1200KM / tag
Windows — platform tag
1101 related reference pages for platform: Windows.
Meaning and evidence boundary
Navigation membership is based on explicit metadata in this pinned module, not a claim of detection effectiveness or live validation.
Related pages
- AADInternals · tool
- Active Directory Credential Request · telemetry
- Active Directory Object Access · telemetry
- Active Directory Object Creation · telemetry
- Active Directory Object Deletion · telemetry
- Active Directory Object Modification · telemetry
- AdFind · tool
- Application Log Content · telemetry
- Arp · tool
- AsyncRAT · tool
- at · tool
- attrib · tool
- BITSAdmin · tool
- BloodHound · tool
- Brute Ratel C4 · tool
- Cachedump · tool
- CARROTBALL · tool
- certutil · tool
- cipher.exe · tool
- Cloud Service Disable · telemetry
- Cloud Service Enumeration · telemetry
- Cloud Service Metadata · telemetry
- Cloud Service Modification · telemetry
- Cloud Storage Access · telemetry
- Cloud Storage Deletion · telemetry
- Cloud Storage Enumeration · telemetry
- Cloud Storage Modification · telemetry
- cmd · tool
- Cobalt Strike · tool
- Command Execution · telemetry
- ConnectWise · tool
- Container Creation · telemetry
- Container Enumeration · telemetry
- Container Start · telemetry
- Covenant · tool
- CrackMapExec · tool
- CSPY Downloader · tool
- DCRAT · tool
- Diskpart · tool
- Domain Registration · telemetry
- Donut · tool
- Drive Access · telemetry
- Drive Creation · telemetry
- Drive Modification · telemetry
- Driver Load · telemetry
- Driver Metadata · telemetry
- dsquery · tool
- Empire · tool
- esentutl · tool
- Expand · tool
- Fgdump · tool
- File Access · telemetry
- File Creation · telemetry
- File Deletion · telemetry
- File Metadata · telemetry
- File Modification · telemetry
- Firewall Rule Modification · telemetry
- Firmware Modification · telemetry
- FRP · tool
- ftp · tool
- Group Enumeration · telemetry
- gsecdump · tool
- Host Status · telemetry
- HTRAN · tool
- Image Metadata · telemetry
- Imminent Monitor · tool
- Impacket · tool
- Instance Creation · telemetry
- Instance Enumeration · telemetry
- Instance Modification · telemetry
- Instance Start · telemetry
- Instance Stop · telemetry
- IronNetInjector · tool
- Kernel Module Load · telemetry
- Koadic · tool
- LaZagne · tool
- Logon Session Creation · telemetry
- Logon Session Metadata · telemetry
- Lslsass · tool
- MailSniper · tool
- MCMD · tool
- meek · tool
- Mimikatz · tool
- Module Load · telemetry
- Mythic · tool
- Named Pipe Metadata · telemetry
- NBTscan · tool
- Net · tool
- netsh · tool
- Network Connection Creation · telemetry
- Network Share Access · telemetry
- Network Traffic Content · telemetry
- Network Traffic Flow · telemetry
- ngrok · tool
- Nltest · tool
- NPPSPY · tool
- OS API Execution · telemetry
- Out1 · tool
- PcShare · tool
- PoshC2 · tool
- PowerSploit · tool
- Process Access · telemetry
- Process Creation · telemetry
- Process Metadata · telemetry
- Process Modification · telemetry
- Process Termination · telemetry
- PsExec · tool
- Pupy · tool
- pwdump · tool
- QuasarRAT · tool
- Quick Assist · tool
- RawDisk · tool
- Rclone · tool
- Reg · tool
- Remcos · tool
- RemoteUtilities · tool
- Response Content · telemetry
- Response Metadata · telemetry
- Rubeus · tool
- Ruler · tool
- Scheduled Job Creation · telemetry
- Scheduled Job Metadata · telemetry
- Scheduled Job Modification · telemetry
- schtasks · tool
- Script Execution · telemetry
- SDelete · tool
- Service Creation · telemetry
- Service Metadata · telemetry
- Service Modification · telemetry
- ShimRatReporter · tool
- SILENTTRINITY · tool
- Sliver · tool
- Snapshot Creation · telemetry
- Snapshot Deletion · telemetry
- spwebmember · tool
- T1001 Data Obfuscation · simulation
- T1001 Data Obfuscation detections · detection
- T1001.001 Junk Data · simulation
- T1001.001 Junk Data detections · detection
- T1001.002 Steganography · simulation
- T1001.002 Steganography detections · detection
- T1001.003 Protocol or Service Impersonation · simulation
- T1001.003 Protocol or Service Impersonation detections · detection
- T1003 OS Credential Dumping · simulation
- T1003 OS Credential Dumping detections · detection
- T1003.001 LSASS Memory · simulation
- T1003.001 LSASS Memory detections · detection
- T1003.002 Security Account Manager · simulation
- T1003.002 Security Account Manager detections · detection
- T1003.003 NTDS · simulation
- T1003.003 NTDS detections · detection
- T1003.004 LSA Secrets · simulation
- T1003.004 LSA Secrets detections · detection
- T1003.005 Cached Domain Credentials · simulation
- T1003.005 Cached Domain Credentials detections · detection
- T1003.006 DCSync · simulation
- T1003.006 DCSync detections · detection
- T1005 Data from Local System · simulation
- T1005 Data from Local System detections · detection
- T1006 Direct Volume Access · simulation
- T1006 Direct Volume Access detections · detection
- T1007 System Service Discovery · simulation
- T1007 System Service Discovery detections · detection
- T1008 Fallback Channels · simulation
- T1008 Fallback Channels detections · detection
- T1010 Application Window Discovery · simulation
- T1010 Application Window Discovery detections · detection
- T1011 Exfiltration Over Other Network Medium · simulation
- T1011 Exfiltration Over Other Network Medium detections · detection
- T1011.001 Exfiltration Over Bluetooth · simulation
- T1011.001 Exfiltration Over Bluetooth detections · detection
- T1012 Query Registry · simulation
- T1012 Query Registry detections · detection
- T1014 Rootkit · simulation
- T1014 Rootkit detections · detection
- T1016 System Network Configuration Discovery · simulation
- T1016 System Network Configuration Discovery detections · detection
- T1016.001 Internet Connection Discovery · simulation
- T1016.001 Internet Connection Discovery detections · detection
- T1016.002 Wi-Fi Discovery · simulation
- T1016.002 Wi-Fi Discovery detections · detection
- T1018 Remote System Discovery · simulation
- T1018 Remote System Discovery detections · detection
- T1020 Automated Exfiltration · simulation
- T1020 Automated Exfiltration detections · detection
- T1021 Remote Services · simulation
- T1021 Remote Services detections · detection
- T1021.001 Remote Desktop Protocol · simulation
- T1021.001 Remote Desktop Protocol detections · detection
- T1021.002 SMB/Windows Admin Shares · simulation
- T1021.002 SMB/Windows Admin Shares detections · detection
- T1021.003 Distributed Component Object Model · simulation
- T1021.003 Distributed Component Object Model detections · detection
- T1021.005 VNC · simulation
- T1021.005 VNC detections · detection
- T1021.006 Windows Remote Management · simulation
- T1021.006 Windows Remote Management detections · detection
- T1025 Data from Removable Media · simulation
- T1025 Data from Removable Media detections · detection
- T1027 Obfuscated Files or Information · simulation
- T1027 Obfuscated Files or Information detections · detection
- T1027.001 Binary Padding · simulation
- T1027.001 Binary Padding detections · detection
- T1027.002 Software Packing · simulation
- T1027.002 Software Packing detections · detection
- T1027.003 Steganography · simulation
- T1027.003 Steganography detections · detection
- T1027.004 Compile After Delivery · simulation
- T1027.004 Compile After Delivery detections · detection
- T1027.005 Indicator Removal from Tools · simulation
- T1027.005 Indicator Removal from Tools detections · detection
- T1027.006 HTML Smuggling · simulation
- T1027.006 HTML Smuggling detections · detection
- T1027.007 Dynamic API Resolution · simulation
- T1027.007 Dynamic API Resolution detections · detection
- T1027.008 Stripped Payloads · simulation
- T1027.008 Stripped Payloads detections · detection
- T1027.009 Embedded Payloads · simulation
- T1027.009 Embedded Payloads detections · detection
- T1027.010 Command Obfuscation · simulation
- T1027.010 Command Obfuscation detections · detection
- T1027.011 Fileless Storage · simulation
- T1027.011 Fileless Storage detections · detection
- T1027.012 LNK Icon Smuggling · simulation
- T1027.012 LNK Icon Smuggling detections · detection
- T1027.013 Encrypted/Encoded File · simulation
- T1027.013 Encrypted/Encoded File detections · detection
- T1027.014 Polymorphic Code · simulation
- T1027.014 Polymorphic Code detections · detection
- T1027.015 Compression · simulation
- T1027.015 Compression detections · detection
- T1027.016 Junk Code Insertion · simulation
- T1027.016 Junk Code Insertion detections · detection
- T1027.017 SVG Smuggling · simulation
- T1027.017 SVG Smuggling detections · detection
- T1027.018 Invisible Unicode · simulation
- T1027.018 Invisible Unicode detections · detection
- T1029 Scheduled Transfer · simulation
- T1029 Scheduled Transfer detections · detection
- T1030 Data Transfer Size Limits · simulation
- T1030 Data Transfer Size Limits detections · detection
- T1033 System Owner/User Discovery · simulation
- T1033 System Owner/User Discovery detections · detection
- T1036 Masquerading · simulation
- T1036 Masquerading detections · detection
- T1036.001 Invalid Code Signature · simulation
- T1036.001 Invalid Code Signature detections · detection
- T1036.002 Right-to-Left Override · simulation
- T1036.002 Right-to-Left Override detections · detection
- T1036.003 Rename Legitimate Utilities · simulation
- T1036.003 Rename Legitimate Utilities detections · detection
- T1036.004 Masquerade Task or Service · simulation
- T1036.004 Masquerade Task or Service detections · detection
- T1036.005 Match Legitimate Resource Name or Location · simulation
- T1036.005 Match Legitimate Resource Name or Location detections · detection
- T1036.007 Double File Extension · simulation
- T1036.007 Double File Extension detections · detection
- T1036.008 Masquerade File Type · simulation
- T1036.008 Masquerade File Type detections · detection
- T1036.010 Masquerade Account Name · simulation
- T1036.010 Masquerade Account Name detections · detection
- T1036.012 Browser Fingerprint · simulation
- T1036.012 Browser Fingerprint detections · detection
- T1037 Boot or Logon Initialization Scripts · simulation
- T1037 Boot or Logon Initialization Scripts detections · detection
- T1037.001 Logon Script (Windows) · simulation
- T1037.001 Logon Script (Windows) detections · detection
- T1037.003 Network Logon Script · simulation
- T1037.003 Network Logon Script detections · detection
- T1039 Data from Network Shared Drive · simulation
- T1039 Data from Network Shared Drive detections · detection
- T1040 Network Sniffing · simulation
- T1040 Network Sniffing detections · detection
- T1041 Exfiltration Over C2 Channel · simulation
- T1041 Exfiltration Over C2 Channel detections · detection
- T1046 Network Service Discovery · simulation
- T1046 Network Service Discovery detections · detection
- T1047 Windows Management Instrumentation · simulation
- T1047 Windows Management Instrumentation detections · detection
- T1048 Exfiltration Over Alternative Protocol · simulation
- T1048 Exfiltration Over Alternative Protocol detections · detection
- T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol · simulation
- T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol detections · detection
- T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol · simulation
- T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol detections · detection
- T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol · simulation
- T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol detections · detection
- T1049 System Network Connections Discovery · simulation
- T1049 System Network Connections Discovery detections · detection
- T1052 Exfiltration Over Physical Medium · simulation
- T1052 Exfiltration Over Physical Medium detections · detection
- T1052.001 Exfiltration over USB · simulation
- T1052.001 Exfiltration over USB detections · detection
- T1053 Scheduled Task/Job · simulation
- T1053 Scheduled Task/Job detections · detection
- T1053.002 At · simulation
- T1053.002 At detections · detection
- T1053.005 Scheduled Task · simulation
- T1053.005 Scheduled Task detections · detection
- T1055 Process Injection · simulation
- T1055 Process Injection detections · detection
- T1055.001 Dynamic-link Library Injection · simulation
- T1055.001 Dynamic-link Library Injection detections · detection
- T1055.002 Portable Executable Injection · simulation
- T1055.002 Portable Executable Injection detections · detection
- T1055.003 Thread Execution Hijacking · simulation
- T1055.003 Thread Execution Hijacking detections · detection
- T1055.004 Asynchronous Procedure Call · simulation
- T1055.004 Asynchronous Procedure Call detections · detection
- T1055.005 Thread Local Storage · simulation
- T1055.005 Thread Local Storage detections · detection
- T1055.011 Extra Window Memory Injection · simulation
- T1055.011 Extra Window Memory Injection detections · detection
- T1055.012 Process Hollowing · simulation
- T1055.012 Process Hollowing detections · detection
- T1055.013 Process Doppelgänging · simulation
- T1055.013 Process Doppelgänging detections · detection
- T1055.015 ListPlanting · simulation
- T1055.015 ListPlanting detections · detection
- T1056 Input Capture · simulation
- T1056 Input Capture detections · detection
- T1056.001 Keylogging · simulation
- T1056.001 Keylogging detections · detection
- T1056.002 GUI Input Capture · simulation
- T1056.002 GUI Input Capture detections · detection
- T1056.003 Web Portal Capture · simulation
- T1056.003 Web Portal Capture detections · detection
- T1056.004 Credential API Hooking · simulation
- T1056.004 Credential API Hooking detections · detection
- T1057 Process Discovery · simulation
- T1057 Process Discovery detections · detection
- T1059 Command and Scripting Interpreter · simulation
- T1059 Command and Scripting Interpreter detections · detection
- T1059.001 PowerShell · simulation
- T1059.001 PowerShell detections · detection
- T1059.003 Windows Command Shell · simulation
- T1059.003 Windows Command Shell detections · detection
- T1059.005 Visual Basic · simulation
- T1059.005 Visual Basic detections · detection
- T1059.006 Python · simulation
- T1059.006 Python detections · detection
- T1059.007 JavaScript · simulation
- T1059.007 JavaScript detections · detection
- T1059.010 AutoHotKey & AutoIT · simulation
- T1059.010 AutoHotKey & AutoIT detections · detection
- T1059.011 Lua · simulation
- T1059.011 Lua detections · detection
- T1068 Exploitation for Privilege Escalation · simulation
- T1068 Exploitation for Privilege Escalation detections · detection
- T1069 Permission Groups Discovery · simulation
- T1069 Permission Groups Discovery detections · detection
- T1069.001 Local Groups · simulation
- T1069.001 Local Groups detections · detection
- T1069.002 Domain Groups · simulation
- T1069.002 Domain Groups detections · detection
- T1070 Indicator Removal · simulation
- T1070 Indicator Removal detections · detection
- T1070.003 Clear Command History · simulation
- T1070.003 Clear Command History detections · detection
- T1070.004 File Deletion · simulation
- T1070.004 File Deletion detections · detection
- T1070.005 Network Share Connection Removal · simulation
- T1070.005 Network Share Connection Removal detections · detection
- T1070.006 Timestomp · simulation
- T1070.006 Timestomp detections · detection
- T1070.007 Clear Network Connection History and Configurations · simulation
- T1070.007 Clear Network Connection History and Configurations detections · detection
- T1070.008 Clear Mailbox Data · simulation
- T1070.008 Clear Mailbox Data detections · detection
- T1070.009 Clear Persistence · simulation
- T1070.009 Clear Persistence detections · detection
- T1070.010 Relocate Malware · simulation
- T1070.010 Relocate Malware detections · detection
- T1071 Application Layer Protocol · simulation
- T1071 Application Layer Protocol detections · detection
- T1071.001 Web Protocols · simulation
- T1071.001 Web Protocols detections · detection
- T1071.002 File Transfer Protocols · simulation
- T1071.002 File Transfer Protocols detections · detection
- T1071.003 Mail Protocols · simulation
- T1071.003 Mail Protocols detections · detection
- T1071.004 DNS · simulation
- T1071.004 DNS detections · detection
- T1071.005 Publish/Subscribe Protocols · simulation
- T1071.005 Publish/Subscribe Protocols detections · detection
- T1072 Software Deployment Tools · simulation
- T1072 Software Deployment Tools detections · detection
- T1074 Data Staged · simulation
- T1074 Data Staged detections · detection
- T1074.001 Local Data Staging · simulation
- T1074.001 Local Data Staging detections · detection
- T1074.002 Remote Data Staging · simulation
- T1074.002 Remote Data Staging detections · detection
- T1078 Valid Accounts · simulation
- T1078 Valid Accounts detections · detection
- T1078.001 Default Accounts · simulation
- T1078.001 Default Accounts detections · detection
- T1078.002 Domain Accounts · simulation
- T1078.002 Domain Accounts detections · detection
- T1078.003 Local Accounts · simulation
- T1078.003 Local Accounts detections · detection
- T1080 Taint Shared Content · simulation
- T1080 Taint Shared Content detections · detection
- T1082 System Information Discovery · simulation
- T1082 System Information Discovery detections · detection
- T1083 File and Directory Discovery · simulation
- T1083 File and Directory Discovery detections · detection
- T1087 Account Discovery · simulation
- T1087 Account Discovery detections · detection
- T1087.001 Local Account · simulation
- T1087.001 Local Account detections · detection
- T1087.002 Domain Account · simulation
- T1087.002 Domain Account detections · detection
- T1087.003 Email Account · simulation
- T1087.003 Email Account detections · detection
- T1090 Proxy · simulation
- T1090 Proxy detections · detection
- T1090.001 Internal Proxy · simulation
- T1090.001 Internal Proxy detections · detection
- T1090.002 External Proxy · simulation
- T1090.002 External Proxy detections · detection
- T1090.003 Multi-hop Proxy · simulation
- T1090.003 Multi-hop Proxy detections · detection
- T1090.004 Domain Fronting · simulation
- T1090.004 Domain Fronting detections · detection
- T1091 Replication Through Removable Media · simulation
- T1091 Replication Through Removable Media detections · detection
- T1092 Communication Through Removable Media · simulation
- T1092 Communication Through Removable Media detections · detection
- T1095 Non-Application Layer Protocol · simulation
- T1095 Non-Application Layer Protocol detections · detection
- T1098 Account Manipulation · simulation
- T1098 Account Manipulation detections · detection
- T1098.002 Additional Email Delegate Permissions · simulation
- T1098.002 Additional Email Delegate Permissions detections · detection
- T1098.005 Device Registration · simulation
- T1098.005 Device Registration detections · detection
- T1098.007 Additional Local or Domain Groups · simulation
- T1098.007 Additional Local or Domain Groups detections · detection
- T1102 Web Service · simulation
- T1102 Web Service detections · detection
- T1102.001 Dead Drop Resolver · simulation
- T1102.001 Dead Drop Resolver detections · detection
- T1102.002 Bidirectional Communication · simulation
- T1102.002 Bidirectional Communication detections · detection
- T1102.003 One-Way Communication · simulation
- T1102.003 One-Way Communication detections · detection
- T1104 Multi-Stage Channels · simulation
- T1104 Multi-Stage Channels detections · detection
- T1105 Ingress Tool Transfer · simulation
- T1105 Ingress Tool Transfer detections · detection
- T1106 Native API · simulation
- T1106 Native API detections · detection
- T1110 Brute Force · simulation
- T1110 Brute Force detections · detection
- T1110.001 Password Guessing · simulation
- T1110.001 Password Guessing detections · detection
- T1110.002 Password Cracking · simulation
- T1110.002 Password Cracking detections · detection
- T1110.003 Password Spraying · simulation
- T1110.003 Password Spraying detections · detection
- T1110.004 Credential Stuffing · simulation
- T1110.004 Credential Stuffing detections · detection
- T1111 Multi-Factor Authentication Interception · simulation
- T1111 Multi-Factor Authentication Interception detections · detection
- T1112 Modify Registry · simulation
- T1112 Modify Registry detections · detection
- T1113 Screen Capture · simulation
- T1113 Screen Capture detections · detection
- T1114 Email Collection · simulation
- T1114 Email Collection detections · detection
- T1114.001 Local Email Collection · simulation
- T1114.001 Local Email Collection detections · detection
- T1114.002 Remote Email Collection · simulation
- T1114.002 Remote Email Collection detections · detection
- T1114.003 Email Forwarding Rule · simulation
- T1114.003 Email Forwarding Rule detections · detection
- T1115 Clipboard Data · simulation
- T1115 Clipboard Data detections · detection
- T1119 Automated Collection · simulation
- T1119 Automated Collection detections · detection
- T1120 Peripheral Device Discovery · simulation
- T1120 Peripheral Device Discovery detections · detection
- T1123 Audio Capture · simulation
- T1123 Audio Capture detections · detection
- T1124 System Time Discovery · simulation
- T1124 System Time Discovery detections · detection
- T1125 Video Capture · simulation
- T1125 Video Capture detections · detection
- T1127 Trusted Developer Utilities Proxy Execution · simulation
- T1127 Trusted Developer Utilities Proxy Execution detections · detection
- T1127.001 MSBuild · simulation
- T1127.001 MSBuild detections · detection
- T1127.002 ClickOnce · simulation
- T1127.002 ClickOnce detections · detection
- T1127.003 JamPlus · simulation
- T1127.003 JamPlus detections · detection
- T1129 Shared Modules · simulation
- T1129 Shared Modules detections · detection
- T1132 Data Encoding · simulation
- T1132 Data Encoding detections · detection
- T1132.001 Standard Encoding · simulation
- T1132.001 Standard Encoding detections · detection
- T1132.002 Non-Standard Encoding · simulation
- T1132.002 Non-Standard Encoding detections · detection
- T1133 External Remote Services · simulation
- T1133 External Remote Services detections · detection
- T1134 Access Token Manipulation · simulation
- T1134 Access Token Manipulation detections · detection
- T1134.001 Token Impersonation/Theft · simulation
- T1134.001 Token Impersonation/Theft detections · detection
- T1134.002 Create Process with Token · simulation
- T1134.002 Create Process with Token detections · detection
- T1134.003 Make and Impersonate Token · simulation
- T1134.003 Make and Impersonate Token detections · detection
- T1134.004 Parent PID Spoofing · simulation
- T1134.004 Parent PID Spoofing detections · detection
- T1134.005 SID-History Injection · simulation
- T1134.005 SID-History Injection detections · detection
- T1135 Network Share Discovery · simulation
- T1135 Network Share Discovery detections · detection
- T1136 Create Account · simulation
- T1136 Create Account detections · detection
- T1136.001 Local Account · simulation
- T1136.001 Local Account detections · detection
- T1136.002 Domain Account · simulation
- T1136.002 Domain Account detections · detection
- T1137 Office Application Startup · simulation
- T1137 Office Application Startup detections · detection
- T1137.001 Office Template Macros · simulation
- T1137.001 Office Template Macros detections · detection
- T1137.002 Office Test · simulation
- T1137.002 Office Test detections · detection
- T1137.003 Outlook Forms · simulation
- T1137.003 Outlook Forms detections · detection
- T1137.004 Outlook Home Page · simulation
- T1137.004 Outlook Home Page detections · detection
- T1137.005 Outlook Rules · simulation
- T1137.005 Outlook Rules detections · detection
- T1137.006 Add-ins · simulation
- T1137.006 Add-ins detections · detection
- T1140 Deobfuscate/Decode Files or Information · simulation
- T1140 Deobfuscate/Decode Files or Information detections · detection
- T1176 Software Extensions · simulation
- T1176 Software Extensions detections · detection
- T1176.001 Browser Extensions · simulation
- T1176.001 Browser Extensions detections · detection
- T1176.002 IDE Extensions · simulation
- T1176.002 IDE Extensions detections · detection
- T1185 Browser Session Hijacking · simulation
- T1185 Browser Session Hijacking detections · detection
- T1187 Forced Authentication · simulation
- T1187 Forced Authentication detections · detection
- T1189 Drive-by Compromise · simulation
- T1189 Drive-by Compromise detections · detection
- T1190 Exploit Public-Facing Application · simulation
- T1190 Exploit Public-Facing Application detections · detection
- T1195 Supply Chain Compromise · simulation
- T1195 Supply Chain Compromise detections · detection
- T1195.001 Compromise Software Dependencies and Development Tools · simulation
- T1195.001 Compromise Software Dependencies and Development Tools detections · detection
- T1195.002 Compromise Software Supply Chain · simulation
- T1195.002 Compromise Software Supply Chain detections · detection
- T1195.003 Compromise Hardware Supply Chain · simulation
- T1195.003 Compromise Hardware Supply Chain detections · detection
- T1197 BITS Jobs · simulation
- T1197 BITS Jobs detections · detection
- T1199 Trusted Relationship · simulation
- T1199 Trusted Relationship detections · detection
- T1200 Hardware Additions · simulation
- T1200 Hardware Additions detections · detection
- T1201 Password Policy Discovery · simulation
- T1201 Password Policy Discovery detections · detection
- T1202 Indirect Command Execution · simulation
- T1202 Indirect Command Execution detections · detection
- T1203 Exploitation for Client Execution · simulation
- T1203 Exploitation for Client Execution detections · detection
- T1204 User Execution · simulation
- T1204 User Execution detections · detection
- T1204.001 Malicious Link · simulation
- T1204.001 Malicious Link detections · detection
- T1204.002 Malicious File · simulation
- T1204.002 Malicious File detections · detection
- T1204.004 Malicious Copy and Paste · simulation
- T1204.004 Malicious Copy and Paste detections · detection
- T1204.005 Malicious Library · simulation
- T1204.005 Malicious Library detections · detection
- T1205 Traffic Signaling · simulation
- T1205 Traffic Signaling detections · detection
- T1205.001 Port Knocking · simulation
- T1205.001 Port Knocking detections · detection
- T1205.002 Socket Filters · simulation
- T1205.002 Socket Filters detections · detection
- T1207 Rogue Domain Controller · simulation
- T1207 Rogue Domain Controller detections · detection
- T1210 Exploitation of Remote Services · simulation
- T1210 Exploitation of Remote Services detections · detection
- T1211 Exploitation for Stealth · simulation
- T1211 Exploitation for Stealth detections · detection
- T1212 Exploitation for Credential Access · simulation
- T1212 Exploitation for Credential Access detections · detection
- T1213 Data from Information Repositories · simulation
- T1213 Data from Information Repositories detections · detection
- T1213.002 Sharepoint · simulation
- T1213.002 Sharepoint detections · detection
- T1213.006 Databases · simulation
- T1213.006 Databases detections · detection
- T1216 System Script Proxy Execution · simulation
- T1216 System Script Proxy Execution detections · detection
- T1216.001 PubPrn · simulation
- T1216.001 PubPrn detections · detection
- T1216.002 SyncAppvPublishingServer · simulation
- T1216.002 SyncAppvPublishingServer detections · detection
- T1217 Browser Information Discovery · simulation
- T1217 Browser Information Discovery detections · detection
- T1218 System Binary Proxy Execution · simulation
- T1218 System Binary Proxy Execution detections · detection
- T1218.001 Compiled HTML File · simulation
- T1218.001 Compiled HTML File detections · detection
- T1218.002 Control Panel · simulation
- T1218.002 Control Panel detections · detection
- T1218.003 CMSTP · simulation
- T1218.003 CMSTP detections · detection
- T1218.004 InstallUtil · simulation
- T1218.004 InstallUtil detections · detection
- T1218.005 Mshta · simulation
- T1218.005 Mshta detections · detection
- T1218.007 Msiexec · simulation
- T1218.007 Msiexec detections · detection
- T1218.008 Odbcconf · simulation
- T1218.008 Odbcconf detections · detection
- T1218.009 Regsvcs/Regasm · simulation
- T1218.009 Regsvcs/Regasm detections · detection
- T1218.010 Regsvr32 · simulation
- T1218.010 Regsvr32 detections · detection
- T1218.011 Rundll32 · simulation
- T1218.011 Rundll32 detections · detection
- T1218.012 Verclsid · simulation
- T1218.012 Verclsid detections · detection
- T1218.013 Mavinject · simulation
- T1218.013 Mavinject detections · detection
- T1218.014 MMC · simulation
- T1218.014 MMC detections · detection
- T1218.015 Electron Applications · simulation
- T1218.015 Electron Applications detections · detection
- T1219 Remote Access Tools · simulation
- T1219 Remote Access Tools detections · detection
- T1219.001 IDE Tunneling · simulation
- T1219.001 IDE Tunneling detections · detection
- T1219.002 Remote Desktop Software · simulation
- T1219.002 Remote Desktop Software detections · detection
- T1219.003 Remote Access Hardware · simulation
- T1219.003 Remote Access Hardware detections · detection
- T1220 XSL Script Processing · simulation
- T1220 XSL Script Processing detections · detection
- T1221 Template Injection · simulation
- T1221 Template Injection detections · detection
- T1222 File and Directory Permissions Modification · simulation
- T1222 File and Directory Permissions Modification detections · detection
- T1222.001 Windows Permissions · simulation
- T1222.001 Windows Permissions detections · detection
- T1480 Execution Guardrails · simulation
- T1480 Execution Guardrails detections · detection
- T1480.001 Environmental Keying · simulation
- T1480.001 Environmental Keying detections · detection
- T1480.002 Mutual Exclusion · simulation
- T1480.002 Mutual Exclusion detections · detection
- T1482 Domain Trust Discovery · simulation
- T1482 Domain Trust Discovery detections · detection
- T1484 Domain or Tenant Policy Modification · simulation
- T1484 Domain or Tenant Policy Modification detections · detection
- T1484.001 Group Policy Modification · simulation
- T1484.001 Group Policy Modification detections · detection
- T1484.002 Trust Modification · simulation
- T1484.002 Trust Modification detections · detection
- T1485 Data Destruction · simulation
- T1485 Data Destruction detections · detection
- T1486 Data Encrypted for Impact · simulation
- T1486 Data Encrypted for Impact detections · detection
- T1489 Service Stop · simulation
- T1489 Service Stop detections · detection
- T1490 Inhibit System Recovery · simulation
- T1490 Inhibit System Recovery detections · detection
- T1491 Defacement · simulation
- T1491 Defacement detections · detection
- T1491.001 Internal Defacement · simulation
- T1491.001 Internal Defacement detections · detection
- T1491.002 External Defacement · simulation
- T1491.002 External Defacement detections · detection
- T1495 Firmware Corruption · simulation
- T1495 Firmware Corruption detections · detection
- T1496 Resource Hijacking · simulation
- T1496 Resource Hijacking detections · detection
- T1496.001 Compute Hijacking · simulation
- T1496.001 Compute Hijacking detections · detection
- T1496.002 Bandwidth Hijacking · simulation
- T1496.002 Bandwidth Hijacking detections · detection
- T1497 Virtualization/Sandbox Evasion · simulation
- T1497 Virtualization/Sandbox Evasion detections · detection
- T1497.001 System Checks · simulation
- T1497.001 System Checks detections · detection
- T1497.002 User Activity Based Checks · simulation
- T1497.002 User Activity Based Checks detections · detection
- T1497.003 Time Based Checks · simulation
- T1497.003 Time Based Checks detections · detection
- T1498 Network Denial of Service · simulation
- T1498 Network Denial of Service detections · detection
- T1498.001 Direct Network Flood · simulation
- T1498.001 Direct Network Flood detections · detection
- T1498.002 Reflection Amplification · simulation
- T1498.002 Reflection Amplification detections · detection
- T1499 Endpoint Denial of Service · simulation
- T1499 Endpoint Denial of Service detections · detection
- T1499.001 OS Exhaustion Flood · simulation
- T1499.001 OS Exhaustion Flood detections · detection
- T1499.002 Service Exhaustion Flood · simulation
- T1499.002 Service Exhaustion Flood detections · detection
- T1499.003 Application Exhaustion Flood · simulation
- T1499.003 Application Exhaustion Flood detections · detection
- T1499.004 Application or System Exploitation · simulation
- T1499.004 Application or System Exploitation detections · detection
- T1505 Server Software Component · simulation
- T1505 Server Software Component detections · detection
- T1505.001 SQL Stored Procedures · simulation
- T1505.001 SQL Stored Procedures detections · detection
- T1505.002 Transport Agent · simulation
- T1505.002 Transport Agent detections · detection
- T1505.003 Web Shell · simulation
- T1505.003 Web Shell detections · detection
- T1505.004 IIS Components · simulation
- T1505.004 IIS Components detections · detection
- T1505.005 Terminal Services DLL · simulation
- T1505.005 Terminal Services DLL detections · detection
- T1518 Software Discovery · simulation
- T1518 Software Discovery detections · detection
- T1518.001 Security Software Discovery · simulation
- T1518.001 Security Software Discovery detections · detection
- T1518.002 Backup Software Discovery · simulation
- T1518.002 Backup Software Discovery detections · detection
- T1529 System Shutdown/Reboot · simulation
- T1529 System Shutdown/Reboot detections · detection
- T1531 Account Access Removal · simulation
- T1531 Account Access Removal detections · detection
- T1534 Internal Spearphishing · simulation
- T1534 Internal Spearphishing detections · detection
- T1539 Steal Web Session Cookie · simulation
- T1539 Steal Web Session Cookie detections · detection
- T1542 Pre-OS Boot · simulation
- T1542 Pre-OS Boot detections · detection
- T1542.001 System Firmware · simulation
- T1542.001 System Firmware detections · detection
- T1542.002 Component Firmware · simulation
- T1542.002 Component Firmware detections · detection
- T1542.003 Bootkit · simulation
- T1542.003 Bootkit detections · detection
- T1543 Create or Modify System Process · simulation
- T1543 Create or Modify System Process detections · detection
- T1543.003 Windows Service · simulation
- T1543.003 Windows Service detections · detection
- T1546 Event Triggered Execution · simulation
- T1546 Event Triggered Execution detections · detection
- T1546.001 Change Default File Association · simulation
- T1546.001 Change Default File Association detections · detection
- T1546.002 Screensaver · simulation
- T1546.002 Screensaver detections · detection
- T1546.003 Windows Management Instrumentation Event Subscription · simulation
- T1546.003 Windows Management Instrumentation Event Subscription detections · detection
- T1546.007 Netsh Helper DLL · simulation
- T1546.007 Netsh Helper DLL detections · detection
- T1546.008 Accessibility Features · simulation
- T1546.008 Accessibility Features detections · detection
- T1546.009 AppCert DLLs · simulation
- T1546.009 AppCert DLLs detections · detection
- T1546.010 AppInit DLLs · simulation
- T1546.010 AppInit DLLs detections · detection
- T1546.011 Application Shimming · simulation
- T1546.011 Application Shimming detections · detection
- T1546.012 Image File Execution Options Injection · simulation
- T1546.012 Image File Execution Options Injection detections · detection
- T1546.013 PowerShell Profile · simulation
- T1546.013 PowerShell Profile detections · detection
- T1546.015 Component Object Model Hijacking · simulation
- T1546.015 Component Object Model Hijacking detections · detection
- T1546.016 Installer Packages · simulation
- T1546.016 Installer Packages detections · detection
- T1546.018 Python Startup Hooks · simulation
- T1546.018 Python Startup Hooks detections · detection
- T1547 Boot or Logon Autostart Execution · simulation
- T1547 Boot or Logon Autostart Execution detections · detection
- T1547.001 Registry Run Keys / Startup Folder · simulation
- T1547.001 Registry Run Keys / Startup Folder detections · detection
- T1547.002 Authentication Package · simulation
- T1547.002 Authentication Package detections · detection
- T1547.003 Time Providers · simulation
- T1547.003 Time Providers detections · detection
- T1547.004 Winlogon Helper DLL · simulation
- T1547.004 Winlogon Helper DLL detections · detection
- T1547.005 Security Support Provider · simulation
- T1547.005 Security Support Provider detections · detection
- T1547.008 LSASS Driver · simulation
- T1547.008 LSASS Driver detections · detection
- T1547.009 Shortcut Modification · simulation
- T1547.009 Shortcut Modification detections · detection
- T1547.010 Port Monitors · simulation
- T1547.010 Port Monitors detections · detection
- T1547.012 Print Processors · simulation
- T1547.012 Print Processors detections · detection
- T1547.014 Active Setup · simulation
- T1547.014 Active Setup detections · detection
- T1548 Abuse Elevation Control Mechanism · simulation
- T1548 Abuse Elevation Control Mechanism detections · detection
- T1548.002 Bypass User Account Control · simulation
- T1548.002 Bypass User Account Control detections · detection
- T1550 Use Alternate Authentication Material · simulation
- T1550 Use Alternate Authentication Material detections · detection
- T1550.002 Pass the Hash · simulation
- T1550.002 Pass the Hash detections · detection
- T1550.003 Pass the Ticket · simulation
- T1550.003 Pass the Ticket detections · detection
- T1552 Unsecured Credentials · simulation
- T1552 Unsecured Credentials detections · detection
- T1552.001 Credentials In Files · simulation
- T1552.001 Credentials In Files detections · detection
- T1552.002 Credentials in Registry · simulation
- T1552.002 Credentials in Registry detections · detection
- T1552.003 Shell History · simulation
- T1552.003 Shell History detections · detection
- T1552.004 Private Keys · simulation
- T1552.004 Private Keys detections · detection
- T1552.006 Group Policy Preferences · simulation
- T1552.006 Group Policy Preferences detections · detection
- T1553 Subvert Trust Controls · simulation
- T1553 Subvert Trust Controls detections · detection
- T1553.002 Code Signing · simulation
- T1553.002 Code Signing detections · detection
- T1553.003 SIP and Trust Provider Hijacking · simulation
- T1553.003 SIP and Trust Provider Hijacking detections · detection
- T1553.004 Install Root Certificate · simulation
- T1553.004 Install Root Certificate detections · detection
- T1553.005 Mark-of-the-Web Bypass · simulation
- T1553.005 Mark-of-the-Web Bypass detections · detection
- T1553.006 Code Signing Policy Modification · simulation
- T1553.006 Code Signing Policy Modification detections · detection
- T1554 Compromise Host Software Binary · simulation
- T1554 Compromise Host Software Binary detections · detection
- T1555 Credentials from Password Stores · simulation
- T1555 Credentials from Password Stores detections · detection
- T1555.003 Credentials from Web Browsers · simulation
- T1555.003 Credentials from Web Browsers detections · detection
- T1555.004 Windows Credential Manager · simulation
- T1555.004 Windows Credential Manager detections · detection
- T1555.005 Password Managers · simulation
- T1555.005 Password Managers detections · detection
- T1556 Modify Authentication Process · simulation
- T1556 Modify Authentication Process detections · detection
- T1556.001 Domain Controller Authentication · simulation
- T1556.001 Domain Controller Authentication detections · detection
- T1556.002 Password Filter DLL · simulation
- T1556.002 Password Filter DLL detections · detection
- T1556.005 Reversible Encryption · simulation
- T1556.005 Reversible Encryption detections · detection
- T1556.006 Multi-Factor Authentication · simulation
- T1556.006 Multi-Factor Authentication detections · detection
- T1556.007 Hybrid Identity · simulation
- T1556.007 Hybrid Identity detections · detection
- T1556.008 Network Provider DLL · simulation
- T1556.008 Network Provider DLL detections · detection
- T1557 Adversary-in-the-Middle · simulation
- T1557 Adversary-in-the-Middle detections · detection
- T1557.001 Name Resolution Poisoning and SMB Relay · simulation
- T1557.001 Name Resolution Poisoning and SMB Relay detections · detection
- T1557.002 ARP Cache Poisoning · simulation
- T1557.002 ARP Cache Poisoning detections · detection
- T1557.003 DHCP Spoofing · simulation
- T1557.003 DHCP Spoofing detections · detection
- T1558 Steal or Forge Kerberos Tickets · simulation
- T1558 Steal or Forge Kerberos Tickets detections · detection
- T1558.001 Golden Ticket · simulation
- T1558.001 Golden Ticket detections · detection
- T1558.002 Silver Ticket · simulation
- T1558.002 Silver Ticket detections · detection
- T1558.003 Kerberoasting · simulation
- T1558.003 Kerberoasting detections · detection
- T1558.004 AS-REP Roasting · simulation
- T1558.004 AS-REP Roasting detections · detection
- T1559 Inter-Process Communication · simulation
- T1559 Inter-Process Communication detections · detection
- T1559.001 Component Object Model · simulation
- T1559.001 Component Object Model detections · detection
- T1559.002 Dynamic Data Exchange · simulation
- T1559.002 Dynamic Data Exchange detections · detection
- T1560 Archive Collected Data · simulation
- T1560 Archive Collected Data detections · detection
- T1560.001 Archive via Utility · simulation
- T1560.001 Archive via Utility detections · detection
- T1560.002 Archive via Library · simulation
- T1560.002 Archive via Library detections · detection
- T1560.003 Archive via Custom Method · simulation
- T1560.003 Archive via Custom Method detections · detection
- T1561 Disk Wipe · simulation
- T1561 Disk Wipe detections · detection
- T1561.001 Disk Content Wipe · simulation
- T1561.001 Disk Content Wipe detections · detection
- T1561.002 Disk Structure Wipe · simulation
- T1561.002 Disk Structure Wipe detections · detection
- T1563 Remote Service Session Hijacking · simulation
- T1563 Remote Service Session Hijacking detections · detection
- T1563.002 RDP Hijacking · simulation
- T1563.002 RDP Hijacking detections · detection
- T1564 Hide Artifacts · simulation
- T1564 Hide Artifacts detections · detection
- T1564.001 Hidden Files and Directories · simulation
- T1564.001 Hidden Files and Directories detections · detection
- T1564.002 Hidden Users · simulation
- T1564.002 Hidden Users detections · detection
- T1564.003 Hidden Window · simulation
- T1564.003 Hidden Window detections · detection
- T1564.004 NTFS File Attributes · simulation
- T1564.004 NTFS File Attributes detections · detection
- T1564.005 Hidden File System · simulation
- T1564.005 Hidden File System detections · detection
- T1564.006 Run Virtual Instance · simulation
- T1564.006 Run Virtual Instance detections · detection
- T1564.007 VBA Stomping · simulation
- T1564.007 VBA Stomping detections · detection
- T1564.008 Email Hiding Rules · simulation
- T1564.008 Email Hiding Rules detections · detection
- T1564.010 Process Argument Spoofing · simulation
- T1564.010 Process Argument Spoofing detections · detection
- T1564.011 Ignore Process Interrupts · simulation
- T1564.011 Ignore Process Interrupts detections · detection
- T1564.012 File/Path Exclusions · simulation
- T1564.012 File/Path Exclusions detections · detection
- T1565 Data Manipulation · simulation
- T1565 Data Manipulation detections · detection
- T1565.001 Stored Data Manipulation · simulation
- T1565.001 Stored Data Manipulation detections · detection
- T1565.002 Transmitted Data Manipulation · simulation
- T1565.002 Transmitted Data Manipulation detections · detection
- T1565.003 Runtime Data Manipulation · simulation
- T1565.003 Runtime Data Manipulation detections · detection
- T1566 Phishing · simulation
- T1566 Phishing detections · detection
- T1566.001 Spearphishing Attachment · simulation
- T1566.001 Spearphishing Attachment detections · detection
- T1566.002 Spearphishing Link · simulation
- T1566.002 Spearphishing Link detections · detection
- T1566.003 Spearphishing via Service · simulation
- T1566.003 Spearphishing via Service detections · detection
- T1566.004 Spearphishing Voice · simulation
- T1566.004 Spearphishing Voice detections · detection
- T1567 Exfiltration Over Web Service · simulation
- T1567 Exfiltration Over Web Service detections · detection
- T1567.001 Exfiltration to Code Repository · simulation
- T1567.001 Exfiltration to Code Repository detections · detection
- T1567.002 Exfiltration to Cloud Storage · simulation
- T1567.002 Exfiltration to Cloud Storage detections · detection
- T1567.003 Exfiltration to Text Storage Sites · simulation
- T1567.003 Exfiltration to Text Storage Sites detections · detection
- T1567.004 Exfiltration Over Webhook · simulation
- T1567.004 Exfiltration Over Webhook detections · detection
- T1568 Dynamic Resolution · simulation
- T1568 Dynamic Resolution detections · detection
- T1568.001 Fast Flux DNS · simulation
- T1568.001 Fast Flux DNS detections · detection
- T1568.002 Domain Generation Algorithms · simulation
- T1568.002 Domain Generation Algorithms detections · detection
- T1568.003 DNS Calculation · simulation
- T1568.003 DNS Calculation detections · detection
- T1569 System Services · simulation
- T1569 System Services detections · detection
- T1569.002 Service Execution · simulation
- T1569.002 Service Execution detections · detection
- T1570 Lateral Tool Transfer · simulation
- T1570 Lateral Tool Transfer detections · detection
- T1571 Non-Standard Port · simulation
- T1571 Non-Standard Port detections · detection
- T1572 Protocol Tunneling · simulation
- T1572 Protocol Tunneling detections · detection
- T1573 Encrypted Channel · simulation
- T1573 Encrypted Channel detections · detection
- T1573.001 Symmetric Cryptography · simulation
- T1573.001 Symmetric Cryptography detections · detection
- T1573.002 Asymmetric Cryptography · simulation
- T1573.002 Asymmetric Cryptography detections · detection
- T1574 Hijack Execution Flow · simulation
- T1574 Hijack Execution Flow detections · detection
- T1574.001 DLL · simulation
- T1574.001 DLL detections · detection
- T1574.005 Executable Installer File Permissions Weakness · simulation
- T1574.005 Executable Installer File Permissions Weakness detections · detection
- T1574.007 Path Interception by PATH Environment Variable · simulation
- T1574.007 Path Interception by PATH Environment Variable detections · detection
- T1574.008 Path Interception by Search Order Hijacking · simulation
- T1574.008 Path Interception by Search Order Hijacking detections · detection
- T1574.009 Path Interception by Unquoted Path · simulation
- T1574.009 Path Interception by Unquoted Path detections · detection
- T1574.010 Services File Permissions Weakness · simulation
- T1574.010 Services File Permissions Weakness detections · detection
- T1574.011 Services Registry Permissions Weakness · simulation
- T1574.011 Services Registry Permissions Weakness detections · detection
- T1574.012 COR_PROFILER · simulation
- T1574.012 COR_PROFILER detections · detection
- T1574.013 KernelCallbackTable · simulation
- T1574.013 KernelCallbackTable detections · detection
- T1574.014 AppDomainManager · simulation
- T1574.014 AppDomainManager detections · detection
- T1606 Forge Web Credentials · simulation
- T1606 Forge Web Credentials detections · detection
- T1606.001 Web Cookies · simulation
- T1606.001 Web Cookies detections · detection
- T1606.002 SAML Tokens · simulation
- T1606.002 SAML Tokens detections · detection
- T1611 Escape to Host · simulation
- T1611 Escape to Host detections · detection
- T1614 System Location Discovery · simulation
- T1614 System Location Discovery detections · detection
- T1614.001 System Language Discovery · simulation
- T1614.001 System Language Discovery detections · detection
- T1615 Group Policy Discovery · simulation
- T1615 Group Policy Discovery detections · detection
- T1620 Reflective Code Loading · simulation
- T1620 Reflective Code Loading detections · detection
- T1621 Multi-Factor Authentication Request Generation · simulation
- T1621 Multi-Factor Authentication Request Generation detections · detection
- T1622 Debugger Evasion · simulation
- T1622 Debugger Evasion detections · detection
- T1649 Steal or Forge Authentication Certificates · simulation
- T1649 Steal or Forge Authentication Certificates detections · detection
- T1652 Device Driver Discovery · simulation
- T1652 Device Driver Discovery detections · detection
- T1653 Power Settings · simulation
- T1653 Power Settings detections · detection
- T1654 Log Enumeration · simulation
- T1654 Log Enumeration detections · detection
- T1657 Financial Theft · simulation
- T1657 Financial Theft detections · detection
- T1659 Content Injection · simulation
- T1659 Content Injection detections · detection
- T1665 Hide Infrastructure · simulation
- T1665 Hide Infrastructure detections · detection
- T1667 Email Bombing · simulation
- T1667 Email Bombing detections · detection
- T1668 Exclusive Control · simulation
- T1668 Exclusive Control detections · detection
- T1669 Wi-Fi Networks · simulation
- T1669 Wi-Fi Networks detections · detection
- T1673 Virtual Machine Discovery · simulation
- T1673 Virtual Machine Discovery detections · detection
- T1674 Input Injection · simulation
- T1674 Input Injection detections · detection
- T1678 Delay Execution · simulation
- T1678 Delay Execution detections · detection
- T1679 Selective Exclusion · simulation
- T1679 Selective Exclusion detections · detection
- T1680 Local Storage Discovery · simulation
- T1680 Local Storage Discovery detections · detection
- T1684 Social Engineering · simulation
- T1684 Social Engineering detections · detection
- T1684.001 Impersonation · simulation
- T1684.001 Impersonation detections · detection
- T1684.002 Email Spoofing · simulation
- T1684.002 Email Spoofing detections · detection
- T1685 Disable or Modify Tools · simulation
- T1685 Disable or Modify Tools detections · detection
- T1685.001 Disable or Modify Windows Event Log · simulation
- T1685.001 Disable or Modify Windows Event Log detections · detection
- T1685.003 Modify or Spoof Tool UI · simulation
- T1685.003 Modify or Spoof Tool UI detections · detection
- T1685.005 Clear Windows Event Logs · simulation
- T1685.005 Clear Windows Event Logs detections · detection
- T1686 Disable or Modify System Firewall · simulation
- T1686 Disable or Modify System Firewall detections · detection
- T1686.003 Windows Host Firewall · simulation
- T1686.003 Windows Host Firewall detections · detection
- T1687 Exploitation for Defense Impairment · simulation
- T1687 Exploitation for Defense Impairment detections · detection
- T1688 Safe Mode Boot · simulation
- T1688 Safe Mode Boot detections · detection
- T1689 Downgrade Attack · simulation
- T1689 Downgrade Attack detections · detection
- T1690 Prevent Command History Logging · simulation
- T1690 Prevent Command History Logging detections · detection
- Tor · tool
- TruffleHog · tool
- User Account Authentication · telemetry
- User Account Creation · telemetry
- User Account Deletion · telemetry
- User Account Metadata · telemetry
- User Account Modification · telemetry
- Volume Creation · telemetry
- Volume Deletion · telemetry
- Volume Modification · telemetry
- Web Credential Creation · telemetry
- Web Credential Usage · telemetry
- Wevtutil · tool
- Windows Credential Editor · tool
- Windows Registry Key Access · telemetry
- Windows Registry Key Creation · telemetry
- Windows Registry Key Modification · telemetry
- WMI Creation · telemetry
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.