Files
2026-05-01 23:10:14 -04:00

42 KiB

1TacticTechnique #Technique NameTest #Test NameTest GUIDExecutor Name
2stealthT1027.013Obfuscated Files or Information: Encrypted/Encoded File1Decode Eicar File and Write to File7693ccaa-8d64-4043-92a5-a2eb70359535powershell
3stealthT1027.013Obfuscated Files or Information: Encrypted/Encoded File2Decrypt Eicar File and Write to Fileb404caaa-12ce-43c7-9214-62a531c044f7powershell
4stealthT1027.013Obfuscated Files or Information: Encrypted/Encoded File3Password-Protected ZIP Payload Extraction and Executionc2ca068a-eb1e-498f-9f93-3d554c455916bash
5stealthT1036.005Masquerading: Match Legitimate Name or Location1Execute a process from a directory masquerading as the current parent directory812c3ab8-94b0-4698-a9bf-9420af23ce24sh
6stealthT1497.001Virtualization/Sandbox Evasion: System Checks4Detect Virtualization Environment via iorega960185f-aef6-4547-8350-d1ce16680d09sh
7stealthT1497.001Virtualization/Sandbox Evasion: System Checks6Detect Virtualization Environment using sysctl (hw.model)6beae646-eb4c-4730-95be-691a4094408csh
8stealthT1497.001Virtualization/Sandbox Evasion: System Checks7Check if System Integrity Protection is enabled2b73cd9b-b2fb-4357-b9d7-c73c41d9e945sh
9stealthT1497.001Virtualization/Sandbox Evasion: System Checks8Detect Virtualization Environment using system_profilere04d2e89-de15-4d90-92f9-a335c7337f0fsh
10stealthT1070.003Indicator Removal on Host: Clear Command History1Clear Bash history (rm)a934276e-2be5-4a36-93fd-98adbb5bd4fcsh
11stealthT1070.003Indicator Removal on Host: Clear Command History3Clear Bash history (cat dev/null)b1251c35-dcd3-4ea1-86da-36d27b54f31fsh
12stealthT1070.003Indicator Removal on Host: Clear Command History4Clear Bash history (ln dev/null)23d348f3-cc5c-4ba9-bd0a-ae09069f0914sh
13stealthT1070.003Indicator Removal on Host: Clear Command History6Clear history of a bunch of shells7e6721df-5f08-4370-9255-f06d8a77af4csh
14stealthT1070.003Indicator Removal on Host: Clear Command History7Clear and Disable Bash History Logging784e4011-bd1a-4ecd-a63a-8feb278512e6bash
15stealthT1070.003Indicator Removal on Host: Clear Command History8Use Space Before Command to Avoid Logging to History53b03a54-4529-4992-852d-a00b4b7215a6sh
16stealthT1140Deobfuscate/Decode Files or Information3Base64 decoding with Python356dc0e8-684f-4428-bb94-9313998ad608sh
17stealthT1140Deobfuscate/Decode Files or Information4Base64 decoding with Perl6604d964-b9f6-4d4b-8ce8-499829a14d0ash
18stealthT1140Deobfuscate/Decode Files or Information5Base64 decoding with shell utilitiesb4f6a567-a27a-41e5-b8ef-ac4b4008bb7esh
19stealthT1140Deobfuscate/Decode Files or Information8Hex decoding with shell utilities005943f9-8dd5-4349-8b46-0313c0a9f973sh
20stealthT1140Deobfuscate/Decode Files or Information9Linux Base64 Encoded Shebang in CLI3a15c372-67c1-4430-ac8e-ec06d641ce4dsh
21stealthT1140Deobfuscate/Decode Files or Information10XOR decoding and command execution using Pythonc3b65cd5-ee51-4e98-b6a3-6cbdec138efcbash
22stealthT1070.008Email Collection: Mailbox Manipulation3Copy and Delete Mailbox Data on macOS3824130e-a6e4-4528-8091-3a52eeb540f6bash
23stealthT1070.008Email Collection: Mailbox Manipulation6Copy and Modify Mailbox Data on macOS8a0b1579-5a36-483a-9cde-0236983e1665bash
24stealthT1070.006Indicator Removal on Host: Timestomp1Set a file's access timestamp5f9113d5-ed75-47ed-ba23-ea3573d05810sh
25stealthT1070.006Indicator Removal on Host: Timestomp2Set a file's modification timestamp20ef1523-8758-4898-b5a2-d026cc3d2c52sh
26stealthT1070.006Indicator Removal on Host: Timestomp3Set a file's creation timestamp8164a4a6-f99c-4661-ac4f-80f5e4e78d2bsh
27stealthT1070.006Indicator Removal on Host: Timestomp4Modify file timestamps using reference file631ea661-d661-44b0-abdb-7a7f3fc08e50sh
28stealthT1070.006Indicator Removal on Host: Timestomp9MacOS - Timestomp Date Modified87fffff4-d371-4057-a539-e3b24c37e564sh
29stealthT1497.003Time Based Evasion1Delay execution with ping8b87dd03-8204-478c-bac3-3959f6528de3sh
30stealthT1027.001Obfuscated Files or Information: Binary Padding1Pad Binary to Change Hash - Linux/macOS ddffe2346c-abd5-4b45-a713-bf5f1ebd573ash
31stealthT1027.001Obfuscated Files or Information: Binary Padding2Pad Binary to Change Hash using truncate command - Linux/macOSe22a9e89-69c7-410f-a473-e6c212cd2292sh
32stealthT1078.001Valid Accounts: Default Accounts3Enable Guest Account on macOS0315bdff-4178-47e9-81e4-f31a6d23f7e4sh
33stealthT1574.006Hijack Execution Flow: LD_PRELOAD3Dylib Injection via DYLD_INSERT_LIBRARIES4d66029d-7355-43fd-93a4-b63ba92ea1bebash
34stealthT1564.002Hide Artifacts: Hidden Users1Create Hidden User using UniqueID < 5004238a7f0-a980-4fff-98a2-dfc0a363d507sh
35stealthT1564.002Hide Artifacts: Hidden Users2Create Hidden User using IsHidden optionde87ed7b-52c3-43fd-9554-730f695e7f31sh
36stealthT1027Obfuscated Files or Information1Decode base64 Data into Scriptf45df6be-2e1e-4136-a384-8f18ab3826fbsh
37stealthT1027.004Obfuscated Files or Information: Compile After Delivery3C compiled0377aa6-850a-42b2-95f0-de558d80be57sh
38stealthT1027.004Obfuscated Files or Information: Compile After Delivery4CC compileda97bb11-d6d0-4fc1-b445-e443d1346efesh
39stealthT1027.004Obfuscated Files or Information: Compile After Delivery5Go compile78bd3fa7-773c-449e-a978-dc1f1500bc52sh
40stealthT1070.004Indicator Removal on Host: File Deletion1Delete a single file - FreeBSD/Linux/macOS562d737f-2fc6-4b09-8c2a-7f8ff0828480sh
41stealthT1070.004Indicator Removal on Host: File Deletion2Delete an entire folder - FreeBSD/Linux/macOSa415f17e-ce8d-4ce2-a8b4-83b674e7017esh
42stealthT1027.002Obfuscated Files or Information: Software Packing3Binary simply packed by UPXb16ef901-00bb-4dda-b4fc-a04db5067e20sh
43stealthT1027.002Obfuscated Files or Information: Software Packing4Binary packed by UPX, with modified headers4d46e16b-5765-4046-9f25-a600d3e65e4dsh
44stealthT1036.006Masquerading: Space after Filename1Space After Filename (Manual)89a7dd26-e510-4c9f-9b15-f3bae333360fmanual
45stealthT1036.006Masquerading: Space after Filename2Space After Filenameb95ce2eb-a093-4cd8-938d-5258cef656eash
46stealthT1564.001Hide Artifacts: Hidden Files and Directories1Create a hidden file in a hidden directory61a782e5-9a19-40b5-8ba4-69a4b9f3d7besh
47stealthT1564.001Hide Artifacts: Hidden Files and Directories2Mac Hidden filecddb9098-3b47-4e01-9d3b-6f5f323288a9sh
48stealthT1564.001Hide Artifacts: Hidden Files and Directories5Hidden files3b7015f2-3144-4205-b799-b05580621379sh
49stealthT1564.001Hide Artifacts: Hidden Files and Directories6Hide a Directoryb115ecaf-3b24-4ed2-aefe-2fcb9db913d3sh
50stealthT1564.001Hide Artifacts: Hidden Files and Directories7Show all hidden files9a1ec7da-b892-449f-ad68-67066d04380csh
51stealthT1078.003Valid Accounts: Local Accounts2Create local account with admin privileges - MacOSf1275566-1c26-4b66-83e3-7f9f7f964daabash
52stealthT1078.003Valid Accounts: Local Accounts3Create local account with admin privileges using sysadminctl utility - MacOS191db57d-091a-47d5-99f3-97fde53de505bash
53stealthT1078.003Valid Accounts: Local Accounts4Enable root account using dsenableroot utility - MacOS20b40ea9-0e17-4155-b8e6-244911a678acbash
54stealthT1078.003Valid Accounts: Local Accounts5Add a new/existing user to the admin group using dseditgroup utility - macOS433842ba-e796-4fd5-a14f-95d3a1970875bash
55persistenceT1053.003Scheduled Task/Job: Cron1Cron - Replace crontab with referenced file435057fb-74b1-410e-9403-d81baf194f75sh
56persistenceT1053.003Scheduled Task/Job: Cron2Cron - Add script to all cron subfoldersb7d42afa-9086-4c8a-b7b0-8ea3faa6ebb0bash
57persistenceT1176Browser Extensions1Chrome/Chromium (Developer Mode)3ecd790d-2617-4abf-9a8c-4e8d47da9ee1manual
58persistenceT1176Browser Extensions2Firefoxcb790029-17e6-4c43-b96f-002ce5f10938manual
59persistenceT1176Browser Extensions3Edge Chromium Addon - VPN3d456e2b-a7db-4af8-b5b3-720e7c4d9da5manual
60persistenceT1037.002Boot or Logon Initialization Scripts: Logon Script (Mac)1Logon Scripts - Macf047c7de-a2d9-406e-a62b-12a09d9516f4manual
61persistenceT1543.004Create or Modify System Process: Launch Daemon1Launch Daemon03ab8df5-3a6b-4417-b6bd-bb7a5cfd74cfbash
62persistenceT1078.001Valid Accounts: Default Accounts3Enable Guest Account on macOS0315bdff-4178-47e9-81e4-f31a6d23f7e4sh
63persistenceT1546.005Event Triggered Execution: Trap1Trap EXITa74b2e07-5952-4c03-8b56-56274b076b61sh
64persistenceT1546.005Event Triggered Execution: Trap3Trap SIGINTa547d1ba-1d7a-4cc5-a9cb-8d65e8809636sh
65persistenceT1136.001Create Account: Local Account3Create a user account on a MacOS system01993ba5-1da3-4e15-a719-b690d4f0f0b2bash
66persistenceT1098.004SSH Authorized Keys1Modify SSH Authorized Keys342cc723-127c-4d3a-8292-9c0c6b4ecadcsh
67persistenceT1547.015Boot or Logon Autostart Execution: Login Items2Add macOS LoginItem using Applescript716e756a-607b-41f3-8204-b214baf37c1dbash
68persistenceT1546.014Event Triggered Execution: Emond1Persistance with Event Monitor - emond23c9c127-322b-4c75-95ca-eff464906114sh
69persistenceT1547.006Boot or Logon Autostart Execution: Kernel Modules and Extensions2MacOS - Load Kernel Module via kextload and kmutilf4391089-d3a5-4dd1-ab22-0419527f2672bash
70persistenceT1547.006Boot or Logon Autostart Execution: Kernel Modules and Extensions3MacOS - Load Kernel Module via KextManagerLoadKextWithURL()f0007753-beb3-41ea-9948-760785e4c1e5bash
71persistenceT1546.004Event Triggered Execution: .bash_profile .bashrc and .shrc1Add command to .bash_profile94500ae1-7e31-47e3-886b-c328da46872fsh
72persistenceT1546.004Event Triggered Execution: .bash_profile .bashrc and .shrc2Add command to .bashrc0a898315-4cfa-4007-bafe-33a4646d115fsh
73persistenceT1037.005Boot or Logon Initialization Scripts: Startup Items1Add file to Local Library StartupItems134627c3-75db-410e-bff8-7a920075f198sh
74persistenceT1037.005Boot or Logon Initialization Scripts: Startup Items2Add launch script to launch daemonfc369906-90c7-4a15-86fd-d37da624dde6bash
75persistenceT1037.005Boot or Logon Initialization Scripts: Startup Items3Add launch script to launch agent10cf5bec-49dd-4ebf-8077-8f47e420096fbash
76persistenceT1546.018Event Triggered Execution: Python Startup Hooks4Python Startup Hook - atomic_hook.pth (macOS)28ca4f81-fa96-47ff-8555-dde98017e89bsh
77persistenceT1546.018Event Triggered Execution: Python Startup Hooks5Python Startup Hook - usercustomize.py (Linux / MacOS)6e78084a-a433-4702-a838-cc7b765d87e8sh
78persistenceT1543.001Create or Modify System Process: Launch Agent1Launch Agenta5983dee-bf6c-4eaf-951c-dbc1a7b90900bash
79persistenceT1543.001Create or Modify System Process: Launch Agent2Event Monitor Daemon Persistence11979f23-9b9d-482a-9935-6fc9cd022c3ebash
80persistenceT1543.001Create or Modify System Process: Launch Agent3Launch Agent - Root Directory66774fa8-c562-4bae-a58d-5264a0dd9dd7bash
81persistenceT1037.004Boot or Logon Initialization Scripts: Rc.common1rc.common97a48daa-8bca-4bc0-b1a9-c1d163e762debash
82persistenceT1547.007Boot or Logon Autostart Execution: Re-opened Applications1Copy in loginwindow.plist for Re-Opened Applications5fefd767-ef54-4ac6-84d3-751ab85e8abash
83persistenceT1547.007Boot or Logon Autostart Execution: Re-opened Applications2Re-Opened Applications using LoginHook5f5b71da-e03f-42e7-ac98-d63f9e0465cbsh
84persistenceT1547.007Boot or Logon Autostart Execution: Re-opened Applications3Append to existing loginwindow for Re-Opened Applications766b6c3c-9353-4033-8b7e-38b309fa3a93sh
85persistenceT1078.003Valid Accounts: Local Accounts2Create local account with admin privileges - MacOSf1275566-1c26-4b66-83e3-7f9f7f964daabash
86persistenceT1078.003Valid Accounts: Local Accounts3Create local account with admin privileges using sysadminctl utility - MacOS191db57d-091a-47d5-99f3-97fde53de505bash
87persistenceT1078.003Valid Accounts: Local Accounts4Enable root account using dsenableroot utility - MacOS20b40ea9-0e17-4155-b8e6-244911a678acbash
88persistenceT1078.003Valid Accounts: Local Accounts5Add a new/existing user to the admin group using dseditgroup utility - macOS433842ba-e796-4fd5-a14f-95d3a1970875bash
89command-and-controlT1132.001Data Encoding: Standard Encoding1Base64 Encoded data.1164f70f-9a88-4dff-b9ff-dc70e7bf0c25sh
90command-and-controlT1659Content Injection1MITM Proxy Injection9b360eaf-c778-4f07-a6e7-895c4f01ac1cbash
91command-and-controlT1572Protocol Tunneling5Microsoft Dev tunnels (Linux/macOS)9f94a112-1ce2-464d-a63b-83c1f465f801bash
92command-and-controlT1572Protocol Tunneling6VSCode tunnels (Linux/macOS)b877943f-0377-44f4-8477-f79db7f07c4dsh
93command-and-controlT1572Protocol Tunneling7Cloudflare tunnels (Linux/macOS)228c336a-2f79-4043-8aef-bfa453a611d5sh
94command-and-controlT1090.003Proxy: Multi-hop Proxy4Tor Proxy Usage - MacOS12631354-fdbc-4164-92be-402527e748dash
95command-and-controlT1571Non-Standard Port2Testing usage of uncommonly used port5db21e1d-dd9c-4a50-b885-b1e748912767sh
96command-and-controlT1071.001Application Layer Protocol: Web Protocols3Malicious User Agents - Nix2d7c471a-e887-4b78-b0dc-b0df1f2e0658sh
97command-and-controlT1105Ingress Tool Transfer1rsync remote file copy (push)0fc6e977-cb12-44f6-b263-2824ba917409sh
98command-and-controlT1105Ingress Tool Transfer2rsync remote file copy (pull)3180f7d5-52c0-4493-9ea0-e3431a84773fsh
99command-and-controlT1105Ingress Tool Transfer3scp remote file copy (push)83a49600-222b-4866-80a0-37736ad29344sh
100command-and-controlT1105Ingress Tool Transfer4scp remote file copy (pull)b9d22b9a-9778-4426-abf0-568ea64e9c33sh
101command-and-controlT1105Ingress Tool Transfer5sftp remote file copy (push)f564c297-7978-4aa9-b37a-d90477feea4ebash
102command-and-controlT1105Ingress Tool Transfer6sftp remote file copy (pull)0139dba1-f391-405e-a4f5-f3989f2c88efsh
103command-and-controlT1105Ingress Tool Transfer14whois file downloadc99a829f-0bb8-4187-b2c6-d47d1df74cabsh
104command-and-controlT1105Ingress Tool Transfer31File download via nscurl5bcefe5f-3f30-4f1c-a61a-8d7db3f4450csh
105command-and-controlT1090.001Proxy: Internal Proxy1Connection Proxy0ac21132-4485-4212-a681-349e8a6637cdsh
106command-and-controlT1090.001Proxy: Internal Proxy2Connection Proxy for macOS UI648d68c1-8bcd-4486-9abe-71c6655b6a2csh
107collectionT1560.001Archive Collected Data: Archive via Utility5Data Compressed - nix - zipc51cec55-28dd-4ad2-9461-1eacbc82c3a0bash
108collectionT1560.001Archive Collected Data: Archive via Utility6Data Compressed - nix - gzip Single Filecde3c2af-3485-49eb-9c1f-0ed60e9cc0afsh
109collectionT1560.001Archive Collected Data: Archive via Utility7Data Compressed - nix - tar Folder or File7af2b51e-ad1c-498c-aca8-d3290c19535ash
110collectionT1560.001Archive Collected Data: Archive via Utility8Data Encrypted with zip and gpg symmetric0286eb44-e7ce-41a0-b109-3da516e05a5fsh
111collectionT1560.001Archive Collected Data: Archive via Utility9Encrypts collected data with AES-256 and Base64a743e3a6-e8b2-4a30-abe7-ca85d201b5d3bash
112collectionT1113Screen Capture1Screencapture0f47ceb1-720f-4275-96b8-21f0562217acbash
113collectionT1113Screen Capture2Screencapture (silent)deb7d358-5fbd-4dc4-aecc-ee0054d2d9a4bash
114collectionT1056.001Input Capture: Keylogging8MacOS Swift Keyloggeraee3a097-4c5c-4fff-bbd3-0a705867ae29bash
115collectionT1123Audio Capture3using Quicktime Playerc7a0bb71-70ce-4a53-b115-881f241b795bsh
116collectionT1074.001Data Staged: Local Data Staging2Stage data from Discovery.sh39ce0303-ae16-4b9e-bb5b-4f53e8262066sh
117collectionT1115Clipboard Data3Execute commands from clipboard1ac2247f-65f8-4051-b51f-b0ccdfaaa5ffbash
118collectionT1005Data from Local System3Copy Apple Notes database files using AppleScriptcfb6d400-a269-4c06-a347-6d88d584d5f7sh
119collectionT1056.002Input Capture: GUI Input Capture1AppleScript - Prompt User for Password76628574-0bc1-4646-8fe2-8f4427b47d15bash
120collectionT1056.002Input Capture: GUI Input Capture3AppleScript - Spoofing a credential prompt using osascriptb7037b89-947a-427a-ba29-e7e9f09bc045bash
121lateral-movementT1021.005Remote Services:VNC1Enable Apple Remote Desktop Agent8a930abe-841c-4d4f-a877-72e9fe90b9eash
122defense-impairmentT1222.002File and Directory Permissions Modification: FreeBSD, Linux and Mac File and Directory Permissions Modification1chmod - Change file or folder mode (numeric mode)34ca1464-de9d-40c6-8c77-690adf36a135sh
123defense-impairmentT1222.002File and Directory Permissions Modification: FreeBSD, Linux and Mac File and Directory Permissions Modification2chmod - Change file or folder mode (symbolic mode)fc9d6695-d022-4a80-91b1-381f5c35aff3sh
124defense-impairmentT1222.002File and Directory Permissions Modification: FreeBSD, Linux and Mac File and Directory Permissions Modification3chmod - Change file or folder mode (numeric mode) recursivelyea79f937-4a4d-4348-ace6-9916aec453a4sh
125defense-impairmentT1222.002File and Directory Permissions Modification: FreeBSD, Linux and Mac File and Directory Permissions Modification4chmod - Change file or folder mode (symbolic mode) recursively0451125c-b5f6-488f-993b-5a32b09f7d8fbash
126defense-impairmentT1222.002File and Directory Permissions Modification: FreeBSD, Linux and Mac File and Directory Permissions Modification5chown - Change file or folder ownership and groupd169e71b-85f9-44ec-8343-27093ff3dfc0bash
127defense-impairmentT1222.002File and Directory Permissions Modification: FreeBSD, Linux and Mac File and Directory Permissions Modification6chown - Change file or folder ownership and group recursivelyb78598be-ff39-448f-a463-adbf2a5b7848bash
128defense-impairmentT1222.002File and Directory Permissions Modification: FreeBSD, Linux and Mac File and Directory Permissions Modification7chown - Change file or folder mode ownership only967ba79d-f184-4e0e-8d09-6362b3162e99sh
129defense-impairmentT1222.002File and Directory Permissions Modification: FreeBSD, Linux and Mac File and Directory Permissions Modification8chown - Change file or folder ownership recursively3b015515-b3d8-44e9-b8cd-6fa84faf30b2bash
130defense-impairmentT1222.002File and Directory Permissions Modification: FreeBSD, Linux and Mac File and Directory Permissions Modification9chattr - Remove immutable file attributee7469fe2-ad41-4382-8965-99b94dd3c13fsh
131defense-impairmentT1222.002File and Directory Permissions Modification: FreeBSD, Linux and Mac File and Directory Permissions Modification11Chmod through c script973631cf-6680-4ffa-a053-045e1b6b67absh
132defense-impairmentT1222.002File and Directory Permissions Modification: FreeBSD, Linux and Mac File and Directory Permissions Modification13Chown through c script18592ba1-5f88-4e3c-abc8-ab1c6042e389sh
133defense-impairmentT1553.001Subvert Trust Controls: Gatekeeper Bypass1Gatekeeper Bypassfb3d46c6-9480-4803-8d7d-ce676e1f1a9bsh
134defense-impairmentT1685.006Disable or Modify Tools: Clear Linux or Mac System Logs1rm -rf989cc1b1-3642-4260-a809-54f9dd559683sh
135defense-impairmentT1685.006Disable or Modify Tools: Clear Linux or Mac System Logs3Delete log files using built-in log utility653d39cd-bae7-499a-898c-9fb96b8b5cd1sh
136defense-impairmentT1685.006Disable or Modify Tools: Clear Linux or Mac System Logs4Truncate system log files via truncate utility6290f8a8-8ee9-4661-b9cf-390031bf6973sh
137defense-impairmentT1685.006Disable or Modify Tools: Clear Linux or Mac System Logs6Delete log files via cat utility by appending /dev/null or /dev/zeroc23bdb88-928d-493e-b46d-df2906a50941sh
138defense-impairmentT1685.006Disable or Modify Tools: Clear Linux or Mac System Logs8System log file deletion via find utilitybc8eeb4a-cc3e-45ec-aa6e-41e973da2558sh
139defense-impairmentT1685.006Disable or Modify Tools: Clear Linux or Mac System Logs9Overwrite macOS system log via echo utility0208ea60-98f1-4e8c-8052-930dce8f742csh
140defense-impairmentT1685.006Disable or Modify Tools: Clear Linux or Mac System Logs11Real-time system log clearance/deletion848e43b3-4c0a-4e4c-b4c9-d1e8cea9651csh
141defense-impairmentT1685.006Disable or Modify Tools: Clear Linux or Mac System Logs12Delete system log files via unlink utility03013b4b-01db-437d-909b-1fdaa5010ee8sh
142defense-impairmentT1685.006Disable or Modify Tools: Clear Linux or Mac System Logs14Delete system log files using shred utility86f0e4d5-3ca7-45fb-829d-4eda32b232bbsh
143defense-impairmentT1685.006Disable or Modify Tools: Clear Linux or Mac System Logs15Delete system log files using srm utilityb0768a5e-0f32-4e75-ae5b-d036edcf96b6sh
144defense-impairmentT1685.006Disable or Modify Tools: Clear Linux or Mac System Logs16Delete system log files using OSAScript810a465f-cd4f-47bc-b43e-d2de3b033eccsh
145defense-impairmentT1685.006Disable or Modify Tools: Clear Linux or Mac System Logs17Delete system log files using Applescripte62f8694-cbc7-468f-862c-b10cd07e1757sh
146defense-impairmentT1647Plist File Modification1Plist Modification394a538e-09bb-4a4a-95d1-b93cf12682a8manual
147defense-impairmentT1690Prevent Command History Logging1Disable history collection4eafdb45-0f79-4d66-aa86-a3e2c08791f5sh
148defense-impairmentT1690Prevent Command History Logging3Mac HISTCONTROL468566d5-83e5-40c1-b338-511e1659628dmanual
149defense-impairmentT1685Disable or Modify Tools9Disable Carbon Black Response8fba7766-2d11-4b4a-979a-1e3d9cc9a88csh
150defense-impairmentT1685Disable or Modify Tools10Disable LittleSnitch62155dd8-bb3d-4f32-b31c-6532ff3ac6a3sh
151defense-impairmentT1685Disable or Modify Tools11Disable OpenDNS Umbrella07f43b33-1e15-4e99-be70-bc094157c849sh
152defense-impairmentT1685Disable or Modify Tools12Disable macOS Gatekeeper2a821573-fb3f-4e71-92c3-daac7432f053sh
153defense-impairmentT1685Disable or Modify Tools13Stop and unload Crowdstrike Falcon on macOSb3e7510c-2d4c-4249-a33f-591a2bc83eefsh
154defense-impairmentT1685Disable or Modify Tools50Tamper with Defender ATP on Linux/MacOS40074085-dbc8-492b-90a3-11bcfc52fda8sh
155defense-impairmentT1553.004Subvert Trust Controls: Install Root Certificate4Install root CA on macOScc4a0b8c-426f-40ff-9426-4e10e5bf4c49sh
156privilege-escalationT1548.003Abuse Elevation Control Mechanism: Sudo and Sudo Caching1Sudo usage150c3a08-ee6e-48a6-aeaf-3659d24ceb4esh
157privilege-escalationT1548.003Abuse Elevation Control Mechanism: Sudo and Sudo Caching3Unlimited sudo cache timeouta7b17659-dd5e-46f7-b7d1-e6792c91d0bcsh
158privilege-escalationT1548.003Abuse Elevation Control Mechanism: Sudo and Sudo Caching5Disable tty_tickets for sudo caching91a60b03-fb75-4d24-a42e-2eb8956e8de1sh
159privilege-escalationT1053.003Scheduled Task/Job: Cron1Cron - Replace crontab with referenced file435057fb-74b1-410e-9403-d81baf194f75sh
160privilege-escalationT1053.003Scheduled Task/Job: Cron2Cron - Add script to all cron subfoldersb7d42afa-9086-4c8a-b7b0-8ea3faa6ebb0bash
161privilege-escalationT1037.002Boot or Logon Initialization Scripts: Logon Script (Mac)1Logon Scripts - Macf047c7de-a2d9-406e-a62b-12a09d9516f4manual
162privilege-escalationT1543.004Create or Modify System Process: Launch Daemon1Launch Daemon03ab8df5-3a6b-4417-b6bd-bb7a5cfd74cfbash
163privilege-escalationT1078.001Valid Accounts: Default Accounts3Enable Guest Account on macOS0315bdff-4178-47e9-81e4-f31a6d23f7e4sh
164privilege-escalationT1546.005Event Triggered Execution: Trap1Trap EXITa74b2e07-5952-4c03-8b56-56274b076b61sh
165privilege-escalationT1546.005Event Triggered Execution: Trap3Trap SIGINTa547d1ba-1d7a-4cc5-a9cb-8d65e8809636sh
166privilege-escalationT1548.001Abuse Elevation Control Mechanism: Setuid and Setgid1Make and modify binary from C source896dfe97-ae43-4101-8e96-9a7996555d80sh
167privilege-escalationT1548.001Abuse Elevation Control Mechanism: Setuid and Setgid3Set a SetUID flag on file759055b3-3885-4582-a8ec-c00c9d64dd79sh
168privilege-escalationT1548.001Abuse Elevation Control Mechanism: Setuid and Setgid5Set a SetGID flag on filedb55f666-7cba-46c6-9fe6-205a05c3242csh
169privilege-escalationT1098.004SSH Authorized Keys1Modify SSH Authorized Keys342cc723-127c-4d3a-8292-9c0c6b4ecadcsh
170privilege-escalationT1547.015Boot or Logon Autostart Execution: Login Items2Add macOS LoginItem using Applescript716e756a-607b-41f3-8204-b214baf37c1dbash
171privilege-escalationT1546.014Event Triggered Execution: Emond1Persistance with Event Monitor - emond23c9c127-322b-4c75-95ca-eff464906114sh
172privilege-escalationT1547.006Boot or Logon Autostart Execution: Kernel Modules and Extensions2MacOS - Load Kernel Module via kextload and kmutilf4391089-d3a5-4dd1-ab22-0419527f2672bash
173privilege-escalationT1547.006Boot or Logon Autostart Execution: Kernel Modules and Extensions3MacOS - Load Kernel Module via KextManagerLoadKextWithURL()f0007753-beb3-41ea-9948-760785e4c1e5bash
174privilege-escalationT1546.004Event Triggered Execution: .bash_profile .bashrc and .shrc1Add command to .bash_profile94500ae1-7e31-47e3-886b-c328da46872fsh
175privilege-escalationT1546.004Event Triggered Execution: .bash_profile .bashrc and .shrc2Add command to .bashrc0a898315-4cfa-4007-bafe-33a4646d115fsh
176privilege-escalationT1037.005Boot or Logon Initialization Scripts: Startup Items1Add file to Local Library StartupItems134627c3-75db-410e-bff8-7a920075f198sh
177privilege-escalationT1037.005Boot or Logon Initialization Scripts: Startup Items2Add launch script to launch daemonfc369906-90c7-4a15-86fd-d37da624dde6bash
178privilege-escalationT1037.005Boot or Logon Initialization Scripts: Startup Items3Add launch script to launch agent10cf5bec-49dd-4ebf-8077-8f47e420096fbash
179privilege-escalationT1546.018Event Triggered Execution: Python Startup Hooks4Python Startup Hook - atomic_hook.pth (macOS)28ca4f81-fa96-47ff-8555-dde98017e89bsh
180privilege-escalationT1546.018Event Triggered Execution: Python Startup Hooks5Python Startup Hook - usercustomize.py (Linux / MacOS)6e78084a-a433-4702-a838-cc7b765d87e8sh
181privilege-escalationT1543.001Create or Modify System Process: Launch Agent1Launch Agenta5983dee-bf6c-4eaf-951c-dbc1a7b90900bash
182privilege-escalationT1543.001Create or Modify System Process: Launch Agent2Event Monitor Daemon Persistence11979f23-9b9d-482a-9935-6fc9cd022c3ebash
183privilege-escalationT1543.001Create or Modify System Process: Launch Agent3Launch Agent - Root Directory66774fa8-c562-4bae-a58d-5264a0dd9dd7bash
184privilege-escalationT1037.004Boot or Logon Initialization Scripts: Rc.common1rc.common97a48daa-8bca-4bc0-b1a9-c1d163e762debash
185privilege-escalationT1547.007Boot or Logon Autostart Execution: Re-opened Applications1Copy in loginwindow.plist for Re-Opened Applications5fefd767-ef54-4ac6-84d3-751ab85e8abash
186privilege-escalationT1547.007Boot or Logon Autostart Execution: Re-opened Applications2Re-Opened Applications using LoginHook5f5b71da-e03f-42e7-ac98-d63f9e0465cbsh
187privilege-escalationT1547.007Boot or Logon Autostart Execution: Re-opened Applications3Append to existing loginwindow for Re-Opened Applications766b6c3c-9353-4033-8b7e-38b309fa3a93sh
188privilege-escalationT1078.003Valid Accounts: Local Accounts2Create local account with admin privileges - MacOSf1275566-1c26-4b66-83e3-7f9f7f964daabash
189privilege-escalationT1078.003Valid Accounts: Local Accounts3Create local account with admin privileges using sysadminctl utility - MacOS191db57d-091a-47d5-99f3-97fde53de505bash
190privilege-escalationT1078.003Valid Accounts: Local Accounts4Enable root account using dsenableroot utility - MacOS20b40ea9-0e17-4155-b8e6-244911a678acbash
191privilege-escalationT1078.003Valid Accounts: Local Accounts5Add a new/existing user to the admin group using dseditgroup utility - macOS433842ba-e796-4fd5-a14f-95d3a1970875bash
192credential-accessT1056.001Input Capture: Keylogging8MacOS Swift Keyloggeraee3a097-4c5c-4fff-bbd3-0a705867ae29bash
193credential-accessT1539Steal Web Session Cookie3Steal Chrome Cookies via Remote Debugging (Mac)e43cfdaf-3fb8-4a45-8de0-7eee8741d072bash
194credential-accessT1539Steal Web Session Cookie5Copy Safari BinaryCookies files using AppleScripte57ba07b-3a33-40cd-a892-748273b9b49ash
195credential-accessT1555.001Credentials from Password Stores: Keychain1Keychain Dump88e1fa00-bf63-4e5b-a3e1-e2ea51c8cca6sh
196credential-accessT1555.001Credentials from Password Stores: Keychain2Export Certificate Item(s)1864fdec-ff86-4452-8c30-f12507582a93sh
197credential-accessT1555.001Credentials from Password Stores: Keychain3Import Certificate Item(s) into Keychaine544bbcb-c4e0-4bd0-b614-b92131635f59sh
198credential-accessT1555.001Credentials from Password Stores: Keychain4Copy Keychain using cat utility5c32102a-c508-49d3-978f-288f8a9f6617sh
199credential-accessT1040Network Sniffing3Packet Capture macOS using tcpdump or tshark9d04efee-eff5-4240-b8d2-07792b873608bash
200credential-accessT1040Network Sniffing8Packet Capture macOS using /dev/bpfN with sudoe6fe5095-545d-4c8b-a0ae-e863914be3aabash
201credential-accessT1040Network Sniffing9Filtered Packet Capture macOS using /dev/bpfN with sudoe2480aee-23f3-4f34-80ce-de221e27cd19bash
202credential-accessT1552Unsecured Credentials1AWS - Retrieve EC2 Password Data using stratusa21118de-b11e-4ebd-b655-42f11142df0csh
203credential-accessT1555.003Credentials from Password Stores: Credentials from Web Browsers2Search macOS Safari Cookiesc1402f7b-67ca-43a8-b5f3-3143abedc01bsh
204credential-accessT1555.003Credentials from Password Stores: Credentials from Web Browsers14Simulating Access to Chrome Login Data - MacOS124e13e5-d8a1-4378-a6ee-a53cd0c7e369sh
205credential-accessT1552.004Unsecured Credentials: Private Keys2Discover Private SSH Keys46959285-906d-40fa-9437-5a439accd878sh
206credential-accessT1552.004Unsecured Credentials: Private Keys5Copy Private SSH Keys with rsync864bb0b2-6bb5-489a-b43b-a77b3a16d68ash
207credential-accessT1552.004Unsecured Credentials: Private Keys7Copy the users GnuPG directory with rsync2a5a0601-f5fb-4e2e-aa09-73282ae6afcash
208credential-accessT1552.003Unsecured Credentials: Bash History1Search Through Bash History3cfde62b-7c33-4b26-a61e-755d6131c8cesh
209credential-accessT1552.001Unsecured Credentials: Credentials In Files1Find AWS credentials37807632-d3da-442e-8c2e-00f44928ff8fsh
210credential-accessT1552.001Unsecured Credentials: Credentials In Files2Extract Browser and System credentials with LaZagne9e507bb8-1d30-4e3b-a49b-cb5727d7ea79bash
211credential-accessT1552.001Unsecured Credentials: Credentials In Files3Extract passwords with grepbd4cf0d1-7646-474e-8610-78ccf5a097c4sh
212credential-accessT1552.001Unsecured Credentials: Credentials In Files6Find and Access Github Credentialsda4f751a-020b-40d7-b9ff-d433b7799803bash
213credential-accessT1552.001Unsecured Credentials: Credentials In Files15Find Azure credentialsa8f6148d-478a-4f43-bc62-5efee9f931a4sh
214credential-accessT1552.001Unsecured Credentials: Credentials In Files16Find GCP credentialsaa12eb29-2dbb-414e-8b20-33d34af93543sh
215credential-accessT1552.001Unsecured Credentials: Credentials In Files17Find OCI credentials9d9c22c9-fa97-4008-a204-478cf68c40afsh
216credential-accessT1056.002Input Capture: GUI Input Capture1AppleScript - Prompt User for Password76628574-0bc1-4646-8fe2-8f4427b47d15bash
217credential-accessT1056.002Input Capture: GUI Input Capture3AppleScript - Spoofing a credential prompt using osascriptb7037b89-947a-427a-ba29-e7e9f09bc045bash
218credential-accessT1110.004Brute Force: Credential Stuffing2SSH Credential Stuffing From MacOSd546a3d9-0be5-40c7-ad82-5a7d79e1b66bbash
219discoveryT1033System Owner/User Discovery2System Owner/User Discovery2a9b677d-a230-44f4-ad86-782df1ef108csh
220discoveryT1016.001System Network Configuration Discovery: Internet Connection Discovery2Check internet connection using ping freebsd, linux or macosbe8f4019-d8b6-434c-a814-53123cdcc11ebash
221discoveryT1652Device Driver Discovery4List loaded kernel extensions (macOS)71eab73d-5d7d-4681-9a72-7873489a5b85bash
222discoveryT1652Device Driver Discovery5Find Kernel Extensions (macOS)c63bbe52-6f17-4832-b221-f07ba8b1736fbash
223discoveryT1087.001Account Discovery: Local Account2View sudoers accessfed9be70-0186-4bde-9f8a-20945f9370c2sh
224discoveryT1087.001Account Discovery: Local Account3View accounts with UID 0c955a599-3653-4fe5-b631-f11c00eb0397sh
225discoveryT1087.001Account Discovery: Local Account4List opened files by user7e46c7a5-0142-45be-a858-1a3ecb4fd3cbsh
226discoveryT1087.001Account Discovery: Local Account6Enumerate users and groupse6f36545-dc1e-47f0-9f48-7f730f54a02esh
227discoveryT1087.001Account Discovery: Local Account7Enumerate users and groups319e9f6c-7a9e-432e-8c62-9385c803b6f2sh
228discoveryT1497.001Virtualization/Sandbox Evasion: System Checks4Detect Virtualization Environment via iorega960185f-aef6-4547-8350-d1ce16680d09sh
229discoveryT1497.001Virtualization/Sandbox Evasion: System Checks6Detect Virtualization Environment using sysctl (hw.model)6beae646-eb4c-4730-95be-691a4094408csh
230discoveryT1497.001Virtualization/Sandbox Evasion: System Checks7Check if System Integrity Protection is enabled2b73cd9b-b2fb-4357-b9d7-c73c41d9e945sh
231discoveryT1497.001Virtualization/Sandbox Evasion: System Checks8Detect Virtualization Environment using system_profilere04d2e89-de15-4d90-92f9-a335c7337f0fsh
232discoveryT1007System Service Discovery5System Service Discovery - macOS launchctl9b378962-a75e-4856-b117-2503d6dcebbash
233discoveryT1040Network Sniffing3Packet Capture macOS using tcpdump or tshark9d04efee-eff5-4240-b8d2-07792b873608bash
234discoveryT1040Network Sniffing8Packet Capture macOS using /dev/bpfN with sudoe6fe5095-545d-4c8b-a0ae-e863914be3aabash
235discoveryT1040Network Sniffing9Filtered Packet Capture macOS using /dev/bpfN with sudoe2480aee-23f3-4f34-80ce-de221e27cd19bash
236discoveryT1135Network Share Discovery1Network Share Discoveryf94b5ad9-911c-4eff-9718-fd21899db4f7sh
237discoveryT1082System Information Discovery2System Information Discoveryedff98ec-0f73-4f63-9890-6b117092aff6sh
238discoveryT1082System Information Discovery3List OS Informationcccb070c-df86-4216-a5bc-9fb60c74e27csh
239discoveryT1082System Information Discovery8Hostname Discovery486e88ea-4f56-470f-9b57-3f4d73f39133sh
240discoveryT1082System Information Discovery12Environment variables discovery on freebsd, macos and linuxfcbdd43f-f4ad-42d5-98f3-0218097e2720sh
241discoveryT1082System Information Discovery13Show System Integrity Protection status (MacOS)327cc050-9e99-4c8e-99b5-1d15f2fb6b96sh
242discoveryT1082System Information Discovery33sysctl to gather macOS hardware infoc8d40da9-31bd-47da-a497-11ea55d1ef6csh
243discoveryT1497.003Time Based Evasion1Delay execution with ping8b87dd03-8204-478c-bac3-3959f6528de3sh
244discoveryT1217Browser Bookmark Discovery2List Mozilla Firefox Bookmark Database Files on macOS1ca1f9c7-44bc-46bb-8c85-c50e2e94267bsh
245discoveryT1217Browser Bookmark Discovery3List Google Chrome Bookmark JSON Files on macOSb789d341-154b-4a42-a071-9111588be9bcsh
246discoveryT1217Browser Bookmark Discovery9List Safari Bookmarks on MacOS5fc528dd-79de-47f5-8188-25572b7fafe0sh
247discoveryT1016System Network Configuration Discovery3System Network Configuration Discoveryc141bbdb-7fca-4254-9fd6-f47e79447e17sh
248discoveryT1016System Network Configuration Discovery8List macOS Firewall Rulesff1d8c25-2aa4-4f18-a425-fede4a41ee88bash
249discoveryT1083File and Directory Discovery3Nix File and Directory Discoveryffc8b249-372a-4b74-adcd-e4c0430842desh
250discoveryT1083File and Directory Discovery4Nix File and Directory Discovery 213c5e1ae-605b-46c4-a79f-db28c77ff24esh
251discoveryT1049System Network Connections Discovery4System Network Connections Discovery via ss or lsof (Linux/MacOS)bcf05343-ef1d-4052-8a27-b00c9be42b9fbash
252discoveryT1049System Network Connections Discovery5System Network Connections Discovery FreeBSD, Linux & MacOS9ae28d3f-190f-4fa0-b023-c7bd3e0eabf2sh
253discoveryT1057Process Discovery1Process Discovery - ps4ff64f0b-aaf2-4866-b39d-38d9791407ccsh
254discoveryT1069.001Permission Groups Discovery: Local Groups1Permission Groups Discovery (Local)952931a4-af0b-4335-bbbe-73c8c5b327aesh
255discoveryT1201Password Policy Discovery8Examine password policy - macOS4b7fa042-9482-45e1-b348-4b756b2a0742bash
256discoveryT1614System Location Discovery2Get geolocation info through IP-Lookup services using curl freebsd, linux or macos552b4db3-8850-412c-abce-ab5cc8a86604bash
257discoveryT1518.001Software Discovery: Security Software Discovery3Security Software Discovery - ps (macOS)ba62ce11-e820-485f-9c17-6f3c857cd840sh
258discoveryT1018Remote System Discovery6Remote System Discovery - arp nixacb6b1ff-e2ad-4d64-806c-6c35fe73b951sh
259discoveryT1018Remote System Discovery7Remote System Discovery - sweep96db2632-8417-4dbb-b8bb-a8b92ba391desh
260discoveryT1046Network Service Discovery1Port Scan68e907da-2539-48f6-9fc9-257a78c05540bash
261discoveryT1046Network Service Discovery2Port Scan Nmap515942b0-a09f-4163-a7bb-22fefb6f185fsh
262discoveryT1046Network Service Discovery12Port Scan using nmap (Port range)0d5a2b03-3a26-45e4-96ae-89485b4d1f97sh
263discoveryT1518Software Discovery3Find and Display Safari Browser Version103d6533-fd2a-4d08-976a-4a598565280fsh
264discoveryT1124System Time Discovery3System Time Discovery in FreeBSD/macOSf449c933-0891-407f-821e-7916a21a1a6fsh
265executionT1053.003Scheduled Task/Job: Cron1Cron - Replace crontab with referenced file435057fb-74b1-410e-9403-d81baf194f75sh
266executionT1053.003Scheduled Task/Job: Cron2Cron - Add script to all cron subfoldersb7d42afa-9086-4c8a-b7b0-8ea3faa6ebb0bash
267executionT1059.002Command and Scripting Interpreter: AppleScript1AppleScript3600d97d-81b9-4171-ab96-e4386506e2c2sh
268executionT1574.006Hijack Execution Flow: LD_PRELOAD3Dylib Injection via DYLD_INSERT_LIBRARIES4d66029d-7355-43fd-93a4-b63ba92ea1bebash
269executionT1569.001System Services: Launchctl1Launchctl6fb61988-724e-4755-a595-07743749d4e2bash
270executionT1059.004Command and Scripting Interpreter: Bash1Create and Execute Bash Shell Script7e7ac3ed-f795-4fa5-b711-09d6fbe9b873sh
271executionT1059.004Command and Scripting Interpreter: Bash2Command-Line Interfaced0c88567-803d-4dca-99b4-7ce65e7b257csh
272executionT1059.004Command and Scripting Interpreter: Bash14Shell Creation using awk commandee72b37d-b8f5-46a5-a9e7-0ff50035ffd5sh
273executionT1059.004Command and Scripting Interpreter: Bash15Creating shell using cpan commandbcd4c2bc-490b-4f91-bd31-3709fe75bbdfsh
274executionT1059.004Command and Scripting Interpreter: Bash17emacs spawning an interactive system shelle0742e38-6efe-4dd4-ba5c-2078095b6156sh
275impactT1531Account Access Removal4Change User Password via passwd3c717bf3-2ecc-4d79-8ac8-0bfbf08fbce6sh
276impactT1531Account Access Removal5Delete User via dscl utility4d938c43-2fe8-4d70-a5b3-5bf239aa7846sh
277impactT1531Account Access Removal6Delete User via sysadminctl utilityd3812c4e-30ee-466a-a0aa-07e355b561d6sh
278impactT1486Data Encrypted for Impact6Encrypt files using 7z utility - macOS645f0f5a-ef09-48d8-b9bc-f0e24c642d72sh
279impactT1486Data Encrypted for Impact7Encrypt files using openssl utility - macOS1a01f6b8-b1e8-418e-bbe3-78a6f822759esh
280impactT1496Resource Hijacking1FreeBSD/macOS/Linux - Simulate CPU Load with Yes904a5a0e-fb02-490d-9f8d-0e256eb37549sh
281impactT1485Data Destruction2FreeBSD/macOS/Linux - Overwrite file with DD38deee99-fd65-4031-bec8-bfa4f9f26146sh
282impactT1490Inhibit System Recovery12Disable Time Machineed952f70-91d4-445a-b7ff-30966bfb1affsh
283impactT1529System Shutdown/Reboot3Restart System via `shutdown` - FreeBSD/macOS/Linux6326dbc4-444b-4c04-88f4-27e94d0327cbsh
284impactT1529System Shutdown/Reboot4Shutdown System via `shutdown` - FreeBSD/macOS/Linux4963a81e-a3ad-4f02-adda-812343b351desh
285impactT1529System Shutdown/Reboot5Restart System via `reboot` - FreeBSD/macOS/Linux47d0b042-a918-40ab-8cf9-150ffe919027sh
286initial-accessT1659Content Injection1MITM Proxy Injection9b360eaf-c778-4f07-a6e7-895c4f01ac1cbash
287initial-accessT1078.001Valid Accounts: Default Accounts3Enable Guest Account on macOS0315bdff-4178-47e9-81e4-f31a6d23f7e4sh
288initial-accessT1078.003Valid Accounts: Local Accounts2Create local account with admin privileges - MacOSf1275566-1c26-4b66-83e3-7f9f7f964daabash
289initial-accessT1078.003Valid Accounts: Local Accounts3Create local account with admin privileges using sysadminctl utility - MacOS191db57d-091a-47d5-99f3-97fde53de505bash
290initial-accessT1078.003Valid Accounts: Local Accounts4Enable root account using dsenableroot utility - MacOS20b40ea9-0e17-4155-b8e6-244911a678acbash
291initial-accessT1078.003Valid Accounts: Local Accounts5Add a new/existing user to the admin group using dseditgroup utility - macOS433842ba-e796-4fd5-a14f-95d3a1970875bash
292exfiltrationT1048.002Exfiltration Over Alternative Protocol - Exfiltration Over Asymmetric Encrypted Non-C2 Protocol2Exfiltrate data HTTPS using curl freebsd,linux or macos4a4f31e2-46ea-4c26-ad89-f09ad1d5fe01bash
293exfiltrationT1048Exfiltration Over Alternative Protocol1Exfiltration Over Alternative Protocol - SSHf6786cc8-beda-4915-a4d6-ac2f193bb988sh
294exfiltrationT1048Exfiltration Over Alternative Protocol2Exfiltration Over Alternative Protocol - SSH7c3cb337-35ae-4d06-bf03-3032ed2ec268sh
295exfiltrationT1048Exfiltration Over Alternative Protocol4Exfiltrate Data using DNS Queries via diga27916da-05f2-4316-a3ee-feec67a437bebash
296exfiltrationT1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage2Exfiltrate data with rclone to cloud Storage - AWS S3a4b74723-5cee-4300-91c3-5e34166909b4powershell
297exfiltrationT1030Data Transfer Size Limits1Data Transfer Size Limitsab936c51-10f4-46ce-9144-e02137b2016ash
298exfiltrationT1048.003Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol1Exfiltration Over Alternative Protocol - HTTP1d1abbd6-a3d3-4b2e-bef5-c59293f46effmanual