T1001Data Obfuscation (T1001) is an Enterprise ATT&CK technique associated with Command and Control. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1001.001Junk Data (T1001.001) is an Enterprise ATT&CK sub-technique under Data Obfuscation. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.
Open profile →T1001.002Steganography (T1001.002) is an Enterprise ATT&CK sub-technique under Data Obfuscation. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.
Open profile →T1001.003Protocol or Service Impersonation (T1001.003) is an Enterprise ATT&CK sub-technique under Data Obfuscation. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.
Open profile →T1003An adversary reads operating-system memory, databases, caches, registry material, or directory replication data to obtain credential artifacts.
Open profile →T1003Windows Credential Guard uses virtualization-based security to isolate selected domain credentials from the normal operating system so that compromise of the host is less likely to expose reusable NTLM hashes and Kerberos ticket-granting tickets.
Open profile →T1003.001The Local Security Authority Subsystem Service enforces local security policy, validates certain logons, creates access tokens, and handles credential material; protecting LSASS is central to limiting credential theft from Windows endpoints.
Open profile →T1003.001LSASS Memory (T1003.001) is an Enterprise ATT&CK sub-technique under OS Credential Dumping. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1003.002Security Account Manager (T1003.002) is an Enterprise ATT&CK sub-technique under OS Credential Dumping. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1003.003NTDS (T1003.003) is an Enterprise ATT&CK sub-technique under OS Credential Dumping. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1003.004LSA Secrets (T1003.004) is an Enterprise ATT&CK sub-technique under OS Credential Dumping. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1003.005Cached Domain Credentials (T1003.005) is an Enterprise ATT&CK sub-technique under OS Credential Dumping. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1003.006DCSync is an abuse of Active Directory replication rights in which an attacker makes a system act like a domain controller and requests password-derived credential data through normal directory replication protocols.
Open profile →T1003.006DCSync (T1003.006) is an Enterprise ATT&CK sub-technique under OS Credential Dumping. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1003.007Proc Filesystem (T1003.007) is an Enterprise ATT&CK sub-technique under OS Credential Dumping. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1003.008/etc/passwd and /etc/shadow (T1003.008) is an Enterprise ATT&CK sub-technique under OS Credential Dumping. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1005An adversary searches for and reads files, databases, application data, or other information stored on a compromised local system.
Open profile →T1006Direct Volume Access (T1006) is an Enterprise ATT&CK technique associated with Stealth. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1007System Service Discovery (T1007) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1008Fallback Channels (T1008) is an Enterprise ATT&CK technique associated with Command and Control. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1010Application Window Discovery (T1010) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1011Exfiltration Over Other Network Medium (T1011) is an Enterprise ATT&CK technique associated with Exfiltration. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1011.001Exfiltration Over Bluetooth (T1011.001) is an Enterprise ATT&CK sub-technique under Exfiltration Over Other Network Medium. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Exfiltration context.
Open profile →T1012Query Registry (T1012) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1014Rootkit (T1014) is an Enterprise ATT&CK technique associated with Stealth. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1016An adversary queries addresses, interfaces, routes, DNS settings, proxies, adapters, and other network configuration to understand connectivity.
Open profile →T1016.001Internet Connection Discovery (T1016.001) is an Enterprise ATT&CK sub-technique under System Network Configuration Discovery. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Discovery context.
Open profile →T1016.002Wi-Fi Discovery (T1016.002) is an Enterprise ATT&CK sub-technique under System Network Configuration Discovery. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Discovery context.
Open profile →T1018Remote System Discovery (T1018) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1020Automated Exfiltration (T1020) is an Enterprise ATT&CK technique associated with Exfiltration. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1020.001Traffic Duplication (T1020.001) is an Enterprise ATT&CK sub-technique under Automated Exfiltration. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Exfiltration context.
Open profile →T1021Lateral movement is the use of credentials, remote services, trust relationships, and administrative tools to move from one system or account to another.
Open profile →T1021An adversary uses authenticated remote services such as RDP, SMB, WinRM, SSH, VNC, or management protocols to access another system.
Open profile →T1021.001Remote Desktop Protocol (T1021.001) is an Enterprise ATT&CK sub-technique under Remote Services. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Lateral Movement context.
Open profile →T1021.001Remote Desktop security protects Windows interactive administrative sessions by controlling who can connect, how endpoints authenticate, where credentials are exposed, which channels are redirected, and how activity is monitored and contained.
Open profile →T1021.002SMB/Windows Admin Shares (T1021.002) is an Enterprise ATT&CK sub-technique under Remote Services. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Lateral Movement context.
Open profile →T1021.003Distributed Component Object Model (T1021.003) is an Enterprise ATT&CK sub-technique under Remote Services. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Lateral Movement context.
Open profile →T1021.004SSH (T1021.004) is an Enterprise ATT&CK sub-technique under Remote Services. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Lateral Movement context.
Open profile →T1021.005VNC (T1021.005) is an Enterprise ATT&CK sub-technique under Remote Services. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Lateral Movement context.
Open profile →T1021.006Windows Remote Management (T1021.006) is an Enterprise ATT&CK sub-technique under Remote Services. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Lateral Movement context.
Open profile →T1021.007Cloud Services (T1021.007) is an Enterprise ATT&CK sub-technique under Remote Services. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Lateral Movement context.
Open profile →T1021.008Direct Cloud VM Connections (T1021.008) is an Enterprise ATT&CK sub-technique under Remote Services. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Lateral Movement context.
Open profile →T1025Data from Removable Media (T1025) is an Enterprise ATT&CK technique associated with Collection. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1027An adversary encodes, encrypts, packs, fragments, or otherwise transforms files and information to make discovery or analysis more difficult.
Open profile →T1027YARA is a pattern-matching language used to classify files, memory, and other byte or text content by combining strings, metadata, modules, and Boolean conditions into reusable detection rules.
Open profile →T1027.001Binary Padding (T1027.001) is an Enterprise ATT&CK sub-technique under Obfuscated Files or Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1027.002Software Packing (T1027.002) is an Enterprise ATT&CK sub-technique under Obfuscated Files or Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1027.003Steganography (T1027.003) is an Enterprise ATT&CK sub-technique under Obfuscated Files or Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1027.004Compile After Delivery (T1027.004) is an Enterprise ATT&CK sub-technique under Obfuscated Files or Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1027.005Indicator Removal from Tools (T1027.005) is an Enterprise ATT&CK sub-technique under Obfuscated Files or Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1027.006HTML Smuggling (T1027.006) is an Enterprise ATT&CK sub-technique under Obfuscated Files or Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1027.007Dynamic API Resolution (T1027.007) is an Enterprise ATT&CK sub-technique under Obfuscated Files or Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1027.008Stripped Payloads (T1027.008) is an Enterprise ATT&CK sub-technique under Obfuscated Files or Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1027.009Embedded Payloads (T1027.009) is an Enterprise ATT&CK sub-technique under Obfuscated Files or Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1027.010Command Obfuscation (T1027.010) is an Enterprise ATT&CK sub-technique under Obfuscated Files or Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1027.011Fileless Storage (T1027.011) is an Enterprise ATT&CK sub-technique under Obfuscated Files or Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1027.012LNK Icon Smuggling (T1027.012) is an Enterprise ATT&CK sub-technique under Obfuscated Files or Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1027.013Encrypted/Encoded File (T1027.013) is an Enterprise ATT&CK sub-technique under Obfuscated Files or Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1027.014Polymorphic Code (T1027.014) is an Enterprise ATT&CK sub-technique under Obfuscated Files or Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1027.015Compression (T1027.015) is an Enterprise ATT&CK sub-technique under Obfuscated Files or Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1027.016Junk Code Insertion (T1027.016) is an Enterprise ATT&CK sub-technique under Obfuscated Files or Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1027.017SVG Smuggling (T1027.017) is an Enterprise ATT&CK sub-technique under Obfuscated Files or Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1027.018Invisible Unicode (T1027.018) is an Enterprise ATT&CK sub-technique under Obfuscated Files or Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1029Scheduled Transfer (T1029) is an Enterprise ATT&CK technique associated with Exfiltration. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1030Data Transfer Size Limits (T1030) is an Enterprise ATT&CK technique associated with Exfiltration. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1033System Owner/User Discovery (T1033) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1036An adversary makes an artifact, process, account, service, or task appear legitimate by using misleading names, locations, metadata, or presentation.
Open profile →T1036.001Invalid Code Signature (T1036.001) is an Enterprise ATT&CK sub-technique under Masquerading. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1036.002Right-to-Left Override (T1036.002) is an Enterprise ATT&CK sub-technique under Masquerading. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1036.003Rename Legitimate Utilities (T1036.003) is an Enterprise ATT&CK sub-technique under Masquerading. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1036.004Masquerade Task or Service (T1036.004) is an Enterprise ATT&CK sub-technique under Masquerading. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1036.005Match Legitimate Resource Name or Location (T1036.005) is an Enterprise ATT&CK sub-technique under Masquerading. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1036.006Space after Filename (T1036.006) is an Enterprise ATT&CK sub-technique under Masquerading. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1036.007Double File Extension (T1036.007) is an Enterprise ATT&CK sub-technique under Masquerading. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1036.008Masquerade File Type (T1036.008) is an Enterprise ATT&CK sub-technique under Masquerading. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1036.009Break Process Trees (T1036.009) is an Enterprise ATT&CK sub-technique under Masquerading. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1036.010Masquerade Account Name (T1036.010) is an Enterprise ATT&CK sub-technique under Masquerading. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1036.011Overwrite Process Arguments (T1036.011) is an Enterprise ATT&CK sub-technique under Masquerading. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1036.012Browser Fingerprint (T1036.012) is an Enterprise ATT&CK sub-technique under Masquerading. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1037Boot or Logon Initialization Scripts (T1037) is an Enterprise ATT&CK technique associated with Persistence, Privilege Escalation. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1037.001Logon Script (Windows) (T1037.001) is an Enterprise ATT&CK sub-technique under Boot or Logon Initialization Scripts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1037.002Login Hook (T1037.002) is an Enterprise ATT&CK sub-technique under Boot or Logon Initialization Scripts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1037.003Network Logon Script (T1037.003) is an Enterprise ATT&CK sub-technique under Boot or Logon Initialization Scripts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1037.004RC Scripts (T1037.004) is an Enterprise ATT&CK sub-technique under Boot or Logon Initialization Scripts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1037.005Startup Items (T1037.005) is an Enterprise ATT&CK sub-technique under Boot or Logon Initialization Scripts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1039Data from Network Shared Drive (T1039) is an Enterprise ATT&CK technique associated with Collection. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1040Network Sniffing (T1040) is an Enterprise ATT&CK technique associated with Credential Access, Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1041Data exfiltration detection looks for unauthorized movement of information through network, cloud, endpoint, application, and removable-media paths.
Open profile →T1041An adversary sends collected data through the same command-and-control channel used to manage compromised systems.
Open profile →T1046Network Service Discovery (T1046) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1047An adversary uses Windows Management Instrumentation to query, execute, configure, or remotely manage Windows systems.
Open profile →T1048Exfiltration Over Alternative Protocol (T1048) is an Enterprise ATT&CK technique associated with Exfiltration. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1048.001Exfiltration Over Symmetric Encrypted Non-C2 Protocol (T1048.001) is an Enterprise ATT&CK sub-technique under Exfiltration Over Alternative Protocol. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Exfiltration context.
Open profile →T1048.002Exfiltration Over Asymmetric Encrypted Non-C2 Protocol (T1048.002) is an Enterprise ATT&CK sub-technique under Exfiltration Over Alternative Protocol. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Exfiltration context.
Open profile →T1048.003Exfiltration Over Unencrypted Non-C2 Protocol (T1048.003) is an Enterprise ATT&CK sub-technique under Exfiltration Over Alternative Protocol. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Exfiltration context.
Open profile →T1049System Network Connections Discovery (T1049) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1052Exfiltration Over Physical Medium (T1052) is an Enterprise ATT&CK technique associated with Exfiltration. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1052.001Exfiltration over USB (T1052.001) is an Enterprise ATT&CK sub-technique under Exfiltration Over Physical Medium. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Exfiltration context.
Open profile →T1053An adversary creates or modifies a scheduled task, cron job, cloud schedule, or similar mechanism to run code at a chosen time or event.
Open profile →T1053.002At (T1053.002) is an Enterprise ATT&CK sub-technique under Scheduled Task/Job. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution, Persistence, Privilege Escalation context.
Open profile →T1053.003Cron (T1053.003) is an Enterprise ATT&CK sub-technique under Scheduled Task/Job. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution, Persistence, Privilege Escalation context.
Open profile →T1053.005Scheduled Task (T1053.005) is an Enterprise ATT&CK sub-technique under Scheduled Task/Job. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution, Persistence, Privilege Escalation context.
Open profile →T1053.006Systemd Timers (T1053.006) is an Enterprise ATT&CK sub-technique under Scheduled Task/Job. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution, Persistence, Privilege Escalation context.
Open profile →T1053.007Container Orchestration Job (T1053.007) is an Enterprise ATT&CK sub-technique under Scheduled Task/Job. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution, Persistence, Privilege Escalation context.
Open profile →T1055Process Injection (T1055) is an Enterprise ATT&CK technique associated with Stealth, Privilege Escalation. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1055.001Dynamic-link Library Injection (T1055.001) is an Enterprise ATT&CK sub-technique under Process Injection. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Privilege Escalation context.
Open profile →T1055.002Portable Executable Injection (T1055.002) is an Enterprise ATT&CK sub-technique under Process Injection. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Privilege Escalation context.
Open profile →T1055.003Thread Execution Hijacking (T1055.003) is an Enterprise ATT&CK sub-technique under Process Injection. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Privilege Escalation context.
Open profile →T1055.004Asynchronous Procedure Call (T1055.004) is an Enterprise ATT&CK sub-technique under Process Injection. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Privilege Escalation context.
Open profile →T1055.005Thread Local Storage (T1055.005) is an Enterprise ATT&CK sub-technique under Process Injection. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Privilege Escalation context.
Open profile →T1055.008Ptrace System Calls (T1055.008) is an Enterprise ATT&CK sub-technique under Process Injection. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Privilege Escalation context.
Open profile →T1055.009Proc Memory (T1055.009) is an Enterprise ATT&CK sub-technique under Process Injection. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Privilege Escalation context.
Open profile →T1055.011Extra Window Memory Injection (T1055.011) is an Enterprise ATT&CK sub-technique under Process Injection. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Privilege Escalation context.
Open profile →T1055.012Process Hollowing (T1055.012) is an Enterprise ATT&CK sub-technique under Process Injection. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Privilege Escalation context.
Open profile →T1055.013Process Doppelgänging (T1055.013) is an Enterprise ATT&CK sub-technique under Process Injection. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Privilege Escalation context.
Open profile →T1055.014VDSO Hijacking (T1055.014) is an Enterprise ATT&CK sub-technique under Process Injection. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Privilege Escalation context.
Open profile →T1055.015ListPlanting (T1055.015) is an Enterprise ATT&CK sub-technique under Process Injection. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Privilege Escalation context.
Open profile →T1056Input Capture (T1056) is an Enterprise ATT&CK technique associated with Collection, Credential Access. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1056.001Keylogging (T1056.001) is an Enterprise ATT&CK sub-technique under Input Capture. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Collection, Credential Access context.
Open profile →T1056.002GUI Input Capture (T1056.002) is an Enterprise ATT&CK sub-technique under Input Capture. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Collection, Credential Access context.
Open profile →T1056.003Web Portal Capture (T1056.003) is an Enterprise ATT&CK sub-technique under Input Capture. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Collection, Credential Access context.
Open profile →T1056.004Credential API Hooking (T1056.004) is an Enterprise ATT&CK sub-technique under Input Capture. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Collection, Credential Access context.
Open profile →T1057An adversary lists running processes, services, containers, or workloads to identify security tools, applications, users, and possible targets.
Open profile →T1059Application allowlisting permits only approved executables, scripts, libraries, installers, or other code to run under defined rules.
Open profile →T1059Detection as code manages analytic rules, queries, parsers, tests, documentation, and deployment through version-controlled engineering practices so detection changes are reviewable, reproducible, testable, and safely promoted.
Open profile →T1059An adversary uses a shell, command interpreter, scripting language, or administrative console to execute instructions and automate activity.
Open profile →T1059Sigma Rules is an operational security practice used to collect evidence, detect suspicious behavior, investigate events, or guide incident decisions.
Open profile →T1059Sysmon is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Open profile →T1059Threat hunting is a structured search for adversary behavior or hidden compromise that has not been fully identified by existing alerts.
Open profile →T1059.001PowerShell (T1059.001) is an Enterprise ATT&CK sub-technique under Command and Scripting Interpreter. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution context.
Open profile →T1059.001PowerShell Security and Logging is an operational security practice used to collect evidence, detect suspicious behavior, investigate events, or guide incident decisions.
Open profile →T1059.002AppleScript (T1059.002) is an Enterprise ATT&CK sub-technique under Command and Scripting Interpreter. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution context.
Open profile →T1059.003Windows Command Shell (T1059.003) is an Enterprise ATT&CK sub-technique under Command and Scripting Interpreter. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution context.
Open profile →T1059.004Unix Shell (T1059.004) is an Enterprise ATT&CK sub-technique under Command and Scripting Interpreter. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution context.
Open profile →T1059.005Visual Basic (T1059.005) is an Enterprise ATT&CK sub-technique under Command and Scripting Interpreter. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution context.
Open profile →T1059.006Python (T1059.006) is an Enterprise ATT&CK sub-technique under Command and Scripting Interpreter. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution context.
Open profile →T1059.007JavaScript (T1059.007) is an Enterprise ATT&CK sub-technique under Command and Scripting Interpreter. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution context.
Open profile →T1059.008Network Device CLI (T1059.008) is an Enterprise ATT&CK sub-technique under Command and Scripting Interpreter. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution context.
Open profile →T1059.009Cloud API (T1059.009) is an Enterprise ATT&CK sub-technique under Command and Scripting Interpreter. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution context.
Open profile →T1059.010AutoHotKey & AutoIT (T1059.010) is an Enterprise ATT&CK sub-technique under Command and Scripting Interpreter. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution context.
Open profile →T1059.011Lua (T1059.011) is an Enterprise ATT&CK sub-technique under Command and Scripting Interpreter. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution context.
Open profile →T1059.012Hypervisor CLI (T1059.012) is an Enterprise ATT&CK sub-technique under Command and Scripting Interpreter. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution context.
Open profile →T1059.013Container CLI/API (T1059.013) is an Enterprise ATT&CK sub-technique under Command and Scripting Interpreter. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution context.
Open profile →T1068An adversary exploits a software or configuration weakness to cross a local or workload privilege boundary.
Open profile →T1069Permission Groups Discovery (T1069) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1069.001Local Groups (T1069.001) is an Enterprise ATT&CK sub-technique under Permission Groups Discovery. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Discovery context.
Open profile →T1069.002Domain Groups (T1069.002) is an Enterprise ATT&CK sub-technique under Permission Groups Discovery. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Discovery context.
Open profile →T1069.003Cloud Groups (T1069.003) is an Enterprise ATT&CK sub-technique under Permission Groups Discovery. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Discovery context.
Open profile →T1070Log source onboarding is the controlled process of bringing a new event source into security monitoring with validated collection, parsing, timestamps, identifiers, access controls, retention, health checks, and documented analytic value.
Open profile →T1070An adversary deletes or alters logs, files, timestamps, command history, accounts, or other evidence to reduce the visible record of activity.
Open profile →T1070.001Windows Event Logs is an operational security practice used to collect evidence, detect suspicious behavior, investigate events, or guide incident decisions.
Open profile →T1070.003Clear Command History (T1070.003) is an Enterprise ATT&CK sub-technique under Indicator Removal. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1070.004File Deletion (T1070.004) is an Enterprise ATT&CK sub-technique under Indicator Removal. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1070.005Network Share Connection Removal (T1070.005) is an Enterprise ATT&CK sub-technique under Indicator Removal. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1070.006Timestomp (T1070.006) is an Enterprise ATT&CK sub-technique under Indicator Removal. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1070.007Clear Network Connection History and Configurations (T1070.007) is an Enterprise ATT&CK sub-technique under Indicator Removal. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1070.008Clear Mailbox Data (T1070.008) is an Enterprise ATT&CK sub-technique under Indicator Removal. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1070.009Clear Persistence (T1070.009) is an Enterprise ATT&CK sub-technique under Indicator Removal. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1070.010Relocate Malware (T1070.010) is an Enterprise ATT&CK sub-technique under Indicator Removal. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1071Command and Control Channels is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Open profile →T1071Command and control detection identifies the channels, timing patterns, protocol misuse, infrastructure, and host behavior used to direct compromised systems.
Open profile →T1071An adversary uses common application protocols such as web, DNS, mail, or file transfer to carry command-and-control traffic.
Open profile →T1071Network traffic analysis examines packet, flow, DNS, proxy, TLS, routing, and session metadata to understand communication patterns, identify suspicious behavior, and reconstruct activity across network trust boundaries.
Open profile →T1071Packet Capture and PCAP Analysis is an operational security practice used to collect evidence, detect suspicious behavior, investigate events, or guide incident decisions.
Open profile →T1071.001Web Protocols (T1071.001) is an Enterprise ATT&CK sub-technique under Application Layer Protocol. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.
Open profile →T1071.002File Transfer Protocols (T1071.002) is an Enterprise ATT&CK sub-technique under Application Layer Protocol. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.
Open profile →T1071.003Mail Protocols (T1071.003) is an Enterprise ATT&CK sub-technique under Application Layer Protocol. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.
Open profile →T1071.004DNS (T1071.004) is an Enterprise ATT&CK sub-technique under Application Layer Protocol. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.
Open profile →T1071.005Publish/Subscribe Protocols (T1071.005) is an Enterprise ATT&CK sub-technique under Application Layer Protocol. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.
Open profile →T1072Software Deployment Tools (T1072) is an Enterprise ATT&CK technique associated with Execution, Lateral Movement. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1074Data Staging and Exfiltration describes an adversary technique, campaign pattern, or malicious capability. Defenders study the conditions that make it possible, the behaviors it produces, and the controls that can prevent, detect, contain, and recover from it.
Open profile →T1074Data Staged (T1074) is an Enterprise ATT&CK technique associated with Collection. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1074.001Local Data Staging (T1074.001) is an Enterprise ATT&CK sub-technique under Data Staged. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Collection context.
Open profile →T1074.002Remote Data Staging (T1074.002) is an Enterprise ATT&CK sub-technique under Data Staged. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Collection context.
Open profile →T1078Valid Accounts (T1078) is an Enterprise ATT&CK technique associated with Stealth, Persistence, Privilege Escalation, Initial Access. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1078.001Default Accounts (T1078.001) is an Enterprise ATT&CK sub-technique under Valid Accounts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Persistence, Privilege Escalation, Initial Access context.
Open profile →T1078.002Domain Accounts (T1078.002) is an Enterprise ATT&CK sub-technique under Valid Accounts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Persistence, Privilege Escalation, Initial Access context.
Open profile →T1078.003Local Accounts (T1078.003) is an Enterprise ATT&CK sub-technique under Valid Accounts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Persistence, Privilege Escalation, Initial Access context.
Open profile →T1078.004Cloud Accounts (T1078.004) is an Enterprise ATT&CK sub-technique under Valid Accounts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Persistence, Privilege Escalation, Initial Access context.
Open profile →T1080Taint Shared Content (T1080) is an Enterprise ATT&CK technique associated with Lateral Movement. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1082An adversary queries operating-system, architecture, hardware, version, patch, hostname, or instance information to guide later actions.
Open profile →T1083File and Directory Discovery (T1083) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1087An adversary enumerates local, domain, cloud, service, or application accounts and groups to identify useful identities and privileges.
Open profile →T1087.001Local Account (T1087.001) is an Enterprise ATT&CK sub-technique under Account Discovery. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Discovery context.
Open profile →T1087.002Active Directory Fundamentals concerns the secure design, configuration, operation, monitoring, or recovery of computing platforms and connected devices.
Open profile →T1087.002Domain Account (T1087.002) is an Enterprise ATT&CK sub-technique under Account Discovery. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Discovery context.
Open profile →T1087.003Email Account (T1087.003) is an Enterprise ATT&CK sub-technique under Account Discovery. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Discovery context.
Open profile →T1087.004Cloud Account (T1087.004) is an Enterprise ATT&CK sub-technique under Account Discovery. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Discovery context.
Open profile →T1090Proxy (T1090) is an Enterprise ATT&CK technique associated with Command and Control. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1090.001Internal Proxy (T1090.001) is an Enterprise ATT&CK sub-technique under Proxy. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.
Open profile →T1090.002External Proxy (T1090.002) is an Enterprise ATT&CK sub-technique under Proxy. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.
Open profile →T1090.003Multi-hop Proxy (T1090.003) is an Enterprise ATT&CK sub-technique under Proxy. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.
Open profile →T1090.004Domain Fronting (T1090.004) is an Enterprise ATT&CK sub-technique under Proxy. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.
Open profile →T1091Replication Through Removable Media (T1091) is an Enterprise ATT&CK technique associated with Lateral Movement, Initial Access. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1092Communication Through Removable Media (T1092) is an Enterprise ATT&CK technique associated with Command and Control. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1095Non-Application Layer Protocol (T1095) is an Enterprise ATT&CK technique associated with Command and Control. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1098Account Manipulation (T1098) is an Enterprise ATT&CK technique associated with Persistence, Privilege Escalation. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1098.001Additional Cloud Credentials (T1098.001) is an Enterprise ATT&CK sub-technique under Account Manipulation. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1098.002Additional Email Delegate Permissions (T1098.002) is an Enterprise ATT&CK sub-technique under Account Manipulation. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1098.003Additional Cloud Roles (T1098.003) is an Enterprise ATT&CK sub-technique under Account Manipulation. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1098.004SSH Authorized Keys (T1098.004) is an Enterprise ATT&CK sub-technique under Account Manipulation. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1098.005Device Registration (T1098.005) is an Enterprise ATT&CK sub-technique under Account Manipulation. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1098.006Additional Container Cluster Roles (T1098.006) is an Enterprise ATT&CK sub-technique under Account Manipulation. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1098.007Additional Local or Domain Groups (T1098.007) is an Enterprise ATT&CK sub-technique under Account Manipulation. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1102Web Service (T1102) is an Enterprise ATT&CK technique associated with Command and Control. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1102.001Dead Drop Resolver (T1102.001) is an Enterprise ATT&CK sub-technique under Web Service. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.
Open profile →T1102.002Bidirectional Communication (T1102.002) is an Enterprise ATT&CK sub-technique under Web Service. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.
Open profile →T1102.003One-Way Communication (T1102.003) is an Enterprise ATT&CK sub-technique under Web Service. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.
Open profile →T1104Multi-Stage Channels (T1104) is an Enterprise ATT&CK technique associated with Command and Control. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1105An adversary transfers tools or files from an external location into a compromised environment, often through an existing command channel.
Open profile →T1106An adversary calls operating-system or runtime application programming interfaces directly to perform actions that might otherwise require ordinary utilities.
Open profile →T1110An adversary repeatedly attempts passwords, keys, or authentication combinations, including guessing, spraying, cracking, and credential stuffing.
Open profile →T1110Password Attacks describes an adversary technique, campaign pattern, or malicious capability. Defenders study the conditions that make it possible, the behaviors it produces, and the controls that can prevent, detect, contain, and recover from it.
Open profile →T1110.001Password Guessing (T1110.001) is an Enterprise ATT&CK sub-technique under Brute Force. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1110.002Password Cracking (T1110.002) is an Enterprise ATT&CK sub-technique under Brute Force. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1110.003Password Spraying (T1110.003) is an Enterprise ATT&CK sub-technique under Brute Force. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1110.003Password Spraying describes an adversary technique, campaign pattern, or malicious capability. Defenders study the conditions that make it possible, the behaviors it produces, and the controls that can prevent, detect, contain, and recover from it.
Open profile →T1110.004Credential Stuffing is part of the process used to establish identity, make access decisions, control privileges, or maintain trusted sessions.
Open profile →T1110.004Credential Stuffing (T1110.004) is an Enterprise ATT&CK sub-technique under Brute Force. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1111Multi-Factor Authentication Interception (T1111) is an Enterprise ATT&CK technique associated with Credential Access. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1112Modify Registry (T1112) is an Enterprise ATT&CK technique associated with Defense Impairment, Persistence. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1113An adversary captures screenshots or display content to collect information visible in applications, sessions, and user workflows.
Open profile →T1114Email Collection (T1114) is an Enterprise ATT&CK technique associated with Collection. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1114.001Local Email Collection (T1114.001) is an Enterprise ATT&CK sub-technique under Email Collection. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Collection context.
Open profile →T1114.002Remote Email Collection (T1114.002) is an Enterprise ATT&CK sub-technique under Email Collection. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Collection context.
Open profile →T1114.003Email Forwarding Rule (T1114.003) is an Enterprise ATT&CK sub-technique under Email Collection. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Collection context.
Open profile →T1115An adversary reads clipboard contents to collect copied credentials, commands, documents, or other data exchanged through the user interface.
Open profile →T1119Automated Collection (T1119) is an Enterprise ATT&CK technique associated with Collection. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1120Peripheral Device Discovery (T1120) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1123Audio Capture (T1123) is an Enterprise ATT&CK technique associated with Collection. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1124System Time Discovery (T1124) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1125Video Capture (T1125) is an Enterprise ATT&CK technique associated with Collection. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1127Trusted Developer Utilities Proxy Execution (T1127) is an Enterprise ATT&CK technique associated with Stealth, Execution. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1127.001MSBuild (T1127.001) is an Enterprise ATT&CK sub-technique under Trusted Developer Utilities Proxy Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Execution context.
Open profile →T1127.002ClickOnce (T1127.002) is an Enterprise ATT&CK sub-technique under Trusted Developer Utilities Proxy Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Execution context.
Open profile →T1127.003JamPlus (T1127.003) is an Enterprise ATT&CK sub-technique under Trusted Developer Utilities Proxy Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Execution context.
Open profile →T1129Shared Modules (T1129) is an Enterprise ATT&CK technique associated with Execution. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1132Data Encoding (T1132) is an Enterprise ATT&CK technique associated with Command and Control. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1132.001Standard Encoding (T1132.001) is an Enterprise ATT&CK sub-technique under Data Encoding. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.
Open profile →T1132.002Non-Standard Encoding (T1132.002) is an Enterprise ATT&CK sub-technique under Data Encoding. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.
Open profile →T1133An adversary uses externally reachable VPN, remote desktop, SSH, virtual application, management, or other remote-access services to enter or return to an environment.
Open profile →T1134An adversary duplicates, creates, replaces, or impersonates Windows access tokens to act in another security context.
Open profile →T1134.001Token Impersonation/Theft (T1134.001) is an Enterprise ATT&CK sub-technique under Access Token Manipulation. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Privilege Escalation context.
Open profile →T1134.002Create Process with Token (T1134.002) is an Enterprise ATT&CK sub-technique under Access Token Manipulation. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Privilege Escalation context.
Open profile →T1134.003Make and Impersonate Token (T1134.003) is an Enterprise ATT&CK sub-technique under Access Token Manipulation. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Privilege Escalation context.
Open profile →T1134.004Parent PID Spoofing (T1134.004) is an Enterprise ATT&CK sub-technique under Access Token Manipulation. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Privilege Escalation context.
Open profile →T1134.005SID-History Injection (T1134.005) is an Enterprise ATT&CK sub-technique under Access Token Manipulation. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Privilege Escalation context.
Open profile →T1135Network Share Discovery (T1135) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1136An adversary creates a local, domain, cloud, service, or application account that can be used for continued access.
Open profile →T1136.001Local Account (T1136.001) is an Enterprise ATT&CK sub-technique under Create Account. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence context.
Open profile →T1136.002Domain Account (T1136.002) is an Enterprise ATT&CK sub-technique under Create Account. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence context.
Open profile →T1136.003Cloud Account (T1136.003) is an Enterprise ATT&CK sub-technique under Create Account. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence context.
Open profile →T1137Office Application Startup (T1137) is an Enterprise ATT&CK technique associated with Persistence. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1137.001Office Template Macros (T1137.001) is an Enterprise ATT&CK sub-technique under Office Application Startup. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence context.
Open profile →T1137.002Office Test (T1137.002) is an Enterprise ATT&CK sub-technique under Office Application Startup. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence context.
Open profile →T1137.003Outlook Forms (T1137.003) is an Enterprise ATT&CK sub-technique under Office Application Startup. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence context.
Open profile →T1137.004Outlook Home Page (T1137.004) is an Enterprise ATT&CK sub-technique under Office Application Startup. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence context.
Open profile →T1137.005Outlook Rules (T1137.005) is an Enterprise ATT&CK sub-technique under Office Application Startup. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence context.
Open profile →T1137.006Add-ins (T1137.006) is an Enterprise ATT&CK sub-technique under Office Application Startup. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence context.
Open profile →T1140Deobfuscate/Decode Files or Information (T1140) is an Enterprise ATT&CK technique associated with Stealth. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1176Software Extensions (T1176) is an Enterprise ATT&CK technique associated with Persistence. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1176.001Browser Extensions (T1176.001) is an Enterprise ATT&CK sub-technique under Software Extensions. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence context.
Open profile →T1176.002IDE Extensions (T1176.002) is an Enterprise ATT&CK sub-technique under Software Extensions. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence context.
Open profile →T1185Browser Session Hijacking (T1185) is an Enterprise ATT&CK technique associated with Collection. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1187Forced Authentication (T1187) is an Enterprise ATT&CK technique associated with Credential Access. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1189A user is exposed to malicious web content that exploits a browser or convinces the user to retrieve and run harmful content, creating an entry path through normal browsing.
Open profile →T1190File Upload Security is an application-security topic involving trust boundaries, input handling, browser or API behavior, identity, authorization, or server-side processing.
Open profile →T1190An adversary exploits a weakness in an internet-accessible application, service, appliance, management interface, or workload to gain access.
Open profile →T1190Server-Side Request Forgery is an application-security topic involving trust boundaries, input handling, browser or API behavior, identity, authorization, or server-side processing.
Open profile →T1190Web application attack classes include injection, broken access control, authentication failures, insecure design, misconfiguration, component risk, request forgery, and unsafe handling of data and sessions.
Open profile →T1195Supply Chain Compromise (T1195) is an Enterprise ATT&CK technique associated with Initial Access. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1195Supply Chain Compromise is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Open profile →T1195.001Compromise Software Dependencies and Development Tools (T1195.001) is an Enterprise ATT&CK sub-technique under Supply Chain Compromise. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Initial Access context.
Open profile →T1195.002Compromise Software Supply Chain (T1195.002) is an Enterprise ATT&CK sub-technique under Supply Chain Compromise. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Initial Access context.
Open profile →T1195.003Compromise Hardware Supply Chain (T1195.003) is an Enterprise ATT&CK sub-technique under Supply Chain Compromise. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Initial Access context.
Open profile →T1197BITS Jobs (T1197) is an Enterprise ATT&CK technique associated with Stealth, Persistence, Execution. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1199Active Directory organizes identities and resources into domains; related domains form trees, one or more trees form a forest, and trusts define which security principals may be recognized across boundaries.
Open profile →T1199An adversary abuses a supplier, partner, managed service, federation, software, or other trusted relationship to reach the target environment.
Open profile →T1199Third-party risk management identifies, evaluates, treats, monitors, and responds to cyber risk introduced by vendors, cloud services, software, partners, and other external dependencies.
Open profile →T1200Hardware Additions (T1200) is an Enterprise ATT&CK technique associated with Initial Access. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1201Password Policy Discovery (T1201) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1202Indirect Command Execution (T1202) is an Enterprise ATT&CK technique associated with Stealth. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1203Exploitation for Client Execution (T1203) is an Enterprise ATT&CK technique associated with Execution. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1204An adversary depends on a user to open, launch, approve, install, or otherwise trigger malicious content or code.
Open profile →T1204.001Malicious Link (T1204.001) is an Enterprise ATT&CK sub-technique under User Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution context.
Open profile →T1204.002Malicious File (T1204.002) is an Enterprise ATT&CK sub-technique under User Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution context.
Open profile →T1204.003Malicious Image (T1204.003) is an Enterprise ATT&CK sub-technique under User Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution context.
Open profile →T1204.004Malicious Copy and Paste (T1204.004) is an Enterprise ATT&CK sub-technique under User Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution context.
Open profile →T1204.005Malicious Library (T1204.005) is an Enterprise ATT&CK sub-technique under User Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution context.
Open profile →T1205Traffic Signaling (T1205) is an Enterprise ATT&CK technique associated with Stealth, Persistence, Command and Control. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1205.001Port Knocking (T1205.001) is an Enterprise ATT&CK sub-technique under Traffic Signaling. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Persistence, Command and Control context.
Open profile →T1205.002Socket Filters (T1205.002) is an Enterprise ATT&CK sub-technique under Traffic Signaling. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Persistence, Command and Control context.
Open profile →T1207Rogue Domain Controller (T1207) is an Enterprise ATT&CK technique associated with Defense Impairment. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1210An adversary exploits a weakness in an internal remote service to gain access to another system without relying solely on valid credentials.
Open profile →T1211Exploitation for Stealth (T1211) is an Enterprise ATT&CK technique associated with Stealth. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1212Exploitation for Credential Access (T1212) is an Enterprise ATT&CK technique associated with Credential Access. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1213Data from Information Repositories (T1213) is an Enterprise ATT&CK technique associated with Collection. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1213.001Confluence (T1213.001) is an Enterprise ATT&CK sub-technique under Data from Information Repositories. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Collection context.
Open profile →T1213.002Sharepoint (T1213.002) is an Enterprise ATT&CK sub-technique under Data from Information Repositories. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Collection context.
Open profile →T1213.003Code Repositories (T1213.003) is an Enterprise ATT&CK sub-technique under Data from Information Repositories. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Collection context.
Open profile →T1213.004Customer Relationship Management Software (T1213.004) is an Enterprise ATT&CK sub-technique under Data from Information Repositories. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Collection context.
Open profile →T1213.005Messaging Applications (T1213.005) is an Enterprise ATT&CK sub-technique under Data from Information Repositories. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Collection context.
Open profile →T1213.006Databases (T1213.006) is an Enterprise ATT&CK sub-technique under Data from Information Repositories. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Collection context.
Open profile →T1216System Script Proxy Execution (T1216) is an Enterprise ATT&CK technique associated with Stealth. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1216.001PubPrn (T1216.001) is an Enterprise ATT&CK sub-technique under System Script Proxy Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1216.002SyncAppvPublishingServer (T1216.002) is an Enterprise ATT&CK sub-technique under System Script Proxy Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1217Browser Information Discovery (T1217) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1218System Binary Proxy Execution (T1218) is an Enterprise ATT&CK technique associated with Stealth. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1218.001Compiled HTML File (T1218.001) is an Enterprise ATT&CK sub-technique under System Binary Proxy Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1218.002Control Panel (T1218.002) is an Enterprise ATT&CK sub-technique under System Binary Proxy Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1218.003CMSTP (T1218.003) is an Enterprise ATT&CK sub-technique under System Binary Proxy Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1218.004InstallUtil (T1218.004) is an Enterprise ATT&CK sub-technique under System Binary Proxy Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1218.005Mshta (T1218.005) is an Enterprise ATT&CK sub-technique under System Binary Proxy Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1218.007Msiexec (T1218.007) is an Enterprise ATT&CK sub-technique under System Binary Proxy Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1218.008Odbcconf (T1218.008) is an Enterprise ATT&CK sub-technique under System Binary Proxy Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1218.009Regsvcs/Regasm (T1218.009) is an Enterprise ATT&CK sub-technique under System Binary Proxy Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1218.010Regsvr32 (T1218.010) is an Enterprise ATT&CK sub-technique under System Binary Proxy Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1218.011Rundll32 (T1218.011) is an Enterprise ATT&CK sub-technique under System Binary Proxy Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1218.012Verclsid (T1218.012) is an Enterprise ATT&CK sub-technique under System Binary Proxy Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1218.013Mavinject (T1218.013) is an Enterprise ATT&CK sub-technique under System Binary Proxy Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1218.014MMC (T1218.014) is an Enterprise ATT&CK sub-technique under System Binary Proxy Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1218.015Electron Applications (T1218.015) is an Enterprise ATT&CK sub-technique under System Binary Proxy Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1219Remote Access Tools (T1219) is an Enterprise ATT&CK technique associated with Command and Control. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1219.001IDE Tunneling (T1219.001) is an Enterprise ATT&CK sub-technique under Remote Access Tools. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.
Open profile →T1219.002Remote Desktop Software (T1219.002) is an Enterprise ATT&CK sub-technique under Remote Access Tools. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.
Open profile →T1219.003Remote Access Hardware (T1219.003) is an Enterprise ATT&CK sub-technique under Remote Access Tools. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.
Open profile →T1220XSL Script Processing (T1220) is an Enterprise ATT&CK technique associated with Stealth. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1221Template Injection (T1221) is an Enterprise ATT&CK technique associated with Stealth. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1222File and Directory Permissions Modification (T1222) is an Enterprise ATT&CK technique associated with Defense Impairment. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1222.001Windows Permissions (T1222.001) is an Enterprise ATT&CK sub-technique under File and Directory Permissions Modification. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment context.
Open profile →T1222.002Linux and Mac Permissions (T1222.002) is an Enterprise ATT&CK sub-technique under File and Directory Permissions Modification. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment context.
Open profile →T1480Execution Guardrails (T1480) is an Enterprise ATT&CK technique associated with Stealth. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1480.001Environmental Keying (T1480.001) is an Enterprise ATT&CK sub-technique under Execution Guardrails. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1480.002Mutual Exclusion (T1480.002) is an Enterprise ATT&CK sub-technique under Execution Guardrails. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1482Domain Trust Discovery (T1482) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1484An adversary changes domain, federation, identity-provider, tenant, or cloud policy to weaken controls, grant access, or alter trusted behavior.
Open profile →T1484.001Group Policy Modification (T1484.001) is an Enterprise ATT&CK sub-technique under Domain or Tenant Policy Modification. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment, Privilege Escalation context.
Open profile →T1484.002Trust Modification (T1484.002) is an Enterprise ATT&CK sub-technique under Domain or Tenant Policy Modification. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment, Privilege Escalation context.
Open profile →T1485Data Destruction (T1485) is an Enterprise ATT&CK technique associated with Impact. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1485.001Lifecycle-Triggered Deletion (T1485.001) is an Enterprise ATT&CK sub-technique under Data Destruction. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Impact context.
Open profile →T1486An adversary encrypts files, databases, virtual machines, or other information to disrupt availability and pressure the victim.
Open profile →T1486Ransomware operations disrupt access to systems or data and may combine encryption with theft, extortion, public pressure, and attacks on recovery systems.
Open profile →T1489Service Stop (T1489) is an Enterprise ATT&CK technique associated with Impact. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1490Backup and recovery strategies preserve usable copies of data and system state so services can be restored after failure, error, corruption, or attack.
Open profile →T1490An adversary deletes, disables, corrupts, or reconfigures backups, snapshots, recovery partitions, services, or boot options to make restoration harder.
Open profile →T1490Recovery testing and restore assurance verify that protected data, systems, dependencies, procedures, and personnel can meet defined recovery needs.
Open profile →T1490Incident recovery validation confirms that services are restored, attacker access is removed, controls are effective, data is trustworthy, and monitoring can detect recurrence.
Open profile →T1491Defacement (T1491) is an Enterprise ATT&CK technique associated with Impact. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1491.001Internal Defacement (T1491.001) is an Enterprise ATT&CK sub-technique under Defacement. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Impact context.
Open profile →T1491.002External Defacement (T1491.002) is an Enterprise ATT&CK sub-technique under Defacement. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Impact context.
Open profile →T1495Firmware Corruption (T1495) is an Enterprise ATT&CK technique associated with Impact. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1496Resource Hijacking (T1496) is an Enterprise ATT&CK technique associated with Impact. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1496.001Compute Hijacking (T1496.001) is an Enterprise ATT&CK sub-technique under Resource Hijacking. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Impact context.
Open profile →T1496.002Bandwidth Hijacking (T1496.002) is an Enterprise ATT&CK sub-technique under Resource Hijacking. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Impact context.
Open profile →T1496.003SMS Pumping (T1496.003) is an Enterprise ATT&CK sub-technique under Resource Hijacking. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Impact context.
Open profile →T1496.004Cloud Service Hijacking (T1496.004) is an Enterprise ATT&CK sub-technique under Resource Hijacking. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Impact context.
Open profile →T1497Virtualization/Sandbox Evasion (T1497) is an Enterprise ATT&CK technique associated with Stealth, Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1497.001System Checks (T1497.001) is an Enterprise ATT&CK sub-technique under Virtualization/Sandbox Evasion. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Discovery context.
Open profile →T1497.002User Activity Based Checks (T1497.002) is an Enterprise ATT&CK sub-technique under Virtualization/Sandbox Evasion. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Discovery context.
Open profile →T1497.003Time Based Checks (T1497.003) is an Enterprise ATT&CK sub-technique under Virtualization/Sandbox Evasion. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Discovery context.
Open profile →T1498Network Denial of Service (T1498) is an Enterprise ATT&CK technique associated with Impact. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1498.001Direct Network Flood (T1498.001) is an Enterprise ATT&CK sub-technique under Network Denial of Service. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Impact context.
Open profile →T1498.002Reflection Amplification (T1498.002) is an Enterprise ATT&CK sub-technique under Network Denial of Service. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Impact context.
Open profile →T1499Endpoint Denial of Service (T1499) is an Enterprise ATT&CK technique associated with Impact. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1499.001OS Exhaustion Flood (T1499.001) is an Enterprise ATT&CK sub-technique under Endpoint Denial of Service. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Impact context.
Open profile →T1499.002Service Exhaustion Flood (T1499.002) is an Enterprise ATT&CK sub-technique under Endpoint Denial of Service. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Impact context.
Open profile →T1499.003Application Exhaustion Flood (T1499.003) is an Enterprise ATT&CK sub-technique under Endpoint Denial of Service. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Impact context.
Open profile →T1499.004Application or System Exploitation (T1499.004) is an Enterprise ATT&CK sub-technique under Endpoint Denial of Service. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Impact context.
Open profile →T1505An adversary adds or modifies a component within server software—such as a web shell, plug-in, module, or management extension—to preserve access or execute code.
Open profile →T1505.001SQL Stored Procedures (T1505.001) is an Enterprise ATT&CK sub-technique under Server Software Component. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence context.
Open profile →T1505.002Transport Agent (T1505.002) is an Enterprise ATT&CK sub-technique under Server Software Component. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence context.
Open profile →T1505.003Web Shell (T1505.003) is an Enterprise ATT&CK sub-technique under Server Software Component. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence context.
Open profile →T1505.004IIS Components (T1505.004) is an Enterprise ATT&CK sub-technique under Server Software Component. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence context.
Open profile →T1505.005Terminal Services DLL (T1505.005) is an Enterprise ATT&CK sub-technique under Server Software Component. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence context.
Open profile →T1505.006vSphere Installation Bundles (T1505.006) is an Enterprise ATT&CK sub-technique under Server Software Component. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence context.
Open profile →T1518Software Discovery (T1518) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1518.001Security Software Discovery (T1518.001) is an Enterprise ATT&CK sub-technique under Software Discovery. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Discovery context.
Open profile →T1518.002Backup Software Discovery (T1518.002) is an Enterprise ATT&CK sub-technique under Software Discovery. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Discovery context.
Open profile →T1525Implant Internal Image (T1525) is an Enterprise ATT&CK technique associated with Persistence. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1526Cloud Service Discovery (T1526) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1528Steal Application Access Token (T1528) is an Enterprise ATT&CK technique associated with Credential Access. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1529System Shutdown/Reboot (T1529) is an Enterprise ATT&CK technique associated with Impact. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1530Data from Cloud Storage (T1530) is an Enterprise ATT&CK technique associated with Collection. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1531Account Access Removal (T1531) is an Enterprise ATT&CK technique associated with Impact. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1534Internal Spearphishing (T1534) is an Enterprise ATT&CK technique associated with Lateral Movement. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1535Unused/Unsupported Cloud Regions (T1535) is an Enterprise ATT&CK technique associated with Stealth. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1537Transfer Data to Cloud Account (T1537) is an Enterprise ATT&CK technique associated with Exfiltration. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1538Cloud Service Dashboard (T1538) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1539Steal Web Session Cookie (T1539) is an Enterprise ATT&CK technique associated with Credential Access. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1542Pre-OS Boot (T1542) is an Enterprise ATT&CK technique associated with Stealth, Persistence. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1542.001System Firmware (T1542.001) is an Enterprise ATT&CK sub-technique under Pre-OS Boot. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Persistence context.
Open profile →T1542.002Component Firmware (T1542.002) is an Enterprise ATT&CK sub-technique under Pre-OS Boot. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Persistence context.
Open profile →T1542.003Bootkit (T1542.003) is an Enterprise ATT&CK sub-technique under Pre-OS Boot. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Persistence context.
Open profile →T1542.004ROMMONkit (T1542.004) is an Enterprise ATT&CK sub-technique under Pre-OS Boot. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Persistence context.
Open profile →T1542.005TFTP Boot (T1542.005) is an Enterprise ATT&CK sub-technique under Pre-OS Boot. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Persistence context.
Open profile →T1543Create or Modify System Process (T1543) is an Enterprise ATT&CK technique associated with Persistence, Privilege Escalation. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1543.001Launch Agent (T1543.001) is an Enterprise ATT&CK sub-technique under Create or Modify System Process. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1543.002Systemd Service (T1543.002) is an Enterprise ATT&CK sub-technique under Create or Modify System Process. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1543.003Windows Service (T1543.003) is an Enterprise ATT&CK sub-technique under Create or Modify System Process. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1543.004Launch Daemon (T1543.004) is an Enterprise ATT&CK sub-technique under Create or Modify System Process. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1543.005Container Service (T1543.005) is an Enterprise ATT&CK sub-technique under Create or Modify System Process. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1546Event Triggered Execution (T1546) is an Enterprise ATT&CK technique associated with Privilege Escalation, Persistence. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1546.001Change Default File Association (T1546.001) is an Enterprise ATT&CK sub-technique under Event Triggered Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Privilege Escalation, Persistence context.
Open profile →T1546.002Screensaver (T1546.002) is an Enterprise ATT&CK sub-technique under Event Triggered Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Privilege Escalation, Persistence context.
Open profile →T1546.003Windows Management Instrumentation Event Subscription (T1546.003) is an Enterprise ATT&CK sub-technique under Event Triggered Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Privilege Escalation, Persistence context.
Open profile →T1546.004Unix Shell Configuration Modification (T1546.004) is an Enterprise ATT&CK sub-technique under Event Triggered Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Privilege Escalation, Persistence context.
Open profile →T1546.005Trap (T1546.005) is an Enterprise ATT&CK sub-technique under Event Triggered Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Privilege Escalation, Persistence context.
Open profile →T1546.006LC_LOAD_DYLIB Addition (T1546.006) is an Enterprise ATT&CK sub-technique under Event Triggered Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Privilege Escalation, Persistence context.
Open profile →T1546.007Netsh Helper DLL (T1546.007) is an Enterprise ATT&CK sub-technique under Event Triggered Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Privilege Escalation, Persistence context.
Open profile →T1546.008Accessibility Features (T1546.008) is an Enterprise ATT&CK sub-technique under Event Triggered Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Privilege Escalation, Persistence context.
Open profile →T1546.009AppCert DLLs (T1546.009) is an Enterprise ATT&CK sub-technique under Event Triggered Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Privilege Escalation, Persistence context.
Open profile →T1546.010AppInit DLLs (T1546.010) is an Enterprise ATT&CK sub-technique under Event Triggered Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Privilege Escalation, Persistence context.
Open profile →T1546.011Application Shimming (T1546.011) is an Enterprise ATT&CK sub-technique under Event Triggered Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Privilege Escalation, Persistence context.
Open profile →T1546.012Image File Execution Options Injection (T1546.012) is an Enterprise ATT&CK sub-technique under Event Triggered Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Privilege Escalation, Persistence context.
Open profile →T1546.013PowerShell Profile (T1546.013) is an Enterprise ATT&CK sub-technique under Event Triggered Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Privilege Escalation, Persistence context.
Open profile →T1546.014Emond (T1546.014) is an Enterprise ATT&CK sub-technique under Event Triggered Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Privilege Escalation, Persistence context.
Open profile →T1546.015Component Object Model Hijacking (T1546.015) is an Enterprise ATT&CK sub-technique under Event Triggered Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Privilege Escalation, Persistence context.
Open profile →T1546.016Installer Packages (T1546.016) is an Enterprise ATT&CK sub-technique under Event Triggered Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Privilege Escalation, Persistence context.
Open profile →T1546.017Udev Rules (T1546.017) is an Enterprise ATT&CK sub-technique under Event Triggered Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Privilege Escalation, Persistence context.
Open profile →T1546.018Python Startup Hooks (T1546.018) is an Enterprise ATT&CK sub-technique under Event Triggered Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Privilege Escalation, Persistence context.
Open profile →T1547An adversary changes startup or sign-in mechanisms so code runs automatically during system boot or user logon.
Open profile →T1547.001Registry Run Keys / Startup Folder (T1547.001) is an Enterprise ATT&CK sub-technique under Boot or Logon Autostart Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1547.002Authentication Package (T1547.002) is an Enterprise ATT&CK sub-technique under Boot or Logon Autostart Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1547.003Time Providers (T1547.003) is an Enterprise ATT&CK sub-technique under Boot or Logon Autostart Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1547.004Winlogon Helper DLL (T1547.004) is an Enterprise ATT&CK sub-technique under Boot or Logon Autostart Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1547.005Security Support Provider (T1547.005) is an Enterprise ATT&CK sub-technique under Boot or Logon Autostart Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1547.006Kernel Modules and Extensions (T1547.006) is an Enterprise ATT&CK sub-technique under Boot or Logon Autostart Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1547.007Re-opened Applications (T1547.007) is an Enterprise ATT&CK sub-technique under Boot or Logon Autostart Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1547.008LSASS Driver (T1547.008) is an Enterprise ATT&CK sub-technique under Boot or Logon Autostart Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1547.009Shortcut Modification (T1547.009) is an Enterprise ATT&CK sub-technique under Boot or Logon Autostart Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1547.010Port Monitors (T1547.010) is an Enterprise ATT&CK sub-technique under Boot or Logon Autostart Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1547.012Print Processors (T1547.012) is an Enterprise ATT&CK sub-technique under Boot or Logon Autostart Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1547.013XDG Autostart Entries (T1547.013) is an Enterprise ATT&CK sub-technique under Boot or Logon Autostart Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1547.014Active Setup (T1547.014) is an Enterprise ATT&CK sub-technique under Boot or Logon Autostart Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1547.015Login Items (T1547.015) is an Enterprise ATT&CK sub-technique under Boot or Logon Autostart Execution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Persistence, Privilege Escalation context.
Open profile →T1548An adversary misuses an operating-system mechanism intended to govern privilege elevation so activity runs with higher permissions.
Open profile →T1548.001Setuid and Setgid (T1548.001) is an Enterprise ATT&CK sub-technique under Abuse Elevation Control Mechanism. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Privilege Escalation context.
Open profile →T1548.002Bypass User Account Control (T1548.002) is an Enterprise ATT&CK sub-technique under Abuse Elevation Control Mechanism. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Privilege Escalation context.
Open profile →T1548.003Sudo and Sudo Caching (T1548.003) is an Enterprise ATT&CK sub-technique under Abuse Elevation Control Mechanism. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Privilege Escalation context.
Open profile →T1548.004Elevated Execution with Prompt (T1548.004) is an Enterprise ATT&CK sub-technique under Abuse Elevation Control Mechanism. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Privilege Escalation context.
Open profile →T1548.005Temporary Elevated Cloud Access (T1548.005) is an Enterprise ATT&CK sub-technique under Abuse Elevation Control Mechanism. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Privilege Escalation context.
Open profile →T1548.006TCC Manipulation (T1548.006) is an Enterprise ATT&CK sub-technique under Abuse Elevation Control Mechanism. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Privilege Escalation context.
Open profile →T1550Use Alternate Authentication Material (T1550) is an Enterprise ATT&CK technique associated with Lateral Movement. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1550.001Application Access Token (T1550.001) is an Enterprise ATT&CK sub-technique under Use Alternate Authentication Material. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Lateral Movement context.
Open profile →T1550.002Pass the Hash (T1550.002) is an Enterprise ATT&CK sub-technique under Use Alternate Authentication Material. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Lateral Movement context.
Open profile →T1550.002Pass-the-Hash is a credential replay technique in which an attacker uses a captured NTLM password hash to authenticate without learning or typing the original plaintext password.
Open profile →T1550.003Pass the Ticket (T1550.003) is an Enterprise ATT&CK sub-technique under Use Alternate Authentication Material. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Lateral Movement context.
Open profile →T1550.004Web Session Cookie (T1550.004) is an Enterprise ATT&CK sub-technique under Use Alternate Authentication Material. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Lateral Movement context.
Open profile →T1552An adversary searches files, repositories, scripts, logs, environment variables, instance metadata, or configuration for exposed authentication material.
Open profile →T1552.001Credentials In Files (T1552.001) is an Enterprise ATT&CK sub-technique under Unsecured Credentials. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1552.002Credentials in Registry (T1552.002) is an Enterprise ATT&CK sub-technique under Unsecured Credentials. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1552.003Shell History (T1552.003) is an Enterprise ATT&CK sub-technique under Unsecured Credentials. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1552.004Private Keys (T1552.004) is an Enterprise ATT&CK sub-technique under Unsecured Credentials. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1552.005Cloud Instance Metadata API (T1552.005) is an Enterprise ATT&CK sub-technique under Unsecured Credentials. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1552.006Group Policy Preferences (T1552.006) is an Enterprise ATT&CK sub-technique under Unsecured Credentials. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1552.007Container API (T1552.007) is an Enterprise ATT&CK sub-technique under Unsecured Credentials. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1552.008Chat Messages (T1552.008) is an Enterprise ATT&CK sub-technique under Unsecured Credentials. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1553Subvert Trust Controls (T1553) is an Enterprise ATT&CK technique associated with Defense Impairment. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1553.001Gatekeeper Bypass (T1553.001) is an Enterprise ATT&CK sub-technique under Subvert Trust Controls. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment context.
Open profile →T1553.002Code Signing (T1553.002) is an Enterprise ATT&CK sub-technique under Subvert Trust Controls. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment context.
Open profile →T1553.003SIP and Trust Provider Hijacking (T1553.003) is an Enterprise ATT&CK sub-technique under Subvert Trust Controls. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment context.
Open profile →T1553.004Install Root Certificate (T1553.004) is an Enterprise ATT&CK sub-technique under Subvert Trust Controls. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment context.
Open profile →T1553.005Mark-of-the-Web Bypass (T1553.005) is an Enterprise ATT&CK sub-technique under Subvert Trust Controls. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment context.
Open profile →T1553.006Code Signing Policy Modification (T1553.006) is an Enterprise ATT&CK sub-technique under Subvert Trust Controls. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment context.
Open profile →T1554Compromise Host Software Binary (T1554) is an Enterprise ATT&CK technique associated with Persistence. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1555An adversary extracts credentials, keys, cookies, or tokens from browsers, password managers, operating-system stores, or application repositories.
Open profile →T1555.001Keychain (T1555.001) is an Enterprise ATT&CK sub-technique under Credentials from Password Stores. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1555.002Securityd Memory (T1555.002) is an Enterprise ATT&CK sub-technique under Credentials from Password Stores. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1555.003Credentials from Web Browsers (T1555.003) is an Enterprise ATT&CK sub-technique under Credentials from Password Stores. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1555.004Windows Credential Manager (T1555.004) is an Enterprise ATT&CK sub-technique under Credentials from Password Stores. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1555.005Password Managers (T1555.005) is an Enterprise ATT&CK sub-technique under Credentials from Password Stores. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1555.006Cloud Secrets Management Stores (T1555.006) is an Enterprise ATT&CK sub-technique under Credentials from Password Stores. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1556Modify Authentication Process (T1556) is an Enterprise ATT&CK technique associated with Defense Impairment, Persistence, Credential Access. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1556.001Domain Controller Authentication (T1556.001) is an Enterprise ATT&CK sub-technique under Modify Authentication Process. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment, Persistence, Credential Access context.
Open profile →T1556.002Password Filter DLL (T1556.002) is an Enterprise ATT&CK sub-technique under Modify Authentication Process. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment, Persistence, Credential Access context.
Open profile →T1556.003Pluggable Authentication Modules (T1556.003) is an Enterprise ATT&CK sub-technique under Modify Authentication Process. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment, Persistence, Credential Access context.
Open profile →T1556.004Network Device Authentication (T1556.004) is an Enterprise ATT&CK sub-technique under Modify Authentication Process. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment, Persistence, Credential Access context.
Open profile →T1556.005Reversible Encryption (T1556.005) is an Enterprise ATT&CK sub-technique under Modify Authentication Process. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment, Persistence, Credential Access context.
Open profile →T1556.006Multi-Factor Authentication (T1556.006) is an Enterprise ATT&CK sub-technique under Modify Authentication Process. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment, Persistence, Credential Access context.
Open profile →T1556.007Hybrid Identity (T1556.007) is an Enterprise ATT&CK sub-technique under Modify Authentication Process. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment, Persistence, Credential Access context.
Open profile →T1556.008Network Provider DLL (T1556.008) is an Enterprise ATT&CK sub-technique under Modify Authentication Process. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment, Persistence, Credential Access context.
Open profile →T1556.009Conditional Access Policies (T1556.009) is an Enterprise ATT&CK sub-technique under Modify Authentication Process. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment, Persistence, Credential Access context.
Open profile →T1557Adversary-in-the-Middle (T1557) is an Enterprise ATT&CK technique associated with Credential Access, Collection. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1557On-Path Attacks describes an adversary technique, campaign pattern, or malicious capability. Defenders study the conditions that make it possible, the behaviors it produces, and the controls that can prevent, detect, contain, and recover from it.
Open profile →T1557.001Name Resolution Poisoning and SMB Relay (T1557.001) is an Enterprise ATT&CK sub-technique under Adversary-in-the-Middle. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access, Collection context.
Open profile →T1557.002ARP Cache Poisoning (T1557.002) is an Enterprise ATT&CK sub-technique under Adversary-in-the-Middle. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access, Collection context.
Open profile →T1557.003DHCP Spoofing (T1557.003) is an Enterprise ATT&CK sub-technique under Adversary-in-the-Middle. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access, Collection context.
Open profile →T1557.004Evil Twin (T1557.004) is an Enterprise ATT&CK sub-technique under Adversary-in-the-Middle. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access, Collection context.
Open profile →T1558Kerberos in Active Directory is a ticket-based authentication system in which domain controllers acting as key distribution centers issue time-limited tickets that let users and services prove identity without repeatedly transmitting passwords.
Open profile →T1558Steal or Forge Kerberos Tickets (T1558) is an Enterprise ATT&CK technique associated with Credential Access. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1558.001Golden Ticket (T1558.001) is an Enterprise ATT&CK sub-technique under Steal or Forge Kerberos Tickets. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1558.002Silver Ticket (T1558.002) is an Enterprise ATT&CK sub-technique under Steal or Forge Kerberos Tickets. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1558.003Kerberoasting is an attack technique in which an authenticated domain user requests Kerberos service tickets for service principal names and attempts to crack the ticket material offline to recover weak service-account passwords.
Open profile →T1558.003Kerberoasting (T1558.003) is an Enterprise ATT&CK sub-technique under Steal or Forge Kerberos Tickets. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1558.004AS-REP roasting targets Active Directory accounts that do not require Kerberos preauthentication, allowing an attacker to request an authentication response containing password-derived material and attempt offline password guessing.
Open profile →T1558.004AS-REP Roasting (T1558.004) is an Enterprise ATT&CK sub-technique under Steal or Forge Kerberos Tickets. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1558.005Ccache Files (T1558.005) is an Enterprise ATT&CK sub-technique under Steal or Forge Kerberos Tickets. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1559Inter-Process Communication (T1559) is an Enterprise ATT&CK technique associated with Execution. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1559.001Component Object Model (T1559.001) is an Enterprise ATT&CK sub-technique under Inter-Process Communication. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution context.
Open profile →T1559.002Dynamic Data Exchange (T1559.002) is an Enterprise ATT&CK sub-technique under Inter-Process Communication. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution context.
Open profile →T1559.003XPC Services (T1559.003) is an Enterprise ATT&CK sub-technique under Inter-Process Communication. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution context.
Open profile →T1560Archive Collected Data (T1560) is an Enterprise ATT&CK technique associated with Collection. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1560.001Archive via Utility (T1560.001) is an Enterprise ATT&CK sub-technique under Archive Collected Data. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Collection context.
Open profile →T1560.002Archive via Library (T1560.002) is an Enterprise ATT&CK sub-technique under Archive Collected Data. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Collection context.
Open profile →T1560.003Archive via Custom Method (T1560.003) is an Enterprise ATT&CK sub-technique under Archive Collected Data. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Collection context.
Open profile →T1561Disk Wipe (T1561) is an Enterprise ATT&CK technique associated with Impact. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1561.001Disk Content Wipe (T1561.001) is an Enterprise ATT&CK sub-technique under Disk Wipe. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Impact context.
Open profile →T1561.002Disk Structure Wipe (T1561.002) is an Enterprise ATT&CK sub-technique under Disk Wipe. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Impact context.
Open profile →T1562Impair Defenses (T1562) is retained as a historical ATT&CK mapping. Enterprise ATT&CK v19.2 reorganized this behavior; use the linked current successor profiles for active catalog mapping.
Open profile →T1562.001Disable or Modify Tools (T1562.001) is retained as a historical ATT&CK mapping. Enterprise ATT&CK v19.2 reorganized this behavior; use the linked current successor profiles for active catalog mapping.
Open profile →T1562.004Disable or Modify System Firewall (T1562.004) is retained as a historical ATT&CK mapping. Enterprise ATT&CK v19.2 reorganized this behavior; use the linked current successor profiles for active catalog mapping.
Open profile →T1563Remote Service Session Hijacking (T1563) is an Enterprise ATT&CK technique associated with Lateral Movement. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1563.001SSH Hijacking (T1563.001) is an Enterprise ATT&CK sub-technique under Remote Service Session Hijacking. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Lateral Movement context.
Open profile →T1563.002RDP Hijacking (T1563.002) is an Enterprise ATT&CK sub-technique under Remote Service Session Hijacking. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Lateral Movement context.
Open profile →T1564An adversary conceals files, directories, processes, windows, accounts, services, or cloud resources from ordinary inspection.
Open profile →T1564.001Hidden Files and Directories (T1564.001) is an Enterprise ATT&CK sub-technique under Hide Artifacts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1564.002Hidden Users (T1564.002) is an Enterprise ATT&CK sub-technique under Hide Artifacts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1564.003Hidden Window (T1564.003) is an Enterprise ATT&CK sub-technique under Hide Artifacts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1564.004NTFS File Attributes (T1564.004) is an Enterprise ATT&CK sub-technique under Hide Artifacts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1564.005Hidden File System (T1564.005) is an Enterprise ATT&CK sub-technique under Hide Artifacts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1564.006Run Virtual Instance (T1564.006) is an Enterprise ATT&CK sub-technique under Hide Artifacts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1564.007VBA Stomping (T1564.007) is an Enterprise ATT&CK sub-technique under Hide Artifacts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1564.008Email Hiding Rules (T1564.008) is an Enterprise ATT&CK sub-technique under Hide Artifacts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1564.009Resource Forking (T1564.009) is an Enterprise ATT&CK sub-technique under Hide Artifacts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1564.010Process Argument Spoofing (T1564.010) is an Enterprise ATT&CK sub-technique under Hide Artifacts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1564.011Ignore Process Interrupts (T1564.011) is an Enterprise ATT&CK sub-technique under Hide Artifacts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1564.012File/Path Exclusions (T1564.012) is an Enterprise ATT&CK sub-technique under Hide Artifacts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1564.013Bind Mounts (T1564.013) is an Enterprise ATT&CK sub-technique under Hide Artifacts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1564.014Extended Attributes (T1564.014) is an Enterprise ATT&CK sub-technique under Hide Artifacts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1565Data Manipulation (T1565) is an Enterprise ATT&CK technique associated with Impact. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1565.001Stored Data Manipulation (T1565.001) is an Enterprise ATT&CK sub-technique under Data Manipulation. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Impact context.
Open profile →T1565.002Transmitted Data Manipulation (T1565.002) is an Enterprise ATT&CK sub-technique under Data Manipulation. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Impact context.
Open profile →T1565.003Runtime Data Manipulation (T1565.003) is an Enterprise ATT&CK sub-technique under Data Manipulation. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Impact context.
Open profile →T1566Phishing (T1566) is an Enterprise ATT&CK technique associated with Initial Access. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1566Phishing uses deceptive messages, sites, calls, or prompts to persuade a person to reveal information, approve access, send money, or run malicious content.
Open profile →T1566.001Spearphishing Attachment (T1566.001) is an Enterprise ATT&CK sub-technique under Phishing. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Initial Access context.
Open profile →T1566.002Spearphishing Link (T1566.002) is an Enterprise ATT&CK sub-technique under Phishing. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Initial Access context.
Open profile →T1566.003Spearphishing via Service (T1566.003) is an Enterprise ATT&CK sub-technique under Phishing. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Initial Access context.
Open profile →T1566.004Spearphishing Voice (T1566.004) is an Enterprise ATT&CK sub-technique under Phishing. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Initial Access context.
Open profile →T1567An adversary uploads information through a web service, cloud-storage provider, code-sharing service, or other internet platform that may resemble normal use.
Open profile →T1567.001Exfiltration to Code Repository (T1567.001) is an Enterprise ATT&CK sub-technique under Exfiltration Over Web Service. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Exfiltration context.
Open profile →T1567.002Cloud storage exfiltration detection looks for unusual reads, downloads, copies, sharing changes, presigned access, cross-account movement, and data-transfer patterns.
Open profile →T1567.002Exfiltration to Cloud Storage (T1567.002) is an Enterprise ATT&CK sub-technique under Exfiltration Over Web Service. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Exfiltration context.
Open profile →T1567.003Exfiltration to Text Storage Sites (T1567.003) is an Enterprise ATT&CK sub-technique under Exfiltration Over Web Service. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Exfiltration context.
Open profile →T1567.004Exfiltration Over Webhook (T1567.004) is an Enterprise ATT&CK sub-technique under Exfiltration Over Web Service. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Exfiltration context.
Open profile →T1568Dynamic Resolution (T1568) is an Enterprise ATT&CK technique associated with Command and Control. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1568.001Fast Flux DNS (T1568.001) is an Enterprise ATT&CK sub-technique under Dynamic Resolution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.
Open profile →T1568.002Domain Generation Algorithms (T1568.002) is an Enterprise ATT&CK sub-technique under Dynamic Resolution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.
Open profile →T1568.003DNS Calculation (T1568.003) is an Enterprise ATT&CK sub-technique under Dynamic Resolution. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.
Open profile →T1569System Services (T1569) is an Enterprise ATT&CK technique associated with Execution. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1569.001Launchctl (T1569.001) is an Enterprise ATT&CK sub-technique under System Services. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution context.
Open profile →T1569.002Service Execution (T1569.002) is an Enterprise ATT&CK sub-technique under System Services. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution context.
Open profile →T1569.003Systemctl (T1569.003) is an Enterprise ATT&CK sub-technique under System Services. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Execution context.
Open profile →T1570An adversary copies tools or files between systems inside the target environment to support continued movement and execution.
Open profile →T1571Non-Standard Port (T1571) is an Enterprise ATT&CK technique associated with Command and Control. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1572Protocol Tunneling (T1572) is an Enterprise ATT&CK technique associated with Command and Control. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1573An adversary protects command traffic with encryption or an encrypted protocol to conceal content and complicate inspection.
Open profile →T1573.001Symmetric Cryptography (T1573.001) is an Enterprise ATT&CK sub-technique under Encrypted Channel. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.
Open profile →T1573.002Asymmetric Cryptography (T1573.002) is an Enterprise ATT&CK sub-technique under Encrypted Channel. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.
Open profile →T1574Hijack Execution Flow (T1574) is an Enterprise ATT&CK technique associated with Stealth, Execution. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1574.001DLL (T1574.001) is an Enterprise ATT&CK sub-technique under Hijack Execution Flow. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Execution context.
Open profile →T1574.004Dylib Hijacking (T1574.004) is an Enterprise ATT&CK sub-technique under Hijack Execution Flow. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Execution context.
Open profile →T1574.005Executable Installer File Permissions Weakness (T1574.005) is an Enterprise ATT&CK sub-technique under Hijack Execution Flow. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Execution context.
Open profile →T1574.006Dynamic Linker Hijacking (T1574.006) is an Enterprise ATT&CK sub-technique under Hijack Execution Flow. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Execution context.
Open profile →T1574.007Path Interception by PATH Environment Variable (T1574.007) is an Enterprise ATT&CK sub-technique under Hijack Execution Flow. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Execution context.
Open profile →T1574.008Path Interception by Search Order Hijacking (T1574.008) is an Enterprise ATT&CK sub-technique under Hijack Execution Flow. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Execution context.
Open profile →T1574.009Path Interception by Unquoted Path (T1574.009) is an Enterprise ATT&CK sub-technique under Hijack Execution Flow. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Execution context.
Open profile →T1574.010Services File Permissions Weakness (T1574.010) is an Enterprise ATT&CK sub-technique under Hijack Execution Flow. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Execution context.
Open profile →T1574.011Services Registry Permissions Weakness (T1574.011) is an Enterprise ATT&CK sub-technique under Hijack Execution Flow. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Execution context.
Open profile →T1574.012COR_PROFILER (T1574.012) is an Enterprise ATT&CK sub-technique under Hijack Execution Flow. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Execution context.
Open profile →T1574.013KernelCallbackTable (T1574.013) is an Enterprise ATT&CK sub-technique under Hijack Execution Flow. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Execution context.
Open profile →T1574.014AppDomainManager (T1574.014) is an Enterprise ATT&CK sub-technique under Hijack Execution Flow. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth, Execution context.
Open profile →T1578Modify Cloud Compute Infrastructure (T1578) is an Enterprise ATT&CK technique associated with Defense Impairment. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1578.001Create Snapshot (T1578.001) is an Enterprise ATT&CK sub-technique under Modify Cloud Compute Infrastructure. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment context.
Open profile →T1578.002Create Cloud Instance (T1578.002) is an Enterprise ATT&CK sub-technique under Modify Cloud Compute Infrastructure. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment context.
Open profile →T1578.003Delete Cloud Instance (T1578.003) is an Enterprise ATT&CK sub-technique under Modify Cloud Compute Infrastructure. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment context.
Open profile →T1578.004Revert Cloud Instance (T1578.004) is an Enterprise ATT&CK sub-technique under Modify Cloud Compute Infrastructure. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment context.
Open profile →T1578.005Modify Cloud Compute Configurations (T1578.005) is an Enterprise ATT&CK sub-technique under Modify Cloud Compute Infrastructure. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment context.
Open profile →T1580Cloud Infrastructure Discovery (T1580) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1583An operator obtains domains, servers, cloud resources, virtual private servers, certificates, or other infrastructure used to stage or conduct malicious activity.
Open profile →T1583.001Domains (T1583.001) is an Enterprise ATT&CK sub-technique under Acquire Infrastructure. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1583.002DNS Server (T1583.002) is an Enterprise ATT&CK sub-technique under Acquire Infrastructure. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1583.003Virtual Private Server (T1583.003) is an Enterprise ATT&CK sub-technique under Acquire Infrastructure. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1583.004Server (T1583.004) is an Enterprise ATT&CK sub-technique under Acquire Infrastructure. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1583.005Botnet (T1583.005) is an Enterprise ATT&CK sub-technique under Acquire Infrastructure. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1583.006Web Services (T1583.006) is an Enterprise ATT&CK sub-technique under Acquire Infrastructure. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1583.007Serverless (T1583.007) is an Enterprise ATT&CK sub-technique under Acquire Infrastructure. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1583.008Malvertising (T1583.008) is an Enterprise ATT&CK sub-technique under Acquire Infrastructure. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1584Compromise Infrastructure (T1584) is an Enterprise ATT&CK technique associated with Resource Development. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1584.001Domains (T1584.001) is an Enterprise ATT&CK sub-technique under Compromise Infrastructure. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1584.002DNS Server (T1584.002) is an Enterprise ATT&CK sub-technique under Compromise Infrastructure. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1584.003Virtual Private Server (T1584.003) is an Enterprise ATT&CK sub-technique under Compromise Infrastructure. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1584.004Server (T1584.004) is an Enterprise ATT&CK sub-technique under Compromise Infrastructure. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1584.005Botnet (T1584.005) is an Enterprise ATT&CK sub-technique under Compromise Infrastructure. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1584.006Web Services (T1584.006) is an Enterprise ATT&CK sub-technique under Compromise Infrastructure. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1584.007Serverless (T1584.007) is an Enterprise ATT&CK sub-technique under Compromise Infrastructure. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1584.008Network Devices (T1584.008) is an Enterprise ATT&CK sub-technique under Compromise Infrastructure. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1585Establish Accounts (T1585) is an Enterprise ATT&CK technique associated with Resource Development. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1585.001Social Media Accounts (T1585.001) is an Enterprise ATT&CK sub-technique under Establish Accounts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1585.002Email Accounts (T1585.002) is an Enterprise ATT&CK sub-technique under Establish Accounts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1585.003Cloud Accounts (T1585.003) is an Enterprise ATT&CK sub-technique under Establish Accounts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1586Compromise Accounts (T1586) is an Enterprise ATT&CK technique associated with Resource Development. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1586.001Social Media Accounts (T1586.001) is an Enterprise ATT&CK sub-technique under Compromise Accounts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1586.002Email Accounts (T1586.002) is an Enterprise ATT&CK sub-technique under Compromise Accounts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1586.003Cloud Accounts (T1586.003) is an Enterprise ATT&CK sub-technique under Compromise Accounts. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1587An operator creates malware, exploits, certificates, tools, or other capabilities tailored to the intended operation.
Open profile →T1587.001Malware (T1587.001) is an Enterprise ATT&CK sub-technique under Develop Capabilities. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1587.002Code Signing Certificates (T1587.002) is an Enterprise ATT&CK sub-technique under Develop Capabilities. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1587.003Digital Certificates (T1587.003) is an Enterprise ATT&CK sub-technique under Develop Capabilities. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1587.004Exploits (T1587.004) is an Enterprise ATT&CK sub-technique under Develop Capabilities. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1588An operator purchases, steals, downloads, or otherwise acquires exploits, malware, credentials, information, or tools rather than developing them independently.
Open profile →T1588.001Malware (T1588.001) is an Enterprise ATT&CK sub-technique under Obtain Capabilities. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1588.002Tool (T1588.002) is an Enterprise ATT&CK sub-technique under Obtain Capabilities. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1588.003Code Signing Certificates (T1588.003) is an Enterprise ATT&CK sub-technique under Obtain Capabilities. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1588.004Digital Certificates (T1588.004) is an Enterprise ATT&CK sub-technique under Obtain Capabilities. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1588.005Exploits (T1588.005) is an Enterprise ATT&CK sub-technique under Obtain Capabilities. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1588.006Vulnerabilities (T1588.006) is an Enterprise ATT&CK sub-technique under Obtain Capabilities. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1588.007Artificial Intelligence (T1588.007) is an Enterprise ATT&CK sub-technique under Obtain Capabilities. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1589An operator collects names, usernames, email addresses, roles, relationships, or other identity details that can support targeting, credential attacks, and believable pretexts.
Open profile →T1589.001Credentials (T1589.001) is an Enterprise ATT&CK sub-technique under Gather Victim Identity Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1589.002Email Addresses (T1589.002) is an Enterprise ATT&CK sub-technique under Gather Victim Identity Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1589.003Employee Names (T1589.003) is an Enterprise ATT&CK sub-technique under Gather Victim Identity Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1590Gather Victim Network Information (T1590) is an Enterprise ATT&CK technique associated with Reconnaissance. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1590.001Domain Properties (T1590.001) is an Enterprise ATT&CK sub-technique under Gather Victim Network Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1590.002DNS (T1590.002) is an Enterprise ATT&CK sub-technique under Gather Victim Network Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1590.003Network Trust Dependencies (T1590.003) is an Enterprise ATT&CK sub-technique under Gather Victim Network Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1590.004Network Topology (T1590.004) is an Enterprise ATT&CK sub-technique under Gather Victim Network Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1590.005IP Addresses (T1590.005) is an Enterprise ATT&CK sub-technique under Gather Victim Network Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1590.006Network Security Appliances (T1590.006) is an Enterprise ATT&CK sub-technique under Gather Victim Network Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1591Gather Victim Org Information (T1591) is an Enterprise ATT&CK technique associated with Reconnaissance. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1591.001Determine Physical Locations (T1591.001) is an Enterprise ATT&CK sub-technique under Gather Victim Org Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1591.002Business Relationships (T1591.002) is an Enterprise ATT&CK sub-technique under Gather Victim Org Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1591.003Identify Business Tempo (T1591.003) is an Enterprise ATT&CK sub-technique under Gather Victim Org Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1591.004Identify Roles (T1591.004) is an Enterprise ATT&CK sub-technique under Gather Victim Org Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1592Gather Victim Host Information (T1592) is an Enterprise ATT&CK technique associated with Reconnaissance. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1592.001Hardware (T1592.001) is an Enterprise ATT&CK sub-technique under Gather Victim Host Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1592.002Software (T1592.002) is an Enterprise ATT&CK sub-technique under Gather Victim Host Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1592.003Firmware (T1592.003) is an Enterprise ATT&CK sub-technique under Gather Victim Host Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1592.004Client Configurations (T1592.004) is an Enterprise ATT&CK sub-technique under Gather Victim Host Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1593An operator searches public websites, social platforms, code repositories, technical forums, and organizational domains for information useful to an operation.
Open profile →T1593.001Social Media (T1593.001) is an Enterprise ATT&CK sub-technique under Search Open Websites/Domains. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1593.002Search Engines (T1593.002) is an Enterprise ATT&CK sub-technique under Search Open Websites/Domains. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1593.003Code Repositories (T1593.003) is an Enterprise ATT&CK sub-technique under Search Open Websites/Domains. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1594Search Victim-Owned Websites (T1594) is an Enterprise ATT&CK technique associated with Reconnaissance. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1595Attack surface management identifies and tracks the systems, services, identities, data paths, and external dependencies that an attacker could reach or influence.
Open profile →T1595An operator actively probes addresses, domains, services, applications, or network ranges to learn what is reachable and how it may be exposed.
Open profile →T1595.001Scanning IP Blocks (T1595.001) is an Enterprise ATT&CK sub-technique under Active Scanning. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1595.002Vulnerability Scanning (T1595.002) is an Enterprise ATT&CK sub-technique under Active Scanning. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1595.002Vulnerability scanning uses automated checks to identify known weaknesses, missing updates, unsafe configurations, exposed services, and other conditions that may require review.
Open profile →T1595.003Wordlist Scanning (T1595.003) is an Enterprise ATT&CK sub-technique under Active Scanning. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1596Search Open Technical Databases (T1596) is an Enterprise ATT&CK technique associated with Reconnaissance. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1596.001DNS/Passive DNS (T1596.001) is an Enterprise ATT&CK sub-technique under Search Open Technical Databases. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1596.002WHOIS (T1596.002) is an Enterprise ATT&CK sub-technique under Search Open Technical Databases. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1596.003Digital Certificates (T1596.003) is an Enterprise ATT&CK sub-technique under Search Open Technical Databases. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1596.004CDNs (T1596.004) is an Enterprise ATT&CK sub-technique under Search Open Technical Databases. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1596.005Scan Databases (T1596.005) is an Enterprise ATT&CK sub-technique under Search Open Technical Databases. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1597Search Closed Sources (T1597) is an Enterprise ATT&CK technique associated with Reconnaissance. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1597.001Threat Intel Vendors (T1597.001) is an Enterprise ATT&CK sub-technique under Search Closed Sources. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1597.002Purchase Technical Data (T1597.002) is an Enterprise ATT&CK sub-technique under Search Closed Sources. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1598Phishing for Information (T1598) is an Enterprise ATT&CK technique associated with Reconnaissance. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1598.001Spearphishing Service (T1598.001) is an Enterprise ATT&CK sub-technique under Phishing for Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1598.002Spearphishing Attachment (T1598.002) is an Enterprise ATT&CK sub-technique under Phishing for Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1598.003Spearphishing Link (T1598.003) is an Enterprise ATT&CK sub-technique under Phishing for Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1598.004Spearphishing Voice (T1598.004) is an Enterprise ATT&CK sub-technique under Phishing for Information. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Reconnaissance context.
Open profile →T1599Network Boundary Bridging (T1599) is an Enterprise ATT&CK technique associated with Defense Impairment. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1599.001Network Address Translation Traversal (T1599.001) is an Enterprise ATT&CK sub-technique under Network Boundary Bridging. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment context.
Open profile →T1600Weaken Encryption (T1600) is an Enterprise ATT&CK technique associated with Defense Impairment. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1600.001Reduce Key Space (T1600.001) is an Enterprise ATT&CK sub-technique under Weaken Encryption. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment context.
Open profile →T1600.002Disable Crypto Hardware (T1600.002) is an Enterprise ATT&CK sub-technique under Weaken Encryption. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment context.
Open profile →T1601Modify System Image (T1601) is an Enterprise ATT&CK technique associated with Defense Impairment. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1601.001Patch System Image (T1601.001) is an Enterprise ATT&CK sub-technique under Modify System Image. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment context.
Open profile →T1601.002Downgrade System Image (T1601.002) is an Enterprise ATT&CK sub-technique under Modify System Image. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment context.
Open profile →T1602Data from Configuration Repository (T1602) is an Enterprise ATT&CK technique associated with Collection. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1602.001SNMP (MIB Dump) (T1602.001) is an Enterprise ATT&CK sub-technique under Data from Configuration Repository. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Collection context.
Open profile →T1602.002Network Device Configuration Dump (T1602.002) is an Enterprise ATT&CK sub-technique under Data from Configuration Repository. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Collection context.
Open profile →T1606Forge Web Credentials (T1606) is an Enterprise ATT&CK technique associated with Credential Access. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1606.001Web Cookies (T1606.001) is an Enterprise ATT&CK sub-technique under Forge Web Credentials. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1606.002SAML Tokens (T1606.002) is an Enterprise ATT&CK sub-technique under Forge Web Credentials. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.
Open profile →T1608Stage Capabilities (T1608) is an Enterprise ATT&CK technique associated with Resource Development. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1608.001Upload Malware (T1608.001) is an Enterprise ATT&CK sub-technique under Stage Capabilities. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1608.002Upload Tool (T1608.002) is an Enterprise ATT&CK sub-technique under Stage Capabilities. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1608.003Install Digital Certificate (T1608.003) is an Enterprise ATT&CK sub-technique under Stage Capabilities. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1608.004Drive-by Target (T1608.004) is an Enterprise ATT&CK sub-technique under Stage Capabilities. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1608.005Link Target (T1608.005) is an Enterprise ATT&CK sub-technique under Stage Capabilities. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1608.006SEO Poisoning (T1608.006) is an Enterprise ATT&CK sub-technique under Stage Capabilities. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1609Container Administration Command (T1609) is an Enterprise ATT&CK technique associated with Execution. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1610Deploy Container (T1610) is an Enterprise ATT&CK technique associated with Execution. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1611Escape to Host (T1611) is an Enterprise ATT&CK technique associated with Privilege Escalation. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1612Build Image on Host (T1612) is an Enterprise ATT&CK technique associated with Stealth. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1613Container and Resource Discovery (T1613) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1614System Location Discovery (T1614) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1614.001System Language Discovery (T1614.001) is an Enterprise ATT&CK sub-technique under System Location Discovery. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Discovery context.
Open profile →T1615Group Policy Discovery (T1615) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1619Cloud Storage Object Discovery (T1619) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1620Reflective Code Loading (T1620) is an Enterprise ATT&CK technique associated with Stealth. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1621Multi-Factor Authentication Request Generation (T1621) is an Enterprise ATT&CK technique associated with Credential Access. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1622Debugger Evasion (T1622) is an Enterprise ATT&CK technique associated with Stealth, Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1647Plist File Modification (T1647) is an Enterprise ATT&CK technique associated with Defense Impairment. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1648Serverless Execution (T1648) is an Enterprise ATT&CK technique associated with Execution. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1649Steal or Forge Authentication Certificates (T1649) is an Enterprise ATT&CK technique associated with Credential Access. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1650Acquire Access (T1650) is an Enterprise ATT&CK technique associated with Resource Development. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1651Cloud Administration Command (T1651) is an Enterprise ATT&CK technique associated with Execution. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1652Device Driver Discovery (T1652) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1653Power Settings (T1653) is an Enterprise ATT&CK technique associated with Persistence. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1654Log Enumeration (T1654) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1657Financial Theft (T1657) is an Enterprise ATT&CK technique associated with Impact. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1659Content Injection (T1659) is an Enterprise ATT&CK technique associated with Initial Access, Command and Control. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1665Hide Infrastructure (T1665) is an Enterprise ATT&CK technique associated with Command and Control. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1666Modify Cloud Resource Hierarchy (T1666) is an Enterprise ATT&CK technique associated with Defense Impairment. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1667Email Bombing (T1667) is an Enterprise ATT&CK technique associated with Impact. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1668Exclusive Control (T1668) is an Enterprise ATT&CK technique associated with Persistence. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1669Wi-Fi Networks (T1669) is an Enterprise ATT&CK technique associated with Initial Access. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1671Cloud Application Integration (T1671) is an Enterprise ATT&CK technique associated with Persistence. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1673Virtual Machine Discovery (T1673) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1674Input Injection (T1674) is an Enterprise ATT&CK technique associated with Execution. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1675ESXi Administration Command (T1675) is an Enterprise ATT&CK technique associated with Execution. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1677Poisoned Pipeline Execution (T1677) is an Enterprise ATT&CK technique associated with Execution. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1678Delay Execution (T1678) is an Enterprise ATT&CK technique associated with Stealth. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1679Selective Exclusion (T1679) is an Enterprise ATT&CK technique associated with Stealth. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1680Local Storage Discovery (T1680) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1681Search Threat Vendor Data (T1681) is an Enterprise ATT&CK technique associated with Reconnaissance. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1682Query Public AI Services (T1682) is an Enterprise ATT&CK technique associated with Reconnaissance. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1683Generate Content (T1683) is an Enterprise ATT&CK technique associated with Resource Development. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1683.001Written Content (T1683.001) is an Enterprise ATT&CK sub-technique under Generate Content. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1683.002Audio-Visual Content (T1683.002) is an Enterprise ATT&CK sub-technique under Generate Content. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Resource Development context.
Open profile →T1684Social Engineering (T1684) is an Enterprise ATT&CK technique associated with Stealth. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1684Social engineering manipulates trust, urgency, authority, fear, helpfulness, or curiosity to influence a person into taking an unsafe action.
Open profile →T1684.001Impersonation (T1684.001) is an Enterprise ATT&CK sub-technique under Social Engineering. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1684.002Email Spoofing (T1684.002) is an Enterprise ATT&CK sub-technique under Social Engineering. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Stealth context.
Open profile →T1685Disable or Modify Tools (T1685) is an Enterprise ATT&CK technique associated with Defense Impairment. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1685.001Disable or Modify Windows Event Log (T1685.001) is an Enterprise ATT&CK sub-technique under Disable or Modify Tools. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment context.
Open profile →T1685.002Disable or Modify Cloud Log (T1685.002) is an Enterprise ATT&CK sub-technique under Disable or Modify Tools. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment context.
Open profile →T1685.003Modify or Spoof Tool UI (T1685.003) is an Enterprise ATT&CK sub-technique under Disable or Modify Tools. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment context.
Open profile →T1685.004Disable or Modify Linux Audit System Log (T1685.004) is an Enterprise ATT&CK sub-technique under Disable or Modify Tools. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment context.
Open profile →T1685.005Clear Windows Event Logs (T1685.005) is an Enterprise ATT&CK sub-technique under Disable or Modify Tools. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment context.
Open profile →T1685.006Clear Linux or Mac System Logs (T1685.006) is an Enterprise ATT&CK sub-technique under Disable or Modify Tools. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment context.
Open profile →T1686Disable or Modify System Firewall (T1686) is an Enterprise ATT&CK technique associated with Defense Impairment. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1686.001Cloud Firewall (T1686.001) is an Enterprise ATT&CK sub-technique under Disable or Modify System Firewall. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment context.
Open profile →T1686.002Network Device Firewall (T1686.002) is an Enterprise ATT&CK sub-technique under Disable or Modify System Firewall. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment context.
Open profile →T1686.003Host firewall policy limits inbound, outbound, and forwarded traffic at the workload boundary using explicit service intent, stateful rules, controlled administration, and verified persistence.
Open profile →T1686.003Windows Host Firewall (T1686.003) is an Enterprise ATT&CK sub-technique under Disable or Modify System Firewall. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Defense Impairment context.
Open profile →T1686.003Stateful and Stateless Firewalls is a cybersecurity concept used to describe, protect, analyze, or operate an important part of a modern information environment.
Open profile →T1686.003Windows Defender Firewall is a stateful host firewall that applies profile-aware inbound and outbound rules to programs, services, ports, protocols, interfaces, users, and network conditions.
Open profile →T1687Exploitation for Defense Impairment (T1687) is an Enterprise ATT&CK technique associated with Defense Impairment. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1688Safe Mode Boot (T1688) is an Enterprise ATT&CK technique associated with Defense Impairment. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1689Downgrade Attack (T1689) is an Enterprise ATT&CK technique associated with Defense Impairment. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →T1690Prevent Command History Logging (T1690) is an Enterprise ATT&CK technique associated with Defense Impairment. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.
Open profile →