Kusto non-Windows coverage

1,924 non-Windows Kusto detection rules across 13 platforms, grouped by MITRE ATT&CK technique within each platform. The Windows coverage matrix lives at /rules/kusto/; this page reorganizes the same corpus along platform × technique because non-Windows rules have no catalog event IDs to plot.

For coverage organized by each platform's native action vocabulary across all vendors, see the platform matrices: AWS, Azure AD, GCP, M365, Okta. This page is the vendor-organized browse of the same rules.

Platform (all)
Domain (all)

Linux

Reconnaissance

Active Scanning T1595 1 rule

Initial Access

Exploit Public-Facing Application T1190 18 rules
Phishing T1566 15 rules
Drive-by Compromise T1189 10 rules
Supply Chain Compromise T1195 2 rules
Trusted Relationship T1199 1 rule
Hardware Additions T1200 1 rule

Execution

User Execution: Malicious File T1204.002 5 rules
User Execution T1204 4 rules
Command and Scripting Interpreter T1059 3 rules
Exploitation for Client Execution T1203 2 rules
Scheduled Task/Job T1053 1 rule
Native API T1106 1 rule
System Services T1569 1 rule

Persistence

External Remote Services T1133 12 rules
Account Manipulation T1098 4 rules
Create Account T1136 1 rule
Create or Modify System Process T1543 1 rule

Privilege Escalation

Abuse Elevation Control Mechanism T1548 5 rules
Exploitation for Privilege Escalation T1068 2 rules
Event Triggered Execution T1546 1 rule

Stealth

Valid Accounts T1078 26 rules
Impair Defenses T1562 24 rules
Indicator Removal T1070 18 rules
Masquerading T1036 1 rule
Process Injection T1055 1 rule
Indicator Removal: File Deletion T1070.004 1 rule
Valid Accounts: Cloud Accounts T1078.004 1 rule
Impair Defenses: Disable Windows Event Logging T1562.002 1 rule
Hijack Execution Flow T1574 1 rule

Defense Impairment

Modify Authentication Process T1556 2 rules

Credential Access

Brute Force T1110 9 rules
Exploitation for Credential Access T1212 2 rules
Steal Application Access Token T1528 1 rule
Unsecured Credentials T1552 1 rule
Credentials from Password Stores T1555 1 rule
Steal or Forge Kerberos Tickets: Kerberoasting T1558.003 1 rule
No specific technique 1 rule

Discovery

Cloud Service Discovery T1526 3 rules
Cloud Infrastructure Discovery T1580 2 rules
Network Service Discovery T1046 1 rule
System Information Discovery T1082 1 rule
Cloud Service Dashboard T1538 1 rule
No specific technique 1 rule

Lateral Movement

Remote Services T1021 3 rules
Exploitation of Remote Services T1210 3 rules

Collection

Automated Collection T1119 2 rules
Data from Local System T1005 1 rule
Data from Information Repositories T1213 1 rule

Command & Control

Application Layer Protocol T1071 25 rules
Web Service T1102 7 rules
Fallback Channels T1008 2 rules
Proxy T1090 2 rules
Dynamic Resolution T1568 2 rules
Data Obfuscation T1001 1 rule
Data Encoding T1132 1 rule

Exfiltration

Exfiltration Over Alternative Protocol T1048 15 rules
Exfiltration Over Web Service T1567 7 rules
Automated Exfiltration T1020 2 rules
Exfiltration Over C2 Channel T1041 2 rules
Scheduled Transfer T1029 1 rule
Exfiltration Over Physical Medium T1052 1 rule
Transfer Data to Cloud Account T1537 1 rule

Impact

Data Encrypted for Impact T1486 11 rules
Data Destruction T1485 7 rules
System Shutdown/Reboot T1529 5 rules
Inhibit System Recovery T1490 2 rules
Data Manipulation T1565 2 rules
Resource Hijacking T1496 1 rule
Network Denial of Service T1498 1 rule
Endpoint Denial of Service T1499 1 rule

Untagged

macOS

Reconnaissance

Active Scanning T1595 1 rule

Initial Access

Exploit Public-Facing Application T1190 15 rules
Phishing T1566 11 rules
Drive-by Compromise T1189 1 rule
Trusted Relationship T1199 1 rule

Execution

User Execution: Malicious File T1204.002 4 rules
User Execution T1204 3 rules
Scheduled Task/Job T1053 1 rule
Command and Scripting Interpreter T1059 1 rule
Native API T1106 1 rule
Exploitation for Client Execution T1203 1 rule
System Services T1569 1 rule

Persistence

External Remote Services T1133 9 rules
Account Manipulation T1098 1 rule

Privilege Escalation

Abuse Elevation Control Mechanism T1548 3 rules
Event Triggered Execution T1546 1 rule

Stealth

Valid Accounts T1078 13 rules
Indicator Removal T1070 7 rules
Impair Defenses T1562 3 rules
Masquerading T1036 1 rule
Valid Accounts: Cloud Accounts T1078.004 1 rule
Hijack Execution Flow T1574 1 rule

Credential Access

Exploitation for Credential Access T1212 1 rule
Steal Application Access Token T1528 1 rule
Credentials from Password Stores T1555 1 rule
Steal or Forge Kerberos Tickets: Kerberoasting T1558.003 1 rule
No specific technique 1 rule

Discovery

Cloud Service Discovery T1526 3 rules
Cloud Infrastructure Discovery T1580 2 rules
Cloud Service Dashboard T1538 1 rule
No specific technique 1 rule

Lateral Movement

Exploitation of Remote Services T1210 3 rules
Remote Services T1021 1 rule

Command & Control

Application Layer Protocol T1071 18 rules
Web Service T1102 2 rules

Exfiltration

Exfiltration Over Web Service T1567 6 rules
Exfiltration Over Alternative Protocol T1048 4 rules
Exfiltration Over Physical Medium T1052 1 rule
Transfer Data to Cloud Account T1537 1 rule

Impact

Data Encrypted for Impact T1486 7 rules
Data Destruction T1485 4 rules
Inhibit System Recovery T1490 1 rule
Data Manipulation T1565 1 rule

Untagged

AWS

Reconnaissance

Gather Victim Identity Information: Email Addresses T1589.002 1 rule
Gather Victim Identity Information: Employee Names T1589.003 1 rule
Gather Victim Network Information T1590 1 rule
Gather Victim Org Information T1591 1 rule
Gather Victim Host Information: Client Configurations T1592.004 1 rule
Active Scanning T1595 1 rule
Search Open Technical Databases T1596 1 rule

Resource Development

Acquire Infrastructure T1583 1 rule

Initial Access

Exploit Public-Facing Application T1190 2 rules
Drive-by Compromise T1189 1 rule

Execution

Command and Scripting Interpreter T1059 4 rules
Exploitation for Client Execution T1203 3 rules
User Execution T1204 1 rule
Cloud Administration Command T1651 1 rule

Persistence

Account Manipulation: Additional Cloud Roles T1098.003 27 rules
Account Manipulation: Additional Cloud Credentials T1098.001 3 rules
Account Manipulation T1098 1 rule
External Remote Services T1133 1 rule

Stealth

Valid Accounts T1078 5 rules
Impair Defenses: Disable or Modify Cloud Firewall T1562.007 5 rules
Impair Defenses: Disable or Modify Cloud Logs T1562.008 3 rules
Access Token Manipulation T1134 2 rules
Indicator Removal T1070 1 rule
Valid Accounts: Default Accounts T1078.001 1 rule
Valid Accounts: Domain Accounts T1078.002 1 rule
Valid Accounts: Cloud Accounts T1078.004 1 rule
Access Token Manipulation: Token Impersonation/Theft T1134.001 1 rule
Access Token Manipulation: Make and Impersonate Token T1134.003 1 rule
Impair Defenses T1562 1 rule
Impair Defenses: Disable or Modify Tools T1562.001 1 rule

Defense Impairment

Domain or Tenant Policy Modification T1484 12 rules
Modify Authentication Process: Multi-Factor Authentication T1556.006 1 rule

Credential Access

Brute Force T1110 4 rules

Discovery

Network Service Discovery T1046 2 rules
Cloud Infrastructure Discovery T1580 2 rules
File and Directory Discovery T1083 1 rule
Cloud Service Discovery T1526 1 rule

Lateral Movement

Remote Services T1021 1 rule
Exploitation of Remote Services T1210 1 rule

Collection

Data from Cloud Storage T1530 3 rules

Command & Control

Application Layer Protocol T1071 7 rules
Non-Application Layer Protocol T1095 3 rules

Exfiltration

Transfer Data to Cloud Account T1537 5 rules
Data Transfer Size Limits T1030 1 rule
Exfiltration Over Web Service T1567 1 rule

Impact

Data Encrypted for Impact T1486 2 rules
Data Manipulation: Stored Data Manipulation T1565.001 2 rules
Data Destruction T1485 1 rule
Resource Hijacking T1496 1 rule

Untagged

Azure

Reconnaissance

Active Scanning: Scanning IP Blocks T1595.001 2 rules

Resource Development

Establish Accounts: Cloud Accounts T1585.003 1 rule
Develop Capabilities T1587 1 rule

Initial Access

Exploit Public-Facing Application T1190 12 rules
Phishing T1566 8 rules
Trusted Relationship T1199 2 rules
No specific technique 1 rule

Execution

Cloud Administration Command T1651 6 rules
User Execution T1204 3 rules
Command and Scripting Interpreter T1059 2 rules
Command and Scripting Interpreter: PowerShell T1059.001 2 rules
Scheduled Task/Job T1053 1 rule
Command and Scripting Interpreter: Windows Command Shell T1059.003 1 rule
Software Deployment Tools T1072 1 rule
Inter-Process Communication T1559 1 rule
System Services T1569 1 rule
No specific technique 1 rule

Persistence

Account Manipulation T1098 26 rules
Create Account: Cloud Account T1136.003 11 rules
Account Manipulation: Additional Cloud Credentials T1098.001 2 rules
Account Manipulation: Additional Cloud Roles T1098.003 2 rules
External Remote Services T1133 2 rules
Server Software Component T1505 2 rules
Create Account T1136 1 rule
No specific technique 1 rule

Privilege Escalation

Abuse Elevation Control Mechanism T1548 3 rules
Exploitation for Privilege Escalation T1068 2 rules

Stealth

Valid Accounts: Cloud Accounts T1078.004 52 rules
Valid Accounts T1078 32 rules
Impair Defenses: Disable or Modify Cloud Firewall T1562.007 5 rules
Masquerading T1036 3 rules
Impair Defenses: Disable or Modify Cloud Logs T1562.008 3 rules
Impair Defenses T1562 2 rules
Hide Artifacts T1564 1 rule
No specific technique 1 rule

Defense Impairment

Modify Cloud Compute Infrastructure T1578 6 rules
Modify Authentication Process T1556 2 rules
Modify Authentication Process: Hybrid Identity T1556.007 2 rules
Domain or Tenant Policy Modification T1484 1 rule
Modify Authentication Process: Multi-Factor Authentication T1556.006 1 rule
Modify Authentication Process: Conditional Access Policies T1556.009 1 rule
Modify Cloud Compute Infrastructure: Create Cloud Instance T1578.002 1 rule
Modify Cloud Compute Infrastructure: Delete Cloud Instance T1578.003 1 rule

Credential Access

Brute Force T1110 20 rules
Steal Application Access Token T1528 8 rules
Forge Web Credentials T1606 5 rules
OS Credential Dumping T1003 4 rules
Credentials from Password Stores T1555 3 rules
Adversary-in-the-Middle T1557 3 rules
Brute Force: Password Spraying T1110.003 2 rules
Brute Force: Credential Stuffing T1110.004 2 rules
Exploitation for Credential Access T1212 2 rules
Unsecured Credentials T1552 2 rules
Brute Force: Password Guessing T1110.001 1 rule
Brute Force: Password Cracking T1110.002 1 rule
Multi-Factor Authentication Interception T1111 1 rule
No specific technique 1 rule

Discovery

Account Discovery: Cloud Account T1087.004 8 rules
Network Service Discovery T1046 7 rules
System Information Discovery T1082 2 rules
Account Discovery T1087 1 rule
Cloud Infrastructure Discovery T1580 1 rule
No specific technique 2 rules

Lateral Movement

Use Alternate Authentication Material T1550 4 rules
Use Alternate Authentication Material: Application Access Token T1550.001 4 rules
Remote Services: Direct Cloud VM Connections T1021.008 2 rules
Exploitation of Remote Services T1210 2 rules
Lateral Tool Transfer T1570 2 rules
Remote Services T1021 1 rule
Internal Spearphishing T1534 1 rule
No specific technique 2 rules

Collection

Email Collection T1114 1 rule
Automated Collection T1119 1 rule
Data from Information Repositories: Databases T1213.006 1 rule
No specific technique 2 rules

Command & Control

Application Layer Protocol T1071 35 rules
Non-Standard Port T1571 4 rules
Application Layer Protocol: Web Protocols T1071.001 1 rule
Ingress Tool Transfer T1105 1 rule
Dynamic Resolution: Fast Flux DNS T1568.001 1 rule
Dynamic Resolution: Domain Generation Algorithms T1568.002 1 rule
Protocol Tunneling T1572 1 rule
No specific technique 1 rule

Exfiltration

Exfiltration Over C2 Channel T1041 4 rules
Exfiltration Over Web Service T1567 3 rules
Data Transfer Size Limits T1030 1 rule
Exfiltration Over Alternative Protocol T1048 1 rule
Exfiltration Over Physical Medium T1052 1 rule
No specific technique 2 rules

Impact

Resource Hijacking T1496 9 rules
Data Destruction T1485 6 rules
Network Denial of Service T1498 3 rules
Account Access Removal T1531 2 rules
Data Encrypted for Impact T1486 1 rule
Service Stop T1489 1 rule
Defacement T1491 1 rule
Data Manipulation T1565 1 rule
No specific technique 1 rule

Untagged

GCP

Resource Development

Compromise Infrastructure: DNS Server T1584.002 1 rule

Initial Access

Phishing T1566 3 rules
Exploit Public-Facing Application T1190 1 rule
Supply Chain Compromise T1195 1 rule

Execution

Command and Scripting Interpreter T1059 2 rules
Native API T1106 1 rule

Persistence

External Remote Services T1133 2 rules
Boot or Logon Autostart Execution T1547 2 rules
Create Account T1136 1 rule

Privilege Escalation

Exploitation for Privilege Escalation T1068 3 rules
Abuse Elevation Control Mechanism T1548 2 rules

Stealth

Impair Defenses: Disable or Modify Tools T1562.001 6 rules
Valid Accounts T1078 4 rules
Valid Accounts: Cloud Accounts T1078.004 2 rules
Impair Defenses T1562 2 rules
Impair Defenses: Disable or Modify System Firewall T1562.004 1 rule
Impair Defenses: Disable or Modify Cloud Logs T1562.008 1 rule

Credential Access

Unsecured Credentials T1552 4 rules
Forced Authentication T1187 1 rule
Adversary-in-the-Middle T1557 1 rule

Discovery

Permission Groups Discovery T1069 5 rules
Network Service Discovery T1046 2 rules
Account Discovery T1087 1 rule
Cloud Service Discovery T1526 1 rule

Lateral Movement

Use Alternate Authentication Material T1550 3 rules
Remote Services T1021 1 rule

Collection

Data from Cloud Storage T1530 1 rule

Command & Control

Non-Application Layer Protocol T1095 5 rules
Application Layer Protocol: DNS T1071.004 2 rules

Exfiltration

Exfiltration Over Web Service T1567 1 rule
Exfiltration Over Web Service: Exfiltration to Cloud Storage T1567.002 1 rule

Impact

Data Destruction T1485 1 rule
Inhibit System Recovery T1490 1 rule

Microsoft 365

Initial Access

Phishing T1566 13 rules
Phishing: Spearphishing Link T1566.002 2 rules
Trusted Relationship T1199 1 rule

Execution

User Execution T1204 1 rule
User Execution: Malicious Link T1204.001 1 rule

Persistence

Account Manipulation T1098 6 rules
Create Account T1136 2 rules

Privilege Escalation

Abuse Elevation Control Mechanism T1548 1 rule

Stealth

Valid Accounts T1078 6 rules
Impair Defenses T1562 2 rules

Credential Access

OS Credential Dumping: LSA Secrets T1003.004 1 rule

Lateral Movement

Lateral Tool Transfer T1570 1 rule

Collection

Email Collection T1114 6 rules

Command & Control

Application Layer Protocol T1071 7 rules
Ingress Tool Transfer T1105 1 rule

Exfiltration

Automated Exfiltration T1020 6 rules
Data Transfer Size Limits T1030 2 rules
Exfiltration Over Alternative Protocol T1048 2 rules
Exfiltration Over Web Service T1567 1 rule

Impact

Data Destruction T1485 1 rule
Service Stop T1489 1 rule

Untagged

Google Workspace

Initial Access

Exploit Public-Facing Application T1190 1 rule
Phishing T1566 1 rule

Persistence

Account Manipulation T1098 2 rules
External Remote Services T1133 1 rule
Software Extensions T1176 1 rule
Compromise Host Software Binary T1554 1 rule

Stealth

Masquerading T1036 1 rule

Credential Access

Brute Force T1110 1 rule
Multi-Factor Authentication Interception T1111 1 rule

Lateral Movement

Use Alternate Authentication Material T1550 1 rule

Collection

Email Collection T1114 1 rule
Browser Session Hijacking T1185 1 rule

Okta

Initial Access

Phishing T1566 1 rule

Persistence

Account Manipulation T1098 2 rules

Stealth

Valid Accounts T1078 1 rule
Valid Accounts: Cloud Accounts T1078.004 1 rule
Access Token Manipulation: Make and Impersonate Token T1134.003 1 rule

Defense Impairment

Modify Authentication Process T1556 1 rule

Credential Access

Brute Force T1110 1 rule
Brute Force: Password Spraying T1110.003 1 rule
Multi-Factor Authentication Request Generation T1621 1 rule

GitHub

Initial Access

Exploit Public-Facing Application T1190 1 rule

Execution

Exploitation for Client Execution T1203 1 rule

Privilege Escalation

Exploitation for Privilege Escalation T1068 1 rule

Stealth

Valid Accounts T1078 11 rules
Impair Defenses T1562 2 rules
Exploitation for Stealth T1211 1 rule

Credential Access

Exploitation for Credential Access T1212 1 rule
Unsecured Credentials T1552 1 rule

Lateral Movement

Exploitation of Remote Services T1210 1 rule

Collection

Data from Information Repositories T1213 1 rule
Data from Cloud Storage T1530 1 rule

Network

Reconnaissance

Active Scanning T1595 4 rules

Resource Development

Develop Capabilities: Malware T1587.001 1 rule

Initial Access

Exploit Public-Facing Application T1190 92 rules
Phishing T1566 19 rules
Drive-by Compromise T1189 14 rules
Phishing: Spearphishing Attachment T1566.001 1 rule
Phishing: Spearphishing Link T1566.002 1 rule
No specific technique 2 rules

Execution

Command and Scripting Interpreter T1059 9 rules
Exploitation for Client Execution T1203 9 rules
Scheduled Task/Job T1053 2 rules
Command and Scripting Interpreter: PowerShell T1059.001 2 rules
User Execution: Malicious File T1204.002 2 rules
User Execution T1204 1 rule
User Execution: Malicious Link T1204.001 1 rule

Persistence

External Remote Services T1133 77 rules
Server Software Component T1505 4 rules
Account Manipulation T1098 2 rules
Create Account T1136 1 rule

Privilege Escalation

Abuse Elevation Control Mechanism T1548 9 rules
Exploitation for Privilege Escalation T1068 2 rules
Event Triggered Execution T1546 2 rules

Stealth

Valid Accounts T1078 20 rules
Exploitation for Stealth T1211 3 rules
Obfuscated Files or Information T1027 2 rules
Masquerading T1036 2 rules
Access Token Manipulation T1134 1 rule
Deobfuscate/Decode Files or Information T1140 1 rule
Impair Defenses T1562 1 rule
No specific technique 1 rule

Defense Impairment

Modify Authentication Process T1556 1 rule
Network Boundary Bridging T1599 1 rule

Credential Access

OS Credential Dumping T1003 8 rules
Brute Force T1110 6 rules
Adversary-in-the-Middle T1557 2 rules
Forced Authentication T1187 1 rule

Discovery

Account Discovery T1087 9 rules
Network Service Discovery T1046 8 rules
Remote System Discovery T1018 5 rules
System Information Discovery T1082 2 rules
Network Share Discovery T1135 2 rules
Process Discovery T1057 1 rule
File and Directory Discovery T1083 1 rule

Lateral Movement

Remote Services T1021 12 rules
Exploitation of Remote Services T1210 3 rules
Lateral Tool Transfer T1570 1 rule

Collection

Automated Collection T1119 6 rules
Data from Local System T1005 1 rule

Command & Control

Application Layer Protocol T1071 47 rules
Application Layer Protocol: Web Protocols T1071.001 10 rules
Dynamic Resolution T1568 5 rules
Web Service T1102 4 rules
Non-Standard Port T1571 4 rules
Protocol Tunneling T1572 4 rules
Fallback Channels T1008 2 rules
Proxy T1090 2 rules
Web Service: Bidirectional Communication T1102.002 2 rules
Data Encoding T1132 2 rules
Encrypted Channel T1573 2 rules
Data Obfuscation: Protocol or Service Impersonation T1001.003 1 rule
Application Layer Protocol: File Transfer Protocols T1071.002 1 rule
Non-Application Layer Protocol T1095 1 rule
Ingress Tool Transfer T1105 1 rule
No specific technique 9 rules

Exfiltration

Exfiltration Over C2 Channel T1041 16 rules
Data Transfer Size Limits T1030 7 rules
Exfiltration Over Alternative Protocol T1048 5 rules
Automated Exfiltration T1020 3 rules
Exfiltration Over Web Service T1567 3 rules
Exfiltration Over Web Service: Exfiltration to Cloud Storage T1567.002 2 rules
Exfiltration Over Other Network Medium T1011 1 rule
No specific technique 1 rule

Impact

Network Denial of Service T1498 20 rules
Endpoint Denial of Service T1499 9 rules
Data Manipulation T1565 9 rules
Resource Hijacking T1496 4 rules
Data Encrypted for Impact T1486 2 rules
System Shutdown/Reboot T1529 2 rules
Service Stop T1489 1 rule
Inhibit System Recovery T1490 1 rule
Data Manipulation: Stored Data Manipulation T1565.001 1 rule

Untagged

SaaS

Initial Access

Drive-by Compromise T1189 3 rules

Persistence

Account Manipulation T1098 1 rule
External Remote Services T1133 1 rule

Stealth

Valid Accounts T1078 20 rules
Indicator Removal T1070 1 rule
Valid Accounts: Cloud Accounts T1078.004 1 rule

Credential Access

Brute Force T1110 2 rules

Discovery

System Information Discovery T1082 1 rule
Account Discovery T1087 1 rule
Software Discovery T1518 1 rule
Cloud Service Discovery T1526 1 rule

Collection

Automated Collection T1119 2 rules
Data from Information Repositories T1213 1 rule
Data from Cloud Storage T1530 1 rule

Command & Control

Application Layer Protocol: Web Protocols T1071.001 1 rule

Exfiltration

Exfiltration Over Web Service T1567 3 rules
Exfiltration Over Alternative Protocol T1048 2 rules
Transfer Data to Cloud Account T1537 1 rule
Exfiltration Over Web Service: Exfiltration to Cloud Storage T1567.002 1 rule

Impact

Account Access Removal T1531 4 rules
Data Destruction T1485 2 rules
Endpoint Denial of Service T1499 1 rule

Identity

Persistence

Account Manipulation T1098 4 rules

Privilege Escalation

Exploitation for Privilege Escalation T1068 1 rule

Stealth

Valid Accounts T1078 22 rules

Credential Access

Network Sniffing T1040 1 rule
Unsecured Credentials T1552 1 rule
Credentials from Password Stores T1555 1 rule

Discovery

Cloud Infrastructure Discovery T1580 1 rule

Command & Control

Application Layer Protocol T1071 2 rules

Impact

Account Access Removal T1531 2 rules
Service Stop T1489 1 rule

Application

Reconnaissance

Active Scanning T1595 34 rules
Gather Victim Identity Information T1589 15 rules
Search Open Websites/Domains T1593 13 rules
Gather Victim Host Information T1592 11 rules
Active Scanning: Vulnerability Scanning T1595.002 10 rules
Phishing for Information T1598 9 rules
Gather Victim Identity Information: Employee Names T1589.003 4 rules
Gather Victim Org Information T1591 3 rules
Gather Victim Network Information T1590 2 rules
Gather Victim Org Information: Business Relationships T1591.002 2 rules
Search Open Technical Databases T1596 2 rules
Phishing for Information: Spearphishing Link T1598.003 1 rule
No specific technique 1 rule

Resource Development

Acquire Infrastructure T1583 6 rules
Acquire Infrastructure: Domains T1583.001 6 rules
Establish Accounts: Social Media Accounts T1585.001 6 rules
Establish Accounts T1585 5 rules
Compromise Accounts T1586 4 rules
Obtain Capabilities T1588 3 rules
Compromise Infrastructure T1584 2 rules
Establish Accounts: Email Accounts T1585.002 2 rules
Compromise Accounts: Email Accounts T1586.002 2 rules
Develop Capabilities: Malware T1587.001 2 rules
Develop Capabilities T1587 1 rule
Stage Capabilities T1608 1 rule

Initial Access

Exploit Public-Facing Application T1190 62 rules
Phishing T1566 42 rules
Phishing: Spearphishing Link T1566.002 28 rules
Phishing: Spearphishing Attachment T1566.001 23 rules
Drive-by Compromise T1189 22 rules
Phishing: Spearphishing via Service T1566.003 4 rules
Content Injection T1659 4 rules
Supply Chain Compromise T1195 3 rules
Trusted Relationship T1199 2 rules
No specific technique 1 rule

Execution

Command and Scripting Interpreter T1059 41 rules
User Execution T1204 30 rules
User Execution: Malicious Link T1204.001 16 rules
Exploitation for Client Execution T1203 12 rules
Scheduled Task/Job T1053 6 rules
Scheduled Task/Job: Scheduled Task T1053.005 6 rules
Command and Scripting Interpreter: PowerShell T1059.001 2 rules
Command and Scripting Interpreter: Windows Command Shell T1059.003 2 rules
User Execution: Malicious File T1204.002 2 rules
Software Deployment Tools T1072 1 rule
Deploy Container T1610 1 rule
No specific technique 1 rule

Persistence

External Remote Services T1133 38 rules
Account Manipulation T1098 23 rules
Boot or Logon Autostart Execution T1547 10 rules
Server Software Component T1505 9 rules
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder T1547.001 6 rules
Create Account T1136 4 rules
Server Software Component: Web Shell T1505.003 4 rules
Compromise Host Software Binary T1554 4 rules
Create or Modify System Process T1543 2 rules
No specific technique 2 rules

Privilege Escalation

Abuse Elevation Control Mechanism T1548 34 rules
Event Triggered Execution T1546 17 rules
Exploitation for Privilege Escalation T1068 8 rules
Abuse Elevation Control Mechanism: Bypass User Account Control T1548.002 4 rules
No specific technique 3 rules

Stealth

Valid Accounts T1078 46 rules
Impair Defenses T1562 42 rules
Obfuscated Files or Information T1027 15 rules
Masquerading T1036 11 rules
Indicator Removal T1070 10 rules
Process Injection T1055 6 rules
Impair Defenses: Disable or Modify Tools T1562.001 5 rules
Access Token Manipulation T1134 4 rules
Deobfuscate/Decode Files or Information T1140 4 rules
System Binary Proxy Execution T1218 2 rules
Impair Defenses: Indicator Blocking T1562.006 2 rules
Masquerading: Match Legitimate Resource Name or Location T1036.005 1 rule
Trusted Developer Utilities Proxy Execution T1127 1 rule
Exploitation for Stealth T1211 1 rule
Execution Guardrails T1480 1 rule
Impair Defenses: Disable or Modify Cloud Logs T1562.008 1 rule
Hide Artifacts T1564 1 rule
No specific technique 2 rules

Defense Impairment

Modify Authentication Process T1556 9 rules
Subvert Trust Controls T1553 7 rules
Modify Authentication Process: Password Filter DLL T1556.002 4 rules
Rogue Domain Controller T1207 1 rule
File and Directory Permissions Modification T1222 1 rule
Modify Cloud Compute Infrastructure T1578 1 rule

Credential Access

Unsecured Credentials T1552 22 rules
OS Credential Dumping T1003 21 rules
Brute Force T1110 17 rules
Credentials from Password Stores T1555 11 rules
Credentials from Password Stores: Credentials from Web Browsers T1555.003 8 rules
Exploitation for Credential Access T1212 5 rules
Steal Application Access Token T1528 5 rules
Brute Force: Password Spraying T1110.003 4 rules
Forge Web Credentials T1606 3 rules
OS Credential Dumping: LSASS Memory T1003.001 2 rules
Network Sniffing T1040 2 rules
Unsecured Credentials: Credentials In Files T1552.001 2 rules
Forge Web Credentials: Web Cookies T1606.001 2 rules
Forced Authentication T1187 1 rule
Steal Web Session Cookie T1539 1 rule
Steal or Forge Kerberos Tickets T1558 1 rule
Steal or Forge Kerberos Tickets: Golden Ticket T1558.001 1 rule
No specific technique 3 rules

Discovery

System Information Discovery T1082 30 rules
Account Discovery T1087 19 rules
Network Service Discovery T1046 8 rules
File and Directory Discovery T1083 8 rules
Cloud Storage Object Discovery T1619 5 rules
Process Discovery T1057 3 rules
Cloud Service Discovery T1526 3 rules
Permission Groups Discovery T1069 2 rules
Account Discovery: Cloud Account T1087.004 2 rules
Cloud Infrastructure Discovery T1580 2 rules
Remote System Discovery T1018 1 rule
No specific technique 4 rules

Lateral Movement

Remote Services T1021 17 rules
Exploitation of Remote Services T1210 11 rules
Remote Services: SMB/Windows Admin Shares T1021.002 6 rules
Internal Spearphishing T1534 2 rules
Use Alternate Authentication Material T1550 1 rule
No specific technique 3 rules

Collection

Data from Cloud Storage T1530 38 rules
Data from Information Repositories T1213 23 rules
Automated Collection T1119 19 rules
Email Collection T1114 10 rules
Archive Collected Data T1560 10 rules
Data from Local System T1005 5 rules
Data Staged T1074 3 rules
Screen Capture T1113 2 rules
Data from Removable Media T1025 1 rule
Input Capture T1056 1 rule

Command & Control

Application Layer Protocol T1071 43 rules
Application Layer Protocol: Web Protocols T1071.001 22 rules
Proxy T1090 15 rules
Fallback Channels T1008 9 rules
Dynamic Resolution: Domain Generation Algorithms T1568.002 8 rules
Data Obfuscation T1001 6 rules
Protocol Tunneling T1572 5 rules
Proxy: Multi-hop Proxy T1090.003 4 rules
Ingress Tool Transfer T1105 4 rules
Dynamic Resolution T1568 4 rules
Encrypted Channel: Symmetric Cryptography T1573.001 4 rules
Application Layer Protocol: Mail Protocols T1071.003 2 rules
Web Service T1102 2 rules
Encrypted Channel T1573 2 rules
Proxy: External Proxy T1090.002 1 rule
Non-Application Layer Protocol T1095 1 rule
Non-Standard Port T1571 1 rule
No specific technique 1 rule

Exfiltration

Exfiltration Over C2 Channel T1041 32 rules
Exfiltration Over Web Service T1567 14 rules
Exfiltration Over Alternative Protocol T1048 12 rules
Transfer Data to Cloud Account T1537 11 rules
Automated Exfiltration T1020 5 rules
Data Transfer Size Limits T1030 5 rules
Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol T1048.002 4 rules
Exfiltration Over Web Service: Exfiltration to Cloud Storage T1567.002 2 rules
No specific technique 1 rule

Impact

Data Manipulation T1565 27 rules
Endpoint Denial of Service T1499 19 rules
Data Destruction T1485 18 rules
Data Encrypted for Impact T1486 18 rules
Defacement T1491 10 rules
Network Denial of Service T1498 10 rules
System Shutdown/Reboot T1529 8 rules
Resource Hijacking T1496 6 rules
Account Access Removal T1531 6 rules
Service Stop T1489 2 rules
Financial Theft T1657 1 rule
No specific technique 1 rule

Untagged