ATT&CKTechniques

Techniques

475 results

IDNameTacticsSub-techniquesExamples
T1001.001 Junk Data 018
T1001.002 Steganography 013
T1001.003 Protocol or Service Impersonation 022
T1003.001 LSASS Memory 079
T1003.002 Security Account Manager 036
T1003.003 NTDS 026
T1003.004 LSA Secrets 019
T1003.005 Cached Domain Credentials 08
T1003.006 DCSync 08
T1003.007 Proc Filesystem 05
T1003.008 /etc/passwd and /etc/shadow 02
T1011.001 Exfiltration Over Bluetooth 01
T1016.001 Internet Connection Discovery 026
T1016.002 Wi-Fi Discovery 07
T1020.001 Traffic Duplication 00
T1021.001 Remote Desktop Protocol 063
T1021.002 SMB/Windows Admin Shares 065
T1021.003 Distributed Component Object Model 03
T1021.004 SSH 027
T1021.005 VNC 011
T1021.006 Windows Remote Management 010
T1021.007 Cloud Services 05
T1021.008 Direct Cloud VM Connections 00
T1027.001 Binary Padding 030
T1027.002 Software Packing 0103
T1027.003 Steganography 031
T1027.004 Compile After Delivery 010
T1027.005 Indicator Removal from Tools 018
T1027.006 HTML Smuggling 03
T1027.007 Dynamic API Resolution 020
T1027.008 Stripped Payloads 02
T1027.009 Embedded Payloads 024
T1027.010 Command Obfuscation 070
T1027.011 Fileless Storage 031
T1027.012 LNK Icon Smuggling 04
T1027.013 Encrypted/Encoded File 0248
T1027.014 Polymorphic Code 01
T1027.015 Compression 035
T1027.016 Junk Code Insertion 024
T1027.017 SVG Smuggling 00
T1027.018 Invisible Unicode 01
T1036.001 Invalid Code Signature 09
T1036.002 Right-to-Left Override 05
T1036.003 Rename Legitimate Utilities 011
T1036.004 Masquerade Task or Service 093
T1036.005 Match Legitimate Resource Name or Location 0221
T1036.006 Space after Filename 02
T1036.007 Double File Extension 05
T1036.008 Masquerade File Type 020
T1036.009 Break Process Trees 02

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.