MITRE ATT&CK
Adversary tactics and techniques framework
691
Techniques
14
Tactics
0
Mitigations
4.362
Actor-Technique Links
MITRE ATT&CK 691
| ID | Techniques | Tactic | Platforms | Threat Actors | Actions |
|---|---|---|---|---|---|
| T1037.003 | Network Logon Script Sub | Persistence, Privilege Es... | Windows | 0 | |
| T1037.004 | RC Scripts Sub | Persistence, Privilege Es... | macOS, Linux, Networ... | 3 | |
| T1037.005 | Startup Items Sub | Persistence, Privilege Es... | macOS | 0 | |
| T1039 | Data from Network Shared Drive | Collection | Linux, macOS, Window | 8 | |
| T1040 | Network Sniffing | Credential Access, Discov... | Linux, macOS, Window... | 8 | |
| T1041 | Exfiltration Over C2 Channel | Exfiltration | ESXi, Linux, macOS... | 25 | |
| T1046 | Network Service Discovery | Discovery | Containers, IaaS, Li... | 31 | |
| T1047 | Windows Management Instrumentation | Execution | Windows | 39 | |
| T1048 | Exfiltration Over Alternative Protocol | Exfiltration | ESXi, IaaS, Linux... | 2 | |
| T1048.001 | Exfiltration Over Symmetric Encrypted Non-C2 Protocol Sub | Exfiltration | Linux, macOS, Window... | 0 | |
| T1048.002 | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol Sub | Exfiltration | Linux, macOS, Window... | 3 | |
| T1048.003 | Exfiltration Over Unencrypted Non-C2 Protocol Sub | Exfiltration | ESXi, Linux, macOS... | 11 | |
| T1049 | System Network Connections Discovery | Discovery | Windows, IaaS, Linux... | 32 | |
| T1052 | Exfiltration Over Physical Medium | Exfiltration | Linux, macOS, Window | 0 | |
| T1052.001 | Exfiltration over USB Sub | Exfiltration | Linux, Windows, macO | 2 | |
| T1053 | Scheduled Task/Job | Execution, Persistence, P... | Windows, Linux, macO... | 0 | |
| T1053.002 | At Sub | Execution, Persistence, P... | Windows, Linux, macO | 3 | |
| T1053.003 | Cron Sub | Execution, Persistence, P... | Linux, macOS, ESXi | 3 | |
| T1053.005 | Scheduled Task Sub | Execution, Persistence, P... | Windows | 54 | |
| T1053.006 | Systemd Timers Sub | Execution, Persistence, P... | Linux | 0 | |
| T1053.007 | Container Orchestration Job Sub | Execution, Persistence, P... | Containers | 0 | |
| T1055 | Process Injection | Privilege Escalation, Def... | Linux, macOS, Window | 15 | |
| T1055.001 | Dynamic-link Library Injection Sub | Privilege Escalation, Def... | Windows | 9 | |
| T1055.002 | Portable Executable Injection Sub | Privilege Escalation, Def... | Windows | 2 | |
| T1055.003 | Thread Execution Hijacking Sub | Privilege Escalation, Def... | Windows | 0 |