← all publishers

santosomar

@santosomar source repo

800 published skills · page 3 of 8

  1. Attack Ics T0866 Exploitation Of Remote Services · santosomar bundle
    Analyze MITRE ATT&CK T0866 Exploitation of Remote Services in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0866, Exploitation of Remote Services, or ics ATT&CK. Adversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself to enable remote service abuse.
    0 installs
  2. Attack Ics T0873 001 Siemens Project File Format · santosomar bundle
    Analyze MITRE ATT&CK T0873.001 Siemens Project File Format in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0873.001, Siemens Project File Format, or ics ATT&CK. Adversaries may infect Siemens PLC project files (i.e., Step 7, WinCC, etc.) to achieve [Execution](https://attack.mitre.org/tactics/TA0104), [Persistence](https://attack.mitre.org/tactics/TA0110), and [Lateral Movement…
    0 installs
  3. Attack Mob T1407 Download New Code At Runtime · santosomar bundle
    Analyze MITRE ATT&CK T1407 Download New Code at Runtime in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1407, Download New Code at Runtime, or mobile ATT&CK. Adversaries may download and execute dynamic code not included in the original application package after installation.
    0 installs
  4. Attack Mob T1420 File And Directory Discovery · santosomar bundle
    Analyze MITRE ATT&CK T1420 File and Directory Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1420, File and Directory Discovery, or mobile ATT&CK. Adversaries may enumerate files and directories or search in specific device locations for desired information within a filesystem.
    0 installs
  5. Attack Mob T1426 System Information Discovery · santosomar bundle
    Analyze MITRE ATT&CK T1426 System Information Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1426, System Information Discovery, or mobile ATT&CK. Adversaries may attempt to get detailed information about a device’s operating system and hardware, including versions, patches, and architecture.
    0 installs
  6. Attack Ent T1491 001 Internal Defacement · santosomar bundle
    Analyze MITRE ATT&CK T1491.001 Internal Defacement in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1491.001, Internal Defacement, or enterprise ATT&CK. An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
    0 installs
  7. Attack Ent T1499 001 Os Exhaustion Flood · santosomar bundle
    Analyze MITRE ATT&CK T1499.001 OS Exhaustion Flood in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1499.001, OS Exhaustion Flood, or enterprise ATT&CK. Adversaries may launch a denial of service (DoS) attack targeting an endpoint's operating system (OS).
    0 installs
  8. Attack Ent T1526 Cloud Service Discovery · santosomar bundle
    Analyze MITRE ATT&CK T1526 Cloud Service Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1526, Cloud Service Discovery, or enterprise ATT&CK. An adversary may attempt to enumerate the cloud services running on a system after gaining access.
    0 installs
  9. Attack Ent T1530 Data From Cloud Storage · santosomar bundle
    Analyze MITRE ATT&CK T1530 Data from Cloud Storage in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1530, Data from Cloud Storage, or enterprise ATT&CK. Adversaries may access data from cloud storage.
    0 installs
  10. Attack Ent T1538 Cloud Service Dashboard · santosomar bundle
    Analyze MITRE ATT&CK T1538 Cloud Service Dashboard in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1538, Cloud Service Dashboard, or enterprise ATT&CK. An adversary may use a cloud service dashboard GUI with stolen credentials to gain useful information from an operational cloud environment, such as specific services, resources, and features.
    0 installs
  11. Attack Ent T1030 Data Transfer Size Limits · santosomar bundle
    Analyze MITRE ATT&CK T1030 Data Transfer Size Limits in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1030, Data Transfer Size Limits, or enterprise ATT&CK. An adversary may exfiltrate data in fixed size chunks instead of whole files or limit packet sizes below certain thresholds.
    0 installs
  12. Attack Ent T1036 007 Double File Extension · santosomar bundle
    Analyze MITRE ATT&CK T1036.007 Double File Extension in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1036.007, Double File Extension, or enterprise ATT&CK. Adversaries may abuse a double extension in the filename as a means of masquerading the true file type.
    0 installs
  13. Attack Ent T1046 Network Service Discovery · santosomar bundle
    Analyze MITRE ATT&CK T1046 Network Service Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1046, Network Service Discovery, or enterprise ATT&CK. Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation.
    0 installs
  14. Attack Ent T1052 001 Exfiltration Over Usb · santosomar bundle
    Analyze MITRE ATT&CK T1052.001 Exfiltration over USB in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1052.001, Exfiltration over USB, or enterprise ATT&CK. Adversaries may attempt to exfiltrate data over a USB connected physical device.
    0 installs
  15. Attack Ent T1055 013 Process Doppelg Nging · santosomar bundle
    Analyze MITRE ATT&CK T1055.013 Process Doppelgänging in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1055.013, Process Doppelgänging, or enterprise ATT&CK. Adversaries may inject malicious code into process via process doppelgänging in order to evade process-based defenses as well as possibly elevate privileges.
    0 installs
  16. Attack Ent T1059 003 Windows Command Shell · santosomar bundle
    Analyze MITRE ATT&CK T1059.003 Windows Command Shell in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1059.003, Windows Command Shell, or enterprise ATT&CK. Adversaries may abuse the Windows command shell for execution.
    0 installs
  17. Attack Ent T1070 003 Clear Command History · santosomar bundle
    Analyze MITRE ATT&CK T1070.003 Clear Command History in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1070.003, Clear Command History, or enterprise ATT&CK. In addition to clearing system logs, an adversary may clear the command history of a compromised account to conceal the actions undertaken during an intrusion.
    0 installs
  18. Attack Ent T1211 Exploitation For Stealth · santosomar bundle
    Analyze MITRE ATT&CK T1211 Exploitation for Stealth in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1211, Exploitation for Stealth, or enterprise ATT&CK. Adversaries may exploit vulnerabilities to evade detection by hiding activity, suppressing logging, or operating within trusted or unmonitored components.
    0 installs
  19. Attack Ent T1480 001 Environmental Keying · santosomar bundle
    Analyze MITRE ATT&CK T1480.001 Environmental Keying in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1480.001, Environmental Keying, or enterprise ATT&CK. Adversaries may environmentally key payloads or other features of malware to evade defenses and constraint execution to a specific target environment.
    0 installs
  20. Attack Ent T1498 001 Direct Network Flood · santosomar bundle
    Analyze MITRE ATT&CK T1498.001 Direct Network Flood in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1498.001, Direct Network Flood, or enterprise ATT&CK. Adversaries may attempt to cause a denial of service (DoS) by directly sending a high-volume of network traffic to a target.
    0 installs
  21. Attack Ent T1539 Steal Web Session Cookie · santosomar bundle
    Analyze MITRE ATT&CK T1539 Steal Web Session Cookie in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1539, Steal Web Session Cookie, or enterprise ATT&CK. An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials.
    0 installs
  22. Attack Ent T1546 011 Application Shimming · santosomar bundle
    Analyze MITRE ATT&CK T1546.011 Application Shimming in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1546.011, Application Shimming, or enterprise ATT&CK. Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims.
    0 installs
  23. Attack Ent T1546 018 Python Startup Hooks · santosomar bundle
    Analyze MITRE ATT&CK T1546.018 Python Startup Hooks in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1546.018, Python Startup Hooks, or enterprise ATT&CK. Adversaries may achieve persistence by leveraging Python’s startup mechanisms, including path configuration (`.pth`) files and the `sitecustomize.py` or `usercustomize.py` modules.
    0 installs
  24. Attack Ent T1552 001 Credentials In Files · santosomar bundle
    Analyze MITRE ATT&CK T1552.001 Credentials In Files in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1552.001, Credentials In Files, or enterprise ATT&CK. Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials.
    0 installs
  25. Attack Ent T1499 Endpoint Denial Of Service · santosomar bundle
    Analyze MITRE ATT&CK T1499 Endpoint Denial of Service in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1499, Endpoint Denial of Service, or enterprise ATT&CK. Adversaries may perform Endpoint Denial of Service (DoS) attacks to degrade or block the availability of services to users.
    0 installs
  26. Attack Ent T1546 008 Accessibility Features · santosomar bundle
    Analyze MITRE ATT&CK T1546.008 Accessibility Features in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1546.008, Accessibility Features, or enterprise ATT&CK. Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by accessibility features.
    0 installs
  27. Attack Ent T1547 002 Authentication Package · santosomar bundle
    Analyze MITRE ATT&CK T1547.002 Authentication Package in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1547.002, Authentication Package, or enterprise ATT&CK. Adversaries may abuse authentication packages to execute DLLs when the system boots.
    0 installs
  28. Attack Ent T1559 001 Component Object Model · santosomar bundle
    Analyze MITRE ATT&CK T1559.001 Component Object Model in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1559.001, Component Object Model, or enterprise ATT&CK. Adversaries may use the Windows Component Object Model (COM) for local code execution.
    0 installs
  29. Attack Ent T1573 001 Symmetric Cryptography · santosomar bundle
    Analyze MITRE ATT&CK T1573.001 Symmetric Cryptography in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1573.001, Symmetric Cryptography, or enterprise ATT&CK. Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
    0 installs
  30. Attack Ent T1583 003 Virtual Private Server · santosomar bundle
    Analyze MITRE ATT&CK T1583.003 Virtual Private Server in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1583.003, Virtual Private Server, or enterprise ATT&CK. Adversaries may rent Virtual Private Servers (VPSs) that can be used during targeting.
    0 installs
  31. Attack Ent T1591 002 Business Relationships · santosomar bundle
    Analyze MITRE ATT&CK T1591.002 Business Relationships in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1591.002, Business Relationships, or enterprise ATT&CK. Adversaries may gather information about the victim's business relationships that can be used during targeting.
    0 installs
  32. Attack Ent T1072 Software Deployment Tools · santosomar bundle
    Analyze MITRE ATT&CK T1072 Software Deployment Tools in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1072, Software Deployment Tools, or enterprise ATT&CK. Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network.
    0 installs
  33. Attack Ent T1102 003 One Way Communication · santosomar bundle
    Analyze MITRE ATT&CK T1102.003 One-Way Communication in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1102.003, One-Way Communication, or enterprise ATT&CK. Adversaries may use an existing, legitimate external Web service as a means for sending commands to a compromised system without receiving return output over the Web service channel.
    0 installs
  34. Attack Ent T1114 003 Email Forwarding Rule · santosomar bundle
    Analyze MITRE ATT&CK T1114.003 Email Forwarding Rule in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1114.003, Email Forwarding Rule, or enterprise ATT&CK. Adversaries may setup email forwarding rules to collect sensitive information.
    0 installs
  35. Attack Ent T1132 002 Non Standard Encoding · santosomar bundle
    Analyze MITRE ATT&CK T1132.002 Non-Standard Encoding in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1132.002, Non-Standard Encoding, or enterprise ATT&CK. Adversaries may encode data with a non-standard data encoding system to make the content of command and control traffic more difficult to detect.
    0 installs
  36. Attack Ent T1134 Access Token Manipulation · santosomar bundle
    Analyze MITRE ATT&CK T1134 Access Token Manipulation in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1134, Access Token Manipulation, or enterprise ATT&CK. Adversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls.
    0 installs
  37. Attack Ent T1185 Browser Session Hijacking · santosomar bundle
    Analyze MITRE ATT&CK T1185 Browser Session Hijacking in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1185, Browser Session Hijacking, or enterprise ATT&CK. Adversaries may take advantage of security vulnerabilities and inherent functionality in browser software to change content, modify user-behaviors, and intercept information as part of various browser session hijacking…
    0 installs
  38. Attack Ent T1201 Password Policy Discovery · santosomar bundle
    Analyze MITRE ATT&CK T1201 Password Policy Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1201, Password Policy Discovery, or enterprise ATT&CK. Adversaries may attempt to access detailed information about the password policy used within an enterprise network or cloud environment.
    0 installs
  39. Attack Ent T1556 008 Network Provider Dll · santosomar bundle
    Analyze MITRE ATT&CK T1556.008 Network Provider DLL in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1556.008, Network Provider DLL, or enterprise ATT&CK. Adversaries may register malicious network provider dynamic link libraries (DLLs) to capture cleartext user credentials during the authentication process.
    0 installs
  40. Attack Ent T1564 004 Ntfs File Attributes · santosomar bundle
    Analyze MITRE ATT&CK T1564.004 NTFS File Attributes in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1564.004, NTFS File Attributes, or enterprise ATT&CK. Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection.
    0 installs
  41. Attack Ent T1564 006 Run Virtual Instance · santosomar bundle
    Analyze MITRE ATT&CK T1564.006 Run Virtual Instance in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1564.006, Run Virtual Instance, or enterprise ATT&CK. Adversaries may carry out malicious operations using a virtual instance to avoid detection.
    0 installs
  42. Attack Ent T1587 003 Digital Certificates · santosomar bundle
    Analyze MITRE ATT&CK T1587.003 Digital Certificates in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1587.003, Digital Certificates, or enterprise ATT&CK. Adversaries may create self-signed SSL/TLS certificates that can be used during targeting.
    0 installs
  43. Attack Ent T1588 004 Digital Certificates · santosomar bundle
    Analyze MITRE ATT&CK T1588.004 Digital Certificates in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1588.004, Digital Certificates, or enterprise ATT&CK. Adversaries may buy and/or steal SSL/TLS certificates that can be used during targeting.
    0 installs
  44. Attack Ent T1596 003 Digital Certificates · santosomar bundle
    Analyze MITRE ATT&CK T1596.003 Digital Certificates in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1596.003, Digital Certificates, or enterprise ATT&CK. Adversaries may search public digital certificate data for information about victims that can be used during targeting.
    0 installs
  45. Attack Ent T1597 001 Threat Intel Vendors · santosomar bundle
    Analyze MITRE ATT&CK T1597.001 Threat Intel Vendors in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1597.001, Threat Intel Vendors, or enterprise ATT&CK. Adversaries may search private data from threat intelligence vendors for information that can be used during targeting.
    0 installs
  46. Attack Mob T1630 Indicator Removal On Host · santosomar bundle
    Analyze MITRE ATT&CK T1630 Indicator Removal on Host in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1630, Indicator Removal on Host, or mobile ATT&CK. Adversaries may delete, alter, or hide generated artifacts on a device, including files, jailbreak status, or the malicious application itself.
    0 installs
  47. Attack Ent T1005 Data From Local System · santosomar bundle
    Analyze MITRE ATT&CK T1005 Data from Local System in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1005, Data from Local System, or enterprise ATT&CK. Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.
    0 installs
  48. Attack Ent T1020 Automated Exfiltration · santosomar bundle
    Analyze MITRE ATT&CK T1020 Automated Exfiltration in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1020, Automated Exfiltration, or enterprise ATT&CK. Adversaries may exfiltrate data, such as sensitive documents, through the use of automated processing after being gathered during Collection.(Citation: ESET Gamaredon June 2020) When automated exfiltration is used, othe…
    0 installs
  49. Attack Ent T1027 012 Lnk Icon Smuggling · santosomar bundle
    Analyze MITRE ATT&CK T1027.012 LNK Icon Smuggling in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.012, LNK Icon Smuggling, or enterprise ATT&CK. Adversaries may smuggle commands to download malicious payloads past content filters by hiding them within otherwise seemingly benign windows shortcut files.
    0 installs
  50. Attack Ent T1056 003 Web Portal Capture · santosomar bundle
    Analyze MITRE ATT&CK T1056.003 Web Portal Capture in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1056.003, Web Portal Capture, or enterprise ATT&CK. Adversaries may install code on externally facing portals, such as a VPN login page, to capture and transmit credentials of users who attempt to log into the service.
    0 installs
  51. Attack Ent T1098 005 Device Registration · santosomar bundle
    Analyze MITRE ATT&CK T1098.005 Device Registration in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1098.005, Device Registration, or enterprise ATT&CK. Adversaries may register a device to an adversary-controlled account.
    0 installs
  52. Attack Ent T1110 004 Credential Stuffing · santosomar bundle
    Analyze MITRE ATT&CK T1110.004 Credential Stuffing in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1110.004, Credential Stuffing, or enterprise ATT&CK. Adversaries may use credentials obtained from breach dumps of unrelated accounts to gain access to target accounts through credential overlap.
    0 installs
  53. Attack Ent T1134 004 Parent Pid Spoofing · santosomar bundle
    Analyze MITRE ATT&CK T1134.004 Parent PID Spoofing in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1134.004, Parent PID Spoofing, or enterprise ATT&CK. Adversaries may spoof the parent process identifier (PPID) of a new process to evade process-monitoring defenses or to elevate privileges.
    0 installs
  54. Attack Ent T1135 Network Share Discovery · santosomar bundle
    Analyze MITRE ATT&CK T1135 Network Share Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1135, Network Share Discovery, or enterprise ATT&CK. Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Mov…
    0 installs
  55. Attack Ent T1195 Supply Chain Compromise · santosomar bundle
    Analyze MITRE ATT&CK T1195 Supply Chain Compromise in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1195, Supply Chain Compromise, or enterprise ATT&CK. Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.
    0 installs
  56. Attack Ent T1207 Rogue Domain Controller · santosomar bundle
    Analyze MITRE ATT&CK T1207 Rogue Domain Controller in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1207, Rogue Domain Controller, or enterprise ATT&CK. Adversaries may register a rogue Domain Controller to enable manipulation of Active Directory data.
    0 installs
  57. Attack Ent T1222 001 Windows Permissions · santosomar bundle
    Analyze MITRE ATT&CK T1222.001 Windows Permissions in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1222.001, Windows Permissions, or enterprise ATT&CK. Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.(Citation: Hybrid Analysis Icacls1 June 2018)(Citation: Hybrid Analysis Icacls2 May 2018) F…
    0 installs
  58. Attack Ent T1490 Inhibit System Recovery · santosomar bundle
    Analyze MITRE ATT&CK T1490 Inhibit System Recovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1490, Inhibit System Recovery, or enterprise ATT&CK. Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.(Citation: Talos Olympic Destroyer 2018)(Citation: FireEye WannaCry 2017) Th…
    0 installs
  59. Attack Ics T0840 Network Connection Enumeration · santosomar bundle
    Analyze MITRE ATT&CK T0840 Network Connection Enumeration in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0840, Network Connection Enumeration, or ics ATT&CK. Adversaries may perform network connection enumeration to discover information about device communication patterns.
    0 installs
  60. Attack Mob T1629 003 Disable Or Modify Tools · santosomar bundle
    Analyze MITRE ATT&CK T1629.003 Disable or Modify Tools in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1629.003, Disable or Modify Tools, or mobile ATT&CK. Adversaries may disable security tools to avoid potential detection of their tools and activities.
    0 installs
  61. Attack Ent T1007 System Service Discovery · santosomar bundle
    Analyze MITRE ATT&CK T1007 System Service Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1007, System Service Discovery, or enterprise ATT&CK. Adversaries may try to gather information about registered local system services.
    0 installs
  62. Attack Ent T1036 008 Masquerade File Type · santosomar bundle
    Analyze MITRE ATT&CK T1036.008 Masquerade File Type in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1036.008, Masquerade File Type, or enterprise ATT&CK. Adversaries may masquerade malicious payloads as legitimate files through changes to the payload's formatting, including the file’s signature, extension, icon, and contents.
    0 installs
  63. Attack Ent T1037 001 Logon Script Windows · santosomar bundle
    Analyze MITRE ATT&CK T1037.001 Logon Script (Windows) in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1037.001, Logon Script (Windows), or enterprise ATT&CK. Adversaries may use Windows logon scripts automatically executed at logon initialization to establish persistence.
    0 installs
  64. Attack Ent T1037 003 Network Logon Script · santosomar bundle
    Analyze MITRE ATT&CK T1037.003 Network Logon Script in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1037.003, Network Logon Script, or enterprise ATT&CK. Adversaries may use network logon scripts automatically executed at logon initialization to establish persistence.
    0 installs
  65. Attack Ent T1133 External Remote Services · santosomar bundle
    Analyze MITRE ATT&CK T1133 External Remote Services in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1133, External Remote Services, or enterprise ATT&CK. Adversaries may leverage external-facing remote services to initially access and/or persist within a network.
    0 installs
  66. Attack Ent T1615 Group Policy Discovery · santosomar bundle
    Analyze MITRE ATT&CK T1615 Group Policy Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1615, Group Policy Discovery, or enterprise ATT&CK. Adversaries may gather information on Group Policy settings to identify paths for privilege escalation, security measures applied within a domain, and to discover patterns in domain objects that can be manipulated or us…
    0 installs
  67. Attack Ics T0894 System Binary Proxy Execution · santosomar bundle
    Analyze MITRE ATT&CK T0894 System Binary Proxy Execution in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0894, System Binary Proxy Execution, or ics ATT&CK. Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries.
    0 installs
  68. Attack Mob T1437 Application Layer Protocol · santosomar bundle
    Analyze MITRE ATT&CK T1437 Application Layer Protocol in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1437, Application Layer Protocol, or mobile ATT&CK. Adversaries may communicate using application layer protocols to avoid detection/network filtering by blending in with existing traffic.
    0 installs
  69. Attack Mob T1521 001 Symmetric Cryptography · santosomar bundle
    Analyze MITRE ATT&CK T1521.001 Symmetric Cryptography in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1521.001, Symmetric Cryptography, or mobile ATT&CK. Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic, rather than relying on any inherent protections provided by a communication protocol.
    0 installs
  70. Attack Mob T1642 Endpoint Denial Of Service · santosomar bundle
    Analyze MITRE ATT&CK T1642 Endpoint Denial of Service in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1642, Endpoint Denial of Service, or mobile ATT&CK. Adversaries may perform Endpoint Denial of Service (DoS) attacks to degrade or block the availability of services to users.
    0 installs
  71. Attack Ent T1018 Remote System Discovery · santosomar bundle
    Analyze MITRE ATT&CK T1018 Remote System Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1018, Remote System Discovery, or enterprise ATT&CK. Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
    0 installs
  72. Attack Ent T1020 001 Traffic Duplication · santosomar bundle
    Analyze MITRE ATT&CK T1020.001 Traffic Duplication in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1020.001, Traffic Duplication, or enterprise ATT&CK. Adversaries may leverage traffic mirroring in order to automate data exfiltration over compromised infrastructure.
    0 installs
  73. Attack Ent T1548 001 Setuid And Setgid · santosomar bundle
    Analyze MITRE ATT&CK T1548.001 Setuid and Setgid in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1548.001, Setuid and Setgid, or enterprise ATT&CK. An adversary may abuse configurations where an application has the setuid or setgid bits set in order to get code running in a different (and possibly more privileged) user’s context.
    0 installs
  74. Attack Ent T1552 Unsecured Credentials · santosomar bundle
    Analyze MITRE ATT&CK T1552 Unsecured Credentials in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1552, Unsecured Credentials, or enterprise ATT&CK. Adversaries may search compromised systems to find and obtain insecurely stored credentials.
    0 installs
  75. Attack Ent T1553 001 Gatekeeper Bypass · santosomar bundle
    Analyze MITRE ATT&CK T1553.001 Gatekeeper Bypass in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1553.001, Gatekeeper Bypass, or enterprise ATT&CK. Adversaries may modify file attributes and subvert Gatekeeper functionality to evade user prompts and execute untrusted programs.
    0 installs
  76. Attack Ent T1555 005 Password Managers · santosomar bundle
    Analyze MITRE ATT&CK T1555.005 Password Managers in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1555.005, Password Managers, or enterprise ATT&CK. Adversaries may acquire user credentials from third-party password managers.(Citation: ise Password Manager February 2019) Password managers are applications designed to store user credentials, normally in an encrypted…
    0 installs
  77. Attack Ent T1561 001 Disk Content Wipe · santosomar bundle
    Analyze MITRE ATT&CK T1561.001 Disk Content Wipe in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1561.001, Disk Content Wipe, or enterprise ATT&CK. Adversaries may erase the contents of storage devices on specific systems or in large numbers in a network to interrupt availability to system and network resources.
    0 installs
  78. Attack Ent T1569 002 Service Execution · santosomar bundle
    Analyze MITRE ATT&CK T1569.002 Service Execution in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1569.002, Service Execution, or enterprise ATT&CK. Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
    0 installs
  79. Attack Ent T1570 Lateral Tool Transfer · santosomar bundle
    Analyze MITRE ATT&CK T1570 Lateral Tool Transfer in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1570, Lateral Tool Transfer, or enterprise ATT&CK. Adversaries may transfer tools or other files between systems in a compromised environment.
    0 installs
  80. Attack Ent T1547 004 Winlogon Helper Dll · santosomar bundle
    Analyze MITRE ATT&CK T1547.004 Winlogon Helper DLL in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1547.004, Winlogon Helper DLL, or enterprise ATT&CK. Adversaries may abuse features of Winlogon to execute DLLs and/or executables when a user logs in.
    0 installs
  81. Attack Ent T1557 002 Arp Cache Poisoning · santosomar bundle
    Analyze MITRE ATT&CK T1557.002 ARP Cache Poisoning in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1557.002, ARP Cache Poisoning, or enterprise ATT&CK. Adversaries may poison Address Resolution Protocol (ARP) caches to position themselves between the communication of two or more networked devices.
    0 installs
  82. Attack Ent T1557 Adversary In The Middle · santosomar bundle
    Analyze MITRE ATT&CK T1557 Adversary-in-the-Middle in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1557, Adversary-in-the-Middle, or enterprise ATT&CK. Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as [Network Sniffing](https://attack.mitre.org/t…
    0 installs
  83. Attack Ent T1560 001 Archive Via Utility · santosomar bundle
    Analyze MITRE ATT&CK T1560.001 Archive via Utility in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1560.001, Archive via Utility, or enterprise ATT&CK. Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
    0 installs
  84. Attack Ent T1560 002 Archive Via Library · santosomar bundle
    Analyze MITRE ATT&CK T1560.002 Archive via Library in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1560.002, Archive via Library, or enterprise ATT&CK. An adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party libraries.
    0 installs
  85. Attack Ent T1561 002 Disk Structure Wipe · santosomar bundle
    Analyze MITRE ATT&CK T1561.002 Disk Structure Wipe in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1561.002, Disk Structure Wipe, or enterprise ATT&CK. Adversaries may corrupt or wipe the disk data structures on a hard drive necessary to boot a system; targeting specific critical systems or in large numbers in a network to interrupt availability to system and network r…
    0 installs
  86. Attack Ent T1564 014 Extended Attributes · santosomar bundle
    Analyze MITRE ATT&CK T1564.014 Extended Attributes in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1564.014, Extended Attributes, or enterprise ATT&CK. Adversaries may abuse extended attributes (xattrs) on macOS and Linux to hide their malicious data in order to evade detection.
    0 installs
  87. Attack Ent T1027 010 Command Obfuscation · santosomar bundle
    Analyze MITRE ATT&CK T1027.010 Command Obfuscation in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.010, Command Obfuscation, or enterprise ATT&CK. Adversaries may obfuscate content during command execution to impede detection.
    0 installs
  88. Attack Ent T1027 016 Junk Code Insertion · santosomar bundle
    Analyze MITRE ATT&CK T1027.016 Junk Code Insertion in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.016, Junk Code Insertion, or enterprise ATT&CK. Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
    0 installs
  89. Attack Ent T1036 009 Break Process Trees · santosomar bundle
    Analyze MITRE ATT&CK T1036.009 Break Process Trees in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1036.009, Break Process Trees, or enterprise ATT&CK. An adversary may attempt to evade process tree-based analysis by modifying executed malware's parent process ID (PPID).
    0 installs
  90. Attack Ent T1036 012 Browser Fingerprint · santosomar bundle
    Analyze MITRE ATT&CK T1036.012 Browser Fingerprint in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1036.012, Browser Fingerprint, or enterprise ATT&CK. Adversaries may attempt to blend in with legitimate traffic by spoofing browser and system attributes like operating system, system language, platform, user-agent string, resolution, time zone, etc.
    0 installs
  91. Attack Ent T1055 008 Ptrace System Calls · santosomar bundle
    Analyze MITRE ATT&CK T1055.008 Ptrace System Calls in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1055.008, Ptrace System Calls, or enterprise ATT&CK. Adversaries may inject malicious code into processes via ptrace (process trace) system calls in order to evade process-based defenses as well as possibly elevate privileges.
    0 installs
  92. Attack Ent T1074 002 Remote Data Staging · santosomar bundle
    Analyze MITRE ATT&CK T1074.002 Remote Data Staging in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1074.002, Remote Data Staging, or enterprise ATT&CK. Adversaries may stage data collected from multiple systems in a central location or directory on one system prior to Exfiltration.
    0 installs
  93. Attack Ent T1098 004 Ssh Authorized Keys · santosomar bundle
    Analyze MITRE ATT&CK T1098.004 SSH Authorized Keys in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1098.004, SSH Authorized Keys, or enterprise ATT&CK. Adversaries may modify the SSH <code>authorized_keys</code> file to maintain persistence on a victim host.
    0 installs
  94. Attack Ent T1574 Hijack Execution Flow · santosomar bundle
    Analyze MITRE ATT&CK T1574 Hijack Execution Flow in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1574, Hijack Execution Flow, or enterprise ATT&CK. Adversaries may execute their own malicious payloads by hijacking the way operating systems run programs.
    0 installs
  95. Attack Ent T1590 001 Domain Properties · santosomar bundle
    Analyze MITRE ATT&CK T1590.001 Domain Properties in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1590.001, Domain Properties, or enterprise ATT&CK. Adversaries may gather information about the victim's network domain(s) that can be used during targeting.
    0 installs
  96. Attack Ent T1593 003 Code Repositories · santosomar bundle
    Analyze MITRE ATT&CK T1593.003 Code Repositories in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1593.003, Code Repositories, or enterprise ATT&CK. Adversaries may search public code repositories for information about victims that can be used during targeting.
    0 installs
  97. Attack Ent T1595 003 Wordlist Scanning · santosomar bundle
    Analyze MITRE ATT&CK T1595.003 Wordlist Scanning in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1595.003, Wordlist Scanning, or enterprise ATT&CK. Adversaries may iteratively probe infrastructure using brute-forcing and crawling techniques.
    0 installs
  98. Attack Ent T1606 Forge Web Credentials · santosomar bundle
    Analyze MITRE ATT&CK T1606 Forge Web Credentials in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1606, Forge Web Credentials, or enterprise ATT&CK. Adversaries may forge credential materials that can be used to gain access to web applications or Internet services.
    0 installs
  99. Attack Mob T1430 002 Impersonate Ss7 Nodes · santosomar bundle
    Analyze MITRE ATT&CK T1430.002 Impersonate SS7 Nodes in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1430.002, Impersonate SS7 Nodes, or mobile ATT&CK. Adversaries may exploit the lack of authentication in signaling system network nodes to track the location of mobile devices by impersonating a node.(Citation: Engel-SS7)(Citation: Engel-SS7-2008)(Citation: 3GPP-Securit…
    0 installs
  100. Attack Mob T1471 Data Encrypted For Impact · santosomar bundle
    Analyze MITRE ATT&CK T1471 Data Encrypted for Impact in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1471, Data Encrypted for Impact, or mobile ATT&CK. An adversary may encrypt files stored on a mobile device to prevent the user from accessing them.
    0 installs