Cyber Posture

Exploiting vulnerabilities

Which techniques are used to exploit vulnerabilities?

We have analyzed each CVE to identify the MITRE ATT&CK Enterprise techniques it enables or facilitates. These charts show the distribution of attack tactics and techniques across 37,236 annotated CVEs, their severity and exploit probability, and how actively-exploited vulnerabilities (CISA KEV) compare to the full set.

Last updated: 28 May 2026 22:48 UTC

Tactics & Techniques

How are vulnerabilities linked to tactics and techniques?

→ Click any tactic bar to filter the technique list below it.

→ Click any technique bar to open its MITRE ATT&CK detail page in a new tab.

Technique Risk

Which techniques are used to exploit the most severe vulnerabilities?

→ Each bubble is one MITRE technique. Bubble size = CVE count. The upper-right quadrant (high CVSS, high EPSS) highlights techniques associated with the most severe and exploit-likely vulnerabilities.

→ Hover (or tap) any bubble for technique details.

Top 25 techniques by CVE count.

IDNameTacticCVEsAvg CVSSAvg EPSS
T1190Exploit Public-Facing ApplicationInitial Access21,8197.470.0169
T1068Exploitation for Privilege EscalationPrivilege Escalation4,9057.790.0073
T1499.004Application or System ExploitationImpact3,5266.770.0036
T1213.006DatabasesCollection3,2317.210.0075
T1059.007JavaScriptExecution2,8265.780.0049
T1203Exploitation for Client ExecutionExecution2,0227.960.0101
T1005Data from Local SystemCollection1,6237.130.0281
T1059.004Unix ShellExecution1,4378.040.0383
T1539Steal Web Session CookieCredential Access1,3256.020.0061
T1505Server Software ComponentPersistence1,2066.640.0047
T1505.003Web ShellPersistence1,0327.810.0401
T1210Exploitation of Remote ServicesLateral Movement1,0078.200.0239
T1185Browser Session HijackingCollection8836.570.0034
T1204.002Malicious FileExecution8407.490.0035
T1189Drive-by CompromiseInitial Access8137.300.0055
T1059Command and Scripting InterpreterExecution7048.000.0193
T1565.001Stored Data ManipulationImpact6347.220.0042
T1552.001Credentials In FilesCredential Access6137.100.0386
T1204.001Malicious LinkExecution5007.090.0036
T1083File and Directory DiscoveryDiscovery4066.850.0508
T1566.002Spearphishing LinkInitial Access4016.650.0044
T1555.003Credentials from Web BrowsersCredential Access3895.480.0083
T1059.008Network Device CLIExecution3627.710.0466
T1105Ingress Tool TransferCommand And Control3587.420.0361
T1552Unsecured CredentialsCredential Access3517.060.0132

KEV Tactics

→ Compares how attack tactics are distributed across all annotated CVEs versus those on the CISA Known Exploited Vulnerabilities list. Tactics with a larger red bar than grey bar are over-represented in actively exploited vulnerabilities.

KEV Techniques

→ Each circle is one MITRE ATT&CK technique used by at least one KEV-listed CVE. Above the dashed diagonal = the technique appears in KEV-listed exploits more frequently than its share of the overall annotated-CVE population (attackers favour it). Below = under-represented. Bubble size encodes KEV count. Hover (or tap) any bubble for technique details.

Top 25 techniques by KEV count, sorted by KEV count descending. Tap any column header to re-sort.

IDNameKEV countAll countKEV %All %Ratio
T1190Exploit Public-Facing Application13022,26656.0%59.80%0.9×
T1068Exploitation for Privilege Escalation455,16319.4%13.87%1.4×
T1203Exploitation for Client Execution302,09212.9%5.62%2.3×
T1059.004Unix Shell181,4607.8%3.92%2.0×
T1005Data from Local System151,6906.5%4.54%1.4×
T1210Exploitation of Remote Services131,0245.6%2.75%2.0×
T1189Drive-by Compromise128225.2%2.21%2.3×
T1195.002Compromise Software Supply Chain8913.4%0.24%14.1×
T1059Command and Scripting Interpreter67342.6%1.97%1.3×
T1204.002Malicious File68602.6%2.31%1.1×
T1505.003Web Shell61,0532.6%2.83%0.9×
T1552.001Credentials In Files66442.6%1.73%1.5×
T1083File and Directory Discovery54352.2%1.17%1.8×
T1078.001Default Accounts42001.7%0.54%3.2×
T1105Ingress Tool Transfer43691.7%0.99%1.7×
T1136.001Local Account4881.7%0.24%7.3×
T1187Forced Authentication4211.7%0.06%30.6×
T1195.001Compromise Software Dependencies and Development Tools4591.7%0.16%10.9×
T1212Exploitation for Credential Access42951.7%0.79%2.2×
T1059.006Python33061.3%0.82%1.6×
T1059.007JavaScript32,8631.3%7.69%0.2×
T1059.008Network Device CLI33641.3%0.98%1.3×
T1211Exploitation for Stealth31311.3%0.35%3.7×
T1611Escape to Host3971.3%0.26%5.0×
T1003OS Credential Dumping2130.9%0.03%24.7×

Mitigating Controls per Technique

Which NIST 800-53 r5 controls mitigate each ATT&CK technique?

→ One row per technique. The # Controls column counts the NIST 800-53 r5 controls that have a published mitigation relationship with this technique (Center for Threat-Informed Defense / mappings-explorer, refreshed to ATT&CK v19).

→ Hover any control pill for its NIST title. Tap the column headers to re-sort; tap "more" inside a row to see additional controls.

TechniqueNameTactic(s)# ControlsTop mitigating controls (NIST 800-53 r5)
T1530Data from Cloud StorageCollection32AC-16 AC-17 AC-18 AC-19 AC-2
+27 more
AC-20 AC-3 AC-4 AC-5 AC-6 AC-7 CA-7 CM-2 CM-5 CM-6 CM-7 CM-8 IA-2 IA-3 IA-4 IA-5 IA-6 IA-8 RA-5 SC-28 SC-4 SC-7 SI-10 SI-12 SI-15 SI-4 SI-7
T1552Unsecured CredentialsCredential Access32AC-16 AC-17 AC-18 AC-19 AC-2
+27 more
AC-20 AC-3 AC-4 AC-5 AC-6 CA-7 CM-2 CM-5 CM-6 CM-7 IA-2 IA-3 IA-4 IA-5 RA-5 SA-11 SA-15 SC-12 SC-28 SC-4 SC-7 SI-10 SI-12 SI-15 SI-2 SI-4 SI-7
T1210Exploitation of Remote ServicesLateral Movement31AC-2 AC-3 AC-4 AC-5 AC-6
+26 more
CA-2 CA-7 CM-2 CM-5 CM-6 CM-7 CM-8 IA-2 IA-8 RA-10 RA-5 SC-18 SC-2 SC-26 SC-29 SC-3 SC-30 SC-35 SC-39 SC-46 SC-7 SI-2 SI-3 SI-4 SI-5 SI-7
T1190Exploit Public-Facing ApplicationInitial Access29AC-2 AC-3 AC-4 AC-5 AC-6
+24 more
CA-2 CA-7 CM-5 CM-6 CM-7 CM-8 IA-2 IA-8 RA-10 RA-5 SA-8 SC-18 SC-2 SC-29 SC-3 SC-30 SC-39 SC-46 SC-7 SI-10 SI-2 SI-3 SI-4 SI-7
T1072Software Deployment ToolsExecution, Lateral Movement27AC-12 AC-2 AC-20 AC-3 AC-4
+22 more
AC-5 AC-6 CA-7 CM-11 CM-2 CM-5 CM-6 CM-7 CM-8 IA-2 IA-5 SA-10 SA-9 SC-12 SC-17 SC-46 SC-7 SI-2 SI-23 SI-3 SI-4 SI-7
T1565Data ManipulationImpact26AC-16 AC-17 AC-18 AC-19 AC-20
+21 more
AC-3 AC-4 CA-7 CM-2 CM-6 CM-7 CM-8 CP-10 CP-6 CP-7 CP-9 SC-28 SC-36 SC-4 SC-46 SC-7 SI-12 SI-16 SI-23 SI-4 SI-7
T1078Valid AccountsStealth, Persistence, Privilege Escalation, Initial Access25AC-2 AC-3 AC-5 AC-6 CA-3
+20 more
CA-7 CM-5 CM-6 CM-7 IA-12 IA-13 IA-2 IA-5 RA-5 SA-10 SA-11 SA-15 SA-17 SA-3 SA-4 SA-8 SC-28 SC-43 SC-7 SI-4
T1602Data from Configuration RepositoryCollection25AC-16 AC-17 AC-18 AC-19 AC-20
+20 more
AC-3 AC-4 CA-7 CM-2 CM-6 CM-7 CM-8 IA-3 IA-4 SC-28 SC-3 SC-4 SC-7 SC-8 SI-10 SI-12 SI-15 SI-3 SI-4 SI-7
T1602.001SNMP (MIB Dump)Collection25AC-16 AC-17 AC-18 AC-19 AC-20
+20 more
AC-3 AC-4 CA-7 CM-2 CM-6 CM-7 CM-8 IA-3 IA-4 SC-28 SC-3 SC-4 SC-7 SC-8 SI-10 SI-12 SI-15 SI-3 SI-4 SI-7
T1602.002Network Device Configuration DumpCollection25AC-16 AC-17 AC-18 AC-19 AC-20
+20 more
AC-3 AC-4 CA-7 CM-2 CM-6 CM-7 CM-8 IA-3 IA-4 SC-28 SC-3 SC-4 SC-7 SC-8 SI-10 SI-12 SI-15 SI-3 SI-4 SI-7
T1078.004Cloud AccountsStealth, Persistence, Privilege Escalation, Initial Access24AC-2 AC-20 AC-3 AC-5 AC-6
+19 more
AC-7 CA-7 CM-5 CM-6 CM-7 IA-12 IA-13 IA-2 IA-5 SA-10 SA-11 SA-15 SA-17 SA-3 SA-4 SA-8 SC-28 SC-43 SI-4
T1212Exploitation for Credential AccessCredential Access24AC-2 AC-4 AC-6 CA-7 CM-2
+19 more
CM-6 CM-8 IA-2 IA-5 RA-10 RA-5 SC-18 SC-2 SC-26 SC-3 SC-30 SC-35 SC-39 SC-7 SI-2 SI-3 SI-4 SI-5 SI-7
T1213Data from Information RepositoriesCollection24AC-16 AC-17 AC-2 AC-21 AC-23
+19 more
AC-3 AC-4 AC-5 AC-6 CA-7 CM-2 CM-3 CM-5 CM-6 CM-7 CM-8 IA-2 IA-4 IA-8 RA-5 SC-28 SC-37 SI-4 SI-7
T1213.005Messaging ApplicationsCollection24AC-16 AC-17 AC-2 AC-21 AC-23
+19 more
AC-3 AC-4 AC-6 CA-7 CM-2 CM-3 CM-5 CM-6 CM-7 CM-8 IA-2 IA-4 IA-8 RA-5 SC-28 SC-37 SI-2 SI-4 SI-7
T1557Adversary-in-the-MiddleCredential Access, Collection24AC-16 AC-17 AC-18 AC-19 AC-20
+19 more
AC-3 AC-4 CA-7 CM-2 CM-6 CM-7 CM-8 RA-5 SC-23 SC-4 SC-46 SC-7 SC-8 SI-10 SI-12 SI-15 SI-3 SI-4 SI-7
T1601Modify System ImageDefense Impairment24AC-2 AC-3 AC-4 AC-5 AC-6
+19 more
CM-2 CM-3 CM-5 CM-6 CM-7 CM-8 IA-2 IA-5 IA-7 RA-9 SA-10 SA-11 SC-34 SI-2 SI-4 SI-7 SR-11 SR-4 SR-5
T1601.001Patch System ImageDefense Impairment24AC-2 AC-3 AC-4 AC-5 AC-6
+19 more
CM-2 CM-3 CM-5 CM-6 CM-7 CM-8 IA-2 IA-5 IA-7 RA-9 SA-10 SA-11 SC-34 SI-2 SI-4 SI-7 SR-11 SR-4 SR-5
T1601.002Downgrade System ImageDefense Impairment24AC-2 AC-3 AC-4 AC-5 AC-6
+19 more
CM-2 CM-3 CM-5 CM-6 CM-7 CM-8 IA-2 IA-5 IA-7 RA-9 SA-10 SA-11 SC-34 SI-2 SI-4 SI-7 SR-11 SR-4 SR-5
T1021.001Remote Desktop ProtocolLateral Movement23AC-11 AC-12 AC-17 AC-2 AC-20
+18 more
AC-3 AC-4 AC-5 AC-6 AC-7 CM-2 CM-5 CM-6 CM-7 CM-8 IA-2 IA-4 IA-5 IA-6 RA-5 SC-46 SC-7 SI-4
T1048Exfiltration Over Alternative ProtocolExfiltration23AC-16 AC-2 AC-20 AC-23 AC-3
+18 more
AC-4 AC-6 CA-3 CA-7 CM-2 CM-6 CM-7 SA-8 SA-9 SC-28 SC-31 SC-46 SC-7 SI-10 SI-15 SI-3 SI-4 SR-4
T1048.002Exfiltration Over Asymmetric Encrypted Non-C2 ProtocolExfiltration23AC-16 AC-2 AC-20 AC-23 AC-3
+18 more
AC-4 AC-6 CA-3 CA-7 CM-2 CM-6 CM-7 SA-8 SA-9 SC-28 SC-31 SC-46 SC-7 SI-10 SI-15 SI-3 SI-4 SR-4
T1048.003Exfiltration Over Unencrypted Non-C2 ProtocolExfiltration23AC-16 AC-2 AC-20 AC-23 AC-3
+18 more
AC-4 AC-6 CA-3 CA-7 CM-2 CM-6 CM-7 SA-8 SA-9 SC-13 SC-28 SC-31 SC-7 SI-10 SI-15 SI-3 SI-4 SR-4
T1059Command and Scripting InterpreterExecution23AC-17 AC-2 AC-3 AC-5 AC-6
+18 more
CA-7 CM-11 CM-2 CM-5 CM-6 CM-7 CM-8 IA-2 IA-8 IA-9 RA-5 SC-18 SI-10 SI-16 SI-2 SI-3 SI-4 SI-7
T1213.001ConfluenceCollection23AC-16 AC-17 AC-2 AC-21 AC-23
+18 more
AC-3 AC-4 AC-5 AC-6 CA-7 CM-2 CM-3 CM-5 CM-6 CM-7 CM-8 IA-2 IA-4 IA-8 RA-5 SC-28 SI-4 SI-7
T1213.002SharepointCollection23AC-16 AC-17 AC-2 AC-21 AC-23
+18 more
AC-3 AC-4 AC-5 AC-6 CA-7 CM-2 CM-3 CM-5 CM-6 CM-7 CM-8 IA-2 IA-4 IA-8 RA-5 SC-28 SI-4 SI-7
T1542.005TFTP BootStealth, Persistence23AC-2 AC-3 AC-5 AC-6 CA-7
+18 more
CM-2 CM-3 CM-5 CM-6 CM-7 CM-8 IA-2 IA-7 IA-8 RA-5 RA-9 SA-10 SA-11 SC-34 SC-7 SI-2 SI-4 SI-7
T1565.001Stored Data ManipulationImpact23AC-16 AC-17 AC-18 AC-19 AC-20
+18 more
AC-3 CA-7 CM-2 CM-6 CM-8 CP-10 CP-6 CP-7 CP-9 SC-28 SC-36 SC-4 SC-7 SI-12 SI-16 SI-23 SI-4 SI-7
T1003OS Credential DumpingCredential Access22AC-16 AC-2 AC-3 AC-4 AC-5
+17 more
AC-6 CA-7 CM-2 CM-5 CM-6 CM-7 CP-9 IA-2 IA-4 IA-5 SC-28 SC-39 SI-12 SI-2 SI-3 SI-4 SI-7
T1021.005VNCLateral Movement22AC-17 AC-2 AC-3 AC-4 AC-6
+17 more
CA-7 CM-11 CM-2 CM-3 CM-5 CM-6 CM-7 CM-8 IA-2 IA-4 IA-6 RA-5 SC-7 SI-10 SI-15 SI-3 SI-4
T1070.008Clear Mailbox DataStealth22AC-16 AC-17 AC-18 AC-19 AC-2
+17 more
AC-20 AC-3 AC-4 AC-5 AC-6 CA-7 CM-2 CM-6 CP-6 CP-7 CP-9 SC-36 SC-4 SI-12 SI-3 SI-4 SI-7
T1195Supply Chain CompromiseInitial Access22AC-2 AC-3 AC-6 CA-2 CA-7
+17 more
CM-11 CM-2 CM-3 CM-5 CM-6 CM-7 CM-8 RA-10 RA-5 SA-22 SI-2 SI-3 SI-4 SI-7 SR-11 SR-4 SR-5
T1211Exploitation for StealthStealth22AC-4 AC-6 CA-7 CM-2 CM-6
+17 more
CM-8 RA-10 RA-5 SC-18 SC-2 SC-26 SC-29 SC-3 SC-30 SC-35 SC-39 SC-7 SI-2 SI-3 SI-4 SI-5 SI-7
T1505.004IIS ComponentsPersistence22AC-17 AC-3 AC-4 AC-6 CM-11
+17 more
CM-2 CM-6 CM-7 CM-8 IA-2 RA-5 SA-10 SA-11 SC-7 SI-14 SI-16 SI-3 SI-4 SI-7 SR-11 SR-4 SR-5
T1548Abuse Elevation Control MechanismPrivilege Escalation22AC-16 AC-2 AC-3 AC-5 AC-6
+17 more
CA-7 CM-2 CM-3 CM-5 CM-6 CM-7 CM-8 IA-2 RA-5 SC-18 SC-34 SI-12 SI-16 SI-2 SI-3 SI-4 SI-7
T1557.002ARP Cache PoisoningCredential Access, Collection22AC-16 AC-17 AC-18 AC-19 AC-20
+17 more
AC-3 AC-4 CA-7 CM-2 CM-6 CM-7 CM-8 SC-23 SC-4 SC-7 SC-8 SI-10 SI-12 SI-15 SI-3 SI-4 SI-7
T1020.001Traffic DuplicationExfiltration21AC-16 AC-17 AC-18 AC-19 AC-2
+16 more
AC-20 AC-3 AC-4 AC-6 CA-3 CM-2 CM-5 CM-6 CM-7 CM-8 SC-4 SC-7 SC-8 SI-12 SI-4 SI-7
T1068Exploitation for Privilege EscalationPrivilege Escalation21AC-2 AC-4 AC-6 CA-7 CM-2
+16 more
CM-6 CM-7 CM-8 RA-10 RA-5 SC-18 SC-2 SC-3 SC-30 SC-39 SC-7 SI-2 SI-3 SI-4 SI-5 SI-7
T1505Server Software ComponentPersistence21AC-16 AC-2 AC-3 AC-5 AC-6
+16 more
CM-11 CM-2 CM-5 CM-6 CM-8 IA-2 RA-5 SA-10 SA-11 SC-16 SI-14 SI-4 SI-7 SR-11 SR-4 SR-5
T1505.002Transport AgentPersistence21AC-16 AC-2 AC-3 AC-5 AC-6
+16 more
CM-11 CM-2 CM-5 CM-6 CM-8 IA-2 RA-5 SA-10 SA-11 SC-16 SI-14 SI-4 SI-7 SR-11 SR-4 SR-5
T1552.004Private KeysCredential Access21AC-16 AC-17 AC-18 AC-19 AC-2
+16 more
AC-20 CA-7 CM-2 CM-6 IA-2 IA-5 RA-5 SA-11 SA-15 SC-12 SC-28 SC-4 SC-7 SI-12 SI-4 SI-7
T1685.005Clear Windows Event LogsDefense Impairment21AC-16 AC-17 AC-18 AC-19 AC-2
+16 more
AC-3 AC-5 AC-6 CA-7 CM-2 CM-6 CP-6 CP-7 CP-9 SC-36 SC-4 SI-12 SI-23 SI-3 SI-4 SI-7
T1685.006Clear Linux or Mac System LogsDefense Impairment21AC-16 AC-17 AC-18 AC-19 AC-2
+16 more
AC-3 AC-5 AC-6 CA-7 CM-2 CM-6 CP-6 CP-7 CP-9 SC-36 SC-4 SI-12 SI-23 SI-3 SI-4 SI-7
T1070Indicator RemovalStealth20AC-16 AC-17 AC-18 AC-2 AC-3
+15 more
AC-5 AC-6 CA-7 CM-2 CM-6 CP-6 CP-7 CP-9 SC-36 SC-4 SI-12 SI-23 SI-3 SI-4 SI-7
T1218System Binary Proxy ExecutionStealth20AC-2 AC-3 AC-4 AC-5 AC-6
+15 more
CA-7 CM-11 CM-2 CM-5 CM-6 CM-7 CM-8 IA-2 RA-5 SC-7 SI-10 SI-16 SI-3 SI-4 SI-7
T1537Transfer Data to Cloud AccountExfiltration20AC-16 AC-17 AC-2 AC-20 AC-3
+15 more
AC-4 AC-5 AC-6 CA-7 CM-5 CM-6 CM-7 IA-2 IA-3 IA-4 IA-8 SC-7 SI-10 SI-15 SI-4
T1543Create or Modify System ProcessPersistence, Privilege Escalation20AC-17 AC-2 AC-3 AC-5 AC-6
+15 more
CA-7 CM-11 CM-2 CM-3 CM-5 CM-6 CM-7 IA-2 IA-4 RA-5 SA-22 SI-16 SI-3 SI-4 SI-7
T1553Subvert Trust ControlsDefense Impairment20AC-2 AC-3 AC-6 CM-10 CM-2
+15 more
CM-3 CM-5 CM-6 CM-7 CM-8 IA-7 IA-9 RA-9 SA-10 SA-11 SC-34 SI-10 SI-2 SI-4 SI-7
T1003.001LSASS MemoryCredential Access19AC-2 AC-3 AC-4 AC-5 AC-6
+14 more
CA-7 CM-2 CM-5 CM-6 CM-7 IA-2 IA-5 SC-28 SC-3 SC-39 SI-16 SI-2 SI-3 SI-4
T1021.003Distributed Component Object ModelLateral Movement19AC-17 AC-2 AC-3 AC-4 AC-5
+14 more
AC-6 CM-2 CM-5 CM-6 CM-7 CM-8 IA-2 RA-5 SC-18 SC-3 SC-46 SC-7 SI-3 SI-4
T1052Exfiltration Over Physical MediumExfiltration19AC-16 AC-2 AC-20 AC-23 AC-3
+14 more
AC-6 CA-7 CM-2 CM-6 CM-7 CM-8 MP-7 RA-5 SA-8 SC-28 SC-41 SI-3 SI-4 SR-4
T1052.001Exfiltration over USBExfiltration19AC-16 AC-2 AC-20 AC-23 AC-3
+14 more
AC-6 CA-7 CM-2 CM-6 CM-7 CM-8 MP-7 RA-5 SA-8 SC-28 SC-41 SI-3 SI-4 SR-4
T1059.001PowerShellExecution19AC-17 AC-2 AC-3 AC-5 AC-6
+14 more
CM-2 CM-5 CM-6 CM-8 IA-2 IA-8 IA-9 RA-5 SI-10 SI-16 SI-2 SI-3 SI-4 SI-7
T1078.003Local AccountsStealth, Persistence, Privilege Escalation, Initial Access19AC-2 AC-3 AC-5 AC-6 CA-7
+14 more
CM-5 CM-6 IA-12 IA-2 SA-10 SA-11 SA-15 SA-16 SA-17 SA-3 SA-4 SA-8 SC-28 SI-4
T1528Steal Application Access TokenCredential Access19AC-10 AC-2 AC-3 AC-4 AC-5
+14 more
AC-6 CA-7 CM-2 CM-5 CM-6 IA-13 IA-2 IA-4 IA-5 IA-8 RA-5 SA-11 SA-15 SI-4
T1542Pre-OS BootStealth, Persistence19AC-2 AC-3 AC-5 AC-6 CM-2
+14 more
CM-3 CM-5 CM-6 CM-8 IA-2 IA-7 IA-8 RA-9 SA-10 SA-11 SC-34 SC-7 SI-2 SI-7
T1542.004ROMMONkitStealth, Persistence19AC-3 AC-6 CA-7 CM-2 CM-3
+14 more
CM-5 CM-6 CM-7 CM-8 IA-7 RA-5 RA-9 SA-10 SA-11 SC-34 SC-7 SI-2 SI-4 SI-7
T1558Steal or Forge Kerberos TicketsCredential Access19AC-16 AC-17 AC-18 AC-19 AC-2
+14 more
AC-3 AC-5 AC-6 CA-7 CM-2 CM-5 CM-6 IA-2 IA-5 SC-4 SI-12 SI-3 SI-4 SI-7
T1558.002Silver TicketCredential Access19AC-16 AC-17 AC-18 AC-19 AC-2
+14 more
AC-3 AC-5 AC-6 CA-7 CM-2 CM-5 CM-6 IA-2 IA-5 SC-4 SI-12 SI-3 SI-4 SI-7
T1558.003KerberoastingCredential Access19AC-16 AC-17 AC-18 AC-19 AC-2
+14 more
AC-3 AC-5 AC-6 CA-7 CM-2 CM-5 CM-6 IA-2 IA-5 SC-4 SI-12 SI-3 SI-4 SI-7
T1558.004AS-REP RoastingCredential Access19AC-16 AC-17 AC-18 AC-19 AC-2
+14 more
AC-3 CA-7 CM-2 CM-6 IA-2 IA-5 RA-5 SA-11 SA-15 SC-4 SI-12 SI-3 SI-4 SI-7
T1559Inter-Process CommunicationExecution19AC-2 AC-3 AC-4 AC-5 AC-6
+14 more
CM-10 CM-2 CM-5 CM-6 CM-7 CM-8 IA-2 RA-5 SC-18 SC-3 SC-7 SI-2 SI-3 SI-4
T1563Remote Service Session HijackingLateral Movement19AC-12 AC-17 AC-2 AC-3 AC-4
+14 more
AC-5 AC-6 CM-2 CM-5 CM-6 CM-7 CM-8 IA-2 IA-4 IA-6 RA-5 SC-46 SC-7 SI-4
T1611Escape to HostPrivilege Escalation19AC-2 AC-3 AC-4 AC-5 AC-6
+14 more
CM-5 CM-6 CM-7 IA-2 SC-2 SC-3 SC-34 SC-39 SC-7 SI-16 SI-2 SI-3 SI-4 SI-7
T1685Disable or Modify ToolsDefense Impairment19AC-2 AC-3 AC-5 AC-6 CA-7
+14 more
CM-10 CM-2 CM-5 CM-6 CM-7 IA-2 IA-4 IA-9 RA-5 SC-23 SC-8 SI-3 SI-4 SI-7
T1003.003NTDSCredential Access18AC-16 AC-2 AC-3 AC-5 AC-6
+13 more
CA-7 CM-2 CM-5 CM-6 CP-9 IA-2 IA-5 SC-28 SC-39 SI-12 SI-3 SI-4 SI-7
T1041Exfiltration Over C2 ChannelExfiltration18AC-16 AC-2 AC-20 AC-23 AC-3
+13 more
AC-4 AC-6 CA-3 CA-7 SA-8 SA-9 SC-13 SC-28 SC-31 SC-7 SI-3 SI-4 SR-4
T1071.004DNSCommand And Control18AC-3 AC-4 CA-7 CM-2 CM-6
+13 more
CM-7 SC-10 SC-20 SC-21 SC-22 SC-23 SC-31 SC-37 SC-7 SI-10 SI-15 SI-3 SI-4
T1189Drive-by CompromiseInitial Access18AC-4 AC-6 CA-7 CM-2 CM-6
+13 more
CM-8 SA-22 SC-18 SC-2 SC-29 SC-3 SC-30 SC-39 SC-7 SI-2 SI-3 SI-4 SI-7
T1195.001Compromise Software Dependencies and Development ToolsInitial Access18CA-2 CA-7 CM-11 CM-5 CM-6
+13 more
CM-7 RA-10 RA-5 SA-10 SA-11 SA-15 SA-22 SI-2 SI-4 SI-7 SR-11 SR-4 SR-5
T1213.004Customer Relationship Management SoftwareCollection18AC-16 AC-2 AC-21 AC-23 AC-3
+13 more
AC-4 AC-5 AC-6 CA-7 CM-6 CM-7 IA-2 IA-4 IA-8 SC-28 SI-12 SI-4 SI-7
T1218.015Electron ApplicationsStealth18AC-2 AC-6 CA-7 CM-2 CM-5
+13 more
CM-6 CM-7 CM-8 RA-5 SC-18 SC-34 SC-7 SI-10 SI-15 SI-16 SI-3 SI-4 SI-7
T1542.003BootkitStealth, Persistence18AC-2 AC-3 AC-5 AC-6 CM-2
+13 more
CM-3 CM-5 CM-6 CM-8 IA-2 IA-7 IA-8 RA-9 SA-10 SA-11 SC-34 SI-2 SI-7
T1547.006Kernel Modules and ExtensionsPersistence, Privilege Escalation18AC-2 AC-3 AC-5 AC-6 CM-5
+13 more
CM-6 CM-7 IA-2 IA-4 IA-8 RA-5 SI-10 SI-14 SI-16 SI-2 SI-3 SI-4 SI-7
T1552.002Credentials in RegistryCredential Access18AC-17 AC-2 AC-3 AC-5 AC-6
+13 more
CA-7 CM-2 CM-5 CM-6 IA-2 IA-5 RA-5 SA-11 SA-15 SC-12 SC-28 SC-4 SI-4
T1563.002RDP HijackingLateral Movement18AC-11 AC-12 AC-17 AC-2 AC-3
+13 more
AC-4 AC-5 AC-6 CM-2 CM-5 CM-6 CM-7 CM-8 IA-2 RA-5 SC-46 SC-7 SI-4
T1574Hijack Execution FlowStealth, Execution18AC-2 AC-3 AC-4 AC-5 AC-6
+13 more
CA-7 CM-2 CM-5 CM-6 CM-7 CM-8 IA-2 RA-5 SI-10 SI-2 SI-3 SI-4 SI-7
T1599Network Boundary BridgingDefense Impairment18AC-2 AC-3 AC-4 AC-5 AC-6
+13 more
CA-7 CM-2 CM-5 CM-6 CM-7 IA-2 IA-5 SC-28 SC-7 SI-10 SI-15 SI-4 SI-7
T1599.001Network Address Translation TraversalDefense Impairment18AC-2 AC-3 AC-4 AC-5 AC-6
+13 more
CA-7 CM-2 CM-5 CM-6 CM-7 IA-2 IA-5 SC-28 SC-7 SI-10 SI-15 SI-4 SI-7
T1003.005Cached Domain CredentialsCredential Access17AC-2 AC-3 AC-4 AC-5 AC-6
+12 more
CA-7 CM-2 CM-5 CM-6 CM-7 IA-2 IA-4 IA-5 SC-28 SC-39 SI-3 SI-4
T1047Windows Management InstrumentationExecution17AC-17 AC-2 AC-3 AC-5 AC-6
+12 more
CM-2 CM-5 CM-6 CM-7 IA-2 RA-5 SC-3 SI-16 SI-2 SI-3 SI-4 SI-7
T1059.005Visual BasicExecution17AC-17 AC-2 AC-3 AC-6 CA-7
+12 more
CM-2 CM-6 CM-7 CM-8 RA-5 SC-18 SI-10 SI-16 SI-2 SI-3 SI-4 SI-7
T1119Automated CollectionCollection17AC-16 AC-17 AC-18 AC-19 AC-20
+12 more
CM-2 CM-6 CM-8 CP-6 CP-7 CP-9 SC-36 SC-4 SI-12 SI-23 SI-4 SI-7
T1133External Remote ServicesPersistence, Initial Access17AC-17 AC-20 AC-3 AC-4 AC-6
+12 more
AC-7 CM-2 CM-6 CM-7 CM-8 IA-2 IA-5 RA-5 SC-46 SC-7 SI-4 SI-7
T1542.001System FirmwareStealth, Persistence17AC-2 AC-3 AC-5 AC-6 CM-3
+12 more
CM-5 CM-6 CM-8 IA-2 IA-7 IA-8 RA-9 SA-10 SA-11 SC-34 SI-2 SI-7
T1548.006TCC ManipulationPrivilege Escalation17AC-16 AC-2 AC-3 AC-5 AC-6
+12 more
CA-7 CM-2 CM-5 CM-6 CM-7 CM-8 RA-5 SI-10 SI-2 SI-3 SI-4 SI-7
T1552.001Credentials In FilesCredential Access17AC-2 AC-4 AC-5 AC-6 CA-7
+12 more
CM-2 CM-6 IA-2 IA-5 RA-5 SA-11 SA-15 SC-12 SC-28 SC-4 SC-7 SI-4
T1556Modify Authentication ProcessDefense Impairment, Persistence, Credential Access17AC-2 AC-20 AC-3 AC-5 AC-6
+12 more
AC-7 CA-7 CM-2 CM-5 CM-6 CM-7 IA-13 IA-2 IA-5 SC-39 SI-4 SI-7
T1563.001SSH HijackingLateral Movement17AC-17 AC-2 AC-3 AC-5 AC-6
+12 more
CA-7 CM-2 CM-5 CM-6 CM-7 CM-8 IA-2 IA-5 RA-5 SC-12 SC-23 SI-4
T1567Exfiltration Over Web ServiceExfiltration17AC-16 AC-2 AC-20 AC-23 AC-3
+12 more
AC-4 AC-6 CA-3 CA-7 SA-8 SA-9 SC-28 SC-31 SC-7 SI-3 SI-4 SR-4
T1574.001DLLStealth, Execution17CM-2 CM-6 CM-7 RA-5 SA-10
+12 more
SA-11 SA-15 SA-16 SA-17 SA-3 SA-4 SA-8 SI-10 SI-2 SI-3 SI-4 SI-7
T1003.006DCSyncCredential Access16AC-2 AC-3 AC-4 AC-5 AC-6
+11 more
CA-7 CM-2 CM-5 CM-6 IA-2 IA-4 IA-5 SC-28 SC-39 SI-3 SI-4
T1021.002SMB/Windows Admin SharesLateral Movement16AC-17 AC-2 AC-3 AC-4 AC-5
+11 more
AC-6 CA-7 CM-2 CM-5 CM-6 CM-7 IA-2 SC-7 SI-10 SI-15 SI-4
T1021.006Windows Remote ManagementLateral Movement16AC-17 AC-2 AC-3 AC-4 AC-5
+11 more
AC-6 CM-2 CM-5 CM-6 CM-7 CM-8 IA-2 RA-5 SC-46 SC-7 SI-4
T1059.007JavaScriptExecution16AC-17 AC-2 AC-3 AC-6 CA-7
+11 more
CM-2 CM-6 CM-7 CM-8 RA-5 SC-18 SI-10 SI-16 SI-3 SI-4 SI-7
T1203Exploitation for Client ExecutionExecution16AC-4 AC-6 CA-7 CM-8 SC-18
+11 more
SC-2 SC-29 SC-3 SC-30 SC-39 SC-44 SC-7 SI-2 SI-3 SI-4 SI-7
T1204.003Malicious ImageExecution16AC-4 CA-7 CM-2 CM-6 CM-7
+11 more
RA-5 SC-44 SC-7 SI-2 SI-3 SI-4 SI-7 SI-8 SR-11 SR-4 SR-5
T1218.012VerclsidStealth16AC-3 AC-4 CA-7 CM-11 CM-2
+11 more
CM-6 CM-7 CM-8 RA-5 SC-7 SI-10 SI-15 SI-16 SI-3 SI-4 SI-7
T1495Firmware CorruptionImpact16AC-2 AC-3 AC-5 AC-6 CM-2
+11 more
CM-3 CM-5 CM-6 CM-8 IA-2 IA-7 RA-9 SA-10 SA-11 SI-2 SI-7
T1543.002Systemd ServicePersistence, Privilege Escalation16AC-2 AC-3 AC-5 AC-6 CA-7
+11 more
CM-11 CM-2 CM-3 CM-5 CM-6 IA-2 SA-22 SI-16 SI-3 SI-4 SI-7
T1557.004Evil TwinCredential Access, Collection16AC-18 AC-19 AC-3 AC-4 CA-7
+11 more
CM-2 CM-6 SC-13 SC-23 SC-40 SC-46 SC-7 SC-8 SI-12 SI-4 SI-7
T1003.002Security Account ManagerCredential Access15AC-2 AC-3 AC-5 AC-6 CA-7
+10 more
CM-2 CM-5 CM-6 CM-7 IA-2 IA-5 SC-28 SC-39 SI-3 SI-4
T1021.004SSHLateral Movement15AC-17 AC-2 AC-20 AC-3 AC-5
+10 more
AC-6 AC-7 CM-2 CM-5 CM-6 CM-8 IA-2 IA-5 RA-5 SI-4
T1025Data from Removable MediaCollection15AC-16 AC-2 AC-23 AC-3 AC-6
+10 more
CM-12 CP-9 MP-7 SA-8 SC-13 SC-28 SC-38 SC-41 SI-3 SI-4
T1059.002AppleScriptExecution15AC-17 AC-2 AC-3 AC-6 CM-2
+10 more
CM-6 IA-9 SI-10 SI-16 SI-3 SI-4 SI-7 SR-11 SR-4 SR-5
T1059.006PythonExecution15AC-17 AC-2 AC-3 AC-6 CM-11
+10 more
CM-2 CM-3 CM-5 CM-6 SI-10 SI-16 SI-2 SI-3 SI-4 SI-7
T1059.008Network Device CLIExecution15AC-17 AC-2 AC-3 AC-5 AC-6
+10 more
CM-2 CM-5 CM-6 IA-2 IA-8 SI-10 SI-16 SI-3 SI-4 SI-7
T1071Application Layer ProtocolCommand And Control15AC-4 CA-7 CM-2 CM-6 CM-7
+10 more
SC-10 SC-20 SC-21 SC-22 SC-23 SC-31 SC-37 SC-7 SI-3 SI-4
T1071.001Web ProtocolsCommand And Control15AC-4 CA-7 CM-2 CM-6 CM-7
+10 more
SC-10 SC-20 SC-21 SC-22 SC-23 SC-31 SC-37 SC-7 SI-3 SI-4
T1071.002File Transfer ProtocolsCommand And Control15AC-4 CA-7 CM-2 CM-6 CM-7
+10 more
SC-10 SC-20 SC-21 SC-22 SC-23 SC-31 SC-37 SC-7 SI-3 SI-4
T1071.003Mail ProtocolsCommand And Control15AC-4 CA-7 CM-2 CM-6 CM-7
+10 more
SC-10 SC-20 SC-21 SC-22 SC-23 SC-31 SC-37 SC-7 SI-3 SI-4
T1098.001Additional Cloud CredentialsPersistence, Privilege Escalation15AC-2 AC-20 AC-3 AC-4 AC-5
+10 more
AC-6 CM-5 CM-6 CM-7 IA-2 IA-5 SC-46 SC-7 SI-4 SI-7
T1098.004SSH Authorized KeysPersistence, Privilege Escalation15AC-20 AC-3 AC-5 AC-6 CM-2
+10 more
CM-5 CM-6 CM-7 CM-8 IA-2 IA-5 RA-5 SC-12 SI-3 SI-4
T1114Email CollectionCollection15AC-16 AC-17 AC-19 AC-20 AC-3
+10 more
AC-4 CM-2 CM-6 IA-2 IA-5 SC-37 SC-7 SI-12 SI-4 SI-7
T1136Create AccountPersistence15AC-2 AC-20 AC-3 AC-4 AC-5
+10 more
AC-6 CM-5 CM-6 CM-7 IA-2 IA-5 SC-46 SC-7 SI-4 SI-7
T1136.002Domain AccountPersistence15AC-2 AC-20 AC-3 AC-4 AC-5
+10 more
AC-6 CM-5 CM-6 CM-7 IA-2 IA-5 SC-46 SC-7 SI-4 SI-7
T1525Implant Internal ImagePersistence15AC-2 AC-3 AC-5 AC-6 CM-2
+10 more
CM-5 CM-6 CM-7 IA-2 IA-9 RA-5 SI-2 SI-3 SI-4 SI-7
T1547.013XDG Autostart EntriesPersistence, Privilege Escalation15AC-17 AC-2 AC-3 AC-5 AC-6
+10 more
CA-7 CM-11 CM-2 CM-3 CM-5 CM-6 IA-2 SI-3 SI-4 SI-7
T1550.001Application Access TokenLateral Movement15AC-16 AC-17 AC-19 AC-20 CM-10
+10 more
CM-11 CM-2 CM-6 IA-2 IA-4 SC-28 SC-8 SI-12 SI-4 SI-7
T1557.001Name Resolution Poisoning and SMB RelayCredential Access, Collection15AC-3 AC-4 CA-7 CM-2 CM-6
+10 more
CM-7 CM-8 SC-23 SC-46 SC-7 SC-8 SI-10 SI-15 SI-3 SI-4
T1557.003DHCP SpoofingCredential Access, Collection15AC-3 AC-4 CA-7 CM-2 CM-6
+10 more
CM-7 CM-8 SC-23 SC-46 SC-7 SC-8 SI-10 SI-15 SI-3 SI-4
T1574.007Path Interception by PATH Environment VariableStealth, Execution15AC-2 AC-3 AC-4 AC-5 AC-6
+10 more
CA-7 CM-2 CM-6 CM-7 CM-8 RA-5 SI-10 SI-3 SI-4 SI-7
T1574.008Path Interception by Search Order HijackingStealth, Execution15AC-2 AC-3 AC-4 AC-5 AC-6
+10 more
CA-7 CM-2 CM-6 CM-7 CM-8 RA-5 SI-10 SI-3 SI-4 SI-7
T1574.009Path Interception by Unquoted PathStealth, Execution15AC-2 AC-3 AC-4 AC-5 AC-6
+10 more
CA-7 CM-2 CM-6 CM-7 CM-8 RA-5 SI-10 SI-3 SI-4 SI-7
T1622Debugger EvasionStealth, Discovery15AC-3 AC-4 CA-7 CM-2 CM-6
+10 more
CM-7 CM-8 SC-23 SC-46 SC-7 SC-8 SI-10 SI-15 SI-3 SI-4
T1647Plist File ModificationDefense Impairment15AC-16 AC-17 AC-3 AC-6 CA-7
+10 more
CM-2 CM-3 CM-5 CM-6 CM-7 SA-10 SA-11 SA-8 SI-4 SI-7
T1003.004LSA SecretsCredential Access14AC-2 AC-3 AC-5 AC-6 CA-7
+9 more
CM-2 CM-5 CM-6 IA-2 IA-5 SC-28 SC-39 SI-3 SI-4
T1003.007Proc FilesystemCredential Access14AC-2 AC-3 AC-5 AC-6 CA-7
+9 more
CM-2 CM-5 CM-6 IA-2 IA-5 SC-28 SC-39 SI-3 SI-4
T1003.008/etc/passwd and /etc/shadowCredential Access14AC-2 AC-3 AC-5 AC-6 CA-7
+9 more
CM-2 CM-5 CM-6 IA-2 IA-5 SC-28 SC-39 SI-3 SI-4
T1021Remote ServicesLateral Movement14AC-17 AC-2 AC-20 AC-3 AC-5
+9 more
AC-6 AC-7 CM-2 CM-5 CM-6 CM-7 IA-2 IA-5 SI-4
T1053Scheduled Task/JobExecution, Persistence, Privilege Escalation14AC-2 AC-3 AC-5 AC-6 CM-2
+9 more
CM-5 CM-6 CM-7 CM-8 IA-2 IA-4 IA-8 RA-5 SI-4
T1078.001Default AccountsStealth, Persistence, Privilege Escalation, Initial Access14AC-2 AC-5 AC-6 CA-7 SA-10
+9 more
SA-11 SA-15 SA-16 SA-17 SA-3 SA-4 SA-8 SC-28 SI-4
T1110Brute ForceCredential Access14AC-2 AC-20 AC-3 AC-5 AC-6
+9 more
AC-7 CA-7 CM-2 CM-6 IA-11 IA-2 IA-4 IA-5 SI-4
T1110.001Password GuessingCredential Access14AC-2 AC-20 AC-3 AC-5 AC-6
+9 more
AC-7 CA-7 CM-2 CM-6 IA-11 IA-2 IA-4 IA-5 SI-4
T1110.002Password CrackingCredential Access14AC-2 AC-20 AC-3 AC-5 AC-6
+9 more
AC-7 CA-7 CM-2 CM-6 IA-11 IA-2 IA-4 IA-5 SI-4
T1110.003Password SprayingCredential Access14AC-2 AC-20 AC-3 AC-5 AC-6
+9 more
AC-7 CA-7 CM-2 CM-6 IA-11 IA-2 IA-4 IA-5 SI-4
T1110.004Credential StuffingCredential Access14AC-2 AC-20 AC-3 AC-5 AC-6
+9 more
AC-7 CA-7 CM-2 CM-6 IA-11 IA-2 IA-4 IA-5 SI-4
T1114.002Remote Email CollectionCollection14AC-16 AC-17 AC-19 AC-20 AC-3
+9 more
AC-4 CM-2 CM-6 IA-2 IA-5 SC-37 SI-12 SI-4 SI-7
T1136.003Cloud AccountPersistence14AC-2 AC-20 AC-3 AC-4 AC-5
+9 more
AC-6 CM-5 CM-6 CM-7 IA-2 IA-5 SC-7 SI-4 SI-7
T1176Software ExtensionsPersistence14AC-6 CA-7 CM-11 CM-2 CM-3
+9 more
CM-5 CM-6 CM-7 RA-5 SC-7 SI-10 SI-3 SI-4 SI-7
T1185Browser Session HijackingCollection14AC-10 AC-12 AC-2 AC-3 AC-5
+9 more
AC-6 CA-7 CM-2 CM-5 IA-2 SC-23 SI-3 SI-4 SI-7
T1195.003Compromise Hardware Supply ChainInitial Access14CM-2 CM-3 CM-5 CM-8 IA-7
+9 more
RA-9 SA-10 SA-11 SC-34 SI-2 SI-7 SR-11 SR-4 SR-5
T1197BITS JobsStealth, Persistence, Execution14AC-2 AC-3 AC-4 AC-5 AC-6
+9 more
CA-7 CM-5 CM-6 CM-7 IA-2 SC-7 SI-10 SI-15 SI-4
T1213.003Code RepositoriesCollection14AC-2 AC-3 AC-5 AC-6 CA-7
+9 more
IA-2 IA-9 RA-5 SA-10 SA-11 SA-15 SA-3 SA-8 SI-2
T1221Template InjectionStealth14CA-7 CM-2 CM-6 CM-7 CM-8
+9 more
RA-5 SC-44 SC-7 SI-10 SI-2 SI-3 SI-4 SI-7 SI-8
T1489Service StopImpact14AC-2 AC-3 AC-4 AC-5 AC-6
+9 more
CA-7 CM-5 CM-6 CM-7 IA-2 SC-37 SC-46 SC-7 SI-4
T1552.005Cloud Instance Metadata APICredential Access14AC-16 AC-17 AC-20 AC-3 AC-4
+9 more
CA-7 CM-6 CM-7 IA-3 IA-4 SC-7 SI-10 SI-15 SI-4
T1552.007Container APICredential Access14AC-17 AC-2 AC-23 AC-3 AC-4
+9 more
AC-5 AC-6 CM-5 CM-6 CM-7 IA-2 SC-46 SC-7 SC-8
T1556.001Domain Controller AuthenticationDefense Impairment, Persistence, Credential Access14AC-2 AC-20 AC-3 AC-5 AC-6
+9 more
AC-7 CA-7 CM-5 CM-6 IA-2 IA-5 SC-39 SI-4 SI-7
T1556.009Conditional Access PoliciesDefense Impairment, Persistence, Credential Access14AC-16 AC-2 AC-3 AC-5 AC-6
+9 more
CM-5 CM-6 CM-7 CM-8 IA-13 IA-2 IA-5 SI-4 SI-7
T1559.002Dynamic Data ExchangeExecution14AC-4 AC-6 CM-10 CM-2 CM-6
+9 more
CM-7 CM-8 RA-5 SC-18 SC-3 SC-7 SI-2 SI-3 SI-4
T1569System ServicesExecution14AC-2 AC-3 AC-5 AC-6 CA-7
+9 more
CM-11 CM-2 CM-5 CM-6 CM-7 IA-2 SI-3 SI-4 SI-7
T1005Data from Local SystemCollection13AC-16 AC-2 AC-23 AC-3 AC-6
+8 more
CM-12 CP-9 SA-8 SC-13 SC-28 SC-38 SI-3 SI-4
T1053.002AtExecution, Persistence, Privilege Escalation13AC-2 AC-3 AC-5 AC-6 CM-2
+8 more
CM-5 CM-6 CM-7 CM-8 IA-2 IA-4 RA-5 SI-4
T1053.005Scheduled TaskExecution, Persistence, Privilege Escalation13AC-2 AC-3 AC-5 AC-6 CM-2
+8 more
CM-5 CM-6 CM-7 CM-8 IA-2 IA-4 RA-5 SI-4
T1078.002Domain AccountsStealth, Persistence, Privilege Escalation, Initial Access13AC-2 AC-20 AC-3 AC-5 AC-6
+8 more
AC-7 CM-5 CM-6 IA-12 IA-13 IA-2 IA-5 SI-4
T1134.005SID-History InjectionStealth, Privilege Escalation13AC-20 AC-3 AC-4 AC-5 AC-6
+8 more
CM-2 CM-6 IA-13 SA-11 SA-17 SA-4 SA-8 SC-3
T1137Office Application StartupPersistence13AC-10 AC-17 AC-6 CM-2 CM-6
+8 more
CM-8 RA-5 SC-18 SC-44 SI-2 SI-3 SI-4 SI-8
T1204User ExecutionExecution13AC-4 CA-7 CM-2 CM-6 CM-7
+8 more
SC-44 SC-7 SI-10 SI-2 SI-3 SI-4 SI-7 SI-8
T1219Remote Access ToolsCommand And Control13AC-17 AC-3 AC-4 CA-7 CM-2
+8 more
CM-6 CM-7 SC-7 SI-10 SI-15 SI-3 SI-4 SI-7
T1490Inhibit System RecoveryImpact13AC-2 AC-3 AC-6 CM-2 CM-6
+8 more
CM-7 CP-10 CP-2 CP-7 CP-9 SI-3 SI-4 SI-7
T1546.006LC_LOAD_DYLIB AdditionPrivilege Escalation, Persistence13CM-2 CM-6 CM-7 CM-8 IA-9
+8 more
SI-10 SI-2 SI-3 SI-4 SI-7 SR-11 SR-4 SR-5
T1547.004Winlogon Helper DLLPersistence, Privilege Escalation13AC-17 AC-2 AC-3 AC-5 AC-6
+8 more
CM-5 CM-7 IA-2 SI-10 SI-14 SI-16 SI-4 SI-7
T1548.003Sudo and Sudo CachingPrivilege Escalation13AC-16 AC-2 AC-3 AC-5 AC-6
+8 more
CA-7 CM-2 CM-5 CM-6 CM-7 IA-2 RA-5 SI-4
T1553.006Code Signing Policy ModificationDefense Impairment13AC-6 CM-2 CM-3 CM-5 CM-7
+8 more
CM-8 IA-7 RA-9 SA-10 SA-11 SC-34 SI-2 SI-7
T1556.004Network Device AuthenticationDefense Impairment, Persistence, Credential Access13AC-2 AC-20 AC-3 AC-5 AC-6
+8 more
AC-7 CM-2 CM-5 CM-6 IA-2 IA-5 SI-4 SI-7
T1559.001Component Object ModelExecution13AC-2 AC-3 AC-4 AC-5 AC-6
+8 more
CM-2 CM-5 CM-6 IA-2 SC-18 SC-3 SC-7 SI-3
T1564.009Resource ForkingStealth13CM-11 CM-2 CM-6 CM-7 SA-10
+8 more
SC-4 SC-44 SC-6 SI-10 SI-15 SI-3 SI-4 SI-7
T1565.003Runtime Data ManipulationImpact13AC-3 AC-4 CA-7 CM-6 CM-7
+8 more
CP-9 SC-28 SC-4 SC-46 SC-7 SI-16 SI-4 SI-7
T1566PhishingInitial Access13AC-4 CA-7 CM-2 CM-6 IA-9
+8 more
RA-5 SC-20 SC-44 SC-7 SI-2 SI-3 SI-4 SI-8
T1569.002Service ExecutionExecution13AC-2 AC-3 AC-5 AC-6 CA-7
+8 more
CM-2 CM-5 CM-6 CM-7 IA-2 SI-3 SI-4 SI-7
T1574.004Dylib HijackingStealth, Execution13AC-2 AC-3 AC-4 AC-5 AC-6
+8 more
CA-7 CM-2 CM-6 CM-8 RA-5 SI-3 SI-4 SI-7
T1685.001Disable or Modify Windows Event LogDefense Impairment13AC-2 AC-3 AC-5 AC-6 CA-7
+8 more
CM-2 CM-5 CM-6 CM-7 IA-2 SI-3 SI-4 SI-7
T1686Disable or Modify System FirewallDefense Impairment13AC-2 AC-3 AC-5 AC-6 CA-7
+8 more
CM-2 CM-5 CM-6 CM-7 IA-2 SI-3 SI-4 SI-7
T1688Safe Mode BootDefense Impairment13AC-2 AC-3 AC-5 AC-6 CM-10
+8 more
CM-5 CM-6 CM-7 IA-2 IA-9 SC-23 SC-8 SI-7
T1036MasqueradingStealth12AC-2 AC-3 AC-6 CA-7 CM-2
+7 more
CM-6 CM-7 IA-9 SI-10 SI-3 SI-4 SI-7
T1036.005Match Legitimate Resource Name or LocationStealth12AC-2 AC-3 AC-6 CA-7 CM-2
+7 more
CM-6 CM-7 IA-9 SI-10 SI-3 SI-4 SI-7
T1040Network SniffingCredential Access, Discovery12AC-16 AC-17 AC-18 AC-19 CM-7
+7 more
IA-2 IA-5 SC-4 SC-8 SI-12 SI-4 SI-7
T1048.001Exfiltration Over Symmetric Encrypted Non-C2 ProtocolExfiltration12AC-3 AC-4 CA-7 CM-2 CM-6
+7 more
CM-7 SC-46 SC-7 SI-10 SI-15 SI-3 SI-4
T1055Process InjectionStealth, Privilege Escalation12AC-2 AC-3 AC-5 AC-6 CM-5
+7 more
CM-6 IA-2 SC-18 SC-7 SI-2 SI-3 SI-4
T1055.008Ptrace System CallsStealth, Privilege Escalation12AC-2 AC-3 AC-5 AC-6 CM-5
+7 more
CM-6 IA-2 SC-18 SC-7 SI-2 SI-3 SI-4
T1090ProxyCommand And Control12AC-3 AC-4 CA-7 CM-2 CM-6
+7 more
CM-7 SC-7 SC-8 SI-10 SI-15 SI-3 SI-4
T1114.003Email Forwarding RuleCollection12AC-16 AC-17 AC-19 AC-20 AC-4
+7 more
CM-6 SC-37 SC-43 SC-7 SI-12 SI-4 SI-7
T1204.002Malicious FileExecution12AC-4 CA-7 CM-2 CM-6 CM-7
+7 more
SC-44 SC-7 SI-10 SI-3 SI-4 SI-7 SI-8
T1484Domain or Tenant Policy ModificationDefense Impairment, Privilege Escalation12AC-2 AC-3 AC-4 AC-5 AC-6
+7 more
CM-2 CM-5 CM-6 CM-7 IA-2 RA-5 SI-4
T1505.001SQL Stored ProceduresPersistence12CM-11 CM-2 CM-6 CM-8 RA-5
+7 more
SA-10 SA-11 SI-14 SI-7 SR-11 SR-4 SR-5
T1546.003Windows Management Instrumentation Event SubscriptionPrivilege Escalation, Persistence12AC-2 AC-3 AC-5 AC-6 CA-7
+7 more
CM-2 CM-5 CM-6 IA-2 SI-14 SI-3 SI-4
T1552.006Group Policy PreferencesCredential Access12AC-2 AC-5 AC-6 CM-2 CM-6
+7 more
IA-2 IA-5 RA-5 SA-11 SA-15 SI-2 SI-4
T1556.003Pluggable Authentication ModulesDefense Impairment, Persistence, Credential Access12AC-2 AC-20 AC-3 AC-5 AC-6
+7 more
AC-7 CM-5 CM-6 IA-2 IA-5 SI-4 SI-7
T1565.002Transmitted Data ManipulationImpact12AC-16 AC-17 AC-18 AC-19 AC-20
+7 more
CM-2 CM-6 CM-8 SC-4 SI-12 SI-4 SI-7
T1566.001Spearphishing AttachmentInitial Access12AC-4 CA-7 CM-2 CM-6 IA-9
+7 more
SC-20 SC-44 SC-7 SI-2 SI-3 SI-4 SI-8
T1021.008Direct Cloud VM ConnectionsLateral Movement11AC-17 AC-2 AC-20 AC-3 AC-6
+6 more
CM-5 CM-6 CM-7 IA-2 IA-5 SI-4
T1046Network Service DiscoveryDiscovery11AC-4 CA-7 CM-2 CM-6 CM-7
+6 more
CM-8 RA-5 SC-46 SC-7 SI-3 SI-4
T1059.003Windows Command ShellExecution11AC-17 AC-2 AC-3 AC-6 CM-2
+6 more
CM-6 SI-10 SI-16 SI-3 SI-4 SI-7
T1059.004Unix ShellExecution11AC-17 AC-2 AC-3 AC-6 CM-2
+6 more
CM-6 SI-10 SI-16 SI-3 SI-4 SI-7
T1059.010AutoHotKey & AutoITExecution11AC-2 AC-3 AC-6 CA-7 CM-2
+6 more
CM-6 CM-7 CM-8 SI-3 SI-4 SI-7
T1095Non-Application Layer ProtocolCommand And Control11AC-3 AC-4 CA-7 CM-2 CM-6
+6 more
CM-7 SC-7 SI-10 SI-15 SI-3 SI-4
T1098Account ManipulationPersistence, Privilege Escalation11AC-2 AC-3 AC-4 AC-5 AC-6
+6 more
CM-5 CM-6 CM-7 IA-2 SC-7 SI-4
T1098.002Additional Email Delegate PermissionsPersistence, Privilege Escalation11AC-2 AC-20 AC-3 AC-5 AC-6
+6 more
CM-5 CM-6 IA-2 IA-5 SI-4 SI-7
T1098.003Additional Cloud RolesPersistence, Privilege Escalation11AC-2 AC-20 AC-3 AC-5 AC-6
+6 more
CM-5 CM-6 IA-2 IA-5 SI-4 SI-7
T1098.007Additional Local or Domain GroupsPersistence, Privilege Escalation11AC-2 AC-3 AC-4 AC-5 AC-6
+6 more
CM-5 CM-6 CM-7 IA-2 IA-4 SI-4
T1136.001Local AccountPersistence11AC-2 AC-20 AC-3 AC-5 AC-6
+6 more
CM-5 CM-6 IA-2 IA-5 SI-4 SI-7
T1195.002Compromise Software Supply ChainInitial Access11CA-2 CA-7 CM-11 CM-7 RA-10
+6 more
RA-5 SA-22 SI-2 SR-11 SR-4 SR-5
T1204.001Malicious LinkExecution11AC-4 CA-7 CM-2 CM-6 CM-7
+6 more
SC-44 SC-7 SI-2 SI-3 SI-4 SI-8
T1218.002Control PanelStealth11AC-3 CA-7 CM-11 CM-2 CM-6
+6 more
CM-7 SI-10 SI-16 SI-3 SI-4 SI-7
T1218.003CMSTPStealth11CM-11 CM-2 CM-6 CM-7 CM-8
+6 more
RA-5 SI-10 SI-16 SI-3 SI-4 SI-7
T1218.004InstallUtilStealth11CM-11 CM-2 CM-6 CM-7 CM-8
+6 more
RA-5 SI-10 SI-16 SI-3 SI-4 SI-7
T1218.005MshtaStealth11CM-11 CM-2 CM-6 CM-7 CM-8
+6 more
RA-5 SI-10 SI-16 SI-3 SI-4 SI-7
T1218.008OdbcconfStealth11CM-11 CM-2 CM-6 CM-7 CM-8
+6 more
RA-5 SI-10 SI-16 SI-3 SI-4 SI-7
T1218.009Regsvcs/RegasmStealth11CM-11 CM-2 CM-6 CM-7 CM-8
+6 more
RA-5 SI-10 SI-16 SI-3 SI-4 SI-7
T1218.013MavinjectStealth11CM-11 CM-2 CM-6 CM-7 CM-8
+6 more
RA-5 SI-10 SI-16 SI-3 SI-4 SI-7
T1218.014MMCStealth11CM-11 CM-2 CM-6 CM-7 CM-8
+6 more
RA-5 SI-10 SI-16 SI-3 SI-4 SI-7
T1222File and Directory Permissions ModificationDefense Impairment11AC-16 AC-2 AC-3 AC-5 AC-6
+6 more
CA-7 CM-5 CM-6 IA-2 SI-4 SI-7
T1222.001Windows PermissionsDefense Impairment11AC-16 AC-2 AC-3 AC-5 AC-6
+6 more
CA-7 CM-5 CM-6 IA-2 SI-4 SI-7
T1222.002Linux and Mac PermissionsDefense Impairment11AC-16 AC-2 AC-3 AC-5 AC-6
+6 more
CA-7 CM-5 CM-6 IA-2 SI-4 SI-7
T1486Data Encrypted for ImpactImpact11AC-3 AC-6 CM-2 CP-10 CP-2
+6 more
CP-6 CP-7 CP-9 SI-3 SI-4 SI-7
T1505.005Terminal Services DLLPersistence11AC-12 AC-17 AC-2 AC-20 AC-3
+6 more
AC-5 AC-6 CM-2 CM-6 RA-5 SI-4
T1547.007Re-opened ApplicationsPersistence, Privilege Escalation11AC-16 AC-3 CM-2 CM-3 CM-5
+6 more
CM-6 CM-7 CM-8 RA-5 SI-3 SI-4
T1547.009Shortcut ModificationPersistence, Privilege Escalation11AC-17 AC-2 AC-3 AC-5 AC-6
+6 more
CM-5 CM-6 CM-7 IA-2 SI-3 SI-4
T1548.002Bypass User Account ControlPrivilege Escalation11AC-2 AC-3 AC-5 AC-6 CM-2
+6 more
CM-5 CM-6 IA-2 RA-5 SI-2 SI-4
T1548.004Elevated Execution with PromptPrivilege Escalation11CM-2 CM-6 CM-7 CM-8 SC-18
+6 more
SC-34 SI-12 SI-16 SI-3 SI-4 SI-7
T1550.003Pass the TicketLateral Movement11AC-2 AC-3 AC-5 AC-6 CA-7
+6 more
CM-2 CM-5 CM-6 IA-2 IA-5 SI-4
T1566.002Spearphishing LinkInitial Access11AC-4 CA-7 CM-2 CM-6 IA-9
+6 more
SC-20 SC-44 SC-7 SI-3 SI-4 SI-8
T1570Lateral Tool TransferLateral Movement11AC-3 AC-4 CA-7 CM-2 CM-6
+6 more
CM-7 SC-7 SI-10 SI-15 SI-3 SI-4
T1572Protocol TunnelingCommand And Control11AC-3 AC-4 CA-7 CM-2 CM-6
+6 more
CM-7 SC-7 SI-10 SI-15 SI-3 SI-4
T1573Encrypted ChannelCommand And Control11AC-4 CA-7 CM-2 CM-6 CM-7
+6 more
SC-12 SC-16 SC-23 SC-7 SI-3 SI-4
T1573.001Symmetric CryptographyCommand And Control11AC-4 CA-7 CM-2 CM-6 CM-7
+6 more
SC-12 SC-16 SC-23 SC-7 SI-3 SI-4
T1573.002Asymmetric CryptographyCommand And Control11AC-4 CA-7 CM-2 CM-6 CM-7
+6 more
SC-12 SC-16 SC-23 SC-7 SI-3 SI-4
T1574.005Executable Installer File Permissions WeaknessStealth, Execution11AC-2 AC-3 AC-4 AC-5 AC-6
+6 more
CM-2 CM-5 CM-6 IA-2 RA-5 SI-4
T1574.010Services File Permissions WeaknessStealth, Execution11AC-2 AC-3 AC-4 AC-5 AC-6
+6 more
CM-2 CM-5 CM-6 IA-2 RA-5 SI-4
T1578Modify Cloud Compute InfrastructureDefense Impairment11AC-2 AC-3 AC-5 AC-6 CM-2
+6 more
CM-5 IA-2 IA-4 IA-6 RA-5 SI-4
T1578.001Create SnapshotDefense Impairment11AC-2 AC-3 AC-5 AC-6 CM-2
+6 more
CM-5 IA-2 IA-4 IA-6 RA-5 SI-4
T1578.002Create Cloud InstanceDefense Impairment11AC-2 AC-3 AC-5 AC-6 CM-2
+6 more
CM-5 IA-2 IA-4 IA-6 RA-5 SI-4
T1578.003Delete Cloud InstanceDefense Impairment11AC-2 AC-3 AC-5 AC-6 CM-2
+6 more
CM-5 IA-2 IA-4 IA-6 RA-5 SI-4
T1598Phishing for InformationReconnaissance11AC-4 CA-7 CM-2 CM-6 IA-9
+6 more
SC-20 SC-44 SC-7 SI-3 SI-4 SI-8
T1598.002Spearphishing AttachmentReconnaissance11AC-4 CA-7 CM-2 CM-6 IA-9
+6 more
SC-20 SC-44 SC-7 SI-3 SI-4 SI-8
T1598.003Spearphishing LinkReconnaissance11AC-4 CA-7 CM-2 CM-6 IA-9
+6 more
SC-20 SC-44 SC-7 SI-3 SI-4 SI-8
T1609Container Administration CommandExecution11AC-17 AC-2 AC-3 AC-4 AC-5
+6 more
AC-6 CM-6 CM-7 SC-7 SI-10 SI-7
T1612Build Image on HostStealth11AC-17 AC-2 AC-3 AC-6 CM-2
+6 more
CM-6 CM-7 RA-5 SA-11 SC-7 SI-4
T1053.006Systemd TimersExecution, Persistence, Privilege Escalation10AC-2 AC-3 AC-5 AC-6 CA-7
+5 more
CM-5 CM-6 IA-2 SI-4 SI-7
T1070.003Clear Command HistoryStealth10AC-2 AC-3 AC-5 AC-6 CA-7
+5 more
CM-2 CM-6 SI-3 SI-4 SI-7
T1070.007Clear Network Connection History and ConfigurationsStealth10AC-2 AC-3 AC-5 AC-6 CA-7
+5 more
CM-2 CM-6 SI-3 SI-4 SI-7
T1070.009Clear PersistenceStealth10AC-2 AC-3 AC-5 AC-6 CA-7
+5 more
CM-2 CM-6 SI-3 SI-4 SI-7
T1080Taint Shared ContentLateral Movement10AC-3 CA-7 CM-2 CM-7 SC-4
+5 more
SC-7 SI-10 SI-3 SI-4 SI-7
T1091Replication Through Removable MediaLateral Movement, Initial Access10AC-3 AC-6 CM-2 CM-6 CM-8
+5 more
MP-7 RA-5 SC-41 SI-3 SI-4
T1127.002ClickOnceStealth, Execution10AC-17 CM-2 CM-6 CM-7 CM-8
+5 more
RA-5 SC-18 SI-10 SI-4 SI-7
T1137.001Office Template MacrosPersistence10AC-6 CM-2 CM-6 CM-8 RA-5
+5 more
SC-18 SC-44 SI-3 SI-4 SI-8
T1137.002Office TestPersistence10AC-10 AC-14 AC-17 AC-6 CM-2
+5 more
CM-5 CM-6 SC-18 SC-44 SI-8
T1187Forced AuthenticationCredential Access10AC-3 AC-4 CA-7 CM-2 CM-6
+5 more
CM-7 SC-7 SI-10 SI-15 SI-4
T1218.001Compiled HTML FileStealth10CM-11 CM-2 CM-6 CM-7 SC-18
+5 more
SI-10 SI-16 SI-3 SI-4 SI-7
T1485Data DestructionImpact10AC-3 AC-6 CM-2 CP-10 CP-2
+5 more
CP-7 CP-9 SI-3 SI-4 SI-7
T1491DefacementImpact10AC-3 AC-6 CM-2 CP-10 CP-2
+5 more
CP-7 CP-9 SI-3 SI-4 SI-7
T1491.001Internal DefacementImpact10AC-3 AC-6 CM-2 CP-10 CP-2
+5 more
CP-7 CP-9 SI-3 SI-4 SI-7
T1491.002External DefacementImpact10AC-3 AC-6 CM-2 CP-10 CP-2
+5 more
CP-7 CP-9 SI-3 SI-4 SI-7
T1539Steal Web Session CookieCredential Access10AC-20 AC-3 AC-6 CA-7 CM-2
+5 more
CM-6 IA-2 IA-5 SI-3 SI-4
T1546.013PowerShell ProfilePrivilege Escalation, Persistence10AC-3 AC-6 CA-7 CM-10 CM-2
+5 more
CM-6 IA-9 SI-3 SI-4 SI-7
T1547.003Time ProvidersPersistence, Privilege Escalation10AC-17 AC-3 AC-4 AC-6 CA-7
+5 more
CM-2 CM-5 CM-6 SI-4 SI-7
T1553.003SIP and Trust Provider HijackingDefense Impairment10AC-3 AC-6 CA-7 CM-2 CM-6
+5 more
CM-7 SI-10 SI-3 SI-4 SI-7
T1558.005Ccache FilesCredential Access10AC-2 AC-3 AC-6 CA-7 IA-2
+5 more
IA-5 SC-4 SI-12 SI-4 SI-7
T1561Disk WipeImpact10AC-3 AC-6 CM-2 CP-10 CP-2
+5 more
CP-7 CP-9 SI-3 SI-4 SI-7
T1561.001Disk Content WipeImpact10AC-3 AC-6 CM-2 CP-10 CP-2
+5 more
CP-7 CP-9 SI-3 SI-4 SI-7
T1561.002Disk Structure WipeImpact10AC-3 AC-6 CM-2 CP-10 CP-2
+5 more
CP-7 CP-9 SI-3 SI-4 SI-7
T1566.003Spearphishing via ServiceInitial Access10AC-2 AC-4 AC-6 CA-7 SC-44
+5 more
SC-7 SI-2 SI-3 SI-4 SI-8
T1574.014AppDomainManagerStealth, Execution10AC-3 AC-6 CA-7 CM-5 CM-6
+5 more
CM-7 SI-10 SI-3 SI-4 SI-7
T1613Container and Resource DiscoveryDiscovery10AC-17 AC-2 AC-3 AC-6 CM-6
+5 more
CM-7 IA-2 SC-43 SC-7 SI-4
T1037Boot or Logon Initialization ScriptsPersistence, Privilege Escalation9AC-17 AC-3 CA-7 CM-2 CM-6
+4 more
CM-7 SI-3 SI-4 SI-7
T1053.003CronExecution, Persistence, Privilege Escalation9AC-2 AC-3 AC-5 AC-6 CM-2
+4 more
CM-5 IA-2 RA-5 SI-4
T1055.009Proc MemoryStealth, Privilege Escalation9AC-3 AC-6 CA-7 SC-18 SC-7
+4 more
SI-16 SI-2 SI-3 SI-4
T1059.011LuaExecution9AC-2 AC-3 AC-6 CM-2 CM-6
+4 more
SI-16 SI-3 SI-4 SI-7
T1111Multi-Factor Authentication InterceptionCredential Access9AC-20 CA-7 CM-2 CM-6 IA-13
+4 more
IA-2 IA-5 SI-3 SI-4
T1114.001Local Email CollectionCollection9AC-16 AC-17 AC-19 AC-20 AC-4
+4 more
SC-37 SI-12 SI-4 SI-7
T1205Traffic SignalingStealth, Persistence, Command And Control9AC-3 AC-4 CA-7 CM-2 CM-6
+4 more
CM-7 SC-7 SI-15 SI-4
T1218.007MsiexecStealth9AC-2 AC-3 AC-5 AC-6 CM-2
+4 more
CM-5 CM-6 CM-7 IA-2
T1482Domain Trust DiscoveryDiscovery9AC-4 CM-2 CM-6 CM-7 RA-5
+4 more
SA-17 SA-8 SC-46 SC-7
T1499Endpoint Denial of ServiceImpact9AC-3 AC-4 CA-7 CM-6 CM-7
+4 more
SC-7 SI-10 SI-15 SI-4
T1499.001OS Exhaustion FloodImpact9AC-3 AC-4 CA-7 CM-6 CM-7
+4 more
SC-7 SI-10 SI-15 SI-4
T1499.002Service Exhaustion FloodImpact9AC-3 AC-4 CA-7 CM-6 CM-7
+4 more
SC-7 SI-10 SI-15 SI-4
T1499.003Application Exhaustion FloodImpact9AC-3 AC-4 CA-7 CM-6 CM-7
+4 more
SC-7 SI-10 SI-15 SI-4
T1499.004Application or System ExploitationImpact9AC-3 AC-4 CA-7 CM-6 CM-7
+4 more
SC-7 SI-10 SI-15 SI-4
T1546Event Triggered ExecutionPrivilege Escalation, Persistence9AC-2 AC-3 AC-6 CM-2 CM-3
+4 more
CM-6 IA-9 SI-2 SI-7
T1546.002ScreensaverPrivilege Escalation, Persistence9CM-2 CM-6 CM-7 CM-8 RA-5
+4 more
SI-10 SI-3 SI-4 SI-7
T1554Compromise Host Software BinaryPersistence9CM-2 CM-5 CM-6 IA-9 SI-3
+4 more
SI-7 SR-11 SR-4 SR-5
T1556.008Network Provider DLLDefense Impairment, Persistence, Credential Access9AC-3 AC-6 CM-2 CM-3 CM-5
+4 more
CM-6 CM-7 SI-4 SI-7
T1558.001Golden TicketCredential Access9AC-2 AC-3 AC-5 AC-6 CM-2
+4 more
CM-5 CM-6 IA-2 IA-5
T1574.012COR_PROFILERStealth, Execution9AC-2 AC-3 AC-5 AC-6 CM-5
+4 more
CM-7 IA-2 SI-10 SI-7
T1610Deploy ContainerExecution9AC-17 AC-2 AC-3 AC-6 CM-6
+4 more
CM-7 IA-2 SC-7 SI-4
T1008Fallback ChannelsCommand And Control8AC-4 CA-7 CM-2 CM-6 CM-7
+3 more
SC-7 SI-3 SI-4
T1011.001Exfiltration Over BluetoothExfiltration8AC-18 CM-2 CM-6 CM-7 CM-8
+3 more
RA-5 SI-3 SI-4
T1027Obfuscated Files or InformationStealth8AC-3 CM-2 CM-6 CM-7 SI-2
+3 more
SI-3 SI-4 SI-7
T1036.003Rename Legitimate UtilitiesStealth8AC-2 AC-3 AC-6 CA-7 CM-2
+3 more
CM-6 SI-3 SI-4
T1090.001Internal ProxyCommand And Control8AC-4 CA-7 CM-2 CM-6 CM-7
+3 more
SC-7 SI-3 SI-4
T1090.002External ProxyCommand And Control8AC-4 CA-7 CM-2 CM-6 CM-7
+3 more
SC-7 SI-3 SI-4
T1090.003Multi-hop ProxyCommand And Control8AC-3 AC-4 CA-7 CM-6 CM-7
+3 more
SC-7 SI-10 SI-15
T1092Communication Through Removable MediaCommand And Control8CM-2 CM-6 CM-7 CM-8 MP-7
+3 more
RA-5 SI-3 SI-4
T1102Web ServiceCommand And Control8AC-4 CA-7 CM-2 CM-6 CM-7
+3 more
SC-7 SI-3 SI-4
T1102.001Dead Drop ResolverCommand And Control8AC-4 CA-7 CM-2 CM-6 CM-7
+3 more
SC-7 SI-3 SI-4
T1102.002Bidirectional CommunicationCommand And Control8AC-4 CA-7 CM-2 CM-6 CM-7
+3 more
SC-7 SI-3 SI-4
T1102.003One-Way CommunicationCommand And Control8AC-4 CA-7 CM-2 CM-6 CM-7
+3 more
SC-7 SI-3 SI-4
T1104Multi-Stage ChannelsCommand And Control8AC-4 CA-7 CM-2 CM-6 CM-7
+3 more
SC-7 SI-3 SI-4
T1105Ingress Tool TransferCommand And Control8AC-4 CA-7 CM-2 CM-6 CM-7
+3 more
SC-7 SI-3 SI-4
T1127Trusted Developer Utilities Proxy ExecutionStealth, Execution8CM-2 CM-6 CM-7 CM-8 RA-5
+3 more
SI-10 SI-4 SI-7
T1134Access Token ManipulationStealth, Privilege Escalation8AC-2 AC-3 AC-5 AC-6 CM-5
+3 more
CM-6 IA-13 IA-2
T1134.001Token Impersonation/TheftStealth, Privilege Escalation8AC-2 AC-3 AC-5 AC-6 CM-5
+3 more
CM-6 IA-13 IA-2
T1134.003Make and Impersonate TokenStealth, Privilege Escalation8AC-2 AC-3 AC-5 AC-6 CM-5
+3 more
CM-6 IA-13 IA-2
T1199Trusted RelationshipInitial Access8AC-3 AC-4 AC-6 AC-8 CM-6
+3 more
CM-7 SC-46 SC-7
T1205.001Port KnockingStealth, Persistence, Command And Control8AC-3 AC-4 CA-7 CM-6 CM-7
+3 more
SC-7 SI-15 SI-4
T1498Network Denial of ServiceImpact8AC-3 AC-4 CA-7 CM-6 CM-7
+3 more
SC-7 SI-10 SI-15
T1498.001Direct Network FloodImpact8AC-3 AC-4 CA-7 CM-6 CM-7
+3 more
SC-7 SI-10 SI-15
T1498.002Reflection AmplificationImpact8AC-3 AC-4 CA-7 CM-6 CM-7
+3 more
SC-7 SI-10 SI-15
T1505.003Web ShellPersistence8AC-2 AC-3 AC-5 AC-6 CM-2
+3 more
CM-6 RA-5 SI-4
T1543.001Launch AgentPersistence, Privilege Escalation8AC-2 AC-3 AC-5 AC-6 CM-11
+3 more
CM-2 CM-5 IA-2
T1543.003Windows ServicePersistence, Privilege Escalation8AC-2 AC-3 AC-5 AC-6 CM-11
+3 more
CM-2 CM-5 IA-2
T1543.004Launch DaemonPersistence, Privilege Escalation8AC-2 AC-3 AC-5 AC-6 CM-11
+3 more
CM-2 CM-5 IA-2
T1546.004Unix Shell Configuration ModificationPrivilege Escalation, Persistence8AC-3 AC-6 CA-7 CM-2 CM-6
+3 more
SI-3 SI-4 SI-7
T1547.012Print ProcessorsPersistence, Privilege Escalation8AC-17 AC-2 AC-3 AC-5 AC-6
+3 more
CM-5 IA-2 SI-4
T1550.002Pass the HashLateral Movement8AC-2 AC-3 AC-5 AC-6 CM-5
+3 more
CM-6 IA-2 SI-2
T1555Credentials from Password StoresCredential Access8AC-20 AC-3 AC-6 CA-7 CM-3
+3 more
IA-5 SI-2 SI-4
T1555.005Password ManagersCredential Access8AC-2 AC-3 CM-2 CM-6 IA-2
+3 more
IA-5 SI-2 SI-4
T1568Dynamic ResolutionCommand And Control8AC-4 CA-7 SC-20 SC-21 SC-22
+3 more
SC-7 SI-3 SI-4
T1568.002Domain Generation AlgorithmsCommand And Control8AC-4 CA-7 SC-20 SC-21 SC-22
+3 more
SC-7 SI-3 SI-4
T1571Non-Standard PortCommand And Control8AC-4 CA-7 CM-2 CM-6 CM-7
+3 more
SC-7 SI-3 SI-4
T1648Serverless ExecutionExecution8AC-2 AC-3 AC-6 CM-6 CM-7
+3 more
IA-2 SC-7 SI-4
T1685.004Disable or Modify Linux Audit System LogDefense Impairment8AC-2 AC-3 AC-6 CM-3 CM-5
+3 more
CM-6 SI-4 SI-7
T1001Data ObfuscationCommand And Control7AC-4 CA-7 CM-2 CM-6 SC-7
+2 more
SI-3 SI-4
T1001.001Junk DataCommand And Control7AC-4 CA-7 CM-2 CM-6 SC-7
+2 more
SI-3 SI-4
T1001.002SteganographyCommand And Control7AC-4 CA-7 CM-2 CM-6 SC-7
+2 more
SI-3 SI-4
T1001.003Protocol or Service ImpersonationCommand And Control7AC-4 CA-7 CM-2 CM-6 SC-7
+2 more
SI-3 SI-4
T1021.007Cloud ServicesLateral Movement7AC-2 AC-20 AC-3 AC-5 AC-6
+2 more
IA-2 IA-5
T1029Scheduled TransferExfiltration7AC-4 CA-7 CM-2 CM-6 SC-7
+2 more
SI-3 SI-4
T1030Data Transfer Size LimitsExfiltration7AC-4 CA-7 CM-2 CM-6 SC-7
+2 more
SI-3 SI-4
T1037.002Login HookPersistence, Privilege Escalation7AC-3 CA-7 CM-2 CM-6 SI-3
+2 more
SI-4 SI-7
T1037.003Network Logon ScriptPersistence, Privilege Escalation7AC-3 CA-7 CM-2 CM-6 SI-3
+2 more
SI-4 SI-7
T1037.004RC ScriptsPersistence, Privilege Escalation7AC-3 CA-7 CM-2 CM-6 SI-3
+2 more
SI-4 SI-7
T1037.005Startup ItemsPersistence, Privilege Escalation7AC-3 CA-7 CM-2 CM-6 SI-3
+2 more
SI-4 SI-7
T1053.007Container Orchestration JobExecution, Persistence, Privilege Escalation7AC-2 AC-3 AC-5 AC-6 CM-5
+2 more
IA-2 IA-8
T1056.003Web Portal CaptureCollection, Credential Access7AC-2 AC-3 AC-5 AC-6 CM-5
+2 more
CM-6 IA-2
T1098.005Device RegistrationPersistence, Privilege Escalation7AC-2 AC-20 AC-3 AC-5 AC-6
+2 more
CM-5 CM-6
T1106Native APIExecution7AC-6 CM-2 CM-6 CM-7 SI-2
+2 more
SI-3 SI-4
T1132Data EncodingCommand And Control7AC-4 CA-7 CM-2 CM-6 SC-7
+2 more
SI-3 SI-4
T1132.001Standard EncodingCommand And Control7AC-4 CA-7 CM-2 CM-6 SC-7
+2 more
SI-3 SI-4
T1132.002Non-Standard EncodingCommand And Control7AC-4 CA-7 CM-2 CM-6 SC-7
+2 more
SI-3 SI-4
T1134.002Create Process with TokenStealth, Privilege Escalation7AC-2 AC-3 AC-5 AC-6 CM-5
+2 more
CM-6 IA-2
T1137.003Outlook FormsPersistence7AC-6 CM-2 CM-6 SC-18 SC-44
+2 more
SI-2 SI-8
T1137.004Outlook Home PagePersistence7AC-6 CM-2 CM-6 SC-18 SC-44
+2 more
SI-2 SI-8
T1137.005Outlook RulesPersistence7AC-6 CM-2 CM-6 SC-18 SC-44
+2 more
SI-2 SI-8
T1546.016Installer PackagesPrivilege Escalation, Persistence7AC-6 CA-7 CM-5 CM-6 SI-2
+2 more
SI-3 SI-4
T1547.008LSASS DriverPersistence, Privilege Escalation7CM-2 CM-6 RA-5 SC-39 SI-3
+2 more
SI-4 SI-7
T1550Use Alternate Authentication MaterialLateral Movement7AC-2 AC-3 AC-5 AC-6 CM-5
+2 more
CM-6 IA-2
T1559.003XPC ServicesExecution7CM-5 CM-6 CM-7 SA-10 SA-11
+2 more
SA-8 SI-4
T1564.006Run Virtual InstanceStealth7CM-2 CM-6 CM-7 CM-8 SI-10
+2 more
SI-4 SI-7
T1564.008Email Hiding RulesStealth7AC-4 CM-3 CM-5 CM-7 SI-3
+2 more
SI-4 SI-7
T1569.001LaunchctlExecution7AC-2 AC-3 AC-5 AC-6 CM-11
+2 more
CM-5 IA-2
T1574.013KernelCallbackTableStealth, Execution7CA-7 CM-2 SI-10 SI-2 SI-3
+2 more
SI-4 SI-7
T1598.001Spearphishing ServiceReconnaissance7AC-4 CA-7 SC-44 SC-7 SI-3
+2 more
SI-4 SI-8
T1606Forge Web CredentialsCredential Access7AC-2 AC-3 AC-5 AC-6 IA-13
+2 more
SC-17 SI-2
T1619Cloud Storage Object DiscoveryDiscovery7AC-17 AC-2 AC-3 AC-5 AC-6
+2 more
CM-5 IA-2
T1621Multi-Factor Authentication Request GenerationCredential Access7AC-2 AC-6 CM-5 IA-13 IA-2
+2 more
IA-3 IA-5
T1685.002Disable or Modify Cloud LogDefense Impairment7AC-2 AC-3 AC-5 AC-6 CM-3
+2 more
CM-5 IA-2
T1689Downgrade AttackDefense Impairment7CM-2 CM-6 CM-7 RA-5 SC-8
+2 more
SI-4 SI-7
T1036.007Double File ExtensionStealth6CA-7 CM-2 CM-6 CM-7 IA-2
+1 more
SI-4
T1055.001Dynamic-link Library InjectionStealth, Privilege Escalation6AC-6 SC-18 SC-7 SI-2 SI-3
+1 more
SI-4
T1055.002Portable Executable InjectionStealth, Privilege Escalation6AC-6 SC-18 SC-7 SI-2 SI-3
+1 more
SI-4
T1055.003Thread Execution HijackingStealth, Privilege Escalation6AC-6 SC-18 SC-7 SI-2 SI-3
+1 more
SI-4
T1055.004Asynchronous Procedure CallStealth, Privilege Escalation6AC-6 SC-18 SC-7 SI-2 SI-3
+1 more
SI-4
T1055.005Thread Local StorageStealth, Privilege Escalation6AC-6 SC-18 SC-7 SI-2 SI-3
+1 more
SI-4
T1055.011Extra Window Memory InjectionStealth, Privilege Escalation6AC-6 SC-18 SC-7 SI-2 SI-3
+1 more
SI-4
T1055.012Process HollowingStealth, Privilege Escalation6AC-6 SC-18 SC-7 SI-2 SI-3
+1 more
SI-4
T1055.013Process DoppelgängingStealth, Privilege Escalation6AC-6 SC-18 SC-7 SI-2 SI-3
+1 more
SI-4
T1055.014VDSO HijackingStealth, Privilege Escalation6AC-6 SC-18 SC-7 SI-2 SI-3
+1 more
SI-4
T1059.009Cloud APIExecution6AC-2 AC-3 AC-6 CM-7 IA-2
+1 more
SI-4
T1087.004Cloud AccountDiscovery6AC-2 AC-3 AC-5 AC-6 IA-2
+1 more
IA-8
T1129Shared ModulesExecution6CM-2 CM-7 SI-10 SI-3 SI-4
+1 more
SI-7
T1137.006Add-insPersistence6AC-6 CM-2 CM-6 SC-18 SC-44
+1 more
SI-8
T1216System Script Proxy ExecutionStealth6CM-2 CM-6 CM-7 SI-10 SI-4
+1 more
SI-7
T1216.001PubPrnStealth6CM-2 CM-6 CM-7 SI-10 SI-4
+1 more
SI-7
T1220XSL Script ProcessingStealth6CM-2 CM-6 CM-7 SI-10 SI-4
+1 more
SI-7
T1485.001Lifecycle-Triggered DeletionImpact6AC-2 AC-3 AC-6 CP-10 CP-9
+1 more
SI-7
T1538Cloud Service DashboardDiscovery6AC-2 AC-3 AC-5 AC-6 IA-2
+1 more
IA-8
T1546.008Accessibility FeaturesPrivilege Escalation, Persistence6CM-10 CM-6 CM-7 SI-10 SI-4
+1 more
SI-7
T1546.014EmondPrivilege Escalation, Persistence6CM-2 CM-6 CM-8 RA-5 SI-3
+1 more
SI-4
T1553.001Gatekeeper BypassDefense Impairment6CM-2 CM-6 CM-7 SI-10 SI-4
+1 more
SI-7
T1553.004Install Root CertificateDefense Impairment6CM-10 CM-6 CM-7 IA-9 SC-20
+1 more
SI-4
T1553.005Mark-of-the-Web BypassDefense Impairment6CM-2 CM-6 CM-7 SI-10 SI-4
+1 more
SI-7
T1556.006Multi-Factor AuthenticationDefense Impairment, Persistence, Credential Access6AC-2 AC-3 AC-6 IA-11 IA-13
+1 more
IA-2
T1556.007Hybrid IdentityDefense Impairment, Persistence, Credential Access6AC-2 AC-3 AC-6 IA-11 IA-13
+1 more
IA-2
T1564.004NTFS File AttributesStealth6AC-16 AC-3 CA-7 SI-3 SI-4
+1 more
SI-7
T1651Cloud Administration CommandExecution6AC-17 AC-2 AC-3 AC-6 IA-2
+1 more
SI-4
T1686.001Cloud FirewallDefense Impairment6AC-2 AC-3 AC-5 AC-6 CM-5
+1 more
IA-2
T1011Exfiltration Over Other Network MediumExfiltration5AC-18 CM-6 CM-7 SC-43 SI-4
T1036.001Invalid Code SignatureStealth5CM-2 CM-6 IA-9 SI-4 SI-7
T1036.008Masquerade File TypeStealth5CM-7 SC-7 SI-10 SI-3 SI-4
T1036.010Masquerade Account NameStealth5AC-2 AC-3 CM-6 IA-2 SI-4
T1127.001MSBuildStealth, Execution5CM-2 CM-6 CM-8 RA-5 SI-4
T1200Hardware AdditionsInitial Access5AC-20 AC-3 AC-6 MP-7 SC-41
T1201Password Policy DiscoveryDiscovery5CA-7 CM-2 CM-6 SI-3 SI-4
T1543.005Container ServicePersistence, Privilege Escalation5AC-2 AC-3 AC-5 AC-6 IA-2
T1546.010AppInit DLLsPrivilege Escalation, Persistence5CM-2 CM-7 SI-10 SI-2 SI-7
T1547.002Authentication PackagePersistence, Privilege Escalation5CM-6 SC-39 SI-3 SI-4 SI-7
T1547.005Security Support ProviderPersistence, Privilege Escalation5CM-6 SC-39 SI-3 SI-4 SI-7
T1555.002Securityd MemoryCredential Access5AC-3 AC-6 CA-7 IA-5 SI-4
T1555.004Windows Credential ManagerCredential Access5CM-2 CM-6 CM-7 IA-5 SI-4
T1560Archive Collected DataCollection5CM-2 RA-5 SC-7 SI-3 SI-4
T1560.001Archive via UtilityCollection5CM-2 RA-5 SC-7 SI-3 SI-4
T1578.005Modify Cloud Compute ConfigurationsDefense Impairment5AC-2 AC-20 AC-3 AC-6 CM-3
T1580Cloud Infrastructure DiscoveryDiscovery5AC-2 AC-3 AC-5 AC-6 IA-2
T1590.002DNSReconnaissance5AC-4 CM-6 CM-7 SC-32 SC-7
T1685.003Modify or Spoof Tool UIDefense Impairment5CM-5 CM-6 SI-3 SI-4 SI-7
T1027.002Software PackingStealth4SI-2 SI-3 SI-4 SI-7
T1027.007Dynamic API ResolutionStealth4SI-2 SI-3 SI-4 SI-7
T1027.008Stripped PayloadsStealth4SI-2 SI-3 SI-4 SI-7
T1027.009Embedded PayloadsStealth4SI-2 SI-3 SI-4 SI-7
T1027.010Command ObfuscationStealth4CM-6 SI-10 SI-3 SI-4
T1056.002GUI Input CaptureCollection, Credential Access4CA-7 SI-3 SI-4 SI-7
T1071.005Publish/Subscribe ProtocolsCommand And Control4AC-4 SC-31 SC-7 SI-4
T1087Account DiscoveryDiscovery4AC-2 CM-6 CM-7 SI-4
T1098.006Additional Container Cluster RolesPersistence, Privilege Escalation4AC-2 AC-3 AC-6 IA-5
T1216.002SyncAppvPublishingServerStealth4CM-2 CM-6 CM-7 SI-7
T1218.010Regsvr32Stealth4CA-7 SI-10 SI-4 SI-7
T1218.011Rundll32Stealth4CA-7 SI-10 SI-4 SI-7
T1548.005Temporary Elevated Cloud AccessPrivilege Escalation4AC-2 AC-3 AC-6 CM-5
T1552.003Shell HistoryCredential Access4CM-6 CM-7 SC-28 SI-4
T1555.006Cloud Secrets Management StoresCredential Access4AC-2 AC-3 AC-6 CM-7
T1556.005Reversible EncryptionDefense Impairment, Persistence, Credential Access4AC-2 AC-5 AC-6 IA-5
T1564.007VBA StompingStealth4CM-2 CM-6 CM-8 SI-4
T1574.006Dynamic Linker HijackingStealth, Execution4CM-6 CM-7 SI-10 SI-7
T1606.001Web CookiesCredential Access4AC-2 AC-3 AC-6 SI-2
T1606.002SAML TokensCredential Access4AC-2 AC-3 AC-6 IA-13
T1653Power SettingsPersistence4CM-2 CM-3 CM-7 SI-4
T1654Log EnumerationDiscovery4AC-2 AC-3 AC-4 AC-6
T1690Prevent Command History LoggingDefense Impairment4CM-2 CM-6 CM-7 SI-4
T1070.010Relocate MalwareStealth3SI-3 SI-4 SI-7
T1087.001Local AccountDiscovery3CM-6 CM-7 SI-4
T1087.002Domain AccountDiscovery3CM-6 CM-7 SI-4
T1112Modify RegistryDefense Impairment, Persistence3AC-6 CM-7 SI-7
T1135Network Share DiscoveryDiscovery3CM-6 CM-7 SI-4
T1546.009AppCert DLLsPrivilege Escalation, Persistence3CM-7 SI-10 SI-7
T1548.001Setuid and SetgidPrivilege Escalation3CM-6 CM-7 SI-4
T1550.004Web Session CookieLateral Movement3SC-23 SC-8 SI-7
T1555.001KeychainCredential Access3CA-7 IA-5 SI-4
T1556.002Password Filter DLLDefense Impairment, Persistence, Credential Access3CM-6 CM-7 SI-4
T1564.002Hidden UsersStealth3CM-6 CM-7 SI-4
T1564.003Hidden WindowStealth3CM-7 SI-10 SI-7
T1564.010Process Argument SpoofingStealth3CA-7 SI-4 SI-7
T1567.001Exfiltration to Code RepositoryExfiltration3AC-20 AC-4 SC-7
T1567.002Exfiltration to Cloud StorageExfiltration3AC-20 AC-4 SC-7
T1567.003Exfiltration to Text Storage SitesExfiltration3AC-17 AC-4 SC-7
T1567.004Exfiltration Over WebhookExfiltration3AC-17 AC-4 SC-7
T1649Steal or Forge Authentication CertificatesCredential Access3IA-13 IA-2 IA-5
T1659Content InjectionInitial Access, Command And Control3AC-17 AC-4 SC-7
T1027.012LNK Icon SmugglingStealth2SI-3 SI-4
T1037.001Logon Script (Windows)Persistence, Privilege Escalation2AC-17 CM-7
T1205.002Socket FiltersStealth, Persistence, Command And Control2AC-4 SI-4
T1546.011Application ShimmingPrivilege Escalation, Persistence2AC-6 SI-2
T1552.008Chat MessagesCredential Access2AC-4 SI-4
T1574.011Services Registry Permissions WeaknessStealth, Execution2AC-6 CM-5
T1657Financial TheftImpact2AC-5 AC-6
T1027.011Fileless StorageStealth1SI-4
T1027.013Encrypted/Encoded FileStealth1SI-3
T1027.014Polymorphic CodeStealth1SI-3
T1055.015ListPlantingStealth, Privilege Escalation1SI-3
T1090.004Domain FrontingCommand And Control1SC-8
T1496.003SMS PumpingImpact1SC-5
T1535Unused/Unsupported Cloud RegionsStealth1SC-23
T1564.012File/Path ExclusionsStealth1SI-3
T1593.003Code RepositoriesReconnaissance1CM-8
T1595.003Wordlist ScanningReconnaissance1SC-4
T1666Modify Cloud Resource HierarchyDefense Impairment1CM-3