Files
atomic-red-team/atomics/Indexes/Indexes-CSV/linux-index.csv
T
2026-04-24 07:25:50 +00:00

68 KiB

1TacticTechnique #Technique NameTest #Test NameTest GUIDExecutor Name
2defense-evasionT1556.003Modify Authentication Process: Pluggable Authentication Modules1Malicious PAM rule4b9dde80-ae22-44b1-a82a-644bf009eb9csh
3defense-evasionT1556.003Modify Authentication Process: Pluggable Authentication Modules2Malicious PAM rule (freebsd)b17eacac-282d-4ca8-a240-46602cf863e3sh
4defense-evasionT1556.003Modify Authentication Process: Pluggable Authentication Modules3Malicious PAM module65208808-3125-4a2e-8389-a0a00e9ab326sh
5defense-evasionT1222.002File and Directory Permissions Modification: FreeBSD, Linux and Mac File and Directory Permissions Modification1chmod - Change file or folder mode (numeric mode)34ca1464-de9d-40c6-8c77-690adf36a135sh
6defense-evasionT1222.002File and Directory Permissions Modification: FreeBSD, Linux and Mac File and Directory Permissions Modification2chmod - Change file or folder mode (symbolic mode)fc9d6695-d022-4a80-91b1-381f5c35aff3sh
7defense-evasionT1222.002File and Directory Permissions Modification: FreeBSD, Linux and Mac File and Directory Permissions Modification3chmod - Change file or folder mode (numeric mode) recursivelyea79f937-4a4d-4348-ace6-9916aec453a4sh
8defense-evasionT1222.002File and Directory Permissions Modification: FreeBSD, Linux and Mac File and Directory Permissions Modification4chmod - Change file or folder mode (symbolic mode) recursively0451125c-b5f6-488f-993b-5a32b09f7d8fbash
9defense-evasionT1222.002File and Directory Permissions Modification: FreeBSD, Linux and Mac File and Directory Permissions Modification5chown - Change file or folder ownership and groupd169e71b-85f9-44ec-8343-27093ff3dfc0bash
10defense-evasionT1222.002File and Directory Permissions Modification: FreeBSD, Linux and Mac File and Directory Permissions Modification6chown - Change file or folder ownership and group recursivelyb78598be-ff39-448f-a463-adbf2a5b7848bash
11defense-evasionT1222.002File and Directory Permissions Modification: FreeBSD, Linux and Mac File and Directory Permissions Modification7chown - Change file or folder mode ownership only967ba79d-f184-4e0e-8d09-6362b3162e99sh
12defense-evasionT1222.002File and Directory Permissions Modification: FreeBSD, Linux and Mac File and Directory Permissions Modification8chown - Change file or folder ownership recursively3b015515-b3d8-44e9-b8cd-6fa84faf30b2bash
13defense-evasionT1222.002File and Directory Permissions Modification: FreeBSD, Linux and Mac File and Directory Permissions Modification9chattr - Remove immutable file attributee7469fe2-ad41-4382-8965-99b94dd3c13fsh
14defense-evasionT1222.002File and Directory Permissions Modification: FreeBSD, Linux and Mac File and Directory Permissions Modification10chflags - Remove immutable file attribute60eee3ea-2ebd-453b-a666-c52ce08d2709sh
15defense-evasionT1222.002File and Directory Permissions Modification: FreeBSD, Linux and Mac File and Directory Permissions Modification11Chmod through c script973631cf-6680-4ffa-a053-045e1b6b67absh
16defense-evasionT1222.002File and Directory Permissions Modification: FreeBSD, Linux and Mac File and Directory Permissions Modification12Chmod through c script (freebsd)da40b5fe-3098-4b3b-a410-ff177e49ee2esh
17defense-evasionT1222.002File and Directory Permissions Modification: FreeBSD, Linux and Mac File and Directory Permissions Modification13Chown through c script18592ba1-5f88-4e3c-abc8-ab1c6042e389sh
18defense-evasionT1222.002File and Directory Permissions Modification: FreeBSD, Linux and Mac File and Directory Permissions Modification14Chown through c script (freebsd)eb577a19-b730-4918-9b03-c5edcf51dc4esh
19defense-evasionT1027.013Obfuscated Files or Information: Encrypted/Encoded File1Decode Eicar File and Write to File7693ccaa-8d64-4043-92a5-a2eb70359535powershell
20defense-evasionT1027.013Obfuscated Files or Information: Encrypted/Encoded File2Decrypt Eicar File and Write to Fileb404caaa-12ce-43c7-9214-62a531c044f7powershell
21defense-evasionT1027.013Obfuscated Files or Information: Encrypted/Encoded File3Password-Protected ZIP Payload Extraction and Executionc2ca068a-eb1e-498f-9f93-3d554c455916bash
22defense-evasionT1014Rootkit1Loadable Kernel Module based Rootkitdfb50072-e45a-4c75-a17e-a484809c8553sh
23defense-evasionT1014Rootkit2Loadable Kernel Module based Rootkit75483ef8-f10f-444a-bf02-62eb0e48db6fsh
24defense-evasionT1014Rootkit3dynamic-linker based rootkit (libprocesshider)1338bf0c-fd0c-48c0-9e65-329f18e2c0d3sh
25defense-evasionT1014Rootkit4Loadable Kernel Module based Rootkit (Diamorphine)0b996469-48c6-46e2-8155-a17f8b6c2247sh
26defense-evasionT1548.003Abuse Elevation Control Mechanism: Sudo and Sudo Caching1Sudo usage150c3a08-ee6e-48a6-aeaf-3659d24ceb4esh
27defense-evasionT1548.003Abuse Elevation Control Mechanism: Sudo and Sudo Caching2Sudo usage (freebsd)2bf9a018-4664-438a-b435-cc6f8c6f71b1sh
28defense-evasionT1548.003Abuse Elevation Control Mechanism: Sudo and Sudo Caching3Unlimited sudo cache timeouta7b17659-dd5e-46f7-b7d1-e6792c91d0bcsh
29defense-evasionT1548.003Abuse Elevation Control Mechanism: Sudo and Sudo Caching4Unlimited sudo cache timeout (freebsd)a83ad6e8-6f24-4d7f-8f44-75f8ab742991sh
30defense-evasionT1548.003Abuse Elevation Control Mechanism: Sudo and Sudo Caching5Disable tty_tickets for sudo caching91a60b03-fb75-4d24-a42e-2eb8956e8de1sh
31defense-evasionT1548.003Abuse Elevation Control Mechanism: Sudo and Sudo Caching6Disable tty_tickets for sudo caching (freebsd)4df6a0fe-2bdd-4be8-8618-a6a19654a57ash
32defense-evasionT1036.005Masquerading: Match Legitimate Name or Location1Execute a process from a directory masquerading as the current parent directory812c3ab8-94b0-4698-a9bf-9420af23ce24sh
33defense-evasionT1497.001Virtualization/Sandbox Evasion: System Checks1Detect Virtualization Environment (Linux)dfbd1a21-540d-4574-9731-e852bd6fe840sh
34defense-evasionT1497.001Virtualization/Sandbox Evasion: System Checks2Detect Virtualization Environment (FreeBSD)e129d73b-3e03-4ae9-bf1e-67fc8921e0fdsh
35defense-evasionT1070.002Indicator Removal on Host: Clear FreeBSD, Linux or Mac System Logs1rm -rf989cc1b1-3642-4260-a809-54f9dd559683sh
36defense-evasionT1070.002Indicator Removal on Host: Clear FreeBSD, Linux or Mac System Logs2rm -rfbd8ccc45-d632-481e-b7cf-c467627d68f9sh
37defense-evasionT1070.002Indicator Removal on Host: Clear FreeBSD, Linux or Mac System Logs5Truncate system log files via truncate utility (freebsd)14033063-ee04-4eaf-8f5d-ba07ca7a097csh
38defense-evasionT1070.002Indicator Removal on Host: Clear FreeBSD, Linux or Mac System Logs7Delete log files via cat utility by appending /dev/null or /dev/zero (freebsd)369878c6-fb04-48d6-8fc2-da9d97b3e054sh
39defense-evasionT1070.002Indicator Removal on Host: Clear FreeBSD, Linux or Mac System Logs10Overwrite FreeBSD system log via echo utility11cb8ee1-97fb-4960-8587-69b8388ee9d9sh
40defense-evasionT1070.002Indicator Removal on Host: Clear FreeBSD, Linux or Mac System Logs13Delete system log files via unlink utility (freebsd)45ad4abd-19bd-4c5f-a687-41f3eee8d8c2sh
41defense-evasionT1070.002Indicator Removal on Host: Clear FreeBSD, Linux or Mac System Logs18Delete system journal logs via rm and journalctl utilitiesca50dd85-81ff-48ca-92e1-61f119cb1dcfsh
42defense-evasionT1070.002Indicator Removal on Host: Clear FreeBSD, Linux or Mac System Logs19Overwrite Linux Mail Spool1602ff76-ed7f-4c94-b550-2f727b4782d4bash
43defense-evasionT1070.002Indicator Removal on Host: Clear FreeBSD, Linux or Mac System Logs20Overwrite Linux Logd304b2dc-90b4-4465-a650-16ddd503f7b5bash
44defense-evasionT1070.003Indicator Removal on Host: Clear Command History1Clear Bash history (rm)a934276e-2be5-4a36-93fd-98adbb5bd4fcsh
45defense-evasionT1070.003Indicator Removal on Host: Clear Command History2Clear Bash history (echo)cbf506a5-dd78-43e5-be7e-a46b7c7a0a11sh
46defense-evasionT1070.003Indicator Removal on Host: Clear Command History3Clear Bash history (cat dev/null)b1251c35-dcd3-4ea1-86da-36d27b54f31fsh
47defense-evasionT1070.003Indicator Removal on Host: Clear Command History4Clear Bash history (ln dev/null)23d348f3-cc5c-4ba9-bd0a-ae09069f0914sh
48defense-evasionT1070.003Indicator Removal on Host: Clear Command History5Clear Bash history (truncate)47966a1d-df4f-4078-af65-db6d9aa20739sh
49defense-evasionT1070.003Indicator Removal on Host: Clear Command History6Clear history of a bunch of shells7e6721df-5f08-4370-9255-f06d8a77af4csh
50defense-evasionT1070.003Indicator Removal on Host: Clear Command History7Clear and Disable Bash History Logging784e4011-bd1a-4ecd-a63a-8feb278512e6bash
51defense-evasionT1070.003Indicator Removal on Host: Clear Command History8Use Space Before Command to Avoid Logging to History53b03a54-4529-4992-852d-a00b4b7215a6sh
52defense-evasionT1070.003Indicator Removal on Host: Clear Command History9Disable Bash History Logging with SSH -T5f8abd62-f615-43c5-b6be-f780f25790a1sh
53defense-evasionT1070.003Indicator Removal on Host: Clear Command History10Clear Docker Container Logs553b39f9-1e8c-47b1-abf5-8daf7b0391e9bash
54defense-evasionT1140Deobfuscate/Decode Files or Information3Base64 decoding with Python356dc0e8-684f-4428-bb94-9313998ad608sh
55defense-evasionT1140Deobfuscate/Decode Files or Information4Base64 decoding with Perl6604d964-b9f6-4d4b-8ce8-499829a14d0ash
56defense-evasionT1140Deobfuscate/Decode Files or Information5Base64 decoding with shell utilitiesb4f6a567-a27a-41e5-b8ef-ac4b4008bb7esh
57defense-evasionT1140Deobfuscate/Decode Files or Information6Base64 decoding with shell utilities (freebsd)b6097712-c42e-4174-b8f2-4b1e1a5bbb3dsh
58defense-evasionT1140Deobfuscate/Decode Files or Information7FreeBSD b64encode Shebang in CLI18ee2002-66e8-4518-87c5-c0ec9c8299acsh
59defense-evasionT1140Deobfuscate/Decode Files or Information8Hex decoding with shell utilities005943f9-8dd5-4349-8b46-0313c0a9f973sh
60defense-evasionT1140Deobfuscate/Decode Files or Information9Linux Base64 Encoded Shebang in CLI3a15c372-67c1-4430-ac8e-ec06d641ce4dsh
61defense-evasionT1140Deobfuscate/Decode Files or Information10XOR decoding and command execution using Pythonc3b65cd5-ee51-4e98-b6a3-6cbdec138efcbash
62defense-evasionT1562Impair Defenses2Disable journal logging via systemctl utilityc3a377f9-1203-4454-aa35-9d391d34768fsh
63defense-evasionT1562Impair Defenses3Disable journal logging via sed utility12e5551c-8d5c-408e-b3e4-63f53b03379fsh
64defense-evasionT1070.008Email Collection: Mailbox Manipulation2Copy and Delete Mailbox Data on Linux25e2be0e-96f7-4417-bd16-a4a2500e3802bash
65defense-evasionT1070.008Email Collection: Mailbox Manipulation5Copy and Modify Mailbox Data on Linux6d99f93c-da56-49e3-b195-163090ace4f6bash
66defense-evasionT1070.006Indicator Removal on Host: Timestomp1Set a file's access timestamp5f9113d5-ed75-47ed-ba23-ea3573d05810sh
67defense-evasionT1070.006Indicator Removal on Host: Timestomp2Set a file's modification timestamp20ef1523-8758-4898-b5a2-d026cc3d2c52sh
68defense-evasionT1070.006Indicator Removal on Host: Timestomp3Set a file's creation timestamp8164a4a6-f99c-4661-ac4f-80f5e4e78d2bsh
69defense-evasionT1070.006Indicator Removal on Host: Timestomp4Modify file timestamps using reference file631ea661-d661-44b0-abdb-7a7f3fc08e50sh
70defense-evasionT1497.003Time Based Evasion1Delay execution with ping8b87dd03-8204-478c-bac3-3959f6528de3sh
71defense-evasionT1562.004Impair Defenses: Disable or Modify System Firewall7Stop/Start UFW firewallfe135572-edcd-49a2-afe6-1d39521c5a9ash
72defense-evasionT1562.004Impair Defenses: Disable or Modify System Firewall8Stop/Start Packet Filter0ca82ed1-0a94-4774-9a9a-a2c83a8022b7sh
73defense-evasionT1562.004Impair Defenses: Disable or Modify System Firewall9Stop/Start UFW firewall systemctl9fd99609-1854-4f3c-b47b-97d9a5972bd1sh
74defense-evasionT1562.004Impair Defenses: Disable or Modify System Firewall10Turn off UFW logging8a95b832-2c2a-494d-9cb0-dc9dd97c8badsh
75defense-evasionT1562.004Impair Defenses: Disable or Modify System Firewall11Add and delete UFW firewall rulesb2563a4e-c4b8-429c-8d47-d5bcb227ba7ash
76defense-evasionT1562.004Impair Defenses: Disable or Modify System Firewall12Add and delete Packet Filter rules8b23cae1-66c1-41c5-b79d-e095b6098b5bsh
77defense-evasionT1562.004Impair Defenses: Disable or Modify System Firewall13Edit UFW firewall user.rules filebeaf815a-c883-4194-97e9-fdbbb2bbdd7csh
78defense-evasionT1562.004Impair Defenses: Disable or Modify System Firewall14Edit UFW firewall ufw.conf filec1d8c4eb-88da-4927-ae97-c7c25893803bsh
79defense-evasionT1562.004Impair Defenses: Disable or Modify System Firewall15Edit UFW firewall sysctl.conf filec4ae0701-88d3-4cd8-8bce-4801ed9f97e4sh
80defense-evasionT1562.004Impair Defenses: Disable or Modify System Firewall16Edit UFW firewall main configuration file7b697ece-8270-46b5-bbc7-6b9e27081831sh
81defense-evasionT1562.004Impair Defenses: Disable or Modify System Firewall17Tail the UFW firewall log file419cca0c-fa52-4572-b0d7-bc7c6f388a27sh
82defense-evasionT1562.004Impair Defenses: Disable or Modify System Firewall18Disable iptables7784c64e-ed0b-4b65-bf63-c86db229fd56sh
83defense-evasionT1562.004Impair Defenses: Disable or Modify System Firewall19Modify/delete iptables firewall rules899a7fb5-d197-4951-8614-f19ac4a73ad4sh
84defense-evasionT1562.012Impair Defenses: Disable or Modify Linux Audit System1Delete all auditd rules using auditctl33a29ab1-cabb-407f-9448-269041bf2856sh
85defense-evasionT1562.012Impair Defenses: Disable or Modify Linux Audit System2Disable auditd using auditctl7906f0a6-b527-46ee-9026-6e81a9184e08sh
86defense-evasionT1027.001Obfuscated Files or Information: Binary Padding1Pad Binary to Change Hash - Linux/macOS ddffe2346c-abd5-4b45-a713-bf5f1ebd573ash
87defense-evasionT1027.001Obfuscated Files or Information: Binary Padding2Pad Binary to Change Hash using truncate command - Linux/macOSe22a9e89-69c7-410f-a473-e6c212cd2292sh
88defense-evasionT1574.006Hijack Execution Flow: LD_PRELOAD1Shared Library Injection via /etc/ld.so.preload39cb0e67-dd0d-4b74-a74b-c072db7ae991bash
89defense-evasionT1574.006Hijack Execution Flow: LD_PRELOAD2Shared Library Injection via LD_PRELOADbc219ff7-789f-4d51-9142-ecae3397deaebash
90defense-evasionT1548.001Abuse Elevation Control Mechanism: Setuid and Setgid1Make and modify binary from C source896dfe97-ae43-4101-8e96-9a7996555d80sh
91defense-evasionT1548.001Abuse Elevation Control Mechanism: Setuid and Setgid2Make and modify binary from C source (freebsd)dd580455-d84b-481b-b8b0-ac96f3b1dc4csh
92defense-evasionT1548.001Abuse Elevation Control Mechanism: Setuid and Setgid3Set a SetUID flag on file759055b3-3885-4582-a8ec-c00c9d64dd79sh
93defense-evasionT1548.001Abuse Elevation Control Mechanism: Setuid and Setgid4Set a SetUID flag on file (freebsd)9be9b827-ff47-4e1b-bef8-217db6fb7283sh
94defense-evasionT1548.001Abuse Elevation Control Mechanism: Setuid and Setgid5Set a SetGID flag on filedb55f666-7cba-46c6-9fe6-205a05c3242csh
95defense-evasionT1548.001Abuse Elevation Control Mechanism: Setuid and Setgid6Set a SetGID flag on file (freebsd)1f73af33-62a8-4bf1-bd10-3bea931f2c0dsh
96defense-evasionT1548.001Abuse Elevation Control Mechanism: Setuid and Setgid7Make and modify capabilities of a binarydb53959c-207d-4000-9e7a-cd8eb417e072sh
97defense-evasionT1548.001Abuse Elevation Control Mechanism: Setuid and Setgid8Provide the SetUID capability to a file1ac3272f-9bcf-443a-9888-4b1d3de785c1sh
98defense-evasionT1548.001Abuse Elevation Control Mechanism: Setuid and Setgid9Do reconnaissance for files that have the setuid bit set8e36da01-cd29-45fd-be72-8a0fcaad4481sh
99defense-evasionT1548.001Abuse Elevation Control Mechanism: Setuid and Setgid10Do reconnaissance for files that have the setgid bit set3fb46e17-f337-4c14-9f9a-a471946533e2sh
100defense-evasionT1562.006Impair Defenses: Indicator Blocking1Auditing Configuration Changes on Linux Host212cfbcf-4770-4980-bc21-303e37abd0e3bash
101defense-evasionT1562.006Impair Defenses: Indicator Blocking2Auditing Configuration Changes on FreeBSD Hostcedaf7e7-28ee-42ab-ba13-456abd35d1bdsh
102defense-evasionT1562.006Impair Defenses: Indicator Blocking3Logging Configuration Changes on Linux Host7d40bc58-94c7-4fbb-88d9-ebce9fcdb60cbash
103defense-evasionT1562.006Impair Defenses: Indicator Blocking4Logging Configuration Changes on FreeBSD Host6b8ca3ab-5980-4321-80c3-bcd77c8daed8sh
104defense-evasionT1036.004Masquerading: Masquerade Task or Service3linux rename /proc/pid/comm using prctlf0e3aaea-5cd9-4db6-a077-631dd19b27a8sh
105defense-evasionT1036.004Masquerading: Masquerade Task or Service4Hiding a malicious process with bind mountsad4b73c2-d6e2-4d8b-9868-4c6f55906e01sh
106defense-evasionT1562.010Impair Defenses: Downgrade Attack1ESXi - Change VIB acceptance level to CommunitySupported via PowerCLI062f92c9-28b1-4391-a5f8-9d8ca6852091powershell
107defense-evasionT1562.003Impair Defenses: Impair Command History Logging1Disable history collection4eafdb45-0f79-4d66-aa86-a3e2c08791f5sh
108defense-evasionT1562.003Impair Defenses: Impair Command History Logging2Disable history collection (freebsd)cada55b4-8251-4c60-819e-8ec1b33c9306sh
109defense-evasionT1562.003Impair Defenses: Impair Command History Logging3Mac HISTCONTROL468566d5-83e5-40c1-b338-511e1659628dmanual
110defense-evasionT1562.003Impair Defenses: Impair Command History Logging4Clear bash history878794f7-c511-4199-a950-8c28b3ed8e5bbash
111defense-evasionT1562.003Impair Defenses: Impair Command History Logging5Setting the HISTCONTROL environment variable10ab786a-028e-4465-96f6-9e83ca6c5f24bash
112defense-evasionT1562.003Impair Defenses: Impair Command History Logging6Setting the HISTFILESIZE environment variable5cafd6c1-2f43-46eb-ac47-a5301ba0a618bash
113defense-evasionT1562.003Impair Defenses: Impair Command History Logging7Setting the HISTSIZE environment variable386d3850-2ce7-4508-b56b-c0558922c814sh
114defense-evasionT1562.003Impair Defenses: Impair Command History Logging8Setting the HISTFILE environment variableb3dacb6c-a9e3-44ec-bf87-38db60c5cad1bash
115defense-evasionT1562.003Impair Defenses: Impair Command History Logging9Setting the HISTFILE environment variable (freebsd)f7308845-6da8-468e-99f2-4271f2f5bb67sh
116defense-evasionT1562.003Impair Defenses: Impair Command History Logging10Setting the HISTIGNORE environment variablef12acddb-7502-4ce6-a146-5b62c59592f1bash
117defense-evasionT1562.001Impair Defenses: Disable or Modify Tools1Disable syslog4ce786f8-e601-44b5-bfae-9ebb15a7d1c8sh
118defense-evasionT1562.001Impair Defenses: Disable or Modify Tools2Disable syslog (freebsd)db9de996-441e-4ae0-947b-61b6871e2fdfsh
119defense-evasionT1562.001Impair Defenses: Disable or Modify Tools3Disable Cb Responseae8943f7-0f8d-44de-962d-fbc2e2f03eb8sh
120defense-evasionT1562.001Impair Defenses: Disable or Modify Tools4Disable SELinuxfc225f36-9279-4c39-b3f9-5141ab74f8d8sh
121defense-evasionT1562.001Impair Defenses: Disable or Modify Tools5Stop Crowdstrike Falcon on Linux828a1278-81cc-4802-96ab-188bf29ca77dsh
122defense-evasionT1562.001Impair Defenses: Disable or Modify Tools39Clear History23b88394-091b-4968-a42d-fb8076992443sh
123defense-evasionT1562.001Impair Defenses: Disable or Modify Tools40Suspend History94f6a1c9-aae7-46a4-9083-2bb1f5768ec4sh
124defense-evasionT1562.001Impair Defenses: Disable or Modify Tools41Reboot Linux Host via Kernel System Request6d6d3154-1a52-4d1a-9d51-92ab8148b32esh
125defense-evasionT1562.001Impair Defenses: Disable or Modify Tools42Clear Pagging Cachef790927b-ea85-4a16-b7b2-7eb44176a510sh
126defense-evasionT1562.001Impair Defenses: Disable or Modify Tools43Disable Memory Swape74e4c63-6fde-4ad2-9ee8-21c3a1733114sh
127defense-evasionT1562.001Impair Defenses: Disable or Modify Tools47Tamper with Defender ATP on Linux/MacOS40074085-dbc8-492b-90a3-11bcfc52fda8sh
128defense-evasionT1562.001Impair Defenses: Disable or Modify Tools50ESXi - Disable Account Lockout Policy via PowerCLI091a6290-cd29-41cb-81ea-b12f133c66cbpowershell
129defense-evasionT1562.001Impair Defenses: Disable or Modify Tools59Disable ASLR Via sysctl parameters - Linuxac333fe1-ce2b-400b-a117-538634427439bash
130defense-evasionT1027Obfuscated Files or Information1Decode base64 Data into Scriptf45df6be-2e1e-4136-a384-8f18ab3826fbsh
131defense-evasionT1036.003Masquerading: Rename System Utilities2Masquerading as FreeBSD or Linux crond process.a315bfff-7a98-403b-b442-2ea1b255e556sh
132defense-evasionT1553.004Subvert Trust Controls: Install Root Certificate1Install root CA on CentOS/RHEL9c096ec4-fd42-419d-a762-d64cc950627esh
133defense-evasionT1553.004Subvert Trust Controls: Install Root Certificate2Install root CA on FreeBSDf4568003-1438-44ab-a234-b3252ea7e7a3sh
134defense-evasionT1553.004Subvert Trust Controls: Install Root Certificate3Install root CA on Debian/Ubuntu53bcf8a0-1549-4b85-b919-010c56d724ffsh
135defense-evasionT1027.004Obfuscated Files or Information: Compile After Delivery3C compiled0377aa6-850a-42b2-95f0-de558d80be57sh
136defense-evasionT1027.004Obfuscated Files or Information: Compile After Delivery4CC compileda97bb11-d6d0-4fc1-b445-e443d1346efesh
137defense-evasionT1027.004Obfuscated Files or Information: Compile After Delivery5Go compile78bd3fa7-773c-449e-a978-dc1f1500bc52sh
138defense-evasionT1070.004Indicator Removal on Host: File Deletion1Delete a single file - FreeBSD/Linux/macOS562d737f-2fc6-4b09-8c2a-7f8ff0828480sh
139defense-evasionT1070.004Indicator Removal on Host: File Deletion2Delete an entire folder - FreeBSD/Linux/macOSa415f17e-ce8d-4ce2-a8b4-83b674e7017esh
140defense-evasionT1070.004Indicator Removal on Host: File Deletion3Overwrite and delete a file with shred039b4b10-2900-404b-b67f-4b6d49aa6499sh
141defense-evasionT1070.004Indicator Removal on Host: File Deletion8Delete Filesystem - Linuxf3aa95fe-4f10-4485-ad26-abf22a764c52sh
142defense-evasionT1027.002Obfuscated Files or Information: Software Packing1Binary simply packed by UPX (linux)11c46cd8-e471-450e-acb8-52a1216ae6a4sh
143defense-evasionT1027.002Obfuscated Files or Information: Software Packing2Binary packed by UPX, with modified headers (linux)f06197f8-ff46-48c2-a0c6-afc1b50665e1sh
144defense-evasionT1036.006Masquerading: Space after Filename2Space After Filenameb95ce2eb-a093-4cd8-938d-5258cef656eash
145defense-evasionT1564.001Hide Artifacts: Hidden Files and Directories1Create a hidden file in a hidden directory61a782e5-9a19-40b5-8ba4-69a4b9f3d7besh
146defense-evasionT1078.003Valid Accounts: Local Accounts8Create local account (Linux)02a91c34-8a5b-4bed-87af-501103eb5357bash
147defense-evasionT1078.003Valid Accounts: Local Accounts9Reactivate a locked/expired account (Linux)d2b95631-62d7-45a3-aaef-0972cea97931bash
148defense-evasionT1078.003Valid Accounts: Local Accounts10Reactivate a locked/expired account (FreeBSD)09e3380a-fae5-4255-8b19-9950be0252cfsh
149defense-evasionT1078.003Valid Accounts: Local Accounts11Login as nobody (Linux)3d2cd093-ee05-41bd-a802-59ee5c301b85bash
150defense-evasionT1078.003Valid Accounts: Local Accounts12Login as nobody (freebsd)16f6374f-7600-459a-9b16-6a88fd96d310sh
151persistenceT1556.003Modify Authentication Process: Pluggable Authentication Modules1Malicious PAM rule4b9dde80-ae22-44b1-a82a-644bf009eb9csh
152persistenceT1556.003Modify Authentication Process: Pluggable Authentication Modules2Malicious PAM rule (freebsd)b17eacac-282d-4ca8-a240-46602cf863e3sh
153persistenceT1556.003Modify Authentication Process: Pluggable Authentication Modules3Malicious PAM module65208808-3125-4a2e-8389-a0a00e9ab326sh
154persistenceT1053.003Scheduled Task/Job: Cron1Cron - Replace crontab with referenced file435057fb-74b1-410e-9403-d81baf194f75sh
155persistenceT1053.003Scheduled Task/Job: Cron2Cron - Add script to all cron subfoldersb7d42afa-9086-4c8a-b7b0-8ea3faa6ebb0bash
156persistenceT1053.003Scheduled Task/Job: Cron3Cron - Add script to /etc/cron.d folder078e69eb-d9fb-450e-b9d0-2e118217c846sh
157persistenceT1053.003Scheduled Task/Job: Cron4Cron - Add script to /var/spool/cron/crontabs/ folder2d943c18-e74a-44bf-936f-25ade6cccab4bash
158persistenceT1176Browser Extensions1Chrome/Chromium (Developer Mode)3ecd790d-2617-4abf-9a8c-4e8d47da9ee1manual
159persistenceT1176Browser Extensions2Firefoxcb790029-17e6-4c43-b96f-002ce5f10938manual
160persistenceT1546.005Event Triggered Execution: Trap1Trap EXITa74b2e07-5952-4c03-8b56-56274b076b61sh
161persistenceT1546.005Event Triggered Execution: Trap2Trap EXIT (freebsd)be1a5d70-6865-44aa-ab50-42244c9fd16fsh
162persistenceT1546.005Event Triggered Execution: Trap3Trap SIGINTa547d1ba-1d7a-4cc5-a9cb-8d65e8809636sh
163persistenceT1546.005Event Triggered Execution: Trap4Trap SIGINT (freebsd)ade10242-1eac-43df-8412-be0d4c704adash
164persistenceT1574.006Hijack Execution Flow: LD_PRELOAD1Shared Library Injection via /etc/ld.so.preload39cb0e67-dd0d-4b74-a74b-c072db7ae991bash
165persistenceT1574.006Hijack Execution Flow: LD_PRELOAD2Shared Library Injection via LD_PRELOADbc219ff7-789f-4d51-9142-ecae3397deaebash
166persistenceT1136.001Create Account: Local Account1Create a user account on a Linux system40d8eabd-e394-46f6-8785-b9bfa1d011d2bash
167persistenceT1136.001Create Account: Local Account2Create a user account on a FreeBSD systema39ee1bc-b8c1-4331-8e5f-1859eb408518sh
168persistenceT1136.001Create Account: Local Account6Create a new user in Linux with `root` UID and GID.a1040a30-d28b-4eda-bd99-bb2861a4616cbash
169persistenceT1136.001Create Account: Local Account7Create a new user in FreeBSD with `root` GID.d141afeb-d2bc-4934-8dd5-b7dba0f9f67ash
170persistenceT1098.004SSH Authorized Keys1Modify SSH Authorized Keys342cc723-127c-4d3a-8292-9c0c6b4ecadcsh
171persistenceT1136.002Create Account: Domain Account4Active Directory Create Admin Account562aa072-524e-459a-ba2b-91f1afccf5absh
172persistenceT1136.002Create Account: Domain Account5Active Directory Create User Account (Non-elevated)8c992cb3-a46e-4fd5-b005-b1bab185af31sh
173persistenceT1547.006Boot or Logon Autostart Execution: Kernel Modules and Extensions1Linux - Load Kernel Module via insmod687dcb93-9656-4853-9c36-9977315e9d23bash
174persistenceT1053.006Scheduled Task/Job: Systemd Timers1Create Systemd Service and Timerf4983098-bb13-44fb-9b2c-46149961807bbash
175persistenceT1053.006Scheduled Task/Job: Systemd Timers2Create a user level transient systemd service and timer3de33f5b-62e5-4e63-a2a0-6fd8808c80ecsh
176persistenceT1053.006Scheduled Task/Job: Systemd Timers3Create a system level transient systemd service and timerd3eda496-1fc0-49e9-aff5-3bec5da9fa22sh
177persistenceT1546.004Event Triggered Execution: .bash_profile .bashrc and .shrc1Add command to .bash_profile94500ae1-7e31-47e3-886b-c328da46872fsh
178persistenceT1546.004Event Triggered Execution: .bash_profile .bashrc and .shrc2Add command to .bashrc0a898315-4cfa-4007-bafe-33a4646d115fsh
179persistenceT1546.004Event Triggered Execution: .bash_profile .bashrc and .shrc3Add command to .shrc41502021-591a-4649-8b6e-83c9192aff53sh
180persistenceT1546.004Event Triggered Execution: .bash_profile .bashrc and .shrc4Append to the system shell profile694b3cc8-6a78-4d35-9e74-0123d009e94bsh
181persistenceT1546.004Event Triggered Execution: .bash_profile .bashrc and .shrc5Append commands user shell profilebbdb06bc-bab6-4f5b-8232-ba3fbed51d77sh
182persistenceT1546.004Event Triggered Execution: .bash_profile .bashrc and .shrc6System shell profile scripts8fe2ccfd-f079-4c03-b1a9-bd9b362b67d4sh
183persistenceT1546.004Event Triggered Execution: .bash_profile .bashrc and .shrc7Create/Append to .bash_logout37ad2f24-7c53-4a50-92da-427a4ad13f58bash
184persistenceT1546.018Event Triggered Execution: Python Startup Hooks3Python Startup Hook - atomic_hook.pth (Linux)a58c066d-f2f0-42a2-ab70-30af73f89e66sh
185persistenceT1546.018Event Triggered Execution: Python Startup Hooks5Python Startup Hook - usercustomize.py (Linux / MacOS)6e78084a-a433-4702-a838-cc7b765d87e8sh
186persistenceT1037.004Boot or Logon Initialization Scripts: Rc.common2rc.commonc33f3d80-5f04-419b-a13a-854d1cbdbf3abash
187persistenceT1037.004Boot or Logon Initialization Scripts: Rc.common3rc.local126f71af-e1c9-405c-94ef-26a47b16c102sh
188persistenceT1543.002Create or Modify System Process: SysV/Systemd Service1Create Systemd Serviced9e4f24f-aa67-4c6e-bcbf-85622b697a7cbash
189persistenceT1543.002Create or Modify System Process: SysV/Systemd Service2Create SysV Service760fe8d2-79d9-494f-905e-a239a3df86f6sh
190persistenceT1543.002Create or Modify System Process: SysV/Systemd Service3Create Systemd Service file, Enable the service , Modify and Reload the service.c35ac4a8-19de-43af-b9f8-755da7e89c89bash
191persistenceT1053.002Scheduled Task/Job: At2At - Schedule a job7266d898-ac82-4ec0-97c7-436075d0d08esh
192persistenceT1078.003Valid Accounts: Local Accounts8Create local account (Linux)02a91c34-8a5b-4bed-87af-501103eb5357bash
193persistenceT1078.003Valid Accounts: Local Accounts9Reactivate a locked/expired account (Linux)d2b95631-62d7-45a3-aaef-0972cea97931bash
194persistenceT1078.003Valid Accounts: Local Accounts10Reactivate a locked/expired account (FreeBSD)09e3380a-fae5-4255-8b19-9950be0252cfsh
195persistenceT1078.003Valid Accounts: Local Accounts11Login as nobody (Linux)3d2cd093-ee05-41bd-a802-59ee5c301b85bash
196persistenceT1078.003Valid Accounts: Local Accounts12Login as nobody (freebsd)16f6374f-7600-459a-9b16-6a88fd96d310sh
197command-and-controlT1132.001Data Encoding: Standard Encoding1Base64 Encoded data.1164f70f-9a88-4dff-b9ff-dc70e7bf0c25sh
198command-and-controlT1132.001Data Encoding: Standard Encoding2Base64 Encoded data (freebsd)2d97c626-7652-449e-a986-b02d9051c298sh
199command-and-controlT1568.002Dynamic Resolution: Domain Generation Algorithms1DGA Simulation (Python)cc367493-3a00-4c4a-a685-16b73339167cbash
200command-and-controlT1659Content Injection1MITM Proxy Injection9b360eaf-c778-4f07-a6e7-895c4f01ac1cbash
201command-and-controlT1572Protocol Tunneling5Microsoft Dev tunnels (Linux/macOS)9f94a112-1ce2-464d-a63b-83c1f465f801bash
202command-and-controlT1572Protocol Tunneling6VSCode tunnels (Linux/macOS)b877943f-0377-44f4-8477-f79db7f07c4dsh
203command-and-controlT1572Protocol Tunneling7Cloudflare tunnels (Linux/macOS)228c336a-2f79-4043-8aef-bfa453a611d5sh
204command-and-controlT1090.003Proxy: Multi-hop Proxy3Tor Proxy Usage - Debian/Ubuntu/FreeBSD5ff9d047-6e9c-4357-b39b-5cf89d9b59c7sh
205command-and-controlT1571Non-Standard Port2Testing usage of uncommonly used port5db21e1d-dd9c-4a50-b885-b1e748912767sh
206command-and-controlT1095Non-Application Layer Protocol4Linux ICMP Reverse Shell using icmp-cnc8e139e1f-1f3a-4be7-901d-afae9738c064manual
207command-and-controlT1071.001Application Layer Protocol: Web Protocols3Malicious User Agents - Nix2d7c471a-e887-4b78-b0dc-b0df1f2e0658sh
208command-and-controlT1105Ingress Tool Transfer1rsync remote file copy (push)0fc6e977-cb12-44f6-b263-2824ba917409sh
209command-and-controlT1105Ingress Tool Transfer2rsync remote file copy (pull)3180f7d5-52c0-4493-9ea0-e3431a84773fsh
210command-and-controlT1105Ingress Tool Transfer3scp remote file copy (push)83a49600-222b-4866-80a0-37736ad29344sh
211command-and-controlT1105Ingress Tool Transfer4scp remote file copy (pull)b9d22b9a-9778-4426-abf0-568ea64e9c33sh
212command-and-controlT1105Ingress Tool Transfer5sftp remote file copy (push)f564c297-7978-4aa9-b37a-d90477feea4ebash
213command-and-controlT1105Ingress Tool Transfer6sftp remote file copy (pull)0139dba1-f391-405e-a4f5-f3989f2c88efsh
214command-and-controlT1105Ingress Tool Transfer14whois file downloadc99a829f-0bb8-4187-b2c6-d47d1df74cabsh
215command-and-controlT1105Ingress Tool Transfer27Linux Download File and Runbdc373c5-e9cf-4563-8a7b-a9ba720a90f3sh
216command-and-controlT1001.002Data Obfuscation via Steganography3Execute Embedded Script in Image via Steganography4ff61684-ad91-405c-9fbc-048354ff1d07sh
217command-and-controlT1090.001Proxy: Internal Proxy1Connection Proxy0ac21132-4485-4212-a681-349e8a6637cdsh
218collectionT1560.001Archive Collected Data: Archive via Utility5Data Compressed - nix - zipc51cec55-28dd-4ad2-9461-1eacbc82c3a0bash
219collectionT1560.001Archive Collected Data: Archive via Utility6Data Compressed - nix - gzip Single Filecde3c2af-3485-49eb-9c1f-0ed60e9cc0afsh
220collectionT1560.001Archive Collected Data: Archive via Utility7Data Compressed - nix - tar Folder or File7af2b51e-ad1c-498c-aca8-d3290c19535ash
221collectionT1560.001Archive Collected Data: Archive via Utility8Data Encrypted with zip and gpg symmetric0286eb44-e7ce-41a0-b109-3da516e05a5fsh
222collectionT1560.001Archive Collected Data: Archive via Utility9Encrypts collected data with AES-256 and Base64a743e3a6-e8b2-4a30-abe7-ca85d201b5d3bash
223collectionT1113Screen Capture3X Windows Capture8206dd0c-faf6-4d74-ba13-7fbe13dce6acbash
224collectionT1113Screen Capture4X Windows Capture (freebsd)562f3bc2-74e8-46c5-95c7-0e01f9ccc65csh
225collectionT1113Screen Capture5Capture Linux Desktop using Import Tool9cd1cccb-91e4-4550-9139-e20a586fcea1bash
226collectionT1113Screen Capture6Capture Linux Desktop using Import Tool (freebsd)18397d87-38aa-4443-a098-8a48a8ca5d8dsh
227collectionT1056.001Input Capture: Keylogging2Living off the land Terminal Input Capture on Linux with pam.d9c6bdb34-a89f-4b90-acb1-5970614c711bsh
228collectionT1056.001Input Capture: Keylogging3Logging bash history to syslog0e59d59d-3265-4d35-bebd-bf5c1ec40db5sh
229collectionT1056.001Input Capture: Keylogging4Logging sh history to syslog/messagesb04284dc-3bd9-4840-8d21-61b8d31c99f2sh
230collectionT1056.001Input Capture: Keylogging5Bash session based keylogger7f85a946-a0ea-48aa-b6ac-8ff539278258bash
231collectionT1056.001Input Capture: Keylogging6SSHD PAM keylogger81d7d2ad-d644-4b6a-bea7-28ffe43beccash
232collectionT1056.001Input Capture: Keylogging7Auditd keyloggera668edb9-334e-48eb-8c2e-5413a40867afsh
233collectionT1074.001Data Staged: Local Data Staging2Stage data from Discovery.sh39ce0303-ae16-4b9e-bb5b-4f53e8262066sh
234collectionT1115Clipboard Data5Add or copy content to clipboard with xClipee363e53-b083-4230-aff3-f8d955f2d5bbsh
235collectionT1005Data from Local System2Find and dump sqlite databases (Linux)00cbb875-7ae4-4cf1-b638-e543fd825300bash
236collectionT1560.002Archive Collected Data: Archive via Library1Compressing data using GZip in Python (FreeBSD/Linux)391f5298-b12d-4636-8482-35d9c17d53a8sh
237collectionT1560.002Archive Collected Data: Archive via Library2Compressing data using bz2 in Python (FreeBSD/Linux)c75612b2-9de0-4d7c-879c-10d7b077072dsh
238collectionT1560.002Archive Collected Data: Archive via Library3Compressing data using zipfile in Python (FreeBSD/Linux)001a042b-859f-44d9-bf81-fd1c4e2200b0sh
239collectionT1560.002Archive Collected Data: Archive via Library4Compressing data using tarfile in Python (FreeBSD/Linux)e86f1b4b-fcc1-4a2a-ae10-b49da01458dbsh
240privilege-escalationT1548.003Abuse Elevation Control Mechanism: Sudo and Sudo Caching1Sudo usage150c3a08-ee6e-48a6-aeaf-3659d24ceb4esh
241privilege-escalationT1548.003Abuse Elevation Control Mechanism: Sudo and Sudo Caching2Sudo usage (freebsd)2bf9a018-4664-438a-b435-cc6f8c6f71b1sh
242privilege-escalationT1548.003Abuse Elevation Control Mechanism: Sudo and Sudo Caching3Unlimited sudo cache timeouta7b17659-dd5e-46f7-b7d1-e6792c91d0bcsh
243privilege-escalationT1548.003Abuse Elevation Control Mechanism: Sudo and Sudo Caching4Unlimited sudo cache timeout (freebsd)a83ad6e8-6f24-4d7f-8f44-75f8ab742991sh
244privilege-escalationT1548.003Abuse Elevation Control Mechanism: Sudo and Sudo Caching5Disable tty_tickets for sudo caching91a60b03-fb75-4d24-a42e-2eb8956e8de1sh
245privilege-escalationT1548.003Abuse Elevation Control Mechanism: Sudo and Sudo Caching6Disable tty_tickets for sudo caching (freebsd)4df6a0fe-2bdd-4be8-8618-a6a19654a57ash
246privilege-escalationT1053.003Scheduled Task/Job: Cron1Cron - Replace crontab with referenced file435057fb-74b1-410e-9403-d81baf194f75sh
247privilege-escalationT1053.003Scheduled Task/Job: Cron2Cron - Add script to all cron subfoldersb7d42afa-9086-4c8a-b7b0-8ea3faa6ebb0bash
248privilege-escalationT1053.003Scheduled Task/Job: Cron3Cron - Add script to /etc/cron.d folder078e69eb-d9fb-450e-b9d0-2e118217c846sh
249privilege-escalationT1053.003Scheduled Task/Job: Cron4Cron - Add script to /var/spool/cron/crontabs/ folder2d943c18-e74a-44bf-936f-25ade6cccab4bash
250privilege-escalationT1546.005Event Triggered Execution: Trap1Trap EXITa74b2e07-5952-4c03-8b56-56274b076b61sh
251privilege-escalationT1546.005Event Triggered Execution: Trap2Trap EXIT (freebsd)be1a5d70-6865-44aa-ab50-42244c9fd16fsh
252privilege-escalationT1546.005Event Triggered Execution: Trap3Trap SIGINTa547d1ba-1d7a-4cc5-a9cb-8d65e8809636sh
253privilege-escalationT1546.005Event Triggered Execution: Trap4Trap SIGINT (freebsd)ade10242-1eac-43df-8412-be0d4c704adash
254privilege-escalationT1574.006Hijack Execution Flow: LD_PRELOAD1Shared Library Injection via /etc/ld.so.preload39cb0e67-dd0d-4b74-a74b-c072db7ae991bash
255privilege-escalationT1574.006Hijack Execution Flow: LD_PRELOAD2Shared Library Injection via LD_PRELOADbc219ff7-789f-4d51-9142-ecae3397deaebash
256privilege-escalationT1548.001Abuse Elevation Control Mechanism: Setuid and Setgid1Make and modify binary from C source896dfe97-ae43-4101-8e96-9a7996555d80sh
257privilege-escalationT1548.001Abuse Elevation Control Mechanism: Setuid and Setgid2Make and modify binary from C source (freebsd)dd580455-d84b-481b-b8b0-ac96f3b1dc4csh
258privilege-escalationT1548.001Abuse Elevation Control Mechanism: Setuid and Setgid3Set a SetUID flag on file759055b3-3885-4582-a8ec-c00c9d64dd79sh
259privilege-escalationT1548.001Abuse Elevation Control Mechanism: Setuid and Setgid4Set a SetUID flag on file (freebsd)9be9b827-ff47-4e1b-bef8-217db6fb7283sh
260privilege-escalationT1548.001Abuse Elevation Control Mechanism: Setuid and Setgid5Set a SetGID flag on filedb55f666-7cba-46c6-9fe6-205a05c3242csh
261privilege-escalationT1548.001Abuse Elevation Control Mechanism: Setuid and Setgid6Set a SetGID flag on file (freebsd)1f73af33-62a8-4bf1-bd10-3bea931f2c0dsh
262privilege-escalationT1548.001Abuse Elevation Control Mechanism: Setuid and Setgid7Make and modify capabilities of a binarydb53959c-207d-4000-9e7a-cd8eb417e072sh
263privilege-escalationT1548.001Abuse Elevation Control Mechanism: Setuid and Setgid8Provide the SetUID capability to a file1ac3272f-9bcf-443a-9888-4b1d3de785c1sh
264privilege-escalationT1548.001Abuse Elevation Control Mechanism: Setuid and Setgid9Do reconnaissance for files that have the setuid bit set8e36da01-cd29-45fd-be72-8a0fcaad4481sh
265privilege-escalationT1548.001Abuse Elevation Control Mechanism: Setuid and Setgid10Do reconnaissance for files that have the setgid bit set3fb46e17-f337-4c14-9f9a-a471946533e2sh
266privilege-escalationT1098.004SSH Authorized Keys1Modify SSH Authorized Keys342cc723-127c-4d3a-8292-9c0c6b4ecadcsh
267privilege-escalationT1547.006Boot or Logon Autostart Execution: Kernel Modules and Extensions1Linux - Load Kernel Module via insmod687dcb93-9656-4853-9c36-9977315e9d23bash
268privilege-escalationT1053.006Scheduled Task/Job: Systemd Timers1Create Systemd Service and Timerf4983098-bb13-44fb-9b2c-46149961807bbash
269privilege-escalationT1053.006Scheduled Task/Job: Systemd Timers2Create a user level transient systemd service and timer3de33f5b-62e5-4e63-a2a0-6fd8808c80ecsh
270privilege-escalationT1053.006Scheduled Task/Job: Systemd Timers3Create a system level transient systemd service and timerd3eda496-1fc0-49e9-aff5-3bec5da9fa22sh
271privilege-escalationT1546.004Event Triggered Execution: .bash_profile .bashrc and .shrc1Add command to .bash_profile94500ae1-7e31-47e3-886b-c328da46872fsh
272privilege-escalationT1546.004Event Triggered Execution: .bash_profile .bashrc and .shrc2Add command to .bashrc0a898315-4cfa-4007-bafe-33a4646d115fsh
273privilege-escalationT1546.004Event Triggered Execution: .bash_profile .bashrc and .shrc3Add command to .shrc41502021-591a-4649-8b6e-83c9192aff53sh
274privilege-escalationT1546.004Event Triggered Execution: .bash_profile .bashrc and .shrc4Append to the system shell profile694b3cc8-6a78-4d35-9e74-0123d009e94bsh
275privilege-escalationT1546.004Event Triggered Execution: .bash_profile .bashrc and .shrc5Append commands user shell profilebbdb06bc-bab6-4f5b-8232-ba3fbed51d77sh
276privilege-escalationT1546.004Event Triggered Execution: .bash_profile .bashrc and .shrc6System shell profile scripts8fe2ccfd-f079-4c03-b1a9-bd9b362b67d4sh
277privilege-escalationT1546.004Event Triggered Execution: .bash_profile .bashrc and .shrc7Create/Append to .bash_logout37ad2f24-7c53-4a50-92da-427a4ad13f58bash
278privilege-escalationT1546.018Event Triggered Execution: Python Startup Hooks3Python Startup Hook - atomic_hook.pth (Linux)a58c066d-f2f0-42a2-ab70-30af73f89e66sh
279privilege-escalationT1546.018Event Triggered Execution: Python Startup Hooks5Python Startup Hook - usercustomize.py (Linux / MacOS)6e78084a-a433-4702-a838-cc7b765d87e8sh
280privilege-escalationT1037.004Boot or Logon Initialization Scripts: Rc.common2rc.commonc33f3d80-5f04-419b-a13a-854d1cbdbf3abash
281privilege-escalationT1037.004Boot or Logon Initialization Scripts: Rc.common3rc.local126f71af-e1c9-405c-94ef-26a47b16c102sh
282privilege-escalationT1543.002Create or Modify System Process: SysV/Systemd Service1Create Systemd Serviced9e4f24f-aa67-4c6e-bcbf-85622b697a7cbash
283privilege-escalationT1543.002Create or Modify System Process: SysV/Systemd Service2Create SysV Service760fe8d2-79d9-494f-905e-a239a3df86f6sh
284privilege-escalationT1543.002Create or Modify System Process: SysV/Systemd Service3Create Systemd Service file, Enable the service , Modify and Reload the service.c35ac4a8-19de-43af-b9f8-755da7e89c89bash
285privilege-escalationT1053.002Scheduled Task/Job: At2At - Schedule a job7266d898-ac82-4ec0-97c7-436075d0d08esh
286privilege-escalationT1078.003Valid Accounts: Local Accounts8Create local account (Linux)02a91c34-8a5b-4bed-87af-501103eb5357bash
287privilege-escalationT1078.003Valid Accounts: Local Accounts9Reactivate a locked/expired account (Linux)d2b95631-62d7-45a3-aaef-0972cea97931bash
288privilege-escalationT1078.003Valid Accounts: Local Accounts10Reactivate a locked/expired account (FreeBSD)09e3380a-fae5-4255-8b19-9950be0252cfsh
289privilege-escalationT1078.003Valid Accounts: Local Accounts11Login as nobody (Linux)3d2cd093-ee05-41bd-a802-59ee5c301b85bash
290privilege-escalationT1078.003Valid Accounts: Local Accounts12Login as nobody (freebsd)16f6374f-7600-459a-9b16-6a88fd96d310sh
291credential-accessT1556.003Modify Authentication Process: Pluggable Authentication Modules1Malicious PAM rule4b9dde80-ae22-44b1-a82a-644bf009eb9csh
292credential-accessT1556.003Modify Authentication Process: Pluggable Authentication Modules2Malicious PAM rule (freebsd)b17eacac-282d-4ca8-a240-46602cf863e3sh
293credential-accessT1556.003Modify Authentication Process: Pluggable Authentication Modules3Malicious PAM module65208808-3125-4a2e-8389-a0a00e9ab326sh
294credential-accessT1056.001Input Capture: Keylogging2Living off the land Terminal Input Capture on Linux with pam.d9c6bdb34-a89f-4b90-acb1-5970614c711bsh
295credential-accessT1056.001Input Capture: Keylogging3Logging bash history to syslog0e59d59d-3265-4d35-bebd-bf5c1ec40db5sh
296credential-accessT1056.001Input Capture: Keylogging4Logging sh history to syslog/messagesb04284dc-3bd9-4840-8d21-61b8d31c99f2sh
297credential-accessT1056.001Input Capture: Keylogging5Bash session based keylogger7f85a946-a0ea-48aa-b6ac-8ff539278258bash
298credential-accessT1056.001Input Capture: Keylogging6SSHD PAM keylogger81d7d2ad-d644-4b6a-bea7-28ffe43beccash
299credential-accessT1056.001Input Capture: Keylogging7Auditd keyloggera668edb9-334e-48eb-8c2e-5413a40867afsh
300credential-accessT1110.001Brute Force: Password Guessing5SUDO Brute Force - Debianba1bf0b6-f32b-4db0-b7cc-d78cacc76700bash
301credential-accessT1110.001Brute Force: Password Guessing6SUDO Brute Force - Redhat4097bc00-5eeb-4d56-aaf9-287d60351d95bash
302credential-accessT1110.001Brute Force: Password Guessing7SUDO Brute Force - FreeBSDabcde488-e083-4ee7-bc85-a5684edd7541bash
303credential-accessT1003.007OS Credential Dumping: Proc Filesystem1Dump individual process memory with sh (Local)7e91138a-8e74-456d-a007-973d67a0bb80sh
304credential-accessT1003.007OS Credential Dumping: Proc Filesystem2Dump individual process memory with sh on FreeBSD (Local)fa37b633-e097-4415-b2b8-c5bf4c86e423sh
305credential-accessT1003.007OS Credential Dumping: Proc Filesystem3Dump individual process memory with Python (Local)437b2003-a20d-4ed8-834c-4964f24eec63sh
306credential-accessT1003.007OS Credential Dumping: Proc Filesystem4Capture Passwords with MimiPenguina27418de-bdce-4ebd-b655-38f04842bf0cbash
307credential-accessT1040Network Sniffing1Packet Capture Linux using tshark or tcpdump7fe741f7-b265-4951-a7c7-320889083b3ebash
308credential-accessT1040Network Sniffing2Packet Capture FreeBSD using tshark or tcpdumpc93f2492-9ebe-44b5-8b45-36574cccfe67sh
309credential-accessT1040Network Sniffing10Packet Capture FreeBSD using /dev/bpfN with sudoe2028771-1bfb-48f5-b5e6-e50ee0942a14sh
310credential-accessT1040Network Sniffing11Filtered Packet Capture FreeBSD using /dev/bpfN with sudoa3a0d4c9-c068-4563-a08d-583bd05b884csh
311credential-accessT1040Network Sniffing12Packet Capture Linux socket AF_PACKET,SOCK_RAW with sudo10c710c9-9104-4d5f-8829-5b65391e2a29bash
312credential-accessT1040Network Sniffing13Packet Capture Linux socket AF_INET,SOCK_RAW,TCP with sudo7a0895f0-84c1-4adf-8491-a21510b1d4c1bash
313credential-accessT1040Network Sniffing14Packet Capture Linux socket AF_INET,SOCK_PACKET,UDP with sudo515575ab-d213-42b1-aa64-ef6a2dd4641bbash
314credential-accessT1040Network Sniffing15Packet Capture Linux socket AF_PACKET,SOCK_RAW with BPF filter for UDP with sudob1cbdf8b-6078-48f5-a890-11ea19d7f8e9bash
315credential-accessT1552Unsecured Credentials1AWS - Retrieve EC2 Password Data using stratusa21118de-b11e-4ebd-b655-42f11142df0csh
316credential-accessT1555.003Credentials from Password Stores: Credentials from Web Browsers9LaZagne.py - Dump Credentials from Firefox Browser87e88698-621b-4c45-8a89-4eaebdeaabb1sh
317credential-accessT1552.004Unsecured Credentials: Private Keys2Discover Private SSH Keys46959285-906d-40fa-9437-5a439accd878sh
318credential-accessT1552.004Unsecured Credentials: Private Keys3Copy Private SSH Keys with CP7c247dc7-5128-4643-907b-73a76d9135c3sh
319credential-accessT1552.004Unsecured Credentials: Private Keys4Copy Private SSH Keys with CP (freebsd)12e4a260-a7fd-4ed8-bf18-1a28c1395775sh
320credential-accessT1552.004Unsecured Credentials: Private Keys5Copy Private SSH Keys with rsync864bb0b2-6bb5-489a-b43b-a77b3a16d68ash
321credential-accessT1552.004Unsecured Credentials: Private Keys6Copy Private SSH Keys with rsync (freebsd)922b1080-0b95-42b0-9585-b9a5ea0af044sh
322credential-accessT1552.004Unsecured Credentials: Private Keys7Copy the users GnuPG directory with rsync2a5a0601-f5fb-4e2e-aa09-73282ae6afcash
323credential-accessT1552.004Unsecured Credentials: Private Keys8Copy the users GnuPG directory with rsync (freebsd)b05ac39b-515f-48e9-88e9-2f141b5bcad0sh
324credential-accessT1552.003Unsecured Credentials: Bash History1Search Through Bash History3cfde62b-7c33-4b26-a61e-755d6131c8cesh
325credential-accessT1552.003Unsecured Credentials: Bash History2Search Through sh Historyd87d3b94-05b4-40f2-a80f-99864ffa6803sh
326credential-accessT1552.001Unsecured Credentials: Credentials In Files1Find AWS credentials37807632-d3da-442e-8c2e-00f44928ff8fsh
327credential-accessT1552.001Unsecured Credentials: Credentials In Files3Extract passwords with grepbd4cf0d1-7646-474e-8610-78ccf5a097c4sh
328credential-accessT1552.001Unsecured Credentials: Credentials In Files6Find and Access Github Credentialsda4f751a-020b-40d7-b9ff-d433b7799803bash
329credential-accessT1552.001Unsecured Credentials: Credentials In Files15Find Azure credentialsa8f6148d-478a-4f43-bc62-5efee9f931a4sh
330credential-accessT1552.001Unsecured Credentials: Credentials In Files16Find GCP credentialsaa12eb29-2dbb-414e-8b20-33d34af93543sh
331credential-accessT1552.001Unsecured Credentials: Credentials In Files17Find OCI credentials9d9c22c9-fa97-4008-a204-478cf68c40afsh
332credential-accessT1110.004Brute Force: Credential Stuffing1SSH Credential Stuffing From Linux4f08197a-2a8a-472d-9589-cd2895ef22adbash
333credential-accessT1110.004Brute Force: Credential Stuffing3SSH Credential Stuffing From FreeBSDa790d50e-7ebf-48de-8daa-d9367e0911d4sh
334credential-accessT1003.008OS Credential Dumping: /etc/passwd, /etc/master.passwd and /etc/shadow1Access /etc/shadow (Local)3723ab77-c546-403c-8fb4-bb577033b235bash
335credential-accessT1003.008OS Credential Dumping: /etc/passwd, /etc/master.passwd and /etc/shadow2Access /etc/master.passwd (Local)5076874f-a8e6-4077-8ace-9e5ab54114a5sh
336credential-accessT1003.008OS Credential Dumping: /etc/passwd, /etc/master.passwd and /etc/shadow3Access /etc/passwd (Local)60e860b6-8ae6-49db-ad07-5e73edd88f5dsh
337credential-accessT1003.008OS Credential Dumping: /etc/passwd, /etc/master.passwd and /etc/shadow4Access /etc/{shadow,passwd,master.passwd} with a standard bin that's not catdf1a55ae-019d-4120-bc35-94f4bc5c4b0ash
338credential-accessT1003.008OS Credential Dumping: /etc/passwd, /etc/master.passwd and /etc/shadow5Access /etc/{shadow,passwd,master.passwd} with shell builtinsf5aa6543-6cb2-4fae-b9c2-b96e14721713sh
339discoveryT1033System Owner/User Discovery2System Owner/User Discovery2a9b677d-a230-44f4-ad86-782df1ef108csh
340discoveryT1016.001System Network Configuration Discovery: Internet Connection Discovery2Check internet connection using ping freebsd, linux or macosbe8f4019-d8b6-434c-a814-53123cdcc11ebash
341discoveryT1652Device Driver Discovery2Device Driver Discovery (Linux)d57dfc9e-ed9a-418e-88f8-b59c85f8cfd1bash
342discoveryT1652Device Driver Discovery3Enumerate Kernel Driver Files (Linux)13c0fef5-9be9-4d7f-9c6b-901624e53770bash
343discoveryT1087.002Account Discovery: Domain Account23Active Directory Domain Search096b6d2a-b63f-4100-8fa0-525da4cd25cash
344discoveryT1087.002Account Discovery: Domain Account24Account Enumeration with LDAPDomainDumpa54d497e-8dbe-4558-9895-44944baa395fsh
345discoveryT1087.001Account Discovery: Local Account1Enumerate all accounts (Local)f8aab3dd-5990-4bf8-b8ab-2226c951696fsh
346discoveryT1087.001Account Discovery: Local Account2View sudoers accessfed9be70-0186-4bde-9f8a-20945f9370c2sh
347discoveryT1087.001Account Discovery: Local Account3View accounts with UID 0c955a599-3653-4fe5-b631-f11c00eb0397sh
348discoveryT1087.001Account Discovery: Local Account4List opened files by user7e46c7a5-0142-45be-a858-1a3ecb4fd3cbsh
349discoveryT1087.001Account Discovery: Local Account5Show if a user account has ever logged in remotely0f0b6a29-08c3-44ad-a30b-47fd996b2110sh
350discoveryT1087.001Account Discovery: Local Account6Enumerate users and groupse6f36545-dc1e-47f0-9f48-7f730f54a02esh
351discoveryT1497.001Virtualization/Sandbox Evasion: System Checks1Detect Virtualization Environment (Linux)dfbd1a21-540d-4574-9731-e852bd6fe840sh
352discoveryT1497.001Virtualization/Sandbox Evasion: System Checks2Detect Virtualization Environment (FreeBSD)e129d73b-3e03-4ae9-bf1e-67fc8921e0fdsh
353discoveryT1069.002Permission Groups Discovery: Domain Groups15Active Directory Domain Search Using LDAP - Linux (Ubuntu)/macOSd58d749c-4450-4975-a9e9-8b1d562755c2sh
354discoveryT1007System Service Discovery3System Service Discovery - systemctl/servicef4b26bce-4c2c-46c0-bcc5-fce062d38befbash
355discoveryT1007System Service Discovery8System Service Discovery - Linux init scripts8f2a5d2b-4018-46d4-8f3f-0fea53754690sh
356discoveryT1040Network Sniffing1Packet Capture Linux using tshark or tcpdump7fe741f7-b265-4951-a7c7-320889083b3ebash
357discoveryT1040Network Sniffing2Packet Capture FreeBSD using tshark or tcpdumpc93f2492-9ebe-44b5-8b45-36574cccfe67sh
358discoveryT1040Network Sniffing10Packet Capture FreeBSD using /dev/bpfN with sudoe2028771-1bfb-48f5-b5e6-e50ee0942a14sh
359discoveryT1040Network Sniffing11Filtered Packet Capture FreeBSD using /dev/bpfN with sudoa3a0d4c9-c068-4563-a08d-583bd05b884csh
360discoveryT1040Network Sniffing12Packet Capture Linux socket AF_PACKET,SOCK_RAW with sudo10c710c9-9104-4d5f-8829-5b65391e2a29bash
361discoveryT1040Network Sniffing13Packet Capture Linux socket AF_INET,SOCK_RAW,TCP with sudo7a0895f0-84c1-4adf-8491-a21510b1d4c1bash
362discoveryT1040Network Sniffing14Packet Capture Linux socket AF_INET,SOCK_PACKET,UDP with sudo515575ab-d213-42b1-aa64-ef6a2dd4641bbash
363discoveryT1040Network Sniffing15Packet Capture Linux socket AF_PACKET,SOCK_RAW with BPF filter for UDP with sudob1cbdf8b-6078-48f5-a890-11ea19d7f8e9bash
364discoveryT1135Network Share Discovery2Network Share Discovery - linux875805bc-9e86-4e87-be86-3a5527315caebash
365discoveryT1135Network Share Discovery3Network Share Discovery - FreeBSD77e468a6-3e5c-45a1-9948-c4b5603747cbsh
366discoveryT1082System Information Discovery3List OS Informationcccb070c-df86-4216-a5bc-9fb60c74e27csh
367discoveryT1082System Information Discovery4Linux VM Check via Hardware31dad7ad-2286-4c02-ae92-274418c85fecbash
368discoveryT1082System Information Discovery5Linux VM Check via Kernel Modules8057d484-0fae-49a4-8302-4812c4f1e64ebash
369discoveryT1082System Information Discovery6FreeBSD VM Check via Kernel Moduleseefe6a49-d88b-41d8-8fc2-b46822da90d3sh
370discoveryT1082System Information Discovery8Hostname Discovery486e88ea-4f56-470f-9b57-3f4d73f39133sh
371discoveryT1082System Information Discovery12Environment variables discovery on freebsd, macos and linuxfcbdd43f-f4ad-42d5-98f3-0218097e2720sh
372discoveryT1082System Information Discovery25Linux List Kernel Modules034fe21c-3186-49dd-8d5d-128b35f181c7sh
373discoveryT1082System Information Discovery26FreeBSD List Kernel Modules4947897f-643a-4b75-b3f5-bed6885749f6sh
374discoveryT1497.003Time Based Evasion1Delay execution with ping8b87dd03-8204-478c-bac3-3959f6528de3sh
375discoveryT1217Browser Bookmark Discovery1List Mozilla Firefox Bookmark Database Files on FreeBSD/Linux3a41f169-a5ab-407f-9269-abafdb5da6c2sh
376discoveryT1217Browser Bookmark Discovery4List Google Chromium Bookmark JSON Files on FreeBSD88ca025b-3040-44eb-9168-bd8af22b82fash
377discoveryT1016System Network Configuration Discovery3System Network Configuration Discoveryc141bbdb-7fca-4254-9fd6-f47e79447e17sh
378discoveryT1083File and Directory Discovery3Nix File and Directory Discoveryffc8b249-372a-4b74-adcd-e4c0430842desh
379discoveryT1083File and Directory Discovery4Nix File and Directory Discovery 213c5e1ae-605b-46c4-a79f-db28c77ff24esh
380discoveryT1083File and Directory Discovery8Identifying Network Shares - Linux361fe49d-0c19-46ec-a483-ccb92d38e88esh
381discoveryT1049System Network Connections Discovery4System Network Connections Discovery via ss or lsof (Linux/MacOS)bcf05343-ef1d-4052-8a27-b00c9be42b9fbash
382discoveryT1049System Network Connections Discovery5System Network Connections Discovery FreeBSD, Linux & MacOS9ae28d3f-190f-4fa0-b023-c7bd3e0eabf2sh
383discoveryT1049System Network Connections Discovery6System Network Connections Discovery via sockstat (Linux, FreeBSD)997bb0a6-421e-40c7-b5d2-0f493904ef9bsh
384discoveryT1057Process Discovery1Process Discovery - ps4ff64f0b-aaf2-4866-b39d-38d9791407ccsh
385discoveryT1069.001Permission Groups Discovery: Local Groups1Permission Groups Discovery (Local)952931a4-af0b-4335-bbbe-73c8c5b327aesh
386discoveryT1201Password Policy Discovery1Examine password complexity policy - Ubuntu085fe567-ac84-47c7-ac4c-2688ce28265bbash
387discoveryT1201Password Policy Discovery2Examine password complexity policy - FreeBSDa7893624-a3d7-4aed-9676-80498f31820fsh
388discoveryT1201Password Policy Discovery3Examine password complexity policy - CentOS/RHEL 7.x78a12e65-efff-4617-bc01-88f17d71315dbash
389discoveryT1201Password Policy Discovery4Examine password complexity policy - CentOS/RHEL 6.x6ce12552-0adb-4f56-89ff-95ce268f6358bash
390discoveryT1201Password Policy Discovery5Examine password expiration policy - All Linux7c86c55c-70fa-4a05-83c9-3aa19b145d1abash
391discoveryT1614.001System Location Discovery: System Language Discovery3Discover System Language with locale837d609b-845e-4519-90ce-edc3b4b0e138sh
392discoveryT1614.001System Location Discovery: System Language Discovery4Discover System Language with localectl07ce871a-b3c3-44a3-97fa-a20118fdc7c9sh
393discoveryT1614.001System Location Discovery: System Language Discovery5Discover System Language by locale file5d7057c9-2c8a-4026-91dd-13b5584daa69sh
394discoveryT1614.001System Location Discovery: System Language Discovery6Discover System Language by Environment Variable Querycb8f7cdc-36c4-4ed0-befc-7ad7d24dfd7ash
395discoveryT1614System Location Discovery2Get geolocation info through IP-Lookup services using curl freebsd, linux or macos552b4db3-8850-412c-abce-ab5cc8a86604bash
396discoveryT1518.001Software Discovery: Security Software Discovery4Security Software Discovery - ps (Linux)23b91cd2-c99c-4002-9e41-317c63e024a2sh
397discoveryT1518.001Software Discovery: Security Software Discovery5Security Software Discovery - pgrep (FreeBSD)fa96c21c-5fd6-4428-aa28-51a2fbecdbdcsh
398discoveryT1018Remote System Discovery6Remote System Discovery - arp nixacb6b1ff-e2ad-4d64-806c-6c35fe73b951sh
399discoveryT1018Remote System Discovery7Remote System Discovery - sweep96db2632-8417-4dbb-b8bb-a8b92ba391desh
400discoveryT1018Remote System Discovery12Remote System Discovery - ip neighbour158bd4dd-6359-40ab-b13c-285b9ef6fa25sh
401discoveryT1018Remote System Discovery13Remote System Discovery - ip route1a4ebe70-31d0-417b-ade2-ef4cb3e7d0e1sh
402discoveryT1018Remote System Discovery14Remote System Discovery - netstatd2791d72-b67f-4615-814f-ec824a91f514sh
403discoveryT1018Remote System Discovery15Remote System Discovery - ip tcp_metrics6c2da894-0b57-43cb-87af-46ea3b501388sh
404discoveryT1046Network Service Discovery1Port Scan68e907da-2539-48f6-9fc9-257a78c05540bash
405discoveryT1046Network Service Discovery2Port Scan Nmap515942b0-a09f-4163-a7bb-22fefb6f185fsh
406discoveryT1046Network Service Discovery12Port Scan using nmap (Port range)0d5a2b03-3a26-45e4-96ae-89485b4d1f97sh
407discoveryT1124System Time Discovery3System Time Discovery in FreeBSD/macOSf449c933-0891-407f-821e-7916a21a1a6fsh
408executionT1053.003Scheduled Task/Job: Cron1Cron - Replace crontab with referenced file435057fb-74b1-410e-9403-d81baf194f75sh
409executionT1053.003Scheduled Task/Job: Cron2Cron - Add script to all cron subfoldersb7d42afa-9086-4c8a-b7b0-8ea3faa6ebb0bash
410executionT1053.003Scheduled Task/Job: Cron3Cron - Add script to /etc/cron.d folder078e69eb-d9fb-450e-b9d0-2e118217c846sh
411executionT1053.003Scheduled Task/Job: Cron4Cron - Add script to /var/spool/cron/crontabs/ folder2d943c18-e74a-44bf-936f-25ade6cccab4bash
412executionT1569.003System Services: Systemctl1Create and Enable a Malicious systemd Service Unite58c8723-5503-4533-b642-535cd20ec648sh
413executionT1569.003System Services: Systemctl2Create systemd Service Unit from /tmp (Unusual Location)a1fa406e-2354-4a24-b6d6-94157e7564d4sh
414executionT1569.003System Services: Systemctl3Create systemd Service Unit from /dev/shm (Unusual Location)dce49381-a26b-4d95-bdfa-c607ffe8bee5sh
415executionT1569.003System Services: Systemctl4Modify Existing systemd Service to Execute Malicious Command6123928f-6389-4914-8d25-a5d69bd657fash
416executionT1569.003System Services: Systemctl5Execute Command via Transient systemd Service (systemd-run)a73a886f-23c5-4e8f-b1ab-b1bbc1f5e236sh
417executionT1569.003System Services: Systemctl6Enumerate All systemd Services Using systemctl1e5be8d4-605a-4acb-8709-2f80b2d8ea95sh
418executionT1569.003System Services: Systemctl7Enable systemd Service for Persistence with Auto-Restart2fc6c0ab-4f88-4eb8-ab1b-f739fc22bba7sh
419executionT1569.003System Services: Systemctl8Masquerade Malicious Service as Legitimate System Service6fec8560-ff64-4bbf-bc79-734fea48f7cash
420executionT1053.006Scheduled Task/Job: Systemd Timers1Create Systemd Service and Timerf4983098-bb13-44fb-9b2c-46149961807bbash
421executionT1053.006Scheduled Task/Job: Systemd Timers2Create a user level transient systemd service and timer3de33f5b-62e5-4e63-a2a0-6fd8808c80ecsh
422executionT1053.006Scheduled Task/Job: Systemd Timers3Create a system level transient systemd service and timerd3eda496-1fc0-49e9-aff5-3bec5da9fa22sh
423executionT1059.004Command and Scripting Interpreter: Bash1Create and Execute Bash Shell Script7e7ac3ed-f795-4fa5-b711-09d6fbe9b873sh
424executionT1059.004Command and Scripting Interpreter: Bash2Command-Line Interfaced0c88567-803d-4dca-99b4-7ce65e7b257csh
425executionT1059.004Command and Scripting Interpreter: Bash3Harvest SUID executable files46274fc6-08a7-4956-861b-24cbbaa0503csh
426executionT1059.004Command and Scripting Interpreter: Bash4LinEnum tool executiona2b35a63-9df1-4806-9a4d-5fe0500845f2sh
427executionT1059.004Command and Scripting Interpreter: Bash5New script file in the tmp directory8cd1947b-4a54-41fb-b5ea-07d0ace04f81sh
428executionT1059.004Command and Scripting Interpreter: Bash6What shell is running7b38e5cc-47be-44f0-a425-390305c76c17sh
429executionT1059.004Command and Scripting Interpreter: Bash7What shells are availablebf23c7dc-1004-4949-8262-4c1d1ef87702sh
430executionT1059.004Command and Scripting Interpreter: Bash8Command line scriptsb04ed73c-7d43-4dc8-b563-a2fc595cba1ash
431executionT1059.004Command and Scripting Interpreter: Bash9Obfuscated command line scripts5bec4cc8-f41e-437b-b417-33ff60acf9afsh
432executionT1059.004Command and Scripting Interpreter: Bash10Change login shellc7ac59cb-13cc-4622-81dc-6d2fee9bfac7bash
433executionT1059.004Command and Scripting Interpreter: Bash11Environment variable scriptsbdaebd56-368b-4970-a523-f905ff4a8a51sh
434executionT1059.004Command and Scripting Interpreter: Bash12Detecting pipe-to-shellfca246a8-a585-4f28-a2df-6495973976a1sh
435executionT1059.004Command and Scripting Interpreter: Bash13Current kernel information enumeration3a53734a-9e26-4f4b-ad15-059e767f5f14sh
436executionT1059.004Command and Scripting Interpreter: Bash14Shell Creation using awk commandee72b37d-b8f5-46a5-a9e7-0ff50035ffd5sh
437executionT1059.004Command and Scripting Interpreter: Bash15Creating shell using cpan commandbcd4c2bc-490b-4f91-bd31-3709fe75bbdfsh
438executionT1059.004Command and Scripting Interpreter: Bash16Shell Creation using busybox commandab4d04af-68dc-4fee-9c16-6545265b3276sh
439executionT1059.004Command and Scripting Interpreter: Bash17emacs spawning an interactive system shelle0742e38-6efe-4dd4-ba5c-2078095b6156sh
440executionT1059.006Command and Scripting Interpreter: Python1Execute shell script via python's command mode arguement3a95cdb2-c6ea-4761-b24e-02b71889b8bbsh
441executionT1059.006Command and Scripting Interpreter: Python2Execute Python via scripts6c4d1dcb-33c7-4c36-a8df-c6cfd0408be8sh
442executionT1059.006Command and Scripting Interpreter: Python3Execute Python via Python executables0b44d79b-570a-4b27-a31f-3bf2156e5eaash
443executionT1059.006Command and Scripting Interpreter: Python4Python pty module and spawn function used to spawn sh or bash161d694c-b543-4434-85c3-c3a433e33792sh
444executionT1053.002Scheduled Task/Job: At2At - Schedule a job7266d898-ac82-4ec0-97c7-436075d0d08esh
445impactT1489Service Stop4Linux - Stop service using systemctl42e3a5bd-1e45-427f-aa08-2a65fa29a820sh
446impactT1489Service Stop5Linux - Stop service by killing process using killalle5d95be6-02ee-4ff1-aebe-cf86013b6189sh
447impactT1489Service Stop6Linux - Stop service by killing process using kill332f4c76-7e96-41a6-8cc2-7361c49db8besh
448impactT1489Service Stop7Linux - Stop service by killing process using pkill08b4718f-a8bf-4bb5-a552-294fc5178feash
449impactT1489Service Stop8Abuse of linux magic system request key for Send a SIGTERM to all processes6e76f56f-2373-4a6c-a63f-98b7b72761f1bash
450impactT1531Account Access Removal4Change User Password via passwd3c717bf3-2ecc-4d79-8ac8-0bfbf08fbce6sh
451impactT1486Data Encrypted for Impact1Encrypt files using gpg (FreeBSD/Linux)7b8ce084-3922-4618-8d22-95f996173765sh
452impactT1486Data Encrypted for Impact2Encrypt files using 7z (FreeBSD/Linux)53e6735a-4727-44cc-b35b-237682a151adsh
453impactT1486Data Encrypted for Impact3Encrypt files using ccrypt (FreeBSD/Linux)08cbf59f-85da-4369-a5f4-049cffd7709fsh
454impactT1486Data Encrypted for Impact4Encrypt files using openssl (FreeBSD/Linux)142752dc-ca71-443b-9359-cf6f497315f1sh
455impactT1496Resource Hijacking1FreeBSD/macOS/Linux - Simulate CPU Load with Yes904a5a0e-fb02-490d-9f8d-0e256eb37549sh
456impactT1485Data Destruction2FreeBSD/macOS/Linux - Overwrite file with DD38deee99-fd65-4031-bec8-bfa4f9f26146sh
457impactT1529System Shutdown/Reboot3Restart System via `shutdown` - FreeBSD/macOS/Linux6326dbc4-444b-4c04-88f4-27e94d0327cbsh
458impactT1529System Shutdown/Reboot4Shutdown System via `shutdown` - FreeBSD/macOS/Linux4963a81e-a3ad-4f02-adda-812343b351desh
459impactT1529System Shutdown/Reboot5Restart System via `reboot` - FreeBSD/macOS/Linux47d0b042-a918-40ab-8cf9-150ffe919027sh
460impactT1529System Shutdown/Reboot6Shutdown System via `halt` - FreeBSD/Linux918f70ab-e1ef-49ff-bc57-b27021df84ddsh
461impactT1529System Shutdown/Reboot7Reboot System via `halt` - FreeBSD7b1cee42-320f-4890-b056-d65c8b884ba5sh
462impactT1529System Shutdown/Reboot8Reboot System via `halt` - Linux78f92e14-f1e9-4446-b3e9-f1b921f2459ebash
463impactT1529System Shutdown/Reboot9Shutdown System via `poweroff` - FreeBSD/Linux73a90cd2-48a2-4ac5-8594-2af35fa909fash
464impactT1529System Shutdown/Reboot10Reboot System via `poweroff` - FreeBSD5a282e50-86ff-438d-8cef-8ae01c9e62e1sh
465impactT1529System Shutdown/Reboot11Reboot System via `poweroff` - Linux61303105-ff60-427b-999e-efb90b314e41bash
466impactT1529System Shutdown/Reboot16Abuse of Linux Magic System Request Key for Rebootd2a1f4bc-a064-4223-8281-a086dce5423cbash
467initial-accessT1659Content Injection1MITM Proxy Injection9b360eaf-c778-4f07-a6e7-895c4f01ac1cbash
468initial-accessT1195.002Compromise Software Supply Chain1Simulate npm package installation on a Linux systema9604672-cd46-493b-b58f-fd4124c22dd3bash
469initial-accessT1078.003Valid Accounts: Local Accounts8Create local account (Linux)02a91c34-8a5b-4bed-87af-501103eb5357bash
470initial-accessT1078.003Valid Accounts: Local Accounts9Reactivate a locked/expired account (Linux)d2b95631-62d7-45a3-aaef-0972cea97931bash
471initial-accessT1078.003Valid Accounts: Local Accounts10Reactivate a locked/expired account (FreeBSD)09e3380a-fae5-4255-8b19-9950be0252cfsh
472initial-accessT1078.003Valid Accounts: Local Accounts11Login as nobody (Linux)3d2cd093-ee05-41bd-a802-59ee5c301b85bash
473initial-accessT1078.003Valid Accounts: Local Accounts12Login as nobody (freebsd)16f6374f-7600-459a-9b16-6a88fd96d310sh
474exfiltrationT1048.002Exfiltration Over Alternative Protocol - Exfiltration Over Asymmetric Encrypted Non-C2 Protocol2Exfiltrate data HTTPS using curl freebsd,linux or macos4a4f31e2-46ea-4c26-ad89-f09ad1d5fe01bash
475exfiltrationT1048.002Exfiltration Over Alternative Protocol - Exfiltration Over Asymmetric Encrypted Non-C2 Protocol3Exfiltrate data in a file over HTTPS using wget7ccdfcfa-6707-46bc-b812-007ab6ff951csh
476exfiltrationT1048.002Exfiltration Over Alternative Protocol - Exfiltration Over Asymmetric Encrypted Non-C2 Protocol4Exfiltrate data as text over HTTPS using wget8bec51da-7a6d-4346-b941-51eca448c4b0sh
477exfiltrationT1048Exfiltration Over Alternative Protocol1Exfiltration Over Alternative Protocol - SSHf6786cc8-beda-4915-a4d6-ac2f193bb988sh
478exfiltrationT1048Exfiltration Over Alternative Protocol2Exfiltration Over Alternative Protocol - SSH7c3cb337-35ae-4d06-bf03-3032ed2ec268sh
479exfiltrationT1048Exfiltration Over Alternative Protocol4Exfiltrate Data using DNS Queries via diga27916da-05f2-4316-a3ee-feec67a437bebash
480exfiltrationT1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage2Exfiltrate data with rclone to cloud Storage - AWS S3a4b74723-5cee-4300-91c3-5e34166909b4powershell
481exfiltrationT1030Data Transfer Size Limits1Data Transfer Size Limitsab936c51-10f4-46ce-9144-e02137b2016ash
482exfiltrationT1048.003Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol1Exfiltration Over Alternative Protocol - HTTP1d1abbd6-a3d3-4b2e-bef5-c59293f46effmanual
483exfiltrationT1048.003Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol3Exfiltration Over Alternative Protocol - DNSc403b5a4-b5fc-49f2-b181-d1c80d27db45manual
484exfiltrationT1048.003Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol8Python3 http.server3ea1f938-f80a-4305-9aa8-431bc4867313sh