mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
39 KiB
39 KiB
| 1 | mitre_id | technique | tactics | groups |
|---|---|---|---|---|
| 2 | T1205.001 | Port Knocking | Defense Evasion|Persistence|Command And Control | no |
| 3 | T1564.006 | Run Virtual Instance | Defense Evasion | no |
| 4 | T1564.005 | Hidden File System | Defense Evasion | Strider|Equation |
| 5 | T1556.003 | Pluggable Authentication Modules | Credential Access|Defense Evasion | no |
| 6 | T1574.012 | COR_PROFILER | Persistence|Privilege Escalation|Defense Evasion | Blue Mockingbird |
| 7 | T1562.007 | Disable or Modify Cloud Firewall | Defense Evasion | no |
| 8 | T1098.004 | SSH Authorized Keys | Persistence | no |
| 9 | T1480.001 | Environmental Keying | Defense Evasion | APT41|Equation |
| 10 | T1059.007 | JavaScript/JScript | Execution | APT32|FIN7|Cobalt Group|Molerats|TA505|Silence|Leafminer |
| 11 | T1578.004 | Revert Cloud Instance | Defense Evasion | no |
| 12 | T1578.003 | Delete Cloud Instance | Defense Evasion | no |
| 13 | T1578.001 | Create Snapshot | Defense Evasion | no |
| 14 | T1578.002 | Create Cloud Instance | Defense Evasion | no |
| 15 | T1127.001 | MSBuild | Defense Evasion | Frankenstein |
| 16 | T1027.005 | Indicator Removal from Tools | Defense Evasion | Soft Cell|TEMP.Veles|Patchwork|APT3|Turla|OilRig|Deep Panda |
| 17 | T1562.006 | Indicator Blocking | Defense Evasion | no |
| 18 | T1573.002 | Asymmetric Cryptography | Command And Control | Tropic Trooper|Cobalt Group|OilRig|FIN8|FIN6 |
| 19 | T1573.001 | Symmetric Cryptography | Command And Control | Frankenstein|Inception|APT28|APT33|BRONZE BUTLER|Stealth Falcon|Lazarus Group |
| 20 | T1573 | Encrypted Channel | Command And Control | Tropic Trooper |
| 21 | T1027.004 | Compile After Delivery | Defense Evasion | Gamaredon Group|Rocke|MuddyWater |
| 22 | T1574.004 | Dylib Hijacking | Persistence|Privilege Escalation|Defense Evasion | no |
| 23 | T1546.015 | Component Object Model Hijacking | Privilege Escalation|Persistence | APT28 |
| 24 | T1071.004 | DNS | Command And Control | APT39|Tropic Trooper|OilRig|Ke3chang|Cobalt Group|APT18|APT41|FIN7 |
| 25 | T1071.003 | Mail Protocols | Command And Control | APT32|SilverTerrier|APT28 |
| 26 | T1071.002 | File Transfer Protocols | Command And Control | APT41|SilverTerrier|Machete|Honeybee |
| 27 | T1071.001 | Web Protocols | Command And Control | Sandworm Team|TA505|Rocke|APT39|Tropic Trooper|MuddyWater|Wizard Spider|Inception|APT41|SilverTerrier|Machete|APT28|WIRTE|APT33|FIN4|Night Dragon|APT18|APT38|Cobalt Group|APT19|Threat Group-3390|Rancor|Orangeworm|APT37|Ke3chang|Dark Caracal|Turla|Lazarus Group|BRONZE BUTLER|APT32|OilRig|Magic Hound|Gamaredon Group|Stealth Falcon |
| 28 | T1572 | Protocol Tunneling | Command And Control | OilRig|Cobalt Group|FIN6 |
| 29 | T1048.003 | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | Exfiltration | APT32|APT33|Thrip|FIN8|OilRig|Lazarus Group |
| 30 | T1048.002 | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol | Exfiltration | no |
| 31 | T1048.001 | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Exfiltration | no |
| 32 | T1001.003 | Protocol Impersonation | Command And Control | Lazarus Group |
| 33 | T1001.002 | Steganography | Command And Control | Axiom |
| 34 | T1001.001 | Junk Data | Command And Control | APT28 |
| 35 | T1132.002 | Non-Standard Encoding | Command And Control | no |
| 36 | T1132.001 | Standard Encoding | Command And Control | Sandworm Team|Tropic Trooper|MuddyWater|APT33|APT19|Lazarus Group|BRONZE BUTLER|Patchwork |
| 37 | T1090.004 | Domain Fronting | Command And Control | APT29 |
| 38 | T1090.003 | Multi-hop Proxy | Command And Control | Inception|FIN4|APT29 |
| 39 | T1090.002 | External Proxy | Command And Control | APT39|Silence|Soft Cell|MuddyWater|APT3|FIN5|Lazarus Group|menuPass|APT28 |
| 40 | T1090.001 | Internal Proxy | Command And Control | APT39|Strider |
| 41 | T1102.003 | One-Way Communication | Command And Control | Leviathan |
| 42 | T1102.002 | Bidirectional Communication | Command And Control | Sandworm Team|APT39|APT12|Turla|FIN7|APT37|Magic Hound|Carbanak |
| 43 | T1102.001 | Dead Drop Resolver | Command And Control | Rocke|APT41|BRONZE BUTLER|RTM|Patchwork |
| 44 | T1571 | Non-Standard Port | Command And Control | Sandworm Team|Rocke|DarkVishnya|Silence|APT-C-36|Magic Hound|APT33|APT32|TEMP.Veles|Lazarus Group|FIN7 |
| 45 | T1074.002 | Remote Data Staging | Collection | Threat Group-3390|menuPass|FIN6|Night Dragon|FIN8 |
| 46 | T1074.001 | Local Data Staging | Collection | Machete|Soft Cell|TEMP.Veles|Patchwork|Dragonfly 2.0|Honeybee|Leviathan|APT3|FIN5|menuPass|FIN6|Lazarus Group|Threat Group-3390|APT28 |
| 47 | T1078.004 | Cloud Accounts | Defense Evasion|Persistence|Privilege Escalation|Initial Access | APT33 |
| 48 | T1564.004 | NTFS File Attributes | Defense Evasion | APT32 |
| 49 | T1564.003 | Hidden Window | Defense Evasion | Gorgon Group|Deep Panda|DarkHydrus|CopyKittens|APT19|APT32|APT28|APT3|Magic Hound |
| 50 | T1078.003 | Local Accounts | Defense Evasion|Persistence|Privilege Escalation|Initial Access | Tropic Trooper|FIN10|Stolen Pencil|APT32 |
| 51 | T1078.002 | Domain Accounts | Defense Evasion|Persistence|Privilege Escalation|Initial Access | TA505|APT3|Threat Group-1314 |
| 52 | T1078.001 | Default Accounts | Defense Evasion|Persistence|Privilege Escalation|Initial Access | no |
| 53 | T1564.002 | Hidden Users | Defense Evasion | no |
| 54 | T1574.006 | LD_PRELOAD | Persistence|Privilege Escalation|Defense Evasion | Rocke |
| 55 | T1574.002 | DLL Side-Loading | Persistence|Privilege Escalation|Defense Evasion | BRONZE BUTLER|Naikon|APT41|Soft Cell|Tropic Trooper|Patchwork|APT19|APT32|APT3|menuPass|Threat Group-3390 |
| 56 | T1574.001 | DLL Search Order Hijacking | Persistence|Privilege Escalation|Defense Evasion | Whitefly|RTM|Threat Group-3390|menuPass |
| 57 | T1574.008 | Path Interception by Search Order Hijacking | Persistence|Privilege Escalation|Defense Evasion | no |
| 58 | T1574.007 | Path Interception by PATH Environment Variable | Persistence|Privilege Escalation|Defense Evasion | no |
| 59 | T1574.009 | Path Interception by Unquoted Path | Persistence|Privilege Escalation|Defense Evasion | no |
| 60 | T1574.011 | Services Registry Permissions Weakness | Persistence|Privilege Escalation|Defense Evasion | no |
| 61 | T1574.005 | Executable Installer File Permissions Weakness | Persistence|Privilege Escalation|Defense Evasion | no |
| 62 | T1574.010 | Services File Permissions Weakness | Persistence|Privilege Escalation|Defense Evasion | no |
| 63 | T1574 | Hijack Execution Flow | Persistence|Privilege Escalation|Defense Evasion | no |
| 64 | T1069.001 | Local Groups | Discovery | Turla|OilRig|admin@338 |
| 65 | T1570 | Lateral Tool Transfer | Lateral Movement | APT32|Wizard Spider|Turla|FIN10 |
| 66 | T1568.003 | DNS Calculation | Command And Control | APT12 |
| 67 | T1204.002 | Malicious File | Execution | Magic Hound|Windshift|APT33|Sandworm Team|Naikon|Whitefly|Tropic Trooper|Gamaredon Group|Sharpshooter|Molerats|Wizard Spider|Mofang|Frankenstein|RTM|Inception|BlackTech|APT-C-36|Machete|admin@338|APT12|TA505|Silence|The White Company|APT39|FIN4|Darkhotel|Gallmaker|APT19|Dragonfly 2.0|BRONZE BUTLER|Cobalt Group|DarkHydrus|Gorgon Group|Patchwork|OilRig|Dark Caracal|MuddyWater|Lazarus Group|FIN7|APT32|Rancor|APT37|FIN8|APT28|Elderwood|TA459|APT29|Leviathan|menuPass|PLATINUM |
| 68 | T1204.001 | Malicious Link | Execution | Patchwork|Windshift|APT32|Molerats|Mofang|BlackTech|TA505|OilRig|Machete|Leviathan|FIN8|FIN4|Elderwood|Dragonfly 2.0|Cobalt Group|APT39|Night Dragon|APT33|Turla |
| 69 | T1195.003 | Compromise Hardware Supply Chain | Initial Access | no |
| 70 | T1195.002 | Compromise Software Supply Chain | Initial Access | Sandworm Team|APT41 |
| 71 | T1195.001 | Compromise Software Dependencies and Development Tools | Initial Access | no |
| 72 | T1568.001 | Fast Flux DNS | Command And Control | TA505 |
| 73 | T1052.001 | Exfiltration over USB | Exfiltration | Tropic Trooper |
| 74 | T1569.002 | Service Execution | Execution | Blue Mockingbird|APT39|APT41|Silence|FIN6|APT32|Honeybee|Ke3chang |
| 75 | T1569.001 | Launchctl | Execution | no |
| 76 | T1569 | System Services | Execution | no |
| 77 | T1568.002 | Domain Generation Algorithms | Command And Control | APT41 |
| 78 | T1568 | Dynamic Resolution | Command And Control | no |
| 79 | T1011.001 | Exfiltration Over Bluetooth | Exfiltration | no |
| 80 | T1567.002 | Exfiltration to Cloud Storage | Exfiltration | Leviathan|Turla |
| 81 | T1567.001 | Exfiltration to Code Repository | Exfiltration | no |
| 82 | T1059.006 | Python | Execution | Rocke|BRONZE BUTLER|APT39|Dragonfly 2.0|Machete |
| 83 | T1059.005 | Visual Basic | Execution | APT33|Sandworm Team|Gamaredon Group|Sharpshooter|Molerats|Frankenstein|Inception|APT-C-36|Rancor|Patchwork|MuddyWater|Honeybee|FIN7|APT37|BRONZE BUTLER|APT32|Turla|TA505|Silence|WIRTE|FIN4|Cobalt Group|Gorgon Group|Leviathan|TA459|Magic Hound |
| 84 | T1059.004 | Unix Shell | Execution | Rocke|APT41 |
| 85 | T1059.003 | Windows Command Shell | Execution | TA505|Blue Mockingbird|Tropic Trooper|Frankenstein|OilRig|Lazarus Group|Honeybee|Cobalt Group|FIN7|APT41|Soft Cell|Turla|Silence|APT32|APT39|Darkhotel|MuddyWater|APT18|APT38|Dark Caracal|Gorgon Group|Dragonfly 2.0|Rancor|Ke3chang|APT37|Leviathan|FIN8|APT28|Magic Hound|Sowbug|BRONZE BUTLER|FIN10|Threat Group-3390|menuPass|Gamaredon Group|Suckfly|Patchwork|Threat Group-1314|APT3|admin@338|APT1 |
| 86 | T1059.002 | AppleScript | Execution | no |
| 87 | T1059.001 | PowerShell | Execution | Blue Mockingbird|APT39|DarkVishnya|Molerats|Wizard Spider|Frankenstein|Inception|Silence|APT41|Kimsuky|Soft Cell|TA505|WIRTE|TEMP.Veles|APT33|Gallmaker|Turla|APT19|DarkHydrus|APT28|Thrip|Gorgon Group|Cobalt Group|Dragonfly 2.0|Leviathan|TA459|FIN8|MuddyWater|Magic Hound|OilRig|BRONZE BUTLER|CopyKittens|APT32|FIN7|FIN10|Threat Group-3390|menuPass|Patchwork|Stealth Falcon|FIN6|Poseidon Group|APT3|APT29|Deep Panda |
| 88 | T1567 | Exfiltration Over Web Service | Exfiltration | no |
| 89 | T1497.003 | Time Based Evasion | Defense Evasion|Discovery | no |
| 90 | T1497.002 | User Activity Based Checks | Defense Evasion|Discovery | FIN7 |
| 91 | T1497.001 | System Checks | Defense Evasion|Discovery | Frankenstein |
| 92 | T1498.002 | Reflection Amplification | Impact | no |
| 93 | T1498.001 | Direct Network Flood | Impact | no |
| 94 | T1566.003 | Spearphishing via Service | Initial Access | Magic Hound|Windshift|FIN6|OilRig|Dark Caracal |
| 95 | T1566.002 | Spearphishing Link | Initial Access | Windshift|Molerats|Mofang|BlackTech|Machete|Kimsuky|TA505|Stolen Pencil|APT39|FIN4|APT32|Night Dragon|Turla|APT28|Cobalt Group|Dragonfly 2.0|OilRig|APT33|Elderwood|Leviathan|Magic Hound|Patchwork|APT29|FIN8 |
| 96 | T1566.001 | Spearphishing Attachment | Initial Access | Magic Hound|Windshift|APT33|Sandworm Team|Naikon|Gamaredon Group|Sharpshooter|Molerats|Mofang|Wizard Spider|RTM|Frankenstein|Inception|BlackTech|APT-C-36|APT41|Machete|admin@338|Kimsuky|APT12|TA505|Silence|The White Company|APT39|FIN4|Darkhotel|Gallmaker|Tropic Trooper|Turla|Gorgon Group|Rancor|DarkHydrus|Cobalt Group|FIN7|OilRig|Lazarus Group|APT19|Dragonfly 2.0|BRONZE BUTLER|APT32|FIN8|MuddyWater|APT28|TA459|Leviathan|Patchwork|PLATINUM|Elderwood|APT29|APT37|menuPass |
| 97 | T1566 | Phishing | Initial Access | no |
| 98 | T1565.003 | Runtime Data Manipulation | Impact | APT38 |
| 99 | T1565.002 | Transmitted Data Manipulation | Impact | APT38 |
| 100 | T1565.001 | Stored Data Manipulation | Impact | FIN4|APT38 |
| 101 | T1565 | Data Manipulation | Impact | no |
| 102 | T1564.001 | Hidden Files and Directories | Defense Evasion | Rocke|APT32|Tropic Trooper|APT28|Lazarus Group |
| 103 | T1564 | Hide Artifacts | Defense Evasion | no |
| 104 | T1563.002 | RDP Hijacking | Lateral Movement | no |
| 105 | T1563.001 | SSH Hijacking | Lateral Movement | no |
| 106 | T1563 | Remote Service Session Hijacking | Lateral Movement | no |
| 107 | T1518.001 | Security Software Discovery | Discovery | Turla|Rocke|Frankenstein|The White Company|Cobalt Group|Darkhotel|MuddyWater|Tropic Trooper|FIN8|Patchwork|Naikon |
| 108 | T1069.003 | Cloud Groups | Discovery | no |
| 109 | T1069.002 | Domain Groups | Discovery | Turla|Wizard Spider|Inception|OilRig|FIN6|Dragonfly 2.0|Ke3chang |
| 110 | T1087.004 | Cloud Account | Discovery | no |
| 111 | T1087.003 | Email Account | Discovery | Sandworm Team|TA505 |
| 112 | T1087.002 | Domain Account | Discovery | Turla|Sandworm Team|Dragonfly 2.0|OilRig|BRONZE BUTLER|menuPass|FIN6|Poseidon Group|Ke3chang |
| 113 | T1087.001 | Local Account | Discovery | Turla|Poseidon Group|OilRig|Ke3chang|APT32|APT1|Threat Group-3390|APT3|admin@338 |
| 114 | T1553.004 | Install Root Certificate | Defense Evasion | no |
| 115 | T1562.004 | Disable or Modify System Firewall | Defense Evasion | Rocke|Lazarus Group|Kimsuky|Dragonfly 2.0|Carbanak |
| 116 | T1562.003 | HISTCONTROL | Defense Evasion | no |
| 117 | T1562.002 | Disable Windows Event Logging | Defense Evasion | Threat Group-3390 |
| 118 | T1562.001 | Disable or Modify Tools | Defense Evasion | Gamaredon Group|BRONZE BUTLER|Rocke|Kimsuky|Turla|Night Dragon|Gorgon Group|Lazarus Group|Putter Panda |
| 119 | T1562 | Impair Defenses | Defense Evasion | no |
| 120 | T1003.004 | LSA Secrets | Credential Access | OilRig|MuddyWater|menuPass|Leafminer|Ke3chang|Dragonfly 2.0|APT33|Threat Group-3390 |
| 121 | T1003.005 | Cached Domain Credentials | Credential Access | OilRig|MuddyWater|Leafminer|APT33 |
| 122 | T1561.002 | Disk Structure Wipe | Impact | Sandworm Team|Lazarus Group|APT38|APT37 |
| 123 | T1561.001 | Disk Content Wipe | Impact | Lazarus Group |
| 124 | T1561 | Disk Wipe | Impact | no |
| 125 | T1560.003 | Archive via Custom Method | Collection | Lazarus Group|Kimsuky|CopyKittens|FIN6 |
| 126 | T1560.002 | Archive via Library | Collection | Lazarus Group|Threat Group-3390 |
| 127 | T1560.001 | Archive via Utility | Collection | APT41|Soft Cell|Turla|Gallmaker|APT33|APT39|MuddyWater|Magic Hound|FIN8|BRONZE BUTLER|CopyKittens|APT3|Sowbug|menuPass|APT1|Ke3chang |
| 128 | T1560 | Archive Collected Data | Collection | menuPass|APT32|Honeybee|Patchwork|APT28|Dragonfly 2.0|FIN6|Lazarus Group|Ke3chang |
| 129 | T1499.004 | Application or System Exploitation | Impact | no |
| 130 | T1499.003 | Application Exhaustion Flood | Impact | no |
| 131 | T1499.002 | Service Exhaustion Flood | Impact | no |
| 132 | T1499.001 | OS Exhaustion Flood | Impact | no |
| 133 | T1491.002 | External Defacement | Impact | no |
| 134 | T1491.001 | Internal Defacement | Impact | Lazarus Group |
| 135 | T1114.003 | Email Forwarding Rule | Collection | no |
| 136 | T1114.002 | Remote Email Collection | Collection | APT1|FIN4|APT28|Dragonfly 2.0|Ke3chang|Leafminer |
| 137 | T1114.001 | Local Email Collection | Collection | Magic Hound|APT1 |
| 138 | T1134.005 | SID-History Injection | Defense Evasion|Privilege Escalation | no |
| 139 | T1134.004 | Parent PID Spoofing | Defense Evasion|Privilege Escalation | no |
| 140 | T1134.003 | Make and Impersonate Token | Defense Evasion|Privilege Escalation | no |
| 141 | T1134.002 | Create Process with Token | Defense Evasion|Privilege Escalation | Turla|Lazarus Group |
| 142 | T1134.001 | Token Impersonation/Theft | Defense Evasion|Privilege Escalation | APT28 |
| 143 | T1213.002 | Sharepoint | Collection | Ke3chang|APT28 |
| 144 | T1213.001 | Confluence | Collection | no |
| 145 | T1555.003 | Credentials from Web Browsers | Credential Access | Magic Hound|Sandworm Team|Inception|Stealth Falcon|OilRig|Leafminer|APT33|APT3|Kimsuky|TA505|Stolen Pencil|MuddyWater|APT37|Patchwork|Molerats |
| 146 | T1555.002 | Securityd Memory | Credential Access | no |
| 147 | T1555.001 | Keychain | Credential Access | no |
| 148 | T1559.002 | Dynamic Data Exchange | Execution | Sharpshooter|TA505|MuddyWater|Gallmaker|Patchwork|Cobalt Group|APT37|APT28|FIN7 |
| 149 | T1559.001 | Component Object Model | Execution | Gamaredon Group|MuddyWater |
| 150 | T1559 | Inter-Process Communication | Execution | no |
| 151 | T1558.002 | Silver Ticket | Credential Access | no |
| 152 | T1558.001 | Golden Ticket | Credential Access | Ke3chang |
| 153 | T1558 | Steal or Forge Kerberos Tickets | Credential Access | no |
| 154 | T1557.001 | LLMNR/NBT-NS Poisoning and SMB Relay | Credential Access|Collection | no |
| 155 | T1557 | Man-in-the-Middle | Credential Access|Collection | no |
| 156 | T1556.002 | Password Filter DLL | Credential Access|Defense Evasion | Strider |
| 157 | T1556.001 | Domain Controller Authentication | Credential Access|Defense Evasion | no |
| 158 | T1556 | Modify Authentication Process | Credential Access|Defense Evasion | no |
| 159 | T1056.004 | Credential API Hooking | Collection|Credential Access | PLATINUM |
| 160 | T1056.003 | Web Portal Capture | Collection|Credential Access | no |
| 161 | T1056.002 | GUI Input Capture | Collection|Credential Access | FIN4 |
| 162 | T1056.001 | Keylogging | Collection|Credential Access | APT32|Sandworm Team|APT39|APT41|Kimsuky|menuPass|Stolen Pencil|FIN4|APT38|Ke3chang|OilRig|PLATINUM|Sowbug|Magic Hound|Group5|Lazarus Group|Threat Group-3390|APT3|Darkhotel|APT28 |
| 163 | T1555 | Credentials from Password Stores | Credential Access | APT39|OilRig|MuddyWater|Leafminer|APT33|Turla|Stealth Falcon |
| 164 | T1552.005 | Cloud Instance Metadata API | Credential Access | no |
| 165 | T1003.008 | /etc/passwd and /etc/shadow | Credential Access | no |
| 166 | T1003.007 | Proc Filesystem | Credential Access | no |
| 167 | T1003.006 | DCSync | Credential Access | no |
| 168 | T1558.003 | Kerberoasting | Credential Access | no |
| 169 | T1552.006 | Group Policy Preferences | Credential Access | APT33 |
| 170 | T1003.003 | NTDS | Credential Access | FIN6|Dragonfly 2.0 |
| 171 | T1003.002 | Security Account Manager | Credential Access | Threat Group-3390|Ke3chang|Soft Cell|Night Dragon|Dragonfly 2.0|menuPass |
| 172 | T1003.001 | LSASS Memory | Credential Access | Sandworm Team|Whitefly|Blue Mockingbird|Silence|Threat Group-3390|Leviathan|APT41|Soft Cell|TEMP.Veles|APT33|APT39|Stolen Pencil|APT32|Lazarus Group|Leafminer|Magic Hound|MuddyWater|PLATINUM|FIN8|BRONZE BUTLER|OilRig|FIN6|APT3|APT28|APT1|Ke3chang|Cleaver |
| 173 | T1110.004 | Credential Stuffing | Credential Access | no |
| 174 | T1110.003 | Password Spraying | Credential Access | APT33|Leafminer|Lazarus Group |
| 175 | T1110.002 | Password Cracking | Credential Access | APT41|Dragonfly 2.0|APT3 |
| 176 | T1110.001 | Password Guessing | Credential Access | no |
| 177 | T1021.006 | Windows Remote Management | Lateral Movement | Threat Group-3390 |
| 178 | T1021.005 | VNC | Lateral Movement | GCMAN |
| 179 | T1021.004 | SSH | Lateral Movement | Rocke|TEMP.Veles|Leviathan|APT39|OilRig|menuPass|GCMAN |
| 180 | T1021.003 | Distributed Component Object Model | Lateral Movement | no |
| 181 | T1021.002 | SMB/Windows Admin Shares | Lateral Movement | Blue Mockingbird|APT39|APT32|Orangeworm|FIN8|APT3|Lazarus Group|Threat Group-1314|Turla|Deep Panda|Ke3chang |
| 182 | T1021.001 | Remote Desktop Protocol | Lateral Movement | Blue Mockingbird|Wizard Spider|Silence|APT41|TEMP.Veles|Leviathan|APT39|Stolen Pencil|Cobalt Group|Dragonfly 2.0|FIN8|APT3|OilRig|menuPass|FIN10|Patchwork|FIN6|Lazarus Group|APT1|Axiom |
| 183 | T1554 | Compromise Client Software Binary | Persistence | no |
| 184 | T1036.006 | Space after Filename | Defense Evasion | no |
| 185 | T1036.005 | Match Legitimate Name or Location | Defense Evasion | Rocke|Sandworm Team|APT39|Blue Mockingbird|Whitefly|Tropic Trooper|Silence|APT41|menuPass|TEMP.Veles|MuddyWater|BRONZE BUTLER|Sowbug|APT32|Patchwork|Poseidon Group|admin@338|Carbanak|APT1 |
| 186 | T1036.004 | Masquerade Task or Service | Defense Evasion | Wizard Spider|APT-C-36|Carbanak|APT32|FIN6|FIN7 |
| 187 | T1036.003 | Rename System Utilities | Defense Evasion | menuPass|APT32|Soft Cell|PLATINUM |
| 188 | T1036.002 | Right-to-Left Override | Defense Evasion | BRONZE BUTLER|BlackTech|Ke3chang|Scarlet Mimic |
| 189 | T1036.001 | Invalid Code Signature | Defense Evasion | Windshift |
| 190 | T1553.003 | SIP and Trust Provider Hijacking | Defense Evasion | no |
| 191 | T1553.002 | Code Signing | Defense Evasion | Patchwork|Silence|APT41|FIN6|TA505|FIN7|Honeybee|Leviathan|APT37|CopyKittens|Winnti Group|Suckfly|Molerats|Darkhotel |
| 192 | T1553.001 | Gatekeeper Bypass | Defense Evasion | no |
| 193 | T1553 | Subvert Trust Controls | Defense Evasion | no |
| 194 | T1027.003 | Steganography | Defense Evasion | BRONZE BUTLER|Tropic Trooper|MuddyWater|APT37 |
| 195 | T1027.002 | Software Packing | Defense Evasion | TA505|Rocke|Soft Cell|The White Company|APT39|APT38|Dark Caracal|Elderwood|APT3|Patchwork|APT29|Night Dragon |
| 196 | T1027.001 | Binary Padding | Defense Evasion | Gamaredon Group|Patchwork|APT32|Leviathan|BRONZE BUTLER|Moafee |
| 197 | T1222.002 | Linux and Mac File and Directory Permissions Modification | Defense Evasion | Rocke|APT32 |
| 198 | T1222.001 | Windows File and Directory Permissions Modification | Defense Evasion | no |
| 199 | T1552.004 | Private Keys | Credential Access | Rocke |
| 200 | T1552.003 | Bash History | Credential Access | no |
| 201 | T1552.002 | Credentials in Registry | Credential Access | APT32 |
| 202 | T1552.001 | Credentials In Files | Credential Access | Leafminer|APT33|OilRig|TA505|Stolen Pencil|MuddyWater|APT3 |
| 203 | T1552 | Unsecured Credentials | Credential Access | no |
| 204 | T1216.001 | PubPrn | Defense Evasion | APT32 |
| 205 | T1070.006 | Timestomp | Defense Evasion | Rocke|TEMP.Veles|APT32|Lazarus Group|APT28 |
| 206 | T1070.005 | Network Share Connection Removal | Defense Evasion | Threat Group-3390 |
| 207 | T1070.004 | File Deletion | Defense Evasion | Sandworm Team|Rocke|Tropic Trooper|Gamaredon Group|Wizard Spider|APT41|Kimsuky|Silence|The White Company|TEMP.Veles|APT32|APT38|Patchwork|Honeybee|Cobalt Group|Dragonfly 2.0|menuPass|FIN8|OilRig|FIN5|BRONZE BUTLER|Magic Hound|APT3|FIN10|APT28|Threat Group-3390|Group5|Lazarus Group|APT18|APT29 |
| 208 | T1070.003 | Clear Command History | Defense Evasion | APT41 |
| 209 | T1550.004 | Web Session Cookie | Defense Evasion|Lateral Movement | no |
| 210 | T1550.001 | Application Access Token | Defense Evasion|Lateral Movement | APT28 |
| 211 | T1550.003 | Pass the Ticket | Defense Evasion|Lateral Movement | APT32|BRONZE BUTLER|APT29 |
| 212 | T1550.002 | Pass the Hash | Defense Evasion|Lateral Movement | Soft Cell|APT32|Night Dragon|APT28|APT1 |
| 213 | T1550 | Use Alternate Authentication Material | Defense Evasion|Lateral Movement | no |
| 214 | T1548.004 | Elevated Execution with Prompt | Privilege Escalation|Defense Evasion | no |
| 215 | T1548.003 | Sudo and Sudo Caching | Privilege Escalation|Defense Evasion | no |
| 216 | T1548.002 | Bypass User Access Control | Privilege Escalation|Defense Evasion | APT37|MuddyWater|Honeybee|Cobalt Group|Threat Group-3390|BRONZE BUTLER|Patchwork|APT29 |
| 217 | T1548.001 | Setuid and Setgid | Privilege Escalation|Defense Evasion | no |
| 218 | T1548 | Abuse Elevation Control Mechanism | Privilege Escalation|Defense Evasion | no |
| 219 | T1136.003 | Cloud Account | Persistence | no |
| 220 | T1070.002 | Clear Linux or Mac System Logs | Defense Evasion | Rocke |
| 221 | T1070.001 | Clear Windows Event Logs | Defense Evasion | APT41|APT38|Dragonfly 2.0|APT32|FIN8|FIN5|APT28 |
| 222 | T1136.002 | Domain Account | Persistence | Soft Cell |
| 223 | T1136.001 | Local Account | Persistence | APT39|APT41|Dragonfly 2.0|Leafminer|APT3 |
| 224 | T1547.011 | Plist Modification | Persistence|Privilege Escalation | no |
| 225 | T1547.010 | Port Monitors | Persistence|Privilege Escalation | no |
| 226 | T1547.009 | Shortcut Modification | Persistence|Privilege Escalation | APT39|Darkhotel|APT29|Gorgon Group|Dragonfly 2.0|Leviathan|Lazarus Group |
| 227 | T1547.008 | LSASS Driver | Persistence|Privilege Escalation | no |
| 228 | T1547.007 | Re-opened Applications | Persistence|Privilege Escalation | no |
| 229 | T1547.006 | Kernel Modules and Extensions | Persistence|Privilege Escalation | no |
| 230 | T1547.005 | Security Support Provider | Persistence|Privilege Escalation | no |
| 231 | T1547.004 | Winlogon Helper DLL | Persistence|Privilege Escalation | Tropic Trooper|Turla |
| 232 | T1547.003 | Time Providers | Persistence|Privilege Escalation | no |
| 233 | T1546.014 | Emond | Privilege Escalation|Persistence | no |
| 234 | T1546.013 | PowerShell Profile | Privilege Escalation|Persistence | Turla |
| 235 | T1546.012 | Image File Execution Options Injection | Privilege Escalation|Persistence | TEMP.Veles |
| 236 | T1218.008 | Odbcconf | Defense Evasion | Cobalt Group |
| 237 | T1546.011 | Application Shimming | Privilege Escalation|Persistence | FIN7 |
| 238 | T1547.002 | Authentication Package | Persistence|Privilege Escalation | no |
| 239 | T1546.010 | AppInit DLLs | Privilege Escalation|Persistence | no |
| 240 | T1546.009 | AppCert DLLs | Privilege Escalation|Persistence | Honeybee |
| 241 | T1218.007 | Msiexec | Defense Evasion | TA505|Rancor |
| 242 | T1546.008 | Accessibility Features | Privilege Escalation|Persistence | APT41|APT3|APT29|Deep Panda|Axiom |
| 243 | T1546.007 | Netsh Helper DLL | Privilege Escalation|Persistence | no |
| 244 | T1546.006 | LC_LOAD_DYLIB Addition | Privilege Escalation|Persistence | no |
| 245 | T1546.005 | Trap | Privilege Escalation|Persistence | no |
| 246 | T1546.004 | .bash_profile and .bashrc | Privilege Escalation|Persistence | no |
| 247 | T1546.003 | Windows Management Instrumentation Event Subscription | Privilege Escalation|Persistence | APT33|Blue Mockingbird|Turla|Leviathan|APT29 |
| 248 | T1546.002 | Screensaver | Privilege Escalation|Persistence | no |
| 249 | T1546.001 | Change Default File Association | Privilege Escalation|Persistence | Kimsuky |
| 250 | T1547.001 | Registry Run Keys / Startup Folder | Persistence|Privilege Escalation | Rocke|Tropic Trooper|Gamaredon Group|Sharpshooter|Molerats|Silence|RTM|Inception|APT41|Machete|Kimsuky|APT33|APT39|APT32|APT18|Turla|Dark Caracal|Cobalt Group|Honeybee|Threat Group-3390|Dragonfly 2.0|Gorgon Group|Ke3chang|APT19|Leviathan|MuddyWater|APT37|BRONZE BUTLER|Magic Hound|APT3|FIN10|FIN7|Patchwork|FIN6|Lazarus Group|Putter Panda|APT29|Darkhotel |
| 251 | T1218.002 | Control Panel | Defense Evasion | no |
| 252 | T1218.010 | Regsvr32 | Defense Evasion | Blue Mockingbird|Inception|WIRTE|Cobalt Group|APT19|Leviathan|APT32|Deep Panda |
| 253 | T1218.009 | Regsvcs/Regasm | Defense Evasion | no |
| 254 | T1218.005 | Mshta | Defense Evasion | Inception|Kimsuky|APT32|MuddyWater|FIN7 |
| 255 | T1218.004 | InstallUtil | Defense Evasion | no |
| 256 | T1218.001 | Compiled HTML File | Defense Evasion | APT41|Silence|Lazarus Group|Dark Caracal|OilRig |
| 257 | T1218.003 | CMSTP | Defense Evasion | Cobalt Group|MuddyWater |
| 258 | T1218.011 | Rundll32 | Defense Evasion | APT32|Sandworm Team|Blue Mockingbird|TA505|MuddyWater|APT29|APT19|CopyKittens|APT3|Carbanak|APT28 |
| 259 | T1547 | Boot or Logon Autostart Execution | Persistence|Privilege Escalation | no |
| 260 | T1546 | Event Triggered Execution | Privilege Escalation|Persistence | no |
| 261 | T1098.003 | Add Office 365 Global Administrator Role | Persistence | no |
| 262 | T1098.002 | Exchange Email Delegate Permissions | Persistence | Magic Hound |
| 263 | T1098.001 | Additional Azure Service Principal Credentials | Persistence | no |
| 264 | T1543.004 | Launch Daemon | Persistence|Privilege Escalation | no |
| 265 | T1543.003 | Windows Service | Persistence|Privilege Escalation | Blue Mockingbird|DarkVishnya|Wizard Spider|APT32|APT41|Kimsuky|Tropic Trooper|Cobalt Group|Ke3chang|Honeybee|FIN7|Threat Group-3390|APT19|APT3|Lazarus Group|Carbanak |
| 266 | T1543.002 | Systemd Service | Persistence|Privilege Escalation | Rocke |
| 267 | T1543.001 | Launch Agent | Persistence|Privilege Escalation | no |
| 268 | T1037.005 | Startup Items | Persistence|Privilege Escalation | no |
| 269 | T1037.004 | Rc.common | Persistence|Privilege Escalation | no |
| 270 | T1055.012 | Process Hollowing | Defense Evasion|Privilege Escalation | Threat Group-3390|menuPass|Gorgon Group|Patchwork |
| 271 | T1055.013 | Process Doppelgänging | Defense Evasion|Privilege Escalation | Leafminer |
| 272 | T1055.011 | Extra Window Memory Injection | Defense Evasion|Privilege Escalation | no |
| 273 | T1055.014 | VDSO Hijacking | Defense Evasion|Privilege Escalation | no |
| 274 | T1055.009 | Proc Memory | Defense Evasion|Privilege Escalation | no |
| 275 | T1055.008 | Ptrace System Calls | Defense Evasion|Privilege Escalation | no |
| 276 | T1055.005 | Thread Local Storage | Defense Evasion|Privilege Escalation | no |
| 277 | T1055.004 | Asynchronous Procedure Call | Defense Evasion|Privilege Escalation | no |
| 278 | T1055.003 | Thread Execution Hijacking | Defense Evasion|Privilege Escalation | no |
| 279 | T1055.002 | Portable Executable Injection | Defense Evasion|Privilege Escalation | Rocke|Gorgon Group |
| 280 | T1055.001 | Dynamic-link Library Injection | Defense Evasion|Privilege Escalation | TA505|Turla|Tropic Trooper|Lazarus Group|Putter Panda |
| 281 | T1037.003 | Network Logon Script | Persistence|Privilege Escalation | no |
| 282 | T1543 | Create or Modify System Process | Persistence|Privilege Escalation | no |
| 283 | T1037.002 | Logon Script (Mac) | Persistence|Privilege Escalation | no |
| 284 | T1037.001 | Logon Script (Windows) | Persistence|Privilege Escalation | Cobalt Group|APT28 |
| 285 | T1542.003 | Bootkit | Persistence|Defense Evasion | APT41|Lazarus Group|APT28 |
| 286 | T1542.002 | Component Firmware | Persistence|Defense Evasion | Equation |
| 287 | T1542.001 | System Firmware | Persistence|Defense Evasion | no |
| 288 | T1505.003 | Web Shell | Persistence | Tropic Trooper|Soft Cell|Threat Group-3390|TEMP.Veles|Leviathan|APT39|Dragonfly 2.0|APT32|OilRig|Deep Panda |
| 289 | T1505.002 | Transport Agent | Persistence | no |
| 290 | T1505.001 | SQL Stored Procedures | Persistence | no |
| 291 | T1053.003 | Cron | Execution|Persistence|Privilege Escalation | Rocke |
| 292 | T1053.004 | Launchd | Execution|Persistence|Privilege Escalation | no |
| 293 | T1053.001 | At (Linux) | Execution|Persistence|Privilege Escalation | no |
| 294 | T1053.005 | Scheduled Task | Execution|Persistence|Privilege Escalation | Gamaredon Group|Blue Mockingbird|MuddyWater|Wizard Spider|Frankenstein|APT-C-36|BRONZE BUTLER|APT41|Machete|Soft Cell|Silence|TEMP.Veles|APT33|APT39|Dragonfly 2.0|Patchwork|OilRig|Rancor|Cobalt Group|FIN8|menuPass|FIN10|APT32|FIN7|Stealth Falcon|FIN6|APT3|APT29 |
| 295 | T1053.002 | At (Windows) | Execution|Persistence|Privilege Escalation | BRONZE BUTLER|Threat Group-3390|APT18 |
| 296 | T1542 | Pre-OS Boot | Defense Evasion|Persistence | no |
| 297 | T1137.001 | Office Template Macros | Persistence | MuddyWater |
| 298 | T1137.004 | Outlook Home Page | Persistence | OilRig |
| 299 | T1137.003 | Outlook Forms | Persistence | no |
| 300 | T1137.005 | Outlook Rules | Persistence | no |
| 301 | T1137.006 | Add-ins | Persistence | Naikon |
| 302 | T1137.002 | Office Test | Persistence | APT28 |
| 303 | T1531 | Account Access Removal | Impact | no |
| 304 | T1539 | Steal Web Session Cookie | Credential Access | no |
| 305 | T1529 | System Shutdown/Reboot | Impact | Lazarus Group|APT38|APT37 |
| 306 | T1518 | Software Discovery | Discovery | BRONZE BUTLER|Tropic Trooper|Inception |
| 307 | T1534 | Internal Spearphishing | Lateral Movement | Gamaredon Group |
| 308 | T1528 | Steal Application Access Token | Credential Access | APT28 |
| 309 | T1535 | Unused/Unsupported Cloud Regions | Defense Evasion | no |
| 310 | T1525 | Implant Container Image | Persistence | no |
| 311 | T1538 | Cloud Service Dashboard | Discovery | no |
| 312 | T1530 | Data from Cloud Storage Object | Collection | no |
| 313 | T1578 | Modify Cloud Compute Infrastructure | Defense Evasion | no |
| 314 | T1537 | Transfer Data to Cloud Account | Exfiltration | no |
| 315 | T1526 | Cloud Service Discovery | Discovery | no |
| 316 | T1505 | Server Software Component | Persistence | no |
| 317 | T1499 | Endpoint Denial of Service | Impact | no |
| 318 | T1497 | Virtualization/Sandbox Evasion | Defense Evasion|Discovery | no |
| 319 | T1498 | Network Denial of Service | Impact | no |
| 320 | T1496 | Resource Hijacking | Impact | Blue Mockingbird|Rocke|APT41|Lazarus Group |
| 321 | T1495 | Firmware Corruption | Impact | no |
| 322 | T1491 | Defacement | Impact | no |
| 323 | T1490 | Inhibit System Recovery | Impact | no |
| 324 | T1489 | Service Stop | Impact | Lazarus Group |
| 325 | T1486 | Data Encrypted for Impact | Impact | APT41|TA505|APT38 |
| 326 | T1485 | Data Destruction | Impact | Sandworm Team|Lazarus Group|APT38 |
| 327 | T1484 | Group Policy Modification | Defense Evasion|Privilege Escalation | no |
| 328 | T1482 | Domain Trust Discovery | Discovery | Wizard Spider |
| 329 | T1480 | Execution Guardrails | Defense Evasion | no |
| 330 | T1222 | File and Directory Permissions Modification | Defense Evasion | no |
| 331 | T1221 | Template Injection | Defense Evasion | Gamaredon Group|Frankenstein|Inception|APT28|Tropic Trooper|Dragonfly 2.0|DarkHydrus |
| 332 | T1220 | XSL Script Processing | Defense Evasion | Cobalt Group |
| 333 | T1197 | BITS Jobs | Defense Evasion|Persistence | Patchwork|APT41|Leviathan |
| 334 | T1217 | Browser Bookmark Discovery | Discovery | no |
| 335 | T1213 | Data from Information Repositories | Collection | Turla |
| 336 | T1189 | Drive-by Compromise | Initial Access | Turla|Windshift|RTM|Darkhotel|APT38|Dragonfly 2.0|BRONZE BUTLER|Leafminer|Dark Caracal|APT19|APT32|Lazarus Group|Threat Group-3390|Elderwood|APT37|Patchwork|PLATINUM |
| 337 | T1203 | Exploitation for Client Execution | Execution | Sandworm Team|MuddyWater|Frankenstein|Inception|BlackTech|APT41|admin@338|Threat Group-3390|APT12|The White Company|APT33|APT32|APT28|Tropic Trooper|Lazarus Group|BRONZE BUTLER|Cobalt Group|APT37|Patchwork|Leviathan|Elderwood|TA459|APT29 |
| 338 | T1212 | Exploitation for Credential Access | Credential Access | no |
| 339 | T1211 | Exploitation for Defense Evasion | Defense Evasion | APT28 |
| 340 | T1190 | Exploit Public-Facing Application | Initial Access | Blue Mockingbird|Rocke|APT39|BlackTech|APT41|Soft Cell|Night Dragon|Axiom |
| 341 | T1210 | Exploitation of Remote Services | Lateral Movement | Threat Group-3390|APT28 |
| 342 | T1202 | Indirect Command Execution | Defense Evasion | no |
| 343 | T1200 | Hardware Additions | Initial Access | DarkVishnya |
| 344 | T1201 | Password Policy Discovery | Discovery | Turla|OilRig |
| 345 | T1219 | Remote Access Software | Command And Control | Sandworm Team|DarkVishnya|RTM|Kimsuky|Night Dragon|Thrip|Cobalt Group|Carbanak |
| 346 | T1207 | Rogue Domain Controller | Defense Evasion | no |
| 347 | T1199 | Trusted Relationship | Initial Access | APT28|menuPass |
| 348 | T1218 | Signed Binary Proxy Execution | Defense Evasion | no |
| 349 | T1204 | User Execution | Execution | no |
| 350 | T1216 | Signed Script Proxy Execution | Defense Evasion | no |
| 351 | T1195 | Supply Chain Compromise | Initial Access | Elderwood |
| 352 | T1205 | Traffic Signaling | Defense Evasion|Persistence|Command And Control | no |
| 353 | T1176 | Browser Extensions | Persistence | Kimsuky|Stolen Pencil |
| 354 | T1175 | Component Object Model and Distributed COM | Lateral Movement|Execution | no |
| 355 | T1187 | Forced Authentication | Credential Access | DarkHydrus|Dragonfly 2.0 |
| 356 | T1185 | Man in the Browser | Collection | no |
| 357 | T1134 | Access Token Manipulation | Defense Evasion|Privilege Escalation | Blue Mockingbird |
| 358 | T1136 | Create Account | Persistence | no |
| 359 | T1140 | Deobfuscate/Decode Files or Information | Defense Evasion | Rocke|Sandworm Team|Gamaredon Group|Molerats|Frankenstein|Turla|WIRTE|Darkhotel|Tropic Trooper|menuPass|Honeybee|Threat Group-3390|APT19|Gorgon Group|Leviathan|MuddyWater|APT28|OilRig|BRONZE BUTLER |
| 360 | T1149 | LC_MAIN Hijacking | Defense Evasion | no |
| 361 | T1135 | Network Share Discovery | Discovery | APT32|APT39|DarkVishnya|APT41|Tropic Trooper|APT1|Dragonfly 2.0|Sowbug |
| 362 | T1137 | Office Application Startup | Persistence | Gamaredon Group|APT32 |
| 363 | T1153 | Source | Execution | no |
| 364 | T1133 | External Remote Services | Persistence|Initial Access | Sandworm Team|APT41|Soft Cell|TEMP.Veles|Night Dragon|OilRig|Dragonfly 2.0|Ke3chang|FIN5|Threat Group-3390|APT18 |
| 365 | T1132 | Data Encoding | Command And Control | no |
| 366 | T1129 | Shared Modules | Execution | no |
| 367 | T1127 | Trusted Developer Utilities Proxy Execution | Defense Evasion | no |
| 368 | T1125 | Video Capture | Collection | Silence|FIN7 |
| 369 | T1124 | System Time Discovery | Discovery | The White Company|Lazarus Group|BRONZE BUTLER|Turla |
| 370 | T1123 | Audio Capture | Collection | APT37 |
| 371 | T1120 | Peripheral Device Discovery | Discovery | Turla|APT37|Gamaredon Group|Equation|APT28 |
| 372 | T1119 | Automated Collection | Collection | Tropic Trooper|Frankenstein|APT1|APT28|Patchwork|OilRig|FIN5|Threat Group-3390|FIN6 |
| 373 | T1115 | Clipboard Data | Collection | APT39|APT38 |
| 374 | T1114 | Email Collection | Collection | no |
| 375 | T1113 | Screen Capture | Collection | Gamaredon Group|APT39|Silence|MuddyWater|Dragonfly 2.0|OilRig|Dark Caracal|FIN7|BRONZE BUTLER|Magic Hound|Group5|APT28 |
| 376 | T1112 | Modify Registry | Defense Evasion | Gamaredon Group|Blue Mockingbird|Wizard Spider|Silence|APT41|Turla|APT32|APT38|Dragonfly 2.0|APT19|Threat Group-3390|Honeybee|Patchwork|Gorgon Group|FIN8 |
| 377 | T1111 | Two-Factor Authentication Interception | Credential Access | no |
| 378 | T1110 | Brute Force | Credential Access | DarkVishnya|APT39|OilRig|FIN5|Turla |
| 379 | T1108 | Redundant Access | Defense Evasion|Persistence | no |
| 380 | T1106 | Native API | Execution | Gamaredon Group|Tropic Trooper|Sharpshooter|Turla|Silence|Gorgon Group|APT37 |
| 381 | T1105 | Ingress Tool Transfer | Command And Control | Sandworm Team|Whitefly|Rocke|APT39|Tropic Trooper|Sharpshooter|Molerats|Frankenstein|Silence|APT-C-36|APT41|Soft Cell|TA505|WIRTE|APT33|MuddyWater|APT18|APT38|Rancor|Cobalt Group|Turla|Gorgon Group|OilRig|Dragonfly 2.0|APT37|FIN8|PLATINUM|Leviathan|Elderwood|Magic Hound|APT3|APT32|BRONZE BUTLER|menuPass|FIN7|Gamaredon Group|Patchwork|Lazarus Group|Threat Group-3390|APT28 |
| 382 | T1104 | Multi-Stage Channels | Command And Control | APT41|MuddyWater|APT3 |
| 383 | T1102 | Web Service | Command And Control | Gamaredon Group|Rocke|Inception|FIN6 |
| 384 | T1098 | Account Manipulation | Persistence | APT3|Dragonfly 2.0|Lazarus Group |
| 385 | T1095 | Non-Application Layer Protocol | Command And Control | APT29|PLATINUM|APT3 |
| 386 | T1092 | Communication Through Removable Media | Command And Control | APT28 |
| 387 | T1091 | Replication Through Removable Media | Lateral Movement|Initial Access | Tropic Trooper|Darkhotel|APT28 |
| 388 | T1090 | Proxy | Command And Control | Sandworm Team|Blue Mockingbird|Wizard Spider|APT41|Turla |
| 389 | T1087 | Account Discovery | Discovery | no |
| 390 | T1083 | File and Directory Discovery | Discovery | Gamaredon Group|Tropic Trooper|Inception|APT41|Kimsuky|APT32|MuddyWater|APT18|Leafminer|Honeybee|Dark Caracal|Dragonfly 2.0|Magic Hound|Sowbug|BRONZE BUTLER|APT3|APT28|Patchwork|Lazarus Group|Dust Storm|admin@338|Turla|Ke3chang |
| 391 | T1082 | System Information Discovery | Discovery | Rocke|Sandworm Team|Blue Mockingbird|Tropic Trooper|Frankenstein|Inception|Kimsuky|Darkhotel|MuddyWater|APT18|Honeybee|APT19|APT37|APT32|Magic Hound|OilRig|APT3|Sowbug|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|admin@338|Turla|Ke3chang |
| 392 | T1080 | Taint Shared Content | Lateral Movement | BRONZE BUTLER|Darkhotel |
| 393 | T1078 | Valid Accounts | Defense Evasion|Persistence|Privilege Escalation|Initial Access | Sandworm Team|Wizard Spider|Silence|APT41|Soft Cell|TEMP.Veles|APT39|FIN4|Night Dragon|Dragonfly 2.0|FIN8|Leviathan|APT33|OilRig|FIN5|menuPass|APT28|FIN10|Suckfly|FIN6|Threat Group-3390|APT18|PittyTiger|Carbanak |
| 394 | T1074 | Data Staged | Collection | Wizard Spider |
| 395 | T1072 | Software Deployment Tools | Execution|Lateral Movement | Silence|APT32|Threat Group-1314 |
| 396 | T1071 | Application Layer Protocol | Command And Control | Rocke|Magic Hound|Dragonfly 2.0 |
| 397 | T1070 | Indicator Removal on Host | Defense Evasion | no |
| 398 | T1069 | Permission Groups Discovery | Discovery | TA505|APT3 |
| 399 | T1068 | Exploitation for Privilege Escalation | Privilege Escalation | Whitefly|APT33|Cobalt Group|PLATINUM|FIN8|APT32|Threat Group-3390|FIN6|APT28 |
| 400 | T1064 | Scripting | Defense Evasion|Execution | no |
| 401 | T1062 | Hypervisor | Persistence | no |
| 402 | T1061 | Graphical User Interface | Execution | no |
| 403 | T1059 | Command and Scripting Interpreter | Execution | APT32|Molerats|Whitefly|Dragonfly 2.0|APT19|FIN7|OilRig|FIN5|Stealth Falcon|FIN6|Ke3chang |
| 404 | T1057 | Process Discovery | Discovery | Rocke|Frankenstein|Inception|Darkhotel|MuddyWater|APT1|APT38|Tropic Trooper|APT37|Honeybee|OilRig|APT3|Magic Hound|APT28|Winnti Group|Stealth Falcon|Poseidon Group|Lazarus Group|Molerats|Turla|Deep Panda|Ke3chang |
| 405 | T1056 | Input Capture | Collection|Credential Access | no |
| 406 | T1055 | Process Injection | Defense Evasion|Privilege Escalation | APT32|Sharpshooter|Silence|APT41|Kimsuky|Turla|Cobalt Group|APT37|Honeybee|PLATINUM |
| 407 | T1053 | Scheduled Task/Job | Execution|Persistence|Privilege Escalation | no |
| 408 | T1052 | Exfiltration Over Physical Medium | Exfiltration | no |
| 409 | T1051 | Shared Webroot | Lateral Movement | no |
| 410 | T1049 | System Network Connections Discovery | Discovery | Tropic Trooper|APT41|APT38|Soft Cell|APT32|APT1|OilRig|APT3|menuPass|Threat Group-3390|Poseidon Group|admin@338|Turla|Ke3chang |
| 411 | T1048 | Exfiltration Over Alternative Protocol | Exfiltration | no |
| 412 | T1047 | Windows Management Instrumentation | Execution | Blue Mockingbird|Wizard Spider|Frankenstein|APT41|FIN6|Soft Cell|APT32|MuddyWater|OilRig|Threat Group-3390|FIN8|Leviathan|menuPass|Stealth Falcon|Lazarus Group|APT29|Deep Panda |
| 413 | T1046 | Network Service Scanning | Discovery | Rocke|DarkVishnya|APT41|Tropic Trooper|APT39|APT32|Leafminer|OilRig|Cobalt Group|menuPass|Suckfly|FIN6|Threat Group-3390 |
| 414 | T1043 | Commonly Used Port | Command And Control | Machete|OilRig|APT28|TEMP.Veles|Night Dragon|APT29|APT18|APT19|Dragonfly 2.0|FIN7|FIN8|APT37|Magic Hound|APT3|Lazarus Group|Threat Group-3390 |
| 415 | T1041 | Exfiltration Over C2 Channel | Exfiltration | Sandworm Team|MuddyWater|Wizard Spider|Frankenstein|Kimsuky|Soft Cell|APT32|APT3|Gamaredon Group|Stealth Falcon|Lazarus Group|Ke3chang |
| 416 | T1040 | Network Sniffing | Credential Access|Discovery | Sandworm Team|DarkVishnya|APT33|Stolen Pencil|APT28 |
| 417 | T1039 | Data from Network Shared Drive | Collection | Sowbug|BRONZE BUTLER|menuPass |
| 418 | T1037 | Boot or Logon Initialization Scripts | Persistence|Privilege Escalation | Rocke |
| 419 | T1036 | Masquerading | Defense Evasion | Windshift|APT32|BRONZE BUTLER|menuPass|Dragonfly 2.0 |
| 420 | T1034 | Path Interception | Persistence|Privilege Escalation | no |
| 421 | T1033 | System Owner/User Discovery | Discovery | Frankenstein|APT41|Soft Cell|Tropic Trooper|APT39|MuddyWater|APT32|APT37|APT19|Dragonfly 2.0|OilRig|Magic Hound|FIN10|Gamaredon Group|Patchwork|Stealth Falcon|Lazarus Group|APT3 |
| 422 | T1030 | Data Transfer Size Limits | Exfiltration | Threat Group-3390 |
| 423 | T1029 | Scheduled Transfer | Exfiltration | no |
| 424 | T1027 | Obfuscated Files or Information | Defense Evasion | Gamaredon Group|Rocke|Sandworm Team|Blue Mockingbird|Whitefly|Molerats|Wizard Spider|Mofang|Frankenstein|Inception|APT-C-36|APT41|Machete|Soft Cell|Turla|TA505|Silence|APT33|Night Dragon|Darkhotel|Gallmaker|APT29|APT18|Tropic Trooper|Cobalt Group|Patchwork|Leafminer|APT37|Threat Group-3390|Honeybee|Dark Caracal|menuPass|APT19|BlackOasis|FIN8|Leviathan|Elderwood|MuddyWater|FIN7|Magic Hound|OilRig|APT3|APT32|Group5|Dust Storm|Lazarus Group|Putter Panda|APT28 |
| 425 | T1026 | Multiband Communication | Command And Control | Lazarus Group |
| 426 | T1025 | Data from Removable Media | Collection | Machete|Turla|Gamaredon Group|APT28 |
| 427 | T1021 | Remote Services | Lateral Movement | no |
| 428 | T1020 | Automated Exfiltration | Exfiltration | Tropic Trooper|Frankenstein|Honeybee |
| 429 | T1018 | Remote System Discovery | Discovery | Sandworm Team|Rocke|Wizard Spider|Silence|Soft Cell|APT39|APT32|Deep Panda|Threat Group-3390|Dragonfly 2.0|Leafminer|Ke3chang|FIN8|APT3|FIN5|BRONZE BUTLER|menuPass|FIN6|Turla |
| 430 | T1016 | System Network Configuration Discovery | Discovery | Sandworm Team|Tropic Trooper|Frankenstein|APT41|Soft Cell|APT32|Darkhotel|MuddyWater|APT1|APT19|Dragonfly 2.0|Magic Hound|OilRig|menuPass|Threat Group-3390|Stealth Falcon|Lazarus Group|APT3|Naikon|admin@338|Turla|Ke3chang |
| 431 | T1014 | Rootkit | Defense Evasion | Rocke|APT41|APT28|Winnti Group |
| 432 | T1012 | Query Registry | Discovery | APT32|Dragonfly 2.0|Threat Group-3390|OilRig|Stealth Falcon|Lazarus Group|Turla |
| 433 | T1011 | Exfiltration Over Other Network Medium | Exfiltration | no |
| 434 | T1010 | Application Window Discovery | Discovery | Lazarus Group |
| 435 | T1008 | Fallback Channels | Command And Control | APT41|OilRig|Lazarus Group |
| 436 | T1007 | System Service Discovery | Discovery | BRONZE BUTLER|APT1|OilRig|Poseidon Group|admin@338|Turla|Ke3chang |
| 437 | T1006 | Direct Volume Access | Defense Evasion | no |
| 438 | T1005 | Data from Local System | Collection | Gamaredon Group|APT39|Frankenstein|Inception|Kimsuky|Soft Cell|Turla|menuPass|Dark Caracal|Dragonfly 2.0|Honeybee|APT37|APT28|APT3|BRONZE BUTLER|Patchwork|Stealth Falcon|Lazarus Group|Dust Storm|Threat Group-3390|APT1|Ke3chang |
| 439 | T1003 | OS Credential Dumping | Credential Access | APT39|Frankenstein|APT32|APT28|Leviathan|Sowbug|Suckfly|Poseidon Group|Axiom |
| 440 | T1001 | Data Obfuscation | Command And Control | Axiom |