Tactic.View on attack.mitre.org
The adversary is trying to run malicious code.
Execution consists of techniques that result in adversary-controlled code running on a local or remote system. Techniques that run malicious code are often paired with techniques from all other tactics to achieve broader goals, like exploring a network or stealing data. For example, an adversary might use a remote access tool to run a PowerShell script that does Remote System Discovery.
| ID | Name | Sub-techniques | Examples |
|---|---|---|---|
| T1047 | Windows Management Instrumentation | 0 | 147 |
| T1053 | Scheduled Task/Job | 5 | 216 |
| T1059 | Command and Scripting Interpreter | 13 | 1033 |
| T1072 | Software Deployment Tools | 0 | 10 |
| T1106 | Native API | 0 | 228 |
| T1127 | Trusted Developer Utilities Proxy Execution | 3 | 5 |
| T1129 | Shared Modules | 0 | 22 |
| T1197 | BITS Jobs | 0 | 13 |
| T1203 | Exploitation for Client Execution | 0 | 61 |
| T1204 | User Execution | 5 | 296 |
| T1559 | Inter-Process Communication | 3 | 60 |
| T1569 | System Services | 3 | 80 |
| T1574 | Hijack Execution Flow | 12 | 152 |
| T1609 | Container Administration Command | 0 | 8 |
| T1610 | Deploy Container | 0 | 4 |
| T1648 | Serverless Execution | 0 | 1 |
| T1651 | Cloud Administration Command | 0 | 4 |
| T1674 | Input Injection | 0 | 1 |
| T1675 | ESXi Administration Command | 0 | 2 |
| T1677 | Poisoned Pipeline Execution | 0 | 4 |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.