Detection rules

14,038 catalog-relevant detection rules from Sigma, Elastic, Splunk, and Kusto. Each page shows its parsed predicates, exclusions, and shared indicators.

Status (all)
Vendor (all)
Platform (all)
Domain (all)

MITRE ATT&CK

Other frameworks

MITRE ATT&CK

MITRE ATT&CK

MITRE ATLAS

Email threats

Detection categories

Reconnaissance

Gather Victim Identity Information T1589 9 rules
Gather Victim Identity Information: Credentials T1589.001 2 rules
Gather Victim Identity Information: Email Addresses T1589.002 3 rules
Gather Victim Identity Information: Employee Names T1589.003 1 rule
Gather Victim Network Information T1590 17 rules
Gather Victim Network Information: Domain Properties T1590.001 2 rules
Gather Victim Network Information: DNS T1590.002 2 rules
Gather Victim Network Information: IP Addresses T1590.005 4 rules
Gather Victim Org Information T1591 5 rules
Gather Victim Org Information: Identify Roles T1591.004 2 rules
Gather Victim Host Information T1592 13 rules
Gather Victim Host Information: Hardware T1592.001 1 rule
Gather Victim Host Information: Software T1592.002 1 rule
Gather Victim Host Information: Client Configurations T1592.004 5 rules
Search Open Websites/Domains T1593 4 rules
Search Open Websites/Domains: Code Repositories T1593.003 2 rules
Active Scanning T1595 61 rules
Active Scanning: Scanning IP Blocks T1595.001 11 rules
Active Scanning: Vulnerability Scanning T1595.002 16 rules
Active Scanning: Wordlist Scanning T1595.003 8 rules
Search Open Technical Databases T1596 1 rule
Phishing for Information T1598 9 rules
Phishing for Information: Spearphishing Attachment T1598.002 2 rules
No specific technique 8 rules

Resource Development

Acquire Infrastructure T1583 4 rules
Acquire Infrastructure: Domains T1583.001 1 rule
Acquire Infrastructure: Web Services T1583.006 2 rules
Compromise Infrastructure T1584 10 rules
Compromise Infrastructure: Domains T1584.001 3 rules
Compromise Infrastructure: DNS Server T1584.002 1 rule
Establish Accounts T1585 2 rules
Establish Accounts: Cloud Accounts T1585.003 1 rule
Compromise Accounts T1586 41 rules
Compromise Accounts: Cloud Accounts T1586.003 36 rules
Develop Capabilities T1587 23 rules
Develop Capabilities: Malware T1587.001 13 rules
Develop Capabilities: Code Signing Certificates T1587.002 1 rule
Develop Capabilities: Digital Certificates T1587.003 1 rule
Obtain Capabilities T1588 21 rules
Obtain Capabilities: Malware T1588.001 2 rules
Obtain Capabilities: Tool T1588.002 13 rules
Obtain Capabilities: Digital Certificates T1588.004 1 rule
Stage Capabilities T1608 13 rules
Stage Capabilities: Upload Malware T1608.001 3 rules
Stage Capabilities: Upload Tool T1608.002 1 rule
Stage Capabilities: Install Digital Certificate T1608.003 1 rule
No specific technique 1 rule

Initial Access

Valid Accounts T1078 728 rules
Valid Accounts: Default Accounts T1078.001 15 rules
Valid Accounts: Domain Accounts T1078.002 28 rules
Valid Accounts: Local Accounts T1078.003 23 rules
Valid Accounts: Cloud Accounts T1078.004 290 rules
Replication Through Removable Media T1091 9 rules
External Remote Services T1133 216 rules
Drive-by Compromise T1189 39 rules
Exploit Public-Facing Application T1190 516 rules
Supply Chain Compromise T1195 82 rules
Supply Chain Compromise: Compromise Software Dependencies and Development Tools T1195.001 10 rules
Supply Chain Compromise: Compromise Software Supply Chain T1195.002 51 rules
Trusted Relationship T1199 18 rules
Hardware Additions T1200 14 rules
Phishing T1566 255 rules
Phishing: Spearphishing Attachment T1566.001 94 rules
Phishing: Spearphishing Link T1566.002 57 rules
Phishing: Spearphishing via Service T1566.003 1 rule
Content Injection T1659 4 rules
No specific technique 29 rules

Execution

Windows Management Instrumentation T1047 117 rules
Scheduled Task/Job T1053 197 rules
Scheduled Task/Job: At T1053.002 18 rules
Scheduled Task/Job: Cron T1053.003 29 rules
Scheduled Task/Job: Scheduled Task T1053.005 118 rules
Scheduled Task/Job: Systemd Timers T1053.006 6 rules
Scheduled Task/Job: Container Orchestration Job T1053.007 4 rules
Command and Scripting Interpreter T1059 1092 rules
Command and Scripting Interpreter: PowerShell T1059.001 471 rules
Command and Scripting Interpreter: AppleScript T1059.002 27 rules
Command and Scripting Interpreter: Windows Command Shell T1059.003 148 rules
Command and Scripting Interpreter: Unix Shell T1059.004 162 rules
Command and Scripting Interpreter: Visual Basic T1059.005 62 rules
Command and Scripting Interpreter: Python T1059.006 54 rules
Command and Scripting Interpreter: JavaScript T1059.007 70 rules
Command and Scripting Interpreter: Cloud API T1059.009 6 rules
Command and Scripting Interpreter: AutoHotKey & AutoIT T1059.010 1 rule
Command and Scripting Interpreter: Lua T1059.011 9 rules
Command and Scripting Interpreter: Hypervisor CLI T1059.012 9 rules
Command and Scripting Interpreter: Container CLI/API T1059.013 1 rule
Software Deployment Tools T1072 31 rules
Native API T1106 35 rules
Trusted Developer Utilities Proxy Execution T1127 58 rules
Trusted Developer Utilities Proxy Execution: MSBuild T1127.001 22 rules
Trusted Developer Utilities Proxy Execution: ClickOnce T1127.002 1 rule
Shared Modules T1129 17 rules
BITS Jobs T1197 35 rules
Exploitation for Client Execution T1203 106 rules
User Execution T1204 266 rules
User Execution: Malicious Link T1204.001 16 rules
User Execution: Malicious File T1204.002 145 rules
User Execution: Malicious Image T1204.003 10 rules
User Execution: Malicious Copy and Paste T1204.004 8 rules
User Execution: Malicious Library T1204.005 1 rule
Inter-Process Communication T1559 31 rules
Inter-Process Communication: Component Object Model T1559.001 17 rules
Inter-Process Communication: Dynamic Data Exchange T1559.002 1 rule
System Services T1569 102 rules
System Services: Launchctl T1569.001 2 rules
System Services: Service Execution T1569.002 85 rules
Hijack Execution Flow T1574 246 rules
Hijack Execution Flow: DLL T1574.001 123 rules
Hijack Execution Flow: DLL Side-Loading T1574.002 11 rules
Hijack Execution Flow: Dylib Hijacking T1574.004 1 rule
Hijack Execution Flow: Executable Installer File Permissions Weakness T1574.005 2 rules
Hijack Execution Flow: Dynamic Linker Hijacking T1574.006 24 rules
Hijack Execution Flow: Path Interception by PATH Environment Variable T1574.007 9 rules
Hijack Execution Flow: Path Interception by Search Order Hijacking T1574.008 6 rules
Hijack Execution Flow: Path Interception by Unquoted Path T1574.009 4 rules
Hijack Execution Flow: Services File Permissions Weakness T1574.010 7 rules
Hijack Execution Flow: Services Registry Permissions Weakness T1574.011 17 rules
Hijack Execution Flow: COR_PROFILER T1574.012 2 rules
Hijack Execution Flow: KernelCallbackTable T1574.013 2 rules
Hijack Execution Flow: AppDomainManager T1574.014 1 rule
Container Administration Command T1609 27 rules
Deploy Container T1610 22 rules
Serverless Execution T1648 12 rules
Cloud Administration Command T1651 22 rules
No specific technique 152 rules

Persistence

Boot or Logon Initialization Scripts T1037 37 rules
Boot or Logon Initialization Scripts: Logon Script (Windows) T1037.001 8 rules
Boot or Logon Initialization Scripts: Login Hook T1037.002 3 rules
Boot or Logon Initialization Scripts: RC Scripts T1037.004 11 rules
Boot or Logon Initialization Scripts: Startup Items T1037.005 2 rules
Scheduled Task/Job T1053 197 rules
Scheduled Task/Job: At T1053.002 18 rules
Scheduled Task/Job: Cron T1053.003 29 rules
Scheduled Task/Job: Scheduled Task T1053.005 118 rules
Scheduled Task/Job: Systemd Timers T1053.006 6 rules
Scheduled Task/Job: Container Orchestration Job T1053.007 4 rules
Valid Accounts T1078 728 rules
Valid Accounts: Default Accounts T1078.001 15 rules
Valid Accounts: Domain Accounts T1078.002 28 rules
Valid Accounts: Local Accounts T1078.003 23 rules
Valid Accounts: Cloud Accounts T1078.004 290 rules
Account Manipulation T1098 529 rules
Account Manipulation: Additional Cloud Credentials T1098.001 56 rules
Account Manipulation: Additional Email Delegate Permissions T1098.002 8 rules
Account Manipulation: Additional Cloud Roles T1098.003 107 rules
Account Manipulation: SSH Authorized Keys T1098.004 12 rules
Account Manipulation: Device Registration T1098.005 22 rules
Account Manipulation: Additional Container Cluster Roles T1098.006 12 rules
Account Manipulation: Additional Local or Domain Groups T1098.007 9 rules
Redundant Access T1108 3 rules
Modify Registry T1112 254 rules
External Remote Services T1133 216 rules
Create Account T1136 157 rules
Create Account: Local Account T1136.001 49 rules
Create Account: Domain Account T1136.002 18 rules
Create Account: Cloud Account T1136.003 56 rules
Office Application Startup T1137 27 rules
Office Application Startup: Office Template Macros T1137.001 1 rule
Office Application Startup: Office Test T1137.002 3 rules
Office Application Startup: Outlook Forms T1137.003 1 rule
Office Application Startup: Outlook Home Page T1137.004 1 rule
Office Application Startup: Outlook Rules T1137.005 3 rules
Office Application Startup: Add-ins T1137.006 6 rules
Software Extensions T1176 10 rules
Software Extensions: Browser Extensions T1176.001 5 rules
BITS Jobs T1197 35 rules
Traffic Signaling T1205 1 rule
Traffic Signaling: Port Knocking T1205.001 1 rule
Server Software Component T1505 144 rules
Server Software Component: SQL Stored Procedures T1505.001 18 rules
Server Software Component: Transport Agent T1505.002 6 rules
Server Software Component: Web Shell T1505.003 77 rules
Server Software Component: IIS Components T1505.004 22 rules
Server Software Component: Terminal Services DLL T1505.005 1 rule
Server Software Component: vSphere Installation Bundles T1505.006 1 rule
Implant Internal Image T1525 5 rules
Pre-OS Boot T1542 17 rules
Pre-OS Boot: System Firmware T1542.001 4 rules
Pre-OS Boot: Bootkit T1542.003 4 rules
Pre-OS Boot: TFTP Boot T1542.005 1 rule
Create or Modify System Process T1543 218 rules
Create or Modify System Process: Launch Agent T1543.001 11 rules
Create or Modify System Process: Systemd Service T1543.002 14 rules
Create or Modify System Process: Windows Service T1543.003 117 rules
Create or Modify System Process: Launch Daemon T1543.004 9 rules
Create or Modify System Process: Container Service T1543.005 2 rules
Event Triggered Execution T1546 212 rules
Event Triggered Execution: Change Default File Association T1546.001 7 rules
Event Triggered Execution: Screensaver T1546.002 8 rules
Event Triggered Execution: Windows Management Instrumentation Event Subscription T1546.003 23 rules
Event Triggered Execution: Unix Shell Configuration Modification T1546.004 14 rules
Event Triggered Execution: Trap T1546.005 1 rule
Event Triggered Execution: Netsh Helper DLL T1546.007 7 rules
Event Triggered Execution: Accessibility Features T1546.008 22 rules
Event Triggered Execution: AppCert DLLs T1546.009 5 rules
Event Triggered Execution: AppInit DLLs T1546.010 3 rules
Event Triggered Execution: Application Shimming T1546.011 11 rules
Event Triggered Execution: Image File Execution Options Injection T1546.012 10 rules
Event Triggered Execution: PowerShell Profile T1546.013 4 rules
Event Triggered Execution: Emond T1546.014 3 rules
Event Triggered Execution: Component Object Model Hijacking T1546.015 22 rules
Event Triggered Execution: Installer Packages T1546.016 9 rules
Event Triggered Execution: Udev Rules T1546.017 3 rules
Event Triggered Execution: Python Startup Hooks T1546.018 2 rules
Boot or Logon Autostart Execution T1547 201 rules
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder T1547.001 87 rules
Boot or Logon Autostart Execution: Authentication Package T1547.002 8 rules
Boot or Logon Autostart Execution: Time Providers T1547.003 3 rules
Boot or Logon Autostart Execution: Winlogon Helper DLL T1547.004 8 rules
Boot or Logon Autostart Execution: Security Support Provider T1547.005 7 rules
Boot or Logon Autostart Execution: Kernel Modules and Extensions T1547.006 28 rules
Boot or Logon Autostart Execution: LSASS Driver T1547.008 4 rules
Boot or Logon Autostart Execution: Shortcut Modification T1547.009 13 rules
Boot or Logon Autostart Execution: Port Monitors T1547.010 11 rules
Boot or Logon Autostart Execution: Plist Modification T1547.011 3 rules
Boot or Logon Autostart Execution: Print Processors T1547.012 8 rules
Boot or Logon Autostart Execution: XDG Autostart Entries T1547.013 5 rules
Boot or Logon Autostart Execution: Active Setup T1547.014 4 rules
Boot or Logon Autostart Execution: Login Items T1547.015 2 rules
Compromise Host Software Binary T1554 32 rules
Modify Authentication Process T1556 145 rules
Modify Authentication Process: Password Filter DLL T1556.002 5 rules
Modify Authentication Process: Pluggable Authentication Modules T1556.003 5 rules
Modify Authentication Process: Network Device Authentication T1556.004 2 rules
Modify Authentication Process: Multi-Factor Authentication T1556.006 33 rules
Modify Authentication Process: Hybrid Identity T1556.007 6 rules
Modify Authentication Process: Network Provider DLL T1556.008 1 rule
Modify Authentication Process: Conditional Access Policies T1556.009 13 rules
Power Settings T1653 1 rule
No specific technique 97 rules

Privilege Escalation

Boot or Logon Initialization Scripts T1037 37 rules
Boot or Logon Initialization Scripts: Logon Script (Windows) T1037.001 8 rules
Boot or Logon Initialization Scripts: Login Hook T1037.002 3 rules
Boot or Logon Initialization Scripts: RC Scripts T1037.004 11 rules
Boot or Logon Initialization Scripts: Startup Items T1037.005 2 rules
Scheduled Task/Job T1053 197 rules
Scheduled Task/Job: At T1053.002 18 rules
Scheduled Task/Job: Cron T1053.003 29 rules
Scheduled Task/Job: Scheduled Task T1053.005 118 rules
Scheduled Task/Job: Systemd Timers T1053.006 6 rules
Scheduled Task/Job: Container Orchestration Job T1053.007 4 rules
Process Injection T1055 147 rules
Process Injection: Dynamic-link Library Injection T1055.001 21 rules
Process Injection: Portable Executable Injection T1055.002 8 rules
Process Injection: Thread Execution Hijacking T1055.003 4 rules
Process Injection: Asynchronous Procedure Call T1055.004 2 rules
Process Injection: Ptrace System Calls T1055.008 4 rules
Process Injection: Proc Memory T1055.009 2 rules
Process Injection: Extra Window Memory Injection T1055.011 1 rule
Process Injection: Process Hollowing T1055.012 10 rules
Process Injection: Process Doppelgänging T1055.013 1 rule
Exploitation for Privilege Escalation T1068 145 rules
Valid Accounts T1078 728 rules
Valid Accounts: Default Accounts T1078.001 15 rules
Valid Accounts: Domain Accounts T1078.002 28 rules
Valid Accounts: Local Accounts T1078.003 23 rules
Valid Accounts: Cloud Accounts T1078.004 290 rules
Account Manipulation T1098 529 rules
Account Manipulation: Additional Cloud Credentials T1098.001 56 rules
Account Manipulation: Additional Email Delegate Permissions T1098.002 8 rules
Account Manipulation: Additional Cloud Roles T1098.003 107 rules
Account Manipulation: SSH Authorized Keys T1098.004 12 rules
Account Manipulation: Device Registration T1098.005 22 rules
Account Manipulation: Additional Container Cluster Roles T1098.006 12 rules
Account Manipulation: Additional Local or Domain Groups T1098.007 9 rules
Access Token Manipulation T1134 73 rules
Access Token Manipulation: Token Impersonation/Theft T1134.001 23 rules
Access Token Manipulation: Create Process with Token T1134.002 18 rules
Access Token Manipulation: Make and Impersonate Token T1134.003 7 rules
Access Token Manipulation: Parent PID Spoofing T1134.004 6 rules
Access Token Manipulation: SID-History Injection T1134.005 6 rules
Domain or Tenant Policy Modification T1484 85 rules
Domain or Tenant Policy Modification: Group Policy Modification T1484.001 24 rules
Domain or Tenant Policy Modification: Trust Modification T1484.002 15 rules
Create or Modify System Process T1543 218 rules
Create or Modify System Process: Launch Agent T1543.001 11 rules
Create or Modify System Process: Systemd Service T1543.002 14 rules
Create or Modify System Process: Windows Service T1543.003 117 rules
Create or Modify System Process: Launch Daemon T1543.004 9 rules
Create or Modify System Process: Container Service T1543.005 2 rules
Event Triggered Execution T1546 212 rules
Event Triggered Execution: Change Default File Association T1546.001 7 rules
Event Triggered Execution: Screensaver T1546.002 8 rules
Event Triggered Execution: Windows Management Instrumentation Event Subscription T1546.003 23 rules
Event Triggered Execution: Unix Shell Configuration Modification T1546.004 14 rules
Event Triggered Execution: Trap T1546.005 1 rule
Event Triggered Execution: Netsh Helper DLL T1546.007 7 rules
Event Triggered Execution: Accessibility Features T1546.008 22 rules
Event Triggered Execution: AppCert DLLs T1546.009 5 rules
Event Triggered Execution: AppInit DLLs T1546.010 3 rules
Event Triggered Execution: Application Shimming T1546.011 11 rules
Event Triggered Execution: Image File Execution Options Injection T1546.012 10 rules
Event Triggered Execution: PowerShell Profile T1546.013 4 rules
Event Triggered Execution: Emond T1546.014 3 rules
Event Triggered Execution: Component Object Model Hijacking T1546.015 22 rules
Event Triggered Execution: Installer Packages T1546.016 9 rules
Event Triggered Execution: Udev Rules T1546.017 3 rules
Event Triggered Execution: Python Startup Hooks T1546.018 2 rules
Boot or Logon Autostart Execution T1547 201 rules
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder T1547.001 87 rules
Boot or Logon Autostart Execution: Authentication Package T1547.002 8 rules
Boot or Logon Autostart Execution: Time Providers T1547.003 3 rules
Boot or Logon Autostart Execution: Winlogon Helper DLL T1547.004 8 rules
Boot or Logon Autostart Execution: Security Support Provider T1547.005 7 rules
Boot or Logon Autostart Execution: Kernel Modules and Extensions T1547.006 28 rules
Boot or Logon Autostart Execution: LSASS Driver T1547.008 4 rules
Boot or Logon Autostart Execution: Shortcut Modification T1547.009 13 rules
Boot or Logon Autostart Execution: Port Monitors T1547.010 11 rules
Boot or Logon Autostart Execution: Plist Modification T1547.011 3 rules
Boot or Logon Autostart Execution: Print Processors T1547.012 8 rules
Boot or Logon Autostart Execution: XDG Autostart Entries T1547.013 5 rules
Boot or Logon Autostart Execution: Active Setup T1547.014 4 rules
Boot or Logon Autostart Execution: Login Items T1547.015 2 rules
Abuse Elevation Control Mechanism T1548 311 rules
Abuse Elevation Control Mechanism: Setuid and Setgid T1548.001 28 rules
Abuse Elevation Control Mechanism: Bypass User Account Control T1548.002 106 rules
Abuse Elevation Control Mechanism: Sudo and Sudo Caching T1548.003 58 rules
Abuse Elevation Control Mechanism: Elevated Execution with Prompt T1548.004 2 rules
Abuse Elevation Control Mechanism: Temporary Elevated Cloud Access T1548.005 7 rules
Abuse Elevation Control Mechanism: TCC Manipulation T1548.006 3 rules
Escape to Host T1611 51 rules
No specific technique 48 rules

Stealth

Direct Volume Access T1006 8 rules
Rootkit T1014 30 rules
Obfuscated Files or Information T1027 242 rules
Obfuscated Files or Information: Binary Padding T1027.001 6 rules
Obfuscated Files or Information: Software Packing T1027.002 1 rule
Obfuscated Files or Information: Steganography T1027.003 5 rules
Obfuscated Files or Information: Compile After Delivery T1027.004 14 rules
Obfuscated Files or Information: Indicator Removal from Tools T1027.005 6 rules
Obfuscated Files or Information: HTML Smuggling T1027.006 1 rule
Obfuscated Files or Information: Embedded Payloads T1027.009 2 rules
Obfuscated Files or Information: Command Obfuscation T1027.010 39 rules
Obfuscated Files or Information: Fileless Storage T1027.011 3 rules
Obfuscated Files or Information: Encrypted/Encoded File T1027.013 6 rules
Obfuscated Files or Information: Compression T1027.015 3 rules
Masquerading T1036 261 rules
Masquerading: Invalid Code Signature T1036.001 18 rules
Masquerading: Right-to-Left Override T1036.002 6 rules
Masquerading: Rename Legitimate Utilities T1036.003 55 rules
Masquerading: Masquerade Task or Service T1036.004 17 rules
Masquerading: Match Legitimate Resource Name or Location T1036.005 62 rules
Masquerading: Space after Filename T1036.006 3 rules
Masquerading: Double File Extension T1036.007 6 rules
Masquerading: Masquerade File Type T1036.008 8 rules
Masquerading: Break Process Trees T1036.009 6 rules
Process Injection T1055 147 rules
Process Injection: Dynamic-link Library Injection T1055.001 21 rules
Process Injection: Portable Executable Injection T1055.002 8 rules
Process Injection: Thread Execution Hijacking T1055.003 4 rules
Process Injection: Asynchronous Procedure Call T1055.004 2 rules
Process Injection: Ptrace System Calls T1055.008 4 rules
Process Injection: Proc Memory T1055.009 2 rules
Process Injection: Extra Window Memory Injection T1055.011 1 rule
Process Injection: Process Hollowing T1055.012 10 rules
Process Injection: Process Doppelgänging T1055.013 1 rule
Indicator Removal T1070 172 rules
Indicator Removal: Clear Windows Event Logs T1070.001 14 rules
Indicator Removal: Clear Linux or Mac System Logs T1070.002 4 rules
Indicator Removal: Clear Command History T1070.003 15 rules
Indicator Removal: File Deletion T1070.004 46 rules
Indicator Removal: Network Share Connection Removal T1070.005 6 rules
Indicator Removal: Timestomp T1070.006 15 rules
Indicator Removal: Clear Mailbox Data T1070.008 9 rules
Indicator Removal: Clear Persistence T1070.009 2 rules
Valid Accounts T1078 728 rules
Valid Accounts: Default Accounts T1078.001 15 rules
Valid Accounts: Domain Accounts T1078.002 28 rules
Valid Accounts: Local Accounts T1078.003 23 rules
Valid Accounts: Cloud Accounts T1078.004 290 rules
Redundant Access T1108 3 rules
Trusted Developer Utilities Proxy Execution T1127 58 rules
Trusted Developer Utilities Proxy Execution: MSBuild T1127.001 22 rules
Trusted Developer Utilities Proxy Execution: ClickOnce T1127.002 1 rule
Access Token Manipulation T1134 73 rules
Access Token Manipulation: Token Impersonation/Theft T1134.001 23 rules
Access Token Manipulation: Create Process with Token T1134.002 18 rules
Access Token Manipulation: Make and Impersonate Token T1134.003 7 rules
Access Token Manipulation: Parent PID Spoofing T1134.004 6 rules
Access Token Manipulation: SID-History Injection T1134.005 6 rules
Deobfuscate/Decode Files or Information T1140 79 rules
BITS Jobs T1197 35 rules
Indirect Command Execution T1202 69 rules
Traffic Signaling T1205 1 rule
Traffic Signaling: Port Knocking T1205.001 1 rule
Exploitation for Stealth T1211 15 rules
System Script Proxy Execution T1216 19 rules
System Script Proxy Execution: PubPrn T1216.001 2 rules
System Binary Proxy Execution T1218 552 rules
System Binary Proxy Execution: Compiled HTML File T1218.001 22 rules
System Binary Proxy Execution: Control Panel T1218.002 10 rules
System Binary Proxy Execution: CMSTP T1218.003 24 rules
System Binary Proxy Execution: InstallUtil T1218.004 16 rules
System Binary Proxy Execution: Mshta T1218.005 55 rules
System Binary Proxy Execution: Msiexec T1218.007 51 rules
System Binary Proxy Execution: Odbcconf T1218.008 17 rules
System Binary Proxy Execution: Regsvcs/Regasm T1218.009 17 rules
System Binary Proxy Execution: Regsvr32 T1218.010 50 rules
System Binary Proxy Execution: Rundll32 T1218.011 124 rules
System Binary Proxy Execution: Verclsid T1218.012 1 rule
System Binary Proxy Execution: Mavinject T1218.013 3 rules
System Binary Proxy Execution: MMC T1218.014 22 rules
XSL Script Processing T1220 15 rules
Template Injection T1221 2 rules
Execution Guardrails T1480 2 rules
Virtualization/Sandbox Evasion T1497 20 rules
Virtualization/Sandbox Evasion: System Checks T1497.001 8 rules
Virtualization/Sandbox Evasion: Time Based Checks T1497.003 4 rules
Unused/Unsupported Cloud Regions T1535 10 rules
Pre-OS Boot T1542 17 rules
Pre-OS Boot: System Firmware T1542.001 4 rules
Pre-OS Boot: Bootkit T1542.003 4 rules
Pre-OS Boot: TFTP Boot T1542.005 1 rule
Impair Defenses T1562 421 rules
Impair Defenses: Disable or Modify Tools T1562.001 158 rules
Impair Defenses: Disable Windows Event Logging T1562.002 12 rules
Impair Defenses: Impair Command History Logging T1562.003 1 rule
Impair Defenses: Disable or Modify System Firewall T1562.004 25 rules
Impair Defenses: Indicator Blocking T1562.006 8 rules
Impair Defenses: Disable or Modify Cloud Firewall T1562.007 53 rules
Impair Defenses: Disable or Modify Cloud Logs T1562.008 67 rules
Impair Defenses: Downgrade Attack T1562.010 5 rules
Hide Artifacts T1564 137 rules
Hide Artifacts: Hidden Files and Directories T1564.001 28 rules
Hide Artifacts: Hidden Users T1564.002 10 rules
Hide Artifacts: Hidden Window T1564.003 13 rules
Hide Artifacts: NTFS File Attributes T1564.004 34 rules
Hide Artifacts: Run Virtual Instance T1564.006 9 rules
Hide Artifacts: Email Hiding Rules T1564.008 9 rules
Hijack Execution Flow T1574 246 rules
Hijack Execution Flow: DLL T1574.001 123 rules
Hijack Execution Flow: DLL Side-Loading T1574.002 11 rules
Hijack Execution Flow: Dylib Hijacking T1574.004 1 rule
Hijack Execution Flow: Executable Installer File Permissions Weakness T1574.005 2 rules
Hijack Execution Flow: Dynamic Linker Hijacking T1574.006 24 rules
Hijack Execution Flow: Path Interception by PATH Environment Variable T1574.007 9 rules
Hijack Execution Flow: Path Interception by Search Order Hijacking T1574.008 6 rules
Hijack Execution Flow: Path Interception by Unquoted Path T1574.009 4 rules
Hijack Execution Flow: Services File Permissions Weakness T1574.010 7 rules
Hijack Execution Flow: Services Registry Permissions Weakness T1574.011 17 rules
Hijack Execution Flow: COR_PROFILER T1574.012 2 rules
Hijack Execution Flow: KernelCallbackTable T1574.013 2 rules
Hijack Execution Flow: AppDomainManager T1574.014 1 rule
Reflective Code Loading T1620 12 rules
Debugger Evasion T1622 2 rules
Impersonation T1656 1 rule
No specific technique 142 rules

Defense Impairment

Modify Registry T1112 254 rules
Rogue Domain Controller T1207 13 rules
File and Directory Permissions Modification T1222 79 rules
File and Directory Permissions Modification: Windows Permissions T1222.001 41 rules
File and Directory Permissions Modification: Linux and Mac Permissions T1222.002 18 rules
Domain or Tenant Policy Modification T1484 85 rules
Domain or Tenant Policy Modification: Group Policy Modification T1484.001 24 rules
Domain or Tenant Policy Modification: Trust Modification T1484.002 15 rules
Subvert Trust Controls T1553 59 rules
Subvert Trust Controls: Gatekeeper Bypass T1553.001 8 rules
Subvert Trust Controls: Code Signing T1553.002 6 rules
Subvert Trust Controls: SIP and Trust Provider Hijacking T1553.003 7 rules
Subvert Trust Controls: Install Root Certificate T1553.004 17 rules
Subvert Trust Controls: Mark-of-the-Web Bypass T1553.005 13 rules
Subvert Trust Controls: Code Signing Policy Modification T1553.006 2 rules
Modify Authentication Process T1556 145 rules
Modify Authentication Process: Password Filter DLL T1556.002 5 rules
Modify Authentication Process: Pluggable Authentication Modules T1556.003 5 rules
Modify Authentication Process: Network Device Authentication T1556.004 2 rules
Modify Authentication Process: Multi-Factor Authentication T1556.006 33 rules
Modify Authentication Process: Hybrid Identity T1556.007 6 rules
Modify Authentication Process: Network Provider DLL T1556.008 1 rule
Modify Authentication Process: Conditional Access Policies T1556.009 13 rules
Modify Cloud Compute Infrastructure T1578 31 rules
Modify Cloud Compute Infrastructure: Create Snapshot T1578.001 1 rule
Modify Cloud Compute Infrastructure: Create Cloud Instance T1578.002 5 rules
Modify Cloud Compute Infrastructure: Delete Cloud Instance T1578.003 2 rules
Modify Cloud Compute Infrastructure: Revert Cloud Instance T1578.004 1 rule
Modify Cloud Compute Infrastructure: Modify Cloud Compute Configurations T1578.005 15 rules
Network Boundary Bridging T1599 6 rules
Network Boundary Bridging: Network Address Translation Traversal T1599.001 1 rule
Weaken Encryption T1600 3 rules
Weaken Encryption: Reduce Key Space T1600.001 2 rules
Modify System Image T1601 2 rules
Modify System Image: Patch System Image T1601.001 2 rules
Plist File Modification T1647 6 rules
Modify Cloud Resource Hierarchy T1666 1 rule
Disable or Modify Tools T1685 359 rules
Disable or Modify Tools: Disable or Modify Windows Event Log T1685.001 41 rules
Disable or Modify Tools: Disable or Modify Cloud Log T1685.002 22 rules
Disable or Modify Tools: Disable or Modify Linux Audit System Log T1685.004 4 rules
Disable or Modify Tools: Clear Windows Event Logs T1685.005 12 rules
Disable or Modify Tools: Clear Linux or Mac System Logs T1685.006 4 rules
Disable or Modify System Firewall T1686 50 rules
Disable or Modify System Firewall: Cloud Firewall T1686.001 12 rules
Disable or Modify System Firewall: Windows Host Firewall T1686.003 20 rules
Safe Mode Boot T1688 1 rule
Downgrade Attack T1689 2 rules
Prevent Command History Logging T1690 3 rules
No specific technique 26 rules

Credential Access

OS Credential Dumping T1003 389 rules
OS Credential Dumping: LSASS Memory T1003.001 168 rules
OS Credential Dumping: Security Account Manager T1003.002 58 rules
OS Credential Dumping: NTDS T1003.003 58 rules
OS Credential Dumping: LSA Secrets T1003.004 23 rules
OS Credential Dumping: Cached Domain Credentials T1003.005 16 rules
OS Credential Dumping: DCSync T1003.006 26 rules
OS Credential Dumping: Proc Filesystem T1003.007 5 rules
OS Credential Dumping: /etc/passwd and /etc/shadow T1003.008 13 rules
Network Sniffing T1040 24 rules
Input Capture T1056 20 rules
Input Capture: Keylogging T1056.001 5 rules
Input Capture: GUI Input Capture T1056.002 5 rules
Input Capture: Credential API Hooking T1056.004 4 rules
Brute Force T1110 296 rules
Brute Force: Password Guessing T1110.001 44 rules
Brute Force: Password Cracking T1110.002 3 rules
Brute Force: Password Spraying T1110.003 81 rules
Brute Force: Credential Stuffing T1110.004 31 rules
Multi-Factor Authentication Interception T1111 4 rules
Forced Authentication T1187 29 rules
Exploitation for Credential Access T1212 20 rules
Steal Application Access Token T1528 73 rules
Steal Web Session Cookie T1539 21 rules
Unsecured Credentials T1552 210 rules
Unsecured Credentials: Credentials In Files T1552.001 76 rules
Unsecured Credentials: Credentials in Registry T1552.002 10 rules
Unsecured Credentials: Shell History T1552.003 3 rules
Unsecured Credentials: Private Keys T1552.004 28 rules
Unsecured Credentials: Cloud Instance Metadata API T1552.005 14 rules
Unsecured Credentials: Group Policy Preferences T1552.006 8 rules
Unsecured Credentials: Container API T1552.007 24 rules
Credentials from Password Stores T1555 98 rules
Credentials from Password Stores: Keychain T1555.001 8 rules
Credentials from Password Stores: Credentials from Web Browsers T1555.003 19 rules
Credentials from Password Stores: Windows Credential Manager T1555.004 15 rules
Credentials from Password Stores: Password Managers T1555.005 4 rules
Credentials from Password Stores: Cloud Secrets Management Stores T1555.006 8 rules
Modify Authentication Process T1556 145 rules
Modify Authentication Process: Password Filter DLL T1556.002 5 rules
Modify Authentication Process: Pluggable Authentication Modules T1556.003 5 rules
Modify Authentication Process: Network Device Authentication T1556.004 2 rules
Modify Authentication Process: Multi-Factor Authentication T1556.006 33 rules
Modify Authentication Process: Hybrid Identity T1556.007 6 rules
Modify Authentication Process: Network Provider DLL T1556.008 1 rule
Modify Authentication Process: Conditional Access Policies T1556.009 13 rules
Adversary-in-the-Middle T1557 61 rules
Adversary-in-the-Middle: Name Resolution Poisoning and SMB Relay T1557.001 28 rules
Adversary-in-the-Middle: ARP Cache Poisoning T1557.002 3 rules
Adversary-in-the-Middle: DHCP Spoofing T1557.003 1 rule
Steal or Forge Kerberos Tickets T1558 84 rules
Steal or Forge Kerberos Tickets: Golden Ticket T1558.001 14 rules
Steal or Forge Kerberos Tickets: Silver Ticket T1558.002 7 rules
Steal or Forge Kerberos Tickets: Kerberoasting T1558.003 40 rules
Steal or Forge Kerberos Tickets: AS-REP Roasting T1558.004 10 rules
Steal or Forge Kerberos Tickets: Ccache Files T1558.005 3 rules
Forge Web Credentials T1606 16 rules
Forge Web Credentials: Web Cookies T1606.001 1 rule
Forge Web Credentials: SAML Tokens T1606.002 2 rules
Multi-Factor Authentication Request Generation T1621 31 rules
Steal or Forge Authentication Certificates T1649 27 rules
No specific technique 34 rules

Discovery

System Service Discovery T1007 25 rules
Application Window Discovery T1010 2 rules
Query Registry T1012 34 rules
System Network Configuration Discovery T1016 70 rules
System Network Configuration Discovery: Internet Connection Discovery T1016.001 8 rules
Remote System Discovery T1018 85 rules
System Owner/User Discovery T1033 78 rules
Network Sniffing T1040 24 rules
Network Service Discovery T1046 96 rules
System Network Connections Discovery T1049 33 rules
Process Discovery T1057 33 rules
Permission Groups Discovery T1069 124 rules
Permission Groups Discovery: Local Groups T1069.001 46 rules
Permission Groups Discovery: Domain Groups T1069.002 74 rules
Permission Groups Discovery: Cloud Groups T1069.003 8 rules
System Information Discovery T1082 158 rules
File and Directory Discovery T1083 67 rules
Account Discovery T1087 197 rules
Account Discovery: Local Account T1087.001 47 rules
Account Discovery: Domain Account T1087.002 91 rules
Account Discovery: Email Account T1087.003 1 rule
Account Discovery: Cloud Account T1087.004 26 rules
Peripheral Device Discovery T1120 6 rules
System Time Discovery T1124 6 rules
Network Share Discovery T1135 36 rules
Password Policy Discovery T1201 30 rules
Browser Information Discovery T1217 4 rules
Domain Trust Discovery T1482 57 rules
Virtualization/Sandbox Evasion T1497 20 rules
Virtualization/Sandbox Evasion: System Checks T1497.001 8 rules
Virtualization/Sandbox Evasion: Time Based Checks T1497.003 4 rules
Software Discovery T1518 42 rules
Software Discovery: Security Software Discovery T1518.001 19 rules
Cloud Service Discovery T1526 44 rules
Cloud Service Dashboard T1538 4 rules
Cloud Infrastructure Discovery T1580 42 rules
Container and Resource Discovery T1613 43 rules
System Location Discovery T1614 6 rules
System Location Discovery: System Language Discovery T1614.001 4 rules
Group Policy Discovery T1615 10 rules
Cloud Storage Object Discovery T1619 7 rules
Debugger Evasion T1622 2 rules
Device Driver Discovery T1652 1 rule
Log Enumeration T1654 2 rules
Virtual Machine Discovery T1673 4 rules
No specific technique 26 rules

Lateral Movement

Remote Services T1021 378 rules
Remote Services: Remote Desktop Protocol T1021.001 80 rules
Remote Services: SMB/Windows Admin Shares T1021.002 108 rules
Remote Services: Distributed Component Object Model T1021.003 42 rules
Remote Services: SSH T1021.004 41 rules
Remote Services: VNC T1021.005 4 rules
Remote Services: Windows Remote Management T1021.006 37 rules
Remote Services: Cloud Services T1021.007 19 rules
Remote Services: Direct Cloud VM Connections T1021.008 4 rules
Software Deployment Tools T1072 31 rules
Taint Shared Content T1080 4 rules
Replication Through Removable Media T1091 9 rules
Exploitation of Remote Services T1210 69 rules
Internal Spearphishing T1534 4 rules
Use Alternate Authentication Material T1550 123 rules
Use Alternate Authentication Material: Application Access Token T1550.001 55 rules
Use Alternate Authentication Material: Pass the Hash T1550.002 16 rules
Use Alternate Authentication Material: Pass the Ticket T1550.003 13 rules
Use Alternate Authentication Material: Web Session Cookie T1550.004 8 rules
Remote Service Session Hijacking T1563 18 rules
Remote Service Session Hijacking: SSH Hijacking T1563.001 8 rules
Remote Service Session Hijacking: RDP Hijacking T1563.002 8 rules
Lateral Tool Transfer T1570 46 rules
No specific technique 12 rules

Collection

Data from Local System T1005 70 rules
Data from Removable Media T1025 5 rules
Data from Network Shared Drive T1039 14 rules
Input Capture T1056 20 rules
Input Capture: Keylogging T1056.001 5 rules
Input Capture: GUI Input Capture T1056.002 5 rules
Input Capture: Credential API Hooking T1056.004 4 rules
Data Staged T1074 32 rules
Data Staged: Local Data Staging T1074.001 19 rules
Data Staged: Remote Data Staging T1074.002 4 rules
Screen Capture T1113 24 rules
Email Collection T1114 68 rules
Email Collection: Local Email Collection T1114.001 14 rules
Email Collection: Remote Email Collection T1114.002 19 rules
Email Collection: Email Forwarding Rule T1114.003 16 rules
Clipboard Data T1115 20 rules
Automated Collection T1119 35 rules
Audio Capture T1123 11 rules
Video Capture T1125 8 rules
Browser Session Hijacking T1185 17 rules
Data from Information Repositories T1213 54 rules
Data from Information Repositories: Sharepoint T1213.002 4 rules
Data from Information Repositories: Code Repositories T1213.003 14 rules
Data from Information Repositories: Databases T1213.006 3 rules
Data from Cloud Storage T1530 80 rules
Adversary-in-the-Middle T1557 61 rules
Adversary-in-the-Middle: Name Resolution Poisoning and SMB Relay T1557.001 28 rules
Adversary-in-the-Middle: ARP Cache Poisoning T1557.002 3 rules
Adversary-in-the-Middle: DHCP Spoofing T1557.003 1 rule
Archive Collected Data T1560 44 rules
Archive Collected Data: Archive via Utility T1560.001 35 rules
Archive Collected Data: Archive via Library T1560.002 3 rules
No specific technique 5 rules

Command & Control

Data Obfuscation T1001 8 rules
Data Obfuscation: Protocol or Service Impersonation T1001.003 3 rules
Fallback Channels T1008 16 rules
Application Layer Protocol T1071 387 rules
Application Layer Protocol: Web Protocols T1071.001 107 rules
Application Layer Protocol: File Transfer Protocols T1071.002 8 rules
Application Layer Protocol: Mail Protocols T1071.003 4 rules
Application Layer Protocol: DNS T1071.004 44 rules
Proxy T1090 82 rules
Proxy: Internal Proxy T1090.001 10 rules
Proxy: External Proxy T1090.002 7 rules
Proxy: Multi-hop Proxy T1090.003 13 rules
Proxy: Domain Fronting T1090.004 1 rule
Non-Application Layer Protocol T1095 42 rules
Web Service T1102 59 rules
Web Service: Dead Drop Resolver T1102.001 8 rules
Web Service: Bidirectional Communication T1102.002 19 rules
Web Service: One-Way Communication T1102.003 4 rules
Ingress Tool Transfer T1105 265 rules
Data Encoding T1132 15 rules
Data Encoding: Standard Encoding T1132.001 6 rules
Traffic Signaling T1205 1 rule
Traffic Signaling: Port Knocking T1205.001 1 rule
Remote Access Tools T1219 100 rules
Remote Access Tools: Remote Desktop Software T1219.002 50 rules
Dynamic Resolution T1568 34 rules
Dynamic Resolution: Fast Flux DNS T1568.001 1 rule
Dynamic Resolution: Domain Generation Algorithms T1568.002 14 rules
Non-Standard Port T1571 27 rules
Protocol Tunneling T1572 82 rules
Encrypted Channel T1573 23 rules
Encrypted Channel: Asymmetric Cryptography T1573.002 9 rules
Content Injection T1659 4 rules
No specific technique 49 rules

Exfiltration

Exfiltration Over Other Network Medium T1011 3 rules
Exfiltration Over Other Network Medium: Exfiltration Over Bluetooth T1011.001 1 rule
Automated Exfiltration T1020 49 rules
Automated Exfiltration: Traffic Duplication T1020.001 1 rule
Scheduled Transfer T1029 2 rules
Data Transfer Size Limits T1030 26 rules
Exfiltration Over C2 Channel T1041 77 rules
Exfiltration Over Alternative Protocol T1048 118 rules
Exfiltration Over Alternative Protocol: Exfiltration Over Symmetric Encrypted Non-C2 Protocol T1048.001 2 rules
Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol T1048.002 4 rules
Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol T1048.003 31 rules
Exfiltration Over Physical Medium T1052 6 rules
Exfiltration Over Physical Medium: Exfiltration over USB T1052.001 4 rules
Transfer Data to Cloud Account T1537 55 rules
Exfiltration Over Web Service T1567 151 rules
Exfiltration Over Web Service: Exfiltration to Code Repository T1567.001 11 rules
Exfiltration Over Web Service: Exfiltration to Cloud Storage T1567.002 43 rules
Exfiltration Over Web Service: Exfiltration to Text Storage Sites T1567.003 3 rules
Exfiltration Over Web Service: Exfiltration Over Webhook T1567.004 1 rule
No specific technique 16 rules

Impact

Data Destruction T1485 177 rules
Data Destruction: Lifecycle-Triggered Deletion T1485.001 4 rules
Data Encrypted for Impact T1486 75 rules
Service Stop T1489 78 rules
Inhibit System Recovery T1490 96 rules
Defacement T1491 12 rules
Defacement: Internal Defacement T1491.001 4 rules
Defacement: External Defacement T1491.002 1 rule
Firmware Corruption T1495 1 rule
Resource Hijacking T1496 51 rules
Resource Hijacking: Compute Hijacking T1496.001 2 rules
Resource Hijacking: Cloud Service Hijacking T1496.004 5 rules
Network Denial of Service T1498 46 rules
Network Denial of Service: Reflection Amplification T1498.002 1 rule
Endpoint Denial of Service T1499 37 rules
Endpoint Denial of Service: OS Exhaustion Flood T1499.001 1 rule
Endpoint Denial of Service: Service Exhaustion Flood T1499.002 2 rules
Endpoint Denial of Service: Application Exhaustion Flood T1499.003 2 rules
Endpoint Denial of Service: Application or System Exploitation T1499.004 4 rules
System Shutdown/Reboot T1529 35 rules
Account Access Removal T1531 62 rules
Disk Wipe T1561 4 rules
Disk Wipe: Disk Content Wipe T1561.001 2 rules
Disk Wipe: Disk Structure Wipe T1561.002 3 rules
Data Manipulation T1565 69 rules
Data Manipulation: Stored Data Manipulation T1565.001 26 rules
Data Manipulation: Transmitted Data Manipulation T1565.002 3 rules
Financial Theft T1657 1 rule
No specific technique 48 rules

MITRE ATT&CK

Initial Access

Drive-By Compromise T1456 1 rule
Supply Chain Compromise T1474 2 rules
Phishing T1660 1 rule

Execution

Command and Scripting Interpreter T1623 1 rule

Persistence

Foreground Persistence T1541 1 rule
Event Triggered Execution T1624 1 rule
Hijack Execution Flow T1625 1 rule

Privilege Escalation

Exploitation for Privilege Escalation T1404 1 rule
Abuse Elevation Control Mechanism T1626 2 rules
Process Injection T1631 1 rule

Defense Evasion

Obfuscated Files or Information T1406 1 rule
Input Injection T1516 1 rule
Foreground Persistence T1541 1 rule
Hooking T1617 1 rule
Execution Guardrails T1627 1 rule
Hide Artifacts T1628 1 rule
Impair Defenses T1629 7 rules
Indicator Removal on Host T1630 2 rules
Process Injection T1631 1 rule
Virtualization/Sandbox Evasion T1633 1 rule
Masquerading T1655 1 rule

Credential Access

Clipboard Data T1414 1 rule
Input Capture T1417 2 rules
Access Notifications T1517 1 rule
Credentials from Password Store T1634 1 rule
Steal Application Access Token T1635 2 rules

Discovery

Software Discovery T1418 3 rules
System Network Configuration Discovery T1422 1 rule
Network Service Scanning T1423 1 rule
Process Discovery T1424 2 rules
Location Tracking T1430 1 rule

Lateral Movement

Exploitation of Remote Services T1428 1 rule

Collection

Stored Application Data T1409 1 rule
Clipboard Data T1414 1 rule
Input Capture T1417 2 rules
Audio Capture T1429 1 rule
Location Tracking T1430 1 rule
Video Capture T1512 1 rule
Screen Capture T1513 1 rule
Access Notifications T1517 1 rule
Archive Collected Data T1532 1 rule
Call Control T1616 1 rule
Protected User Data T1636 1 rule
Protected User Data: Contact List T1636.003 1 rule
Adversary-in-the-Middle T1638 1 rule

Command and Control

Web Service T1481 1 rule
Non-Standard Port T1509 1 rule
Ingress Tool Transfer T1544 1 rule
Call Control T1616 1 rule

Exfiltration

Exfiltration Over Alternative Protocol T1639 1 rule

Impact

Data Encrypted for Impact T1471 1 rule
Input Injection T1516 1 rule
SMS Control T1582 1 rule
Call Control T1616 1 rule
Account Access Removal T1640 1 rule
Data Manipulation T1641 2 rules
Endpoint Denial of Service T1642 1 rule
Generate Traffic from Victim T1643 1 rule

MITRE ATT&CK

Initial Access

Exploit Public-Facing Application T0819 3 rules
External Remote Services T0822 1 rule
Rogue Master T0848 1 rule
Supply Chain Compromise T0862 1 rule
Spearphishing Attachment T0865 5 rules
Exploitation of Remote Services T0866 5 rules
Internet Accessible Device T0883 1 rule
Remote Services T0886 4 rules

Execution

Native API T0834 1 rule
Scripting T0853 7 rules
Change Operating Mode T0858 4 rules
User Execution T0863 4 rules
Execution through API T0871 5 rules

Persistence

Module Firmware T0839 1 rule
System Firmware T0857 2 rules
Valid Accounts T0859 7 rules
Project File Infection T0873 3 rules
Modify Program T0889 1 rule

Privilege Escalation

Exploitation for Privilege Escalation T0890 4 rules

Evasion

Rootkit T0851 1 rule
Change Operating Mode T0858 4 rules

Discovery

Network Connection Enumeration T0840 1 rule
Network Sniffing T0842 4 rules
Remote System Discovery T0846 1 rule
Remote System Information Discovery T0888 1 rule

Lateral Movement

Program Download T0843 2 rules
Valid Accounts T0859 7 rules
Exploitation of Remote Services T0866 5 rules
Remote Services T0886 4 rules

Collection

Program Upload T0845 1 rule

Command and Control

Connection Proxy T0884 1 rule
Commonly Used Port T0885 1 rule

Inhibit Response Function

Denial of Service T0814 1 rule
Device Restart/Shutdown T0816 1 rule
Rootkit T0851 1 rule
System Firmware T0857 2 rules
Service Stop T0881 1 rule

Impair Process Control

Brute Force I/O T0806 1 rule
Modify Parameter T0836 1 rule
Module Firmware T0839 1 rule
Unauthorized Command Message T0855 3 rules

Impact

Denial of Control T0813 3 rules
Loss of Availability T0826 4 rules
Loss of Control T0827 2 rules
Loss of Productivity and Revenue T0828 2 rules
Manipulation of Control T0831 1 rule
Loss of Protection T0837 1 rule
Damage to Property T0879 1 rule
Theft of Operational Information T0882 2 rules

Initial Access

AI Supply Chain Compromise: Model AML.T0010.003 1 rule
Evade AI Model AML.T0015 2 rules

AI Model Access

AI Model Inference API Access AML.T0040 1 rule
Full AI Model Access AML.T0044 2 rules

Execution

LLM Prompt Injection AML.T0051 8 rules
AI Agent Tool Invocation AML.T0053 2 rules

Privilege Escalation

AI Agent Tool Invocation AML.T0053 2 rules
LLM Jailbreak AML.T0054 7 rules

Defense Evasion

Evade AI Model AML.T0015 2 rules
LLM Jailbreak AML.T0054 7 rules

Credential Access

Unsecured Credentials AML.T0055 1 rule

Collection

Data from AI Services AML.T0085 1 rule
Data from AI Services: AI Agent Tools AML.T0085.001 1 rule

Exfiltration

Exfiltration via AI Inference API AML.T0024 1 rule
Exfiltration via AI Inference API: Infer Training Data Membership AML.T0024.000 1 rule
Exfiltration via AI Agent Tool Invocation AML.T0086 3 rules

Impact

Evade AI Model AML.T0015 2 rules
Denial of AI Service AML.T0029 1 rule
Cost Harvesting AML.T0034 2 rules
Spamming AI System with Chaff Data AML.T0046 1 rule

Credential Phishing

Credential Phishing 1 rule
Encryption 12 rules
Evasion 306 rules
Exploit 4 rules
Free email provider 26 rules
Free file host 82 rules
Free subdomain host 42 rules
HTML injection 1 rule
HTML smuggling 44 rules
ICS Phishing 12 rules
IPFS 4 rules
ISO 1 rule
Image as content 27 rules
Impersonation: Brand 236 rules
Impersonation: Domain 2 rules
Impersonation: Email address 1 rule
Impersonation: Employee 12 rules
Impersonation: VIP 4 rules
LNK 1 rule
Lookalike domain 52 rules
Macros 6 rules
OneNote 4 rules
Open redirect 141 rules
Out of band pivot 4 rules
PDF 64 rules
Punycode 2 rules
QR code 29 rules
Scripting 39 rules
Service abuse 1 rule
Social engineering 439 rules
Spoofing 22 rules
No specific technique 8 rules

Malware/Ransomware

Encryption 18 rules
Evasion 151 rules
Exploit 10 rules
Free email provider 3 rules
Free file host 20 rules
Free subdomain host 10 rules
HTML smuggling 37 rules
ICS Phishing 7 rules
IPFS 2 rules
ISO 1 rule
Image as content 6 rules
Impersonation: Brand 18 rules
Impersonation: Domain 2 rules
Impersonation: Email address 1 rule
Impersonation: Employee 2 rules
LNK 5 rules
Lookalike domain 2 rules
Macros 13 rules
OneNote 1 rule
Open redirect 102 rules
Out of band pivot 1 rule
PDF 24 rules
Punycode 1 rule
QR code 3 rules
Scripting 53 rules
Social engineering 50 rules
Spoofing 3 rules
No specific technique 9 rules

BEC/Fraud

Encryption 2 rules
Evasion 67 rules
Free email provider 32 rules
Free file host 15 rules
Free subdomain host 6 rules
HTML injection 1 rule
ICS Phishing 4 rules
Impersonation: Brand 51 rules
Impersonation: Domain 2 rules
Impersonation: Email address 1 rule
Impersonation: Employee 14 rules
Impersonation: VIP 12 rules
Lookalike domain 11 rules
Macros 1 rule
OneNote 1 rule
Open redirect 5 rules
Out of band pivot 7 rules
PDF 16 rules
QR code 1 rule
Scripting 2 rules
Social engineering 164 rules
Spoofing 12 rules
No specific technique 2 rules

Callback Phishing

Encryption 1 rule
Evasion 33 rules
Exploit 3 rules
Free email provider 20 rules
Free file host 7 rules
Free subdomain host 3 rules
ICS Phishing 3 rules
Image as content 1 rule
Impersonation: Brand 40 rules
Impersonation: Employee 2 rules
Impersonation: VIP 1 rule
Out of band pivot 31 rules
PDF 5 rules
Social engineering 79 rules
Spoofing 1 rule

Spam

Encryption 1 rule
Evasion 27 rules
Exploit 1 rule
Free email provider 22 rules
Free file host 7 rules
Free subdomain host 5 rules
ICS Phishing 2 rules
Image as content 6 rules
Impersonation: Brand 23 rules
Lookalike domain 3 rules
Open redirect 4 rules
PDF 1 rule
Scripting 1 rule
Social engineering 53 rules
Spoofing 2 rules
No specific technique 4 rules

Extortion

Encryption 1 rule
Evasion 4 rules
Free file host 2 rules
Impersonation: Brand 5 rules
PDF 1 rule
Social engineering 8 rules
Spoofing 2 rules

Reconnaissance

No specific technique 2 rules

Uncategorized

Evasion 1 rule
Free subdomain host 1 rule
HTML smuggling 2 rules
ICS Phishing 1 rule
Impersonation: VIP 1 rule
Social engineering 1 rule
Spoofing 2 rules

Cloud & SaaS activity monitoring

Cloud, SaaS, and identity governance: app registrations, OAuth grants, role and permission changes, sharing and config drift -- audit activity no single ATT&CK technique describes.

Veeam 96 rules
GCP 30 rules
AWS 27 rules
Kubernetes 24 rules
Google Workspace 17 rules
Auth0 16 rules
Notion 16 rules
Duo 15 rules
Entra ID / Azure AD 15 rules
GitHub 15 rules
Okta 14 rules
Snowflake 13 rules
Asana 11 rules
Snyk 10 rules
Dropbox 9 rules
Tines 9 rules
Microsoft Graph 7 rules
Push Security 7 rules
Zoom 7 rules
MongoDB 6 rules
Docusign 5 rules
Microsoft 365 5 rules
Axonius 4 rules
VMware SD-WAN and SASE 4 rules
CrowdStrike 3 rules
OneLogin 3 rules
Tailscale 3 rules
Other cloud & SaaS 19 rules

Endpoint & network anomalies

Statistical and behavioral outliers on hosts and networks: process-tree analysis, command-line and volume spikes, baselining.

Panther 17 rules
Splunk 6 rules
Kusto 4 rules
YARA-L 4 rules
Elastic 2 rules

Threat-intelligence matching

Indicator and reputation matching: hash, IP, URL, and domain lookups against threat feeds, VirusTotal, Safebrowsing, and prevalence sources.

YARA-L 28 rules
Panther 15 rules
Elastic 7 rules
Splunk 2 rules
Sublime MQL 1 rule

Alert correlation & meta-detections

Meta-detections that consume the output of other detections or tools: multi-alert aggregation and vendor-verdict passthroughs.

Elastic 34 rules
Panther 28 rules
Kusto 17 rules
Splunk 4 rules
Sigma 2 rules
YARA-L 1 rule

Threat hunting

Exploratory hunting queries that surface broad activity for analyst triage rather than firing on a specific malicious match.

YARA-L 17 rules
Kusto 5 rules
Panther 1 rule

AI & LLM governance

AI and LLM content-safety and governance: prompt-injection, toxicity, bias, banned-topic, and model-policy violations.

Kusto 38 rules
Elastic 2 rules
Splunk 1 rule

Data loss prevention

Data-loss-prevention content patterns: payment cards, national IDs, passports, bank accounts, and other regulated or sensitive data.

National IDs & passports 33 rules
Payment cards (PCI) 17 rules
Bank & financial accounts 15 rules
Health & medical 3 rules
Other sensitive data 62 rules

Operational & security hygiene

Operational and security-hygiene checks: agent and signature staleness, unsupported versions, deployment posture, and outbreak thresholds.

Panther 46 rules
Kusto 22 rules
Sigma 3 rules
Splunk 3 rules
Elastic 1 rule

Untagged