Help Ukraine, click for information
mitre-attack-lookup

root@sovietghost:~/tools/mitre-lookup#

Search 56 curated MITRE ATT&CK techniques by ID, name, or keyword.

56 results

T1566Phishing
Initial Access

Adversaries send phishing messages to gain access to victim systems.

T1566.001Spearphishing Attachment
Initial Access

Malicious attachment delivered via targeted email.

T1566.002Spearphishing Link
Initial Access

Malicious URL delivered via targeted email.

T1190Exploit Public-Facing Application
Initial Access

Exploit a vulnerability in an internet-facing service.

T1078Valid Accounts
Initial Access

Use stolen or default credentials for access.

T1133External Remote Services
Initial Access

Abuse VPN, RDP, or other remote access to gain entry.

T1059Command and Scripting Interpreter
Execution

Execute malicious commands via interpreters.

T1059.001PowerShell
Execution

Abuse PowerShell to execute commands and scripts.

T1059.003Windows Command Shell
Execution

Use cmd.exe to execute commands.

T1059.006Python
Execution

Execute malicious Python scripts.

T1059.007JavaScript
Execution

Execute malicious JavaScript (WSH, Node, browser).

T1204User Execution
Execution

Trick user into running malicious code.

T1204.001Malicious Link
Execution

User clicks a link that triggers execution.

T1204.002Malicious File
Execution

User opens a malicious document or executable.

T1053.005Scheduled Task
Persistence

Create or modify a Windows scheduled task for persistence.

T1547.001Registry Run Keys
Persistence

Add keys to HKCU/HKLM Run to execute on logon.

T1543.003Windows Service
Persistence

Create or modify a Windows service.

T1574.002DLL Side-Loading
Persistence

Place a malicious DLL beside a legitimate executable.

T1548.002Bypass UAC
Privilege Escalation

Bypass User Account Control to elevate privileges.

T1055Process Injection
Privilege Escalation

Inject malicious code into another process.

T1134Access Token Manipulation
Privilege Escalation

Steal or forge access tokens to escalate.

T1027Obfuscated Files or Information
Defense Evasion

Encrypt, encode, or pack payloads to evade detection.

T1562.001Disable Security Tools
Defense Evasion

Disable AV, EDR, or other security software.

T1036Masquerading
Defense Evasion

Disguise malicious artifacts as legitimate ones.

T1140Deobfuscate/Decode Files
Defense Evasion

Decode encoded payloads at runtime.

T1218.011Rundll32
Defense Evasion

Use rundll32.exe to proxy execution of malicious DLLs.

T1218.010Regsvr32
Defense Evasion

Use regsvr32 to execute arbitrary DLLs.

T1070.004File Deletion
Defense Evasion

Delete artifacts after execution to remove evidence.

T1110Brute Force
Credential Access

Systematically guess credentials.

T1110.003Password Spraying
Credential Access

Try one password against many accounts.

T1003OS Credential Dumping
Credential Access

Dump credentials from the OS or applications.

T1003.001LSASS Memory
Credential Access

Dump LSASS process memory to get credentials.

T1555Credentials from Password Stores
Credential Access

Steal credentials from browsers, keychains, vaults.

T1082System Information Discovery
Discovery

Gather OS version, hostname, architecture info.

T1083File and Directory Discovery
Discovery

Enumerate files and directories.

T1016System Network Config Discovery
Discovery

Discover IP addresses, interfaces, routes.

T1057Process Discovery
Discovery

List running processes on the system.

T1046Network Service Discovery
Discovery

Scan for open ports and running services.

T1021.001Remote Desktop Protocol
Lateral Movement

Use RDP to move laterally to other hosts.

T1021.002SMB/Windows Admin Shares
Lateral Movement

Authenticate over SMB and access admin shares.

T1021.006Windows Remote Management
Lateral Movement

Use WinRM/WMI for remote command execution.

T1550.002Pass the Hash
Lateral Movement

Authenticate using an NTLM hash without the plaintext.

T1560Archive Collected Data
Collection

Compress or encrypt data before exfiltration.

T1005Data from Local System
Collection

Search and collect files from the local host.

T1071.001Web Protocols (C2)
C2

Use HTTP/S for command and control traffic.

T1071.004DNS (C2)
C2

Encode C2 traffic in DNS queries.

T1105Ingress Tool Transfer
C2

Transfer tools or payloads to compromised system.

T1573Encrypted Channel
C2

Encrypt C2 communications to evade inspection.

T1102Web Service (C2)
C2

Use legitimate web services (GitHub, Pastebin) for C2.

T1041Exfil Over C2 Channel
Exfiltration

Exfiltrate data through the existing C2 channel.

T1048Exfil Over Alternative Protocol
Exfiltration

Exfiltrate using DNS, ICMP, or other protocols.

T1486Data Encrypted for Impact
Impact

Encrypt victim data to demand ransom.

T1490Inhibit System Recovery
Impact

Delete shadow copies and backups.

T1489Service Stop
Impact

Stop or disable critical services.

T1595Active Scanning
Reconnaissance

Scan victim infrastructure prior to targeting.

T1592Gather Victim Host Information
Reconnaissance

Collect information about victim hosts.

> Thanks for visiting. Stay curious and stay secure. _