235 indexed

ATT&CKATT&CK techniques

235 top-level MITRE ATT&CK Enterprise techniques (T-IDs), grouped by tactic. Filter to a tactic or browse the full kill chain, then click into a technique for sub-techniques and mitigations. Authored by Adam Lundqvist.

12 in Reconnaissance · 235 total

IDTitleSummary
T1589Gather Victim Identity InformationAdversaries may gather information about the victim's identity that can be used during targeting. Information about identities may include a variety of details…
T1590Gather Victim Network InformationAdversaries may gather information about the victim's networks that can be used during targeting. Information about networks may include a variety of details, …
T1591Gather Victim Org InformationAdversaries may gather information about the victim's organization that can be used during targeting. Information about an organization may include a variety o…
T1592Gather Victim Host InformationAdversaries may gather information about the victim's hosts that can be used during targeting. Information about hosts may include a variety of details, includ…
T1593Search Open Websites/DomainsAdversaries may search freely available websites and/or domains for information about victims that can be used during targeting. Information about victims may …
T1594Search Victim-Owned WebsitesAdversaries may search websites owned by the victim for information that can be used during targeting. Victim-owned websites may contain a variety of details, …
T1595Active ScanningAdversaries may execute active reconnaissance scans to gather information that can be used during targeting. Active scans are those where the adversary probes …
T1596Search Open Technical DatabasesAdversaries may search freely available technical databases for information about victims that can be used during targeting. Information about victims may be a…
T1597Search Closed SourcesAdversaries may search and gather information about victims from closed (e.g., paid, private, or otherwise not freely available) sources that can be used durin…
T1598Phishing for InformationAdversaries may send phishing messages to elicit sensitive information that can be used during targeting. Phishing for information is an attempt to trick targe…
T1681Search Threat Vendor DataThreat actors may seek information/indicators from closed or open threat intelligence sources gathered about their own campaigns, as well as those conducted by…
T1682Query Public AI ServicesAdversaries may query publicly accessible artificial intelligence (AI) services, such as large language models (LLMs), to support targeting and operations. In …
Sourced from MITRE ATT&CK Enterprise (current release). Curated by Adam Lundqvist, Founder at SQUR.
MITRE ATT&CK techniques — by tactic | SQUR Knowledge Base