Reconnaissance
22 techniques under Reconnaissance, most-observed first.
- T1595 Active Scanning340 threats
- T1589 Gather Victim Identity Information228 threats
- T1595.002 Vulnerability Scanning207 threats
- T1592 Gather Victim Host Information153 threats
- T1590 Gather Victim Network Information99 threats
- T1598 Phishing for Information98 threats
- T1596 Search Open Technical Databases95 threats
- T1591 Gather Victim Org Information92 threats
- T1593 Search Open Websites/Domains79 threats
- T1592.002 Software68 threats
- T1589.002 Email Addresses51 threats
- T1598.003 Spearphishing Link41 threats
- T1594 Search Victim-Owned Websites38 threats
- T1595.001 Scanning IP Blocks35 threats
- T1589.001 Credentials30 threats
- T1596.005 Scan Databases26 threats
- T1598.004 Spearphishing Voice18 threats
- T1592.004 Client Configurations17 threats
- T1591.004 Identify Roles16 threats
- T1589.003 Employee Names12 threats
- T1593.001 Social Media11 threats
- T1593.003 Code Repositories10 threats
Resource Development
36 techniques under Resource Development, most-observed first.
- T1583 Acquire Infrastructure611 threats
- T1587 Develop Capabilities402 threats
- T1588 Obtain Capabilities363 threats
- T1583.001 Domains314 threats
- T1585 Establish Accounts250 threats
- T1608 Stage Capabilities250 threats
- T1587.001 Malware210 threats
- T1583.006 Web Services178 threats
- T1584 Compromise Infrastructure164 threats
- T1588.002 Tool153 threats
- T1608.001 Upload Malware142 threats
- T1586 Compromise Accounts140 threats
- T1588.005 Exploits129 threats
- T1588.006 Vulnerabilities125 threats
- T1587.004 Exploits122 threats
- T1585.001 Social Media Accounts87 threats
- T1583.003 Virtual Private Server72 threats
- T1583.004 Server67 threats
- T1585.002 Email Accounts53 threats
- T1584.004 Server41 threats
- T1608.005 Link Target39 threats
- T1588.001 Malware38 threats
- T1583.008 Malvertising35 threats
- T1586.002 Email Accounts32 threats
- T1584.001 Domains25 threats
- T1584.006 Web Services25 threats
- T1608.006 SEO Poisoning25 threats
- T1650 Acquire Access25 threats
- T1588.003 Code Signing Certificates21 threats
- T1588.007 Artificial Intelligence21 threats
- T1583.005 Botnet19 threats
- T1608.004 Drive-by Target18 threats
- T1585.003 Cloud Accounts17 threats
- T1584.005 Botnet12 threats
- T1584.008 Network Devices11 threats
- T1608.002 Upload Tool11 threats
Initial Access
20 techniques under Initial Access, most-observed first.
- T1190 Exploit Public-Facing Application958 threats
- T1078 Valid Accounts718 threats
- T1566 Phishing641 threats
- T1195 Supply Chain Compromise333 threats
- T1199 Trusted Relationship319 threats
- T1566.002 Spearphishing Link308 threats
- T1133 External Remote Services307 threats
- T1189 Drive-by Compromise276 threats
- T1566.001 Spearphishing Attachment194 threats
- T1195.002 Compromise Software Supply Chain166 threats
- T1078.004 Cloud Accounts134 threats
- T1195.001 Compromise Software Dependencies and Development Tools90 threats
- T1566.003 Spearphishing via Service62 threats
- T1566.004 Spearphishing Voice50 threats
- T1078.002 Domain Accounts42 threats
- T1078.003 Local Accounts38 threats
- T1091 Replication Through Removable Media38 threats
- T1078.001 Default Accounts32 threats
- T1200 Hardware Additions16 threats
- T1195.003 Compromise Hardware Supply Chain15 threats
Execution
32 techniques under Execution, most-observed first.
- T1059 Command and Scripting Interpreter1050 threats
- T1204 User Execution571 threats
- T1204.002 Malicious File445 threats
- T1203 Exploitation for Client Execution363 threats
- T1059.001 PowerShell342 threats
- T1106 Native API308 threats
- T1059.004 Unix Shell276 threats
- T1053 Scheduled Task/Job271 threats
- T1059.007 JavaScript241 threats
- T1204.001 Malicious Link218 threats
- T1053.005 Scheduled Task216 threats
- T1574 Hijack Execution Flow214 threats
- T1059.003 Windows Command Shell205 threats
- T1059.006 Python150 threats
- T1574.001 DLL150 threats
- T1047 Windows Management Instrumentation104 threats
- T1059.005 Visual Basic75 threats
- T1129 Shared Modules68 threats
- T1569 System Services66 threats
- T1053.003 Cron61 threats
- T1204.004 Malicious Copy and Paste59 threats
- T1569.002 Service Execution57 threats
- T1559 Inter-Process Communication41 threats
- T1610 Deploy Container39 threats
- T1072 Software Deployment Tools30 threats
- T1059.002 AppleScript29 threats
- T1127 Trusted Developer Utilities Proxy Execution18 threats
- T1574.006 Dynamic Linker Hijacking15 threats
- T1609 Container Administration Command15 threats
- T1648 Serverless Execution13 threats
- T1204.003 Malicious Image11 threats
- T1559.001 Component Object Model10 threats
Persistence
43 techniques under Persistence, most-observed first.
- T1078 Valid Accounts718 threats
- T1547 Boot or Logon Autostart Execution349 threats
- T1133 External Remote Services307 threats
- T1098 Account Manipulation288 threats
- T1053 Scheduled Task/Job271 threats
- T1505 Server Software Component265 threats
- T1547.001 Registry Run Keys / Startup Folder242 threats
- T1543 Create or Modify System Process232 threats
- T1053.005 Scheduled Task216 threats
- T1112 Modify Registry183 threats
- T1505.003 Web Shell170 threats
- T1136 Create Account152 threats
- T1556 Modify Authentication Process147 threats
- T1546 Event Triggered Execution145 threats
- T1078.004 Cloud Accounts134 threats
- T1554 Compromise Host Software Binary82 threats
- T1543.003 Windows Service78 threats
- T1176 Software Extensions75 threats
- T1136.001 Local Account73 threats
- T1053.003 Cron61 threats
- T1543.001 Launch Agent57 threats
- T1543.002 Systemd Service49 threats
- T1078.002 Domain Accounts42 threats
- T1078.003 Local Accounts38 threats
- T1078.001 Default Accounts32 threats
- T1098.001 Additional Cloud Credentials32 threats
- T1037 Boot or Logon Initialization Scripts29 threats
- T1098.005 Device Registration28 threats
- T1546.004 Unix Shell Configuration Modification28 threats
- T1542 Pre-OS Boot23 threats
- T1205 Traffic Signaling22 threats
- T1556.006 Multi-Factor Authentication22 threats
- T1137 Office Application Startup20 threats
- T1098.003 Additional Cloud Roles19 threats
- T1037.004 RC Scripts18 threats
- T1098.004 SSH Authorized Keys17 threats
- T1136.002 Domain Account17 threats
- T1525 Implant Internal Image15 threats
- T1546.015 Component Object Model Hijacking15 threats
- T1547.006 Kernel Modules and Extensions15 threats
- T1543.004 Launch Daemon14 threats
- T1547.009 Shortcut Modification11 threats
- T1547.013 XDG Autostart Entries10 threats
Privilege Escalation
43 techniques under Privilege Escalation, most-observed first.
- T1078 Valid Accounts718 threats
- T1068 Exploitation for Privilege Escalation503 threats
- T1547 Boot or Logon Autostart Execution349 threats
- T1098 Account Manipulation288 threats
- T1548 Abuse Elevation Control Mechanism281 threats
- T1053 Scheduled Task/Job271 threats
- T1055 Process Injection269 threats
- T1547.001 Registry Run Keys / Startup Folder242 threats
- T1543 Create or Modify System Process232 threats
- T1053.005 Scheduled Task216 threats
- T1546 Event Triggered Execution145 threats
- T1078.004 Cloud Accounts134 threats
- T1611 Escape to Host97 threats
- T1134 Access Token Manipulation83 threats
- T1543.003 Windows Service78 threats
- T1548.002 Bypass User Account Control78 threats
- T1053.003 Cron61 threats
- T1543.001 Launch Agent57 threats
- T1055.012 Process Hollowing51 threats
- T1543.002 Systemd Service49 threats
- T1078.002 Domain Accounts42 threats
- T1078.003 Local Accounts38 threats
- T1078.001 Default Accounts32 threats
- T1098.001 Additional Cloud Credentials32 threats
- T1484 Domain or Tenant Policy Modification30 threats
- T1037 Boot or Logon Initialization Scripts29 threats
- T1098.005 Device Registration28 threats
- T1546.004 Unix Shell Configuration Modification28 threats
- T1548.001 Setuid and Setgid26 threats
- T1055.001 Dynamic-link Library Injection25 threats
- T1548.003 Sudo and Sudo Caching24 threats
- T1098.003 Additional Cloud Roles19 threats
- T1134.001 Token Impersonation/Theft19 threats
- T1037.004 RC Scripts18 threats
- T1098.004 SSH Authorized Keys17 threats
- T1055.004 Asynchronous Procedure Call15 threats
- T1546.015 Component Object Model Hijacking15 threats
- T1547.006 Kernel Modules and Extensions15 threats
- T1484.001 Group Policy Modification14 threats
- T1543.004 Launch Daemon14 threats
- T1134.002 Create Process with Token13 threats
- T1547.009 Shortcut Modification11 threats
- T1547.013 XDG Autostart Entries10 threats
Stealth (formerly Defense Evasion)
61 techniques under Stealth (formerly Defense Evasion), most-observed first.
- T1027 Obfuscated Files or Information1177 threats
- T1036 Masquerading845 threats
- T1140 Deobfuscate/Decode Files or Information720 threats
- T1078 Valid Accounts718 threats
- T1036.005 Match Legitimate Resource Name or Location475 threats
- T1070 Indicator Removal432 threats
- T1497 Virtualization/Sandbox Evasion282 threats
- T1211 Exploitation for Stealth278 threats
- T1055 Process Injection269 threats
- T1620 Reflective Code Loading242 threats
- T1684.001 Impersonation228 threats
- T1574 Hijack Execution Flow214 threats
- T1070.004 File Deletion207 threats
- T1564 Hide Artifacts174 threats
- T1218 System Binary Proxy Execution170 threats
- T1574.001 DLL150 threats
- T1078.004 Cloud Accounts134 threats
- T1497.001 System Checks131 threats
- T1564.001 Hidden Files and Directories84 threats
- T1134 Access Token Manipulation83 threats
- T1014 Rootkit81 threats
- T1622 Debugger Evasion79 threats
- T1027.002 Software Packing77 threats
- T1027.013 Encrypted/Encoded File69 threats
- T1480 Execution Guardrails63 threats
- T1055.012 Process Hollowing51 threats
- T1078.002 Domain Accounts42 threats
- T1027.003 Steganography40 threats
- T1078.003 Local Accounts38 threats
- T1070.006 Timestomp37 threats
- T1218.005 Mshta37 threats
- T1218.007 Msiexec37 threats
- T1564.003 Hidden Window37 threats
- T1078.001 Default Accounts32 threats
- T1027.010 Command Obfuscation31 threats
- T1497.003 Time Based Checks31 threats
- T1218.011 Rundll3230 threats
- T1036.004 Masquerade Task or Service25 threats
- T1055.001 Dynamic-link Library Injection25 threats
- T1036.008 Masquerade File Type24 threats
- T1542 Pre-OS Boot23 threats
- T1036.003 Rename Legitimate Utilities22 threats
- T1205 Traffic Signaling22 threats
- T1070.003 Clear Command History21 threats
- T1202 Indirect Command Execution21 threats
- T1134.001 Token Impersonation/Theft19 threats
- T1127 Trusted Developer Utilities Proxy Execution18 threats
- T1027.004 Compile After Delivery17 threats
- T1027.009 Embedded Payloads15 threats
- T1055.004 Asynchronous Procedure Call15 threats
- T1574.006 Dynamic Linker Hijacking15 threats
- T1027.001 Binary Padding14 threats
- T1218.010 Regsvr3214 threats
- T1480.001 Environmental Keying14 threats
- T1027.007 Dynamic API Resolution13 threats
- T1036.001 Invalid Code Signature13 threats
- T1036.007 Double File Extension13 threats
- T1134.002 Create Process with Token13 threats
- T1027.006 HTML Smuggling11 threats
- T1564.004 NTFS File Attributes11 threats
- T1564.008 Email Hiding Rules11 threats
Defense Impairment
22 techniques under Defense Impairment, most-observed first.
- T1685 Disable or Modify Tools750 threats
- T1112 Modify Registry183 threats
- T1553 Subvert Trust Controls160 threats
- T1556 Modify Authentication Process147 threats
- T1553.002 Code Signing82 threats
- T1685.005 Clear Windows Event Logs41 threats
- T1686 Disable or Modify System Firewall35 threats
- T1222 File and Directory Permissions Modification33 threats
- T1601 Modify System Image32 threats
- T1685.006 Clear Linux or Mac System Logs32 threats
- T1484 Domain or Tenant Policy Modification30 threats
- T1556.006 Multi-Factor Authentication22 threats
- T1553.001 Gatekeeper Bypass20 threats
- T1222.002 Linux and Mac Permissions17 threats
- T1578 Modify Cloud Compute Infrastructure15 threats
- T1484.001 Group Policy Modification14 threats
- T1553.006 Code Signing Policy Modification14 threats
- T1553.005 Mark-of-the-Web Bypass13 threats
- T1599 Network Boundary Bridging12 threats
- T1601.001 Patch System Image11 threats
- T1685.002 Disable or Modify Cloud Log11 threats
- T1688 Safe Mode Boot10 threats
Credential Access
43 techniques under Credential Access, most-observed first.
- T1552 Unsecured Credentials551 threats
- T1539 Steal Web Session Cookie461 threats
- T1555 Credentials from Password Stores445 threats
- T1528 Steal Application Access Token401 threats
- T1552.001 Credentials In Files345 threats
- T1003 OS Credential Dumping291 threats
- T1056 Input Capture285 threats
- T1555.003 Credentials from Web Browsers262 threats
- T1110 Brute Force175 threats
- T1557 Adversary-in-the-Middle170 threats
- T1556 Modify Authentication Process147 threats
- T1056.001 Keylogging134 threats
- T1111 Multi-Factor Authentication Interception121 threats
- T1606 Forge Web Credentials93 threats
- T1212 Exploitation for Credential Access92 threats
- T1003.001 LSASS Memory78 threats
- T1552.004 Private Keys75 threats
- T1040 Network Sniffing71 threats
- T1187 Forced Authentication68 threats
- T1621 Multi-Factor Authentication Request Generation62 threats
- T1056.003 Web Portal Capture58 threats
- T1552.005 Cloud Instance Metadata API53 threats
- T1555.001 Keychain45 threats
- T1110.003 Password Spraying41 threats
- T1558 Steal or Forge Kerberos Tickets39 threats
- T1056.002 GUI Input Capture36 threats
- T1110.001 Password Guessing36 threats
- T1110.004 Credential Stuffing33 threats
- T1649 Steal or Forge Authentication Certificates33 threats
- T1555.005 Password Managers25 threats
- T1110.002 Password Cracking22 threats
- T1556.006 Multi-Factor Authentication22 threats
- T1003.003 NTDS17 threats
- T1003.002 Security Account Manager16 threats
- T1552.007 Container API15 threats
- T1056.004 Credential API Hooking14 threats
- T1558.003 Kerberoasting14 threats
- T1003.006 DCSync13 threats
- T1003.008 /etc/passwd and /etc/shadow13 threats
- T1555.004 Windows Credential Manager13 threats
- T1557.001 Name Resolution Poisoning and SMB Relay13 threats
- T1552.002 Credentials in Registry11 threats
- T1003.007 Proc Filesystem10 threats
Discovery
38 techniques under Discovery, most-observed first.
- T1082 System Information Discovery1143 threats
- T1083 File and Directory Discovery519 threats
- T1046 Network Service Discovery374 threats
- T1057 Process Discovery367 threats
- T1518 Software Discovery340 threats
- T1087 Account Discovery339 threats
- T1497 Virtualization/Sandbox Evasion282 threats
- T1016 System Network Configuration Discovery239 threats
- T1018 Remote System Discovery206 threats
- T1033 System Owner/User Discovery194 threats
- T1526 Cloud Service Discovery157 threats
- T1497.001 System Checks131 threats
- T1518.001 Security Software Discovery114 threats
- T1069 Permission Groups Discovery101 threats
- T1580 Cloud Infrastructure Discovery100 threats
- T1482 Domain Trust Discovery90 threats
- T1135 Network Share Discovery85 threats
- T1622 Debugger Evasion79 threats
- T1087.002 Domain Account75 threats
- T1614 System Location Discovery74 threats
- T1040 Network Sniffing71 threats
- T1217 Browser Information Discovery68 threats
- T1012 Query Registry63 threats
- T1087.004 Cloud Account45 threats
- T1049 System Network Connections Discovery44 threats
- T1010 Application Window Discovery40 threats
- T1007 System Service Discovery37 threats
- T1613 Container and Resource Discovery37 threats
- T1120 Peripheral Device Discovery34 threats
- T1069.002 Domain Groups32 threats
- T1497.003 Time Based Checks31 threats
- T1087.001 Local Account30 threats
- T1538 Cloud Service Dashboard28 threats
- T1614.001 System Language Discovery27 threats
- T1619 Cloud Storage Object Discovery19 threats
- T1069.003 Cloud Groups16 threats
- T1124 System Time Discovery13 threats
- T1069.001 Local Groups10 threats
Lateral Movement
16 techniques under Lateral Movement, most-observed first.
- T1021 Remote Services364 threats
- T1210 Exploitation of Remote Services223 threats
- T1550 Use Alternate Authentication Material207 threats
- T1570 Lateral Tool Transfer172 threats
- T1021.001 Remote Desktop Protocol103 threats
- T1550.001 Application Access Token98 threats
- T1021.002 SMB/Windows Admin Shares90 threats
- T1021.004 SSH63 threats
- T1550.004 Web Session Cookie50 threats
- T1091 Replication Through Removable Media38 threats
- T1534 Internal Spearphishing35 threats
- T1072 Software Deployment Tools30 threats
- T1080 Taint Shared Content24 threats
- T1550.002 Pass the Hash19 threats
- T1021.006 Windows Remote Management12 threats
- T1021.005 VNC11 threats
Collection
29 techniques under Collection, most-observed first.
- T1005 Data from Local System1173 threats
- T1213 Data from Information Repositories412 threats
- T1113 Screen Capture330 threats
- T1119 Automated Collection300 threats
- T1056 Input Capture285 threats
- T1560 Archive Collected Data224 threats
- T1557 Adversary-in-the-Middle170 threats
- T1115 Clipboard Data163 threats
- T1530 Data from Cloud Storage135 threats
- T1056.001 Keylogging134 threats
- T1114 Email Collection129 threats
- T1074 Data Staged120 threats
- T1125 Video Capture85 threats
- T1185 Browser Session Hijacking83 threats
- T1123 Audio Capture80 threats
- T1074.001 Local Data Staging66 threats
- T1560.001 Archive via Utility63 threats
- T1056.003 Web Portal Capture58 threats
- T1039 Data from Network Shared Drive49 threats
- T1114.002 Remote Email Collection46 threats
- T1056.002 GUI Input Capture36 threats
- T1213.003 Code Repositories26 threats
- T1602 Data from Configuration Repository25 threats
- T1213.002 Sharepoint20 threats
- T1025 Data from Removable Media17 threats
- T1114.003 Email Forwarding Rule15 threats
- T1056.004 Credential API Hooking14 threats
- T1114.001 Local Email Collection13 threats
- T1557.001 Name Resolution Poisoning and SMB Relay13 threats
Command and Control
29 techniques under Command and Control, most-observed first.
- T1071 Application Layer Protocol859 threats
- T1105 Ingress Tool Transfer730 threats
- T1071.001 Web Protocols690 threats
- T1102 Web Service396 threats
- T1090 Proxy367 threats
- T1573 Encrypted Channel364 threats
- T1219 Remote Access Tools272 threats
- T1572 Protocol Tunneling235 threats
- T1571 Non-Standard Port215 threats
- T1573.001 Symmetric Cryptography155 threats
- T1102.002 Bidirectional Communication139 threats
- T1095 Non-Application Layer Protocol124 threats
- T1573.002 Asymmetric Cryptography90 threats
- T1090.002 External Proxy86 threats
- T1102.001 Dead Drop Resolver84 threats
- T1008 Fallback Channels81 threats
- T1568 Dynamic Resolution80 threats
- T1132.001 Standard Encoding72 threats
- T1132 Data Encoding70 threats
- T1090.003 Multi-hop Proxy68 threats
- T1071.004 DNS56 threats
- T1090.001 Internal Proxy41 threats
- T1001 Data Obfuscation30 threats
- T1568.002 Domain Generation Algorithms27 threats
- T1104 Multi-Stage Channels22 threats
- T1205 Traffic Signaling22 threats
- T1090.004 Domain Fronting12 threats
- T1665 Hide Infrastructure12 threats
- T1132.002 Non-Standard Encoding11 threats
Exfiltration
10 techniques under Exfiltration, most-observed first.
- T1041 Exfiltration Over C2 Channel865 threats
- T1567 Exfiltration Over Web Service572 threats
- T1048 Exfiltration Over Alternative Protocol155 threats
- T1020 Automated Exfiltration130 threats
- T1567.002 Exfiltration to Cloud Storage120 threats
- T1537 Transfer Data to Cloud Account69 threats
- T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol27 threats
- T1567.001 Exfiltration to Code Repository26 threats
- T1030 Data Transfer Size Limits20 threats
- T1567.004 Exfiltration Over Webhook15 threats
Impact
23 techniques under Impact, most-observed first.
- T1657 Financial Theft468 threats
- T1486 Data Encrypted for Impact295 threats
- T1489 Service Stop220 threats
- T1490 Inhibit System Recovery220 threats
- T1485 Data Destruction194 threats
- T1565 Data Manipulation192 threats
- T1496 Resource Hijacking162 threats
- T1531 Account Access Removal139 threats
- T1499 Endpoint Denial of Service127 threats
- T1565.001 Stored Data Manipulation98 threats
- T1529 System Shutdown/Reboot80 threats
- T1499.004 Application or System Exploitation74 threats
- T1491 Defacement73 threats
- T1498 Network Denial of Service69 threats
- T1561 Disk Wipe35 threats
- T1491.002 External Defacement24 threats
- T1495 Firmware Corruption21 threats
- T1499.003 Application Exhaustion Flood21 threats
- T1491.001 Internal Defacement19 threats
- T1498.001 Direct Network Flood18 threats
- T1565.002 Transmitted Data Manipulation15 threats
- T1499.002 Service Exhaustion Flood10 threats
- T1561.001 Disk Content Wipe10 threats
Collection (Mobile)
15 techniques under Collection (Mobile), most-observed first.
- T1513 Screen Capture33 threats
- T1417 Input Capture31 threats
- T1430 Location Tracking31 threats
- T1636 Protected User Data27 threats
- T1533 Data from Local System26 threats
- T1429 Audio Capture24 threats
- T1512 Video Capture20 threats
- T1517 Access Notifications20 threats
- T1636.004 SMS Messages20 threats
- T1417.002 GUI Input Capture18 threats
- T1636.003 Contact List17 threats
- T1414 Clipboard Data16 threats
- T1409 Stored Application Data15 threats
- T1417.001 Keylogging12 threats
- T1453 Abuse Accessibility Features10 threats
Command and Control (Mobile)
3 techniques under Command and Control (Mobile), most-observed first.
- T1437 Application Layer Protocol34 threats
- T1521 Encrypted Channel12 threats
- T1481 Web Service11 threats
Credential Access (Mobile)
6 techniques under Credential Access (Mobile), most-observed first.
- T1417 Input Capture31 threats
- T1517 Access Notifications20 threats
- T1417.002 GUI Input Capture18 threats
- T1414 Clipboard Data16 threats
- T1417.001 Keylogging12 threats
- T1453 Abuse Accessibility Features10 threats
Defense Evasion (Mobile)
9 techniques under Defense Evasion (Mobile), most-observed first.
- T1541 Foreground Persistence27 threats
- T1406 Obfuscated Files or Information25 threats
- T1516 Input Injection24 threats
- T1655 Masquerading23 threats
- T1407 Download New Code at Runtime20 threats
- T1628 Hide Artifacts20 threats
- T1575 Native API14 threats
- T1629 Impair Defenses14 threats
- T1630 Indicator Removal on Host11 threats
Discovery (Mobile)
5 techniques under Discovery (Mobile), most-observed first.
- T1426 System Information Discovery38 threats
- T1418 Software Discovery34 threats
- T1430 Location Tracking31 threats
- T1420 File and Directory Discovery13 threats
- T1422 System Network Configuration Discovery12 threats
Execution (Mobile)
1 technique under Execution (Mobile), most-observed first.
- T1575 Native API14 threats
Exfiltration (Mobile)
1 technique under Exfiltration (Mobile), most-observed first.
- T1646 Exfiltration Over C2 Channel36 threats
Impact (Mobile)
2 techniques under Impact (Mobile), most-observed first.
- T1516 Input Injection24 threats
- T1582 SMS Control10 threats
Initial Access (Mobile)
2 techniques under Initial Access (Mobile), most-observed first.
- T1660 Phishing53 threats
- T1456 Drive-By Compromise12 threats
Persistence (Mobile)
3 techniques under Persistence (Mobile), most-observed first.
- T1541 Foreground Persistence27 threats
- T1624 Event Triggered Execution19 threats
- T1624.001 Broadcast Receivers10 threats
Privilege Escalation (Mobile)
2 techniques under Privilege Escalation (Mobile), most-observed first.
Impact (ICS)
1 technique under Impact (ICS), most-observed first.
- T0831 Manipulation of Control10 threats
Defense Evasion (ATLAS)
1 technique under Defense Evasion (ATLAS), most-observed first.
- AML.T0054 LLM Jailbreak17 threats
Execution (ATLAS)
3 techniques under Execution (ATLAS), most-observed first.
- AML.T0051 LLM Prompt Injection19 threats
- AML.T0051.001 LLM Prompt Injection: Indirect11 threats
- AML.T0053 AI Agent Tool Invocation11 threats