Live Active security incident? Get immediate response
MITRE ATT&CK® Reference

Data Sources

Detection telemetry sources used by SOC and detection engineering teams.

61 records · validated library

Data Sources results

Results are validated against normalized ATT&CK source records when available; sample records are used only in development or empty-data environments.

Data Source Enterprise

DS0019: Service

A computer process that is configured to execute continuously in the background and perform system tasks, in some cases before any user has logged in[1][2]

LinuxWindowsmacOS Revoked/deprecated
Data Source ICS

DS0019: Service

A computer process that is configured to execute continuously in the background and perform system tasks, in some cases before any user has logged in[1][2]

LinuxWindowsmacOS Revoked/deprecated
Data Source Enterprise

DS0020: Snapshot

A point-in-time copy of cloud volumes (files, settings, etc.) that can be created and/or deployed in cloud environments[1][2]

IaaS Revoked/deprecated
Data Source Enterprise

DS0002: User Account

A profile representing a user, device, service, or application used to authenticate and access resources

ContainersIaaSLinux Revoked/deprecated
Data Source ICS

DS0002: User Account

A profile representing a user, device, service, or application used to authenticate and access resources

ContainersIaaSLinux Revoked/deprecated
Data Source Mobile

DS0042: User Interface

Visual activity on the device that could alert the user to potentially malicious behavior.

AndroidiOS Revoked/deprecated
Data Source Enterprise

DS0034: Volume

Block object storage hosted on-premise or by third-party providers, typically made available to resources as virtualized hard drives[1][2][3]

IaaSLinuxWindows Revoked/deprecated
Data Source Enterprise

DS0005: WMI

The infrastructure for management data and operations that enables local and remote management of Windows personal computers and servers[1][2]

Windows Revoked/deprecated
Data Source Enterprise

DS0006: Web Credential

Credential material, such as session cookies or tokens, used to authenticate to web applications and services[1][2]

LinuxSaaSWindows Revoked/deprecated
Data Source Enterprise

DS0024: Windows Registry

A Windows OS hierarchical database that stores much of the information and settings for software programs, hardware devices, user preferences, and operating-system configurations[1]

Windows Revoked/deprecated
Data Source ICS

DS0024: Windows Registry

A Windows OS hierarchical database that stores much of the information and settings for software programs, hardware devices, user preferences, and operating-system configurations[1]

Windows Revoked/deprecated
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.