Elastic non-Windows coverage

1,299 non-Windows Elastic detection rules across 14 platforms, grouped by MITRE ATT&CK technique within each platform. The Windows coverage matrix lives at /rules/elastic/; this page reorganizes the same corpus along platform × technique because non-Windows rules have no catalog event IDs to plot.

For coverage organized by each platform's native action vocabulary across all vendors, see the platform matrices: AWS, Azure AD, GCP, M365, Okta. This page is the vendor-organized browse of the same rules.

Platform (all)
Domain (all)

Linux

Reconnaissance

Active Scanning T1595 2 rules
Active Scanning: Vulnerability Scanning T1595.002 1 rule
Active Scanning: Wordlist Scanning T1595.003 1 rule

Resource Development

Develop Capabilities: Malware T1587.001 1 rule
Obtain Capabilities: Malware T1588.001 1 rule

Initial Access

Exploit Public-Facing Application T1190 18 rules
Supply Chain Compromise: Compromise Software Supply Chain T1195.002 6 rules
Supply Chain Compromise: Compromise Software Dependencies and Development Tools T1195.001 1 rule

Execution

Command and Scripting Interpreter: Unix Shell T1059.004 109 rules
Command and Scripting Interpreter: Python T1059.006 23 rules
Container Administration Command T1609 15 rules
Command and Scripting Interpreter T1059 14 rules
User Execution: Malicious File T1204.002 13 rules
Exploitation for Client Execution T1203 9 rules
Scheduled Task/Job: Cron T1053.003 8 rules
Command and Scripting Interpreter: Lua T1059.011 7 rules
Deploy Container T1610 7 rules
Command and Scripting Interpreter: PowerShell T1059.001 5 rules
Scheduled Task/Job: At T1053.002 4 rules
Command and Scripting Interpreter: JavaScript T1059.007 4 rules
Native API T1106 3 rules
Cloud Administration Command T1651 3 rules
Scheduled Task/Job: Systemd Timers T1053.006 2 rules
Scheduled Task/Job: Container Orchestration Job T1053.007 2 rules
Inter-Process Communication T1559 2 rules
Command and Scripting Interpreter: AppleScript T1059.002 1 rule
Command and Scripting Interpreter: Windows Command Shell T1059.003 1 rule
Software Deployment Tools T1072 1 rule
Shared Modules T1129 1 rule
System Services: Service Execution T1569.002 1 rule

Persistence

Create or Modify System Process T1543 34 rules
Boot or Logon Autostart Execution: Kernel Modules and Extensions T1547.006 14 rules
Server Software Component: Web Shell T1505.003 12 rules
Create or Modify System Process: Systemd Service T1543.002 10 rules
Boot or Logon Initialization Scripts: RC Scripts T1037.004 9 rules
Create Account: Local Account T1136.001 8 rules
Boot or Logon Initialization Scripts T1037 7 rules
Account Manipulation: SSH Authorized Keys T1098.004 7 rules
Account Manipulation T1098 5 rules
External Remote Services T1133 5 rules
Boot or Logon Autostart Execution: XDG Autostart Entries T1547.013 5 rules
Compromise Host Software Binary T1554 4 rules
Event Triggered Execution: Udev Rules T1546.017 3 rules
Account Manipulation: Additional Local or Domain Groups T1098.007 2 rules
Create or Modify System Process: Container Service T1543.005 2 rules
Event Triggered Execution: Python Startup Hooks T1546.018 2 rules
Create or Modify System Process: Windows Service T1543.003 1 rule
Create or Modify System Process: Launch Daemon T1543.004 1 rule
Boot or Logon Autostart Execution T1547 1 rule

Privilege Escalation

Exploitation for Privilege Escalation T1068 29 rules
Escape to Host T1611 25 rules
Abuse Elevation Control Mechanism: Setuid and Setgid T1548.001 19 rules
Abuse Elevation Control Mechanism: Sudo and Sudo Caching T1548.003 17 rules
Event Triggered Execution T1546 9 rules
Event Triggered Execution: Unix Shell Configuration Modification T1546.004 9 rules
Event Triggered Execution: Installer Packages T1546.016 8 rules
Abuse Elevation Control Mechanism T1548 6 rules

Stealth

Hijack Execution Flow T1574 26 rules
Rootkit T1014 22 rules
Impair Defenses: Disable or Modify Tools T1562.001 20 rules
Deobfuscate/Decode Files or Information T1140 16 rules
Hijack Execution Flow: Dynamic Linker Hijacking T1574.006 15 rules
Hide Artifacts: Hidden Files and Directories T1564.001 10 rules
Obfuscated Files or Information T1027 7 rules
Masquerading: Match Legitimate Resource Name or Location T1036.005 7 rules
Indicator Removal: File Deletion T1070.004 7 rules
Valid Accounts T1078 7 rules
System Binary Proxy Execution T1218 6 rules
Pre-OS Boot T1542 6 rules
Hide Artifacts T1564 6 rules
Reflective Code Loading T1620 6 rules
Obfuscated Files or Information: Command Obfuscation T1027.010 4 rules
Process Injection: Ptrace System Calls T1055.008 4 rules
Indicator Removal: Clear Linux or Mac System Logs T1070.002 4 rules
Direct Volume Access T1006 3 rules
Masquerading T1036 3 rules
Masquerading: Masquerade Task or Service T1036.004 3 rules
Process Injection T1055 3 rules
Valid Accounts: Local Accounts T1078.003 3 rules
Indirect Command Execution T1202 3 rules
Hijack Execution Flow: Path Interception by PATH Environment Variable T1574.007 3 rules
Masquerading: Rename Legitimate Utilities T1036.003 2 rules
Masquerading: Break Process Trees T1036.009 2 rules
Indicator Removal: Clear Command History T1070.003 2 rules
Virtualization/Sandbox Evasion: System Checks T1497.001 2 rules
Impair Defenses: Indicator Blocking T1562.006 2 rules
Hide Artifacts: Hidden Users T1564.002 2 rules
Hijack Execution Flow: KernelCallbackTable T1574.013 2 rules
Obfuscated Files or Information: Compile After Delivery T1027.004 1 rule
Obfuscated Files or Information: Compression T1027.015 1 rule
Masquerading: Space after Filename T1036.006 1 rule
Masquerading: Masquerade File Type T1036.008 1 rule
Indicator Removal T1070 1 rule
Indicator Removal: Timestomp T1070.006 1 rule
Trusted Developer Utilities Proxy Execution T1127 1 rule
Traffic Signaling: Port Knocking T1205.001 1 rule
Exploitation for Stealth T1211 1 rule
System Binary Proxy Execution: Rundll32 T1218.011 1 rule
Pre-OS Boot: Bootkit T1542.003 1 rule
Impair Defenses T1562 1 rule
Impair Defenses: Disable or Modify System Firewall T1562.004 1 rule

Defense Impairment

File and Directory Permissions Modification: Linux and Mac Permissions T1222.002 10 rules
Modify Authentication Process T1556 7 rules
Modify Authentication Process: Pluggable Authentication Modules T1556.003 5 rules
Subvert Trust Controls T1553 2 rules
Subvert Trust Controls: Install Root Certificate T1553.004 1 rule
Modify System Image: Patch System Image T1601.001 1 rule

Credential Access

Unsecured Credentials: Credentials In Files T1552.001 21 rules
OS Credential Dumping: /etc/passwd and /etc/shadow T1003.008 7 rules
Brute Force: Password Guessing T1110.001 6 rules
OS Credential Dumping: Proc Filesystem T1003.007 5 rules
Steal Application Access Token T1528 5 rules
Brute Force: Password Spraying T1110.003 4 rules
Unsecured Credentials: Private Keys T1552.004 4 rules
OS Credential Dumping T1003 3 rules
Network Sniffing T1040 3 rules
Exploitation for Credential Access T1212 3 rules
Unsecured Credentials: Cloud Instance Metadata API T1552.005 3 rules
Credentials from Password Stores T1555 2 rules
Brute Force T1110 1 rule
Brute Force: Password Cracking T1110.002 1 rule
Steal Web Session Cookie T1539 1 rule
Unsecured Credentials T1552 1 rule
Unsecured Credentials: Container API T1552.007 1 rule

Discovery

System Information Discovery T1082 28 rules
Container and Resource Discovery T1613 27 rules
File and Directory Discovery T1083 20 rules
Network Service Discovery T1046 11 rules
Process Discovery T1057 11 rules
Software Discovery T1518 9 rules
System Owner/User Discovery T1033 8 rules
System Network Configuration Discovery T1016 5 rules
System Network Connections Discovery T1049 4 rules
Remote System Discovery T1018 3 rules
Permission Groups Discovery T1069 3 rules
Permission Groups Discovery: Local Groups T1069.001 3 rules
Account Discovery: Local Account T1087.001 3 rules
Permission Groups Discovery: Domain Groups T1069.002 2 rules
Software Discovery: Security Software Discovery T1518.001 2 rules
Account Discovery T1087 1 rule
Account Discovery: Domain Account T1087.002 1 rule
Network Share Discovery T1135 1 rule

Lateral Movement

Remote Services: SSH T1021.004 15 rules
Exploitation of Remote Services T1210 13 rules
Remote Service Session Hijacking: SSH Hijacking T1563.001 8 rules
Remote Services: Remote Desktop Protocol T1021.001 7 rules
Lateral Tool Transfer T1570 7 rules
Remote Services T1021 5 rules
Use Alternate Authentication Material T1550 2 rules
Use Alternate Authentication Material: Application Access Token T1550.001 2 rules
No specific technique 1 rule

Collection

Data from Local System T1005 16 rules
Archive Collected Data: Archive via Utility T1560.001 4 rules
Input Capture T1056 2 rules
Data from Network Shared Drive T1039 1 rule
Data Staged: Local Data Staging T1074.001 1 rule
Screen Capture T1113 1 rule
Clipboard Data T1115 1 rule
Automated Collection T1119 1 rule
Audio Capture T1123 1 rule
Video Capture T1125 1 rule
Data from Information Repositories T1213 1 rule
Data from Information Repositories: Code Repositories T1213.003 1 rule
Archive Collected Data: Archive via Library T1560.002 1 rule

Command & Control

Application Layer Protocol T1071 35 rules
Ingress Tool Transfer T1105 22 rules
Non-Application Layer Protocol T1095 15 rules
Protocol Tunneling T1572 13 rules
Proxy T1090 9 rules
Application Layer Protocol: Web Protocols T1071.001 8 rules
Non-Standard Port T1571 4 rules
Web Service: Bidirectional Communication T1102.002 3 rules
Proxy: External Proxy T1090.002 2 rules
Proxy: Multi-hop Proxy T1090.003 2 rules
Application Layer Protocol: DNS T1071.004 1 rule
Proxy: Internal Proxy T1090.001 1 rule
Web Service T1102 1 rule
Web Service: Dead Drop Resolver T1102.001 1 rule
Data Encoding: Standard Encoding T1132.001 1 rule
Remote Access Tools T1219 1 rule
Dynamic Resolution: Domain Generation Algorithms T1568.002 1 rule
Encrypted Channel: Asymmetric Cryptography T1573.002 1 rule

Exfiltration

Exfiltration Over C2 Channel T1041 7 rules
Exfiltration Over Alternative Protocol T1048 4 rules
Data Transfer Size Limits T1030 2 rules
Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol T1048.003 2 rules
Exfiltration Over Physical Medium: Exfiltration over USB T1052.001 2 rules
Exfiltration Over Other Network Medium: Exfiltration Over Bluetooth T1011.001 1 rule
Exfiltration Over Web Service: Exfiltration to Code Repository T1567.001 1 rule
Exfiltration Over Web Service: Exfiltration to Cloud Storage T1567.002 1 rule
Exfiltration Over Web Service: Exfiltration to Text Storage Sites T1567.003 1 rule

Impact

Service Stop T1489 8 rules
Data Encrypted for Impact T1486 5 rules
Data Destruction T1485 2 rules
Resource Hijacking T1496 2 rules
Resource Hijacking: Compute Hijacking T1496.001 2 rules
Account Access Removal T1531 2 rules
Data Manipulation: Stored Data Manipulation T1565.001 2 rules
Network Denial of Service T1498 1 rule
Data Manipulation: Transmitted Data Manipulation T1565.002 1 rule
No specific technique 2 rules

Untagged

macOS

Resource Development

Develop Capabilities: Malware T1587.001 1 rule

Initial Access

Exploit Public-Facing Application T1190 5 rules
Supply Chain Compromise: Compromise Software Supply Chain T1195.002 5 rules
Supply Chain Compromise: Compromise Software Dependencies and Development Tools T1195.001 4 rules
Drive-by Compromise T1189 1 rule
Phishing: Spearphishing Attachment T1566.001 1 rule

Execution

Command and Scripting Interpreter: Unix Shell T1059.004 20 rules
Command and Scripting Interpreter: Python T1059.006 20 rules
Command and Scripting Interpreter: AppleScript T1059.002 16 rules
Command and Scripting Interpreter: JavaScript T1059.007 14 rules
Command and Scripting Interpreter: PowerShell T1059.001 10 rules
User Execution: Malicious File T1204.002 8 rules
Command and Scripting Interpreter T1059 6 rules
Exploitation for Client Execution T1203 4 rules
Scheduled Task/Job: Cron T1053.003 3 rules
Command and Scripting Interpreter: Windows Command Shell T1059.003 3 rules
Container Administration Command T1609 2 rules
Deploy Container T1610 2 rules
Cloud Administration Command T1651 2 rules
Command and Scripting Interpreter: Visual Basic T1059.005 1 rule
Command and Scripting Interpreter: Lua T1059.011 1 rule
Software Deployment Tools T1072 1 rule
Shared Modules T1129 1 rule
User Execution T1204 1 rule
User Execution: Malicious Library T1204.005 1 rule
System Services: Launchctl T1569.001 1 rule

Persistence

Create or Modify System Process: Launch Agent T1543.001 6 rules
External Remote Services T1133 5 rules
Create or Modify System Process: Launch Daemon T1543.004 5 rules
Create or Modify System Process T1543 3 rules
Boot or Logon Initialization Scripts T1037 2 rules
Boot or Logon Initialization Scripts: Login Hook T1037.002 2 rules
Account Manipulation: Additional Local or Domain Groups T1098.007 2 rules
Boot or Logon Autostart Execution T1547 2 rules
Boot or Logon Autostart Execution: Plist Modification T1547.011 2 rules
Compromise Host Software Binary T1554 2 rules
Boot or Logon Initialization Scripts: RC Scripts T1037.004 1 rule
Boot or Logon Initialization Scripts: Startup Items T1037.005 1 rule
Account Manipulation: SSH Authorized Keys T1098.004 1 rule
Create Account: Local Account T1136.001 1 rule
Software Extensions: Browser Extensions T1176.001 1 rule
Server Software Component: Web Shell T1505.003 1 rule
Boot or Logon Autostart Execution: Authentication Package T1547.002 1 rule
Boot or Logon Autostart Execution: Kernel Modules and Extensions T1547.006 1 rule
Boot or Logon Autostart Execution: Shortcut Modification T1547.009 1 rule
Boot or Logon Autostart Execution: Login Items T1547.015 1 rule

Privilege Escalation

Event Triggered Execution T1546 5 rules
Abuse Elevation Control Mechanism: Sudo and Sudo Caching T1548.003 3 rules
Abuse Elevation Control Mechanism: TCC Manipulation T1548.006 3 rules
Exploitation for Privilege Escalation T1068 2 rules
Event Triggered Execution: Screensaver T1546.002 2 rules
Event Triggered Execution: Unix Shell Configuration Modification T1546.004 2 rules
Event Triggered Execution: Emond T1546.014 2 rules
Abuse Elevation Control Mechanism T1548 2 rules
Abuse Elevation Control Mechanism: Elevated Execution with Prompt T1548.004 2 rules
Event Triggered Execution: Trap T1546.005 1 rule
Event Triggered Execution: Installer Packages T1546.016 1 rule
Abuse Elevation Control Mechanism: Setuid and Setgid T1548.001 1 rule
Escape to Host T1611 1 rule

Stealth

Impair Defenses: Disable or Modify Tools T1562.001 9 rules
Hide Artifacts: Hidden Files and Directories T1564.001 5 rules
Valid Accounts T1078 4 rules
Valid Accounts: Local Accounts T1078.003 4 rules
Deobfuscate/Decode Files or Information T1140 3 rules
Hijack Execution Flow T1574 3 rules
Obfuscated Files or Information T1027 2 rules
Masquerading T1036 2 rules
Masquerading: Space after Filename T1036.006 2 rules
Process Injection T1055 2 rules
System Binary Proxy Execution: Rundll32 T1218.011 2 rules
Virtualization/Sandbox Evasion: System Checks T1497.001 2 rules
Hijack Execution Flow: Dynamic Linker Hijacking T1574.006 2 rules
Reflective Code Loading T1620 2 rules
Direct Volume Access T1006 1 rule
Obfuscated Files or Information: Compile After Delivery T1027.004 1 rule
Obfuscated Files or Information: Command Obfuscation T1027.010 1 rule
Obfuscated Files or Information: Encrypted/Encoded File T1027.013 1 rule
Masquerading: Rename Legitimate Utilities T1036.003 1 rule
Masquerading: Match Legitimate Resource Name or Location T1036.005 1 rule
Masquerading: Break Process Trees T1036.009 1 rule
Indicator Removal: Clear Command History T1070.003 1 rule
Indicator Removal: File Deletion T1070.004 1 rule
Indicator Removal: Timestomp T1070.006 1 rule
System Binary Proxy Execution T1218 1 rule
Virtualization/Sandbox Evasion T1497 1 rule
Hide Artifacts: Hidden Users T1564.002 1 rule
Hijack Execution Flow: Path Interception by PATH Environment Variable T1574.007 1 rule

Defense Impairment

Subvert Trust Controls: Gatekeeper Bypass T1553.001 5 rules
Plist File Modification T1647 5 rules
Modify Authentication Process T1556 2 rules
Subvert Trust Controls: Install Root Certificate T1553.004 1 rule

Credential Access

Unsecured Credentials: Credentials In Files T1552.001 7 rules
Steal Web Session Cookie T1539 5 rules
Credentials from Password Stores: Keychain T1555.001 5 rules
OS Credential Dumping T1003 3 rules
Credentials from Password Stores T1555 3 rules
Steal or Forge Kerberos Tickets: Ccache Files T1558.005 3 rules
Steal Application Access Token T1528 2 rules
Unsecured Credentials T1552 2 rules
Credentials from Password Stores: Credentials from Web Browsers T1555.003 2 rules
Steal or Forge Kerberos Tickets: Kerberoasting T1558.003 2 rules
OS Credential Dumping: /etc/passwd and /etc/shadow T1003.008 1 rule
Brute Force T1110 1 rule
Unsecured Credentials: Cloud Instance Metadata API T1552.005 1 rule
Unsecured Credentials: Container API T1552.007 1 rule
Adversary-in-the-Middle T1557 1 rule

Discovery

System Information Discovery T1082 5 rules
System Network Configuration Discovery T1016 4 rules
Container and Resource Discovery T1613 4 rules
System Network Configuration Discovery: Internet Connection Discovery T1016.001 2 rules
System Owner/User Discovery T1033 2 rules
Permission Groups Discovery T1069 2 rules
Permission Groups Discovery: Local Groups T1069.001 2 rules
Permission Groups Discovery: Domain Groups T1069.002 2 rules
File and Directory Discovery T1083 2 rules
Account Discovery: Local Account T1087.001 2 rules
Account Discovery: Domain Account T1087.002 2 rules
Software Discovery: Security Software Discovery T1518.001 2 rules
Remote System Discovery T1018 1 rule
Network Service Discovery T1046 1 rule
System Network Connections Discovery T1049 1 rule
Process Discovery T1057 1 rule

Lateral Movement

Exploitation of Remote Services T1210 11 rules
Remote Services: Remote Desktop Protocol T1021.001 7 rules
Lateral Tool Transfer T1570 4 rules
Remote Services: SSH T1021.004 2 rules
Remote Services T1021 1 rule
Remote Services: SMB/Windows Admin Shares T1021.002 1 rule
Replication Through Removable Media T1091 1 rule
Use Alternate Authentication Material: Application Access Token T1550.001 1 rule
Use Alternate Authentication Material: Pass the Hash T1550.002 1 rule
Use Alternate Authentication Material: Pass the Ticket T1550.003 1 rule
Remote Service Session Hijacking: SSH Hijacking T1563.001 1 rule
No specific technique 1 rule

Collection

Data from Local System T1005 8 rules
Data Staged: Local Data Staging T1074.001 3 rules
Clipboard Data T1115 2 rules
Data from Network Shared Drive T1039 1 rule
Input Capture T1056 1 rule
Input Capture: GUI Input Capture T1056.002 1 rule
Browser Session Hijacking T1185 1 rule
Data from Information Repositories: Code Repositories T1213.003 1 rule
Archive Collected Data T1560 1 rule
Archive Collected Data: Archive via Utility T1560.001 1 rule
Archive Collected Data: Archive via Library T1560.002 1 rule

Command & Control

Ingress Tool Transfer T1105 13 rules
Application Layer Protocol: Web Protocols T1071.001 9 rules
Web Service T1102 4 rules
Non-Standard Port T1571 4 rules
Application Layer Protocol T1071 3 rules
Proxy T1090 3 rules
Web Service: Bidirectional Communication T1102.002 3 rules
Non-Application Layer Protocol T1095 2 rules
Web Service: Dead Drop Resolver T1102.001 2 rules
Remote Access Tools T1219 2 rules
Protocol Tunneling T1572 2 rules
Application Layer Protocol: DNS T1071.004 1 rule
Web Service: One-Way Communication T1102.003 1 rule

Exfiltration

Exfiltration Over C2 Channel T1041 4 rules
Exfiltration Over Physical Medium: Exfiltration over USB T1052.001 3 rules
Exfiltration Over Web Service: Exfiltration to Cloud Storage T1567.002 2 rules
Exfiltration Over Other Network Medium: Exfiltration Over Bluetooth T1011.001 1 rule
Data Transfer Size Limits T1030 1 rule
Exfiltration Over Alternative Protocol: Exfiltration Over Symmetric Encrypted Non-C2 Protocol T1048.001 1 rule
Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol T1048.003 1 rule
Exfiltration Over Web Service T1567 1 rule
Exfiltration Over Web Service: Exfiltration to Text Storage Sites T1567.003 1 rule
Exfiltration Over Web Service: Exfiltration Over Webhook T1567.004 1 rule

Impact

Data Encrypted for Impact T1486 2 rules
Service Stop T1489 1 rule
Resource Hijacking: Compute Hijacking T1496.001 1 rule
Data Manipulation: Stored Data Manipulation T1565.001 1 rule
Data Manipulation: Transmitted Data Manipulation T1565.002 1 rule
No specific technique 2 rules

Untagged

AWS

Resource Development

Compromise Infrastructure: Domains T1584.001 2 rules
Acquire Infrastructure: Domains T1583.001 1 rule
Stage Capabilities T1608 1 rule

Execution

Serverless Execution T1648 3 rules
Cloud Administration Command T1651 3 rules
Command and Scripting Interpreter: Cloud API T1059.009 2 rules

Persistence

Account Manipulation T1098 13 rules
Account Manipulation: Additional Cloud Roles T1098.003 11 rules
Account Manipulation: Additional Cloud Credentials T1098.001 8 rules
External Remote Services T1133 4 rules
Create Account: Cloud Account T1136.003 4 rules
Server Software Component T1505 3 rules
Account Manipulation: Additional Container Cluster Roles T1098.006 2 rules
Account Manipulation: SSH Authorized Keys T1098.004 1 rule
Account Manipulation: Device Registration T1098.005 1 rule
Implant Internal Image T1525 1 rule

Privilege Escalation

Abuse Elevation Control Mechanism: Temporary Elevated Cloud Access T1548.005 7 rules
Abuse Elevation Control Mechanism T1548 4 rules
Event Triggered Execution T1546 1 rule

Stealth

Valid Accounts: Cloud Accounts T1078.004 35 rules
Impair Defenses: Disable or Modify Cloud Logs T1562.008 17 rules
Impair Defenses: Disable or Modify Tools T1562.001 14 rules
Impair Defenses: Disable or Modify Cloud Firewall T1562.007 6 rules
Indicator Removal T1070 2 rules
Impair Defenses T1562 2 rules
Impair Defenses: Indicator Blocking T1562.006 1 rule

Defense Impairment

Modify Cloud Compute Infrastructure: Modify Cloud Compute Configurations T1578.005 10 rules
Domain or Tenant Policy Modification: Trust Modification T1484.002 3 rules
Modify Authentication Process: Multi-Factor Authentication T1556.006 3 rules
Modify Authentication Process T1556 1 rule
Modify Authentication Process: Conditional Access Policies T1556.009 1 rule
Modify Cloud Compute Infrastructure T1578 1 rule
Modify Cloud Compute Infrastructure: Create Snapshot T1578.001 1 rule
Modify Cloud Compute Infrastructure: Create Cloud Instance T1578.002 1 rule
Modify Cloud Compute Infrastructure: Revert Cloud Instance T1578.004 1 rule

Credential Access

Credentials from Password Stores: Cloud Secrets Management Stores T1555.006 5 rules
Unsecured Credentials T1552 3 rules
Unsecured Credentials: Cloud Instance Metadata API T1552.005 3 rules
Network Sniffing T1040 1 rule
Brute Force T1110 1 rule
Brute Force: Password Guessing T1110.001 1 rule
Unsecured Credentials: Credentials In Files T1552.001 1 rule
Unsecured Credentials: Private Keys T1552.004 1 rule
Adversary-in-the-Middle T1557 1 rule

Discovery

Cloud Infrastructure Discovery T1580 12 rules
Cloud Service Discovery T1526 8 rules
Account Discovery: Cloud Account T1087.004 5 rules
Cloud Storage Object Discovery T1619 3 rules
System Owner/User Discovery T1033 1 rule
Permission Groups Discovery: Cloud Groups T1069.003 1 rule
Software Discovery T1518 1 rule
Cloud Service Dashboard T1538 1 rule

Lateral Movement

Use Alternate Authentication Material: Application Access Token T1550.001 11 rules
Remote Services: Cloud Services T1021.007 4 rules
Remote Services: SSH T1021.004 2 rules
Internal Spearphishing T1534 1 rule

Collection

Data from Cloud Storage T1530 12 rules
Data from Information Repositories T1213 2 rules
Data from Information Repositories: Databases T1213.006 2 rules
Data from Local System T1005 1 rule
Data Staged T1074 1 rule
Data Staged: Remote Data Staging T1074.002 1 rule
Automated Collection T1119 1 rule

Command & Control

Web Service T1102 1 rule
Web Service: One-Way Communication T1102.003 1 rule

Exfiltration

Transfer Data to Cloud Account T1537 8 rules
Exfiltration Over Web Service: Exfiltration to Cloud Storage T1567.002 5 rules
Exfiltration Over Web Service T1567 3 rules
Automated Exfiltration T1020 1 rule
Exfiltration Over C2 Channel T1041 1 rule

Impact

Data Destruction T1485 10 rules
Data Manipulation: Stored Data Manipulation T1565.001 6 rules
Data Encrypted for Impact T1486 4 rules
Inhibit System Recovery T1490 4 rules
Resource Hijacking: Cloud Service Hijacking T1496.004 4 rules
Data Destruction: Lifecycle-Triggered Deletion T1485.001 2 rules
Account Access Removal T1531 2 rules
Service Stop T1489 1 rule
Defacement: External Defacement T1491.002 1 rule
Financial Theft T1657 1 rule

Untagged

Azure

Resource Development

Compromise Infrastructure: Domains T1584.001 1 rule
Stage Capabilities T1608 1 rule

Initial Access

Phishing: Spearphishing Link T1566.002 12 rules
Trusted Relationship T1199 3 rules
Phishing T1566 2 rules

Execution

Cloud Administration Command T1651 2 rules
Scheduled Task/Job T1053 1 rule
Command and Scripting Interpreter: PowerShell T1059.001 1 rule
Serverless Execution T1648 1 rule

Persistence

Account Manipulation: Device Registration T1098.005 9 rules
Account Manipulation: Additional Cloud Credentials T1098.001 7 rules
Account Manipulation: Additional Cloud Roles T1098.003 6 rules
Account Manipulation T1098 3 rules
Create Account: Cloud Account T1136.003 2 rules
Account Manipulation: Additional Container Cluster Roles T1098.006 1 rule

Privilege Escalation

Event Triggered Execution T1546 1 rule
Abuse Elevation Control Mechanism T1548 1 rule

Stealth

Valid Accounts: Cloud Accounts T1078.004 40 rules
Impair Defenses: Disable or Modify Tools T1562.001 5 rules
Valid Accounts T1078 4 rules
Impair Defenses: Disable or Modify Cloud Logs T1562.008 4 rules
Impair Defenses: Disable or Modify Cloud Firewall T1562.007 2 rules
Impersonation T1656 1 rule

Defense Impairment

File and Directory Permissions Modification T1222 2 rules
Domain or Tenant Policy Modification: Trust Modification T1484.002 2 rules
Modify Authentication Process T1556 2 rules
Modify Authentication Process: Multi-Factor Authentication T1556.006 2 rules
Modify Authentication Process: Conditional Access Policies T1556.009 2 rules
Modify Authentication Process: Hybrid Identity T1556.007 1 rule
Modify Cloud Compute Infrastructure: Create Cloud Instance T1578.002 1 rule
Modify Cloud Compute Infrastructure: Modify Cloud Compute Configurations T1578.005 1 rule

Credential Access

Steal Application Access Token T1528 12 rules
Brute Force: Password Spraying T1110.003 7 rules
Brute Force: Password Guessing T1110.001 4 rules
Brute Force: Credential Stuffing T1110.004 3 rules
Credentials from Password Stores: Cloud Secrets Management Stores T1555.006 3 rules
Steal Web Session Cookie T1539 2 rules
Unsecured Credentials: Cloud Instance Metadata API T1552.005 2 rules
Unsecured Credentials: Container API T1552.007 2 rules
Network Sniffing T1040 1 rule
Multi-Factor Authentication Request Generation T1621 1 rule

Discovery

Cloud Service Discovery T1526 5 rules
Cloud Infrastructure Discovery T1580 4 rules
Permission Groups Discovery: Cloud Groups T1069.003 2 rules
System Information Discovery T1082 2 rules
Account Discovery: Cloud Account T1087.004 2 rules
Password Policy Discovery T1201 2 rules
Virtual Machine Discovery T1673 2 rules
Account Discovery T1087 1 rule
Cloud Storage Object Discovery T1619 1 rule

Lateral Movement

Use Alternate Authentication Material: Application Access Token T1550.001 18 rules
Use Alternate Authentication Material T1550 2 rules
Remote Services: Cloud Services T1021.007 1 rule
Use Alternate Authentication Material: Web Session Cookie T1550.004 1 rule

Collection

Data from Cloud Storage T1530 2 rules
Email Collection: Remote Email Collection T1114.002 1 rule
Data from Information Repositories T1213 1 rule
Data from Information Repositories: Sharepoint T1213.002 1 rule

Command & Control

Application Layer Protocol T1071 2 rules

Exfiltration

Exfiltration Over C2 Channel T1041 1 rule
Transfer Data to Cloud Account T1537 1 rule
Exfiltration Over Web Service: Exfiltration to Cloud Storage T1567.002 1 rule

Impact

Data Destruction T1485 7 rules
Inhibit System Recovery T1490 6 rules
Service Stop T1489 4 rules
System Shutdown/Reboot T1529 2 rules

Untagged

GCP

Execution

Cloud Administration Command T1651 1 rule

Persistence

Account Manipulation: Additional Cloud Roles T1098.003 2 rules
Account Manipulation T1098 1 rule
Account Manipulation: Additional Cloud Credentials T1098.001 1 rule
Create Account: Cloud Account T1136.003 1 rule

Stealth

Impair Defenses: Disable or Modify Cloud Firewall T1562.007 6 rules
Valid Accounts: Cloud Accounts T1078.004 3 rules
Impair Defenses: Disable or Modify Cloud Logs T1562.008 3 rules
Impair Defenses T1562 2 rules
Valid Accounts T1078 1 rule

Defense Impairment

Modify Cloud Compute Infrastructure: Modify Cloud Compute Configurations T1578.005 3 rules
File and Directory Permissions Modification T1222 1 rule

Discovery

Cloud Service Discovery T1526 2 rules
Cloud Infrastructure Discovery T1580 2 rules

Lateral Movement

Remote Services: Cloud Services T1021.007 1 rule

Collection

Data from Cloud Storage T1530 2 rules
Automated Collection T1119 1 rule

Exfiltration

Exfiltration Over C2 Channel T1041 1 rule
Transfer Data to Cloud Account T1537 1 rule

Impact

Account Access Removal T1531 4 rules
Data Destruction T1485 2 rules
Service Stop T1489 2 rules

Microsoft 365

Resource Development

Stage Capabilities: Upload Malware T1608.001 2 rules

Initial Access

Phishing: Spearphishing Link T1566.002 7 rules
Phishing T1566 3 rules
Phishing: Spearphishing Attachment T1566.001 3 rules
Phishing: Spearphishing via Service T1566.003 1 rule
No specific technique 1 rule

Execution

Command and Scripting Interpreter: PowerShell T1059.001 2 rules
User Execution T1204 1 rule
User Execution: Malicious Link T1204.001 1 rule
User Execution: Malicious File T1204.002 1 rule

Persistence

Account Manipulation T1098 4 rules
Account Manipulation: Additional Cloud Roles T1098.003 3 rules
Account Manipulation: Device Registration T1098.005 2 rules
Office Application Startup: Outlook Rules T1137.005 2 rules
Account Manipulation: Additional Email Delegate Permissions T1098.002 1 rule

Stealth

Impair Defenses: Disable or Modify Tools T1562.001 12 rules
Valid Accounts: Cloud Accounts T1078.004 7 rules
Impair Defenses T1562 2 rules
Hide Artifacts: Email Hiding Rules T1564.008 2 rules
Indicator Removal: Clear Mailbox Data T1070.008 1 rule

Defense Impairment

Domain or Tenant Policy Modification T1484 8 rules
Domain or Tenant Policy Modification: Trust Modification T1484.002 1 rule

Credential Access

Steal Application Access Token T1528 4 rules
Brute Force: Password Spraying T1110.003 3 rules
Brute Force: Password Guessing T1110.001 2 rules
Brute Force: Credential Stuffing T1110.004 2 rules
Steal Web Session Cookie T1539 1 rule
Forge Web Credentials: SAML Tokens T1606.002 1 rule
No specific technique 1 rule

Discovery

Cloud Storage Object Discovery T1619 1 rule

Lateral Movement

Taint Shared Content T1080 2 rules
Use Alternate Authentication Material: Application Access Token T1550.001 1 rule

Collection

Data from Cloud Storage T1530 4 rules
Email Collection: Remote Email Collection T1114.002 2 rules
Email Collection: Email Forwarding Rule T1114.003 2 rules
Data from Information Repositories: Sharepoint T1213.002 2 rules
Data from Local System T1005 1 rule
Email Collection T1114 1 rule
No specific technique 2 rules

Exfiltration

Transfer Data to Cloud Account T1537 2 rules
Automated Exfiltration T1020 1 rule
Exfiltration Over Web Service T1567 1 rule
Exfiltration Over Web Service: Exfiltration to Cloud Storage T1567.002 1 rule
No specific technique 2 rules

Impact

Data Destruction T1485 1 rule
Data Encrypted for Impact T1486 1 rule
Data Manipulation: Stored Data Manipulation T1565.001 1 rule
No specific technique 3 rules

Google Workspace

Initial Access

Phishing: Spearphishing Link T1566.002 2 rules

Execution

User Execution: Malicious Link T1204.001 1 rule

Persistence

Account Manipulation T1098 5 rules
Account Manipulation: Additional Cloud Roles T1098.003 3 rules
Account Manipulation: Device Registration T1098.005 3 rules
Account Manipulation: Additional Cloud Credentials T1098.001 2 rules

Stealth

Valid Accounts: Cloud Accounts T1078.004 7 rules
Impair Defenses: Disable or Modify Tools T1562.001 3 rules
Impair Defenses: Disable or Modify Cloud Firewall T1562.007 1 rule

Defense Impairment

Domain or Tenant Policy Modification T1484 5 rules
Modify Authentication Process T1556 2 rules
Domain or Tenant Policy Modification: Trust Modification T1484.002 1 rule
Modify Authentication Process: Multi-Factor Authentication T1556.006 1 rule

Credential Access

Adversary-in-the-Middle T1557 3 rules
Steal Application Access Token T1528 2 rules
Unsecured Credentials: Private Keys T1552.004 1 rule

Lateral Movement

Use Alternate Authentication Material: Application Access Token T1550.001 1 rule

Collection

Data Staged: Remote Data Staging T1074.002 1 rule
Email Collection: Email Forwarding Rule T1114.003 1 rule
Data from Cloud Storage T1530 1 rule

Exfiltration

Transfer Data to Cloud Account T1537 1 rule

Impact

Account Access Removal T1531 2 rules

Untagged

Okta

Initial Access

Trusted Relationship T1199 1 rule
Phishing: Spearphishing Link T1566.002 1 rule

Persistence

Account Manipulation: Additional Cloud Roles T1098.003 2 rules
Account Manipulation T1098 1 rule
Account Manipulation: Additional Cloud Credentials T1098.001 1 rule
External Remote Services T1133 1 rule
Create Account T1136 1 rule

Stealth

Valid Accounts: Cloud Accounts T1078.004 15 rules
Impair Defenses: Disable or Modify Cloud Firewall T1562.007 9 rules
Valid Accounts T1078 1 rule

Defense Impairment

Modify Authentication Process: Multi-Factor Authentication T1556.006 5 rules
Domain or Tenant Policy Modification T1484 4 rules
Domain or Tenant Policy Modification: Trust Modification T1484.002 2 rules
Modify Authentication Process T1556 2 rules
Modify Authentication Process: Hybrid Identity T1556.007 1 rule
Modify Authentication Process: Conditional Access Policies T1556.009 1 rule

Credential Access

Brute Force: Password Spraying T1110.003 6 rules
Brute Force: Password Guessing T1110.001 4 rules
Brute Force: Credential Stuffing T1110.004 4 rules
Steal Web Session Cookie T1539 3 rules
Multi-Factor Authentication Request Generation T1621 2 rules
Brute Force T1110 1 rule
Multi-Factor Authentication Interception T1111 1 rule

Lateral Movement

Use Alternate Authentication Material: Web Session Cookie T1550.004 3 rules
Use Alternate Authentication Material: Application Access Token T1550.001 1 rule

Impact

Service Stop T1489 2 rules
Network Denial of Service T1498 1 rule
Endpoint Denial of Service: Service Exhaustion Flood T1499.002 1 rule
Endpoint Denial of Service: Application Exhaustion Flood T1499.003 1 rule
Account Access Removal T1531 1 rule
No specific technique 1 rule

Untagged

GitHub

Resource Development

Acquire Infrastructure: Web Services T1583.006 1 rule

Initial Access

Supply Chain Compromise: Compromise Software Supply Chain T1195.002 4 rules
Supply Chain Compromise: Compromise Software Dependencies and Development Tools T1195.001 2 rules
Trusted Relationship T1199 1 rule

Execution

Serverless Execution T1648 7 rules
Command and Scripting Interpreter T1059 3 rules
Software Deployment Tools T1072 1 rule
No specific technique 1 rule

Persistence

Account Manipulation: Additional Cloud Credentials T1098.001 4 rules
Account Manipulation: Additional Cloud Roles T1098.003 3 rules
Create Account: Cloud Account T1136.003 2 rules
Account Manipulation T1098 1 rule

Privilege Escalation

Event Triggered Execution T1546 1 rule

Stealth

Valid Accounts: Cloud Accounts T1078.004 8 rules
Impair Defenses: Disable or Modify Tools T1562.001 3 rules

Credential Access

Steal Application Access Token T1528 1 rule

Lateral Movement

Use Alternate Authentication Material: Application Access Token T1550.001 3 rules

Collection

Data from Information Repositories: Code Repositories T1213.003 5 rules

Exfiltration

Automated Exfiltration T1020 5 rules
Exfiltration Over Web Service: Exfiltration to Code Repository T1567.001 5 rules

Impact

Data Destruction T1485 4 rules
Data Manipulation: Stored Data Manipulation T1565.001 4 rules
Account Access Removal T1531 3 rules

Kubernetes

Reconnaissance

Active Scanning: Wordlist Scanning T1595.003 1 rule

Execution

Deploy Container T1610 8 rules
Container Administration Command T1609 7 rules
Command and Scripting Interpreter T1059 1 rule
No specific technique 1 rule

Persistence

Account Manipulation: Additional Container Cluster Roles T1098.006 9 rules
External Remote Services T1133 1 rule

Privilege Escalation

Escape to Host T1611 8 rules
Event Triggered Execution T1546 1 rule

Stealth

Valid Accounts: Default Accounts T1078.001 2 rules
Indicator Removal: File Deletion T1070.004 1 rule
Valid Accounts T1078 1 rule
Access Token Manipulation T1134 1 rule
Impair Defenses T1562 1 rule

Credential Access

Unsecured Credentials: Container API T1552.007 8 rules
Unsecured Credentials: Credentials In Files T1552.001 1 rule
Unsecured Credentials: Cloud Instance Metadata API T1552.005 1 rule

Discovery

Container and Resource Discovery T1613 8 rules
Permission Groups Discovery: Cloud Groups T1069.003 1 rule

Lateral Movement

Use Alternate Authentication Material: Application Access Token T1550.001 1 rule

Collection

Data from Information Repositories T1213 1 rule
Data from Cloud Storage T1530 1 rule

Command & Control

Ingress Tool Transfer T1105 1 rule

Impact

Data Manipulation: Stored Data Manipulation T1565.001 2 rules

Untagged

Network

Reconnaissance

Active Scanning: Scanning IP Blocks T1595.001 3 rules
Active Scanning T1595 1 rule

Initial Access

Exploit Public-Facing Application T1190 14 rules

Execution

Command and Scripting Interpreter: JavaScript T1059.007 3 rules

Persistence

External Remote Services T1133 4 rules

Stealth

Valid Accounts T1078 2 rules
Valid Accounts: Cloud Accounts T1078.004 1 rule

Credential Access

Forge Web Credentials: SAML Tokens T1606.002 1 rule

Discovery

Network Service Discovery T1046 3 rules
Remote System Discovery T1018 1 rule

Lateral Movement

Remote Services T1021 1 rule
Remote Services: Remote Desktop Protocol T1021.001 1 rule
Remote Services: Distributed Component Object Model T1021.003 1 rule
Remote Services: VNC T1021.005 1 rule
Exploitation of Remote Services T1210 1 rule

Command & Control

Dynamic Resolution: Domain Generation Algorithms T1568.002 7 rules
Application Layer Protocol: Web Protocols T1071.001 4 rules
Application Layer Protocol: DNS T1071.004 4 rules
Application Layer Protocol T1071 3 rules
Web Service: Bidirectional Communication T1102.002 2 rules
Remote Access Tools T1219 2 rules
Encrypted Channel T1573 2 rules
Application Layer Protocol: Mail Protocols T1071.003 1 rule
Non-Application Layer Protocol T1095 1 rule
Ingress Tool Transfer T1105 1 rule
Non-Standard Port T1571 1 rule
Protocol Tunneling T1572 1 rule

Exfiltration

Exfiltration Over Alternative Protocol T1048 2 rules

Impact

Endpoint Denial of Service: Application or System Exploitation T1499.004 1 rule

Untagged

Web

Reconnaissance

Active Scanning: Vulnerability Scanning T1595.002 6 rules
Active Scanning: Wordlist Scanning T1595.003 6 rules
Active Scanning: Scanning IP Blocks T1595.001 1 rule

Initial Access

Exploit Public-Facing Application T1190 4 rules

Execution

Command and Scripting Interpreter: Unix Shell T1059.004 2 rules
Command and Scripting Interpreter: Python T1059.006 1 rule
Command and Scripting Interpreter: Lua T1059.011 1 rule

Persistence

Server Software Component T1505 1 rule
Server Software Component: Web Shell T1505.003 1 rule

Stealth

Deobfuscate/Decode Files or Information T1140 1 rule
Impair Defenses: Downgrade Attack T1562.010 1 rule

Credential Access

Unsecured Credentials: Credentials In Files T1552.001 2 rules
OS Credential Dumping: /etc/passwd and /etc/shadow T1003.008 1 rule
Brute Force T1110 1 rule

Discovery

File and Directory Discovery T1083 2 rules

Collection

Data from Local System T1005 1 rule

Command & Control

Application Layer Protocol T1071 2 rules
Ingress Tool Transfer T1105 1 rule

Identity

Persistence

Account Manipulation T1098 6 rules
Account Manipulation: Additional Local or Domain Groups T1098.007 3 rules
Create Account T1136 1 rule

Privilege Escalation

Exploitation for Privilege Escalation T1068 10 rules
Abuse Elevation Control Mechanism T1548 2 rules

Stealth

Valid Accounts T1078 18 rules
Valid Accounts: Cloud Accounts T1078.004 3 rules
Obfuscated Files or Information T1027 1 rule
Valid Accounts: Domain Accounts T1078.002 1 rule
Access Token Manipulation T1134 1 rule

Discovery

Permission Groups Discovery T1069 1 rule

Untagged

Application

Reconnaissance

Active Scanning T1595 2 rules
Gather Victim Network Information T1590 1 rule
Active Scanning: Scanning IP Blocks T1595.001 1 rule

Initial Access

Phishing: Spearphishing Attachment T1566.001 2 rules
Phishing: Spearphishing Link T1566.002 2 rules
Drive-by Compromise T1189 1 rule
Phishing T1566 1 rule

Execution

Exploitation for Client Execution T1203 2 rules
User Execution T1204 1 rule
User Execution: Malicious Link T1204.001 1 rule
User Execution: Malicious File T1204.002 1 rule

Privilege Escalation

Exploitation for Privilege Escalation T1068 3 rules

Stealth

Valid Accounts T1078 3 rules
Process Injection T1055 2 rules
Valid Accounts: Domain Accounts T1078.002 2 rules
Valid Accounts: Local Accounts T1078.003 2 rules
Access Token Manipulation T1134 2 rules
Access Token Manipulation: Token Impersonation/Theft T1134.001 2 rules
Impair Defenses T1562 1 rule

Credential Access

Brute Force: Password Spraying T1110.003 3 rules
OS Credential Dumping: LSASS Memory T1003.001 2 rules
Brute Force T1110 1 rule
Brute Force: Password Guessing T1110.001 1 rule

Discovery

Network Service Discovery T1046 4 rules
Remote System Discovery T1018 1 rule

Lateral Movement

Remote Services T1021 1 rule

Command & Control

Application Layer Protocol T1071 4 rules
Application Layer Protocol: Web Protocols T1071.001 3 rules
Application Layer Protocol: DNS T1071.004 3 rules
Ingress Tool Transfer T1105 2 rules
Web Service T1102 1 rule
Dynamic Resolution T1568 1 rule
Protocol Tunneling T1572 1 rule

Exfiltration

Exfiltration Over C2 Channel T1041 7 rules
Exfiltration Over Alternative Protocol T1048 4 rules

Impact

Network Denial of Service T1498 3 rules
Endpoint Denial of Service T1499 3 rules
Service Stop T1489 1 rule

Untagged