ATT&CKMatrix

Enterprise matrix

Shade shows how many procedure examples MITRE documents for a technique, counting its sub-techniques. The number on the right is the sub-technique count. Scroll the matrix sideways to see all 15 tactics.

none1 to 78 to 4041 to 173more than 173

Reconnaissance12 techniques

Active Scanning3Gather Victim Host Information4Gather Victim Identity Information3Gather Victim Network Information6Gather Victim Org Information4Phishing for Information4Query Public AI ServicesSearch Closed Sources2Search Open Technical Databases5Search Open Websites/Domains3Search Threat Vendor DataSearch Victim-Owned Websites

Resource Development9 techniques

Acquire AccessAcquire Infrastructure8Compromise Accounts3Compromise Infrastructure8Develop Capabilities4Establish Accounts3Generate Content2Obtain Capabilities7Stage Capabilities6

Initial Access11 techniques

Content InjectionDrive-by CompromiseExploit Public-Facing ApplicationExternal Remote ServicesHardware AdditionsPhishing4Replication Through Removable MediaSupply Chain Compromise3Trusted RelationshipValid Accounts4Wi-Fi Networks

Execution20 techniques

BITS JobsCloud Administration CommandCommand and Scripting Interpreter13Container Administration CommandDeploy ContainerESXi Administration CommandExploitation for Client ExecutionHijack Execution Flow12Input InjectionInter-Process Communication3Native APIPoisoned Pipeline ExecutionScheduled Task/Job5Serverless ExecutionShared ModulesSoftware Deployment ToolsSystem Services3Trusted Developer Utilities Proxy Execution3User Execution5Windows Management Instrumentation

Persistence22 techniques

Account Manipulation7BITS JobsBoot or Logon Autostart Execution14Boot or Logon Initialization Scripts5Cloud Application IntegrationCompromise Host Software BinaryCreate Account3Create or Modify System Process5Event Triggered Execution18Exclusive ControlExternal Remote ServicesImplant Internal ImageModify Authentication Process9Modify RegistryOffice Application Startup6Power SettingsPre-OS Boot5Scheduled Task/Job5Server Software Component6Software Extensions2Traffic Signaling2Valid Accounts4

Privilege Escalation13 techniques

Abuse Elevation Control Mechanism6Access Token Manipulation5Account Manipulation7Boot or Logon Autostart Execution14Boot or Logon Initialization Scripts5Create or Modify System Process5Domain or Tenant Policy Modification2Escape to HostEvent Triggered Execution18Exploitation for Privilege EscalationProcess Injection12Scheduled Task/Job5Valid Accounts4

Stealth30 techniques

Access Token Manipulation5BITS JobsBuild Image on HostDebugger EvasionDelay ExecutionDeobfuscate/Decode Files or InformationDirect Volume AccessExecution Guardrails2Exploitation for StealthHide Artifacts14Hijack Execution Flow12Indicator Removal8Indirect Command ExecutionMasquerading12Obfuscated Files or Information18Pre-OS Boot5Process Injection12Reflective Code LoadingRootkitSelective ExclusionSocial Engineering2System Binary Proxy Execution14System Script Proxy Execution2Template InjectionTraffic Signaling2Trusted Developer Utilities Proxy Execution3Unused/Unsupported Cloud RegionsValid Accounts4Virtualization/Sandbox Evasion3XSL Script Processing

Defense Impairment18 techniques

Disable or Modify System Firewall3Disable or Modify Tools6Domain or Tenant Policy Modification2Downgrade AttackExploitation for Defense ImpairmentFile and Directory Permissions Modification2Modify Authentication Process9Modify Cloud Compute Infrastructure5Modify Cloud Resource HierarchyModify RegistryModify System Image2Network Boundary Bridging1Plist File ModificationPrevent Command History LoggingRogue Domain ControllerSafe Mode BootSubvert Trust Controls6Weaken Encryption2

Credential Access17 techniques

Adversary-in-the-Middle4Brute Force4Credentials from Password Stores6Exploitation for Credential AccessForced AuthenticationForge Web Credentials2Input Capture4Modify Authentication Process9Multi-Factor Authentication InterceptionMulti-Factor Authentication Request GenerationNetwork SniffingOS Credential Dumping8Steal Application Access TokenSteal or Forge Authentication CertificatesSteal or Forge Kerberos Tickets5Steal Web Session CookieUnsecured Credentials8

Discovery34 techniques

Account Discovery4Application Window DiscoveryBrowser Information DiscoveryCloud Infrastructure DiscoveryCloud Service DashboardCloud Service DiscoveryCloud Storage Object DiscoveryContainer and Resource DiscoveryDebugger EvasionDevice Driver DiscoveryDomain Trust DiscoveryFile and Directory DiscoveryGroup Policy DiscoveryLocal Storage DiscoveryLog EnumerationNetwork Service DiscoveryNetwork Share DiscoveryNetwork SniffingPassword Policy DiscoveryPeripheral Device DiscoveryPermission Groups Discovery3Process DiscoveryQuery RegistryRemote System DiscoverySoftware Discovery2System Information DiscoverySystem Location Discovery1System Network Configuration Discovery2System Network Connections DiscoverySystem Owner/User DiscoverySystem Service DiscoverySystem Time DiscoveryVirtual Machine DiscoveryVirtualization/Sandbox Evasion3

Lateral Movement9 techniques

Exploitation of Remote ServicesInternal SpearphishingLateral Tool TransferRemote Service Session Hijacking2Remote Services8Replication Through Removable MediaSoftware Deployment ToolsTaint Shared ContentUse Alternate Authentication Material4

Collection17 techniques

Adversary-in-the-Middle4Archive Collected Data3Audio CaptureAutomated CollectionBrowser Session HijackingClipboard DataData from Cloud StorageData from Configuration Repository2Data from Information Repositories6Data from Local SystemData from Network Shared DriveData from Removable MediaData Staged2Email Collection3Input Capture4Screen CaptureVideo Capture

Command and Control18 techniques

Application Layer Protocol5Communication Through Removable MediaContent InjectionData Encoding2Data Obfuscation3Dynamic Resolution3Encrypted Channel2Fallback ChannelsHide InfrastructureIngress Tool TransferMulti-Stage ChannelsNon-Application Layer ProtocolNon-Standard PortProtocol TunnelingProxy4Remote Access Tools3Traffic Signaling2Web Service3

Exfiltration9 techniques

Automated Exfiltration1Data Transfer Size LimitsExfiltration Over Alternative Protocol3Exfiltration Over C2 ChannelExfiltration Over Other Network Medium1Exfiltration Over Physical Medium1Exfiltration Over Web Service4Scheduled TransferTransfer Data to Cloud Account

Impact15 techniques

Account Access RemovalData Destruction1Data Encrypted for ImpactData Manipulation3Defacement2Disk Wipe2Email BombingEndpoint Denial of Service4Financial TheftFirmware CorruptionInhibit System RecoveryNetwork Denial of Service2Resource Hijacking4Service StopSystem Shutdown/Reboot

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.