Skip to content
THE HUNTER’S LEDGER
ATT&CK Coverage
Techniques across the corpus
283 techniques mapped by the published reports and detection rules, laid out as the ATT&CK matrix (v19.2). Darker cells are mapped more often; the score is reports plus rules. Every cell opens a page listing exactly which reports, rules and tracked actors map that technique. Download the Navigator layer to open the same view in ATT&CK Navigator.
Stealth61
T1014 Rootkit 13 T1027 Obfuscated Files or Information 41 T1027.001 Binary Padding 1 T1027.002 Software Packing 13 T1027.005 Indicator Removal from Tools 1 T1027.007 Dynamic API Resolution 2 T1027.008 Stripped Payloads 1 T1027.009 Embedded Payloads 5 T1027.010 Command Obfuscation 4 T1027.011 Fileless Storage 5 T1027.013 Encrypted/Encoded File 10 T1036 Masquerading 12 T1036.001 Invalid Code Signature 1 T1036.002 Right-to-Left Override 1 T1036.004 Masquerade Task or Service 9 T1036.005 Match Legitimate Resource Name or Location 46 T1036.007 Double File Extension 1 T1036.008 Masquerade File Type 1 T1055 Process Injection 19 T1055.001 Dynamic-link Library Injection 1 T1055.002 Portable Executable Injection 7 T1055.003 Thread Execution Hijacking 6 T1055.008 Ptrace System Calls 1 T1055.012 Process Hollowing 16 T1055.015 ListPlanting 1 T1070 Indicator Removal 5 T1070.004 File Deletion 16 T1070.006 Timestomp 2 T1078 Valid Accounts 12 T1078.001 Default Accounts 1 T1078.002 Domain Accounts 3 T1078.003 Local Accounts 1 T1078.004 Cloud Accounts 1 T1127.001 MSBuild 3 T1134 Access Token Manipulation 4 T1134.001 Token Impersonation/Theft 9 T1134.002 Create Process with Token 3 T1134.004 Parent PID Spoofing 5 T1140 Deobfuscate/Decode Files or Information 27 T1218 System Binary Proxy Execution 1 T1218.004 InstallUtil 1 T1218.005 Mshta 1 T1218.007 Msiexec 3 T1218.008 Odbcconf 1 T1218.011 Rundll32 4 T1218.014 MMC 4 T1480 Execution Guardrails 6 T1480.002 Mutual Exclusion 2 T1497 Virtualization/Sandbox Evasion 10 T1497.001 System Checks 18 T1497.003 Time Based Checks 4 T1542.001 System Firmware 2 T1542.003 Bootkit 3 T1564.001 Hidden Files and Directories 11 T1564.002 Hidden Users 2 T1564.003 Hidden Window 3 T1574.001 DLL 4 T1574.006 Dynamic Linker Hijacking 14 T1620 Reflective Code Loading 33 T1622 Debugger Evasion 6 T1684.001 Impersonation 3

A technique that belongs to more than one tactic appears in each of its columns. The matrix lists only techniques something on the site maps, so an empty tactic is a gap in the corpus, not in the matrix.

Most mapped techniques

  1. T1071.001 Web Protocols 28 reports, 86 rules, 18 actors
  2. T1190 Exploit Public-Facing Application 11 reports, 48 rules, 7 actors
  3. T1036.005 Match Legitimate Resource Name or Location 14 reports, 32 rules, 13 actors
  4. T1105 Ingress Tool Transfer 17 reports, 26 rules, 14 actors
  5. T1027 Obfuscated Files or Information 19 reports, 22 rules, 17 actors
  6. T1685 Disable or Modify Tools 13 reports, 25 rules, 9 actors
  7. T1059.001 PowerShell 15 reports, 21 rules, 12 actors
  8. T1620 Reflective Code Loading 13 reports, 20 rules, 10 actors
  9. T1572 Protocol Tunneling 10 reports, 22 rules, 14 actors
  10. T1547.001 Registry Run Keys / Startup Folder 15 reports, 17 rules, 6 actors
  11. T1505.003 Web Shell 7 reports, 23 rules, 6 actors
  12. T1059.006 Python 5 reports, 24 rules, 10 actors
  13. T1041 Exfiltration Over C2 Channel 17 reports, 12 rules, 13 actors
  14. T1059.004 Unix Shell 7 reports, 21 rules, 10 actors
  15. T1140 Deobfuscate/Decode Files or Information 14 reports, 13 rules, 13 actors

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. The heatmap is built from each report's own ATT&CK mapping table and each detection page's coverage lines; it is this publication's reading of its own evidence, not a measure of how common a technique is in the wild.