235 indexed

ATT&CKATT&CK techniques

235 top-level MITRE ATT&CK Enterprise techniques (T-IDs), grouped by tactic. Filter to a tactic or browse the full kill chain, then click into a technique for sub-techniques and mitigations. Authored by Adam Lundqvist.

16 in Execution · 235 total

IDTitleSummary
T1047Windows Management InstrumentationAdversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastru…
T1053Scheduled Task/JobAdversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code. Utilities exist within all major operating …
T1059Command and Scripting InterpreterAdversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting wit…
T1072Software Deployment ToolsAdversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. C…
T1106Native APIAdversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low…
T1129Shared ModulesAdversaries may execute malicious payloads via loading shared modules. Shared modules are executable files that are loaded into processes to provide access to …
T1203Exploitation for Client ExecutionAdversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices…
T1204User ExecutionAn adversary may rely upon specific actions by a user in order to gain execution. Users may be subjected to social engineering to get them to execute malicious…
T1559Inter-Process CommunicationAdversaries may abuse inter-process communication (IPC) mechanisms for local code or command execution. IPC is typically used by processes to share data, commu…
T1569System ServicesAdversaries may abuse system services or daemons to execute commands or programs. Adversaries can execute malicious content by interacting with or creating ser…
T1609Container Administration CommandAdversaries may abuse a container administration service to execute commands within a container. A container administration service such as the Docker daemon, …
T1648Serverless ExecutionAdversaries may abuse serverless computing, integration, and automation services to execute arbitrary code in cloud environments. Many cloud providers offer a …
T1651Cloud Administration CommandAdversaries may abuse cloud management services to execute commands within virtual machines. Resources such as AWS Systems Manager, Azure RunCommand, and Runbo…
T1674Input InjectionAdversaries may simulate keystrokes on a victim’s computer by various means to perform any type of action on behalf of the user, such as launching the command …
T1675ESXi Administration CommandAdversaries may abuse ESXi administration services to execute commands on guest machines hosted within an ESXi virtual environment. Persistent background servi…
T1677Poisoned Pipeline ExecutionAdversaries may manipulate continuous integration / continuous development (CI/CD) processes by injecting malicious code into the build process. There are seve…
Sourced from MITRE ATT&CK Enterprise (current release). Curated by Adam Lundqvist, Founder at SQUR.
MITRE ATT&CK techniques — by tactic | SQUR Knowledge Base