212 indexed

ATT&CKATT&CK techniques

212 top-level MITRE ATT&CK Enterprise techniques (T-IDs), grouped by tactic. Filter to a tactic or browse the full kill chain, then click into a technique for sub-techniques and mitigations. Authored by Adam Lundqvist.

44 in Defense Evasion · 212 total

IDTitleSummary
T1006Direct Volume AccessAdversaries may directly access a volume to bypass file access controls and file system monitoring. Windows allows programs to have direct access to logical vo…
T1014RootkitAdversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Rootkits are program…
T1027Obfuscated Files or InformationAdversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the sy…
T1036MasqueradingAdversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs …
T1055Process InjectionAdversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of ex…
T1070Indicator RemovalAdversaries may delete or modify artifacts generated within systems to remove evidence of their presence or hinder defenses. Various artifacts may be created b…
T1078Valid AccountsAdversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. …
T1112Modify RegistryAdversaries may interact with the Windows Registry to hide configuration information within Registry keys, remove information as part of cleaning up, or as par…
T1127Trusted Developer Utilities Proxy ExecutionAdversaries may take advantage of trusted developer utilities to proxy execution of malicious payloads. There are many utilities used for software development …
T1134Access Token ManipulationAdversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls. Windows uses a…
T1140Deobfuscate/Decode Files or InformationAdversaries may use [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027) to hide artifacts of an intrusion from analysis. They may requ…
T1197BITS JobsAdversaries may abuse BITS jobs to persistently execute code and perform various background tasks. Windows Background Intelligent Transfer Service (BITS) is a …
T1202Indirect Command ExecutionAdversaries may abuse utilities that allow for command execution to bypass security restrictions that limit the use of command-line interpreters. Various Windo…
T1205Traffic SignalingAdversaries may use traffic signaling to hide open ports or other malicious functionality used for persistence or command and control. Traffic signaling involv…
T1207Rogue Domain ControllerAdversaries may register a rogue Domain Controller to enable manipulation of Active Directory data. DCShadow may be used to create a rogue Domain Controller (D…
T1211Exploitation for Defense EvasionAdversaries may exploit a system or application vulnerability to bypass security features. Exploitation of a vulnerability occurs when an adversary takes advan…
T1216System Script Proxy ExecutionAdversaries may use trusted scripts, often signed with certificates, to proxy the execution of malicious files. Several Microsoft signed scripts that have been…
T1218System Binary Proxy ExecutionAdversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries. Binaries…
T1220XSL Script ProcessingAdversaries may bypass application control and obscure execution of code by embedding scripts inside XSL files. Extensible Stylesheet Language (XSL) files are …
T1221Template InjectionAdversaries may create or modify references in user document templates to conceal malicious code or force authentication attempts. For example, Microsoft’s Off…
T1222File and Directory Permissions ModificationAdversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.(Citation: Hybrid Analysis Icac…
T1480Execution GuardrailsAdversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to…
T1484Domain Policy ModificationAdversaries may modify the configuration settings of a domain to evade defenses and/or escalate privileges in domain environments. Domains provide a centralize…
T1497Virtualization/Sandbox EvasionAdversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of …
T1502Parent PID SpoofingAdversaries may spoof the parent process identifier (PPID) of a new process to evade process-monitoring defenses or to elevate privileges. New processes are ty…
T1506Web Session CookieAdversaries can use stolen session cookies to authenticate to web applications and services. This technique bypasses some multi-factor authentication protocols…
T1527Application Access TokenAdversaries may use application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote s…
T1535Unused/Unsupported Cloud RegionsAdversaries may create cloud instances in unused geographic service regions in order to evade detection. Access is usually obtained through compromising accoun…
T1536Revert Cloud InstanceAn adversary may revert changes made to a cloud instance after they have performed malicious activities in attempt to evade detection and remove evidence of th…
T1542Pre-OS BootAdversaries may abuse Pre-OS Boot mechanisms as a way to establish persistence on a system. During the booting process of a computer, firmware and various star…
T1550Use Alternate Authentication MaterialAdversaries may use alternate authentication material, such as password hashes, Kerberos tickets, and application access tokens, in order to move laterally wit…
T1553Subvert Trust ControlsAdversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted programs. Operating systems and…
T1562Impair DefensesAdversaries may maliciously modify components of a victim environment in order to hinder or disable defensive mechanisms. This not only involves impairing prev…
T1564Hide ArtifactsAdversaries may attempt to hide artifacts associated with their behaviors to evade detection. Operating systems may have features to hide various artifacts, su…
T1578Modify Cloud Compute InfrastructureAn adversary may attempt to modify a cloud account's compute service infrastructure to evade defenses. A modification to the compute service infrastructure can…
T1599Network Boundary BridgingAdversaries may bridge network boundaries by compromising perimeter network devices or internal devices responsible for network segmentation. Breaching these d…
T1600Weaken EncryptionAdversaries may compromise a network device’s encryption capability in order to bypass encryption that would otherwise protect data communications. (Citation: …
T1601Modify System ImageAdversaries may make changes to the operating system of embedded network devices to weaken defenses and provide new capabilities for themselves. On such devic…
T1610Deploy ContainerAdversaries may deploy a container into an environment to facilitate execution or evade defenses. In some cases, adversaries may deploy a new container to exec…
T1612Build Image on HostAdversaries may build a container image directly on a host to bypass defenses that monitor for the retrieval of malicious images from a public registry. A remo…
T1620Reflective Code LoadingAdversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then exec…
T1622Debugger EvasionAdversaries may employ various means to detect and avoid debuggers. Debuggers are typically used by defenders to trace and/or analyze the execution of potentia…
T1647Plist File ModificationAdversaries may modify property list files (plist files) to enable other malicious activity, while also potentially evading and bypassing system defenses. macO…
T1656ImpersonationAdversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf. For example, …
Sourced from MITRE ATT&CK Enterprise (current release). Curated by Adam Lundqvist, Founder at SQUR.
MITRE ATT&CK techniques — by tactic | SQUR Knowledge Base