, Linux, macOS, Windows | 1.6 |
| Remote Services: Cloud Services T1021.007 · sub-technique of T1021 STIX ID attack-pattern--8861073d-d1b8-4941-82ce-dce621d398f0 | Lateral Movement | IaaS, Identity Provider, Office Suite, SaaS | 1.1 |
| Remote Services: Direct Cloud VM Connections T1021.008 · sub-technique of T1021 STIX ID attack-pattern--45241b9e-9bbc-4826-a2cc-78855e51ca09 | Lateral Movement | IaaS | 1.0 |
| Remote Services: Distributed Component Object Model T1021.003 · sub-technique of T1021 STIX ID attack-pattern--68a0c5ed-bee2-4513-830d-5b0d650139bd | Lateral Movement | Windows | 1.3 |
| Remote Services: Remote Desktop Protocol T1021.001 · sub-technique of T1021 STIX ID attack-pattern--eb062747-2193-45de-8fa2-e62549c37ddf | Lateral Movement | Windows | 1.4 |
| Remote Services: SMB/Windows Admin Shares T1021.002 · sub-technique of T1021 STIX ID attack-pattern--4f9ca633-15c5-463c-9724-bdcd54fde541 | Lateral Movement | Windows | 1.3 |
| Remote Services: SSH T1021.004 · sub-technique of T1021 STIX ID attack-pattern--2db31dcd-54da-405d-acef-b9129b816ed6 | Lateral Movement | ESXi, Linux, macOS | 1.3 |
| Remote Services: VNC T1021.005 · sub-technique of T1021 STIX ID attack-pattern--01327cde-66c4-4123-bf34-5f258d59457b | Lateral Movement | Linux, macOS, Windows | 1.2 |
| Remote Services: Windows Remote Management T1021.006 · sub-technique of T1021 STIX ID attack-pattern--60d0c01d-e2bf-49dd-a453-f8a9c9fa6f65 | Lateral Movement | Windows | 1.2 |
| Remote System Discovery T1018 STIX ID attack-pattern--e358d692-23c0-4a31-9eb6-ecc13a8d7735 | Discovery | ESXi, Linux, macOS, Network Devices, Windows | 3.6 |
| Replication Through Removable Media T1091 STIX ID attack-pattern--3b744087-9945-4a6f-91e8-9dbceda417a4 | Initial Access, Lateral Movement | Windows | 1.3 |
| Resource Hijacking T1496 STIX ID attack-pattern--cd25c1b4-935c-4f0e-ba8d-552f28bc4783 | Impact | Containers, IaaS, Linux, macOS, SaaS, Windows | 2.0 |
| Resource Hijacking: Bandwidth Hijacking T1496.002 · sub-technique of T1496 STIX ID attack-pattern--718cb208-6446-4572-a2f0-9c799c60091e | Impact | Containers, IaaS, Linux, macOS, Windows | 1.0 |
| Resource Hijacking: Cloud Service Hijacking T1496.004 · sub-technique of T1496 STIX ID attack-pattern--924d273c-be0d-4d8d-af58-2dddb15ef1e2 | Impact | SaaS | 1.0 |
| Resource Hijacking: Compute Hijacking T1496.001 · sub-technique of T1496 STIX ID attack-pattern--a718a0c8-5768-41a1-9958-a1cc3f995e99 | Impact | Containers, IaaS, Linux, macOS, Windows | 1.0 |
| Resource Hijacking: SMS Pumping T1496.003 · sub-technique of T1496 STIX ID attack-pattern--130d4494-b2d6-4040-bcea-6e59f05222fe | Impact | SaaS | 1.0 |
| Rogue Domain Controller T1207 STIX ID attack-pattern--564998d8-ab3e-4123-93fb-eccaa6b9714a | Defense Impairment | Windows | 3.0 |
| Rootkit T1014 STIX ID attack-pattern--0f20e3cb-245b-4a61-8a91-2d93f7cb0e9b | Stealth | Linux, macOS, Windows | 2.0 |
| Safe Mode Boot T1688 STIX ID attack-pattern--c7660f19-f8c5-4ae3-a5e5-24381c270376 | Defense Impairment | Windows | 1.0 |
| Scheduled Task/Job T1053 STIX ID attack-pattern--35dd844a-b219-4e2b-a6bb-efa9a75995a9 | Execution, Persistence, Privilege Escalation | Containers, ESXi, Linux, macOS, Network Devices, Windows | 2.5 |
| Scheduled Task/Job: At T1053.002 · sub-technique of T1053 STIX ID attack-pattern--f3d95a1f-bba2-44ce-9af7-37866cd63fd0 | Execution, Persistence, Privilege Escalation | Linux, macOS, Windows | 2.4 |
| Scheduled Task/Job: Container Orchestration Job T1053.007 · sub-technique of T1053 STIX ID attack-pattern--1126cab1-c700-412f-a510-61f4937bb096 | Execution, Persistence, Privilege Escalation | Containers | 1.4 |
| Scheduled Task/Job: Cron T1053.003 · sub-technique of T1053 STIX ID attack-pattern--2acf44aa-542f-4366-b4eb-55ef5747759c | Execution, Persistence, Privilege Escalation | ESXi, Linux, macOS | 1.3 |
| Scheduled Task/Job: Scheduled Task T1053.005 · sub-technique of T1053 STIX ID attack-pattern--005a06c6-14bf-4118-afa0-ebcd8aebb0c9 | Execution, Persistence, Privilege Escalation | Windows | 1.8 |
| Scheduled Task/Job: Systemd Timers T1053.006 · sub-technique of T1053 STIX ID attack-pattern--a542bac9-7bc1-4da7-9a09-96f69e23cc21 | Execution, Persistence, Privilege Escalation | Linux | 1.3 |
| Scheduled Transfer T1029 STIX ID attack-pattern--4eeaf8a9-c86b-4954-a663-9555fb406466 | Exfiltration | Linux, macOS, Windows | 1.1 |
| Screen Capture T1113 STIX ID attack-pattern--0259baeb-9f63-4c69-bf10-eb038c390688 | Collection | Linux, macOS, Windows | 1.1 |
| Search Closed Sources T1597 STIX ID attack-pattern--a51eb150-93b1-484b-a503-e51453b127a4 | Reconnaissance | PRE | 1.1 |
| Search Closed Sources: Purchase Technical Data T1597.002 · sub-technique of T1597 STIX ID attack-pattern--0a241b6c-7bb2-48f9-98f7-128145b4d27f | Reconnaissance | PRE | 1.0 |
| Search Closed Sources: Threat Intel Vendors T1597.001 · sub-technique of T1597 STIX ID attack-pattern--51e54974-a541-4fb6-a61b-0518e4c6de41 | Reconnaissance | PRE | 2.0 |
| Search Open Technical Databases T1596 STIX ID attack-pattern--55fc4df0-b42c-479a-b860-7a6761bcaad0 | Reconnaissance | PRE | 1.0 |
| Search Open Technical Databases: CDNs T1596.004 · sub-technique of T1596 STIX ID attack-pattern--91177e6d-b616-4a03-ba4b-f3b32f7dda75 | Reconnaissance | PRE | 1.0 |
| Search Open Technical Databases: DNS/Passive DNS T1596.001 · sub-technique of T1596 STIX ID attack-pattern--17fd695c-b88c-455a-a3d1-43b6cb728532 | Reconnaissance | PRE | 1.0 |
| Search Open Technical Databases: Digital Certificates T1596.003 · sub-technique of T1596 STIX ID attack-pattern--0979abf9-4e26-43ec-9b6e-54efc4e70fca | Reconnaissance | PRE | 1.0 |
| Search Open Technical Databases: Scan Databases T1596.005 · sub-technique of T1596 STIX ID attack-pattern--ec4be82f-940c-4dcb-87fe-2bbdd17c692f | Reconnaissance | PRE | 1.0 |
| Search Open Technical Databases: WHOIS T1596.002 · sub-technique of T1596 STIX ID attack-pattern--166de1c6-2814-4fe5-8438-4e80f76b169f | Reconnaissance | PRE | 1.0 |
| Search Open Websites/Domains T1593 STIX ID attack-pattern--a0e6614a-7740-4b24-bd65-f1bde09fc365 | Reconnaissance | PRE | 1.1 |
| Search Open Websites/Domains: Code Repositories T1593.003 · sub-technique of T1593 STIX ID attack-pattern--70910fbd-58dc-4c1c-8c48-814d11fcd022 | Reconnaissance | PRE | 1.0 |
| Search Open Websites/Domains: Search Engines T1593.002 · sub-technique of T1593 STIX ID attack-pattern--6e561441-8431-4773-a9b8-ccf28ef6a968 | Reconnaissance | PRE | 1.0 |
| Search Open Websites/Domains: Social Media T1593.001 · sub-technique of T1593 STIX ID attack-pattern--bbe5b322-e2af-4a5e-9625-a4e62bf84ed3 | Reconnaissance | PRE | 1.0 |
| Search Threat Vendor Data T1681 STIX ID attack-pattern--63b24abc-5702-4745-b1e4-ac70b20a43f2 | Reconnaissance | PRE | 1.0 |
| Search Victim-Owned Websites T1594 STIX ID attack-pattern--16cdd21f-da65-4e4f-bc04-dd7d198c7b26 | Reconnaissance | PRE | 1.1 |
| Selective Exclusion T1679 STIX ID attack-pattern--9b00925a-7c4b-4e53-bfc8-9a6a806fde03 | Stealth | Windows | 2.0 |
| Server Software Component T1505 STIX ID attack-pattern--d456de47-a16f-4e46-8980-e67478a12dcb | Persistence | ESXi, Linux, macOS, Network Devices, Windows | 1.5 |
| Server Software Component: IIS Components T1505.004 · sub-technique of T1505 STIX ID attack-pattern--b46a801b-fd98-491c-a25a-bca25d6e3001 | Persistence | Windows | 1.1 |
| Server Software Component: SQL Stored Procedures T1505.001 · sub-technique of T1505 STIX ID attack-pattern--f9e9365a-9ca2-4d9c-8e7c-050d73d1101a | Persistence | Linux, Windows | 1.1 |
| Server Software Component: Terminal Services DLL T1505.005 · sub-technique of T1505 STIX ID attack-pattern--379809f6-2fac-42c1-bd2e-e9dee70b27f8 | Persistence | Windows | 1.0 |
| Server Software Component: Transport Agent T1505.002 · sub-technique of T1505 STIX ID attack-pattern--35187df2-31ed-43b6-a1f5-2f1d3d58d3f1 | Persistence | Linux, Windows | 1.1 |
| Server Software Component: Web Shell T1505.003 · sub-technique of T1505 STIX ID attack-pattern--5d0d3609-d06d-49e1-b9c9-b544e0c618cb | Persistence | Linux, macOS, Network Devices, Windows | 1.5 |
| Server Software Component: vSphere Installation Bundles T1505.006 · sub-technique of T1505 STIX ID attack-pattern--f8ba7d61-11c5-4130-bafd-7c3ff5fbf4b5 | Persistence | ESXi | 1.0 |
| Serverless Execution T1648 STIX ID attack-pattern--e848506b-8484-4410-8017-3d235a52f5b3 | Execution | IaaS, Office Suite, SaaS | 1.2 |
| Service Stop T1489 STIX ID attack-pattern--20fb2507-d71c-455d-9b6d-6104461cf26b | Impact | ESXi, IaaS, Linux, macOS, Windows | 1.4 |
| Shared Modules T1129 STIX ID attack-pattern--0a5231ec-41af-4a35-83d0-6bdf11f28c65 | Execution | Linux, macOS, Windows | 2.3 |
| Social Engineering T1684 STIX ID attack-pattern--41e4d77a-6275-4976-9e35-785985598519 | Stealth | Linux, macOS, Office Suite, SaaS, Windows | 1.0 |
| Social Engineering: Email Spoofing T1684.002 · sub-technique of T1684 STIX ID attack-pattern--fcf5bccf-be7a-48ff-b7a7-8d6019279301 | Stealth | Linux, macOS, Office Suite, Windows | 1.0 |
| Social Engineering: Impersonation T1684.001 · sub-technique of T1684 STIX ID attack-pattern--cd92d2b8-ce43-4666-9472-f1b4b9f4f8be | Stealth | Linux, macOS, Office Suite, SaaS, Windows | 1.0 |
| Software Deployment Tools T1072 STIX ID attack-pattern--92a78814-b191-47ca-909c-1ccfe3777414 | Execution, Lateral Movement | Linux, macOS, Network Devices, SaaS, Windows | 3.2 |
| Software Discovery T1518 STIX ID attack-pattern--e3b6daca-e963-4a69-aee6-ed4fd653ad58 | Discovery | ESXi, IaaS, Linux, macOS, Windows | 1.5 |
| Software Discovery: Backup Software Discovery T1518.002 · sub-technique of T1518 STIX ID attack-pattern--4a6cfdae-1417-40c7-a84e-f59d21c58266 | Discovery | Linux, macOS, Windows | 1.0 |
| Software Discovery: Security Software Discovery T1518.001 · sub-technique of T1518 STIX ID attack-pattern--cba37adb-d6fb-4610-b069-dd04c0643384 | Discovery | IaaS, Linux, macOS, Windows | 1.5 |
| Software Extensions T1176 STIX ID attack-pattern--389735f1-f21c-4208-b8f0-f8031e7169b8 | Persistence | Linux, macOS, Windows | 2.0 |
| Software Extensions: Browser Extensions T1176.001 · sub-technique of T1176 STIX ID attack-pattern--278716b1-61ce-4a74-8d17-891d0c494101 | Persistence | Linux, macOS, Windows | 1.1 |
| Software Extensions: IDE Extensions T1176.002 · sub-technique of T1176 STIX ID attack-pattern--66b34be7-6915-4b83-8d5a-b0f0592b5e41 | Persistence | Linux, macOS, Windows | 1.0 |
| Stage Capabilities T1608 STIX ID attack-pattern--84771bc3-f6a0-403e-b144-01af70e5fda0 | Resource Development | PRE | 1.2 |
| Stage Capabilities: Drive-by Target T1608.004 · sub-technique of T1608 STIX ID attack-pattern--31fe0ba2-62fd-4fd9-9293-4043d84f7fe9 | Resource Development | PRE | 1.3 |
| Stage Capabilities: Install Digital Certificate T1608.003 · sub-technique of T1608 STIX ID attack-pattern--c071d8c1-3b3a-4f22-9407-ca4e96921069 | Resource Development | PRE | 1.1 |
| Stage Capabilities: Link Target T1608.005 · sub-technique of T1608 STIX ID attack-pattern--84ae8255-b4f4-4237-b5c5-e717405a9701 | Resource Development | PRE | 1.4 |
| Stage Capabilities: SEO Poisoning T1608.006 · sub-technique of T1608 STIX ID attack-pattern--e5d550f3-2202-4634-85f2-4a200a1d49b3 | Resource Development | PRE | 1.1 |
| Stage Capabilities: Upload Malware T1608.001 · sub-technique of T1608 STIX ID attack-pattern--3ee16395-03f0-4690-a32e-69ce9ada0f9e | Resource Development | PRE | 1.3 |
| Stage Capabilities: Upload Tool T1608.002 · sub-technique of T1608 STIX ID attack-pattern--506f6f49-7045-4156-9007-7474cb44ad6d | Resource Development | PRE | 1.2 |
| Steal Application Access Token T1528 STIX ID attack-pattern--890c9858-598c-401d-a4d5-c67ebcdd703a | Credential Access | Containers, IaaS, Identity Provider, Office Suite, SaaS | 1.5 |
| Steal Web Session Cookie T1539 STIX ID attack-pattern--10ffac09-e42d-4f56-ab20-db94c67d76ff | Credential Access | Linux, macOS, Office Suite, SaaS, Windows | 1.5 |
| Steal or Forge Authentication Certificates T1649 STIX ID attack-pattern--7de1f7ac-5d0c-4c9c-8873-627202205331 | Credential Access | Identity Provider, Linux, macOS, Windows | 1.2 |
| Steal or Forge Kerberos Tickets T1558 STIX ID attack-pattern--3fc01293-ef5e-41c6-86ce-61f10706b64a | Credential Access | Linux, macOS, Windows | 1.7 |
| Steal or Forge Kerberos Tickets: AS-REP Roasting T1558.004 · sub-technique of T1558 STIX ID attack-pattern--3986e7fd-a8e9-4ecb-bfc6-55920855912b | Credential Access | Windows | 1.2 |
| Steal or Forge Kerberos Tickets: Ccache Files T1558.005 · sub-technique of T1558 STIX ID attack-pattern--394220d9-8efc-4252-9040-664f7b115be6 | Credential Access | Linux, macOS | 1.0 |
| Steal or Forge Kerberos Tickets: Golden Ticket T1558.001 · sub-technique of T1558 STIX ID attack-pattern--768dce68-8d0d-477a-b01d-0eea98b963a1 | Credential Access | Windows | 1.2 |
| Steal or Forge Kerberos Tickets: Kerberoasting T1558.003 · sub-technique of T1558 STIX ID attack-pattern--f2877f7f-9a4c-4251-879f-1224e3006bee | Credential Access | Windows | 1.3 |
| Steal or Forge Kerberos Tickets: Silver Ticket T1558.002 · sub-technique of T1558 STIX ID attack-pattern--d273434a-448e-4598-8e14-607f4a0d5e27 | Credential Access | Windows | 1.1 |
| Subvert Trust Controls T1553 STIX ID attack-pattern--b83e166d-13d7-4b52-8677-dff90c548fd7 | Defense Impairment | Linux, macOS, Windows | 2.0 |
| Subvert Trust Controls: Code Signing T1553.002 · sub-technique of T1553 STIX ID attack-pattern--32901740-b42c-4fdd-bc02-345b5dc57082 | Defense Impairment | macOS, Windows | 2.0 |
| Subvert Trust Controls: Code Signing Policy Modification T1553.006 · sub-technique of T1553 STIX ID attack-pattern--565275d5-fcc3-4b66-b4e7-928e4cac6b8c | Defense Impairment | macOS, Windows | 2.0 |
| Subvert Trust Controls: Gatekeeper Bypass T1553.001 · sub-technique of T1553 STIX ID attack-pattern--31a0a2ac-c67c-4a7e-b9ed-6a96477d4e8e | Defense Impairment | macOS | 2.0 |
| Subvert Trust Controls: Install Root Certificate T1553.004 · sub-technique of T1553 STIX ID attack-pattern--c615231b-f253-4f58-9d47-d5b4cbdb6839 | Defense Impairment | Linux, macOS, Windows | 2.0 |
| Subvert Trust Controls: Mark-of-the-Web Bypass T1553.005 · sub-technique of T1553 STIX ID attack-pattern--7e7c2fba-7cca-486c-9582-4c1bb2851961 | Defense Impairment | Windows | 2.0 |
| Subvert Trust Controls: SIP and Trust Provider Hijacking T1553.003 · sub-technique of T1553 STIX ID attack-pattern--543fceb5-cb92-40cb-aacf-6913d4db58bc | Defense Impairment | Windows | 2.0 |
| Supply Chain Compromise T1195 STIX ID attack-pattern--3f18edba-28f4-4bb9-82c3-8aa60dcac5f7 | Initial Access | Linux, macOS, SaaS, Windows | 1.7 |
| Supply Chain Compromise: Compromise Hardware Supply Chain T1195.003 · sub-technique of T1195 STIX ID attack-pattern--39131305-9282-45e4-ac3b-591d2d4fc3ef | Initial Access | Linux, macOS, Windows | 1.1 |
| Supply Chain Compromise: Compromise Software Dependencies and Development Tools T1195.001 · sub-technique of T1195 STIX ID attack-pattern--191cc6af-1bb2-4344-ab5f-28e496638720 | Initial Access | Linux, macOS, Windows | 1.3 |
| Supply Chain Compromise: Compromise Software Supply Chain T1195.002 · sub-technique of T1195 STIX ID attack-pattern--bd369cd9-abb8-41ce-b5bb-fff23ee86c00 | Initial Access | Linux, macOS, Windows | 1.1 |
| System Binary Proxy Execution T1218 STIX ID attack-pattern--457c7820-d331-465a-915e-42f85500ccc4 | Stealth | Linux, macOS, Windows | 4.0 |
| System Binary Proxy Execution: CMSTP T1218.003 · sub-technique of T1218 STIX ID attack-pattern--4cbc6a62-9e34-4f94-8a19-5c1a11392a49 | Stealth | Windows | 3.0 |
| System Binary Proxy Execution: Compiled HTML File T1218.001 · sub-technique of T1218 STIX ID attack-pattern--a6937325-9321-4e2e-bb2b-3ed2d40b2a9d | Stealth | Windows | 3.0 |
| System Binary Proxy Execution: Control Panel T1218.002 · sub-technique of T1218 STIX ID attack-pattern--4ff5d6a8-c062-4c68-a778-36fc5edd564f | Stealth | Windows | 3.0 |
| System Binary Proxy Execution: Electron Applications T1218.015 · sub-technique of T1218 STIX ID attack-pattern--561ae9aa-c28a-4144-9eec-e7027a14c8c3 | Stealth | Linux, macOS, Windows | 2.0 |
| System Binary Proxy Execution: InstallUtil T1218.004 · sub-technique of T1218 STIX ID attack-pattern--2cd950a6-16c4-404a-aa01-044322395107 | Stealth | Windows | 3.0 |
| System Binary Proxy Execution: MMC T1218.014 · sub-technique of T1218 STIX ID attack-pattern--ffbcfdb0-de22-4106-9ed3-fc23c8a01407 | Stealth | Windows | 3.0 |
| System Binary Proxy Execution: Mavinject T1218.013 · sub-technique of T1218 STIX ID attack-pattern--1bae753e-8e52-4055-a66d-2ead90303ca9 | Stealth | Windows | 3.0 |
| System Binary Proxy Execution: Mshta T1218.005 · sub-technique of T1218 STIX ID attack-pattern--840a987a-99bd-4a80-a5c9-0cb2baa6cade | Stealth | Windows | 3.0 |
| System Binary Proxy Execution: Msiexec T1218.007 · sub-technique of T1218 STIX ID attack-pattern--365be77f-fc0e-42ee-bac8-4faf806d9336 | Stealth | Windows | 3.0 |
| System Binary Proxy Execution: Odbcconf T1218.008 · sub-technique of T1218 STIX ID attack-pattern--6e3bd510-6b33-41a4-af80-2d80f3ee0071 | Stealth | Windows | 3.0 |
| System Binary Proxy Execution: Regsvcs/Regasm T1218.009 · sub-technique of T1218 STIX ID attack-pattern--c48a67ee-b657-45c1-91bf-6cdbe27205f8 | Stealth | Windows | 3.0 |
| System Binary Proxy Execution: Regsvr32 T1218.010 · sub-technique of T1218 STIX ID attack-pattern--b97f1d35-4249-4486-a6b5-ee60ccf24fab | Stealth | Windows | 3.0 |
| System Binary Proxy Execution: Rundll32 T1218.011 · sub-technique of T1218 STIX ID attack-pattern--045d0922-2310-4e60-b5e4-3302302cb3c5 | Stealth | Windows | 3.0 |
| System Binary Proxy Execution: Verclsid T1218.012 · sub-technique of T1218 STIX ID attack-pattern--808e6329-ca91-4b87-ac2d-8eadc5f8f327 | Stealth | Windows | 3.0 |
| System Information Discovery T1082 STIX ID attack-pattern--354a7f88-63fb-41b5-a801-ce3b377b36f1 | Discovery | ESXi, IaaS, Linux, macOS, Network Devices, Windows | 3.0 |
| System Location Discovery T1614 STIX ID attack-pattern--c877e33f-1df6-40d6-b1e7-ce70f16f4979 | Discovery | IaaS, Linux, macOS, Windows | 1.1 |
| System Location Discovery: System Language Discovery T1614.001 · sub-technique of T1614 STIX ID attack-pattern--c1b68a96-3c48-49ea-a6c0-9b27359f9c19 | Discovery | Linux, macOS, Windows | 1.1 |
| System Network Configuration Discovery T1016 STIX ID attack-pattern--707399d6-ab3e-4963-9315-d9d3818cd6a0 | Discovery | ESXi, Linux, macOS, Network Devices, Windows | 1.7 |
| System Network Configuration Discovery: Internet Connection Discovery T1016.001 · sub-technique of T1016 STIX ID attack-pattern--132d5b37-aac5-4378-a8dc-3127b18a73dc | Discovery | ESXi, Linux, macOS, Windows | 1.2 |
| System Network Configuration Discovery: Wi-Fi Discovery T1016.002 · sub-technique of T1016 STIX ID attack-pattern--494ab9f0-36e0-4b06-b10d-57285b040a06 | Discovery | Linux, macOS, Windows | 1.1 |
| System Network Connections Discovery T1049 STIX ID attack-pattern--7e150503-88e7-4861-866b-ff1ac82c4475 | Discovery | ESXi, IaaS, Linux, macOS, Network Devices, Windows | 2.5 |
| System Owner/User Discovery T1033 STIX ID attack-pattern--03d7999c-1f4c-42cc-8373-e7690d318104 | Discovery | Linux, macOS, Network Devices, Windows | 1.6 |
| System Script Proxy Execution T1216 STIX ID attack-pattern--f6fe9070-7a65-49ea-ae72-76292f42cebe | Stealth | Windows | 3.0 |
| System Script Proxy Execution: PubPrn T1216.001 · sub-technique of T1216 STIX ID attack-pattern--09cd431f-eaf4-4d2a-acaf-2a7acfe7ed58 | Stealth | Windows | 3.0 |
| System Script Proxy Execution: SyncAppvPublishingServer T1216.002 · sub-technique of T1216 STIX ID attack-pattern--e6f19759-dde3-47fc-99cc-d9f5fa4ade60 | Stealth | Windows | 2.0 |
| System Service Discovery T1007 STIX ID attack-pattern--322bad5a-1c49-4d23-ab79-76d641794afa | Discovery | Linux, macOS, Windows | 1.6 |
| System Services T1569 STIX ID attack-pattern--d157f9d2-d09a-4efa-bb2a-64963f94e253 | Execution | Linux, macOS, Windows | 1.4 |
| System Services: Launchctl T1569.001 · sub-technique of T1569 STIX ID attack-pattern--810aa4ad-61c9-49cb-993f-daa06199421d | Execution | macOS | 1.3 |
| System Services: Service Execution T1569.002 · sub-technique of T1569 STIX ID attack-pattern--f1951e8a-500e-4a26-8803-76d95c4554b4 | Execution | Windows | 1.3 |
| System Services: Systemctl T1569.003 · sub-technique of T1569 STIX ID attack-pattern--4b46767d-4a61-4f30-995e-c19a75c2e536 | Execution | Linux | 1.0 |
| System Shutdown/Reboot T1529 STIX ID attack-pattern--ff73aa03-0090-4464-83ac-f89e233c02bc | Impact | ESXi, Linux, macOS, Network Devices, Windows | 1.5 |
| System Time Discovery T1124 STIX ID attack-pattern--f3c544dc-673c-4ef3-accb-53229f1ae077 | Discovery | ESXi, Linux, macOS, Network Devices, Windows | 1.5 |
| Taint Shared Content T1080 STIX ID attack-pattern--246fd3c7-f5e3-466d-8787-4c13d9e3b61c | Lateral Movement | Linux, macOS, Office Suite, SaaS, Windows | 1.6 |
| Template Injection T1221 STIX ID attack-pattern--dc31fe1e-d722-49da-8f5f-92c7b5aff534 | Stealth | Windows | 2.0 |
| Traffic Signaling T1205 STIX ID attack-pattern--451a9977-d255-43c9-b431-66de80130c8c | Command and Control, Persistence, Stealth | Linux, macOS, Network Devices, Windows | 3.0 |
| Traffic Signaling: Port Knocking T1205.001 · sub-technique of T1205 STIX ID attack-pattern--8868cb5b-d575-4a60-acb2-07d37389a2fd | Command and Control, Persistence, Stealth | Linux, macOS, Network Devices, Windows | 2.0 |
| Traffic Signaling: Socket Filters T1205.002 · sub-technique of T1205 STIX ID attack-pattern--005cc321-08ce-4d17-b1ea-cb5275926520 | Command and Control, Persistence, Stealth | Linux, macOS, Windows | 2.0 |
| Transfer Data to Cloud Account T1537 STIX ID attack-pattern--d4bdbdea-eaec-4071-b4f9-5105e12ea4b6 | Exfiltration | IaaS, Office Suite, SaaS | 1.5 |
| Trusted Developer Utilities Proxy Execution T1127 STIX ID attack-pattern--ff25900d-76d5-449b-a351-8824e62fc81b | Execution, Stealth | Windows | 2.0 |
| Trusted Developer Utilities Proxy Execution: ClickOnce T1127.002 · sub-technique of T1127 STIX ID attack-pattern--cc279e50-df85-4c8e-be80-6dc2eda8849c | Execution, Stealth | Windows | 2.0 |
| Trusted Developer Utilities Proxy Execution: JamPlus T1127.003 · sub-technique of T1127 STIX ID attack-pattern--7d356151-a69d-404e-896b-71618952702a | Execution, Stealth | Windows | 2.0 |
| Trusted Developer Utilities Proxy Execution: MSBuild T1127.001 · sub-technique of T1127 STIX ID attack-pattern--c92e3d68-2349-49e4-a341-7edca2deff96 | Execution, Stealth | Windows | 2.0 |
| Trusted Relationship T1199 STIX ID attack-pattern--9fa07bef-9c81-421e-a8e5-ad4366c5a925 | Initial Access | IaaS, Identity Provider, Linux, macOS, Office Suite, SaaS, Windows | 2.4 |
| Unsecured Credentials T1552 STIX ID attack-pattern--435dfb86-2697-4867-85b5-2fef496c0517 | Credential Access | Containers, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows | 1.5 |
| Unsecured Credentials: Chat Messages T1552.008 · sub-technique of T1552 STIX ID attack-pattern--9664ad0e-789e-40ac-82e2-d7b17fbe8fb3 | Credential Access | Office Suite, SaaS | 1.1 |
| Unsecured Credentials: Cloud Instance Metadata API T1552.005 · sub-technique of T1552 STIX ID attack-pattern--19bf235b-8620-4997-b5b4-94e0659ed7c3 | Credential Access | IaaS | 1.4 |
| Unsecured Credentials: Container API T1552.007 · sub-technique of T1552 STIX ID attack-pattern--f8ef3a62-3f44-40a4-abca-761ab235c436 | Credential Access | Containers | 1.2 |
| Unsecured Credentials: Credentials In Files T1552.001 · sub-technique of T1552 STIX ID attack-pattern--837f9164-50af-4ac0-8219-379d8a74cefc | Credential Access | Containers, IaaS, Linux, macOS, Windows | 1.3 |
| Unsecured Credentials: Credentials in Registry T1552.002 · sub-technique of T1552 STIX ID attack-pattern--341e222a-a6e3-4f6f-b69c-831d792b1580 | Credential Access | Windows | 1.2 |
| Unsecured Credentials: Group Policy Preferences T1552.006 · sub-technique of T1552 STIX ID attack-pattern--8d7bd4f5-3a89-4453-9c82-2c8894d5655e | Credential Access | Windows | 1.1 |
| Unsecured Credentials: Private Keys T1552.004 · sub-technique of T1552 STIX ID attack-pattern--60b508a1-6a5e-46b1-821a-9f7b78752abf | Credential Access | Linux, macOS, Network Devices, Windows | 1.3 |
| Unsecured Credentials: Shell History T1552.003 · sub-technique of T1552 STIX ID attack-pattern--8187bd2a-866f-4457-9009-86b0ddedffa3 | Credential Access | Linux, macOS, Windows | 2.0 |
| Unused/Unsupported Cloud Regions T1535 STIX ID attack-pattern--59bd0dec-f8b2-4b9a-9141-37a1e6899761 | Stealth | IaaS | 2.0 |
| Use Alternate Authentication Material T1550 STIX ID attack-pattern--51a14c76-dd3b-440b-9c20-2bf91d25a814 | Lateral Movement | Containers, IaaS, Identity Provider, Linux, Office Suite, SaaS, Windows | 2.0 |
| Use Alternate Authentication Material: Application Access Token T1550.001 · sub-technique of T1550 STIX ID attack-pattern--f005e783-57d4-4837-88ad-dbe7faee1c51 | Lateral Movement | Containers, IaaS, Identity Provider, Office Suite, SaaS | 2.0 |
| Use Alternate Authentication Material: Pass the Hash T1550.002 · sub-technique of T1550 STIX ID attack-pattern--e624264c-033a-424d-9fd7-fc9c3bbdb03e | Lateral Movement | Windows | 2.0 |
| Use Alternate Authentication Material: Pass the Ticket T1550.003 · sub-technique of T1550 STIX ID attack-pattern--7b211ac6-c815-4189-93a9-ab415deca926 | Lateral Movement | Windows | 2.0 |
| Use Alternate Authentication Material: Web Session Cookie T1550.004 · sub-technique of T1550 STIX ID attack-pattern--c3c8c916-2f3c-4e71-94b2-240bdfc996f0 | Lateral Movement | IaaS, Office Suite, SaaS | 2.0 |
| User Execution T1204 STIX ID attack-pattern--8c32eb4d-805f-4fc5-bf60-c4d476c131b5 | Execution | Containers, IaaS, Linux, macOS, Windows | 1.8 |
| User Execution: Malicious Copy and Paste T1204.004 · sub-technique of T1204 STIX ID attack-pattern--e261a979-f354-41a8-963e-6cadac27c4bf | Execution | Linux, macOS, Windows | 1.1 |
| User Execution: Malicious File T1204.002 · sub-technique of T1204 STIX ID attack-pattern--232b7f21-adf9-4b42-b936-b9d6f7df856e | Execution | Linux, macOS, Windows | 1.6 |
| User Execution: Malicious Image T1204.003 · sub-technique of T1204 STIX ID attack-pattern--b0c74ef9-c61e-4986-88cb-78da98a355ec | Execution | Containers, IaaS | 1.2 |
| User Execution: Malicious Library T1204.005 · sub-technique of T1204 STIX ID attack-pattern--73b24a10-6bf4-4af1-a81e-67b8bcb6c4e6 | Execution | Linux, macOS, Windows | 1.0 |
| User Execution: Malicious Link T1204.001 · sub-technique of T1204 STIX ID attack-pattern--ef67e13e-5598-4adc-bdb2-998225874fa9 | Execution | Linux, macOS, Windows | 1.2 |
| Valid Accounts T1078 STIX ID attack-pattern--b17a1a56-e99c-403c-8948-561df0cffe81 | Initial Access, Persistence, Privilege Escalation, Stealth | Containers, ESXi, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows | 3.0 |
| Valid Accounts: Cloud Accounts T1078.004 · sub-technique of T1078 STIX ID attack-pattern--f232fa7a-025c-4d43-abc7-318e81a73d65 | Initial Access, Persistence, Privilege Escalation, Stealth | IaaS, Identity Provider, Office Suite, SaaS | 2.0 |
| Valid Accounts: Default Accounts T1078.001 · sub-technique of T1078 STIX ID attack-pattern--6151cbea-819b-455a-9fa6-99a1cc58797d | Initial Access, Persistence, Privilege Escalation, Stealth | Containers, ESXi, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows | 2.0 |
| Valid Accounts: Domain Accounts T1078.002 · sub-technique of T1078 STIX ID attack-pattern--c3d4bdd9-2cfe-4a80-9d0c-07a29ecdce8f | Initial Access, Persistence, Privilege Escalation, Stealth | ESXi, Linux, macOS, Windows | 2.0 |
| Valid Accounts: Local Accounts T1078.003 · sub-technique of T1078 STIX ID attack-pattern--fdc47f44-dd32-4b99-af5f-209f556f63c2 | Initial Access, Persistence, Privilege Escalation, Stealth | Containers, ESXi, Linux, macOS, Network Devices, Windows | 2.0 |
| Video Capture T1125 STIX ID attack-pattern--6faf650d-bf31-4eb4-802d-1000cf38efaf | Collection | Linux, macOS, Windows | 1.2 |
| Virtual Machine Discovery T1673 STIX ID attack-pattern--6bc7f9aa-b91f-4b23-84b8-5e756eba68eb | Discovery | ESXi, Linux, macOS, Windows | 1.0 |
| Virtualization/Sandbox Evasion T1497 STIX ID attack-pattern--82caa33e-d11a-433a-94ea-9b5a5fbef81d | Discovery, Stealth | Linux, macOS, Windows | 2.0 |
| Virtualization/Sandbox Evasion: System Checks T1497.001 · sub-technique of T1497 STIX ID attack-pattern--29be378d-262d-4e99-b00d-852d573628e6 | Discovery, Stealth | Linux, macOS, Windows | 3.0 |
| Virtualization/Sandbox Evasion: Time Based Checks T1497.003 · sub-technique of T1497 STIX ID attack-pattern--4bed873f-0b7d-41d4-b93a-b6905d1f90b0 | Discovery, Stealth | Linux, macOS, Windows | 3.0 |
| Virtualization/Sandbox Evasion: User Activity Based Checks T1497.002 · sub-technique of T1497 STIX ID attack-pattern--91541e7e-b969-40c6-bbd8-1b5352ec2938 | Discovery, Stealth | Linux, macOS, Windows | 2.0 |
| Weaken Encryption T1600 STIX ID attack-pattern--1f9012ef-1e10-4e48-915e-e03563435fe8 | Defense Impairment | Network Devices | 2.0 |
| Weaken Encryption: Disable Crypto Hardware T1600.002 · sub-technique of T1600 STIX ID attack-pattern--7efba77e-3bc4-4ca5-8292-d8201dcd64b5 | Defense Impairment | Network Devices | 2.0 |
| Weaken Encryption: Reduce Key Space T1600.001 · sub-technique of T1600 STIX ID attack-pattern--3a40f208-a9c1-4efa-a598-4003c3681fb8 | Defense Impairment | Network Devices | 2.0 |
| Web Service T1102 STIX ID attack-pattern--830c9528-df21-472c-8c14-a036bf17d665 | Command and Control | ESXi, Linux, macOS, Windows | 1.3 |
| Web Service: Bidirectional Communication T1102.002 · sub-technique of T1102 STIX ID attack-pattern--be055942-6e63-49d7-9fa1-9cb7d8a8f3f4 | Command and Control | ESXi, Linux, macOS, Windows | 1.1 |
| Web Service: Dead Drop Resolver T1102.001 · sub-technique of T1102 STIX ID attack-pattern--f7827069-0bf2-4764-af4f-23fae0d181b7 | Command and Control | ESXi, Linux, macOS, Windows | 1.1 |
| Web Service: One-Way Communication T1102.003 · sub-technique of T1102 STIX ID attack-pattern--9c99724c-a483-4d60-ad9d-7f004e42e8e8 | Command and Control | ESXi, Linux, macOS, Windows | 1.1 |
| Wi-Fi Networks T1669 STIX ID attack-pattern--fde016f6-211a-41c8-a4ab-301f1e419c62 | Initial Access | Linux, macOS, Network Devices, Windows | 1.0 |
| Windows Management Instrumentation T1047 STIX ID attack-pattern--01a5a209-b94c-450b-b7f9-946497d91055 | Execution | Windows | 1.6 |
| XSL Script Processing T1220 STIX ID attack-pattern--ebbe170d-aa74-4946-8511-9921243415a3 | Stealth | Windows | 2.0 |
Try a broader query or remove the tactic filter.
Privacy floor
Cross-customer cells require 5 contributors Suppressed results display “Insufficient data,” never zero. No people, hostnames, raw content, or exact timestamps cross tenant boundaries.Reference data
Based in part on MITRE ATT&CK® v19.1 STIX 2.1 projection · snapshot retrieved 2026-07-27T03:45:00Z · no MITRE endorsement implied. Official dataset LicenseCross-framework context
Versioned OWASP risks, related—not equivalent Fortitude-authored crosswalks may be primary, supporting, conditional, or explicitly unmapped. No OWASP endorsement implied. OWASP Top 10 2025 OWASP Top 10 for LLM Applications 2025 OWASP Top 10 for Agentic Applications 2026 OWASP MCP Top 10 2025 · Beta Sources retrieved 2026-07-26 · OWASP terms