212 indexed

ATT&CKATT&CK techniques

212 top-level MITRE ATT&CK Enterprise techniques (T-IDs), grouped by tactic. Filter to a tactic or browse the full kill chain, then click into a technique for sub-techniques and mitigations. Authored by Adam Lundqvist.

15 in Command and Control · 212 total

IDTitleSummary
T1001Data ObfuscationAdversaries may obfuscate command and control traffic to make it more difficult to detect. Command and control (C2) communications are hidden (but not necessar…
T1008Fallback ChannelsAdversaries may use fallback or alternate communication channels if the primary channel is compromised or inaccessible in order to maintain reliable command an…
T1071Application Layer ProtocolAdversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic. Commands to the re…
T1090ProxyAdversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control …
T1092Communication Through Removable MediaAdversaries can perform command and control between compromised hosts on potentially disconnected networks using removable media to transfer commands from syst…
T1095Non-Application Layer ProtocolAdversaries may use an OSI non-application layer protocol for communication between host and C2 server or among infected hosts within a network. The list of po…
T1102Web ServiceAdversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system. Popular websites and social media a…
T1104Multi-Stage ChannelsAdversaries may create multiple stages for command and control that are employed under different conditions or for certain functions. Use of multiple stages ma…
T1105Ingress Tool TransferAdversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-c…
T1132Data EncodingAdversaries may encode data to make the content of command and control traffic more difficult to detect. Command and control (C2) information can be encoded us…
T1219Remote Access SoftwareAn adversary may use legitimate desktop support and remote access software to establish an interactive command and control channel to target systems within net…
T1568Dynamic ResolutionAdversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations. This may be achieved by us…
T1571Non-Standard PortAdversaries may communicate using a protocol and port pairing that are typically not associated. For example, HTTPS over port 8088(Citation: Symantec Elfin Mar…
T1572Protocol TunnelingAdversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access …
T1573Encrypted ChannelAdversaries may employ a known encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a commun…
Sourced from MITRE ATT&CK Enterprise (current release). Curated by Adam Lundqvist, Founder at SQUR.
MITRE ATT&CK techniques — by tactic | SQUR Knowledge Base