santosomar
- 800 skills
- 0 followers
- 8 hours ago last updated
- ▌ Pt Maintaining Access · santosomarEvaluates whether an attacker could retain foothold and move laterally after initial compromise, within strict authorization limits. Use when testing persistence, session resilience, and detection/response effectiveness during a pen test.
- ▌ Pt Fuzzing Binary Protocol · santosomarPerforms authorized fuzz testing of binary formats and network protocols to uncover parser vulnerabilities, memory safety defects, and denial-of-service conditions. Use when assessing protocol handlers, file parsers, and service robustness against malformed inputs.
- ▌ Pt Nuclei Template Creation · santosomar bundleCreates Nuclei YAML templates for vulnerability detection across HTTP, DNS, TCP, SSL, and other protocols. Use when converting a confirmed vulnerability, misconfiguration, or exposure into a reusable automated check — for example, turning a manual finding into a detection rule, writing a CVE check, or codifying a technology fingerprint.
- ▌ Pt Embedded Device Assessment · santosomarPerforms authorized security assessment of embedded and IoT devices across hardware, firmware, interfaces, and update mechanisms. Use when testing device boot flows, debug interfaces, firmware integrity, and local/network attack surfaces.
- ▌ Pt Web Application Assessment · santosomarPerforms authorized web application and API penetration testing with focus on OWASP-style risks and business logic flaws. Use when assessing websites, web APIs, authentication flows, session handling, and input validation.
- ▌ Pt Scanning · santosomarPerforms authorized security scanning using static, dynamic, and vulnerability-focused methods. Use when mapping exposed services, profiling application behavior, and identifying known weaknesses for validation.
- ▌ Pt Gaining Access · santosomarGuides controlled exploitation of validated vulnerabilities to measure real-world impact. Use when the user requests proof-of-concept validation, privilege escalation testing, or attack path confirmation in an authorized environment.
- ▌ Pt Planning Recon · santosomarDefines penetration test scope and performs authorized reconnaissance using passive and active methods. Use when planning a test engagement, collecting target intelligence, building asset inventories, or preparing recon findings.
- ▌ Pt Fuzzing Web API · santosomarPerforms authorized fuzzing of web applications and APIs to discover input validation failures, parser bugs, and stability issues. Use when testing HTTP endpoints, request parameters, payload handling, and error behavior under malformed or unexpected inputs.
- ▌ Pt Lotl Techniques · santosomarDemonstrates Living-off-the-Land (LotL) techniques using native OS tools to simulate realistic threat actor behavior during authorized penetration tests. Use when proving attack feasibility without custom malware, testing detection coverage, and validating what a real adversary could achieve with only built-in system capabilities.
- ▌ Pt Report Creation · santosomarCreates penetration test deliverables for executive and technical audiences, including prioritized findings and remediation plans. Use when drafting, structuring, or finalizing pen test reports from collected evidence.
- ▌ Pt Post Exploitation · santosomarPerforms authorized post-exploitation activities to assess impact, lateral movement paths, credential exposure, and detection gaps after initial compromise. Use when a foothold has been validated and the test requires controlled impact expansion analysis.
- ▌ Pt Analysis Reporting · santosomarProduces penetration test reports with executive summary, technical findings, and remediation guidance. Use when consolidating test evidence, prioritizing risk, and preparing stakeholder-ready deliverables.
- ▌ Attack Ent T1195 001 Compromise Software Dependencies And · santosomar bundleAnalyze MITRE ATT&CK T1195.001 Compromise Software Dependencies and Development Tools in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1195.001, Compromise Software Dependencies and Development Tools, or enterprise ATT&CK. Adversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise.
- ▌ Attack Ent T1546 003 Windows Management Instrumentation E · santosomar bundleAnalyze MITRE ATT&CK T1546.003 Windows Management Instrumentation Event Subscription in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1546.003, Windows Management Instrumentation Event Subscription, or enterprise ATT&CK. Adversaries may establish persistence and elevate privileges by executing malicious content triggered by a Windows Management Instrumentation (WMI) event subscription.
- ▌ Attack Ent T1546 004 Unix Shell Configuration Modificatio · santosomar bundleAnalyze MITRE ATT&CK T1546.004 Unix Shell Configuration Modification in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1546.004, Unix Shell Configuration Modification, or enterprise ATT&CK. Adversaries may establish persistence through executing malicious commands triggered by a user’s shell.
- ▌ Attack Ent T1546 012 Image File Execution Options Injecti · santosomar bundleAnalyze MITRE ATT&CK T1546.012 Image File Execution Options Injection in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1546.012, Image File Execution Options Injection, or enterprise ATT&CK. Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by Image File Execution Options (IFEO) debuggers.
- ▌ Attack Ent T1557 001 Name Resolution Poisoning And Smb Re · santosomar bundleAnalyze MITRE ATT&CK T1557.001 Name Resolution Poisoning and SMB Relay in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1557.001, Name Resolution Poisoning and SMB Relay, or enterprise ATT&CK. By responding to LLMNR/NBT-NS/mDNS network traffic, adversaries may spoof an authoritative source for name resolution to force communication with an adversary controlled system.(Citation: BlackCat ransomware) This activ…
- ▌ Attack Ent T1484 Domain Or Tenant Policy Modification · santosomar bundleAnalyze MITRE ATT&CK T1484 Domain or Tenant Policy Modification in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1484, Domain or Tenant Policy Modification, or enterprise ATT&CK. Adversaries may modify the configuration settings of a domain or identity tenant to evade defenses and/or escalate privileges in centrally managed environments.
- ▌ Attack Ent T1546 015 Component Object Model Hijacking · santosomar bundleAnalyze MITRE ATT&CK T1546.015 Component Object Model Hijacking in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1546.015, Component Object Model Hijacking, or enterprise ATT&CK. Adversaries may establish persistence by executing malicious content triggered by hijacked references to Component Object Model (COM) objects.
- ▌ Attack Ent T1547 001 Registry Run Keys Startup Folder · santosomar bundleAnalyze MITRE ATT&CK T1547.001 Registry Run Keys / Startup Folder in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1547.001, Registry Run Keys / Startup Folder, or enterprise ATT&CK. Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
- ▌ Attack Ent T1550 Use Alternate Authentication Materia · santosomar bundleAnalyze MITRE ATT&CK T1550 Use Alternate Authentication Material in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1550, Use Alternate Authentication Material, or enterprise ATT&CK. Adversaries may use alternate authentication material, such as password hashes, Kerberos tickets, and application access tokens, in order to move laterally within an environment and bypass normal system access controls.
- ▌ Attack Ent T1553 003 Sip And Trust Provider Hijacking · santosomar bundleAnalyze MITRE ATT&CK T1553.003 SIP and Trust Provider Hijacking in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1553.003, SIP and Trust Provider Hijacking, or enterprise ATT&CK. Adversaries may tamper with SIP and trust provider components to mislead the operating system and application control tools when conducting signature validation checks.
- ▌ Attack Ent T1553 006 Code Signing Policy Modification · santosomar bundleAnalyze MITRE ATT&CK T1553.006 Code Signing Policy Modification in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1553.006, Code Signing Policy Modification, or enterprise ATT&CK. Adversaries may modify code signing policies to enable execution of unsigned or self-signed code.
- ▌ Attack Ent T1649 Steal Or Forge Authentication Certif · santosomar bundleAnalyze MITRE ATT&CK T1649 Steal or Forge Authentication Certificates in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1649, Steal or Forge Authentication Certificates, or enterprise ATT&CK. Adversaries may steal or forge certificates used for authentication to access remote systems or resources.
- ▌ Attack Ent T1098 007 Additional Local Or Domain Groups · santosomar bundleAnalyze MITRE ATT&CK T1098.007 Additional Local or Domain Groups in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1098.007, Additional Local or Domain Groups, or enterprise ATT&CK. An adversary may add additional local or domain groups to an adversary-controlled account to maintain persistent access to a system or domain.
- ▌ Attack Ent T1021 003 Distributed Component Object Model · santosomar bundleAnalyze MITRE ATT&CK T1021.003 Distributed Component Object Model in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1021.003, Distributed Component Object Model, or enterprise ATT&CK. Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to interact with remote machines by taking advantage of Distributed Component Object Model (DCOM).
- ▌ Attack Ent T1685 001 Disable Or Modify Windows Event Log · santosomar bundleAnalyze MITRE ATT&CK T1685.001 Disable or Modify Windows Event Log in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1685.001, Disable or Modify Windows Event Log, or enterprise ATT&CK. Adversaries may disable or modify the Windows Event Log to limit data that can be leveraged for detections and audits.
- ▌ Attack Ent T1048 002 Exfiltration Over Asymmetric Encrypt · santosomar bundleAnalyze MITRE ATT&CK T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1048.002, Exfiltration Over Asymmetric Encrypted Non-C2 Protocol, or enterprise ATT&CK. Adversaries may steal data by exfiltrating it over an asymmetrically encrypted network protocol other than that of the existing command and control channel.
- ▌ Attack Ent T1048 003 Exfiltration Over Unencrypted Non C2 · santosomar bundleAnalyze MITRE ATT&CK T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1048.003, Exfiltration Over Unencrypted Non-C2 Protocol, or enterprise ATT&CK. Adversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel.
- ▌ Attack Ent T1070 007 Clear Network Connection History And · santosomar bundleAnalyze MITRE ATT&CK T1070.007 Clear Network Connection History and Configurations in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1070.007, Clear Network Connection History and Configurations, or enterprise ATT&CK. Adversaries may clear or remove evidence of malicious network connections in order to clean up traces of their operations.
- ▌ Attack Ent T1098 002 Additional Email Delegate Permission · santosomar bundleAnalyze MITRE ATT&CK T1098.002 Additional Email Delegate Permissions in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1098.002, Additional Email Delegate Permissions, or enterprise ATT&CK. Adversaries may grant additional permission levels to maintain persistent access to an adversary-controlled email account.
- ▌ Attack Mob T1398 Boot Or Logon Initialization Scripts · santosomar bundleAnalyze MITRE ATT&CK T1398 Boot or Logon Initialization Scripts in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1398, Boot or Logon Initialization Scripts, or mobile ATT&CK. Adversaries may use scripts automatically executed at boot or logon initialization to establish persistence.
- ▌ Attack Mob T1404 Exploitation For Privilege Escalatio · santosomar bundleAnalyze MITRE ATT&CK T1404 Exploitation for Privilege Escalation in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1404, Exploitation for Privilege Escalation, or mobile ATT&CK. Adversaries may exploit software vulnerabilities in order to elevate privileges.
- ▌ Attack Mob T1421 System Network Connections Discovery · santosomar bundleAnalyze MITRE ATT&CK T1421 System Network Connections Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1421, System Network Connections Discovery, or mobile ATT&CK. Adversaries may attempt to get a listing of network connections to or from the compromised device they are currently accessing or from remote systems by querying for information over the network.
- ▌ Attack Mob T1422 System Network Configuration Discove · santosomar bundleAnalyze MITRE ATT&CK T1422 System Network Configuration Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1422, System Network Configuration Discovery, or mobile ATT&CK. Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of devices they access or through information discovery of remote systems.
- ▌ Attack Mob T1474 003 Compromise Software Supply Chain · santosomar bundleAnalyze MITRE ATT&CK T1474.003 Compromise Software Supply Chain in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1474.003, Compromise Software Supply Chain, or mobile ATT&CK. Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise.
- ▌ Attack Ent T1048 Exfiltration Over Alternative Protoc · santosomar bundleAnalyze MITRE ATT&CK T1048 Exfiltration Over Alternative Protocol in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1048, Exfiltration Over Alternative Protocol, or enterprise ATT&CK. Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel.
- ▌ Attack Ent T1049 System Network Connections Discovery · santosomar bundleAnalyze MITRE ATT&CK T1049 System Network Connections Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1049, System Network Connections Discovery, or enterprise ATT&CK. Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
- ▌ Attack Ent T1068 Exploitation For Privilege Escalatio · santosomar bundleAnalyze MITRE ATT&CK T1068 Exploitation for Privilege Escalation in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1068, Exploitation for Privilege Escalation, or enterprise ATT&CK. Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
- ▌ Attack Ent T1070 005 Network Share Connection Removal · santosomar bundleAnalyze MITRE ATT&CK T1070.005 Network Share Connection Removal in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1070.005, Network Share Connection Removal, or enterprise ATT&CK. Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation.
- ▌ Attack Ent T1111 Multi Factor Authentication Intercep · santosomar bundleAnalyze MITRE ATT&CK T1111 Multi-Factor Authentication Interception in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1111, Multi-Factor Authentication Interception, or enterprise ATT&CK. Adversaries may target multi-factor authentication (MFA) mechanisms, (i.e., smart cards, token generators, etc.) to gain access to credentials that can be used to access systems, services, and network resources.
- ▌ Attack Ent T1140 Deobfuscate Decode Files Or Informat · santosomar bundleAnalyze MITRE ATT&CK T1140 Deobfuscate/Decode Files or Information in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1140, Deobfuscate/Decode Files or Information, or enterprise ATT&CK. Adversaries may use [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027) to hide artifacts of an intrusion from analysis.
- ▌ Attack Ent T1195 002 Compromise Software Supply Chain · santosomar bundleAnalyze MITRE ATT&CK T1195.002 Compromise Software Supply Chain in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1195.002, Compromise Software Supply Chain, or enterprise ATT&CK. Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise.
- ▌ Attack Ent T1222 File And Directory Permissions Modif · santosomar bundleAnalyze MITRE ATT&CK T1222 File and Directory Permissions Modification in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1222, File and Directory Permissions Modification, or enterprise ATT&CK. Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.(Citation: Hybrid Analysis Icacls1 June 2018)(Citation: Hybrid Analysis Icacls2 May 2018) F…
- ▌ Attack Ent T1027 005 Indicator Removal From Tools · santosomar bundleAnalyze MITRE ATT&CK T1027.005 Indicator Removal from Tools in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.005, Indicator Removal from Tools, or enterprise ATT&CK. Adversaries may remove indicators from tools if they believe their malicious tool was detected, quarantined, or otherwise curtailed.
- ▌ Attack Ent T1098 001 Additional Cloud Credentials · santosomar bundleAnalyze MITRE ATT&CK T1098.001 Additional Cloud Credentials in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1098.001, Additional Cloud Credentials, or enterprise ATT&CK. Adversaries may add adversary-controlled credentials to a cloud account to maintain persistent access to victim accounts and instances within the environment.
- ▌ Attack Ent T1505 006 Vsphere Installation Bundles · santosomar bundleAnalyze MITRE ATT&CK T1505.006 vSphere Installation Bundles in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1505.006, vSphere Installation Bundles, or enterprise ATT&CK. Adversaries may abuse vSphere Installation Bundles (VIBs) to establish persistent access to ESXi hypervisors.
- ▌ Attack Ent T1555 Credentials From Password Stores · santosomar bundleAnalyze MITRE ATT&CK T1555 Credentials from Password Stores in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1555, Credentials from Password Stores, or enterprise ATT&CK. Adversaries may search for common password storage locations to obtain user credentials.(Citation: F-Secure The Dukes) Passwords are stored in several places on a system, depending on the operating system or application…
- ▌ Attack Ent T1564 001 Hidden Files And Directories · santosomar bundleAnalyze MITRE ATT&CK T1564.001 Hidden Files and Directories in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1564.001, Hidden Files and Directories, or enterprise ATT&CK. Adversaries may set files and directories to be hidden to evade detection mechanisms.
- ▌ Attack Ent T1568 002 Domain Generation Algorithms · santosomar bundleAnalyze MITRE ATT&CK T1568.002 Domain Generation Algorithms in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1568.002, Domain Generation Algorithms, or enterprise ATT&CK. Adversaries may make use of Domain Generation Algorithms (DGAs) to dynamically identify a destination domain for command and control traffic rather than relying on a list of static IP addresses or domains.
- ▌ Attack Ent T1609 Container Administration Command · santosomar bundleAnalyze MITRE ATT&CK T1609 Container Administration Command in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1609, Container Administration Command, or enterprise ATT&CK. Adversaries may abuse a container administration service to execute commands within a container.
- ▌ Attack Ent T1213 Data From Information Repositories · santosomar bundleAnalyze MITRE ATT&CK T1213 Data from Information Repositories in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1213, Data from Information Repositories, or enterprise ATT&CK. Adversaries may leverage information repositories to mine valuable information.
- ▌ Attack Ent T1589 Gather Victim Identity Information · santosomar bundleAnalyze MITRE ATT&CK T1589 Gather Victim Identity Information in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1589, Gather Victim Identity Information, or enterprise ATT&CK. Adversaries may gather information about the victim's identity that can be used during targeting.
- ▌ Attack Ent T1685 006 Clear Linux Or Mac System Logs · santosomar bundleAnalyze MITRE ATT&CK T1685.006 Clear Linux or Mac System Logs in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1685.006, Clear Linux or Mac System Logs, or enterprise ATT&CK. Adversaries may clear system logs to hide evidence of an intrusion.
- ▌ Attack Ent T1091 Replication Through Removable Media · santosomar bundleAnalyze MITRE ATT&CK T1091 Replication Through Removable Media in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1091, Replication Through Removable Media, or enterprise ATT&CK. Adversaries may move onto systems, possibly those on disconnected or air-gapped networks, by copying malware to removable media and taking advantage of Autorun features when the media is inserted into a system and execu…
- ▌ Attack Ent T1548 005 Temporary Elevated Cloud Access · santosomar bundleAnalyze MITRE ATT&CK T1548.005 Temporary Elevated Cloud Access in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1548.005, Temporary Elevated Cloud Access, or enterprise ATT&CK. Adversaries may abuse permission configurations that allow them to gain temporarily elevated access to cloud resources.
- ▌ Attack Ent T1621 Multi Factor Authentication Request · santosomar bundleAnalyze MITRE ATT&CK T1621 Multi-Factor Authentication Request Generation in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1621, Multi-Factor Authentication Request Generation, or enterprise ATT&CK. Adversaries may attempt to bypass multi-factor authentication (MFA) mechanisms and gain access to accounts by generating MFA requests sent to users.
- ▌ Attack Ent T1016 System Network Configuration Discove · santosomar bundleAnalyze MITRE ATT&CK T1016 System Network Configuration Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1016, System Network Configuration Discovery, or enterprise ATT&CK. Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
- ▌ Attack Mob T1626 001 Device Administrator Permissions · santosomar bundleAnalyze MITRE ATT&CK T1626.001 Device Administrator Permissions in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1626.001, Device Administrator Permissions, or mobile ATT&CK. Adversaries may abuse Android’s device administration API to obtain a higher degree of control over the device.
- ▌ Attack Mob T1632 001 Code Signing Policy Modification · santosomar bundleAnalyze MITRE ATT&CK T1632.001 Code Signing Policy Modification in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1632.001, Code Signing Policy Modification, or mobile ATT&CK. Adversaries may modify code signing policies to enable execution of applications signed with unofficial or unknown keys.
- ▌ Attack Ent T1016 001 Internet Connection Discovery · santosomar bundleAnalyze MITRE ATT&CK T1016.001 Internet Connection Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1016.001, Internet Connection Discovery, or enterprise ATT&CK. Adversaries may check for Internet connectivity on compromised systems.
- ▌ Attack Ent T1055 002 Portable Executable Injection · santosomar bundleAnalyze MITRE ATT&CK T1055.002 Portable Executable Injection in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1055.002, Portable Executable Injection, or enterprise ATT&CK. Adversaries may inject portable executables (PE) into processes in order to evade process-based defenses as well as possibly elevate privileges.
- ▌ Attack Ent T1055 011 Extra Window Memory Injection · santosomar bundleAnalyze MITRE ATT&CK T1055.011 Extra Window Memory Injection in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1055.011, Extra Window Memory Injection, or enterprise ATT&CK. Adversaries may inject malicious code into process via Extra Window Memory (EWM) in order to evade process-based defenses as well as possibly elevate privileges.
- ▌ Attack Ent T1059 Command And Scripting Interpreter · santosomar bundleAnalyze MITRE ATT&CK T1059 Command and Scripting Interpreter in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1059, Command and Scripting Interpreter, or enterprise ATT&CK. Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries.
- ▌ Attack Ent T1190 Exploit Public Facing Application · santosomar bundleAnalyze MITRE ATT&CK T1190 Exploit Public-Facing Application in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1190, Exploit Public-Facing Application, or enterprise ATT&CK. Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
- ▌ Attack Ent T1203 Exploitation For Client Execution · santosomar bundleAnalyze MITRE ATT&CK T1203 Exploitation for Client Execution in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1203, Exploitation for Client Execution, or enterprise ATT&CK. Adversaries may exploit software vulnerabilities in client applications to execute code.
- ▌ Attack Ent T1574 005 Executable Installer File Permission · santosomar bundleAnalyze MITRE ATT&CK T1574.005 Executable Installer File Permissions Weakness in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1574.005, Executable Installer File Permissions Weakness, or enterprise ATT&CK. Adversaries may execute their own malicious payloads by hijacking the binaries used by an installer.
- ▌ Attack Ent T1574 007 Path Interception By Path Environmen · santosomar bundleAnalyze MITRE ATT&CK T1574.007 Path Interception by PATH Environment Variable in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1574.007, Path Interception by PATH Environment Variable, or enterprise ATT&CK. Adversaries may execute their own malicious payloads by hijacking environment variables used to load libraries.
- ▌ Attack Ent T1574 008 Path Interception By Search Order Hi · santosomar bundleAnalyze MITRE ATT&CK T1574.008 Path Interception by Search Order Hijacking in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1574.008, Path Interception by Search Order Hijacking, or enterprise ATT&CK. Adversaries may execute their own malicious payloads by hijacking the search order used to load other programs.
- ▌ Attack Ent T1574 011 Services Registry Permissions Weakne · santosomar bundleAnalyze MITRE ATT&CK T1574.011 Services Registry Permissions Weakness in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1574.011, Services Registry Permissions Weakness, or enterprise ATT&CK. Adversaries may execute their own malicious payloads by hijacking the Registry entries used by services.
- ▌ Attack Ent T1599 001 Network Address Translation Traversa · santosomar bundleAnalyze MITRE ATT&CK T1599.001 Network Address Translation Traversal in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1599.001, Network Address Translation Traversal, or enterprise ATT&CK. Adversaries may bridge network boundaries by modifying a network device’s Network Address Translation (NAT) configuration.
- ▌ Attack Ent T1548 002 Bypass User Account Control · santosomar bundleAnalyze MITRE ATT&CK T1548.002 Bypass User Account Control in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1548.002, Bypass User Account Control, or enterprise ATT&CK. Adversaries may bypass UAC mechanisms to elevate process privileges on system.
- ▌ Attack Ent T1554 Compromise Host Software Binary · santosomar bundleAnalyze MITRE ATT&CK T1554 Compromise Host Software Binary in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1554, Compromise Host Software Binary, or enterprise ATT&CK. Adversaries may modify host software binaries to establish persistent access to systems.
- ▌ Attack Ent T1556 006 Multi Factor Authentication · santosomar bundleAnalyze MITRE ATT&CK T1556.006 Multi-Factor Authentication in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1556.006, Multi-Factor Authentication, or enterprise ATT&CK. Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
- ▌ Attack Ent T1666 Modify Cloud Resource Hierarchy · santosomar bundleAnalyze MITRE ATT&CK T1666 Modify Cloud Resource Hierarchy in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1666, Modify Cloud Resource Hierarchy, or enterprise ATT&CK. Adversaries may attempt to modify hierarchical structures in infrastructure-as-a-service (IaaS) environments in order to evade defenses.
- ▌ Attack Ent T1685 002 Disable Or Modify Cloud Log · santosomar bundleAnalyze MITRE ATT&CK T1685.002 Disable or Modify Cloud Log in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1685.002, Disable or Modify Cloud Log, or enterprise ATT&CK. An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection.
- ▌ Attack Ent T1690 Prevent Command History Logging · santosomar bundleAnalyze MITRE ATT&CK T1690 Prevent Command History Logging in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1690, Prevent Command History Logging, or enterprise ATT&CK. Adversaries may impair command history logging to hide commands they run on a compromised system.
- ▌ Attack Mob T1630 001 Uninstall Malicious Application · santosomar bundleAnalyze MITRE ATT&CK T1630.001 Uninstall Malicious Application in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1630.001, Uninstall Malicious Application, or mobile ATT&CK. Adversaries may include functionality in malware that uninstalls the malicious application from the device.
- ▌ Attack Ent T1547 006 Kernel Modules And Extensions · santosomar bundleAnalyze MITRE ATT&CK T1547.006 Kernel Modules and Extensions in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1547.006, Kernel Modules and Extensions, or enterprise ATT&CK. Adversaries may modify the kernel to automatically execute programs on system boot.
- ▌ Attack Ent T1555 003 Credentials From Web Browsers · santosomar bundleAnalyze MITRE ATT&CK T1555.003 Credentials from Web Browsers in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1555.003, Credentials from Web Browsers, or enterprise ATT&CK. Adversaries may acquire credentials from web browsers by reading files specific to the target browser.(Citation: Talos Olympic Destroyer 2018) Web browsers commonly save credentials such as website usernames and passwor…
- ▌ Attack Ent T1567 002 Exfiltration To Cloud Storage · santosomar bundleAnalyze MITRE ATT&CK T1567.002 Exfiltration to Cloud Storage in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1567.002, Exfiltration to Cloud Storage, or enterprise ATT&CK. Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
- ▌ Attack Mob T1655 001 Match Legitimate Name Or Location · santosomar bundleAnalyze MITRE ATT&CK T1655.001 Match Legitimate Name or Location in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1655.001, Match Legitimate Name or Location, or mobile ATT&CK. Adversaries may match or approximate the name or location of legitimate files or resources when naming/placing them.
- ▌ Attack Ent T1047 Windows Management Instrumentation · santosomar bundleAnalyze MITRE ATT&CK T1047 Windows Management Instrumentation in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1047, Windows Management Instrumentation, or enterprise ATT&CK. Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
- ▌ Attack Ent T1055 001 Dynamic Link Library Injection · santosomar bundleAnalyze MITRE ATT&CK T1055.001 Dynamic-link Library Injection in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1055.001, Dynamic-link Library Injection, or enterprise ATT&CK. Adversaries may inject dynamic-link libraries (DLLs) into processes in order to evade process-based defenses as well as possibly elevate privileges.
- ▌ Attack Ent T1212 Exploitation For Credential Access · santosomar bundleAnalyze MITRE ATT&CK T1212 Exploitation for Credential Access in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1212, Exploitation for Credential Access, or enterprise ATT&CK. Adversaries may exploit software vulnerabilities in an attempt to collect credentials.
- ▌ Attack Ent T1098 003 Additional Cloud Roles · santosomar bundleAnalyze MITRE ATT&CK T1098.003 Additional Cloud Roles in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1098.003, Additional Cloud Roles, or enterprise ATT&CK. An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant.
- ▌ Attack Ent T1114 001 Local Email Collection · santosomar bundleAnalyze MITRE ATT&CK T1114.001 Local Email Collection in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1114.001, Local Email Collection, or enterprise ATT&CK. Adversaries may target user email on local systems to collect sensitive information.
- ▌ Attack Ent T1137 001 Office Template Macros · santosomar bundleAnalyze MITRE ATT&CK T1137.001 Office Template Macros in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1137.001, Office Template Macros, or enterprise ATT&CK. Adversaries may abuse Microsoft Office templates to obtain persistence on a compromised system.
- ▌ Attack Ent T1137 Office Application Startup · santosomar bundleAnalyze MITRE ATT&CK T1137 Office Application Startup in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1137, Office Application Startup, or enterprise ATT&CK. Adversaries may leverage Microsoft Office-based applications for persistence between startups.
- ▌ Attack Ent T1213 005 Messaging Applications · santosomar bundleAnalyze MITRE ATT&CK T1213.005 Messaging Applications in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1213.005, Messaging Applications, or enterprise ATT&CK. Adversaries may leverage chat and messaging applications, such as Microsoft Teams, Google Chat, and Slack, to mine valuable information.
- ▌ Attack Ent T1134 001 Token Impersonation Theft · santosomar bundleAnalyze MITRE ATT&CK T1134.001 Token Impersonation/Theft in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1134.001, Token Impersonation/Theft, or enterprise ATT&CK. Adversaries may duplicate then impersonate another user's existing token to escalate privileges and bypass access controls.
- ▌ Attack Ent T1134 002 Create Process With Token · santosomar bundleAnalyze MITRE ATT&CK T1134.002 Create Process with Token in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1134.002, Create Process with Token, or enterprise ATT&CK. Adversaries may create a new process with an existing token to escalate privileges and bypass access controls.
- ▌ Attack Ent T1217 Browser Information Discovery · santosomar bundleAnalyze MITRE ATT&CK T1217 Browser Information Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1217, Browser Information Discovery, or enterprise ATT&CK. Adversaries may enumerate information about browsers to learn more about compromised environments.
- ▌ Attack Ent T1218 System Binary Proxy Execution · santosomar bundleAnalyze MITRE ATT&CK T1218 System Binary Proxy Execution in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1218, System Binary Proxy Execution, or enterprise ATT&CK. Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries.
- ▌ Attack Ent T1027 Obfuscated Files Or Information · santosomar bundleAnalyze MITRE ATT&CK T1027 Obfuscated Files or Information in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027, Obfuscated Files or Information, or enterprise ATT&CK. Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit.
- ▌ Attack Ent T1036 003 Rename Legitimate Utilities · santosomar bundleAnalyze MITRE ATT&CK T1036.003 Rename Legitimate Utilities in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1036.003, Rename Legitimate Utilities, or enterprise ATT&CK. Adversaries may rename legitimate / system utilities to try to evade security mechanisms concerning the usage of those utilities.
- ▌ Attack Ent T1055 004 Asynchronous Procedure Call · santosomar bundleAnalyze MITRE ATT&CK T1055.004 Asynchronous Procedure Call in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1055.004, Asynchronous Procedure Call, or enterprise ATT&CK. Adversaries may inject malicious code into processes via the asynchronous procedure call (APC) queue in order to evade process-based defenses as well as possibly elevate privileges.
- ▌ Attack Ent T1102 002 Bidirectional Communication · santosomar bundleAnalyze MITRE ATT&CK T1102.002 Bidirectional Communication in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1102.002, Bidirectional Communication, or enterprise ATT&CK. Adversaries may use an existing, legitimate external Web service as a means for sending commands to and receiving output from a compromised system over the Web service channel.
- ▌ Attack Ent T1210 Exploitation Of Remote Services · santosomar bundleAnalyze MITRE ATT&CK T1210 Exploitation of Remote Services in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1210, Exploitation of Remote Services, or enterprise ATT&CK. Adversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network.