ATT&CKTechniques

Techniques

222 results

IDNameTacticsSub-techniquesExamples
T1001 Data Obfuscation 315
T1003 OS Credential Dumping 820
T1005 Data from Local System 0230
T1006 Direct Volume Access 05
T1007 System Service Discovery 069
T1008 Fallback Channels 057
T1010 Application Window Discovery 037
T1011 Exfiltration Over Other Network Medium 10
T1012 Query Registry 0119
T1014 Rootkit 032
T1016 System Network Configuration Discovery 2289
T1018 Remote System Discovery 0104
T1020 Automated Exfiltration 131
T1021 Remote Services 87
T1025 Data from Removable Media 024
T1027 Obfuscated Files or Information 18160
T1029 Scheduled Transfer 018
T1030 Data Transfer Size Limits 021
T1033 System Owner/User Discovery 0244
T1036 Masquerading 1260
T1037 Boot or Logon Initialization Scripts 58
T1039 Data from Network Shared Drive 013
T1040 Network Sniffing 028
T1041 Exfiltration Over C2 Channel 0203
T1046 Network Service Discovery 073
T1047 Windows Management Instrumentation 0147
T1048 Exfiltration Over Alternative Protocol 39
T1049 System Network Connections Discovery 098
T1052 Exfiltration Over Physical Medium 10
T1053 Scheduled Task/Job 52
T1055 Process Injection 1287
T1056 Input Capture 412
T1057 Process Discovery 0319
T1059 Command and Scripting Interpreter 1344
T1068 Exploitation for Privilege Escalation 043
T1069 Permission Groups Discovery 313
T1070 Indicator Removal 833
T1071 Application Layer Protocol 516
T1072 Software Deployment Tools 010
T1074 Data Staged 29
T1078 Valid Accounts 465
T1080 Taint Shared Content 012
T1082 System Information Discovery 0427
T1083 File and Directory Discovery 0373
T1087 Account Discovery 410
T1090 Proxy 476
T1091 Replication Through Removable Media 028
T1092 Communication Through Removable Media 03
T1095 Non-Application Layer Protocol 0108
T1098 Account Manipulation 79

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.