MITRE ATT&CK knowledge base

Techniques, groups, software and campaigns, linked to the procedure examples and reports behind them. Find what attackers do, then check that your detections cover it.

Tactics

An attack moves left to right through these goals. Each box shows how many techniques serve it.

  1. Reconnaissance12 techniques
  2. Resource Development9 techniques
  3. Initial Access11 techniques
  4. Execution20 techniques
  5. Persistence22 techniques
  6. Privilege Escalation13 techniques
  7. Stealth30 techniques
  8. Defense Impairment18 techniques
  9. Credential Access17 techniques
  10. Discovery34 techniques
  11. Lateral Movement9 techniques
  12. Collection17 techniques
  13. Command and Control18 techniques
  14. Exfiltration9 techniques
  15. Impact15 techniques

Most documented techniques

TechniqueExamples
T1059 Command and Scripting Interpreter1033
T1027 Obfuscated Files or Information815
T1071 Application Layer Protocol547
T1105 Ingress Tool Transfer520
T1070 Indicator Removal443
T1036 Masquerading437
T1082 System Information Discovery427
T1083 File and Directory Discovery373
T1140 Deobfuscate/Decode Files or Information353
T1547 Boot or Logon Autostart Execution333

Groups with the widest coverage

Software with the widest coverage

Browse everything

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.