Attack path: CVE-2026-54665
Where this CVE sits in the complete attacker lifecycle.
0 techniques directly attributed and 7 inferred, across 4 phases. Each technique shows its mapping confidence; follow-on techniques come from shared-actor co-occurrence.
Highlighted from CVE-2026-54665 · primary technique T1134
Reconnaissance
·
Resource Dev
Persistence
T1136.003
34.0x
Cloud Account
✓ detection content available
T1098.001
13.6x
Additional Cloud Credentials
✓ detection content available
T1098.005
11.3x
Device Registration
✓ detection content available
T1098.002
10.2x
Additional Email Delegate Permissions
T1137.006
4.4x
Add-ins
✓ detection content available
T1037.003
4.4x
Network Logon Script
Priv Escalation
Stealth
T1134
inferred
Access Token Manipulation
✓ detection content available
T1134.001
inferred
Token Impersonation/Theft
✓ detection content available
T1070.006
6.8x
Timestomp
✓ detection content available
T1134.002
4.4x
Create Process with Token
✓ detection content available
T1562.006
4.4x
Indicator Blocking
T1027.007
4.4x
Dynamic API Resolution
T1027.013
1.7x
Encrypted/Encoded File
T1027.005
Indicator Removal from Tools
✓ detection content available
Defense Impairment
Credential Access
T1557.002
inferred
ARP Cache Poisoning
T1528
inferred
Steal Application Access Token
✓ detection content available
T1539
inferred
Steal Web Session Cookie
✓ detection content available
T1606.002
20.4x
SAML Tokens
T1606.001
20.4x
Web Cookies
T1606
12.8x
Forge Web Credentials
✓ detection content available
T1557
11.3x
Adversary-in-the-Middle
✓ detection content available
T1003.003
4.7x
NTDS
✓ detection content available
Discovery
T1526
34.0x
Cloud Service Discovery
✓ detection content available
T1087.004
20.4x
Cloud Account
✓ detection content available
T1069.001
14.4x
Local Groups
✓ detection content available
T1069.002
7.9x
Domain Groups
✓ detection content available
T1580
3.7x
Cloud Infrastructure Discovery
✓ detection content available
T1087.003
3.7x
Email Account
Lateral Movement
Collection
T1213.002
22.7x
Sharepoint
T1074.002
14.9x
Remote Data Staging
T1114.003
12.4x
Email Forwarding Rule
✓ detection content available
T1213.003
10.5x
Code Repositories
✓ detection content available
T1213.006
4.4x
Databases
T1560.002
4.4x
Archive via Library
T1056.002
3.7x
GUI Input Capture
✓ detection content available
T1185
3.3x
Browser Session Hijacking
✓ detection content available
C2
T1571
6.6x
Non-Standard Port
✓ detection content available
T1219
4.7x
Remote Access Tools
✓ detection content available
T1104
4.4x
Multi-Stage Channels
T1008
4.4x
Fallback Channels
✓ detection content available
T1102.002
2.8x
Bidirectional Communication
✓ detection content available
T1568.002
1.6x
Domain Generation Algorithms
✓ detection content available
T1102
Web Service
✓ detection content available
Exfiltration
Impact
Want your real detection gaps for this chain?
Declare your detection stack - your rules, telemetry, and techniques - and we will show exactly which of these techniques you cannot see. We do not grade you against a public rule corpus, only against what you actually run.
Direct - an ATT&CK/nuclei source names this CVE
Inferred - derived via CWE/CAPEC (lower confidence, may be off)
Likely follow-on (shared-actor co-occurrence)
✓We hold public detection content
Lift = how strongly a follow-on co-occurs with this CVE across shared threat actors (1x expected, 5x highly distinctive).
Hunt package
All 62 techniques in this view - Sigma rules, Atomic tests, and coverage in one place.