Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks
| Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Stealth | Defense Impairment | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
T1589 Gather Victim Identity Information |
T1538.008 Malvertising |
T1021.001 Remote Services: Remote Desktop Protocol |
T1047 Windows Management Instrumentation |
T1037 Boot or Logon Initialization Scripts |
T1053 Scheduled Task/Job |
T1006 Direct Volume Access |
T1112 Modify Registry |
T1003 OS Credential Dumping |
T1007 System Service Discovery |
T1021 Remote Services |
T1005 Data from Local System |
T1001 Data Obfuscation |
T1011 Exfiltration Over Other Network Medium |
T1485 Data Destruction |
|
T1589.001 Gather Victim Identity Information: Credentials |
T1583 Acquire Infrastructure |
T1078 Valid Accounts |
T1053 Scheduled Task/Job |
T1053 Scheduled Task/Job |
T1053.005 Scheduled Task/Job: Scheduled Task |
T1014 Rootkit |
T1484.001 Domain or Tenant Policy Modification: Group Policy Modification |
T1003.001 OS Credential Dumping: LSASS Memory |
T1010 Application Window Discovery |
T1021.001 Remote Services: Remote Desktop Protocol |
T1039 Data from Network Shared Drive |
T1001.001 Data Obfuscation: Junk Data |
T1011.001 Exfiltration Over Other Network Medium: Exfiltration Over Bluetooth |
T1486 Data Encrypted for Impact |
|
T1589.002 Gather Victim Identity Information: Email Addresses |
T1583.001 Acquire Infrastructure: Domains |
T1078 Valid Accounts: Remote Desktop Protocol |
T1053.005 Scheduled Task/Job: Scheduled Task |
T1053.003 Scheduled Task/Job: Cron |
T1055 Process Injection |
T1021.001 Remote Services: Remote Desktop Protocol |
T1553.002 Subvert Trust Controls: Code Signing |
T1003.002 OS Credential Dumping: Security Account Manager |
T1012 Query Registry |
T1021.001 Remote Desktop Protocol |
T1056 Input Capture |
T1001.003 Data Obfuscation: Protocol or Service Impersonation |
T1020 Automated Exfiltration |
T1489 Service Stop |
|
T1590.004 Gather Victim Network Information: Network Topology |
T1583.003 Acquire Infrastructure: Virtual Private Server |
T1078.002 Valid Accounts: Domain Accounts |
T1059 Command and Scripting Interpreter |
T1053.005 Scheduled Task/Job: Scheduled Task |
T1055.003 Thread Execution Hijacking |
T1027 Obfuscated Files or Information |
T1578.002 Modify Cloud Compute Infrastructure: Create Cloud Instance |
T1003.003 OS Credential Dumping: NTDS |
T1016 System Network Configuration Discovery |
T1021.002 Remote Services: SMB/Windows Admin Shares |
T1074 Data Staged |
T1008 Fallback Channels |
T1020 Automated Exfiltration; Exfiltration Over Web Service |
T1490 Inhibit System Recovery |
|
T1591 Gather Victim Org Information |
T1583.004 Acquire Infrastructure: Server |
T1078.003 Valid Accounts: Local Accounts |
T1059.001 Command and Scripting Interpreter: PowerShell |
T1078 Valid Accounts |
T1055.012 Process Injection: Process Hollowing |
T1027.001 Obfuscated Files or Information: Binary Padding |
T1578.003 Modify Cloud Compute Infrastructure: Delete Cloud Instance |
T1003.006 OS Credential Dumping: DCSync |
T1016.001 Network Configuration Discovery: Network Connection Enumeration |
T1021.002 SMB/Windows Admin Shares |
T1074.001 Data Staged: Local Data Staging |
T1071 Application Layer Protocol |
T1030 Data Transfer Size Limits |
T1491 Defacement |
|
T1591.002 Gather Victim Org Information: Business Relationships |
T1583.006 Acquire Infrastructure: Web Services |
T1078.004 Valid Accounts: Cloud Accounts |
T1059.001 PowerShell |
T1078.002 Valid Accounts: Domain Accounts |
T1068 Exploitation for Privilege Escalation |
T1027.002 Software Packing |
T1685 Disable or Modify Tools |
T1003.008 OS Credential Dumping: /etc/passwd and /etc/shadow |
T1016.001 Internet Connection Discovery |
T1021.004 Remote Services: SSH |
T1113 Screen Capture |
T1071.001 Application Layer Protocol: Web Protocols |
T1041 Exfiltration Over C2 Channel |
T1491.001 Defacement: Internal Defacement |
|
T1591.004 Gather Victim Org Information: Identify Roles |
T1584.001 Compromise Infrastructure: Domains |
T1091 Replication Through Removable Media |
T1059.002 System Services: Service Execution |
T1078.003 Valid Accounts: Local Accounts |
T1078 Valid Accounts |
T1027.002 Obfuscated Files or Information: Software Packing |
T1685.005 Disable or Modify Tools: Clear Windows Event Logs |
T1021.002 Remote Services: External Remote Services |
T1018 Remote System Discovery |
T1047 Windows Management Instrumentation |
T1114 Email Collection |
T1071.001 Web Protocols |
T1048 Exfiltration Over Alternative Protocol |
T1498 Network Denial of Service |
|
T1593.001 Search Open Websites/Domains: Social Media |
T1584.002 Compromise Infrastructure: DNS Server |
T1110 Brute Force |
T1059.003 Command and Scripting Interpreter: Windows Command Shell |
T1078.004 Valid Accounts: Cloud Accounts |
T1078.002 Valid Accounts: Domain Accounts |
T1027.005 Indicator Removal from Tools |
T1686 Disable or Modify System Firewall |
T1040 Network Sniffing |
T1033 System Owner/User Discovery |
T1072 Software Deployment Tools |
T1114.002 Email Collection: Remote Email Collection |
T1071.004 Application Layer Protocol: DNS |
T1048.001 Exfiltration Over Alternative Protocol: Exfiltration Over Symmetric Encrypted Non-C2 Protocol |
T1529 System Shutdown/Reboot |
|
T1593.003 Search Open Websites/Domains: Code Repositories |
T1584.004 Compromise Infrastructure: Server |
T1110.003 Brute Force: Password Spraying |
T1059.004 Command and Scripting Interpreter: Unix Shell |
T1098 Account Manipulation |
T1078.002 Domain Accounts |
T1027.005 Obfuscated Files or Information: Indicator Removal from Tools |
T1686.003 Disable or Modify System Firewall: Windows Host Firewall |
T1056 Input Capture |
T1040 Network Sniffing |
T1078.002 Valid Accounts: Domain Accounts |
T1114.003 Email Collection: Email Forwarding Rule |
T1090 Proxy |
T1048.002 Exfiltration Over Alternative Protocol: Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
T1531 Account Access Removal |
|
T1595 Active Scanning |
T1585.001 Establish Accounts: Social Media Accounts |
T1133 External Remote Services |
T1059.005 Command and Scripting Interpreter: Visual Basic |
T1098.003 Account Manipulation: Additional Cloud Credentials |
T1078.003 Valid Accounts: Local Accounts |
T1027.006 Obfuscated Files or Information: HTML Smuggling |
T1690 Prevent Command History Logging |
T1056.001 Input Capture: Keylogging |
T1046 Network Service Discovery |
T1080 Taint Shared Content |
T1119 Automated Collection |
T1090.001 Proxy: Internal Proxy |
T1048.002 Exfiltration Over Alternative Protocol: Asymmetric Encrypted Non-C2 Protocol |
T1561 Disk Wipe |
|
T1595.002 Active Scanning: Vulnerability Scanning |
T1585.002 Establish Accounts: Email Accounts |
T1189 Drive-by Compromise |
T1059.006 Command and Scripting Interpreter: Python |
T1098.003 Account Manipulation: Additional Cloud Roles |
T1078.004 Valid Accounts: Cloud Accounts |
T1027.007 Obfuscated Files or Information: Dynamic API Resolution |
T1110 Brute Force |
T1046 Network Service Scanning |
T1091 Replication Through Removable Media |
T1123 Audio Capture |
T1090.002 Proxy: External Proxy |
T1048.003 Exfiltration Over Alternative Protocol: Exfiltration Over Unencrypted Non-C2 Protocol |
T1561.001 Disk Wipe: Disk Content Wipe |
|
|
T1597.002 Search Closed Sources: Purchase Technical Data |
T1586 Compromise Accounts |
T1190 Exploit Public-Facing Application |
T1064 Scripting |
T1098.004 Account Manipulation: SSH Authorized Keys |
T1098 Account Manipulation |
T1027.009 Embedded Payloads |
T1110.001 Brute Force: Password Guessing |
T1049 System Network Connections Discovery |
T1210 Exploitation of Remote Services |
T1125 Video Capture |
T1090.003 Multi-hop Proxy |
T1048.003 Exfiltration Over Alternative Protocol: Unencrypted Non-C2 Protocol |
T1561.002 Disk Wipe: Disk Structure Wipe |
|
|
T1598 Phishing for Information |
T1586.002 Compromise Accounts: Email Accounts |
T1195 Supply Chain Compromise |
T1072 Software Deployment Tools |
T1112 Modify Registry |
T1098.003 Account Manipulation: Additional Cloud Roles |
T1027.009 Obfuscated Files or Information: Embedded Payloads |
T1110.002 Brute Force: Password Cracking |
T1057 Process Discovery |
T1333 External Remote Services |
T1213 Data from Information Repositories |
T1090.003 Proxy: Multi-hop Proxy |
T1052.001 Exfiltration over USB |
T1657 Financial Theft |
|
|
T1598.002 Phishing for Information: Spearphishing Attachment |
T1586.004 Establish Accounts: Phone/SIM |
T1199 Trusted Relationship |
T1106 Native API |
T1133 External Remote Services |
T1134 Access Token Manipulation |
T1027.010 Obfuscated Files or Information: Command Obfuscation |
T1110.003 Brute Force: Password Spraying |
T1069 Permission Groups Discovery |
T1534 Internal Spearphishing |
T1213.001 Data from Information Repositories: Confluence |
T1095 Non-Application Layer Protocol |
T1052.001 Exfiltration Over Physical Medium: Exfiltration over USB |
||
|
T1598.004 Spearphishing Voice |
T1587 Develop Capabilities |
T1210 Exploitation of Remote Services |
T1129 Shared Modules |
T1136 Create Account |
T1134.001 Token Impersonation/Theft |
T1027.011 Obfuscated Files or Information: Fileless Storage |
T1110.004 Brute Force: Credential Stuffing |
T1069.002 Permission Groups Discovery: Domain Groups |
T1550 Use Alternate Authentication Material |
T1213.002 Data from Information Repositories: Sharepoint |
T1102 Web Service |
T1537 Transfer Data to Cloud Account |
||
|
T1598.004 Phishing for Information: Spearphishing Voice |
T1587.001 Develop Capabilities: Malware |
T1548.002 Abusing Elevation Control Mechanism: Bypass User Account Control |
T1203 Exploitation for Client Execution |
T1136.001 Create Account: Local Account |
T1134.002 Access Token Manipulation: Create Process with Token |
T1027.013 Obfuscated Files or Information: Encrypted/Encoded File |
T1111 Multi-Factor Authentication Interception |
T1082 System Information Discovery |
T1550.002 Use Alternate Authentication Material: Pass the Hash |
T1213.003 Data from Information Repositories: Code Repositories |
T1102.002 Web Service: Bidirectional Communication |
T1567 Exfiltration Over Web Service |
||
|
T1587.002 Develop Capabilities: Code Signing Certificates |
T1552.004 Unsecured Credentials: Private Keys |
T1204 User Execution |
T1136.002 Create Account: Domain Account |
T1134.003 Access Token Manipulation: Make and Impersonate Token |
T1027.015 Obfuscated Files or Information: Compression |
T1212 Exploitation for Credential Access |
T1083 File and Directory Discovery |
T1563 Remote Service Session Hijacking |
T1213.005 Data from Information Repositories: Messaging Applications |
T1104 Multi-Stage Channels |
T1567.002 Exfiltration Over Web Service: Exfiltration to Cloud Storage |
|||
|
T1588.001 Obtain Capabilities: Malware |
T1566 Phishing |
T1204.001 User Execution: Malicious Link |
T1136.003 Create Account: Cloud Account |
T1134.004 Parent PID Spoofing |
T1027.016 Obfuscated Files or Information: Junk Code Insertion |
T1539 Steal Web Session Cookie |
T1087 Account Discovery |
T1570 Lateral Tool Transfer |
T1530 Data from Cloud Storage |
T1105 Ingress Tool Transfer |
T1567.002 Exfiltration to Cloud Storage |
|||
|
T1588.002 Obtain Capabilities: Tool |
T1566.001 Phishing: Spearphishing Attachment |
T1204.002 User Execution: Malicious File |
T1505.003 Server Software Component: Web Shell |
T1134.004 Access Token Manipulation: Parent PID Spoofing |
T1036 Masquerading |
T1552 Unsecured Credentials |
T1087.001 Account Discovery: Local Account |
T1570 Tool Transfer |
T1560 Archive Collected Data |
T1132.001 Data Encoding: Standard Encoding |
T1567.004 Exfiltration Over Webhook |
|||
|
T1588.003 Obtain Capabilities: Code Signing Certificates |
T1566.001 Phishing: Spear phishing Attachment |
T1204.004 User Execution: Malicious Copy and Paste |
T1505.004 Server Software Component: IIS Components |
T1136 Create Account: Cloud Account |
T1036.001 Masquerading: invalid code signature |
T1552.001 Unsecured Credentials: Credentials In Files |
T1087.002 Account Discovery: Domain Account |
T1560.001 Archive Collected Data: Archive via Utility |
T1219 Remote Access Tools |
|||||
|
T1588.004 Obtain Capabilities: Digital Certificates |
T1566.001 Phishing: Spear-phishing attachment |
T1218.007 Signed Binary Proxy Execution: Msiexec |
T1542.003 Pre-OS Boot: Bootkit |
T1187 Forced Authentication |
T1036.003 Masquerading: Rename Legitimate Utilities |
T1552.002 Unsecured Credentials: Credentials in Registry |
T1119 Automated Collection |
T1560.002 Archive Collected Data: Archive via Library |
T1219 Remote Desktop Protocol |
|||||
|
T1608.001 Stage Capabilities: Upload Malware |
T1566.002 Phishing: Spear phishing Link |
T1559.001 Inter-Process Communication: Component Object Model |
T1543 Create or Modify System Process |
T1484.001 Domain Policy Modification: Group Policy Modification |
T1036.004 Masquerading: Masquerade Task or Service |
T1552.008 Unsecured Credentials: Chat Messages |
T1120 Peripheral Device Discovery |
T1560.003 Archive Collected Data: Archive via Custom Method |
T1219.002 Remote Access Tools: Remote Desktop Software |
|||||
|
T1608.002 Stage Capabilities: Upload Tool |
T1566.002 Phishing: Spearphishing Link |
T1569 System Services |
T1543.003 Create or Modify System Process: Windows Service |
T1484.001 Domain or Tenant Policy Modification: Group Policy Modification |
T1036.005 Masquerading: Match Legitimate Resource Name or Location |
T1555 Credentials from Password Stores |
T1124 Time Discovery |
T1602.002 Network Device Configuration Dump |
T1219.002 Remote Access Software: Remote Desktop Software |
|||||
|
T1650 Acquire Access |
T1566.003 Phishing: Spearphishing Voice (Vishing) |
T1651 Cloud Administration Command |
T1543.003 Windows Services |
T1543 Create or Modify System Process |
T1036.005 Masquerading: Match Legitimate Name or Location |
T1555.003 Credentials from Web Browsers |
T1135 Network Share Discovery |
T1229 Remote Access Software |
||||||
|
T1566.003 Phishing: Spearphishing via Service |
T1675 ESXi Administration Command |
T1547 Boot or Logon Autostart Execution |
T1543.003 Create or Modify System Process: Windows Service |
T1036.007 Masquerading: Double File Extension |
T1555.003 Credentials from Password Stores: Credentials from Web Browsers |
T1482 Domain Trust Discovery |
T1571 Non-Standard Port |
|||||||
|
T1566.004 Phishing: Spearphishing Voice |
T1547 Server Software Component |
T1543.003 Service Execution |
T1036.008 Masquerading: Masquerade File Type |
T1555.005 Credentials from Password Stores: Password Managers |
T1497 Virtualization/Sandbox Evasion |
T1572 Protocol Tunneling |
||||||||
|
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys |
T1547 Boot or Logon Autostart Execution |
T1055 Process Injection |
T1557.001 Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning |
T1518 Software Discovery |
T1573 Encrypted Channel |
|||||||||
|
T1547.001 Registry Run Keys/Startup Folder |
T1547.001 Registry Run Keys/Startup Files |
T1055.001 Process injection: DLL injection |
T1558 Steal or Forge Kerberos Tickets |
T1518.001 Security Software Discovery |
T1573.001 Encrypted Channel: Symmetric Cryptography |
|||||||||
|
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder |
T1547.001 Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder |
T1055.003 Thread Execution Hijacking |
T1621 Multi-Factor Authentication Request Generation |
T1518.001 Software Discovery: Security Software Discovery |
T1573.002 Encrypted Channel: Asymmetric Cryptography |
|||||||||
|
T1547.001 Registry Run Keys / Startup Folder |
T1547.001 Registry Run Keys |
T1055.012 Process Injection: Process Hollowing |
T1649 Steal or Forge Authentication Certificates |
T1526 Cloud Service Discovery |
||||||||||
|
T1547.004 Boot or Logon Autostart Execution: Winlogon Helper DLL |
T1548 Abuse Elevation Control Mechanism |
T1064 Scripting |
T1538 Cloud Service Dashboard |
|||||||||||
|
T1547.009 Boot or Logon Autostart Execution: Shortcut Modification |
T1548.002 Abuse Elevation Control Mechanism: Bypass User Account Control |
T1068 Exploitation for Privilege Escalation |
T1580 Cloud Infrastructure Discovery |
|||||||||||
|
T1574.001 Hijack Execution Flow: DLL Search Order Hijacking |
T1548.002 Abuse Elevation Control Mechanism: Bypass UAC |
T1070 Indicator Removal |
T1614 System Location Discovery |
|||||||||||
|
T1548.002 Bypass User Account Control |
T1070.001 Indicator Removal: Clear Windows Event Logs |
T1614.001 System Location Discovery: System Language Discovery |
||||||||||||
|
T1557 Adversary-in-the-Middle |
T1070.001 Indicator removal on host: clear Windows event logs |
T1615 Group Policy Discovery |
||||||||||||
|
T1574 Hijack execution flow |
T1070.001 Clear Windows Event Logs |
T1652 Device Driver Discovery |
||||||||||||
|
T1574.001 Hijack Execution Flow: DLL Search Order Hijacking |
T1070.003 Indicator Removal: Clear Command History |
TA0007 Discovery |
||||||||||||
|
TA0004 Privilege Escalation |
T1070.004 File Deletion |
|||||||||||||
|
T1070.004 Indicator Removal: File Deletion |
||||||||||||||
|
T1070.004 Indicator removal on host: file deletion |
||||||||||||||
|
T1070.006 Indicator Removal: Timestomp |
||||||||||||||
|
T1078 Valid Accounts |
||||||||||||||
|
T1078.002 Valid Accounts: Domain Accounts |
||||||||||||||
|
T1078.002 Domain Accounts |
||||||||||||||
|
T1078.003 Valid Accounts: Local Accounts |
||||||||||||||
|
T1078.004 Valid Accounts: Cloud Accounts |
||||||||||||||
|
T1090 Proxy |
||||||||||||||
|
T1112 Modify Registry |
||||||||||||||
|
T1119 Automated Collection |
||||||||||||||
|
T1134 Access Token Manipulation |
||||||||||||||
|
T1134.001 Access Token Manipulation: Token Impersonation/Theft |
||||||||||||||
|
T1134.003 Access Token Manipulation: Make and Impersonate Token |
||||||||||||||
|
T1134.004 Access Token Manipulation: Parent PID Spoofing |
||||||||||||||
|
T1140 Deobfuscate/Decode Files or Information |
||||||||||||||
|
T1202 Indirect Command Execution |
||||||||||||||
|
T1211 Exploitation for Defense Evasion |
||||||||||||||
|
T1218 System Binary Proxy Execution |
||||||||||||||
|
T1218.004 System Binary Proxy Execution: InstallUtil |
||||||||||||||
|
T1218.005 System Binary Proxy Execution: Mshta |
||||||||||||||
|
T1218.007 System Binary Proxy Execution: Msiexec |
||||||||||||||
|
T1218.010 System Binary Proxy Execution: Regsvr32 |
||||||||||||||
|
T1218.011 Signed Binary Proxy Execution: Rundll32 |
||||||||||||||
|
T1218.011 System Binary Proxy Execution: Rundll32 |
||||||||||||||
|
T1218.014 System Binary Proxy Execution: MMC |
||||||||||||||
|
T1220 XSL Script Processing |
||||||||||||||
|
T1221 Template Injection |
||||||||||||||
|
T1222 File and Directory Permissions Modification |
||||||||||||||
|
T1222.001 File and Directory Permissions Modification: Windows Permissions |
||||||||||||||
|
T1480 Execution Guardrails |
||||||||||||||
|
T1484 Domain or Tenant Policy Modification |
||||||||||||||
|
T1484.001 Domain Policy Modification: Group Policy Modification |
||||||||||||||
|
T1484.001 Domain or Tenant Policy Modification: Group Policy Modification |
||||||||||||||
|
T1497 Virtualization/Sandbox Evasion |
||||||||||||||
|
T1497.001 Virtualization/Sandbox Evasion: System Checks |
||||||||||||||
|
T1497.003 Virtualization/Sandbox Evasion: Time Based Checks |
||||||||||||||
|
T1531 Account Access Removal |
||||||||||||||
|
T1548 Abuse Elevation Control Mechanism |
||||||||||||||
|
T1550.001 Use Alternate Authentication Material: Application Access Token |
||||||||||||||
|
T1550.004 Use Alternate Authentication Material: Web Session Cookie |
||||||||||||||
|
T1553.002 Subvert Trust Controls: Code Signing |
||||||||||||||
|
T1562 Impair Defenses |
||||||||||||||
|
T1562.001 Impair Defenses: Disable or Modify Tools |
||||||||||||||
|
T1562.001 Disable or Modify Tools |
||||||||||||||
|
T1562.004 Impair Defenses: Disable or Modify System Firewall |
||||||||||||||
|
T1562.004 Disable or Modify System Firewall Settings |
||||||||||||||
|
T1562.009 Safe Mode Boot |
||||||||||||||
|
T1564 Hidden Artifacts |
||||||||||||||
|
T1564 Hide Artifacts |
||||||||||||||
|
T1564.001 Hidden Files and Directories |
||||||||||||||
|
T1564.001 Hidden Artifacts: Hidden Files and Directories |
||||||||||||||
|
T1564.003 Hidden Window |
||||||||||||||
|
T1564.003 Hide Artifacts: Hidden Window |
||||||||||||||
|
T1564.003 Hidden Artifacts: Hidden Window |
||||||||||||||
|
T1564.004 NTFS File Attributes |
||||||||||||||
|
T1564.012 Hide Artifacts: File/Path Exclusions |
||||||||||||||
|
T1574 Hijack Execution Flow |
||||||||||||||
|
T1574.013 Hijack Execution Flow: KernelCallbackTable |
||||||||||||||
|
T1620 Reflective DLL Injection |
||||||||||||||
|
T1622 Debugger Evasion |
||||||||||||||
|
T1672 Email Spoofing |
||||||||||||||
|
T1678 Delay Execution |
||||||||||||||
|
T1679 Selective Exclusion |
||||||||||||||
|
T1684.001 Social Engineering: Impersonation |
Based on the MITRE ATT&CK® Enterprise Matrix v19 (April 2026).