MITRE ATT&CK Technique Hub
Every MITRE ATT&CK technique cross-referenced against the IntelFusions graph: which detection rules cover it, which malware implements it, and which threat actors use it.
Techniques
- T1001 — Data Obfuscation
- T1003 — OS Credential Dumping
- T1005 — Data from Local System
- T1006 — Direct Volume Access
- T1007 — System Service Discovery
- T1008 — Fallback Channels
- T1010 — Application Window Discovery
- T1011 — Exfiltration Over Other Network Medium
- T1012 — Query Registry
- T1014 — Rootkit
- T1016 — System Network Configuration Discovery
- T1018 — Remote System Discovery
- T1020 — Automated Exfiltration
- T1021 — Remote Services
- T1025 — Data from Removable Media
- T1027 — Obfuscated Files or Information
- T1029 — Scheduled Transfer
- T1030 — Data Transfer Size Limits
- T1033 — System Owner/User Discovery
- T1036 — Masquerading
- T1037 — Boot or Logon Initialization Scripts
- T1039 — Data from Network Shared Drive
- T1040 — Network Sniffing
- T1041 — Exfiltration Over C2 Channel
- T1046 — Network Service Discovery
- T1047 — Windows Management Instrumentation
- T1048 — Exfiltration Over Alternative Protocol
- T1049 — System Network Connections Discovery
- T1052 — Exfiltration Over Physical Medium
- T1053 — Scheduled Task/Job
- T1055 — Process Injection
- T1056 — Input Capture
- T1057 — Process Discovery
- T1059 — Command and Scripting Interpreter
- T1068 — Exploitation for Privilege Escalation
- T1069 — Permission Groups Discovery
- T1070 — Indicator Removal
- T1071 — Application Layer Protocol
- T1072 — Software Deployment Tools
- T1074 — Data Staged
- T1078 — Valid Accounts
- T1080 — Taint Shared Content
- T1082 — System Information Discovery
- T1083 — File and Directory Discovery
- T1087 — Account Discovery
- T1090 — Proxy
- T1091 — Replication Through Removable Media
- T1092 — Communication Through Removable Media
- T1095 — Non-Application Layer Protocol
- T1098 — Account Manipulation