santosomar
- 800 skills
- 0 followers
- 10 hours ago last updated
- ▌ Attack Ent T1578 001 Create Snapshot · santosomar bundleAnalyze MITRE ATT&CK T1578.001 Create Snapshot in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1578.001, Create Snapshot, or enterprise ATT&CK. An adversary may create a snapshot or data backup within a cloud account to evade defenses.
- ▌ Attack Ent T1584 008 Network Devices · santosomar bundleAnalyze MITRE ATT&CK T1584.008 Network Devices in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1584.008, Network Devices, or enterprise ATT&CK. Adversaries may compromise third-party network devices that can be used during targeting.
- ▌ Attack Ent T1586 Compromise Accounts · santosomar bundleAnalyze MITRE ATT&CK T1586 Compromise Accounts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1586, Compromise Accounts, or enterprise ATT&CK. Adversaries may compromise accounts with services that can be used during targeting.
- ▌ Attack Ent T1588 006 Vulnerabilities · santosomar bundleAnalyze MITRE ATT&CK T1588.006 Vulnerabilities in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1588.006, Vulnerabilities, or enterprise ATT&CK. Adversaries may acquire information about vulnerabilities that can be used during targeting.
- ▌ Attack Ent T1588 Obtain Capabilities · santosomar bundleAnalyze MITRE ATT&CK T1588 Obtain Capabilities in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1588, Obtain Capabilities, or enterprise ATT&CK. Adversaries may buy and/or steal capabilities that can be used during targeting.
- ▌ Attack Ent T1589 002 Email Addresses · santosomar bundleAnalyze MITRE ATT&CK T1589.002 Email Addresses in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1589.002, Email Addresses, or enterprise ATT&CK. Adversaries may gather email addresses that can be used during targeting.
- ▌ Attack Ent T1029 Scheduled Transfer · santosomar bundleAnalyze MITRE ATT&CK T1029 Scheduled Transfer in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1029, Scheduled Transfer, or enterprise ATT&CK. Adversaries may schedule data exfiltration to be performed only at certain times of day or at certain intervals.
- ▌ Attack Ent T1053 005 Scheduled Task · santosomar bundleAnalyze MITRE ATT&CK T1053.005 Scheduled Task in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1053.005, Scheduled Task, or enterprise ATT&CK. Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code.
- ▌ Attack Ent T1053 006 Systemd Timers · santosomar bundleAnalyze MITRE ATT&CK T1053.006 Systemd Timers in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1053.006, Systemd Timers, or enterprise ATT&CK. Adversaries may abuse systemd timers to perform task scheduling for initial or recurring execution of malicious code.
- ▌ Attack Ent T1053 Scheduled Task Job · santosomar bundleAnalyze MITRE ATT&CK T1053 Scheduled Task/Job in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1053, Scheduled Task/Job, or enterprise ATT&CK. Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code.
- ▌ Attack Ent T1055 014 Vdso Hijacking · santosomar bundleAnalyze MITRE ATT&CK T1055.014 VDSO Hijacking in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1055.014, VDSO Hijacking, or enterprise ATT&CK. Adversaries may inject malicious code into processes via VDSO hijacking in order to evade process-based defenses as well as possibly elevate privileges.
- ▌ Attack Ics T1694 002 Hardcoded Credentials · santosomar bundleAnalyze MITRE ATT&CK T1694.002 Hardcoded Credentials in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1694.002, Hardcoded Credentials, or ics ATT&CK. Adversaries may leverage credentials that are hardcoded in software or firmware to gain an unauthorized interactive user session to an asset.
- ▌ Attack Mob T1481 001 Dead Drop Resolver · santosomar bundleAnalyze MITRE ATT&CK T1481.001 Dead Drop Resolver in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1481.001, Dead Drop Resolver, or mobile ATT&CK. Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure.
- ▌ Attack Mob T1532 Archive Collected Data · santosomar bundleAnalyze MITRE ATT&CK T1532 Archive Collected Data in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1532, Archive Collected Data, or mobile ATT&CK. Adversaries may compress and/or encrypt data that is collected prior to exfiltration.
- ▌ Attack Mob T1533 Data From Local System · santosomar bundleAnalyze MITRE ATT&CK T1533 Data from Local System in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1533, Data from Local System, or mobile ATT&CK. Adversaries may search local system sources, such as file systems or local databases, to find files of interest and sensitive data prior to exfiltration.
- ▌ Attack Mob T1541 Foreground Persistence · santosomar bundleAnalyze MITRE ATT&CK T1541 Foreground Persistence in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1541, Foreground Persistence, or mobile ATT&CK. Adversaries may abuse Android's `startForeground()` API method to maintain continuous sensor access.
- ▌ Attack Mob T1632 Subvert Trust Controls · santosomar bundleAnalyze MITRE ATT&CK T1632 Subvert Trust Controls in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1632, Subvert Trust Controls, or mobile ATT&CK. Adversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted applications.
- ▌ Attack Mob T1640 Account Access Removal · santosomar bundleAnalyze MITRE ATT&CK T1640 Account Access Removal in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1640, Account Access Removal, or mobile ATT&CK. Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users.
- ▌ Attack Ent T1090 003 Multi Hop Proxy · santosomar bundleAnalyze MITRE ATT&CK T1090.003 Multi-hop Proxy in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1090.003, Multi-hop Proxy, or enterprise ATT&CK. Adversaries may chain together multiple proxies to disguise the source of malicious traffic.
- ▌ Attack Ent T1090 004 Domain Fronting · santosomar bundleAnalyze MITRE ATT&CK T1090.004 Domain Fronting in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1090.004, Domain Fronting, or enterprise ATT&CK. Adversaries may take advantage of routing schemes in Content Delivery Networks (CDNs) and other services which host multiple domains to obfuscate the intended destination of HTTPS traffic or traffic tunneled through HTT…
- ▌ Attack Ent T1176 Software Extensions · santosomar bundleAnalyze MITRE ATT&CK T1176 Software Extensions in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1176, Software Extensions, or enterprise ATT&CK. Adversaries may abuse software extensions to establish persistent access to victim systems.
- ▌ Attack Ent T1189 Drive By Compromise · santosomar bundleAnalyze MITRE ATT&CK T1189 Drive-by Compromise in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1189, Drive-by Compromise, or enterprise ATT&CK. Adversaries may gain access to a system through a user visiting a website over the normal course of browsing.
- ▌ Attack Ent T1204 003 Malicious Image · santosomar bundleAnalyze MITRE ATT&CK T1204.003 Malicious Image in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1204.003, Malicious Image, or enterprise ATT&CK. Adversaries may rely on a user running a malicious image to facilitate execution.
- ▌ Attack Ent T1219 Remote Access Tools · santosomar bundleAnalyze MITRE ATT&CK T1219 Remote Access Tools in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1219, Remote Access Tools, or enterprise ATT&CK. An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network.
- ▌ Attack Ent T1495 Firmware Corruption · santosomar bundleAnalyze MITRE ATT&CK T1495 Firmware Corruption in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1495, Firmware Corruption, or enterprise ATT&CK. Adversaries may overwrite or corrupt the flash memory contents of system BIOS or other firmware in devices attached to a system in order to render them inoperable or unable to boot, thus denying the availability to use…
- ▌ Attack Ent T1585 003 Cloud Accounts · santosomar bundleAnalyze MITRE ATT&CK T1585.003 Cloud Accounts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1585.003, Cloud Accounts, or enterprise ATT&CK. Adversaries may create accounts with cloud providers that can be used during targeting.
- ▌ Attack Ent T1585 Establish Accounts · santosomar bundleAnalyze MITRE ATT&CK T1585 Establish Accounts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1585, Establish Accounts, or enterprise ATT&CK. Adversaries may create and cultivate accounts with services that can be used during targeting.
- ▌ Attack Ent T1586 002 Email Accounts · santosomar bundleAnalyze MITRE ATT&CK T1586.002 Email Accounts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1586.002, Email Accounts, or enterprise ATT&CK. Adversaries may compromise email accounts that can be used during targeting.
- ▌ Attack Ent T1586 003 Cloud Accounts · santosomar bundleAnalyze MITRE ATT&CK T1586.003 Cloud Accounts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1586.003, Cloud Accounts, or enterprise ATT&CK. Adversaries may compromise cloud accounts that can be used during targeting.
- ▌ Attack Ent T1589 003 Employee Names · santosomar bundleAnalyze MITRE ATT&CK T1589.003 Employee Names in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1589.003, Employee Names, or enterprise ATT&CK. Adversaries may gather employee names that can be used during targeting.
- ▌ Attack Ent T1591 004 Identify Roles · santosomar bundleAnalyze MITRE ATT&CK T1591.004 Identify Roles in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1591.004, Identify Roles, or enterprise ATT&CK. Adversaries may gather information about identities and roles within the victim organization that can be used during targeting.
- ▌ Attack Ent T1593 002 Search Engines · santosomar bundleAnalyze MITRE ATT&CK T1593.002 Search Engines in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1593.002, Search Engines, or enterprise ATT&CK. Adversaries may use search engines to collect information about victims that can be used during targeting.
- ▌ Attack Ent T1608 006 SEO Poisoning · santosomar bundleAnalyze MITRE ATT&CK T1608.006 SEO Poisoning in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1608.006, SEO Poisoning, or enterprise ATT&CK. Adversaries may poison mechanisms that influence search engine optimization (SEO) to further lure staged capabilities towards potential victims.
- ▌ Attack Ent T1659 Content Injection · santosomar bundleAnalyze MITRE ATT&CK T1659 Content Injection in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1659, Content Injection, or enterprise ATT&CK. Adversaries may gain access and continuously communicate with victims by injecting malicious content into systems through online network traffic.
- ▌ Attack Ent T1668 Exclusive Control · santosomar bundleAnalyze MITRE ATT&CK T1668 Exclusive Control in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1668, Exclusive Control, or enterprise ATT&CK. Adversaries who successfully compromise a system may attempt to maintain persistence by “closing the door” behind them – in other words, by preventing other threat actors from initially accessing or maintaining a footho…
- ▌ Attack Ent T1684 001 Impersonation · santosomar bundleAnalyze MITRE ATT&CK T1684.001 Impersonation in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1684.001, Impersonation, or enterprise ATT&CK. Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf.
- ▌ Attack Ics T0820 Exploitation For Evasion · santosomar bundleAnalyze MITRE ATT&CK T0820 Exploitation for Evasion in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0820, Exploitation for Evasion, or ics ATT&CK. Adversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself to evade detection.
- ▌ Attack Ics T0822 External Remote Services · santosomar bundleAnalyze MITRE ATT&CK T0822 External Remote Services in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0822, External Remote Services, or ics ATT&CK. Adversaries may leverage external remote services as a point of initial access into your network.
- ▌ Attack Ics T0823 Graphical User Interface · santosomar bundleAnalyze MITRE ATT&CK T0823 Graphical User Interface in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0823, Graphical User Interface, or ics ATT&CK. Adversaries may attempt to gain access to a machine via a Graphical User Interface (GUI) to enhance execution capabilities.
- ▌ Attack Ics T0861 Point Tag Identification · santosomar bundleAnalyze MITRE ATT&CK T0861 Point & Tag Identification in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0861, Point & Tag Identification, or ics ATT&CK. Adversaries may collect point and tag values to gain a more comprehensive understanding of the process environment.
- ▌ Attack Ent T1505 002 Transport Agent · santosomar bundleAnalyze MITRE ATT&CK T1505.002 Transport Agent in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1505.002, Transport Agent, or enterprise ATT&CK. Adversaries may abuse Microsoft transport agents to establish persistent access to systems.
- ▌ Attack Ent T1542 001 System Firmware · santosomar bundleAnalyze MITRE ATT&CK T1542.001 System Firmware in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1542.001, System Firmware, or enterprise ATT&CK. Adversaries may modify system firmware to persist on systems.The BIOS (Basic Input/Output System) and The Unified Extensible Firmware Interface (UEFI) or Extensible Firmware Interface (EFI) are examples of system firmwa…
- ▌ Attack Ent T1543 002 Systemd Service · santosomar bundleAnalyze MITRE ATT&CK T1543.002 Systemd Service in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1543.002, Systemd Service, or enterprise ATT&CK. Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence.
- ▌ Attack Ent T1543 003 Windows Service · santosomar bundleAnalyze MITRE ATT&CK T1543.003 Windows Service in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1543.003, Windows Service, or enterprise ATT&CK. Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence.
- ▌ Attack Ent T1550 003 Pass The Ticket · santosomar bundleAnalyze MITRE ATT&CK T1550.003 Pass the Ticket in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1550.003, Pass the Ticket, or enterprise ATT&CK. Adversaries may “pass the ticket” using stolen Kerberos tickets to move laterally within an environment, bypassing normal system access controls.
- ▌ Attack Ent T1556 007 Hybrid Identity · santosomar bundleAnalyze MITRE ATT&CK T1556.007 Hybrid Identity in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1556.007, Hybrid Identity, or enterprise ATT&CK. Adversaries may patch, modify, or otherwise backdoor cloud authentication processes that are tied to on-premises user identities in order to bypass typical authentication mechanisms, access credentials, and enable persi…
- ▌ Attack Ent T1558 004 As Rep Roasting · santosomar bundleAnalyze MITRE ATT&CK T1558.004 AS-REP Roasting in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1558.004, AS-REP Roasting, or enterprise ATT&CK. Adversaries may reveal credentials of accounts that have disabled Kerberos preauthentication by [Password Cracking](https://attack.mitre.org/techniques/T1110/002) Kerberos messages.(Citation: Harmj0y Roasting AS-REPs Ja…
- ▌ Attack Ent T1568 003 Dns Calculation · santosomar bundleAnalyze MITRE ATT&CK T1568.003 DNS Calculation in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1568.003, DNS Calculation, or enterprise ATT&CK. Adversaries may perform calculations on addresses returned in DNS results to determine which port and IP address to use for command and control, rather than relying on a predetermined port number or the actual returned…
- ▌ Attack Ent T1596 005 Scan Databases · santosomar bundleAnalyze MITRE ATT&CK T1596.005 Scan Databases in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1596.005, Scan Databases, or enterprise ATT&CK. Adversaries may search within public scan databases for information about victims that can be used during targeting.
- ▌ Attack Ent T1608 001 Upload Malware · santosomar bundleAnalyze MITRE ATT&CK T1608.001 Upload Malware in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1608.001, Upload Malware, or enterprise ATT&CK. Adversaries may upload malware to third-party or adversary controlled infrastructure to make it accessible during targeting.
- ▌ Attack Ent T1608 Stage Capabilities · santosomar bundleAnalyze MITRE ATT&CK T1608 Stage Capabilities in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1608, Stage Capabilities, or enterprise ATT&CK. Adversaries may upload, install, or otherwise set up capabilities that can be used during targeting.
- ▌ Attack Ent T1684 002 Email Spoofing · santosomar bundleAnalyze MITRE ATT&CK T1684.002 Email Spoofing in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1684.002, Email Spoofing, or enterprise ATT&CK. Adversaries may fake, or spoof, a sender’s identity by modifying the value of relevant email headers in order to establish contact with victims under false pretenses.(Citation: Proofpoint TA427 April 2024) In addition t…
- ▌ Attack Ent T1684 Social Engineering · santosomar bundleAnalyze MITRE ATT&CK T1684 Social Engineering in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1684, Social Engineering, or enterprise ATT&CK. Adversaries may use social engineering techniques to influence users to take actions that result in unauthorized access, approval of changes, disclosure of sensitive information, or execution of adversary-supplied instr…
- ▌ Attack Ent T1686 001 Cloud Firewall · santosomar bundleAnalyze MITRE ATT&CK T1686.001 Cloud Firewall in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1686.001, Cloud Firewall, or enterprise ATT&CK. Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.
- ▌ Attack Ics T0821 Modify Controller Tasking · santosomar bundleAnalyze MITRE ATT&CK T0821 Modify Controller Tasking in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0821, Modify Controller Tasking, or ics ATT&CK. Adversaries may modify the tasking of a controller to allow for the execution of their own programs.
- ▌ Attack Ics T0872 Indicator Removal On Host · santosomar bundleAnalyze MITRE ATT&CK T0872 Indicator Removal on Host in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0872, Indicator Removal on Host, or ics ATT&CK. Adversaries may attempt to remove indicators of their presence on a system in an effort to cover their tracks.
- ▌ Attack Ent T1136 002 Domain Account · santosomar bundleAnalyze MITRE ATT&CK T1136.002 Domain Account in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1136.002, Domain Account, or enterprise ATT&CK. Adversaries may create a domain account to maintain access to victim systems.
- ▌ Attack Ent T1176 002 Ide Extensions · santosomar bundleAnalyze MITRE ATT&CK T1176.002 IDE Extensions in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1176.002, IDE Extensions, or enterprise ATT&CK. Adversaries may abuse an integrated development environment (IDE) extension to establish persistent access to victim systems.(Citation: Mnemonic misuse visual studio) IDEs such as Visual Studio Code, IntelliJ IDEA, and…
- ▌ Attack Ent T1200 Hardware Additions · santosomar bundleAnalyze MITRE ATT&CK T1200 Hardware Additions in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1200, Hardware Additions, or enterprise ATT&CK. Adversaries may physically introduce computer accessories, networking hardware, or other computing devices into a system or network that can be used as a vector to gain access.
- ▌ Attack Ent T1204 001 Malicious Link · santosomar bundleAnalyze MITRE ATT&CK T1204.001 Malicious Link in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1204.001, Malicious Link, or enterprise ATT&CK. An adversary may rely upon a user clicking a malicious link in order to gain execution.
- ▌ Attack Ent T1204 002 Malicious File · santosomar bundleAnalyze MITRE ATT&CK T1204.002 Malicious File in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1204.002, Malicious File, or enterprise ATT&CK. An adversary may rely upon a user opening a malicious file in order to gain execution.
- ▌ Attack Ent T1205 002 Socket Filters · santosomar bundleAnalyze MITRE ATT&CK T1205.002 Socket Filters in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1205.002, Socket Filters, or enterprise ATT&CK. Adversaries may attach filters to a network socket to monitor then activate backdoors used for persistence or command and control.
- ▌ Attack Ent T1218 009 Regsvcs Regasm · santosomar bundleAnalyze MITRE ATT&CK T1218.009 Regsvcs/Regasm in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1218.009, Regsvcs/Regasm, or enterprise ATT&CK. Adversaries may abuse Regsvcs and Regasm to proxy execution of code through a trusted Windows utility.
- ▌ Attack Ent T1221 Template Injection · santosomar bundleAnalyze MITRE ATT&CK T1221 Template Injection in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1221, Template Injection, or enterprise ATT&CK. Adversaries may create or modify references in user document templates to conceal malicious code or force authentication attempts.
- ▌ Attack Ent T1552 008 Chat Messages · santosomar bundleAnalyze MITRE ATT&CK T1552.008 Chat Messages in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1552.008, Chat Messages, or enterprise ATT&CK. Adversaries may directly collect unsecured credentials stored or passed through user communication services.
- ▌ Attack Ent T1557 003 Dhcp Spoofing · santosomar bundleAnalyze MITRE ATT&CK T1557.003 DHCP Spoofing in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1557.003, DHCP Spoofing, or enterprise ATT&CK. Adversaries may redirect network traffic to adversary-owned systems by spoofing Dynamic Host Configuration Protocol (DHCP) traffic and acting as a malicious DHCP server on the victim network.
- ▌ Attack Ent T1558 001 Golden Ticket · santosomar bundleAnalyze MITRE ATT&CK T1558.001 Golden Ticket in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1558.001, Golden Ticket, or enterprise ATT&CK. Adversaries who have the KRBTGT account password hash may forge Kerberos ticket-granting tickets (TGT), also known as a golden ticket.(Citation: AdSecurity Kerberos GT Aug 2015) Golden tickets enable adversaries to gene…
- ▌ Attack Ent T1558 002 Silver Ticket · santosomar bundleAnalyze MITRE ATT&CK T1558.002 Silver Ticket in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1558.002, Silver Ticket, or enterprise ATT&CK. Adversaries who have the password hash of a target service account (e.g.
- ▌ Attack Ent T1558 003 Kerberoasting · santosomar bundleAnalyze MITRE ATT&CK T1558.003 Kerberoasting in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1558.003, Kerberoasting, or enterprise ATT&CK. Adversaries may abuse a valid Kerberos ticket-granting ticket (TGT) or sniff network traffic to obtain a ticket-granting service (TGS) ticket that may be vulnerable to [Brute Force](https://attack.mitre.org/techniques/T…
- ▌ Attack Ent T1563 001 Ssh Hijacking · santosomar bundleAnalyze MITRE ATT&CK T1563.001 SSH Hijacking in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1563.001, SSH Hijacking, or enterprise ATT&CK. Adversaries may hijack a legitimate user's SSH session to move laterally within an environment.
- ▌ Attack Ent T1563 002 Rdp Hijacking · santosomar bundleAnalyze MITRE ATT&CK T1563.002 RDP Hijacking in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1563.002, RDP Hijacking, or enterprise ATT&CK. Adversaries may hijack a legitimate user’s remote desktop session to move laterally within an environment.
- ▌ Attack Ent T1070 Indicator Removal · santosomar bundleAnalyze MITRE ATT&CK T1070 Indicator Removal in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1070, Indicator Removal, or enterprise ATT&CK. Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity.
- ▌ Attack Ent T1071 001 Web Protocols · santosomar bundleAnalyze MITRE ATT&CK T1071.001 Web Protocols in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1071.001, Web Protocols, or enterprise ATT&CK. Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic.
- ▌ Attack Ent T1087 001 Local Account · santosomar bundleAnalyze MITRE ATT&CK T1087.001 Local Account in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1087.001, Local Account, or enterprise ATT&CK. Adversaries may attempt to get a listing of local system accounts.
- ▌ Attack Ent T1087 003 Email Account · santosomar bundleAnalyze MITRE ATT&CK T1087.003 Email Account in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1087.003, Email Account, or enterprise ATT&CK. Adversaries may attempt to get a listing of email addresses and accounts.
- ▌ Attack Ent T1087 004 Cloud Account · santosomar bundleAnalyze MITRE ATT&CK T1087.004 Cloud Account in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1087.004, Cloud Account, or enterprise ATT&CK. Adversaries may attempt to get a listing of cloud accounts.
- ▌ Attack Ent T1496 Resource Hijacking · santosomar bundleAnalyze MITRE ATT&CK T1496 Resource Hijacking in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1496, Resource Hijacking, or enterprise ATT&CK. Adversaries may leverage the resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.
- ▌ Attack Ent T1505 004 Iis Components · santosomar bundleAnalyze MITRE ATT&CK T1505.004 IIS Components in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1505.004, IIS Components, or enterprise ATT&CK. Adversaries may install malicious components that run on Internet Information Services (IIS) web servers to establish persistence.
- ▌ Attack Ent T1518 Software Discovery · santosomar bundleAnalyze MITRE ATT&CK T1518 Software Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1518, Software Discovery, or enterprise ATT&CK. Adversaries may attempt to get a listing of software and software versions that are installed on a system or in a cloud environment.
- ▌ Attack Ent T1547 003 Time Providers · santosomar bundleAnalyze MITRE ATT&CK T1547.003 Time Providers in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1547.003, Time Providers, or enterprise ATT&CK. Adversaries may abuse time providers to execute DLLs when the system boots.
- ▌ Attack Ent T1568 Dynamic Resolution · santosomar bundleAnalyze MITRE ATT&CK T1568 Dynamic Resolution in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1568, Dynamic Resolution, or enterprise ATT&CK. Adversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations.
- ▌ Attack Ent T1572 Protocol Tunneling · santosomar bundleAnalyze MITRE ATT&CK T1572 Protocol Tunneling in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1572, Protocol Tunneling, or enterprise ATT&CK. Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems.
- ▌ Attack Ent T1585 002 Email Accounts · santosomar bundleAnalyze MITRE ATT&CK T1585.002 Email Accounts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1585.002, Email Accounts, or enterprise ATT&CK. Adversaries may create email accounts that can be used during targeting.
- ▌ Attack Ent T1564 003 Hidden Window · santosomar bundleAnalyze MITRE ATT&CK T1564.003 Hidden Window in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1564.003, Hidden Window, or enterprise ATT&CK. Adversaries may use hidden windows to conceal malicious activity from the plain sight of users.
- ▌ Attack Ent T1565 Data Manipulation · santosomar bundleAnalyze MITRE ATT&CK T1565 Data Manipulation in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1565, Data Manipulation, or enterprise ATT&CK. Adversaries may insert, delete, or manipulate data in order to influence external outcomes or hide activity, thus threatening the integrity of the data.(Citation: Sygnia Elephant Beetle Jan 2022) By manipulating data, a…
- ▌ Attack Ent T1568 001 Fast Flux Dns · santosomar bundleAnalyze MITRE ATT&CK T1568.001 Fast Flux DNS in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1568.001, Fast Flux DNS, or enterprise ATT&CK. Adversaries may use Fast Flux DNS to hide a command and control channel behind an array of rapidly changing IP addresses linked to a single domain resolution.
- ▌ Attack Ent T1571 Non Standard Port · santosomar bundleAnalyze MITRE ATT&CK T1571 Non-Standard Port in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1571, Non-Standard Port, or enterprise ATT&CK. Adversaries may communicate using a protocol and port pairing that are typically not associated.
- ▌ Attack Ent T1573 Encrypted Channel · santosomar bundleAnalyze MITRE ATT&CK T1573 Encrypted Channel in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1573, Encrypted Channel, or enterprise ATT&CK. Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
- ▌ Attack Ent T1600 Weaken Encryption · santosomar bundleAnalyze MITRE ATT&CK T1600 Weaken Encryption in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1600, Weaken Encryption, or enterprise ATT&CK. Adversaries may compromise a network device’s encryption capability in order to bypass encryption that would otherwise protect data communications.(Citation: Cisco Synful Knock Evolution) Encryption can be used to prote…
- ▌ Attack Ent T1602 001 Snmp Mib Dump · santosomar bundleAnalyze MITRE ATT&CK T1602.001 SNMP (MIB Dump) in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1602.001, SNMP (MIB Dump), or enterprise ATT&CK. Adversaries may target the Management Information Base (MIB) to collect and/or mine valuable information in a network managed using Simple Network Management Protocol (SNMP).
- ▌ Attack Ics T1694 001 Default Credentials · santosomar bundleAnalyze MITRE ATT&CK T1694.001 Default Credentials in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1694.001, Default Credentials, or ics ATT&CK. Adversaries may leverage manufacturer or supplier set default credentials on control system devices.
- ▌ Attack Mob T1406 002 Software Packing · santosomar bundleAnalyze MITRE ATT&CK T1406.002 Software Packing in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1406.002, Software Packing, or mobile ATT&CK. Adversaries may perform software packing to conceal their code.
- ▌ Attack Mob T1517 Access Notifications · santosomar bundleAnalyze MITRE ATT&CK T1517 Access Notifications in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1517, Access Notifications, or mobile ATT&CK. Adversaries may collect data within notifications sent by the operating system or other applications.
- ▌ Attack Mob T1604 Proxy Through Victim · santosomar bundleAnalyze MITRE ATT&CK T1604 Proxy Through Victim in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1604, Proxy Through Victim, or mobile ATT&CK. Adversaries may use a compromised device as a proxy server to the Internet.
- ▌ Attack Mob T1627 Execution Guardrails · santosomar bundleAnalyze MITRE ATT&CK T1627 Execution Guardrails in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1627, Execution Guardrails, or mobile ATT&CK. Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target.
- ▌ Attack Mob T1636 001 Calendar Entries · santosomar bundleAnalyze MITRE ATT&CK T1636.001 Calendar Entries in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1636.001, Calendar Entries, or mobile ATT&CK. Adversaries may utilize standard operating system APIs to gather calendar entry data.
- ▌ Attack Ent T1001 002 Steganography · santosomar bundleAnalyze MITRE ATT&CK T1001.002 Steganography in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1001.002, Steganography, or enterprise ATT&CK. Adversaries may use steganographic techniques to hide command and control traffic to make detection efforts more difficult.
- ▌ Attack Ent T1008 Fallback Channels · santosomar bundleAnalyze MITRE ATT&CK T1008 Fallback Channels in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1008, Fallback Channels, or enterprise ATT&CK. Adversaries may use fallback or alternate communication channels if the primary channel is compromised or inaccessible in order to maintain reliable command and control and to avoid data transfer thresholds.
- ▌ Attack Ent T1059 012 Hypervisor CLI · santosomar bundleAnalyze MITRE ATT&CK T1059.012 Hypervisor CLI in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1059.012, Hypervisor CLI, or enterprise ATT&CK. Adversaries may abuse hypervisor command line interpreters (CLIs) to execute malicious commands.
- ▌ Attack Ent T1071 003 Mail Protocols · santosomar bundleAnalyze MITRE ATT&CK T1071.003 Mail Protocols in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1071.003, Mail Protocols, or enterprise ATT&CK. Adversaries may communicate using application layer protocols associated with electronic mail delivery to avoid detection/network filtering by blending in with existing traffic.