Live Active security incident? Get immediate response
MITRE ATT&CK® Reference

Detections

Detection strategies and analytics from ATT&CK where present.

2,986 records · validated library

Detections results

Results are validated against normalized ATT&CK source records when available; sample records are used only in development or empty-data environments.

Analytic Enterprise

AN1521: Analytic 1521

Series of authentication failures (Event ID 4625) targeting the same or similar user accounts over time from one or more remote IPs

Windows
Analytic Enterprise

AN1522: Analytic 1522

Repeated failed SSH login attempts followed by a possible success from the same remote host

Linux
Analytic Enterprise

AN1523: Analytic 1523

Series of failed logins from loginwindow or sshd with repeated usernames or password prompts

macOS
Analytic Enterprise

AN1524: Analytic 1524

Multiple failed sign-in attempts from external sources across many users followed by success from the same IP

Identity Provider
Analytic Enterprise

AN1525: Analytic 1525

Login attempt failures over SNMP, Telnet, or SSH interface, often reflected in logs or syslog events

Network Devices
Analytic Enterprise

AN1526: Analytic 1526

Password guessing attempts against web-based apps (e.g., Dropbox, Google Workspace) reflected in API or sign-in logs

SaaS
Analytic Enterprise

AN1527: Analytic 1527

Detects creation or modification of Windows Services through command-line tools (e.g., `sc.exe`, `powershell.exe`), Registry key changes under `HKLM\System\CurrentControlSet\Services`, and service execution under SYSTEM with unsigned or anomalous binary paths. Detects privilege escalation via driver installation or `CreateServiceW` usage. Correlates parent-child lineage, startup behavior, and rare service names.

Windows
Analytic Enterprise

AN1528: Analytic 1528

Detects the creation or execution of padded binary files (e.g., large size but minimal legitimate content) followed by process execution or lateral movement from the host.

Windows
Analytic Enterprise

AN1529: Analytic 1529

Detects abnormal creation of binary files with significant size that are subsequently executed or accessed by non-standard users.

Linux
Analytic Enterprise

AN1530: Analytic 1530

Monitors for anomalous binary files written to disk with padded size and subsequent execution by user or service context.

macOS
Analytic Enterprise

AN1531: Analytic 1531

Detection of non-interactive or suspicious processes accessing Bluetooth interfaces and transmitting outbound traffic following file access or staging activity.

Windows
Analytic Enterprise

AN1532: Analytic 1532

Use of hcitool, bluetoothctl, or rfcomm to initialize Bluetooth connection paired with recent file reads by the same user or session.

Linux
Analytic Enterprise

AN1533: Analytic 1533

Observation of `blueutil`/`networksetup` commands or low-level APIs toggling Bluetooth or initiating transfers, especially if paired with recent large file read activity by non-GUI processes.

macOS
Analytic Enterprise

AN1534: Analytic 1534

Detection focuses on identifying unauthorized file creation or modification within `/etc/emond.d/rules/` or `/private/var/db/emondClients`, which indicate attempts to register a malicious emond rule. Correlate with process execution of `/sbin/emond` and any launched commands it invokes, especially during boot or login events. Anomalies may include rules created by non-root users or unexpected shell commands executed by emond.

macOS
Analytic Enterprise

AN1535: Analytic 1535

MSBuild.exe is invoked outside expected developer/build contexts or with anomalous arguments (e.g., non-canonical paths, remote shares, Base64/obfuscated property values). Within a short window, it (a) spawns high-risk LOLBins/script interpreters, (b) writes new PE/DLL/script artifacts into user-writable paths and executes them, (c) loads unsigned/user-writable modules, (d) performs memory injection/thread creation into other processes, and/or (e) initiates outbound network connections.

Windows
Analytic Enterprise

AN1536: Analytic 1536

Registry key modification to AppInit_DLLs value followed by anomalous DLL loading by processes importing user32.dll, especially unsigned or uncommon DLLs, suggesting unauthorized AppInit persistence or privilege escalation.

Windows
Analytic Enterprise

AN1537: Analytic 1537

Detects suspicious use of ESXi native CLI tools like esxcli and vim-cmd by unauthorized users or outside expected maintenance windows. Focus is on actions such as stopping VMs, reconfiguring network/firewall settings, and enabling SSH or logging.

ESXi
Analytic Enterprise

AN1538: Analytic 1538

Correlate process execution of shutdown/reboot commands (e.g., shutdown.exe, restart-computer) with host status change logs (Event IDs 1074, 6006) and absence of related administrative context (e.g., user not in Helpdesk group).

Windows
Analytic Enterprise

AN1539: Analytic 1539

Detect 'shutdown', 'reboot', or 'systemctl poweroff' executions with auditd/syslog and absence of scheduled maintenance windows or approved user context.

Linux
Analytic Enterprise

AN1540: Analytic 1540

Identify use of 'shutdown', 'reboot', or 'osascript' system shutdown invocations within unified logs and track unexpected shutdown sequences initiated by GUI or script. Cross-reference with user activity or absence thereof.

macOS
Analytic Enterprise

AN1541: Analytic 1541

Detect commands such as 'esxcli system shutdown' or 'vim-cmd vmsvc/power.shutdown' executed outside of maintenance windows or via unusual users. Reboot logs in hostd.log and shell logs should be correlated.

ESXi
Analytic Enterprise

AN1542: Analytic 1542

Monitor CLI 'reload' commands issued without scheduled maintenance, and correlate to TACACS+/AAA logs for privilege validation.

Network Devices
Analytic Enterprise

AN1543: Analytic 1543

Detection of compromised or misused valid accounts via anomalous logon patterns, abnormal logon types, and inconsistent geographic or time-based activity across Windows endpoints.

Windows
Analytic Enterprise

AN1544: Analytic 1544

Detection of valid account misuse through SSH logins, sudo/su abuse, and service account anomalies outside expected patterns.

Linux
Analytic Enterprise

AN1545: Analytic 1545

Detection of interactive and remote logins by service accounts or users at unusual times, with unexpected child process activity.

macOS
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.