212 indexed

ATT&CKATT&CK techniques

212 top-level MITRE ATT&CK Enterprise techniques (T-IDs), grouped by tactic. Filter to a tactic or browse the full kill chain, then click into a technique for sub-techniques and mitigations. Authored by Adam Lundqvist.

8 in Resource Development · 212 total

IDTitleSummary
T1583Acquire InfrastructureAdversaries may buy, lease, or rent infrastructure that can be used during targeting. A wide variety of infrastructure exists for hosting and orchestrating adv…
T1584Compromise InfrastructureAdversaries may compromise third-party infrastructure that can be used during targeting. Infrastructure solutions include physical or cloud servers, domains, a…
T1585Establish AccountsAdversaries may create and cultivate accounts with services that can be used during targeting. Adversaries can create accounts that can be used to build a pers…
T1586Compromise AccountsAdversaries may compromise accounts with services that can be used during targeting. For operations incorporating social engineering, the utilization of an onl…
T1587Develop CapabilitiesAdversaries may build capabilities that can be used during targeting. Rather than purchasing, freely downloading, or stealing capabilities, adversaries may dev…
T1588Obtain CapabilitiesAdversaries may buy and/or steal capabilities that can be used during targeting. Rather than developing their own capabilities in-house, adversaries may purcha…
T1608Stage CapabilitiesAdversaries may upload, install, or otherwise set up capabilities that can be used during targeting. To support their operations, an adversary may need to take…
T1650Acquire AccessAdversaries may purchase or otherwise acquire an existing access to a target system or network. A variety of online services and initial access broker networks…
Sourced from MITRE ATT&CK Enterprise (current release). Curated by Adam Lundqvist, Founder at SQUR.
MITRE ATT&CK techniques — by tactic | SQUR Knowledge Base