santosomar
- 800 skills
- 0 followers
- 14 hours ago last updated
- ▌ Attack Ent T1078 003 Local Accounts · santosomar bundleAnalyze MITRE ATT&CK T1078.003 Local Accounts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1078.003, Local Accounts, or enterprise ATT&CK. Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
- ▌ Attack Ent T1078 004 Cloud Accounts · santosomar bundleAnalyze MITRE ATT&CK T1078.004 Cloud Accounts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1078.004, Cloud Accounts, or enterprise ATT&CK. Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
- ▌ Attack Ent T1087 002 Domain Account · santosomar bundleAnalyze MITRE ATT&CK T1087.002 Domain Account in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1087.002, Domain Account, or enterprise ATT&CK. Adversaries may attempt to get a listing of domain accounts.
- ▌ Attack Ent T1090 001 Internal Proxy · santosomar bundleAnalyze MITRE ATT&CK T1090.001 Internal Proxy in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1090.001, Internal Proxy, or enterprise ATT&CK. Adversaries may use an internal proxy to direct command and control traffic between two or more systems in a compromised environment.
- ▌ Attack Ent T1090 002 External Proxy · santosomar bundleAnalyze MITRE ATT&CK T1090.002 External Proxy in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1090.002, External Proxy, or enterprise ATT&CK. Adversaries may use an external proxy to act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure.
- ▌ Attack Ent T1218 002 Control Panel · santosomar bundleAnalyze MITRE ATT&CK T1218.002 Control Panel in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1218.002, Control Panel, or enterprise ATT&CK. Adversaries may abuse control.exe to proxy execution of malicious payloads.
- ▌ Attack Ent T1219 001 Ide Tunneling · santosomar bundleAnalyze MITRE ATT&CK T1219.001 IDE Tunneling in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1219.001, IDE Tunneling, or enterprise ATT&CK. Adversaries may abuse Integrated Development Environment (IDE) software with remote development features to establish an interactive command and control channel on target systems within a network.
- ▌ Attack Ent T1497 001 System Checks · santosomar bundleAnalyze MITRE ATT&CK T1497.001 System Checks in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1497.001, System Checks, or enterprise ATT&CK. Adversaries may employ various system checks to detect and avoid virtualization and analysis environments.
- ▌ Attack Ent T1543 004 Launch Daemon · santosomar bundleAnalyze MITRE ATT&CK T1543.004 Launch Daemon in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1543.004, Launch Daemon, or enterprise ATT&CK. Adversaries may create or modify Launch Daemons to execute malicious payloads as part of persistence.
- ▌ Attack Ent T1547 010 Port Monitors · santosomar bundleAnalyze MITRE ATT&CK T1547.010 Port Monitors in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1547.010, Port Monitors, or enterprise ATT&CK. Adversaries may use port monitors to run an adversary supplied DLL during system boot for persistence or privilege escalation.
- ▌ Attack Ent T1550 002 Pass The Hash · santosomar bundleAnalyze MITRE ATT&CK T1550.002 Pass the Hash in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1550.002, Pass the Hash, or enterprise ATT&CK. Adversaries may “pass the hash” using stolen password hashes to move laterally within an environment, bypassing normal system access controls.
- ▌ Attack Ent T1552 003 Shell History · santosomar bundleAnalyze MITRE ATT&CK T1552.003 Shell History in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1552.003, Shell History, or enterprise ATT&CK. Adversaries may search the command history on compromised systems for insecurely stored credentials.
- ▌ Attack Ent T1552 007 Container API · santosomar bundleAnalyze MITRE ATT&CK T1552.007 Container API in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1552.007, Container API, or enterprise ATT&CK. Adversaries may gather credentials via APIs within a containers environment.
- ▌ Attack Ent T1027 003 Steganography · santosomar bundleAnalyze MITRE ATT&CK T1027.003 Steganography in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.003, Steganography, or enterprise ATT&CK. Adversaries may use steganography techniques in order to prevent the detection of hidden information.
- ▌ Attack Ent T1027 017 Svg Smuggling · santosomar bundleAnalyze MITRE ATT&CK T1027.017 SVG Smuggling in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.017, SVG Smuggling, or enterprise ATT&CK. Adversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign SVG files.(Citation: Trustwave SVG Smuggling 2025) SVGs, or Scalable Vector Graphics, are vector-based…
- ▌ Attack Ent T1037 005 Startup Items · santosomar bundleAnalyze MITRE ATT&CK T1037.005 Startup Items in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1037.005, Startup Items, or enterprise ATT&CK. Adversaries may use startup items automatically executed at boot initialization to establish persistence.
- ▌ Attack Ent T1055 Process Injection · santosomar bundleAnalyze MITRE ATT&CK T1055 Process Injection in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1055, Process Injection, or enterprise ATT&CK. Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges.
- ▌ Attack Ent T1057 Process Discovery · santosomar bundleAnalyze MITRE ATT&CK T1057 Process Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1057, Process Discovery, or enterprise ATT&CK. Adversaries may attempt to get information about running processes on a system.
- ▌ Attack Ent T1069 002 Domain Groups · santosomar bundleAnalyze MITRE ATT&CK T1069.002 Domain Groups in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1069.002, Domain Groups, or enterprise ATT&CK. Adversaries may attempt to find domain-level groups and permission settings.
- ▌ Attack Ent T1070 004 File Deletion · santosomar bundleAnalyze MITRE ATT&CK T1070.004 File Deletion in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1070.004, File Deletion, or enterprise ATT&CK. Adversaries may delete files left behind by the actions of their intrusion activity.
- ▌ Attack Ent T1611 Escape To Host · santosomar bundleAnalyze MITRE ATT&CK T1611 Escape to Host in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1611, Escape to Host, or enterprise ATT&CK. Adversaries may break out of a container or virtualized environment to gain access to the underlying host.
- ▌ Attack Ent T1650 Acquire Access · santosomar bundleAnalyze MITRE ATT&CK T1650 Acquire Access in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1650, Acquire Access, or enterprise ATT&CK. Adversaries may purchase or otherwise acquire an existing access to a target system or network.
- ▌ Attack Ent T1653 Power Settings · santosomar bundleAnalyze MITRE ATT&CK T1653 Power Settings in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1653, Power Settings, or enterprise ATT&CK. Adversaries may impair a system's ability to hibernate, reboot, or shut down in order to extend access to infected machines.
- ▌ Attack Ent T1669 Wi Fi Networks · santosomar bundleAnalyze MITRE ATT&CK T1669 Wi-Fi Networks in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1669, Wi-Fi Networks, or enterprise ATT&CK. Adversaries may gain initial access to target systems by connecting to wireless networks.
- ▌ Attack Ent T1688 Safe Mode Boot · santosomar bundleAnalyze MITRE ATT&CK T1688 Safe Mode Boot in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1688, Safe Mode Boot, or enterprise ATT&CK. Adversaries may abuse Windows safe mode to disable endpoint defenses.
- ▌ Attack Ics T0816 Device Restart Shutdown · santosomar bundleAnalyze MITRE ATT&CK T0816 Device Restart/Shutdown in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0816, Device Restart/Shutdown, or ics ATT&CK. Adversaries may forcibly restart or shutdown a device in an ICS environment to disrupt and potentially negatively impact physical processes.
- ▌ Attack Ics T0830 Adversary In The Middle · santosomar bundleAnalyze MITRE ATT&CK T0830 Adversary-in-the-Middle in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0830, Adversary-in-the-Middle, or ics ATT&CK. Adversaries with privileged network access may seek to modify network traffic in real time using adversary-in-the-middle (AiTM) attacks.
- ▌ Attack Ics T0831 Manipulation Of Control · santosomar bundleAnalyze MITRE ATT&CK T0831 Manipulation of Control in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0831, Manipulation of Control, or ics ATT&CK. Adversaries may manipulate physical process control within the industrial environment.
- ▌ Attack Ics T0846 002 Broadcast Discovery · santosomar bundleAnalyze MITRE ATT&CK T0846.002 Broadcast Discovery in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0846.002, Broadcast Discovery, or ics ATT&CK. Adversaries may perform broadcast discovery requests to enumerate systems and devices on a network.
- ▌ Attack Ics T0846 003 Multicast Discovery · santosomar bundleAnalyze MITRE ATT&CK T0846.003 Multicast Discovery in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0846.003, Multicast Discovery, or ics ATT&CK. Adversaries may perform multicast discovery requests which is when one system or device sends messages to all systems and devices in a pre-defined group on a network (or subnet) and then waits for a response.
- ▌ Attack Ics T0846 Remote System Discovery · santosomar bundleAnalyze MITRE ATT&CK T0846 Remote System Discovery in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0846, Remote System Discovery, or ics ATT&CK. Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for subsequent Lateral Movement or Discovery techniques.
- ▌ Attack Ics T0862 Supply Chain Compromise · santosomar bundleAnalyze MITRE ATT&CK T0862 Supply Chain Compromise in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0862, Supply Chain Compromise, or ics ATT&CK. Adversaries may perform supply chain compromise to gain control systems environment access by means of infected products, software, and workflows.
- ▌ Attack Ent T1055 015 Listplanting · santosomar bundleAnalyze MITRE ATT&CK T1055.015 ListPlanting in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1055.015, ListPlanting, or enterprise ATT&CK. Adversaries may abuse list-view controls to inject malicious code into hijacked processes in order to evade process-based defenses as well as possibly elevate privileges.
- ▌ Attack Ent T1059 005 Visual Basic · santosomar bundleAnalyze MITRE ATT&CK T1059.005 Visual Basic in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1059.005, Visual Basic, or enterprise ATT&CK. Adversaries may abuse Visual Basic (VB) for execution.
- ▌ Attack Ent T1069 001 Local Groups · santosomar bundleAnalyze MITRE ATT&CK T1069.001 Local Groups in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1069.001, Local Groups, or enterprise ATT&CK. Adversaries may attempt to find local system groups and permission settings.
- ▌ Attack Ent T1069 003 Cloud Groups · santosomar bundleAnalyze MITRE ATT&CK T1069.003 Cloud Groups in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1069.003, Cloud Groups, or enterprise ATT&CK. Adversaries may attempt to find cloud groups and permission settings.
- ▌ Attack Ent T1114 Email Collection · santosomar bundleAnalyze MITRE ATT&CK T1114 Email Collection in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1114, Email Collection, or enterprise ATT&CK. Adversaries may target user email to collect sensitive information.
- ▌ Attack Ent T1087 Account Discovery · santosomar bundleAnalyze MITRE ATT&CK T1087 Account Discovery in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1087, Account Discovery, or enterprise ATT&CK. Adversaries may attempt to get a listing of valid accounts, usernames, or email addresses on a system or within a compromised environment.
- ▌ Attack Ent T1136 001 Local Account · santosomar bundleAnalyze MITRE ATT&CK T1136.001 Local Account in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1136.001, Local Account, or enterprise ATT&CK. Adversaries may create a local account to maintain access to victim systems.
- ▌ Attack Ent T1136 003 Cloud Account · santosomar bundleAnalyze MITRE ATT&CK T1136.003 Cloud Account in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1136.003, Cloud Account, or enterprise ATT&CK. Adversaries may create a cloud account to maintain access to victim systems.
- ▌ Attack Ent T1137 003 Outlook Forms · santosomar bundleAnalyze MITRE ATT&CK T1137.003 Outlook Forms in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1137.003, Outlook Forms, or enterprise ATT&CK. Adversaries may abuse Microsoft Outlook forms to obtain persistence on a compromised system.
- ▌ Attack Ent T1137 005 Outlook Rules · santosomar bundleAnalyze MITRE ATT&CK T1137.005 Outlook Rules in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1137.005, Outlook Rules, or enterprise ATT&CK. Adversaries may abuse Microsoft Outlook rules to obtain persistence on a compromised system.
- ▌ Attack Ent T1205 001 Port Knocking · santosomar bundleAnalyze MITRE ATT&CK T1205.001 Port Knocking in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1205.001, Port Knocking, or enterprise ATT&CK. Adversaries may use port knocking to hide open ports used for persistence or command and control.
- ▌ Attack Ent T1205 Traffic Signaling · santosomar bundleAnalyze MITRE ATT&CK T1205 Traffic Signaling in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1205, Traffic Signaling, or enterprise ATT&CK. Adversaries may use traffic signaling to hide open ports or other malicious functionality used for persistence or command and control.
- ▌ Attack Ent T1078 Valid Accounts · santosomar bundleAnalyze MITRE ATT&CK T1078 Valid Accounts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1078, Valid Accounts, or enterprise ATT&CK. Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
- ▌ Attack Ent T1113 Screen Capture · santosomar bundleAnalyze MITRE ATT&CK T1113 Screen Capture in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1113, Screen Capture, or enterprise ATT&CK. Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation.
- ▌ Attack Ent T1115 Clipboard Data · santosomar bundleAnalyze MITRE ATT&CK T1115 Clipboard Data in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1115, Clipboard Data, or enterprise ATT&CK. Adversaries may collect data stored in the clipboard from users copying information within or between applications.
- ▌ Attack Ent T1129 Shared Modules · santosomar bundleAnalyze MITRE ATT&CK T1129 Shared Modules in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1129, Shared Modules, or enterprise ATT&CK. Adversaries may execute malicious payloads via loading shared modules.
- ▌ Attack Ent T1136 Create Account · santosomar bundleAnalyze MITRE ATT&CK T1136 Create Account in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1136, Create Account, or enterprise ATT&CK. Adversaries may create an account to maintain access to victim systems.(Citation: Symantec WastedLocker June 2020) With a sufficient level of access, creating such accounts may be used to establish secondary credentiale…
- ▌ Attack Ent T1204 User Execution · santosomar bundleAnalyze MITRE ATT&CK T1204 User Execution in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1204, User Execution, or enterprise ATT&CK. An adversary may rely upon specific actions by a user in order to gain execution.
- ▌ Attack Ent T1213 001 Confluence · santosomar bundleAnalyze MITRE ATT&CK T1213.001 Confluence in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1213.001, Confluence, or enterprise ATT&CK. Adversaries may leverage Confluence repositories to mine valuable information.
- ▌ Attack Ent T1553 002 Code Signing · santosomar bundleAnalyze MITRE ATT&CK T1553.002 Code Signing in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1553.002, Code Signing, or enterprise ATT&CK. Adversaries may create, acquire, or steal code signing materials to sign their malware or tools.
- ▌ Attack Ent T1558 005 Ccache Files · santosomar bundleAnalyze MITRE ATT&CK T1558.005 Ccache Files in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1558.005, Ccache Files, or enterprise ATT&CK. Adversaries may attempt to steal Kerberos tickets stored in credential cache files (or ccache).
- ▌ Attack Ent T1559 003 Xpc Services · santosomar bundleAnalyze MITRE ATT&CK T1559.003 XPC Services in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1559.003, XPC Services, or enterprise ATT&CK. Adversaries can provide malicious content to an XPC service daemon for local code execution.
- ▌ Attack Ent T1564 002 Hidden Users · santosomar bundleAnalyze MITRE ATT&CK T1564.002 Hidden Users in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1564.002, Hidden Users, or enterprise ATT&CK. Adversaries may use hidden users to hide the presence of user accounts they create or modify.
- ▌ Attack Ent T1564 007 Vba Stomping · santosomar bundleAnalyze MITRE ATT&CK T1564.007 VBA Stomping in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1564.007, VBA Stomping, or enterprise ATT&CK. Adversaries may hide malicious Visual Basic for Applications (VBA) payloads embedded within MS Office documents by replacing the VBA source code with benign data.(Citation: FireEye VBA stomp Feb 2020) MS Office document…
- ▌ Attack Ent T1574 012 Cor Profiler · santosomar bundleAnalyze MITRE ATT&CK T1574.012 COR_PROFILER in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1574.012, COR_PROFILER, or enterprise ATT&CK. Adversaries may leverage the COR_PROFILER environment variable to hijack the execution flow of programs that load the .NET CLR.
- ▌ Attack Ent T1583 006 Web Services · santosomar bundleAnalyze MITRE ATT&CK T1583.006 Web Services in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1583.006, Web Services, or enterprise ATT&CK. Adversaries may register for web services that can be used during targeting.
- ▌ Attack Ent T1608 002 Upload Tool · santosomar bundleAnalyze MITRE ATT&CK T1608.002 Upload Tool in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1608.002, Upload Tool, or enterprise ATT&CK. Adversaries may upload tools to third-party or adversary controlled infrastructure to make it accessible during targeting.
- ▌ Attack Ent T1608 005 Link Target · santosomar bundleAnalyze MITRE ATT&CK T1608.005 Link Target in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1608.005, Link Target, or enterprise ATT&CK. Adversaries may put in place resources that are referenced by a link that can be used during targeting.
- ▌ Attack Ent T1654 Log Enumeration · santosomar bundleAnalyze MITRE ATT&CK T1654 Log Enumeration in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1654, Log Enumeration, or enterprise ATT&CK. Adversaries may enumerate system and service logs to find useful data.
- ▌ Attack Ent T1657 Financial Theft · santosomar bundleAnalyze MITRE ATT&CK T1657 Financial Theft in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1657, Financial Theft, or enterprise ATT&CK. Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these resources for…
- ▌ Attack Ent T1674 Input Injection · santosomar bundleAnalyze MITRE ATT&CK T1674 Input Injection in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1674, Input Injection, or enterprise ATT&CK. Adversaries may simulate keystrokes on a victim’s computer by various means to perform any type of action on behalf of the user, such as launching the command interpreter using keyboard shortcuts, typing an inline scrip…
- ▌ Attack Ent T1678 Delay Execution · santosomar bundleAnalyze MITRE ATT&CK T1678 Delay Execution in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1678, Delay Execution, or enterprise ATT&CK. Adversaries may employ various time-based methods to evade detection and analysis.
- ▌ Attack Ics T0807 Command Line Interface · santosomar bundleAnalyze MITRE ATT&CK T0807 Command-Line Interface in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0807, Command-Line Interface, or ics ATT&CK. Adversaries may utilize command-line interfaces (CLIs) to interact with systems and execute commands.
- ▌ Attack Ent T1213 002 Sharepoint · santosomar bundleAnalyze MITRE ATT&CK T1213.002 Sharepoint in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1213.002, Sharepoint, or enterprise ATT&CK. Adversaries may leverage the SharePoint repository as a source to mine valuable information.
- ▌ Attack Ent T1546 017 Udev Rules · santosomar bundleAnalyze MITRE ATT&CK T1546.017 Udev Rules in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1546.017, Udev Rules, or enterprise ATT&CK. Adversaries may maintain persistence through executing malicious content triggered using udev rules.
- ▌ Attack Ent T1564 Hide Artifacts · santosomar bundleAnalyze MITRE ATT&CK T1564 Hide Artifacts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1564, Hide Artifacts, or enterprise ATT&CK. Adversaries may attempt to hide artifacts associated with their behaviors to evade detection.
- ▌ Attack Ent T1583 002 Dns Server · santosomar bundleAnalyze MITRE ATT&CK T1583.002 DNS Server in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1583.002, DNS Server, or enterprise ATT&CK. Adversaries may set up their own Domain Name System (DNS) servers that can be used during targeting.
- ▌ Attack Ent T1583 007 Serverless · santosomar bundleAnalyze MITRE ATT&CK T1583.007 Serverless in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1583.007, Serverless, or enterprise ATT&CK. Adversaries may purchase and configure serverless cloud infrastructure, such as Cloudflare Workers, AWS Lambda functions, or Google Apps Scripts, that can be used during targeting.
- ▌ Attack Ent T1584 002 Dns Server · santosomar bundleAnalyze MITRE ATT&CK T1584.002 DNS Server in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1584.002, DNS Server, or enterprise ATT&CK. Adversaries may compromise third-party DNS servers that can be used during targeting.
- ▌ Attack Ent T1584 007 Serverless · santosomar bundleAnalyze MITRE ATT&CK T1584.007 Serverless in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1584.007, Serverless, or enterprise ATT&CK. Adversaries may compromise serverless cloud infrastructure, such as Cloudflare Workers, AWS Lambda functions, or Google Apps Scripts, that can be used during targeting.
- ▌ Attack Ent T1583 008 Malvertising · santosomar bundleAnalyze MITRE ATT&CK T1583.008 Malvertising in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1583.008, Malvertising, or enterprise ATT&CK. Adversaries may purchase online advertisements that can be abused to distribute malware to victims.
- ▌ Attack Ent T1584 006 Web Services · santosomar bundleAnalyze MITRE ATT&CK T1584.006 Web Services in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1584.006, Web Services, or enterprise ATT&CK. Adversaries may compromise access to third-party web services that can be used during targeting.
- ▌ Attack Ent T1590 005 Ip Addresses · santosomar bundleAnalyze MITRE ATT&CK T1590.005 IP Addresses in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1590.005, IP Addresses, or enterprise ATT&CK. Adversaries may gather the victim's IP addresses that can be used during targeting.
- ▌ Attack Ent T1593 001 Social Media · santosomar bundleAnalyze MITRE ATT&CK T1593.001 Social Media in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1593.001, Social Media, or enterprise ATT&CK. Adversaries may search social media for information about victims that can be used during targeting.
- ▌ Attack Ent T1610 Deploy Container · santosomar bundleAnalyze MITRE ATT&CK T1610 Deploy Container in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1610, Deploy Container, or enterprise ATT&CK. Adversaries may deploy a container into an environment to facilitate execution or evade defenses.
- ▌ Attack Ent T1622 Debugger Evasion · santosomar bundleAnalyze MITRE ATT&CK T1622 Debugger Evasion in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1622, Debugger Evasion, or enterprise ATT&CK. Adversaries may employ various means to detect and avoid debuggers.
- ▌ Attack Ent T1683 Generate Content · santosomar bundleAnalyze MITRE ATT&CK T1683 Generate Content in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1683, Generate Content, or enterprise ATT&CK. Adversaries may create or generate content to support targeting and operations.
- ▌ Attack Ent T1689 Downgrade Attack · santosomar bundleAnalyze MITRE ATT&CK T1689 Downgrade Attack in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1689, Downgrade Attack, or enterprise ATT&CK. Adversaries may downgrade or use a version of system features that may be outdated, vulnerable, and/or does not support updated security controls.
- ▌ Attack Ics T0873 Project File Infection · santosomar bundleAnalyze MITRE ATT&CK T0873 Project File Infection in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0873, Project File Infection, or ics ATT&CK. Adversaries may attempt to infect project files with malicious code.
- ▌ Attack Ics T0893 Data From Local System · santosomar bundleAnalyze MITRE ATT&CK T0893 Data from Local System in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0893, Data from Local System, or ics ATT&CK. Adversaries may target and collect data from local system sources, such as file systems, configuration files, or local databases.
- ▌ Attack Mob T1422 002 Wi Fi Discovery · santosomar bundleAnalyze MITRE ATT&CK T1422.002 Wi-Fi Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1422.002, Wi-Fi Discovery, or mobile ATT&CK. Adversaries may search for information about Wi-Fi networks, such as network names and passwords, on compromised systems.
- ▌ Attack Mob T1456 Drive By Compromise · santosomar bundleAnalyze MITRE ATT&CK T1456 Drive-By Compromise in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1456, Drive-By Compromise, or mobile ATT&CK. Adversaries may gain access to a system through a user visiting a website over the normal course of browsing.
- ▌ Attack Mob T1636 Protected User Data · santosomar bundleAnalyze MITRE ATT&CK T1636 Protected User Data in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1636, Protected User Data, or mobile ATT&CK. Adversaries may utilize standard operating system APIs to collect data from permission-backed data stores on a device, such as the calendar or contact list.
- ▌ Attack Ent T1001 Data Obfuscation · santosomar bundleAnalyze MITRE ATT&CK T1001 Data Obfuscation in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1001, Data Obfuscation, or enterprise ATT&CK. Adversaries may obfuscate command and control traffic to make it more difficult to detect.(Citation: Bitdefender FunnyDream Campaign November 2020) Command and control (C2) communications are hidden (but not necessarily…
- ▌ Attack Ent T1003 001 Lsass Memory · santosomar bundleAnalyze MITRE ATT&CK T1003.001 LSASS Memory in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1003.001, LSASS Memory, or enterprise ATT&CK. Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
- ▌ Attack Ent T1040 Network Sniffing · santosomar bundleAnalyze MITRE ATT&CK T1040 Network Sniffing in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1040, Network Sniffing, or enterprise ATT&CK. Adversaries may passively sniff network traffic to capture information about an environment, including authentication material passed over the network.
- ▌ Attack Mob T1641 Data Manipulation · santosomar bundleAnalyze MITRE ATT&CK T1641 Data Manipulation in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1641, Data Manipulation, or mobile ATT&CK. Adversaries may insert, delete, or alter data in order to manipulate external outcomes or hide activity.
- ▌ Attack Ent T1012 Query Registry · santosomar bundleAnalyze MITRE ATT&CK T1012 Query Registry in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1012, Query Registry, or enterprise ATT&CK. Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.
- ▌ Attack Ent T1037 002 Login Hook · santosomar bundleAnalyze MITRE ATT&CK T1037.002 Login Hook in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1037.002, Login Hook, or enterprise ATT&CK. Adversaries may use a Login Hook to establish persistence executed upon user logon.
- ▌ Attack Ent T1037 004 Rc Scripts · santosomar bundleAnalyze MITRE ATT&CK T1037.004 RC Scripts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1037.004, RC Scripts, or enterprise ATT&CK. Adversaries may establish persistence by modifying RC scripts, which are executed during a Unix-like system’s startup.
- ▌ Attack Ent T1056 001 Keylogging · santosomar bundleAnalyze MITRE ATT&CK T1056.001 Keylogging in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1056.001, Keylogging, or enterprise ATT&CK. Adversaries may log user keystrokes to intercept credentials as the user types them.
- ▌ Attack Ent T1059 001 Powershell · santosomar bundleAnalyze MITRE ATT&CK T1059.001 PowerShell in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1059.001, PowerShell, or enterprise ATT&CK. Adversaries may abuse PowerShell commands and scripts for execution.
- ▌ Attack Ent T1059 004 Unix Shell · santosomar bundleAnalyze MITRE ATT&CK T1059.004 Unix Shell in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1059.004, Unix Shell, or enterprise ATT&CK. Adversaries may abuse Unix shell commands and scripts for execution.
- ▌ Attack Ent T1059 007 Javascript · santosomar bundleAnalyze MITRE ATT&CK T1059.007 JavaScript in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1059.007, JavaScript, or enterprise ATT&CK. Adversaries may abuse various implementations of JavaScript for execution.
- ▌ Attack Ent T1485 Data Destruction · santosomar bundleAnalyze MITRE ATT&CK T1485 Data Destruction in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1485, Data Destruction, or enterprise ATT&CK. Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources.
- ▌ Attack Ent T1543 001 Launch Agent · santosomar bundleAnalyze MITRE ATT&CK T1543.001 Launch Agent in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1543.001, Launch Agent, or enterprise ATT&CK. Adversaries may create or modify launch agents to repeatedly execute malicious payloads as part of persistence.
- ▌ Attack Ent T1546 009 Appcert Dlls · santosomar bundleAnalyze MITRE ATT&CK T1546.009 AppCert DLLs in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1546.009, AppCert DLLs, or enterprise ATT&CK. Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppCert DLLs loaded into processes.
- ▌ Attack Ent T1546 010 Appinit Dlls · santosomar bundleAnalyze MITRE ATT&CK T1546.010 AppInit DLLs in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1546.010, AppInit DLLs, or enterprise ATT&CK. Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppInit DLLs loaded into processes.