santosomar
- 800 skills
- 0 followers
- 14 hours ago last updated
- ▌ Attack Ent T1547 008 Lsass Driver · santosomar bundleAnalyze MITRE ATT&CK T1547.008 LSASS Driver in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1547.008, LSASS Driver, or enterprise ATT&CK. Adversaries may modify or add LSASS drivers to obtain persistence on compromised systems.
- ▌ Attack Ent T1547 014 Active Setup · santosomar bundleAnalyze MITRE ATT&CK T1547.014 Active Setup in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1547.014, Active Setup, or enterprise ATT&CK. Adversaries may achieve persistence by adding a Registry key to the Active Setup of the local machine.
- ▌ Attack Ent T1552 004 Private Keys · santosomar bundleAnalyze MITRE ATT&CK T1552.004 Private Keys in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1552.004, Private Keys, or enterprise ATT&CK. Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials.
- ▌ Attack Ent T1547 015 Login Items · santosomar bundleAnalyze MITRE ATT&CK T1547.015 Login Items in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1547.015, Login Items, or enterprise ATT&CK. Adversaries may add login items to execute upon user login to gain persistence or escalate privileges.
- ▌ Attack Ent T1564 013 Bind Mounts · santosomar bundleAnalyze MITRE ATT&CK T1564.013 Bind Mounts in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1564.013, Bind Mounts, or enterprise ATT&CK. Adversaries may abuse bind mounts on file structures to hide their activity and artifacts from native utilities.
- ▌ Attack Ent T1569 System Services · santosomar bundleAnalyze MITRE ATT&CK T1569 System Services in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1569, System Services, or enterprise ATT&CK. Adversaries may abuse system services or daemons to execute commands or programs.
- ▌ Attack Ent T1589 001 Credentials · santosomar bundleAnalyze MITRE ATT&CK T1589.001 Credentials in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1589.001, Credentials, or enterprise ATT&CK. Adversaries may gather credentials that can be used during targeting.
- ▌ Attack Ent T1595 Active Scanning · santosomar bundleAnalyze MITRE ATT&CK T1595 Active Scanning in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1595, Active Scanning, or enterprise ATT&CK. Adversaries may execute active reconnaissance scans to gather information that can be used during targeting.
- ▌ Attack Ent T1606 001 Web Cookies · santosomar bundleAnalyze MITRE ATT&CK T1606.001 Web Cookies in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1606.001, Web Cookies, or enterprise ATT&CK. Adversaries may forge web cookies that can be used to gain access to web applications or Internet services.
- ▌ Attack Ent T1606 002 Saml Tokens · santosomar bundleAnalyze MITRE ATT&CK T1606.002 SAML Tokens in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1606.002, SAML Tokens, or enterprise ATT&CK. An adversary may forge SAML tokens with any permissions claims and lifetimes if they possess a valid SAML token-signing certificate.(Citation: Microsoft SolarWinds Steps) The default lifetime of a SAML token is one hour…
- ▌ Attack Ics T0835 Manipulate I O Image · santosomar bundleAnalyze MITRE ATT&CK T0835 Manipulate I/O Image in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0835, Manipulate I/O Image, or ics ATT&CK. Adversaries may manipulate the I/O image of PLCs through various means to prevent them from functioning as expected.
- ▌ Attack Ics T1692 Unauthorized Message · santosomar bundleAnalyze MITRE ATT&CK T1692 Unauthorized Message in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1692, Unauthorized Message, or ics ATT&CK. Adversaries may send unauthorized messages to ICS systems and devices to evade defenses or manipulate processes.
- ▌ Attack Ics T1694 Insecure Credentials · santosomar bundleAnalyze MITRE ATT&CK T1694 Insecure Credentials in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1694, Insecure Credentials, or ics ATT&CK. Adversaries may target insecure credentials as a means to persist on a system or device or move laterally from one system or device to another.
- ▌ Attack Ics T1695 Block Communications · santosomar bundleAnalyze MITRE ATT&CK T1695 Block Communications in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1695, Block Communications, or ics ATT&CK. Operational technology communications occur over serial COM, Ethernet, Wi-Fi, cellular (4G/5G), and satellite mediums.
- ▌ Attack Mob T1406 001 Steganography · santosomar bundleAnalyze MITRE ATT&CK T1406.001 Steganography in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1406.001, Steganography, or mobile ATT&CK. Adversaries may use steganography techniques in order to prevent the detection of hidden information.
- ▌ Attack Mob T1424 Process Discovery · santosomar bundleAnalyze MITRE ATT&CK T1424 Process Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1424, Process Discovery, or mobile ATT&CK. Adversaries may attempt to get information about running processes on a device.
- ▌ Attack Mob T1430 Location Tracking · santosomar bundleAnalyze MITRE ATT&CK T1430 Location Tracking in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1430, Location Tracking, or mobile ATT&CK. Adversaries may track a device’s physical location through use of standard operating system APIs via malicious or exploited applications on the compromised device.
- ▌ Attack Mob T1437 001 Web Protocols · santosomar bundleAnalyze MITRE ATT&CK T1437.001 Web Protocols in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1437.001, Web Protocols, or mobile ATT&CK. Adversaries may communicate using application layer protocols associated with web protocols traffic to avoid detection/network filtering by blending in with existing traffic.
- ▌ Attack Ent T1056 Input Capture · santosomar bundleAnalyze MITRE ATT&CK T1056 Input Capture in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1056, Input Capture, or enterprise ATT&CK. Adversaries may use methods of capturing user input to obtain credentials or collect information.
- ▌ Attack Ent T1059 009 Cloud API · santosomar bundleAnalyze MITRE ATT&CK T1059.009 Cloud API in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1059.009, Cloud API, or enterprise ATT&CK. Adversaries may abuse cloud APIs to execute malicious commands.
- ▌ Attack Ent T1070 006 Timestomp · santosomar bundleAnalyze MITRE ATT&CK T1070.006 Timestomp in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1070.006, Timestomp, or enterprise ATT&CK. Adversaries may modify file time attributes to hide new files or changes to existing files.
- ▌ Attack Ent T1123 Audio Capture · santosomar bundleAnalyze MITRE ATT&CK T1123 Audio Capture in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1123, Audio Capture, or enterprise ATT&CK. An adversary can leverage a computer's peripheral devices (e.g., microphones and webcams) or applications (e.g., voice and video call services) to capture audio recordings for the purpose of listening into sensitive con…
- ▌ Attack Ent T1125 Video Capture · santosomar bundleAnalyze MITRE ATT&CK T1125 Video Capture in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1125, Video Capture, or enterprise ATT&CK. An adversary can leverage a computer's peripheral devices (e.g., integrated cameras or webcams) or applications (e.g., video call services) to capture video recordings for the purpose of gathering information.
- ▌ Attack Ent T1127 002 Clickonce · santosomar bundleAnalyze MITRE ATT&CK T1127.002 ClickOnce in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1127.002, ClickOnce, or enterprise ATT&CK. Adversaries may use ClickOnce applications (.appref-ms and .application files) to proxy execution of code through a trusted Windows utility.(Citation: Burke/CISA ClickOnce BlackHat) ClickOnce is a deployment that enable…
- ▌ Attack Ent T1132 Data Encoding · santosomar bundleAnalyze MITRE ATT&CK T1132 Data Encoding in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1132, Data Encoding, or enterprise ATT&CK. Adversaries may encode data to make the content of command and control traffic more difficult to detect.
- ▌ Attack Ics T1692 002 Reporting Message · santosomar bundleAnalyze MITRE ATT&CK T1692.002 Reporting Message in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1692.002, Reporting Message, or ics ATT&CK. Adversaries may spoof reporting messages in control system environments for evasion and to impair process control.
- ▌ Attack Mob T1418 Software Discovery · santosomar bundleAnalyze MITRE ATT&CK T1418 Software Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1418, Software Discovery, or mobile ATT&CK. Adversaries may attempt to get a listing of applications that are installed on a device.
- ▌ Attack Mob T1603 Scheduled Task Job · santosomar bundleAnalyze MITRE ATT&CK T1603 Scheduled Task/Job in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1603, Scheduled Task/Job, or mobile ATT&CK. Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code.
- ▌ Attack Mob T1629 002 Device Lockout · santosomar bundleAnalyze MITRE ATT&CK T1629.002 Device Lockout in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1629.002, Device Lockout, or mobile ATT&CK. An adversary may seek to inhibit user interaction by locking the legitimate user out of the device.
- ▌ Attack Mob T1637 Dynamic Resolution · santosomar bundleAnalyze MITRE ATT&CK T1637 Dynamic Resolution in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1637, Dynamic Resolution, or mobile ATT&CK. Adversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations.
- ▌ Attack Ent T1003 004 Lsa Secrets · santosomar bundleAnalyze MITRE ATT&CK T1003.004 LSA Secrets in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1003.004, LSA Secrets, or enterprise ATT&CK. Adversaries with SYSTEM access to a host may attempt to access Local Security Authority (LSA) secrets, which can contain a variety of different credential materials, such as credentials for service accounts.(Citation: P…
- ▌ Attack Ent T1021 Remote Services · santosomar bundleAnalyze MITRE ATT&CK T1021 Remote Services in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1021, Remote Services, or enterprise ATT&CK. Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to log into a service that accepts remote connections, such as telnet, SSH, and VNC.
- ▌ Attack Mob T1461 Lockscreen Bypass · santosomar bundleAnalyze MITRE ATT&CK T1461 Lockscreen Bypass in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1461, Lockscreen Bypass, or mobile ATT&CK. An adversary with physical access to a mobile device may seek to bypass the device’s lockscreen.
- ▌ Attack Mob T1509 Non Standard Port · santosomar bundleAnalyze MITRE ATT&CK T1509 Non-Standard Port in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1509, Non-Standard Port, or mobile ATT&CK. Adversaries may generate network traffic using a protocol and port pairing that are typically not associated.
- ▌ Attack Mob T1521 Encrypted Channel · santosomar bundleAnalyze MITRE ATT&CK T1521 Encrypted Channel in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1521, Encrypted Channel, or mobile ATT&CK. Adversaries may explicitly employ a known encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
- ▌ Attack Mob T1630 002 File Deletion · santosomar bundleAnalyze MITRE ATT&CK T1630.002 File Deletion in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1630.002, File Deletion, or mobile ATT&CK. Adversaries may wipe a device or delete individual files in order to manipulate external outcomes or hide activity.
- ▌ Attack Mob T1631 Process Injection · santosomar bundleAnalyze MITRE ATT&CK T1631 Process Injection in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1631, Process Injection, or mobile ATT&CK. Adversaries may inject code into processes in order to evade process-based defenses or even elevate privileges.
- ▌ Attack Mob T1633 001 System Checks · santosomar bundleAnalyze MITRE ATT&CK T1633.001 System Checks in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1633.001, System Checks, or mobile ATT&CK. Adversaries may employ various system checks to detect and avoid virtualization and analysis environments.
- ▌ Attack Mob T1635 001 Uri Hijacking · santosomar bundleAnalyze MITRE ATT&CK T1635.001 URI Hijacking in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1635.001, URI Hijacking, or mobile ATT&CK. Adversaries may register Uniform Resource Identifiers (URIs) to intercept sensitive data.
- ▌ Attack Ent T1213 006 Databases · santosomar bundleAnalyze MITRE ATT&CK T1213.006 Databases in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1213.006, Databases, or enterprise ATT&CK. Adversaries may leverage databases to mine valuable information.
- ▌ Attack Ent T1218 013 Mavinject · santosomar bundleAnalyze MITRE ATT&CK T1218.013 Mavinject in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1218.013, Mavinject, or enterprise ATT&CK. Adversaries may abuse mavinject.exe to proxy execution of malicious code.
- ▌ Attack Ent T1505 003 Web Shell · santosomar bundleAnalyze MITRE ATT&CK T1505.003 Web Shell in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1505.003, Web Shell, or enterprise ATT&CK. Adversaries may backdoor web servers with web shells to establish persistent access to systems.
- ▌ Attack Ent T1542 004 Rommonkit · santosomar bundleAnalyze MITRE ATT&CK T1542.004 ROMMONkit in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1542.004, ROMMONkit, or enterprise ATT&CK. Adversaries may abuse the ROM Monitor (ROMMON) by loading an unauthorized firmware with adversary code to provide persistent access and manipulate device behavior that is difficult to detect.
- ▌ Attack Ent T1542 005 Tftp Boot · santosomar bundleAnalyze MITRE ATT&CK T1542.005 TFTP Boot in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1542.005, TFTP Boot, or enterprise ATT&CK. Adversaries may abuse netbooting to load an unauthorized network device operating system from a Trivial File Transfer Protocol (TFTP) server.
- ▌ Attack Ent T1027 015 Compression · santosomar bundleAnalyze MITRE ATT&CK T1027.015 Compression in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1027.015, Compression, or enterprise ATT&CK. Adversaries may use compression to obfuscate their payloads or files.
- ▌ Attack Ent T1055 009 Proc Memory · santosomar bundleAnalyze MITRE ATT&CK T1055.009 Proc Memory in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1055.009, Proc Memory, or enterprise ATT&CK. Adversaries may inject malicious code into processes via the /proc filesystem in order to evade process-based defenses as well as possibly elevate privileges.
- ▌ Attack Ent T1059 002 Applescript · santosomar bundleAnalyze MITRE ATT&CK T1059.002 AppleScript in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1059.002, AppleScript, or enterprise ATT&CK. Adversaries may abuse AppleScript for execution.
- ▌ Attack Ent T1112 Modify Registry · santosomar bundleAnalyze MITRE ATT&CK T1112 Modify Registry in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1112, Modify Registry, or enterprise ATT&CK. Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
- ▌ Attack Ent T1137 002 Office Test · santosomar bundleAnalyze MITRE ATT&CK T1137.002 Office Test in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1137.002, Office Test, or enterprise ATT&CK. Adversaries may abuse the Microsoft Office "Office Test" Registry key to obtain persistence on a compromised system.
- ▌ Attack Ent T1218 004 Installutil · santosomar bundleAnalyze MITRE ATT&CK T1218.004 InstallUtil in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1218.004, InstallUtil, or enterprise ATT&CK. Adversaries may use InstallUtil to proxy execution of code through a trusted Windows utility.
- ▌ Attack Ent T1496 003 Sms Pumping · santosomar bundleAnalyze MITRE ATT&CK T1496.003 SMS Pumping in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1496.003, SMS Pumping, or enterprise ATT&CK. Adversaries may leverage messaging services for SMS pumping, which may impact system and/or hosted service availability.(Citation: Twilio SMS Pumping) SMS pumping is a type of telecommunications fraud whereby a threat a…
- ▌ Attack Ent T1546 002 Screensaver · santosomar bundleAnalyze MITRE ATT&CK T1546.002 Screensaver in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1546.002, Screensaver, or enterprise ATT&CK. Adversaries may establish persistence by executing malicious content triggered by user inactivity.
- ▌ Attack Ent T1557 004 Evil Twin · santosomar bundleAnalyze MITRE ATT&CK T1557.004 Evil Twin in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1557.004, Evil Twin, or enterprise ATT&CK. Adversaries may host seemingly genuine Wi-Fi access points to deceive users into connecting to malicious networks as a way of supporting follow-on behaviors such as [Network Sniffing](https://attack.mitre.org/techniques…
- ▌ Attack Ent T1569 001 Launchctl · santosomar bundleAnalyze MITRE ATT&CK T1569.001 Launchctl in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1569.001, Launchctl, or enterprise ATT&CK. Adversaries may abuse launchctl to execute commands or programs.
- ▌ Attack Ent T1569 003 Systemctl · santosomar bundleAnalyze MITRE ATT&CK T1569.003 Systemctl in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1569.003, Systemctl, or enterprise ATT&CK. Adversaries may abuse systemctl to execute commands or programs.
- ▌ Attack Ent T1667 Email Bombing · santosomar bundleAnalyze MITRE ATT&CK T1667 Email Bombing in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1667, Email Bombing, or enterprise ATT&CK. Adversaries may flood targeted email addresses with an overwhelming volume of messages.
- ▌ Attack Ics T0802 Automated Collection · santosomar bundleAnalyze MITRE ATT&CK T0802 Automated Collection in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0802, Automated Collection, or ics ATT&CK. Adversaries may automate collection of industrial environment information using tools or scripts.
- ▌ Attack Ics T0826 Loss Of Availability · santosomar bundleAnalyze MITRE ATT&CK T0826 Loss of Availability in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0826, Loss of Availability, or ics ATT&CK. Adversaries may attempt to disrupt essential components or systems to prevent owner and operator from delivering products or services.
- ▌ Attack Ics T0832 Manipulation Of View · santosomar bundleAnalyze MITRE ATT&CK T0832 Manipulation of View in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0832, Manipulation of View, or ics ATT&CK. Adversaries may attempt to manipulate the information reported back to operators or controllers.
- ▌ Attack Ics T1693 001 System Firmware · santosomar bundleAnalyze MITRE ATT&CK T1693.001 System Firmware in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1693.001, System Firmware, or ics ATT&CK. System firmware on modern assets is often designed with an update feature.
- ▌ Attack Ics T1693 002 Module Firmware · santosomar bundleAnalyze MITRE ATT&CK T1693.002 Module Firmware in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1693.002, Module Firmware, or ics ATT&CK. Adversaries may install malicious or vulnerable firmware onto modular hardware devices.
- ▌ Attack Mob T1628 002 User Evasion · santosomar bundleAnalyze MITRE ATT&CK T1628.002 User Evasion in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1628.002, User Evasion, or mobile ATT&CK. Adversaries may attempt to avoid detection by hiding malicious behavior from the user.
- ▌ Attack Mob T1636 003 Contact List · santosomar bundleAnalyze MITRE ATT&CK T1636.003 Contact List in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1636.003, Contact List, or mobile ATT&CK. Adversaries may utilize standard operating system APIs to gather contact list data.
- ▌ Attack Mob T1636 004 Sms Messages · santosomar bundleAnalyze MITRE ATT&CK T1636.004 SMS Messages in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1636.004, SMS Messages, or mobile ATT&CK. Adversaries may utilize standard operating system APIs to gather SMS messages.
- ▌ Attack Mob T1644 Out Of Band Data · santosomar bundleAnalyze MITRE ATT&CK T1644 Out of Band Data in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1644, Out of Band Data, or mobile ATT&CK. Adversaries may communicate with compromised devices using out of band data streams.
- ▌ Attack Mob T1662 Data Destruction · santosomar bundleAnalyze MITRE ATT&CK T1662 Data Destruction in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1662, Data Destruction, or mobile ATT&CK. Adversaries may destroy data and files on specific devices or in large numbers to interrupt availability to systems, services, and network resources.
- ▌ Attack Ent T1001 001 Junk Data · santosomar bundleAnalyze MITRE ATT&CK T1001.001 Junk Data in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1001.001, Junk Data, or enterprise ATT&CK. Adversaries may add junk data to protocols used for command and control to make detection more difficult.(Citation: FireEye SUNBURST Backdoor December 2020) By adding random or meaningless data to the protocols used for…
- ▌ Attack Ics T0801 Monitor Process State · santosomar bundleAnalyze MITRE ATT&CK T0801 Monitor Process State in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0801, Monitor Process State, or ics ATT&CK. Adversaries may gather information about the physical process state.
- ▌ Attack Ics T0838 Modify Alarm Settings · santosomar bundleAnalyze MITRE ATT&CK T0838 Modify Alarm Settings in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0838, Modify Alarm Settings, or ics ATT&CK. Adversaries may modify alarm settings to prevent alerts that may inform operators of their presence or to prevent responses to dangerous and unintended scenarios.
- ▌ Attack Ics T0858 Change Operating Mode · santosomar bundleAnalyze MITRE ATT&CK T0858 Change Operating Mode in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0858, Change Operating Mode, or ics ATT&CK. Adversaries may change the operating mode of a controller to gain additional access to engineering functions such as Program Download.
- ▌ Attack Ics T0864 Transient Cyber Asset · santosomar bundleAnalyze MITRE ATT&CK T0864 Transient Cyber Asset in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0864, Transient Cyber Asset, or ics ATT&CK. Adversaries may target devices that are transient across ICS networks and external networks.
- ▌ Attack Ics T0867 Lateral Tool Transfer · santosomar bundleAnalyze MITRE ATT&CK T0867 Lateral Tool Transfer in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0867, Lateral Tool Transfer, or ics ATT&CK. Adversaries may transfer tools or other files from one system to another to stage adversary tools or other files over the course of an operation.
- ▌ Attack Ics T0868 Detect Operating Mode · santosomar bundleAnalyze MITRE ATT&CK T0868 Detect Operating Mode in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0868, Detect Operating Mode, or ics ATT&CK. Adversaries may gather information about a PLCs or controllers current operating mode.
- ▌ Attack Ics T0871 Execution Through API · santosomar bundleAnalyze MITRE ATT&CK T0871 Execution through API in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0871, Execution through API, or ics ATT&CK. Adversaries may attempt to leverage Application Program Interfaces (APIs) used for communication between control software and the hardware.
- ▌ Attack Ics T1691 002 Reporting Message · santosomar bundleAnalyze MITRE ATT&CK T1691.002 Reporting Message in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1691.002, Reporting Message, or ics ATT&CK. Adversaries may block or prevent a reporting message from reaching its intended target.
- ▌ Attack Ent T1218 008 Odbcconf · santosomar bundleAnalyze MITRE ATT&CK T1218.008 Odbcconf in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1218.008, Odbcconf, or enterprise ATT&CK. Adversaries may abuse odbcconf.exe to proxy execution of malicious payloads.
- ▌ Attack Ent T1218 010 Regsvr32 · santosomar bundleAnalyze MITRE ATT&CK T1218.010 Regsvr32 in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1218.010, Regsvr32, or enterprise ATT&CK. Adversaries may abuse Regsvr32.exe to proxy execution of malicious code.
- ▌ Attack Ent T1218 011 Rundll32 · santosomar bundleAnalyze MITRE ATT&CK T1218.011 Rundll32 in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1218.011, Rundll32, or enterprise ATT&CK. Adversaries may abuse rundll32.exe to proxy execution of malicious code.
- ▌ Attack Ent T1218 012 Verclsid · santosomar bundleAnalyze MITRE ATT&CK T1218.012 Verclsid in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1218.012, Verclsid, or enterprise ATT&CK. Adversaries may abuse verclsid.exe to proxy execution of malicious code.
- ▌ Attack Ent T1489 Service Stop · santosomar bundleAnalyze MITRE ATT&CK T1489 Service Stop in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1489, Service Stop, or enterprise ATT&CK. Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
- ▌ Attack Ent T1555 001 Keychain · santosomar bundleAnalyze MITRE ATT&CK T1555.001 Keychain in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1555.001, Keychain, or enterprise ATT&CK. Adversaries may acquire credentials from Keychain.
- ▌ Attack Ent T1587 004 Exploits · santosomar bundleAnalyze MITRE ATT&CK T1587.004 Exploits in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1587.004, Exploits, or enterprise ATT&CK. Adversaries may develop exploits that can be used during targeting.
- ▌ Attack Ent T1588 005 Exploits · santosomar bundleAnalyze MITRE ATT&CK T1588.005 Exploits in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1588.005, Exploits, or enterprise ATT&CK. Adversaries may buy, steal, or download exploits that can be used during targeting.
- ▌ Attack Mob T1417 001 Keylogging · santosomar bundleAnalyze MITRE ATT&CK T1417.001 Keylogging in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1417.001, Keylogging, or mobile ATT&CK. Adversaries may log user keystrokes to intercept credentials or other information from the user as the user types them.
- ▌ Attack Mob T1513 Screen Capture · santosomar bundleAnalyze MITRE ATT&CK T1513 Screen Capture in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1513, Screen Capture, or mobile ATT&CK. Adversaries may use screen capture to collect additional information about a target device, such as applications running in the foreground, user data, credentials, or other sensitive information.
- ▌ Attack Mob T1623 001 Unix Shell · santosomar bundleAnalyze MITRE ATT&CK T1623.001 Unix Shell in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1623.001, Unix Shell, or mobile ATT&CK. Adversaries may abuse Unix shell commands and scripts for execution.
- ▌ Attack Mob T1627 001 Geofencing · santosomar bundleAnalyze MITRE ATT&CK T1627.001 Geofencing in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1627.001, Geofencing, or mobile ATT&CK. Adversaries may use a device’s geographical location to limit certain malicious behaviors.
- ▌ Attack Mob T1628 Hide Artifacts · santosomar bundleAnalyze MITRE ATT&CK T1628 Hide Artifacts in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1628, Hide Artifacts, or mobile ATT&CK. Adversaries may attempt to hide artifacts associated with their behaviors to evade detection.
- ▌ Attack Mob T1676 Linked Devices · santosomar bundleAnalyze MITRE ATT&CK T1676 Linked Devices in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1676, Linked Devices, or mobile ATT&CK. Adversaries may abuse the “linked devices” feature on messaging applications, such as Signal and WhatsApp, to register the user’s account to an adversary-controlled device.
- ▌ Attack Ent T1074 Data Staged · santosomar bundleAnalyze MITRE ATT&CK T1074 Data Staged in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1074, Data Staged, or enterprise ATT&CK. Adversaries may stage collected data in a central location or directory prior to Exfiltration.
- ▌ Attack Ent T1102 Web Service · santosomar bundleAnalyze MITRE ATT&CK T1102 Web Service in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1102, Web Service, or enterprise ATT&CK. Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system.
- ▌ Attack Ent T1596 004 Cdns · santosomar bundleAnalyze MITRE ATT&CK T1596.004 CDNs in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1596.004, CDNs, or enterprise ATT&CK. Adversaries may search content delivery network (CDN) data about victims that can be used during targeting.
- ▌ Attack Ics T0806 Brute Force I O · santosomar bundleAnalyze MITRE ATT&CK T0806 Brute Force I/O in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0806, Brute Force I/O, or ics ATT&CK. Adversaries may repetitively or successively change I/O point values to perform an action.
- ▌ Attack Ics T0827 Loss Of Control · santosomar bundleAnalyze MITRE ATT&CK T0827 Loss of Control in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0827, Loss of Control, or ics ATT&CK. Adversaries may seek to achieve a sustained loss of control or a runaway condition in which operators cannot issue any commands even if the malicious interference has subsided.
- ▌ Attack Ics T0843 002 Online Edit · santosomar bundleAnalyze MITRE ATT&CK T0843.002 Online Edit in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0843.002, Online Edit, or ics ATT&CK. Adversaries may execute an online edit of a PLC to update parts of an existing program.
- ▌ Attack Ics T0886 Remote Services · santosomar bundleAnalyze MITRE ATT&CK T0886 Remote Services in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0886, Remote Services, or ics ATT&CK. Adversaries may leverage remote services to move between assets and network segments.
- ▌ Attack Ent T1592 001 Hardware · santosomar bundleAnalyze MITRE ATT&CK T1592.001 Hardware in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1592.001, Hardware, or enterprise ATT&CK. Adversaries may gather information about the victim's host hardware that can be used during targeting.
- ▌ Attack Ent T1592 002 Software · santosomar bundleAnalyze MITRE ATT&CK T1592.002 Software in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1592.002, Software, or enterprise ATT&CK. Adversaries may gather information about the victim's host software that can be used during targeting.
- ▌ Attack Ent T1592 003 Firmware · santosomar bundleAnalyze MITRE ATT&CK T1592.003 Firmware in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1592.003, Firmware, or enterprise ATT&CK. Adversaries may gather information about the victim's host firmware that can be used during targeting.
- ▌ Attack Ics T0817 Drive By Compromise · santosomar bundleAnalyze MITRE ATT&CK T0817 Drive-by Compromise in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0817, Drive-by Compromise, or ics ATT&CK. Adversaries may gain access to a system during a drive-by compromise, when a user visits a website as part of a regular browsing session.