LiveActive security incident?Get immediate response
MITRE ATT&CK® Malware

S0030: Carbanak

Carbanak is a full-featured, remote backdoor used by a group of the same name (Carbanak). It is intended for espionage, data exfiltration, and providing remote access to infected machines. [1] [2]

EnterpriseS0030MalwareObject v1.1Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceHigh

Carbanak matters because ATT&CK describes it as a full-featured Windows remote backdoor intended for espionage, data exfiltration, and remote access. For leaders, the decision value is not just “malware exists”; it is whether the organization can prove it would notice and contain a Windows compromise that combines credential theft, persistence, command execution, remote access, collection, encrypted or encoded web-based command-and-control, and staged exfiltration behavior.

Executive priority

Prioritize Carbanak as a resilience and fraud-risk scenario, especially where Windows endpoints support financial, retail, hospitality, healthcare, cloud services, transportation, utilities, or other high-value operations referenced in the related FIN7 context. Executives should ask whether SOC, identity, endpoint, and network teams can show evidence for: credential-dumping detection, abnormal RDP and remote access use, suspicious startup persistence, local account creation, collection of screenshots or local email data, and web-protocol C2/exfiltration patterns. Because ATT&CK provides no official detection text for this object, coverage should be validated through control evidence and incident-response exercises rather than assumed from malware-name signatures.

Technical view

Treat Carbanak as a Windows backdoor behavior cluster mapped through its ATT&CK relationships. Validate detections and response playbooks around OS Credential Dumping, Query Registry, RDP use, obfuscated files, data transfer size limits, PE injection, keylogging, process discovery, Windows command shell execution, file deletion, web-protocol C2, screen capture, local email collection, standard encoding, local account creation, remote access tools, Registry Run Keys/Startup Folder persistence, and symmetric cryptography. Detection engineering should correlate endpoint process, registry, account, authentication, and network evidence rather than rely on a single indicator or family name.

Likely telemetry

  • Windows endpoint process creation and command-line telemetry
  • Windows Registry change and query telemetry, especially Run Keys and startup locations
  • Authentication and RDP session logs
  • Local account creation and privilege-related account activity
  • Endpoint alerts or behavioral evidence for credential dumping, keylogging, process injection, screen capture, and file deletion

Detection direction

  • Because MITRE provides no official detection guidance for Carbanak, validate coverage against the related ATT&CK techniques rather than a named-malware signature alone.
  • Tune correlations for Windows sequences such as registry persistence followed by command shell execution, process discovery, credential access behavior, RDP or remote access activity, collection activity, and outbound web-protocol traffic.
  • Review false positives carefully for administrator activity, help desk tools, legitimate RDP, endpoint management software, backup jobs, and normal email-client access.
  • Look for blind spots in unmanaged Windows endpoints, limited command-line logging, missing registry telemetry, weak RDP logging, encrypted web traffic visibility gaps, and lack of endpoint visibility into injection or credential access behaviors.
  • Use the group relationships as threat-intelligence context: ATT&CK links this malware to Carbanak group and FIN7 use, but local detection should be behavior-led and evidence-based.

Mitigation priorities

  • First, ensure Windows endpoint visibility and retention are sufficient for process, registry, authentication, account, file, and network investigations.
  • Harden identity controls around credential theft and lateral movement: reduce local admin exposure, monitor account creation, and review RDP access paths.
  • Constrain persistence and execution opportunities by monitoring startup locations, limiting unnecessary command shell and remote access use where feasible, and maintaining application/control baselines.
  • Inventory and govern legitimate remote access tools so attacker use of approved tooling is distinguishable from authorized support activity.
  • Improve egress monitoring for web-protocol C2 and staged exfiltration patterns, including size-limited transfers where practical.
Additional notes and limits

ATT&CK identifies Carbanak as malware S0030, a Windows remote backdoor associated through relationships with the Carbanak group and FIN7. The relationship set is useful for building a defensive validation plan because it maps the malware to credential access, discovery, execution, persistence, collection, command-and-control, exfiltration, lateral movement, and stealth techniques. This take intentionally avoids asserting current activity or guaranteed exposure.

The supplied ATT&CK object does not include official detection text, tactics on the malware object itself, aliases, labels, or detailed procedure examples in the prompt. Several related techniques list platforms beyond Windows, but the malware object platform is Windows, so defensive conclusions should be centered on Windows unless local intelligence supports broader scope. Local telemetry, asset criticality, and business process context are required to determine priority and coverage.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

Carbanak

Carbanak is a full-featured, remote backdoor used by a group of the same name (Carbanak). It is intended for espionage, data exfiltration, and providing remote access to infected machines. [1] [2]

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

18 rows
DomainIDNameRelationship / procedure
EnterpriseT1003OS Credential Dumping

Carbanak obtains Windows logon password details.[2]

EnterpriseT1113Screen Capture

Carbanak performs desktop video recording and captures screenshots of the desktop and sends it to the C2 server.[2]

EnterpriseT1071.001Web ProtocolsSub-technique

The Carbanak malware communicates to its command server using HTTP with an encrypted payload.[1]

EnterpriseT1012Query Registry

Carbanak checks the Registry key HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings for proxy configurations information.[2]

EnterpriseT1021.001Remote Desktop ProtocolSub-technique

Carbanak enables concurrent Remote Desktop Protocol (RDP) sessions.[2]

EnterpriseT1059.003Windows Command ShellSub-technique

Carbanak has a command to create a reverse shell.[2]

EnterpriseT1055.002Portable Executable InjectionSub-technique

Carbanak downloads an executable and injects it directly into a new process.[2]

EnterpriseT1114.001Local Email CollectionSub-technique

Carbanak searches recursively for Outlook personal storage tables (PST) files within user directories and sends them back to the C2 server.[2]

EnterpriseT1057Process Discovery

Carbanak lists running processes.[2]

EnterpriseT1027Obfuscated Files or Information

Carbanak encrypts strings to make analysis more difficult.[2]

EnterpriseT1219Remote Access Tools

Carbanak has a plugin for VNC and Ammyy Admin Tool.[2]

EnterpriseT1056.001KeyloggingSub-technique

Carbanak logs key strokes for configured processes and sends them back to the C2 server.[1][2]

EnterpriseT1547.001Registry Run Keys / Startup FolderSub-technique

Carbanak stores a configuration files in the startup directory to automatically execute commands in order to persist across reboots.[2]

EnterpriseT1136.001Local AccountSub-technique

Carbanak can create a Windows account.[2]

EnterpriseT1573.001Symmetric CryptographySub-technique

Carbanak encrypts the message body of HTTP traffic with RC2 (in CBC mode). Carbanak also uses XOR with random keys for its communications.[1][2]

EnterpriseT1070.004File DeletionSub-technique

Carbanak has a command to delete files.[2]

EnterpriseT1132.001Standard EncodingSub-technique

Carbanak encodes the message body of HTTP traffic with Base64.[1][2]

EnterpriseT1030Data Transfer Size Limits

Carbanak exfiltrates data in compressed chunks if a message is larger than 4096 bytes .[2]

Associated objects

Groups, software, and campaigns

GroupEnterprise

G0046: FIN7

FIN7 is a financially-motivated threat group that has been active since 2013. FIN7 has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media, food and beverage, transportation, pharmaceutical, and utilities industries in the United States. A portion of FIN7 was operated out of a front company called Combi Security and often used point-of-sale malware for targeting efforts. Since 2020, FIN7 shifted operations to big game hunting (BGH), including use of REvil ransomware and their own Ransomware-as-a-Service (RaaS), Darkside. FIN7 may be linked to the Carbanak Group, but multiple threat groups have been observed using Carbanak, leading these groups to be tracked separately.[1][2][3][4][5][6][7]

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.1
Created
Modified
Raw hash
569f46b1c2424ef2...
Imported snapshots across ATT&CK releases(1)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.11.1Current bundle569f46b1c242…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    Kaspersky Carbanak

    Kaspersky Lab's Global Research and Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved August 23, 2018.

    Open source URL
  2. [2]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  3. [3]
    FireEye FIN7 March 2017

    Miller, S., et al. (2017, March 7). FIN7 Spear Phishing Campaign Targets Personnel Involved in SEC Filings. Retrieved March 8, 2017.

    Open source URL
  4. [4]
    FireEye FIN7 Aug 2018

    Carr, N., et al. (2018, August 01). On the Hunt for FIN7: Pursuing an Enigmatic and Evasive Global Criminal Operation. Retrieved August 23, 2018.

    Open source URL
  5. [5]
    DOJ FIN7 Aug 2018

    Department of Justice. (2018, August 01). HOW FIN7 ATTACKED AND STOLE DATA. Retrieved August 24, 2018.

    Open source URL
  6. [6]
    IBM Ransomware Trends September 2020

    Singleton, C. and Kiefer, C. (2020, September 28). Ransomware 2020: Attack Trends Affecting Organizations Worldwide. Retrieved September 20, 2021.

    Open source URL
  7. [7]
    CrowdStrike Carbon Spider August 2021

    Loui, E. and Reynolds, J. (2021, August 30). CARBON SPIDER Embraces Big Game Hunting, Part 1. Retrieved September 20, 2021.

    Open source URL
  8. [8]
    FBI Flash FIN7 USB

    The Record. (2022, January 7). FBI: FIN7 hackers target US companies with BadUSB devices to install ransomware. Retrieved January 14, 2022.

    Open source URL
  9. [9]
    Mandiant FIN7 Apr 2022

    Abdo, B., et al. (2022, April 4). FIN7 Power Hour: Adversary Archaeology and the Evolution of FIN7. Retrieved April 5, 2022.

    Open source URL
  10. [10]
    BlackBerry_FIN7_April2024

    The BlackBerry Research and Intelligence Team. (2024, April 17). Threat Group FIN7 Targets the U.S. Automotive Industry. Retrieved May 1, 2025.

    Open source URL
  11. [11]
    Anunak

    (Citation: Fox-It Anunak Feb 2015) (Citation: FireEye CARBANAK June 2017)

  12. [12]
    Anunak

    (Citation: Fox-It Anunak Feb 2015) (Citation: FireEye CARBANAK June 2017)

  13. [13]
    Anunak

    (Citation: Fox-It Anunak Feb 2015) (Citation: FireEye CARBANAK June 2017)

  14. [14]
    Carbanak

    (Citation: FireEye CARBANAK June 2017)

  15. [15]
    Carbanak

    (Citation: FireEye CARBANAK June 2017)

  16. [16]
    Carbanak

    (Citation: FireEye CARBANAK June 2017)

  17. [17]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  18. [18]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  19. [19]
    Fox-It Anunak Feb 2015

    Prins, R. (2015, February 16). Anunak (aka Carbanak) Update. Retrieved January 20, 2017.

    Open source URL
  20. [20]
    Fox-It Anunak Feb 2015

    Prins, R. (2015, February 16). Anunak (aka Carbanak) Update. Retrieved January 20, 2017.

    Open source URL
  21. [21]
    Fox-It Anunak Feb 2015

    Prins, R. (2015, February 16). Anunak (aka Carbanak) Update. Retrieved January 20, 2017.

    Open source URL
  22. [22]
    Kaspersky Carbanak

    Kaspersky Lab's Global Research and Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved August 23, 2018.

    Open source URL
  23. [23]
    Kaspersky Carbanak

    Kaspersky Lab's Global Research and Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved August 23, 2018.

    Open source URL
  24. [24]
    mitre-attackS0030
    Open source URL
  25. [25]
    mitre-attackS0030
    Open source URL
  26. [26]
    mitre-attackS0030
    Open source URL
  27. [27]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  28. [28]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  29. [29]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  30. [30]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  31. [31]
    Kaspersky Carbanak

    Kaspersky Lab's Global Research and Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved August 23, 2018.

    Open source URL
  32. [32]
    Kaspersky Carbanak

    Kaspersky Lab's Global Research and Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved August 23, 2018.

    Open source URL
  33. [33]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  34. [34]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  35. [35]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  36. [36]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  37. [37]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  38. [38]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  39. [39]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  40. [40]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  41. [41]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  42. [42]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  43. [43]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  44. [44]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  45. [45]
    BlackBerry_FIN7_April2024

    The BlackBerry Research and Intelligence Team. (2024, April 17). Threat Group FIN7 Targets the U.S. Automotive Industry. Retrieved May 1, 2025.

    Open source URL
  46. [46]
    CrowdStrike Carbon Spider August 2021

    Loui, E. and Reynolds, J. (2021, August 30). CARBON SPIDER Embraces Big Game Hunting, Part 1. Retrieved September 20, 2021.

    Open source URL
  47. [47]
    DOJ FIN7 Aug 2018

    Department of Justice. (2018, August 01). HOW FIN7 ATTACKED AND STOLE DATA. Retrieved August 24, 2018.

    Open source URL
  48. [48]
    FBI Flash FIN7 USB

    The Record. (2022, January 7). FBI: FIN7 hackers target US companies with BadUSB devices to install ransomware. Retrieved January 14, 2022.

    Open source URL
  49. [49]
    FireEye FIN7 Aug 2018

    Carr, N., et al. (2018, August 01). On the Hunt for FIN7: Pursuing an Enigmatic and Evasive Global Criminal Operation. Retrieved August 23, 2018.

    Open source URL
  50. [50]
    FireEye FIN7 March 2017

    Miller, S., et al. (2017, March 7). FIN7 Spear Phishing Campaign Targets Personnel Involved in SEC Filings. Retrieved March 8, 2017.

    Open source URL
  51. [51]
    IBM Ransomware Trends September 2020

    Singleton, C. and Kiefer, C. (2020, September 28). Ransomware 2020: Attack Trends Affecting Organizations Worldwide. Retrieved September 20, 2021.

    Open source URL
  52. [52]
    Mandiant FIN7 Apr 2022

    Abdo, B., et al. (2022, April 4). FIN7 Power Hour: Adversary Archaeology and the Evolution of FIN7. Retrieved April 5, 2022.

    Open source URL
  53. [53]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  54. [54]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  55. [55]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  56. [56]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  57. [57]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  58. [58]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  59. [59]
    Kaspersky Carbanak

    Kaspersky Lab's Global Research and Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved August 23, 2018.

    Open source URL
  60. [60]
    Kaspersky Carbanak

    Kaspersky Lab's Global Research and Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved August 23, 2018.

    Open source URL
  61. [61]
    Kaspersky Carbanak

    Kaspersky Lab's Global Research and Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved August 23, 2018.

    Open source URL
  62. [62]
    Kaspersky Carbanak

    Kaspersky Lab's Global Research and Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved August 23, 2018.

    Open source URL
  63. [63]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  64. [64]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  65. [65]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  66. [66]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  67. [67]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  68. [68]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  69. [69]
    Kaspersky Carbanak

    Kaspersky Lab's Global Research and Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved August 23, 2018.

    Open source URL
  70. [70]
    Kaspersky Carbanak

    Kaspersky Lab's Global Research and Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved August 23, 2018.

    Open source URL
  71. [71]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  72. [72]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  73. [73]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  74. [74]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
  75. [75]
    Kaspersky Carbanak

    Kaspersky Lab's Global Research and Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved August 23, 2018.

    Open source URL
  76. [76]
    Kaspersky Carbanak

    Kaspersky Lab's Global Research and Analysis Team. (2015, February). CARBANAK APT THE GREAT BANK ROBBERY. Retrieved August 23, 2018.

    Open source URL
  77. [77]
    FireEye CARBANAK June 2017

    Bennett, J., Vengerik, B. (2017, June 12). Behind the CARBANAK Backdoor. Retrieved June 11, 2018.

    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.