santosomar
- 800 skills
- 0 followers
- 11 hours ago last updated
- ▌ Attack Ics T0860 Wireless Compromise · santosomar bundleAnalyze MITRE ATT&CK T0860 Wireless Compromise in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0860, Wireless Compromise, or ics ATT&CK. Adversaries may perform wireless compromise as a method of gaining communications and unauthorized access to a wireless network.
- ▌ Attack Ics T1691 001 Command Message · santosomar bundleAnalyze MITRE ATT&CK T1691.001 Command Message in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1691.001, Command Message, or ics ATT&CK. Adversaries may block a command message from reaching its intended target to prevent command execution.
- ▌ Attack Ics T1692 001 Command Message · santosomar bundleAnalyze MITRE ATT&CK T1692.001 Command Message in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1692.001, Command Message, or ics ATT&CK. Adversaries may send unauthorized command messages to instruct control system assets to perform actions outside of their intended functionality, or without the logical preconditions to trigger their expected function.
- ▌ Attack Ent T1110 Brute Force · santosomar bundleAnalyze MITRE ATT&CK T1110 Brute Force in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1110, Brute Force, or enterprise ATT&CK. Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.(Citation: TrendMicro Pawn Storm Dec 2020) Without knowledge of the password for an a…
- ▌ Attack Ent T1127 001 Msbuild · santosomar bundleAnalyze MITRE ATT&CK T1127.001 MSBuild in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1127.001, MSBuild, or enterprise ATT&CK. Adversaries may use MSBuild to proxy execution of code through a trusted Windows utility.
- ▌ Attack Ent T1127 003 Jamplus · santosomar bundleAnalyze MITRE ATT&CK T1127.003 JamPlus in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1127.003, JamPlus, or enterprise ATT&CK. Adversaries may use `JamPlus` to proxy the execution of a malicious script.
- ▌ Attack Ent T1137 006 Add Ins · santosomar bundleAnalyze MITRE ATT&CK T1137.006 Add-ins in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1137.006, Add-ins, or enterprise ATT&CK. Adversaries may abuse Microsoft Office add-ins to obtain persistence on a compromised system.
- ▌ Attack Ent T1218 007 Msiexec · santosomar bundleAnalyze MITRE ATT&CK T1218.007 Msiexec in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1218.007, Msiexec, or enterprise ATT&CK. Adversaries may abuse msiexec.exe to proxy execution of malicious payloads.
- ▌ Attack Ics T0815 Denial Of View · santosomar bundleAnalyze MITRE ATT&CK T0815 Denial of View in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0815, Denial of View, or ics ATT&CK. Adversaries may cause a denial of view in attempt to disrupt and prevent operator oversight on the status of an ICS environment.
- ▌ Attack Ics T0845 Program Upload · santosomar bundleAnalyze MITRE ATT&CK T0845 Program Upload in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0845, Program Upload, or ics ATT&CK. Adversaries may attempt to upload a program from a PLC to gather information about an industrial process.
- ▌ Attack Ics T0852 Screen Capture · santosomar bundleAnalyze MITRE ATT&CK T0852 Screen Capture in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0852, Screen Capture, or ics ATT&CK. Adversaries may attempt to perform screen capture of devices in the control system environment.
- ▌ Attack Ics T0859 Valid Accounts · santosomar bundleAnalyze MITRE ATT&CK T0859 Valid Accounts in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0859, Valid Accounts, or ics ATT&CK. Adversaries may steal the credentials of a specific user or service account using credential access techniques.
- ▌ Attack Ics T0863 User Execution · santosomar bundleAnalyze MITRE ATT&CK T0863 User Execution in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0863, User Execution, or ics ATT&CK. Adversaries may rely on a targeted organizations user interaction for the execution of malicious code.
- ▌ Attack Ics T0880 Loss Of Safety · santosomar bundleAnalyze MITRE ATT&CK T0880 Loss of Safety in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0880, Loss of Safety, or ics ATT&CK. Adversaries may compromise safety system functions designed to maintain safe operation of a process when unacceptable or dangerous conditions occur.
- ▌ Attack Ics T0889 Modify Program · santosomar bundleAnalyze MITRE ATT&CK T0889 Modify Program in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0889, Modify Program, or ics ATT&CK. Adversaries may modify or add a program on a controller to affect how it interacts with the physical process, peripheral devices and other hosts on the network.
- ▌ Attack Ics T1695 001 Serial Com · santosomar bundleAnalyze MITRE ATT&CK T1695.001 Serial COM in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1695.001, Serial COM, or ics ATT&CK. Adversaries may block access to serial COM to prevent instructions or configurations from reaching target devices.
- ▌ Attack Ics T0843 003 Program Append · santosomar bundleAnalyze MITRE ATT&CK T0843.003 Program Append in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0843.003, Program Append, or ics ATT&CK. Adversaries may execute a program append to a PLC to update parts of an existing program.
- ▌ Attack Ics T0879 Damage To Property · santosomar bundleAnalyze MITRE ATT&CK T0879 Damage to Property in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0879, Damage to Property, or ics ATT&CK. Adversaries may cause damage and destruction of property to infrastructure, equipment, and the surrounding environment when attacking control systems.
- ▌ Attack Ics T0885 Commonly Used Port · santosomar bundleAnalyze MITRE ATT&CK T0885 Commonly Used Port in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0885, Commonly Used Port, or ics ATT&CK. Adversaries may communicate over a commonly used port to bypass firewalls or network detection systems and to blend in with normal network activity, to avoid more detailed inspection.
- ▌ Attack Mob T1516 Input Injection · santosomar bundleAnalyze MITRE ATT&CK T1516 Input Injection in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1516, Input Injection, or mobile ATT&CK. A malicious application can inject input to the user interface to mimic user interaction through the abuse of Android's accessibility APIs.
- ▌ Attack Mob T1521 003 Ssl Pinning · santosomar bundleAnalyze MITRE ATT&CK T1521.003 SSL Pinning in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1521.003, SSL Pinning, or mobile ATT&CK. Adversaries may use [SSL Pinning](https://attack.mitre.org/techniques/T1521/003) to protect the C2 traffic from being intercepted and analyzed.
- ▌ Attack Mob T1629 Impair Defenses · santosomar bundleAnalyze MITRE ATT&CK T1629 Impair Defenses in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1629, Impair Defenses, or mobile ATT&CK. Adversaries may maliciously modify components of a victim environment in order to hinder or disable defensive mechanisms.
- ▌ Attack Ent T1036 Masquerading · santosomar bundleAnalyze MITRE ATT&CK T1036 Masquerading in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1036, Masquerading, or enterprise ATT&CK. Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools.
- ▌ Attack Ent T1584 005 Botnet · santosomar bundleAnalyze MITRE ATT&CK T1584.005 Botnet in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1584.005, Botnet, or enterprise ATT&CK. Adversaries may compromise numerous third-party systems to form a botnet that can be used during targeting.
- ▌ Attack Ics T0813 Denial Of Control · santosomar bundleAnalyze MITRE ATT&CK T0813 Denial of Control in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0813, Denial of Control, or ics ATT&CK. Adversaries may cause a denial of control to temporarily prevent operators and engineers from interacting with process controls.
- ▌ Attack Ics T0814 Denial Of Service · santosomar bundleAnalyze MITRE ATT&CK T0814 Denial of Service in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0814, Denial of Service, or ics ATT&CK. Adversaries may perform Denial-of-Service (DoS) attacks to disrupt expected device functionality.
- ▌ Attack Ics T0878 Alarm Suppression · santosomar bundleAnalyze MITRE ATT&CK T0878 Alarm Suppression in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0878, Alarm Suppression, or ics ATT&CK. Adversaries may target protection function alarms to prevent them from notifying operators of critical conditions.
- ▌ Attack Ics T0887 Wireless Sniffing · santosomar bundleAnalyze MITRE ATT&CK T0887 Wireless Sniffing in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0887, Wireless Sniffing, or ics ATT&CK. Adversaries may seek to capture radio frequency (RF) communication used for remote control and reporting in distributed environments.
- ▌ Attack Ics T0892 Change Credential · santosomar bundleAnalyze MITRE ATT&CK T0892 Change Credential in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0892, Change Credential, or ics ATT&CK. Adversaries may modify software and device credentials to prevent operator and responder access.
- ▌ Attack Mob T1414 Clipboard Data · santosomar bundleAnalyze MITRE ATT&CK T1414 Clipboard Data in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1414, Clipboard Data, or mobile ATT&CK. Adversaries may abuse clipboard manager APIs to obtain sensitive information copied to the device clipboard.
- ▌ Attack Mob T1481 Web Service · santosomar bundleAnalyze MITRE ATT&CK T1481 Web Service in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1481, Web Service, or mobile ATT&CK. Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system.
- ▌ Attack Mob T1582 Sms Control · santosomar bundleAnalyze MITRE ATT&CK T1582 SMS Control in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1582, SMS Control, or mobile ATT&CK. Adversaries may delete, alter, or send SMS messages without user authorization.
- ▌ Attack Ent T1003 003 Ntds · santosomar bundleAnalyze MITRE ATT&CK T1003.003 NTDS in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1003.003, NTDS, or enterprise ATT&CK. Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as devices, users, and a…
- ▌ Attack Ent T1053 003 Cron · santosomar bundleAnalyze MITRE ATT&CK T1053.003 Cron in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1053.003, Cron, or enterprise ATT&CK. Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code.(Citation: 20 macOS Common Tools and Techniques) The <code>cron</code> utility is a tim…
- ▌ Attack Ent T1546 005 Trap · santosomar bundleAnalyze MITRE ATT&CK T1546.005 Trap in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1546.005, Trap, or enterprise ATT&CK. Adversaries may establish persistence by executing malicious content triggered by an interrupt signal.
- ▌ Attack Ent T1566 Phishing · santosomar bundleAnalyze MITRE ATT&CK T1566 Phishing in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1566, Phishing, or enterprise ATT&CK. Adversaries may send phishing messages to gain access to victim systems.
- ▌ Attack Ent T1588 002 Tool · santosomar bundleAnalyze MITRE ATT&CK T1588.002 Tool in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1588.002, Tool, or enterprise ATT&CK. Adversaries may buy, steal, or download software tools that can be used during targeting.
- ▌ Attack Ics T0843 001 Download All · santosomar bundleAnalyze MITRE ATT&CK T0843.001 Download All in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0843.001, Download All, or ics ATT&CK. Adversaries may execute a full program download to a PLC to overwrite the entire PLC program and configuration to deploy a new project or make major changes.
- ▌ Attack Ics T0843 Program Download · santosomar bundleAnalyze MITRE ATT&CK T0843 Program Download in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0843, Program Download, or ics ATT&CK. Adversaries may perform a program download to transfer a user program to a controller.
- ▌ Attack Ics T0884 Connection Proxy · santosomar bundleAnalyze MITRE ATT&CK T0884 Connection Proxy in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0884, Connection Proxy, or ics ATT&CK. Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications.
- ▌ Attack Mob T1417 Input Capture · santosomar bundleAnalyze MITRE ATT&CK T1417 Input Capture in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1417, Input Capture, or mobile ATT&CK. Adversaries may use methods of capturing user input to obtain credentials or collect information.
- ▌ Attack Mob T1429 Audio Capture · santosomar bundleAnalyze MITRE ATT&CK T1429 Audio Capture in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1429, Audio Capture, or mobile ATT&CK. Adversaries may capture audio to collect information by leveraging standard operating system APIs of a mobile device.
- ▌ Attack Mob T1451 Sim Card Swap · santosomar bundleAnalyze MITRE ATT&CK T1451 SIM Card Swap in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1451, SIM Card Swap, or mobile ATT&CK. Adversaries may gain access to mobile devices through transfers or swaps from victims’ phone numbers to adversary-controlled SIM cards and mobile devices.(Citation: ATT SIM Swap Scams)(Citation: Verizon SIM Swapping) Th…
- ▌ Attack Mob T1512 Video Capture · santosomar bundleAnalyze MITRE ATT&CK T1512 Video Capture in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1512, Video Capture, or mobile ATT&CK. An adversary can leverage a device’s cameras to gather information by capturing video recordings.
- ▌ Attack Ent T1021 004 Ssh · santosomar bundleAnalyze MITRE ATT&CK T1021.004 SSH in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1021.004, SSH, or enterprise ATT&CK. Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to log into remote machines using Secure Shell (SSH).
- ▌ Attack Ent T1021 005 Vnc · santosomar bundleAnalyze MITRE ATT&CK T1021.005 VNC in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1021.005, VNC, or enterprise ATT&CK. Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to remotely control machines using Virtual Network Computing (VNC).
- ▌ Attack Ent T1059 011 Lua · santosomar bundleAnalyze MITRE ATT&CK T1059.011 Lua in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1059.011, Lua, or enterprise ATT&CK. Adversaries may abuse Lua commands and scripts for execution.
- ▌ Attack Ent T1071 004 Dns · santosomar bundleAnalyze MITRE ATT&CK T1071.004 DNS in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1071.004, DNS, or enterprise ATT&CK. Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic.
- ▌ Attack Ent T1218 014 Mmc · santosomar bundleAnalyze MITRE ATT&CK T1218.014 MMC in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1218.014, MMC, or enterprise ATT&CK. Adversaries may abuse mmc.exe to proxy execution of malicious .msc files.
- ▌ Attack Ent T1574 001 Dll · santosomar bundleAnalyze MITRE ATT&CK T1574.001 DLL in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1574.001, DLL, or enterprise ATT&CK. Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses.
- ▌ Attack Ent T1590 002 Dns · santosomar bundleAnalyze MITRE ATT&CK T1590.002 DNS in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1590.002, DNS, or enterprise ATT&CK. Adversaries may gather information about the victim's DNS that can be used during targeting.
- ▌ Attack Ent T1542 003 Bootkit · santosomar bundleAnalyze MITRE ATT&CK T1542.003 Bootkit in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1542.003, Bootkit, or enterprise ATT&CK. Adversaries may use bootkits to persist on systems.
- ▌ Attack Ent T1542 Pre Os Boot · santosomar bundleAnalyze MITRE ATT&CK T1542 Pre-OS Boot in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1542, Pre-OS Boot, or enterprise ATT&CK. Adversaries may abuse Pre-OS Boot mechanisms as a way to establish persistence on a system.
- ▌ Attack Ent T1583 001 Domains · santosomar bundleAnalyze MITRE ATT&CK T1583.001 Domains in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1583.001, Domains, or enterprise ATT&CK. Adversaries may acquire domains that can be used during targeting.
- ▌ Attack Ent T1584 001 Domains · santosomar bundleAnalyze MITRE ATT&CK T1584.001 Domains in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1584.001, Domains, or enterprise ATT&CK. Adversaries may hijack domains and/or subdomains that can be used during targeting.
- ▌ Attack Ent T1587 001 Malware · santosomar bundleAnalyze MITRE ATT&CK T1587.001 Malware in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1587.001, Malware, or enterprise ATT&CK. Adversaries may develop malware and malware components that can be used during targeting.
- ▌ Attack Ent T1588 001 Malware · santosomar bundleAnalyze MITRE ATT&CK T1588.001 Malware in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1588.001, Malware, or enterprise ATT&CK. Adversaries may buy, steal, or download malware that can be used during targeting.
- ▌ Attack Ics T0837 Loss Of Protection · santosomar bundleAnalyze MITRE ATT&CK T0837 Loss of Protection in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0837, Loss of Protection, or ics ATT&CK. Adversaries may compromise protective system functions designed to prevent the effects of faults and abnormal conditions.
- ▌ Attack Ent T1003 006 Dcsync · santosomar bundleAnalyze MITRE ATT&CK T1003.006 DCSync in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1003.006, DCSync, or enterprise ATT&CK. Adversaries may attempt to access credentials and other sensitive information by abusing a Windows Domain Controller's application programming interface (API)(Citation: Microsoft DRSR Dec 2017) (Citation: Microsoft GetN…
- ▌ Attack Ent T1059 006 Python · santosomar bundleAnalyze MITRE ATT&CK T1059.006 Python in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1059.006, Python, or enterprise ATT&CK. Adversaries may abuse Python commands and scripts for execution.
- ▌ Attack Ent T1106 Native API · santosomar bundleAnalyze MITRE ATT&CK T1106 Native API in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1106, Native API, or enterprise ATT&CK. Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
- ▌ Attack Ent T1216 001 Pubprn · santosomar bundleAnalyze MITRE ATT&CK T1216.001 PubPrn in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1216.001, PubPrn, or enterprise ATT&CK. Adversaries may use PubPrn to proxy execution of malicious remote files.
- ▌ Attack Ent T1491 Defacement · santosomar bundleAnalyze MITRE ATT&CK T1491 Defacement in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1491, Defacement, or enterprise ATT&CK. Adversaries may modify visual content available internally or externally to an enterprise network, thus affecting the integrity of the original content.
- ▌ Attack Ent T1583 004 Server · santosomar bundleAnalyze MITRE ATT&CK T1583.004 Server in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1583.004, Server, or enterprise ATT&CK. Adversaries may buy, lease, rent, or obtain physical servers that can be used during targeting.
- ▌ Attack Ent T1583 005 Botnet · santosomar bundleAnalyze MITRE ATT&CK T1583.005 Botnet in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1583.005, Botnet, or enterprise ATT&CK. Adversaries may buy, lease, or rent a network of compromised systems that can be used during targeting.
- ▌ Attack Ent T1584 004 Server · santosomar bundleAnalyze MITRE ATT&CK T1584.004 Server in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1584.004, Server, or enterprise ATT&CK. Adversaries may compromise third-party servers that can be used during targeting.
- ▌ Attack Ent T1218 003 Cmstp · santosomar bundleAnalyze MITRE ATT&CK T1218.003 CMSTP in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1218.003, CMSTP, or enterprise ATT&CK. Adversaries may abuse CMSTP to proxy execution of malicious code.
- ▌ Attack Ent T1218 005 Mshta · santosomar bundleAnalyze MITRE ATT&CK T1218.005 Mshta in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1218.005, Mshta, or enterprise ATT&CK. Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and Javascript or VBScript through a trusted Windows utility.
- ▌ Attack Ent T1546 014 Emond · santosomar bundleAnalyze MITRE ATT&CK T1546.014 Emond in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1546.014, Emond, or enterprise ATT&CK. Adversaries may gain persistence and elevate privileges by executing malicious content triggered by the Event Monitor Daemon (emond).
- ▌ Attack Ent T1561 Disk Wipe · santosomar bundleAnalyze MITRE ATT&CK T1561 Disk Wipe in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1561, Disk Wipe, or enterprise ATT&CK. Adversaries may wipe or corrupt raw disk data on specific systems or in large numbers in a network to interrupt availability to system and network resources.
- ▌ Attack Ent T1596 002 Whois · santosomar bundleAnalyze MITRE ATT&CK T1596.002 WHOIS in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1596.002, WHOIS, or enterprise ATT&CK. Adversaries may search public WHOIS data for information about victims that can be used during targeting.
- ▌ Attack Ics T0809 Data Destruction · santosomar bundleAnalyze MITRE ATT&CK T0809 Data Destruction in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0809, Data Destruction, or ics ATT&CK. Adversaries may perform data destruction over the course of an operation.
- ▌ Attack Ics T0836 Modify Parameter · santosomar bundleAnalyze MITRE ATT&CK T0836 Modify Parameter in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0836, Modify Parameter, or ics ATT&CK. Adversaries may modify parameters used to instruct industrial control system devices.
- ▌ Attack Ics T0842 Network Sniffing · santosomar bundleAnalyze MITRE ATT&CK T0842 Network Sniffing in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0842, Network Sniffing, or ics ATT&CK. Network sniffing is the practice of using a network interface on a computer system to monitor or capture information (Citation: Enterprise ATT&CK January 2018) regardless of whether it is the specified destination for t…
- ▌ Attack Ics T0849 Masquerading · santosomar bundleAnalyze MITRE ATT&CK T0849 Masquerading in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0849, Masquerading, or ics ATT&CK. Adversaries may use masquerading to disguise a malicious application or executable as another file, to avoid operator and engineer suspicion.
- ▌ Attack Ics T0881 Service Stop · santosomar bundleAnalyze MITRE ATT&CK T0881 Service Stop in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0881, Service Stop, or ics ATT&CK. Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
- ▌ Attack Ics T1695 002 Ethernet · santosomar bundleAnalyze MITRE ATT&CK T1695.002 Ethernet in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1695.002, Ethernet, or ics ATT&CK. Adversaries may block access to Ethernet communications to prevent instructions or configurations messages from reaching target systems and devices.
- ▌ Attack Ent T1053 002 At · santosomar bundleAnalyze MITRE ATT&CK T1053.002 At in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1053.002, At, or enterprise ATT&CK. Adversaries may abuse the [at](https://attack.mitre.org/software/S0110) utility to perform task scheduling for initial or recurring execution of malicious code.
- ▌ Attack Ics T0846 001 Port Scan · santosomar bundleAnalyze MITRE ATT&CK T0846.001 Port Scan in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0846.001, Port Scan, or ics ATT&CK. Adversaries may perform a port scan on a system, device, or network to identify live hosts, enumerate open ports and running services, identify operating systems, and map out the network.(Citation: NIST SP 800-82r3) The…
- ▌ Attack Ics T0895 Autorun Image · santosomar bundleAnalyze MITRE ATT&CK T0895 Autorun Image in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0895, Autorun Image, or ics ATT&CK. Adversaries may leverage AutoRun functionality or scripts to execute malicious code.
- ▌ Attack Mob T1575 Native API · santosomar bundleAnalyze MITRE ATT&CK T1575 Native API in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1575, Native API, or mobile ATT&CK. Adversaries may use Android’s Native Development Kit (NDK) to write native functions that can achieve execution of binaries or functions.
- ▌ Attack Ent T1014 Rootkit · santosomar bundleAnalyze MITRE ATT&CK T1014 Rootkit in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1014, Rootkit, or enterprise ATT&CK. Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components.
- ▌ Attack Ics T1693 Modify Firmware · santosomar bundleAnalyze MITRE ATT&CK T1693 Modify Firmware in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1693, Modify Firmware, or ics ATT&CK. Firmware is low-level software embedded in hardware that enables systems and devices to function properly and is commonly found in ICS environments.
- ▌ Attack Mob T1616 Call Control · santosomar bundleAnalyze MITRE ATT&CK T1616 Call Control in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1616, Call Control, or mobile ATT&CK. Adversaries may make, forward, or block phone calls without user authorization.
- ▌ Attack Mob T1634 001 Keychain · santosomar bundleAnalyze MITRE ATT&CK T1634.001 Keychain in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1634.001, Keychain, or mobile ATT&CK. Adversaries may collect keychain data from an iOS device to acquire credentials.
- ▌ Attack Mob T1636 002 Call Log · santosomar bundleAnalyze MITRE ATT&CK T1636.002 Call Log in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1636.002, Call Log, or mobile ATT&CK. Adversaries may utilize standard operating system APIs to gather call log data.
- ▌ Attack Mob T1636 005 Accounts · santosomar bundleAnalyze MITRE ATT&CK T1636.005 Accounts in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1636.005, Accounts, or mobile ATT&CK. Adversaries may utilize standard operating system APIs to gather account data.
- ▌ Attack Mob T1655 Masquerading · santosomar bundleAnalyze MITRE ATT&CK T1655 Masquerading in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1655, Masquerading, or mobile ATT&CK. Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools.
- ▌ Attack Ent T1197 Bits Jobs · santosomar bundleAnalyze MITRE ATT&CK T1197 BITS Jobs in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1197, BITS Jobs, or enterprise ATT&CK. Adversaries may abuse BITS jobs to persistently execute code and perform various background tasks.
- ▌ Attack Ics T1695 003 Wi Fi · santosomar bundleAnalyze MITRE ATT&CK T1695.003 Wi-Fi in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1695.003, Wi-Fi, or ics ATT&CK. Adversaries may block access to Wi-Fi communications to prevent messages from reaching target systems and devices.
- ▌ Attack Ics T0834 Native API · santosomar bundleAnalyze MITRE ATT&CK T0834 Native API in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0834, Native API, or ics ATT&CK. Adversaries may directly interact with the native OS application programming interface (API) to access system functions.
- ▌ Attack Mob T1617 Hooking · santosomar bundleAnalyze MITRE ATT&CK T1617 Hooking in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1617, Hooking, or mobile ATT&CK. Adversaries may utilize hooking to hide the presence of artifacts associated with their behaviors to evade detection.
- ▌ Attack Mob T1660 Phishing · santosomar bundleAnalyze MITRE ATT&CK T1660 Phishing in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1660, Phishing, or mobile ATT&CK. Adversaries may send malicious content to users in order to gain access to their mobile devices.
- ▌ Attack Ent T1090 Proxy · santosomar bundleAnalyze MITRE ATT&CK T1090 Proxy in the enterprise matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1090, Proxy, or enterprise ATT&CK. Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure.
- ▌ Attack Ics T0829 Loss Of View · santosomar bundleAnalyze MITRE ATT&CK T0829 Loss of View in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0829, Loss of View, or ics ATT&CK. Adversaries may cause a sustained or permanent loss of view where the ICS equipment will require local, hands-on operator intervention; for instance, a restart or manual operation.
- ▌ Attack Ics T0848 Rogue Master · santosomar bundleAnalyze MITRE ATT&CK T0848 Rogue Master in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0848, Rogue Master, or ics ATT&CK. Adversaries may setup a rogue master to leverage control server functions to communicate with outstations.
- ▌ Attack Ics T0851 Rootkit · santosomar bundleAnalyze MITRE ATT&CK T0851 Rootkit in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0851, Rootkit, or ics ATT&CK. Adversaries may deploy rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components.
- ▌ Attack Ics T0874 Hooking · santosomar bundleAnalyze MITRE ATT&CK T0874 Hooking in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0874, Hooking, or ics ATT&CK. Adversaries may hook into application programming interface (API) functions used by processes to redirect calls for execution and privilege escalation means.
- ▌ Attack Ics T0853 Scripting · santosomar bundleAnalyze MITRE ATT&CK T0853 Scripting in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0853, Scripting, or ics ATT&CK. Adversaries may use scripting languages to execute arbitrary code in the form of a pre-written script or in the form of user-supplied code to an interpreter.
- ▌ Attack Ics T0877 I O Image · santosomar bundleAnalyze MITRE ATT&CK T0877 I/O Image in the ics matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T0877, I/O Image, or ics ATT&CK. Adversaries may seek to capture process values related to the inputs and outputs of a PLC.