222 results
| ID | Name | Tactics | Sub-techniques | Examples |
|---|---|---|---|---|
| T1102 | Web Service | 3 | 50 | |
| T1104 | Multi-Stage Channels | 0 | 15 | |
| T1105 | Ingress Tool Transfer | 0 | 520 | |
| T1106 | Native API | 0 | 228 | |
| T1110 | Brute Force | 4 | 25 | |
| T1111 | Multi-Factor Authentication Interception | 0 | 9 | |
| T1112 | Modify Registry | 0 | 173 | |
| T1113 | Screen Capture | 0 | 171 | |
| T1114 | Email Collection | 3 | 6 | |
| T1115 | Clipboard Data | 0 | 46 | |
| T1119 | Automated Collection | 0 | 75 | |
| T1120 | Peripheral Device Discovery | 0 | 58 | |
| T1123 | Audio Capture | 0 | 32 | |
| T1124 | System Time Discovery | 0 | 100 | |
| T1125 | Video Capture | 0 | 35 | |
| T1127 | Trusted Developer Utilities Proxy Execution | 3 | 0 | |
| T1129 | Shared Modules | 0 | 22 | |
| T1132 | Data Encoding | 2 | 8 | |
| T1133 | External Remote Services | 0 | 43 | |
| T1134 | Access Token Manipulation | 5 | 23 | |
| T1135 | Network Share Discovery | 0 | 77 | |
| T1136 | Create Account | 3 | 5 | |
| T1137 | Office Application Startup | 6 | 2 | |
| T1140 | Deobfuscate/Decode Files or Information | 0 | 353 | |
| T1176 | Software Extensions | 2 | 0 | |
| T1185 | Browser Session Hijacking | 0 | 16 | |
| T1187 | Forced Authentication | 0 | 3 | |
| T1189 | Drive-by Compromise | 0 | 44 | |
| T1190 | Exploit Public-Facing Application | 0 | 75 | |
| T1195 | Supply Chain Compromise | 3 | 5 | |
| T1197 | BITS Jobs | 0 | 13 | |
| T1199 | Trusted Relationship | 0 | 13 | |
| T1200 | Hardware Additions | 0 | 1 | |
| T1201 | Password Policy Discovery | 0 | 8 | |
| T1202 | Indirect Command Execution | 0 | 4 | |
| T1203 | Exploitation for Client Execution | 0 | 61 | |
| T1204 | User Execution | 5 | 5 | |
| T1205 | Traffic Signaling | 2 | 23 | |
| T1207 | Rogue Domain Controller | 0 | 1 | |
| T1210 | Exploitation of Remote Services | 0 | 25 | |
| T1211 | Exploitation for Stealth | 0 | 2 | |
| T1212 | Exploitation for Credential Access | 0 | 2 | |
| T1213 | Data from Information Repositories | 6 | 4 | |
| T1216 | System Script Proxy Execution | 2 | 0 | |
| T1217 | Browser Information Discovery | 0 | 29 | |
| T1218 | System Binary Proxy Execution | 14 | 2 | |
| T1219 | Remote Access Tools | 3 | 22 | |
| T1220 | XSL Script Processing | 0 | 4 | |
| T1221 | Template Injection | 0 | 12 | |
| T1222 | File and Directory Permissions Modification | 2 | 1 |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.