Skip to main content

Suspicious and Malicious Activity by MITRE ATT&CK

This catalog describes observable suspicious and malicious activity aligned to the current MITRE ATT&CK Enterprise tactics and techniques. Each activity links directly to the vendor-neutral log sources that can report it.

ATT&CK techniques describe how adversaries achieve an objective. A single activity can map to multiple techniques, and a single technique can produce several observable activities. The listed log sources indicate potential observability, not guaranteed detection. Collection, audit policy, retention, and field availability still determine whether the activity is visible.

Reconnaissance

Reconnaissance activity occurs before initial access and is often observable only at public-facing systems or through external monitoring.

Suspicious or malicious activityATT&CKLog sources that can report it
Repeated probing of public services, ports, and protocolsT1595 Active ScanningNetwork Firewall Logs, Network Flow Logs, Network Intrusion Detection Logs, Web Application Firewall Logs
Enumeration of public web paths, APIs, parameters, and filesT1595.003 Wordlist ScanningWeb Server Access Logs, Web Application Firewall Logs, API Gateway Logs
DNS enumeration and attempted zone transferT1590 Gather Victim Network InformationAuthoritative DNS Logs, Network Intrusion Detection Logs
Scraping public applications, repositories, or exposed documentsT1593 Search Open Websites/DomainsWeb Server Access Logs, API Gateway Logs, Source-Code Management Audit Logs
Discovery of newly exposed public assets and servicesT1595 Active ScanningAttack-Surface Management Logs, Network Firewall Logs

Resource Development

Most resource-development activity occurs outside the target environment. It becomes observable when adversary-controlled infrastructure or capabilities interact with monitored systems.

Suspicious or malicious activityATT&CKLog sources that can report it
Lookalike domain, certificate, or external infrastructure begins interacting with the environmentT1583 Acquire InfrastructureDNS Resolver Logs, TLS and Certificate Metadata Logs, Threat-Intelligence Platform Logs
Staged malicious files or tools are delivered from external hostingT1608 Stage CapabilitiesProxy and Secure Web Gateway Logs, Email Gateway Logs, Content Inspection and Malware Scanning Logs
Compromised accounts or infrastructure are used to distribute contentT1584 Compromise InfrastructureIdentity Provider Sign-In Logs, Email Gateway Logs, Web Server Access Logs

Initial Access

Suspicious or malicious activityATT&CKLog sources that can report it
Malicious attachment, link, or message delivered to a userT1566 PhishingEmail Gateway Logs, Mailbox Audit Logs, Content Inspection and Malware Scanning Logs
User opens a delivered file or follows a malicious linkT1566 PhishingEndpoint Detection and Response Telemetry, Process Execution Logs, Proxy and Secure Web Gateway Logs
Public-facing application receives exploit-like requestsT1190 Exploit Public-Facing ApplicationWeb Application Firewall Logs, Web Server Access Logs, Application Runtime Logs, Network Intrusion Detection Logs
Valid credentials are used from an unusual source or contextT1078 Valid AccountsIdentity Provider Sign-In Logs, Directory-Service Authentication Logs, Remote Access and VPN Authentication Logs
Remote service accepts an external login or sessionT1133 External Remote ServicesRemote Access and VPN Authentication Logs, Remote Desktop and Remote Support Logs, Network Firewall Logs
Malicious content is injected into an online traffic channelT1659 Content InjectionPacket-Capture Data, Network Metadata Logs, TLS and Certificate Metadata Logs
Compromised software or update package is installedT1195 Supply Chain CompromisePackage and Software Installation Logs, Application-Control Logs, Artifact Repository Logs, Continuous Integration and Continuous Delivery/Deployment Logs

Execution

Suspicious or malicious activityATT&CKLog sources that can report it
Command shell or interpreter executes commandsT1059 Command and Scripting InterpreterProcess Execution Logs, Command-Line and Shell History Logs, Script-Execution Logs
PowerShell executes scripts, encoded content, or remote commandsT1059.001 PowerShellWindows PowerShell Logs, Process Execution Logs, Endpoint Detection and Response Telemetry
A user launches or approves execution of malicious contentT1204 User ExecutionProcess Execution Logs, File-System Activity Logs, Email Gateway Logs
Client application behavior changes immediately after exploitationT1203 Exploitation for Client ExecutionEndpoint Detection and Response Telemetry, Memory-Protection and Exploit-Mitigation Logs, Application Runtime Logs
Trusted or signed system binary launches unexpected contentT1218 System Binary Proxy ExecutionProcess Execution Logs, Application-Control Logs, Module, Library, and Image-Load Logs
Scheduled job, service, or automation executes a payloadT1053 Scheduled Task/JobScheduled Task and Job Logs, Service and Daemon Management Logs, Process Execution Logs
Container administration interface executes a command in a workloadT1609 Container Administration CommandOrchestrator Audit Logs, Container Runtime Logs, Container Runtime Security Logs
Serverless function or cloud workload is invoked unexpectedlyT1648 Serverless ExecutionCloud Function and Serverless Logs, Cloud Control-Plane Audit Logs, Cloud Identity and Access Management Logs

Persistence

Suspicious or malicious activityATT&CKLog sources that can report it
New local, domain, cloud, or service account is createdT1136 Create AccountWindows Security Event Logs, Directory-Service Audit Logs, Identity Provider Audit Logs, Cloud Identity and Access Management Logs
Credentials, group memberships, roles, or account properties are modifiedT1098 Account ManipulationDirectory-Service Audit Logs, Identity Provider Audit Logs, Cloud Identity and Access Management Logs
Startup, logon, or shell configuration is changed to launch codeT1547 Boot or Logon Autostart ExecutionRegistry and Configuration-Store Logs, File-System Activity Logs, Process Execution Logs
New or modified system service launches an executableT1543 Create or Modify System ProcessService and Daemon Management Logs, Windows System Event Logs, Linux System Logs
Scheduled task or job is created or modified for recurring executionT1053 Scheduled Task/JobScheduled Task and Job Logs, Windows Task Scheduler Logs, Linux Service-Manager Logs
Email forwarding or mailbox rule is createdT1114.003 Email Forwarding RuleMailbox Audit Logs, Identity Provider Audit Logs, Application Audit Logs
New cloud role, key, token, application, or service identity is addedT1098 Account ManipulationCloud Identity and Access Management Logs, Cloud Control-Plane Audit Logs, Cloud Key-Management Logs
New privileged or long-running container workload is deployedT1610 Deploy ContainerOrchestrator Audit Logs, Container Runtime Logs, Container Image Registry Logs

Privilege Escalation

Suspicious or malicious activityATT&CKLog sources that can report it
Process or account invokes an elevation-control mechanismT1548 Abuse Elevation Control MechanismProcess Execution Logs, Linux Authentication Logs, Windows Security Event Logs
Exploit causes a process to gain elevated privilegesT1068 Exploitation for Privilege EscalationEndpoint Detection and Response Telemetry, System-Call Telemetry, Memory-Protection and Exploit-Mitigation Logs
Permissions, roles, or group memberships grant new administrative accessT1098 Account ManipulationDirectory-Service Audit Logs, Identity Provider Audit Logs, Cloud Identity and Access Management Logs
Access token, process token, or security context is manipulatedT1134 Access Token ManipulationWindows Security Event Logs, Process Execution Logs, Endpoint Detection and Response Telemetry
Privileged container or workload is createdT1610 Deploy ContainerOrchestrator Audit Logs, Container Runtime Security Logs, Container Runtime Logs

Defense Evasion (TA0005) — Evasion Behaviors

Suspicious or malicious activityATT&CKLog sources that can report it
File, process, service, account, or resource is renamed or made to resemble a trusted objectT1036 MasqueradingProcess Execution Logs, File-System Activity Logs, Application-Control Logs
Payload, script, command, or file content is encoded, packed, or obfuscatedT1027 Obfuscated Files or InformationScript-Execution Logs, Content Inspection and Malware Scanning Logs, Sandbox Analysis Logs
Existing trusted software or native functionality is abusedT1218 System Binary Proxy ExecutionProcess Execution Logs, Application-Control Logs, Endpoint Detection and Response Telemetry
File timestamps, metadata, or indicators are modifiedT1070 Indicator RemovalFile-System Activity Logs, File-Integrity Monitoring Logs, Operating-System Audit Logs
Process injection or in-memory execution changes another processT1055 Process InjectionEndpoint Detection and Response Telemetry, Memory-Protection and Exploit-Mitigation Logs, System-Call Telemetry
Social interaction manipulates a user into taking an unsafe actionT1566 PhishingEmail Gateway Logs, Collaboration Platform Audit Logs, Mailbox Audit Logs
Security capability is downgraded to an older or weaker versionT1562.010 Impair Defenses: Downgrade AttackPackage and Software Installation Logs, Configuration and Compliance Scanner Logs, Application Audit Logs

Defense Evasion (TA0005) — Defense Impairment Behaviors

Suspicious or malicious activityATT&CKLog sources that can report it
Security agent, monitoring process, or protection tool is stopped, disabled, or modifiedT1562.001 Impair Defenses: Disable or Modify ToolsEndpoint Sensor Health Logs, Service and Daemon Management Logs, Antivirus and Antimalware Logs
Audit, logging, or telemetry collection is disabled or reducedT1562.001 Impair Defenses: Disable or Modify ToolsCentral Log Collector Logs, Security Information and Event Management Logs, Operating-System Audit Logs
Security or system logs are cleared or deletedT1070.001 Clear Windows Event LogsWindows Security Event Logs, Central Log Collector Logs, Security Information and Event Management Logs
Host, cloud, or network firewall policy is disabled or weakenedT1562.004 Impair Defenses: Disable or Modify System FirewallLocal Firewall Logs, Network Firewall Logs, Cloud Firewall and Security-Group Logs
Security policy, access control, or monitoring configuration is modifiedT1562 Impair DefensesIdentity Provider Audit Logs, Cloud Control-Plane Audit Logs, Network Configuration Change Logs
Vulnerability is exploited specifically to disable or bypass defensesT1562 Impair DefensesMemory-Protection and Exploit-Mitigation Logs, Endpoint Detection and Response Telemetry, Application Runtime Logs

Credential Access

Suspicious or malicious activityATT&CKLog sources that can report it
Repeated password guessing, spraying, or credential stuffingT1110 Brute ForceIdentity Provider Sign-In Logs, Directory-Service Authentication Logs, Application Authentication Logs, Remote Access and VPN Authentication Logs
MFA prompts are repeatedly generated or deniedT1621 Multi-Factor Authentication Request GenerationMulti-Factor Authentication Logs, Identity Provider Sign-In Logs
Password stores, browser credentials, keychains, or vaults are accessedT1555 Credentials from Password StoresFile-System Activity Logs, Endpoint Detection and Response Telemetry, Password-Management and Credential-Vault Logs
Operating-system credential material or protected memory is accessedT1003 OS Credential DumpingEndpoint Detection and Response Telemetry, Process Execution Logs, Memory-Protection and Exploit-Mitigation Logs
Kerberos tickets are requested or manipulated abnormallyT1558 Steal or Forge Kerberos TicketsDirectory-Service Authentication Logs, Windows Security Event Logs
Input, clipboard, or screen content is capturedT1056 Input CaptureEndpoint Detection and Response Telemetry, Mobile Endpoint Security Logs, Remote Desktop and Remote Support Logs
Cloud secrets, keys, certificates, or tokens are retrievedT1552 Unsecured CredentialsCloud Secrets-Manager Logs, Cloud Key-Management Logs, Secrets-Management Logs, Certificate-Authority and Public-Key Infrastructure Logs

Discovery

Suspicious or malicious activityATT&CKLog sources that can report it
Accounts, groups, roles, or permissions are enumeratedT1087 Account DiscoveryDirectory-Service Audit Logs, Cloud Identity and Access Management Logs, Process Execution Logs
Files, directories, shares, or storage objects are enumeratedT1083 File and Directory DiscoveryFile-System Activity Logs, Cloud Object-Storage Access Logs, Process Execution Logs
Network services, ports, systems, or subnets are scanned internallyT1046 Network Service DiscoveryNetwork Flow Logs, Network Firewall Logs, Network Detection and Response Telemetry
Running processes, services, software, or security tools are enumeratedT1057 Process DiscoveryProcess Execution Logs, Endpoint Detection and Response Telemetry, Asset Inventory and Discovery Logs
System, host, domain, or operating-system information is collectedT1082 System Information DiscoveryProcess Execution Logs, Operating-System Logs, Endpoint Detection and Response Telemetry
Cloud resources, services, regions, or configurations are enumeratedT1580 Cloud Infrastructure DiscoveryCloud Control-Plane Audit Logs, Cloud Resource-Configuration Inventory, Cloud Identity and Access Management Logs
Container, cluster, namespace, secret, or workload information is enumeratedT1613 Container and Resource DiscoveryOrchestrator Audit Logs, Container Runtime Logs, Orchestrator Control-Plane Component Logs

Lateral Movement

Suspicious or malicious activityATT&CKLog sources that can report it
Remote desktop, shell, management, or administrative service is used between systemsT1021 Remote ServicesRemote Desktop and Remote Support Logs, Windows Remote Management Logs, Linux Authentication Logs, Network Flow Logs
Valid credentials or alternate authentication material are reused on another systemT1550 Use Alternate Authentication MaterialDirectory-Service Authentication Logs, Windows Security Event Logs, Identity Provider Sign-In Logs
Tool, payload, or file is transferred to another internal systemT1570 Lateral Tool TransferFile-System Activity Logs, Network Flow Logs, File Transfer Service Logs
Remote service, task, or process is created on another hostT1021 Remote ServicesService and Daemon Management Logs, Scheduled Task and Job Logs, Process Execution Logs
Internal host begins connecting broadly to peers or new administrative pathsT1021 Remote ServicesNetwork Flow Logs, Network Detection and Response Telemetry, Network Firewall Logs
Container or workload identity accesses another namespace, node, or serviceT1021 Remote ServicesContainer Network Logs, Service Mesh Logs, Orchestrator Audit Logs

Collection

Suspicious or malicious activityATT&CKLog sources that can report it
Files, records, messages, or objects are accessed in bulkT1119 Automated CollectionFile-System Activity Logs, Database Audit Logs, Cloud Object-Storage Access Logs, Mailbox Audit Logs
Data is collected from local files, network shares, or repositoriesT1005 Data from Local SystemFile-System Activity Logs, Storage-System Audit Logs, Source-Code Management Audit Logs
Email messages, attachments, or mailbox content are collectedT1114 Email CollectionMailbox Audit Logs, Mail Transport Logs, Application Audit Logs
Database contents are queried, copied, or exportedT1213 Data from Information RepositoriesDatabase Audit Logs, Data Warehouse Audit Logs, Application Audit Logs
Cloud-hosted documents, objects, snapshots, or backups are accessedT1530 Data from Cloud StorageCloud Object-Storage Access Logs, Cloud Data-Plane Access Logs, Backup and Recovery Logs
Data is staged, compressed, encrypted, or archived before transferT1074 Data StagedFile-System Activity Logs, Process Execution Logs, Endpoint Detection and Response Telemetry
Screens, input, audio, or video are capturedT1113 Screen CaptureEndpoint Detection and Response Telemetry, Mobile Endpoint Security Logs, Application Audit Logs

Command and Control

Suspicious or malicious activityATT&CKLog sources that can report it
Endpoint or workload communicates periodically with an external destinationT1071 Application Layer ProtocolNetwork Flow Logs, Network Detection and Response Telemetry, Proxy and Secure Web Gateway Logs
DNS queries or responses carry command, control, or encoded dataT1071.004 DNSDNS Resolver Logs, Packet-Capture Data, Network Detection and Response Telemetry
Encrypted or obfuscated network channel is establishedT1573 Encrypted ChannelTLS and Certificate Metadata Logs, Network Flow Logs, Network Metadata Logs
Web, cloud, social, or collaboration service is used as a control channelT1102 Web ServiceProxy and Secure Web Gateway Logs, Collaboration Platform Audit Logs, Cloud Data-Plane Access Logs
Tool or payload is downloaded into the environmentT1105 Ingress Tool TransferProxy and Secure Web Gateway Logs, File-System Activity Logs, Content Inspection and Malware Scanning Logs
Proxy, relay, tunnel, or port forwarding is configuredT1090 ProxyProcess Execution Logs, Network Flow Logs, Network Configuration Change Logs
Multiple staged communication channels are usedT1104 Multi-Stage ChannelsNetwork Detection and Response Telemetry, DNS Resolver Logs, Proxy and Secure Web Gateway Logs

Exfiltration

Suspicious or malicious activityATT&CKLog sources that can report it
Large or unusual outbound transfer leaves the environmentT1041 Exfiltration Over C2 ChannelNetwork Flow Logs, Network Firewall Logs, Data Loss Prevention Logs
Data is uploaded to cloud storage, web service, or external repositoryT1567 Exfiltration Over Web ServiceProxy and Secure Web Gateway Logs, Cloud Data-Plane Access Logs, Source-Code Management Audit Logs, Data Loss Prevention Logs
Data leaves through DNS, email, file transfer, or another alternate protocolT1048 Exfiltration Over Alternative ProtocolDNS Resolver Logs, Email Gateway Logs, File Transfer Service Logs, Network Metadata Logs
Removable media receives copied dataT1052 Exfiltration Over Physical MediumRemovable-Media and Peripheral Device Logs, File-System Activity Logs, Data Loss Prevention Logs
Automated process repeatedly transfers staged dataT1020 Automated ExfiltrationProcess Execution Logs, Network Flow Logs, Scheduled Task and Job Logs
Transfer size, timing, or channel is deliberately limited to evade controlsT1030 Data Transfer Size LimitsNetwork Flow Logs, Proxy and Secure Web Gateway Logs, Data Loss Prevention Logs

Impact

Suspicious or malicious activityATT&CKLog sources that can report it
Files, records, cloud objects, or resources are deleted or destroyedT1485 Data DestructionFile-System Activity Logs, Database Audit Logs, Cloud Control-Plane Audit Logs, Cloud Object-Storage Access Logs
Files or systems are encrypted for impactT1486 Data Encrypted for ImpactFile-System Activity Logs, Endpoint Detection and Response Telemetry, File-Integrity Monitoring Logs
Service, host, network, or account availability is disruptedT1499 Endpoint Denial of ServiceMetrics and Monitoring-System Logs, Network Firewall Logs, Application Runtime Logs, Operating-System Crash and Diagnostic Logs
Accounts, roles, or access are removed to lock out legitimate usersT1531 Account Access RemovalIdentity Provider Audit Logs, Directory-Service Audit Logs, Cloud Identity and Access Management Logs
Backup, snapshot, or recovery capability is deleted or impairedT1490 Inhibit System RecoveryBackup and Recovery Logs, Process Execution Logs, Cloud Control-Plane Audit Logs
Configuration, firmware, or device state is modified to cause operational impactT1495 Firmware CorruptionInfrastructure Management Interface Logs, Hardware and Environmental Monitoring Logs, Industrial Control System Logs
Data or application content is manipulated to undermine integrityT1565 Data ManipulationDatabase Audit Logs, Application Audit Logs, File-Integrity Monitoring Logs
Resource use rises sharply due to unauthorized computation or abuseT1496 Resource HijackingMetrics and Monitoring-System Logs, Cloud Billing and Usage Logs, Process Execution Logs, Container Runtime Logs

Observability Notes

  1. A linked source can report an activity only when the relevant audit or collection capability is enabled.
  2. Several sources are often required to establish actor, action, target, timing, and outcome.
  3. Some ATT&CK activities occur outside defender-controlled infrastructure and may have no direct internal log source.
  4. Aggregation platforms such as EDR, NDR, SIEM, XDR, and UEBA derive activity from underlying sources and should not replace source-level collection.
  5. ATT&CK mappings should be validated against the exact technique and platform before being used in production detection content.

MITRE ATT&CK References