Techniques, groups, software and campaigns, linked to the procedure examples and reports behind them. Find what attackers do, then check that your detections cover it.
An attack moves left to right through these goals. Each box shows how many techniques serve it.
| Technique | Examples |
|---|---|
| T1059 Command and Scripting Interpreter | 1033 |
| T1027 Obfuscated Files or Information | 815 |
| T1071 Application Layer Protocol | 547 |
| T1105 Ingress Tool Transfer | 520 |
| T1070 Indicator Removal | 443 |
| T1036 Masquerading | 437 |
| T1082 System Information Discovery | 427 |
| T1083 File and Directory Discovery | 373 |
| T1140 Deobfuscate/Decode Files or Information | 353 |
| T1547 Boot or Logon Autostart Execution | 333 |
| Group | Techniques |
|---|---|
| Kimsuky | 130 |
| APT28 | 93 |
| Lazarus Group | 93 |
| Mustang Panda | 85 |
| APT41 | 82 |
| Volt Typhoon | 81 |
| Sandworm Team | 79 |
| APT32 | 78 |
| Magic Hound | 78 |
| OilRig | 76 |
| Software | Techniques |
|---|---|
| Cobalt Strike | 73 |
| Empire | 73 |
| InvisiMole | 73 |
| QakBot | 71 |
| DarkGate | 58 |
| Mini Shai-Hulud | 55 |
| TrickBot | 55 |
| SILENTTRINITY | 53 |
| Qilin | 52 |
| Bazar | 51 |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.