Tactic.View on attack.mitre.org
The adversary is trying to get into your network.
Initial Access consists of techniques that use various entry vectors to gain their initial foothold within a network. Techniques used to gain a foothold include targeted spearphishing and exploiting weaknesses on public-facing web servers. Footholds gained through initial access may allow for continued access, like valid accounts and use of external remote services, or may be limited-use due to changing passwords.
| ID | Name | Sub-techniques | Examples |
|---|---|---|---|
| T1078 | Valid Accounts | 4 | 149 |
| T1091 | Replication Through Removable Media | 0 | 28 |
| T1133 | External Remote Services | 0 | 43 |
| T1189 | Drive-by Compromise | 0 | 44 |
| T1190 | Exploit Public-Facing Application | 0 | 75 |
| T1195 | Supply Chain Compromise | 3 | 28 |
| T1199 | Trusted Relationship | 0 | 13 |
| T1200 | Hardware Additions | 0 | 1 |
| T1566 | Phishing | 4 | 264 |
| T1659 | Content Injection | 0 | 2 |
| T1669 | Wi-Fi Networks | 0 | 2 |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.