Live Active security incident? Get immediate response
MITRE ATT&CK® Reference

Detections

Detection strategies and analytics from ATT&CK where present.

2,986 records · validated library

Detections results

Results are validated against normalized ATT&CK source records when available; sample records are used only in development or empty-data environments.

Analytic Enterprise

AN0146: Analytic 0146

Flags unexpected user applications initiating long-lived HTTP(S) sessions with irregular traffic patterns.

macOS
Analytic Enterprise

AN0147: Analytic 0147

Sequence of internal email sent from a recently compromised user account (preceded by abnormal logon or device activity), with attachments or links leading to execution or credential harvesting. Defender observes: internal mail delivery to peers with high entropy attachments, followed by click events, process initiation, or credential prompts.

Windows
Analytic Enterprise

AN0148: Analytic 0148

Delivery of suspicious internal communication (e.g., Thunderbird, Evolution) using compromised internal accounts. Sequence of: unexpected user activity + mail transfer logs + download or execution of attachments.

Linux
Analytic Enterprise

AN0149: Analytic 0149

Abnormal Apple Mail use, including internal email relays followed by file execution or script events (e.g., attachments launched via Preview, terminal triggered from Mail.app)

macOS
Analytic Enterprise

AN0150: Analytic 0150

Internal spearphishing via SaaS applications (e.g., Slack, Teams, Gmail): message sent from compromised user with attachment or URL, followed by click and credential access behavior.

SaaS
Analytic Enterprise

AN0151: Analytic 0151

Outlook or Word used to forward suspicious internal attachments with macro content. Defender observes attachment forwarding, auto-opening behaviors, or macro prompt interactions.

Office Suite
Analytic Enterprise

AN0152: Analytic 0152

Detection of adversary attempts to enumerate Group Policy settings through suspicious command execution (gpresult), PowerShell enumeration (Get-DomainGPO, Get-DomainGPOLocalGroup), and abnormal LDAP queries targeting groupPolicyContainer objects. Defenders observe unusual process lineage, script execution, or LDAP filter activity against domain controllers.

Windows
Analytic Enterprise

AN0153: Analytic 0153

Detection of unauthorized modifications to Windows root certificate stores by monitoring registry keys, certificate installation processes, and creation of new certificate entries not in baseline trusted lists.

Windows
Analytic Enterprise

AN0154: Analytic 0154

Detection of unexpected additions or modifications to system-wide certificate stores or execution of commands adding certificates to trusted stores.

Linux
Analytic Enterprise

AN0155: Analytic 0155

Detection of malicious certificate installation via monitoring execution of the `security add-trusted-cert` command and modifications to system keychains.

macOS
Analytic Enterprise

AN0156: Analytic 0156

Detects suspicious memory access attempts targeting the `securityd` process. Observes tools invoking process memory read operations (e.g., ptrace, task_for_pid) against `securityd`. Correlates with anomalous parent process lineage, root privilege escalation, or repeated unauthorized attempts.

macOS
Analytic Enterprise

AN0157: Analytic 0157

Detects adversaries attempting to attach debuggers or memory dump utilities to credential storage daemons analogous to macOS `securityd`. Observes ptrace syscalls, /proc//mem access, or gcore dumps against sensitive processes. Correlates anomalies with privilege escalation or credential dumping attempts.

Linux
Analytic Enterprise

AN0158: Analytic 0158

Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior).

Windows
Analytic Enterprise

AN0159: Analytic 0159

Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior).

Linux
Analytic Enterprise

AN0160: Analytic 0160

Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior).

macOS
Analytic Enterprise

AN0161: Analytic 0161

Detection of a process or script that accesses a common web service to retrieve content containing obfuscated indicators of a secondary C2 server (dead drop resolver behavior).

ESXi
Analytic Enterprise

AN0162: Analytic 0162

Correlate unauthorized or anomalous file modifications, deletions, or metadata changes with suspicious process execution or API calls. Detect abnormal changes to structured data (e.g., database files, logs, financial records) outside expected business process activity.

Windows
Analytic Enterprise

AN0163: Analytic 0163

Detect unauthorized manipulation of log files, database entries, or system configuration files through auditd and syslog. Correlate shell commands that alter HISTFILE or data-related processes with abnormal file access patterns.

Linux
Analytic Enterprise

AN0164: Analytic 0164

Detect manipulation of system or application files in `/Library`, `/System`, or user data directories using FSEvents and Unified Logs. Identify anomalous process execution modifying plist files, structured data, or logs outside expected update cycles.

macOS
Analytic Enterprise

AN0165: Analytic 0165

Unusual or uncommon processes initiate network connections to external destinations followed by file creation (tools downloaded).

Windows
Analytic Enterprise

AN0166: Analytic 0166

Shell-based tools (curl, wget, scp) initiate connections to external domains followed by creation of executable files on disk.

Linux
Analytic Enterprise

AN0167: Analytic 0167

Process execution of curl or wget followed by a network connection and a file created in temporary or user-specific directories.

macOS
Analytic Enterprise

AN0168: Analytic 0168

Command line interface or vCLI triggers remote transfer using wget or curl, writing files into datastore paths or local tmp directories.

ESXi
Analytic Enterprise

AN0169: Analytic 0169

Network device logs show anomalous inbound file transfers or uncharacteristic flows with high payload volume to network devices with storage or automation hooks.

Network Devices
Analytic Enterprise

AN0170: Analytic 0170

Detects modification of registry keys used for default file handlers, followed by anomalous process execution from user-initiated file opens. This includes tracking changes under HKCU and HKCR for file extension mappings, and correlating them with new or suspicious handler paths launching unusual child processes (e.g., PowerShell, cmd, wscript).

Windows
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.