235 indexed

ATT&CKATT&CK techniques

235 top-level MITRE ATT&CK Enterprise techniques (T-IDs), grouped by tactic. Filter to a tactic or browse the full kill chain, then click into a technique for sub-techniques and mitigations. Authored by Adam Lundqvist.

8 in Initial Access · 235 total

IDTitleSummary
T1189Drive-by CompromiseAdversaries may gain access to a system through a user visiting a website over the normal course of browsing. Multiple ways of delivering exploit code to a bro…
T1190Exploit Public-Facing ApplicationAdversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software …
T1195Supply Chain CompromiseAdversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise. Supply c…
T1199Trusted RelationshipAdversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an exist…
T1200Hardware AdditionsAdversaries may physically introduce computer accessories, networking hardware, or other computing devices into a system or network that can be used as a vecto…
T1566PhishingAdversaries may send phishing messages to gain access to victim systems. All forms of phishing are electronically delivered social engineering. Phishing can be…
T1659Content InjectionAdversaries may gain access and continuously communicate with victims by injecting malicious content into systems through online network traffic. Rather than l…
T1669Wi-Fi NetworksAdversaries may gain initial access to target systems by connecting to wireless networks. They may accomplish this by exploiting open Wi-Fi networks used by ta…
Sourced from MITRE ATT&CK Enterprise (current release). Curated by Adam Lundqvist, Founder at SQUR.
MITRE ATT&CK techniques — by tactic | SQUR Knowledge Base