santosomar
- 800 skills
- 0 followers
- 9 hours ago last updated
- ▌ Attack Ics T0866 Exploitation Of Remote Services · santosomar bundleAnalyze MITRE ATT&CK T0866 Exploitation of Remote Services in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0866, Exploitation of Remote Services, or ics ATT&CK. Adversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself to enable remote service abuse.
- ▌ Attack Ics T0873 001 Siemens Project File Format · santosomar bundleAnalyze MITRE ATT&CK T0873.001 Siemens Project File Format in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0873.001, Siemens Project File Format, or ics ATT&CK. Adversaries may infect Siemens PLC project files (i.e., Step 7, WinCC, etc.) to achieve [Execution](https://attack.mitre.org/tactics/TA0104), [Persistence](https://attack.mitre.org/tactics/TA0110), and [Lateral Movement…
- ▌ Attack Mob T1407 Download New Code At Runtime · santosomar bundleAnalyze MITRE ATT&CK T1407 Download New Code at Runtime in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1407, Download New Code at Runtime, or mobile ATT&CK. Adversaries may download and execute dynamic code not included in the original application package after installation.
- ▌ Attack Mob T1420 File And Directory Discovery · santosomar bundleAnalyze MITRE ATT&CK T1420 File and Directory Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1420, File and Directory Discovery, or mobile ATT&CK. Adversaries may enumerate files and directories or search in specific device locations for desired information within a filesystem.
- ▌ Attack Mob T1426 System Information Discovery · santosomar bundleAnalyze MITRE ATT&CK T1426 System Information Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1426, System Information Discovery, or mobile ATT&CK. Adversaries may attempt to get detailed information about a device’s operating system and hardware, including versions, patches, and architecture.
- ▌ Attack Ent T1491 001 Internal Defacement · santosomar bundleAnalyze MITRE ATT&CK T1491.001 Internal Defacement in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1491.001, Internal Defacement, or enterprise ATT&CK. An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
- ▌ Attack Ent T1499 001 Os Exhaustion Flood · santosomar bundleAnalyze MITRE ATT&CK T1499.001 OS Exhaustion Flood in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1499.001, OS Exhaustion Flood, or enterprise ATT&CK. Adversaries may launch a denial of service (DoS) attack targeting an endpoint's operating system (OS).
- ▌ Attack Ent T1526 Cloud Service Discovery · santosomar bundleAnalyze MITRE ATT&CK T1526 Cloud Service Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1526, Cloud Service Discovery, or enterprise ATT&CK. An adversary may attempt to enumerate the cloud services running on a system after gaining access.
- ▌ Attack Ent T1530 Data From Cloud Storage · santosomar bundleAnalyze MITRE ATT&CK T1530 Data from Cloud Storage in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1530, Data from Cloud Storage, or enterprise ATT&CK. Adversaries may access data from cloud storage.
- ▌ Attack Ent T1538 Cloud Service Dashboard · santosomar bundleAnalyze MITRE ATT&CK T1538 Cloud Service Dashboard in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1538, Cloud Service Dashboard, or enterprise ATT&CK. An adversary may use a cloud service dashboard GUI with stolen credentials to gain useful information from an operational cloud environment, such as specific services, resources, and features.
- ▌ Attack Ent T1030 Data Transfer Size Limits · santosomar bundleAnalyze MITRE ATT&CK T1030 Data Transfer Size Limits in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1030, Data Transfer Size Limits, or enterprise ATT&CK. An adversary may exfiltrate data in fixed size chunks instead of whole files or limit packet sizes below certain thresholds.
- ▌ Attack Ent T1036 007 Double File Extension · santosomar bundleAnalyze MITRE ATT&CK T1036.007 Double File Extension in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1036.007, Double File Extension, or enterprise ATT&CK. Adversaries may abuse a double extension in the filename as a means of masquerading the true file type.
- ▌ Attack Ent T1046 Network Service Discovery · santosomar bundleAnalyze MITRE ATT&CK T1046 Network Service Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1046, Network Service Discovery, or enterprise ATT&CK. Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation.
- ▌ Attack Ent T1052 001 Exfiltration Over Usb · santosomar bundleAnalyze MITRE ATT&CK T1052.001 Exfiltration over USB in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1052.001, Exfiltration over USB, or enterprise ATT&CK. Adversaries may attempt to exfiltrate data over a USB connected physical device.
- ▌ Attack Ent T1055 013 Process Doppelg Nging · santosomar bundleAnalyze MITRE ATT&CK T1055.013 Process Doppelgänging in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1055.013, Process Doppelgänging, or enterprise ATT&CK. Adversaries may inject malicious code into process via process doppelgänging in order to evade process-based defenses as well as possibly elevate privileges.
- ▌ Attack Ent T1059 003 Windows Command Shell · santosomar bundleAnalyze MITRE ATT&CK T1059.003 Windows Command Shell in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1059.003, Windows Command Shell, or enterprise ATT&CK. Adversaries may abuse the Windows command shell for execution.
- ▌ Attack Ent T1070 003 Clear Command History · santosomar bundleAnalyze MITRE ATT&CK T1070.003 Clear Command History in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1070.003, Clear Command History, or enterprise ATT&CK. In addition to clearing system logs, an adversary may clear the command history of a compromised account to conceal the actions undertaken during an intrusion.
- ▌ Attack Ent T1211 Exploitation For Stealth · santosomar bundleAnalyze MITRE ATT&CK T1211 Exploitation for Stealth in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1211, Exploitation for Stealth, or enterprise ATT&CK. Adversaries may exploit vulnerabilities to evade detection by hiding activity, suppressing logging, or operating within trusted or unmonitored components.
- ▌ Attack Ent T1480 001 Environmental Keying · santosomar bundleAnalyze MITRE ATT&CK T1480.001 Environmental Keying in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1480.001, Environmental Keying, or enterprise ATT&CK. Adversaries may environmentally key payloads or other features of malware to evade defenses and constraint execution to a specific target environment.
- ▌ Attack Ent T1498 001 Direct Network Flood · santosomar bundleAnalyze MITRE ATT&CK T1498.001 Direct Network Flood in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1498.001, Direct Network Flood, or enterprise ATT&CK. Adversaries may attempt to cause a denial of service (DoS) by directly sending a high-volume of network traffic to a target.
- ▌ Attack Ent T1539 Steal Web Session Cookie · santosomar bundleAnalyze MITRE ATT&CK T1539 Steal Web Session Cookie in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1539, Steal Web Session Cookie, or enterprise ATT&CK. An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials.
- ▌ Attack Ent T1546 011 Application Shimming · santosomar bundleAnalyze MITRE ATT&CK T1546.011 Application Shimming in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1546.011, Application Shimming, or enterprise ATT&CK. Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims.
- ▌ Attack Ent T1546 018 Python Startup Hooks · santosomar bundleAnalyze MITRE ATT&CK T1546.018 Python Startup Hooks in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1546.018, Python Startup Hooks, or enterprise ATT&CK. Adversaries may achieve persistence by leveraging Python’s startup mechanisms, including path configuration (`.pth`) files and the `sitecustomize.py` or `usercustomize.py` modules.
- ▌ Attack Ent T1552 001 Credentials In Files · santosomar bundleAnalyze MITRE ATT&CK T1552.001 Credentials In Files in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1552.001, Credentials In Files, or enterprise ATT&CK. Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials.
- ▌ Attack Ent T1499 Endpoint Denial Of Service · santosomar bundleAnalyze MITRE ATT&CK T1499 Endpoint Denial of Service in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1499, Endpoint Denial of Service, or enterprise ATT&CK. Adversaries may perform Endpoint Denial of Service (DoS) attacks to degrade or block the availability of services to users.
- ▌ Attack Ent T1546 008 Accessibility Features · santosomar bundleAnalyze MITRE ATT&CK T1546.008 Accessibility Features in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1546.008, Accessibility Features, or enterprise ATT&CK. Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by accessibility features.
- ▌ Attack Ent T1547 002 Authentication Package · santosomar bundleAnalyze MITRE ATT&CK T1547.002 Authentication Package in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1547.002, Authentication Package, or enterprise ATT&CK. Adversaries may abuse authentication packages to execute DLLs when the system boots.
- ▌ Attack Ent T1559 001 Component Object Model · santosomar bundleAnalyze MITRE ATT&CK T1559.001 Component Object Model in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1559.001, Component Object Model, or enterprise ATT&CK. Adversaries may use the Windows Component Object Model (COM) for local code execution.
- ▌ Attack Ent T1573 001 Symmetric Cryptography · santosomar bundleAnalyze MITRE ATT&CK T1573.001 Symmetric Cryptography in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1573.001, Symmetric Cryptography, or enterprise ATT&CK. Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
- ▌ Attack Ent T1583 003 Virtual Private Server · santosomar bundleAnalyze MITRE ATT&CK T1583.003 Virtual Private Server in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1583.003, Virtual Private Server, or enterprise ATT&CK. Adversaries may rent Virtual Private Servers (VPSs) that can be used during targeting.
- ▌ Attack Ent T1591 002 Business Relationships · santosomar bundleAnalyze MITRE ATT&CK T1591.002 Business Relationships in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1591.002, Business Relationships, or enterprise ATT&CK. Adversaries may gather information about the victim's business relationships that can be used during targeting.
- ▌ Attack Ent T1072 Software Deployment Tools · santosomar bundleAnalyze MITRE ATT&CK T1072 Software Deployment Tools in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1072, Software Deployment Tools, or enterprise ATT&CK. Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network.
- ▌ Attack Ent T1102 003 One Way Communication · santosomar bundleAnalyze MITRE ATT&CK T1102.003 One-Way Communication in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1102.003, One-Way Communication, or enterprise ATT&CK. Adversaries may use an existing, legitimate external Web service as a means for sending commands to a compromised system without receiving return output over the Web service channel.
- ▌ Attack Ent T1114 003 Email Forwarding Rule · santosomar bundleAnalyze MITRE ATT&CK T1114.003 Email Forwarding Rule in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1114.003, Email Forwarding Rule, or enterprise ATT&CK. Adversaries may setup email forwarding rules to collect sensitive information.
- ▌ Attack Ent T1132 002 Non Standard Encoding · santosomar bundleAnalyze MITRE ATT&CK T1132.002 Non-Standard Encoding in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1132.002, Non-Standard Encoding, or enterprise ATT&CK. Adversaries may encode data with a non-standard data encoding system to make the content of command and control traffic more difficult to detect.
- ▌ Attack Ent T1134 Access Token Manipulation · santosomar bundleAnalyze MITRE ATT&CK T1134 Access Token Manipulation in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1134, Access Token Manipulation, or enterprise ATT&CK. Adversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls.
- ▌ Attack Ent T1185 Browser Session Hijacking · santosomar bundleAnalyze MITRE ATT&CK T1185 Browser Session Hijacking in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1185, Browser Session Hijacking, or enterprise ATT&CK. Adversaries may take advantage of security vulnerabilities and inherent functionality in browser software to change content, modify user-behaviors, and intercept information as part of various browser session hijacking…
- ▌ Attack Ent T1201 Password Policy Discovery · santosomar bundleAnalyze MITRE ATT&CK T1201 Password Policy Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1201, Password Policy Discovery, or enterprise ATT&CK. Adversaries may attempt to access detailed information about the password policy used within an enterprise network or cloud environment.
- ▌ Attack Ent T1556 008 Network Provider Dll · santosomar bundleAnalyze MITRE ATT&CK T1556.008 Network Provider DLL in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1556.008, Network Provider DLL, or enterprise ATT&CK. Adversaries may register malicious network provider dynamic link libraries (DLLs) to capture cleartext user credentials during the authentication process.
- ▌ Attack Ent T1564 004 Ntfs File Attributes · santosomar bundleAnalyze MITRE ATT&CK T1564.004 NTFS File Attributes in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1564.004, NTFS File Attributes, or enterprise ATT&CK. Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection.
- ▌ Attack Ent T1564 006 Run Virtual Instance · santosomar bundleAnalyze MITRE ATT&CK T1564.006 Run Virtual Instance in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1564.006, Run Virtual Instance, or enterprise ATT&CK. Adversaries may carry out malicious operations using a virtual instance to avoid detection.
- ▌ Attack Ent T1587 003 Digital Certificates · santosomar bundleAnalyze MITRE ATT&CK T1587.003 Digital Certificates in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1587.003, Digital Certificates, or enterprise ATT&CK. Adversaries may create self-signed SSL/TLS certificates that can be used during targeting.
- ▌ Attack Ent T1588 004 Digital Certificates · santosomar bundleAnalyze MITRE ATT&CK T1588.004 Digital Certificates in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1588.004, Digital Certificates, or enterprise ATT&CK. Adversaries may buy and/or steal SSL/TLS certificates that can be used during targeting.
- ▌ Attack Ent T1596 003 Digital Certificates · santosomar bundleAnalyze MITRE ATT&CK T1596.003 Digital Certificates in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1596.003, Digital Certificates, or enterprise ATT&CK. Adversaries may search public digital certificate data for information about victims that can be used during targeting.
- ▌ Attack Ent T1597 001 Threat Intel Vendors · santosomar bundleAnalyze MITRE ATT&CK T1597.001 Threat Intel Vendors in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1597.001, Threat Intel Vendors, or enterprise ATT&CK. Adversaries may search private data from threat intelligence vendors for information that can be used during targeting.
- ▌ Attack Mob T1630 Indicator Removal On Host · santosomar bundleAnalyze MITRE ATT&CK T1630 Indicator Removal on Host in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1630, Indicator Removal on Host, or mobile ATT&CK. Adversaries may delete, alter, or hide generated artifacts on a device, including files, jailbreak status, or the malicious application itself.
- ▌ Attack Ent T1005 Data From Local System · santosomar bundleAnalyze MITRE ATT&CK T1005 Data from Local System in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1005, Data from Local System, or enterprise ATT&CK. Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.
- ▌ Attack Ent T1020 Automated Exfiltration · santosomar bundleAnalyze MITRE ATT&CK T1020 Automated Exfiltration in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1020, Automated Exfiltration, or enterprise ATT&CK. Adversaries may exfiltrate data, such as sensitive documents, through the use of automated processing after being gathered during Collection.(Citation: ESET Gamaredon June 2020) When automated exfiltration is used, othe…
- ▌ Attack Ent T1027 012 Lnk Icon Smuggling · santosomar bundleAnalyze MITRE ATT&CK T1027.012 LNK Icon Smuggling in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.012, LNK Icon Smuggling, or enterprise ATT&CK. Adversaries may smuggle commands to download malicious payloads past content filters by hiding them within otherwise seemingly benign windows shortcut files.
- ▌ Attack Ent T1056 003 Web Portal Capture · santosomar bundleAnalyze MITRE ATT&CK T1056.003 Web Portal Capture in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1056.003, Web Portal Capture, or enterprise ATT&CK. Adversaries may install code on externally facing portals, such as a VPN login page, to capture and transmit credentials of users who attempt to log into the service.
- ▌ Attack Ent T1098 005 Device Registration · santosomar bundleAnalyze MITRE ATT&CK T1098.005 Device Registration in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1098.005, Device Registration, or enterprise ATT&CK. Adversaries may register a device to an adversary-controlled account.
- ▌ Attack Ent T1110 004 Credential Stuffing · santosomar bundleAnalyze MITRE ATT&CK T1110.004 Credential Stuffing in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1110.004, Credential Stuffing, or enterprise ATT&CK. Adversaries may use credentials obtained from breach dumps of unrelated accounts to gain access to target accounts through credential overlap.
- ▌ Attack Ent T1134 004 Parent Pid Spoofing · santosomar bundleAnalyze MITRE ATT&CK T1134.004 Parent PID Spoofing in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1134.004, Parent PID Spoofing, or enterprise ATT&CK. Adversaries may spoof the parent process identifier (PPID) of a new process to evade process-monitoring defenses or to elevate privileges.
- ▌ Attack Ent T1135 Network Share Discovery · santosomar bundleAnalyze MITRE ATT&CK T1135 Network Share Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1135, Network Share Discovery, or enterprise ATT&CK. Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Mov…
- ▌ Attack Ent T1195 Supply Chain Compromise · santosomar bundleAnalyze MITRE ATT&CK T1195 Supply Chain Compromise in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1195, Supply Chain Compromise, or enterprise ATT&CK. Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.
- ▌ Attack Ent T1207 Rogue Domain Controller · santosomar bundleAnalyze MITRE ATT&CK T1207 Rogue Domain Controller in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1207, Rogue Domain Controller, or enterprise ATT&CK. Adversaries may register a rogue Domain Controller to enable manipulation of Active Directory data.
- ▌ Attack Ent T1222 001 Windows Permissions · santosomar bundleAnalyze MITRE ATT&CK T1222.001 Windows Permissions in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1222.001, Windows Permissions, or enterprise ATT&CK. Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.(Citation: Hybrid Analysis Icacls1 June 2018)(Citation: Hybrid Analysis Icacls2 May 2018) F…
- ▌ Attack Ent T1490 Inhibit System Recovery · santosomar bundleAnalyze MITRE ATT&CK T1490 Inhibit System Recovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1490, Inhibit System Recovery, or enterprise ATT&CK. Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.(Citation: Talos Olympic Destroyer 2018)(Citation: FireEye WannaCry 2017) Th…
- ▌ Attack Ics T0840 Network Connection Enumeration · santosomar bundleAnalyze MITRE ATT&CK T0840 Network Connection Enumeration in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0840, Network Connection Enumeration, or ics ATT&CK. Adversaries may perform network connection enumeration to discover information about device communication patterns.
- ▌ Attack Mob T1629 003 Disable Or Modify Tools · santosomar bundleAnalyze MITRE ATT&CK T1629.003 Disable or Modify Tools in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1629.003, Disable or Modify Tools, or mobile ATT&CK. Adversaries may disable security tools to avoid potential detection of their tools and activities.
- ▌ Attack Ent T1007 System Service Discovery · santosomar bundleAnalyze MITRE ATT&CK T1007 System Service Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1007, System Service Discovery, or enterprise ATT&CK. Adversaries may try to gather information about registered local system services.
- ▌ Attack Ent T1036 008 Masquerade File Type · santosomar bundleAnalyze MITRE ATT&CK T1036.008 Masquerade File Type in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1036.008, Masquerade File Type, or enterprise ATT&CK. Adversaries may masquerade malicious payloads as legitimate files through changes to the payload's formatting, including the file’s signature, extension, icon, and contents.
- ▌ Attack Ent T1037 001 Logon Script Windows · santosomar bundleAnalyze MITRE ATT&CK T1037.001 Logon Script (Windows) in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1037.001, Logon Script (Windows), or enterprise ATT&CK. Adversaries may use Windows logon scripts automatically executed at logon initialization to establish persistence.
- ▌ Attack Ent T1037 003 Network Logon Script · santosomar bundleAnalyze MITRE ATT&CK T1037.003 Network Logon Script in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1037.003, Network Logon Script, or enterprise ATT&CK. Adversaries may use network logon scripts automatically executed at logon initialization to establish persistence.
- ▌ Attack Ent T1133 External Remote Services · santosomar bundleAnalyze MITRE ATT&CK T1133 External Remote Services in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1133, External Remote Services, or enterprise ATT&CK. Adversaries may leverage external-facing remote services to initially access and/or persist within a network.
- ▌ Attack Ent T1615 Group Policy Discovery · santosomar bundleAnalyze MITRE ATT&CK T1615 Group Policy Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1615, Group Policy Discovery, or enterprise ATT&CK. Adversaries may gather information on Group Policy settings to identify paths for privilege escalation, security measures applied within a domain, and to discover patterns in domain objects that can be manipulated or us…
- ▌ Attack Ics T0894 System Binary Proxy Execution · santosomar bundleAnalyze MITRE ATT&CK T0894 System Binary Proxy Execution in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0894, System Binary Proxy Execution, or ics ATT&CK. Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries.
- ▌ Attack Mob T1437 Application Layer Protocol · santosomar bundleAnalyze MITRE ATT&CK T1437 Application Layer Protocol in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1437, Application Layer Protocol, or mobile ATT&CK. Adversaries may communicate using application layer protocols to avoid detection/network filtering by blending in with existing traffic.
- ▌ Attack Mob T1521 001 Symmetric Cryptography · santosomar bundleAnalyze MITRE ATT&CK T1521.001 Symmetric Cryptography in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1521.001, Symmetric Cryptography, or mobile ATT&CK. Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic, rather than relying on any inherent protections provided by a communication protocol.
- ▌ Attack Mob T1642 Endpoint Denial Of Service · santosomar bundleAnalyze MITRE ATT&CK T1642 Endpoint Denial of Service in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1642, Endpoint Denial of Service, or mobile ATT&CK. Adversaries may perform Endpoint Denial of Service (DoS) attacks to degrade or block the availability of services to users.
- ▌ Attack Ent T1018 Remote System Discovery · santosomar bundleAnalyze MITRE ATT&CK T1018 Remote System Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1018, Remote System Discovery, or enterprise ATT&CK. Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
- ▌ Attack Ent T1020 001 Traffic Duplication · santosomar bundleAnalyze MITRE ATT&CK T1020.001 Traffic Duplication in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1020.001, Traffic Duplication, or enterprise ATT&CK. Adversaries may leverage traffic mirroring in order to automate data exfiltration over compromised infrastructure.
- ▌ Attack Ent T1548 001 Setuid And Setgid · santosomar bundleAnalyze MITRE ATT&CK T1548.001 Setuid and Setgid in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1548.001, Setuid and Setgid, or enterprise ATT&CK. An adversary may abuse configurations where an application has the setuid or setgid bits set in order to get code running in a different (and possibly more privileged) user’s context.
- ▌ Attack Ent T1552 Unsecured Credentials · santosomar bundleAnalyze MITRE ATT&CK T1552 Unsecured Credentials in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1552, Unsecured Credentials, or enterprise ATT&CK. Adversaries may search compromised systems to find and obtain insecurely stored credentials.
- ▌ Attack Ent T1553 001 Gatekeeper Bypass · santosomar bundleAnalyze MITRE ATT&CK T1553.001 Gatekeeper Bypass in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1553.001, Gatekeeper Bypass, or enterprise ATT&CK. Adversaries may modify file attributes and subvert Gatekeeper functionality to evade user prompts and execute untrusted programs.
- ▌ Attack Ent T1555 005 Password Managers · santosomar bundleAnalyze MITRE ATT&CK T1555.005 Password Managers in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1555.005, Password Managers, or enterprise ATT&CK. Adversaries may acquire user credentials from third-party password managers.(Citation: ise Password Manager February 2019) Password managers are applications designed to store user credentials, normally in an encrypted…
- ▌ Attack Ent T1561 001 Disk Content Wipe · santosomar bundleAnalyze MITRE ATT&CK T1561.001 Disk Content Wipe in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1561.001, Disk Content Wipe, or enterprise ATT&CK. Adversaries may erase the contents of storage devices on specific systems or in large numbers in a network to interrupt availability to system and network resources.
- ▌ Attack Ent T1569 002 Service Execution · santosomar bundleAnalyze MITRE ATT&CK T1569.002 Service Execution in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1569.002, Service Execution, or enterprise ATT&CK. Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
- ▌ Attack Ent T1570 Lateral Tool Transfer · santosomar bundleAnalyze MITRE ATT&CK T1570 Lateral Tool Transfer in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1570, Lateral Tool Transfer, or enterprise ATT&CK. Adversaries may transfer tools or other files between systems in a compromised environment.
- ▌ Attack Ent T1547 004 Winlogon Helper Dll · santosomar bundleAnalyze MITRE ATT&CK T1547.004 Winlogon Helper DLL in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1547.004, Winlogon Helper DLL, or enterprise ATT&CK. Adversaries may abuse features of Winlogon to execute DLLs and/or executables when a user logs in.
- ▌ Attack Ent T1557 002 Arp Cache Poisoning · santosomar bundleAnalyze MITRE ATT&CK T1557.002 ARP Cache Poisoning in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1557.002, ARP Cache Poisoning, or enterprise ATT&CK. Adversaries may poison Address Resolution Protocol (ARP) caches to position themselves between the communication of two or more networked devices.
- ▌ Attack Ent T1557 Adversary In The Middle · santosomar bundleAnalyze MITRE ATT&CK T1557 Adversary-in-the-Middle in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1557, Adversary-in-the-Middle, or enterprise ATT&CK. Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as [Network Sniffing](https://attack.mitre.org/t…
- ▌ Attack Ent T1560 001 Archive Via Utility · santosomar bundleAnalyze MITRE ATT&CK T1560.001 Archive via Utility in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1560.001, Archive via Utility, or enterprise ATT&CK. Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
- ▌ Attack Ent T1560 002 Archive Via Library · santosomar bundleAnalyze MITRE ATT&CK T1560.002 Archive via Library in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1560.002, Archive via Library, or enterprise ATT&CK. An adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party libraries.
- ▌ Attack Ent T1561 002 Disk Structure Wipe · santosomar bundleAnalyze MITRE ATT&CK T1561.002 Disk Structure Wipe in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1561.002, Disk Structure Wipe, or enterprise ATT&CK. Adversaries may corrupt or wipe the disk data structures on a hard drive necessary to boot a system; targeting specific critical systems or in large numbers in a network to interrupt availability to system and network r…
- ▌ Attack Ent T1564 014 Extended Attributes · santosomar bundleAnalyze MITRE ATT&CK T1564.014 Extended Attributes in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1564.014, Extended Attributes, or enterprise ATT&CK. Adversaries may abuse extended attributes (xattrs) on macOS and Linux to hide their malicious data in order to evade detection.
- ▌ Attack Ent T1027 010 Command Obfuscation · santosomar bundleAnalyze MITRE ATT&CK T1027.010 Command Obfuscation in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.010, Command Obfuscation, or enterprise ATT&CK. Adversaries may obfuscate content during command execution to impede detection.
- ▌ Attack Ent T1027 016 Junk Code Insertion · santosomar bundleAnalyze MITRE ATT&CK T1027.016 Junk Code Insertion in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.016, Junk Code Insertion, or enterprise ATT&CK. Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
- ▌ Attack Ent T1036 009 Break Process Trees · santosomar bundleAnalyze MITRE ATT&CK T1036.009 Break Process Trees in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1036.009, Break Process Trees, or enterprise ATT&CK. An adversary may attempt to evade process tree-based analysis by modifying executed malware's parent process ID (PPID).
- ▌ Attack Ent T1036 012 Browser Fingerprint · santosomar bundleAnalyze MITRE ATT&CK T1036.012 Browser Fingerprint in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1036.012, Browser Fingerprint, or enterprise ATT&CK. Adversaries may attempt to blend in with legitimate traffic by spoofing browser and system attributes like operating system, system language, platform, user-agent string, resolution, time zone, etc.
- ▌ Attack Ent T1055 008 Ptrace System Calls · santosomar bundleAnalyze MITRE ATT&CK T1055.008 Ptrace System Calls in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1055.008, Ptrace System Calls, or enterprise ATT&CK. Adversaries may inject malicious code into processes via ptrace (process trace) system calls in order to evade process-based defenses as well as possibly elevate privileges.
- ▌ Attack Ent T1074 002 Remote Data Staging · santosomar bundleAnalyze MITRE ATT&CK T1074.002 Remote Data Staging in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1074.002, Remote Data Staging, or enterprise ATT&CK. Adversaries may stage data collected from multiple systems in a central location or directory on one system prior to Exfiltration.
- ▌ Attack Ent T1098 004 Ssh Authorized Keys · santosomar bundleAnalyze MITRE ATT&CK T1098.004 SSH Authorized Keys in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1098.004, SSH Authorized Keys, or enterprise ATT&CK. Adversaries may modify the SSH <code>authorized_keys</code> file to maintain persistence on a victim host.
- ▌ Attack Ent T1574 Hijack Execution Flow · santosomar bundleAnalyze MITRE ATT&CK T1574 Hijack Execution Flow in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1574, Hijack Execution Flow, or enterprise ATT&CK. Adversaries may execute their own malicious payloads by hijacking the way operating systems run programs.
- ▌ Attack Ent T1590 001 Domain Properties · santosomar bundleAnalyze MITRE ATT&CK T1590.001 Domain Properties in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1590.001, Domain Properties, or enterprise ATT&CK. Adversaries may gather information about the victim's network domain(s) that can be used during targeting.
- ▌ Attack Ent T1593 003 Code Repositories · santosomar bundleAnalyze MITRE ATT&CK T1593.003 Code Repositories in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1593.003, Code Repositories, or enterprise ATT&CK. Adversaries may search public code repositories for information about victims that can be used during targeting.
- ▌ Attack Ent T1595 003 Wordlist Scanning · santosomar bundleAnalyze MITRE ATT&CK T1595.003 Wordlist Scanning in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1595.003, Wordlist Scanning, or enterprise ATT&CK. Adversaries may iteratively probe infrastructure using brute-forcing and crawling techniques.
- ▌ Attack Ent T1606 Forge Web Credentials · santosomar bundleAnalyze MITRE ATT&CK T1606 Forge Web Credentials in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1606, Forge Web Credentials, or enterprise ATT&CK. Adversaries may forge credential materials that can be used to gain access to web applications or Internet services.
- ▌ Attack Mob T1430 002 Impersonate Ss7 Nodes · santosomar bundleAnalyze MITRE ATT&CK T1430.002 Impersonate SS7 Nodes in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1430.002, Impersonate SS7 Nodes, or mobile ATT&CK. Adversaries may exploit the lack of authentication in signaling system network nodes to track the location of mobile devices by impersonating a node.(Citation: Engel-SS7)(Citation: Engel-SS7-2008)(Citation: 3GPP-Securit…
- ▌ Attack Mob T1471 Data Encrypted For Impact · santosomar bundleAnalyze MITRE ATT&CK T1471 Data Encrypted for Impact in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1471, Data Encrypted for Impact, or mobile ATT&CK. An adversary may encrypt files stored on a mobile device to prevent the user from accessing them.