475 results
| ID | Name | Tactics | Sub-techniques | Examples |
|---|---|---|---|---|
| T1036.010 | Masquerade Account Name | 0 | 7 | |
| T1036.011 | Overwrite Process Arguments | 0 | 1 | |
| T1036.012 | Browser Fingerprint | 0 | 1 | |
| T1037.001 | Logon Script (Windows) | 0 | 6 | |
| T1037.002 | Login Hook | 0 | 0 | |
| T1037.003 | Network Logon Script | 0 | 0 | |
| T1037.004 | RC Scripts | 0 | 7 | |
| T1037.005 | Startup Items | 0 | 1 | |
| T1048.001 | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | 0 | 0 | |
| T1048.002 | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol | 0 | 8 | |
| T1048.003 | Exfiltration Over Unencrypted Non-C2 Protocol | 0 | 35 | |
| T1052.001 | Exfiltration over USB | 0 | 7 | |
| T1053.002 | At | 0 | 6 | |
| T1053.003 | Cron | 0 | 16 | |
| T1053.005 | Scheduled Task | 0 | 190 | |
| T1053.006 | Systemd Timers | 0 | 2 | |
| T1053.007 | Container Orchestration Job | 0 | 0 | |
| T1055.001 | Dynamic-link Library Injection | 0 | 67 | |
| T1055.002 | Portable Executable Injection | 0 | 15 | |
| T1055.003 | Thread Execution Hijacking | 0 | 4 | |
| T1055.004 | Asynchronous Procedure Call | 0 | 13 | |
| T1055.005 | Thread Local Storage | 0 | 2 | |
| T1055.008 | Ptrace System Calls | 0 | 1 | |
| T1055.009 | Proc Memory | 0 | 1 | |
| T1055.011 | Extra Window Memory Injection | 0 | 2 | |
| T1055.012 | Process Hollowing | 0 | 43 | |
| T1055.013 | Process Doppelgänging | 0 | 3 | |
| T1055.014 | VDSO Hijacking | 0 | 0 | |
| T1055.015 | ListPlanting | 0 | 1 | |
| T1056.001 | Keylogging | 0 | 155 | |
| T1056.002 | GUI Input Capture | 0 | 15 | |
| T1056.003 | Web Portal Capture | 0 | 6 | |
| T1056.004 | Credential API Hooking | 0 | 12 | |
| T1059.001 | PowerShell | 0 | 233 | |
| T1059.002 | AppleScript | 0 | 6 | |
| T1059.003 | Windows Command Shell | 0 | 386 | |
| T1059.004 | Unix Shell | 0 | 66 | |
| T1059.005 | Visual Basic | 0 | 131 | |
| T1059.006 | Python | 0 | 63 | |
| T1059.007 | JavaScript | 0 | 75 | |
| T1059.008 | Network Device CLI | 0 | 5 | |
| T1059.009 | Cloud API | 0 | 6 | |
| T1059.010 | AutoHotKey & AutoIT | 0 | 6 | |
| T1059.011 | Lua | 0 | 5 | |
| T1059.012 | Hypervisor CLI | 0 | 4 | |
| T1059.013 | Container CLI/API | 0 | 3 | |
| T1069.001 | Local Groups | 0 | 32 | |
| T1069.002 | Domain Groups | 0 | 38 | |
| T1069.003 | Cloud Groups | 0 | 5 | |
| T1070.003 | Clear Command History | 0 | 11 |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.