Loading the current evidence view. Navigation and account controls remain available.
ATT&CK knowledge
Loading the current evidence view. Navigation and account controls remain available.
mitre att&ck · enterprise
254 parent techniques across 15 tactics. Each cell is shaded by how many tracked actors use it. Click through to the actors, the software that implements it, and every matching indicator we hold.
Discovery
discovery · 34
T1082
System Information Discovery
57 actors
T1083
File and Directory Discovery
51 actors
T1016
System Network Configuration Discovery
43 actors
T1057
Process Discovery
41 actors
T1018
Remote System Discovery
40 actors
T1033
System Owner/User Discovery
40 actors
T1049
System Network Connections Discovery
32 actors
T1046
Network Service Discovery
31 actors
T1012
Query Registry
19 actors
T1135
Network Share Discovery
16 actors
T1007
System Service Discovery
15 actors
T1124
System Time Discovery
14 actors
+22 more
Stealth
stealth · 30
T1078
Valid Accounts
45 actors
T1140
Deobfuscate/Decode Files or Information
38 actors
T1036
Masquerading
20 actors
T1027
Obfuscated Files or Information
18 actors
T1055
Process Injection
15 actors
T1221
Template Injection
8 actors
Persistence
persistence · 22
T1078
Valid Accounts
45 actors
T1112
Modify Registry
29 actors
T1133
External Remote Services
28 actors
T1197
BITS Jobs
5 actors
T1037
Boot or Logon Initialization Scripts
4 actors
T1098
Account Manipulation
4 actors
Execution
execution · 20
T1047
Windows Management Instrumentation
42 actors
T1203
Exploitation for Client Execution
41 actors
T1106
Native API
20 actors
T1059
Command and Scripting Interpreter
17 actors
T1072
Software Deployment Tools
7 actors
T1197
BITS Jobs
5 actors
Command and Control
command-and-control · 18
T1105
Ingress Tool Transfer
86 actors
T1090
Proxy
19 actors
T1571
Non-Standard Port
17 actors
T1102
Web Service
15 actors
T1572
Protocol Tunneling
15 actors
T1095
Non-Application Layer Protocol
12 actors
Defense Impairment
defense-impairment · 18
T1685
Disable or Modify Tools
32 actors
T1112
Modify Registry
29 actors
T1686
Disable or Modify System Firewall
13 actors
T1690
Prevent Command History Logging
4 actors
T1553
Subvert Trust Controls
1 actor
T1556
Modify Authentication Process
1 actor
Credential Access
credential-access · 17
T1110
Brute Force
15 actors
T1003
OS Credential Dumping
13 actors
T1555
Credentials from Password Stores
12 actors
T1040
Network Sniffing
8 actors
T1539
Steal Web Session Cookie
8 actors
T1111
Multi-Factor Authentication Interception
4 actors
Collection
collection · 17
T1005
Data from Local System
45 actors
T1119
Automated Collection
21 actors
T1113
Screen Capture
19 actors
T1560
Archive Collected Data
13 actors
T1039
Data from Network Shared Drive
8 actors
T1074
Data Staged
5 actors
Impact
impact · 15
T1486
Data Encrypted for Impact
18 actors
T1657
Financial Theft
15 actors
T1489
Service Stop
7 actors
T1490
Inhibit System Recovery
7 actors
T1485
Data Destruction
6 actors
T1529
System Shutdown/Reboot
4 actors
Privilege Escalation
privilege-escalation · 13
T1078
Valid Accounts
45 actors
T1068
Exploitation for Privilege Escalation
22 actors
T1055
Process Injection
15 actors
T1037
Boot or Logon Initialization Scripts
4 actors
T1098
Account Manipulation
4 actors
T1134
Access Token Manipulation
3 actors
Reconnaissance
reconnaissance · 12
T1589
Gather Victim Identity Information
10 actors
T1591
Gather Victim Org Information
7 actors
T1593
Search Open Websites/Domains
6 actors
T1594
Search Victim-Owned Websites
6 actors
T1598
Phishing for Information
5 actors
T1590
Gather Victim Network Information
3 actors
Initial Access
initial-access · 11
T1078
Valid Accounts
45 actors
T1190
Exploit Public-Facing Application
44 actors
T1189
Drive-by Compromise
31 actors
T1133
External Remote Services
28 actors
T1199
Trusted Relationship
12 actors
T1091
Replication Through Removable Media
8 actors
Resource Development
resource-development · 9
T1583
Acquire Infrastructure
8 actors
T1585
Establish Accounts
5 actors
T1587
Develop Capabilities
3 actors
T1608
Stage Capabilities
1 actor
T1650
Acquire Access
1 actor
T1584
Compromise Infrastructure
no tracked actors
most-used across the matrix
tracked actors using it
+18 more
+10 more
+8 more
+6 more
+6 more
+5 more
+5 more
+3 more
+1 more
what this matrix is for
Every indicator we resolve is tagged with the techniques its behaviour implies. That makes the matrix a coverage map in both directions: pick a technique to see which actors and which of our indicators exercise it, or start from a verdict and walk up to the tactic it belongs to.
Only parent techniques appear here. Sub-techniques are reachable from any technique page, actor profile, or search result.