← all publishers

santosomar

@santosomar source repo

800 published skills · page 2 of 8

  1. Attack Ent T1518 001 Security Software Discovery · santosomar bundle
    Analyze MITRE ATT&CK T1518.001 Security Software Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1518.001, Security Software Discovery, or enterprise ATT&CK. Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
    0 installs
  2. Attack Ent T1543 Create Or Modify System Process · santosomar bundle
    Analyze MITRE ATT&CK T1543 Create or Modify System Process in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1543, Create or Modify System Process, or enterprise ATT&CK. Adversaries may create or modify system-level processes to repeatedly execute malicious payloads as part of persistence.
    0 installs
  3. Attack Mob T1634 Credentials From Password Store · santosomar bundle
    Analyze MITRE ATT&CK T1634 Credentials from Password Store in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1634, Credentials from Password Store, or mobile ATT&CK. Adversaries may search common password storage locations to obtain user credentials.
    0 installs
  4. Attack Mob T1664 Exploitation For Initial Access · santosomar bundle
    Analyze MITRE ATT&CK T1664 Exploitation for Initial Access in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1664, Exploitation for Initial Access, or mobile ATT&CK. Adversaries may exploit software vulnerabilities to gain initial access to a mobile device.
    0 installs
  5. Attack Ent T1003 002 Security Account Manager · santosomar bundle
    Analyze MITRE ATT&CK T1003.002 Security Account Manager in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1003.002, Security Account Manager, or enterprise ATT&CK. Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is stored.
    0 installs
  6. Attack Ent T1010 Application Window Discovery · santosomar bundle
    Analyze MITRE ATT&CK T1010 Application Window Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1010, Application Window Discovery, or enterprise ATT&CK. Adversaries may attempt to get a listing of open application windows.
    0 installs
  7. Attack Ent T1021 002 Smb Windows Admin Shares · santosomar bundle
    Analyze MITRE ATT&CK T1021.002 SMB/Windows Admin Shares in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1021.002, SMB/Windows Admin Shares, or enterprise ATT&CK. Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to interact with a remote network share using Server Message Block (SMB).
    0 installs
  8. Attack Ent T1041 Exfiltration Over C2 Channel · santosomar bundle
    Analyze MITRE ATT&CK T1041 Exfiltration Over C2 Channel in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1041, Exfiltration Over C2 Channel, or enterprise ATT&CK. Adversaries may steal data by exfiltrating it over an existing command and control channel.
    0 installs
  9. Attack Ent T1082 System Information Discovery · santosomar bundle
    Analyze MITRE ATT&CK T1082 System Information Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1082, System Information Discovery, or enterprise ATT&CK. An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
    0 installs
  10. Attack Ent T1586 001 Social Media Accounts · santosomar bundle
    Analyze MITRE ATT&CK T1586.001 Social Media Accounts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1586.001, Social Media Accounts, or enterprise ATT&CK. Adversaries may compromise social media accounts that can be used during targeting.
    0 installs
  11. Attack Ent T1592 004 Client Configurations · santosomar bundle
    Analyze MITRE ATT&CK T1592.004 Client Configurations in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1592.004, Client Configurations, or enterprise ATT&CK. Adversaries may gather information about the victim's client configurations that can be used during targeting.
    0 installs
  12. Attack Ent T1598 001 Spearphishing Service · santosomar bundle
    Analyze MITRE ATT&CK T1598.001 Spearphishing Service in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1598.001, Spearphishing Service, or enterprise ATT&CK. Adversaries may send spearphishing messages via third-party services to elicit sensitive information that can be used during targeting.
    0 installs
  13. Attack Ent T1599 Network Boundary Bridging · santosomar bundle
    Analyze MITRE ATT&CK T1599 Network Boundary Bridging in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1599, Network Boundary Bridging, or enterprise ATT&CK. Adversaries may bridge network boundaries by compromising perimeter network devices or internal devices responsible for network segmentation.
    0 installs
  14. Attack Ent T1614 System Location Discovery · santosomar bundle
    Analyze MITRE ATT&CK T1614 System Location Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1614, System Location Discovery, or enterprise ATT&CK. Adversaries may gather information in an attempt to calculate the geographical location of a victim host.
    0 installs
  15. Attack Ent T1686 003 Windows Host Firewall · santosomar bundle
    Analyze MITRE ATT&CK T1686.003 Windows Host Firewall in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1686.003, Windows Host Firewall, or enterprise ATT&CK. Adversaries may disable or modify the Windows host firewall to bypass controls limiting network usage.
    0 installs
  16. Attack Ics T0828 Loss Of Productivity And Revenue · santosomar bundle
    Analyze MITRE ATT&CK T0828 Loss of Productivity and Revenue in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0828, Loss of Productivity and Revenue, or ics ATT&CK. Adversaries may cause loss of productivity and revenue through disruption and even damage to the availability and integrity of control system operations, devices, and related processes.
    0 installs
  17. Attack Ent T1614 001 System Language Discovery · santosomar bundle
    Analyze MITRE ATT&CK T1614.001 System Language Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1614.001, System Language Discovery, or enterprise ATT&CK. Adversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host.
    0 installs
  18. Attack Ent T1671 Cloud Application Integration · santosomar bundle
    Analyze MITRE ATT&CK T1671 Cloud Application Integration in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1671, Cloud Application Integration, or enterprise ATT&CK. Adversaries may achieve persistence by leveraging OAuth application integrations in a software-as-a-service environment.
    0 installs
  19. Attack Mob T1422 001 Internet Connection Discovery · santosomar bundle
    Analyze MITRE ATT&CK T1422.001 Internet Connection Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1422.001, Internet Connection Discovery, or mobile ATT&CK. Adversaries may check for Internet connectivity on compromised systems.
    0 installs
  20. Attack Mob T1641 001 Transmitted Data Manipulation · santosomar bundle
    Analyze MITRE ATT&CK T1641.001 Transmitted Data Manipulation in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1641.001, Transmitted Data Manipulation, or mobile ATT&CK. Adversaries may alter data en route to storage or other systems in order to manipulate external outcomes or hide activity.
    0 installs
  21. Attack Mob T1645 Compromise Client Software Binary · santosomar bundle
    Analyze MITRE ATT&CK T1645 Compromise Client Software Binary in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1645, Compromise Client Software Binary, or mobile ATT&CK. Adversaries may modify system software binaries to establish persistent access to devices.
    0 installs
  22. Attack Mob T1658 Exploitation For Client Execution · santosomar bundle
    Analyze MITRE ATT&CK T1658 Exploitation for Client Execution in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1658, Exploitation for Client Execution, or mobile ATT&CK. Adversaries may exploit software vulnerabilities in client applications to execute code.
    0 installs
  23. Attack Ent T1036 004 Masquerade Task Or Service · santosomar bundle
    Analyze MITRE ATT&CK T1036.004 Masquerade Task or Service in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1036.004, Masquerade Task or Service, or enterprise ATT&CK. Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign.
    0 installs
  24. Attack Ent T1083 File And Directory Discovery · santosomar bundle
    Analyze MITRE ATT&CK T1083 File and Directory Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1083, File and Directory Discovery, or enterprise ATT&CK. Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
    0 installs
  25. Attack Ent T1204 004 Malicious Copy And Paste · santosomar bundle
    Analyze MITRE ATT&CK T1204.004 Malicious Copy and Paste in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1204.004, Malicious Copy and Paste, or enterprise ATT&CK. An adversary may rely upon a user copying and pasting code in order to gain execution.
    0 installs
  26. Attack Ent T1498 002 Reflection Amplification · santosomar bundle
    Analyze MITRE ATT&CK T1498.002 Reflection Amplification in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1498.002, Reflection Amplification, or enterprise ATT&CK. Adversaries may attempt to cause a denial of service (DoS) by reflecting a high-volume of network traffic to a target.
    0 installs
  27. Attack Ent T1550 001 Application Access Token · santosomar bundle
    Analyze MITRE ATT&CK T1550.001 Application Access Token in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1550.001, Application Access Token, or enterprise ATT&CK. Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems.
    0 installs
  28. Attack Ent T1552 006 Group Policy Preferences · santosomar bundle
    Analyze MITRE ATT&CK T1552.006 Group Policy Preferences in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1552.006, Group Policy Preferences, or enterprise ATT&CK. Adversaries may attempt to find unsecured credentials in Group Policy Preferences (GPP).
    0 installs
  29. Attack Ent T1553 004 Install Root Certificate · santosomar bundle
    Analyze MITRE ATT&CK T1553.004 Install Root Certificate in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1553.004, Install Root Certificate, or enterprise ATT&CK. Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
    0 installs
  30. Attack Ent T1566 001 Spearphishing Attachment · santosomar bundle
    Analyze MITRE ATT&CK T1566.001 Spearphishing Attachment in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1566.001, Spearphishing Attachment, or enterprise ATT&CK. Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems.
    0 installs
  31. Attack Ics T0882 Theft Of Operational Information · santosomar bundle
    Analyze MITRE ATT&CK T0882 Theft of Operational Information in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0882, Theft of Operational Information, or ics ATT&CK. Adversaries may steal operational information on a production environment as a direct mission outcome for personal gain or to inform future operations.
    0 installs
  32. Attack Mob T1628 001 Suppress Application Icon · santosomar bundle
    Analyze MITRE ATT&CK T1628.001 Suppress Application Icon in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1628.001, Suppress Application Icon, or mobile ATT&CK. A malicious application could suppress its icon from being displayed to the user in the application launcher.
    0 installs
  33. Attack Ent T1027 004 Compile After Delivery · santosomar bundle
    Analyze MITRE ATT&CK T1027.004 Compile After Delivery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.004, Compile After Delivery, or enterprise ATT&CK. Adversaries may attempt to make payloads difficult to discover and analyze by delivering files to victims as uncompiled code.
    0 installs
  34. Attack Ent T1027 007 Dynamic API Resolution · santosomar bundle
    Analyze MITRE ATT&CK T1027.007 Dynamic API Resolution in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.007, Dynamic API Resolution, or enterprise ATT&CK. Adversaries may obfuscate then dynamically resolve API functions called by their malware in order to conceal malicious functionalities and impair defensive analysis.
    0 installs
  35. Attack Ent T1027 013 Encrypted Encoded File · santosomar bundle
    Analyze MITRE ATT&CK T1027.013 Encrypted/Encoded File in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.013, Encrypted/Encoded File, or enterprise ATT&CK. Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
    0 installs
  36. Attack Ent T1036 002 Right To Left Override · santosomar bundle
    Analyze MITRE ATT&CK T1036.002 Right-to-Left Override in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1036.002, Right-to-Left Override, or enterprise ATT&CK. Adversaries may abuse the right-to-left override (RTLO or RLO) character (U+202E) to disguise a string and/or file name to make it appear benign.
    0 installs
  37. Attack Ent T1056 004 Credential API Hooking · santosomar bundle
    Analyze MITRE ATT&CK T1056.004 Credential API Hooking in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1056.004, Credential API Hooking, or enterprise ATT&CK. Adversaries may hook into Windows application programming interface (API) functions and Linux system functions to collect user credentials.
    0 installs
  38. Attack Ent T1071 Application Layer Protocol · santosomar bundle
    Analyze MITRE ATT&CK T1071 Application Layer Protocol in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1071, Application Layer Protocol, or enterprise ATT&CK. Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic.
    0 installs
  39. Attack Ent T1039 Data From Network Shared Drive · santosomar bundle
    Analyze MITRE ATT&CK T1039 Data from Network Shared Drive in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1039, Data from Network Shared Drive, or enterprise ATT&CK. Adversaries may search network shares on computers they have compromised to find files of interest.
    0 installs
  40. Attack Ent T1095 Non Application Layer Protocol · santosomar bundle
    Analyze MITRE ATT&CK T1095 Non-Application Layer Protocol in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1095, Non-Application Layer Protocol, or enterprise ATT&CK. Adversaries may use an OSI non-application layer protocol for communication between host and C2 server or among infected hosts within a network.
    0 installs
  41. Attack Ent T1497 Virtualization Sandbox Evasion · santosomar bundle
    Analyze MITRE ATT&CK T1497 Virtualization/Sandbox Evasion in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1497, Virtualization/Sandbox Evasion, or enterprise ATT&CK. Adversaries may employ various means to detect and avoid virtualization and analysis environments.
    0 installs
  42. Attack Ent T1528 Steal Application Access Token · santosomar bundle
    Analyze MITRE ATT&CK T1528 Steal Application Access Token in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1528, Steal Application Access Token, or enterprise ATT&CK. Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.
    0 installs
  43. Attack Ent T1537 Transfer Data To Cloud Account · santosomar bundle
    Analyze MITRE ATT&CK T1537 Transfer Data to Cloud Account in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1537, Transfer Data to Cloud Account, or enterprise ATT&CK. Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.
    0 installs
  44. Attack Ent T1555 004 Windows Credential Manager · santosomar bundle
    Analyze MITRE ATT&CK T1555.004 Windows Credential Manager in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1555.004, Windows Credential Manager, or enterprise ATT&CK. Adversaries may acquire credentials from the Windows Credential Manager.
    0 installs
  45. Attack Ent T1580 Cloud Infrastructure Discovery · santosomar bundle
    Analyze MITRE ATT&CK T1580 Cloud Infrastructure Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1580, Cloud Infrastructure Discovery, or enterprise ATT&CK. An adversary may attempt to discover infrastructure and resources that are available within an infrastructure-as-a-service (IaaS) environment.
    0 installs
  46. Attack Ent T1592 Gather Victim Host Information · santosomar bundle
    Analyze MITRE ATT&CK T1592 Gather Victim Host Information in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1592, Gather Victim Host Information, or enterprise ATT&CK. Adversaries may gather information about the victim's hosts that can be used during targeting.
    0 installs
  47. Attack Ent T1574 006 Dynamic Linker Hijacking · santosomar bundle
    Analyze MITRE ATT&CK T1574.006 Dynamic Linker Hijacking in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1574.006, Dynamic Linker Hijacking, or enterprise ATT&CK. Adversaries may execute their own malicious payloads by hijacking environment variables the dynamic linker uses to load shared libraries.
    0 installs
  48. Attack Ent T1594 Search Victim Owned Websites · santosomar bundle
    Analyze MITRE ATT&CK T1594 Search Victim-Owned Websites in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1594, Search Victim-Owned Websites, or enterprise ATT&CK. Adversaries may search websites owned by the victim for information that can be used during targeting.
    0 installs
  49. Attack Ent T1598 002 Spearphishing Attachment · santosomar bundle
    Analyze MITRE ATT&CK T1598.002 Spearphishing Attachment in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1598.002, Spearphishing Attachment, or enterprise ATT&CK. Adversaries may send spearphishing messages with a malicious attachment to elicit sensitive information that can be used during targeting.
    0 installs
  50. Attack Ent T1651 Cloud Administration Command · santosomar bundle
    Analyze MITRE ATT&CK T1651 Cloud Administration Command in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1651, Cloud Administration Command, or enterprise ATT&CK. Adversaries may abuse cloud management services to execute commands within virtual machines.
    0 installs
  51. Attack Ent T1685 005 Clear Windows Event Logs · santosomar bundle
    Analyze MITRE ATT&CK T1685.005 Clear Windows Event Logs in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1685.005, Clear Windows Event Logs, or enterprise ATT&CK. Adversaries may clear Windows Event Logs to hide the activity of an intrusion.
    0 installs
  52. Attack Ics T0869 Standard Application Layer Protocol · santosomar bundle
    Analyze MITRE ATT&CK T0869 Standard Application Layer Protocol in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0869, Standard Application Layer Protocol, or ics ATT&CK. Adversaries may establish command and control capabilities over commonly used application layer protocols such as HTTP(S), OPC, RDP, telnet, DNP3, and modbus.
    0 installs
  53. Attack Ent T1003 005 Cached Domain Credentials · santosomar bundle
    Analyze MITRE ATT&CK T1003.005 Cached Domain Credentials in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1003.005, Cached Domain Credentials, or enterprise ATT&CK. Adversaries may attempt to access cached domain credentials used to allow authentication to occur in the event a domain controller is unavailable.(Citation: Microsoft - Cached Creds) On Windows Vista and newer, the hash…
    0 installs
  54. Attack Ent T1021 006 Windows Remote Management · santosomar bundle
    Analyze MITRE ATT&CK T1021.006 Windows Remote Management in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1021.006, Windows Remote Management, or enterprise ATT&CK. Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to interact with remote systems using Windows Remote Management (WinRM).
    0 installs
  55. Attack Mob T1453 Abuse Accessibility Features · santosomar bundle
    Analyze MITRE ATT&CK T1453 Abuse Accessibility Features in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1453, Abuse Accessibility Features, or mobile ATT&CK. Adversaries may abuse accessibility features in Android devices to steal sensitive data and to spread malware to other devices.
    0 installs
  56. Attack Mob T1628 003 Conceal Multimedia Files · santosomar bundle
    Analyze MITRE ATT&CK T1628.003 Conceal Multimedia Files in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1628.003, Conceal Multimedia Files, or mobile ATT&CK. Adversaries may attempt to hide multimedia files from the user.
    0 installs
  57. Attack Mob T1643 Generate Traffic From Victim · santosomar bundle
    Analyze MITRE ATT&CK T1643 Generate Traffic from Victim in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1643, Generate Traffic from Victim, or mobile ATT&CK. Adversaries may generate outbound traffic from devices.
    0 installs
  58. Attack Mob T1646 Exfiltration Over C2 Channel · santosomar bundle
    Analyze MITRE ATT&CK T1646 Exfiltration Over C2 Channel in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1646, Exfiltration Over C2 Channel, or mobile ATT&CK. Adversaries may steal data by exfiltrating it over an existing command and control channel.
    0 installs
  59. Attack Ent T1025 Data From Removable Media · santosomar bundle
    Analyze MITRE ATT&CK T1025 Data from Removable Media in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1025, Data from Removable Media, or enterprise ATT&CK. Adversaries may search connected removable media on computers they have compromised to find files of interest.
    0 installs
  60. Attack Ent T1219 002 Remote Desktop Software · santosomar bundle
    Analyze MITRE ATT&CK T1219.002 Remote Desktop Software in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1219.002, Remote Desktop Software, or enterprise ATT&CK. An adversary may use legitimate desktop support software to establish an interactive command and control channel to target systems within networks.
    0 installs
  61. Attack Ent T1552 002 Credentials In Registry · santosomar bundle
    Analyze MITRE ATT&CK T1552.002 Credentials in Registry in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1552.002, Credentials in Registry, or enterprise ATT&CK. Adversaries may search the Registry on compromised systems for insecurely stored credentials.
    0 installs
  62. Attack Ent T1559 Inter Process Communication · santosomar bundle
    Analyze MITRE ATT&CK T1559 Inter-Process Communication in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1559, Inter-Process Communication, or enterprise ATT&CK. Adversaries may abuse inter-process communication (IPC) mechanisms for local code or command execution.
    0 installs
  63. Attack Ent T1573 002 Asymmetric Cryptography · santosomar bundle
    Analyze MITRE ATT&CK T1573.002 Asymmetric Cryptography in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1573.002, Asymmetric Cryptography, or enterprise ATT&CK. Adversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
    0 installs
  64. Attack Ent T1677 Poisoned Pipeline Execution · santosomar bundle
    Analyze MITRE ATT&CK T1677 Poisoned Pipeline Execution in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1677, Poisoned Pipeline Execution, or enterprise ATT&CK. Adversaries may manipulate continuous integration / continuous development (CI/CD) processes by injecting malicious code into the build process.
    0 installs
  65. Attack Mob T1406 Obfuscated Files Or Information · santosomar bundle
    Analyze MITRE ATT&CK T1406 Obfuscated Files or Information in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1406, Obfuscated Files or Information, or mobile ATT&CK. Adversaries may attempt to make a payload or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the device or in transit.
    0 installs
  66. Attack Mob T1418 001 Security Software Discovery · santosomar bundle
    Analyze MITRE ATT&CK T1418.001 Security Software Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1418.001, Security Software Discovery, or mobile ATT&CK. Adversaries may attempt to get a listing of security applications and configurations that are installed on a device.
    0 installs
  67. Attack Mob T1629 001 Prevent Application Removal · santosomar bundle
    Analyze MITRE ATT&CK T1629.001 Prevent Application Removal in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1629.001, Prevent Application Removal, or mobile ATT&CK. Adversaries may abuse the Android device administration API to prevent the user from uninstalling a target application.
    0 installs
  68. Attack Ent T1547 013 Xdg Autostart Entries · santosomar bundle
    Analyze MITRE ATT&CK T1547.013 XDG Autostart Entries in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1547.013, XDG Autostart Entries, or enterprise ATT&CK. Adversaries may add or modify XDG Autostart Entries to execute malicious programs or commands when a user’s desktop environment is loaded at login.
    0 installs
  69. Attack Ent T1548 003 Sudo And Sudo Caching · santosomar bundle
    Analyze MITRE ATT&CK T1548.003 Sudo and Sudo Caching in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1548.003, Sudo and Sudo Caching, or enterprise ATT&CK. Adversaries may perform sudo caching and/or use the sudoers file to elevate privileges.
    0 installs
  70. Attack Ent T1556 005 Reversible Encryption · santosomar bundle
    Analyze MITRE ATT&CK T1556.005 Reversible Encryption in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1556.005, Reversible Encryption, or enterprise ATT&CK. An adversary may abuse Active Directory authentication encryption properties to gain access to credentials on Windows systems.
    0 installs
  71. Attack Ent T1559 002 Dynamic Data Exchange · santosomar bundle
    Analyze MITRE ATT&CK T1559.002 Dynamic Data Exchange in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1559.002, Dynamic Data Exchange, or enterprise ATT&CK. Adversaries may use Windows Dynamic Data Exchange (DDE) to execute arbitrary commands.
    0 installs
  72. Attack Ent T1578 003 Delete Cloud Instance · santosomar bundle
    Analyze MITRE ATT&CK T1578.003 Delete Cloud Instance in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1578.003, Delete Cloud Instance, or enterprise ATT&CK. An adversary may delete a cloud instance after they have performed malicious activities in an attempt to evade detection and remove evidence of their presence.
    0 installs
  73. Attack Ent T1584 Compromise Infrastructure · santosomar bundle
    Analyze MITRE ATT&CK T1584 Compromise Infrastructure in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1584, Compromise Infrastructure, or enterprise ATT&CK. Adversaries may compromise third-party infrastructure that can be used during targeting.
    0 installs
  74. Attack Ent T1585 001 Social Media Accounts · santosomar bundle
    Analyze MITRE ATT&CK T1585.001 Social Media Accounts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1585.001, Social Media Accounts, or enterprise ATT&CK. Adversaries may create and cultivate social media accounts that can be used during targeting.
    0 installs
  75. Attack Ent T1222 002 Linux And Mac Permissions · santosomar bundle
    Analyze MITRE ATT&CK T1222.002 Linux and Mac Permissions in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1222.002, Linux and Mac Permissions, or enterprise ATT&CK. Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.(Citation: Hybrid Analysis Icacls1 June 2018)(Citation: Hybrid Analysis Icacls2 May 2018) F…
    0 installs
  76. Attack Ent T1484 001 Group Policy Modification · santosomar bundle
    Analyze MITRE ATT&CK T1484.001 Group Policy Modification in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1484.001, Group Policy Modification, or enterprise ATT&CK. Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain.
    0 installs
  77. Attack Ent T1556 Modify Authentication Process · santosomar bundle
    Analyze MITRE ATT&CK T1556 Modify Authentication Process in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1556, Modify Authentication Process, or enterprise ATT&CK. Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts.
    0 installs
  78. Attack Ent T1560 003 Archive Via Custom Method · santosomar bundle
    Analyze MITRE ATT&CK T1560.003 Archive via Custom Method in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1560.003, Archive via Custom Method, or enterprise ATT&CK. An adversary may compress or encrypt data that is collected prior to exfiltration using a custom method.
    0 installs
  79. Attack Ent T1566 003 Spearphishing Via Service · santosomar bundle
    Analyze MITRE ATT&CK T1566.003 Spearphishing via Service in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1566.003, Spearphishing via Service, or enterprise ATT&CK. Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems.
    0 installs
  80. Attack Ent T1567 004 Exfiltration Over Webhook · santosomar bundle
    Analyze MITRE ATT&CK T1567.004 Exfiltration Over Webhook in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1567.004, Exfiltration Over Webhook, or enterprise ATT&CK. Adversaries may exfiltrate data to a webhook endpoint rather than over their primary command and control channel.
    0 installs
  81. Attack Ent T1567 Exfiltration Over Web Service · santosomar bundle
    Analyze MITRE ATT&CK T1567 Exfiltration Over Web Service in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1567, Exfiltration Over Web Service, or enterprise ATT&CK. Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel.
    0 installs
  82. Attack Ent T1588 003 Code Signing Certificates · santosomar bundle
    Analyze MITRE ATT&CK T1588.003 Code Signing Certificates in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1588.003, Code Signing Certificates, or enterprise ATT&CK. Adversaries may buy and/or steal code signing certificates that can be used during targeting.
    0 installs
  83. Attack Ent T1595 002 Vulnerability Scanning · santosomar bundle
    Analyze MITRE ATT&CK T1595.002 Vulnerability Scanning in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1595.002, Vulnerability Scanning, or enterprise ATT&CK. Adversaries may scan victims for vulnerabilities that can be used during targeting.
    0 installs
  84. Attack Ent T1021 001 Remote Desktop Protocol · santosomar bundle
    Analyze MITRE ATT&CK T1021.001 Remote Desktop Protocol in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1021.001, Remote Desktop Protocol, or enterprise ATT&CK. Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to log into a computer using the Remote Desktop Protocol (RDP).
    0 installs
  85. Attack Ent T1033 System Owner User Discovery · santosomar bundle
    Analyze MITRE ATT&CK T1033 System Owner/User Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1033, System Owner/User Discovery, or enterprise ATT&CK. Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system.
    0 installs
  86. Attack Ent T1069 Permission Groups Discovery · santosomar bundle
    Analyze MITRE ATT&CK T1069 Permission Groups Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1069, Permission Groups Discovery, or enterprise ATT&CK. Adversaries may attempt to discover group and permission settings.
    0 installs
  87. Attack Ent T1071 002 File Transfer Protocols · santosomar bundle
    Analyze MITRE ATT&CK T1071.002 File Transfer Protocols in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1071.002, File Transfer Protocols, or enterprise ATT&CK. Adversaries may communicate using application layer protocols associated with transferring files to avoid detection/network filtering by blending in with existing traffic.
    0 installs
  88. Attack Ent T1114 002 Remote Email Collection · santosomar bundle
    Analyze MITRE ATT&CK T1114.002 Remote Email Collection in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1114.002, Remote Email Collection, or enterprise ATT&CK. Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information.
    0 installs
  89. Attack Ent T1120 Peripheral Device Discovery · santosomar bundle
    Analyze MITRE ATT&CK T1120 Peripheral Device Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1120, Peripheral Device Discovery, or enterprise ATT&CK. Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system.(Citation: Peripheral Discovery Linux)(Citation: Peripheral Discovery macOS) Peripheral devic…
    0 installs
  90. Attack Ent T1218 015 Electron Applications · santosomar bundle
    Analyze MITRE ATT&CK T1218.015 Electron Applications in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1218.015, Electron Applications, or enterprise ATT&CK. Adversaries may abuse components of the Electron framework to execute malicious code.
    0 installs
  91. Attack Ent T1486 Data Encrypted For Impact · santosomar bundle
    Analyze MITRE ATT&CK T1486 Data Encrypted for Impact in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1486, Data Encrypted for Impact, or enterprise ATT&CK. Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
    0 installs
  92. Attack Ent T1498 Network Denial Of Service · santosomar bundle
    Analyze MITRE ATT&CK T1498 Network Denial of Service in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1498, Network Denial of Service, or enterprise ATT&CK. Adversaries may perform Network Denial of Service (DoS) attacks to degrade or block the availability of targeted resources to users.
    0 installs
  93. Attack Ent T1505 001 SQL Stored Procedures · santosomar bundle
    Analyze MITRE ATT&CK T1505.001 SQL Stored Procedures in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1505.001, SQL Stored Procedures, or enterprise ATT&CK. Adversaries may abuse SQL stored procedures to establish persistent access to systems.
    0 installs
  94. Attack Ent T1505 005 Terminal Services Dll · santosomar bundle
    Analyze MITRE ATT&CK T1505.005 Terminal Services DLL in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1505.005, Terminal Services DLL, or enterprise ATT&CK. Adversaries may abuse components of Terminal Services to enable persistent access to systems.
    0 installs
  95. Attack Ent T1505 Server Software Component · santosomar bundle
    Analyze MITRE ATT&CK T1505 Server Software Component in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1505, Server Software Component, or enterprise ATT&CK. Adversaries may abuse legitimate extensible development features of servers to establish persistent access to systems.
    0 installs
  96. Attack Ent T1546 Event Triggered Execution · santosomar bundle
    Analyze MITRE ATT&CK T1546 Event Triggered Execution in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1546, Event Triggered Execution, or enterprise ATT&CK. Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events.
    0 installs
  97. Attack Ent T1547 009 Shortcut Modification · santosomar bundle
    Analyze MITRE ATT&CK T1547.009 Shortcut Modification in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1547.009, Shortcut Modification, or enterprise ATT&CK. Adversaries may create or modify shortcuts that can execute a program during system boot or user login.
    0 installs
  98. Attack Ent T1598 Phishing For Information · santosomar bundle
    Analyze MITRE ATT&CK T1598 Phishing for Information in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1598, Phishing for Information, or enterprise ATT&CK. Adversaries may send phishing messages to elicit sensitive information that can be used during targeting.
    0 installs
  99. Attack Ent T1682 Query Public AI Services · santosomar bundle
    Analyze MITRE ATT&CK T1682 Query Public AI Services in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1682, Query Public AI Services, or enterprise ATT&CK. Adversaries may query publicly accessible artificial intelligence (AI) services, such as large language models (LLMs), to support targeting and operations.
    0 installs
  100. Attack Ent T1683 002 Audio Visual Content · santosomar bundle
    Analyze MITRE ATT&CK T1683.002 Audio-Visual Content in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1683.002, Audio-Visual Content, or enterprise ATT&CK. Adversaries may create or manipulate audio, image, and video content to support targeting and malicious operations.
    0 installs