212 indexed

ATT&CKATT&CK techniques

212 top-level MITRE ATT&CK Enterprise techniques (T-IDs), grouped by tactic. Filter to a tactic or browse the full kill chain, then click into a technique for sub-techniques and mitigations. Authored by Adam Lundqvist.

16 in Collection · 212 total

IDTitleSummary
T1005Data from Local SystemAdversaries may search local system sources, such as file systems and configuration files or local databases, to find files of interest and sensitive data prio…
T1025Data from Removable MediaAdversaries may search connected removable media on computers they have compromised to find files of interest. Sensitive data can be collected from any removab…
T1039Data from Network Shared DriveAdversaries may search network shares on computers they have compromised to find files of interest. Sensitive data can be collected from remote systems via sha…
T1056Input CaptureAdversaries may use methods of capturing user input to obtain credentials or collect information. During normal system usage, users often provide credentials t…
T1074Data StagedAdversaries may stage collected data in a central location or directory prior to Exfiltration. Data may be kept in separate files or combined into one file thr…
T1113Screen CaptureAdversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be inc…
T1114Email CollectionAdversaries may target user email to collect sensitive information. Emails may contain sensitive data, including trade secrets or personal information, that ca…
T1115Clipboard DataAdversaries may collect data stored in the clipboard from users copying information within or between applications. For example, on Windows adversaries can a…
T1119Automated CollectionOnce established within a system or network, an adversary may use automated techniques for collecting internal data. Methods for performing this technique coul…
T1123Audio CaptureAn adversary can leverage a computer's peripheral devices (e.g., microphones and webcams) or applications (e.g., voice and video call services) to capture audi…
T1125Video CaptureAn adversary can leverage a computer's peripheral devices (e.g., integrated cameras or webcams) or applications (e.g., video call services) to capture video re…
T1185Browser Session HijackingAdversaries may take advantage of security vulnerabilities and inherent functionality in browser software to change content, modify user-behaviors, and interce…
T1213Data from Information RepositoriesAdversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typic…
T1530Data from Cloud StorageAdversaries may access data from cloud storage. Many IaaS providers offer solutions for online data object storage such as Amazon S3, Azure Storage, and Googl…
T1560Archive Collected DataAn adversary may compress and/or encrypt data that is collected prior to exfiltration. Compressing the data can help to obfuscate the collected data and minimi…
T1602Data from Configuration RepositoryAdversaries may collect data related to managed devices from configuration repositories. Configuration repositories are used by management systems in order to …
Sourced from MITRE ATT&CK Enterprise (current release). Curated by Adam Lundqvist, Founder at SQUR.
MITRE ATT&CK techniques — by tactic | SQUR Knowledge Base