Files
atomic-red-team/atomics/Indexes/Indexes-CSV/index.csv
T
2020-04-03 17:14:40 +00:00

35 KiB

1TacticTechnique #Test #Test Name
2persistenceT11561Add command to .bash_profile
3persistenceT11562Add command to .bashrc
4persistenceT10151Attaches Command Prompt as a Debugger to a List of Target Processes
5persistenceT10981Admin Account Manipulate
6persistenceT11031Install AppInit Shim
7persistenceT11381Application Shim Installation
8persistenceT11382New shim database files created in the default shim database directory
9persistenceT11383Registry key creation and/or modification events for SDB
10persistenceT11971Bitsadmin Download (cmd)
11persistenceT11972Bitsadmin Download (PowerShell)
12persistenceT11973Persist, Download, & Execute
13persistenceT11761Chrome (Developer Mode)
14persistenceT11762Chrome (Chrome Web Store)
15persistenceT11763Firefox
16persistenceT10421Change Default File Association
17persistenceT11361Create a user account on a Linux system
18persistenceT11362Create a user account on a MacOS system
19persistenceT11363Create a new user in a command prompt
20persistenceT11364Create a new user in PowerShell
21persistenceT11365Create a new user in Linux with `root` UID and GID.
22persistenceT10381DLL Search Order Hijacking - amsi.dll
23persistenceT15191Persistance with Event Monitor - emond
24persistenceT10441File System Permissions Weakness
25persistenceT11581Create a hidden file in a hidden directory
26persistenceT11582Mac Hidden file
27persistenceT11583Create Windows System File with Attrib
28persistenceT11584Create Windows Hidden File with Attrib
29persistenceT11585Hidden files
30persistenceT11586Hide a Directory
31persistenceT11587Show all hidden files
32persistenceT11588Create ADS command prompt
33persistenceT11589Create ADS PowerShell
34persistenceT11791Hook PowerShell TLS Encrypt/Decrypt Messages
35persistenceT10621Installing Hyper-V Feature
36persistenceT11831IFEO Add Debugger
37persistenceT11832IFEO Global Flags
38persistenceT12151Linux - Load Kernel Module via insmod
39persistenceT11591Launch Agent
40persistenceT11601Launch Daemon
41persistenceT11521Launchctl
42persistenceT11681Cron - Replace crontab with referenced file
43persistenceT11682Cron - Add script to cron folder
44persistenceT11683Event Monitor Daemon Persistence
45persistenceT10371Logon Scripts
46persistenceT10372Scheduled Task Startup Script
47persistenceT10373Logon Scripts - Mac
48persistenceT10374Supicious vbs file run from startup Folder
49persistenceT10375Supicious jse file run from startup Folder
50persistenceT10376Supicious bat file run from startup Folder
51persistenceT10311Modify Fax service to run PowerShell
52persistenceT11281Netsh Helper DLL Registration
53persistenceT10501Service Installation
54persistenceT10502Service Installation PowerShell
55persistenceT11371DDEAUTO
56persistenceT11501Plist Modification
57persistenceT15041Append malicious start-process cmdlet
58persistenceT11631rc.common
59persistenceT11641Re-Opened Applications
60persistenceT11642Re-Opened Applications
61persistenceT10601Reg Key Run
62persistenceT10602Reg Key RunOnce
63persistenceT10603PowerShell Registry RunOnce
64persistenceT10531At.exe Scheduled task
65persistenceT10532Scheduled task Local
66persistenceT10533Scheduled task Remote
67persistenceT10534Powershell Cmdlet Scheduled Task
68persistenceT11801Set Arbitrary Binary as Screensaver
69persistenceT11011Modify SSP configuration in registry
70persistenceT15051Install MS Exchange Transport Agent Persistence
71persistenceT10581Service Registry Permissions Weakness
72persistenceT11661Make and modify binary from C source
73persistenceT11662Set a SetUID flag on file
74persistenceT11663Set a SetGID flag on file
75persistenceT10231Shortcut Modification
76persistenceT10232Create shortcut to cmd in startup folders
77persistenceT11651add file to Local Library StartupItems
78persistenceT15011Create Systemd Service
79persistenceT11541Trap
80persistenceT11001Web Shell Written to Disk
81persistenceT10841Persistence via WMI Event Subscription
82persistenceT10041Winlogon Shell Key Persistence - PowerShell
83persistenceT10042Winlogon Userinit Key Persistence - PowerShell
84persistenceT10043Winlogon Notify Key Logon Persistence - PowerShell
85defense-evasionT11971Bitsadmin Download (cmd)
86defense-evasionT11972Bitsadmin Download (PowerShell)
87defense-evasionT11973Persist, Download, & Execute
88defense-evasionT10091Pad Binary to Change Hash - Linux/macOS dd
89defense-evasionT10881Bypass UAC using Event Viewer (cmd)
90defense-evasionT10882Bypass UAC using Event Viewer (PowerShell)
91defense-evasionT10883Bypass UAC using Fodhelper
92defense-evasionT10884Bypass UAC using Fodhelper - PowerShell
93defense-evasionT10885Bypass UAC using ComputerDefaults (PowerShell)
94defense-evasionT10886Bypass UAC by Mocking Trusted Directories
95defense-evasionT11911CMSTP Executing Remote Scriptlet
96defense-evasionT11912CMSTP Executing UAC Bypass
97defense-evasionT11461Clear Bash history (rm)
98defense-evasionT11462Clear Bash history (echo)
99defense-evasionT11463Clear Bash history (cat dev/null)
100defense-evasionT11464Clear Bash history (ln dev/null)
101defense-evasionT11465Clear Bash history (truncate)
102defense-evasionT11466Clear history of a bunch of shells
103defense-evasionT15001Compile After Delivery using csc.exe
104defense-evasionT12231Compiled HTML Help Local Payload
105defense-evasionT12232Compiled HTML Help Remote Payload
106defense-evasionT10901Connection Proxy
107defense-evasionT10902portproxy reg key
108defense-evasionT11961Control Panel Items
109defense-evasionT12071DCShadow - Mimikatz
110defense-evasionT10381DLL Search Order Hijacking - amsi.dll
111defense-evasionT10731DLL Side-Loading using the Notepad++ GUP.exe binary
112defense-evasionT11401Deobfuscate/Decode Files Or Information
113defense-evasionT11402Certutil Rename and Decode
114defense-evasionT10891Disable iptables firewall
115defense-evasionT10892Disable syslog
116defense-evasionT10893Disable Cb Response
117defense-evasionT10894Disable SELinux
118defense-evasionT10895Disable Carbon Black Response
119defense-evasionT10896Disable LittleSnitch
120defense-evasionT10897Disable OpenDNS Umbrella
121defense-evasionT10898Unload Sysmon Filter Driver
122defense-evasionT10899Disable Windows IIS HTTP Logging
123defense-evasionT108910Uninstall Sysmon
124defense-evasionT108911AMSI Bypass - AMSI InitFailed
125defense-evasionT108912AMSI Bypass - Remove AMSI Provider Reg Key
126defense-evasionT108913Disable Arbitrary Security Windows Service
127defense-evasionT108914Disable PowerShell Script Block Logging
128defense-evasionT108915PowerShell Bypass of AntiMalware Scripting Interface
129defense-evasionT108916Tamper with Windows Defender ATP PowerShell
130defense-evasionT108917Tamper with Windows Defender Command Prompt
131defense-evasionT108918Tamper with Windows Defender Registry
132defense-evasionT108919Disable Microft Office Security Features
133defense-evasionT108920Remove Windows Defender Definition Files
134defense-evasionT11071Delete a single file - Linux/macOS
135defense-evasionT11072Delete an entire folder - Linux/macOS
136defense-evasionT11073Overwrite and delete a file with shred
137defense-evasionT11074Delete a single file - Windows cmd
138defense-evasionT11075Delete an entire folder - Windows cmd
139defense-evasionT11076Delete a single file - Windows PowerShell
140defense-evasionT11077Delete an entire folder - Windows PowerShell
141defense-evasionT11078Delete Filesystem - Linux
142defense-evasionT11079Delete-PrefetchFile
143defense-evasionT110710Delete TeamViewer Log Files
144defense-evasionT12221Take ownership using takeown utility
145defense-evasionT12222Take ownership recursively using takeown utility
146defense-evasionT12223cacls - Grant permission to specified user or group
147defense-evasionT12224cacls - Grant permission to specified user or group recursively
148defense-evasionT12225icacls - Grant permission to specified user or group
149defense-evasionT12226icacls - Grant permission to specified user or group recursively
150defense-evasionT12227attrib - Remove read-only attribute
151defense-evasionT12228chmod - Change file or folder mode (numeric mode)
152defense-evasionT12229chmod - Change file or folder mode (symbolic mode)
153defense-evasionT122210chmod - Change file or folder mode (numeric mode) recursively
154defense-evasionT122211chmod - Change file or folder mode (symbolic mode) recursively
155defense-evasionT122212chown - Change file or folder ownership and group
156defense-evasionT122213chown - Change file or folder ownership and group recursively
157defense-evasionT122214chown - Change file or folder mode ownership only
158defense-evasionT122215chown - Change file or folder ownership recursively
159defense-evasionT122216chattr - Remove immutable file attribute
160defense-evasionT11441Gatekeeper Bypass
161defense-evasionT11481Disable history collection
162defense-evasionT11482Mac HISTCONTROL
163defense-evasionT11581Create a hidden file in a hidden directory
164defense-evasionT11582Mac Hidden file
165defense-evasionT11583Create Windows System File with Attrib
166defense-evasionT11584Create Windows Hidden File with Attrib
167defense-evasionT11585Hidden files
168defense-evasionT11586Hide a Directory
169defense-evasionT11587Show all hidden files
170defense-evasionT11588Create ADS command prompt
171defense-evasionT11589Create ADS PowerShell
172defense-evasionT11471Hidden Users
173defense-evasionT11431Hidden Window
174defense-evasionT11831IFEO Add Debugger
175defense-evasionT11832IFEO Global Flags
176defense-evasionT10701Clear Logs
177defense-evasionT10702FSUtil
178defense-evasionT10703rm -rf
179defense-evasionT10704Overwrite Linux Mail Spool
180defense-evasionT10705Overwrite Linux Log
181defense-evasionT10706Delete System Logs Using PowerShell
182defense-evasionT10707Delete System Logs Using Clear-EventLogId
183defense-evasionT12021Indirect Command Execution - pcalua.exe
184defense-evasionT12022Indirect Command Execution - forfiles.exe
185defense-evasionT11301Install root CA on CentOS/RHEL
186defense-evasionT11181CheckIfInstallable method call
187defense-evasionT11182InstallHelper method call
188defense-evasionT11183InstallUtil class constructor method call
189defense-evasionT11184InstallUtil Install method call
190defense-evasionT11185InstallUtil Uninstall method call - /U variant
191defense-evasionT11186InstallUtil Uninstall method call - '/installtype=notransaction /action=uninstall' variant
192defense-evasionT11187InstallUtil HelpText method call
193defense-evasionT11188InstallUtil evasive invocation
194defense-evasionT11521Launchctl
195defense-evasionT10361Masquerading as Windows LSASS process
196defense-evasionT10362Masquerading as Linux crond process.
197defense-evasionT10363Masquerading - cscript.exe running as notepad.exe
198defense-evasionT10364Masquerading - wscript.exe running as svchost.exe
199defense-evasionT10365Masquerading - powershell.exe running as taskhostw.exe
200defense-evasionT10366Masquerading - non-windows exe running as windows exe
201defense-evasionT10367Masquerading - windows exe running as different windows exe
202defense-evasionT10368Malicious process Masquerading as LSM.exe
203defense-evasionT11121Modify Registry of Current User Profile - cmd
204defense-evasionT11122Modify Registry of Local Machine - cmd
205defense-evasionT11123Modify registry to store logon credentials
206defense-evasionT11124Add domain to Trusted sites Zone
207defense-evasionT11125Javascript in registry
208defense-evasionT11701Mshta executes JavaScript Scheme Fetch Remote Payload With GetObject
209defense-evasionT11702Mshta calls a local VBScript file to launch notepad.exe
210defense-evasionT11703Mshta executes VBScript to execute malicious command
211defense-evasionT11704Mshta Executes Remote HTML Application (HTA)
212defense-evasionT10961Alternate Data Streams (ADS)
213defense-evasionT10962Store file in Alternate Data Stream (ADS)
214defense-evasionT11261Add Network Share
215defense-evasionT11262Remove Network Share
216defense-evasionT11263Remove Network Share PowerShell
217defense-evasionT10271Decode base64 Data into Script
218defense-evasionT10272Execute base64-encoded PowerShell
219defense-evasionT10273Execute base64-encoded PowerShell from Windows Registry
220defense-evasionT15021Parent PID Spoofing using PowerShell
221defense-evasionT11501Plist Modification
222defense-evasionT10931Process Hollowing using PowerShell
223defense-evasionT10551Process Injection via mavinject.exe
224defense-evasionT10552Shared Library Injection via /etc/ld.so.preload
225defense-evasionT10553Shared Library Injection via LD_PRELOAD
226defense-evasionT10554Process Injection via C#
227defense-evasionT10555svchost writing a file to a UNC path
228defense-evasionT11211Regasm Uninstall Method Call Test
229defense-evasionT11212Regsvs Uninstall Method Call Test
230defense-evasionT11171Regsvr32 local COM scriptlet execution
231defense-evasionT11172Regsvr32 remote COM scriptlet execution
232defense-evasionT11173Regsvr32 local DLL execution
233defense-evasionT10141Loadable Kernel Module based Rootkit
234defense-evasionT10142Loadable Kernel Module based Rootkit
235defense-evasionT10143Windows Signed Driver Rootkit Test
236defense-evasionT10851Rundll32 execute JavaScript Remote Payload With GetObject
237defense-evasionT10852Rundll32 execute VBscript command
238defense-evasionT10853Rundll32 advpack.dll Execution
239defense-evasionT10854Rundll32 ieadvpack.dll Execution
240defense-evasionT10855Rundll32 syssetup.dll Execution
241defense-evasionT10856Rundll32 setupapi.dll Execution
242defense-evasionT10641Create and Execute Bash Shell Script
243defense-evasionT10642Create and Execute Batch Script
244defense-evasionT12181mavinject - Inject DLL into running process
245defense-evasionT12182SyncAppvPublishingServer - Execute arbitrary PowerShell code
246defense-evasionT12183Register-CimProvider - Execute evil dll
247defense-evasionT12184Msiexec.exe - Execute Local MSI file
248defense-evasionT12185Msiexec.exe - Execute Remote MSI file
249defense-evasionT12186Msiexec.exe - Execute Arbitrary DLL
250defense-evasionT12187Odbcconf.exe - Execute Arbitrary DLL
251defense-evasionT12188InfDefaultInstall.exe .inf Execution
252defense-evasionT12161PubPrn.vbs Signed Script Bypass
253defense-evasionT12162SyncAppvPublishingServer Signed Script PowerShell Command Execution
254defense-evasionT12163manage-bde.wsf Signed Script Command Execution
255defense-evasionT11511Space After Filename
256defense-evasionT10991Set a file's access timestamp
257defense-evasionT10992Set a file's modification timestamp
258defense-evasionT10993Set a file's creation timestamp
259defense-evasionT10994Modify file timestamps using reference file
260defense-evasionT10995Windows - Modify file creation timestamp with PowerShell
261defense-evasionT10996Windows - Modify file last modified timestamp with PowerShell
262defense-evasionT10997Windows - Modify file last access timestamp with PowerShell
263defense-evasionT11271MSBuild Bypass Using Inline Tasks
264defense-evasionT11021Reach out to C2 Pointer URLs via command_prompt
265defense-evasionT11022Reach out to C2 Pointer URLs via powershell
266defense-evasionT12201MSXSL Bypass using local files
267defense-evasionT12202MSXSL Bypass using remote files
268defense-evasionT12203WMIC bypass using local XSL file
269defense-evasionT12204WMIC bypass using remote XSL file
270privilege-escalationT10151Attaches Command Prompt as a Debugger to a List of Target Processes
271privilege-escalationT11031Install AppInit Shim
272privilege-escalationT11381Application Shim Installation
273privilege-escalationT11382New shim database files created in the default shim database directory
274privilege-escalationT11383Registry key creation and/or modification events for SDB
275privilege-escalationT10881Bypass UAC using Event Viewer (cmd)
276privilege-escalationT10882Bypass UAC using Event Viewer (PowerShell)
277privilege-escalationT10883Bypass UAC using Fodhelper
278privilege-escalationT10884Bypass UAC using Fodhelper - PowerShell
279privilege-escalationT10885Bypass UAC using ComputerDefaults (PowerShell)
280privilege-escalationT10886Bypass UAC by Mocking Trusted Directories
281privilege-escalationT10381DLL Search Order Hijacking - amsi.dll
282privilege-escalationT15191Persistance with Event Monitor - emond
283privilege-escalationT10441File System Permissions Weakness
284privilege-escalationT11791Hook PowerShell TLS Encrypt/Decrypt Messages
285privilege-escalationT11831IFEO Add Debugger
286privilege-escalationT11832IFEO Global Flags
287privilege-escalationT11601Launch Daemon
288privilege-escalationT10501Service Installation
289privilege-escalationT10502Service Installation PowerShell
290privilege-escalationT15021Parent PID Spoofing using PowerShell
291privilege-escalationT11501Plist Modification
292privilege-escalationT15041Append malicious start-process cmdlet
293privilege-escalationT10551Process Injection via mavinject.exe
294privilege-escalationT10552Shared Library Injection via /etc/ld.so.preload
295privilege-escalationT10553Shared Library Injection via LD_PRELOAD
296privilege-escalationT10554Process Injection via C#
297privilege-escalationT10555svchost writing a file to a UNC path
298privilege-escalationT10531At.exe Scheduled task
299privilege-escalationT10532Scheduled task Local
300privilege-escalationT10533Scheduled task Remote
301privilege-escalationT10534Powershell Cmdlet Scheduled Task
302privilege-escalationT10581Service Registry Permissions Weakness
303privilege-escalationT11661Make and modify binary from C source
304privilege-escalationT11662Set a SetUID flag on file
305privilege-escalationT11663Set a SetGID flag on file
306privilege-escalationT11651add file to Local Library StartupItems
307privilege-escalationT11691Sudo usage
308privilege-escalationT12061Unlimited sudo cache timeout
309privilege-escalationT12062Disable tty_tickets for sudo caching
310privilege-escalationT11001Web Shell Written to Disk
311impactT15311Change User Password - Windows
312impactT15312Delete User - Windows
313impactT14851Windows - Overwrite file with Sysinternals SDelete
314impactT14852macOS/Linux - Overwrite file with DD
315impactT14901Windows - Delete Volume Shadow Copies
316impactT14902Windows - Delete Volume Shadow Copies via WMI
317impactT14903Windows - Delete Windows Backup Catalog
318impactT14904Windows - Disable Windows Recovery Console Repair
319impactT14905Windows - Delete Volume Shadow Copies via WMI with PowerShell
320impactT14906Windows - Delete Backup Files
321impactT14961macOS/Linux - Simulate CPU Load with Yes
322impactT14891Windows - Stop service using Service Controller
323impactT14892Windows - Stop service using net.exe
324impactT14893Windows - Stop service by killing process
325impactT15291Shutdown System - Windows
326impactT15292Restart System - Windows
327impactT15293Restart System via `shutdown` - macOS/Linux
328impactT15294Shutdown System via `shutdown` - macOS/Linux
329impactT15295Restart System via `reboot` - macOS/Linux
330impactT15296Shutdown System via `halt` - Linux
331impactT15297Reboot System via `halt` - Linux
332impactT15298Shutdown System via `poweroff` - Linux
333impactT15299Reboot System via `poweroff` - Linux
334discoveryT10871Enumerate all accounts
335discoveryT10872View sudoers access
336discoveryT10873View accounts with UID 0
337discoveryT10874List opened files by user
338discoveryT10875Show if a user account has ever logged in remotely
339discoveryT10876Enumerate users and groups
340discoveryT10877Enumerate users and groups
341discoveryT10878Enumerate all accounts
342discoveryT10879Enumerate all accounts via PowerShell
343discoveryT108710Enumerate logged on users
344discoveryT108711Enumerate logged on users via PowerShell
345discoveryT10101List Process Main Windows - C# .NET
346discoveryT12171List Mozilla Firefox Bookmark Database Files on Linux
347discoveryT12172List Mozilla Firefox Bookmark Database Files on macOS
348discoveryT12173List Google Chrome Bookmark JSON Files on macOS
349discoveryT12174List Google Chrome Bookmarks on Windows with powershell
350discoveryT12175List Google Chrome Bookmarks on Windows with command prompt
351discoveryT14821Windows - Discover domain trusts with dsquery
352discoveryT14822Windows - Discover domain trusts with nltest
353discoveryT14823Powershell enumerate domains and forests
354discoveryT10831File and Directory Discovery (cmd.exe)
355discoveryT10832File and Directory Discovery (PowerShell)
356discoveryT10833Nix File and Diectory Discovery
357discoveryT10834Nix File and Directory Discovery 2
358discoveryT10461Port Scan
359discoveryT10462Port Scan Nmap
360discoveryT11351Network Share Discovery
361discoveryT11352Network Share Discovery command prompt
362discoveryT11353Network Share Discovery PowerShell
363discoveryT11354View available share drives
364discoveryT10401Packet Capture Linux
365discoveryT10402Packet Capture macOS
366discoveryT10403Packet Capture Windows Command Prompt
367discoveryT10404Packet Capture PowerShell
368discoveryT12011Examine password complexity policy - Ubuntu
369discoveryT12012Examine password complexity policy - CentOS/RHEL 7.x
370discoveryT12013Examine password complexity policy - CentOS/RHEL 6.x
371discoveryT12014Examine password expiration policy - All Linux
372discoveryT12015Examine local password policy - Windows
373discoveryT12016Examine domain password policy - Windows
374discoveryT12017Examine password policy - macOS
375discoveryT10691Permission Groups Discovery
376discoveryT10692Basic Permission Groups Discovery Windows
377discoveryT10693Permission Groups Discovery PowerShell
378discoveryT10694Elevated group enumeration using net group
379discoveryT10571Process Discovery - ps
380discoveryT10572Process Discovery - tasklist
381discoveryT10121Query Registry
382discoveryT10181Remote System Discovery - net
383discoveryT10182Remote System Discovery - net group Domain Computers
384discoveryT10183Remote System Discovery - nltest
385discoveryT10184Remote System Discovery - ping sweep
386discoveryT10185Remote System Discovery - arp
387discoveryT10186Remote System Discovery - arp nix
388discoveryT10187Remote System Discovery - sweep
389discoveryT10188Remote System Discovery - nslookup
390discoveryT10631Security Software Discovery
391discoveryT10632Security Software Discovery - powershell
392discoveryT10633Security Software Discovery - ps
393discoveryT10634Security Software Discovery - Sysmon Service
394discoveryT10635Security Software Discovery - AV Discovery via WMI
395discoveryT15181Find and Display Internet Explorer Browser Version
396discoveryT15182Applications Installed
397discoveryT10821System Information Discovery
398discoveryT10822System Information Discovery
399discoveryT10823List OS Information
400discoveryT10824Linux VM Check via Hardware
401discoveryT10825Linux VM Check via Kernel Modules
402discoveryT10826Hostname Discovery (Windows)
403discoveryT10827Hostname Discovery
404discoveryT10828Windows MachineGUID Discovery
405discoveryT10161System Network Configuration Discovery
406discoveryT10162List Windows Firewall Rules
407discoveryT10163System Network Configuration Discovery
408discoveryT10164System Network Configuration Discovery (TrickBot Style)
409discoveryT10165List Open Egress Ports
410discoveryT10491System Network Connections Discovery
411discoveryT10492System Network Connections Discovery with PowerShell
412discoveryT10493System Network Connections Discovery Linux & MacOS
413discoveryT10331System Owner/User Discovery
414discoveryT10332System Owner/User Discovery
415discoveryT10071System Service Discovery
416discoveryT10072System Service Discovery - net.exe
417discoveryT11241System Time Discovery
418discoveryT11242System Time Discovery - PowerShell
419credential-accessT10981Admin Account Manipulate
420credential-accessT11391Search Through Bash History
421credential-accessT11101Brute Force Credentials
422credential-accessT10031Powershell Mimikatz
423credential-accessT10032Gsecdump
424credential-accessT10033Windows Credential Editor
425credential-accessT10034Registry dump of SAM, creds, and secrets
426credential-accessT10035Dump LSASS.exe Memory using ProcDump
427credential-accessT10036Dump LSASS.exe Memory using comsvcs.dll
428credential-accessT10037Dump LSASS.exe Memory using direct system calls and API unhooking
429credential-accessT10038Dump LSASS.exe Memory using Windows Task Manager
430credential-accessT10039Offline Credential Theft With Mimikatz
431credential-accessT100310Dump Active Directory Database with NTDSUtil
432credential-accessT100311Create Volume Shadow Copy with NTDS.dit
433credential-accessT100312Copy NTDS.dit from Volume Shadow Copy
434credential-accessT100313GPP Passwords (findstr)
435credential-accessT100314GPP Passwords (Get-GPPPassword)
436credential-accessT100315LSASS read with pypykatz
437credential-accessT100316Registry parse with pypykatz
438credential-accessT10811Extract Browser and System credentials with LaZagne
439credential-accessT10812Extract passwords with grep
440credential-accessT10813Extracting passwords with findstr
441credential-accessT10814Access unattend.xml
442credential-accessT12141Enumeration for Credentials in Registry
443credential-accessT12142Enumeration for PuTTY Credentials in Registry
444credential-accessT11791Hook PowerShell TLS Encrypt/Decrypt Messages
445credential-accessT10561Input Capture
446credential-accessT11411AppleScript - Prompt User for Password
447credential-accessT11412PowerShell - Prompt User for Password
448credential-accessT12081Request for service tickets
449credential-accessT11421Keychain
450credential-accessT10401Packet Capture Linux
451credential-accessT10402Packet Capture macOS
452credential-accessT10403Packet Capture Windows Command Prompt
453credential-accessT10404Packet Capture PowerShell
454credential-accessT11741Install and Register Password Filter DLL
455credential-accessT11451Private Keys
456credential-accessT11452Discover Private SSH Keys
457credential-accessT11453Copy Private SSH Keys with CP
458credential-accessT11454Copy Private SSH Keys with rsync
459executionT11551AppleScript
460executionT11911CMSTP Executing Remote Scriptlet
461executionT11912CMSTP Executing UAC Bypass
462executionT10591Command-Line Interface
463executionT12231Compiled HTML Help Local Payload
464executionT12232Compiled HTML Help Remote Payload
465executionT11961Control Panel Items
466executionT11731Execute Commands
467executionT11732Execute PowerShell script via Word DDE
468executionT11181CheckIfInstallable method call
469executionT11182InstallHelper method call
470executionT11183InstallUtil class constructor method call
471executionT11184InstallUtil Install method call
472executionT11185InstallUtil Uninstall method call - /U variant
473executionT11186InstallUtil Uninstall method call - '/installtype=notransaction /action=uninstall' variant
474executionT11187InstallUtil HelpText method call
475executionT11188InstallUtil evasive invocation
476executionT11521Launchctl
477executionT11681Cron - Replace crontab with referenced file
478executionT11682Cron - Add script to cron folder
479executionT11683Event Monitor Daemon Persistence
480executionT11701Mshta executes JavaScript Scheme Fetch Remote Payload With GetObject
481executionT11702Mshta calls a local VBScript file to launch notepad.exe
482executionT11703Mshta executes VBScript to execute malicious command
483executionT11704Mshta Executes Remote HTML Application (HTA)
484executionT10861Mimikatz
485executionT10862BloodHound
486executionT10863Obfuscation Tests
487executionT10864Mimikatz - Cradlecraft PsSendKeys
488executionT10865Invoke-AppPathBypass
489executionT10866PowerShell Add User
490executionT10867Powershell MsXml COM object - no prompt
491executionT10868Powershell MsXml COM object - with prompt
492executionT10869Powershell XML requests
493executionT108610Powershell invoke mshta.exe download
494executionT108611Powershell Invoke-DownloadCradle
495executionT108612PowerShell Fileless Script Execution
496executionT108613PowerShell Downgrade Attack
497executionT108614NTFS Alternate Data Stream Access
498executionT11211Regasm Uninstall Method Call Test
499executionT11212Regsvs Uninstall Method Call Test
500executionT11171Regsvr32 local COM scriptlet execution
501executionT11172Regsvr32 remote COM scriptlet execution
502executionT11173Regsvr32 local DLL execution
503executionT10851Rundll32 execute JavaScript Remote Payload With GetObject
504executionT10852Rundll32 execute VBscript command
505executionT10853Rundll32 advpack.dll Execution
506executionT10854Rundll32 ieadvpack.dll Execution
507executionT10855Rundll32 syssetup.dll Execution
508executionT10856Rundll32 setupapi.dll Execution
509executionT10531At.exe Scheduled task
510executionT10532Scheduled task Local
511executionT10533Scheduled task Remote
512executionT10534Powershell Cmdlet Scheduled Task
513executionT10641Create and Execute Bash Shell Script
514executionT10642Create and Execute Batch Script
515executionT10351Execute a Command as a Service
516executionT10352Use PsExec to execute a command on a remote host
517executionT12181mavinject - Inject DLL into running process
518executionT12182SyncAppvPublishingServer - Execute arbitrary PowerShell code
519executionT12183Register-CimProvider - Execute evil dll
520executionT12184Msiexec.exe - Execute Local MSI file
521executionT12185Msiexec.exe - Execute Remote MSI file
522executionT12186Msiexec.exe - Execute Arbitrary DLL
523executionT12187Odbcconf.exe - Execute Arbitrary DLL
524executionT12188InfDefaultInstall.exe .inf Execution
525executionT12161PubPrn.vbs Signed Script Bypass
526executionT12162SyncAppvPublishingServer Signed Script PowerShell Command Execution
527executionT12163manage-bde.wsf Signed Script Command Execution
528executionT11531Execute Script using Source
529executionT11532Execute Script using Source Alias
530executionT11511Space After Filename
531executionT11541Trap
532executionT11271MSBuild Bypass Using Inline Tasks
533executionT12041OSTap Style Macro Execution
534executionT12042Maldoc choice flags command execution
535executionT12043OSTAP JS version
536executionT10471WMI Reconnaissance Users
537executionT10472WMI Reconnaissance Processes
538executionT10473WMI Reconnaissance Software
539executionT10474WMI Reconnaissance List Remote Services
540executionT10475WMI Execute Local Process
541executionT10476WMI Execute Remote Process
542executionT10281Enable Windows Remote Management
543executionT10282PowerShell Lateral Movement
544executionT10283WMIC Process Call Create
545executionT10284Psexec
546executionT10285Invoke-Command
547executionT12201MSXSL Bypass using local files
548executionT12202MSXSL Bypass using remote files
549executionT12203WMIC bypass using local XSL file
550executionT12204WMIC bypass using remote XSL file
551lateral-movementT11551AppleScript
552lateral-movementT10371Logon Scripts
553lateral-movementT10372Scheduled Task Startup Script
554lateral-movementT10373Logon Scripts - Mac
555lateral-movementT10374Supicious vbs file run from startup Folder
556lateral-movementT10375Supicious jse file run from startup Folder
557lateral-movementT10376Supicious bat file run from startup Folder
558lateral-movementT10751Mimikatz Pass the Hash
559lateral-movementT10752crackmapexec Pass the Hash
560lateral-movementT10971Mimikatz Kerberos Ticket Attack
561lateral-movementT10761RDP
562lateral-movementT10762RDPto-DomainController
563lateral-movementT11051rsync remote file copy (push)
564lateral-movementT11052rsync remote file copy (pull)
565lateral-movementT11053scp remote file copy (push)
566lateral-movementT11054scp remote file copy (pull)
567lateral-movementT11055sftp remote file copy (push)
568lateral-movementT11056sftp remote file copy (pull)
569lateral-movementT11057certutil download (urlcache)
570lateral-movementT11058certutil download (verifyctl)
571lateral-movementT11059Windows - BITSAdmin BITS Download
572lateral-movementT110510Windows - PowerShell Download
573lateral-movementT110511OSTAP Worming Activity
574lateral-movementT10771Map admin share
575lateral-movementT10772Map Admin Share PowerShell
576lateral-movementT10773Copy and Execute File with PsExec
577lateral-movementT10774Execute command writing output to local Admin Share
578lateral-movementT10281Enable Windows Remote Management
579lateral-movementT10282PowerShell Lateral Movement
580lateral-movementT10283WMIC Process Call Create
581lateral-movementT10284Psexec
582lateral-movementT10285Invoke-Command
583collectionT11231using device audio capture commandlet
584collectionT11191Automated Collection Command Prompt
585collectionT11192Automated Collection PowerShell
586collectionT11193Recon information for export with PowerShell
587collectionT11194Recon information for export with Command Prompt
588collectionT11151Utilize Clipboard to store or execute commands from
589collectionT11152PowerShell
590collectionT10741Stage data from Discovery.bat
591collectionT10742Stage data from Discovery.sh
592collectionT10743Zip a Folder with PowerShell for Staging in Temp
593collectionT10051Search macOS Safari Cookies
594collectionT11141T1114 Email Collection with PowerShell
595collectionT10561Input Capture
596collectionT11131Screencapture
597collectionT11132Screencapture (silent)
598collectionT11133X Windows Capture
599collectionT11134Import
600exfiltrationT10021Compress Data for Exfiltration With PowerShell
601exfiltrationT10022Compress Data for Exfiltration With Rar
602exfiltrationT10023Data Compressed - nix - zip
603exfiltrationT10024Data Compressed - nix - gzip Single File
604exfiltrationT10025Data Compressed - nix - tar Folder or File
605exfiltrationT10221Data Encrypted with zip and gpg symmetric
606exfiltrationT10222Compress Data and lock with password for Exfiltration with winrar
607exfiltrationT10223Compress Data and lock with password for Exfiltration with winzip
608exfiltrationT10224Compress Data and lock with password for Exfiltration with 7zip
609exfiltrationT10301Data Transfer Size Limits
610exfiltrationT10481Exfiltration Over Alternative Protocol - SSH
611exfiltrationT10482Exfiltration Over Alternative Protocol - SSH
612exfiltrationT10483Exfiltration Over Alternative Protocol - HTTP
613exfiltrationT10484Exfiltration Over Alternative Protocol - ICMP
614exfiltrationT10485Exfiltration Over Alternative Protocol - DNS
615command-and-controlT10901Connection Proxy
616command-and-controlT10902portproxy reg key
617command-and-controlT11321Base64 Encoded data.
618command-and-controlT12191TeamViewer Files Detected Test on Windows
619command-and-controlT11051rsync remote file copy (push)
620command-and-controlT11052rsync remote file copy (pull)
621command-and-controlT11053scp remote file copy (push)
622command-and-controlT11054scp remote file copy (pull)
623command-and-controlT11055sftp remote file copy (push)
624command-and-controlT11056sftp remote file copy (pull)
625command-and-controlT11057certutil download (urlcache)
626command-and-controlT11058certutil download (verifyctl)
627command-and-controlT11059Windows - BITSAdmin BITS Download
628command-and-controlT110510Windows - PowerShell Download
629command-and-controlT110511OSTAP Worming Activity
630command-and-controlT10711Malicious User Agents - Powershell
631command-and-controlT10712Malicious User Agents - CMD
632command-and-controlT10713Malicious User Agents - Nix
633command-and-controlT10714DNS Large Query Volume
634command-and-controlT10715DNS Regular Beaconing
635command-and-controlT10716DNS Long Domain Query
636command-and-controlT10717DNS C2
637command-and-controlT10718OSTap Payload Download
638command-and-controlT10321OpenSSL C2
639command-and-controlT10951ICMP C2
640command-and-controlT10952Netcat C2
641command-and-controlT10953Powercat C2
642command-and-controlT10651Testing usage of uncommonly used port with PowerShell
643command-and-controlT10652Testing usage of uncommonly used port
644command-and-controlT11021Reach out to C2 Pointer URLs via command_prompt
645command-and-controlT11022Reach out to C2 Pointer URLs via powershell
646initial-accessT11931Download Phishing Attachment - VBScript