LiveActive security incident?Get immediate response
MITRE ATT&CK® Reference

MITRE ATT&CK® Reference Library

Searchable adversary behavior context, detection guidance, mitigations, and Glexia analyst summaries built from official MITRE ATT&CK source data.

Official ATT&CK source data

Use official ATT&CK context without losing operational focus

Glexia mirrors official MITRE ATT&CK releases, normalizes objects into searchable records, and adds defensive context for executives, SOC teams, detection engineers, and incident responders.

Matrix-first workflow

Start with the ATT&CK matrix, then drill into Glexia context

MITRE’s official site centers on matrix navigation. Glexia keeps that familiar mental model, then adds fast search, defensive metadata, CVE relevance, and executive-ready triage context.

Recently changed

Recently changed in ATT&CK

These records are sorted from the normalized ATT&CK object modified timestamp. Counts and rows come from imported data, not hard-coded totals.

collectionMobile

Mobile ATT&CK

ATT&CK for Mobile is a matrix of adversary behavior against mobile devices (smartphones and tablets running the Android or iOS/iPadOS operating systems). ATT&CK for Mobile builds upon NIST's Mobile Threat Catalogue and also contains a separate matrix of network-based effects, which are techniques that an adversary can employ without access to the mobile device itself.

collectionICS

ICS ATT&CK

The ATT&CK for Industrial Control Systems (ICS) knowledge base categorizes the unique set of tactics, techniques, and procedures (TTPs) used by threat actors in the ICS technology domain. ATT&CK for ICS outlines the portions of an ICS attack that are out of scope of Enterprise and reflects the various phases of an adversary’s attack life cycle and the assets and systems they are known to target.

collectionEnterprise

Enterprise ATT&CK

ATT&CK for Enterprise provides a knowledge base of real-world adversary behavior targeting traditional enterprise networks. ATT&CK for Enterprise covers the following platforms: Windows, macOS, Linux, PRE, Office 365, Google Workspace, IaaS, Network, and Containers.

TechniqueEnterprise

T1546: Event Triggered Execution

Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events. Various operating systems have means to monitor and subscribe to events such as logons or other user activity such as running specific applications/binaries. Cloud environments may also support various functions and services that monitor and can be invoked in response to specific cloud events.[1][2][3]

Adversaries may abuse these mechanisms as a means of maintaining persistent access to a victim via repeatedly executing malicious code. After gaining access to a victim system, adversaries may create/modify event triggers to point to malicious content that will be executed whenever the event trigger is invoked.[4][5][6]

Since the execution can be proxied by an account with higher permissions, such as SYSTEM or service accounts, an adversary may be able to abuse these triggered execution mechanisms to escalate their privileges.

privilege-escalationpersistenceLinuxmacOSWindows
Domains

Enterprise, Mobile, and ICS coverage

Enterprise
Version 19.2 · 4,823 objects
Mobile
Version 19.2 · 745 objects
ICS
Version 19.2 · 505 objects
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.