ATT&CKTechniques

Techniques

475 results

IDNameTacticsSub-techniquesExamples
T1546.012 Image File Execution Options Injection 03
T1546.013 PowerShell Profile 01
T1546.014 Emond 00
T1546.015 Component Object Model Hijacking 012
T1546.016 Installer Packages 05
T1546.017 Udev Rules 01
T1546.018 Python Startup Hooks 02
T1547.001 Registry Run Keys / Startup Folder 0261
T1547.002 Authentication Package 01
T1547.003 Time Providers 00
T1547.004 Winlogon Helper DLL 013
T1547.005 Security Support Provider 03
T1547.006 Kernel Modules and Extensions 04
T1547.007 Re-opened Applications 00
T1547.008 LSASS Driver 02
T1547.009 Shortcut Modification 029
T1547.010 Port Monitors 00
T1547.012 Print Processors 03
T1547.013 XDG Autostart Entries 07
T1547.014 Active Setup 01
T1547.015 Login Items 03
T1548.001 Setuid and Setgid 02
T1548.002 Bypass User Account Control 063
T1548.003 Sudo and Sudo Caching 06
T1548.004 Elevated Execution with Prompt 01
T1548.005 Temporary Elevated Cloud Access 00
T1548.006 TCC Manipulation 01
T1550.001 Application Access Token 011
T1550.002 Pass the Hash 022
T1550.003 Pass the Ticket 06
T1550.004 Web Session Cookie 02
T1552.001 Credentials In Files 041
T1552.002 Credentials in Registry 010
T1552.003 Shell History 02
T1552.004 Private Keys 023
T1552.005 Cloud Instance Metadata API 06
T1552.006 Group Policy Preferences 05
T1552.007 Container API 03
T1552.008 Chat Messages 01
T1553.001 Gatekeeper Bypass 06
T1553.002 Code Signing 089
T1553.003 SIP and Trust Provider Hijacking 00
T1553.004 Install Root Certificate 05
T1553.005 Mark-of-the-Web Bypass 05
T1553.006 Code Signing Policy Modification 05
T1555.001 Keychain 012
T1555.002 Securityd Memory 01
T1555.003 Credentials from Web Browsers 089
T1555.004 Windows Credential Manager 014
T1555.005 Password Managers 013

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.