Loading
Loading
Reference library
Adversary behavior. This is a curated subset of MITRE ATT&CK, kept so a detection has a specific technique to catch. D3FEND is the countermeasure set. ATLAS covers attacks on AI and ML systems and is not folded into these tactics.
01
Gathering information to plan future adversary operations.
No techniques in this subset
02
Establishing resources to support operations.
No techniques in this subset
03
Techniques to gain an initial foothold within a network.
04
Running malicious code on a local or remote system.
05
Maintaining presence across system restarts and credential changes.
06
Gaining higher-level permissions on a system or network.
07
Avoiding detection throughout an operation.
08
Stealing credentials like account names and passwords.
09
Gaining knowledge about the system and internal network.
No techniques in this subset
10
Moving through the environment to reach objectives.
11
Gathering data of interest for exfiltration.
No techniques in this subset
12
Communicating with compromised systems to control them.
13
Stealing data from the network.
No techniques in this subset
14
Disrupting availability or compromising integrity.
Public MITRE knowledge bases. ATT&CK for adversary behavior, D3FEND for defensive countermeasures, ATLAS for attacks on AI and ML systems.