Knowledge is Power

Sitewide Search

Search Bare Metal Cyber

Search exact control and technique identifiers, Cyber Wiki articles, framework records, playbooks, books, podcasts, Academy courses, and individual lessons.

Threat-Informed Defense

Browse adversary behavior through a defensive lens.

Find active technique and sub-technique profiles by ATT&CK ID, behavior name, tactic, or platform.

T1001

Data Obfuscation (T1001)

Data Obfuscation (T1001) is an Enterprise ATT&CK technique associated with Command and Control. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.

Open profile →
T1001.001

Junk Data (T1001.001)

Junk Data (T1001.001) is an Enterprise ATT&CK sub-technique under Data Obfuscation. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.

Open profile →
T1001.002

Steganography (T1001.002)

Steganography (T1001.002) is an Enterprise ATT&CK sub-technique under Data Obfuscation. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.

Open profile →
T1001.003

Protocol or Service Impersonation (T1001.003)

Protocol or Service Impersonation (T1001.003) is an Enterprise ATT&CK sub-technique under Data Obfuscation. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Command and Control context.

Open profile →
T1003

Windows Credential Guard

Windows Credential Guard uses virtualization-based security to isolate selected domain credentials from the normal operating system so that compromise of the host is less likely to expose reusable NTLM hashes and Kerberos ticket-granting tickets.

Open profile →
T1003.001

LSASS and Credential Protection

The Local Security Authority Subsystem Service enforces local security policy, validates certain logons, creates access tokens, and handles credential material; protecting LSASS is central to limiting credential theft from Windows endpoints.

Open profile →
T1003.001

LSASS Memory (T1003.001)

LSASS Memory (T1003.001) is an Enterprise ATT&CK sub-technique under OS Credential Dumping. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.

Open profile →
T1003.002

Security Account Manager (T1003.002)

Security Account Manager (T1003.002) is an Enterprise ATT&CK sub-technique under OS Credential Dumping. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.

Open profile →
T1003.003

NTDS (T1003.003)

NTDS (T1003.003) is an Enterprise ATT&CK sub-technique under OS Credential Dumping. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.

Open profile →
T1003.004

LSA Secrets (T1003.004)

LSA Secrets (T1003.004) is an Enterprise ATT&CK sub-technique under OS Credential Dumping. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.

Open profile →
T1003.005

Cached Domain Credentials (T1003.005)

Cached Domain Credentials (T1003.005) is an Enterprise ATT&CK sub-technique under OS Credential Dumping. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.

Open profile →
T1003.006

DCSync

DCSync is an abuse of Active Directory replication rights in which an attacker makes a system act like a domain controller and requests password-derived credential data through normal directory replication protocols.

Open profile →
T1003.006

DCSync (T1003.006)

DCSync (T1003.006) is an Enterprise ATT&CK sub-technique under OS Credential Dumping. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.

Open profile →
T1003.007

Proc Filesystem (T1003.007)

Proc Filesystem (T1003.007) is an Enterprise ATT&CK sub-technique under OS Credential Dumping. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.

Open profile →
T1003.008

/etc/passwd and /etc/shadow (T1003.008)

/etc/passwd and /etc/shadow (T1003.008) is an Enterprise ATT&CK sub-technique under OS Credential Dumping. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Credential Access context.

Open profile →
T1006

Direct Volume Access (T1006)

Direct Volume Access (T1006) is an Enterprise ATT&CK technique associated with Stealth. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.

Open profile →
T1007

System Service Discovery (T1007)

System Service Discovery (T1007) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.

Open profile →
T1008

Fallback Channels (T1008)

Fallback Channels (T1008) is an Enterprise ATT&CK technique associated with Command and Control. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.

Open profile →
T1010

Application Window Discovery (T1010)

Application Window Discovery (T1010) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.

Open profile →
T1011

Exfiltration Over Other Network Medium (T1011)

Exfiltration Over Other Network Medium (T1011) is an Enterprise ATT&CK technique associated with Exfiltration. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.

Open profile →
T1011.001

Exfiltration Over Bluetooth (T1011.001)

Exfiltration Over Bluetooth (T1011.001) is an Enterprise ATT&CK sub-technique under Exfiltration Over Other Network Medium. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Exfiltration context.

Open profile →
T1012

Query Registry (T1012)

Query Registry (T1012) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.

Open profile →
T1014

Rootkit (T1014)

Rootkit (T1014) is an Enterprise ATT&CK technique associated with Stealth. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.

Open profile →
T1016.001

Internet Connection Discovery (T1016.001)

Internet Connection Discovery (T1016.001) is an Enterprise ATT&CK sub-technique under System Network Configuration Discovery. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Discovery context.

Open profile →
T1016.002

Wi-Fi Discovery (T1016.002)

Wi-Fi Discovery (T1016.002) is an Enterprise ATT&CK sub-technique under System Network Configuration Discovery. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Discovery context.

Open profile →
T1018

Remote System Discovery (T1018)

Remote System Discovery (T1018) is an Enterprise ATT&CK technique associated with Discovery. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.

Open profile →
T1020

Automated Exfiltration (T1020)

Automated Exfiltration (T1020) is an Enterprise ATT&CK technique associated with Exfiltration. This Bare Metal Cyber profile explains the behavior in plain language and focuses on evidence, detection, defensive design, response, and safe learning.

Open profile →
T1020.001

Traffic Duplication (T1020.001)

Traffic Duplication (T1020.001) is an Enterprise ATT&CK sub-technique under Automated Exfiltration. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Exfiltration context.

Open profile →
T1021

Lateral Movement

Lateral movement is the use of credentials, remote services, trust relationships, and administrative tools to move from one system or account to another.

Open profile →
T1021.001

Remote Desktop Protocol (T1021.001)

Remote Desktop Protocol (T1021.001) is an Enterprise ATT&CK sub-technique under Remote Services. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Lateral Movement context.

Open profile →
T1021.001

Remote Desktop Security

Remote Desktop security protects Windows interactive administrative sessions by controlling who can connect, how endpoints authenticate, where credentials are exposed, which channels are redirected, and how activity is monitored and contained.

Open profile →
T1021.002

SMB/Windows Admin Shares (T1021.002)

SMB/Windows Admin Shares (T1021.002) is an Enterprise ATT&CK sub-technique under Remote Services. This Bare Metal Cyber profile explains how defenders can recognize, investigate, limit, and safely study the behavior within the Lateral Movement context.

Open profile →

Framework metadata remains source-controlled by MITRE.

Bare Metal Cyber profiles add original educational and defensive context. Verify current object status, relationships, and underlying references on the official ATT&CK site before using a profile for operational or attribution decisions.

MITRE ATT&CK® and ATT&CK® are registered trademarks of The MITRE Corporation. Bare Metal Cyber is not affiliated with or endorsed by MITRE.