250 techniques38% have ≥1 framework
ATT&CKATT&CK Matrix — coloured by compliance coverage
250 top-level ATT&CK Enterprise techniques across 14 tactics. Heat = distinct frameworks that map to a technique via the cs-graph corroborator. Authored by Adam Lundqvist.
compliance coverage
0
1
2-3
4-5
6+
ISO 27001 · 202DORA · 186CIS v8 · 159NIS2 · 140GDPR · 88OWASP Top 10 · 80NIST CSF · 80OWASP LLM Top 10 · 68PCI DSS v4 · 68OWASP API Top 10 · 67EU AI Act · 59iso27701 · 37EU CRA · 26tiber_eu · 24
TA0001Initial Access10 techniques
T1078
▾ 4
T1078 Valid Accounts
Mapped by 12 frameworks: EU AI Act, CIS v8, DORA, GDPR, ISO 27001, iso27701, NIS2, NIST CSF, OWASP API Top 10, OWASP LLM Top 10, OWASP Top 10, PCI DSS v4
Tactic: defense-evasion, persistence, privilege-escalation, initial-access · Click to open
T1190
T1190 Exploit Public-Facing Application
Mapped by 11 frameworks: EU AI Act, CIS v8, DORA, GDPR, ISO 27001, NIS2, NIST CSF, OWASP API Top 10, OWASP LLM Top 10, OWASP Top 10, PCI DSS v4
Tactic: initial-access · Click to open
T1133
T1133 External Remote Services
Mapped by 9 frameworks: CIS v8, DORA, GDPR, ISO 27001, NIS2, NIST CSF, OWASP API Top 10, OWASP LLM Top 10, PCI DSS v4
Tactic: persistence, initial-access · Click to open
T1566
▾ 4
T1566 Phishing
Mapped by 9 frameworks: EU AI Act, CIS v8, DORA, GDPR, ISO 27001, iso27701, NIS2, NIST CSF, PCI DSS v4
Tactic: initial-access · Click to open
T1195
▾ 3
T1195 Supply Chain Compromise
Mapped by 2 frameworks: DORA, OWASP LLM Top 10
Tactic: initial-access · Click to open
T1189
T1189 Drive-by Compromise
Mapped by 1 framework: ISO 27001
Tactic: initial-access · Click to open
T1091
T1091 Replication Through Removable Media
Not mapped by any framework
Tactic: lateral-movement, initial-access · Click to open
T1199
T1199 Trusted Relationship
Not mapped by any framework
Tactic: initial-access · Click to open
T1200
T1200 Hardware Additions
Not mapped by any framework
Tactic: initial-access · Click to open
T1659
T1659 Content Injection
Not mapped by any framework
Tactic: initial-access, command-and-control · Click to open
TA0002Execution14 techniques
T1059
▾ 9
T1059 Command and Scripting Interpreter
Mapped by 10 frameworks: EU AI Act, CIS v8, DORA, GDPR, ISO 27001, iso27701, NIS2, NIST CSF, OWASP LLM Top 10, OWASP Top 10
Tactic: execution · Click to open
T1053
▾ 7
T1053 Scheduled Task/Job
Mapped by 5 frameworks: CIS v8, DORA, GDPR, ISO 27001, NIS2
Tactic: execution, persistence, privilege-escalation · Click to open
T1047
T1047 Windows Management Instrumentation
Mapped by 4 frameworks: CIS v8, DORA, GDPR, NIS2
Tactic: execution · Click to open
T1203
T1203 Exploitation for Client Execution
Mapped by 3 frameworks: ISO 27001, OWASP LLM Top 10, OWASP Top 10
Tactic: execution · Click to open
T1072
T1072 Software Deployment Tools
Not mapped by any framework
Tactic: execution, lateral-movement · Click to open
T1106
T1106 Native API
Not mapped by any framework
Tactic: execution · Click to open
T1129
T1129 Shared Modules
Not mapped by any framework
Tactic: execution · Click to open
T1204
▾ 3
T1204 User Execution
Not mapped by any framework
Tactic: execution · Click to open
T1559
▾ 3
T1559 Inter-Process Communication
Not mapped by any framework
Tactic: execution · Click to open
T1569
▾ 2
T1569 System Services
Not mapped by any framework
Tactic: execution · Click to open
T1609
T1609 Container Administration Command
Not mapped by any framework
Tactic: execution · Click to open
T1610
T1610 Deploy Container
Not mapped by any framework
Tactic: defense-evasion, execution · Click to open
T1648
T1648 Serverless Execution
Not mapped by any framework
Tactic: execution · Click to open
T1651
T1651 Cloud Administration Command
Not mapped by any framework
Tactic: execution · Click to open
TA0003Persistence22 techniques
T1078
▾ 4
T1078 Valid Accounts
Mapped by 12 frameworks: EU AI Act, CIS v8, DORA, GDPR, ISO 27001, iso27701, NIS2, NIST CSF, OWASP API Top 10, OWASP LLM Top 10, OWASP Top 10, PCI DSS v4
Tactic: defense-evasion, persistence, privilege-escalation, initial-access · Click to open
T1547
▾ 15
T1547 Boot or Logon Autostart Execution
Mapped by 10 frameworks: EU AI Act, CIS v8, DORA, GDPR, ISO 27001, NIS2, NIST CSF, OWASP LLM Top 10, OWASP Top 10, PCI DSS v4
Tactic: persistence, privilege-escalation · Click to open
T1133
T1133 External Remote Services
Mapped by 9 frameworks: CIS v8, DORA, GDPR, ISO 27001, NIS2, NIST CSF, OWASP API Top 10, OWASP LLM Top 10, PCI DSS v4
Tactic: persistence, initial-access · Click to open
T1098
▾ 6
T1098 Account Manipulation
Mapped by 7 frameworks: CIS v8, DORA, ISO 27001, NIS2, NIST CSF, OWASP API Top 10, OWASP Top 10
Tactic: persistence, privilege-escalation · Click to open
T1053
▾ 7
T1053 Scheduled Task/Job
Mapped by 5 frameworks: CIS v8, DORA, GDPR, ISO 27001, NIS2
Tactic: execution, persistence, privilege-escalation · Click to open
T1136
▾ 3
T1136 Create Account
Mapped by 5 frameworks: CIS v8, ISO 27001, OWASP API Top 10, OWASP Top 10, PCI DSS v4
Tactic: persistence · Click to open
T1037
▾ 5
T1037 Boot or Logon Initialization Scripts
Mapped by 2 frameworks: CIS v8, NIS2
Tactic: persistence, privilege-escalation · Click to open
T1543
▾ 4
T1543 Create or Modify System Process
Mapped by 1 framework: ISO 27001
Tactic: persistence, privilege-escalation · Click to open
T1574
▾ 12
T1574 Hijack Execution Flow
Mapped by 1 framework: ISO 27001
Tactic: persistence, privilege-escalation, defense-evasion · Click to open
T1137
▾ 6
T1137 Office Application Startup
Not mapped by any framework
Tactic: persistence · Click to open
T1176
T1176 Browser Extensions
Not mapped by any framework
Tactic: persistence · Click to open
T1197
T1197 BITS Jobs
Not mapped by any framework
Tactic: defense-evasion, persistence · Click to open
T1205
▾ 2
T1205 Traffic Signaling
Not mapped by any framework
Tactic: defense-evasion, persistence, command-and-control · Click to open
T1504
T1504 PowerShell Profile
Not mapped by any framework
Tactic: persistence, privilege-escalation · Click to open
T1505
▾ 5
T1505 Server Software Component
Not mapped by any framework
Tactic: persistence · Click to open
T1519
T1519 Emond
Not mapped by any framework
Tactic: persistence, privilege-escalation · Click to open
T1525
T1525 Implant Internal Image
Not mapped by any framework
Tactic: persistence · Click to open
T1542
▾ 5
T1542 Pre-OS Boot
Not mapped by any framework
Tactic: defense-evasion, persistence · Click to open
T1546
▾ 16
T1546 Event Triggered Execution
Not mapped by any framework
Tactic: privilege-escalation, persistence · Click to open
T1554
T1554 Compromise Client Software Binary
Not mapped by any framework
Tactic: persistence · Click to open
T1556
▾ 8
T1556 Modify Authentication Process
Not mapped by any framework
Tactic: credential-access, defense-evasion, persistence · Click to open
T1653
T1653 Power Settings
Not mapped by any framework
Tactic: persistence · Click to open
TA0004Privilege Escalation18 techniques
T1068
T1068 Exploitation for Privilege Escalation
Mapped by 13 frameworks: EU AI Act, CIS v8, EU CRA, DORA, GDPR, ISO 27001, iso27701, NIS2, NIST CSF, OWASP API Top 10, OWASP LLM Top 10, OWASP Top 10, PCI DSS v4
Tactic: privilege-escalation · Click to open
T1078
▾ 4
T1078 Valid Accounts
Mapped by 12 frameworks: EU AI Act, CIS v8, DORA, GDPR, ISO 27001, iso27701, NIS2, NIST CSF, OWASP API Top 10, OWASP LLM Top 10, OWASP Top 10, PCI DSS v4
Tactic: defense-evasion, persistence, privilege-escalation, initial-access · Click to open
T1547
▾ 15
T1547 Boot or Logon Autostart Execution
Mapped by 10 frameworks: EU AI Act, CIS v8, DORA, GDPR, ISO 27001, NIS2, NIST CSF, OWASP LLM Top 10, OWASP Top 10, PCI DSS v4
Tactic: persistence, privilege-escalation · Click to open
T1055
▾ 12
T1055 Process Injection
Mapped by 8 frameworks: CIS v8, DORA, ISO 27001, NIS2, NIST CSF, OWASP API Top 10, OWASP Top 10, PCI DSS v4
Tactic: defense-evasion, privilege-escalation · Click to open
T1098
▾ 6
T1098 Account Manipulation
Mapped by 7 frameworks: CIS v8, DORA, ISO 27001, NIS2, NIST CSF, OWASP API Top 10, OWASP Top 10
Tactic: persistence, privilege-escalation · Click to open
T1053
▾ 7
T1053 Scheduled Task/Job
Mapped by 5 frameworks: CIS v8, DORA, GDPR, ISO 27001, NIS2
Tactic: execution, persistence, privilege-escalation · Click to open
T1037
▾ 5
T1037 Boot or Logon Initialization Scripts
Mapped by 2 frameworks: CIS v8, NIS2
Tactic: persistence, privilege-escalation · Click to open
T1543
▾ 4
T1543 Create or Modify System Process
Mapped by 1 framework: ISO 27001
Tactic: persistence, privilege-escalation · Click to open
T1574
▾ 12
T1574 Hijack Execution Flow
Mapped by 1 framework: ISO 27001
Tactic: persistence, privilege-escalation, defense-evasion · Click to open
T1134
▾ 5
T1134 Access Token Manipulation
Not mapped by any framework
Tactic: defense-evasion, privilege-escalation · Click to open
T1484
▾ 2
T1484 Domain Policy Modification
Not mapped by any framework
Tactic: defense-evasion, privilege-escalation · Click to open
T1502
T1502 Parent PID Spoofing
Not mapped by any framework
Tactic: defense-evasion, privilege-escalation · Click to open
T1504
T1504 PowerShell Profile
Not mapped by any framework
Tactic: persistence, privilege-escalation · Click to open
T1514
T1514 Elevated Execution with Prompt
Not mapped by any framework
Tactic: privilege-escalation · Click to open
T1519
T1519 Emond
Not mapped by any framework
Tactic: persistence, privilege-escalation · Click to open
T1546
▾ 16
T1546 Event Triggered Execution
Not mapped by any framework
Tactic: privilege-escalation, persistence · Click to open
T1548
▾ 5
T1548 Abuse Elevation Control Mechanism
Not mapped by any framework
Tactic: privilege-escalation, defense-evasion · Click to open
T1611
T1611 Escape to Host
Not mapped by any framework
Tactic: privilege-escalation · Click to open
TA0005Defense Evasion47 techniques
T1078
▾ 4
T1078 Valid Accounts
Mapped by 12 frameworks: EU AI Act, CIS v8, DORA, GDPR, ISO 27001, iso27701, NIS2, NIST CSF, OWASP API Top 10, OWASP LLM Top 10, OWASP Top 10, PCI DSS v4
Tactic: defense-evasion, persistence, privilege-escalation, initial-access · Click to open
T1027
▾ 12
T1027 Obfuscated Files or Information
Mapped by 9 frameworks: EU AI Act, CIS v8, DORA, GDPR, ISO 27001, NIS2, NIST CSF, OWASP LLM Top 10, OWASP Top 10
Tactic: defense-evasion · Click to open
T1055
▾ 12
T1055 Process Injection
Mapped by 8 frameworks: CIS v8, DORA, ISO 27001, NIS2, NIST CSF, OWASP API Top 10, OWASP Top 10, PCI DSS v4
Tactic: defense-evasion, privilege-escalation · Click to open
T1036
▾ 9
T1036 Masquerading
Mapped by 6 frameworks: CIS v8, DORA, GDPR, ISO 27001, NIS2, OWASP LLM Top 10
Tactic: defense-evasion · Click to open
T1070
▾ 9
T1070 Indicator Removal
Mapped by 6 frameworks: EU AI Act, CIS v8, DORA, GDPR, ISO 27001, NIST CSF
Tactic: defense-evasion · Click to open
T1562
▾ 11
T1562 Impair Defenses
Mapped by 6 frameworks: CIS v8, EU CRA, OWASP API Top 10, OWASP LLM Top 10, OWASP Top 10, PCI DSS v4
Tactic: defense-evasion · Click to open
T1014
T1014 Rootkit
Mapped by 1 framework: NIST CSF
Tactic: defense-evasion · Click to open
T1218
▾ 13
T1218 System Binary Proxy Execution
Mapped by 1 framework: OWASP Top 10
Tactic: defense-evasion · Click to open
T1535
T1535 Unused/Unsupported Cloud Regions
Mapped by 1 framework: ISO 27001
Tactic: defense-evasion · Click to open
T1574
▾ 12
T1574 Hijack Execution Flow
Mapped by 1 framework: ISO 27001
Tactic: persistence, privilege-escalation, defense-evasion · Click to open
T1006
T1006 Direct Volume Access
Not mapped by any framework
Tactic: defense-evasion · Click to open
T1112
T1112 Modify Registry
Not mapped by any framework
Tactic: defense-evasion · Click to open
T1127
▾ 1
T1127 Trusted Developer Utilities Proxy Execution
Not mapped by any framework
Tactic: defense-evasion · Click to open
T1134
▾ 5
T1134 Access Token Manipulation
Not mapped by any framework
Tactic: defense-evasion, privilege-escalation · Click to open
T1140
T1140 Deobfuscate/Decode Files or Information
Not mapped by any framework
Tactic: defense-evasion · Click to open
T1197
T1197 BITS Jobs
Not mapped by any framework
Tactic: defense-evasion, persistence · Click to open
T1202
T1202 Indirect Command Execution
Not mapped by any framework
Tactic: defense-evasion · Click to open
T1205
▾ 2
T1205 Traffic Signaling
Not mapped by any framework
Tactic: defense-evasion, persistence, command-and-control · Click to open
T1207
T1207 Rogue Domain Controller
Not mapped by any framework
Tactic: defense-evasion · Click to open
T1211
T1211 Exploitation for Defense Evasion
Not mapped by any framework
Tactic: defense-evasion · Click to open
T1216
▾ 1
T1216 System Script Proxy Execution
Not mapped by any framework
Tactic: defense-evasion · Click to open
T1220
T1220 XSL Script Processing
Not mapped by any framework
Tactic: defense-evasion · Click to open
T1221
T1221 Template Injection
Not mapped by any framework
Tactic: defense-evasion · Click to open
T1222
▾ 2
T1222 File and Directory Permissions Modification
Not mapped by any framework
Tactic: defense-evasion · Click to open
T1480
▾ 1
T1480 Execution Guardrails
Not mapped by any framework
Tactic: defense-evasion · Click to open
T1484
▾ 2
T1484 Domain Policy Modification
Not mapped by any framework
Tactic: defense-evasion, privilege-escalation · Click to open
T1497
▾ 3
T1497 Virtualization/Sandbox Evasion
Not mapped by any framework
Tactic: defense-evasion, discovery · Click to open
T1502
T1502 Parent PID Spoofing
Not mapped by any framework
Tactic: defense-evasion, privilege-escalation · Click to open
T1506
T1506 Web Session Cookie
Not mapped by any framework
Tactic: defense-evasion, lateral-movement · Click to open
T1527
T1527 Application Access Token
Not mapped by any framework
Tactic: defense-evasion, lateral-movement · Click to open
T1536
T1536 Revert Cloud Instance
Not mapped by any framework
Tactic: defense-evasion · Click to open
T1542
▾ 5
T1542 Pre-OS Boot
Not mapped by any framework
Tactic: defense-evasion, persistence · Click to open
T1548
▾ 5
T1548 Abuse Elevation Control Mechanism
Not mapped by any framework
Tactic: privilege-escalation, defense-evasion · Click to open
T1550
▾ 4
T1550 Use Alternate Authentication Material
Not mapped by any framework
Tactic: defense-evasion, lateral-movement · Click to open
T1553
▾ 6
T1553 Subvert Trust Controls
Not mapped by any framework
Tactic: defense-evasion · Click to open
T1556
▾ 8
T1556 Modify Authentication Process
Not mapped by any framework
Tactic: credential-access, defense-evasion, persistence · Click to open
T1564
▾ 11
T1564 Hide Artifacts
Not mapped by any framework
Tactic: defense-evasion · Click to open
T1578
▾ 5
T1578 Modify Cloud Compute Infrastructure
Not mapped by any framework
Tactic: defense-evasion · Click to open
T1599
▾ 1
T1599 Network Boundary Bridging
Not mapped by any framework
Tactic: defense-evasion · Click to open
T1600
▾ 2
T1600 Weaken Encryption
Not mapped by any framework
Tactic: defense-evasion · Click to open
T1601
▾ 2
T1601 Modify System Image
Not mapped by any framework
Tactic: defense-evasion · Click to open
T1610
T1610 Deploy Container
Not mapped by any framework
Tactic: defense-evasion, execution · Click to open
T1612
T1612 Build Image on Host
Not mapped by any framework
Tactic: defense-evasion · Click to open
T1620
T1620 Reflective Code Loading
Not mapped by any framework
Tactic: defense-evasion · Click to open
T1622
T1622 Debugger Evasion
Not mapped by any framework
Tactic: defense-evasion, discovery · Click to open
T1647
T1647 Plist File Modification
Not mapped by any framework
Tactic: defense-evasion · Click to open
T1656
T1656 Impersonation
Not mapped by any framework
Tactic: defense-evasion · Click to open
TA0006Credential Access20 techniques
T1003
▾ 8
T1003 OS Credential Dumping
Mapped by 12 frameworks: EU AI Act, CIS v8, EU CRA, DORA, GDPR, ISO 27001, iso27701, NIS2, NIST CSF, OWASP LLM Top 10, OWASP Top 10, PCI DSS v4
Tactic: credential-access · Click to open
T1552
▾ 8
T1552 Unsecured Credentials
Mapped by 6 frameworks: ISO 27001, iso27701, NIS2, OWASP LLM Top 10, OWASP Top 10, PCI DSS v4
Tactic: credential-access · Click to open
T1056
▾ 4
T1056 Input Capture
Mapped by 4 frameworks: DORA, NIS2, NIST CSF, OWASP LLM Top 10
Tactic: collection, credential-access · Click to open
T1110
▾ 4
T1110 Brute Force
Mapped by 4 frameworks: CIS v8, NIS2, OWASP API Top 10, PCI DSS v4
Tactic: credential-access · Click to open
T1040
T1040 Network Sniffing
Mapped by 3 frameworks: ISO 27001, NIS2, PCI DSS v4
Tactic: credential-access, discovery · Click to open
T1555
▾ 6
T1555 Credentials from Password Stores
Mapped by 2 frameworks: iso27701, PCI DSS v4
Tactic: credential-access · Click to open
T1528
T1528 Steal Application Access Token
Mapped by 1 framework: OWASP Top 10
Tactic: credential-access · Click to open
T1539
T1539 Steal Web Session Cookie
Mapped by 1 framework: NIS2
Tactic: credential-access · Click to open
T1111
T1111 Multi-Factor Authentication Interception
Not mapped by any framework
Tactic: credential-access · Click to open
T1167
T1167 Securityd Memory
Not mapped by any framework
Tactic: credential-access · Click to open
T1187
T1187 Forced Authentication
Not mapped by any framework
Tactic: credential-access · Click to open
T1212
T1212 Exploitation for Credential Access
Not mapped by any framework
Tactic: credential-access · Click to open
T1503
T1503 Credentials from Web Browsers
Not mapped by any framework
Tactic: credential-access · Click to open
T1522
T1522 Cloud Instance Metadata API
Not mapped by any framework
Tactic: credential-access · Click to open
T1556
▾ 8
T1556 Modify Authentication Process
Not mapped by any framework
Tactic: credential-access, defense-evasion, persistence · Click to open
T1557
▾ 3
T1557 Adversary-in-the-Middle
Not mapped by any framework
Tactic: credential-access, collection · Click to open
T1558
▾ 4
T1558 Steal or Forge Kerberos Tickets
Not mapped by any framework
Tactic: credential-access · Click to open
T1606
▾ 2
T1606 Forge Web Credentials
Not mapped by any framework
Tactic: credential-access · Click to open
T1621
T1621 Multi-Factor Authentication Request Generation
Not mapped by any framework
Tactic: credential-access · Click to open
T1649
T1649 Steal or Forge Authentication Certificates
Not mapped by any framework
Tactic: credential-access · Click to open
TA0007Discovery32 techniques
T1083
T1083 File and Directory Discovery
Mapped by 12 frameworks: EU AI Act, CIS v8, DORA, GDPR, ISO 27001, iso27701, NIS2, NIST CSF, OWASP API Top 10, OWASP LLM Top 10, OWASP Top 10, PCI DSS v4
Tactic: discovery · Click to open
T1087
▾ 4
T1087 Account Discovery
Mapped by 9 frameworks: EU AI Act, CIS v8, DORA, ISO 27001, NIS2, NIST CSF, OWASP API Top 10, OWASP Top 10, PCI DSS v4
Tactic: discovery · Click to open
T1018
T1018 Remote System Discovery
Mapped by 8 frameworks: CIS v8, DORA, ISO 27001, NIS2, NIST CSF, OWASP API Top 10, OWASP LLM Top 10, OWASP Top 10
Tactic: discovery · Click to open
T1046
T1046 Network Service Discovery
Mapped by 8 frameworks: CIS v8, DORA, GDPR, ISO 27001, NIS2, NIST CSF, OWASP Top 10, PCI DSS v4
Tactic: discovery · Click to open
T1012
T1012 Query Registry
Mapped by 5 frameworks: CIS v8, DORA, GDPR, ISO 27001, NIS2
Tactic: discovery · Click to open
T1049
T1049 System Network Connections Discovery
Mapped by 5 frameworks: CIS v8, DORA, ISO 27001, NIS2, NIST CSF
Tactic: discovery · Click to open
T1082
T1082 System Information Discovery
Mapped by 5 frameworks: EU CRA, DORA, OWASP API Top 10, OWASP LLM Top 10, OWASP Top 10
Tactic: discovery · Click to open
T1016
▾ 2
T1016 System Network Configuration Discovery
Mapped by 4 frameworks: DORA, GDPR, ISO 27001, NIS2
Tactic: discovery · Click to open
T1033
T1033 System Owner/User Discovery
Mapped by 4 frameworks: CIS v8, DORA, GDPR, NIST CSF
Tactic: discovery · Click to open
T1040
T1040 Network Sniffing
Mapped by 3 frameworks: ISO 27001, NIS2, PCI DSS v4
Tactic: credential-access, discovery · Click to open
T1007
T1007 System Service Discovery
Mapped by 1 framework: DORA
Tactic: discovery · Click to open
T1057
T1057 Process Discovery
Mapped by 1 framework: DORA
Tactic: discovery · Click to open
T1069
▾ 3
T1069 Permission Groups Discovery
Mapped by 1 framework: DORA
Tactic: discovery · Click to open
T1135
T1135 Network Share Discovery
Mapped by 1 framework: EU CRA
Tactic: discovery · Click to open
T1526
T1526 Cloud Service Discovery
Mapped by 1 framework: ISO 27001
Tactic: discovery · Click to open
T1010
T1010 Application Window Discovery
Not mapped by any framework
Tactic: discovery · Click to open
T1120
T1120 Peripheral Device Discovery
Not mapped by any framework
Tactic: discovery · Click to open
T1124
T1124 System Time Discovery
Not mapped by any framework
Tactic: discovery · Click to open
T1201
T1201 Password Policy Discovery
Not mapped by any framework
Tactic: discovery · Click to open
T1217
T1217 Browser Information Discovery
Not mapped by any framework
Tactic: discovery · Click to open
T1482
T1482 Domain Trust Discovery
Not mapped by any framework
Tactic: discovery · Click to open
T1497
▾ 3
T1497 Virtualization/Sandbox Evasion
Not mapped by any framework
Tactic: defense-evasion, discovery · Click to open
T1518
▾ 1
T1518 Software Discovery
Not mapped by any framework
Tactic: discovery · Click to open
T1538
T1538 Cloud Service Dashboard
Not mapped by any framework
Tactic: discovery · Click to open
T1580
T1580 Cloud Infrastructure Discovery
Not mapped by any framework
Tactic: discovery · Click to open
T1613
T1613 Container and Resource Discovery
Not mapped by any framework
Tactic: discovery · Click to open
T1614
▾ 1
T1614 System Location Discovery
Not mapped by any framework
Tactic: discovery · Click to open
T1615
T1615 Group Policy Discovery
Not mapped by any framework
Tactic: discovery · Click to open
T1619
T1619 Cloud Storage Object Discovery
Not mapped by any framework
Tactic: discovery · Click to open
T1622
T1622 Debugger Evasion
Not mapped by any framework
Tactic: defense-evasion, discovery · Click to open
T1652
T1652 Device Driver Discovery
Not mapped by any framework
Tactic: discovery · Click to open
T1654
T1654 Log Enumeration
Not mapped by any framework
Tactic: discovery · Click to open
TA0008Lateral Movement11 techniques
T1021
▾ 8
T1021 Remote Services
Mapped by 11 frameworks: CIS v8, EU CRA, DORA, GDPR, ISO 27001, iso27701, NIS2, NIST CSF, OWASP LLM Top 10, OWASP Top 10, PCI DSS v4
Tactic: lateral-movement · Click to open
T1210
T1210 Exploitation of Remote Services
Mapped by 2 frameworks: CIS v8, OWASP Top 10
Tactic: lateral-movement · Click to open
T1072
T1072 Software Deployment Tools
Not mapped by any framework
Tactic: execution, lateral-movement · Click to open
T1080
T1080 Taint Shared Content
Not mapped by any framework
Tactic: lateral-movement · Click to open
T1091
T1091 Replication Through Removable Media
Not mapped by any framework
Tactic: lateral-movement, initial-access · Click to open
T1506
T1506 Web Session Cookie
Not mapped by any framework
Tactic: defense-evasion, lateral-movement · Click to open
T1527
T1527 Application Access Token
Not mapped by any framework
Tactic: defense-evasion, lateral-movement · Click to open
T1534
T1534 Internal Spearphishing
Not mapped by any framework
Tactic: lateral-movement · Click to open
T1550
▾ 4
T1550 Use Alternate Authentication Material
Not mapped by any framework
Tactic: defense-evasion, lateral-movement · Click to open
T1563
▾ 2
T1563 Remote Service Session Hijacking
Not mapped by any framework
Tactic: lateral-movement · Click to open
T1570
T1570 Lateral Tool Transfer
Not mapped by any framework
Tactic: lateral-movement · Click to open
TA0009Collection17 techniques
T1005
T1005 Data from Local System
Mapped by 12 frameworks: EU AI Act, CIS v8, DORA, GDPR, ISO 27001, iso27701, NIS2, NIST CSF, OWASP API Top 10, OWASP LLM Top 10, OWASP Top 10, PCI DSS v4
Tactic: collection · Click to open
T1039
T1039 Data from Network Shared Drive
Mapped by 10 frameworks: CIS v8, EU CRA, DORA, GDPR, iso27701, NIS2, OWASP LLM Top 10, OWASP Top 10, PCI DSS v4, tiber_eu
Tactic: collection · Click to open
T1530
T1530 Data from Cloud Storage
Mapped by 6 frameworks: CIS v8, GDPR, ISO 27001, iso27701, OWASP API Top 10, OWASP LLM Top 10
Tactic: collection · Click to open
T1056
▾ 4
T1056 Input Capture
Mapped by 4 frameworks: DORA, NIS2, NIST CSF, OWASP LLM Top 10
Tactic: collection, credential-access · Click to open
T1119
T1119 Automated Collection
Mapped by 4 frameworks: iso27701, OWASP API Top 10, OWASP LLM Top 10, OWASP Top 10
Tactic: collection · Click to open
T1074
▾ 2
T1074 Data Staged
Mapped by 2 frameworks: GDPR, OWASP API Top 10
Tactic: collection · Click to open
T1025
T1025 Data from Removable Media
Mapped by 1 framework: iso27701
Tactic: collection · Click to open
T1114
▾ 3
T1114 Email Collection
Mapped by 1 framework: NIS2
Tactic: collection · Click to open
T1560
▾ 3
T1560 Archive Collected Data
Mapped by 1 framework: iso27701
Tactic: collection · Click to open
T1113
T1113 Screen Capture
Not mapped by any framework
Tactic: collection · Click to open
T1115
T1115 Clipboard Data
Not mapped by any framework
Tactic: collection · Click to open
T1123
T1123 Audio Capture
Not mapped by any framework
Tactic: collection · Click to open
T1125
T1125 Video Capture
Not mapped by any framework
Tactic: collection · Click to open
T1185
T1185 Browser Session Hijacking
Not mapped by any framework
Tactic: collection · Click to open
T1213
▾ 3
T1213 Data from Information Repositories
Not mapped by any framework
Tactic: collection · Click to open
T1557
▾ 3
T1557 Adversary-in-the-Middle
Not mapped by any framework
Tactic: credential-access, collection · Click to open
T1602
▾ 2
T1602 Data from Configuration Repository
Not mapped by any framework
Tactic: collection · Click to open
TA0010Exfiltration9 techniques
T1041
T1041 Exfiltration Over C2 Channel
Mapped by 13 frameworks: EU AI Act, CIS v8, EU CRA, DORA, GDPR, ISO 27001, iso27701, NIS2, NIST CSF, OWASP API Top 10, OWASP LLM Top 10, OWASP Top 10, PCI DSS v4
Tactic: exfiltration · Click to open
T1048
▾ 3
T1048 Exfiltration Over Alternative Protocol
Mapped by 6 frameworks: EU CRA, DORA, GDPR, ISO 27001, iso27701, NIS2
Tactic: exfiltration · Click to open
T1567
▾ 4
T1567 Exfiltration Over Web Service
Mapped by 4 frameworks: ISO 27001, iso27701, OWASP API Top 10, PCI DSS v4
Tactic: exfiltration · Click to open
T1020
▾ 1
T1020 Automated Exfiltration
Mapped by 3 frameworks: DORA, OWASP API Top 10, PCI DSS v4
Tactic: exfiltration · Click to open
T1011
▾ 1
T1011 Exfiltration Over Other Network Medium
Mapped by 2 frameworks: DORA, GDPR
Tactic: exfiltration · Click to open
T1537
T1537 Transfer Data to Cloud Account
Mapped by 2 frameworks: ISO 27001, OWASP API Top 10
Tactic: exfiltration · Click to open
T1029
T1029 Scheduled Transfer
Not mapped by any framework
Tactic: exfiltration · Click to open
T1030
T1030 Data Transfer Size Limits
Not mapped by any framework
Tactic: exfiltration · Click to open
T1052
▾ 1
T1052 Exfiltration Over Physical Medium
Not mapped by any framework
Tactic: exfiltration · Click to open
TA0011Command and Control17 techniques
T1071
▾ 4
T1071 Application Layer Protocol
Mapped by 10 frameworks: EU AI Act, CIS v8, DORA, GDPR, ISO 27001, NIS2, NIST CSF, OWASP LLM Top 10, OWASP Top 10, PCI DSS v4
Tactic: command-and-control · Click to open
T1090
▾ 4
T1090 Proxy
Mapped by 4 frameworks: CIS v8, DORA, ISO 27001, OWASP Top 10
Tactic: command-and-control · Click to open
T1572
T1572 Protocol Tunneling
Mapped by 3 frameworks: OWASP API Top 10, OWASP Top 10, PCI DSS v4
Tactic: command-and-control · Click to open
T1105
T1105 Ingress Tool Transfer
Mapped by 2 frameworks: NIS2, OWASP LLM Top 10
Tactic: command-and-control · Click to open
T1001
▾ 3
T1001 Data Obfuscation
Mapped by 1 framework: GDPR
Tactic: command-and-control · Click to open
T1008
T1008 Fallback Channels
Mapped by 1 framework: DORA
Tactic: command-and-control · Click to open
T1092
T1092 Communication Through Removable Media
Not mapped by any framework
Tactic: command-and-control · Click to open
T1095
T1095 Non-Application Layer Protocol
Not mapped by any framework
Tactic: command-and-control · Click to open
T1102
▾ 3
T1102 Web Service
Not mapped by any framework
Tactic: command-and-control · Click to open
T1104
T1104 Multi-Stage Channels
Not mapped by any framework
Tactic: command-and-control · Click to open
T1132
▾ 2
T1132 Data Encoding
Not mapped by any framework
Tactic: command-and-control · Click to open
T1205
▾ 2
T1205 Traffic Signaling
Not mapped by any framework
Tactic: defense-evasion, persistence, command-and-control · Click to open
T1219
T1219 Remote Access Software
Not mapped by any framework
Tactic: command-and-control · Click to open
T1568
▾ 3
T1568 Dynamic Resolution
Not mapped by any framework
Tactic: command-and-control · Click to open
T1571
T1571 Non-Standard Port
Not mapped by any framework
Tactic: command-and-control · Click to open
T1573
▾ 2
T1573 Encrypted Channel
Not mapped by any framework
Tactic: command-and-control · Click to open
T1659
T1659 Content Injection
Not mapped by any framework
Tactic: initial-access, command-and-control · Click to open
TA0040Impact15 techniques
T1485
T1485 Data Destruction
Mapped by 11 frameworks: EU AI Act, CIS v8, GDPR, ISO 27001, iso27701, NIS2, NIST CSF, OWASP API Top 10, OWASP LLM Top 10, OWASP Top 10, PCI DSS v4
Tactic: impact · Click to open
T1486
T1486 Data Encrypted for Impact
Mapped by 11 frameworks: EU AI Act, CIS v8, DORA, GDPR, ISO 27001, iso27701, NIS2, NIST CSF, OWASP LLM Top 10, OWASP Top 10, PCI DSS v4
Tactic: impact · Click to open
T1490
T1490 Inhibit System Recovery
Mapped by 9 frameworks: EU AI Act, CIS v8, DORA, ISO 27001, NIS2, OWASP API Top 10, OWASP LLM Top 10, OWASP Top 10, PCI DSS v4
Tactic: impact · Click to open
T1499
▾ 4
T1499 Endpoint Denial of Service
Mapped by 3 frameworks: OWASP API Top 10, OWASP LLM Top 10, OWASP Top 10
Tactic: impact · Click to open
T1498
▾ 2
T1498 Network Denial of Service
Mapped by 2 frameworks: NIS2, NIST CSF
Tactic: impact · Click to open
T1529
T1529 System Shutdown/Reboot
Mapped by 2 frameworks: NIS2, NIST CSF
Tactic: impact · Click to open
T1531
T1531 Account Access Removal
Mapped by 2 frameworks: NIST CSF, OWASP LLM Top 10
Tactic: impact · Click to open
T1491
▾ 2
T1491 Defacement
Mapped by 1 framework: NIST CSF
Tactic: impact · Click to open
T1561
▾ 2
T1561 Disk Wipe
Mapped by 1 framework: EU AI Act
Tactic: impact · Click to open
T1487
T1487 Disk Structure Wipe
Not mapped by any framework
Tactic: impact · Click to open
T1489
T1489 Service Stop
Not mapped by any framework
Tactic: impact · Click to open
T1495
T1495 Firmware Corruption
Not mapped by any framework
Tactic: impact · Click to open
T1496
T1496 Resource Hijacking
Not mapped by any framework
Tactic: impact · Click to open
T1565
▾ 3
T1565 Data Manipulation
Not mapped by any framework
Tactic: impact · Click to open
T1657
T1657 Financial Theft
Not mapped by any framework
Tactic: impact · Click to open
TA0042Resource Development8 techniques
T1583
▾ 8
T1583 Acquire Infrastructure
Not mapped by any framework
Tactic: resource-development · Click to open
T1584
▾ 7
T1584 Compromise Infrastructure
Not mapped by any framework
Tactic: resource-development · Click to open
T1585
▾ 3
T1585 Establish Accounts
Not mapped by any framework
Tactic: resource-development · Click to open
T1586
▾ 3
T1586 Compromise Accounts
Not mapped by any framework
Tactic: resource-development · Click to open
T1587
▾ 4
T1587 Develop Capabilities
Not mapped by any framework
Tactic: resource-development · Click to open
T1588
▾ 6
T1588 Obtain Capabilities
Not mapped by any framework
Tactic: resource-development · Click to open
T1608
▾ 6
T1608 Stage Capabilities
Not mapped by any framework
Tactic: resource-development · Click to open
T1650
T1650 Acquire Access
Not mapped by any framework
Tactic: resource-development · Click to open
TA0043Reconnaissance10 techniques
T1592
▾ 4
T1592 Gather Victim Host Information
Mapped by 2 frameworks: NIS2, OWASP API Top 10
Tactic: reconnaissance · Click to open
T1589
▾ 3
T1589 Gather Victim Identity Information
Not mapped by any framework
Tactic: reconnaissance · Click to open
T1590
▾ 6
T1590 Gather Victim Network Information
Not mapped by any framework
Tactic: reconnaissance · Click to open
T1591
▾ 4
T1591 Gather Victim Org Information
Not mapped by any framework
Tactic: reconnaissance · Click to open
T1593
▾ 3
T1593 Search Open Websites/Domains
Not mapped by any framework
Tactic: reconnaissance · Click to open
T1594
T1594 Search Victim-Owned Websites
Not mapped by any framework
Tactic: reconnaissance · Click to open
T1595
▾ 3
T1595 Active Scanning
Not mapped by any framework
Tactic: reconnaissance · Click to open
T1596
▾ 5
T1596 Search Open Technical Databases
Not mapped by any framework
Tactic: reconnaissance · Click to open
T1597
▾ 2
T1597 Search Closed Sources
Not mapped by any framework
Tactic: reconnaissance · Click to open
T1598
▾ 4
T1598 Phishing for Information
Not mapped by any framework
Tactic: reconnaissance · Click to open
compliance_tests_technique edges in the cs-graph corroborator. Curated by Adam Lundqvist, Founder at SQUR.