ATT&CK Coverage
Techniques across the corpus
283 techniques mapped by the published reports and detection rules, laid out as the ATT&CK matrix (v19.2). Darker cells are mapped more often; the score is reports plus rules. Every cell opens a page listing exactly which reports, rules and tracked actors map that technique. Download the Navigator layer to open the same view in ATT&CK Navigator.
Reconnaissance11
T1589
Gather Victim Identity Information
1
T1589.001
Credentials
2
T1590.005
IP Addresses
1
T1592.004
Client Configurations
1
T1593.002
Search Engines
1
T1594
Search Victim-Owned Websites
1
T1595.001
Scanning IP Blocks
1
T1595.002
Vulnerability Scanning
9
T1595.003
Wordlist Scanning
1
T1596.003
Digital Certificates
1
T1596.005
Scan Databases
7
Resource Development23
T1583.001
Domains
11
T1583.003
Virtual Private Server
12
T1583.004
Server
4
T1583.006
Web Services
6
T1583.008
Malvertising
2
T1584.001
Domains
1
T1584.004
Server
2
T1585
Establish Accounts
2
T1585.001
Social Media Accounts
3
T1585.002
Email Accounts
2
T1585.003
Cloud Accounts
1
T1587
Develop Capabilities
12
T1587.001
Malware
19
T1587.002
Code Signing Certificates
1
T1587.003
Digital Certificates
2
T1587.004
Exploits
1
T1588.001
Malware
3
T1588.002
Tool
11
T1588.004
Digital Certificates
1
T1588.005
Exploits
5
T1608.001
Upload Malware
4
T1608.003
Install Digital Certificate
1
T1608.005
Link Target
4
Initial Access16
T1078
Valid Accounts
12
T1078.001
Default Accounts
1
T1078.002
Domain Accounts
3
T1078.003
Local Accounts
1
T1078.004
Cloud Accounts
1
T1091
Replication Through Removable Media
6
T1133
External Remote Services
4
T1189
Drive-by Compromise
2
T1190
Exploit Public-Facing Application
59
T1195.002
Compromise Software Supply Chain
1
T1199
Trusted Relationship
1
T1566
Phishing
1
T1566.001
Spearphishing Attachment
4
T1566.002
Spearphishing Link
6
T1566.003
Spearphishing via Service
1
T1566.004
Spearphishing Voice
2
Execution21
T1047
Windows Management Instrumentation
4
T1053.003
Cron
10
T1053.005
Scheduled Task
26
T1059
Command and Scripting Interpreter
5
T1059.001
PowerShell
36
T1059.003
Windows Command Shell
21
T1059.004
Unix Shell
28
T1059.005
Visual Basic
12
T1059.006
Python
29
T1059.007
JavaScript
11
T1106
Native API
11
T1127.001
MSBuild
3
T1129
Shared Modules
4
T1203
Exploitation for Client Execution
1
T1204
User Execution
1
T1204.002
Malicious File
9
T1204.004
Malicious Copy and Paste
4
T1559
Inter-Process Communication
1
T1569.002
Service Execution
4
T1574.001
DLL
4
T1574.006
Dynamic Linker Hijacking
14
Persistence31
T1037.004
RC Scripts
3
T1053.003
Cron
10
T1053.005
Scheduled Task
26
T1078
Valid Accounts
12
T1078.001
Default Accounts
1
T1078.002
Domain Accounts
3
T1078.003
Local Accounts
1
T1078.004
Cloud Accounts
1
T1098
Account Manipulation
9
T1098.004
SSH Authorized Keys
9
T1098.005
Device Registration
1
T1098.007
Additional Local or Domain Groups
1
T1112
Modify Registry
13
T1133
External Remote Services
4
T1136.001
Local Account
8
T1136.002
Domain Account
6
T1505.001
SQL Stored Procedures
6
T1505.003
Web Shell
30
T1542.001
System Firmware
2
T1542.003
Bootkit
3
T1543
Create or Modify System Process
2
T1543.002
Systemd Service
15
T1543.003
Windows Service
11
T1546.004
Unix Shell Configuration Modification
1
T1547
Boot or Logon Autostart Execution
2
T1547.001
Registry Run Keys / Startup Folder
32
T1547.004
Winlogon Helper DLL
4
T1547.006
Kernel Modules and Extensions
1
T1547.009
Shortcut Modification
6
T1554
Compromise Host Software Binary
5
T1653
Power Settings
1
Privilege Escalation36
T1037.004
RC Scripts
3
T1053.003
Cron
10
T1053.005
Scheduled Task
26
T1055
Process Injection
19
T1055.001
Dynamic-link Library Injection
1
T1055.002
Portable Executable Injection
7
T1055.003
Thread Execution Hijacking
6
T1055.008
Ptrace System Calls
1
T1055.012
Process Hollowing
16
T1055.015
ListPlanting
1
T1068
Exploitation for Privilege Escalation
10
T1078
Valid Accounts
12
T1078.001
Default Accounts
1
T1078.002
Domain Accounts
3
T1078.003
Local Accounts
1
T1078.004
Cloud Accounts
1
T1098
Account Manipulation
9
T1098.004
SSH Authorized Keys
9
T1098.005
Device Registration
1
T1098.007
Additional Local or Domain Groups
1
T1134
Access Token Manipulation
4
T1134.001
Token Impersonation/Theft
9
T1134.002
Create Process with Token
3
T1134.004
Parent PID Spoofing
5
T1543
Create or Modify System Process
2
T1543.002
Systemd Service
15
T1543.003
Windows Service
11
T1546.004
Unix Shell Configuration Modification
1
T1547
Boot or Logon Autostart Execution
2
T1547.001
Registry Run Keys / Startup Folder
32
T1547.004
Winlogon Helper DLL
4
T1547.006
Kernel Modules and Extensions
1
T1547.009
Shortcut Modification
6
T1548.001
Setuid and Setgid
1
T1548.002
Bypass User Account Control
13
T1611
Escape to Host
2
Stealth61
T1014
Rootkit
13
T1027
Obfuscated Files or Information
41
T1027.001
Binary Padding
1
T1027.002
Software Packing
13
T1027.005
Indicator Removal from Tools
1
T1027.007
Dynamic API Resolution
2
T1027.008
Stripped Payloads
1
T1027.009
Embedded Payloads
5
T1027.010
Command Obfuscation
4
T1027.011
Fileless Storage
5
T1027.013
Encrypted/Encoded File
10
T1036
Masquerading
12
T1036.001
Invalid Code Signature
1
T1036.002
Right-to-Left Override
1
T1036.004
Masquerade Task or Service
9
T1036.005
Match Legitimate Resource Name or Location
46
T1036.007
Double File Extension
1
T1036.008
Masquerade File Type
1
T1055
Process Injection
19
T1055.001
Dynamic-link Library Injection
1
T1055.002
Portable Executable Injection
7
T1055.003
Thread Execution Hijacking
6
T1055.008
Ptrace System Calls
1
T1055.012
Process Hollowing
16
T1055.015
ListPlanting
1
T1070
Indicator Removal
5
T1070.004
File Deletion
16
T1070.006
Timestomp
2
T1078
Valid Accounts
12
T1078.001
Default Accounts
1
T1078.002
Domain Accounts
3
T1078.003
Local Accounts
1
T1078.004
Cloud Accounts
1
T1127.001
MSBuild
3
T1134
Access Token Manipulation
4
T1134.001
Token Impersonation/Theft
9
T1134.002
Create Process with Token
3
T1134.004
Parent PID Spoofing
5
T1140
Deobfuscate/Decode Files or Information
27
T1218
System Binary Proxy Execution
1
T1218.004
InstallUtil
1
T1218.005
Mshta
1
T1218.007
Msiexec
3
T1218.008
Odbcconf
1
T1218.011
Rundll32
4
T1218.014
MMC
4
T1480
Execution Guardrails
6
T1480.002
Mutual Exclusion
2
T1497
Virtualization/Sandbox Evasion
10
T1497.001
System Checks
18
T1497.003
Time Based Checks
4
T1542.001
System Firmware
2
T1542.003
Bootkit
3
T1564.001
Hidden Files and Directories
11
T1564.002
Hidden Users
2
T1564.003
Hidden Window
3
T1574.001
DLL
4
T1574.006
Dynamic Linker Hijacking
14
T1620
Reflective Code Loading
33
T1622
Debugger Evasion
6
T1684.001
Impersonation
3
Defense Impairment8
T1112
Modify Registry
13
T1222.002
Linux and Mac Permissions
2
T1553.002
Code Signing
3
T1553.004
Install Root Certificate
2
T1553.005
Mark-of-the-Web Bypass
4
T1685
Disable or Modify Tools
38
T1686
Disable or Modify System Firewall
4
T1686.003
Windows Host Firewall
1
Credential Access31
T1003
OS Credential Dumping
1
T1003.001
LSASS Memory
6
T1003.002
Security Account Manager
7
T1003.003
NTDS
1
T1003.004
LSA Secrets
2
T1003.006
DCSync
1
T1056
Input Capture
1
T1056.001
Keylogging
15
T1056.002
GUI Input Capture
1
T1056.003
Web Portal Capture
1
T1110
Brute Force
3
T1110.001
Password Guessing
8
T1110.003
Password Spraying
7
T1110.004
Credential Stuffing
1
T1212
Exploitation for Credential Access
6
T1528
Steal Application Access Token
4
T1539
Steal Web Session Cookie
11
T1552.001
Credentials In Files
12
T1552.004
Private Keys
3
T1552.005
Cloud Instance Metadata API
7
T1555
Credentials from Password Stores
4
T1555.003
Credentials from Web Browsers
18
T1555.004
Windows Credential Manager
1
T1555.005
Password Managers
2
T1557
Adversary-in-the-Middle
2
T1558.001
Golden Ticket
1
T1558.003
Kerberoasting
2
T1558.004
AS-REP Roasting
1
T1606
Forge Web Credentials
1
T1606.001
Web Cookies
2
T1649
Steal or Forge Authentication Certificates
1
Discovery25
T1007
System Service Discovery
1
T1010
Application Window Discovery
2
T1012
Query Registry
2
T1016
System Network Configuration Discovery
5
T1016.001
Internet Connection Discovery
1
T1018
Remote System Discovery
4
T1033
System Owner/User Discovery
6
T1046
Network Service Discovery
13
T1049
System Network Connections Discovery
2
T1057
Process Discovery
14
T1069.002
Domain Groups
3
T1082
System Information Discovery
22
T1083
File and Directory Discovery
9
T1087
Account Discovery
2
T1087.002
Domain Account
3
T1135
Network Share Discovery
3
T1482
Domain Trust Discovery
3
T1497
Virtualization/Sandbox Evasion
10
T1497.001
System Checks
18
T1497.003
Time Based Checks
4
T1518
Software Discovery
1
T1518.001
Security Software Discovery
7
T1538
Cloud Service Dashboard
1
T1614
System Location Discovery
2
T1622
Debugger Evasion
6
Lateral Movement12
T1021
Remote Services
3
T1021.001
Remote Desktop Protocol
4
T1021.002
SMB/Windows Admin Shares
9
T1021.004
SSH
8
T1021.005
VNC
1
T1021.006
Windows Remote Management
4
T1091
Replication Through Removable Media
6
T1210
Exploitation of Remote Services
1
T1534
Internal Spearphishing
1
T1550.003
Pass the Ticket
1
T1563.002
RDP Hijacking
1
T1570
Lateral Tool Transfer
6
Collection18
T1005
Data from Local System
14
T1056
Input Capture
1
T1056.001
Keylogging
15
T1056.002
GUI Input Capture
1
T1056.003
Web Portal Capture
1
T1074.001
Local Data Staging
2
T1113
Screen Capture
19
T1115
Clipboard Data
7
T1119
Automated Collection
11
T1123
Audio Capture
7
T1125
Video Capture
6
T1185
Browser Session Hijacking
3
T1213
Data from Information Repositories
7
T1213.002
Sharepoint
1
T1530
Data from Cloud Storage
2
T1557
Adversary-in-the-Middle
2
T1560
Archive Collected Data
3
T1602.002
Network Device Configuration Dump
1
Command and Control31
T1001
Data Obfuscation
1
T1008
Fallback Channels
1
T1071
Application Layer Protocol
5
T1071.001
Web Protocols
114
T1071.002
File Transfer Protocols
3
T1071.003
Mail Protocols
1
T1071.004
DNS
3
T1090
Proxy
6
T1090.001
Internal Proxy
13
T1090.002
External Proxy
7
T1090.003
Multi-hop Proxy
10
T1090.004
Domain Fronting
6
T1095
Non-Application Layer Protocol
19
T1102
Web Service
9
T1102.001
Dead Drop Resolver
11
T1102.002
Bidirectional Communication
5
T1104
Multi-Stage Channels
1
T1105
Ingress Tool Transfer
43
T1132
Data Encoding
1
T1132.001
Standard Encoding
14
T1132.002
Non-Standard Encoding
1
T1219
Remote Access Tools
16
T1219.002
Remote Desktop Software
1
T1568
Dynamic Resolution
1
T1568.002
Domain Generation Algorithms
2
T1571
Non-Standard Port
19
T1572
Protocol Tunneling
32
T1573
Encrypted Channel
6
T1573.001
Symmetric Cryptography
19
T1573.002
Asymmetric Cryptography
9
T1665
Hide Infrastructure
1
Exfiltration5
T1020
Automated Exfiltration
3
T1041
Exfiltration Over C2 Channel
29
T1048.003
Exfiltration Over Unencrypted Non-C2 Protocol
4
T1567
Exfiltration Over Web Service
1
T1567.002
Exfiltration to Cloud Storage
6
Impact15
T1485
Data Destruction
3
T1486
Data Encrypted for Impact
6
T1489
Service Stop
4
T1490
Inhibit System Recovery
5
T1491.001
Internal Defacement
3
T1496
Resource Hijacking
3
T1496.001
Compute Hijacking
12
T1498
Network Denial of Service
1
T1498.001
Direct Network Flood
7
T1498.002
Reflection Amplification
3
T1499
Endpoint Denial of Service
1
T1529
System Shutdown/Reboot
3
T1531
Account Access Removal
2
T1565.001
Stored Data Manipulation
1
T1657
Financial Theft
14
No technique matches that filter.
A technique that belongs to more than one tactic appears in each of its columns. The matrix lists only techniques something on the site maps, so an empty tactic is a gap in the corpus, not in the matrix.
Most mapped techniques
T1071.001Web Protocols 28 reports, 86 rules, 18 actorsT1190Exploit Public-Facing Application 11 reports, 48 rules, 7 actorsT1036.005Match Legitimate Resource Name or Location 14 reports, 32 rules, 13 actorsT1105Ingress Tool Transfer 17 reports, 26 rules, 14 actorsT1027Obfuscated Files or Information 19 reports, 22 rules, 17 actorsT1685Disable or Modify Tools 13 reports, 25 rules, 9 actorsT1059.001PowerShell 15 reports, 21 rules, 12 actorsT1620Reflective Code Loading 13 reports, 20 rules, 10 actorsT1572Protocol Tunneling 10 reports, 22 rules, 14 actorsT1547.001Registry Run Keys / Startup Folder 15 reports, 17 rules, 6 actorsT1505.003Web Shell 7 reports, 23 rules, 6 actorsT1059.006Python 5 reports, 24 rules, 10 actorsT1041Exfiltration Over C2 Channel 17 reports, 12 rules, 13 actorsT1059.004Unix Shell 7 reports, 21 rules, 10 actorsT1140Deobfuscate/Decode Files or Information 14 reports, 13 rules, 13 actors
MITRE ATT&CK® is a registered trademark of The MITRE Corporation. The heatmap is built from each report's own ATT&CK mapping table and each detection page's coverage lines; it is this publication's reading of its own evidence, not a measure of how common a technique is in the wild.