← all publishers

santosomar

@santosomar source repo

800 published skills · page 5 of 8

  1. Attack Ent T1578 001 Create Snapshot · santosomar bundle
    Analyze MITRE ATT&CK T1578.001 Create Snapshot in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1578.001, Create Snapshot, or enterprise ATT&CK. An adversary may create a snapshot or data backup within a cloud account to evade defenses.
    0 installs
  2. Attack Ent T1584 008 Network Devices · santosomar bundle
    Analyze MITRE ATT&CK T1584.008 Network Devices in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1584.008, Network Devices, or enterprise ATT&CK. Adversaries may compromise third-party network devices that can be used during targeting.
    0 installs
  3. Attack Ent T1586 Compromise Accounts · santosomar bundle
    Analyze MITRE ATT&CK T1586 Compromise Accounts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1586, Compromise Accounts, or enterprise ATT&CK. Adversaries may compromise accounts with services that can be used during targeting.
    0 installs
  4. Attack Ent T1588 006 Vulnerabilities · santosomar bundle
    Analyze MITRE ATT&CK T1588.006 Vulnerabilities in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1588.006, Vulnerabilities, or enterprise ATT&CK. Adversaries may acquire information about vulnerabilities that can be used during targeting.
    0 installs
  5. Attack Ent T1588 Obtain Capabilities · santosomar bundle
    Analyze MITRE ATT&CK T1588 Obtain Capabilities in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1588, Obtain Capabilities, or enterprise ATT&CK. Adversaries may buy and/or steal capabilities that can be used during targeting.
    0 installs
  6. Attack Ent T1589 002 Email Addresses · santosomar bundle
    Analyze MITRE ATT&CK T1589.002 Email Addresses in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1589.002, Email Addresses, or enterprise ATT&CK. Adversaries may gather email addresses that can be used during targeting.
    0 installs
  7. Attack Ent T1029 Scheduled Transfer · santosomar bundle
    Analyze MITRE ATT&CK T1029 Scheduled Transfer in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1029, Scheduled Transfer, or enterprise ATT&CK. Adversaries may schedule data exfiltration to be performed only at certain times of day or at certain intervals.
    0 installs
  8. Attack Ent T1053 005 Scheduled Task · santosomar bundle
    Analyze MITRE ATT&CK T1053.005 Scheduled Task in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1053.005, Scheduled Task, or enterprise ATT&CK. Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code.
    0 installs
  9. Attack Ent T1053 006 Systemd Timers · santosomar bundle
    Analyze MITRE ATT&CK T1053.006 Systemd Timers in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1053.006, Systemd Timers, or enterprise ATT&CK. Adversaries may abuse systemd timers to perform task scheduling for initial or recurring execution of malicious code.
    0 installs
  10. Attack Ent T1053 Scheduled Task Job · santosomar bundle
    Analyze MITRE ATT&CK T1053 Scheduled Task/Job in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1053, Scheduled Task/Job, or enterprise ATT&CK. Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code.
    0 installs
  11. Attack Ent T1055 014 Vdso Hijacking · santosomar bundle
    Analyze MITRE ATT&CK T1055.014 VDSO Hijacking in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1055.014, VDSO Hijacking, or enterprise ATT&CK. Adversaries may inject malicious code into processes via VDSO hijacking in order to evade process-based defenses as well as possibly elevate privileges.
    0 installs
  12. Attack Ics T1694 002 Hardcoded Credentials · santosomar bundle
    Analyze MITRE ATT&CK T1694.002 Hardcoded Credentials in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1694.002, Hardcoded Credentials, or ics ATT&CK. Adversaries may leverage credentials that are hardcoded in software or firmware to gain an unauthorized interactive user session to an asset.
    0 installs
  13. Attack Mob T1481 001 Dead Drop Resolver · santosomar bundle
    Analyze MITRE ATT&CK T1481.001 Dead Drop Resolver in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1481.001, Dead Drop Resolver, or mobile ATT&CK. Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure.
    0 installs
  14. Attack Mob T1532 Archive Collected Data · santosomar bundle
    Analyze MITRE ATT&CK T1532 Archive Collected Data in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1532, Archive Collected Data, or mobile ATT&CK. Adversaries may compress and/or encrypt data that is collected prior to exfiltration.
    0 installs
  15. Attack Mob T1533 Data From Local System · santosomar bundle
    Analyze MITRE ATT&CK T1533 Data from Local System in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1533, Data from Local System, or mobile ATT&CK. Adversaries may search local system sources, such as file systems or local databases, to find files of interest and sensitive data prior to exfiltration.
    0 installs
  16. Attack Mob T1541 Foreground Persistence · santosomar bundle
    Analyze MITRE ATT&CK T1541 Foreground Persistence in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1541, Foreground Persistence, or mobile ATT&CK. Adversaries may abuse Android's `startForeground()` API method to maintain continuous sensor access.
    0 installs
  17. Attack Mob T1632 Subvert Trust Controls · santosomar bundle
    Analyze MITRE ATT&CK T1632 Subvert Trust Controls in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1632, Subvert Trust Controls, or mobile ATT&CK. Adversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted applications.
    0 installs
  18. Attack Mob T1640 Account Access Removal · santosomar bundle
    Analyze MITRE ATT&CK T1640 Account Access Removal in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1640, Account Access Removal, or mobile ATT&CK. Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users.
    0 installs
  19. Attack Ent T1090 003 Multi Hop Proxy · santosomar bundle
    Analyze MITRE ATT&CK T1090.003 Multi-hop Proxy in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1090.003, Multi-hop Proxy, or enterprise ATT&CK. Adversaries may chain together multiple proxies to disguise the source of malicious traffic.
    0 installs
  20. Attack Ent T1090 004 Domain Fronting · santosomar bundle
    Analyze MITRE ATT&CK T1090.004 Domain Fronting in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1090.004, Domain Fronting, or enterprise ATT&CK. Adversaries may take advantage of routing schemes in Content Delivery Networks (CDNs) and other services which host multiple domains to obfuscate the intended destination of HTTPS traffic or traffic tunneled through HTT…
    0 installs
  21. Attack Ent T1176 Software Extensions · santosomar bundle
    Analyze MITRE ATT&CK T1176 Software Extensions in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1176, Software Extensions, or enterprise ATT&CK. Adversaries may abuse software extensions to establish persistent access to victim systems.
    0 installs
  22. Attack Ent T1189 Drive By Compromise · santosomar bundle
    Analyze MITRE ATT&CK T1189 Drive-by Compromise in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1189, Drive-by Compromise, or enterprise ATT&CK. Adversaries may gain access to a system through a user visiting a website over the normal course of browsing.
    0 installs
  23. Attack Ent T1204 003 Malicious Image · santosomar bundle
    Analyze MITRE ATT&CK T1204.003 Malicious Image in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1204.003, Malicious Image, or enterprise ATT&CK. Adversaries may rely on a user running a malicious image to facilitate execution.
    0 installs
  24. Attack Ent T1219 Remote Access Tools · santosomar bundle
    Analyze MITRE ATT&CK T1219 Remote Access Tools in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1219, Remote Access Tools, or enterprise ATT&CK. An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network.
    0 installs
  25. Attack Ent T1495 Firmware Corruption · santosomar bundle
    Analyze MITRE ATT&CK T1495 Firmware Corruption in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1495, Firmware Corruption, or enterprise ATT&CK. Adversaries may overwrite or corrupt the flash memory contents of system BIOS or other firmware in devices attached to a system in order to render them inoperable or unable to boot, thus denying the availability to use…
    0 installs
  26. Attack Ent T1585 003 Cloud Accounts · santosomar bundle
    Analyze MITRE ATT&CK T1585.003 Cloud Accounts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1585.003, Cloud Accounts, or enterprise ATT&CK. Adversaries may create accounts with cloud providers that can be used during targeting.
    0 installs
  27. Attack Ent T1585 Establish Accounts · santosomar bundle
    Analyze MITRE ATT&CK T1585 Establish Accounts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1585, Establish Accounts, or enterprise ATT&CK. Adversaries may create and cultivate accounts with services that can be used during targeting.
    0 installs
  28. Attack Ent T1586 002 Email Accounts · santosomar bundle
    Analyze MITRE ATT&CK T1586.002 Email Accounts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1586.002, Email Accounts, or enterprise ATT&CK. Adversaries may compromise email accounts that can be used during targeting.
    0 installs
  29. Attack Ent T1586 003 Cloud Accounts · santosomar bundle
    Analyze MITRE ATT&CK T1586.003 Cloud Accounts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1586.003, Cloud Accounts, or enterprise ATT&CK. Adversaries may compromise cloud accounts that can be used during targeting.
    0 installs
  30. Attack Ent T1589 003 Employee Names · santosomar bundle
    Analyze MITRE ATT&CK T1589.003 Employee Names in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1589.003, Employee Names, or enterprise ATT&CK. Adversaries may gather employee names that can be used during targeting.
    0 installs
  31. Attack Ent T1591 004 Identify Roles · santosomar bundle
    Analyze MITRE ATT&CK T1591.004 Identify Roles in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1591.004, Identify Roles, or enterprise ATT&CK. Adversaries may gather information about identities and roles within the victim organization that can be used during targeting.
    0 installs
  32. Attack Ent T1593 002 Search Engines · santosomar bundle
    Analyze MITRE ATT&CK T1593.002 Search Engines in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1593.002, Search Engines, or enterprise ATT&CK. Adversaries may use search engines to collect information about victims that can be used during targeting.
    0 installs
  33. Attack Ent T1608 006 SEO Poisoning · santosomar bundle
    Analyze MITRE ATT&CK T1608.006 SEO Poisoning in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1608.006, SEO Poisoning, or enterprise ATT&CK. Adversaries may poison mechanisms that influence search engine optimization (SEO) to further lure staged capabilities towards potential victims.
    0 installs
  34. Attack Ent T1659 Content Injection · santosomar bundle
    Analyze MITRE ATT&CK T1659 Content Injection in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1659, Content Injection, or enterprise ATT&CK. Adversaries may gain access and continuously communicate with victims by injecting malicious content into systems through online network traffic.
    0 installs
  35. Attack Ent T1668 Exclusive Control · santosomar bundle
    Analyze MITRE ATT&CK T1668 Exclusive Control in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1668, Exclusive Control, or enterprise ATT&CK. Adversaries who successfully compromise a system may attempt to maintain persistence by “closing the door” behind them – in other words, by preventing other threat actors from initially accessing or maintaining a footho…
    0 installs
  36. Attack Ent T1684 001 Impersonation · santosomar bundle
    Analyze MITRE ATT&CK T1684.001 Impersonation in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1684.001, Impersonation, or enterprise ATT&CK. Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf.
    0 installs
  37. Attack Ics T0820 Exploitation For Evasion · santosomar bundle
    Analyze MITRE ATT&CK T0820 Exploitation for Evasion in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0820, Exploitation for Evasion, or ics ATT&CK. Adversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself to evade detection.
    0 installs
  38. Attack Ics T0822 External Remote Services · santosomar bundle
    Analyze MITRE ATT&CK T0822 External Remote Services in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0822, External Remote Services, or ics ATT&CK. Adversaries may leverage external remote services as a point of initial access into your network.
    0 installs
  39. Attack Ics T0823 Graphical User Interface · santosomar bundle
    Analyze MITRE ATT&CK T0823 Graphical User Interface in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0823, Graphical User Interface, or ics ATT&CK. Adversaries may attempt to gain access to a machine via a Graphical User Interface (GUI) to enhance execution capabilities.
    0 installs
  40. Attack Ics T0861 Point Tag Identification · santosomar bundle
    Analyze MITRE ATT&CK T0861 Point & Tag Identification in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0861, Point & Tag Identification, or ics ATT&CK. Adversaries may collect point and tag values to gain a more comprehensive understanding of the process environment.
    0 installs
  41. Attack Ent T1505 002 Transport Agent · santosomar bundle
    Analyze MITRE ATT&CK T1505.002 Transport Agent in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1505.002, Transport Agent, or enterprise ATT&CK. Adversaries may abuse Microsoft transport agents to establish persistent access to systems.
    0 installs
  42. Attack Ent T1542 001 System Firmware · santosomar bundle
    Analyze MITRE ATT&CK T1542.001 System Firmware in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1542.001, System Firmware, or enterprise ATT&CK. Adversaries may modify system firmware to persist on systems.The BIOS (Basic Input/Output System) and The Unified Extensible Firmware Interface (UEFI) or Extensible Firmware Interface (EFI) are examples of system firmwa…
    0 installs
  43. Attack Ent T1543 002 Systemd Service · santosomar bundle
    Analyze MITRE ATT&CK T1543.002 Systemd Service in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1543.002, Systemd Service, or enterprise ATT&CK. Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence.
    0 installs
  44. Attack Ent T1543 003 Windows Service · santosomar bundle
    Analyze MITRE ATT&CK T1543.003 Windows Service in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1543.003, Windows Service, or enterprise ATT&CK. Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence.
    0 installs
  45. Attack Ent T1550 003 Pass The Ticket · santosomar bundle
    Analyze MITRE ATT&CK T1550.003 Pass the Ticket in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1550.003, Pass the Ticket, or enterprise ATT&CK. Adversaries may “pass the ticket” using stolen Kerberos tickets to move laterally within an environment, bypassing normal system access controls.
    0 installs
  46. Attack Ent T1556 007 Hybrid Identity · santosomar bundle
    Analyze MITRE ATT&CK T1556.007 Hybrid Identity in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1556.007, Hybrid Identity, or enterprise ATT&CK. Adversaries may patch, modify, or otherwise backdoor cloud authentication processes that are tied to on-premises user identities in order to bypass typical authentication mechanisms, access credentials, and enable persi…
    0 installs
  47. Attack Ent T1558 004 As Rep Roasting · santosomar bundle
    Analyze MITRE ATT&CK T1558.004 AS-REP Roasting in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1558.004, AS-REP Roasting, or enterprise ATT&CK. Adversaries may reveal credentials of accounts that have disabled Kerberos preauthentication by [Password Cracking](https://attack.mitre.org/techniques/T1110/002) Kerberos messages.(Citation: Harmj0y Roasting AS-REPs Ja…
    0 installs
  48. Attack Ent T1568 003 Dns Calculation · santosomar bundle
    Analyze MITRE ATT&CK T1568.003 DNS Calculation in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1568.003, DNS Calculation, or enterprise ATT&CK. Adversaries may perform calculations on addresses returned in DNS results to determine which port and IP address to use for command and control, rather than relying on a predetermined port number or the actual returned…
    0 installs
  49. Attack Ent T1596 005 Scan Databases · santosomar bundle
    Analyze MITRE ATT&CK T1596.005 Scan Databases in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1596.005, Scan Databases, or enterprise ATT&CK. Adversaries may search within public scan databases for information about victims that can be used during targeting.
    0 installs
  50. Attack Ent T1608 001 Upload Malware · santosomar bundle
    Analyze MITRE ATT&CK T1608.001 Upload Malware in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1608.001, Upload Malware, or enterprise ATT&CK. Adversaries may upload malware to third-party or adversary controlled infrastructure to make it accessible during targeting.
    0 installs
  51. Attack Ent T1608 Stage Capabilities · santosomar bundle
    Analyze MITRE ATT&CK T1608 Stage Capabilities in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1608, Stage Capabilities, or enterprise ATT&CK. Adversaries may upload, install, or otherwise set up capabilities that can be used during targeting.
    0 installs
  52. Attack Ent T1684 002 Email Spoofing · santosomar bundle
    Analyze MITRE ATT&CK T1684.002 Email Spoofing in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1684.002, Email Spoofing, or enterprise ATT&CK. Adversaries may fake, or spoof, a sender’s identity by modifying the value of relevant email headers in order to establish contact with victims under false pretenses.(Citation: Proofpoint TA427 April 2024) In addition t…
    0 installs
  53. Attack Ent T1684 Social Engineering · santosomar bundle
    Analyze MITRE ATT&CK T1684 Social Engineering in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1684, Social Engineering, or enterprise ATT&CK. Adversaries may use social engineering techniques to influence users to take actions that result in unauthorized access, approval of changes, disclosure of sensitive information, or execution of adversary-supplied instr…
    0 installs
  54. Attack Ent T1686 001 Cloud Firewall · santosomar bundle
    Analyze MITRE ATT&CK T1686.001 Cloud Firewall in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1686.001, Cloud Firewall, or enterprise ATT&CK. Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.
    0 installs
  55. Attack Ics T0821 Modify Controller Tasking · santosomar bundle
    Analyze MITRE ATT&CK T0821 Modify Controller Tasking in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0821, Modify Controller Tasking, or ics ATT&CK. Adversaries may modify the tasking of a controller to allow for the execution of their own programs.
    0 installs
  56. Attack Ics T0872 Indicator Removal On Host · santosomar bundle
    Analyze MITRE ATT&CK T0872 Indicator Removal on Host in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0872, Indicator Removal on Host, or ics ATT&CK. Adversaries may attempt to remove indicators of their presence on a system in an effort to cover their tracks.
    0 installs
  57. Attack Ent T1136 002 Domain Account · santosomar bundle
    Analyze MITRE ATT&CK T1136.002 Domain Account in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1136.002, Domain Account, or enterprise ATT&CK. Adversaries may create a domain account to maintain access to victim systems.
    0 installs
  58. Attack Ent T1176 002 Ide Extensions · santosomar bundle
    Analyze MITRE ATT&CK T1176.002 IDE Extensions in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1176.002, IDE Extensions, or enterprise ATT&CK. Adversaries may abuse an integrated development environment (IDE) extension to establish persistent access to victim systems.(Citation: Mnemonic misuse visual studio) IDEs such as Visual Studio Code, IntelliJ IDEA, and…
    0 installs
  59. Attack Ent T1200 Hardware Additions · santosomar bundle
    Analyze MITRE ATT&CK T1200 Hardware Additions in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1200, Hardware Additions, or enterprise ATT&CK. Adversaries may physically introduce computer accessories, networking hardware, or other computing devices into a system or network that can be used as a vector to gain access.
    0 installs
  60. Attack Ent T1204 001 Malicious Link · santosomar bundle
    Analyze MITRE ATT&CK T1204.001 Malicious Link in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1204.001, Malicious Link, or enterprise ATT&CK. An adversary may rely upon a user clicking a malicious link in order to gain execution.
    0 installs
  61. Attack Ent T1204 002 Malicious File · santosomar bundle
    Analyze MITRE ATT&CK T1204.002 Malicious File in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1204.002, Malicious File, or enterprise ATT&CK. An adversary may rely upon a user opening a malicious file in order to gain execution.
    0 installs
  62. Attack Ent T1205 002 Socket Filters · santosomar bundle
    Analyze MITRE ATT&CK T1205.002 Socket Filters in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1205.002, Socket Filters, or enterprise ATT&CK. Adversaries may attach filters to a network socket to monitor then activate backdoors used for persistence or command and control.
    0 installs
  63. Attack Ent T1218 009 Regsvcs Regasm · santosomar bundle
    Analyze MITRE ATT&CK T1218.009 Regsvcs/Regasm in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1218.009, Regsvcs/Regasm, or enterprise ATT&CK. Adversaries may abuse Regsvcs and Regasm to proxy execution of code through a trusted Windows utility.
    0 installs
  64. Attack Ent T1221 Template Injection · santosomar bundle
    Analyze MITRE ATT&CK T1221 Template Injection in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1221, Template Injection, or enterprise ATT&CK. Adversaries may create or modify references in user document templates to conceal malicious code or force authentication attempts.
    0 installs
  65. Attack Ent T1552 008 Chat Messages · santosomar bundle
    Analyze MITRE ATT&CK T1552.008 Chat Messages in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1552.008, Chat Messages, or enterprise ATT&CK. Adversaries may directly collect unsecured credentials stored or passed through user communication services.
    0 installs
  66. Attack Ent T1557 003 Dhcp Spoofing · santosomar bundle
    Analyze MITRE ATT&CK T1557.003 DHCP Spoofing in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1557.003, DHCP Spoofing, or enterprise ATT&CK. Adversaries may redirect network traffic to adversary-owned systems by spoofing Dynamic Host Configuration Protocol (DHCP) traffic and acting as a malicious DHCP server on the victim network.
    0 installs
  67. Attack Ent T1558 001 Golden Ticket · santosomar bundle
    Analyze MITRE ATT&CK T1558.001 Golden Ticket in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1558.001, Golden Ticket, or enterprise ATT&CK. Adversaries who have the KRBTGT account password hash may forge Kerberos ticket-granting tickets (TGT), also known as a golden ticket.(Citation: AdSecurity Kerberos GT Aug 2015) Golden tickets enable adversaries to gene…
    0 installs
  68. Attack Ent T1558 002 Silver Ticket · santosomar bundle
    Analyze MITRE ATT&CK T1558.002 Silver Ticket in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1558.002, Silver Ticket, or enterprise ATT&CK. Adversaries who have the password hash of a target service account (e.g.
    0 installs
  69. Attack Ent T1558 003 Kerberoasting · santosomar bundle
    Analyze MITRE ATT&CK T1558.003 Kerberoasting in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1558.003, Kerberoasting, or enterprise ATT&CK. Adversaries may abuse a valid Kerberos ticket-granting ticket (TGT) or sniff network traffic to obtain a ticket-granting service (TGS) ticket that may be vulnerable to [Brute Force](https://attack.mitre.org/techniques/T…
    0 installs
  70. Attack Ent T1563 001 Ssh Hijacking · santosomar bundle
    Analyze MITRE ATT&CK T1563.001 SSH Hijacking in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1563.001, SSH Hijacking, or enterprise ATT&CK. Adversaries may hijack a legitimate user's SSH session to move laterally within an environment.
    0 installs
  71. Attack Ent T1563 002 Rdp Hijacking · santosomar bundle
    Analyze MITRE ATT&CK T1563.002 RDP Hijacking in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1563.002, RDP Hijacking, or enterprise ATT&CK. Adversaries may hijack a legitimate user’s remote desktop session to move laterally within an environment.
    0 installs
  72. Attack Ent T1070 Indicator Removal · santosomar bundle
    Analyze MITRE ATT&CK T1070 Indicator Removal in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1070, Indicator Removal, or enterprise ATT&CK. Adversaries may selectively delete or modify artifacts generated to reduce indications of their presence and blend in with legitimate activity.
    0 installs
  73. Attack Ent T1071 001 Web Protocols · santosomar bundle
    Analyze MITRE ATT&CK T1071.001 Web Protocols in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1071.001, Web Protocols, or enterprise ATT&CK. Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic.
    0 installs
  74. Attack Ent T1087 001 Local Account · santosomar bundle
    Analyze MITRE ATT&CK T1087.001 Local Account in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1087.001, Local Account, or enterprise ATT&CK. Adversaries may attempt to get a listing of local system accounts.
    0 installs
  75. Attack Ent T1087 003 Email Account · santosomar bundle
    Analyze MITRE ATT&CK T1087.003 Email Account in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1087.003, Email Account, or enterprise ATT&CK. Adversaries may attempt to get a listing of email addresses and accounts.
    0 installs
  76. Attack Ent T1087 004 Cloud Account · santosomar bundle
    Analyze MITRE ATT&CK T1087.004 Cloud Account in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1087.004, Cloud Account, or enterprise ATT&CK. Adversaries may attempt to get a listing of cloud accounts.
    0 installs
  77. Attack Ent T1496 Resource Hijacking · santosomar bundle
    Analyze MITRE ATT&CK T1496 Resource Hijacking in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1496, Resource Hijacking, or enterprise ATT&CK. Adversaries may leverage the resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.
    0 installs
  78. Attack Ent T1505 004 Iis Components · santosomar bundle
    Analyze MITRE ATT&CK T1505.004 IIS Components in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1505.004, IIS Components, or enterprise ATT&CK. Adversaries may install malicious components that run on Internet Information Services (IIS) web servers to establish persistence.
    0 installs
  79. Attack Ent T1518 Software Discovery · santosomar bundle
    Analyze MITRE ATT&CK T1518 Software Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1518, Software Discovery, or enterprise ATT&CK. Adversaries may attempt to get a listing of software and software versions that are installed on a system or in a cloud environment.
    0 installs
  80. Attack Ent T1547 003 Time Providers · santosomar bundle
    Analyze MITRE ATT&CK T1547.003 Time Providers in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1547.003, Time Providers, or enterprise ATT&CK. Adversaries may abuse time providers to execute DLLs when the system boots.
    0 installs
  81. Attack Ent T1568 Dynamic Resolution · santosomar bundle
    Analyze MITRE ATT&CK T1568 Dynamic Resolution in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1568, Dynamic Resolution, or enterprise ATT&CK. Adversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations.
    0 installs
  82. Attack Ent T1572 Protocol Tunneling · santosomar bundle
    Analyze MITRE ATT&CK T1572 Protocol Tunneling in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1572, Protocol Tunneling, or enterprise ATT&CK. Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems.
    0 installs
  83. Attack Ent T1585 002 Email Accounts · santosomar bundle
    Analyze MITRE ATT&CK T1585.002 Email Accounts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1585.002, Email Accounts, or enterprise ATT&CK. Adversaries may create email accounts that can be used during targeting.
    0 installs
  84. Attack Ent T1564 003 Hidden Window · santosomar bundle
    Analyze MITRE ATT&CK T1564.003 Hidden Window in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1564.003, Hidden Window, or enterprise ATT&CK. Adversaries may use hidden windows to conceal malicious activity from the plain sight of users.
    0 installs
  85. Attack Ent T1565 Data Manipulation · santosomar bundle
    Analyze MITRE ATT&CK T1565 Data Manipulation in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1565, Data Manipulation, or enterprise ATT&CK. Adversaries may insert, delete, or manipulate data in order to influence external outcomes or hide activity, thus threatening the integrity of the data.(Citation: Sygnia Elephant Beetle Jan 2022) By manipulating data, a…
    0 installs
  86. Attack Ent T1568 001 Fast Flux Dns · santosomar bundle
    Analyze MITRE ATT&CK T1568.001 Fast Flux DNS in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1568.001, Fast Flux DNS, or enterprise ATT&CK. Adversaries may use Fast Flux DNS to hide a command and control channel behind an array of rapidly changing IP addresses linked to a single domain resolution.
    0 installs
  87. Attack Ent T1571 Non Standard Port · santosomar bundle
    Analyze MITRE ATT&CK T1571 Non-Standard Port in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1571, Non-Standard Port, or enterprise ATT&CK. Adversaries may communicate using a protocol and port pairing that are typically not associated.
    0 installs
  88. Attack Ent T1573 Encrypted Channel · santosomar bundle
    Analyze MITRE ATT&CK T1573 Encrypted Channel in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1573, Encrypted Channel, or enterprise ATT&CK. Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
    0 installs
  89. Attack Ent T1600 Weaken Encryption · santosomar bundle
    Analyze MITRE ATT&CK T1600 Weaken Encryption in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1600, Weaken Encryption, or enterprise ATT&CK. Adversaries may compromise a network device’s encryption capability in order to bypass encryption that would otherwise protect data communications.(Citation: Cisco Synful Knock Evolution) Encryption can be used to prote…
    0 installs
  90. Attack Ent T1602 001 Snmp Mib Dump · santosomar bundle
    Analyze MITRE ATT&CK T1602.001 SNMP (MIB Dump) in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1602.001, SNMP (MIB Dump), or enterprise ATT&CK. Adversaries may target the Management Information Base (MIB) to collect and/or mine valuable information in a network managed using Simple Network Management Protocol (SNMP).
    0 installs
  91. Attack Ics T1694 001 Default Credentials · santosomar bundle
    Analyze MITRE ATT&CK T1694.001 Default Credentials in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1694.001, Default Credentials, or ics ATT&CK. Adversaries may leverage manufacturer or supplier set default credentials on control system devices.
    0 installs
  92. Attack Mob T1406 002 Software Packing · santosomar bundle
    Analyze MITRE ATT&CK T1406.002 Software Packing in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1406.002, Software Packing, or mobile ATT&CK. Adversaries may perform software packing to conceal their code.
    0 installs
  93. Attack Mob T1517 Access Notifications · santosomar bundle
    Analyze MITRE ATT&CK T1517 Access Notifications in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1517, Access Notifications, or mobile ATT&CK. Adversaries may collect data within notifications sent by the operating system or other applications.
    0 installs
  94. Attack Mob T1604 Proxy Through Victim · santosomar bundle
    Analyze MITRE ATT&CK T1604 Proxy Through Victim in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1604, Proxy Through Victim, or mobile ATT&CK. Adversaries may use a compromised device as a proxy server to the Internet.
    0 installs
  95. Attack Mob T1627 Execution Guardrails · santosomar bundle
    Analyze MITRE ATT&CK T1627 Execution Guardrails in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1627, Execution Guardrails, or mobile ATT&CK. Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target.
    0 installs
  96. Attack Mob T1636 001 Calendar Entries · santosomar bundle
    Analyze MITRE ATT&CK T1636.001 Calendar Entries in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1636.001, Calendar Entries, or mobile ATT&CK. Adversaries may utilize standard operating system APIs to gather calendar entry data.
    0 installs
  97. Attack Ent T1001 002 Steganography · santosomar bundle
    Analyze MITRE ATT&CK T1001.002 Steganography in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1001.002, Steganography, or enterprise ATT&CK. Adversaries may use steganographic techniques to hide command and control traffic to make detection efforts more difficult.
    0 installs
  98. Attack Ent T1008 Fallback Channels · santosomar bundle
    Analyze MITRE ATT&CK T1008 Fallback Channels in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1008, Fallback Channels, or enterprise ATT&CK. Adversaries may use fallback or alternate communication channels if the primary channel is compromised or inaccessible in order to maintain reliable command and control and to avoid data transfer thresholds.
    0 installs
  99. Attack Ent T1059 012 Hypervisor CLI · santosomar bundle
    Analyze MITRE ATT&CK T1059.012 Hypervisor CLI in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1059.012, Hypervisor CLI, or enterprise ATT&CK. Adversaries may abuse hypervisor command line interpreters (CLIs) to execute malicious commands.
    0 installs
  100. Attack Ent T1071 003 Mail Protocols · santosomar bundle
    Analyze MITRE ATT&CK T1071.003 Mail Protocols in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1071.003, Mail Protocols, or enterprise ATT&CK. Adversaries may communicate using application layer protocols associated with electronic mail delivery to avoid detection/network filtering by blending in with existing traffic.
    0 installs