MITRE ATT&CK
Adversary tactics and techniques framework
691
Techniques
14
Tactics
0
Mitigations
4.362
Actor-Technique Links
MITRE ATT&CK 691
| ID | Techniques | Tactic | Platforms | Threat Actors | Actions |
|---|---|---|---|---|---|
| T1018 | Remote System Discovery | Discovery | ESXi, Linux, macOS... | 39 | |
| T1020 | Automated Exfiltration | Exfiltration | Linux, macOS, Networ... | 6 | |
| T1020.001 | Traffic Duplication Sub | Exfiltration | Network Devices, Iaa | 0 | |
| T1021 | Remote Services | Lateral Movement | Linux, macOS, Window... | 3 | |
| T1021.001 | Remote Desktop Protocol Sub | Lateral Movement | Windows | 35 | |
| T1021.002 | SMB/Windows Admin Shares Sub | Lateral Movement | Windows | 26 | |
| T1021.003 | Distributed Component Object Model Sub | Lateral Movement | Windows | 0 | |
| T1021.004 | SSH Sub | Lateral Movement | ESXi, Linux, macOS | 19 | |
| T1021.005 | VNC Sub | Lateral Movement | Linux, Windows, macO | 4 | |
| T1021.006 | Windows Remote Management Sub | Lateral Movement | Windows | 5 | |
| T1021.007 | Cloud Services Sub | Lateral Movement | IaaS, Identity Provi... | 3 | |
| T1021.008 | Direct Cloud VM Connections Sub | Lateral Movement | IaaS | 0 | |
| T1025 | Data from Removable Media | Collection | Linux, macOS, Window | 4 | |
| T1027 | Obfuscated Files or Information | Defense Evasion | ESXi, Linux, macOS... | 18 | |
| T1027.001 | Binary Padding Sub | Defense Evasion | Linux, Windows, macO | 8 | |
| T1027.002 | Software Packing Sub | Defense Evasion | Linux, macOS, Window | 23 | |
| T1027.003 | Steganography Sub | Defense Evasion | Linux, macOS, Window | 8 | |
| T1027.004 | Compile After Delivery Sub | Defense Evasion | Linux, macOS, Window | 4 | |
| T1027.005 | Indicator Removal from Tools Sub | Defense Evasion | Linux, macOS, Window | 7 | |
| T1027.006 | HTML Smuggling Sub | Defense Evasion | Windows, Linux, macO | 1 | |
| T1027.007 | Dynamic API Resolution Sub | Defense Evasion | Windows | 2 | |
| T1027.008 | Stripped Payloads Sub | Defense Evasion | macOS, Linux, Window... | 0 | |
| T1027.009 | Embedded Payloads Sub | Defense Evasion | Linux, macOS, Window | 3 | |
| T1027.010 | Command Obfuscation Sub | Defense Evasion | Linux, macOS, Window | 28 | |
| T1027.011 | Fileless Storage Sub | Defense Evasion | Windows, Linux | 2 |