235 indexed

ATT&CKATT&CK techniques

235 top-level MITRE ATT&CK Enterprise techniques (T-IDs), grouped by tactic. Filter to a tactic or browse the full kill chain, then click into a technique for sub-techniques and mitigations. Authored by Adam Lundqvist.

17 in Persistence · 235 total

IDTitleSummary
T1037Boot or Logon Initialization ScriptsAdversaries may use scripts automatically executed at boot or logon initialization to establish persistence.(Citation: Mandiant APT29 Eye Spy Email Nov 22)(Cit…
T1098Account ManipulationAdversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modif…
T1133External Remote ServicesAdversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other a…
T1136Create AccountAdversaries may create an account to maintain access to victim systems.(Citation: Symantec WastedLocker June 2020) With a sufficient level of access, creating …
T1137Office Application StartupAdversaries may leverage Microsoft Office-based applications for persistence between startups. Microsoft Office is a fairly common application suite on Windows…
T1176Software ExtensionsAdversaries may abuse software extensions to establish persistent access to victim systems. Software extensions are modular components that enhance or customiz…
T1504PowerShell ProfileAdversaries may gain persistence and elevate privileges in certain situations by abusing [PowerShell](https://attack.mitre.org/techniques/T1086) profiles. A Po…
T1505Server Software ComponentAdversaries may abuse legitimate extensible development features of servers to establish persistent access to systems. Enterprise server applications may inclu…
T1519EmondAdversaries may use Event Monitor Daemon (emond) to establish persistence by scheduling malicious commands to run on predictable event triggers. Emond is a [La…
T1525Implant Internal ImageAdversaries may implant cloud or container images with malicious code to establish persistence after gaining access to an environment. Amazon Web Services (AWS…
T1543Create or Modify System ProcessAdversaries may create or modify system-level processes to repeatedly execute malicious payloads as part of persistence. When operating systems boot up, they c…
T1547Boot or Logon Autostart ExecutionAdversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privilege…
T1554Compromise Host Software BinaryAdversaries may modify host software binaries to establish persistent access to systems. Software binaries/executables provide a wide range of system commands …
T1574Hijack Execution FlowAdversaries may execute their own malicious payloads by hijacking the way operating systems run programs. Hijacking execution flow can be for the purposes of p…
T1653Power SettingsAdversaries may impair a system's ability to hibernate, reboot, or shut down in order to extend access to infected machines. When a computer enters a dormant s…
T1668Exclusive ControlAdversaries who successfully compromise a system may attempt to maintain persistence by “closing the door” behind them – in other words, by preventing other t…
T1671Cloud Application IntegrationAdversaries may achieve persistence by leveraging OAuth application integrations in a software-as-a-service environment. Adversaries may create a custom applic…
Sourced from MITRE ATT&CK Enterprise (current release). Curated by Adam Lundqvist, Founder at SQUR.
MITRE ATT&CK techniques — by tactic | SQUR Knowledge Base