475 results
| ID | Name | Tactics | Sub-techniques | Examples |
|---|---|---|---|---|
| T1546.012 | Image File Execution Options Injection | 0 | 3 | |
| T1546.013 | PowerShell Profile | 0 | 1 | |
| T1546.014 | Emond | 0 | 0 | |
| T1546.015 | Component Object Model Hijacking | 0 | 12 | |
| T1546.016 | Installer Packages | 0 | 5 | |
| T1546.017 | Udev Rules | 0 | 1 | |
| T1546.018 | Python Startup Hooks | 0 | 2 | |
| T1547.001 | Registry Run Keys / Startup Folder | 0 | 261 | |
| T1547.002 | Authentication Package | 0 | 1 | |
| T1547.003 | Time Providers | 0 | 0 | |
| T1547.004 | Winlogon Helper DLL | 0 | 13 | |
| T1547.005 | Security Support Provider | 0 | 3 | |
| T1547.006 | Kernel Modules and Extensions | 0 | 4 | |
| T1547.007 | Re-opened Applications | 0 | 0 | |
| T1547.008 | LSASS Driver | 0 | 2 | |
| T1547.009 | Shortcut Modification | 0 | 29 | |
| T1547.010 | Port Monitors | 0 | 0 | |
| T1547.012 | Print Processors | 0 | 3 | |
| T1547.013 | XDG Autostart Entries | 0 | 7 | |
| T1547.014 | Active Setup | 0 | 1 | |
| T1547.015 | Login Items | 0 | 3 | |
| T1548.001 | Setuid and Setgid | 0 | 2 | |
| T1548.002 | Bypass User Account Control | 0 | 63 | |
| T1548.003 | Sudo and Sudo Caching | 0 | 6 | |
| T1548.004 | Elevated Execution with Prompt | 0 | 1 | |
| T1548.005 | Temporary Elevated Cloud Access | 0 | 0 | |
| T1548.006 | TCC Manipulation | 0 | 1 | |
| T1550.001 | Application Access Token | 0 | 11 | |
| T1550.002 | Pass the Hash | 0 | 22 | |
| T1550.003 | Pass the Ticket | 0 | 6 | |
| T1550.004 | Web Session Cookie | 0 | 2 | |
| T1552.001 | Credentials In Files | 0 | 41 | |
| T1552.002 | Credentials in Registry | 0 | 10 | |
| T1552.003 | Shell History | 0 | 2 | |
| T1552.004 | Private Keys | 0 | 23 | |
| T1552.005 | Cloud Instance Metadata API | 0 | 6 | |
| T1552.006 | Group Policy Preferences | 0 | 5 | |
| T1552.007 | Container API | 0 | 3 | |
| T1552.008 | Chat Messages | 0 | 1 | |
| T1553.001 | Gatekeeper Bypass | 0 | 6 | |
| T1553.002 | Code Signing | 0 | 89 | |
| T1553.003 | SIP and Trust Provider Hijacking | 0 | 0 | |
| T1553.004 | Install Root Certificate | 0 | 5 | |
| T1553.005 | Mark-of-the-Web Bypass | 0 | 5 | |
| T1553.006 | Code Signing Policy Modification | 0 | 5 | |
| T1555.001 | Keychain | 0 | 12 | |
| T1555.002 | Securityd Memory | 0 | 1 | |
| T1555.003 | Credentials from Web Browsers | 0 | 89 | |
| T1555.004 | Windows Credential Manager | 0 | 14 | |
| T1555.005 | Password Managers | 0 | 13 |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.