ATT&CKTechniques

Techniques

475 results

IDNameTacticsSub-techniquesExamples
T1036.010 Masquerade Account Name 07
T1036.011 Overwrite Process Arguments 01
T1036.012 Browser Fingerprint 01
T1037.001 Logon Script (Windows) 06
T1037.002 Login Hook 00
T1037.003 Network Logon Script 00
T1037.004 RC Scripts 07
T1037.005 Startup Items 01
T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol 00
T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol 08
T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol 035
T1052.001 Exfiltration over USB 07
T1053.002 At 06
T1053.003 Cron 016
T1053.005 Scheduled Task 0190
T1053.006 Systemd Timers 02
T1053.007 Container Orchestration Job 00
T1055.001 Dynamic-link Library Injection 067
T1055.002 Portable Executable Injection 015
T1055.003 Thread Execution Hijacking 04
T1055.004 Asynchronous Procedure Call 013
T1055.005 Thread Local Storage 02
T1055.008 Ptrace System Calls 01
T1055.009 Proc Memory 01
T1055.011 Extra Window Memory Injection 02
T1055.012 Process Hollowing 043
T1055.013 Process Doppelgänging 03
T1055.014 VDSO Hijacking 00
T1055.015 ListPlanting 01
T1056.001 Keylogging 0155
T1056.002 GUI Input Capture 015
T1056.003 Web Portal Capture 06
T1056.004 Credential API Hooking 012
T1059.001 PowerShell 0233
T1059.002 AppleScript 06
T1059.003 Windows Command Shell 0386
T1059.004 Unix Shell 066
T1059.005 Visual Basic 0131
T1059.006 Python 063
T1059.007 JavaScript 075
T1059.008 Network Device CLI 05
T1059.009 Cloud API 06
T1059.010 AutoHotKey & AutoIT 06
T1059.011 Lua 05
T1059.012 Hypervisor CLI 04
T1059.013 Container CLI/API 03
T1069.001 Local Groups 032
T1069.002 Domain Groups 038
T1069.003 Cloud Groups 05
T1070.003 Clear Command History 011

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.