santosomar
- 800 skills
- 0 followers
- 10 hours ago last updated
- ▌ Attack Mob T1624 Event Triggered Execution · santosomar bundleAnalyze MITRE ATT&CK T1624 Event Triggered Execution in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1624, Event Triggered Execution, or mobile ATT&CK. Adversaries may establish persistence using system mechanisms that trigger execution based on specific events.
- ▌ Attack Ent T1566 004 Spearphishing Voice · santosomar bundleAnalyze MITRE ATT&CK T1566.004 Spearphishing Voice in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1566.004, Spearphishing Voice, or enterprise ATT&CK. Adversaries may use voice communications to ultimately gain access to victim systems.
- ▌ Attack Ent T1574 013 Kernelcallbacktable · santosomar bundleAnalyze MITRE ATT&CK T1574.013 KernelCallbackTable in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1574.013, KernelCallbackTable, or enterprise ATT&CK. Adversaries may abuse the <code>KernelCallbackTable</code> of a process to hijack its execution flow in order to run their own payloads.(Citation: Lazarus APT January 2022)(Citation: FinFisher exposed ) The <code>Kernel…
- ▌ Attack Ent T1598 004 Spearphishing Voice · santosomar bundleAnalyze MITRE ATT&CK T1598.004 Spearphishing Voice in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1598.004, Spearphishing Voice, or enterprise ATT&CK. Adversaries may use voice communications to elicit sensitive information that can be used during targeting.
- ▌ Attack Ent T1620 Reflective Code Loading · santosomar bundleAnalyze MITRE ATT&CK T1620 Reflective Code Loading in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1620, Reflective Code Loading, or enterprise ATT&CK. Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads.
- ▌ Attack Ent T1647 Plist File Modification · santosomar bundleAnalyze MITRE ATT&CK T1647 Plist File Modification in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1647, Plist File Modification, or enterprise ATT&CK. Adversaries may modify property list files (plist files) to enable other malicious activity, while also potentially evading and bypassing system defenses.
- ▌ Attack Ent T1652 Device Driver Discovery · santosomar bundleAnalyze MITRE ATT&CK T1652 Device Driver Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1652, Device Driver Discovery, or enterprise ATT&CK. Adversaries may attempt to enumerate local device drivers on a victim host.
- ▌ Attack Ent T1680 Local Storage Discovery · santosomar bundleAnalyze MITRE ATT&CK T1680 Local Storage Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1680, Local Storage Discovery, or enterprise ATT&CK. Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number.
- ▌ Attack Ent T1685 Disable Or Modify Tools · santosomar bundleAnalyze MITRE ATT&CK T1685 Disable or Modify Tools in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1685, Disable or Modify Tools, or enterprise ATT&CK. Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair…
- ▌ Attack Ent T1560 Archive Collected Data · santosomar bundleAnalyze MITRE ATT&CK T1560 Archive Collected Data in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1560, Archive Collected Data, or enterprise ATT&CK. An adversary may compress and/or encrypt data that is collected prior to exfiltration.
- ▌ Attack Ent T1564 005 Hidden File System · santosomar bundleAnalyze MITRE ATT&CK T1564.005 Hidden File System in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1564.005, Hidden File System, or enterprise ATT&CK. Adversaries may use a hidden file system to conceal malicious activity from users and security tools.
- ▌ Attack Ent T1564 008 Email Hiding Rules · santosomar bundleAnalyze MITRE ATT&CK T1564.008 Email Hiding Rules in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1564.008, Email Hiding Rules, or enterprise ATT&CK. Adversaries may use email rules to hide inbound emails in a compromised user's mailbox.
- ▌ Attack Ent T1566 002 Spearphishing Link · santosomar bundleAnalyze MITRE ATT&CK T1566.002 Spearphishing Link in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1566.002, Spearphishing Link, or enterprise ATT&CK. Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems.
- ▌ Attack Ent T1583 Acquire Infrastructure · santosomar bundleAnalyze MITRE ATT&CK T1583 Acquire Infrastructure in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1583, Acquire Infrastructure, or enterprise ATT&CK. Adversaries may buy, lease, rent, or obtain infrastructure that can be used during targeting.
- ▌ Attack Ent T1598 003 Spearphishing Link · santosomar bundleAnalyze MITRE ATT&CK T1598.003 Spearphishing Link in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1598.003, Spearphishing Link, or enterprise ATT&CK. Adversaries may send spearphishing messages with a malicious link to elicit sensitive information that can be used during targeting.
- ▌ Attack Ent T1601 001 Patch System Image · santosomar bundleAnalyze MITRE ATT&CK T1601.001 Patch System Image in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1601.001, Patch System Image, or enterprise ATT&CK. Adversaries may modify the operating system of a network device to introduce new capabilities or weaken existing defenses.(Citation: Killing the myth of Cisco IOS rootkits) (Citation: Killing IOS diversity myth) (Citati…
- ▌ Attack Ent T1104 Multi Stage Channels · santosomar bundleAnalyze MITRE ATT&CK T1104 Multi-Stage Channels in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1104, Multi-Stage Channels, or enterprise ATT&CK. Adversaries may create multiple stages for command and control that are employed under different conditions or for certain functions.
- ▌ Attack Ent T1119 Automated Collection · santosomar bundleAnalyze MITRE ATT&CK T1119 Automated Collection in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1119, Automated Collection, or enterprise ATT&CK. Once established within a system or network, an adversary may use automated techniques for collecting internal data.
- ▌ Attack Ent T1199 Trusted Relationship · santosomar bundleAnalyze MITRE ATT&CK T1199 Trusted Relationship in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1199, Trusted Relationship, or enterprise ATT&CK. Adversaries may breach or otherwise leverage organizations who have access to intended victims.
- ▌ Attack Ent T1480 002 Mutual Exclusion · santosomar bundleAnalyze MITRE ATT&CK T1480.002 Mutual Exclusion in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1480.002, Mutual Exclusion, or enterprise ATT&CK. Adversaries may constrain execution or actions based on the presence of a mutex associated with malware.
- ▌ Attack Ent T1480 Execution Guardrails · santosomar bundleAnalyze MITRE ATT&CK T1480 Execution Guardrails in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1480, Execution Guardrails, or enterprise ATT&CK. Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target.
- ▌ Attack Ent T1137 004 Outlook Home Page · santosomar bundleAnalyze MITRE ATT&CK T1137.004 Outlook Home Page in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1137.004, Outlook Home Page, or enterprise ATT&CK. Adversaries may abuse Microsoft Outlook's Home Page feature to obtain persistence on a compromised system.
- ▌ Attack Ent T1187 Forced Authentication · santosomar bundleAnalyze MITRE ATT&CK T1187 Forced Authentication in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1187, Forced Authentication, or enterprise ATT&CK. Adversaries may gather credential material by invoking or forcing a user to automatically provide authentication information through a mechanism in which they can intercept.
- ▌ Attack Ent T1213 003 Code Repositories · santosomar bundleAnalyze MITRE ATT&CK T1213.003 Code Repositories in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1213.003, Code Repositories, or enterprise ATT&CK. Adversaries may leverage code repositories to collect valuable information.
- ▌ Attack Ent T1220 Xsl Script Processing · santosomar bundleAnalyze MITRE ATT&CK T1220 XSL Script Processing in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1220, XSL Script Processing, or enterprise ATT&CK. Adversaries may bypass application control and obscure execution of code by embedding scripts inside XSL files.
- ▌ Attack Ent T1496 001 Compute Hijacking · santosomar bundleAnalyze MITRE ATT&CK T1496.001 Compute Hijacking in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1496.001, Compute Hijacking, or enterprise ATT&CK. Adversaries may leverage the compute resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.
- ▌ Attack Ent T1497 003 Time Based Checks · santosomar bundleAnalyze MITRE ATT&CK T1497.003 Time Based Checks in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1497.003, Time Based Checks, or enterprise ATT&CK. Adversaries may employ various time-based methods to detect virtualization and analysis environments, particularly those that attempt to manipulate time mechanisms to simulate longer elapses of time.
- ▌ Attack Ent T1543 005 Container Service · santosomar bundleAnalyze MITRE ATT&CK T1543.005 Container Service in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1543.005, Container Service, or enterprise ATT&CK. Adversaries may create or modify container or container cluster management tools that run as daemons, agents, or services on individual hosts.
- ▌ Attack Mob T1423 Network Service Scanning · santosomar bundleAnalyze MITRE ATT&CK T1423 Network Service Scanning in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1423, Network Service Scanning, or mobile ATT&CK. Adversaries may attempt to get a listing of services running on remote hosts, including those that may be vulnerable to remote software exploitation.
- ▌ Attack Ent T1003 Os Credential Dumping · santosomar bundleAnalyze MITRE ATT&CK T1003 OS Credential Dumping in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1003, OS Credential Dumping, or enterprise ATT&CK. Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password.
- ▌ Attack Ent T1027 009 Embedded Payloads · santosomar bundleAnalyze MITRE ATT&CK T1027.009 Embedded Payloads in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.009, Embedded Payloads, or enterprise ATT&CK. Adversaries may embed payloads within other files to conceal malicious content from defenses.
- ▌ Attack Ent T1027 018 Invisible Unicode · santosomar bundleAnalyze MITRE ATT&CK T1027.018 Invisible Unicode in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.018, Invisible Unicode, or enterprise ATT&CK. Adversaries may abuse invisible or non-printing Unicode characters to conceal malicious content within files, scripts, or text.
- ▌ Attack Ent T1055 012 Process Hollowing · santosomar bundleAnalyze MITRE ATT&CK T1055.012 Process Hollowing in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1055.012, Process Hollowing, or enterprise ATT&CK. Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses.
- ▌ Attack Ent T1056 002 Gui Input Capture · santosomar bundleAnalyze MITRE ATT&CK T1056.002 GUI Input Capture in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1056.002, GUI Input Capture, or enterprise ATT&CK. Adversaries may mimic common operating system GUI components to prompt users for credentials with a seemingly legitimate prompt.
- ▌ Attack Ent T1059 010 Autohotkey Autoit · santosomar bundleAnalyze MITRE ATT&CK T1059.010 AutoHotKey & AutoIT in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1059.010, AutoHotKey & AutoIT, or enterprise ATT&CK. Adversaries may execute commands and perform malicious tasks using AutoIT and AutoHotKey automation scripts.
- ▌ Attack Ent T1529 System Shutdown Reboot · santosomar bundleAnalyze MITRE ATT&CK T1529 System Shutdown/Reboot in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1529, System Shutdown/Reboot, or enterprise ATT&CK. Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems.
- ▌ Attack Ent T1531 Account Access Removal · santosomar bundleAnalyze MITRE ATT&CK T1531 Account Access Removal in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1531, Account Access Removal, or enterprise ATT&CK. Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users.
- ▌ Attack Ent T1534 Internal Spearphishing · santosomar bundleAnalyze MITRE ATT&CK T1534 Internal Spearphishing in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1534, Internal Spearphishing, or enterprise ATT&CK. After they already have access to accounts or systems within the environment, adversaries may use internal spearphishing to gain access to additional information or compromise other users within the same organization.
- ▌ Attack Ent T1542 002 Component Firmware · santosomar bundleAnalyze MITRE ATT&CK T1542.002 Component Firmware in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1542.002, Component Firmware, or enterprise ATT&CK. Adversaries may modify component firmware to persist on systems.
- ▌ Attack Ent T1546 013 Powershell Profile · santosomar bundleAnalyze MITRE ATT&CK T1546.013 PowerShell Profile in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1546.013, PowerShell Profile, or enterprise ATT&CK. Adversaries may gain persistence and elevate privileges by executing malicious content triggered by PowerShell profiles.
- ▌ Attack Ent T1546 016 Installer Packages · santosomar bundleAnalyze MITRE ATT&CK T1546.016 Installer Packages in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1546.016, Installer Packages, or enterprise ATT&CK. Adversaries may establish persistence and elevate privileges by using an installer to trigger the execution of malicious content.
- ▌ Attack Ent T1550 004 Web Session Cookie · santosomar bundleAnalyze MITRE ATT&CK T1550.004 Web Session Cookie in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1550.004, Web Session Cookie, or enterprise ATT&CK. Adversaries can use stolen session cookies to authenticate to web applications and services.
- ▌ Attack Ent T1553 Subvert Trust Controls · santosomar bundleAnalyze MITRE ATT&CK T1553 Subvert Trust Controls in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1553, Subvert Trust Controls, or enterprise ATT&CK. Adversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted programs.
- ▌ Attack Ent T1027 002 Software Packing · santosomar bundleAnalyze MITRE ATT&CK T1027.002 Software Packing in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.002, Software Packing, or enterprise ATT&CK. Adversaries may perform software packing or virtual machine software protection to conceal their code.
- ▌ Attack Ent T1027 011 Fileless Storage · santosomar bundleAnalyze MITRE ATT&CK T1027.011 Fileless Storage in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.011, Fileless Storage, or enterprise ATT&CK. Adversaries may store data in "fileless" formats to conceal malicious activity from defenses.
- ▌ Attack Ent T1027 014 Polymorphic Code · santosomar bundleAnalyze MITRE ATT&CK T1027.014 Polymorphic Code in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.014, Polymorphic Code, or enterprise ATT&CK. Adversaries may utilize polymorphic code (also known as metamorphic or mutating code) to evade detection.
- ▌ Attack Ent T1070 010 Relocate Malware · santosomar bundleAnalyze MITRE ATT&CK T1070.010 Relocate Malware in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1070.010, Relocate Malware, or enterprise ATT&CK. Once a payload is delivered, adversaries may reproduce copies of the same malware on the victim system to remove evidence of their presence and/or avoid defenses.
- ▌ Attack Ent T1078 001 Default Accounts · santosomar bundleAnalyze MITRE ATT&CK T1078.001 Default Accounts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1078.001, Default Accounts, or enterprise ATT&CK. Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
- ▌ Attack Ent T1080 Taint Shared Content · santosomar bundleAnalyze MITRE ATT&CK T1080 Taint Shared Content in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1080, Taint Shared Content, or enterprise ATT&CK. Adversaries may deliver payloads to remote systems by adding content to shared storage locations, such as network drives or internal code repositories.
- ▌ Attack Ent T1098 Account Manipulation · santosomar bundleAnalyze MITRE ATT&CK T1098 Account Manipulation in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1098, Account Manipulation, or enterprise ATT&CK. Adversaries may manipulate accounts to maintain and/or elevate access to victim systems.
- ▌ Attack Ent T1059 013 Container CLI API · santosomar bundleAnalyze MITRE ATT&CK T1059.013 Container CLI/API in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1059.013, Container CLI/API, or enterprise ATT&CK. Adversaries may abuse built-in CLI tools or API calls to execute malicious commands in containerized environments.
- ▌ Attack Ent T1070 009 Clear Persistence · santosomar bundleAnalyze MITRE ATT&CK T1070.009 Clear Persistence in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1070.009, Clear Persistence, or enterprise ATT&CK. Adversaries may clear artifacts associated with previously established persistence on a host system to remove evidence of their activity.
- ▌ Attack Ent T1105 Ingress Tool Transfer · santosomar bundleAnalyze MITRE ATT&CK T1105 Ingress Tool Transfer in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1105, Ingress Tool Transfer, or enterprise ATT&CK. Adversaries may transfer tools or other files from an external system into a compromised environment.
- ▌ Attack Ent T1110 001 Password Guessing · santosomar bundleAnalyze MITRE ATT&CK T1110.001 Password Guessing in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1110.001, Password Guessing, or enterprise ATT&CK. Adversaries with no prior knowledge of legitimate credentials within the system or environment may guess passwords to attempt access to accounts.
- ▌ Attack Ent T1110 002 Password Cracking · santosomar bundleAnalyze MITRE ATT&CK T1110.002 Password Cracking in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1110.002, Password Cracking, or enterprise ATT&CK. Adversaries may use password cracking to attempt to recover usable credentials, such as plaintext passwords, when credential material such as password hashes are obtained.
- ▌ Attack Ent T1110 003 Password Spraying · santosomar bundleAnalyze MITRE ATT&CK T1110.003 Password Spraying in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1110.003, Password Spraying, or enterprise ATT&CK. Adversaries may use a single or small list of commonly used passwords against many different accounts to attempt to acquire valid account credentials.
- ▌ Attack Ent T1124 System Time Discovery · santosomar bundleAnalyze MITRE ATT&CK T1124 System Time Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1124, System Time Discovery, or enterprise ATT&CK. An adversary may gather the system time and/or time zone settings from a local or remote system.
- ▌ Attack Ent T1132 001 Standard Encoding · santosomar bundleAnalyze MITRE ATT&CK T1132.001 Standard Encoding in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1132.001, Standard Encoding, or enterprise ATT&CK. Adversaries may encode data with a standard data encoding system to make the content of command and control traffic more difficult to detect.
- ▌ Attack Mob T1661 Application Versioning · santosomar bundleAnalyze MITRE ATT&CK T1661 Application Versioning in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1661, Application Versioning, or mobile ATT&CK. An adversary may push an update to a previously benign application to add malicious code.
- ▌ Attack Mob T1663 Remote Access Software · santosomar bundleAnalyze MITRE ATT&CK T1663 Remote Access Software in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1663, Remote Access Software, or mobile ATT&CK. Adversaries may use legitimate remote access software, such as `VNC`, `TeamViewer`, `AirDroid`, `AirMirror`, etc., to establish an interactive command and control channel to target mobile devices.
- ▌ Attack Ent T1003 007 Proc Filesystem · santosomar bundleAnalyze MITRE ATT&CK T1003.007 Proc Filesystem in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1003.007, Proc Filesystem, or enterprise ATT&CK. Adversaries may gather credentials from the proc filesystem or `/proc`.
- ▌ Attack Ent T1016 002 Wi Fi Discovery · santosomar bundleAnalyze MITRE ATT&CK T1016.002 Wi-Fi Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1016.002, Wi-Fi Discovery, or enterprise ATT&CK. Adversaries may search for information about Wi-Fi networks, such as network names and passwords, on compromised systems.
- ▌ Attack Ent T1078 002 Domain Accounts · santosomar bundleAnalyze MITRE ATT&CK T1078.002 Domain Accounts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1078.002, Domain Accounts, or enterprise ATT&CK. Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.(Citation: TechNet Credential Theft) Domain accounts are those…
- ▌ Attack Ent T1596 001 Dns Passive Dns · santosomar bundleAnalyze MITRE ATT&CK T1596.001 DNS/Passive DNS in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1596.001, DNS/Passive DNS, or enterprise ATT&CK. Adversaries may search DNS data for information about victims that can be used during targeting.
- ▌ Attack Ent T1601 Modify System Image · santosomar bundleAnalyze MITRE ATT&CK T1601 Modify System Image in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1601, Modify System Image, or enterprise ATT&CK. Adversaries may make changes to the operating system of embedded network devices to weaken defenses and provide new capabilities for themselves.
- ▌ Attack Ent T1608 004 Drive By Target · santosomar bundleAnalyze MITRE ATT&CK T1608.004 Drive-by Target in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1608.004, Drive-by Target, or enterprise ATT&CK. Adversaries may prepare an operational environment to infect systems that visit a website over the normal course of browsing.
- ▌ Attack Ent T1612 Build Image On Host · santosomar bundleAnalyze MITRE ATT&CK T1612 Build Image on Host in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1612, Build Image on Host, or enterprise ATT&CK. Adversaries may build a container image directly on a host to bypass defenses that monitor for the retrieval of malicious images from a public registry.
- ▌ Attack Ent T1665 Hide Infrastructure · santosomar bundleAnalyze MITRE ATT&CK T1665 Hide Infrastructure in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1665, Hide Infrastructure, or enterprise ATT&CK. Adversaries may manipulate network traffic in order to hide and evade detection of their C2 infrastructure.
- ▌ Attack Ent T1679 Selective Exclusion · santosomar bundleAnalyze MITRE ATT&CK T1679 Selective Exclusion in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1679, Selective Exclusion, or enterprise ATT&CK. Adversaries may intentionally exclude certain files, folders, directories, file types, or system components from encryption or tampering during a ransomware or malicious payload execution.
- ▌ Attack Ent T1683 001 Written Content · santosomar bundleAnalyze MITRE ATT&CK T1683.001 Written Content in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1683.001, Written Content, or enterprise ATT&CK. Adversaries may create or tailor written materials to support targeting and malicious operations.
- ▌ Attack Ent T1546 007 Netsh Helper Dll · santosomar bundleAnalyze MITRE ATT&CK T1546.007 Netsh Helper DLL in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1546.007, Netsh Helper DLL, or enterprise ATT&CK. Adversaries may establish persistence by executing malicious content triggered by Netsh Helper DLLs.
- ▌ Attack Ent T1547 012 Print Processors · santosomar bundleAnalyze MITRE ATT&CK T1547.012 Print Processors in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1547.012, Print Processors, or enterprise ATT&CK. Adversaries may abuse print processors to run malicious DLLs during system boot for persistence and/or privilege escalation.
- ▌ Attack Ent T1548 006 Tcc Manipulation · santosomar bundleAnalyze MITRE ATT&CK T1548.006 TCC Manipulation in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1548.006, TCC Manipulation, or enterprise ATT&CK. Adversaries can manipulate or abuse the Transparency, Consent, & Control (TCC) service or database to grant malicious executables elevated permissions.
- ▌ Attack Ent T1555 002 Securityd Memory · santosomar bundleAnalyze MITRE ATT&CK T1555.002 Securityd Memory in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1555.002, Securityd Memory, or enterprise ATT&CK. An adversary with root access may gather credentials by reading `securityd`’s memory.
- ▌ Attack Ent T1564 009 Resource Forking · santosomar bundleAnalyze MITRE ATT&CK T1564.009 Resource Forking in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1564.009, Resource Forking, or enterprise ATT&CK. Adversaries may abuse resource forks to hide malicious code or executables to evade detection and bypass security applications.
- ▌ Attack Ent T1590 004 Network Topology · santosomar bundleAnalyze MITRE ATT&CK T1590.004 Network Topology in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1590.004, Network Topology, or enterprise ATT&CK. Adversaries may gather information about the victim's network topology that can be used during targeting.
- ▌ Attack Ent T1648 Serverless Execution · santosomar bundleAnalyze MITRE ATT&CK T1648 Serverless Execution in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1648, Serverless Execution, or enterprise ATT&CK. Adversaries may abuse serverless computing, integration, and automation services to execute arbitrary code in cloud environments.
- ▌ Attack Ent T1070 008 Clear Mailbox Data · santosomar bundleAnalyze MITRE ATT&CK T1070.008 Clear Mailbox Data in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1070.008, Clear Mailbox Data, or enterprise ATT&CK. Adversaries may modify mail and mail application data to remove evidence of their activity.
- ▌ Attack Ent T1074 001 Local Data Staging · santosomar bundleAnalyze MITRE ATT&CK T1074.001 Local Data Staging in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1074.001, Local Data Staging, or enterprise ATT&CK. Adversaries may stage collected data in a central location or directory on the local system prior to Exfiltration.
- ▌ Attack Ent T1102 001 Dead Drop Resolver · santosomar bundleAnalyze MITRE ATT&CK T1102.001 Dead Drop Resolver in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1102.001, Dead Drop Resolver, or enterprise ATT&CK. Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure.
- ▌ Attack Ent T1176 001 Browser Extensions · santosomar bundleAnalyze MITRE ATT&CK T1176.001 Browser Extensions in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1176.001, Browser Extensions, or enterprise ATT&CK. Adversaries may abuse internet browser extensions to establish persistent access to victim systems.
- ▌ Attack Ent T1482 Domain Trust Discovery · santosomar bundleAnalyze MITRE ATT&CK T1482 Domain Trust Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1482, Domain Trust Discovery, or enterprise ATT&CK. Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments.
- ▌ Attack Ent T1484 002 Trust Modification · santosomar bundleAnalyze MITRE ATT&CK T1484.002 Trust Modification in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1484.002, Trust Modification, or enterprise ATT&CK. Adversaries may add new domain trusts, modify the properties of existing domain trusts, or otherwise change the configuration of trust relationships between domains and tenants to evade defenses and/or elevate privilege…
- ▌ Attack Ent T1525 Implant Internal Image · santosomar bundleAnalyze MITRE ATT&CK T1525 Implant Internal Image in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1525, Implant Internal Image, or enterprise ATT&CK. Adversaries may implant cloud or container images with malicious code to establish persistence after gaining access to an environment.
- ▌ Attack Ics T0883 Internet Accessible Device · santosomar bundleAnalyze MITRE ATT&CK T0883 Internet Accessible Device in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0883, Internet Accessible Device, or ics ATT&CK. Adversaries may gain access into industrial environments through systems exposed directly to the internet for remote access rather than through [External Remote Services](https://attack.mitre.org/techniques/T0822).
- ▌ Attack Mob T1409 Stored Application Data · santosomar bundleAnalyze MITRE ATT&CK T1409 Stored Application Data in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1409, Stored Application Data, or mobile ATT&CK. Adversaries may try to access and collect application data resident on the device.
- ▌ Attack Mob T1474 Supply Chain Compromise · santosomar bundleAnalyze MITRE ATT&CK T1474 Supply Chain Compromise in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1474, Supply Chain Compromise, or mobile ATT&CK. Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.
- ▌ Attack Mob T1624 001 Broadcast Receivers · santosomar bundleAnalyze MITRE ATT&CK T1624.001 Broadcast Receivers in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1624.001, Broadcast Receivers, or mobile ATT&CK. Adversaries may establish persistence using system mechanisms that trigger execution based on specific events.
- ▌ Attack Mob T1631 001 Ptrace System Calls · santosomar bundleAnalyze MITRE ATT&CK T1631.001 Ptrace System Calls in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1631.001, Ptrace System Calls, or mobile ATT&CK. Adversaries may inject malicious code into processes via ptrace (process trace) system calls in order to evade process-based defenses as well as possibly elevate privileges.
- ▌ Attack Mob T1638 Adversary In The Middle · santosomar bundleAnalyze MITRE ATT&CK T1638 Adversary-in-the-Middle in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1638, Adversary-in-the-Middle, or mobile ATT&CK. Adversaries may attempt to position themselves between two or more networked devices to support follow-on behaviors such as [Transmitted Data Manipulation](https://attack.mitre.org/techniques/T1565/002) or [Endpoint Den…
- ▌ Attack Mob T1670 Virtualization Solution · santosomar bundleAnalyze MITRE ATT&CK T1670 Virtualization Solution in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1670, Virtualization Solution, or mobile ATT&CK. Adversaries may carry out malicious operations using virtualization solutions to escape from Android sandboxes and to avoid detection.
- ▌ Attack Ent T1006 Direct Volume Access · santosomar bundleAnalyze MITRE ATT&CK T1006 Direct Volume Access in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1006, Direct Volume Access, or enterprise ATT&CK. Adversaries may directly access a volume to bypass file access controls and file system monitoring.
- ▌ Attack Ics T0865 Spearphishing Attachment · santosomar bundleAnalyze MITRE ATT&CK T0865 Spearphishing Attachment in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0865, Spearphishing Attachment, or ics ATT&CK. Adversaries may use a spearphishing attachment, a variant of spearphishing, as a form of a social engineering attack against specific targets.
- ▌ Attack Mob T1417 002 Gui Input Capture · santosomar bundleAnalyze MITRE ATT&CK T1417.002 GUI Input Capture in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1417.002, GUI Input Capture, or mobile ATT&CK. Adversaries may mimic common operating system GUI components to prompt users for sensitive information with a seemingly legitimate prompt.
- ▌ Attack Mob T1544 Ingress Tool Transfer · santosomar bundleAnalyze MITRE ATT&CK T1544 Ingress Tool Transfer in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1544, Ingress Tool Transfer, or mobile ATT&CK. Adversaries may transfer tools or other files from an external system onto a compromised device to facilitate follow-on actions.
- ▌ Attack Mob T1625 Hijack Execution Flow · santosomar bundleAnalyze MITRE ATT&CK T1625 Hijack Execution Flow in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1625, Hijack Execution Flow, or mobile ATT&CK. Adversaries may execute their own malicious payloads by hijacking the way operating systems run applications.
- ▌ Attack Ent T1021 007 Cloud Services · santosomar bundleAnalyze MITRE ATT&CK T1021.007 Cloud Services in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1021.007, Cloud Services, or enterprise ATT&CK. Adversaries may log into accessible cloud services within a compromised environment using [Valid Accounts](https://attack.mitre.org/techniques/T1078) that are synchronized with or federated to on-premises user identitie…
- ▌ Attack Ent T1027 001 Binary Padding · santosomar bundleAnalyze MITRE ATT&CK T1027.001 Binary Padding in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.001, Binary Padding, or enterprise ATT&CK. Adversaries may use binary padding to add junk data and change the on-disk representation of malware.
- ▌ Attack Ent T1027 006 HTML Smuggling · santosomar bundleAnalyze MITRE ATT&CK T1027.006 HTML Smuggling in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.006, HTML Smuggling, or enterprise ATT&CK. Adversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign HTML files.
- ▌ Attack Ent T1574 004 Dylib Hijacking · santosomar bundleAnalyze MITRE ATT&CK T1574.004 Dylib Hijacking in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1574.004, Dylib Hijacking, or enterprise ATT&CK. Adversaries may execute their own payloads by placing a malicious dynamic library (dylib) with an expected name in a path a victim application searches at runtime.