Live Active security incident? Get immediate response
MITRE ATT&CK® Reference

Detections

Detection strategies and analytics from ATT&CK where present.

2,986 records · validated library

Detections results

Results are validated against normalized ATT&CK source records when available; sample records are used only in development or empty-data environments.

Analytic Enterprise

AN0521: Analytic 0521

Detects deletion or overwriting of bash history, syslog, audit logs, and .ssh metadata following privilege elevation or suspicious process spawning.

Linux
Analytic Enterprise

AN0522: Analytic 0522

Detects clearing of unified logs, deletion of plist files tied to persistence, and manipulation of Terminal history after initial execution.

macOS
Analytic Enterprise

AN0523: Analytic 0523

Monitors tampering with audit logs, volumes, or mounted storage often used for side-channel logging (e.g., /var/log inside containers) post-compromise.

Containers
Analytic Enterprise

AN0524: Analytic 0524

Tracks suspicious use of ESXi shell commands or PowerCLI to delete logs, rotate system files, or tamper with hostd/vpxa history.

ESXi
Analytic Enterprise

AN0525: Analytic 0525

Detects deletion or hiding of security-related mail rules, audit mailboxes, or calendar/log sync artifacts indicative of tampering post-intrusion.

Office Suite
Analytic Enterprise

AN0526: Analytic 0526

Use of AWS STS or GCP IAM APIs to request temporary tokens or federation sessions inconsistent with normal account activity, including from unexpected principals or regions.

IaaS
Analytic Enterprise

AN0527: Analytic 0527

OAuth or SAML access tokens reused across multiple sessions or clients without corresponding MFA or login activity.

Identity Provider
Analytic Enterprise

AN0528: Analytic 0528

Application access tokens used to call APIs (e.g., Google Workspace, Salesforce) without interactive logins, often with unusual scopes or elevated permissions.

SaaS
Analytic Enterprise

AN0529: Analytic 0529

OAuth token usage for Exchange Online or SharePoint API access without preceding login or from unauthorized clients.

Office Suite
Analytic Enterprise

AN0530: Analytic 0530

Compromised service account tokens mounted inside containers and reused for external API calls or lateral movement across services.

Containers
Analytic Enterprise

AN0531: Analytic 0531

Automated execution of native utilities and scripts to discover, enumerate, and exfiltrate files and clipboard content. Focus is on detecting repeated file access, scripting engine use, and use of command-line utilities commonly leveraged by collection scripts.

Windows
Analytic Enterprise

AN0532: Analytic 0532

Repeated or automated access to user document directories or clipboard using shell scripts or utilities like xclip/pbpaste. Detectable via auditd syscall logs or osquery file events.

Linux
Analytic Enterprise

AN0533: Analytic 0533

Use of pbpaste, AppleScript, or third-party automation frameworks (e.g., Automator) to collect clipboard or file content in bursts. Observable via unified logs.

macOS
Analytic Enterprise

AN0534: Analytic 0534

Suspicious sign-ins to Graph API or sensitive resources using non-browser scripting agents (e.g., Python, PowerShell), often for programmatic access to mailbox or OneDrive content.

SaaS
Analytic Enterprise

AN0535: Analytic 0535

Detection of attempts to disable or tamper with Windows Event Logging. This includes stopping or disabling the EventLog service, modifying registry keys related to EventLog and Autologger, using `auditpol` or `wevtutil` to disable categories or clear audit policies, and detecting suspicious gaps or resets in event logs. Defenders observe registry changes, service state changes, process execution of disabling commands, and anomalies in event record sequences.

Windows
Analytic Enterprise

AN0536: Analytic 0536

Drive enumeration using PowerShell (`Get-PSDrive`), `wmic logicaldisk`, or Win32 API indicative of local volume enumeration by non-admin users or executed outside of baseline system inventory scripts.

Windows
Analytic Enterprise

AN0537: Analytic 0537

Abnormal use of `lsblk`, `fdisk -l`, `lshw -class disk`, or `parted` by non-admin users or within non-interactive shells suggests suspicious disk enumeration activity.

Linux
Analytic Enterprise

AN0538: Analytic 0538

Disk enumeration via `diskutil list` or `system_profiler SPStorageDataType` run outside of user login or not associated with system inventory tools

macOS
Analytic Enterprise

AN0539: Analytic 0539

Use of `esxcli storage` or `vim-cmd vmsvc/getallvms` by unusual sessions or through interactive shells unrelated to administrative maintenance tasks.

ESXi
Analytic Enterprise

AN0540: Analytic 0540

Detection of known tools or malware flagged by antivirus, followed by a near-term drop of a similar binary with modified signature and resumed activity (execution, C2, or persistence).

Windows
Analytic Enterprise

AN0541: Analytic 0541

Detection of anti-malware quarantining or flagging a tool, followed by a new binary written to disk with a similar function or name and a resumed process chain.

Linux
Analytic Enterprise

AN0542: Analytic 0542

Detection of XProtect or AV quarantining a known tool, followed by modification (file size, hash, string) and subsequent re-execution by the same or related user.

macOS
Analytic Enterprise

AN0543: Analytic 0543

Detects registry and Group Policy modifications that disable or weaken MFA, suspicious PowerShell usage modifying MFA-related attributes, and anomalous login sessions succeeding without expected MFA challenge.

Windows
Analytic Enterprise

AN0544: Analytic 0544

Detects conditional access policy changes, exclusion of accounts from MFA enforcement, or registration of new MFA factors by non-admin or anomalous users.

Identity Provider
Analytic Enterprise

AN0545: Analytic 0545

Detects API calls to cloud secrets/MFA configurations where MFA enforcement policies are disabled or bypassed.

IaaS
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.