-
Technique
Confidence 100
windows
macos
MITRE
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug,…
· Source: The MITRE Corporation
-
Technique
Confidence 100
windows
MITRE
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key. Adding an entry to the "run keys" in…
· Source: The MITRE Corporation
-
Technique
Confidence 100
windows
macos
MITRE
Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by an adversary…
· Source: The MITRE Corporation
-
Technique
Confidence 100
windows
MITRE
Adversaries may abuse dynamic-link library files (DLLs) in order to achieve persistence, escalate privileges, and evade defenses. DLLs are libraries that contain code and data that can be…
· Source: The MITRE Corporation
-
Technique
Confidence 100
windows
macos
MITRE
Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries. Binaries used in this technique are often Microsoft-signed files,…
· Source: The MITRE Corporation
-
Technique
Confidence 100
windows
macos
MITRE
Adversaries may abuse Visual Basic (VB) for execution. VB is a programming language created by Microsoft with interoperability with many Windows technologies such as [Component Object Model](https://attack.mitre.org/techniques/T1559/001) and…
· Source: The MITRE Corporation
-
Technique
Confidence 100
windows
macos
MITRE
An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open…
· Source: The MITRE Corporation
-
Technique
Confidence 100
PRE
MITRE
Adversaries may acquire domains that can be used during targeting. Domain names are the human readable names used to represent one or more IP addresses. They can be…
· Source: The MITRE Corporation
-
Technique
Confidence 100
windows
macos
MITRE
Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems. Spearphishing attachment is a specific variant of spearphishing. Spearphishing attachment…
· Source: The MITRE Corporation
-
Technique
Confidence 100
windows
macos
MITRE
Adversaries may use [Obfuscated Files or Information](https://attack.mitre.org/techniques/T1027) to hide artifacts of an intrusion from analysis. They may require separate mechanisms to decode or deobfuscate that information depending on…
· Source: The MITRE Corporation
-
Technique
Confidence 100
windows
macos
MITRE
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them. This is done for the sake of evading…
· Source: The MITRE Corporation
-
Technique
Confidence 100
windows
macos
MITRE
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often…
· Source: The MITRE Corporation
-
Technique
Confidence 100
windows
macos
MITRE
Adversaries may use an internal proxy to direct command and control traffic between two or more systems in a compromised environment. Many tools exist that enable traffic redirection…
· Source: The MITRE Corporation
-
Technique
Confidence 100
windows
macos
MITRE
Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol. Symmetric encryption…
· Source: The MITRE Corporation
-
Technique
Confidence 100
PRE
MITRE
Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target host/application (ex: software and version) potentially…
· Source: The MITRE Corporation