222 results
| ID | Name | Tactics | Sub-techniques | Examples |
|---|---|---|---|---|
| T1480 | Execution Guardrails | 2 | 50 | |
| T1482 | Domain Trust Discovery | 0 | 33 | |
| T1484 | Domain or Tenant Policy Modification | 2 | 0 | |
| T1485 | Data Destruction | 1 | 40 | |
| T1486 | Data Encrypted for Impact | 0 | 85 | |
| T1489 | Service Stop | 0 | 54 | |
| T1490 | Inhibit System Recovery | 0 | 56 | |
| T1491 | Defacement | 2 | 0 | |
| T1495 | Firmware Corruption | 0 | 3 | |
| T1496 | Resource Hijacking | 4 | 0 | |
| T1497 | Virtualization/Sandbox Evasion | 3 | 27 | |
| T1498 | Network Denial of Service | 2 | 3 | |
| T1499 | Endpoint Denial of Service | 4 | 3 | |
| T1505 | Server Software Component | 6 | 0 | |
| T1518 | Software Discovery | 2 | 53 | |
| T1525 | Implant Internal Image | 0 | 0 | |
| T1526 | Cloud Service Discovery | 0 | 6 | |
| T1528 | Steal Application Access Token | 0 | 13 | |
| T1529 | System Shutdown/Reboot | 0 | 31 | |
| T1530 | Data from Cloud Storage | 0 | 12 | |
| T1531 | Account Access Removal | 0 | 6 | |
| T1534 | Internal Spearphishing | 0 | 8 | |
| T1535 | Unused/Unsupported Cloud Regions | 0 | 0 | |
| T1537 | Transfer Data to Cloud Account | 0 | 3 | |
| T1538 | Cloud Service Dashboard | 0 | 1 | |
| T1539 | Steal Web Session Cookie | 0 | 29 | |
| T1542 | Pre-OS Boot | 5 | 0 | |
| T1543 | Create or Modify System Process | 5 | 8 | |
| T1546 | Event Triggered Execution | 18 | 5 | |
| T1547 | Boot or Logon Autostart Execution | 14 | 6 | |
| T1548 | Abuse Elevation Control Mechanism | 6 | 2 | |
| T1550 | Use Alternate Authentication Material | 4 | 2 | |
| T1552 | Unsecured Credentials | 8 | 6 | |
| T1553 | Subvert Trust Controls | 6 | 2 | |
| T1554 | Compromise Host Software Binary | 0 | 24 | |
| T1555 | Credentials from Password Stores | 6 | 40 | |
| T1556 | Modify Authentication Process | 9 | 6 | |
| T1557 | Adversary-in-the-Middle | 4 | 9 | |
| T1558 | Steal or Forge Kerberos Tickets | 5 | 2 | |
| T1559 | Inter-Process Communication | 3 | 18 | |
| T1560 | Archive Collected Data | 3 | 57 | |
| T1561 | Disk Wipe | 2 | 0 | |
| T1563 | Remote Service Session Hijacking | 2 | 0 | |
| T1564 | Hide Artifacts | 14 | 7 | |
| T1565 | Data Manipulation | 3 | 2 | |
| T1566 | Phishing | 4 | 11 | |
| T1567 | Exfiltration Over Web Service | 4 | 16 | |
| T1568 | Dynamic Resolution | 3 | 24 | |
| T1569 | System Services | 3 | 0 | |
| T1570 | Lateral Tool Transfer | 0 | 55 |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.