235 indexed
ATT&CKATT&CK techniques
235 top-level MITRE ATT&CK Enterprise techniques (T-IDs), grouped by tactic. Filter to a tactic or browse the full kill chain, then click into a technique for sub-techniques and mitigations. Authored by Adam Lundqvist.
10 in Other · 235 total
| ID | Title | Summary |
|---|---|---|
| T1666 | Modify Cloud Resource Hierarchy | Adversaries may attempt to modify hierarchical structures in infrastructure-as-a-service (IaaS) environments in order to evade defenses. IaaS environments o… |
| T1678 | Delay Execution | Adversaries may employ various time-based methods to evade detection and analysis. These techniques often exploit system clocks, delays, or timing mechanisms t… |
| T1679 | Selective Exclusion | Adversaries may intentionally exclude certain files, folders, directories, file types, or system components from encryption or tampering during a ransomware or… |
| T1684 | Social Engineering | Adversaries may use social engineering techniques to influence users to take actions that result in unauthorized access, approval of changes, disclosure of sen… |
| T1685 | Disable or Modify Tools | Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems… |
| T1686 | Disable or Modify System Firewall | Adversaries may disable or modify host-based or network firewalls to impair defensive mechanisms and enable further action. Once an adversary has gathered suff… |
| T1687 | Exploitation for Defense Impairment | Adversaries may exploit vulnerabilities in security software, infrastructure, or defensive components to degrade, disable, or otherwise continue to impair thei… |
| T1688 | Safe Mode Boot | Adversaries may abuse Windows safe mode to disable endpoint defenses. Safe mode starts up the Windows operating system with a limited set of drivers and servic… |
| T1689 | Downgrade Attack | Adversaries may downgrade or use a version of system features that may be outdated, vulnerable, and/or does not support updated security controls. Downgrade at… |
| T1690 | Prevent Command History Logging | Adversaries may impair command history logging to hide commands they run on a compromised system. Various command interpreters keep track of the commands users… |