Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

MITRE ATT&CK × Bidda — 14 Tactics Regulatory Crosswalked

MITRE ATT&CK Enterprise kill-chain mapped to NIST 800-53, ISO 27001, PCI DSS, NIS2, DORA, HIPAA. Free MCP tool for any technique ID.

Free MCP tool: get_mitre_mapping("T1566") returns the Bidda compliance node plus mapped NIST 800-53, ISO 27001, NIS2, DORA, HIPAA, PCI DSS controls.

Tactics: Initial Access, Execution, Persistence, Privilege Escalation, Credential Access, Discovery, Lateral Movement, Collection, Command and Control, Exfiltration, Impact, Stealth, Defense Impairment, Resource Development, Reconnaissance

[initial-access] Initial Access
- T1078 Valid Accounts
Adversary use of compromised credentials for initial access, persistence, privilege escalation, and defense evasion. Sub-techniques cover Default Accounts (T1078.001), Domain Accounts (T1078.002), Local Accounts (T1078.003), and Cloud...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1078-valid-accounts
- T1078.001 Default Accounts
An Enterprise Defense Evasion and Persistence and Privilege Escalation and Initial Access sub-technique of T1078 (Valid Accounts). Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1078-001-default-accounts
- T1078.002 Domain Accounts
An Enterprise Defense Evasion and Persistence and Privilege Escalation and Initial Access sub-technique of T1078 (Valid Accounts). Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1078-002-domain-accounts
- T1078.003 Local Accounts
An Enterprise Defense Evasion and Persistence and Privilege Escalation and Initial Access sub-technique of T1078 (Valid Accounts). Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1078-003-local-accounts
- T1078.004 Cloud Accounts
Adversary use of legitimate cloud account credentials (Microsoft Entra ID / Azure AD, AWS IAM, Google Workspace, GCP, Okta, Salesforce) to gain initial access, maintain persistence, escalate privileges, and evade detection. Cloud...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1078-004-cloud-accounts
- T1091 Replication Through Removable Media
An Enterprise Lateral Movement and Initial Access technique. Adversaries may move onto systems, possibly those on disconnected or air-gapped networks, by copying malware to removable media and taking advantage of Autorun features when...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1091-replication-through-removable-media
- T1133 External Remote Services
An Enterprise Persistence and Initial Access technique. Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1133-external-remote-services
- T1189 Drive-by Compromise
An Enterprise Initial Access technique. Adversaries may gain access to a system through a user visiting a website over the normal course of browsing. With this technique, the user's web browser is typically targeted for exploitation,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1189-drive-by-compromise
- T1190 Exploit Public-Facing Application
Adversary exploitation of weaknesses in internet-facing applications, services, or APIs to gain initial network access. Notable real-world exploitations include MOVEit (CVE-2023-34362, Clop ransomware campaign 2,600+ victims), Log4Shell...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1190-exploit-public-facing-application
- T1195 Supply Chain Compromise
An Enterprise Initial Access technique. Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise can take place at any...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1195-supply-chain-compromise
- T1195.001 Compromise Software Dependencies and Development Tools
An Enterprise Initial Access sub-technique of T1195 (Supply Chain Compromise). Adversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1195-001-compromise-software-dependencies-and-development-tools
- T1195.002 Compromise Software Supply Chain
An Enterprise Initial Access sub-technique of T1195 (Supply Chain Compromise). Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise. Supply chain compromise of...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1195-002-compromise-software-supply-chain
- T1195.003 Compromise Hardware Supply Chain
An Enterprise Initial Access sub-technique of T1195 (Supply Chain Compromise). Adversaries may manipulate hardware components in products prior to receipt by a final consumer for the purpose of data or system compromise. By modifying...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1195-003-compromise-hardware-supply-chain
- T1199 Trusted Relationship
An Enterprise Initial Access technique. Adversaries may breach or otherwise leverage organizations who have access to intended victims. Access through trusted third party relationship abuses an existing connection that may not be...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1199-trusted-relationship
- T1200 Hardware Additions
An Enterprise Initial Access technique. Adversaries may introduce computer accessories, networking hardware, or other computing devices into a system or network that can be used as a vector to gain access. Rather than just connecting...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1200-hardware-additions
- T1566 Phishing
Adversary delivery of malicious content via electronic messages (email, instant messenger, SMS) to gain initial access. The technique has four sub-techniques: T1566.001 (Spearphishing Attachment), T1566.002 (Spearphishing Link),...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1566-phishing
- T1566.001 Spearphishing Attachment
Adversary delivery of malicious files via email attachments to trick users into execution. Office documents with malicious macros, OLE objects, ISO/IMG containers bypassing Mark of the Web, OneNote attachments, and HTML smuggling are...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1566-001-spearphishing-attachment
- T1566.002 Spearphishing Link
Adversary delivery of malicious URLs via email to phish credentials or deliver malware. Modern attackers use look-alike domains, recently-registered domains, URL shorteners, legitimate cloud-hosted phishing pages (Microsoft 365, AWS S3,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1566-002-spearphishing-link
- T1566.003 Spearphishing via Service
An Enterprise Initial Access sub-technique of T1566 (Phishing). Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems. Spearphishing via service is a specific variant of...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1566-003-spearphishing-via-service
- T1566.004 Spearphishing Voice
An Enterprise Initial Access sub-technique of T1566 (Phishing). Adversaries may use voice communications to ultimately gain access to victim systems. Spearphishing voice is a specific variant of spearphishing. It is different from other...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1566-004-spearphishing-voice
- T1659 Content Injection
An Enterprise Initial Access and Command and Control technique. Adversaries may gain access and continuously communicate with victims by injecting malicious content into systems through online network traffic. Rather than luring victims...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1659-content-injection
- T1669 Wi-Fi Networks
An Enterprise Initial Access technique. Adversaries may gain initial access to target systems by connecting to wireless networks. They may accomplish this by exploiting open Wi-Fi networks used by target devices or by accessing secured...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1669-wi-fi-networks

[execution] Execution
- T1047 Windows Management Instrumentation
An Enterprise Execution technique. Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1047-windows-management-instrumentation
- T1053 Scheduled Task/Job
An Enterprise Execution and Persistence and Privilege Escalation technique. Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code. Utilities exist within all major operating...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1053-scheduled-task-job
- T1053.002 At
An Enterprise Execution and Persistence and Privilege Escalation sub-technique of T1053 (Scheduled Task/Job). Adversaries may abuse the at utility to perform task scheduling for initial or recurring execution of malicious code. The at...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1053-002-at
- T1053.003 Cron
An Enterprise Execution and Persistence and Privilege Escalation sub-technique of T1053 (Scheduled Task/Job). Adversaries may abuse the cron utility to perform task scheduling for initial or recurring execution of malicious code. The...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1053-003-cron
- T1053.005 Scheduled Task
An Enterprise Execution and Persistence and Privilege Escalation sub-technique of T1053 (Scheduled Task/Job). Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1053-005-scheduled-task
- T1053.006 Systemd Timers
An Enterprise Execution and Persistence and Privilege Escalation sub-technique of T1053 (Scheduled Task/Job). Adversaries may abuse systemd timers to perform task scheduling for initial or recurring execution of malicious code. Systemd...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1053-006-systemd-timers
- T1053.007 Container Orchestration Job
An Enterprise Execution and Persistence and Privilege Escalation sub-technique of T1053 (Scheduled Task/Job). Adversaries may abuse task scheduling functionality provided by container orchestration tools such as Kubernetes to schedule...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1053-007-container-orchestration-job
- T1059 Command and Scripting Interpreter
Adversary abuse of command and scripting interpreters (PowerShell, Bash, Python, JavaScript, Visual Basic, Windows Command Shell, Network Device CLI) to execute commands, scripts, and binaries. The technique has 10 named sub-techniques...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1059-command-and-scripting-interpreter
- T1059.001 PowerShell
Adversary abuse of PowerShell for execution, lateral movement, and discovery. PowerShell is the dominant living-off-the-land interpreter on Windows: every modern ransomware operator (LockBit, BlackCat, Cl0p, Akira, Royal) uses...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1059-001-powershell
- T1059.002 AppleScript
An Enterprise Execution sub-technique of T1059 (Command and Scripting Interpreter). Adversaries may abuse AppleScript for execution. AppleScript is a macOS scripting language designed to control applications and parts of the OS via...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1059-002-applescript
- T1059.003 Windows Command Shell
An Enterprise Execution sub-technique of T1059 (Command and Scripting Interpreter). Adversaries may abuse the Windows command shell for execution. The Windows command shell (cmd) is the primary command prompt on Windows systems. The...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1059-003-windows-command-shell
- T1059.004 Unix Shell
An Enterprise Execution sub-technique of T1059 (Command and Scripting Interpreter). Adversaries may abuse Unix shell commands and scripts for execution. Unix shells are the primary command prompt on Linux and macOS systems, though many...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1059-004-unix-shell
- T1059.005 Visual Basic
An Enterprise Execution sub-technique of T1059 (Command and Scripting Interpreter). Adversaries may abuse Visual Basic (VB) for execution. VB is a programming language created by Microsoft with interoperability with many Windows...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1059-005-visual-basic
- T1059.006 Python
An Enterprise Execution sub-technique of T1059 (Command and Scripting Interpreter). Adversaries may abuse Python commands and scripts for execution. Python is a very popular scripting/programming language, with capabilities to perform...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1059-006-python
- T1059.007 JavaScript
An Enterprise Execution sub-technique of T1059 (Command and Scripting Interpreter). Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1059-007-javascript
- T1059.008 Network Device CLI
An Enterprise Execution sub-technique of T1059 (Command and Scripting Interpreter). Adversaries may abuse scripting or built-in command line interpreters (CLI) on network devices to execute malicious command and payloads. The CLI is the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1059-008-network-device-cli
- T1059.009 Cloud API
An Enterprise Execution sub-technique of T1059 (Command and Scripting Interpreter). Adversaries may abuse cloud APIs to execute malicious commands. APIs available in cloud environments provide various functionalities and are a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1059-009-cloud-api
- T1059.010 AutoHotKey & AutoIT
An Enterprise Execution sub-technique of T1059 (Command and Scripting Interpreter). Adversaries may execute commands and perform malicious tasks using AutoIT and AutoHotKey automation scripts. AutoIT and AutoHotkey (AHK) are scripting...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1059-010-autohotkey-autoit
- T1059.011 Lua
An Enterprise Execution sub-technique of T1059 (Command and Scripting Interpreter). Adversaries may abuse Lua commands and scripts for execution. Lua is a cross-platform scripting and programming language primarily designed for embedded...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1059-011-lua
- T1059.012 Hypervisor CLI
An Enterprise Execution technique. Adversaries may abuse hypervisor command line interpreters (CLIs) to execute malicious commands. Hypervisor CLIs typically enable a wide variety of functionality for managing both the hypervisor itself...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1059-012-hypervisor-cli
- T1059.013 Container CLI/API
An Enterprise Execution technique. Adversaries may abuse built-in CLI tools or API calls to execute malicious commands in containerized environments. The Docker CLI is used for managing containers via an exposed API point from the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1059-013-container-cli-api
- T1072 Software Deployment Tools
An Enterprise Execution and Lateral Movement technique. Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1072-software-deployment-tools
- T1106 Native API
Adversary direct invocation of operating system APIs to execute code, bypassing higher-level interpreters and detection mechanisms that rely on parent-process telemetry. Common implementations include direct syscalls in Windows...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1106-native-api
- T1127 Trusted Developer Utilities Proxy Execution
An Enterprise Defense Evasion technique. Adversaries may take advantage of trusted developer utilities to proxy execution of malicious payloads. There are many utilities used for software development related tasks that can be used to...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1127-trusted-developer-utilities-proxy-execution
- T1127.001 MSBuild
An Enterprise Defense Evasion sub-technique of T1127 (Trusted Developer Utilities Proxy Execution). Adversaries may use MSBuild to proxy execution of code through a trusted Windows utility. MSBuild.exe (Microsoft Build Engine) is a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1127-001-msbuild
- T1127.002 ClickOnce
An Enterprise Defense Evasion sub-technique of T1127 (Trusted Developer Utilities Proxy Execution). Adversaries may use ClickOnce applications (.appref-ms and .application files) to proxy execution of code through a trusted Windows...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1127-002-clickonce
- T1127.003 JamPlus
An Enterprise Stealth, Execution technique. Adversaries may use `JamPlus` to proxy the execution of a malicious script. `JamPlus` is a build utility tool for code and data build systems. It works with several popular compilers and can...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1127-003-jamplus
- T1129 Shared Modules
An Enterprise Execution technique. Adversaries may execute malicious payloads via loading shared modules. Shared modules are executable files that are loaded into processes to provide access to reusable code, such as specific custom...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1129-shared-modules
- T1197 BITS Jobs
An Enterprise Defense Evasion and Persistence technique. Adversaries may abuse BITS jobs to persistently execute code and perform various background tasks. Windows Background Intelligent Transfer Service (BITS) is a low-bandwidth,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1197-bits-jobs
- T1203 Exploitation for Client Execution
An Enterprise Execution technique. Adversaries may exploit software vulnerabilities in client applications to execute code. Vulnerabilities can exist in software due to unsecure coding practices that can lead to unanticipated behavior....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1203-exploitation-for-client-execution
- T1204 User Execution
Adversary reliance on specific actions by users to execute malicious code. Sub-techniques cover Malicious Link (T1204.001), Malicious File (T1204.002), and Malicious Image (T1204.003). User Execution is the second-most common execution...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1204-user-execution
- T1204.001 Malicious Link
An Enterprise Execution sub-technique of T1204 (User Execution). An adversary may rely upon a user clicking a malicious link in order to gain execution. Users may be subjected to social engineering to get them to click on a link that...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1204-001-malicious-link
- T1204.002 Malicious File
An Enterprise Execution sub-technique of T1204 (User Execution). An adversary may rely upon a user opening a malicious file in order to gain execution. Users may be subjected to social engineering to get them to open a file that will...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1204-002-malicious-file
- T1204.003 Malicious Image
An Enterprise Execution sub-technique of T1204 (User Execution). Adversaries may rely on a user running a malicious image to facilitate execution. Amazon Web Services (AWS) Amazon Machine Images (AMIs), Google Cloud Platform (GCP)...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1204-003-malicious-image
- T1204.004 Malicious Copy and Paste
An Enterprise Execution technique. An adversary may rely upon a user copying and pasting code in order to gain execution. Users may be subjected to social engineering to get them to copy and paste code directly into a Command and...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1204-004-malicious-copy-and-paste
- T1204.005 Malicious Library
An Enterprise Execution technique. Adversaries may rely on a user installing a malicious library to facilitate execution. Threat actors may Upload Malware to package managers such as NPM and PyPi, as well as to public code repositories...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1204-005-malicious-library
- T1559 Inter-Process Communication
An Enterprise Execution technique. Adversaries may abuse inter-process communication (IPC) mechanisms for local code or command execution. IPC is typically used by processes to share data, communicate with each other, or synchronize...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1559-inter-process-communication
- T1559.001 Component Object Model
An Enterprise Execution sub-technique of T1559 (Inter-Process Communication). Adversaries may use the Windows Component Object Model (COM) for local code execution. COM is an inter-process communication (IPC) component of the native...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1559-001-component-object-model
- T1559.002 Dynamic Data Exchange
An Enterprise Execution sub-technique of T1559 (Inter-Process Communication). Adversaries may use Windows Dynamic Data Exchange (DDE) to execute arbitrary commands. DDE is a client-server protocol for one-time and/or continuous...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1559-002-dynamic-data-exchange
- T1559.003 XPC Services
An Enterprise Execution sub-technique of T1559 (Inter-Process Communication). Adversaries can provide malicious content to an XPC service daemon for local code execution. macOS uses XPC services for basic inter-process communication...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1559-003-xpc-services
- T1569 System Services
An Enterprise Execution technique. Adversaries may abuse system services or daemons to execute commands or programs. Adversaries can execute malicious content by interacting with or creating services either locally or remotely. Many...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1569-system-services
- T1569.001 Launchctl
An Enterprise Execution sub-technique of T1569 (System Services). Adversaries may abuse launchctl to execute commands or programs. Launchctl interfaces with launchd, the service management framework for macOS. Launchctl supports taking...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1569-001-launchctl
- T1569.002 Service Execution
An Enterprise Execution sub-technique of T1569 (System Services). Adversaries may abuse the Windows service control manager to execute malicious commands or payloads. The Windows service control manager (services.exe) is an interface to...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1569-002-service-execution
- T1569.003 Systemctl
An Enterprise Execution technique. Adversaries may abuse systemctl to execute commands or programs. Systemctl is the primary interface for systemd, the Linux init system and service manager. Typically invoked from a shell, Systemctl can...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1569-003-systemctl
- T1574 Hijack Execution Flow
Adversary hijacking of legitimate program execution flow to load malicious code. Sub-techniques include DLL Side-Loading (T1574.002), DLL Search Order Hijacking (T1574.001), DYLIB Hijacking (T1574.004), Executable Path Hijacking...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-hijack-execution-flow
- T1574.001 DLL
An Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking the search order used to load DLLs. Windows systems...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-001-dll-search-order-hijacking
- T1574.002 DLL Side-Loading
An Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by side-loading DLLs. Similar to DLL Search Order Hijacking,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-002-dll-side-loading
- T1574.004 Dylib Hijacking
An Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own payloads by placing a malicious dynamic library (dylib) with an expected name in a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-004-dylib-hijacking
- T1574.005 Executable Installer File Permissions Weakness
An Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking the binaries used by an installer. These processes...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-005-executable-installer-file-permissions-weakness
- T1574.006 Dynamic Linker Hijacking
An Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking environment variables the dynamic linker uses to...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-006-dynamic-linker-hijacking
- T1574.007 Path Interception by PATH Environment Variable
An Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking environment variables used to load libraries. The...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-007-path-interception-by-path-environment-variable
- T1574.008 Path Interception by Search Order Hijacking
An Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking the search order used to load other programs....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-008-path-interception-by-search-order-hijacking
- T1574.009 Path Interception by Unquoted Path
An Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking vulnerable file path references. Adversaries can...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-009-path-interception-by-unquoted-path
- T1574.010 Services File Permissions Weakness
An Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking the binaries used by services. Adversaries may use...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-010-services-file-permissions-weakness
- T1574.011 Services Registry Permissions Weakness
An Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking the Registry entries used by services. Adversaries...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-011-services-registry-permissions-weakness
- T1574.012 COR_PROFILER
An Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may leverage the COR_PROFILER environment variable to hijack the execution flow of programs that load the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-012-cor-profiler
- T1574.013 KernelCallbackTable
An Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may abuse the KernelCallbackTable of a process to hijack its execution flow in order to run their own...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-013-kernelcallbacktable
- T1574.014 AppDomainManager
An Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking how the .NET AppDomainManager loads assemblies. The...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-014-appdomainmanager
- T1609 Container Administration Command
An Enterprise Execution technique. Adversaries may abuse a container administration service to execute commands within a container. A container administration service such as the Docker daemon, the Kubernetes API server, or the kubelet...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1609-container-administration-command
- T1610 Deploy Container
An Enterprise Defense Evasion and Execution technique. Adversaries may deploy a container into an environment to facilitate execution or evade defenses. In some cases, adversaries may deploy a new container to execute processes...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1610-deploy-container
- T1648 Serverless Execution
An Enterprise Execution technique. Adversaries may abuse serverless computing, integration, and automation services to execute arbitrary code in cloud environments. Many cloud providers offer a variety of serverless resources, including...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1648-serverless-execution
- T1651 Cloud Administration Command
An Enterprise Execution technique. Adversaries may abuse cloud management services to execute commands within virtual machines. Resources such as AWS Systems Manager, Azure RunCommand, and Runbooks allow users to remotely run scripts in...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1651-cloud-administration-command
- T1674 Input Injection
An Enterprise Execution technique. Adversaries may simulate keystrokes on a victim’s computer by various means to perform any type of action on behalf of the user, such as launching the command interpreter using keyboard shortcuts,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1674-input-injection
- T1675 ESXi Administration Command
An Enterprise Execution technique. Adversaries may abuse ESXi administration services to execute commands on guest machines hosted within an ESXi virtual environment. Persistent background services on ESXi-hosted VMs, such as the VMware...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1675-esxi-administration-command
- T1677 Poisoned Pipeline Execution
An Enterprise Execution technique. Adversaries may manipulate continuous integration / continuous development (CI/CD) processes by injecting malicious code into the build process. There are several mechanisms for poisoning pipelines: *...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1677-poisoned-pipeline-execution

[persistence] Persistence
- T1037 Boot or Logon Initialization Scripts
An Enterprise Persistence and Privilege Escalation technique. Adversaries may use scripts automatically executed at boot or logon initialization to establish persistence. Initialization scripts can be used to perform administrative...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1037-boot-or-logon-initialization-scripts
- T1037.001 Logon Script (Windows)
MITRE ATT&CK T1037.001 (Logon Script (Windows)) is an Enterprise Persistence and Privilege Escalation sub-technique of T1037 (Boot or Logon Initialization Scripts). Adversaries may use Windows logon scripts automatically executed at...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1037-001-logon-script-windows
- T1037.002 Login Hook
An Enterprise Persistence and Privilege Escalation sub-technique of T1037 (Boot or Logon Initialization Scripts). Adversaries may use a Login Hook to establish persistence executed upon user logon. A login hook is a plist file that...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1037-002-login-hook
- T1037.003 Network Logon Script
An Enterprise Persistence and Privilege Escalation sub-technique of T1037 (Boot or Logon Initialization Scripts). Adversaries may use network logon scripts automatically executed at logon initialization to establish persistence. Network...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1037-003-network-logon-script
- T1037.004 RC Scripts
An Enterprise Persistence and Privilege Escalation sub-technique of T1037 (Boot or Logon Initialization Scripts). Adversaries may establish persistence by modifying RC scripts which are executed during a Unix-like system's startup....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1037-004-rc-scripts
- T1037.005 Startup Items
An Enterprise Persistence and Privilege Escalation sub-technique of T1037 (Boot or Logon Initialization Scripts). Adversaries may use startup items automatically executed at boot initialization to establish persistence. Startup items...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1037-005-startup-items
- T1053 Scheduled Task/Job
An Enterprise Execution and Persistence and Privilege Escalation technique. Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code. Utilities exist within all major operating...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1053-scheduled-task-job
- T1053.002 At
An Enterprise Execution and Persistence and Privilege Escalation sub-technique of T1053 (Scheduled Task/Job). Adversaries may abuse the at utility to perform task scheduling for initial or recurring execution of malicious code. The at...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1053-002-at
- T1053.003 Cron
An Enterprise Execution and Persistence and Privilege Escalation sub-technique of T1053 (Scheduled Task/Job). Adversaries may abuse the cron utility to perform task scheduling for initial or recurring execution of malicious code. The...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1053-003-cron
- T1053.005 Scheduled Task
An Enterprise Execution and Persistence and Privilege Escalation sub-technique of T1053 (Scheduled Task/Job). Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1053-005-scheduled-task
- T1053.006 Systemd Timers
An Enterprise Execution and Persistence and Privilege Escalation sub-technique of T1053 (Scheduled Task/Job). Adversaries may abuse systemd timers to perform task scheduling for initial or recurring execution of malicious code. Systemd...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1053-006-systemd-timers
- T1053.007 Container Orchestration Job
An Enterprise Execution and Persistence and Privilege Escalation sub-technique of T1053 (Scheduled Task/Job). Adversaries may abuse task scheduling functionality provided by container orchestration tools such as Kubernetes to schedule...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1053-007-container-orchestration-job
- T1078 Valid Accounts
Adversary use of compromised credentials for initial access, persistence, privilege escalation, and defense evasion. Sub-techniques cover Default Accounts (T1078.001), Domain Accounts (T1078.002), Local Accounts (T1078.003), and Cloud...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1078-valid-accounts
- T1078.001 Default Accounts
An Enterprise Defense Evasion and Persistence and Privilege Escalation and Initial Access sub-technique of T1078 (Valid Accounts). Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1078-001-default-accounts
- T1078.002 Domain Accounts
An Enterprise Defense Evasion and Persistence and Privilege Escalation and Initial Access sub-technique of T1078 (Valid Accounts). Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1078-002-domain-accounts
- T1078.003 Local Accounts
An Enterprise Defense Evasion and Persistence and Privilege Escalation and Initial Access sub-technique of T1078 (Valid Accounts). Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1078-003-local-accounts
- T1078.004 Cloud Accounts
Adversary use of legitimate cloud account credentials (Microsoft Entra ID / Azure AD, AWS IAM, Google Workspace, GCP, Okta, Salesforce) to gain initial access, maintain persistence, escalate privileges, and evade detection. Cloud...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1078-004-cloud-accounts
- T1098 Account Manipulation
Adversary modification of accounts to maintain or escalate access. Sub-techniques cover Additional Cloud Credentials (T1098.001), Additional Email Delegate Permissions (T1098.002), Additional Cloud Roles (T1098.003), SSH Authorized Keys...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1098-account-manipulation
- T1098.001 Additional Cloud Credentials
An Enterprise Persistence and Privilege Escalation sub-technique of T1098 (Account Manipulation). Adversaries may add adversary-controlled credentials to a cloud account to maintain persistent access to victim accounts and instances...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1098-001-additional-cloud-credentials
- T1098.002 Additional Email Delegate Permissions
An Enterprise Persistence and Privilege Escalation sub-technique of T1098 (Account Manipulation). Adversaries may grant additional permission levels to maintain persistent access to an adversary-controlled email account. For example,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1098-002-additional-email-delegate-permissions
- T1098.003 Additional Cloud Roles
An Enterprise Persistence and Privilege Escalation sub-technique of T1098 (Account Manipulation). An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1098-003-additional-cloud-roles
- T1098.004 SSH Authorized Keys
An Enterprise Persistence and Privilege Escalation sub-technique of T1098 (Account Manipulation). Adversaries may modify the SSH authorized_keys file to maintain persistence on a victim host. Linux distributions and macOS commonly use...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1098-004-ssh-authorized-keys
- T1098.005 Device Registration
An Enterprise Persistence and Privilege Escalation sub-technique of T1098 (Account Manipulation). Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA)...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1098-005-device-registration
- T1098.006 Additional Container Cluster Roles
An Enterprise Persistence and Privilege Escalation sub-technique of T1098 (Account Manipulation). An adversary may add additional roles or permissions to an adversary-controlled user or service account to maintain persistent access to a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1098-006-additional-container-cluster-roles
- T1098.007 Additional Local or Domain Groups
An Enterprise Persistence and Privilege Escalation sub-technique of T1098 (Account Manipulation). An adversary may add additional local or domain groups to an adversary-controlled account to maintain persistent access to a system or...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1098-007-additional-local-or-domain-groups
- T1112 Modify Registry
Adversary modification of the Windows Registry to hide configuration, persist, disable security tools, or evade detection. Common targets: Run keys, Services, Defender exclusions, EnableLUA UAC, IFEO (Image File Execution Options)...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1112-modify-registry
- T1133 External Remote Services
An Enterprise Persistence and Initial Access technique. Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1133-external-remote-services
- T1136 Create Account
Adversary creation of accounts to maintain access. Sub-techniques cover Local Account (T1136.001), Domain Account (T1136.002), and Cloud Account (T1136.003). Adversary-created accounts often evade detection by appearing legitimate;...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1136-create-account
- T1136.001 Local Account
An Enterprise Persistence sub-technique of T1136 (Create Account). Adversaries may create a local account to maintain access to victim systems. Local accounts are those configured by an organization for use by users, remote support,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1136-001-local-account
- T1136.002 Domain Account
An Enterprise Persistence sub-technique of T1136 (Create Account). Adversaries may create a domain account to maintain access to victim systems. Domain accounts are those managed by Active Directory Domain Services where access and...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1136-002-domain-account
- T1136.003 Cloud Account
An Enterprise Persistence sub-technique of T1136 (Create Account). Adversaries may create a cloud account to maintain access to victim systems. With a sufficient level of access, such accounts may be used to establish secondary...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1136-003-cloud-account
- T1137 Office Application Startup
An Enterprise Persistence technique. Adversaries may leverage Microsoft Office-based applications for persistence between startups. Microsoft Office is a fairly common application suite on Windows-based operating systems within an...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1137-office-application-startup
- T1137.001 Office Template Macros
An Enterprise Persistence sub-technique of T1137 (Office Application Startup). Adversaries may abuse Microsoft Office templates to obtain persistence on a compromised system. Microsoft Office contains templates that are part of common...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1137-001-office-template-macros
- T1137.002 Office Test
An Enterprise Persistence sub-technique of T1137 (Office Application Startup). Adversaries may abuse the Microsoft Office "Office Test" Registry key to obtain persistence on a compromised system. An Office Test Registry location exists...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1137-002-office-test
- T1137.003 Outlook Forms
An Enterprise Persistence sub-technique of T1137 (Office Application Startup). Adversaries may abuse Microsoft Outlook forms to obtain persistence on a compromised system. Outlook forms are used as templates for presentation and...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1137-003-outlook-forms
- T1137.004 Outlook Home Page
An Enterprise Persistence sub-technique of T1137 (Office Application Startup). Adversaries may abuse Microsoft Outlook's Home Page feature to obtain persistence on a compromised system. Outlook Home Page is a legacy feature used to...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1137-004-outlook-home-page
- T1137.005 Outlook Rules
An Enterprise Persistence sub-technique of T1137 (Office Application Startup). Adversaries may abuse Microsoft Outlook rules to obtain persistence on a compromised system. Outlook rules allow a user to define automated behavior to...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1137-005-outlook-rules
- T1137.006 Add-ins
An Enterprise Persistence sub-technique of T1137 (Office Application Startup). Adversaries may abuse Microsoft Office add-ins to obtain persistence on a compromised system. Office add-ins can be used to add functionality to Office...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1137-006-add-ins
- T1176 Software Extensions
An Enterprise Persistence technique. Adversaries may abuse Internet browser extensions to establish persistent access to victim systems. Browser extensions or plugins are small programs that can add functionality and customize aspects...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1176-browser-extensions
- T1176.001 Browser Extensions
An Enterprise Persistence technique. Adversaries may abuse internet browser extensions to establish persistent access to victim systems. Browser extensions or plugins are small programs that can add functionality to and customize...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1176-001-browser-extensions
- T1176.002 IDE Extensions
An Enterprise Persistence technique. Adversaries may abuse an integrated development environment (IDE) extension to establish persistent access to victim systems. IDEs such as Visual Studio Code, IntelliJ IDEA, and Eclipse support...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1176-002-ide-extensions
- T1197 BITS Jobs
An Enterprise Defense Evasion and Persistence technique. Adversaries may abuse BITS jobs to persistently execute code and perform various background tasks. Windows Background Intelligent Transfer Service (BITS) is a low-bandwidth,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1197-bits-jobs
- T1205 Traffic Signaling
An Enterprise Defense Evasion and Persistence and Command and Control technique. Adversaries may use traffic signaling to hide open ports or other malicious functionality used for persistence or command and control. Traffic signaling...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1205-traffic-signaling
- T1205.001 Port Knocking
An Enterprise Defense Evasion and Persistence and Command and Control sub-technique of T1205 (Traffic Signaling). Adversaries may use port knocking to hide open ports used for persistence or command and control. To enable a port, an...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1205-001-port-knocking
- T1205.002 Socket Filters
An Enterprise Defense Evasion and Persistence and Command and Control sub-technique of T1205 (Traffic Signaling). Adversaries may attach filters to a network socket to monitor then activate backdoors used for persistence or command and...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1205-002-socket-filters
- T1505 Server Software Component
Adversary deployment of malicious software components into legitimate server software for persistence. Sub-techniques include SQL Stored Procedures (T1505.001), Transport Agent (T1505.002), Web Shell (T1505.003), IIS Components...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1505-server-software-component
- T1505.001 SQL Stored Procedures
An Enterprise Persistence sub-technique of T1505 (Server Software Component). Adversaries may abuse SQL stored procedures to establish persistent access to systems. SQL Stored Procedures are code that can be saved and reused so that...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1505-001-sql-stored-procedures
- T1505.002 Transport Agent
An Enterprise Persistence sub-technique of T1505 (Server Software Component). Adversaries may abuse Microsoft transport agents to establish persistent access to systems. Microsoft Exchange transport agents can operate on email messages...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1505-002-transport-agent
- T1505.003 Web Shell
An Enterprise Persistence sub-technique of T1505 (Server Software Component). Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1505-003-web-shell
- T1505.004 IIS Components
An Enterprise Persistence sub-technique of T1505 (Server Software Component). Adversaries may install malicious components that run on Internet Information Services (IIS) web servers to establish persistence. IIS provides several...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1505-004-iis-components
- T1505.005 Terminal Services DLL
An Enterprise Persistence sub-technique of T1505 (Server Software Component). Adversaries may abuse components of Terminal Services to enable persistent access to systems. Microsoft Terminal Services, renamed to Remote Desktop Services...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1505-005-terminal-services-dll
- T1505.006 vSphere Installation Bundles
An Enterprise Persistence technique. Adversaries may abuse vSphere Installation Bundles (VIBs) to establish persistent access to ESXi hypervisors. VIBs are collections of files used for software distribution and virtual system...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1505-006-vsphere-installation-bundles
- T1525 Implant Internal Image
An Enterprise Persistence technique. Adversaries may implant cloud or container images with malicious code to establish persistence after gaining access to an environment. Amazon Web Services (AWS) Amazon Machine Images (AMIs), Google...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1525-implant-internal-image
- T1542 Pre-OS Boot
An Enterprise Defense Evasion and Persistence technique. Adversaries may abuse Pre-OS Boot mechanisms as a way to establish persistence on a system. During the booting process of a computer, firmware and various startup services are...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1542-pre-os-boot
- T1542.001 System Firmware
An Enterprise Persistence and Defense Evasion sub-technique of T1542 (Pre-OS Boot). Adversaries may modify system firmware to persist on systems.The BIOS (Basic Input/Output System) and The Unified Extensible Firmware Interface (UEFI)...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1542-001-system-firmware
- T1542.002 Component Firmware
An Enterprise Persistence and Defense Evasion sub-technique of T1542 (Pre-OS Boot). Adversaries may modify component firmware to persist on systems. Some adversaries may employ sophisticated means to compromise computer components and...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1542-002-component-firmware
- T1542.003 Bootkit
An Enterprise Persistence and Defense Evasion sub-technique of T1542 (Pre-OS Boot). Adversaries may use bootkits to persist on systems. Bootkits reside at a layer below the operating system and may make it difficult to perform full...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1542-003-bootkit
- T1542.004 ROMMONkit
An Enterprise Defense Evasion and Persistence sub-technique of T1542 (Pre-OS Boot). Adversaries may abuse the ROM Monitor (ROMMON) by loading an unauthorized firmware with adversary code to provide persistent access and manipulate...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1542-004-rommonkit
- T1542.005 TFTP Boot
An Enterprise Defense Evasion and Persistence sub-technique of T1542 (Pre-OS Boot). Adversaries may abuse netbooting to load an unauthorized network device operating system from a Trivial File Transfer Protocol (TFTP) server. TFTP boot...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1542-005-tftp-boot
- T1543 Create or Modify System Process
Adversary creation or modification of OS-level system processes for persistence and privilege escalation. Sub-techniques include Launch Agent (T1543.001 macOS), Systemd Service (T1543.002 Linux), Windows Service (T1543.003), Launch...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1543-create-or-modify-system-process
- T1543.001 Launch Agent
An Enterprise Persistence and Privilege Escalation sub-technique of T1543 (Create or Modify System Process). Adversaries may create or modify launch agents to repeatedly execute malicious payloads as part of persistence. When a user...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1543-001-launch-agent
- T1543.002 Systemd Service
An Enterprise Persistence and Privilege Escalation sub-technique of T1543 (Create or Modify System Process). Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence. Systemd is a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1543-002-systemd-service
- T1543.003 Windows Service
Adversary persistence via Windows Service creation or modification (Service Control Manager). Lateral movement frameworks (PsExec, Impacket-smbexec, Cobalt Strike) and most ransomware operators create services for elevated execution and...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1543-003-windows-service
- T1543.004 Launch Daemon
An Enterprise Persistence and Privilege Escalation sub-technique of T1543 (Create or Modify System Process). Adversaries may create or modify Launch Daemons to execute malicious payloads as part of persistence. Launch Daemons are plist...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1543-004-launch-daemon
- T1543.005 Container Service
An Enterprise Persistence and Privilege Escalation sub-technique of T1543 (Create or Modify System Process). Adversaries may create or modify container or container cluster management tools that run as daemons, agents, or services on...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1543-005-container-service
- T1546 Event Triggered Execution
An Enterprise Privilege Escalation and Persistence technique. Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events. Various operating systems have means...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-event-triggered-execution
- T1546.001 Change Default File Association
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence by executing malicious content triggered by a file type association. When a file is opened, the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-001-change-default-file-association
- T1546.002 Screensaver
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence by executing malicious content triggered by user inactivity. Screensavers are programs that...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-002-screensaver
- T1546.003 Windows Management Instrumentation Event Subscription
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence and elevate privileges by executing malicious content triggered by a Windows Management...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-003-windows-management-instrumentation-event-subscription
- T1546.004 Unix Shell Configuration Modification
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence through executing malicious commands triggered by a user's shell. User Unix Shells execute...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-004-unix-shell-configuration-modification
- T1546.005 Trap
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence by executing malicious content triggered by an interrupt signal. The trap command allows...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-005-trap
- T1546.006 LC_LOAD_DYLIB Addition
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence by executing malicious content triggered by the execution of tainted binaries. Mach-O binaries...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-006-lc-load-dylib-addition
- T1546.007 Netsh Helper DLL
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence by executing malicious content triggered by Netsh Helper DLLs. Netsh.exe (also referred to as...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-007-netsh-helper-dll
- T1546.008 Accessibility Features
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by accessibility features....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-008-accessibility-features
- T1546.009 AppCert DLLs
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppCert DLLs loaded into...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-009-appcert-dlls
- T1546.010 AppInit DLLs
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppInit DLLs loaded into...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-010-appinit-dlls
- T1546.011 Application Shimming
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims. The...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-011-application-shimming
- T1546.012 Image File Execution Options Injection
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by Image File Execution...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-012-image-file-execution-options-injection
- T1546.013 PowerShell Profile
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may gain persistence and elevate privileges by executing malicious content triggered by PowerShell profiles. A PowerShell...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-013-powershell-profile
- T1546.014 Emond
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may gain persistence and elevate privileges by executing malicious content triggered by the Event Monitor Daemon (emond)....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-014-emond
- T1546.015 Component Object Model Hijacking
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence by executing malicious content triggered by hijacked references to Component Object Model (COM)...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-015-component-object-model-hijacking
- T1546.016 Installer Packages
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence and elevate privileges by using an installer to trigger the execution of malicious content....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-016-installer-packages
- T1546.017 Udev Rules
An Enterprise Persistence and Privilege Escalation sub-technique of T1546 (Event Triggered Execution). Adversaries may maintain persistence through executing malicious content triggered using udev rules. Udev is the Linux kernel device...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-017-udev-rules
- T1546.018 Python Startup Hooks
An Enterprise Persistence, Privilege Escalation technique. Adversaries may achieve persistence by leveraging Python’s startup mechanisms, including path configuration (`.pth`) files and the `sitecustomize.py` or `usercustomize.py`...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-018-python-startup-hooks
- T1547 Boot or Logon Autostart Execution
Adversary configuration of system settings to execute malicious code automatically at boot or user logon, providing persistence. The technique has 14 sub-techniques including Registry Run Keys (T1547.001), Authentication Packages...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-boot-logon-autostart-execution
- T1547.001 Registry Run Keys / Startup Folder
Adversary persistence via Windows Registry Run keys (HKLM Software Microsoft Windows CurrentVersion Run/RunOnce and HKCU equivalents) and Startup folder. This is the single most-cited persistence technique in Windows malware: Emotet,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-001-registry-run-keys-startup-folder
- T1547.002 Authentication Package
An Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may abuse authentication packages to execute DLLs when the system boots. Windows authentication package DLLs are...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-002-authentication-package
- T1547.003 Time Providers
An Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may abuse time providers to execute DLLs when the system boots. The Windows Time service (W32Time) enables time...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-003-time-providers
- T1547.004 Winlogon Helper DLL
An Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may abuse features of Winlogon to execute DLLs and/or executables when a user logs in. Winlogon.exe is a Windows...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-004-winlogon-helper-dll
- T1547.005 Security Support Provider
An Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may abuse security support providers (SSPs) to execute DLLs when the system boots. Windows SSP DLLs are loaded...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-005-security-support-provider
- T1547.006 Kernel Modules and Extensions
An Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may modify the kernel to automatically execute programs on system boot. Loadable Kernel Modules (LKMs) are pieces...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-006-kernel-modules-and-extensions
- T1547.007 Re-opened Applications
An Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may modify plist files to automatically run an application when a user logs in. When a user logs out or restarts...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-007-re-opened-applications
- T1547.008 LSASS Driver
An Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may modify or add LSASS drivers to obtain persistence on compromised systems. The Windows security subsystem is a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-008-lsass-driver
- T1547.009 Shortcut Modification
An Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may create or modify shortcuts that can execute a program during system boot or user login. Shortcuts or symbolic...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-009-shortcut-modification
- T1547.010 Port Monitors
An Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may use port monitors to run an adversary supplied DLL during system boot for persistence or privilege...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-010-port-monitors
- T1547.012 Print Processors
An Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may abuse print processors to run malicious DLLs during system boot for persistence and/or privilege escalation....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-012-print-processors
- T1547.013 XDG Autostart Entries
An Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may add or modify XDG Autostart Entries to execute malicious programs or commands when a user's desktop...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-013-xdg-autostart-entries
- T1547.014 Active Setup
An Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may achieve persistence by adding a Registry key to the Active Setup of the local machine. Active Setup is a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-014-active-setup
- T1547.015 Login Items
An Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may add login items to execute upon user login to gain persistence or escalate privileges. Login items are...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-015-login-items
- T1554 Compromise Host Software Binary
An Enterprise Persistence technique. Adversaries may modify host software binaries to establish persistent access to systems. Software binaries/executables provide a wide range of system commands or services, programs, and libraries....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1554-compromise-host-software-binary
- T1556 Modify Authentication Process
An Enterprise Credential Access and Defense Evasion and Persistence technique. Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-modify-authentication-process
- T1556.001 Domain Controller Authentication
An Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may patch the authentication process on a domain controller to bypass the typical authentication...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-001-domain-controller-authentication
- T1556.002 Password Filter DLL
An Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may register malicious password filter dynamic link libraries (DLLs) into the authentication process...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-002-password-filter-dll
- T1556.003 Pluggable Authentication Modules
An Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may modify pluggable authentication modules (PAM) to access user credentials or enable otherwise...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-003-pluggable-authentication-modules
- T1556.004 Network Device Authentication
An Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may use Patch System Image to hard code a password in the operating system, thus bypassing of native...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-004-network-device-authentication
- T1556.005 Reversible Encryption
An Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). An adversary may abuse Active Directory authentication encryption properties to gain access to credentials on...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-005-reversible-encryption
- T1556.006 Multi-Factor Authentication
An Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-006-multi-factor-authentication
- T1556.007 Hybrid Identity
An Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may patch, modify, or otherwise backdoor cloud authentication processes that are tied to on-premises...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-007-hybrid-identity
- T1556.008 Network Provider DLL
An Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may register malicious network provider dynamic link libraries (DLLs) to capture cleartext user...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-008-network-provider-dll
- T1556.009 Conditional Access Policies
An Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may disable or modify conditional access policies to enable persistent access to compromised...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-009-conditional-access-policies
- T1653 Power Settings
An Enterprise Persistence technique. Adversaries may impair a system's ability to hibernate, reboot, or shut down in order to extend access to infected machines. When a computer enters a dormant state, some or all software and hardware...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1653-power-settings
- T1668 Exclusive Control
An Enterprise Persistence technique. Adversaries who successfully compromise a system may attempt to maintain persistence by “closing the door” behind them - in other words, by preventing other threat actors from initially accessing or...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1668-exclusive-control
- T1671 Cloud Application Integration
An Enterprise Persistence technique. Adversaries may achieve persistence by leveraging OAuth application integrations in a software-as-a-service environment. Adversaries may create a custom application, add a legitimate application into...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1671-cloud-application-integration

[privilege-escalation] Privilege Escalation
- T1037 Boot or Logon Initialization Scripts
An Enterprise Persistence and Privilege Escalation technique. Adversaries may use scripts automatically executed at boot or logon initialization to establish persistence. Initialization scripts can be used to perform administrative...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1037-boot-or-logon-initialization-scripts
- T1037.001 Logon Script (Windows)
MITRE ATT&CK T1037.001 (Logon Script (Windows)) is an Enterprise Persistence and Privilege Escalation sub-technique of T1037 (Boot or Logon Initialization Scripts). Adversaries may use Windows logon scripts automatically executed at...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1037-001-logon-script-windows
- T1037.002 Login Hook
An Enterprise Persistence and Privilege Escalation sub-technique of T1037 (Boot or Logon Initialization Scripts). Adversaries may use a Login Hook to establish persistence executed upon user logon. A login hook is a plist file that...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1037-002-login-hook
- T1037.003 Network Logon Script
An Enterprise Persistence and Privilege Escalation sub-technique of T1037 (Boot or Logon Initialization Scripts). Adversaries may use network logon scripts automatically executed at logon initialization to establish persistence. Network...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1037-003-network-logon-script
- T1037.004 RC Scripts
An Enterprise Persistence and Privilege Escalation sub-technique of T1037 (Boot or Logon Initialization Scripts). Adversaries may establish persistence by modifying RC scripts which are executed during a Unix-like system's startup....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1037-004-rc-scripts
- T1037.005 Startup Items
An Enterprise Persistence and Privilege Escalation sub-technique of T1037 (Boot or Logon Initialization Scripts). Adversaries may use startup items automatically executed at boot initialization to establish persistence. Startup items...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1037-005-startup-items
- T1053 Scheduled Task/Job
An Enterprise Execution and Persistence and Privilege Escalation technique. Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code. Utilities exist within all major operating...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1053-scheduled-task-job
- T1053.002 At
An Enterprise Execution and Persistence and Privilege Escalation sub-technique of T1053 (Scheduled Task/Job). Adversaries may abuse the at utility to perform task scheduling for initial or recurring execution of malicious code. The at...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1053-002-at
- T1053.003 Cron
An Enterprise Execution and Persistence and Privilege Escalation sub-technique of T1053 (Scheduled Task/Job). Adversaries may abuse the cron utility to perform task scheduling for initial or recurring execution of malicious code. The...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1053-003-cron
- T1053.005 Scheduled Task
An Enterprise Execution and Persistence and Privilege Escalation sub-technique of T1053 (Scheduled Task/Job). Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1053-005-scheduled-task
- T1053.006 Systemd Timers
An Enterprise Execution and Persistence and Privilege Escalation sub-technique of T1053 (Scheduled Task/Job). Adversaries may abuse systemd timers to perform task scheduling for initial or recurring execution of malicious code. Systemd...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1053-006-systemd-timers
- T1053.007 Container Orchestration Job
An Enterprise Execution and Persistence and Privilege Escalation sub-technique of T1053 (Scheduled Task/Job). Adversaries may abuse task scheduling functionality provided by container orchestration tools such as Kubernetes to schedule...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1053-007-container-orchestration-job
- T1055 Process Injection
An Enterprise Defense Evasion and Privilege Escalation technique. Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1055-process-injection
- T1055.001 Dynamic-link Library Injection
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject dynamic-link libraries (DLLs) into processes in order to evade process-based defenses as well as possibly elevate...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1055-001-dynamic-link-library-injection
- T1055.002 Portable Executable Injection
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject portable executables (PE) into processes in order to evade process-based defenses as well as possibly elevate...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1055-002-portable-executable-injection
- T1055.003 Thread Execution Hijacking
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into hijacked processes in order to evade process-based defenses as well as possibly elevate...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1055-003-thread-execution-hijacking
- T1055.004 Asynchronous Procedure Call
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into processes via the asynchronous procedure call (APC) queue in order to evade process-based...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1055-004-asynchronous-procedure-call
- T1055.005 Thread Local Storage
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into processes via thread local storage (TLS) callbacks in order to evade process-based defenses as...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1055-005-thread-local-storage
- T1055.008 Ptrace System Calls
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into processes via ptrace (process trace) system calls in order to evade process-based defenses as...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1055-008-ptrace-system-calls
- T1055.009 Proc Memory
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into processes via the /proc filesystem in order to evade process-based defenses as well as...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1055-009-proc-memory
- T1055.011 Extra Window Memory Injection
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into process via Extra Window Memory (EWM) in order to evade process-based defenses as well as...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1055-011-extra-window-memory-injection
- T1055.012 Process Hollowing
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses. Process hollowing...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1055-012-process-hollowing
- T1055.013 Process Doppelgänging
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into process via process doppelgänging in order to evade process-based defenses as well as possibly...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1055-013-process-doppelg-nging
- T1055.014 VDSO Hijacking
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into processes via VDSO hijacking in order to evade process-based defenses as well as possibly...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1055-014-vdso-hijacking
- T1055.015 ListPlanting
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may abuse list-view controls to inject malicious code into hijacked processes in order to evade process-based defenses as...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1055-015-listplanting
- T1068 Exploitation for Privilege Escalation
Adversary exploitation of software vulnerabilities to elevate privileges from a lower-privilege context to higher (user to admin, admin to system, container escape to host). Notable real-world exploits include PrintNightmare...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1068-exploitation-privilege-escalation
- T1078 Valid Accounts
Adversary use of compromised credentials for initial access, persistence, privilege escalation, and defense evasion. Sub-techniques cover Default Accounts (T1078.001), Domain Accounts (T1078.002), Local Accounts (T1078.003), and Cloud...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1078-valid-accounts
- T1078.001 Default Accounts
An Enterprise Defense Evasion and Persistence and Privilege Escalation and Initial Access sub-technique of T1078 (Valid Accounts). Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1078-001-default-accounts
- T1078.002 Domain Accounts
An Enterprise Defense Evasion and Persistence and Privilege Escalation and Initial Access sub-technique of T1078 (Valid Accounts). Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1078-002-domain-accounts
- T1078.003 Local Accounts
An Enterprise Defense Evasion and Persistence and Privilege Escalation and Initial Access sub-technique of T1078 (Valid Accounts). Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1078-003-local-accounts
- T1078.004 Cloud Accounts
Adversary use of legitimate cloud account credentials (Microsoft Entra ID / Azure AD, AWS IAM, Google Workspace, GCP, Okta, Salesforce) to gain initial access, maintain persistence, escalate privileges, and evade detection. Cloud...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1078-004-cloud-accounts
- T1098 Account Manipulation
Adversary modification of accounts to maintain or escalate access. Sub-techniques cover Additional Cloud Credentials (T1098.001), Additional Email Delegate Permissions (T1098.002), Additional Cloud Roles (T1098.003), SSH Authorized Keys...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1098-account-manipulation
- T1098.001 Additional Cloud Credentials
An Enterprise Persistence and Privilege Escalation sub-technique of T1098 (Account Manipulation). Adversaries may add adversary-controlled credentials to a cloud account to maintain persistent access to victim accounts and instances...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1098-001-additional-cloud-credentials
- T1098.002 Additional Email Delegate Permissions
An Enterprise Persistence and Privilege Escalation sub-technique of T1098 (Account Manipulation). Adversaries may grant additional permission levels to maintain persistent access to an adversary-controlled email account. For example,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1098-002-additional-email-delegate-permissions
- T1098.003 Additional Cloud Roles
An Enterprise Persistence and Privilege Escalation sub-technique of T1098 (Account Manipulation). An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1098-003-additional-cloud-roles
- T1098.004 SSH Authorized Keys
An Enterprise Persistence and Privilege Escalation sub-technique of T1098 (Account Manipulation). Adversaries may modify the SSH authorized_keys file to maintain persistence on a victim host. Linux distributions and macOS commonly use...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1098-004-ssh-authorized-keys
- T1098.005 Device Registration
An Enterprise Persistence and Privilege Escalation sub-technique of T1098 (Account Manipulation). Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA)...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1098-005-device-registration
- T1098.006 Additional Container Cluster Roles
An Enterprise Persistence and Privilege Escalation sub-technique of T1098 (Account Manipulation). An adversary may add additional roles or permissions to an adversary-controlled user or service account to maintain persistent access to a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1098-006-additional-container-cluster-roles
- T1098.007 Additional Local or Domain Groups
An Enterprise Persistence and Privilege Escalation sub-technique of T1098 (Account Manipulation). An adversary may add additional local or domain groups to an adversary-controlled account to maintain persistent access to a system or...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1098-007-additional-local-or-domain-groups
- T1134 Access Token Manipulation
An Enterprise Defense Evasion and Privilege Escalation technique. Adversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls. Windows uses access...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1134-access-token-manipulation
- T1134.001 Token Impersonation/Theft
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1134 (Access Token Manipulation). Adversaries may duplicate then impersonate another user's existing token to escalate privileges and bypass access controls. For...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1134-001-token-impersonation-theft
- T1134.002 Create Process with Token
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1134 (Access Token Manipulation). Adversaries may create a new process with an existing token to escalate privileges and bypass access controls. Processes can be...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1134-002-create-process-with-token
- T1134.003 Make and Impersonate Token
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1134 (Access Token Manipulation). Adversaries may make new tokens and impersonate users to escalate privileges and bypass access controls. For example, if an...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1134-003-make-and-impersonate-token
- T1134.004 Parent PID Spoofing
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1134 (Access Token Manipulation). Adversaries may spoof the parent process identifier (PPID) of a new process to evade process-monitoring defenses or to elevate...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1134-004-parent-pid-spoofing
- T1134.005 SID-History Injection
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1134 (Access Token Manipulation). Adversaries may use SID-History Injection to escalate privileges and bypass access controls. The Windows security identifier...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1134-005-sid-history-injection
- T1484 Domain or Tenant Policy Modification
An Enterprise Defense Evasion and Privilege Escalation technique. Adversaries may modify the configuration settings of a domain or identity tenant to evade defenses and/or escalate privileges in centrally managed environments. Such...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1484-domain-or-tenant-policy-modification
- T1484.001 Group Policy Modification
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1484 (Domain or Tenant Policy Modification). Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1484-001-group-policy-modification
- T1484.002 Trust Modification
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1484 (Domain or Tenant Policy Modification). Adversaries may add new domain trusts, modify the properties of existing domain trusts, or otherwise change the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1484-002-trust-modification
- T1543 Create or Modify System Process
Adversary creation or modification of OS-level system processes for persistence and privilege escalation. Sub-techniques include Launch Agent (T1543.001 macOS), Systemd Service (T1543.002 Linux), Windows Service (T1543.003), Launch...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1543-create-or-modify-system-process
- T1543.001 Launch Agent
An Enterprise Persistence and Privilege Escalation sub-technique of T1543 (Create or Modify System Process). Adversaries may create or modify launch agents to repeatedly execute malicious payloads as part of persistence. When a user...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1543-001-launch-agent
- T1543.002 Systemd Service
An Enterprise Persistence and Privilege Escalation sub-technique of T1543 (Create or Modify System Process). Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence. Systemd is a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1543-002-systemd-service
- T1543.003 Windows Service
Adversary persistence via Windows Service creation or modification (Service Control Manager). Lateral movement frameworks (PsExec, Impacket-smbexec, Cobalt Strike) and most ransomware operators create services for elevated execution and...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1543-003-windows-service
- T1543.004 Launch Daemon
An Enterprise Persistence and Privilege Escalation sub-technique of T1543 (Create or Modify System Process). Adversaries may create or modify Launch Daemons to execute malicious payloads as part of persistence. Launch Daemons are plist...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1543-004-launch-daemon
- T1543.005 Container Service
An Enterprise Persistence and Privilege Escalation sub-technique of T1543 (Create or Modify System Process). Adversaries may create or modify container or container cluster management tools that run as daemons, agents, or services on...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1543-005-container-service
- T1546 Event Triggered Execution
An Enterprise Privilege Escalation and Persistence technique. Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events. Various operating systems have means...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-event-triggered-execution
- T1546.001 Change Default File Association
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence by executing malicious content triggered by a file type association. When a file is opened, the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-001-change-default-file-association
- T1546.002 Screensaver
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence by executing malicious content triggered by user inactivity. Screensavers are programs that...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-002-screensaver
- T1546.003 Windows Management Instrumentation Event Subscription
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence and elevate privileges by executing malicious content triggered by a Windows Management...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-003-windows-management-instrumentation-event-subscription
- T1546.004 Unix Shell Configuration Modification
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence through executing malicious commands triggered by a user's shell. User Unix Shells execute...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-004-unix-shell-configuration-modification
- T1546.005 Trap
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence by executing malicious content triggered by an interrupt signal. The trap command allows...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-005-trap
- T1546.006 LC_LOAD_DYLIB Addition
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence by executing malicious content triggered by the execution of tainted binaries. Mach-O binaries...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-006-lc-load-dylib-addition
- T1546.007 Netsh Helper DLL
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence by executing malicious content triggered by Netsh Helper DLLs. Netsh.exe (also referred to as...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-007-netsh-helper-dll
- T1546.008 Accessibility Features
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by accessibility features....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-008-accessibility-features
- T1546.009 AppCert DLLs
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppCert DLLs loaded into...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-009-appcert-dlls
- T1546.010 AppInit DLLs
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppInit DLLs loaded into...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-010-appinit-dlls
- T1546.011 Application Shimming
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims. The...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-011-application-shimming
- T1546.012 Image File Execution Options Injection
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by Image File Execution...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-012-image-file-execution-options-injection
- T1546.013 PowerShell Profile
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may gain persistence and elevate privileges by executing malicious content triggered by PowerShell profiles. A PowerShell...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-013-powershell-profile
- T1546.014 Emond
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may gain persistence and elevate privileges by executing malicious content triggered by the Event Monitor Daemon (emond)....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-014-emond
- T1546.015 Component Object Model Hijacking
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence by executing malicious content triggered by hijacked references to Component Object Model (COM)...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-015-component-object-model-hijacking
- T1546.016 Installer Packages
An Enterprise Privilege Escalation and Persistence sub-technique of T1546 (Event Triggered Execution). Adversaries may establish persistence and elevate privileges by using an installer to trigger the execution of malicious content....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-016-installer-packages
- T1546.017 Udev Rules
An Enterprise Persistence and Privilege Escalation sub-technique of T1546 (Event Triggered Execution). Adversaries may maintain persistence through executing malicious content triggered using udev rules. Udev is the Linux kernel device...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-017-udev-rules
- T1546.018 Python Startup Hooks
An Enterprise Persistence, Privilege Escalation technique. Adversaries may achieve persistence by leveraging Python’s startup mechanisms, including path configuration (`.pth`) files and the `sitecustomize.py` or `usercustomize.py`...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1546-018-python-startup-hooks
- T1547 Boot or Logon Autostart Execution
Adversary configuration of system settings to execute malicious code automatically at boot or user logon, providing persistence. The technique has 14 sub-techniques including Registry Run Keys (T1547.001), Authentication Packages...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-boot-logon-autostart-execution
- T1547.001 Registry Run Keys / Startup Folder
Adversary persistence via Windows Registry Run keys (HKLM Software Microsoft Windows CurrentVersion Run/RunOnce and HKCU equivalents) and Startup folder. This is the single most-cited persistence technique in Windows malware: Emotet,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-001-registry-run-keys-startup-folder
- T1547.002 Authentication Package
An Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may abuse authentication packages to execute DLLs when the system boots. Windows authentication package DLLs are...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-002-authentication-package
- T1547.003 Time Providers
An Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may abuse time providers to execute DLLs when the system boots. The Windows Time service (W32Time) enables time...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-003-time-providers
- T1547.004 Winlogon Helper DLL
An Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may abuse features of Winlogon to execute DLLs and/or executables when a user logs in. Winlogon.exe is a Windows...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-004-winlogon-helper-dll
- T1547.005 Security Support Provider
An Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may abuse security support providers (SSPs) to execute DLLs when the system boots. Windows SSP DLLs are loaded...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-005-security-support-provider
- T1547.006 Kernel Modules and Extensions
An Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may modify the kernel to automatically execute programs on system boot. Loadable Kernel Modules (LKMs) are pieces...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-006-kernel-modules-and-extensions
- T1547.007 Re-opened Applications
An Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may modify plist files to automatically run an application when a user logs in. When a user logs out or restarts...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-007-re-opened-applications
- T1547.008 LSASS Driver
An Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may modify or add LSASS drivers to obtain persistence on compromised systems. The Windows security subsystem is a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-008-lsass-driver
- T1547.009 Shortcut Modification
An Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may create or modify shortcuts that can execute a program during system boot or user login. Shortcuts or symbolic...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-009-shortcut-modification
- T1547.010 Port Monitors
An Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may use port monitors to run an adversary supplied DLL during system boot for persistence or privilege...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-010-port-monitors
- T1547.012 Print Processors
An Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may abuse print processors to run malicious DLLs during system boot for persistence and/or privilege escalation....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-012-print-processors
- T1547.013 XDG Autostart Entries
An Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may add or modify XDG Autostart Entries to execute malicious programs or commands when a user's desktop...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-013-xdg-autostart-entries
- T1547.014 Active Setup
An Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may achieve persistence by adding a Registry key to the Active Setup of the local machine. Active Setup is a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-014-active-setup
- T1547.015 Login Items
An Enterprise Persistence and Privilege Escalation sub-technique of T1547 (Boot or Logon Autostart Execution). Adversaries may add login items to execute upon user login to gain persistence or escalate privileges. Login items are...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1547-015-login-items
- T1548 Abuse Elevation Control Mechanism
An Enterprise Privilege Escalation and Defense Evasion technique. Adversaries may circumvent mechanisms designed to control elevate privileges to gain higher-level permissions. Most modern systems contain native elevation control...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1548-abuse-elevation-control-mechanism
- T1548.001 Setuid and Setgid
An Enterprise Privilege Escalation and Defense Evasion sub-technique of T1548 (Abuse Elevation Control Mechanism). An adversary may abuse configurations where an application has the setuid or setgid bits set in order to get code running...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1548-001-setuid-and-setgid
- T1548.002 Bypass User Account Control
An Enterprise Privilege Escalation and Defense Evasion sub-technique of T1548 (Abuse Elevation Control Mechanism). Adversaries may bypass UAC mechanisms to elevate process privileges on system. Windows User Account Control (UAC) allows...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1548-002-bypass-user-account-control
- T1548.003 Sudo and Sudo Caching
An Enterprise Privilege Escalation and Defense Evasion sub-technique of T1548 (Abuse Elevation Control Mechanism). Adversaries may perform sudo caching and/or use the sudoers file to elevate privileges. Adversaries may do this to...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1548-003-sudo-and-sudo-caching
- T1548.004 Elevated Execution with Prompt
An Enterprise Privilege Escalation and Defense Evasion sub-technique of T1548 (Abuse Elevation Control Mechanism). Adversaries may leverage the AuthorizationExecuteWithPrivileges API to escalate privileges by prompting the user for...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1548-004-elevated-execution-with-prompt
- T1548.005 Temporary Elevated Cloud Access
An Enterprise Privilege Escalation and Defense Evasion sub-technique of T1548 (Abuse Elevation Control Mechanism). Adversaries may abuse permission configurations that allow them to gain temporarily elevated access to cloud resources....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1548-005-temporary-elevated-cloud-access
- T1548.006 TCC Manipulation
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1548 (Abuse Elevation Control Mechanism). Adversaries can manipulate or abuse the Transparency, Consent, & Control (TCC) service or database to grant malicious...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1548-006-tcc-manipulation
- T1611 Escape to Host
An Enterprise Privilege Escalation technique. Adversaries may break out of a container to gain access to the underlying host. This can allow an adversary access to other containerized resources from the host level or to the host itself....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1611-escape-to-host

[credential-access] Credential Access
- T1003 OS Credential Dumping
Adversary techniques for dumping credentials from operating systems and software. Sub-techniques include LSASS Memory (T1003.001), Security Account Manager (T1003.002), NTDS (T1003.003), LSA Secrets (T1003.004), Cached Domain...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1003-os-credential-dumping
- T1003.001 LSASS Memory
Adversary extraction of authentication credentials from the Local Security Authority Subsystem Service (LSASS) process memory on Windows endpoints. Mimikatz, Pypykatz, ProcDump, Task Manager dump, Cobalt Strike credential dumping...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1003-001-lsass-memory
- T1003.002 Security Account Manager
An Enterprise Credential Access sub-technique of T1003 (OS Credential Dumping). Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1003-002-security-account-manager
- T1003.003 NTDS
An Enterprise Credential Access sub-technique of T1003 (OS Credential Dumping). Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1003-003-ntds
- T1003.004 LSA Secrets
An Enterprise Credential Access sub-technique of T1003 (OS Credential Dumping). Adversaries with SYSTEM access to a host may attempt to access Local Security Authority (LSA) secrets, which can contain a variety of different credential...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1003-004-lsa-secrets
- T1003.005 Cached Domain Credentials
An Enterprise Credential Access sub-technique of T1003 (OS Credential Dumping). Adversaries may attempt to access cached domain credentials used to allow authentication to occur in the event a domain controller is unavailable. On...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1003-005-cached-domain-credentials
- T1003.006 DCSync
Adversary impersonation of a Domain Controller to retrieve password hashes via Microsoft Directory Replication Service (MS-DRSR) protocol. Tools include Mimikatz lsadump::dcsync, Impacket secretsdump.py, NetExec/CrackMapExec ntds...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1003-006-dcsync
- T1003.007 Proc Filesystem
An Enterprise Credential Access sub-technique of T1003 (OS Credential Dumping). Adversaries may gather credentials from the proc filesystem or /proc. The proc filesystem is a pseudo-filesystem used as an interface to kernel data...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1003-007-proc-filesystem
- T1003.008 /etc/passwd and /etc/shadow
An Enterprise Credential Access sub-technique of T1003 (OS Credential Dumping). Adversaries may attempt to dump the contents of /etc/passwd and /etc/shadow to enable offline password cracking. Most modern Linux operating systems use a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1003-008-etc-passwd-and-etc-shadow
- T1040 Network Sniffing
An Enterprise Credential Access and Discovery technique. Adversaries may passively sniff network traffic to capture information about an environment, including authentication material passed over the network. Network sniffing refers to...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1040-network-sniffing
- T1056 Input Capture
An Enterprise Collection and Credential Access technique. Adversaries may use methods of capturing user input to obtain credentials or collect information. During normal system usage, users often provide credentials to various different...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1056-input-capture
- T1056.001 Keylogging
An Enterprise Collection and Credential Access sub-technique of T1056 (Input Capture). Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1056-001-keylogging
- T1056.002 GUI Input Capture
An Enterprise Collection and Credential Access sub-technique of T1056 (Input Capture). Adversaries may mimic common operating system GUI components to prompt users for credentials with a seemingly legitimate prompt. When programs are...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1056-002-gui-input-capture
- T1056.003 Web Portal Capture
An Enterprise Collection and Credential Access sub-technique of T1056 (Input Capture). Adversaries may install code on externally facing portals, such as a VPN login page, to capture and transmit credentials of users who attempt to log...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1056-003-web-portal-capture
- T1056.004 Credential API Hooking
An Enterprise Collection and Credential Access sub-technique of T1056 (Input Capture). Adversaries may hook into Windows application programming interface (API) functions to collect user credentials. Malicious hooking mechanisms may...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1056-004-credential-api-hooking
- T1110 Brute Force
Adversary attempts to gain access through systematic guessing of credentials. Sub-techniques include Password Guessing (T1110.001), Password Cracking (T1110.002), Password Spraying (T1110.003), and Credential Stuffing (T1110.004)....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1110-brute-force
- T1110.001 Password Guessing
An Enterprise Credential Access sub-technique of T1110 (Brute Force). Adversaries with no prior knowledge of legitimate credentials within the system or environment may guess passwords to attempt access to accounts. Without knowledge of...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1110-001-password-guessing
- T1110.002 Password Cracking
An Enterprise Credential Access sub-technique of T1110 (Brute Force). Adversaries may use password cracking to attempt to recover usable credentials, such as plaintext passwords, when credential material such as password hashes are...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1110-002-password-cracking
- T1110.003 Password Spraying
An Enterprise Credential Access sub-technique of T1110 (Brute Force). Adversaries may use a single or small list of commonly used passwords against many different accounts to attempt to acquire valid account credentials. Password...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1110-003-password-spraying
- T1110.004 Credential Stuffing
An Enterprise Credential Access sub-technique of T1110 (Brute Force). Adversaries may use credentials obtained from breach dumps of unrelated accounts to gain access to target accounts through credential overlap. Occasionally, large...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1110-004-credential-stuffing
- T1111 Multi-Factor Authentication Interception
An Enterprise Credential Access technique. Adversaries may target multi-factor authentication (MFA) mechanisms, (i.e., smart cards, token generators, etc.) to gain access to credentials that can be used to access systems, services, and...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1111-multi-factor-authentication-interception
- T1187 Forced Authentication
An Enterprise Credential Access technique. Adversaries may gather credential material by invoking or forcing a user to automatically provide authentication information through a mechanism in which they can intercept. The Server Message...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1187-forced-authentication
- T1212 Exploitation for Credential Access
An Enterprise Credential Access technique. Adversaries may exploit software vulnerabilities in an attempt to collect credentials. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1212-exploitation-for-credential-access
- T1528 Steal Application Access Token
An Enterprise Credential Access technique. Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources. Application access tokens are used to make authorized API requests on...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1528-steal-application-access-token
- T1539 Steal Web Session Cookie
Adversary theft of web session cookies to bypass MFA and impersonate authenticated users. Storm-0558 (Microsoft, 2023) and SCATTERED SPIDER (Okta, 2023-2024) campaigns leveraged stolen session cookies extensively. Modern infostealers...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1539-steal-web-session-cookie
- T1552 Unsecured Credentials
An Enterprise Credential Access technique. Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1552-unsecured-credentials
- T1552.001 Credentials In Files
An Enterprise Credential Access sub-technique of T1552 (Unsecured Credentials). Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials. These can be files created by users to...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1552-001-credentials-in-files
- T1552.002 Credentials in Registry
An Enterprise Credential Access sub-technique of T1552 (Unsecured Credentials). Adversaries may search the Registry on compromised systems for insecurely stored credentials. The Windows Registry stores configuration information that can...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1552-002-credentials-in-registry
- T1552.003 Shell History
An Enterprise Credential Access sub-technique of T1552 (Unsecured Credentials). Adversaries may search the bash command history on compromised systems for insecurely stored credentials. Bash keeps track of the commands users type on the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1552-003-bash-history
- T1552.004 Private Keys
An Enterprise Credential Access sub-technique of T1552 (Unsecured Credentials). Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials. Private cryptographic keys and...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1552-004-private-keys
- T1552.005 Cloud Instance Metadata API
An Enterprise Credential Access sub-technique of T1552 (Unsecured Credentials). Adversaries may attempt to access the Cloud Instance Metadata API to collect credentials and other sensitive data. Most cloud service providers support a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1552-005-cloud-instance-metadata-api
- T1552.006 Group Policy Preferences
An Enterprise Credential Access sub-technique of T1552 (Unsecured Credentials). Adversaries may attempt to find unsecured credentials in Group Policy Preferences (GPP). GPP are tools that allow administrators to create domain policies...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1552-006-group-policy-preferences
- T1552.007 Container API
An Enterprise Credential Access sub-technique of T1552 (Unsecured Credentials). Adversaries may gather credentials via APIs within a containers environment. APIs in these environments, such as the Docker API and Kubernetes APIs, allow a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1552-007-container-api
- T1552.008 Chat Messages
An Enterprise Credential Access sub-technique of T1552 (Unsecured Credentials). Adversaries may directly collect unsecured credentials stored or passed through user communication services. Credentials may be sent and stored in user chat...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1552-008-chat-messages
- T1555 Credentials from Password Stores
Adversary access to credentials stored in browsers, password managers, and OS credential stores. Sub-techniques include Keychain (T1555.001), Securityd Memory (T1555.002), Credentials from Web Browsers (T1555.003), Windows Credential...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1555-credentials-from-password-stores
- T1555.001 Keychain
An Enterprise Credential Access sub-technique of T1555 (Credentials from Password Stores). Adversaries may acquire credentials from Keychain. Keychain (or Keychain Services) is the macOS credential management system that stores account...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1555-001-keychain
- T1555.002 Securityd Memory
An Enterprise Credential Access sub-technique of T1555 (Credentials from Password Stores). An adversary with root access may gather credentials by reading securityd's memory. securityd is a service/daemon responsible for implementing...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1555-002-securityd-memory
- T1555.003 Credentials from Web Browsers
An Enterprise Credential Access sub-technique of T1555 (Credentials from Password Stores). Adversaries may acquire credentials from web browsers by reading files specific to the target browser. Web browsers commonly save credentials...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1555-003-credentials-from-web-browsers
- T1555.004 Windows Credential Manager
An Enterprise Credential Access sub-technique of T1555 (Credentials from Password Stores). Adversaries may acquire credentials from the Windows Credential Manager. The Credential Manager stores credentials for signing into websites,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1555-004-windows-credential-manager
- T1555.005 Password Managers
An Enterprise Credential Access sub-technique of T1555 (Credentials from Password Stores). Adversaries may acquire user credentials from third-party password managers. Password managers are applications designed to store user...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1555-005-password-managers
- T1555.006 Cloud Secrets Management Stores
An Enterprise Credential Access sub-technique of T1555 (Credentials from Password Stores). Adversaries may acquire credentials from cloud-native secret management solutions such as AWS Secrets Manager, GCP Secret Manager, Azure Key...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1555-006-cloud-secrets-management-stores
- T1556 Modify Authentication Process
An Enterprise Credential Access and Defense Evasion and Persistence technique. Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-modify-authentication-process
- T1556.001 Domain Controller Authentication
An Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may patch the authentication process on a domain controller to bypass the typical authentication...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-001-domain-controller-authentication
- T1556.002 Password Filter DLL
An Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may register malicious password filter dynamic link libraries (DLLs) into the authentication process...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-002-password-filter-dll
- T1556.003 Pluggable Authentication Modules
An Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may modify pluggable authentication modules (PAM) to access user credentials or enable otherwise...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-003-pluggable-authentication-modules
- T1556.004 Network Device Authentication
An Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may use Patch System Image to hard code a password in the operating system, thus bypassing of native...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-004-network-device-authentication
- T1556.005 Reversible Encryption
An Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). An adversary may abuse Active Directory authentication encryption properties to gain access to credentials on...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-005-reversible-encryption
- T1556.006 Multi-Factor Authentication
An Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-006-multi-factor-authentication
- T1556.007 Hybrid Identity
An Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may patch, modify, or otherwise backdoor cloud authentication processes that are tied to on-premises...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-007-hybrid-identity
- T1556.008 Network Provider DLL
An Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may register malicious network provider dynamic link libraries (DLLs) to capture cleartext user...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-008-network-provider-dll
- T1556.009 Conditional Access Policies
An Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may disable or modify conditional access policies to enable persistent access to compromised...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-009-conditional-access-policies
- T1557 Adversary-in-the-Middle
An Enterprise Credential Access and Collection technique. Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1557-adversary-in-the-middle
- T1557.001 Name Resolution Poisoning and SMB Relay
An Enterprise Credential Access and Collection sub-technique of T1557 (Adversary-in-the-Middle). By responding to LLMNR/NBT-NS network traffic, adversaries may spoof an authoritative source for name resolution to force communication...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1557-001-llmnr-nbt-ns-poisoning-and-smb-relay
- T1557.002 ARP Cache Poisoning
An Enterprise Credential Access and Collection sub-technique of T1557 (Adversary-in-the-Middle). Adversaries may poison Address Resolution Protocol (ARP) caches to position themselves between the communication of two or more networked...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1557-002-arp-cache-poisoning
- T1557.003 DHCP Spoofing
An Enterprise Credential Access and Collection sub-technique of T1557 (Adversary-in-the-Middle). Adversaries may redirect network traffic to adversary-owned systems by spoofing Dynamic Host Configuration Protocol (DHCP) traffic and...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1557-003-dhcp-spoofing
- T1557.004 Evil Twin
An Enterprise Credential Access and Collection sub-technique of T1557 (Adversary-in-the-Middle). Adversaries may host seemingly genuine Wi-Fi access points to deceive users into connecting to malicious networks as a way of supporting...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1557-004-evil-twin
- T1558 Steal or Forge Kerberos Tickets
An Enterprise Credential Access technique. Adversaries may attempt to subvert Kerberos authentication by stealing or forging Kerberos tickets to enable Pass the Ticket. Kerberos is an authentication protocol widely used in modern...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1558-steal-or-forge-kerberos-tickets
- T1558.001 Golden Ticket
An Enterprise Credential Access sub-technique of T1558 (Steal or Forge Kerberos Tickets). Adversaries who have the KRBTGT account password hash may forge Kerberos ticket-granting tickets (TGT), also known as a golden ticket. Golden...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1558-001-golden-ticket
- T1558.002 Silver Ticket
An Enterprise Credential Access sub-technique of T1558 (Steal or Forge Kerberos Tickets). Adversaries who have the password hash of a target service account (e.g. SharePoint, MSSQL) may forge Kerberos ticket granting service (TGS)...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1558-002-silver-ticket
- T1558.003 Kerberoasting
An Enterprise Credential Access sub-technique of T1558 (Steal or Forge Kerberos Tickets). Adversaries may abuse a valid Kerberos ticket-granting ticket (TGT) or sniff network traffic to obtain a ticket-granting service (TGS) ticket that...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1558-003-kerberoasting
- T1558.004 AS-REP Roasting
An Enterprise Credential Access sub-technique of T1558 (Steal or Forge Kerberos Tickets). Adversaries may reveal credentials of accounts that have disabled Kerberos preauthentication by Password Cracking Kerberos messages....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1558-004-as-rep-roasting
- T1558.005 Ccache Files
An Enterprise Credential Access sub-technique of T1558 (Steal or Forge Kerberos Tickets). Adversaries may attempt to steal Kerberos tickets stored in credential cache files (or ccache). These files are used for short term storage of a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1558-005-ccache-files
- T1606 Forge Web Credentials
An Enterprise Credential Access technique. Adversaries may forge credential materials that can be used to gain access to web applications or Internet services. Web applications and services (hosted in cloud SaaS environments or...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1606-forge-web-credentials
- T1606.001 Web Cookies
An Enterprise Credential Access sub-technique of T1606 (Forge Web Credentials). Adversaries may forge web cookies that can be used to gain access to web applications or Internet services. Web applications and services (hosted in cloud...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1606-001-web-cookies
- T1606.002 SAML Tokens
An Enterprise Credential Access sub-technique of T1606 (Forge Web Credentials). An adversary may forge SAML tokens with any permissions claims and lifetimes if they possess a valid SAML token-signing certificate. The default lifetime of...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1606-002-saml-tokens
- T1621 Multi-Factor Authentication Request Generation
An Enterprise Credential Access technique. Adversaries may attempt to bypass multi-factor authentication (MFA) mechanisms and gain access to accounts by generating MFA requests sent to users. Adversaries in possession of credentials to...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1621-multi-factor-authentication-request-generation
- T1649 Steal or Forge Authentication Certificates
An Enterprise Credential Access technique. Adversaries may steal or forge certificates used for authentication to access remote systems or resources. Digital certificates are often used to sign and encrypt messages and/or files....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1649-steal-or-forge-authentication-certificates

[discovery] Discovery
- T1007 System Service Discovery
An Enterprise Discovery technique. Adversaries may try to gather information about registered local system services. Adversaries may obtain information about services using tools as well as OS utility commands such as sc query, tasklist...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1007-system-service-discovery
- T1010 Application Window Discovery
An Enterprise Discovery technique. Adversaries may attempt to get a listing of open application windows. Window listings could convey information about how the system is used. For example, information about application windows could be...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1010-application-window-discovery
- T1012 Query Registry
An Enterprise Discovery technique. Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software. The Registry contains a significant amount of information about the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1012-query-registry
- T1016 System Network Configuration Discovery
An Enterprise Discovery technique. Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems. Several...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1016-system-network-configuration-discovery
- T1016.001 Internet Connection Discovery
An Enterprise Discovery sub-technique of T1016 (System Network Configuration Discovery). Adversaries may check for Internet connectivity on compromised systems. This may be performed during automated discovery and can be accomplished in...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1016-001-internet-connection-discovery
- T1016.002 Wi-Fi Discovery
An Enterprise Discovery sub-technique of T1016 (System Network Configuration Discovery). Adversaries may search for information about Wi-Fi networks, such as network names and passwords, on compromised systems. Adversaries may use Wi-Fi...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1016-002-wi-fi-discovery
- T1018 Remote System Discovery
Adversary enumeration of remote systems on the network to enable lateral movement planning. Tools include built-in net commands, nltest, BloodHound, SharpHound, and PowerView. Active Directory enumeration is a hallmark of ransomware...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1018-remote-system-discovery
- T1033 System Owner/User Discovery
An Enterprise Discovery technique. Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system. They may do this, for example,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1033-system-owner-user-discovery
- T1040 Network Sniffing
An Enterprise Credential Access and Discovery technique. Adversaries may passively sniff network traffic to capture information about an environment, including authentication material passed over the network. Network sniffing refers to...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1040-network-sniffing
- T1046 Network Service Discovery
An Enterprise Discovery technique. Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1046-network-service-discovery
- T1049 System Network Connections Discovery
An Enterprise Discovery technique. Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network. An...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1049-system-network-connections-discovery
- T1057 Process Discovery
Adversary enumeration of running processes to identify security tools, valuable applications, and post-exploitation opportunities. Common commands include tasklist, Get-Process, ps, and direct API calls. Process enumeration is typically...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1057-process-discovery
- T1069 Permission Groups Discovery
An Enterprise Discovery technique. Adversaries may attempt to discover group and permission settings. This information can help adversaries determine which user accounts and groups are available, the membership of users in particular...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1069-permission-groups-discovery
- T1069.001 Local Groups
An Enterprise Discovery sub-technique of T1069 (Permission Groups Discovery). Adversaries may attempt to find local system groups and permission settings. The knowledge of local system permission groups can help adversaries determine...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1069-001-local-groups
- T1069.002 Domain Groups
An Enterprise Discovery sub-technique of T1069 (Permission Groups Discovery). Adversaries may attempt to find domain-level groups and permission settings. The knowledge of domain-level permission groups can help adversaries determine...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1069-002-domain-groups
- T1069.003 Cloud Groups
An Enterprise Discovery sub-technique of T1069 (Permission Groups Discovery). Adversaries may attempt to find cloud groups and permission settings. The knowledge of cloud permission groups can help adversaries determine the particular...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1069-003-cloud-groups
- T1083 File and Directory Discovery
Adversary enumeration of files and directories to find files of interest, identify backup locations, and map storage structures. The technique is universally observed across nation-state and criminal campaigns as part of the early...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1083-file-and-directory-discovery
- T1087 Account Discovery
An Enterprise Discovery technique. Adversaries may attempt to get a listing of valid accounts, usernames, or email addresses on a system or within a compromised environment. This information can help adversaries determine which accounts...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1087-account-discovery
- T1087.001 Local Account
An Enterprise Discovery sub-technique of T1087 (Account Discovery). Adversaries may attempt to get a listing of local system accounts. This information can help adversaries determine which local accounts exist on a system to aid in...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1087-001-local-account
- T1087.002 Domain Account
An Enterprise Discovery sub-technique of T1087 (Account Discovery). Adversaries may attempt to get a listing of domain accounts. This information can help adversaries determine which domain accounts exist to aid in follow-on behavior...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1087-002-domain-account
- T1087.003 Email Account
An Enterprise Discovery sub-technique of T1087 (Account Discovery). Adversaries may attempt to get a listing of email addresses and accounts. Adversaries may try to dump Exchange address lists such as global address lists (GALs). In...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1087-003-email-account
- T1087.004 Cloud Account
An Enterprise Discovery sub-technique of T1087 (Account Discovery). Adversaries may attempt to get a listing of cloud accounts. Cloud accounts are those created and configured by an organization for use by users, remote support,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1087-004-cloud-account
- T1120 Peripheral Device Discovery
An Enterprise Discovery technique. Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system. Peripheral devices could include auxiliary resources that support a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1120-peripheral-device-discovery
- T1124 System Time Discovery
An Enterprise Discovery technique. An adversary may gather the system time and/or time zone settings from a local or remote system. The system time is set and stored by services, such as the Windows Time Service on Windows or...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1124-system-time-discovery
- T1135 Network Share Discovery
An Enterprise Discovery technique. Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1135-network-share-discovery
- T1201 Password Policy Discovery
An Enterprise Discovery technique. Adversaries may attempt to access detailed information about the password policy used within an enterprise network or cloud environment. Password policies are a way to enforce complex passwords that...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1201-password-policy-discovery
- T1217 Browser Information Discovery
An Enterprise Discovery technique. Adversaries may enumerate information about browsers to learn more about compromised environments. Data saved by browsers (such as bookmarks, accounts, and browsing history) may reveal a variety of...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1217-browser-information-discovery
- T1482 Domain Trust Discovery
An Enterprise Discovery technique. Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments. Domain trusts...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1482-domain-trust-discovery
- T1497 Virtualization/Sandbox Evasion
An Enterprise Defense Evasion and Discovery technique. Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1497-virtualization-sandbox-evasion
- T1497.001 System Checks
An Enterprise Defense Evasion and Discovery sub-technique of T1497 (Virtualization/Sandbox Evasion). Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1497-001-system-checks
- T1497.002 User Activity Based Checks
An Enterprise Defense Evasion and Discovery sub-technique of T1497 (Virtualization/Sandbox Evasion). Adversaries may employ various user activity checks to detect and avoid virtualization and analysis environments. This may include...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1497-002-user-activity-based-checks
- T1497.003 Time Based Checks
An Enterprise Defense Evasion and Discovery sub-technique of T1497 (Virtualization/Sandbox Evasion). Adversaries may employ various time-based methods to detect and avoid virtualization and analysis environments. This may include...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1497-003-time-based-evasion
- T1518 Software Discovery
An Enterprise Discovery technique. Adversaries may attempt to get a listing of software and software versions that are installed on a system or in a cloud environment. Adversaries may use the information from Software Discovery during...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1518-software-discovery
- T1518.001 Security Software Discovery
An Enterprise Discovery sub-technique of T1518 (Software Discovery). Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1518-001-security-software-discovery
- T1518.002 Backup Software Discovery
An Enterprise Discovery technique. Adversaries may attempt to get a listing of backup software or configurations that are installed on a system. Adversaries may use this information to shape follow-on behaviors, such as Data...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1518-002-backup-software-discovery
- T1526 Cloud Service Discovery
An Enterprise Discovery technique. An adversary may attempt to enumerate the cloud services running on a system after gaining access. These methods can differ from platform-as-a-service (PaaS), to infrastructure-as-a-service (IaaS), or...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1526-cloud-service-discovery
- T1538 Cloud Service Dashboard
An Enterprise Discovery technique. An adversary may use a cloud service dashboard GUI with stolen credentials to gain useful information from an operational cloud environment, such as specific services, resources, and features. For...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1538-cloud-service-dashboard
- T1580 Cloud Infrastructure Discovery
An Enterprise Discovery technique. An adversary may attempt to discover infrastructure and resources that are available within an infrastructure-as-a-service (IaaS) environment. This includes compute service resources such as instances,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1580-cloud-infrastructure-discovery
- T1613 Container and Resource Discovery
An Enterprise Discovery technique. Adversaries may attempt to discover containers and other resources that are available within a containers environment. Other resources may include images, deployments, pods, nodes, and other...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1613-container-and-resource-discovery
- T1614 System Location Discovery
An Enterprise Discovery technique. Adversaries may gather information in an attempt to calculate the geographical location of a victim host. Adversaries may use the information from System Location Discovery during automated discovery...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1614-system-location-discovery
- T1614.001 System Language Discovery
An Enterprise Discovery sub-technique of T1614 (System Location Discovery). Adversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host. This information...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1614-001-system-language-discovery
- T1615 Group Policy Discovery
An Enterprise Discovery technique. Adversaries may gather information on Group Policy settings to identify paths for privilege escalation, security measures applied within a domain, and to discover patterns in domain objects that can be...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1615-group-policy-discovery
- T1619 Cloud Storage Object Discovery
An Enterprise Discovery technique. Adversaries may enumerate objects in cloud storage infrastructure. Adversaries may use this information during automated discovery to shape follow-on behaviors, including requesting all or specific...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1619-cloud-storage-object-discovery
- T1622 Debugger Evasion
An Enterprise Defense Evasion and Discovery technique. Adversaries may employ various means to detect and avoid debuggers. Debuggers are typically used by defenders to trace and/or analyze the execution of potential malware payloads....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1622-debugger-evasion
- T1652 Device Driver Discovery
An Enterprise Discovery technique. Adversaries may attempt to enumerate local device drivers on a victim host. Information about device drivers may highlight various insights that shape follow-on behaviors, such as the function/purpose...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1652-device-driver-discovery
- T1654 Log Enumeration
An Enterprise Discovery technique. Adversaries may enumerate system and service logs to find useful data. These logs may highlight various types of valuable insights for an adversary, such as user authentication records (Account...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1654-log-enumeration
- T1673 Virtual Machine Discovery
An Enterprise Discovery technique. An adversary may attempt to enumerate running virtual machines (VMs) after gaining access to a host or hypervisor. For example, adversaries may enumerate a list of VMs on an ESXi hypervisor using a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1673-virtual-machine-discovery
- T1680 Local Storage Discovery
An Enterprise Discovery technique. Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number. This can be done to prepare for ransomware-related encryption, to...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1680-local-storage-discovery

[lateral-movement] Lateral Movement
- T1021 Remote Services
Adversary use of valid accounts to log into remote services for lateral movement. Sub-techniques cover Remote Desktop Protocol (T1021.001), SMB/Windows Admin Shares (T1021.002), Distributed Component Object Model (T1021.003), SSH...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1021-remote-services
- T1021.001 Remote Desktop Protocol
An Enterprise Lateral Movement sub-technique of T1021 (Remote Services). Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP). The adversary may then perform actions as the logged-on user....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1021-001-remote-desktop-protocol
- T1021.002 SMB/Windows Admin Shares
An Enterprise Lateral Movement sub-technique of T1021 (Remote Services). Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB). The adversary may then perform actions as the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1021-002-smb-windows-admin-shares
- T1021.003 Distributed Component Object Model
An Enterprise Lateral Movement sub-technique of T1021 (Remote Services). Adversaries may use Valid Accounts to interact with remote machines by taking advantage of Distributed Component Object Model (DCOM). The adversary may then...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1021-003-distributed-component-object-model
- T1021.004 SSH
An Enterprise Lateral Movement sub-technique of T1021 (Remote Services). Adversaries may use Valid Accounts to log into remote machines using Secure Shell (SSH). The adversary may then perform actions as the logged-on user. SSH is a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1021-004-ssh
- T1021.005 VNC
An Enterprise Lateral Movement sub-technique of T1021 (Remote Services). Adversaries may use Valid Accounts to remotely control machines using Virtual Network Computing (VNC). VNC is a platform-independent desktop sharing system that...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1021-005-vnc
- T1021.006 Windows Remote Management
An Enterprise Lateral Movement sub-technique of T1021 (Remote Services). Adversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM). The adversary may then perform actions as the logged-on...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1021-006-windows-remote-management
- T1021.007 Cloud Services
An Enterprise Lateral Movement sub-technique of T1021 (Remote Services). Adversaries may log into accessible cloud services within a compromised environment using Valid Accounts that are synchronized with or federated to on-premises...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1021-007-cloud-services
- T1021.008 Direct Cloud VM Connections
An Enterprise Lateral Movement sub-technique of T1021 (Remote Services). Adversaries may leverage Valid Accounts to log directly into accessible cloud hosted compute infrastructure through cloud native methods. Many cloud providers...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1021-008-direct-cloud-vm-connections
- T1072 Software Deployment Tools
An Enterprise Execution and Lateral Movement technique. Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1072-software-deployment-tools
- T1080 Taint Shared Content
An Enterprise Lateral Movement technique. Adversaries may deliver payloads to remote systems by adding content to shared storage locations, such as network drives or internal code repositories. Content stored on network drives or in...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1080-taint-shared-content
- T1091 Replication Through Removable Media
An Enterprise Lateral Movement and Initial Access technique. Adversaries may move onto systems, possibly those on disconnected or air-gapped networks, by copying malware to removable media and taking advantage of Autorun features when...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1091-replication-through-removable-media
- T1210 Exploitation of Remote Services
An Enterprise Lateral Movement technique. Adversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network. Exploitation of a software vulnerability occurs when an adversary takes...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1210-exploitation-of-remote-services
- T1534 Internal Spearphishing
An Enterprise Lateral Movement technique. After they already have access to accounts or systems within the environment, adversaries may use internal spearphishing to gain access to additional information or compromise other users within...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1534-internal-spearphishing
- T1550 Use Alternate Authentication Material
An Enterprise Defense Evasion and Lateral Movement technique. Adversaries may use alternate authentication material, such as password hashes, Kerberos tickets, and application access tokens, in order to move laterally within an...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1550-use-alternate-authentication-material
- T1550.001 Application Access Token
An Enterprise Defense Evasion and Lateral Movement sub-technique of T1550 (Use Alternate Authentication Material). Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1550-001-application-access-token
- T1550.002 Pass the Hash
An Enterprise Defense Evasion and Lateral Movement sub-technique of T1550 (Use Alternate Authentication Material). Adversaries may "pass the hash" using stolen password hashes to move laterally within an environment, bypassing normal...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1550-002-pass-the-hash
- T1550.003 Pass the Ticket
An Enterprise Defense Evasion and Lateral Movement sub-technique of T1550 (Use Alternate Authentication Material). Adversaries may "pass the ticket" using stolen Kerberos tickets to move laterally within an environment, bypassing normal...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1550-003-pass-the-ticket
- T1550.004 Web Session Cookie
An Enterprise Defense Evasion and Lateral Movement sub-technique of T1550 (Use Alternate Authentication Material). Adversaries can use stolen session cookies to authenticate to web applications and services. This technique bypasses some...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1550-004-web-session-cookie
- T1563 Remote Service Session Hijacking
An Enterprise Lateral Movement technique. Adversaries may take control of preexisting sessions with remote services to move laterally in an environment. Users may use valid credentials to log into a service specifically designed to...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1563-remote-service-session-hijacking
- T1563.001 SSH Hijacking
An Enterprise Lateral Movement sub-technique of T1563 (Remote Service Session Hijacking). Adversaries may hijack a legitimate user's SSH session to move laterally within an environment. Secure Shell (SSH) is a standard means of remote...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1563-001-ssh-hijacking
- T1563.002 RDP Hijacking
An Enterprise Lateral Movement sub-technique of T1563 (Remote Service Session Hijacking). Adversaries may hijack a legitimate user's remote desktop session to move laterally within an environment. Remote desktop is a common feature in...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1563-002-rdp-hijacking
- T1570 Lateral Tool Transfer
Adversary transfer of tools or files between systems in a compromised environment to enable continued post-exploitation. Common methods include SMB/admin shares, RDP file transfer, WMI, BITS, certutil downloads, and PowerShell remoting....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1570-lateral-tool-transfer

[collection] Collection
- T1005 Data from Local System
Adversary collection of sensitive data from local system storage after gaining endpoint access. Living-off-the-land enumeration via find, grep, dir, type, Get-ChildItem is the dominant pattern. Compliance obligations include data...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1005-data-from-local-system
- T1025 Data from Removable Media
An Enterprise Collection technique. Adversaries may search connected removable media on computers they have compromised to find files of interest. Sensitive data can be collected from any removable media (optical disk drive, USB memory,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1025-data-from-removable-media
- T1039 Data from Network Shared Drive
An Enterprise Collection technique. Adversaries may search network shares on computers they have compromised to find files of interest. Sensitive data can be collected from remote systems via shared network drives (host shared...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1039-data-from-network-shared-drive
- T1056 Input Capture
An Enterprise Collection and Credential Access technique. Adversaries may use methods of capturing user input to obtain credentials or collect information. During normal system usage, users often provide credentials to various different...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1056-input-capture
- T1056.001 Keylogging
An Enterprise Collection and Credential Access sub-technique of T1056 (Input Capture). Adversaries may log user keystrokes to intercept credentials as the user types them. Keylogging is likely to be used to acquire credentials for new...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1056-001-keylogging
- T1056.002 GUI Input Capture
An Enterprise Collection and Credential Access sub-technique of T1056 (Input Capture). Adversaries may mimic common operating system GUI components to prompt users for credentials with a seemingly legitimate prompt. When programs are...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1056-002-gui-input-capture
- T1056.003 Web Portal Capture
An Enterprise Collection and Credential Access sub-technique of T1056 (Input Capture). Adversaries may install code on externally facing portals, such as a VPN login page, to capture and transmit credentials of users who attempt to log...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1056-003-web-portal-capture
- T1056.004 Credential API Hooking
An Enterprise Collection and Credential Access sub-technique of T1056 (Input Capture). Adversaries may hook into Windows application programming interface (API) functions to collect user credentials. Malicious hooking mechanisms may...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1056-004-credential-api-hooking
- T1074 Data Staged
An Enterprise Collection technique. Adversaries may stage collected data in a central location or directory prior to Exfiltration. Data may be kept in separate files or combined into one file through techniques such as Archive Collected...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1074-data-staged
- T1074.001 Local Data Staging
An Enterprise Collection sub-technique of T1074 (Data Staged). Adversaries may stage collected data in a central location or directory on the local system prior to Exfiltration. Data may be kept in separate files or combined into one...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1074-001-local-data-staging
- T1074.002 Remote Data Staging
An Enterprise Collection sub-technique of T1074 (Data Staged). Adversaries may stage data collected from multiple systems in a central location or directory on one system prior to Exfiltration. Data may be kept in separate files or...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1074-002-remote-data-staging
- T1113 Screen Capture
An Enterprise Collection technique. Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1113-screen-capture
- T1114 Email Collection
Adversary collection of email data through Local Email Collection (T1114.001), Remote Email Collection (T1114.002), and Email Forwarding Rule (T1114.003). Compromised mailboxes are routinely abused for BEC (Business Email Compromise),...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1114-email-collection
- T1114.001 Local Email Collection
An Enterprise Collection sub-technique of T1114 (Email Collection). Adversaries may target user email on local systems to collect sensitive information. Files containing email data can be acquired from a user's local system, such as...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1114-001-local-email-collection
- T1114.002 Remote Email Collection
An Enterprise Collection sub-technique of T1114 (Email Collection). Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information. Adversaries may leverage a user's credentials and interact...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1114-002-remote-email-collection
- T1114.003 Email Forwarding Rule
An Enterprise Collection sub-technique of T1114 (Email Collection). Adversaries may setup email forwarding rules to collect sensitive information. Adversaries may abuse email forwarding rules to monitor the activities of a victim, steal...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1114-003-email-forwarding-rule
- T1115 Clipboard Data
An Enterprise Collection technique. Adversaries may collect data stored in the clipboard from users copying information within or between applications. For example, on Windows adversaries can access clipboard data by using clip.exe or...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1115-clipboard-data
- T1119 Automated Collection
An Enterprise Collection technique. Once established within a system or network, an adversary may use automated techniques for collecting internal data. Methods for performing this technique could include use of a Command and Scripting...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1119-automated-collection
- T1123 Audio Capture
An Enterprise Collection technique. An adversary can leverage a computer's peripheral devices (e.g., microphones and webcams) or applications (e.g., voice and video call services) to capture audio recordings for the purpose of listening...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1123-audio-capture
- T1125 Video Capture
An Enterprise Collection technique. An adversary can leverage a computer's peripheral devices (e.g., integrated cameras or webcams) or applications (e.g., video call services) to capture video recordings for the purpose of gathering...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1125-video-capture
- T1185 Browser Session Hijacking
An Enterprise Collection technique. Adversaries may take advantage of security vulnerabilities and inherent functionality in browser software to change content, modify user-behaviors, and intercept information as part of various browser...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1185-browser-session-hijacking
- T1213 Data from Information Repositories
An Enterprise Collection technique. Adversaries may leverage information repositories to mine valuable information. Information repositories are tools that allow for storage of information, typically to facilitate collaboration or...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1213-data-from-information-repositories
- T1213.001 Confluence
An Enterprise Collection sub-technique of T1213 (Data from Information Repositories). Adversaries may leverage Confluence repositories to mine valuable information. Often found in development environments alongside Atlassian JIRA,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1213-001-confluence
- T1213.002 Sharepoint
An Enterprise Collection sub-technique of T1213 (Data from Information Repositories). Adversaries may leverage the SharePoint repository as a source to mine valuable information. SharePoint will often contain useful information for an...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1213-002-sharepoint
- T1213.003 Code Repositories
An Enterprise Collection sub-technique of T1213 (Data from Information Repositories). Adversaries may leverage code repositories to collect valuable information. Code repositories are tools/services that store source code and automate...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1213-003-code-repositories
- T1213.004 Customer Relationship Management Software
An Enterprise Collection sub-technique of T1213 (Data from Information Repositories). Adversaries may leverage Customer Relationship Management (CRM) software to mine valuable information. CRM software is used to assist organizations in...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1213-004-customer-relationship-management-software
- T1213.005 Messaging Applications
An Enterprise Collection sub-technique of T1213 (Data from Information Repositories). Adversaries may leverage chat and messaging applications, such as Microsoft Teams, Google Chat, and Slack, to mine valuable information. The following...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1213-005-messaging-applications
- T1213.006 Databases
An Enterprise Collection technique. Adversaries may leverage databases to mine valuable information. These databases may be hosted on-premises or in the cloud (both in platform-as-a-service and software-as-a-service environments)....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1213-006-databases
- T1530 Data from Cloud Storage
An Enterprise Collection technique. Adversaries may access data from cloud storage. Many IaaS providers offer solutions for online data object storage such as Amazon S3, Azure Storage, and Google Cloud Storage. Similarly, SaaS...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1530-data-from-cloud-storage
- T1557 Adversary-in-the-Middle
An Enterprise Credential Access and Collection technique. Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1557-adversary-in-the-middle
- T1557.001 Name Resolution Poisoning and SMB Relay
An Enterprise Credential Access and Collection sub-technique of T1557 (Adversary-in-the-Middle). By responding to LLMNR/NBT-NS network traffic, adversaries may spoof an authoritative source for name resolution to force communication...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1557-001-llmnr-nbt-ns-poisoning-and-smb-relay
- T1557.002 ARP Cache Poisoning
An Enterprise Credential Access and Collection sub-technique of T1557 (Adversary-in-the-Middle). Adversaries may poison Address Resolution Protocol (ARP) caches to position themselves between the communication of two or more networked...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1557-002-arp-cache-poisoning
- T1557.003 DHCP Spoofing
An Enterprise Credential Access and Collection sub-technique of T1557 (Adversary-in-the-Middle). Adversaries may redirect network traffic to adversary-owned systems by spoofing Dynamic Host Configuration Protocol (DHCP) traffic and...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1557-003-dhcp-spoofing
- T1557.004 Evil Twin
An Enterprise Credential Access and Collection sub-technique of T1557 (Adversary-in-the-Middle). Adversaries may host seemingly genuine Wi-Fi access points to deceive users into connecting to malicious networks as a way of supporting...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1557-004-evil-twin
- T1560 Archive Collected Data
An Enterprise Collection technique. An adversary may compress and/or encrypt data that is collected prior to exfiltration. Compressing the data can help to obfuscate the collected data and minimize the amount of data sent over the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1560-archive-collected-data
- T1560.001 Archive via Utility
An Enterprise Collection sub-technique of T1560 (Archive Collected Data). Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration. Many utilities include functionalities to compress, encrypt, or...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1560-001-archive-via-utility
- T1560.002 Archive via Library
An Enterprise Collection sub-technique of T1560 (Archive Collected Data). An adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party libraries. Many libraries exist that can archive data, including...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1560-002-archive-via-library
- T1560.003 Archive via Custom Method
An Enterprise Collection sub-technique of T1560 (Archive Collected Data). An adversary may compress or encrypt data that is collected prior to exfiltration using a custom method. Adversaries may choose to use custom archival methods,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1560-003-archive-via-custom-method
- T1602 Data from Configuration Repository
An Enterprise Collection technique. Adversaries may collect data related to managed devices from configuration repositories. Configuration repositories are used by management systems in order to configure, manage, and control data on...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1602-data-from-configuration-repository
- T1602.001 SNMP (MIB Dump)
MITRE ATT&CK T1602.001 (SNMP (MIB Dump)) is an Enterprise Collection sub-technique of T1602 (Data from Configuration Repository). Adversaries may target the Management Information Base (MIB) to collect and/or mine valuable information...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1602-001-snmp-mib-dump
- T1602.002 Network Device Configuration Dump
An Enterprise Collection sub-technique of T1602 (Data from Configuration Repository). Adversaries may access network configuration files to collect sensitive data about the device and the network. The network configuration is a file...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1602-002-network-device-configuration-dump

[command-and-control] Command and Control
- T1001 Data Obfuscation
An Enterprise Command and Control technique. Adversaries may obfuscate command and control traffic to make it more difficult to detect. Command and control (C2) communications are hidden (but not necessarily encrypted) in an attempt to...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1001-data-obfuscation
- T1001.001 Junk Data
An Enterprise Command and Control sub-technique of T1001 (Data Obfuscation). Adversaries may add junk data to protocols used for command and control to make detection more difficult. By adding random or meaningless data to the protocols...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1001-001-junk-data
- T1001.002 Steganography
An Enterprise Command and Control sub-technique of T1001 (Data Obfuscation). Adversaries may use steganographic techniques to hide command and control traffic to make detection efforts more difficult. Steganographic techniques can be...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1001-002-steganography
- T1001.003 Protocol or Service Impersonation
An Enterprise Command and Control sub-technique of T1001 (Data Obfuscation). Adversaries may impersonate legitimate protocols or web service traffic to disguise command and control activity and thwart analysis efforts. By impersonating...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1001-003-protocol-or-service-impersonation
- T1008 Fallback Channels
An Enterprise Command and Control technique. Adversaries may use fallback or alternate communication channels if the primary channel is compromised or inaccessible in order to maintain reliable command and control and to avoid data...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1008-fallback-channels
- T1071 Application Layer Protocol
Adversary use of standard application-layer protocols (HTTP/HTTPS, DNS, mail, file transfer) for command-and-control communication, blending malicious traffic with legitimate enterprise traffic. Sub-techniques include Web Protocols...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1071-application-layer-protocol
- T1071.001 Web Protocols
An Enterprise Command and Control sub-technique of T1071 (Application Layer Protocol). Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1071-001-web-protocols
- T1071.002 File Transfer Protocols
An Enterprise Command and Control sub-technique of T1071 (Application Layer Protocol). Adversaries may communicate using application layer protocols associated with transferring files to avoid detection/network filtering by blending in...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1071-002-file-transfer-protocols
- T1071.003 Mail Protocols
An Enterprise Command and Control sub-technique of T1071 (Application Layer Protocol). Adversaries may communicate using application layer protocols associated with electronic mail delivery to avoid detection/network filtering by...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1071-003-mail-protocols
- T1071.004 DNS
An Enterprise Command and Control sub-technique of T1071 (Application Layer Protocol). Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1071-004-dns
- T1071.005 Publish/Subscribe Protocols
An Enterprise Command and Control sub-technique of T1071 (Application Layer Protocol). Adversaries may communicate using publish/subscribe (pub/sub) application layer protocols to avoid detection/network filtering by blending in with...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1071-005-publish-subscribe-protocols
- T1090 Proxy
Adversary use of proxy infrastructure (Internal Proxy T1090.001, External Proxy T1090.002, Multi-hop Proxy T1090.003 including Tor, Domain Fronting T1090.004) to obfuscate C2 traffic origin. APT29, Cobalt Strike, Sliver, and most...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1090-proxy
- T1090.001 Internal Proxy
An Enterprise Command and Control sub-technique of T1090 (Proxy). Adversaries may use an internal proxy to direct command and control traffic between two or more systems in a compromised environment. Many tools exist that enable traffic...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1090-001-internal-proxy
- T1090.002 External Proxy
An Enterprise Command and Control sub-technique of T1090 (Proxy). Adversaries may use an external proxy to act as an intermediary for network communications to a command and control server to avoid direct connections to their...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1090-002-external-proxy
- T1090.003 Multi-hop Proxy
An Enterprise Command and Control sub-technique of T1090 (Proxy). Adversaries may chain together multiple proxies to disguise the source of malicious traffic. Typically, a defender will be able to identify the last proxy traffic...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1090-003-multi-hop-proxy
- T1090.004 Domain Fronting
An Enterprise Command and Control sub-technique of T1090 (Proxy). Adversaries may take advantage of routing schemes in Content Delivery Networks (CDNs) and other services which host multiple domains to obfuscate the intended destination...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1090-004-domain-fronting
- T1092 Communication Through Removable Media
An Enterprise Command and Control technique. Adversaries can perform command and control between compromised hosts on potentially disconnected networks using removable media to transfer commands from system to system. Both systems would...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1092-communication-through-removable-media
- T1095 Non-Application Layer Protocol
An Enterprise Command and Control technique. Adversaries may use an OSI non-application layer protocol for communication between host and C2 server or among infected hosts within a network. The list of possible protocols is extensive....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1095-non-application-layer-protocol
- T1102 Web Service
Adversary abuse of legitimate web services (GitHub, Pastebin, Discord, Dropbox, Telegram, Slack, X/Twitter, GitHub Gist) for command-and-control communication, blending malicious traffic with legitimate enterprise SaaS use....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1102-web-service
- T1102.001 Dead Drop Resolver
An Enterprise Command and Control sub-technique of T1102 (Web Service). Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure. Adversaries...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1102-001-dead-drop-resolver
- T1102.002 Bidirectional Communication
An Enterprise Command and Control sub-technique of T1102 (Web Service). Adversaries may use an existing, legitimate external Web service as a means for sending commands to and receiving output from a compromised system over the Web...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1102-002-bidirectional-communication
- T1102.003 One-Way Communication
An Enterprise Command and Control sub-technique of T1102 (Web Service). Adversaries may use an existing, legitimate external Web service as a means for sending commands to a compromised system without receiving return output over the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1102-003-one-way-communication
- T1104 Multi-Stage Channels
An Enterprise Command and Control technique. Adversaries may create multiple stages for command and control that are employed under different conditions or for certain functions. Use of multiple stages may obfuscate the command and...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1104-multi-stage-channels
- T1105 Ingress Tool Transfer
An Enterprise Command and Control technique. Adversaries may transfer tools or other files from an external system into a compromised environment. Tools or files may be copied from an external adversary-controlled system to the victim...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1105-ingress-tool-transfer
- T1132 Data Encoding
An Enterprise Command and Control technique. Adversaries may encode data to make the content of command and control traffic more difficult to detect. Command and control (C2) information can be encoded using a standard data encoding...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1132-data-encoding
- T1132.001 Standard Encoding
An Enterprise Command and Control sub-technique of T1132 (Data Encoding). Adversaries may encode data with a standard data encoding system to make the content of command and control traffic more difficult to detect. Command and control...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1132-001-standard-encoding
- T1132.002 Non-Standard Encoding
An Enterprise Command and Control sub-technique of T1132 (Data Encoding). Adversaries may encode data with a non-standard data encoding system to make the content of command and control traffic more difficult to detect. Command and...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1132-002-non-standard-encoding
- T1205 Traffic Signaling
An Enterprise Defense Evasion and Persistence and Command and Control technique. Adversaries may use traffic signaling to hide open ports or other malicious functionality used for persistence or command and control. Traffic signaling...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1205-traffic-signaling
- T1205.001 Port Knocking
An Enterprise Defense Evasion and Persistence and Command and Control sub-technique of T1205 (Traffic Signaling). Adversaries may use port knocking to hide open ports used for persistence or command and control. To enable a port, an...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1205-001-port-knocking
- T1205.002 Socket Filters
An Enterprise Defense Evasion and Persistence and Command and Control sub-technique of T1205 (Traffic Signaling). Adversaries may attach filters to a network socket to monitor then activate backdoors used for persistence or command and...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1205-002-socket-filters
- T1219 Remote Access Tools
An Enterprise Command and Control technique. An adversary may use legitimate desktop support and remote access software to establish an interactive command and control channel to target systems within networks. These services, such as...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1219-remote-access-software
- T1219.001 IDE Tunneling
An Enterprise Command and Control technique. Adversaries may abuse Integrated Development Environment (IDE) software with remote development features to establish an interactive command and control channel on target systems within a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1219-001-ide-tunneling
- T1219.002 Remote Desktop Software
An Enterprise Command and Control technique. An adversary may use legitimate desktop support software to establish an interactive command and control channel to target systems within networks. Desktop support software provides a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1219-002-remote-desktop-software
- T1219.003 Remote Access Hardware
An Enterprise Command and Control technique. An adversary may use legitimate remote access hardware to establish an interactive command and control channel to target systems within networks. These services, including IP-based keyboard,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1219-003-remote-access-hardware
- T1568 Dynamic Resolution
An Enterprise Command and Control technique. Adversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations. This may be achieved by using malware that shares a common...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1568-dynamic-resolution
- T1568.001 Fast Flux DNS
An Enterprise Command and Control sub-technique of T1568 (Dynamic Resolution). Adversaries may use Fast Flux DNS to hide a command and control channel behind an array of rapidly changing IP addresses linked to a single domain...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1568-001-fast-flux-dns
- T1568.002 Domain Generation Algorithms
An Enterprise Command and Control sub-technique of T1568 (Dynamic Resolution). Adversaries may make use of Domain Generation Algorithms (DGAs) to dynamically identify a destination domain for command and control traffic rather than...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1568-002-domain-generation-algorithms
- T1568.003 DNS Calculation
An Enterprise Command and Control sub-technique of T1568 (Dynamic Resolution). Adversaries may perform calculations on addresses returned in DNS results to determine which port and IP address to use for command and control, rather than...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1568-003-dns-calculation
- T1571 Non-Standard Port
An Enterprise Command and Control technique. Adversaries may communicate using a protocol and port pairing that are typically not associated. For example, HTTPS over port 8088 or port 587 as opposed to the traditional port 443....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1571-non-standard-port
- T1572 Protocol Tunneling
Adversary tunneling of one protocol inside another to evade network controls. SSH tunneling for SOCKS proxy, HTTP/HTTPS tunneling for arbitrary TCP, DNS tunneling (iodine, dns2tcp, dnscat2), ICMP tunneling, and WireGuard abuse are the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1572-protocol-tunneling
- T1573 Encrypted Channel
Adversary use of symmetric or asymmetric encryption for command-and-control communication to evade network inspection. Sub-techniques: Symmetric Cryptography (T1573.001), Asymmetric Cryptography (T1573.002). TLS-wrapped C2 dominates in...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1573-encrypted-channel
- T1573.001 Symmetric Cryptography
An Enterprise Command and Control sub-technique of T1573 (Encrypted Channel). Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1573-001-symmetric-cryptography
- T1573.002 Asymmetric Cryptography
An Enterprise Command and Control sub-technique of T1573 (Encrypted Channel). Adversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1573-002-asymmetric-cryptography
- T1659 Content Injection
An Enterprise Initial Access and Command and Control technique. Adversaries may gain access and continuously communicate with victims by injecting malicious content into systems through online network traffic. Rather than luring victims...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1659-content-injection
- T1665 Hide Infrastructure
An Enterprise Command and Control technique. Adversaries may manipulate network traffic in order to hide and evade detection of their C2 infrastructure. This can be accomplished in various ways including by identifying and filtering...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1665-hide-infrastructure

[exfiltration] Exfiltration
- T1011 Exfiltration Over Other Network Medium
An Enterprise Exfiltration technique. Adversaries may attempt to exfiltrate data over a different network medium than the command and control channel. If the command and control network is a wired Internet connection, the exfiltration...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1011-exfiltration-over-other-network-medium
- T1011.001 Exfiltration Over Bluetooth
An Enterprise Exfiltration sub-technique of T1011 (Exfiltration Over Other Network Medium). Adversaries may attempt to exfiltrate data over Bluetooth rather than the command and control channel. If the command and control network is a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1011-001-exfiltration-over-bluetooth
- T1020 Automated Exfiltration
An Enterprise Exfiltration technique. Adversaries may exfiltrate data, such as sensitive documents, through the use of automated processing after being gathered during Collection. When automated exfiltration is used, other exfiltration...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1020-automated-exfiltration
- T1020.001 Traffic Duplication
An Enterprise Exfiltration sub-technique of T1020 (Automated Exfiltration). Adversaries may leverage traffic mirroring in order to automate data exfiltration over compromised infrastructure. Traffic mirroring is a native feature for...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1020-001-traffic-duplication
- T1029 Scheduled Transfer
An Enterprise Exfiltration technique. Adversaries may schedule data exfiltration to be performed only at certain times of day or at certain intervals. This could be done to blend traffic patterns with normal activity or availability....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1029-scheduled-transfer
- T1030 Data Transfer Size Limits
An Enterprise Exfiltration technique. An adversary may exfiltrate data in fixed size chunks instead of whole files or limit packet sizes below certain thresholds. This approach may be used to avoid triggering network data transfer...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1030-data-transfer-size-limits
- T1041 Exfiltration Over C2 Channel
Adversary exfiltration of stolen data over the same command-and-control channel used for adversary communication, blending data theft with normal C2 traffic. This is the dominant exfiltration pattern in modern ransomware...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1041-exfiltration-over-c2-channel
- T1048 Exfiltration Over Alternative Protocol
An Enterprise Exfiltration technique. Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel. The data may also be sent to an alternate network location from the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1048-exfiltration-over-alternative-protocol
- T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol
An Enterprise Exfiltration sub-technique of T1048 (Exfiltration Over Alternative Protocol). Adversaries may steal data by exfiltrating it over a symmetrically encrypted network protocol other than that of the existing command and...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1048-001-exfiltration-over-symmetric-encrypted-non-c2-protocol
- T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
An Enterprise Exfiltration sub-technique of T1048 (Exfiltration Over Alternative Protocol). Adversaries may steal data by exfiltrating it over an asymmetrically encrypted network protocol other than that of the existing command and...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1048-002-exfiltration-over-asymmetric-encrypted-non-c2-protocol
- T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
An Enterprise Exfiltration sub-technique of T1048 (Exfiltration Over Alternative Protocol). Adversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1048-003-exfiltration-over-unencrypted-non-c2-protocol
- T1052 Exfiltration Over Physical Medium
An Enterprise Exfiltration technique. Adversaries may attempt to exfiltrate data via a physical medium, such as a removable drive. In certain circumstances, such as an air-gapped network compromise, exfiltration could occur via a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1052-exfiltration-over-physical-medium
- T1052.001 Exfiltration over USB
An Enterprise Exfiltration sub-technique of T1052 (Exfiltration Over Physical Medium). Adversaries may attempt to exfiltrate data over a USB connected physical device. In certain circumstances, such as an air-gapped network compromise,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1052-001-exfiltration-over-usb
- T1537 Transfer Data to Cloud Account
An Enterprise Exfiltration technique. Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service. A...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1537-transfer-data-to-cloud-account
- T1567 Exfiltration Over Web Service
Adversary exfiltration of stolen data via legitimate web services (cloud storage, code-sharing sites, paste sites) to blend with normal SaaS use. Sub-techniques: Exfiltration to Code Repository (T1567.001), Exfiltration to Cloud Storage...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1567-exfiltration-over-web-service
- T1567.001 Exfiltration to Code Repository
An Enterprise Exfiltration sub-technique of T1567 (Exfiltration Over Web Service). Adversaries may exfiltrate data to a code repository rather than over their primary command and control channel. Code repositories are often accessible...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1567-001-exfiltration-to-code-repository
- T1567.002 Exfiltration to Cloud Storage
An Enterprise Exfiltration sub-technique of T1567 (Exfiltration Over Web Service). Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel. Cloud storage services allow for...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1567-002-exfiltration-to-cloud-storage
- T1567.003 Exfiltration to Text Storage Sites
An Enterprise Exfiltration sub-technique of T1567 (Exfiltration Over Web Service). Adversaries may exfiltrate data to text storage sites instead of their primary command and control channel. Text storage sites, such as pastebin[.]com,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1567-003-exfiltration-to-text-storage-sites
- T1567.004 Exfiltration Over Webhook
An Enterprise Exfiltration sub-technique of T1567 (Exfiltration Over Web Service). Adversaries may exfiltrate data to a webhook endpoint rather than over their primary command and control channel. Webhooks are simple mechanisms for...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1567-004-exfiltration-over-webhook

[impact] Impact
- T1485 Data Destruction
Adversary destruction of victim data and systems through wiper malware, secure deletion, or storage corruption to disrupt operations or destroy evidence. Notable wiper campaigns include NotPetya (2017, USD 10B+ damages), WhisperGate...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1485-data-destruction
- T1485.001 Lifecycle-Triggered Deletion
An Enterprise Impact sub-technique of T1485 (Data Destruction). Adversaries may modify the lifecycle policies of a cloud storage bucket to destroy all objects stored within. Cloud storage buckets often allow users to set lifecycle...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1485-001-lifecycle-triggered-deletion
- T1486 Data Encrypted for Impact
Adversary encryption of victim data and demand for ransom, the canonical ransomware behaviour responsible for the majority of catastrophic enterprise cyber incidents. LockBit, BlackCat/ALPHV, Cl0p, Akira, and Royal remain the dominant...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1486-data-encrypted-for-impact
- T1489 Service Stop
An Enterprise Impact technique. Adversaries may stop or disable services on a system to render those services unavailable to legitimate users. Stopping critical services or processes can inhibit or stop response to an incident or aid in...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1489-service-stop
- T1490 Inhibit System Recovery
An Enterprise Impact technique. Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery. This may deny access to available backups and recovery...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1490-inhibit-system-recovery
- T1491 Defacement
An Enterprise Impact technique. Adversaries may modify visual content available internally or externally to an enterprise network, thus affecting the integrity of the original content. Reasons for Defacement include delivering...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1491-defacement
- T1491.001 Internal Defacement
An Enterprise Impact sub-technique of T1491 (Defacement). An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems. This may take the form...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1491-001-internal-defacement
- T1491.002 External Defacement
An Enterprise Impact sub-technique of T1491 (Defacement). An adversary may deface systems external to an organization in an attempt to deliver messaging, intimidate, or otherwise mislead an organization or users. External Defacement may...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1491-002-external-defacement
- T1495 Firmware Corruption
An Enterprise Impact technique. Adversaries may overwrite or corrupt the flash memory contents of system BIOS or other firmware in devices attached to a system in order to render them inoperable or unable to boot, thus denying the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1495-firmware-corruption
- T1496 Resource Hijacking
An Enterprise Impact technique. Adversaries may leverage the resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability. Resource hijacking may take a number of...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1496-resource-hijacking
- T1496.001 Compute Hijacking
An Enterprise Impact sub-technique of T1496 (Resource Hijacking). Adversaries may leverage the compute resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability. One...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1496-001-compute-hijacking
- T1496.002 Bandwidth Hijacking
An Enterprise Impact sub-technique of T1496 (Resource Hijacking). Adversaries may leverage the network bandwidth resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1496-002-bandwidth-hijacking
- T1496.003 SMS Pumping
An Enterprise Impact sub-technique of T1496 (Resource Hijacking). Adversaries may leverage messaging services for SMS pumping, which may impact system and/or hosted service availability. SMS pumping is a type of telecommunications fraud...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1496-003-sms-pumping
- T1496.004 Cloud Service Hijacking
An Enterprise Impact sub-technique of T1496 (Resource Hijacking). Adversaries may leverage compromised software-as-a-service (SaaS) applications to complete resource-intensive tasks, which may impact hosted service availability. For...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1496-004-cloud-service-hijacking
- T1498 Network Denial of Service
An Enterprise Impact technique. Adversaries may perform Network Denial of Service (DoS) attacks to degrade or block the availability of targeted resources to users. Network DoS can be performed by exhausting the network bandwidth...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1498-network-denial-of-service
- T1498.001 Direct Network Flood
An Enterprise Impact sub-technique of T1498 (Network Denial of Service). Adversaries may attempt to cause a denial of service (DoS) by directly sending a high-volume of network traffic to a target. This DoS attack may also reduce the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1498-001-direct-network-flood
- T1498.002 Reflection Amplification
An Enterprise Impact sub-technique of T1498 (Network Denial of Service). Adversaries may attempt to cause a denial of service (DoS) by reflecting a high-volume of network traffic to a target. This type of Network DoS takes advantage of...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1498-002-reflection-amplification
- T1499 Endpoint Denial of Service
Adversary denial-of-service attacks targeting endpoint resources to make services unavailable. Sub-techniques include OS Exhaustion Flood (T1499.001), Service Exhaustion Flood (T1499.002), Application Exhaustion Flood (T1499.003), and...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1499-endpoint-denial-of-service
- T1499.001 OS Exhaustion Flood
An Enterprise Impact sub-technique of T1499 (Endpoint Denial of Service). Adversaries may launch a denial of service (DoS) attack targeting an endpoint's operating system (OS). A system's OS is responsible for managing the finite...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1499-001-os-exhaustion-flood
- T1499.002 Service Exhaustion Flood
An Enterprise Impact sub-technique of T1499 (Endpoint Denial of Service). Adversaries may target the different network services provided by systems to conduct a denial of service (DoS). Adversaries often target the availability of DNS...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1499-002-service-exhaustion-flood
- T1499.003 Application Exhaustion Flood
An Enterprise Impact sub-technique of T1499 (Endpoint Denial of Service). Adversaries may target resource intensive features of applications to cause a denial of service (DoS), denying availability to those applications. For example,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1499-003-application-exhaustion-flood
- T1499.004 Application or System Exploitation
An Enterprise Impact sub-technique of T1499 (Endpoint Denial of Service). Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users. Some systems may automatically...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1499-004-application-or-system-exploitation
- T1529 System Shutdown/Reboot
An Enterprise Impact technique. Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems. Operating systems may contain commands to initiate a shutdown/reboot of a machine or network...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1529-system-shutdown-reboot
- T1531 Account Access Removal
An Enterprise Impact technique. Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1531-account-access-removal
- T1561 Disk Wipe
An Enterprise Impact technique. Adversaries may wipe or corrupt raw disk data on specific systems or in large numbers in a network to interrupt availability to system and network resources. With direct write access to a disk,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1561-disk-wipe
- T1561.001 Disk Content Wipe
An Enterprise Impact sub-technique of T1561 (Disk Wipe). Adversaries may erase the contents of storage devices on specific systems or in large numbers in a network to interrupt availability to system and network resources. Adversaries...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1561-001-disk-content-wipe
- T1561.002 Disk Structure Wipe
An Enterprise Impact sub-technique of T1561 (Disk Wipe). Adversaries may corrupt or wipe the disk data structures on a hard drive necessary to boot a system; targeting specific critical systems or in large numbers in a network to...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1561-002-disk-structure-wipe
- T1565 Data Manipulation
An Enterprise Impact technique. Adversaries may insert, delete, or manipulate data in order to influence external outcomes or hide activity, thus threatening the integrity of the data. By manipulating data, adversaries may attempt to...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1565-data-manipulation
- T1565.001 Stored Data Manipulation
An Enterprise Impact sub-technique of T1565 (Data Manipulation). Adversaries may insert, delete, or manipulate data at rest in order to influence external outcomes or hide activity, thus threatening the integrity of the data. By...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1565-001-stored-data-manipulation
- T1565.002 Transmitted Data Manipulation
An Enterprise Impact sub-technique of T1565 (Data Manipulation). Adversaries may alter data en route to storage or other systems in order to manipulate external outcomes or hide activity, thus threatening the integrity of the data. By...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1565-002-transmitted-data-manipulation
- T1565.003 Runtime Data Manipulation
An Enterprise Impact sub-technique of T1565 (Data Manipulation). Adversaries may modify systems in order to manipulate the data as it is accessed and displayed to an end user, thus threatening the integrity of the data. By manipulating...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1565-003-runtime-data-manipulation
- T1657 Financial Theft
An Enterprise Impact technique. Adversaries may steal monetary resources from targets through extortion, social engineering, technical theft, or other methods aimed at their own financial gain at the expense of the availability of these...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1657-financial-theft
- T1667 Email Bombing
An Enterprise Impact technique. Adversaries may flood targeted email addresses with an overwhelming volume of messages. This may bury legitimate emails in a flood of spam and disrupt business operations. An adversary may accomplish...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1667-email-bombing

[stealth] Stealth
- T1006 Direct Volume Access
An Enterprise Defense Evasion technique. Adversaries may directly access a volume to bypass file access controls and file system monitoring. Windows allows programs to have direct access to logical volumes. Programs with direct access...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1006-direct-volume-access
- T1014 Rootkit
An Enterprise Defense Evasion technique. Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components. Rootkits are programs that hide the existence of malware...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1014-rootkit
- T1027 Obfuscated Files or Information
Adversary use of obfuscation, encoding, encryption, and packing to evade detection. Sub-techniques include Binary Padding (T1027.001), Software Packing (T1027.002), Steganography (T1027.003), Compile After Delivery (T1027.004),...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1027-obfuscated-files-information
- T1027.001 Binary Padding
An Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may use binary padding to add junk data and change the on-disk representation of malware. This can be done without affecting the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1027-001-binary-padding
- T1027.002 Software Packing
An Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may perform software packing or virtual machine software protection to conceal their code. Software packing is a method of compressing...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1027-002-software-packing
- T1027.003 Steganography
An Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may use steganography techniques in order to prevent the detection of hidden information. Steganographic techniques can be used to hide...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1027-003-steganography
- T1027.004 Compile After Delivery
An Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may attempt to make payloads difficult to discover and analyze by delivering files to victims as uncompiled code. Text-based source code...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1027-004-compile-after-delivery
- T1027.005 Indicator Removal from Tools
An Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may remove indicators from tools if they believe their malicious tool was detected, quarantined, or otherwise curtailed. They can modify...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1027-005-indicator-removal-from-tools
- T1027.006 HTML Smuggling
An Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign HTML files. HTML documents can...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1027-006-html-smuggling
- T1027.007 Dynamic API Resolution
An Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may obfuscate then dynamically resolve API functions called by their malware in order to conceal malicious functionalities and impair...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1027-007-dynamic-api-resolution
- T1027.008 Stripped Payloads
An Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may attempt to make a payload difficult to analyze by removing symbols, strings, and other human readable information. Scripts and...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1027-008-stripped-payloads
- T1027.009 Embedded Payloads
An Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may embed payloads within other files to conceal malicious content from defenses. Otherwise seemingly benign files (such as scripts and...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1027-009-embedded-payloads
- T1027.010 Command Obfuscation
An Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may obfuscate content during command execution to impede detection. Command-line obfuscation is a method of making strings and patterns...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1027-010-command-obfuscation
- T1027.011 Fileless Storage
An Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may store data in "fileless" formats to conceal malicious activity from defenses. Fileless storage can be broadly defined as any format...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1027-011-fileless-storage
- T1027.012 LNK Icon Smuggling
An Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may smuggle commands to download malicious payloads past content filters by hiding them within otherwise seemingly benign windows...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1027-012-lnk-icon-smuggling
- T1027.013 Encrypted/Encoded File
An Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection. Encrypting and/or encoding...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1027-013-encrypted-encoded-file
- T1027.014 Polymorphic Code
An Enterprise Defense Evasion sub-technique of T1027 (Obfuscated Files or Information). Adversaries may utilize polymorphic code (also known as metamorphic or mutating code) to evade detection. Polymorphic code is a type of software...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1027-014-polymorphic-code
- T1027.015 Compression
An Enterprise Stealth technique. Adversaries may use compression to obfuscate their payloads or files. Compressed file formats such as ZIP, gzip, 7z, and RAR can compress and archive multiple files together to make it easier and faster...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1027-015-compression
- T1027.016 Junk Code Insertion
An Enterprise Stealth technique. Adversaries may use junk code / dead code to obfuscate a malware’s functionality. Junk code is code that either does not execute, or if it does execute, does not change the functionality of the code....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1027-016-junk-code-insertion
- T1027.017 SVG Smuggling
An Enterprise Stealth technique. Adversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign SVG files. SVGs, or Scalable Vector Graphics, are vector-based image files constructed...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1027-017-svg-smuggling
- T1027.018 Invisible Unicode
An Enterprise Stealth technique. Adversaries may abuse invisible or non-printing Unicode characters to conceal malicious content within files, scripts, or text. By inserting characters that do not visibly render, adversaries may hide...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1027-018-invisible-unicode
- T1036 Masquerading
An Enterprise Defense Evasion technique. Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools. Masquerading occurs when the name or location of an...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1036-masquerading
- T1036.001 Invalid Code Signature
An Enterprise Defense Evasion sub-technique of T1036 (Masquerading). Adversaries may attempt to mimic features of valid code signatures to increase the chance of deceiving a user, analyst, or tool. Code signing provides a level of...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1036-001-invalid-code-signature
- T1036.002 Right-to-Left Override
An Enterprise Defense Evasion sub-technique of T1036 (Masquerading). Adversaries may abuse the right-to-left override (RTLO or RLO) character (U+202E) to disguise a string and/or file name to make it appear benign. RTLO is a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1036-002-right-to-left-override
- T1036.003 Rename Legitimate Utilities
An Enterprise Defense Evasion sub-technique of T1036 (Masquerading). Adversaries may rename legitimate system utilities to try to evade security mechanisms concerning the usage of those utilities. Security monitoring and control...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1036-003-rename-system-utilities
- T1036.004 Masquerade Task or Service
An Enterprise Defense Evasion sub-technique of T1036 (Masquerading). Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign. Tasks/services executed by the Task Scheduler or systemd...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1036-004-masquerade-task-or-service
- T1036.005 Match Legitimate Resource Name or Location
An Enterprise Defense Evasion sub-technique of T1036 (Masquerading). Adversaries may match or approximate the name or location of legitimate files or resources when naming/placing them. This is done for the sake of evading defenses and...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1036-005-match-legitimate-name-or-location
- T1036.006 Space after Filename
An Enterprise Defense Evasion sub-technique of T1036 (Masquerading). Adversaries can hide a program's true filetype by changing the extension of a file. With certain file types (specifically this does not work with .app extensions),...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1036-006-space-after-filename
- T1036.007 Double File Extension
An Enterprise Defense Evasion sub-technique of T1036 (Masquerading). Adversaries may abuse a double extension in the filename as a means of masquerading the true file type. A file name may include a secondary file type extension that...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1036-007-double-file-extension
- T1036.008 Masquerade File Type
An Enterprise Defense Evasion sub-technique of T1036 (Masquerading). Adversaries may masquerade malicious payloads as legitimate files through changes to the payload's formatting, including the file's signature, extension, and contents....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1036-008-masquerade-file-type
- T1036.009 Break Process Trees
An Enterprise Defense Evasion sub-technique of T1036 (Masquerading). An adversary may attempt to evade process tree-based analysis by modifying executed malware's parent process ID (PPID). If endpoint protection software leverages the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1036-009-break-process-trees
- T1036.010 Masquerade Account Name
An Enterprise Defense Evasion sub-technique of T1036 (Masquerading). Adversaries may match or approximate the names of legitimate accounts to make newly created ones appear benign. This will typically occur during Create Account,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1036-010-masquerade-account-name
- T1036.011 Overwrite Process Arguments
An Enterprise Stealth technique. Adversaries may modify a process's in-memory arguments to change its name in order to appear as a legitimate or benign process. On Linux, the operating system stores command-line arguments in the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1036-011-overwrite-process-arguments
- T1036.012 Browser Fingerprint
An Enterprise Stealth technique. Adversaries may attempt to blend in with legitimate traffic by spoofing browser and system attributes like operating system, system language, platform, user-agent string, resolution, time zone, etc. The...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1036-012-browser-fingerprint
- T1055 Process Injection
An Enterprise Defense Evasion and Privilege Escalation technique. Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges. Process injection is a method of executing...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1055-process-injection
- T1055.001 Dynamic-link Library Injection
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject dynamic-link libraries (DLLs) into processes in order to evade process-based defenses as well as possibly elevate...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1055-001-dynamic-link-library-injection
- T1055.002 Portable Executable Injection
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject portable executables (PE) into processes in order to evade process-based defenses as well as possibly elevate...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1055-002-portable-executable-injection
- T1055.003 Thread Execution Hijacking
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into hijacked processes in order to evade process-based defenses as well as possibly elevate...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1055-003-thread-execution-hijacking
- T1055.004 Asynchronous Procedure Call
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into processes via the asynchronous procedure call (APC) queue in order to evade process-based...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1055-004-asynchronous-procedure-call
- T1055.005 Thread Local Storage
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into processes via thread local storage (TLS) callbacks in order to evade process-based defenses as...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1055-005-thread-local-storage
- T1055.008 Ptrace System Calls
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into processes via ptrace (process trace) system calls in order to evade process-based defenses as...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1055-008-ptrace-system-calls
- T1055.009 Proc Memory
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into processes via the /proc filesystem in order to evade process-based defenses as well as...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1055-009-proc-memory
- T1055.011 Extra Window Memory Injection
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into process via Extra Window Memory (EWM) in order to evade process-based defenses as well as...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1055-011-extra-window-memory-injection
- T1055.012 Process Hollowing
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses. Process hollowing...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1055-012-process-hollowing
- T1055.013 Process Doppelgänging
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into process via process doppelgänging in order to evade process-based defenses as well as possibly...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1055-013-process-doppelg-nging
- T1055.014 VDSO Hijacking
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may inject malicious code into processes via VDSO hijacking in order to evade process-based defenses as well as possibly...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1055-014-vdso-hijacking
- T1055.015 ListPlanting
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1055 (Process Injection). Adversaries may abuse list-view controls to inject malicious code into hijacked processes in order to evade process-based defenses as...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1055-015-listplanting
- T1070 Indicator Removal
Adversary deletion or modification of artifacts generated by intrusion activity to evade detection and impede investigation. Sub-techniques include Clear Windows Event Logs (T1070.001), Clear Linux/macOS Logs (T1070.002), Clear Command...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1070-indicator-removal
- T1070.001 Clear Windows Event Logs
An Enterprise Defense Evasion sub-technique of T1070 (Indicator Removal). Adversaries may clear Windows Event Logs to hide the activity of an intrusion. Windows Event Logs are a record of a computer's alerts and notifications. There are...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1070-001-clear-windows-event-logs
- T1070.002 Clear Linux or Mac System Logs
An Enterprise Defense Evasion sub-technique of T1070 (Indicator Removal). Adversaries may clear system logs to hide evidence of an intrusion. macOS and Linux both keep track of system or user-initiated actions via system logs. The...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1070-002-clear-linux-or-mac-system-logs
- T1070.003 Clear Command History
An Enterprise Defense Evasion sub-technique of T1070 (Indicator Removal). In addition to clearing system logs, an adversary may clear the command history of a compromised account to conceal the actions undertaken during an intrusion....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1070-003-clear-command-history
- T1070.004 File Deletion
An Enterprise Defense Evasion sub-technique of T1070 (Indicator Removal). Adversaries may delete files left behind by the actions of their intrusion activity. Malware, tools, or other non-native files dropped or created on a system by...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1070-004-file-deletion
- T1070.005 Network Share Connection Removal
An Enterprise Defense Evasion sub-technique of T1070 (Indicator Removal). Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation. Windows shared drive and SMB/Windows Admin...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1070-005-network-share-connection-removal
- T1070.006 Timestomp
An Enterprise Defense Evasion sub-technique of T1070 (Indicator Removal). Adversaries may modify file time attributes to hide new files or changes to existing files. Timestomping is a technique that modifies the timestamps of a file...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1070-006-timestomp
- T1070.007 Clear Network Connection History and Configurations
An Enterprise Defense Evasion sub-technique of T1070 (Indicator Removal). Adversaries may clear or remove evidence of malicious network connections in order to clean up traces of their operations. Configuration settings as well as...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1070-007-clear-network-connection-history-and-configurations
- T1070.008 Clear Mailbox Data
An Enterprise Defense Evasion sub-technique of T1070 (Indicator Removal). Adversaries may modify mail and mail application data to remove evidence of their activity. Email applications allow users and other programs to export and delete...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1070-008-clear-mailbox-data
- T1070.009 Clear Persistence
An Enterprise Defense Evasion sub-technique of T1070 (Indicator Removal). Adversaries may clear artifacts associated with previously established persistence on a host system to remove evidence of their activity. This may involve various...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1070-009-clear-persistence
- T1070.010 Relocate Malware
An Enterprise Defense Evasion sub-technique of T1070 (Indicator Removal). Once a payload is delivered, adversaries may reproduce copies of the same malware on the victim system to remove evidence of their presence and/or avoid defenses....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1070-010-relocate-malware
- T1078 Valid Accounts
Adversary use of compromised credentials for initial access, persistence, privilege escalation, and defense evasion. Sub-techniques cover Default Accounts (T1078.001), Domain Accounts (T1078.002), Local Accounts (T1078.003), and Cloud...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1078-valid-accounts
- T1078.001 Default Accounts
An Enterprise Defense Evasion and Persistence and Privilege Escalation and Initial Access sub-technique of T1078 (Valid Accounts). Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1078-001-default-accounts
- T1078.002 Domain Accounts
An Enterprise Defense Evasion and Persistence and Privilege Escalation and Initial Access sub-technique of T1078 (Valid Accounts). Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1078-002-domain-accounts
- T1078.003 Local Accounts
An Enterprise Defense Evasion and Persistence and Privilege Escalation and Initial Access sub-technique of T1078 (Valid Accounts). Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1078-003-local-accounts
- T1078.004 Cloud Accounts
Adversary use of legitimate cloud account credentials (Microsoft Entra ID / Azure AD, AWS IAM, Google Workspace, GCP, Okta, Salesforce) to gain initial access, maintain persistence, escalate privileges, and evade detection. Cloud...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1078-004-cloud-accounts
- T1127 Trusted Developer Utilities Proxy Execution
An Enterprise Defense Evasion technique. Adversaries may take advantage of trusted developer utilities to proxy execution of malicious payloads. There are many utilities used for software development related tasks that can be used to...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1127-trusted-developer-utilities-proxy-execution
- T1127.001 MSBuild
An Enterprise Defense Evasion sub-technique of T1127 (Trusted Developer Utilities Proxy Execution). Adversaries may use MSBuild to proxy execution of code through a trusted Windows utility. MSBuild.exe (Microsoft Build Engine) is a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1127-001-msbuild
- T1127.002 ClickOnce
An Enterprise Defense Evasion sub-technique of T1127 (Trusted Developer Utilities Proxy Execution). Adversaries may use ClickOnce applications (.appref-ms and .application files) to proxy execution of code through a trusted Windows...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1127-002-clickonce
- T1127.003 JamPlus
An Enterprise Stealth, Execution technique. Adversaries may use `JamPlus` to proxy the execution of a malicious script. `JamPlus` is a build utility tool for code and data build systems. It works with several popular compilers and can...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1127-003-jamplus
- T1134 Access Token Manipulation
An Enterprise Defense Evasion and Privilege Escalation technique. Adversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls. Windows uses access...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1134-access-token-manipulation
- T1134.001 Token Impersonation/Theft
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1134 (Access Token Manipulation). Adversaries may duplicate then impersonate another user's existing token to escalate privileges and bypass access controls. For...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1134-001-token-impersonation-theft
- T1134.002 Create Process with Token
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1134 (Access Token Manipulation). Adversaries may create a new process with an existing token to escalate privileges and bypass access controls. Processes can be...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1134-002-create-process-with-token
- T1134.003 Make and Impersonate Token
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1134 (Access Token Manipulation). Adversaries may make new tokens and impersonate users to escalate privileges and bypass access controls. For example, if an...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1134-003-make-and-impersonate-token
- T1134.004 Parent PID Spoofing
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1134 (Access Token Manipulation). Adversaries may spoof the parent process identifier (PPID) of a new process to evade process-monitoring defenses or to elevate...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1134-004-parent-pid-spoofing
- T1134.005 SID-History Injection
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1134 (Access Token Manipulation). Adversaries may use SID-History Injection to escalate privileges and bypass access controls. The Windows security identifier...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1134-005-sid-history-injection
- T1140 Deobfuscate/Decode Files or Information
Adversary actions to reverse obfuscation or encoding applied to payloads after delivery to enable execution. Common patterns include base64 decoding, certutil decoding, PowerShell encoded-command unwrapping, and custom decryption...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1140-deobfuscate-decode-files
- T1197 BITS Jobs
An Enterprise Defense Evasion and Persistence technique. Adversaries may abuse BITS jobs to persistently execute code and perform various background tasks. Windows Background Intelligent Transfer Service (BITS) is a low-bandwidth,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1197-bits-jobs
- T1202 Indirect Command Execution
An Enterprise Defense Evasion technique. Adversaries may abuse utilities that allow for command execution to bypass security restrictions that limit the use of command-line interpreters. Various Windows utilities may be used to execute...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1202-indirect-command-execution
- T1205 Traffic Signaling
An Enterprise Defense Evasion and Persistence and Command and Control technique. Adversaries may use traffic signaling to hide open ports or other malicious functionality used for persistence or command and control. Traffic signaling...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1205-traffic-signaling
- T1205.001 Port Knocking
An Enterprise Defense Evasion and Persistence and Command and Control sub-technique of T1205 (Traffic Signaling). Adversaries may use port knocking to hide open ports used for persistence or command and control. To enable a port, an...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1205-001-port-knocking
- T1205.002 Socket Filters
An Enterprise Defense Evasion and Persistence and Command and Control sub-technique of T1205 (Traffic Signaling). Adversaries may attach filters to a network socket to monitor then activate backdoors used for persistence or command and...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1205-002-socket-filters
- T1211 Exploitation for Stealth
An Enterprise Defense Evasion technique. Adversaries may exploit a system or application vulnerability to bypass security features. Exploitation of a vulnerability occurs when an adversary takes advantage of a programming error in a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1211-exploitation-for-defense-evasion
- T1216 System Script Proxy Execution
An Enterprise Defense Evasion technique. Adversaries may use trusted scripts, often signed with certificates, to proxy the execution of malicious files. Several Microsoft signed scripts that have been downloaded from Microsoft or are...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1216-system-script-proxy-execution
- T1216.001 PubPrn
An Enterprise Defense Evasion sub-technique of T1216 (System Script Proxy Execution). Adversaries may use PubPrn to proxy execution of malicious remote files. PubPrn.vbs is a Visual Basic script that publishes a printer to Active...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1216-001-pubprn
- T1216.002 SyncAppvPublishingServer
An Enterprise Defense Evasion sub-technique of T1216 (System Script Proxy Execution). Adversaries may abuse SyncAppvPublishingServer.vbs to proxy execution of malicious PowerShell commands. SyncAppvPublishingServer.vbs is a Visual Basic...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1216-002-syncappvpublishingserver
- T1218 System Binary Proxy Execution
Adversary use of legitimate signed Windows binaries (LOLBins - Living Off The Land Binaries) to proxy execution of malicious payloads and bypass application allowlisting. Sub-techniques include Compiled HTML File (T1218.001), Control...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1218-system-binary-proxy-execution
- T1218.001 Compiled HTML File
An Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may abuse Compiled HTML files (.chm) to conceal malicious code. CHM files are commonly distributed as part of the Microsoft HTML Help...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1218-001-compiled-html-file
- T1218.002 Control Panel
An Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may abuse control.exe to proxy execution of malicious payloads. The Windows Control Panel process binary (control.exe) handles execution...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1218-002-control-panel
- T1218.003 CMSTP
An Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may abuse CMSTP to proxy execution of malicious code. The Microsoft Connection Manager Profile Installer (CMSTP.exe) is a command-line...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1218-003-cmstp
- T1218.004 InstallUtil
An Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may use InstallUtil to proxy execution of code through a trusted Windows utility. InstallUtil is a command-line utility that allows for...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1218-004-installutil
- T1218.005 Mshta
An Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and Javascript or VBScript through a trusted Windows utility. There are...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1218-005-mshta
- T1218.007 Msiexec
An Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may abuse msiexec.exe to proxy execution of malicious payloads. Msiexec.exe is the command-line utility for the Windows Installer and is...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1218-007-msiexec
- T1218.008 Odbcconf
An Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may abuse odbcconf.exe to proxy execution of malicious payloads. Odbcconf.exe is a Windows utility that allows you to configure Open...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1218-008-odbcconf
- T1218.009 Regsvcs/Regasm
An Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may abuse Regsvcs and Regasm to proxy execution of code through a trusted Windows utility. Regsvcs and Regasm are Windows command-line...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1218-009-regsvcs-regasm
- T1218.010 Regsvr32
An Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may abuse Regsvr32.exe to proxy execution of malicious code. Regsvr32.exe is a command-line program used to register and unregister object...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1218-010-regsvr32
- T1218.011 Rundll32
Adversary use of rundll32.exe to proxy execute malicious DLLs and bypass application allowlisting. Variants include DLL with exported function, javascript: protocol (rundll32 javascript:), and SCT abuse. Used by Cobalt Strike, IcedID,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1218-011-rundll32
- T1218.012 Verclsid
An Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may abuse verclsid.exe to proxy execution of malicious code. Verclsid.exe is known as the Extension CLSID Verification Host and is...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1218-012-verclsid
- T1218.013 Mavinject
An Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may abuse mavinject.exe to proxy execution of malicious code. Mavinject.exe is the Microsoft Application Virtualization Injector, a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1218-013-mavinject
- T1218.014 MMC
An Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may abuse mmc.exe to proxy execution of malicious .msc files. Microsoft Management Console (MMC) is a binary that may be signed by...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1218-014-mmc
- T1218.015 Electron Applications
An Enterprise Defense Evasion sub-technique of T1218 (System Binary Proxy Execution). Adversaries may abuse components of the Electron framework to execute malicious code. The Electron framework hosts many common applications such as...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1218-015-electron-applications
- T1220 XSL Script Processing
An Enterprise Defense Evasion technique. Adversaries may bypass application control and obscure execution of code by embedding scripts inside XSL files. Extensible Stylesheet Language (XSL) files are commonly used to describe the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1220-xsl-script-processing
- T1221 Template Injection
An Enterprise Defense Evasion technique. Adversaries may create or modify references in user document templates to conceal malicious code or force authentication attempts. For example, Microsoft's Office Open XML (OOXML) specification...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1221-template-injection
- T1480 Execution Guardrails
An Enterprise Defense Evasion technique. Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1480-execution-guardrails
- T1480.001 Environmental Keying
An Enterprise Defense Evasion sub-technique of T1480 (Execution Guardrails). Adversaries may environmentally key payloads or other features of malware to evade defenses and constraint execution to a specific target environment....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1480-001-environmental-keying
- T1480.002 Mutual Exclusion
An Enterprise Defense Evasion sub-technique of T1480 (Execution Guardrails). Adversaries may constrain execution or actions based on the presence of a mutex associated with malware. A mutex is a locking mechanism used to synchronize...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1480-002-mutual-exclusion
- T1497 Virtualization/Sandbox Evasion
An Enterprise Defense Evasion and Discovery technique. Adversaries may employ various means to detect and avoid virtualization and analysis environments. This may include changing behaviors based on the results of checks for the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1497-virtualization-sandbox-evasion
- T1497.001 System Checks
An Enterprise Defense Evasion and Discovery sub-technique of T1497 (Virtualization/Sandbox Evasion). Adversaries may employ various system checks to detect and avoid virtualization and analysis environments. This may include changing...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1497-001-system-checks
- T1497.002 User Activity Based Checks
An Enterprise Defense Evasion and Discovery sub-technique of T1497 (Virtualization/Sandbox Evasion). Adversaries may employ various user activity checks to detect and avoid virtualization and analysis environments. This may include...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1497-002-user-activity-based-checks
- T1497.003 Time Based Checks
An Enterprise Defense Evasion and Discovery sub-technique of T1497 (Virtualization/Sandbox Evasion). Adversaries may employ various time-based methods to detect and avoid virtualization and analysis environments. This may include...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1497-003-time-based-evasion
- T1535 Unused/Unsupported Cloud Regions
An Enterprise Defense Evasion technique. Adversaries may create cloud instances in unused geographic service regions in order to evade detection. Access is usually obtained through compromising accounts used to manage cloud...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1535-unused-unsupported-cloud-regions
- T1542 Pre-OS Boot
An Enterprise Defense Evasion and Persistence technique. Adversaries may abuse Pre-OS Boot mechanisms as a way to establish persistence on a system. During the booting process of a computer, firmware and various startup services are...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1542-pre-os-boot
- T1542.001 System Firmware
An Enterprise Persistence and Defense Evasion sub-technique of T1542 (Pre-OS Boot). Adversaries may modify system firmware to persist on systems.The BIOS (Basic Input/Output System) and The Unified Extensible Firmware Interface (UEFI)...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1542-001-system-firmware
- T1542.002 Component Firmware
An Enterprise Persistence and Defense Evasion sub-technique of T1542 (Pre-OS Boot). Adversaries may modify component firmware to persist on systems. Some adversaries may employ sophisticated means to compromise computer components and...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1542-002-component-firmware
- T1542.003 Bootkit
An Enterprise Persistence and Defense Evasion sub-technique of T1542 (Pre-OS Boot). Adversaries may use bootkits to persist on systems. Bootkits reside at a layer below the operating system and may make it difficult to perform full...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1542-003-bootkit
- T1542.004 ROMMONkit
An Enterprise Defense Evasion and Persistence sub-technique of T1542 (Pre-OS Boot). Adversaries may abuse the ROM Monitor (ROMMON) by loading an unauthorized firmware with adversary code to provide persistent access and manipulate...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1542-004-rommonkit
- T1542.005 TFTP Boot
An Enterprise Defense Evasion and Persistence sub-technique of T1542 (Pre-OS Boot). Adversaries may abuse netbooting to load an unauthorized network device operating system from a Trivial File Transfer Protocol (TFTP) server. TFTP boot...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1542-005-tftp-boot
- T1562.001 Disable or Modify Tools
An Enterprise Defense Evasion sub-technique of T1562 (Impair Defenses). Adversaries may modify and/or disable security tools to avoid possible detection of their malware/tools and activities. This may take many forms, such as killing...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1562-001-disable-or-modify-tools
- T1562.002 Disable Windows Event Logging
An Enterprise Defense Evasion sub-technique of T1562 (Impair Defenses). Adversaries may disable Windows event logging to limit data that can be leveraged for detections and audits. Windows event logs record user and system activity such...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1562-002-disable-windows-event-logging
- T1562.003 Impair Command History Logging
An Enterprise Defense Evasion sub-technique of T1562 (Impair Defenses). Adversaries may impair command history logging to hide commands they run on a compromised system. Various command interpreters keep track of the commands users type...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1562-003-impair-command-history-logging
- T1562.004 Disable or Modify System Firewall
An Enterprise Defense Evasion sub-technique of T1562 (Impair Defenses). Adversaries may disable or modify system firewalls in order to bypass controls limiting network usage. Changes could be disabling the entire mechanism as well as...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1562-004-disable-or-modify-system-firewall
- T1562.006 Indicator Blocking
An Enterprise Defense Evasion sub-technique of T1562 (Impair Defenses). An adversary may attempt to block indicators or events typically captured by sensors from being gathered and analyzed. This could include maliciously redirecting or...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1562-006-indicator-blocking
- T1562.007 Disable or Modify Cloud Firewall
An Enterprise Defense Evasion sub-technique of T1562 (Impair Defenses). Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources. Cloud firewalls are separate from...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1562-007-disable-or-modify-cloud-firewall
- T1562.008 Disable or Modify Cloud Logs
An Enterprise Defense Evasion sub-technique of T1562 (Impair Defenses). An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1562-008-disable-or-modify-cloud-logs
- T1562.009 Safe Mode Boot
An Enterprise Defense Evasion sub-technique of T1562 (Impair Defenses). Adversaries may abuse Windows safe mode to disable endpoint defenses. Safe mode starts up the Windows operating system with a limited set of drivers and services....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1562-009-safe-mode-boot
- T1562.010 Downgrade Attack
An Enterprise Defense Evasion sub-technique of T1562 (Impair Defenses). Adversaries may downgrade or use a version of system features that may be outdated, vulnerable, and/or does not support updated security controls. Downgrade attacks...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1562-010-downgrade-attack
- T1562.011 Spoof Security Alerting
An Enterprise Defense Evasion sub-technique of T1562 (Impair Defenses). Adversaries may spoof security alerting from tools, presenting false evidence to impair defenders' awareness of malicious activity. Messages produced by defensive...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1562-011-spoof-security-alerting
- T1562.012 Disable or Modify Linux Audit System
An Enterprise Defense Evasion sub-technique of T1562 (Impair Defenses). Adversaries may disable or modify the Linux audit system to hide malicious activity and avoid detection. Linux admins use the Linux Audit system to track...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1562-012-disable-or-modify-linux-audit-system
- T1564 Hide Artifacts
An Enterprise Defense Evasion technique. Adversaries may attempt to hide artifacts associated with their behaviors to evade detection. Operating systems may have features to hide various artifacts, such as important system files and...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1564-hide-artifacts
- T1564.001 Hidden Files and Directories
An Enterprise Defense Evasion sub-technique of T1564 (Hide Artifacts). Adversaries may set files and directories to be hidden to evade detection mechanisms. To prevent normal users from accidentally changing special files on a system,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1564-001-hidden-files-and-directories
- T1564.002 Hidden Users
An Enterprise Defense Evasion sub-technique of T1564 (Hide Artifacts). Adversaries may use hidden users to hide the presence of user accounts they create or modify. Administrators may want to hide users when there are many user accounts...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1564-002-hidden-users
- T1564.003 Hidden Window
An Enterprise Defense Evasion sub-technique of T1564 (Hide Artifacts). Adversaries may use hidden windows to conceal malicious activity from the plain sight of users. In some cases, windows that would typically be displayed when an...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1564-003-hidden-window
- T1564.004 NTFS File Attributes
An Enterprise Defense Evasion sub-technique of T1564 (Hide Artifacts). Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection. Every New Technology File System (NTFS) formatted partition...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1564-004-ntfs-file-attributes
- T1564.005 Hidden File System
An Enterprise Defense Evasion sub-technique of T1564 (Hide Artifacts). Adversaries may use a hidden file system to conceal malicious activity from users and security tools. File systems provide a structure to store and access data from...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1564-005-hidden-file-system
- T1564.006 Run Virtual Instance
An Enterprise Defense Evasion sub-technique of T1564 (Hide Artifacts). Adversaries may carry out malicious operations using a virtual instance to avoid detection. A wide variety of virtualization technologies exist that allow for the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1564-006-run-virtual-instance
- T1564.007 VBA Stomping
An Enterprise Defense Evasion sub-technique of T1564 (Hide Artifacts). Adversaries may hide malicious Visual Basic for Applications (VBA) payloads embedded within MS Office documents by replacing the VBA source code with benign data. MS...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1564-007-vba-stomping
- T1564.008 Email Hiding Rules
An Enterprise Defense Evasion sub-technique of T1564 (Hide Artifacts). Adversaries may use email rules to hide inbound emails in a compromised user's mailbox. Many email clients allow users to create inbox rules for various email...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1564-008-email-hiding-rules
- T1564.009 Resource Forking
An Enterprise Defense Evasion sub-technique of T1564 (Hide Artifacts). Adversaries may abuse resource forks to hide malicious code or executables to evade detection and bypass security applications. A resource fork provides applications...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1564-009-resource-forking
- T1564.010 Process Argument Spoofing
An Enterprise Defense Evasion sub-technique of T1564 (Hide Artifacts). Adversaries may attempt to hide process command-line arguments by overwriting process memory. Process command-line arguments are stored in the process environment...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1564-010-process-argument-spoofing
- T1564.011 Ignore Process Interrupts
An Enterprise Defense Evasion sub-technique of T1564 (Hide Artifacts). Adversaries may evade defensive mechanisms by executing commands that hide from process interrupt signals. Many operating systems use signals to deliver messages to...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1564-011-ignore-process-interrupts
- T1564.012 File/Path Exclusions
An Enterprise Defense Evasion sub-technique of T1564 (Hide Artifacts). Adversaries may attempt to hide their file-based artifacts by writing them to specific folders or file names excluded from antivirus (AV) scanning and other...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1564-012-file-path-exclusions
- T1564.013 Bind Mounts
An Enterprise Stealth technique. Adversaries may abuse bind mounts on file structures to hide their activity and artifacts from native utilities. A bind mount maps a directory or file from one location on the filesystem to another,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1564-013-bind-mounts
- T1564.014 Extended Attributes
An Enterprise Stealth technique. Adversaries may abuse extended attributes (xattrs) on macOS and Linux to hide their malicious data in order to evade detection. Extended attributes are key-value pairs of file and directory metadata used...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1564-014-extended-attributes
- T1574 Hijack Execution Flow
Adversary hijacking of legitimate program execution flow to load malicious code. Sub-techniques include DLL Side-Loading (T1574.002), DLL Search Order Hijacking (T1574.001), DYLIB Hijacking (T1574.004), Executable Path Hijacking...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-hijack-execution-flow
- T1574.001 DLL
An Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking the search order used to load DLLs. Windows systems...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-001-dll-search-order-hijacking
- T1574.002 DLL Side-Loading
An Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by side-loading DLLs. Similar to DLL Search Order Hijacking,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-002-dll-side-loading
- T1574.004 Dylib Hijacking
An Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own payloads by placing a malicious dynamic library (dylib) with an expected name in a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-004-dylib-hijacking
- T1574.005 Executable Installer File Permissions Weakness
An Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking the binaries used by an installer. These processes...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-005-executable-installer-file-permissions-weakness
- T1574.006 Dynamic Linker Hijacking
An Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking environment variables the dynamic linker uses to...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-006-dynamic-linker-hijacking
- T1574.007 Path Interception by PATH Environment Variable
An Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking environment variables used to load libraries. The...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-007-path-interception-by-path-environment-variable
- T1574.008 Path Interception by Search Order Hijacking
An Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking the search order used to load other programs....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-008-path-interception-by-search-order-hijacking
- T1574.009 Path Interception by Unquoted Path
An Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking vulnerable file path references. Adversaries can...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-009-path-interception-by-unquoted-path
- T1574.010 Services File Permissions Weakness
An Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking the binaries used by services. Adversaries may use...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-010-services-file-permissions-weakness
- T1574.011 Services Registry Permissions Weakness
An Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking the Registry entries used by services. Adversaries...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-011-services-registry-permissions-weakness
- T1574.012 COR_PROFILER
An Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may leverage the COR_PROFILER environment variable to hijack the execution flow of programs that load the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-012-cor-profiler
- T1574.013 KernelCallbackTable
An Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may abuse the KernelCallbackTable of a process to hijack its execution flow in order to run their own...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-013-kernelcallbacktable
- T1574.014 AppDomainManager
An Enterprise Persistence and Privilege Escalation and Defense Evasion sub-technique of T1574 (Hijack Execution Flow). Adversaries may execute their own malicious payloads by hijacking how the .NET AppDomainManager loads assemblies. The...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1574-014-appdomainmanager
- T1612 Build Image on Host
An Enterprise Defense Evasion technique. Adversaries may build a container image directly on a host to bypass defenses that monitor for the retrieval of malicious images from a public registry. A remote build request may be sent to the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1612-build-image-on-host
- T1620 Reflective Code Loading
An Enterprise Defense Evasion technique. Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads. Reflective loading involves allocating then executing payloads directly within the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1620-reflective-code-loading
- T1622 Debugger Evasion
An Enterprise Defense Evasion and Discovery technique. Adversaries may employ various means to detect and avoid debuggers. Debuggers are typically used by defenders to trace and/or analyze the execution of potential malware payloads....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1622-debugger-evasion
- T1656 Impersonation
An Enterprise Defense Evasion technique. Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf. For example, adversaries may communicate with...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1656-impersonation
- T1678 Delay Execution
An Enterprise Stealth technique. Adversaries may employ various time-based methods to evade detection and analysis. These techniques often exploit system clocks, delays, or timing mechanisms to obscure malicious activity, blend in with...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1678-delay-execution
- T1679 Selective Exclusion
An Enterprise Stealth technique. Adversaries may intentionally exclude certain files, folders, directories, file types, or system components from encryption or tampering during a ransomware or malicious payload execution. Some file...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1679-selective-exclusion
- T1684 Social Engineering
An Enterprise Stealth technique. Adversaries may use social engineering techniques to influence users to take actions that result in unauthorized access, approval of changes, disclosure of sensitive information, or execution of...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1684-social-engineering
- T1684.001 Impersonation
An Enterprise Stealth technique. Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf. For example, adversaries may communicate with victims...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1684-001-impersonation
- T1684.002 Email Spoofing
An Enterprise Stealth technique. Adversaries may fake, or spoof, a sender’s identity by modifying the value of relevant email headers in order to establish contact with victims under false pretenses. In addition to actual email content,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1684-002-email-spoofing

[defense-impairment] Defense Impairment
- T1112 Modify Registry
Adversary modification of the Windows Registry to hide configuration, persist, disable security tools, or evade detection. Common targets: Run keys, Services, Defender exclusions, EnableLUA UAC, IFEO (Image File Execution Options)...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1112-modify-registry
- T1207 Rogue Domain Controller
An Enterprise Defense Evasion technique. Adversaries may register a rogue Domain Controller to enable manipulation of Active Directory data. DCShadow may be used to create a rogue Domain Controller (DC). DCShadow is a method of...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1207-rogue-domain-controller
- T1222 File and Directory Permissions Modification
An Enterprise Defense Evasion technique. Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files. File and directory permissions are commonly managed by ACLs...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1222-file-and-directory-permissions-modification
- T1222.001 Windows Permissions
An Enterprise Defense Evasion sub-technique of T1222 (File and Directory Permissions Modification). Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files. File...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1222-001-windows-file-and-directory-permissions-modification
- T1222.002 Linux and Mac Permissions
An Enterprise Defense Evasion sub-technique of T1222 (File and Directory Permissions Modification). Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files. File...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1222-002-linux-and-mac-file-and-directory-permissions-modification
- T1484 Domain or Tenant Policy Modification
An Enterprise Defense Evasion and Privilege Escalation technique. Adversaries may modify the configuration settings of a domain or identity tenant to evade defenses and/or escalate privileges in centrally managed environments. Such...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1484-domain-or-tenant-policy-modification
- T1484.001 Group Policy Modification
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1484 (Domain or Tenant Policy Modification). Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1484-001-group-policy-modification
- T1484.002 Trust Modification
An Enterprise Defense Evasion and Privilege Escalation sub-technique of T1484 (Domain or Tenant Policy Modification). Adversaries may add new domain trusts, modify the properties of existing domain trusts, or otherwise change the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1484-002-trust-modification
- T1553 Subvert Trust Controls
An Enterprise Defense Evasion technique. Adversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted programs. Operating systems and security products may contain...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1553-subvert-trust-controls
- T1553.001 Gatekeeper Bypass
An Enterprise Defense Evasion sub-technique of T1553 (Subvert Trust Controls). Adversaries may modify file attributes and subvert Gatekeeper functionality to evade user prompts and execute untrusted programs. Gatekeeper is a set of...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1553-001-gatekeeper-bypass
- T1553.002 Code Signing
An Enterprise Defense Evasion sub-technique of T1553 (Subvert Trust Controls). Adversaries may create, acquire, or steal code signing materials to sign their malware or tools. Code signing provides a level of authenticity on a binary...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1553-002-code-signing
- T1553.003 SIP and Trust Provider Hijacking
An Enterprise Defense Evasion sub-technique of T1553 (Subvert Trust Controls). Adversaries may tamper with SIP and trust provider components to mislead the operating system and application control tools when conducting signature...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1553-003-sip-and-trust-provider-hijacking
- T1553.004 Install Root Certificate
An Enterprise Defense Evasion sub-technique of T1553 (Subvert Trust Controls). Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers. Root certificates...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1553-004-install-root-certificate
- T1553.005 Mark-of-the-Web Bypass
An Enterprise Defense Evasion sub-technique of T1553 (Subvert Trust Controls). Adversaries may abuse specific file formats to subvert Mark-of-the-Web (MOTW) controls. In Windows, when files are downloaded from the Internet, they are...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1553-005-mark-of-the-web-bypass
- T1553.006 Code Signing Policy Modification
An Enterprise Defense Evasion sub-technique of T1553 (Subvert Trust Controls). Adversaries may modify code signing policies to enable execution of unsigned or self-signed code. Code signing provides a level of authenticity on a program...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1553-006-code-signing-policy-modification
- T1556 Modify Authentication Process
An Enterprise Credential Access and Defense Evasion and Persistence technique. Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-modify-authentication-process
- T1556.001 Domain Controller Authentication
An Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may patch the authentication process on a domain controller to bypass the typical authentication...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-001-domain-controller-authentication
- T1556.002 Password Filter DLL
An Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may register malicious password filter dynamic link libraries (DLLs) into the authentication process...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-002-password-filter-dll
- T1556.003 Pluggable Authentication Modules
An Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may modify pluggable authentication modules (PAM) to access user credentials or enable otherwise...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-003-pluggable-authentication-modules
- T1556.004 Network Device Authentication
An Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may use Patch System Image to hard code a password in the operating system, thus bypassing of native...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-004-network-device-authentication
- T1556.005 Reversible Encryption
An Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). An adversary may abuse Active Directory authentication encryption properties to gain access to credentials on...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-005-reversible-encryption
- T1556.006 Multi-Factor Authentication
An Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-006-multi-factor-authentication
- T1556.007 Hybrid Identity
An Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may patch, modify, or otherwise backdoor cloud authentication processes that are tied to on-premises...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-007-hybrid-identity
- T1556.008 Network Provider DLL
An Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may register malicious network provider dynamic link libraries (DLLs) to capture cleartext user...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-008-network-provider-dll
- T1556.009 Conditional Access Policies
An Enterprise Credential Access and Defense Evasion and Persistence sub-technique of T1556 (Modify Authentication Process). Adversaries may disable or modify conditional access policies to enable persistent access to compromised...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1556-009-conditional-access-policies
- T1578 Modify Cloud Compute Infrastructure
An Enterprise Defense Evasion technique. An adversary may attempt to modify a cloud account's compute service infrastructure to evade defenses. A modification to the compute service infrastructure can include the creation, deletion, or...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1578-modify-cloud-compute-infrastructure
- T1578.001 Create Snapshot
An Enterprise Defense Evasion sub-technique of T1578 (Modify Cloud Compute Infrastructure). An adversary may create a snapshot or data backup within a cloud account to evade defenses. A snapshot is a point-in-time copy of an existing...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1578-001-create-snapshot
- T1578.002 Create Cloud Instance
An Enterprise Defense Evasion sub-technique of T1578 (Modify Cloud Compute Infrastructure). An adversary may create a new instance or virtual machine (VM) within the compute service of a cloud account to evade defenses. Creating a new...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1578-002-create-cloud-instance
- T1578.003 Delete Cloud Instance
An Enterprise Defense Evasion sub-technique of T1578 (Modify Cloud Compute Infrastructure). An adversary may delete a cloud instance after they have performed malicious activities in an attempt to evade detection and remove evidence of...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1578-003-delete-cloud-instance
- T1578.004 Revert Cloud Instance
An Enterprise Defense Evasion sub-technique of T1578 (Modify Cloud Compute Infrastructure). An adversary may revert changes made to a cloud instance after they have performed malicious activities in attempt to evade detection and remove...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1578-004-revert-cloud-instance
- T1578.005 Modify Cloud Compute Configurations
An Enterprise Defense Evasion sub-technique of T1578 (Modify Cloud Compute Infrastructure). Adversaries may modify settings that directly affect the size, locations, and resources available to cloud compute infrastructure in order to...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1578-005-modify-cloud-compute-configurations
- T1599 Network Boundary Bridging
An Enterprise Defense Evasion technique. Adversaries may bridge network boundaries by compromising perimeter network devices or internal devices responsible for network segmentation. Breaching these devices may enable an adversary to...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1599-network-boundary-bridging
- T1599.001 Network Address Translation Traversal
An Enterprise Defense Evasion sub-technique of T1599 (Network Boundary Bridging). Adversaries may bridge network boundaries by modifying a network device's Network Address Translation (NAT) configuration. Malicious modifications to NAT...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1599-001-network-address-translation-traversal
- T1600 Weaken Encryption
An Enterprise Defense Evasion technique. Adversaries may compromise a network device's encryption capability in order to bypass encryption that would otherwise protect data communications. Encryption can be used to protect transmitted...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1600-weaken-encryption
- T1600.001 Reduce Key Space
An Enterprise Defense Evasion sub-technique of T1600 (Weaken Encryption). Adversaries may reduce the level of effort required to decrypt data transmitted over the network by reducing the cipher strength of encrypted communications....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1600-001-reduce-key-space
- T1600.002 Disable Crypto Hardware
An Enterprise Defense Evasion sub-technique of T1600 (Weaken Encryption). Adversaries disable a network device's dedicated hardware encryption, which may enable them to leverage weaknesses in software encryption in order to reduce the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1600-002-disable-crypto-hardware
- T1601 Modify System Image
An Enterprise Defense Evasion technique. Adversaries may make changes to the operating system of embedded network devices to weaken defenses and provide new capabilities for themselves. On such devices, the operating systems are...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1601-modify-system-image
- T1601.001 Patch System Image
An Enterprise Defense Evasion sub-technique of T1601 (Modify System Image). Adversaries may modify the operating system of a network device to introduce new capabilities or weaken existing defenses. Some network devices are built with a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1601-001-patch-system-image
- T1601.002 Downgrade System Image
An Enterprise Defense Evasion sub-technique of T1601 (Modify System Image). Adversaries may install an older version of the operating system of a network device to weaken security. Older operating system versions on network devices...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1601-002-downgrade-system-image
- T1647 Plist File Modification
An Enterprise Defense Evasion technique. Adversaries may modify property list files (plist files) to enable other malicious activity, while also potentially evading and bypassing system defenses. macOS applications use plist files, such...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1647-plist-file-modification
- T1666 Modify Cloud Resource Hierarchy
An Enterprise Defense Evasion technique. Adversaries may attempt to modify hierarchical structures in infrastructure-as-a-service (IaaS) environments in order to evade defenses. IaaS environments often group resources into a hierarchy,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1666-modify-cloud-resource-hierarchy
- T1685 Disable or Modify Tools
An Enterprise Defense Impairment technique. Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1685-disable-or-modify-tools
- T1685.001 Disable or Modify Windows Event Log
An Enterprise Defense Impairment technique. Adversaries may disable or modify the Windows Event Log to limit data that can be leveraged for detections and audits. Windows Event Log records user and system activity such as login attempts...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1685-001-disable-or-modify-windows-event-log
- T1685.002 Disable or Modify Cloud Log
An Enterprise Defense Impairment technique. An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1685-002-disable-or-modify-cloud-log
- T1685.003 Modify or Spoof Tool UI
An Enterprise Defense Impairment technique. Adversaries may spoof or manipulate security tool user interfaces (UIs) to falsely indicate tools are functioning normally and delay detection and response. Adversaries may present misleading...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1685-003-modify-or-spoof-tool-ui
- T1685.004 Disable or Modify Linux Audit System Log
An Enterprise Defense Impairment technique. Adversaries may disable or modify the Linux Audit system to hide malicious activity and avoid detection. Linux admins use the Linux Audit system to track security-relevant information on a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1685-004-disable-or-modify-linux-audit-system-log
- T1685.005 Clear Windows Event Logs
An Enterprise Defense Impairment technique. Adversaries may clear Windows Event Logs to hide the activity of an intrusion. Windows Event Logs are a record of a computer's alerts and notifications. There are three system-defined sources...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1685-005-clear-windows-event-logs
- T1685.006 Clear Linux or Mac System Logs
An Enterprise Defense Impairment technique. Adversaries may clear system logs to hide evidence of an intrusion. macOS and Linux both keep track of system or user-initiated actions via system logs. The majority of native system logging...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1685-006-clear-linux-or-mac-system-logs
- T1686 Disable or Modify System Firewall
An Enterprise Defense Impairment technique. Adversaries may disable or modify host-based or network firewalls to impair defensive mechanisms and enable further action. Once an adversary has gathered sufficient privileges, they can...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1686-disable-or-modify-system-firewall
- T1686.001 Cloud Firewall
An Enterprise Defense Impairment technique. Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources. Cloud environments typically utilize restrictive security...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1686-001-cloud-firewall
- T1686.002 Network Device Firewall
An Enterprise Defense Impairment technique. Adversaries may disable network device-based firewall mechanisms entirely or add, delete, or modify particular rules in order to bypass controls limiting network usage. Adversaries may obtain...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1686-002-network-device-firewall
- T1686.003 Windows Host Firewall
An Enterprise Defense Impairment technique. Adversaries may disable or modify the Windows host firewall to bypass controls limiting network usage. This can include disabling the Windows host firewall entirely, suppressing specific...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1686-003-windows-host-firewall
- T1687 Exploitation for Defense Impairment
An Enterprise Defense Impairment technique. Adversaries may exploit vulnerabilities in security software, infrastructure, or defensive components to degrade, disable, or otherwise continue to impair their ability to prevent, detect, or...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1687-exploitation-for-defense-impairment
- T1688 Safe Mode Boot
An Enterprise Defense Impairment technique. Adversaries may abuse Windows safe mode to disable endpoint defenses. Safe mode starts up the Windows operating system with a limited set of drivers and services. Third-party security software...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1688-safe-mode-boot
- T1689 Downgrade Attack
An Enterprise Defense Impairment technique. Adversaries may downgrade or use a version of system features that may be outdated, vulnerable, and/or does not support updated security controls. Downgrade attacks typically take advantage of...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1689-downgrade-attack
- T1690 Prevent Command History Logging
An Enterprise Defense Impairment technique. Adversaries may impair command history logging to hide commands they run on a compromised system. Various command interpreters keep track of the commands users type in their terminal so that...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1690-prevent-command-history-logging

[resource-development] Resource Development
- T1583 Acquire Infrastructure
Adversary acquisition of infrastructure to support operations: domain registration, server hosting, virtual private servers, DNS services, web services, and serverless platforms. Sub-techniques include Domains (T1583.001), DNS Server...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1583-acquire-infrastructure
- T1583.001 Domains
An Enterprise Resource Development sub-technique of T1583 (Acquire Infrastructure). Adversaries may acquire domains that can be used during targeting. Domain names are the human readable names used to represent one or more IP addresses....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1583-001-domains
- T1583.002 DNS Server
An Enterprise Resource Development sub-technique of T1583 (Acquire Infrastructure). Adversaries may set up their own Domain Name System (DNS) servers that can be used during targeting. During post-compromise activity, adversaries may...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1583-002-dns-server
- T1583.003 Virtual Private Server
An Enterprise Resource Development sub-technique of T1583 (Acquire Infrastructure). Adversaries may rent Virtual Private Servers (VPSs) that can be used during targeting. There exist a variety of cloud service providers that will sell...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1583-003-virtual-private-server
- T1583.004 Server
An Enterprise Resource Development sub-technique of T1583 (Acquire Infrastructure). Adversaries may buy, lease, rent, or obtain physical servers that can be used during targeting. Use of servers allows an adversary to stage, launch, and...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1583-004-server
- T1583.005 Botnet
An Enterprise Resource Development sub-technique of T1583 (Acquire Infrastructure). Adversaries may buy, lease, or rent a network of compromised systems that can be used during targeting. A botnet is a network of compromised systems...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1583-005-botnet
- T1583.006 Web Services
An Enterprise Resource Development sub-technique of T1583 (Acquire Infrastructure). Adversaries may register for web services that can be used during targeting. A variety of popular websites exist for adversaries to register for a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1583-006-web-services
- T1583.007 Serverless
An Enterprise Resource Development sub-technique of T1583 (Acquire Infrastructure). Adversaries may purchase and configure serverless cloud infrastructure, such as Cloudflare Workers, AWS Lambda functions, or Google Apps Scripts, that...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1583-007-serverless
- T1583.008 Malvertising
An Enterprise Resource Development sub-technique of T1583 (Acquire Infrastructure). Adversaries may purchase online advertisements that can be abused to distribute malware to victims. Ads can be purchased to plant as well as favorably...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1583-008-malvertising
- T1584 Compromise Infrastructure
An Enterprise Resource Development technique. Adversaries may compromise third-party infrastructure that can be used during targeting. Infrastructure solutions include physical or cloud servers, domains, network devices, and third-party...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1584-compromise-infrastructure
- T1584.001 Domains
An Enterprise Resource Development sub-technique of T1584 (Compromise Infrastructure). Adversaries may hijack domains and/or subdomains that can be used during targeting. Domain registration hijacking is the act of changing the...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1584-001-domains
- T1584.002 DNS Server
An Enterprise Resource Development sub-technique of T1584 (Compromise Infrastructure). Adversaries may compromise third-party DNS servers that can be used during targeting. During post-compromise activity, adversaries may utilize DNS...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1584-002-dns-server
- T1584.003 Virtual Private Server
An Enterprise Resource Development sub-technique of T1584 (Compromise Infrastructure). Adversaries may compromise third-party Virtual Private Servers (VPSs) that can be used during targeting. There exist a variety of cloud service...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1584-003-virtual-private-server
- T1584.004 Server
An Enterprise Resource Development sub-technique of T1584 (Compromise Infrastructure). Adversaries may compromise third-party servers that can be used during targeting. Use of servers allows an adversary to stage, launch, and execute an...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1584-004-server
- T1584.005 Botnet
An Enterprise Resource Development sub-technique of T1584 (Compromise Infrastructure). Adversaries may compromise numerous third-party systems to form a botnet that can be used during targeting. A botnet is a network of compromised...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1584-005-botnet
- T1584.006 Web Services
An Enterprise Resource Development sub-technique of T1584 (Compromise Infrastructure). Adversaries may compromise access to third-party web services that can be used during targeting. A variety of popular websites exist for legitimate...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1584-006-web-services
- T1584.007 Serverless
An Enterprise Resource Development sub-technique of T1584 (Compromise Infrastructure). Adversaries may compromise serverless cloud infrastructure, such as Cloudflare Workers, AWS Lambda functions, or Google Apps Scripts, that can be...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1584-007-serverless
- T1584.008 Network Devices
An Enterprise Resource Development sub-technique of T1584 (Compromise Infrastructure). Adversaries may compromise third-party network devices that can be used during targeting. Network devices, such as small office/home office (SOHO)...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1584-008-network-devices
- T1585 Establish Accounts
An Enterprise Resource Development technique. Adversaries may create and cultivate accounts with services that can be used during targeting. Adversaries can create accounts that can be used to build a persona to further operations....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1585-establish-accounts
- T1585.001 Social Media Accounts
An Enterprise Resource Development sub-technique of T1585 (Establish Accounts). Adversaries may create and cultivate social media accounts that can be used during targeting. Adversaries can create social media accounts that can be used...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1585-001-social-media-accounts
- T1585.002 Email Accounts
An Enterprise Resource Development sub-technique of T1585 (Establish Accounts). Adversaries may create email accounts that can be used during targeting. Adversaries can use accounts created with email providers to further their...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1585-002-email-accounts
- T1585.003 Cloud Accounts
An Enterprise Resource Development sub-technique of T1585 (Establish Accounts). Adversaries may create accounts with cloud providers that can be used during targeting. Adversaries can use cloud accounts to further their operations,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1585-003-cloud-accounts
- T1586 Compromise Accounts
An Enterprise Resource Development technique. Adversaries may compromise accounts with services that can be used during targeting. For operations incorporating social engineering, the utilization of an online persona may be important....
Bidda node: https://bidda.com/intelligence/mitre-attack-t1586-compromise-accounts
- T1586.001 Social Media Accounts
An Enterprise Resource Development sub-technique of T1586 (Compromise Accounts). Adversaries may compromise social media accounts that can be used during targeting. For operations incorporating social engineering, the utilization of an...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1586-001-social-media-accounts
- T1586.002 Email Accounts
An Enterprise Resource Development sub-technique of T1586 (Compromise Accounts). Adversaries may compromise email accounts that can be used during targeting. Adversaries can use compromised email accounts to further their operations,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1586-002-email-accounts
- T1586.003 Cloud Accounts
An Enterprise Resource Development sub-technique of T1586 (Compromise Accounts). Adversaries may compromise cloud accounts that can be used during targeting. Adversaries can use compromised cloud accounts to further their operations,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1586-003-cloud-accounts
- T1587 Develop Capabilities
An Enterprise Resource Development technique. Adversaries may build capabilities that can be used during targeting. Rather than purchasing, freely downloading, or stealing capabilities, adversaries may develop their own capabilities...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1587-develop-capabilities
- T1587.001 Malware
An Enterprise Resource Development sub-technique of T1587 (Develop Capabilities). Adversaries may develop malware and malware components that can be used during targeting. Building malicious software can include the development of...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1587-001-malware
- T1587.002 Code Signing Certificates
An Enterprise Resource Development sub-technique of T1587 (Develop Capabilities). Adversaries may create self-signed code signing certificates that can be used during targeting. Code signing is the process of digitally signing...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1587-002-code-signing-certificates
- T1587.003 Digital Certificates
An Enterprise Resource Development sub-technique of T1587 (Develop Capabilities). Adversaries may create self-signed SSL/TLS certificates that can be used during targeting. SSL/TLS certificates are designed to instill trust. They...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1587-003-digital-certificates
- T1587.004 Exploits
An Enterprise Resource Development sub-technique of T1587 (Develop Capabilities). Adversaries may develop exploits that can be used during targeting. An exploit takes advantage of a bug or vulnerability in order to cause unintended or...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1587-004-exploits
- T1588 Obtain Capabilities
An Enterprise Resource Development technique. Adversaries may buy and/or steal capabilities that can be used during targeting. Rather than developing their own capabilities in-house, adversaries may purchase, freely download, or steal...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1588-obtain-capabilities
- T1588.001 Malware
An Enterprise Resource Development sub-technique of T1588 (Obtain Capabilities). Adversaries may buy, steal, or download malware that can be used during targeting. Malicious software can include payloads, droppers, post-compromise...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1588-001-malware
- T1588.002 Tool
An Enterprise Resource Development sub-technique of T1588 (Obtain Capabilities). Adversaries may buy, steal, or download software tools that can be used during targeting. Tools can be open or closed source, free or commercial. A tool...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1588-002-tool
- T1588.003 Code Signing Certificates
An Enterprise Resource Development sub-technique of T1588 (Obtain Capabilities). Adversaries may buy and/or steal code signing certificates that can be used during targeting. Code signing is the process of digitally signing executables...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1588-003-code-signing-certificates
- T1588.004 Digital Certificates
An Enterprise Resource Development sub-technique of T1588 (Obtain Capabilities). Adversaries may buy and/or steal SSL/TLS certificates that can be used during targeting. SSL/TLS certificates are designed to instill trust. They include...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1588-004-digital-certificates
- T1588.005 Exploits
An Enterprise Resource Development sub-technique of T1588 (Obtain Capabilities). Adversaries may buy, steal, or download exploits that can be used during targeting. An exploit takes advantage of a bug or vulnerability in order to cause...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1588-005-exploits
- T1588.006 Vulnerabilities
An Enterprise Resource Development sub-technique of T1588 (Obtain Capabilities). Adversaries may acquire information about vulnerabilities that can be used during targeting. A vulnerability is a weakness in computer hardware or software...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1588-006-vulnerabilities
- T1588.007 Artificial Intelligence
An Enterprise Resource Development sub-technique of T1588 (Obtain Capabilities). Adversaries may obtain access to generative artificial intelligence tools, such as large language models (LLMs), to aid various techniques during...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1588-007-artificial-intelligence
- T1608 Stage Capabilities
An Enterprise Resource Development technique. Adversaries may upload, install, or otherwise set up capabilities that can be used during targeting. To support their operations, an adversary may need to take capabilities they developed...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1608-stage-capabilities
- T1608.001 Upload Malware
An Enterprise Resource Development sub-technique of T1608 (Stage Capabilities). Adversaries may upload malware to third-party or adversary controlled infrastructure to make it accessible during targeting. Malicious software can include...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1608-001-upload-malware
- T1608.002 Upload Tool
An Enterprise Resource Development sub-technique of T1608 (Stage Capabilities). Adversaries may upload tools to third-party or adversary controlled infrastructure to make it accessible during targeting. Tools can be open or closed...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1608-002-upload-tool
- T1608.003 Install Digital Certificate
An Enterprise Resource Development sub-technique of T1608 (Stage Capabilities). Adversaries may install SSL/TLS certificates that can be used during targeting. SSL/TLS certificates are files that can be installed on servers to enable...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1608-003-install-digital-certificate
- T1608.004 Drive-by Target
An Enterprise Resource Development sub-technique of T1608 (Stage Capabilities). Adversaries may prepare an operational environment to infect systems that visit a website over the normal course of browsing. Endpoint systems may be...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1608-004-drive-by-target
- T1608.005 Link Target
An Enterprise Resource Development sub-technique of T1608 (Stage Capabilities). Adversaries may put in place resources that are referenced by a link that can be used during targeting. An adversary may rely upon a user clicking a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1608-005-link-target
- T1608.006 SEO Poisoning
An Enterprise Resource Development sub-technique of T1608 (Stage Capabilities). Adversaries may poison mechanisms that influence search engine optimization (SEO) to further lure staged capabilities towards potential victims. Search...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1608-006-seo-poisoning
- T1650 Acquire Access
An Enterprise Resource Development technique. Adversaries may purchase or otherwise acquire an existing access to a target system or network. A variety of online services and initial access broker networks are available to sell access...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1650-acquire-access
- T1683 Generate Content
An Enterprise Resource Development technique. Adversaries may create or generate content to support targeting and operations. This content may be used to establish personas, impersonate known individuals or organizations, and support...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1683-generate-content
- T1683.001 Written Content
An Enterprise Resource Development technique. Adversaries may create or tailor written materials to support targeting and malicious operations. Content may include phishing lures, fraudulent financial communications, fabricated job...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1683-001-written-content
- T1683.002 Audio-Visual Content
An Enterprise Resource Development technique. Adversaries may create or manipulate audio, image, and video content to support targeting and malicious operations. Adversaries may also use synthetic voice recordings, real-time altered...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1683-002-audio-visual-content

[reconnaissance] Reconnaissance
- T1589 Gather Victim Identity Information
Adversary collection of identity information about a target organisation - employee names, email addresses, credentials in breach corpora, executive identifiers - to enable phishing, social engineering, and credential-stuffing...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1589-gather-victim-identity-information
- T1589.001 Credentials
An Enterprise Reconnaissance sub-technique of T1589 (Gather Victim Identity Information). Adversaries may gather credentials that can be used during targeting. Account credentials gathered by adversaries may be those directly associated...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1589-001-credentials
- T1589.002 Email Addresses
An Enterprise Reconnaissance sub-technique of T1589 (Gather Victim Identity Information). Adversaries may gather email addresses that can be used during targeting. Even if internal instances exist, organizations may have public-facing...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1589-002-email-addresses
- T1589.003 Employee Names
An Enterprise Reconnaissance sub-technique of T1589 (Gather Victim Identity Information). Adversaries may gather employee names that can be used during targeting. Employee names be used to derive email addresses as well as to help guide...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1589-003-employee-names
- T1590 Gather Victim Network Information
An Enterprise Reconnaissance technique. Adversaries may gather information about the victim's networks that can be used during targeting. Information about networks may include a variety of details, including administrative data (ex: IP...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1590-gather-victim-network-information
- T1590.001 Domain Properties
An Enterprise Reconnaissance sub-technique of T1590 (Gather Victim Network Information). Adversaries may gather information about the victim's network domain(s) that can be used during targeting. Information about domains and their...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1590-001-domain-properties
- T1590.002 DNS
An Enterprise Reconnaissance sub-technique of T1590 (Gather Victim Network Information). Adversaries may gather information about the victim's DNS that can be used during targeting. DNS information may include a variety of details,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1590-002-dns
- T1590.003 Network Trust Dependencies
An Enterprise Reconnaissance sub-technique of T1590 (Gather Victim Network Information). Adversaries may gather information about the victim's network trust dependencies that can be used during targeting. Information about network...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1590-003-network-trust-dependencies
- T1590.004 Network Topology
An Enterprise Reconnaissance sub-technique of T1590 (Gather Victim Network Information). Adversaries may gather information about the victim's network topology that can be used during targeting. Information about network topologies may...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1590-004-network-topology
- T1590.005 IP Addresses
An Enterprise Reconnaissance sub-technique of T1590 (Gather Victim Network Information). Adversaries may gather the victim's IP addresses that can be used during targeting. Public IP addresses may be allocated to organizations by block,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1590-005-ip-addresses
- T1590.006 Network Security Appliances
An Enterprise Reconnaissance sub-technique of T1590 (Gather Victim Network Information). Adversaries may gather information about the victim's network security appliances that can be used during targeting. Information about network...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1590-006-network-security-appliances
- T1591 Gather Victim Org Information
An Enterprise Reconnaissance technique. Adversaries may gather information about the victim's organization that can be used during targeting. Information about an organization may include a variety of details, including the names of...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1591-gather-victim-org-information
- T1591.001 Determine Physical Locations
An Enterprise Reconnaissance sub-technique of T1591 (Gather Victim Org Information). Adversaries may gather the victim's physical location(s) that can be used during targeting. Information about physical locations of a target...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1591-001-determine-physical-locations
- T1591.002 Business Relationships
An Enterprise Reconnaissance sub-technique of T1591 (Gather Victim Org Information). Adversaries may gather information about the victim's business relationships that can be used during targeting. Information about an organization's...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1591-002-business-relationships
- T1591.003 Identify Business Tempo
An Enterprise Reconnaissance sub-technique of T1591 (Gather Victim Org Information). Adversaries may gather information about the victim's business tempo that can be used during targeting. Information about an organization's business...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1591-003-identify-business-tempo
- T1591.004 Identify Roles
An Enterprise Reconnaissance sub-technique of T1591 (Gather Victim Org Information). Adversaries may gather information about identities and roles within the victim organization that can be used during targeting. Information about...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1591-004-identify-roles
- T1592 Gather Victim Host Information
An Enterprise Reconnaissance technique. Adversaries may gather information about the victim's hosts that can be used during targeting. Information about hosts may include a variety of details, including administrative data (ex: name,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1592-gather-victim-host-information
- T1592.001 Hardware
An Enterprise Reconnaissance sub-technique of T1592 (Gather Victim Host Information). Adversaries may gather information about the victim's host hardware that can be used during targeting. Information about hardware infrastructure may...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1592-001-hardware
- T1592.002 Software
An Enterprise Reconnaissance sub-technique of T1592 (Gather Victim Host Information). Adversaries may gather information about the victim's host software that can be used during targeting. Information about installed software may...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1592-002-software
- T1592.003 Firmware
An Enterprise Reconnaissance sub-technique of T1592 (Gather Victim Host Information). Adversaries may gather information about the victim's host firmware that can be used during targeting. Information about host firmware may include a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1592-003-firmware
- T1592.004 Client Configurations
An Enterprise Reconnaissance sub-technique of T1592 (Gather Victim Host Information). Adversaries may gather information about the victim's client configurations that can be used during targeting. Information about client configurations...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1592-004-client-configurations
- T1593 Search Open Websites/Domains
An Enterprise Reconnaissance technique. Adversaries may search freely available websites and/or domains for information about victims that can be used during targeting. Information about victims may be available in various online sites,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1593-search-open-websites-domains
- T1593.001 Social Media
An Enterprise Reconnaissance sub-technique of T1593 (Search Open Websites/Domains). Adversaries may search social media for information about victims that can be used during targeting. Social media sites may contain various information...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1593-001-social-media
- T1593.002 Search Engines
An Enterprise Reconnaissance sub-technique of T1593 (Search Open Websites/Domains). Adversaries may use search engines to collect information about victims that can be used during targeting. Search engine services typical crawl online...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1593-002-search-engines
- T1593.003 Code Repositories
An Enterprise Reconnaissance sub-technique of T1593 (Search Open Websites/Domains). Adversaries may search public code repositories for information about victims that can be used during targeting. Victims may store code in repositories...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1593-003-code-repositories
- T1594 Search Victim-Owned Websites
An Enterprise Reconnaissance technique. Adversaries may search websites owned by the victim for information that can be used during targeting. Victim-owned websites may contain a variety of details, including names of...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1594-search-victim-owned-websites
- T1595 Active Scanning
Adversary active scanning of target infrastructure to identify services, vulnerabilities, and entry points before attack. Sub-techniques include Scanning IP Blocks (T1595.001), Vulnerability Scanning (T1595.002), and Wordlist Scanning...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1595-active-scanning
- T1595.001 Scanning IP Blocks
An Enterprise Reconnaissance sub-technique of T1595 (Active Scanning). Adversaries may scan victim IP blocks to gather information that can be used during targeting. Public IP addresses may be allocated to organizations by block, or a...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1595-001-scanning-ip-blocks
- T1595.002 Vulnerability Scanning
An Enterprise Reconnaissance sub-technique of T1595 (Active Scanning). Adversaries may scan victims for vulnerabilities that can be used during targeting. Vulnerability scans typically check if the configuration of a target...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1595-002-vulnerability-scanning
- T1595.003 Wordlist Scanning
An Enterprise Reconnaissance sub-technique of T1595 (Active Scanning). Adversaries may iteratively probe infrastructure using brute-forcing and crawling techniques. While this technique employs similar methods to Brute Force, its goal...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1595-003-wordlist-scanning
- T1596 Search Open Technical Databases
An Enterprise Reconnaissance technique. Adversaries may search freely available technical databases for information about victims that can be used during targeting. Information about victims may be available in online databases and...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1596-search-open-technical-databases
- T1596.001 DNS/Passive DNS
An Enterprise Reconnaissance sub-technique of T1596 (Search Open Technical Databases). Adversaries may search DNS data for information about victims that can be used during targeting. DNS information may include a variety of details,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1596-001-dns-passive-dns
- T1596.002 WHOIS
An Enterprise Reconnaissance sub-technique of T1596 (Search Open Technical Databases). Adversaries may search public WHOIS data for information about victims that can be used during targeting. WHOIS data is stored by regional Internet...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1596-002-whois
- T1596.003 Digital Certificates
An Enterprise Reconnaissance sub-technique of T1596 (Search Open Technical Databases). Adversaries may search public digital certificate data for information about victims that can be used during targeting. Digital certificates are...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1596-003-digital-certificates
- T1596.004 CDNs
An Enterprise Reconnaissance sub-technique of T1596 (Search Open Technical Databases). Adversaries may search content delivery network (CDN) data about victims that can be used during targeting. CDNs allow an organization to host...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1596-004-cdns
- T1596.005 Scan Databases
An Enterprise Reconnaissance sub-technique of T1596 (Search Open Technical Databases). Adversaries may search within public scan databases for information about victims that can be used during targeting. Various online services...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1596-005-scan-databases
- T1597 Search Closed Sources
An Enterprise Reconnaissance technique. Adversaries may search and gather information about victims from closed (e.g., paid, private, or otherwise not freely available) sources that can be used during targeting. Information about...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1597-search-closed-sources
- T1597.001 Threat Intel Vendors
An Enterprise Reconnaissance sub-technique of T1597 (Search Closed Sources). Adversaries may search private data from threat intelligence vendors for information that can be used during targeting. Threat intelligence vendors may offer...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1597-001-threat-intel-vendors
- T1597.002 Purchase Technical Data
An Enterprise Reconnaissance sub-technique of T1597 (Search Closed Sources). Adversaries may purchase technical information about victims that can be used during targeting. Information about victims may be available for purchase within...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1597-002-purchase-technical-data
- T1598 Phishing for Information
An Enterprise Reconnaissance technique. Adversaries may send phishing messages to elicit sensitive information that can be used during targeting. Phishing for information is an attempt to trick targets into divulging information,...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1598-phishing-for-information
- T1598.001 Spearphishing Service
An Enterprise Reconnaissance sub-technique of T1598 (Phishing for Information). Adversaries may send spearphishing messages via third-party services to elicit sensitive information that can be used during targeting. Spearphishing for...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1598-001-spearphishing-service
- T1598.002 Spearphishing Attachment
An Enterprise Reconnaissance sub-technique of T1598 (Phishing for Information). Adversaries may send spearphishing messages with a malicious attachment to elicit sensitive information that can be used during targeting. Spearphishing for...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1598-002-spearphishing-attachment
- T1598.003 Spearphishing Link
An Enterprise Reconnaissance sub-technique of T1598 (Phishing for Information). Adversaries may send spearphishing messages with a malicious link to elicit sensitive information that can be used during targeting. Spearphishing for...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1598-003-spearphishing-link
- T1598.004 Spearphishing Voice
An Enterprise Reconnaissance sub-technique of T1598 (Phishing for Information). Adversaries may use voice communications to elicit sensitive information that can be used during targeting. Spearphishing for information is an attempt to...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1598-004-spearphishing-voice
- T1681 Search Threat Vendor Data
An Enterprise Reconnaissance technique. Threat actors may seek information/indicators from closed or open threat intelligence sources gathered about their own campaigns, as well as those conducted by other adversaries that may align...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1681-search-threat-vendor-data
- T1682 Query Public AI Services
An Enterprise Reconnaissance technique. Adversaries may query publicly accessible artificial intelligence (AI) services, such as large language models (LLMs), to support targeting and operations. In addition to searching websites or...
Bidda node: https://bidda.com/intelligence/mitre-attack-t1682-query-public-ai-services

Full interactive matrix: https://bidda.com/mitre-attack
MITRE source: https://attack.mitre.org/matrices/enterprise/

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.