Activity timeline
T1211 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 150 reports, and 278 of the 278 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1211 Exploitation for Stealth is catalogued by MITRE ATT&CK under the Stealth (formerly Defense Evasion) tactic in the Enterprise matrix. Threadlinqs maps 278 of 2623 tracked threats (10.6%) to it; by severity that is 154 critical, 110 high, 11 medium.
Threats that use T1211 most often also use T1068 Exploitation for Privilege Escalation (229 threats), T1190 Exploit Public-Facing Application (191 threats), T1005 Data from Local System (157 threats), T1082 System Information Discovery (151 threats), T1059 Command and Scripting Interpreter (144 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
26 tracked threat actors appear in the threats that use T1211; the most frequent are The Gentlemen (4), Chaotic Eclipse (2), Gamaredon (2), Nightmare Eclipse (2), Storm-2603 (2).
Mitigations
MITRE ATT&CK lists 4 mitigations for T1211.
Data sources
Telemetry that can reveal T1211, per MITRE ATT&CK.
- Application Log — Application Log Content
- Process — Process Creation
Threat actors using it
Tracked threats
The 30 most recent of 278 tracked threats that use T1211.
- Multiple High-Severity Vulnerabilities in TeamViewer Client (CVE-2026-92370, CVE-2026-92368, CVE-2026-92369…high
- CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalogcritical
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- Two Unpatched Citrix NetScaler Zero-Day RCE Vulnerabilities Under Active Exploitationcritical
- CISA Adds Four Actively Exploited KEVs: Check Point Gateway/Management RCE Flaws, Arista VeloCloud…critical
- Elementor Website Builder CSRF Flaw (CVE-2026-62062) Allows Attacker-Controlled WordPress Admin Account…high
- CISA Adds Two Actively Exploited KEVs: SharePoint Code Injection (CVE-2026-65660) and Mikrotik RouterOS Auth…critical
- Multiple Vulnerabilities in Google Chrome Patched in Stable Channel Update 154.0.8037.57 (GovCERT.HK…medium
- CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for…critical
- SolarWinds Access Rights Manager Hard-Coded Cryptographic Key (CVE-2026-28326) Enables Unauthenticated RCEcritical
- CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables…critical
- Critical Pre-Auth RCE in Orkes Conductor Workflow Platform (CVE-2026-58138) Exploited in the Wildcritical
- AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)high
- GitLab Patches Max-Severity Unauthenticated Path Traversal Flaw in Repository Commits API (CVE-2026-85706…critical
- Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880…critical
- Broadcom Patches Critical VMware Workstation and Fusion VM Escape Vulnerabilities (CVE-2026-59346…critical
- Google Patches Chrome Zero-Day CVE-2026-85046 (6th of 2026), Actively Exploited V8 Type Confusionhigh
- Unisoc T612/T606/T7250 Modem Exploit Chain: Malicious VoLTE Video Call Enables Full Android Kernel Access…high
- ServiceNow Patches Four Critical Flaws Including Three CVSS 10.0 Unauthenticated RCE/SQLi Bugs…critical
- PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitationcritical
- Critical Avada WordPress Theme Flaw (CVE-2026-18431) Enables Zero-Click RCEcritical
- Critical Type Confusion in isolated-vm (GHSA-864f-rcv7-6rh4) Enables Sandbox Escape and RCE on Hostcritical
- CVE-2026-69836: Unauthenticated Remote Code Execution in Microsoft Entra ID via Deserialization of Untrusted…critical
- Gogs Critical RCE via Path Traversal in Organization Names (CVE-2026-52813)critical
- CVE-2026-19490 — Critical Authentication Bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) with…critical
- Critical GitLab GraphQL Flaw (CVE-2026-19478, CVSS 9.4) Could Let Unauthenticated Attackers Delete Public…critical
- AmnesiaStealer: macOS Infostealer Hijacks Live Browser Sessions via Chrome DevTools Protocol Remote Controlhigh
- Adobe Patches Critical RCE Flaws in ColdFusion, Campaign Classic, and Commerce (CVE-2026-48362, CVSS 10.0)critical
- SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities (CVE-2026-58231, CVSS 10.0)critical
- SCTPhantom (CVE-2026-64564): 18-Year-Old Use-After-Free in Linux Kernel SCTP ASCONF Handling Enables Local…high
Detection coverage
Threadlinqs maintains 309 detection rules mapped to T1211 (SPL 86, KQL 106, Sigma 115, other 2). Rule content is available to Blue tier accounts and above; this page shows counts only.