235 indexed

ATT&CKATT&CK techniques

235 top-level MITRE ATT&CK Enterprise techniques (T-IDs), grouped by tactic. Filter to a tactic or browse the full kill chain, then click into a technique for sub-techniques and mitigations. Authored by Adam Lundqvist.

10 in Other · 235 total

IDTitleSummary
T1666Modify Cloud Resource HierarchyAdversaries may attempt to modify hierarchical structures in infrastructure-as-a-service (IaaS) environments in order to evade defenses. IaaS environments o…
T1678Delay ExecutionAdversaries may employ various time-based methods to evade detection and analysis. These techniques often exploit system clocks, delays, or timing mechanisms t…
T1679Selective ExclusionAdversaries may intentionally exclude certain files, folders, directories, file types, or system components from encryption or tampering during a ransomware or…
T1684Social EngineeringAdversaries may use social engineering techniques to influence users to take actions that result in unauthorized access, approval of changes, disclosure of sen…
T1685Disable or Modify ToolsAdversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems…
T1686Disable or Modify System FirewallAdversaries may disable or modify host-based or network firewalls to impair defensive mechanisms and enable further action. Once an adversary has gathered suff…
T1687Exploitation for Defense ImpairmentAdversaries may exploit vulnerabilities in security software, infrastructure, or defensive components to degrade, disable, or otherwise continue to impair thei…
T1688Safe Mode BootAdversaries may abuse Windows safe mode to disable endpoint defenses. Safe mode starts up the Windows operating system with a limited set of drivers and servic…
T1689Downgrade AttackAdversaries may downgrade or use a version of system features that may be outdated, vulnerable, and/or does not support updated security controls. Downgrade at…
T1690Prevent Command History LoggingAdversaries may impair command history logging to hide commands they run on a compromised system. Various command interpreters keep track of the commands users…
Sourced from MITRE ATT&CK Enterprise (current release). Curated by Adam Lundqvist, Founder at SQUR.
MITRE ATT&CK techniques — by tactic | SQUR Knowledge Base