Live Active security incident? Get immediate response
MITRE ATT&CK® Reference

Data Sources

Detection telemetry sources used by SOC and detection engineering teams.

61 records · validated library

Data Sources results

Results are validated against normalized ATT&CK source records when available; sample records are used only in development or empty-data environments.

Data Source Enterprise

DS0026: Active Directory

A database and set of services that allows administrators to manage permissions, access to network resources, and stored data objects (user, group, application, or devices)[1]

WindowsIdentity Provider Revoked/deprecated
Data Source Enterprise

DS0015: Application Log

Events collected by third-party services such as mail servers, web applications, or other appliances (not by the native OS or platform)[1]

IaaSLinuxSaaS Revoked/deprecated
Data Source ICS

DS0015: Application Log

Events collected by third-party services such as mail servers, web applications, or other appliances (not by the native OS or platform)[1]

IaaSLinuxSaaS Revoked/deprecated
Data Source ICS

DS0039: Asset

Data sources with information about the set of devices found within the network, along with their current software and configurations

Revoked/deprecated
Data Source Enterprise

DS0037: Certificate

A digital document, which highlights information such as the owner's identity, used to instill trust in public keys used while encrypting network communications

PRE Revoked/deprecated
Data Source Enterprise

DS0025: Cloud Service

Infrastructure, platforms, or software that are hosted on-premise or by third-party providers, made available to users through network connections and/or APIs[1][2]

IaaSSaaSOffice Suite Revoked/deprecated
Data Source Enterprise

DS0010: Cloud Storage

Data object storage infrastructure hosted on-premise or by third-party providers, made available to users through network connections and/or APIs[1][2][3]

IaaS Revoked/deprecated
Data Source Enterprise

DS0031: Cluster

A set of containerized computing resources that are managed together but have separate nodes to execute various tasks and/or applications[1][2]

Containers Revoked/deprecated
Data Source Enterprise

DS0017: Command

A directive given to a computer program, acting as an interpreter of some kind, in order to perform a specific task[1][2]

ContainersLinuxNetwork Devices Revoked/deprecated
Data Source Mobile

DS0017: Command

A directive given to a computer program, acting as an interpreter of some kind, in order to perform a specific task[1][2]

ContainersLinuxNetwork Devices Revoked/deprecated
Data Source ICS

DS0017: Command

A directive given to a computer program, acting as an interpreter of some kind, in order to perform a specific task[1][2]

ContainersLinuxNetwork Devices Revoked/deprecated
Data Source Enterprise

DS0032: Container

A standard unit of virtualized software that packages up code and all its dependencies so the application runs quickly and reliably from one computing environment to another[1]

Containers Revoked/deprecated
Data Source Enterprise

DS0038: Domain Name

Information obtained (commonly through registration or activity logs) regarding one or more IP addresses registered with human readable names (ex: mitre.org)

PRE Revoked/deprecated
Data Source Enterprise

DS0016: Drive

A non-volatile data storage device (hard drive, floppy disk, USB flash drive) with at least one formatted partition, typically mounted to the file system and/or assigned a drive letter[1]

LinuxWindowsmacOS Revoked/deprecated
Data Source ICS

DS0016: Drive

A non-volatile data storage device (hard drive, floppy disk, USB flash drive) with at least one formatted partition, typically mounted to the file system and/or assigned a drive letter[1]

LinuxWindowsmacOS Revoked/deprecated
Data Source Enterprise

DS0027: Driver

A computer program that operates or controls a particular type of device that is attached to a computer. Provides a software interface to hardware devices, enabling operating systems and other computer programs to access hardware functions without needing to know precise details about the hardware being used[1][2]

LinuxWindowsmacOS Revoked/deprecated
Data Source Enterprise

DS0022: File

A computer resource object, managed by the I/O system, for storing data (such as images, text, videos, computer programs, or any wide variety of other media).[1]

LinuxNetwork DevicesWindows Revoked/deprecated
Data Source ICS

DS0022: File

A computer resource object, managed by the I/O system, for storing data (such as images, text, videos, computer programs, or any wide variety of other media).[1]

LinuxNetwork DevicesWindows Revoked/deprecated
Data Source Enterprise

DS0018: Firewall

A network security system, running locally on an endpoint or remotely as a service (ex: cloud environment), that monitors and controls incoming/outgoing network traffic based on predefined rules[1]

IaaSLinuxSaaS Revoked/deprecated
Data Source Enterprise

DS0001: Firmware

Computer software that provides low-level control for the hardware and device(s) of a host, such as BIOS or UEFI/EFI

LinuxWindowsmacOS Revoked/deprecated
Data Source ICS

DS0001: Firmware

Computer software that provides low-level control for the hardware and device(s) of a host, such as BIOS or UEFI/EFI

LinuxWindowsmacOS Revoked/deprecated
Data Source Enterprise

DS0036: Group

A collection of multiple user accounts that share the same access rights to the computer and/or network resources and have common security rights[1]

IaaSSaaSWindows Revoked/deprecated
Data Source Enterprise

DS0007: Image

A single file used to deploy a virtual machine/bootable disk into an on-premise or third-party cloud environment[1][2]

IaaS Revoked/deprecated
Data Source Enterprise

DS0030: Instance

A virtual server environment which runs workloads, hosted on-premise or by third-party cloud providers[1][2]

IaaS Revoked/deprecated
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.