MITRE ATT&CK

Adversary tactics and techniques framework

691
Techniques
14
Tactics
0
Mitigations
4.362
Actor-Technique Links
MITRE ATT&CK 691
ID Techniques Tactic Platforms Threat Actors Actions
T1018 Remote System Discovery Discovery ESXi, Linux, macOS... 39
T1020 Automated Exfiltration Exfiltration Linux, macOS, Networ... 6
T1020.001 Traffic Duplication Sub Exfiltration Network Devices, Iaa 0
T1021 Remote Services Lateral Movement Linux, macOS, Window... 3
T1021.001 Remote Desktop Protocol Sub Lateral Movement Windows 35
T1021.002 SMB/Windows Admin Shares Sub Lateral Movement Windows 26
T1021.003 Distributed Component Object Model Sub Lateral Movement Windows 0
T1021.004 SSH Sub Lateral Movement ESXi, Linux, macOS 19
T1021.005 VNC Sub Lateral Movement Linux, Windows, macO 4
T1021.006 Windows Remote Management Sub Lateral Movement Windows 5
T1021.007 Cloud Services Sub Lateral Movement IaaS, Identity Provi... 3
T1021.008 Direct Cloud VM Connections Sub Lateral Movement IaaS 0
T1025 Data from Removable Media Collection Linux, macOS, Window 4
T1027 Obfuscated Files or Information Defense Evasion ESXi, Linux, macOS... 18
T1027.001 Binary Padding Sub Defense Evasion Linux, Windows, macO 8
T1027.002 Software Packing Sub Defense Evasion Linux, macOS, Window 23
T1027.003 Steganography Sub Defense Evasion Linux, macOS, Window 8
T1027.004 Compile After Delivery Sub Defense Evasion Linux, macOS, Window 4
T1027.005 Indicator Removal from Tools Sub Defense Evasion Linux, macOS, Window 7
T1027.006 HTML Smuggling Sub Defense Evasion Windows, Linux, macO 1
T1027.007 Dynamic API Resolution Sub Defense Evasion Windows 2
T1027.008 Stripped Payloads Sub Defense Evasion macOS, Linux, Window... 0
T1027.009 Embedded Payloads Sub Defense Evasion Linux, macOS, Window 3
T1027.010 Command Obfuscation Sub Defense Evasion Linux, macOS, Window 28
T1027.011 Fileless Storage Sub Defense Evasion Windows, Linux 2