ATT&CK Detection Rule Coverage
16035 detection rules mapped to 655 MITRE ATT&CK techniques and sub-techniques. Click a technique to see every rule written for it, grouped by vendor for easy comparison. Use the vendor chips to show or hide each rule source.
- flat
- side
Execution 17
Hijack Execution Flow (12)
DLL (173) Dylib Hijacking (1) Executable Installer File Permissions Weakness (2) Dynamic Linker Hijacking (26) Path Interception by PATH Environment Variable (11) Path Interception by Search Order Hijacking (6) Path Interception by Unquoted Path (4) Services File Permissions Weakness (7) Services Registry Permissions Weakness (17) COR_PROFILER (2) KernelCallbackTable (2) AppDomainManager (1)
Discovery 33
Credential Access 17
Privilege Escalation 13
Boot or Logon Autostart Execution (13)
Registry Run Keys / Startup Folder (115) Authentication Package (9) Time Providers (3) Winlogon Helper DLL (9) Security Support Provider (8) Kernel Modules and Extensions (37) LSASS Driver (4) Shortcut Modification (15) Port Monitors (11) Print Processors (8) XDG Autostart Entries (5) Active Setup (4) Login Items (2)
Event Triggered Execution (17)
Change Default File Association (8) Screensaver (9) Windows Management Instrumentation Event Subscription (24) Unix Shell Configuration Modification (17) Trap (1) Netsh Helper DLL (7) Accessibility Features (22) AppCert DLLs (6) AppInit DLLs (3) Application Shimming (11) Image File Execution Options Injection (12) PowerShell Profile (4) Emond (4) Component Object Model Hijacking (27) Installer Packages (15) Udev Rules (3) Python Startup Hooks (2)
Persistence 21
Boot or Logon Autostart Execution (13)
Registry Run Keys / Startup Folder (115) Authentication Package (9) Time Providers (3) Winlogon Helper DLL (9) Security Support Provider (8) Kernel Modules and Extensions (37) LSASS Driver (4) Shortcut Modification (15) Port Monitors (11) Print Processors (8) XDG Autostart Entries (5) Active Setup (4) Login Items (2)
Event Triggered Execution (17)
Change Default File Association (8) Screensaver (9) Windows Management Instrumentation Event Subscription (24) Unix Shell Configuration Modification (17) Trap (1) Netsh Helper DLL (7) Accessibility Features (22) AppCert DLLs (6) AppInit DLLs (3) Application Shimming (11) Image File Execution Options Injection (12) PowerShell Profile (4) Emond (4) Component Object Model Hijacking (27) Installer Packages (15) Udev Rules (3) Python Startup Hooks (2)
Stealth 28
Hijack Execution Flow (12)
DLL (173) Dylib Hijacking (1) Executable Installer File Permissions Weakness (2) Dynamic Linker Hijacking (26) Path Interception by PATH Environment Variable (11) Path Interception by Search Order Hijacking (6) Path Interception by Unquoted Path (4) Services File Permissions Weakness (7) Services Registry Permissions Weakness (17) COR_PROFILER (2) KernelCallbackTable (2) AppDomainManager (1)
Defense Impairment 17
MITRE ATT&CK Mobile
Network Effects 0
No techniques tracked.
Remote Service Effects 0
No techniques tracked.