Loading interactive filters…
1200KM / index
Detection Rules
Exact ATT&CK technique workspaces, original Sigma rules and the existing Anomaly Detection Atlas. Source-backed references, not production-validated detectors.
Complete reference directory
- T1001 Data Obfuscation detections
- T1001.001 Junk Data detections
- T1001.002 Steganography detections
- T1001.003 Protocol or Service Impersonation detections
- T1003 OS Credential Dumping detections
- T1003.001 LSASS Memory detections
- T1003.002 Security Account Manager detections
- T1003.003 NTDS detections
- T1003.004 LSA Secrets detections
- T1003.005 Cached Domain Credentials detections
- T1003.006 DCSync detections
- T1003.007 Proc Filesystem detections
- T1003.008 /etc/passwd and /etc/shadow detections
- T1005 Data from Local System detections
- T1006 Direct Volume Access detections
- T1007 System Service Discovery detections
- T1008 Fallback Channels detections
- T1010 Application Window Discovery detections
- T1011 Exfiltration Over Other Network Medium detections
- T1011.001 Exfiltration Over Bluetooth detections
- T1012 Query Registry detections
- T1014 Rootkit detections
- T1016 System Network Configuration Discovery detections
- T1016.001 Internet Connection Discovery detections
- T1016.002 Wi-Fi Discovery detections
- T1018 Remote System Discovery detections
- T1020 Automated Exfiltration detections
- T1020.001 Traffic Duplication detections
- T1021 Remote Services detections
- T1021.001 Remote Desktop Protocol detections
- T1021.002 SMB/Windows Admin Shares detections
- T1021.003 Distributed Component Object Model detections
- T1021.004 SSH detections
- T1021.005 VNC detections
- T1021.006 Windows Remote Management detections
- T1021.007 Cloud Services detections
- T1021.008 Direct Cloud VM Connections detections
- T1025 Data from Removable Media detections
- T1027 Obfuscated Files or Information detections
- T1027.001 Binary Padding detections
- T1027.002 Software Packing detections
- T1027.003 Steganography detections
- T1027.004 Compile After Delivery detections
- T1027.005 Indicator Removal from Tools detections
- T1027.006 HTML Smuggling detections
- T1027.007 Dynamic API Resolution detections
- T1027.008 Stripped Payloads detections
- T1027.009 Embedded Payloads detections
- T1027.010 Command Obfuscation detections
- T1027.011 Fileless Storage detections
- T1027.012 LNK Icon Smuggling detections
- T1027.013 Encrypted/Encoded File detections
- T1027.014 Polymorphic Code detections
- T1027.015 Compression detections
- T1027.016 Junk Code Insertion detections
- T1027.017 SVG Smuggling detections
- T1027.018 Invisible Unicode detections
- T1029 Scheduled Transfer detections
- T1030 Data Transfer Size Limits detections
- T1033 System Owner/User Discovery detections
- T1036 Masquerading detections
- T1036.001 Invalid Code Signature detections
- T1036.002 Right-to-Left Override detections
- T1036.003 Rename Legitimate Utilities detections
- T1036.004 Masquerade Task or Service detections
- T1036.005 Match Legitimate Resource Name or Location detections
- T1036.006 Space after Filename detections
- T1036.007 Double File Extension detections
- T1036.008 Masquerade File Type detections
- T1036.009 Break Process Trees detections
- T1036.010 Masquerade Account Name detections
- T1036.011 Overwrite Process Arguments detections
- T1036.012 Browser Fingerprint detections
- T1037 Boot or Logon Initialization Scripts detections
- T1037.001 Logon Script (Windows) detections
- T1037.002 Login Hook detections
- T1037.003 Network Logon Script detections
- T1037.004 RC Scripts detections
- T1037.005 Startup Items detections
- T1039 Data from Network Shared Drive detections
- T1040 Network Sniffing detections
- T1041 Exfiltration Over C2 Channel detections
- T1046 Network Service Discovery detections
- T1047 Windows Management Instrumentation detections
- T1048 Exfiltration Over Alternative Protocol detections
- T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol detections
- T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol detections
- T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol detections
- T1049 System Network Connections Discovery detections
- T1052 Exfiltration Over Physical Medium detections
- T1052.001 Exfiltration over USB detections
- T1053 Scheduled Task/Job detections
- T1053.002 At detections
- T1053.003 Cron detections
- T1053.005 Scheduled Task detections
- T1053.006 Systemd Timers detections
- T1053.007 Container Orchestration Job detections
- T1055 Process Injection detections
- T1055.001 Dynamic-link Library Injection detections
- T1055.002 Portable Executable Injection detections
- T1055.003 Thread Execution Hijacking detections
- T1055.004 Asynchronous Procedure Call detections
- T1055.005 Thread Local Storage detections
- T1055.008 Ptrace System Calls detections
- T1055.009 Proc Memory detections
- T1055.011 Extra Window Memory Injection detections
- T1055.012 Process Hollowing detections
- T1055.013 Process Doppelgänging detections
- T1055.014 VDSO Hijacking detections
- T1055.015 ListPlanting detections
- T1056 Input Capture detections
- T1056.001 Keylogging detections
- T1056.002 GUI Input Capture detections
- T1056.003 Web Portal Capture detections
- T1056.004 Credential API Hooking detections
- T1057 Process Discovery detections
- T1059 Command and Scripting Interpreter detections
- T1059.001 PowerShell detections
- T1059.002 AppleScript detections
- T1059.003 Windows Command Shell detections
- T1059.004 Unix Shell detections
- T1059.005 Visual Basic detections
- T1059.006 Python detections
- T1059.007 JavaScript detections
- T1059.008 Network Device CLI detections
- T1059.009 Cloud API detections
- T1059.010 AutoHotKey & AutoIT detections
- T1059.011 Lua detections
- T1059.012 Hypervisor CLI detections
- T1059.013 Container CLI/API detections
- T1068 Exploitation for Privilege Escalation detections
- T1069 Permission Groups Discovery detections
- T1069.001 Local Groups detections
- T1069.002 Domain Groups detections
- T1069.003 Cloud Groups detections
- T1070 Indicator Removal detections
- T1070.003 Clear Command History detections
- T1070.004 File Deletion detections
- T1070.005 Network Share Connection Removal detections
- T1070.006 Timestomp detections
- T1070.007 Clear Network Connection History and Configurations detections
- T1070.008 Clear Mailbox Data detections
- T1070.009 Clear Persistence detections
- T1070.010 Relocate Malware detections
- T1071 Application Layer Protocol detections
- T1071.001 Web Protocols detections
- T1071.002 File Transfer Protocols detections
- T1071.003 Mail Protocols detections
- T1071.004 DNS detections
- T1071.005 Publish/Subscribe Protocols detections
- T1072 Software Deployment Tools detections
- T1074 Data Staged detections
- T1074.001 Local Data Staging detections
- T1074.002 Remote Data Staging detections
- T1078 Valid Accounts detections
- T1078.001 Default Accounts detections
- T1078.002 Domain Accounts detections
- T1078.003 Local Accounts detections
- T1078.004 Cloud Accounts detections
- T1080 Taint Shared Content detections
- T1082 System Information Discovery detections
- T1083 File and Directory Discovery detections
- T1087 Account Discovery detections
- T1087.001 Local Account detections
- T1087.002 Domain Account detections
- T1087.003 Email Account detections
- T1087.004 Cloud Account detections
- T1090 Proxy detections
- T1090.001 Internal Proxy detections
- T1090.002 External Proxy detections
- T1090.003 Multi-hop Proxy detections
- T1090.004 Domain Fronting detections
- T1091 Replication Through Removable Media detections
- T1092 Communication Through Removable Media detections
- T1095 Non-Application Layer Protocol detections
- T1098 Account Manipulation detections
- T1098.001 Additional Cloud Credentials detections
- T1098.002 Additional Email Delegate Permissions detections
- T1098.003 Additional Cloud Roles detections
- T1098.004 SSH Authorized Keys detections
- T1098.005 Device Registration detections
- T1098.006 Additional Container Cluster Roles detections
- T1098.007 Additional Local or Domain Groups detections
- T1102 Web Service detections
- T1102.001 Dead Drop Resolver detections
- T1102.002 Bidirectional Communication detections
- T1102.003 One-Way Communication detections
- T1104 Multi-Stage Channels detections
- T1105 Ingress Tool Transfer detections
- T1106 Native API detections
- T1110 Brute Force detections
- T1110.001 Password Guessing detections
- T1110.002 Password Cracking detections
- T1110.003 Password Spraying detections
- T1110.004 Credential Stuffing detections
- T1111 Multi-Factor Authentication Interception detections
- T1112 Modify Registry detections
- T1113 Screen Capture detections
- T1114 Email Collection detections
- T1114.001 Local Email Collection detections
- T1114.002 Remote Email Collection detections
- T1114.003 Email Forwarding Rule detections
- T1115 Clipboard Data detections
- T1119 Automated Collection detections
- T1120 Peripheral Device Discovery detections
- T1123 Audio Capture detections
- T1124 System Time Discovery detections
- T1125 Video Capture detections
- T1127 Trusted Developer Utilities Proxy Execution detections
- T1127.001 MSBuild detections
- T1127.002 ClickOnce detections
- T1127.003 JamPlus detections
- T1129 Shared Modules detections
- T1132 Data Encoding detections
- T1132.001 Standard Encoding detections
- T1132.002 Non-Standard Encoding detections
- T1133 External Remote Services detections
- T1134 Access Token Manipulation detections
- T1134.001 Token Impersonation/Theft detections
- T1134.002 Create Process with Token detections
- T1134.003 Make and Impersonate Token detections
- T1134.004 Parent PID Spoofing detections
- T1134.005 SID-History Injection detections
- T1135 Network Share Discovery detections
- T1136 Create Account detections
- T1136.001 Local Account detections
- T1136.002 Domain Account detections
- T1136.003 Cloud Account detections
- T1137 Office Application Startup detections
- T1137.001 Office Template Macros detections
- T1137.002 Office Test detections
- T1137.003 Outlook Forms detections
- T1137.004 Outlook Home Page detections
- T1137.005 Outlook Rules detections
- T1137.006 Add-ins detections
- T1140 Deobfuscate/Decode Files or Information detections
- T1176 Software Extensions detections
- T1176.001 Browser Extensions detections
- T1176.002 IDE Extensions detections
- T1185 Browser Session Hijacking detections
- T1187 Forced Authentication detections
- T1189 Drive-by Compromise detections
- T1190 Exploit Public-Facing Application detections
- T1195 Supply Chain Compromise detections
- T1195.001 Compromise Software Dependencies and Development Tools detections
- T1195.002 Compromise Software Supply Chain detections
- T1195.003 Compromise Hardware Supply Chain detections
- T1197 BITS Jobs detections
- T1199 Trusted Relationship detections
- T1200 Hardware Additions detections
- T1201 Password Policy Discovery detections
- T1202 Indirect Command Execution detections
- T1203 Exploitation for Client Execution detections
- T1204 User Execution detections
- T1204.001 Malicious Link detections
- T1204.002 Malicious File detections
- T1204.003 Malicious Image detections
- T1204.004 Malicious Copy and Paste detections
- T1204.005 Malicious Library detections
- T1205 Traffic Signaling detections
- T1205.001 Port Knocking detections
- T1205.002 Socket Filters detections
- T1207 Rogue Domain Controller detections
- T1210 Exploitation of Remote Services detections
- T1211 Exploitation for Stealth detections
- T1212 Exploitation for Credential Access detections
- T1213 Data from Information Repositories detections
- T1213.001 Confluence detections
- T1213.002 Sharepoint detections
- T1213.003 Code Repositories detections
- T1213.004 Customer Relationship Management Software detections
- T1213.005 Messaging Applications detections
- T1213.006 Databases detections
- T1216 System Script Proxy Execution detections
- T1216.001 PubPrn detections
- T1216.002 SyncAppvPublishingServer detections
- T1217 Browser Information Discovery detections
- T1218 System Binary Proxy Execution detections
- T1218.001 Compiled HTML File detections
- T1218.002 Control Panel detections
- T1218.003 CMSTP detections
- T1218.004 InstallUtil detections
- T1218.005 Mshta detections
- T1218.007 Msiexec detections
- T1218.008 Odbcconf detections
- T1218.009 Regsvcs/Regasm detections
- T1218.010 Regsvr32 detections
- T1218.011 Rundll32 detections
- T1218.012 Verclsid detections
- T1218.013 Mavinject detections
- T1218.014 MMC detections
- T1218.015 Electron Applications detections
- T1219 Remote Access Tools detections
- T1219.001 IDE Tunneling detections
- T1219.002 Remote Desktop Software detections
- T1219.003 Remote Access Hardware detections
- T1220 XSL Script Processing detections
- T1221 Template Injection detections
- T1222 File and Directory Permissions Modification detections
- T1222.001 Windows Permissions detections
- T1222.002 Linux and Mac Permissions detections
- T1480 Execution Guardrails detections
- T1480.001 Environmental Keying detections
- T1480.002 Mutual Exclusion detections
- T1482 Domain Trust Discovery detections
- T1484 Domain or Tenant Policy Modification detections
- T1484.001 Group Policy Modification detections
- T1484.002 Trust Modification detections
- T1485 Data Destruction detections
- T1485.001 Lifecycle-Triggered Deletion detections
- T1486 Data Encrypted for Impact detections
- T1489 Service Stop detections
- T1490 Inhibit System Recovery detections
- T1491 Defacement detections
- T1491.001 Internal Defacement detections
- T1491.002 External Defacement detections
- T1495 Firmware Corruption detections
- T1496 Resource Hijacking detections
- T1496.001 Compute Hijacking detections
- T1496.002 Bandwidth Hijacking detections
- T1496.003 SMS Pumping detections
- T1496.004 Cloud Service Hijacking detections
- T1497 Virtualization/Sandbox Evasion detections
- T1497.001 System Checks detections
- T1497.002 User Activity Based Checks detections
- T1497.003 Time Based Checks detections
- T1498 Network Denial of Service detections
- T1498.001 Direct Network Flood detections
- T1498.002 Reflection Amplification detections
- T1499 Endpoint Denial of Service detections
- T1499.001 OS Exhaustion Flood detections
- T1499.002 Service Exhaustion Flood detections
- T1499.003 Application Exhaustion Flood detections
- T1499.004 Application or System Exploitation detections
- T1505 Server Software Component detections
- T1505.001 SQL Stored Procedures detections
- T1505.002 Transport Agent detections
- T1505.003 Web Shell detections
- T1505.004 IIS Components detections
- T1505.005 Terminal Services DLL detections
- T1505.006 vSphere Installation Bundles detections
- T1518 Software Discovery detections
- T1518.001 Security Software Discovery detections
- T1518.002 Backup Software Discovery detections
- T1525 Implant Internal Image detections
- T1526 Cloud Service Discovery detections
- T1528 Steal Application Access Token detections
- T1529 System Shutdown/Reboot detections
- T1530 Data from Cloud Storage detections
- T1531 Account Access Removal detections
- T1534 Internal Spearphishing detections
- T1535 Unused/Unsupported Cloud Regions detections
- T1537 Transfer Data to Cloud Account detections
- T1538 Cloud Service Dashboard detections
- T1539 Steal Web Session Cookie detections
- T1542 Pre-OS Boot detections
- T1542.001 System Firmware detections
- T1542.002 Component Firmware detections
- T1542.003 Bootkit detections
- T1542.004 ROMMONkit detections
- T1542.005 TFTP Boot detections
- T1543 Create or Modify System Process detections
- T1543.001 Launch Agent detections
- T1543.002 Systemd Service detections
- T1543.003 Windows Service detections
- T1543.004 Launch Daemon detections
- T1543.005 Container Service detections
- T1546 Event Triggered Execution detections
- T1546.001 Change Default File Association detections
- T1546.002 Screensaver detections
- T1546.003 Windows Management Instrumentation Event Subscription detections
- T1546.004 Unix Shell Configuration Modification detections
- T1546.005 Trap detections
- T1546.006 LC_LOAD_DYLIB Addition detections
- T1546.007 Netsh Helper DLL detections
- T1546.008 Accessibility Features detections
- T1546.009 AppCert DLLs detections
- T1546.010 AppInit DLLs detections
- T1546.011 Application Shimming detections
- T1546.012 Image File Execution Options Injection detections
- T1546.013 PowerShell Profile detections
- T1546.014 Emond detections
- T1546.015 Component Object Model Hijacking detections
- T1546.016 Installer Packages detections
- T1546.017 Udev Rules detections
- T1546.018 Python Startup Hooks detections
- T1547 Boot or Logon Autostart Execution detections
- T1547.001 Registry Run Keys / Startup Folder detections
- T1547.002 Authentication Package detections
- T1547.003 Time Providers detections
- T1547.004 Winlogon Helper DLL detections
- T1547.005 Security Support Provider detections
- T1547.006 Kernel Modules and Extensions detections
- T1547.007 Re-opened Applications detections
- T1547.008 LSASS Driver detections
- T1547.009 Shortcut Modification detections
- T1547.010 Port Monitors detections
- T1547.012 Print Processors detections
- T1547.013 XDG Autostart Entries detections
- T1547.014 Active Setup detections
- T1547.015 Login Items detections
- T1548 Abuse Elevation Control Mechanism detections
- T1548.001 Setuid and Setgid detections
- T1548.002 Bypass User Account Control detections
- T1548.003 Sudo and Sudo Caching detections
- T1548.004 Elevated Execution with Prompt detections
- T1548.005 Temporary Elevated Cloud Access detections
- T1548.006 TCC Manipulation detections
- T1550 Use Alternate Authentication Material detections
- T1550.001 Application Access Token detections
- T1550.002 Pass the Hash detections
- T1550.003 Pass the Ticket detections
- T1550.004 Web Session Cookie detections
- T1552 Unsecured Credentials detections
- T1552.001 Credentials In Files detections
- T1552.002 Credentials in Registry detections
- T1552.003 Shell History detections
- T1552.004 Private Keys detections
- T1552.005 Cloud Instance Metadata API detections
- T1552.006 Group Policy Preferences detections
- T1552.007 Container API detections
- T1552.008 Chat Messages detections
- T1553 Subvert Trust Controls detections
- T1553.001 Gatekeeper Bypass detections
- T1553.002 Code Signing detections
- T1553.003 SIP and Trust Provider Hijacking detections
- T1553.004 Install Root Certificate detections
- T1553.005 Mark-of-the-Web Bypass detections
- T1553.006 Code Signing Policy Modification detections
- T1554 Compromise Host Software Binary detections
- T1555 Credentials from Password Stores detections
- T1555.001 Keychain detections
- T1555.002 Securityd Memory detections
- T1555.003 Credentials from Web Browsers detections
- T1555.004 Windows Credential Manager detections
- T1555.005 Password Managers detections
- T1555.006 Cloud Secrets Management Stores detections
- T1556 Modify Authentication Process detections
- T1556.001 Domain Controller Authentication detections
- T1556.002 Password Filter DLL detections
- T1556.003 Pluggable Authentication Modules detections
- T1556.004 Network Device Authentication detections
- T1556.005 Reversible Encryption detections
- T1556.006 Multi-Factor Authentication detections
- T1556.007 Hybrid Identity detections
- T1556.008 Network Provider DLL detections
- T1556.009 Conditional Access Policies detections
- T1557 Adversary-in-the-Middle detections
- T1557.001 Name Resolution Poisoning and SMB Relay detections
- T1557.002 ARP Cache Poisoning detections
- T1557.003 DHCP Spoofing detections
- T1557.004 Evil Twin detections
- T1558 Steal or Forge Kerberos Tickets detections
- T1558.001 Golden Ticket detections
- T1558.002 Silver Ticket detections
- T1558.003 Kerberoasting detections
- T1558.004 AS-REP Roasting detections
- T1558.005 Ccache Files detections
- T1559 Inter-Process Communication detections
- T1559.001 Component Object Model detections
- T1559.002 Dynamic Data Exchange detections
- T1559.003 XPC Services detections
- T1560 Archive Collected Data detections
- T1560.001 Archive via Utility detections
- T1560.002 Archive via Library detections
- T1560.003 Archive via Custom Method detections
- T1561 Disk Wipe detections
- T1561.001 Disk Content Wipe detections
- T1561.002 Disk Structure Wipe detections
- T1563 Remote Service Session Hijacking detections
- T1563.001 SSH Hijacking detections
- T1563.002 RDP Hijacking detections
- T1564 Hide Artifacts detections
- T1564.001 Hidden Files and Directories detections
- T1564.002 Hidden Users detections
- T1564.003 Hidden Window detections
- T1564.004 NTFS File Attributes detections
- T1564.005 Hidden File System detections
- T1564.006 Run Virtual Instance detections
- T1564.007 VBA Stomping detections
- T1564.008 Email Hiding Rules detections
- T1564.009 Resource Forking detections
- T1564.010 Process Argument Spoofing detections
- T1564.011 Ignore Process Interrupts detections
- T1564.012 File/Path Exclusions detections
- T1564.013 Bind Mounts detections
- T1564.014 Extended Attributes detections
- T1565 Data Manipulation detections
- T1565.001 Stored Data Manipulation detections
- T1565.002 Transmitted Data Manipulation detections
- T1565.003 Runtime Data Manipulation detections
- T1566 Phishing detections
- T1566.001 Spearphishing Attachment detections
- T1566.002 Spearphishing Link detections
- T1566.003 Spearphishing via Service detections
- T1566.004 Spearphishing Voice detections
- T1567 Exfiltration Over Web Service detections
- T1567.001 Exfiltration to Code Repository detections
- T1567.002 Exfiltration to Cloud Storage detections
- T1567.003 Exfiltration to Text Storage Sites detections
- T1567.004 Exfiltration Over Webhook detections
- T1568 Dynamic Resolution detections
- T1568.001 Fast Flux DNS detections
- T1568.002 Domain Generation Algorithms detections
- T1568.003 DNS Calculation detections
- T1569 System Services detections
- T1569.001 Launchctl detections
- T1569.002 Service Execution detections
- T1569.003 Systemctl detections
- T1570 Lateral Tool Transfer detections
- T1571 Non-Standard Port detections
- T1572 Protocol Tunneling detections
- T1573 Encrypted Channel detections
- T1573.001 Symmetric Cryptography detections
- T1573.002 Asymmetric Cryptography detections
- T1574 Hijack Execution Flow detections
- T1574.001 DLL detections
- T1574.004 Dylib Hijacking detections
- T1574.005 Executable Installer File Permissions Weakness detections
- T1574.006 Dynamic Linker Hijacking detections
- T1574.007 Path Interception by PATH Environment Variable detections
- T1574.008 Path Interception by Search Order Hijacking detections
- T1574.009 Path Interception by Unquoted Path detections
- T1574.010 Services File Permissions Weakness detections
- T1574.011 Services Registry Permissions Weakness detections
- T1574.012 COR_PROFILER detections
- T1574.013 KernelCallbackTable detections
- T1574.014 AppDomainManager detections
- T1578 Modify Cloud Compute Infrastructure detections
- T1578.001 Create Snapshot detections
- T1578.002 Create Cloud Instance detections
- T1578.003 Delete Cloud Instance detections
- T1578.004 Revert Cloud Instance detections
- T1578.005 Modify Cloud Compute Configurations detections
- T1580 Cloud Infrastructure Discovery detections
- T1583 Acquire Infrastructure detections
- T1583.001 Domains detections
- T1583.002 DNS Server detections
- T1583.003 Virtual Private Server detections
- T1583.004 Server detections
- T1583.005 Botnet detections
- T1583.006 Web Services detections
- T1583.007 Serverless detections
- T1583.008 Malvertising detections
- T1584 Compromise Infrastructure detections
- T1584.001 Domains detections
- T1584.002 DNS Server detections
- T1584.003 Virtual Private Server detections
- T1584.004 Server detections
- T1584.005 Botnet detections
- T1584.006 Web Services detections
- T1584.007 Serverless detections
- T1584.008 Network Devices detections
- T1585 Establish Accounts detections
- T1585.001 Social Media Accounts detections
- T1585.002 Email Accounts detections
- T1585.003 Cloud Accounts detections
- T1586 Compromise Accounts detections
- T1586.001 Social Media Accounts detections
- T1586.002 Email Accounts detections
- T1586.003 Cloud Accounts detections
- T1587 Develop Capabilities detections
- T1587.001 Malware detections
- T1587.002 Code Signing Certificates detections
- T1587.003 Digital Certificates detections
- T1587.004 Exploits detections
- T1588 Obtain Capabilities detections
- T1588.001 Malware detections
- T1588.002 Tool detections
- T1588.003 Code Signing Certificates detections
- T1588.004 Digital Certificates detections
- T1588.005 Exploits detections
- T1588.006 Vulnerabilities detections
- T1588.007 Artificial Intelligence detections
- T1589 Gather Victim Identity Information detections
- T1589.001 Credentials detections
- T1589.002 Email Addresses detections
- T1589.003 Employee Names detections
- T1590 Gather Victim Network Information detections
- T1590.001 Domain Properties detections
- T1590.002 DNS detections
- T1590.003 Network Trust Dependencies detections
- T1590.004 Network Topology detections
- T1590.005 IP Addresses detections
- T1590.006 Network Security Appliances detections
- T1591 Gather Victim Org Information detections
- T1591.001 Determine Physical Locations detections
- T1591.002 Business Relationships detections
- T1591.003 Identify Business Tempo detections
- T1591.004 Identify Roles detections
- T1592 Gather Victim Host Information detections
- T1592.001 Hardware detections
- T1592.002 Software detections
- T1592.003 Firmware detections
- T1592.004 Client Configurations detections
- T1593 Search Open Websites/Domains detections
- T1593.001 Social Media detections
- T1593.002 Search Engines detections
- T1593.003 Code Repositories detections
- T1594 Search Victim-Owned Websites detections
- T1595 Active Scanning detections
- T1595.001 Scanning IP Blocks detections
- T1595.002 Vulnerability Scanning detections
- T1595.003 Wordlist Scanning detections
- T1596 Search Open Technical Databases detections
- T1596.001 DNS/Passive DNS detections
- T1596.002 WHOIS detections
- T1596.003 Digital Certificates detections
- T1596.004 CDNs detections
- T1596.005 Scan Databases detections
- T1597 Search Closed Sources detections
- T1597.001 Threat Intel Vendors detections
- T1597.002 Purchase Technical Data detections
- T1598 Phishing for Information detections
- T1598.001 Spearphishing Service detections
- T1598.002 Spearphishing Attachment detections
- T1598.003 Spearphishing Link detections
- T1598.004 Spearphishing Voice detections
- T1599 Network Boundary Bridging detections
- T1599.001 Network Address Translation Traversal detections
- T1600 Weaken Encryption detections
- T1600.001 Reduce Key Space detections
- T1600.002 Disable Crypto Hardware detections
- T1601 Modify System Image detections
- T1601.001 Patch System Image detections
- T1601.002 Downgrade System Image detections
- T1602 Data from Configuration Repository detections
- T1602.001 SNMP (MIB Dump) detections
- T1602.002 Network Device Configuration Dump detections
- T1606 Forge Web Credentials detections
- T1606.001 Web Cookies detections
- T1606.002 SAML Tokens detections
- T1608 Stage Capabilities detections
- T1608.001 Upload Malware detections
- T1608.002 Upload Tool detections
- T1608.003 Install Digital Certificate detections
- T1608.004 Drive-by Target detections
- T1608.005 Link Target detections
- T1608.006 SEO Poisoning detections
- T1609 Container Administration Command detections
- T1610 Deploy Container detections
- T1611 Escape to Host detections
- T1612 Build Image on Host detections
- T1613 Container and Resource Discovery detections
- T1614 System Location Discovery detections
- T1614.001 System Language Discovery detections
- T1615 Group Policy Discovery detections
- T1619 Cloud Storage Object Discovery detections
- T1620 Reflective Code Loading detections
- T1621 Multi-Factor Authentication Request Generation detections
- T1622 Debugger Evasion detections
- T1647 Plist File Modification detections
- T1648 Serverless Execution detections
- T1649 Steal or Forge Authentication Certificates detections
- T1650 Acquire Access detections
- T1651 Cloud Administration Command detections
- T1652 Device Driver Discovery detections
- T1653 Power Settings detections
- T1654 Log Enumeration detections
- T1657 Financial Theft detections
- T1659 Content Injection detections
- T1665 Hide Infrastructure detections
- T1666 Modify Cloud Resource Hierarchy detections
- T1667 Email Bombing detections
- T1668 Exclusive Control detections
- T1669 Wi-Fi Networks detections
- T1671 Cloud Application Integration detections
- T1673 Virtual Machine Discovery detections
- T1674 Input Injection detections
- T1675 ESXi Administration Command detections
- T1677 Poisoned Pipeline Execution detections
- T1678 Delay Execution detections
- T1679 Selective Exclusion detections
- T1680 Local Storage Discovery detections
- T1681 Search Threat Vendor Data detections
- T1682 Query Public AI Services detections
- T1683 Generate Content detections
- T1683.001 Written Content detections
- T1683.002 Audio-Visual Content detections
- T1684 Social Engineering detections
- T1684.001 Impersonation detections
- T1684.002 Email Spoofing detections
- T1685 Disable or Modify Tools detections
- T1685.001 Disable or Modify Windows Event Log detections
- T1685.002 Disable or Modify Cloud Log detections
- T1685.003 Modify or Spoof Tool UI detections
- T1685.004 Disable or Modify Linux Audit System Log detections
- T1685.005 Clear Windows Event Logs detections
- T1685.006 Clear Linux or Mac System Logs detections
- T1686 Disable or Modify System Firewall detections
- T1686.001 Cloud Firewall detections
- T1686.002 Network Device Firewall detections
- T1686.003 Windows Host Firewall detections
- T1687 Exploitation for Defense Impairment detections
- T1688 Safe Mode Boot detections
- T1689 Downgrade Attack detections
- T1690 Prevent Command History Logging detections
- T0800 Activate Firmware Update Mode detections
- T0801 Monitor Process State detections
- T0802 Automated Collection detections
- T0806 Brute Force I/O detections
- T0807 Command-Line Interface detections
- T0809 Data Destruction detections
- T0811 Data from Information Repositories detections
- T0813 Denial of Control detections
- T0814 Denial of Service detections
- T0815 Denial of View detections
- T0816 Device Restart/Shutdown detections
- T0817 Drive-by Compromise detections
- T0819 Exploit Public-Facing Application detections
- T0820 Exploitation for Evasion detections
- T0821 Modify Controller Tasking detections
- T0822 External Remote Services detections
- T0823 Graphical User Interface detections
- T0826 Loss of Availability detections
- T0827 Loss of Control detections
- T0828 Loss of Productivity and Revenue detections
- T0829 Loss of View detections
- T0830 Adversary-in-the-Middle detections
- T0831 Manipulation of Control detections
- T0832 Manipulation of View detections
- T0834 Native API detections
- T0835 Manipulate I/O Image detections
- T0836 Modify Parameter detections
- T0837 Loss of Protection detections
- T0838 Modify Alarm Settings detections
- T0840 Network Connection Enumeration detections
- T0842 Network Sniffing detections
- T0843 Program Download detections
- T0843.001 Download All detections
- T0843.002 Online Edit detections
- T0843.003 Program Append detections
- T0845 Program Upload detections
- T0846 Remote System Discovery detections
- T0846.001 Port Scan detections
- T0846.002 Broadcast Discovery detections
- T0846.003 Multicast Discovery detections
- T0847 Replication Through Removable Media detections
- T0848 Rogue Master detections
- T0849 Masquerading detections
- T0851 Rootkit detections
- T0852 Screen Capture detections
- T0853 Scripting detections
- T0858 Change Operating Mode detections
- T0859 Valid Accounts detections
- T0860 Wireless Compromise detections
- T0861 Point & Tag Identification detections
- T0862 Supply Chain Compromise detections
- T0863 User Execution detections
- T0864 Transient Cyber Asset detections
- T0865 Spearphishing Attachment detections
- T0866 Exploitation of Remote Services detections
- T0867 Lateral Tool Transfer detections
- T0868 Detect Operating Mode detections
- T0869 Standard Application Layer Protocol detections
- T0871 Execution through API detections
- T0872 Indicator Removal on Host detections
- T0873 Project File Infection detections
- T0873.001 Siemens Project File Format detections
- T0874 Hooking detections
- T0877 I/O Image detections
- T0878 Alarm Suppression detections
- T0879 Damage to Property detections
- T0880 Loss of Safety detections
- T0881 Service Stop detections
- T0882 Theft of Operational Information detections
- T0883 Internet Accessible Device detections
- T0884 Connection Proxy detections
- T0885 Commonly Used Port detections
- T0886 Remote Services detections
- T0887 Wireless Sniffing detections
- T0888 Remote System Information Discovery detections
- T0889 Modify Program detections
- T0890 Exploitation for Privilege Escalation detections
- T0892 Change Credential detections
- T0893 Data from Local System detections
- T0894 System Binary Proxy Execution detections
- T0895 Autorun Image detections
- T1691 Block Operational Technology Message detections
- T1691.001 Command Message detections
- T1691.002 Reporting Message detections
- T1692 Unauthorized Message detections
- T1692.001 Command Message detections
- T1692.002 Reporting Message detections
- T1693 Modify Firmware detections
- T1693.001 System Firmware detections
- T1693.002 Module Firmware detections
- T1694 Insecure Credentials detections
- T1694.001 Default Credentials detections
- T1694.002 Hardcoded Credentials detections
- T1695 Block Communications detections
- T1695.001 Serial COM detections
- T1695.002 Ethernet detections
- T1695.003 Wi-Fi detections
- T1398 Boot or Logon Initialization Scripts detections
- T1404 Exploitation for Privilege Escalation detections
- T1406 Obfuscated Files or Information detections
- T1406.001 Steganography detections
- T1406.002 Software Packing detections
- T1407 Download New Code at Runtime detections
- T1409 Stored Application Data detections
- T1414 Clipboard Data detections
- T1417 Input Capture detections
- T1417.001 Keylogging detections
- T1417.002 GUI Input Capture detections
- T1418 Software Discovery detections
- T1418.001 Security Software Discovery detections
- T1420 File and Directory Discovery detections
- T1421 System Network Connections Discovery detections
- T1422 System Network Configuration Discovery detections
- T1422.001 Internet Connection Discovery detections
- T1422.002 Wi-Fi Discovery detections
- T1423 Network Service Scanning detections
- T1424 Process Discovery detections
- T1426 System Information Discovery detections
- T1428 Exploitation of Remote Services detections
- T1429 Audio Capture detections
- T1430 Location Tracking detections
- T1430.001 Remote Device Management Services detections
- T1430.002 Impersonate SS7 Nodes detections
- T1437 Application Layer Protocol detections
- T1437.001 Web Protocols detections
- T1451 SIM Card Swap detections
- T1453 Abuse Accessibility Features detections
- T1456 Drive-By Compromise detections
- T1458 Replication Through Removable Media detections
- T1461 Lockscreen Bypass detections
- T1464 Network Denial of Service detections
- T1471 Data Encrypted for Impact detections
- T1474 Supply Chain Compromise detections
- T1474.001 Compromise Software Dependencies and Development Tools detections
- T1474.002 Compromise Hardware Supply Chain detections
- T1474.003 Compromise Software Supply Chain detections
- T1481 Web Service detections
- T1481.001 Dead Drop Resolver detections
- T1481.002 Bidirectional Communication detections
- T1481.003 One-Way Communication detections
- T1509 Non-Standard Port detections
- T1512 Video Capture detections
- T1513 Screen Capture detections
- T1516 Input Injection detections
- T1517 Access Notifications detections
- T1521 Encrypted Channel detections
- T1521.001 Symmetric Cryptography detections
- T1521.002 Asymmetric Cryptography detections
- T1521.003 SSL Pinning detections
- T1532 Archive Collected Data detections
- T1533 Data from Local System detections
- T1541 Foreground Persistence detections
- T1544 Ingress Tool Transfer detections
- T1575 Native API detections
- T1577 Compromise Application Executable detections
- T1582 SMS Control detections
- T1603 Scheduled Task/Job detections
- T1604 Proxy Through Victim detections
- T1616 Call Control detections
- T1617 Hooking detections
- T1623 Command and Scripting Interpreter detections
- T1623.001 Unix Shell detections
- T1624 Event Triggered Execution detections
- T1624.001 Broadcast Receivers detections
- T1625 Hijack Execution Flow detections
- T1625.001 System Runtime API Hijacking detections
- T1626 Abuse Elevation Control Mechanism detections
- T1626.001 Device Administrator Permissions detections
- T1627 Execution Guardrails detections
- T1627.001 Geofencing detections
- T1628 Hide Artifacts detections
- T1628.001 Suppress Application Icon detections
- T1628.002 User Evasion detections
- T1628.003 Conceal Multimedia Files detections
- T1629 Impair Defenses detections
- T1629.001 Prevent Application Removal detections
- T1629.002 Device Lockout detections
- T1629.003 Disable or Modify Tools detections
- T1630 Indicator Removal on Host detections
- T1630.001 Uninstall Malicious Application detections
- T1630.002 File Deletion detections
- T1630.003 Disguise Root/Jailbreak Indicators detections
- T1631 Process Injection detections
- T1631.001 Ptrace System Calls detections
- T1632 Subvert Trust Controls detections
- T1632.001 Code Signing Policy Modification detections
- T1633 Virtualization/Sandbox Evasion detections
- T1633.001 System Checks detections
- T1634 Credentials from Password Store detections
- T1634.001 Keychain detections
- T1635 Steal Application Access Token detections
- T1635.001 URI Hijacking detections
- T1636 Protected User Data detections
- T1636.001 Calendar Entries detections
- T1636.002 Call Log detections
- T1636.003 Contact List detections
- T1636.004 SMS Messages detections
- T1636.005 Accounts detections
- T1637 Dynamic Resolution detections
- T1637.001 Domain Generation Algorithms detections
- T1638 Adversary-in-the-Middle detections
- T1639 Exfiltration Over Alternative Protocol detections
- T1639.001 Exfiltration Over Unencrypted Non-C2 Protocol detections
- T1640 Account Access Removal detections
- T1641 Data Manipulation detections
- T1641.001 Transmitted Data Manipulation detections
- T1642 Endpoint Denial of Service detections
- T1643 Generate Traffic from Victim detections
- T1644 Out of Band Data detections
- T1645 Compromise Client Software Binary detections
- T1646 Exfiltration Over C2 Channel detections
- T1655 Masquerading detections
- T1655.001 Match Legitimate Name or Location detections
- T1658 Exploitation for Client Execution detections
- T1660 Phishing detections
- T1661 Application Versioning detections
- T1662 Data Destruction detections
- T1663 Remote Access Software detections
- T1664 Exploitation for Initial Access detections
- T1670 Virtualization Solution detections
- T1676 Linked Devices detections
Connected ecosystem references
Explore the three modules
Attack Tools · Attack Simulations · Detection Rules · Telemetry · Tags
Individual rule sources
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.