LiveActive security incident?Get immediate response
MITRE ATT&CK® Matrix

Enterprise ATT&CK Matrix

A Glexia-styled visualization of ATT&CK tactics and techniques. This is not the MITRE Navigator UI and does not imply MITRE endorsement.

Matrix workbench

697 techniques and sub-techniques mapped across 15 tactics

Use this as a fast defensive coverage map. Each cell links to the normalized Glexia detail page with official source attribution and relationship context.

TA0009

Collection

41 techniques

T1005Data from Local SystemESXi, LinuxT1025Data from Removable MediaLinux, macOST1039Data from Network Shared DriveLinux, macOST1056Input CaptureLinux, macOST1056.001KeyloggingLinux, macOST1056.002GUI Input CaptureLinux, macOST1056.003Web Portal CaptureLinux, macOST1056.004Credential API HookingWindows, LinuxT1074Data StagedESXi, IaaST1074.001Local Data StagingESXi, LinuxT1074.002Remote Data StagingESXi, IaaST1113Screen CaptureLinux, macOST1114Email CollectionWindows, macOST1114.001Local Email CollectionWindowsT1114.002Remote Email CollectionOffice Suite, WindowsT1114.003Email Forwarding RuleLinux, macOST1115Clipboard DataLinux, macOST1119Automated CollectionIaaS, LinuxT1123Audio CaptureLinux, macOST1125Video CaptureLinux, macOST1185Browser Session HijackingWindowsT1213Data from Information RepositoriesLinux, WindowsT1213.001ConfluenceSaaST1213.002SharepointOffice Suite, WindowsT1213.003Code RepositoriesSaaST1213.004Customer Relationship Management SoftwareSaaST1213.005Messaging ApplicationsOffice Suite, SaaST1213.006DatabasesIaaS, LinuxT1530Data from Cloud StorageIaaS, Office SuiteT1557Adversary-in-the-MiddleLinux, macOST1557.001Name Resolution Poisoning and SMB RelayWindowsT1557.002ARP Cache PoisoningLinux, WindowsT1557.003DHCP SpoofingLinux, WindowsT1557.004Evil TwinNetwork DevicesT1560Archive Collected DataLinux, macOST1560.001Archive via UtilityLinux, macOST1560.002Archive via LibraryLinux, macOST1560.003Archive via Custom MethodLinux, macOST1602Data from Configuration RepositoryNetwork DevicesT1602.001SNMP (MIB Dump)Network DevicesT1602.002Network Device Configuration DumpNetwork Devices
TA0011

Command and Control

45 techniques

T1001Data ObfuscationESXi, LinuxT1001.001Junk DataESXi, LinuxT1001.002SteganographyLinux, macOST1001.003Protocol or Service ImpersonationESXi, LinuxT1008Fallback ChannelsESXi, LinuxT1071Application Layer ProtocolLinux, macOST1071.001Web ProtocolsESXi, LinuxT1071.002File Transfer ProtocolsESXi, LinuxT1071.003Mail ProtocolsLinux, macOST1071.004DNSESXi, LinuxT1071.005Publish/Subscribe ProtocolsmacOS, LinuxT1090ProxyESXi, LinuxT1090.001Internal ProxyESXi, LinuxT1090.002External ProxyESXi, LinuxT1090.003Multi-hop ProxyESXi, LinuxT1090.004Domain FrontingLinux, macOST1092Communication Through Removable MediaLinux, macOST1095Non-Application Layer ProtocolESXi, LinuxT1102Web ServiceESXi, LinuxT1102.001Dead Drop ResolverESXi, LinuxT1102.002Bidirectional CommunicationESXi, LinuxT1102.003One-Way CommunicationLinux, macOST1104Multi-Stage ChannelsLinux, macOST1105Ingress Tool TransferESXi, LinuxT1132Data EncodingESXi, LinuxT1132.001Standard EncodingESXi, LinuxT1132.002Non-Standard EncodingESXi, LinuxT1205Traffic SignalingLinux, macOST1205.001Port KnockingLinux, macOST1205.002Socket FiltersLinux, macOST1219Remote Access ToolsLinux, macOST1219.001IDE TunnelingLinux, macOST1219.002Remote Desktop SoftwareLinux, macOST1219.003Remote Access HardwareLinux, macOST1568Dynamic ResolutionESXi, LinuxT1568.001Fast Flux DNSLinux, macOST1568.002Domain Generation AlgorithmsESXi, LinuxT1568.003DNS CalculationESXi, LinuxT1571Non-Standard PortESXi, LinuxT1572Protocol TunnelingESXi, LinuxT1573Encrypted ChannelESXi, LinuxT1573.001Symmetric CryptographyESXi, LinuxT1573.002Asymmetric CryptographyESXi, LinuxT1659Content InjectionLinux, macOST1665Hide InfrastructureESXi, Linux
TA0006

Credential Access

67 techniques

T1003OS Credential DumpingLinux, macOST1003.001LSASS MemoryWindowsT1003.002Security Account ManagerWindowsT1003.003NTDSWindowsT1003.004LSA SecretsWindowsT1003.005Cached Domain CredentialsWindows, LinuxT1003.006DCSyncWindowsT1003.007Proc FilesystemLinuxT1003.008/etc/passwd and /etc/shadowLinuxT1040Network SniffingIaaS, LinuxT1056Input CaptureLinux, macOST1056.001KeyloggingLinux, macOST1056.002GUI Input CaptureLinux, macOST1056.003Web Portal CaptureLinux, macOST1056.004Credential API HookingWindows, LinuxT1110Brute ForceContainers, ESXiT1110.001Password GuessingContainers, ESXiT1110.002Password CrackingIdentity Provider, LinuxT1110.003Password SprayingContainers, ESXiT1110.004Credential StuffingContainers, ESXiT1111Multi-Factor Authentication InterceptionLinux, macOST1187Forced AuthenticationWindowsT1212Exploitation for Credential AccessLinux, WindowsT1528Steal Application Access TokenContainers, IaaST1539Steal Web Session CookieLinux, macOST1552Unsecured CredentialsWindows, SaaST1552.001Credentials In FilesContainers, IaaST1552.002Credentials in RegistryWindowsT1552.003Shell HistoryLinux, macOST1552.004Private KeysLinux, macOST1552.005Cloud Instance Metadata APIIaaST1552.006Group Policy PreferencesWindowsT1552.007Container APIContainersT1552.008Chat MessagesSaaS, Office SuiteT1555Credentials from Password StoresIaaS, LinuxT1555.001KeychainmacOST1555.002Securityd MemoryLinux, macOST1555.003Credentials from Web BrowsersLinux, macOST1555.004Windows Credential ManagerWindowsT1555.005Password ManagersLinux, macOST1555.006Cloud Secrets Management StoresIaaST1556Modify Authentication ProcessIaaS, Identity ProviderT1556.001Domain Controller AuthenticationWindowsT1556.002Password Filter DLLWindowsT1556.003Pluggable Authentication ModulesLinux, macOST1556.004Network Device AuthenticationNetwork DevicesT1556.005Reversible EncryptionWindowsT1556.006Multi-Factor AuthenticationIaaS, Identity ProviderT1556.007Hybrid IdentityIaaS, Identity ProviderT1556.008Network Provider DLLWindowsT1556.009Conditional Access PoliciesIaaS, Identity ProviderT1557Adversary-in-the-MiddleLinux, macOST1557.001Name Resolution Poisoning and SMB RelayWindowsT1557.002ARP Cache PoisoningLinux, WindowsT1557.003DHCP SpoofingLinux, WindowsT1557.004Evil TwinNetwork DevicesT1558Steal or Forge Kerberos TicketsLinux, macOST1558.001Golden TicketWindowsT1558.002Silver TicketWindowsT1558.003KerberoastingWindowsT1558.004AS-REP RoastingWindowsT1558.005Ccache FilesLinux, macOST1606Forge Web CredentialsSaaS, WindowsT1606.001Web CookiesLinux, macOST1606.002SAML TokensSaaS, WindowsT1621Multi-Factor Authentication Request GenerationWindows, LinuxT1649Steal or Forge Authentication CertificatesWindows, Linux
TA0112

Defense Impairment

56 techniques

T1112Modify RegistryWindowsT1207Rogue Domain ControllerWindowsT1222File and Directory Permissions ModificationESXi, LinuxT1222.001Windows PermissionsWindowsT1222.002Linux and Mac PermissionsLinux, macOST1484Domain or Tenant Policy ModificationWindows, Identity ProviderT1484.001Group Policy ModificationWindowsT1484.002Trust ModificationIdentity Provider, WindowsT1553Subvert Trust ControlsLinux, macOST1553.001Gatekeeper BypassmacOST1553.002Code SigningmacOS, WindowsT1553.003SIP and Trust Provider HijackingWindowsT1553.004Install Root CertificateLinux, macOST1553.005Mark-of-the-Web BypassWindowsT1553.006Code Signing Policy ModificationmacOS, WindowsT1556Modify Authentication ProcessIaaS, Identity ProviderT1556.001Domain Controller AuthenticationWindowsT1556.002Password Filter DLLWindowsT1556.003Pluggable Authentication ModulesLinux, macOST1556.004Network Device AuthenticationNetwork DevicesT1556.005Reversible EncryptionWindowsT1556.006Multi-Factor AuthenticationIaaS, Identity ProviderT1556.007Hybrid IdentityIaaS, Identity ProviderT1556.008Network Provider DLLWindowsT1556.009Conditional Access PoliciesIaaS, Identity ProviderT1578Modify Cloud Compute InfrastructureIaaST1578.001Create SnapshotIaaST1578.002Create Cloud InstanceIaaST1578.003Delete Cloud InstanceIaaST1578.004Revert Cloud InstanceIaaST1578.005Modify Cloud Compute ConfigurationsIaaST1599Network Boundary BridgingNetwork DevicesT1599.001Network Address Translation TraversalNetwork DevicesT1600Weaken EncryptionNetwork DevicesT1600.001Reduce Key SpaceNetwork DevicesT1600.002Disable Crypto HardwareNetwork DevicesT1601Modify System ImageNetwork DevicesT1601.001Patch System ImageNetwork DevicesT1601.002Downgrade System ImageNetwork DevicesT1647Plist File ModificationmacOST1666Modify Cloud Resource HierarchyIaaST1685Disable or Modify ToolsContainers, ESXiT1685.001Disable or Modify Windows Event LogWindowsT1685.002Disable or Modify Cloud LogIaaS, SaaST1685.003Modify or Spoof Tool UILinux, macOST1685.004Disable or Modify Linux Audit System LogLinuxT1685.005Clear Windows Event LogsWindowsT1685.006Clear Linux or Mac System LogsLinux, macOST1686Disable or Modify System FirewallESXi, LinuxT1686.001Cloud FirewallIaaST1686.002Network Device FirewallNetwork DevicesT1686.003Windows Host FirewallWindowsT1687Exploitation for Defense ImpairmentIaaS, LinuxT1688Safe Mode BootWindowsT1689Downgrade AttackmacOS, WindowsT1690Prevent Command History LoggingESXi, Linux
TA0007

Discovery

49 techniques

T1007System Service DiscoveryLinux, macOST1010Application Window DiscoveryLinux, macOST1012Query RegistryWindowsT1016System Network Configuration DiscoveryESXi, LinuxT1016.001Internet Connection DiscoveryWindows, LinuxT1016.002Wi-Fi DiscoveryLinux, WindowsT1018Remote System DiscoveryESXi, LinuxT1033System Owner/User DiscoveryLinux, macOST1040Network SniffingIaaS, LinuxT1046Network Service DiscoveryContainers, IaaST1049System Network Connections DiscoveryESXi, IaaST1057Process DiscoveryESXi, LinuxT1069Permission Groups DiscoveryContainers, IaaST1069.001Local GroupsLinux, macOST1069.002Domain GroupsLinux, macOST1069.003Cloud GroupsSaaS, IaaST1082System Information DiscoveryESXi, IaaST1083File and Directory DiscoveryESXi, LinuxT1087Account DiscoveryESXi, IaaST1087.001Local AccountESXi, LinuxT1087.002Domain AccountLinux, macOST1087.003Email AccountWindows, Office SuiteT1087.004Cloud AccountIaaS, Identity ProviderT1120Peripheral Device DiscoveryLinux, macOST1124System Time DiscoveryESXi, LinuxT1135Network Share DiscoveryLinux, macOST1201Password Policy DiscoveryWindows, LinuxT1217Browser Information DiscoveryLinux, macOST1482Domain Trust DiscoveryWindowsT1497Virtualization/Sandbox EvasionLinux, macOST1497.001System ChecksLinux, macOST1497.002User Activity Based ChecksLinux, macOST1497.003Time Based ChecksLinux, macOST1518Software DiscoveryESXi, IaaST1518.001Security Software DiscoveryIaaS, LinuxT1518.002Backup Software DiscoveryWindows, macOST1526Cloud Service DiscoveryIaaS, Identity ProviderT1538Cloud Service DashboardIaaS, SaaST1580Cloud Infrastructure DiscoveryIaaST1613Container and Resource DiscoveryContainersT1614System Location DiscoveryIaaS, LinuxT1614.001System Language DiscoveryLinux, macOST1615Group Policy DiscoveryWindowsT1619Cloud Storage Object DiscoveryIaaST1622Debugger EvasionLinux, macOST1652Device Driver DiscoveryLinux, macOST1654Log EnumerationESXi, IaaST1673Virtual Machine DiscoveryESXi, LinuxT1680Local Storage DiscoveryESXi, IaaS
TA0002

Execution

64 techniques

T1047Windows Management InstrumentationWindowsT1053Scheduled Task/JobContainers, ESXiT1053.002AtWindows, LinuxT1053.003CronLinux, macOST1053.005Scheduled TaskWindowsT1053.006Systemd TimersLinuxT1053.007Container Orchestration JobContainersT1059Command and Scripting InterpreterContainers, ESXiT1059.001PowerShellWindowsT1059.002AppleScriptmacOST1059.003Windows Command ShellWindowsT1059.004Unix ShellESXi, LinuxT1059.005Visual BasicLinux, macOST1059.006PythonESXi, LinuxT1059.007JavaScriptLinux, macOST1059.008Network Device CLINetwork DevicesT1059.009Cloud APIIaaS, Identity ProviderT1059.010AutoHotKey & AutoITWindowsT1059.011LuaLinux, Network DevicesT1059.012Hypervisor CLIESXiT1059.013Container CLI/APIContainersT1072Software Deployment ToolsLinux, macOST1106Native APILinux, macOST1127Trusted Developer Utilities Proxy ExecutionWindowsT1127.001MSBuildWindowsT1127.002ClickOnceWindowsT1127.003JamPlusWindowsT1129Shared ModulesLinux, macOST1197BITS JobsWindowsT1203Exploitation for Client ExecutionLinux, macOST1204User ExecutionLinux, WindowsT1204.001Malicious LinkLinux, macOST1204.002Malicious FileLinux, macOST1204.003Malicious ImageIaaS, ContainersT1204.004Malicious Copy and PasteLinux, macOST1204.005Malicious LibraryLinux, macOST1559Inter-Process CommunicationLinux, macOST1559.001Component Object ModelWindowsT1559.002Dynamic Data ExchangeWindowsT1559.003XPC ServicesmacOST1569System ServicesWindows, macOST1569.001LaunchctlmacOST1569.002Service ExecutionWindowsT1569.003SystemctlLinuxT1574Hijack Execution FlowLinux, macOST1574.001DLLWindowsT1574.004Dylib HijackingmacOST1574.005Executable Installer File Permissions WeaknessWindowsT1574.006Dynamic Linker HijackingLinux, macOST1574.007Path Interception by PATH Environment VariableLinux, macOST1574.008Path Interception by Search Order HijackingWindowsT1574.009Path Interception by Unquoted PathWindowsT1574.010Services File Permissions WeaknessWindowsT1574.011Services Registry Permissions WeaknessWindowsT1574.012COR_PROFILERWindowsT1574.013KernelCallbackTableWindowsT1574.014AppDomainManagerWindowsT1609Container Administration CommandContainersT1610Deploy ContainerContainersT1648Serverless ExecutionSaaS, IaaST1651Cloud Administration CommandIaaST1674Input InjectionWindows, macOST1675ESXi Administration CommandESXiT1677Poisoned Pipeline ExecutionSaaS
TA0010

Exfiltration

19 techniques

T1011Exfiltration Over Other Network MediumLinux, macOST1011.001Exfiltration Over BluetoothLinux, macOST1020Automated ExfiltrationLinux, macOST1020.001Traffic DuplicationNetwork Devices, IaaST1029Scheduled TransferLinux, macOST1030Data Transfer Size LimitsLinux, macOST1041Exfiltration Over C2 ChannelESXi, LinuxT1048Exfiltration Over Alternative ProtocolESXi, IaaST1048.001Exfiltration Over Symmetric Encrypted Non-C2 ProtocolLinux, macOST1048.002Exfiltration Over Asymmetric Encrypted Non-C2 ProtocolESXi, LinuxT1048.003Exfiltration Over Unencrypted Non-C2 ProtocolESXi, LinuxT1052Exfiltration Over Physical MediumLinux, macOST1052.001Exfiltration over USBLinux, WindowsT1537Transfer Data to Cloud AccountIaaS, Office SuiteT1567Exfiltration Over Web ServiceESXi, LinuxT1567.001Exfiltration to Code RepositoryESXi, LinuxT1567.002Exfiltration to Cloud StorageESXi, LinuxT1567.003Exfiltration to Text Storage SitesLinux, macOST1567.004Exfiltration Over WebhookESXi, Linux
TA0040

Impact

33 techniques

T1485Data DestructionContainers, ESXiT1485.001Lifecycle-Triggered DeletionIaaST1486Data Encrypted for ImpactESXi, IaaST1489Service StopESXi, IaaST1490Inhibit System RecoveryContainers, ESXiT1491DefacementWindows, IaaST1491.001Internal DefacementESXi, LinuxT1491.002External DefacementWindows, IaaST1495Firmware CorruptionLinux, macOST1496Resource HijackingWindows, IaaST1496.001Compute HijackingWindows, IaaST1496.002Bandwidth HijackingLinux, WindowsT1496.003SMS PumpingSaaST1496.004Cloud Service HijackingSaaST1498Network Denial of ServiceWindows, IaaST1498.001Direct Network FloodWindows, IaaST1498.002Reflection AmplificationWindows, IaaST1499Endpoint Denial of ServiceWindows, LinuxT1499.001OS Exhaustion FloodLinux, macOST1499.002Service Exhaustion FloodWindows, IaaST1499.003Application Exhaustion FloodWindows, IaaST1499.004Application or System ExploitationWindows, IaaST1529System Shutdown/RebootESXi, LinuxT1531Account Access RemovalLinux, macOST1561Disk WipeLinux, macOST1561.001Disk Content WipeLinux, macOST1561.002Disk Structure WipeLinux, macOST1565Data ManipulationLinux, macOST1565.001Stored Data ManipulationLinux, macOST1565.002Transmitted Data ManipulationLinux, macOST1565.003Runtime Data ManipulationLinux, macOST1657Financial TheftLinux, macOST1667Email BombingLinux, Office Suite
TA0001

Initial Access

22 techniques

T1078Valid AccountsContainers, ESXiT1078.001Default AccountsContainers, ESXiT1078.002Domain AccountsESXi, LinuxT1078.003Local AccountsContainers, ESXiT1078.004Cloud AccountsIaaS, Identity ProviderT1091Replication Through Removable MediaWindowsT1133External Remote ServicesContainers, LinuxT1189Drive-by CompromiseIdentity Provider, LinuxT1190Exploit Public-Facing ApplicationContainers, ESXiT1195Supply Chain CompromiseLinux, WindowsT1195.001Compromise Software Dependencies and Development ToolsLinux, macOST1195.002Compromise Software Supply ChainLinux, WindowsT1195.003Compromise Hardware Supply ChainLinux, macOST1199Trusted RelationshipIaaS, Identity ProviderT1200Hardware AdditionsWindows, LinuxT1566PhishingIdentity Provider, LinuxT1566.001Spearphishing AttachmentLinux, macOST1566.002Spearphishing LinkIdentity Provider, LinuxT1566.003Spearphishing via ServiceLinux, macOST1566.004Spearphishing VoiceLinux, macOST1659Content InjectionLinux, macOST1669Wi-Fi NetworksLinux, Network Devices
TA0008

Lateral Movement

23 techniques

T1021Remote ServicesLinux, macOST1021.001Remote Desktop ProtocolWindowsT1021.002SMB/Windows Admin SharesWindowsT1021.003Distributed Component Object ModelWindowsT1021.004SSHESXi, LinuxT1021.005VNCLinux, WindowsT1021.006Windows Remote ManagementWindowsT1021.007Cloud ServicesIaaS, Identity ProviderT1021.008Direct Cloud VM ConnectionsIaaST1072Software Deployment ToolsLinux, macOST1080Taint Shared ContentWindows, SaaST1091Replication Through Removable MediaWindowsT1210Exploitation of Remote ServicesLinux, WindowsT1534Internal SpearphishingLinux, macOST1550Use Alternate Authentication MaterialContainers, IaaST1550.001Application Access TokenContainers, IaaST1550.002Pass the HashWindowsT1550.003Pass the TicketWindowsT1550.004Web Session CookieIaaS, Office SuiteT1563Remote Service Session HijackingLinux, macOST1563.001SSH HijackingLinux, macOST1563.002RDP HijackingWindowsT1570Lateral Tool TransferESXi, Linux
TA0003

Persistence

113 techniques

T1037Boot or Logon Initialization ScriptsESXi, LinuxT1037.001Logon Script (Windows)WindowsT1037.002Login HookmacOST1037.003Network Logon ScriptWindowsT1037.004RC ScriptsmacOS, LinuxT1037.005Startup ItemsmacOST1053Scheduled Task/JobContainers, ESXiT1053.002AtWindows, LinuxT1053.003CronLinux, macOST1053.005Scheduled TaskWindowsT1053.006Systemd TimersLinuxT1053.007Container Orchestration JobContainersT1078Valid AccountsContainers, ESXiT1078.001Default AccountsContainers, ESXiT1078.002Domain AccountsESXi, LinuxT1078.003Local AccountsContainers, ESXiT1078.004Cloud AccountsIaaS, Identity ProviderT1098Account ManipulationContainers, ESXiT1098.001Additional Cloud CredentialsIaaS, Identity ProviderT1098.002Additional Email Delegate PermissionsWindows, Office SuiteT1098.003Additional Cloud RolesIaaS, Identity ProviderT1098.004SSH Authorized KeysESXi, IaaST1098.005Device RegistrationWindows, Identity ProviderT1098.006Additional Container Cluster RolesContainersT1098.007Additional Local or Domain GroupsWindows, macOST1112Modify RegistryWindowsT1133External Remote ServicesContainers, LinuxT1136Create AccountWindows, IaaST1136.001Local AccountContainers, ESXiT1136.002Domain AccountLinux, macOST1136.003Cloud AccountIaaS, SaaST1137Office Application StartupWindows, Office SuiteT1137.001Office Template MacrosOffice Suite, WindowsT1137.002Office TestWindows, Office SuiteT1137.003Outlook FormsWindows, Office SuiteT1137.004Outlook Home PageWindows, Office SuiteT1137.005Outlook RulesWindows, Office SuiteT1137.006Add-insWindows, Office SuiteT1176Software ExtensionsLinux, macOST1176.001Browser ExtensionsLinux, WindowsT1176.002IDE ExtensionsLinux, macOST1197BITS JobsWindowsT1205Traffic SignalingLinux, macOST1205.001Port KnockingLinux, macOST1205.002Socket FiltersLinux, macOST1505Server Software ComponentWindows, LinuxT1505.001SQL Stored ProceduresWindows, LinuxT1505.002Transport AgentLinux, WindowsT1505.003Web ShellLinux, macOST1505.004IIS ComponentsWindowsT1505.005Terminal Services DLLWindowsT1505.006vSphere Installation BundlesESXiT1525Implant Internal ImageIaaS, ContainersT1542Pre-OS BootLinux, macOST1542.001System FirmwareNetwork Devices, WindowsT1542.002Component FirmwareWindows, LinuxT1542.003BootkitLinux, WindowsT1542.004ROMMONkitNetwork DevicesT1542.005TFTP BootNetwork DevicesT1543Create or Modify System ProcessContainers, LinuxT1543.001Launch AgentmacOST1543.002Systemd ServiceLinuxT1543.003Windows ServiceWindowsT1543.004Launch DaemonmacOST1543.005Container ServiceContainersT1546Event Triggered ExecutionLinux, macOST1546.001Change Default File AssociationWindowsT1546.002ScreensaverWindowsT1546.003Windows Management Instrumentation Event SubscriptionWindowsT1546.004Unix Shell Configuration ModificationLinux, macOST1546.005TrapmacOS, LinuxT1546.006LC_LOAD_DYLIB AdditionmacOST1546.007Netsh Helper DLLWindowsT1546.008Accessibility FeaturesWindowsT1546.009AppCert DLLsWindowsT1546.010AppInit DLLsWindowsT1546.011Application ShimmingWindowsT1546.012Image File Execution Options InjectionWindowsT1546.013PowerShell ProfileWindowsT1546.014EmondmacOST1546.015Component Object Model HijackingWindowsT1546.016Installer PackagesLinux, macOST1546.017Udev RulesLinuxT1546.018Python Startup HooksLinux, macOST1547Boot or Logon Autostart ExecutionLinux, macOST1547.001Registry Run Keys / Startup FolderWindowsT1547.002Authentication PackageWindowsT1547.003Time ProvidersWindowsT1547.004Winlogon Helper DLLWindowsT1547.005Security Support ProviderWindowsT1547.006Kernel Modules and ExtensionsmacOS, LinuxT1547.007Re-opened ApplicationsmacOST1547.008LSASS DriverWindowsT1547.009Shortcut ModificationWindowsT1547.010Port MonitorsWindowsT1547.012Print ProcessorsWindowsT1547.013XDG Autostart EntriesLinuxT1547.014Active SetupWindowsT1547.015Login ItemsmacOST1554Compromise Host Software BinaryESXi, LinuxT1556Modify Authentication ProcessIaaS, Identity ProviderT1556.001Domain Controller AuthenticationWindowsT1556.002Password Filter DLLWindowsT1556.003Pluggable Authentication ModulesLinux, macOST1556.004Network Device AuthenticationNetwork DevicesT1556.005Reversible EncryptionWindowsT1556.006Multi-Factor AuthenticationIaaS, Identity ProviderT1556.007Hybrid IdentityIaaS, Identity ProviderT1556.008Network Provider DLLWindowsT1556.009Conditional Access PoliciesIaaS, Identity ProviderT1653Power SettingsWindows, LinuxT1668Exclusive ControlLinux, macOST1671Cloud Application IntegrationOffice Suite, SaaS
TA0004

Privilege Escalation

96 techniques

T1037Boot or Logon Initialization ScriptsESXi, LinuxT1037.001Logon Script (Windows)WindowsT1037.002Login HookmacOST1037.003Network Logon ScriptWindowsT1037.004RC ScriptsmacOS, LinuxT1037.005Startup ItemsmacOST1053Scheduled Task/JobContainers, ESXiT1053.002AtWindows, LinuxT1053.003CronLinux, macOST1053.005Scheduled TaskWindowsT1053.006Systemd TimersLinuxT1053.007Container Orchestration JobContainersT1055Process InjectionLinux, macOST1055.001Dynamic-link Library InjectionWindowsT1055.002Portable Executable InjectionWindowsT1055.003Thread Execution HijackingWindowsT1055.004Asynchronous Procedure CallWindowsT1055.005Thread Local StorageWindowsT1055.008Ptrace System CallsLinuxT1055.009Proc MemoryLinuxT1055.011Extra Window Memory InjectionWindowsT1055.012Process HollowingWindowsT1055.013Process DoppelgängingWindowsT1055.014VDSO HijackingLinuxT1055.015ListPlantingWindowsT1068Exploitation for Privilege EscalationContainers, LinuxT1078Valid AccountsContainers, ESXiT1078.001Default AccountsContainers, ESXiT1078.002Domain AccountsESXi, LinuxT1078.003Local AccountsContainers, ESXiT1078.004Cloud AccountsIaaS, Identity ProviderT1098Account ManipulationContainers, ESXiT1098.001Additional Cloud CredentialsIaaS, Identity ProviderT1098.002Additional Email Delegate PermissionsWindows, Office SuiteT1098.003Additional Cloud RolesIaaS, Identity ProviderT1098.004SSH Authorized KeysESXi, IaaST1098.005Device RegistrationWindows, Identity ProviderT1098.006Additional Container Cluster RolesContainersT1098.007Additional Local or Domain GroupsWindows, macOST1134Access Token ManipulationWindowsT1134.001Token Impersonation/TheftWindowsT1134.002Create Process with TokenWindowsT1134.003Make and Impersonate TokenWindowsT1134.004Parent PID SpoofingWindowsT1134.005SID-History InjectionWindowsT1484Domain or Tenant Policy ModificationWindows, Identity ProviderT1484.001Group Policy ModificationWindowsT1484.002Trust ModificationIdentity Provider, WindowsT1543Create or Modify System ProcessContainers, LinuxT1543.001Launch AgentmacOST1543.002Systemd ServiceLinuxT1543.003Windows ServiceWindowsT1543.004Launch DaemonmacOST1543.005Container ServiceContainersT1546Event Triggered ExecutionLinux, macOST1546.001Change Default File AssociationWindowsT1546.002ScreensaverWindowsT1546.003Windows Management Instrumentation Event SubscriptionWindowsT1546.004Unix Shell Configuration ModificationLinux, macOST1546.005TrapmacOS, LinuxT1546.006LC_LOAD_DYLIB AdditionmacOST1546.007Netsh Helper DLLWindowsT1546.008Accessibility FeaturesWindowsT1546.009AppCert DLLsWindowsT1546.010AppInit DLLsWindowsT1546.011Application ShimmingWindowsT1546.012Image File Execution Options InjectionWindowsT1546.013PowerShell ProfileWindowsT1546.014EmondmacOST1546.015Component Object Model HijackingWindowsT1546.016Installer PackagesLinux, macOST1546.017Udev RulesLinuxT1546.018Python Startup HooksLinux, macOST1547Boot or Logon Autostart ExecutionLinux, macOST1547.001Registry Run Keys / Startup FolderWindowsT1547.002Authentication PackageWindowsT1547.003Time ProvidersWindowsT1547.004Winlogon Helper DLLWindowsT1547.005Security Support ProviderWindowsT1547.006Kernel Modules and ExtensionsmacOS, LinuxT1547.007Re-opened ApplicationsmacOST1547.008LSASS DriverWindowsT1547.009Shortcut ModificationWindowsT1547.010Port MonitorsWindowsT1547.012Print ProcessorsWindowsT1547.013XDG Autostart EntriesLinuxT1547.014Active SetupWindowsT1547.015Login ItemsmacOST1548Abuse Elevation Control MechanismLinux, macOST1548.001Setuid and SetgidLinux, macOST1548.002Bypass User Account ControlWindowsT1548.003Sudo and Sudo CachingLinux, macOST1548.004Elevated Execution with PromptmacOST1548.005Temporary Elevated Cloud AccessIaaS, Office SuiteT1548.006TCC ManipulationmacOST1611Escape to HostWindows, Linux
TA0043

Reconnaissance

46 techniques

T1589Gather Victim Identity InformationPRET1589.001CredentialsPRET1589.002Email AddressesPRET1589.003Employee NamesPRET1590Gather Victim Network InformationPRET1590.001Domain PropertiesPRET1590.002DNSPRET1590.003Network Trust DependenciesPRET1590.004Network TopologyPRET1590.005IP AddressesPRET1590.006Network Security AppliancesPRET1591Gather Victim Org InformationPRET1591.001Determine Physical LocationsPRET1591.002Business RelationshipsPRET1591.003Identify Business TempoPRET1591.004Identify RolesPRET1592Gather Victim Host InformationPRET1592.001HardwarePRET1592.002SoftwarePRET1592.003FirmwarePRET1592.004Client ConfigurationsPRET1593Search Open Websites/DomainsPRET1593.001Social MediaPRET1593.002Search EnginesPRET1593.003Code RepositoriesPRET1594Search Victim-Owned WebsitesPRET1595Active ScanningPRET1595.001Scanning IP BlocksPRET1595.002Vulnerability ScanningPRET1595.003Wordlist ScanningPRET1596Search Open Technical DatabasesPRET1596.001DNS/Passive DNSPRET1596.002WHOISPRET1596.003Digital CertificatesPRET1596.004CDNsPRET1596.005Scan DatabasesPRET1597Search Closed SourcesPRET1597.001Threat Intel VendorsPRET1597.002Purchase Technical DataPRET1598Phishing for InformationPRET1598.001Spearphishing ServicePRET1598.002Spearphishing AttachmentPRET1598.003Spearphishing LinkPRET1598.004Spearphishing VoicePRET1681Search Threat Vendor DataPRET1682Query Public AI ServicesPRE
TA0042

Resource Development

50 techniques

T1583Acquire InfrastructurePRET1583.001DomainsPRET1583.002DNS ServerPRET1583.003Virtual Private ServerPRET1583.004ServerPRET1583.005BotnetPRET1583.006Web ServicesPRET1583.007ServerlessPRET1583.008MalvertisingPRET1584Compromise InfrastructurePRET1584.001DomainsPRET1584.002DNS ServerPRET1584.003Virtual Private ServerPRET1584.004ServerPRET1584.005BotnetPRET1584.006Web ServicesPRET1584.007ServerlessPRET1584.008Network DevicesPRET1585Establish AccountsPRET1585.001Social Media AccountsPRET1585.002Email AccountsPRET1585.003Cloud AccountsPRET1586Compromise AccountsPRET1586.001Social Media AccountsPRET1586.002Email AccountsPRET1586.003Cloud AccountsPRET1587Develop CapabilitiesPRET1587.001MalwarePRET1587.002Code Signing CertificatesPRET1587.003Digital CertificatesPRET1587.004ExploitsPRET1588Obtain CapabilitiesPRET1588.001MalwarePRET1588.002ToolPRET1588.003Code Signing CertificatesPRET1588.004Digital CertificatesPRET1588.005ExploitsPRET1588.006VulnerabilitiesPRET1588.007Artificial IntelligencePRET1608Stage CapabilitiesPRET1608.001Upload MalwarePRET1608.002Upload ToolPRET1608.003Install Digital CertificatePRET1608.004Drive-by TargetPRET1608.005Link TargetPRET1608.006SEO PoisoningPRET1650Acquire AccessPRET1683Generate ContentPRET1683.001Written ContentPRET1683.002Audio-Visual ContentPRE
TA0005

Stealth

148 techniques

T1006Direct Volume AccessNetwork Devices, WindowsT1014RootkitLinux, macOST1027Obfuscated Files or InformationESXi, LinuxT1027.001Binary PaddingLinux, macOST1027.002Software PackingLinux, macOST1027.003SteganographyLinux, macOST1027.004Compile After DeliveryLinux, macOST1027.005Indicator Removal from ToolsLinux, macOST1027.006HTML SmugglingLinux, macOST1027.007Dynamic API ResolutionWindowsT1027.008Stripped PayloadsLinux, macOST1027.009Embedded PayloadsLinux, macOST1027.010Command ObfuscationLinux, macOST1027.011Fileless StorageLinux, WindowsT1027.012LNK Icon SmugglingWindowsT1027.013Encrypted/Encoded FileLinux, macOST1027.014Polymorphic CodeLinux, macOST1027.015CompressionLinux, macOST1027.016Junk Code InsertionLinux, macOS` tags that enable adversaries to include malicious javascript payloads. however, svgs may appear less suspicious to users than other types of executable files, as they are often treated as image files. svg smuggling can take a number of forms. for example, threat actors may include content that: * assembles malicious payloads(citation: talos svg smuggling 2022) * downloads malicious payloads(citation: cofense svg smuggling 2024) * redirects users to malicious websites(citation: bleeping computer svg smuggling 2024) * displays interactive content to users, such as fake login forms and download buttons.(citation: bleeping computer svg smuggling 2024) svg smuggling may be used in conjunction with [html smuggling](https://attack.mitre.org/techniques/t1027/006) where an svg with a malicious payload is included inside an html file.(citation: talos svg smuggling 2022) svgs may also be included in other types of documents, such as pdfs. " data-astro-cid-k5lx6g3r>T1027.017SVG SmugglingLinux, macOST1027.018Invisible UnicodeLinux, macOST1036MasqueradingContainers, ESXiT1036.001Invalid Code SignaturemacOS, WindowsT1036.002Right-to-Left OverrideLinux, macOST1036.003Rename Legitimate UtilitiesLinux, macOST1036.004Masquerade Task or ServiceLinux, macOST1036.005Match Legitimate Resource Name or LocationContainers, ESXiT1036.006Space after FilenameLinux, macOST1036.007Double File ExtensionWindowsT1036.008Masquerade File TypeLinux, macOST1036.009Break Process TreesLinux, macOST1036.010Masquerade Account NameContainers, IaaST1036.011Overwrite Process ArgumentsLinuxT1036.012Browser FingerprintLinux, macOST1055Process InjectionLinux, macOST1055.001Dynamic-link Library InjectionWindowsT1055.002Portable Executable InjectionWindowsT1055.003Thread Execution HijackingWindowsT1055.004Asynchronous Procedure CallWindowsT1055.005Thread Local StorageWindowsT1055.008Ptrace System CallsLinuxT1055.009Proc MemoryLinuxT1055.011Extra Window Memory InjectionWindowsT1055.012Process HollowingWindowsT1055.013Process DoppelgängingWindowsT1055.014VDSO HijackingLinuxT1055.015ListPlantingWindowsT1070Indicator RemovalContainers, ESXiT1070.003Clear Command HistoryESXi, LinuxT1070.004File DeletionESXi, LinuxT1070.005Network Share Connection RemovalWindowsT1070.006TimestompESXi, LinuxT1070.007Clear Network Connection History and ConfigurationsLinux, macOST1070.008Clear Mailbox DataLinux, macOST1070.009Clear PersistenceESXi, LinuxT1070.010Relocate MalwareLinux, macOST1078Valid AccountsContainers, ESXiT1078.001Default AccountsContainers, ESXiT1078.002Domain AccountsESXi, LinuxT1078.003Local AccountsContainers, ESXiT1078.004Cloud AccountsIaaS, Identity ProviderT1127Trusted Developer Utilities Proxy ExecutionWindowsT1127.001MSBuildWindowsT1127.002ClickOnceWindowsT1127.003JamPlusWindowsT1134Access Token ManipulationWindowsT1134.001Token Impersonation/TheftWindowsT1134.002Create Process with TokenWindowsT1134.003Make and Impersonate TokenWindowsT1134.004Parent PID SpoofingWindowsT1134.005SID-History InjectionWindowsT1140Deobfuscate/Decode Files or InformationESXi, LinuxT1197BITS JobsWindowsT1202Indirect Command ExecutionWindowsT1205Traffic SignalingLinux, macOST1205.001Port KnockingLinux, macOST1205.002Socket FiltersLinux, macOST1211Exploitation for StealthLinux, WindowsT1216System Script Proxy ExecutionWindowsT1216.001PubPrnWindowsT1216.002SyncAppvPublishingServerWindowsT1218System Binary Proxy ExecutionLinux, macOST1218.001Compiled HTML FileWindowsT1218.002Control PanelWindowsT1218.003CMSTPWindowsT1218.004InstallUtilWindowsT1218.005MshtaWindowsT1218.007MsiexecWindowsT1218.008OdbcconfWindowsT1218.009Regsvcs/RegasmWindowsT1218.010Regsvr32WindowsT1218.011Rundll32WindowsT1218.012VerclsidWindowsT1218.013MavinjectWindowsT1218.014MMCWindowsT1218.015Electron ApplicationsLinux, macOST1220XSL Script ProcessingWindowsT1221Template InjectionWindowsT1480Execution GuardrailsESXi, LinuxT1480.001Environmental KeyingLinux, WindowsT1480.002Mutual ExclusionLinux, macOST1497Virtualization/Sandbox EvasionLinux, macOST1497.001System ChecksLinux, macOST1497.002User Activity Based ChecksLinux, macOST1497.003Time Based ChecksLinux, macOST1535Unused/Unsupported Cloud RegionsIaaST1542Pre-OS BootLinux, macOST1542.001System FirmwareNetwork Devices, WindowsT1542.002Component FirmwareWindows, LinuxT1542.003BootkitLinux, WindowsT1542.004ROMMONkitNetwork DevicesT1542.005TFTP BootNetwork DevicesT1564Hide ArtifactsESXi, LinuxT1564.001Hidden Files and DirectoriesLinux, macOST1564.002Hidden UsersLinux, macOST1564.003Hidden WindowLinux, macOST1564.004NTFS File AttributesWindowsT1564.005Hidden File SystemLinux, macOST1564.006Run Virtual InstanceESXi, LinuxT1564.007VBA StompingLinux, macOST1564.008Email Hiding RulesWindows, LinuxT1564.009Resource ForkingmacOST1564.010Process Argument SpoofingWindowsT1564.011Ignore Process InterruptsLinux, macOST1564.012File/Path ExclusionsLinux, macOST1564.013Bind MountsLinuxT1564.014Extended AttributesLinux, macOST1574Hijack Execution FlowLinux, macOST1574.001DLLWindowsT1574.004Dylib HijackingmacOST1574.005Executable Installer File Permissions WeaknessWindowsT1574.006Dynamic Linker HijackingLinux, macOST1574.007Path Interception by PATH Environment VariableLinux, macOST1574.008Path Interception by Search Order HijackingWindowsT1574.009Path Interception by Unquoted PathWindowsT1574.010Services File Permissions WeaknessWindowsT1574.011Services Registry Permissions WeaknessWindowsT1574.012COR_PROFILERWindowsT1574.013KernelCallbackTableWindowsT1574.014AppDomainManagerWindowsT1612Build Image on HostContainersT1620Reflective Code LoadingLinux, macOST1622Debugger EvasionLinux, macOST1678Delay ExecutionLinux, macOST1679Selective ExclusionWindowsT1684Social EngineeringLinux, macOST1684.001ImpersonationLinux, macOST1684.002Email SpoofingLinux, macOS

Exports

Structured JSON, CSV, and Navigator-layer export generation will use the normalized reference records after full sync. The current page is intentionally lightweight and source-backed.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.