ATT&CKMatrixExecution

Execution

TA0002

Tactic.View on attack.mitre.org

About this tactic

The adversary is trying to run malicious code.

Execution consists of techniques that result in adversary-controlled code running on a local or remote system. Techniques that run malicious code are often paired with techniques from all other tactics to achieve broader goals, like exploring a network or stealing data. For example, an adversary might use a remote access tool to run a PowerShell script that does Remote System Discovery.

Techniques20

IDNameSub-techniquesExamples
T1047Windows Management Instrumentation0147
T1053Scheduled Task/Job5216
T1059Command and Scripting Interpreter131033
T1072Software Deployment Tools010
T1106Native API0228
T1127Trusted Developer Utilities Proxy Execution35
T1129Shared Modules022
T1197BITS Jobs013
T1203Exploitation for Client Execution061
T1204User Execution5296
T1559Inter-Process Communication360
T1569System Services380
T1574Hijack Execution Flow12152
T1609Container Administration Command08
T1610Deploy Container04
T1648Serverless Execution01
T1651Cloud Administration Command04
T1674Input Injection01
T1675ESXi Administration Command02
T1677Poisoned Pipeline Execution04

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.