Live Active security incident? Get immediate response
MITRE ATT&CK® Reference

Data Sources

Detection telemetry sources used by SOC and detection engineering teams.

61 records · validated library

Data Sources results

Results are validated against normalized ATT&CK source records when available; sample records are used only in development or empty-data environments.

Data Source Enterprise

DS0035: Internet Scan

Information obtained (commonly via active network traffic probes or web crawling) regarding various types of resources and servers connected to the public Internet

PRE Revoked/deprecated
Data Source Enterprise

DS0008: Kernel

A computer program, at the core of a computer OS, that resides in memory and facilitates interactions between hardware and software components[1][2]

LinuxmacOS Revoked/deprecated
Data Source Enterprise

DS0028: Logon Session

Logon occurring on a system or resource (local, domain, or cloud) to which a user/device is gaining access after successful authentication and authorization[1]

IaaSLinuxSaaS Revoked/deprecated
Data Source ICS

DS0028: Logon Session

Logon occurring on a system or resource (local, domain, or cloud) to which a user/device is gaining access after successful authentication and authorization[1]

IaaSLinuxSaaS Revoked/deprecated
Data Source Enterprise

DS0004: Malware Repository

Information obtained (via shared or submitted samples) regarding malicious software (droppers, backdoors, etc.) used by adversaries

PRE Revoked/deprecated
Data Source Enterprise

DS0011: Module

Executable files consisting of one or more shared classes and interfaces, such as portable executable (PE) format binaries/dynamic link libraries (DLL), executable and linkable format (ELF) binaries/shared libraries, and Mach-O format binaries/shared libraries[1][2]

LinuxWindowsmacOS Revoked/deprecated
Data Source ICS

DS0011: Module

Executable files consisting of one or more shared classes and interfaces, such as portable executable (PE) format binaries/dynamic link libraries (DLL), executable and linkable format (ELF) binaries/shared libraries, and Mach-O format binaries/shared libraries[1][2]

LinuxWindowsmacOS Revoked/deprecated
Data Source Enterprise

DS0023: Named Pipe

Mechanisms that allow inter-process communication locally or over the network. A named pipe is usually found as a file and processes attach to it[1]

LinuxWindowsmacOS Revoked/deprecated
Data Source Enterprise

DS0033: Network Share

A storage resource (typically a folder or drive) made available from one host to others using network protocols, such as Server Message Block (SMB) or Network File System (NFS)[1]

LinuxWindowsmacOS Revoked/deprecated
Data Source ICS

DS0033: Network Share

A storage resource (typically a folder or drive) made available from one host to others using network protocols, such as Server Message Block (SMB) or Network File System (NFS)[1]

LinuxWindowsmacOS Revoked/deprecated
Data Source Enterprise

DS0029: Network Traffic

Data transmitted across a network (ex: Web, DNS, Mail, File, etc.), that is either summarized (ex: Netflow) and/or captured as raw data in an analyzable format (ex: PCAP)

IaaSLinuxWindows Revoked/deprecated
Data Source Mobile

DS0029: Network Traffic

Data transmitted across a network (ex: Web, DNS, Mail, File, etc.), that is either summarized (ex: Netflow) and/or captured as raw data in an analyzable format (ex: PCAP)

IaaSLinuxWindows Revoked/deprecated
Data Source ICS

DS0029: Network Traffic

Data transmitted across a network (ex: Web, DNS, Mail, File, etc.), that is either summarized (ex: Netflow) and/or captured as raw data in an analyzable format (ex: PCAP)

IaaSLinuxWindows Revoked/deprecated
Data Source ICS

DS0040: Operational Databases

Operational databases contain information about the status of the operational process and associated devices, including any measurements, events, history, or alarms that have occurred

Revoked/deprecated
Data Source Enterprise

DS0021: Persona

A malicious online profile representing a user commonly used by adversaries to social engineer or otherwise target victims

PRE Revoked/deprecated
Data Source Enterprise

DS0014: Pod

A single unit of shared resources within a cluster, comprised of one or more containers[1][2]

Containers Revoked/deprecated
Data Source Enterprise

DS0009: Process

Instances of computer programs that are being executed by at least one thread. Processes have memory space for process executables, loaded modules (DLLs or shared libraries), and allocated memory regions containing everything from user input to application-specific data structures[1]

LinuxWindowsmacOS Revoked/deprecated
Data Source Mobile

DS0009: Process

Instances of computer programs that are being executed by at least one thread. Processes have memory space for process executables, loaded modules (DLLs or shared libraries), and allocated memory regions containing everything from user input to application-specific data structures[1]

LinuxWindowsmacOS Revoked/deprecated
Data Source ICS

DS0009: Process

Instances of computer programs that are being executed by at least one thread. Processes have memory space for process executables, loaded modules (DLLs or shared libraries), and allocated memory regions containing everything from user input to application-specific data structures[1]

LinuxWindowsmacOS Revoked/deprecated
Data Source Enterprise

DS0003: Scheduled Job

Automated tasks that can be executed at a specific time or on a recurring schedule running in the background (ex: Cron daemon, task scheduler, BITS)[1]

ContainersLinuxWindows Revoked/deprecated
Data Source ICS

DS0003: Scheduled Job

Automated tasks that can be executed at a specific time or on a recurring schedule running in the background (ex: Cron daemon, task scheduler, BITS)[1]

ContainersLinuxWindows Revoked/deprecated
Data Source Enterprise

DS0012: Script

A file or stream containing a list of commands, allowing them to be launched in sequence[1][2][3]

WindowsESXi Revoked/deprecated
Data Source ICS

DS0012: Script

A file or stream containing a list of commands, allowing them to be launched in sequence[1][2][3]

WindowsESXi Revoked/deprecated
Data Source Enterprise

DS0013: Sensor Health

Information from host telemetry providing insights about system status, errors, or other notable functional activity

LinuxWindowsmacOS Revoked/deprecated
Data Source Mobile

DS0013: Sensor Health

Information from host telemetry providing insights about system status, errors, or other notable functional activity

LinuxWindowsmacOS Revoked/deprecated
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.