← all publishers

santosomar

@santosomar source repo

800 published skills · page 4 of 8

  1. Attack Mob T1624 Event Triggered Execution · santosomar bundle
    Analyze MITRE ATT&CK T1624 Event Triggered Execution in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1624, Event Triggered Execution, or mobile ATT&CK. Adversaries may establish persistence using system mechanisms that trigger execution based on specific events.
    0 installs
  2. Attack Ent T1566 004 Spearphishing Voice · santosomar bundle
    Analyze MITRE ATT&CK T1566.004 Spearphishing Voice in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1566.004, Spearphishing Voice, or enterprise ATT&CK. Adversaries may use voice communications to ultimately gain access to victim systems.
    0 installs
  3. Attack Ent T1574 013 Kernelcallbacktable · santosomar bundle
    Analyze MITRE ATT&CK T1574.013 KernelCallbackTable in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1574.013, KernelCallbackTable, or enterprise ATT&CK. Adversaries may abuse the <code>KernelCallbackTable</code> of a process to hijack its execution flow in order to run their own payloads.(Citation: Lazarus APT January 2022)(Citation: FinFisher exposed ) The <code>Kernel…
    0 installs
  4. Attack Ent T1598 004 Spearphishing Voice · santosomar bundle
    Analyze MITRE ATT&CK T1598.004 Spearphishing Voice in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1598.004, Spearphishing Voice, or enterprise ATT&CK. Adversaries may use voice communications to elicit sensitive information that can be used during targeting.
    0 installs
  5. Attack Ent T1620 Reflective Code Loading · santosomar bundle
    Analyze MITRE ATT&CK T1620 Reflective Code Loading in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1620, Reflective Code Loading, or enterprise ATT&CK. Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads.
    0 installs
  6. Attack Ent T1647 Plist File Modification · santosomar bundle
    Analyze MITRE ATT&CK T1647 Plist File Modification in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1647, Plist File Modification, or enterprise ATT&CK. Adversaries may modify property list files (plist files) to enable other malicious activity, while also potentially evading and bypassing system defenses.
    0 installs
  7. Attack Ent T1652 Device Driver Discovery · santosomar bundle
    Analyze MITRE ATT&CK T1652 Device Driver Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1652, Device Driver Discovery, or enterprise ATT&CK. Adversaries may attempt to enumerate local device drivers on a victim host.
    0 installs
  8. Attack Ent T1680 Local Storage Discovery · santosomar bundle
    Analyze MITRE ATT&CK T1680 Local Storage Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1680, Local Storage Discovery, or enterprise ATT&CK. Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number.
    0 installs
  9. Attack Ent T1685 Disable Or Modify Tools · santosomar bundle
    Analyze MITRE ATT&CK T1685 Disable or Modify Tools in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1685, Disable or Modify Tools, or enterprise ATT&CK. Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair…
    0 installs
  10. Attack Ent T1560 Archive Collected Data · santosomar bundle
    Analyze MITRE ATT&CK T1560 Archive Collected Data in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1560, Archive Collected Data, or enterprise ATT&CK. An adversary may compress and/or encrypt data that is collected prior to exfiltration.
    0 installs
  11. Attack Ent T1564 005 Hidden File System · santosomar bundle
    Analyze MITRE ATT&CK T1564.005 Hidden File System in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1564.005, Hidden File System, or enterprise ATT&CK. Adversaries may use a hidden file system to conceal malicious activity from users and security tools.
    0 installs
  12. Attack Ent T1564 008 Email Hiding Rules · santosomar bundle
    Analyze MITRE ATT&CK T1564.008 Email Hiding Rules in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1564.008, Email Hiding Rules, or enterprise ATT&CK. Adversaries may use email rules to hide inbound emails in a compromised user's mailbox.
    0 installs
  13. Attack Ent T1566 002 Spearphishing Link · santosomar bundle
    Analyze MITRE ATT&CK T1566.002 Spearphishing Link in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1566.002, Spearphishing Link, or enterprise ATT&CK. Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems.
    0 installs
  14. Attack Ent T1583 Acquire Infrastructure · santosomar bundle
    Analyze MITRE ATT&CK T1583 Acquire Infrastructure in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1583, Acquire Infrastructure, or enterprise ATT&CK. Adversaries may buy, lease, rent, or obtain infrastructure that can be used during targeting.
    0 installs
  15. Attack Ent T1598 003 Spearphishing Link · santosomar bundle
    Analyze MITRE ATT&CK T1598.003 Spearphishing Link in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1598.003, Spearphishing Link, or enterprise ATT&CK. Adversaries may send spearphishing messages with a malicious link to elicit sensitive information that can be used during targeting.
    0 installs
  16. Attack Ent T1601 001 Patch System Image · santosomar bundle
    Analyze MITRE ATT&CK T1601.001 Patch System Image in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1601.001, Patch System Image, or enterprise ATT&CK. Adversaries may modify the operating system of a network device to introduce new capabilities or weaken existing defenses.(Citation: Killing the myth of Cisco IOS rootkits) (Citation: Killing IOS diversity myth) (Citati…
    0 installs
  17. Attack Ent T1104 Multi Stage Channels · santosomar bundle
    Analyze MITRE ATT&CK T1104 Multi-Stage Channels in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1104, Multi-Stage Channels, or enterprise ATT&CK. Adversaries may create multiple stages for command and control that are employed under different conditions or for certain functions.
    0 installs
  18. Attack Ent T1119 Automated Collection · santosomar bundle
    Analyze MITRE ATT&CK T1119 Automated Collection in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1119, Automated Collection, or enterprise ATT&CK. Once established within a system or network, an adversary may use automated techniques for collecting internal data.
    0 installs
  19. Attack Ent T1199 Trusted Relationship · santosomar bundle
    Analyze MITRE ATT&CK T1199 Trusted Relationship in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1199, Trusted Relationship, or enterprise ATT&CK. Adversaries may breach or otherwise leverage organizations who have access to intended victims.
    0 installs
  20. Attack Ent T1480 002 Mutual Exclusion · santosomar bundle
    Analyze MITRE ATT&CK T1480.002 Mutual Exclusion in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1480.002, Mutual Exclusion, or enterprise ATT&CK. Adversaries may constrain execution or actions based on the presence of a mutex associated with malware.
    0 installs
  21. Attack Ent T1480 Execution Guardrails · santosomar bundle
    Analyze MITRE ATT&CK T1480 Execution Guardrails in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1480, Execution Guardrails, or enterprise ATT&CK. Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target.
    0 installs
  22. Attack Ent T1137 004 Outlook Home Page · santosomar bundle
    Analyze MITRE ATT&CK T1137.004 Outlook Home Page in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1137.004, Outlook Home Page, or enterprise ATT&CK. Adversaries may abuse Microsoft Outlook's Home Page feature to obtain persistence on a compromised system.
    0 installs
  23. Attack Ent T1187 Forced Authentication · santosomar bundle
    Analyze MITRE ATT&CK T1187 Forced Authentication in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1187, Forced Authentication, or enterprise ATT&CK. Adversaries may gather credential material by invoking or forcing a user to automatically provide authentication information through a mechanism in which they can intercept.
    0 installs
  24. Attack Ent T1213 003 Code Repositories · santosomar bundle
    Analyze MITRE ATT&CK T1213.003 Code Repositories in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1213.003, Code Repositories, or enterprise ATT&CK. Adversaries may leverage code repositories to collect valuable information.
    0 installs
  25. Attack Ent T1220 Xsl Script Processing · santosomar bundle
    Analyze MITRE ATT&CK T1220 XSL Script Processing in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1220, XSL Script Processing, or enterprise ATT&CK. Adversaries may bypass application control and obscure execution of code by embedding scripts inside XSL files.
    0 installs
  26. Attack Ent T1496 001 Compute Hijacking · santosomar bundle
    Analyze MITRE ATT&CK T1496.001 Compute Hijacking in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1496.001, Compute Hijacking, or enterprise ATT&CK. Adversaries may leverage the compute resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.
    0 installs
  27. Attack Ent T1497 003 Time Based Checks · santosomar bundle
    Analyze MITRE ATT&CK T1497.003 Time Based Checks in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1497.003, Time Based Checks, or enterprise ATT&CK. Adversaries may employ various time-based methods to detect virtualization and analysis environments, particularly those that attempt to manipulate time mechanisms to simulate longer elapses of time.
    0 installs
  28. Attack Ent T1543 005 Container Service · santosomar bundle
    Analyze MITRE ATT&CK T1543.005 Container Service in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1543.005, Container Service, or enterprise ATT&CK. Adversaries may create or modify container or container cluster management tools that run as daemons, agents, or services on individual hosts.
    0 installs
  29. Attack Mob T1423 Network Service Scanning · santosomar bundle
    Analyze MITRE ATT&CK T1423 Network Service Scanning in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1423, Network Service Scanning, or mobile ATT&CK. Adversaries may attempt to get a listing of services running on remote hosts, including those that may be vulnerable to remote software exploitation.
    0 installs
  30. Attack Ent T1003 Os Credential Dumping · santosomar bundle
    Analyze MITRE ATT&CK T1003 OS Credential Dumping in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1003, OS Credential Dumping, or enterprise ATT&CK. Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password.
    0 installs
  31. Attack Ent T1027 009 Embedded Payloads · santosomar bundle
    Analyze MITRE ATT&CK T1027.009 Embedded Payloads in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.009, Embedded Payloads, or enterprise ATT&CK. Adversaries may embed payloads within other files to conceal malicious content from defenses.
    0 installs
  32. Attack Ent T1027 018 Invisible Unicode · santosomar bundle
    Analyze MITRE ATT&CK T1027.018 Invisible Unicode in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.018, Invisible Unicode, or enterprise ATT&CK. Adversaries may abuse invisible or non-printing Unicode characters to conceal malicious content within files, scripts, or text.
    0 installs
  33. Attack Ent T1055 012 Process Hollowing · santosomar bundle
    Analyze MITRE ATT&CK T1055.012 Process Hollowing in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1055.012, Process Hollowing, or enterprise ATT&CK. Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses.
    0 installs
  34. Attack Ent T1056 002 Gui Input Capture · santosomar bundle
    Analyze MITRE ATT&CK T1056.002 GUI Input Capture in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1056.002, GUI Input Capture, or enterprise ATT&CK. Adversaries may mimic common operating system GUI components to prompt users for credentials with a seemingly legitimate prompt.
    0 installs
  35. Attack Ent T1059 010 Autohotkey Autoit · santosomar bundle
    Analyze MITRE ATT&CK T1059.010 AutoHotKey & AutoIT in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1059.010, AutoHotKey & AutoIT, or enterprise ATT&CK. Adversaries may execute commands and perform malicious tasks using AutoIT and AutoHotKey automation scripts.
    0 installs
  36. Attack Ent T1529 System Shutdown Reboot · santosomar bundle
    Analyze MITRE ATT&CK T1529 System Shutdown/Reboot in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1529, System Shutdown/Reboot, or enterprise ATT&CK. Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems.
    0 installs
  37. Attack Ent T1531 Account Access Removal · santosomar bundle
    Analyze MITRE ATT&CK T1531 Account Access Removal in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1531, Account Access Removal, or enterprise ATT&CK. Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users.
    0 installs
  38. Attack Ent T1534 Internal Spearphishing · santosomar bundle
    Analyze MITRE ATT&CK T1534 Internal Spearphishing in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1534, Internal Spearphishing, or enterprise ATT&CK. After they already have access to accounts or systems within the environment, adversaries may use internal spearphishing to gain access to additional information or compromise other users within the same organization.
    0 installs
  39. Attack Ent T1542 002 Component Firmware · santosomar bundle
    Analyze MITRE ATT&CK T1542.002 Component Firmware in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1542.002, Component Firmware, or enterprise ATT&CK. Adversaries may modify component firmware to persist on systems.
    0 installs
  40. Attack Ent T1546 013 Powershell Profile · santosomar bundle
    Analyze MITRE ATT&CK T1546.013 PowerShell Profile in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1546.013, PowerShell Profile, or enterprise ATT&CK. Adversaries may gain persistence and elevate privileges by executing malicious content triggered by PowerShell profiles.
    0 installs
  41. Attack Ent T1546 016 Installer Packages · santosomar bundle
    Analyze MITRE ATT&CK T1546.016 Installer Packages in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1546.016, Installer Packages, or enterprise ATT&CK. Adversaries may establish persistence and elevate privileges by using an installer to trigger the execution of malicious content.
    0 installs
  42. Attack Ent T1550 004 Web Session Cookie · santosomar bundle
    Analyze MITRE ATT&CK T1550.004 Web Session Cookie in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1550.004, Web Session Cookie, or enterprise ATT&CK. Adversaries can use stolen session cookies to authenticate to web applications and services.
    0 installs
  43. Attack Ent T1553 Subvert Trust Controls · santosomar bundle
    Analyze MITRE ATT&CK T1553 Subvert Trust Controls in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1553, Subvert Trust Controls, or enterprise ATT&CK. Adversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted programs.
    0 installs
  44. Attack Ent T1027 002 Software Packing · santosomar bundle
    Analyze MITRE ATT&CK T1027.002 Software Packing in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.002, Software Packing, or enterprise ATT&CK. Adversaries may perform software packing or virtual machine software protection to conceal their code.
    0 installs
  45. Attack Ent T1027 011 Fileless Storage · santosomar bundle
    Analyze MITRE ATT&CK T1027.011 Fileless Storage in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.011, Fileless Storage, or enterprise ATT&CK. Adversaries may store data in "fileless" formats to conceal malicious activity from defenses.
    0 installs
  46. Attack Ent T1027 014 Polymorphic Code · santosomar bundle
    Analyze MITRE ATT&CK T1027.014 Polymorphic Code in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.014, Polymorphic Code, or enterprise ATT&CK. Adversaries may utilize polymorphic code (also known as metamorphic or mutating code) to evade detection.
    0 installs
  47. Attack Ent T1070 010 Relocate Malware · santosomar bundle
    Analyze MITRE ATT&CK T1070.010 Relocate Malware in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1070.010, Relocate Malware, or enterprise ATT&CK. Once a payload is delivered, adversaries may reproduce copies of the same malware on the victim system to remove evidence of their presence and/or avoid defenses.
    0 installs
  48. Attack Ent T1078 001 Default Accounts · santosomar bundle
    Analyze MITRE ATT&CK T1078.001 Default Accounts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1078.001, Default Accounts, or enterprise ATT&CK. Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
    0 installs
  49. Attack Ent T1080 Taint Shared Content · santosomar bundle
    Analyze MITRE ATT&CK T1080 Taint Shared Content in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1080, Taint Shared Content, or enterprise ATT&CK. Adversaries may deliver payloads to remote systems by adding content to shared storage locations, such as network drives or internal code repositories.
    0 installs
  50. Attack Ent T1098 Account Manipulation · santosomar bundle
    Analyze MITRE ATT&CK T1098 Account Manipulation in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1098, Account Manipulation, or enterprise ATT&CK. Adversaries may manipulate accounts to maintain and/or elevate access to victim systems.
    0 installs
  51. Attack Ent T1059 013 Container CLI API · santosomar bundle
    Analyze MITRE ATT&CK T1059.013 Container CLI/API in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1059.013, Container CLI/API, or enterprise ATT&CK. Adversaries may abuse built-in CLI tools or API calls to execute malicious commands in containerized environments.
    0 installs
  52. Attack Ent T1070 009 Clear Persistence · santosomar bundle
    Analyze MITRE ATT&CK T1070.009 Clear Persistence in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1070.009, Clear Persistence, or enterprise ATT&CK. Adversaries may clear artifacts associated with previously established persistence on a host system to remove evidence of their activity.
    0 installs
  53. Attack Ent T1105 Ingress Tool Transfer · santosomar bundle
    Analyze MITRE ATT&CK T1105 Ingress Tool Transfer in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1105, Ingress Tool Transfer, or enterprise ATT&CK. Adversaries may transfer tools or other files from an external system into a compromised environment.
    0 installs
  54. Attack Ent T1110 001 Password Guessing · santosomar bundle
    Analyze MITRE ATT&CK T1110.001 Password Guessing in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1110.001, Password Guessing, or enterprise ATT&CK. Adversaries with no prior knowledge of legitimate credentials within the system or environment may guess passwords to attempt access to accounts.
    0 installs
  55. Attack Ent T1110 002 Password Cracking · santosomar bundle
    Analyze MITRE ATT&CK T1110.002 Password Cracking in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1110.002, Password Cracking, or enterprise ATT&CK. Adversaries may use password cracking to attempt to recover usable credentials, such as plaintext passwords, when credential material such as password hashes are obtained.
    0 installs
  56. Attack Ent T1110 003 Password Spraying · santosomar bundle
    Analyze MITRE ATT&CK T1110.003 Password Spraying in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1110.003, Password Spraying, or enterprise ATT&CK. Adversaries may use a single or small list of commonly used passwords against many different accounts to attempt to acquire valid account credentials.
    0 installs
  57. Attack Ent T1124 System Time Discovery · santosomar bundle
    Analyze MITRE ATT&CK T1124 System Time Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1124, System Time Discovery, or enterprise ATT&CK. An adversary may gather the system time and/or time zone settings from a local or remote system.
    0 installs
  58. Attack Ent T1132 001 Standard Encoding · santosomar bundle
    Analyze MITRE ATT&CK T1132.001 Standard Encoding in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1132.001, Standard Encoding, or enterprise ATT&CK. Adversaries may encode data with a standard data encoding system to make the content of command and control traffic more difficult to detect.
    0 installs
  59. Attack Mob T1661 Application Versioning · santosomar bundle
    Analyze MITRE ATT&CK T1661 Application Versioning in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1661, Application Versioning, or mobile ATT&CK. An adversary may push an update to a previously benign application to add malicious code.
    0 installs
  60. Attack Mob T1663 Remote Access Software · santosomar bundle
    Analyze MITRE ATT&CK T1663 Remote Access Software in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1663, Remote Access Software, or mobile ATT&CK. Adversaries may use legitimate remote access software, such as `VNC`, `TeamViewer`, `AirDroid`, `AirMirror`, etc., to establish an interactive command and control channel to target mobile devices.
    0 installs
  61. Attack Ent T1003 007 Proc Filesystem · santosomar bundle
    Analyze MITRE ATT&CK T1003.007 Proc Filesystem in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1003.007, Proc Filesystem, or enterprise ATT&CK. Adversaries may gather credentials from the proc filesystem or `/proc`.
    0 installs
  62. Attack Ent T1016 002 Wi Fi Discovery · santosomar bundle
    Analyze MITRE ATT&CK T1016.002 Wi-Fi Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1016.002, Wi-Fi Discovery, or enterprise ATT&CK. Adversaries may search for information about Wi-Fi networks, such as network names and passwords, on compromised systems.
    0 installs
  63. Attack Ent T1078 002 Domain Accounts · santosomar bundle
    Analyze MITRE ATT&CK T1078.002 Domain Accounts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1078.002, Domain Accounts, or enterprise ATT&CK. Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.(Citation: TechNet Credential Theft) Domain accounts are those…
    0 installs
  64. Attack Ent T1596 001 Dns Passive Dns · santosomar bundle
    Analyze MITRE ATT&CK T1596.001 DNS/Passive DNS in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1596.001, DNS/Passive DNS, or enterprise ATT&CK. Adversaries may search DNS data for information about victims that can be used during targeting.
    0 installs
  65. Attack Ent T1601 Modify System Image · santosomar bundle
    Analyze MITRE ATT&CK T1601 Modify System Image in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1601, Modify System Image, or enterprise ATT&CK. Adversaries may make changes to the operating system of embedded network devices to weaken defenses and provide new capabilities for themselves.
    0 installs
  66. Attack Ent T1608 004 Drive By Target · santosomar bundle
    Analyze MITRE ATT&CK T1608.004 Drive-by Target in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1608.004, Drive-by Target, or enterprise ATT&CK. Adversaries may prepare an operational environment to infect systems that visit a website over the normal course of browsing.
    0 installs
  67. Attack Ent T1612 Build Image On Host · santosomar bundle
    Analyze MITRE ATT&CK T1612 Build Image on Host in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1612, Build Image on Host, or enterprise ATT&CK. Adversaries may build a container image directly on a host to bypass defenses that monitor for the retrieval of malicious images from a public registry.
    0 installs
  68. Attack Ent T1665 Hide Infrastructure · santosomar bundle
    Analyze MITRE ATT&CK T1665 Hide Infrastructure in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1665, Hide Infrastructure, or enterprise ATT&CK. Adversaries may manipulate network traffic in order to hide and evade detection of their C2 infrastructure.
    0 installs
  69. Attack Ent T1679 Selective Exclusion · santosomar bundle
    Analyze MITRE ATT&CK T1679 Selective Exclusion in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1679, Selective Exclusion, or enterprise ATT&CK. Adversaries may intentionally exclude certain files, folders, directories, file types, or system components from encryption or tampering during a ransomware or malicious payload execution.
    0 installs
  70. Attack Ent T1683 001 Written Content · santosomar bundle
    Analyze MITRE ATT&CK T1683.001 Written Content in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1683.001, Written Content, or enterprise ATT&CK. Adversaries may create or tailor written materials to support targeting and malicious operations.
    0 installs
  71. Attack Ent T1546 007 Netsh Helper Dll · santosomar bundle
    Analyze MITRE ATT&CK T1546.007 Netsh Helper DLL in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1546.007, Netsh Helper DLL, or enterprise ATT&CK. Adversaries may establish persistence by executing malicious content triggered by Netsh Helper DLLs.
    0 installs
  72. Attack Ent T1547 012 Print Processors · santosomar bundle
    Analyze MITRE ATT&CK T1547.012 Print Processors in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1547.012, Print Processors, or enterprise ATT&CK. Adversaries may abuse print processors to run malicious DLLs during system boot for persistence and/or privilege escalation.
    0 installs
  73. Attack Ent T1548 006 Tcc Manipulation · santosomar bundle
    Analyze MITRE ATT&CK T1548.006 TCC Manipulation in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1548.006, TCC Manipulation, or enterprise ATT&CK. Adversaries can manipulate or abuse the Transparency, Consent, & Control (TCC) service or database to grant malicious executables elevated permissions.
    0 installs
  74. Attack Ent T1555 002 Securityd Memory · santosomar bundle
    Analyze MITRE ATT&CK T1555.002 Securityd Memory in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1555.002, Securityd Memory, or enterprise ATT&CK. An adversary with root access may gather credentials by reading `securityd`’s memory.
    0 installs
  75. Attack Ent T1564 009 Resource Forking · santosomar bundle
    Analyze MITRE ATT&CK T1564.009 Resource Forking in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1564.009, Resource Forking, or enterprise ATT&CK. Adversaries may abuse resource forks to hide malicious code or executables to evade detection and bypass security applications.
    0 installs
  76. Attack Ent T1590 004 Network Topology · santosomar bundle
    Analyze MITRE ATT&CK T1590.004 Network Topology in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1590.004, Network Topology, or enterprise ATT&CK. Adversaries may gather information about the victim's network topology that can be used during targeting.
    0 installs
  77. Attack Ent T1648 Serverless Execution · santosomar bundle
    Analyze MITRE ATT&CK T1648 Serverless Execution in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1648, Serverless Execution, or enterprise ATT&CK. Adversaries may abuse serverless computing, integration, and automation services to execute arbitrary code in cloud environments.
    0 installs
  78. Attack Ent T1070 008 Clear Mailbox Data · santosomar bundle
    Analyze MITRE ATT&CK T1070.008 Clear Mailbox Data in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1070.008, Clear Mailbox Data, or enterprise ATT&CK. Adversaries may modify mail and mail application data to remove evidence of their activity.
    0 installs
  79. Attack Ent T1074 001 Local Data Staging · santosomar bundle
    Analyze MITRE ATT&CK T1074.001 Local Data Staging in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1074.001, Local Data Staging, or enterprise ATT&CK. Adversaries may stage collected data in a central location or directory on the local system prior to Exfiltration.
    0 installs
  80. Attack Ent T1102 001 Dead Drop Resolver · santosomar bundle
    Analyze MITRE ATT&CK T1102.001 Dead Drop Resolver in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1102.001, Dead Drop Resolver, or enterprise ATT&CK. Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure.
    0 installs
  81. Attack Ent T1176 001 Browser Extensions · santosomar bundle
    Analyze MITRE ATT&CK T1176.001 Browser Extensions in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1176.001, Browser Extensions, or enterprise ATT&CK. Adversaries may abuse internet browser extensions to establish persistent access to victim systems.
    0 installs
  82. Attack Ent T1482 Domain Trust Discovery · santosomar bundle
    Analyze MITRE ATT&CK T1482 Domain Trust Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1482, Domain Trust Discovery, or enterprise ATT&CK. Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments.
    0 installs
  83. Attack Ent T1484 002 Trust Modification · santosomar bundle
    Analyze MITRE ATT&CK T1484.002 Trust Modification in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1484.002, Trust Modification, or enterprise ATT&CK. Adversaries may add new domain trusts, modify the properties of existing domain trusts, or otherwise change the configuration of trust relationships between domains and tenants to evade defenses and/or elevate privilege…
    0 installs
  84. Attack Ent T1525 Implant Internal Image · santosomar bundle
    Analyze MITRE ATT&CK T1525 Implant Internal Image in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1525, Implant Internal Image, or enterprise ATT&CK. Adversaries may implant cloud or container images with malicious code to establish persistence after gaining access to an environment.
    0 installs
  85. Attack Ics T0883 Internet Accessible Device · santosomar bundle
    Analyze MITRE ATT&CK T0883 Internet Accessible Device in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0883, Internet Accessible Device, or ics ATT&CK. Adversaries may gain access into industrial environments through systems exposed directly to the internet for remote access rather than through [External Remote Services](https://attack.mitre.org/techniques/T0822).
    0 installs
  86. Attack Mob T1409 Stored Application Data · santosomar bundle
    Analyze MITRE ATT&CK T1409 Stored Application Data in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1409, Stored Application Data, or mobile ATT&CK. Adversaries may try to access and collect application data resident on the device.
    0 installs
  87. Attack Mob T1474 Supply Chain Compromise · santosomar bundle
    Analyze MITRE ATT&CK T1474 Supply Chain Compromise in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1474, Supply Chain Compromise, or mobile ATT&CK. Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.
    0 installs
  88. Attack Mob T1624 001 Broadcast Receivers · santosomar bundle
    Analyze MITRE ATT&CK T1624.001 Broadcast Receivers in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1624.001, Broadcast Receivers, or mobile ATT&CK. Adversaries may establish persistence using system mechanisms that trigger execution based on specific events.
    0 installs
  89. Attack Mob T1631 001 Ptrace System Calls · santosomar bundle
    Analyze MITRE ATT&CK T1631.001 Ptrace System Calls in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1631.001, Ptrace System Calls, or mobile ATT&CK. Adversaries may inject malicious code into processes via ptrace (process trace) system calls in order to evade process-based defenses as well as possibly elevate privileges.
    0 installs
  90. Attack Mob T1638 Adversary In The Middle · santosomar bundle
    Analyze MITRE ATT&CK T1638 Adversary-in-the-Middle in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1638, Adversary-in-the-Middle, or mobile ATT&CK. Adversaries may attempt to position themselves between two or more networked devices to support follow-on behaviors such as [Transmitted Data Manipulation](https://attack.mitre.org/techniques/T1565/002) or [Endpoint Den…
    0 installs
  91. Attack Mob T1670 Virtualization Solution · santosomar bundle
    Analyze MITRE ATT&CK T1670 Virtualization Solution in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1670, Virtualization Solution, or mobile ATT&CK. Adversaries may carry out malicious operations using virtualization solutions to escape from Android sandboxes and to avoid detection.
    0 installs
  92. Attack Ent T1006 Direct Volume Access · santosomar bundle
    Analyze MITRE ATT&CK T1006 Direct Volume Access in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1006, Direct Volume Access, or enterprise ATT&CK. Adversaries may directly access a volume to bypass file access controls and file system monitoring.
    0 installs
  93. Attack Ics T0865 Spearphishing Attachment · santosomar bundle
    Analyze MITRE ATT&CK T0865 Spearphishing Attachment in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0865, Spearphishing Attachment, or ics ATT&CK. Adversaries may use a spearphishing attachment, a variant of spearphishing, as a form of a social engineering attack against specific targets.
    0 installs
  94. Attack Mob T1417 002 Gui Input Capture · santosomar bundle
    Analyze MITRE ATT&CK T1417.002 GUI Input Capture in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1417.002, GUI Input Capture, or mobile ATT&CK. Adversaries may mimic common operating system GUI components to prompt users for sensitive information with a seemingly legitimate prompt.
    0 installs
  95. Attack Mob T1544 Ingress Tool Transfer · santosomar bundle
    Analyze MITRE ATT&CK T1544 Ingress Tool Transfer in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1544, Ingress Tool Transfer, or mobile ATT&CK. Adversaries may transfer tools or other files from an external system onto a compromised device to facilitate follow-on actions.
    0 installs
  96. Attack Mob T1625 Hijack Execution Flow · santosomar bundle
    Analyze MITRE ATT&CK T1625 Hijack Execution Flow in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1625, Hijack Execution Flow, or mobile ATT&CK. Adversaries may execute their own malicious payloads by hijacking the way operating systems run applications.
    0 installs
  97. Attack Ent T1021 007 Cloud Services · santosomar bundle
    Analyze MITRE ATT&CK T1021.007 Cloud Services in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1021.007, Cloud Services, or enterprise ATT&CK. Adversaries may log into accessible cloud services within a compromised environment using [Valid Accounts](https://attack.mitre.org/techniques/T1078) that are synchronized with or federated to on-premises user identitie…
    0 installs
  98. Attack Ent T1027 001 Binary Padding · santosomar bundle
    Analyze MITRE ATT&CK T1027.001 Binary Padding in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.001, Binary Padding, or enterprise ATT&CK. Adversaries may use binary padding to add junk data and change the on-disk representation of malware.
    0 installs
  99. Attack Ent T1027 006 HTML Smuggling · santosomar bundle
    Analyze MITRE ATT&CK T1027.006 HTML Smuggling in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.006, HTML Smuggling, or enterprise ATT&CK. Adversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign HTML files.
    0 installs
  100. Attack Ent T1574 004 Dylib Hijacking · santosomar bundle
    Analyze MITRE ATT&CK T1574.004 Dylib Hijacking in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1574.004, Dylib Hijacking, or enterprise ATT&CK. Adversaries may execute their own payloads by placing a malicious dynamic library (dylib) with an expected name in a path a victim application searches at runtime.
    0 installs