222 results
| ID | Name | Tactics | Sub-techniques | Examples |
|---|---|---|---|---|
| T1571 | Non-Standard Port | 0 | 66 | |
| T1572 | Protocol Tunneling | 0 | 42 | |
| T1573 | Encrypted Channel | 2 | 17 | |
| T1574 | Hijack Execution Flow | 12 | 11 | |
| T1578 | Modify Cloud Compute Infrastructure | 5 | 0 | |
| T1580 | Cloud Infrastructure Discovery | 0 | 6 | |
| T1583 | Acquire Infrastructure | 8 | 9 | |
| T1584 | Compromise Infrastructure | 8 | 2 | |
| T1585 | Establish Accounts | 3 | 6 | |
| T1586 | Compromise Accounts | 3 | 0 | |
| T1587 | Develop Capabilities | 4 | 3 | |
| T1588 | Obtain Capabilities | 7 | 0 | |
| T1589 | Gather Victim Identity Information | 3 | 12 | |
| T1590 | Gather Victim Network Information | 6 | 3 | |
| T1591 | Gather Victim Org Information | 4 | 9 | |
| T1592 | Gather Victim Host Information | 4 | 1 | |
| T1593 | Search Open Websites/Domains | 3 | 6 | |
| T1594 | Search Victim-Owned Websites | 0 | 9 | |
| T1595 | Active Scanning | 3 | 1 | |
| T1596 | Search Open Technical Databases | 5 | 2 | |
| T1597 | Search Closed Sources | 2 | 1 | |
| T1598 | Phishing for Information | 4 | 6 | |
| T1599 | Network Boundary Bridging | 1 | 2 | |
| T1600 | Weaken Encryption | 2 | 0 | |
| T1601 | Modify System Image | 2 | 1 | |
| T1602 | Data from Configuration Repository | 2 | 0 | |
| T1606 | Forge Web Credentials | 2 | 0 | |
| T1608 | Stage Capabilities | 6 | 1 | |
| T1609 | Container Administration Command | 0 | 8 | |
| T1610 | Deploy Container | 0 | 4 | |
| T1611 | Escape to Host | 0 | 5 | |
| T1612 | Build Image on Host | 0 | 0 | |
| T1613 | Container and Resource Discovery | 0 | 5 | |
| T1614 | System Location Discovery | 1 | 27 | |
| T1615 | Group Policy Discovery | 0 | 7 | |
| T1619 | Cloud Storage Object Discovery | 0 | 4 | |
| T1620 | Reflective Code Loading | 0 | 32 | |
| T1621 | Multi-Factor Authentication Request Generation | 0 | 4 | |
| T1622 | Debugger Evasion | 0 | 26 | |
| T1647 | Plist File Modification | 0 | 2 | |
| T1648 | Serverless Execution | 0 | 1 | |
| T1649 | Steal or Forge Authentication Certificates | 0 | 4 | |
| T1650 | Acquire Access | 0 | 1 | |
| T1651 | Cloud Administration Command | 0 | 4 | |
| T1652 | Device Driver Discovery | 0 | 4 | |
| T1653 | Power Settings | 0 | 3 | |
| T1654 | Log Enumeration | 0 | 10 | |
| T1657 | Financial Theft | 0 | 26 | |
| T1659 | Content Injection | 0 | 2 | |
| T1665 | Hide Infrastructure | 0 | 8 |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.