222 results
| ID | Name | Tactics | Sub-techniques | Examples |
|---|---|---|---|---|
| T1001 | Data Obfuscation | 3 | 15 | |
| T1003 | OS Credential Dumping | 8 | 20 | |
| T1005 | Data from Local System | 0 | 230 | |
| T1006 | Direct Volume Access | 0 | 5 | |
| T1007 | System Service Discovery | 0 | 69 | |
| T1008 | Fallback Channels | 0 | 57 | |
| T1010 | Application Window Discovery | 0 | 37 | |
| T1011 | Exfiltration Over Other Network Medium | 1 | 0 | |
| T1012 | Query Registry | 0 | 119 | |
| T1014 | Rootkit | 0 | 32 | |
| T1016 | System Network Configuration Discovery | 2 | 289 | |
| T1018 | Remote System Discovery | 0 | 104 | |
| T1020 | Automated Exfiltration | 1 | 31 | |
| T1021 | Remote Services | 8 | 7 | |
| T1025 | Data from Removable Media | 0 | 24 | |
| T1027 | Obfuscated Files or Information | 18 | 160 | |
| T1029 | Scheduled Transfer | 0 | 18 | |
| T1030 | Data Transfer Size Limits | 0 | 21 | |
| T1033 | System Owner/User Discovery | 0 | 244 | |
| T1036 | Masquerading | 12 | 60 | |
| T1037 | Boot or Logon Initialization Scripts | 5 | 8 | |
| T1039 | Data from Network Shared Drive | 0 | 13 | |
| T1040 | Network Sniffing | 0 | 28 | |
| T1041 | Exfiltration Over C2 Channel | 0 | 203 | |
| T1046 | Network Service Discovery | 0 | 73 | |
| T1047 | Windows Management Instrumentation | 0 | 147 | |
| T1048 | Exfiltration Over Alternative Protocol | 3 | 9 | |
| T1049 | System Network Connections Discovery | 0 | 98 | |
| T1052 | Exfiltration Over Physical Medium | 1 | 0 | |
| T1053 | Scheduled Task/Job | 5 | 2 | |
| T1055 | Process Injection | 12 | 87 | |
| T1056 | Input Capture | 4 | 12 | |
| T1057 | Process Discovery | 0 | 319 | |
| T1059 | Command and Scripting Interpreter | 13 | 44 | |
| T1068 | Exploitation for Privilege Escalation | 0 | 43 | |
| T1069 | Permission Groups Discovery | 3 | 13 | |
| T1070 | Indicator Removal | 8 | 33 | |
| T1071 | Application Layer Protocol | 5 | 16 | |
| T1072 | Software Deployment Tools | 0 | 10 | |
| T1074 | Data Staged | 2 | 9 | |
| T1078 | Valid Accounts | 4 | 65 | |
| T1080 | Taint Shared Content | 0 | 12 | |
| T1082 | System Information Discovery | 0 | 427 | |
| T1083 | File and Directory Discovery | 0 | 373 | |
| T1087 | Account Discovery | 4 | 10 | |
| T1090 | Proxy | 4 | 76 | |
| T1091 | Replication Through Removable Media | 0 | 28 | |
| T1092 | Communication Through Removable Media | 0 | 3 | |
| T1095 | Non-Application Layer Protocol | 0 | 108 | |
| T1098 | Account Manipulation | 7 | 9 |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.