TA0002ATT&CK 14.1

TA0002Execution

Description

The adversary is trying to run malicious code. Execution consists of techniques that result in adversary-controlled code running on a local or remote system. Techniques that run malicious code are often paired with techniques from all other tactics to achieve broader goals, like exploring a network or stealing data. For example, an adversary might use a remote access tool to run a PowerShell script that does Remote System Discovery.

Techniques in this tactic· 12

T1047
Windows Management Instrumentation
T1053
Scheduled Task/Job
T1059
Command and Scripting Interpreter
T1072
Software Deployment Tools
T1106
Native API
T1129
Shared Modules
T1203
Exploitation for Client Execution
T1204
User Execution
T1559
Inter-Process Communication
T1569
System Services
T1609
Container Administration Command
T1610
Deploy Container

Sub-techniques in this tactic· 24

T1053.001T1053.002T1053.003T1053.004T1053.005T1053.006T1053.007T1059.001T1059.002T1059.003T1059.004T1059.005T1059.006T1059.007T1059.008T1059.009T1204.001T1204.002T1204.003T1559.001T1559.002T1559.003T1569.001T1569.002

References

  1. https://attack.mitre.org/tactics/TA0002

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Tactic
Discovery
Technique
User Execution
Tactic
Lateral Movement
Technique
Command and Scripting Interpreter
Tactic
Privilege Escalation
Tactic
Command and Control
Sourced from MITRE ATT&CK Enterprise 14.1. Curated by Adam Lundqvist, Founder at SQUR.