mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
58 KiB
58 KiB
| 1 | mitre_id | technique | tactics | groups |
|---|---|---|---|---|
| 2 | T1647 | Plist File Modification | Defense Evasion | no |
| 3 | T1622 | Debugger Evasion | Defense Evasion|Discovery | no |
| 4 | T1621 | Multi-Factor Authentication Request Generation | Credential Access | APT29 |
| 5 | T1505.005 | Terminal Services DLL | Persistence | no |
| 6 | T1557.003 | DHCP Spoofing | Credential Access|Collection | no |
| 7 | T1595.003 | Wordlist Scanning | Reconnaissance | Volatile Cedar |
| 8 | T1098.005 | Device Registration | Persistence | APT29 |
| 9 | T1574.013 | KernelCallbackTable | Persistence|Privilege Escalation|Defense Evasion | Lazarus Group |
| 10 | T1556.005 | Reversible Encryption | Credential Access|Defense Evasion|Persistence | no |
| 11 | T1055.015 | ListPlanting | Defense Evasion|Privilege Escalation | no |
| 12 | T1564.010 | Process Argument Spoofing | Defense Evasion | no |
| 13 | T1564.009 | Resource Forking | Defense Evasion | no |
| 14 | T1559.003 | XPC Services | Execution | no |
| 15 | T1562.010 | Downgrade Attack | Defense Evasion | no |
| 16 | T1547.015 | Login Items | Persistence|Privilege Escalation | no |
| 17 | T1620 | Reflective Code Loading | Defense Evasion | Lazarus Group |
| 18 | T1619 | Cloud Storage Object Discovery | Discovery | no |
| 19 | T1218.014 | MMC | Defense Evasion | no |
| 20 | T1218.013 | Mavinject | Defense Evasion | no |
| 21 | T1614.001 | System Language Discovery | Discovery | Ke3chang|Lazarus Group |
| 22 | T1615 | Group Policy Discovery | Discovery | Turla |
| 23 | T1036.007 | Double File Extension | Defense Evasion | Mustang Panda |
| 24 | T1562.009 | Safe Mode Boot | Defense Evasion | no |
| 25 | T1564.008 | Email Hiding Rules | Defense Evasion | FIN4 |
| 26 | T1505.004 | IIS Components | Persistence | no |
| 27 | T1027.006 | HTML Smuggling | Defense Evasion | APT29 |
| 28 | T1213.003 | Code Repositories | Collection | APT29 |
| 29 | T1553.006 | Code Signing Policy Modification | Defense Evasion | Turla|APT39 |
| 30 | T1614 | System Location Discovery | Discovery | no |
| 31 | T1613 | Container and Resource Discovery | Discovery | TeamTNT |
| 32 | T1552.007 | Container API | Credential Access | no |
| 33 | T1612 | Build Image on Host | Defense Evasion | no |
| 34 | T1611 | Escape to Host | Privilege Escalation | TeamTNT |
| 35 | T1204.003 | Malicious Image | Execution | TeamTNT |
| 36 | T1053.007 | Container Orchestration Job | Execution|Persistence|Privilege Escalation | no |
| 37 | T1610 | Deploy Container | Defense Evasion|Execution | TeamTNT |
| 38 | T1609 | Container Administration Command | Execution | TeamTNT |
| 39 | T1608.005 | Link Target | Resource Development | Silent Librarian |
| 40 | T1608.004 | Drive-by Target | Resource Development | Dragonfly|Transparent Tribe|APT32|Threat Group-3390 |
| 41 | T1608.003 | Install Digital Certificate | Resource Development | no |
| 42 | T1608.002 | Upload Tool | Resource Development | Lazarus Group|Threat Group-3390 |
| 43 | T1608.001 | Upload Malware | Resource Development | Threat Group-3390|LazyScripter|Mustang Panda|Gamaredon Group|Kimsuky|Lazarus Group|TeamTNT|APT32 |
| 44 | T1608 | Stage Capabilities | Resource Development | Mustang Panda |
| 45 | T1016.001 | Internet Connection Discovery | Discovery | Gamaredon Group|APT29|Turla |
| 46 | T1553.005 | Mark-of-the-Web Bypass | Defense Evasion | APT29|TA505 |
| 47 | T1555.005 | Password Managers | Credential Access | Threat Group-3390|Fox Kitten|Operation Wocao |
| 48 | T1484.002 | Domain Trust Modification | Defense Evasion|Privilege Escalation | APT29 |
| 49 | T1484.001 | Group Policy Modification | Defense Evasion|Privilege Escalation | Indrik Spider |
| 50 | T1547.014 | Active Setup | Persistence|Privilege Escalation | no |
| 51 | T1606.002 | SAML Tokens | Credential Access | APT29 |
| 52 | T1606.001 | Web Cookies | Credential Access | APT29 |
| 53 | T1606 | Forge Web Credentials | Credential Access | no |
| 54 | T1555.004 | Windows Credential Manager | Credential Access | Stealth Falcon|OilRig|Turla |
| 55 | T1059.008 | Network Device CLI | Execution | no |
| 56 | T1602.002 | Network Device Configuration Dump | Collection | no |
| 57 | T1542.005 | TFTP Boot | Defense Evasion|Persistence | no |
| 58 | T1542.004 | ROMMONkit | Defense Evasion|Persistence | no |
| 59 | T1602.001 | SNMP (MIB Dump) | Collection | no |
| 60 | T1602 | Data from Configuration Repository | Collection | no |
| 61 | T1601.002 | Downgrade System Image | Defense Evasion | no |
| 62 | T1601.001 | Patch System Image | Defense Evasion | no |
| 63 | T1601 | Modify System Image | Defense Evasion | no |
| 64 | T1600.002 | Disable Crypto Hardware | Defense Evasion | no |
| 65 | T1600.001 | Reduce Key Space | Defense Evasion | no |
| 66 | T1600 | Weaken Encryption | Defense Evasion | no |
| 67 | T1556.004 | Network Device Authentication | Credential Access|Defense Evasion|Persistence | no |
| 68 | T1599.001 | Network Address Translation Traversal | Defense Evasion | no |
| 69 | T1599 | Network Boundary Bridging | Defense Evasion | no |
| 70 | T1020.001 | Traffic Duplication | Exfiltration | no |
| 71 | T1557.002 | ARP Cache Poisoning | Credential Access|Collection | Cleaver |
| 72 | T1588.006 | Vulnerabilities | Resource Development | Sandworm Team |
| 73 | T1053.006 | Systemd Timers | Execution|Persistence|Privilege Escalation | no |
| 74 | T1562.008 | Disable Cloud Logs | Defense Evasion | no |
| 75 | T1547.012 | Print Processors | Persistence|Privilege Escalation | no |
| 76 | T1598.003 | Spearphishing Link | Reconnaissance | APT28|Dragonfly|Magic Hound|Silent Librarian|Sidewinder|Sandworm Team|APT32|Kimsuky |
| 77 | T1598.002 | Spearphishing Attachment | Reconnaissance | Dragonfly|Sidewinder |
| 78 | T1598.001 | Spearphishing Service | Reconnaissance | no |
| 79 | T1598 | Phishing for Information | Reconnaissance | ZIRCONIUM|APT28 |
| 80 | T1597.002 | Purchase Technical Data | Reconnaissance | no |
| 81 | T1597.001 | Threat Intel Vendors | Reconnaissance | no |
| 82 | T1597 | Search Closed Sources | Reconnaissance | no |
| 83 | T1596.005 | Scan Databases | Reconnaissance | no |
| 84 | T1596.004 | CDNs | Reconnaissance | no |
| 85 | T1596.003 | Digital Certificates | Reconnaissance | no |
| 86 | T1596.001 | DNS/Passive DNS | Reconnaissance | no |
| 87 | T1596.002 | WHOIS | Reconnaissance | no |
| 88 | T1596 | Search Open Technical Databases | Reconnaissance | no |
| 89 | T1595.002 | Vulnerability Scanning | Reconnaissance | Magic Hound|Aquatic Panda|Dragonfly|TeamTNT|APT29|Volatile Cedar|APT28|Sandworm Team |
| 90 | T1595.001 | Scanning IP Blocks | Reconnaissance | TeamTNT |
| 91 | T1595 | Active Scanning | Reconnaissance | no |
| 92 | T1594 | Search Victim-Owned Websites | Reconnaissance | Kimsuky|Silent Librarian|Sandworm Team |
| 93 | T1593.002 | Search Engines | Reconnaissance | Kimsuky |
| 94 | T1593.001 | Social Media | Reconnaissance | Lazarus Group|Kimsuky |
| 95 | T1593 | Search Open Websites/Domains | Reconnaissance | Sandworm Team |
| 96 | T1592.004 | Client Configurations | Reconnaissance | HAFNIUM |
| 97 | T1592.003 | Firmware | Reconnaissance | no |
| 98 | T1592.002 | Software | Reconnaissance | Andariel|Sandworm Team |
| 99 | T1592.001 | Hardware | Reconnaissance | no |
| 100 | T1592 | Gather Victim Host Information | Reconnaissance | no |
| 101 | T1591.004 | Identify Roles | Reconnaissance | Lazarus Group |
| 102 | T1591.003 | Identify Business Tempo | Reconnaissance | no |
| 103 | T1591.001 | Determine Physical Locations | Reconnaissance | no |
| 104 | T1591.002 | Business Relationships | Reconnaissance | Dragonfly|Sandworm Team |
| 105 | T1591 | Gather Victim Org Information | Reconnaissance | Kimsuky|Lazarus Group |
| 106 | T1590.006 | Network Security Appliances | Reconnaissance | no |
| 107 | T1590.005 | IP Addresses | Reconnaissance | Andariel|HAFNIUM |
| 108 | T1590.004 | Network Topology | Reconnaissance | no |
| 109 | T1590.003 | Network Trust Dependencies | Reconnaissance | no |
| 110 | T1590.002 | DNS | Reconnaissance | no |
| 111 | T1590.001 | Domain Properties | Reconnaissance | Sandworm Team |
| 112 | T1590 | Gather Victim Network Information | Reconnaissance | HAFNIUM |
| 113 | T1589.003 | Employee Names | Reconnaissance | Kimsuky|Silent Librarian|Sandworm Team |
| 114 | T1589.002 | Email Addresses | Reconnaissance | Lazarus Group|Kimsuky|Magic Hound|TA551|MuddyWater|HAFNIUM|APT32|Silent Librarian|Sandworm Team |
| 115 | T1589.001 | Credentials | Reconnaissance | APT29|Leviathan|APT28|Magic Hound|Chimera |
| 116 | T1589 | Gather Victim Identity Information | Reconnaissance | Magic Hound|APT32 |
| 117 | T1588.005 | Exploits | Resource Development | Kimsuky |
| 118 | T1588.004 | Digital Certificates | Resource Development | BlackTech|Lazarus Group|Silent Librarian |
| 119 | T1588.003 | Code Signing Certificates | Resource Development | BlackTech|Lazarus Group|Wizard Spider |
| 120 | T1588.002 | Tool | Resource Development | Aquatic Panda|BlackTech|Lazarus Group|CostaRicto|Night Dragon|DarkVishnya|FIN5|Gorgon Group|Patchwork|Chimera|Dragonfly|Blue Mockingbird|Whitefly|APT41|FIN6|TEMP.Veles|Kimsuky|PittyTiger|Cobalt Group|APT29|Thrip|Ke3chang|DarkHydrus|APT32|APT38|BRONZE BUTLER|Carbanak|Cleaver|Inception|Leafminer|Threat Group-3390|Ferocious Kitten|IndigoZebra|BackdoorDiplomacy|menuPass|APT-C-36|Magic Hound|APT28|Wizard Spider|Frankenstein|Silence|WIRTE|Turla|APT33|APT19|FIN10|CopyKittens|APT39|APT1|MuddyWater|Silent Librarian|GALLIUM|Sandworm Team |
| 121 | T1588.001 | Malware | Resource Development | Aquatic Panda|LazyScripter|Andariel|BackdoorDiplomacy|Turla|APT1 |
| 122 | T1588 | Obtain Capabilities | Resource Development | no |
| 123 | T1587.004 | Exploits | Resource Development | no |
| 124 | T1587.003 | Digital Certificates | Resource Development | APT29|PROMETHIUM |
| 125 | T1587.002 | Code Signing Certificates | Resource Development | PROMETHIUM|Patchwork |
| 126 | T1587.001 | Malware | Resource Development | Ke3chang|Kimsuky|TeamTNT|APT29|Lazarus Group|Sandworm Team|Turla|FIN7|Night Dragon|Cleaver |
| 127 | T1587 | Develop Capabilities | Resource Development | Kimsuky |
| 128 | T1586.002 | Email Accounts | Resource Development | APT29|APT28|IndigoZebra|Leviathan|Magic Hound|Kimsuky |
| 129 | T1586.001 | Social Media Accounts | Resource Development | Leviathan |
| 130 | T1586 | Compromise Accounts | Resource Development | no |
| 131 | T1585.002 | Email Accounts | Resource Development | Mustang Panda|Kimsuky|Lazarus Group|Leviathan|Magic Hound|Silent Librarian|Sandworm Team|APT1 |
| 132 | T1585.001 | Social Media Accounts | Resource Development | Kimsuky|Lazarus Group|Leviathan|Magic Hound|Fox Kitten|Sandworm Team|APT32|Cleaver |
| 133 | T1585 | Establish Accounts | Resource Development | Fox Kitten|APT17 |
| 134 | T1584.006 | Web Services | Resource Development | Turla |
| 135 | T1584.005 | Botnet | Resource Development | Sandworm Team|Axiom |
| 136 | T1584.004 | Server | Resource Development | Lazarus Group|Dragonfly|Indrik Spider|Turla|APT16 |
| 137 | T1584.003 | Virtual Private Server | Resource Development | Turla |
| 138 | T1584.002 | DNS Server | Resource Development | no |
| 139 | T1584.001 | Domains | Resource Development | Kimsuky|Lazarus Group|Transparent Tribe|Magic Hound|APT29|APT1 |
| 140 | T1583.006 | Web Services | Resource Development | APT28|Confucius|LazyScripter|Kimsuky|Magic Hound|IndigoZebra|ZIRCONIUM|MuddyWater|HAFNIUM|Lazarus Group|Turla|APT32|APT17|APT29 |
| 141 | T1583.005 | Botnet | Resource Development | no |
| 142 | T1583.004 | Server | Resource Development | Kimsuky|Lazarus Group|Gelsemium|GALLIUM|Sandworm Team |
| 143 | T1583.003 | Virtual Private Server | Resource Development | Axiom|Dragonfly|HAFNIUM|TEMP.Veles |
| 144 | T1583.002 | DNS Server | Resource Development | Axiom |
| 145 | T1584 | Compromise Infrastructure | Resource Development | no |
| 146 | T1583.001 | Domains | Resource Development | LazyScripter|Gamaredon Group|Winnti Group|Dragonfly|IndigoZebra|TeamTNT|Ferocious Kitten|FIN7|Transparent Tribe|Leviathan|Magic Hound|APT29|Mustang Panda|ZIRCONIUM|Lazarus Group|Silent Librarian|menuPass|Sandworm Team|APT32|Kimsuky|APT1|APT28 |
| 147 | T1583 | Acquire Infrastructure | Resource Development | no |
| 148 | T1564.007 | VBA Stomping | Defense Evasion | no |
| 149 | T1558.004 | AS-REP Roasting | Credential Access | no |
| 150 | T1580 | Cloud Infrastructure Discovery | Discovery | no |
| 151 | T1218.012 | Verclsid | Defense Evasion | no |
| 152 | T1205.001 | Port Knocking | Defense Evasion|Persistence|Command And Control | PROMETHIUM |
| 153 | T1564.006 | Run Virtual Instance | Defense Evasion | no |
| 154 | T1564.005 | Hidden File System | Defense Evasion | Strider|Equation |
| 155 | T1556.003 | Pluggable Authentication Modules | Credential Access|Defense Evasion|Persistence | no |
| 156 | T1574.012 | COR_PROFILER | Persistence|Privilege Escalation|Defense Evasion | Blue Mockingbird |
| 157 | T1562.007 | Disable or Modify Cloud Firewall | Defense Evasion | no |
| 158 | T1098.004 | SSH Authorized Keys | Persistence | TeamTNT |
| 159 | T1480.001 | Environmental Keying | Defense Evasion | APT41|Equation |
| 160 | T1059.007 | JavaScript | Execution | LazyScripter|Indrik Spider|MuddyWater|Turla|Higaisa|Sidewinder|Evilnum|Kimsuky|FIN6|APT32|FIN7|Cobalt Group|Molerats|TA505|Silence|Leafminer |
| 161 | T1578.004 | Revert Cloud Instance | Defense Evasion | no |
| 162 | T1578.003 | Delete Cloud Instance | Defense Evasion | no |
| 163 | T1578.001 | Create Snapshot | Defense Evasion | no |
| 164 | T1578.002 | Create Cloud Instance | Defense Evasion | no |
| 165 | T1127.001 | MSBuild | Defense Evasion | Frankenstein |
| 166 | T1027.005 | Indicator Removal from Tools | Defense Evasion | Operation Wocao|GALLIUM|TEMP.Veles|Patchwork|APT3|Turla|OilRig|Deep Panda |
| 167 | T1562.006 | Indicator Blocking | Defense Evasion | no |
| 168 | T1573.002 | Asymmetric Cryptography | Command And Control | Operation Wocao|Tropic Trooper|Cobalt Group|OilRig|FIN8|FIN6 |
| 169 | T1573.001 | Symmetric Cryptography | Command And Control | Mustang Panda|Darkhotel|ZIRCONIUM|Higaisa|Frankenstein|Inception|APT28|APT33|BRONZE BUTLER|Stealth Falcon|Lazarus Group |
| 170 | T1573 | Encrypted Channel | Command And Control | APT29|Tropic Trooper |
| 171 | T1027.004 | Compile After Delivery | Defense Evasion | Gamaredon Group|Rocke|MuddyWater |
| 172 | T1574.004 | Dylib Hijacking | Persistence|Privilege Escalation|Defense Evasion | no |
| 173 | T1546.015 | Component Object Model Hijacking | Privilege Escalation|Persistence | APT28 |
| 174 | T1071.004 | DNS | Command And Control | LazyScripter|Chimera|APT39|Tropic Trooper|OilRig|Ke3chang|Cobalt Group|APT18|APT41|FIN7 |
| 175 | T1071.003 | Mail Protocols | Command And Control | Turla|Kimsuky|APT32|SilverTerrier|APT28 |
| 176 | T1071.002 | File Transfer Protocols | Command And Control | Kimsuky|APT41|SilverTerrier|Honeybee |
| 177 | T1071.001 | Web Protocols | Command And Control | Kimsuky|Confucius|TeamTNT|FIN8|APT29|Mustang Panda|Windshift|TA551|Higaisa|HAFNIUM|Sidewinder|Chimera|Sandworm Team|TA505|Rocke|APT39|Tropic Trooper|MuddyWater|Wizard Spider|Inception|APT41|SilverTerrier|APT28|WIRTE|APT33|FIN4|Night Dragon|APT18|APT38|Rancor|Ke3chang|Orangeworm|APT37|APT19|Cobalt Group|Threat Group-3390|Dark Caracal|Turla|Lazarus Group|BRONZE BUTLER|Magic Hound|APT32|OilRig|Gamaredon Group|Stealth Falcon |
| 178 | T1572 | Protocol Tunneling | Command And Control | Leviathan|CostaRicto|Chimera|Fox Kitten|OilRig|Cobalt Group|FIN6 |
| 179 | T1048.003 | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | Exfiltration | Wizard Spider|FIN6|APT32|APT33|Thrip|FIN8|OilRig|Lazarus Group |
| 180 | T1048.002 | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol | Exfiltration | APT28|APT29 |
| 181 | T1048.001 | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Exfiltration | no |
| 182 | T1001.003 | Protocol Impersonation | Command And Control | Higaisa|Lazarus Group |
| 183 | T1001.002 | Steganography | Command And Control | APT29|Axiom |
| 184 | T1001.001 | Junk Data | Command And Control | APT28 |
| 185 | T1132.002 | Non-Standard Encoding | Command And Control | no |
| 186 | T1132.001 | Standard Encoding | Command And Control | HAFNIUM|TA551|Sandworm Team|Tropic Trooper|MuddyWater|APT33|APT19|Lazarus Group|BRONZE BUTLER|Patchwork |
| 187 | T1090.004 | Domain Fronting | Command And Control | APT29 |
| 188 | T1090.003 | Multi-hop Proxy | Command And Control | Leviathan|CostaRicto|APT28|Operation Wocao|Inception|FIN4|APT29 |
| 189 | T1090.002 | External Proxy | Command And Control | Tonto Team|APT39|Silence|GALLIUM|MuddyWater|APT3|FIN5|Lazarus Group|menuPass|APT28 |
| 190 | T1090.001 | Internal Proxy | Command And Control | Lazarus Group|Turla|APT29|Higaisa|Operation Wocao|APT39|Strider |
| 191 | T1102.003 | One-Way Communication | Command And Control | Leviathan |
| 192 | T1102.002 | Bidirectional Communication | Command And Control | Kimsuky|Lazarus Group|ZIRCONIUM|MuddyWater|APT28|APT29|Sandworm Team|APT39|APT12|Turla|FIN7|APT37|Magic Hound|Carbanak |
| 193 | T1102.001 | Dead Drop Resolver | Command And Control | Rocke|APT41|BRONZE BUTLER|RTM|Patchwork |
| 194 | T1571 | Non-Standard Port | Command And Control | WIRTE|Sandworm Team|Rocke|DarkVishnya|Silence|APT-C-36|Magic Hound|APT33|APT32|TEMP.Veles|Lazarus Group|FIN7 |
| 195 | T1074.002 | Remote Data Staging | Collection | Leviathan|APT28|APT29|Chimera|Threat Group-3390|menuPass|FIN6|Night Dragon|FIN8 |
| 196 | T1074.001 | Local Data Staging | Collection | Dragonfly|Indrik Spider|BackdoorDiplomacy|Mustang Panda|Sidewinder|Chimera|Kimsuky|APT39|Operation Wocao|GALLIUM|TEMP.Veles|Patchwork|Honeybee|Dragonfly 2.0|Leviathan|APT3|FIN5|menuPass|Lazarus Group|Threat Group-3390|APT28 |
| 197 | T1078.004 | Cloud Accounts | Defense Evasion|Persistence|Privilege Escalation|Initial Access | Ke3chang|APT29|APT28|APT33 |
| 198 | T1564.004 | NTFS File Attributes | Defense Evasion | APT32 |
| 199 | T1564.003 | Hidden Window | Defense Evasion | Gamaredon Group|Kimsuky|Nomadic Octopus|Higaisa|Gorgon Group|Deep Panda|DarkHydrus|CopyKittens|APT19|APT32|APT28|APT3|Magic Hound |
| 200 | T1078.003 | Local Accounts | Defense Evasion|Persistence|Privilege Escalation|Initial Access | APT29|Kimsuky|HAFNIUM|Turla|Operation Wocao|PROMETHIUM|Tropic Trooper|FIN10|APT32 |
| 201 | T1078.002 | Domain Accounts | Defense Evasion|Persistence|Privilege Escalation|Initial Access | Naikon|Indrik Spider|Chimera|Operation Wocao|Sandworm Team|Wizard Spider|APT29|TA505|APT3|Threat Group-1314 |
| 202 | T1078.001 | Default Accounts | Defense Evasion|Persistence|Privilege Escalation|Initial Access | no |
| 203 | T1564.002 | Hidden Users | Defense Evasion | Kimsuky|Dragonfly|Dragonfly 2.0 |
| 204 | T1574.006 | Dynamic Linker Hijacking | Persistence|Privilege Escalation|Defense Evasion | APT41|Rocke |
| 205 | T1574.002 | DLL Side-Loading | Persistence|Privilege Escalation|Defense Evasion | Lazarus Group|Mustang Panda|Higaisa|BlackTech|Sidewinder|Chimera|BRONZE BUTLER|Naikon|APT41|GALLIUM|Tropic Trooper|APT19|Patchwork|APT32|APT3|menuPass|Threat Group-3390 |
| 206 | T1574.001 | DLL Search Order Hijacking | Persistence|Privilege Escalation|Defense Evasion | Aquatic Panda|BackdoorDiplomacy|Tonto Team|Evilnum|APT41|Whitefly|RTM|Threat Group-3390|menuPass |
| 207 | T1574.008 | Path Interception by Search Order Hijacking | Persistence|Privilege Escalation|Defense Evasion | no |
| 208 | T1574.007 | Path Interception by PATH Environment Variable | Persistence|Privilege Escalation|Defense Evasion | no |
| 209 | T1574.009 | Path Interception by Unquoted Path | Persistence|Privilege Escalation|Defense Evasion | no |
| 210 | T1574.011 | Services Registry Permissions Weakness | Persistence|Privilege Escalation|Defense Evasion | no |
| 211 | T1574.005 | Executable Installer File Permissions Weakness | Persistence|Privilege Escalation|Defense Evasion | no |
| 212 | T1574.010 | Services File Permissions Weakness | Persistence|Privilege Escalation|Defense Evasion | no |
| 213 | T1574 | Hijack Execution Flow | Persistence|Privilege Escalation|Defense Evasion | no |
| 214 | T1069.001 | Local Groups | Discovery | Tonto Team|Chimera|Operation Wocao|Turla|OilRig|admin@338 |
| 215 | T1570 | Lateral Tool Transfer | Lateral Movement | Sandworm Team|Chimera|GALLIUM|Operation Wocao|APT32|Wizard Spider|Turla|FIN10 |
| 216 | T1568.003 | DNS Calculation | Command And Control | APT12 |
| 217 | T1204.002 | Malicious File | Execution | LazyScripter|WIRTE|Confucius|Dragonfly|Threat Group-3390|Nomadic Octopus|Indrik Spider|APT38|Andariel|Ferocious Kitten|IndigoZebra|Transparent Tribe|Tonto Team|Magic Hound|Ajax Security Team|Mustang Panda|TA551|Higaisa|Sidewinder|Kimsuky|FIN6|PROMETHIUM|APT30|Windshift|APT33|Sandworm Team|Naikon|Whitefly|Tropic Trooper|Gamaredon Group|Sharpshooter|Molerats|Wizard Spider|Mofang|Frankenstein|RTM|Inception|BlackTech|APT-C-36|Machete|admin@338|APT12|TA505|Silence|The White Company|APT39|FIN4|Darkhotel|Gallmaker|Dragonfly 2.0|FIN7|BRONZE BUTLER|Gorgon Group|OilRig|Dark Caracal|Cobalt Group|DarkHydrus|Rancor|Patchwork|APT32|APT19|MuddyWater|Lazarus Group|menuPass|APT37|Leviathan|TA459|APT29|APT28|FIN8|PLATINUM|Elderwood |
| 218 | T1204.001 | Malicious Link | Execution | LazyScripter|Kimsuky|Lazarus Group|Confucius|FIN7|Transparent Tribe|APT3|Magic Hound|APT28|APT29|Mustang Panda|Sidewinder|ZIRCONIUM|MuddyWater|Evilnum|Sandworm Team|Wizard Spider|Patchwork|Windshift|APT32|Molerats|Mofang|BlackTech|TA505|OilRig|Machete|Leviathan|FIN8|FIN4|Elderwood|Dragonfly 2.0|Cobalt Group|APT39|Night Dragon|Turla|APT33 |
| 219 | T1195.003 | Compromise Hardware Supply Chain | Initial Access | no |
| 220 | T1195.002 | Compromise Software Supply Chain | Initial Access | Gelsemium|Threat Group-3390|APT29|Cobalt Group|GOLD SOUTHFIELD|Dragonfly|Sandworm Team|APT41 |
| 221 | T1195.001 | Compromise Software Dependencies and Development Tools | Initial Access | no |
| 222 | T1568.001 | Fast Flux DNS | Command And Control | menuPass|TA505 |
| 223 | T1052.001 | Exfiltration over USB | Exfiltration | Mustang Panda|Tropic Trooper |
| 224 | T1569.002 | Service Execution | Execution | APT38|Chimera|Operation Wocao|Wizard Spider|Blue Mockingbird|APT39|APT41|Silence|FIN6|APT32|Honeybee|Ke3chang |
| 225 | T1569.001 | Launchctl | Execution | no |
| 226 | T1569 | System Services | Execution | no |
| 227 | T1568.002 | Domain Generation Algorithms | Command And Control | TA551|APT41 |
| 228 | T1568 | Dynamic Resolution | Command And Control | Gamaredon Group|Gelsemium|Transparent Tribe|APT29 |
| 229 | T1011.001 | Exfiltration Over Bluetooth | Exfiltration | no |
| 230 | T1567.002 | Exfiltration to Cloud Storage | Exfiltration | Kimsuky|Threat Group-3390|Confucius|Lazarus Group|FIN7|ZIRCONIUM|HAFNIUM|Chimera|Leviathan|Turla |
| 231 | T1567.001 | Exfiltration to Code Repository | Exfiltration | no |
| 232 | T1059.006 | Python | Execution | Dragonfly|Tonto Team|APT37|ZIRCONIUM|MuddyWater|Turla|Operation Wocao|Kimsuky|APT29|Rocke|BRONZE BUTLER|APT39|Dragonfly 2.0|Machete |
| 233 | T1059.005 | Visual Basic | Execution | Confucius|Lazarus Group|LazyScripter|OilRig|APT38|Transparent Tribe|APT29|Mustang Panda|Windshift|Higaisa|Sidewinder|APT39|Machete|Operation Wocao|Kimsuky|APT33|Sandworm Team|Gamaredon Group|Sharpshooter|Molerats|Frankenstein|Inception|APT-C-36|Rancor|Patchwork|MuddyWater|Honeybee|FIN7|APT37|BRONZE BUTLER|APT32|Turla|TA505|Silence|WIRTE|FIN4|Cobalt Group|Gorgon Group|Leviathan|TA459|Magic Hound |
| 234 | T1059.004 | Unix Shell | Execution | TeamTNT|Rocke|APT41 |
| 235 | T1059.003 | Windows Command Shell | Execution | Kimsuky|Aquatic Panda|Dragonfly|LazyScripter|Sandworm Team|Nomadic Octopus|TeamTNT|APT29|Mustang Panda|ZIRCONIUM|TA551|Higaisa|Indrik Spider|Chimera|Fox Kitten|Machete|Operation Wocao|Wizard Spider|FIN6|TA505|Blue Mockingbird|Tropic Trooper|Frankenstein|OilRig|Lazarus Group|Honeybee|Cobalt Group|FIN7|APT41|GALLIUM|Turla|Silence|APT32|Darkhotel|MuddyWater|APT18|APT38|Gorgon Group|Dark Caracal|Ke3chang|Dragonfly 2.0|Rancor|FIN8|APT28|APT37|Magic Hound|BRONZE BUTLER|Sowbug|menuPass|FIN10|Threat Group-3390|Gamaredon Group|Patchwork|Suckfly|Threat Group-1314|APT3|admin@338|APT1 |
| 236 | T1059.002 | AppleScript | Execution | no |
| 237 | T1059.001 | PowerShell | Execution | Gamaredon Group|Lazarus Group|Aquatic Panda|Confucius|Dragonfly|LazyScripter|Nomadic Octopus|TeamTNT|APT38|Tonto Team|Mustang Panda|Indrik Spider|HAFNIUM|Sidewinder|Fox Kitten|GOLD SOUTHFIELD|Sandworm Team|Operation Wocao|Chimera|Blue Mockingbird|APT39|DarkVishnya|Molerats|Wizard Spider|Frankenstein|Inception|Silence|APT41|Kimsuky|GALLIUM|TA505|WIRTE|TEMP.Veles|APT33|Gallmaker|Turla|Thrip|Cobalt Group|APT28|DarkHydrus|Dragonfly 2.0|APT19|Gorgon Group|TA459|Leviathan|MuddyWater|FIN8|CopyKittens|OilRig|Magic Hound|BRONZE BUTLER|FIN7|APT32|menuPass|FIN10|Threat Group-3390|Patchwork|Stealth Falcon|FIN6|Poseidon Group|APT3|APT29|Deep Panda |
| 238 | T1567 | Exfiltration Over Web Service | Exfiltration | APT28 |
| 239 | T1497.003 | Time Based Evasion | Defense Evasion|Discovery | no |
| 240 | T1497.002 | User Activity Based Checks | Defense Evasion|Discovery | Darkhotel|FIN7 |
| 241 | T1497.001 | System Checks | Defense Evasion|Discovery | Lazarus Group|OilRig|Darkhotel|Evilnum|Frankenstein |
| 242 | T1498.002 | Reflection Amplification | Impact | no |
| 243 | T1498.001 | Direct Network Flood | Impact | no |
| 244 | T1566.003 | Spearphishing via Service | Initial Access | Lazarus Group|APT29|Ajax Security Team|Magic Hound|Windshift|FIN6|OilRig|Dark Caracal |
| 245 | T1566.002 | Spearphishing Link | Initial Access | Lazarus Group|Confucius|LazyScripter|Transparent Tribe|FIN7|APT3|Mustang Panda|ZIRCONIUM|MuddyWater|Sidewinder|Evilnum|Sandworm Team|Wizard Spider|APT1|Windshift|Molerats|Mofang|BlackTech|Machete|Kimsuky|TA505|APT39|FIN4|APT32|Night Dragon|APT28|Cobalt Group|Turla|Dragonfly 2.0|OilRig|Elderwood|APT33|APT29|Leviathan|FIN8|Patchwork|Magic Hound |
| 246 | T1566.001 | Spearphishing Attachment | Initial Access | WIRTE|Confucius|Dragonfly|LazyScripter|Threat Group-3390|APT38|Andariel|Ferocious Kitten|IndigoZebra|Transparent Tribe|Nomadic Octopus|Tonto Team|Ajax Security Team|Mustang Panda|TA551|Higaisa|Sidewinder|APT1|FIN6|APT30|Windshift|APT33|Sandworm Team|Naikon|Gamaredon Group|Sharpshooter|Molerats|Mofang|Wizard Spider|RTM|Frankenstein|Inception|BlackTech|APT-C-36|APT41|Machete|admin@338|Kimsuky|APT12|TA505|Silence|The White Company|APT39|FIN4|Darkhotel|Gallmaker|Tropic Trooper|DarkHydrus|Lazarus Group|Gorgon Group|OilRig|BRONZE BUTLER|APT19|APT32|Cobalt Group|Rancor|FIN7|Dragonfly 2.0|MuddyWater|APT28|TA459|APT29|APT37|Leviathan|FIN8|Patchwork|menuPass|Elderwood|PLATINUM |
| 247 | T1566 | Phishing | Initial Access | Axiom|GOLD SOUTHFIELD|Dragonfly |
| 248 | T1565.003 | Runtime Data Manipulation | Impact | APT38 |
| 249 | T1565.002 | Transmitted Data Manipulation | Impact | APT38 |
| 250 | T1565.001 | Stored Data Manipulation | Impact | APT38 |
| 251 | T1565 | Data Manipulation | Impact | no |
| 252 | T1564.001 | Hidden Files and Directories | Defense Evasion | Transparent Tribe|Mustang Panda|Rocke|APT32|Tropic Trooper|APT28|Lazarus Group |
| 253 | T1564 | Hide Artifacts | Defense Evasion | no |
| 254 | T1563.002 | RDP Hijacking | Lateral Movement | Axiom |
| 255 | T1563.001 | SSH Hijacking | Lateral Movement | no |
| 256 | T1563 | Remote Service Session Hijacking | Lateral Movement | no |
| 257 | T1518.001 | Security Software Discovery | Discovery | Kimsuky|Aquatic Panda|TeamTNT|APT38|Windshift|Sidewinder|Operation Wocao|Wizard Spider|Turla|Rocke|Frankenstein|The White Company|Cobalt Group|Darkhotel|MuddyWater|Tropic Trooper|FIN8|Patchwork|Naikon |
| 258 | T1069.003 | Cloud Groups | Discovery | no |
| 259 | T1069.002 | Domain Groups | Discovery | APT29|Dragonfly|Turla|Inception|OilRig|Dragonfly 2.0|Ke3chang |
| 260 | T1087.004 | Cloud Account | Discovery | APT29 |
| 261 | T1087.003 | Email Account | Discovery | Sandworm Team|TA505 |
| 262 | T1087.002 | Domain Account | Discovery | APT29|Lazarus Group|Dragonfly|MuddyWater|Fox Kitten|Operation Wocao|Wizard Spider|Chimera|Turla|Sandworm Team|Dragonfly 2.0|OilRig|BRONZE BUTLER|menuPass|FIN6|Poseidon Group|Ke3chang |
| 263 | T1087.001 | Local Account | Discovery | Chimera|Fox Kitten|Turla|Poseidon Group|OilRig|Ke3chang|APT32|APT1|Threat Group-3390|APT3|admin@338 |
| 264 | T1553.004 | Install Root Certificate | Defense Evasion | no |
| 265 | T1562.004 | Disable or Modify System Firewall | Defense Evasion | Dragonfly|TeamTNT|APT38|APT29|Operation Wocao|Rocke|Lazarus Group|Kimsuky|Dragonfly 2.0|Carbanak |
| 266 | T1562.003 | Impair Command History Logging | Defense Evasion | APT38 |
| 267 | T1562.002 | Disable Windows Event Logging | Defense Evasion | Sandworm Team|APT29|Threat Group-3390 |
| 268 | T1562.001 | Disable or Modify Tools | Defense Evasion | Aquatic Panda|TeamTNT|Indrik Spider|APT29|MuddyWater|Wizard Spider|FIN6|Gamaredon Group|BRONZE BUTLER|Rocke|Kimsuky|Turla|Night Dragon|Gorgon Group|Lazarus Group|Putter Panda |
| 269 | T1562 | Impair Defenses | Defense Evasion | no |
| 270 | T1003.004 | LSA Secrets | Credential Access | Dragonfly|OilRig|MuddyWater|menuPass|Leafminer|Ke3chang|Dragonfly 2.0|APT33|Threat Group-3390 |
| 271 | T1003.005 | Cached Domain Credentials | Credential Access | OilRig|MuddyWater|Leafminer|APT33 |
| 272 | T1561.002 | Disk Structure Wipe | Impact | Sandworm Team|Lazarus Group|APT38|APT37 |
| 273 | T1561.001 | Disk Content Wipe | Impact | Lazarus Group |
| 274 | T1561 | Disk Wipe | Impact | no |
| 275 | T1560.003 | Archive via Custom Method | Collection | Mustang Panda|Lazarus Group|Kimsuky|CopyKittens|FIN6 |
| 276 | T1560.002 | Archive via Library | Collection | Lazarus Group|Threat Group-3390 |
| 277 | T1560.001 | Archive via Utility | Collection | Kimsuky|Aquatic Panda|APT28|APT29|Mustang Panda|HAFNIUM|Fox Kitten|Operation Wocao|Chimera|APT41|GALLIUM|Turla|Gallmaker|APT33|APT39|MuddyWater|Magic Hound|FIN8|BRONZE BUTLER|CopyKittens|Sowbug|APT3|menuPass|APT1|Ke3chang |
| 278 | T1560 | Archive Collected Data | Collection | Axiom|Dragonfly|Leviathan|menuPass|APT32|Honeybee|Patchwork|APT28|Dragonfly 2.0|FIN6|Lazarus Group|Ke3chang |
| 279 | T1499.004 | Application or System Exploitation | Impact | no |
| 280 | T1499.003 | Application Exhaustion Flood | Impact | no |
| 281 | T1499.002 | Service Exhaustion Flood | Impact | no |
| 282 | T1499.001 | OS Exhaustion Flood | Impact | no |
| 283 | T1491.002 | External Defacement | Impact | Sandworm Team |
| 284 | T1491.001 | Internal Defacement | Impact | Gamaredon Group|Lazarus Group |
| 285 | T1114.003 | Email Forwarding Rule | Collection | Silent Librarian|Kimsuky |
| 286 | T1114.002 | Remote Email Collection | Collection | Kimsuky|Dragonfly|APT29|HAFNIUM|Chimera|APT1|FIN4|Ke3chang|Leafminer|Dragonfly 2.0|APT28 |
| 287 | T1114.001 | Local Email Collection | Collection | Chimera|Magic Hound|APT1 |
| 288 | T1134.005 | SID-History Injection | Defense Evasion|Privilege Escalation | no |
| 289 | T1134.004 | Parent PID Spoofing | Defense Evasion|Privilege Escalation | no |
| 290 | T1134.003 | Make and Impersonate Token | Defense Evasion|Privilege Escalation | no |
| 291 | T1134.002 | Create Process with Token | Defense Evasion|Privilege Escalation | Turla|Lazarus Group |
| 292 | T1134.001 | Token Impersonation/Theft | Defense Evasion|Privilege Escalation | FIN8|APT28 |
| 293 | T1213.002 | Sharepoint | Collection | Chimera|Ke3chang|APT28 |
| 294 | T1213.001 | Confluence | Collection | no |
| 295 | T1555.003 | Credentials from Web Browsers | Credential Access | APT29|Ajax Security Team|ZIRCONIUM|FIN6|Sandworm Team|Inception|Stealth Falcon|OilRig|Leafminer|APT33|APT3|Kimsuky|TA505|MuddyWater|APT37|Patchwork|Molerats |
| 296 | T1555.002 | Securityd Memory | Credential Access | no |
| 297 | T1555.001 | Keychain | Credential Access | no |
| 298 | T1559.002 | Dynamic Data Exchange | Execution | Leviathan|Sidewinder|Sharpshooter|TA505|MuddyWater|Gallmaker|Patchwork|Cobalt Group|APT37|FIN7|APT28 |
| 299 | T1559.001 | Component Object Model | Execution | Gamaredon Group|MuddyWater |
| 300 | T1559 | Inter-Process Communication | Execution | no |
| 301 | T1558.002 | Silver Ticket | Credential Access | no |
| 302 | T1558.001 | Golden Ticket | Credential Access | Ke3chang |
| 303 | T1558 | Steal or Forge Kerberos Tickets | Credential Access | no |
| 304 | T1557.001 | LLMNR/NBT-NS Poisoning and SMB Relay | Credential Access|Collection | Lazarus Group|Wizard Spider |
| 305 | T1557 | Adversary-in-the-Middle | Credential Access|Collection | Kimsuky |
| 306 | T1556.002 | Password Filter DLL | Credential Access|Defense Evasion|Persistence | Strider |
| 307 | T1556.001 | Domain Controller Authentication | Credential Access|Defense Evasion|Persistence | Chimera |
| 308 | T1556 | Modify Authentication Process | Credential Access|Defense Evasion|Persistence | no |
| 309 | T1056.004 | Credential API Hooking | Collection|Credential Access | PLATINUM |
| 310 | T1056.003 | Web Portal Capture | Collection|Credential Access | no |
| 311 | T1056.002 | GUI Input Capture | Collection|Credential Access | FIN4 |
| 312 | T1056.001 | Keylogging | Collection|Credential Access | Tonto Team|Ajax Security Team|Operation Wocao|APT32|Sandworm Team|APT39|APT41|Kimsuky|menuPass|FIN4|APT38|OilRig|Ke3chang|PLATINUM|Sowbug|Magic Hound|Group5|Lazarus Group|Threat Group-3390|APT3|Darkhotel|APT28 |
| 313 | T1555 | Credentials from Password Stores | Credential Access | APT29|Evilnum|FIN6|APT39|OilRig|MuddyWater|Leafminer|APT33|Stealth Falcon |
| 314 | T1552.005 | Cloud Instance Metadata API | Credential Access | TeamTNT |
| 315 | T1003.008 | /etc/passwd and /etc/shadow | Credential Access | no |
| 316 | T1003.007 | Proc Filesystem | Credential Access | no |
| 317 | T1003.006 | DCSync | Credential Access | APT29|Operation Wocao |
| 318 | T1558.003 | Kerberoasting | Credential Access | FIN7|APT29|Operation Wocao|Wizard Spider |
| 319 | T1552.006 | Group Policy Preferences | Credential Access | APT33 |
| 320 | T1003.003 | NTDS | Credential Access | Ke3chang|Dragonfly|APT28|Mustang Panda|HAFNIUM|Fox Kitten|menuPass|Wizard Spider|Chimera|FIN6|Dragonfly 2.0 |
| 321 | T1003.002 | Security Account Manager | Credential Access | Dragonfly|Wizard Spider|Threat Group-3390|Ke3chang|GALLIUM|Night Dragon|Dragonfly 2.0|menuPass |
| 322 | T1003.001 | LSASS Memory | Credential Access | Aquatic Panda|Indrik Spider|HAFNIUM|Fox Kitten|Operation Wocao|Kimsuky|Sandworm Team|Whitefly|Blue Mockingbird|Silence|Threat Group-3390|Leviathan|APT41|GALLIUM|TEMP.Veles|APT33|APT39|APT32|Leafminer|Magic Hound|FIN8|PLATINUM|MuddyWater|OilRig|BRONZE BUTLER|FIN6|APT3|APT28|APT1|Ke3chang|Cleaver |
| 323 | T1110.004 | Credential Stuffing | Credential Access | Chimera |
| 324 | T1110.003 | Password Spraying | Credential Access | Sandworm Team|APT29|Silent Librarian|Chimera|APT28|APT33|Leafminer|Lazarus Group |
| 325 | T1110.002 | Password Cracking | Credential Access | Dragonfly|FIN6|APT41|Dragonfly 2.0|APT3 |
| 326 | T1110.001 | Password Guessing | Credential Access | APT28 |
| 327 | T1021.006 | Windows Remote Management | Lateral Movement | APT29|Chimera|Wizard Spider|Threat Group-3390 |
| 328 | T1021.005 | VNC | Lateral Movement | Gamaredon Group|FIN7|Fox Kitten|GCMAN |
| 329 | T1021.004 | SSH | Lateral Movement | BlackTech|Lazarus Group|TeamTNT|FIN7|Fox Kitten|Rocke|TEMP.Veles|Leviathan|APT39|OilRig|menuPass|GCMAN |
| 330 | T1021.003 | Distributed Component Object Model | Lateral Movement | no |
| 331 | T1021.002 | SMB/Windows Admin Shares | Lateral Movement | APT29|Sandworm Team|APT28|Fox Kitten|APT41|Operation Wocao|Wizard Spider|Chimera|Blue Mockingbird|APT39|APT32|Orangeworm|FIN8|APT3|Lazarus Group|Threat Group-1314|Turla|Deep Panda|Ke3chang |
| 332 | T1021.001 | Remote Desktop Protocol | Lateral Movement | APT29|Dragonfly|Kimsuky|FIN7|Fox Kitten|Chimera|Blue Mockingbird|Wizard Spider|Silence|APT41|TEMP.Veles|Leviathan|APT39|Cobalt Group|Dragonfly 2.0|FIN8|APT3|OilRig|FIN10|menuPass|Patchwork|FIN6|Lazarus Group|APT1|Axiom |
| 333 | T1554 | Compromise Client Software Binary | Persistence | no |
| 334 | T1036.006 | Space after Filename | Defense Evasion | no |
| 335 | T1036.005 | Match Legitimate Name or Location | Defense Evasion | Ke3chang|Kimsuky|Gamaredon Group|WIRTE|APT28|Ferocious Kitten|FIN7|BackdoorDiplomacy|Transparent Tribe|Naikon|APT29|Mustang Panda|Sidewinder|Darkhotel|Lazarus Group|Indrik Spider|Fox Kitten|Machete|Chimera|PROMETHIUM|Rocke|Sandworm Team|APT39|Blue Mockingbird|Whitefly|Tropic Trooper|Silence|APT41|menuPass|TEMP.Veles|MuddyWater|Sowbug|BRONZE BUTLER|APT32|Patchwork|Poseidon Group|admin@338|Carbanak|APT1 |
| 336 | T1036.004 | Masquerade Task or Service | Defense Evasion | Lazarus Group|BackdoorDiplomacy|APT41|Naikon|ZIRCONIUM|APT29|Higaisa|Fox Kitten|Kimsuky|PROMETHIUM|Wizard Spider|APT-C-36|Carbanak|APT32|FIN6|FIN7 |
| 337 | T1036.003 | Rename System Utilities | Defense Evasion | Lazarus Group|menuPass|APT32|GALLIUM |
| 338 | T1036.002 | Right-to-Left Override | Defense Evasion | Ferocious Kitten|BRONZE BUTLER|BlackTech|Ke3chang|Scarlet Mimic |
| 339 | T1036.001 | Invalid Code Signature | Defense Evasion | Windshift|APT37 |
| 340 | T1553.003 | SIP and Trust Provider Hijacking | Defense Evasion | no |
| 341 | T1553.002 | Code Signing | Defense Evasion | Lazarus Group|menuPass|APT29|GALLIUM|Wizard Spider|Kimsuky|PROMETHIUM|Patchwork|Silence|APT41|FIN6|TA505|FIN7|Honeybee|Leviathan|CopyKittens|Winnti Group|Suckfly|Molerats|Darkhotel |
| 342 | T1553.001 | Gatekeeper Bypass | Defense Evasion | no |
| 343 | T1553 | Subvert Trust Controls | Defense Evasion | Axiom |
| 344 | T1027.003 | Steganography | Defense Evasion | Andariel|Leviathan|TA551|BRONZE BUTLER|Tropic Trooper|MuddyWater|APT37 |
| 345 | T1027.002 | Software Packing | Defense Evasion | Threat Group-3390|Lazarus Group|Sandworm Team|Kimsuky|TeamTNT|ZIRCONIUM|TA505|Rocke|GALLIUM|The White Company|APT39|APT38|Dark Caracal|Elderwood|APT3|Patchwork|APT29|Night Dragon |
| 346 | T1027.001 | Binary Padding | Defense Evasion | APT29|Mustang Panda|Higaisa|Gamaredon Group|Patchwork|APT32|Leviathan|BRONZE BUTLER|Moafee |
| 347 | T1222.002 | Linux and Mac File and Directory Permissions Modification | Defense Evasion | TeamTNT|Rocke|APT32 |
| 348 | T1222.001 | Windows File and Directory Permissions Modification | Defense Evasion | Wizard Spider |
| 349 | T1552.004 | Private Keys | Credential Access | TeamTNT|APT29|Operation Wocao|Rocke |
| 350 | T1552.003 | Bash History | Credential Access | no |
| 351 | T1552.002 | Credentials in Registry | Credential Access | APT32 |
| 352 | T1552.001 | Credentials In Files | Credential Access | TeamTNT|Kimsuky|Fox Kitten|Leafminer|APT33|OilRig|TA505|MuddyWater|APT3 |
| 353 | T1552 | Unsecured Credentials | Credential Access | no |
| 354 | T1216.001 | PubPrn | Defense Evasion | APT32 |
| 355 | T1070.006 | Timestomp | Defense Evasion | APT38|APT29|Chimera|Kimsuky|Rocke|TEMP.Veles|APT32|Lazarus Group|APT28 |
| 356 | T1070.005 | Network Share Connection Removal | Defense Evasion | Threat Group-3390 |
| 357 | T1070.004 | File Deletion | Defense Evasion | Aquatic Panda|Dragonfly|TeamTNT|APT39|Mustang Panda|Chimera|Evilnum|Operation Wocao|FIN6|Sandworm Team|Rocke|Tropic Trooper|Gamaredon Group|Wizard Spider|APT41|Kimsuky|Silence|The White Company|TEMP.Veles|APT32|APT38|Cobalt Group|Dragonfly 2.0|Honeybee|Patchwork|menuPass|FIN8|OilRig|FIN5|BRONZE BUTLER|APT3|Magic Hound|Threat Group-3390|APT28|FIN10|Group5|Lazarus Group|APT18|APT29 |
| 358 | T1070.003 | Clear Command History | Defense Evasion | Lazarus Group|TeamTNT|menuPass|APT41 |
| 359 | T1550.004 | Web Session Cookie | Defense Evasion|Lateral Movement | APT29 |
| 360 | T1550.001 | Application Access Token | Defense Evasion|Lateral Movement | APT29|APT28 |
| 361 | T1550.003 | Pass the Ticket | Defense Evasion|Lateral Movement | APT32|BRONZE BUTLER|APT29 |
| 362 | T1550.002 | Pass the Hash | Defense Evasion|Lateral Movement | Chimera|Kimsuky|GALLIUM|APT32|Night Dragon|APT28|APT1 |
| 363 | T1550 | Use Alternate Authentication Material | Defense Evasion|Lateral Movement | APT29 |
| 364 | T1548.004 | Elevated Execution with Prompt | Privilege Escalation|Defense Evasion | no |
| 365 | T1548.003 | Sudo and Sudo Caching | Privilege Escalation|Defense Evasion | no |
| 366 | T1548.002 | Bypass User Account Control | Privilege Escalation|Defense Evasion | Evilnum|APT37|MuddyWater|Threat Group-3390|Honeybee|Cobalt Group|BRONZE BUTLER|Patchwork|APT29 |
| 367 | T1548.001 | Setuid and Setgid | Privilege Escalation|Defense Evasion | no |
| 368 | T1548 | Abuse Elevation Control Mechanism | Privilege Escalation|Defense Evasion | no |
| 369 | T1136.003 | Cloud Account | Persistence | APT29 |
| 370 | T1070.002 | Clear Linux or Mac System Logs | Defense Evasion | TeamTNT|Rocke |
| 371 | T1070.001 | Clear Windows Event Logs | Defense Evasion | Dragonfly|Indrik Spider|Chimera|Operation Wocao|APT41|APT38|Dragonfly 2.0|APT32|FIN8|FIN5|APT28 |
| 372 | T1136.002 | Domain Account | Persistence | Sandworm Team|HAFNIUM|GALLIUM |
| 373 | T1136.001 | Local Account | Persistence | Kimsuky|Dragonfly|TeamTNT|Fox Kitten|APT39|APT41|Leafminer|Dragonfly 2.0|APT3 |
| 374 | T1547.011 | Plist Modification | Persistence|Privilege Escalation | no |
| 375 | T1547.010 | Port Monitors | Persistence|Privilege Escalation | no |
| 376 | T1547.009 | Shortcut Modification | Persistence|Privilege Escalation | Dragonfly|APT39|Darkhotel|APT29|Gorgon Group|Dragonfly 2.0|Lazarus Group|Leviathan |
| 377 | T1547.008 | LSASS Driver | Persistence|Privilege Escalation | no |
| 378 | T1547.007 | Re-opened Applications | Persistence|Privilege Escalation | no |
| 379 | T1547.006 | Kernel Modules and Extensions | Persistence|Privilege Escalation | no |
| 380 | T1547.005 | Security Support Provider | Persistence|Privilege Escalation | no |
| 381 | T1547.004 | Winlogon Helper DLL | Persistence|Privilege Escalation | Wizard Spider|Tropic Trooper|Turla |
| 382 | T1547.003 | Time Providers | Persistence|Privilege Escalation | no |
| 383 | T1546.014 | Emond | Privilege Escalation|Persistence | no |
| 384 | T1546.013 | PowerShell Profile | Privilege Escalation|Persistence | Turla |
| 385 | T1546.012 | Image File Execution Options Injection | Privilege Escalation|Persistence | TEMP.Veles |
| 386 | T1218.008 | Odbcconf | Defense Evasion | Cobalt Group |
| 387 | T1546.011 | Application Shimming | Privilege Escalation|Persistence | FIN7 |
| 388 | T1547.002 | Authentication Package | Persistence|Privilege Escalation | no |
| 389 | T1546.010 | AppInit DLLs | Privilege Escalation|Persistence | APT39 |
| 390 | T1546.009 | AppCert DLLs | Privilege Escalation|Persistence | Honeybee |
| 391 | T1218.007 | Msiexec | Defense Evasion | ZIRCONIUM|Molerats|Machete|TA505|Rancor |
| 392 | T1546.008 | Accessibility Features | Privilege Escalation|Persistence | Fox Kitten|APT41|APT3|APT29|Deep Panda|Axiom |
| 393 | T1546.007 | Netsh Helper DLL | Privilege Escalation|Persistence | no |
| 394 | T1546.006 | LC_LOAD_DYLIB Addition | Privilege Escalation|Persistence | no |
| 395 | T1546.005 | Trap | Privilege Escalation|Persistence | no |
| 396 | T1546.004 | Unix Shell Configuration Modification | Privilege Escalation|Persistence | no |
| 397 | T1546.003 | Windows Management Instrumentation Event Subscription | Privilege Escalation|Persistence | FIN8|Mustang Panda|APT33|Blue Mockingbird|Turla|Leviathan|APT29 |
| 398 | T1546.002 | Screensaver | Privilege Escalation|Persistence | no |
| 399 | T1546.001 | Change Default File Association | Privilege Escalation|Persistence | Kimsuky |
| 400 | T1547.001 | Registry Run Keys / Startup Folder | Persistence|Privilege Escalation | Confucius|Dragonfly|LazyScripter|TeamTNT|Naikon|Windshift|Mustang Panda|ZIRCONIUM|Higaisa|Sidewinder|APT28|Wizard Spider|PROMETHIUM|Rocke|Tropic Trooper|Gamaredon Group|Sharpshooter|Molerats|Silence|RTM|Inception|APT41|Kimsuky|APT33|APT39|APT32|APT18|Dark Caracal|Threat Group-3390|Honeybee|Turla|Cobalt Group|Ke3chang|Dragonfly 2.0|APT19|Gorgon Group|MuddyWater|APT37|Leviathan|BRONZE BUTLER|APT3|Magic Hound|FIN10|FIN7|Patchwork|FIN6|Lazarus Group|Putter Panda|APT29|Darkhotel |
| 401 | T1218.002 | Control Panel | Defense Evasion | no |
| 402 | T1218.010 | Regsvr32 | Defense Evasion | Kimsuky|Lazarus Group|TA551|Blue Mockingbird|Inception|WIRTE|Cobalt Group|APT19|Leviathan|APT32|Deep Panda |
| 403 | T1218.009 | Regsvcs/Regasm | Defense Evasion | no |
| 404 | T1218.005 | Mshta | Defense Evasion | Gamaredon Group|Confucius|Lazarus Group|APT29|LazyScripter|Mustang Panda|TA551|Sidewinder|Inception|Kimsuky|APT32|MuddyWater|FIN7 |
| 405 | T1218.004 | InstallUtil | Defense Evasion | Mustang Panda|menuPass |
| 406 | T1218.001 | Compiled HTML File | Defense Evasion | APT38|APT41|Silence|Dark Caracal|OilRig|Lazarus Group |
| 407 | T1218.003 | CMSTP | Defense Evasion | Cobalt Group|MuddyWater |
| 408 | T1218.011 | Rundll32 | Defense Evasion | Kimsuky|Lazarus Group|LazyScripter|APT38|HAFNIUM|TA551|APT41|Gamaredon Group|APT32|Sandworm Team|Blue Mockingbird|TA505|MuddyWater|APT29|APT19|CopyKittens|APT3|Carbanak|APT28 |
| 409 | T1547 | Boot or Logon Autostart Execution | Persistence|Privilege Escalation | no |
| 410 | T1546 | Event Triggered Execution | Privilege Escalation|Persistence | no |
| 411 | T1098.003 | Add Office 365 Global Administrator Role | Persistence | APT29 |
| 412 | T1098.002 | Exchange Email Delegate Permissions | Persistence | APT28|APT29|Magic Hound |
| 413 | T1098.001 | Additional Cloud Credentials | Persistence | APT29 |
| 414 | T1543.004 | Launch Daemon | Persistence|Privilege Escalation | no |
| 415 | T1543.003 | Windows Service | Persistence|Privilege Escalation | TeamTNT|APT38|PROMETHIUM|Blue Mockingbird|DarkVishnya|Wizard Spider|APT32|APT41|Kimsuky|Tropic Trooper|Cobalt Group|Ke3chang|FIN7|APT19|Threat Group-3390|Honeybee|APT3|Lazarus Group|Carbanak |
| 416 | T1543.002 | Systemd Service | Persistence|Privilege Escalation | TeamTNT|Rocke |
| 417 | T1543.001 | Launch Agent | Persistence|Privilege Escalation | no |
| 418 | T1037.005 | Startup Items | Persistence|Privilege Escalation | no |
| 419 | T1037.004 | RC Scripts | Persistence|Privilege Escalation | no |
| 420 | T1055.012 | Process Hollowing | Defense Evasion|Privilege Escalation | Kimsuky|Threat Group-3390|menuPass|Gorgon Group|Patchwork |
| 421 | T1055.013 | Process Doppelgänging | Defense Evasion|Privilege Escalation | Leafminer |
| 422 | T1055.011 | Extra Window Memory Injection | Defense Evasion|Privilege Escalation | no |
| 423 | T1055.014 | VDSO Hijacking | Defense Evasion|Privilege Escalation | no |
| 424 | T1055.009 | Proc Memory | Defense Evasion|Privilege Escalation | no |
| 425 | T1055.008 | Ptrace System Calls | Defense Evasion|Privilege Escalation | no |
| 426 | T1055.005 | Thread Local Storage | Defense Evasion|Privilege Escalation | no |
| 427 | T1055.004 | Asynchronous Procedure Call | Defense Evasion|Privilege Escalation | FIN8 |
| 428 | T1055.003 | Thread Execution Hijacking | Defense Evasion|Privilege Escalation | no |
| 429 | T1055.002 | Portable Executable Injection | Defense Evasion|Privilege Escalation | Rocke|Gorgon Group |
| 430 | T1055.001 | Dynamic-link Library Injection | Defense Evasion|Privilege Escalation | BackdoorDiplomacy|Leviathan|Wizard Spider|TA505|Turla|Tropic Trooper|Lazarus Group|Putter Panda |
| 431 | T1037.003 | Network Logon Script | Persistence|Privilege Escalation | no |
| 432 | T1543 | Create or Modify System Process | Persistence|Privilege Escalation | no |
| 433 | T1037.002 | Logon Script (Mac) | Persistence|Privilege Escalation | no |
| 434 | T1037.001 | Logon Script (Windows) | Persistence|Privilege Escalation | Cobalt Group|APT28 |
| 435 | T1542.003 | Bootkit | Persistence|Defense Evasion | APT41|Lazarus Group|APT28 |
| 436 | T1542.002 | Component Firmware | Persistence|Defense Evasion | Equation |
| 437 | T1542.001 | System Firmware | Persistence|Defense Evasion | no |
| 438 | T1505.003 | Web Shell | Persistence | Dragonfly|BackdoorDiplomacy|APT38|APT29|APT28|Tonto Team|Sandworm Team|HAFNIUM|Volatile Cedar|Fox Kitten|Operation Wocao|Kimsuky|Tropic Trooper|GALLIUM|Threat Group-3390|TEMP.Veles|Leviathan|APT39|Dragonfly 2.0|APT32|OilRig|Deep Panda |
| 439 | T1505.002 | Transport Agent | Persistence | no |
| 440 | T1505.001 | SQL Stored Procedures | Persistence | Sandworm Team |
| 441 | T1053.003 | Cron | Execution|Persistence|Privilege Escalation | APT38|Rocke |
| 442 | T1053.001 | At (Linux) | Execution|Persistence|Privilege Escalation | no |
| 443 | T1053.005 | Scheduled Task | Execution|Persistence|Privilege Escalation | Kimsuky|Lazarus Group|Confucius|Dragonfly|APT37|APT38|Naikon|CostaRicto|Mustang Panda|Higaisa|Fox Kitten|Molerats|Machete|Operation Wocao|Chimera|Gamaredon Group|Blue Mockingbird|MuddyWater|Wizard Spider|Frankenstein|APT-C-36|BRONZE BUTLER|APT41|GALLIUM|Silence|TEMP.Veles|APT33|APT39|Rancor|OilRig|Patchwork|Dragonfly 2.0|Cobalt Group|FIN8|menuPass|FIN10|FIN7|APT32|Stealth Falcon|FIN6|APT3|APT29 |
| 444 | T1053.002 | At (Windows) | Execution|Persistence|Privilege Escalation | BRONZE BUTLER|Threat Group-3390|APT18 |
| 445 | T1542 | Pre-OS Boot | Defense Evasion|Persistence | no |
| 446 | T1137.001 | Office Template Macros | Persistence | MuddyWater |
| 447 | T1137.004 | Outlook Home Page | Persistence | OilRig |
| 448 | T1137.003 | Outlook Forms | Persistence | no |
| 449 | T1137.005 | Outlook Rules | Persistence | no |
| 450 | T1137.006 | Add-ins | Persistence | Naikon |
| 451 | T1137.002 | Office Test | Persistence | APT28 |
| 452 | T1531 | Account Access Removal | Impact | no |
| 453 | T1539 | Steal Web Session Cookie | Credential Access | APT29|Evilnum |
| 454 | T1529 | System Shutdown/Reboot | Impact | Lazarus Group|APT38|APT37 |
| 455 | T1518 | Software Discovery | Discovery | Mustang Panda|Windshift|MuddyWater|Windigo|Sidewinder|Operation Wocao|BRONZE BUTLER|Tropic Trooper|Inception |
| 456 | T1547.013 | XDG Autostart Entries | Persistence|Privilege Escalation | no |
| 457 | T1534 | Internal Spearphishing | Lateral Movement | Kimsuky|Lazarus Group|Leviathan|Gamaredon Group |
| 458 | T1528 | Steal Application Access Token | Credential Access | APT28 |
| 459 | T1535 | Unused/Unsupported Cloud Regions | Defense Evasion | no |
| 460 | T1525 | Implant Internal Image | Persistence | no |
| 461 | T1538 | Cloud Service Dashboard | Discovery | no |
| 462 | T1530 | Data from Cloud Storage Object | Collection | Fox Kitten |
| 463 | T1578 | Modify Cloud Compute Infrastructure | Defense Evasion | no |
| 464 | T1537 | Transfer Data to Cloud Account | Exfiltration | no |
| 465 | T1526 | Cloud Service Discovery | Discovery | no |
| 466 | T1505 | Server Software Component | Persistence | no |
| 467 | T1499 | Endpoint Denial of Service | Impact | Sandworm Team |
| 468 | T1497 | Virtualization/Sandbox Evasion | Defense Evasion|Discovery | Darkhotel |
| 469 | T1498 | Network Denial of Service | Impact | APT28 |
| 470 | T1496 | Resource Hijacking | Impact | TeamTNT|Blue Mockingbird|Rocke|APT41 |
| 471 | T1495 | Firmware Corruption | Impact | no |
| 472 | T1491 | Defacement | Impact | no |
| 473 | T1490 | Inhibit System Recovery | Impact | no |
| 474 | T1489 | Service Stop | Impact | Indrik Spider|Wizard Spider|Lazarus Group |
| 475 | T1486 | Data Encrypted for Impact | Impact | FIN7|Indrik Spider|APT41|TA505|APT38 |
| 476 | T1485 | Data Destruction | Impact | Gamaredon Group|Sandworm Team|Lazarus Group|APT38 |
| 477 | T1484 | Domain Policy Modification | Defense Evasion|Privilege Escalation | no |
| 478 | T1482 | Domain Trust Discovery | Discovery | FIN8|APT29|Chimera |
| 479 | T1480 | Execution Guardrails | Defense Evasion | no |
| 480 | T1221 | Template Injection | Defense Evasion | Lazarus Group|Confucius|Dragonfly|Gamaredon Group|Frankenstein|Inception|APT28|Tropic Trooper|DarkHydrus|Dragonfly 2.0 |
| 481 | T1222 | File and Directory Permissions Modification | Defense Evasion | no |
| 482 | T1220 | XSL Script Processing | Defense Evasion | Lazarus Group|Higaisa|Cobalt Group |
| 483 | T1217 | Browser Bookmark Discovery | Discovery | APT38|Chimera|Fox Kitten |
| 484 | T1212 | Exploitation for Credential Access | Credential Access | no |
| 485 | T1189 | Drive-by Compromise | Initial Access | Magic Hound|APT28|Axiom|Transparent Tribe|Andariel|Leviathan|Machete|Windigo|Dragonfly|PROMETHIUM|Turla|Windshift|RTM|Darkhotel|APT38|APT19|Lazarus Group|Threat Group-3390|BRONZE BUTLER|APT32|Dark Caracal|Dragonfly 2.0|Leafminer|Patchwork|APT37|Elderwood|PLATINUM |
| 486 | T1211 | Exploitation for Defense Evasion | Defense Evasion | APT28 |
| 487 | T1197 | BITS Jobs | Defense Evasion|Persistence | APT39|Patchwork|APT41|Leviathan |
| 488 | T1203 | Exploitation for Client Execution | Execution | Axiom|Confucius|Dragonfly|Andariel|Transparent Tribe|APT3|Tonto Team|Mustang Panda|Darkhotel|Higaisa|HAFNIUM|Sidewinder|Sandworm Team|MuddyWater|Frankenstein|Inception|BlackTech|APT41|admin@338|Threat Group-3390|APT12|The White Company|APT33|APT32|APT28|Tropic Trooper|BRONZE BUTLER|Cobalt Group|Lazarus Group|Patchwork|Elderwood|APT29|TA459|APT37|Leviathan |
| 489 | T1201 | Password Policy Discovery | Discovery | Chimera|Turla|OilRig |
| 490 | T1195 | Supply Chain Compromise | Initial Access | no |
| 491 | T1199 | Trusted Relationship | Initial Access | Threat Group-3390|APT29|Sandworm Team|GOLD SOUTHFIELD|APT28|menuPass |
| 492 | T1218 | Signed Binary Proxy Execution | Defense Evasion | Lazarus Group |
| 493 | T1204 | User Execution | Execution | no |
| 494 | T1213 | Data from Information Repositories | Collection | APT29|APT28|Fox Kitten|FIN6|Turla |
| 495 | T1190 | Exploit Public-Facing Application | Initial Access | Threat Group-3390|Ke3chang|Kimsuky|Magic Hound|Dragonfly|BackdoorDiplomacy|menuPass|Volatile Cedar|Fox Kitten|Operation Wocao|APT28|APT29|GOLD SOUTHFIELD|Blue Mockingbird|Rocke|APT39|BlackTech|APT41|GALLIUM|Night Dragon|Axiom |
| 496 | T1210 | Exploitation of Remote Services | Lateral Movement | Dragonfly|Tonto Team|FIN7|Fox Kitten|menuPass|Wizard Spider|Threat Group-3390|APT28 |
| 497 | T1200 | Hardware Additions | Initial Access | DarkVishnya |
| 498 | T1202 | Indirect Command Execution | Defense Evasion | Lazarus Group |
| 499 | T1219 | Remote Access Software | Command And Control | TeamTNT|Mustang Panda|MuddyWater|Evilnum|GOLD SOUTHFIELD|Sandworm Team|DarkVishnya|RTM|Kimsuky|Night Dragon|Cobalt Group|Thrip|Carbanak |
| 500 | T1207 | Rogue Domain Controller | Defense Evasion | no |
| 501 | T1216 | Signed Script Proxy Execution | Defense Evasion | no |
| 502 | T1205 | Traffic Signaling | Defense Evasion|Persistence|Command And Control | no |
| 503 | T1176 | Browser Extensions | Persistence | Kimsuky |
| 504 | T1187 | Forced Authentication | Credential Access | Dragonfly|DarkHydrus|Dragonfly 2.0 |
| 505 | T1185 | Browser Session Hijacking | Collection | no |
| 506 | T1140 | Deobfuscate/Decode Files or Information | Defense Evasion | Lazarus Group|Ke3chang|Kimsuky|APT39|APT29|ZIRCONIUM|Higaisa|Rocke|Sandworm Team|Gamaredon Group|Molerats|Frankenstein|Turla|WIRTE|Darkhotel|Tropic Trooper|Honeybee|Gorgon Group|Threat Group-3390|menuPass|APT19|Leviathan|MuddyWater|APT28|OilRig|BRONZE BUTLER |
| 507 | T1134 | Access Token Manipulation | Defense Evasion|Privilege Escalation | FIN6|Blue Mockingbird |
| 508 | T1136 | Create Account | Persistence | Sandworm Team|Indrik Spider |
| 509 | T1135 | Network Share Discovery | Discovery | Dragonfly|Tonto Team|APT38|Chimera|Operation Wocao|Wizard Spider|APT32|APT39|DarkVishnya|APT41|Tropic Trooper|APT1|Dragonfly 2.0|Sowbug |
| 510 | T1137 | Office Application Startup | Persistence | Gamaredon Group|APT32 |
| 511 | T1133 | External Remote Services | Persistence|Initial Access | Dragonfly|TeamTNT|Leviathan|APT28|APT29|Operation Wocao|Wizard Spider|Kimsuky|GOLD SOUTHFIELD|Chimera|Sandworm Team|APT41|GALLIUM|TEMP.Veles|Night Dragon|Ke3chang|OilRig|Dragonfly 2.0|FIN5|Threat Group-3390|APT18 |
| 512 | T1132 | Data Encoding | Command And Control | no |
| 513 | T1129 | Shared Modules | Execution | no |
| 514 | T1127 | Trusted Developer Utilities Proxy Execution | Defense Evasion | no |
| 515 | T1125 | Video Capture | Collection | Silence|FIN7 |
| 516 | T1124 | System Time Discovery | Discovery | Darkhotel|ZIRCONIUM|Higaisa|Sidewinder|Chimera|Operation Wocao|The White Company|Lazarus Group|BRONZE BUTLER|Turla |
| 517 | T1123 | Audio Capture | Collection | APT37 |
| 518 | T1120 | Peripheral Device Discovery | Discovery | OilRig|BackdoorDiplomacy|Operation Wocao|Turla|APT37|Gamaredon Group|Equation|APT28 |
| 519 | T1119 | Automated Collection | Collection | Ke3chang|Confucius|Mustang Panda|Sidewinder|Chimera|menuPass|Operation Wocao|Gamaredon Group|Tropic Trooper|Frankenstein|APT1|APT28|Patchwork|OilRig|FIN5|Threat Group-3390|FIN6 |
| 520 | T1115 | Clipboard Data | Collection | Operation Wocao|APT39|APT38 |
| 521 | T1114 | Email Collection | Collection | Magic Hound|Silent Librarian |
| 522 | T1113 | Screen Capture | Collection | Dragonfly|GOLD SOUTHFIELD|Gamaredon Group|APT39|Silence|MuddyWater|Dragonfly 2.0|OilRig|Dark Caracal|FIN7|BRONZE BUTLER|Magic Hound|Group5|APT28 |
| 523 | T1112 | Modify Registry | Defense Evasion | Dragonfly|Operation Wocao|Kimsuky|Gamaredon Group|Blue Mockingbird|Wizard Spider|Silence|APT41|Turla|APT32|APT38|Patchwork|Gorgon Group|Threat Group-3390|Dragonfly 2.0|APT19|Honeybee|FIN8 |
| 524 | T1111 | Two-Factor Authentication Interception | Credential Access | Kimsuky|Chimera|Operation Wocao |
| 525 | T1110 | Brute Force | Credential Access | Lazarus Group|Dragonfly|APT38|APT28|Fox Kitten|DarkVishnya|APT39|OilRig|FIN5|Turla |
| 526 | T1106 | Native API | Execution | BlackTech|Lazarus Group|APT38|Higaisa|menuPass|Operation Wocao|Chimera|Gamaredon Group|Tropic Trooper|Sharpshooter|Turla|Silence|APT37|Gorgon Group |
| 527 | T1105 | Ingress Tool Transfer | Command And Control | LazyScripter|Ke3chang|Aquatic Panda|Winnti Group|Confucius|Dragonfly|TeamTNT|Nomadic Octopus|IndigoZebra|Andariel|BackdoorDiplomacy|Tonto Team|HAFNIUM|APT29|Ajax Security Team|Mustang Panda|Windshift|Darkhotel|ZIRCONIUM|TA551|Volatile Cedar|Indrik Spider|Evilnum|Sidewinder|Fox Kitten|Kimsuky|Operation Wocao|Chimera|Sandworm Team|Whitefly|Rocke|APT39|Tropic Trooper|Sharpshooter|Molerats|Frankenstein|Silence|APT-C-36|APT41|GALLIUM|TA505|WIRTE|APT33|MuddyWater|APT18|APT38|Rancor|Gorgon Group|OilRig|Turla|Cobalt Group|Dragonfly 2.0|FIN8|PLATINUM|APT37|Elderwood|Leviathan|APT32|Magic Hound|BRONZE BUTLER|APT3|menuPass|FIN7|Gamaredon Group|Patchwork|Lazarus Group|Threat Group-3390|APT28 |
| 528 | T1104 | Multi-Stage Channels | Command And Control | Lazarus Group|APT41|MuddyWater|APT3 |
| 529 | T1102 | Web Service | Command And Control | Mustang Panda|LazyScripter|TeamTNT|FIN8|Fox Kitten|Turla|APT32|Gamaredon Group|Rocke|Inception|FIN6 |
| 530 | T1098 | Account Manipulation | Persistence | Kimsuky|Dragonfly|Sandworm Team|APT3|Dragonfly 2.0|Lazarus Group |
| 531 | T1095 | Non-Application Layer Protocol | Command And Control | BackdoorDiplomacy|HAFNIUM|Operation Wocao|FIN6|APT29|PLATINUM|APT3 |
| 532 | T1092 | Communication Through Removable Media | Command And Control | APT28 |
| 533 | T1091 | Replication Through Removable Media | Lateral Movement|Initial Access | FIN7|Mustang Panda|Tropic Trooper|Darkhotel|APT28 |
| 534 | T1090 | Proxy | Command And Control | Windigo|Fox Kitten|Operation Wocao|Sandworm Team|Blue Mockingbird|APT41|Turla |
| 535 | T1087 | Account Discovery | Discovery | APT29 |
| 536 | T1083 | File and Directory Discovery | Discovery | Winnti Group|Confucius|Dragonfly|APT38|APT29|Mustang Panda|Darkhotel|Windigo|Sidewinder|Chimera|Fox Kitten|menuPass|APT39|Sandworm Team|Operation Wocao|Gamaredon Group|Tropic Trooper|Inception|APT41|Kimsuky|APT32|MuddyWater|APT18|Leafminer|Honeybee|Dark Caracal|Dragonfly 2.0|APT3|Sowbug|Magic Hound|BRONZE BUTLER|APT28|Patchwork|Lazarus Group|Dust Storm|admin@338|Turla|Ke3chang |
| 537 | T1082 | System Information Discovery | Discovery | Aquatic Panda|Confucius|TeamTNT|APT38|APT29|Mustang Panda|Windshift|ZIRCONIUM|Higaisa|Windigo|Sidewinder|Chimera|Operation Wocao|Wizard Spider|Rocke|Sandworm Team|Blue Mockingbird|Tropic Trooper|Frankenstein|Inception|Kimsuky|Darkhotel|MuddyWater|APT18|APT32|APT37|Honeybee|APT19|Magic Hound|Sowbug|OilRig|APT3|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|admin@338|Turla|Ke3chang |
| 538 | T1080 | Taint Shared Content | Lateral Movement | Gamaredon Group|BRONZE BUTLER|Darkhotel |
| 539 | T1078 | Valid Accounts | Defense Evasion|Persistence|Privilege Escalation|Initial Access | Ke3chang|Lazarus Group|Axiom|Dragonfly|FIN7|Leviathan|APT29|Silent Librarian|Fox Kitten|Operation Wocao|Chimera|Sandworm Team|Wizard Spider|Silence|APT41|GALLIUM|TEMP.Veles|APT39|FIN4|Night Dragon|Dragonfly 2.0|FIN8|APT33|FIN5|OilRig|APT28|menuPass|FIN10|Suckfly|FIN6|Threat Group-3390|APT18|PittyTiger|Carbanak |
| 540 | T1074 | Data Staged | Collection | Wizard Spider |
| 541 | T1072 | Software Deployment Tools | Execution|Lateral Movement | Silence|APT32|Threat Group-1314 |
| 542 | T1071 | Application Layer Protocol | Command And Control | Dragonfly|TeamTNT|Rocke|Magic Hound|Dragonfly 2.0 |
| 543 | T1070 | Indicator Removal on Host | Defense Evasion | Lazarus Group|APT29 |
| 544 | T1069 | Permission Groups Discovery | Discovery | APT29|TA505|APT3 |
| 545 | T1068 | Exploitation for Privilege Escalation | Privilege Escalation | APT29|Tonto Team|ZIRCONIUM|Turla|Whitefly|APT33|Cobalt Group|PLATINUM|FIN8|APT32|Threat Group-3390|FIN6|APT28 |
| 546 | T1059 | Command and Scripting Interpreter | Execution | Dragonfly|APT37|Windigo|Fox Kitten|APT32|Whitefly|APT39|Dragonfly 2.0|FIN7|APT19|OilRig|FIN5|Stealth Falcon|FIN6|Ke3chang |
| 547 | T1057 | Process Discovery | Discovery | Gamaredon Group|Kimsuky|TeamTNT|Andariel|APT29|Mustang Panda|Windshift|Higaisa|Sidewinder|Chimera|Operation Wocao|Rocke|Frankenstein|Inception|Darkhotel|MuddyWater|APT1|APT38|Tropic Trooper|APT37|Honeybee|OilRig|APT3|Magic Hound|APT28|Winnti Group|Stealth Falcon|Poseidon Group|Lazarus Group|Molerats|Turla|Deep Panda|Ke3chang |
| 548 | T1056 | Input Capture | Collection|Credential Access | APT39 |
| 549 | T1055 | Process Injection | Defense Evasion|Privilege Escalation | Operation Wocao|APT32|Sharpshooter|Silence|APT41|Kimsuky|Cobalt Group|Turla|APT37|Honeybee|PLATINUM |
| 550 | T1053 | Scheduled Task/Job | Execution|Persistence|Privilege Escalation | no |
| 551 | T1052 | Exfiltration Over Physical Medium | Exfiltration | no |
| 552 | T1049 | System Network Connections Discovery | Discovery | Lazarus Group|TeamTNT|Andariel|BackdoorDiplomacy|Mustang Panda|MuddyWater|Chimera|Sandworm Team|Operation Wocao|Tropic Trooper|APT41|APT38|GALLIUM|APT32|APT1|OilRig|APT3|menuPass|Threat Group-3390|Poseidon Group|admin@338|Turla|Ke3chang |
| 553 | T1048 | Exfiltration Over Alternative Protocol | Exfiltration | no |
| 554 | T1047 | Windows Management Instrumentation | Execution | Gamaredon Group|Sandworm Team|FIN7|Indrik Spider|Naikon|Mustang Panda|Windshift|Operation Wocao|Chimera|Blue Mockingbird|Wizard Spider|Frankenstein|APT41|FIN6|GALLIUM|APT32|MuddyWater|Threat Group-3390|OilRig|FIN8|Leviathan|menuPass|Stealth Falcon|Lazarus Group|APT29|Deep Panda |
| 555 | T1046 | Network Service Scanning | Discovery | BlackTech|Lazarus Group|TeamTNT|BackdoorDiplomacy|Naikon|CostaRicto|Chimera|Fox Kitten|Operation Wocao|Rocke|DarkVishnya|APT41|Tropic Trooper|APT39|APT32|OilRig|Cobalt Group|Leafminer|menuPass|Suckfly|FIN6|Threat Group-3390 |
| 556 | T1041 | Exfiltration Over C2 Channel | Exfiltration | Confucius|Leviathan|ZIRCONIUM|Higaisa|Chimera|APT39|Operation Wocao|Sandworm Team|MuddyWater|Wizard Spider|Frankenstein|Kimsuky|GALLIUM|APT32|APT3|Gamaredon Group|Stealth Falcon|Lazarus Group|Ke3chang |
| 557 | T1040 | Network Sniffing | Credential Access|Discovery | Kimsuky|Sandworm Team|DarkVishnya|APT33|APT28 |
| 558 | T1039 | Data from Network Shared Drive | Collection | APT28|Chimera|Fox Kitten|Gamaredon Group|BRONZE BUTLER|Sowbug|menuPass |
| 559 | T1037 | Boot or Logon Initialization Scripts | Persistence|Privilege Escalation | Rocke |
| 560 | T1036 | Masquerading | Defense Evasion | Kimsuky|Lazarus Group|Dragonfly|LazyScripter|APT28|Nomadic Octopus|OilRig|APT29|ZIRCONIUM|TA551|Windshift|APT32|BRONZE BUTLER|menuPass|PLATINUM|Dragonfly 2.0 |
| 561 | T1033 | System Owner/User Discovery | Discovery | Threat Group-3390|Ke3chang|Dragonfly|APT38|Windshift|ZIRCONIUM|Sidewinder|Chimera|Sandworm Team|Operation Wocao|Wizard Spider|Frankenstein|APT41|GALLIUM|Tropic Trooper|APT39|MuddyWater|APT37|Dragonfly 2.0|APT19|APT32|Magic Hound|OilRig|FIN10|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|APT3 |
| 562 | T1030 | Data Transfer Size Limits | Exfiltration | APT28|Threat Group-3390 |
| 563 | T1029 | Scheduled Transfer | Exfiltration | Higaisa |
| 564 | T1027 | Obfuscated Files or Information | Defense Evasion | Aquatic Panda|Ke3chang|LazyScripter|TeamTNT|BackdoorDiplomacy|Transparent Tribe|APT39|Mustang Panda|Windshift|TA551|Higaisa|Sidewinder|Fox Kitten|GOLD SOUTHFIELD|Operation Wocao|Kimsuky|FIN6|Chimera|Gamaredon Group|Rocke|Sandworm Team|Blue Mockingbird|Whitefly|Molerats|Wizard Spider|Mofang|Frankenstein|Inception|APT-C-36|APT41|GALLIUM|Turla|TA505|Silence|APT33|Night Dragon|Darkhotel|Gallmaker|APT29|APT18|Tropic Trooper|Patchwork|menuPass|APT37|Threat Group-3390|Cobalt Group|Dark Caracal|Leafminer|Honeybee|APT19|BlackOasis|Leviathan|FIN8|MuddyWater|FIN7|Elderwood|OilRig|Magic Hound|APT3|APT32|Group5|Dust Storm|Lazarus Group|Putter Panda|APT28 |
| 565 | T1025 | Data from Removable Media | Collection | Turla|Gamaredon Group|APT28 |
| 566 | T1021 | Remote Services | Lateral Movement | no |
| 567 | T1020 | Automated Exfiltration | Exfiltration | Ke3chang|Sidewinder|Gamaredon Group|Tropic Trooper|Frankenstein|Honeybee |
| 568 | T1018 | Remote System Discovery | Discovery | Dragonfly|Indrik Spider|Naikon|APT29|Chimera|Fox Kitten|Operation Wocao|Sandworm Team|Rocke|Wizard Spider|Silence|GALLIUM|APT39|APT32|Deep Panda|Ke3chang|Threat Group-3390|Dragonfly 2.0|Leafminer|FIN8|FIN5|APT3|BRONZE BUTLER|menuPass|FIN6|Turla |
| 569 | T1016 | System Network Configuration Discovery | Discovery | Kimsuky|Dragonfly|TeamTNT|ZIRCONIUM|Mustang Panda|Higaisa|Sidewinder|Chimera|Operation Wocao|Wizard Spider|Sandworm Team|Tropic Trooper|Frankenstein|APT41|GALLIUM|APT32|Darkhotel|MuddyWater|APT1|APT19|Dragonfly 2.0|Magic Hound|OilRig|Threat Group-3390|menuPass|Stealth Falcon|Lazarus Group|APT3|Naikon|admin@338|Turla|Ke3chang |
| 570 | T1014 | Rootkit | Defense Evasion | TeamTNT|Rocke|APT41|APT28|Winnti Group |
| 571 | T1012 | Query Registry | Discovery | Kimsuky|Dragonfly|ZIRCONIUM|Chimera|Fox Kitten|APT39|Operation Wocao|APT32|Dragonfly 2.0|Threat Group-3390|OilRig|Stealth Falcon|Lazarus Group|Turla |
| 572 | T1011 | Exfiltration Over Other Network Medium | Exfiltration | no |
| 573 | T1010 | Application Window Discovery | Discovery | Lazarus Group |
| 574 | T1008 | Fallback Channels | Command And Control | FIN7|APT41|OilRig|Lazarus Group |
| 575 | T1007 | System Service Discovery | Discovery | Kimsuky|Aquatic Panda|Indrik Spider|Chimera|Operation Wocao|BRONZE BUTLER|APT1|OilRig|Poseidon Group|admin@338|Turla|Ke3chang |
| 576 | T1006 | Direct Volume Access | Defense Evasion | no |
| 577 | T1005 | Data from Local System | Collection | Axiom|Dragonfly|FIN7|APT41|APT38|Andariel|APT29|Windigo|Fox Kitten|Sandworm Team|Operation Wocao|FIN6|Gamaredon Group|APT39|Frankenstein|Inception|Kimsuky|GALLIUM|Turla|menuPass|Dark Caracal|Dragonfly 2.0|Honeybee|APT37|APT28|APT3|BRONZE BUTLER|Patchwork|Stealth Falcon|Lazarus Group|Dust Storm|Threat Group-3390|APT1|Ke3chang |
| 578 | T1003 | OS Credential Dumping | Credential Access | Tonto Team|APT39|Frankenstein|APT32|APT28|Leviathan|Sowbug|Suckfly|Poseidon Group|Axiom |
| 579 | T1001 | Data Obfuscation | Command And Control | Operation Wocao|Axiom |