Home/Detection coverage
ATT&CK

Detection coverage heatmap

407 of 697 techniques have detection coverage · 58%
Where can you actually see attacks happen, and where are you blind? Every enterprise ATT&CK technique is grouped by tactic and marked green when we hold detection content (Sigma / CAR / network-IDS / YARA / Falco) mapped to it, and red when there is no coverage - the gaps to close. Counts are honest: a technique is covered only when a real rule maps to it.
covered no coverage (gap) Sigma 3,765 · IDS 25,341 · CAR 278 · YARA 5 · Falco 80 rule-to-technique links
58% overall coverage - 407/697 techniques

Reconnaissance

11/46 covered · 23%

Execution

44/64 covered · 68%
T1053.006 · Systemd TimersT1053.007 · Container Orchestration JobT1059.008 · Network Device CLIT1059.010 · AutoHotKey & AutoITT1059.011 · LuaT1059.013 · Container CLI/APIT1127.002 · ClickOnceT1127.003 · JamPlusT1204.003 · Malicious ImageT1204.005 · Malicious LibraryT1559.003 · XPC ServicesT1569.003 · SystemctlT1574.004 · Dylib HijackingT1574.013 · KernelCallbackTableT1574.014 · AppDomainManagerT1648 · Serverless ExecutionT1651 · Cloud Administration CommandT1674 · Input InjectionT1675 · ESXi Administration CommandT1677 · Poisoned Pipeline ExecutionT1047 · Windows Management Instrumentation ✓T1053 · Scheduled Task/Job ✓T1053.002 · At ✓T1053.003 · Cron ✓T1053.005 · Scheduled Task ✓T1059 · Command and Scripting Interpreter ✓T1059.001 · PowerShell ✓T1059.002 · AppleScript ✓T1059.003 · Windows Command Shell ✓T1059.004 · Unix Shell ✓T1059.005 · Visual Basic ✓T1059.006 · Python ✓T1059.007 · JavaScript ✓T1059.009 · Cloud API ✓T1059.012 · Hypervisor CLI ✓T1072 · Software Deployment Tools ✓T1106 · Native API ✓T1127 · Trusted Developer Utilities Proxy Execution ✓T1127.001 · MSBuild ✓T1129 · Shared Modules ✓T1197 · BITS Jobs ✓T1203 · Exploitation for Client Execution ✓T1204 · User Execution ✓T1204.001 · Malicious Link ✓T1204.002 · Malicious File ✓T1204.004 · Malicious Copy and Paste ✓T1559 · Inter-Process Communication ✓T1559.001 · Component Object Model ✓T1559.002 · Dynamic Data Exchange ✓T1569 · System Services ✓T1569.001 · Launchctl ✓T1569.002 · Service Execution ✓T1574 · Hijack Execution Flow ✓T1574.001 · DLL ✓T1574.005 · Executable Installer File Permissions Weakness ✓T1574.006 · Dynamic Linker Hijacking ✓T1574.007 · Path Interception by PATH Environment Variable ✓T1574.008 · Path Interception by Search Order Hijacking ✓T1574.009 · Path Interception by Unquoted Path ✓T1574.010 · Services File Permissions Weakness ✓T1574.011 · Services Registry Permissions Weakness ✓T1574.012 · COR_PROFILER ✓T1609 · Container Administration Command ✓T1610 · Deploy Container ✓

Persistence

77/113 covered · 68%
T1037.002 · Login HookT1037.003 · Network Logon ScriptT1037.004 · RC ScriptsT1053.006 · Systemd TimersT1053.007 · Container Orchestration JobT1098.002 · Additional Email Delegate PermissionsT1098.006 · Additional Container Cluster RolesT1098.007 · Additional Local or Domain GroupsT1137.001 · Office Template MacrosT1137.004 · Outlook Home PageT1137.005 · Outlook RulesT1176 · Software ExtensionsT1176.002 · IDE ExtensionsT1205.002 · Socket FiltersT1505.006 · vSphere Installation BundlesT1542 · Pre-OS BootT1542.002 · Component FirmwareT1542.004 · ROMMONkitT1542.005 · TFTP BootT1543.005 · Container ServiceT1546.005 · TrapT1546.006 · LC_LOAD_DYLIB AdditionT1546.016 · Installer PackagesT1546.017 · Udev RulesT1546.018 · Python Startup HooksT1547.007 · Re-opened ApplicationsT1547.012 · Print ProcessorsT1547.013 · XDG Autostart EntriesT1556.001 · Domain Controller AuthenticationT1556.003 · Pluggable Authentication ModulesT1556.005 · Reversible EncryptionT1556.007 · Hybrid IdentityT1556.008 · Network Provider DLLT1556.009 · Conditional Access PoliciesT1668 · Exclusive ControlT1671 · Cloud Application IntegrationT1037 · Boot or Logon Initialization Scripts ✓T1037.001 · Logon Script (Windows) ✓T1037.005 · Startup Items ✓T1053 · Scheduled Task/Job ✓T1053.002 · At ✓T1053.003 · Cron ✓T1053.005 · Scheduled Task ✓T1078 · Valid Accounts ✓T1078.001 · Default Accounts ✓T1078.002 · Domain Accounts ✓T1078.003 · Local Accounts ✓T1078.004 · Cloud Accounts ✓T1098 · Account Manipulation ✓T1098.001 · Additional Cloud Credentials ✓T1098.003 · Additional Cloud Roles ✓T1098.004 · SSH Authorized Keys ✓T1098.005 · Device Registration ✓T1112 · Modify Registry ✓T1133 · External Remote Services ✓T1136 · Create Account ✓T1136.001 · Local Account ✓T1136.002 · Domain Account ✓T1136.003 · Cloud Account ✓T1137 · Office Application Startup ✓T1137.002 · Office Test ✓T1137.003 · Outlook Forms ✓T1137.006 · Add-ins ✓T1176.001 · Browser Extensions ✓T1197 · BITS Jobs ✓T1205 · Traffic Signaling ✓T1205.001 · Port Knocking ✓T1505 · Server Software Component ✓T1505.001 · SQL Stored Procedures ✓T1505.002 · Transport Agent ✓T1505.003 · Web Shell ✓T1505.004 · IIS Components ✓T1505.005 · Terminal Services DLL ✓T1525 · Implant Internal Image ✓T1542.001 · System Firmware ✓T1542.003 · Bootkit ✓T1543 · Create or Modify System Process ✓T1543.001 · Launch Agent ✓T1543.002 · Systemd Service ✓T1543.003 · Windows Service ✓T1543.004 · Launch Daemon ✓T1546 · Event Triggered Execution ✓T1546.001 · Change Default File Association ✓T1546.002 · Screensaver ✓T1546.003 · Windows Management Instrumentation Event Subscription ✓T1546.004 · Unix Shell Configuration Modification ✓T1546.007 · Netsh Helper DLL ✓T1546.008 · Accessibility Features ✓T1546.009 · AppCert DLLs ✓T1546.010 · AppInit DLLs ✓T1546.011 · Application Shimming ✓T1546.012 · Image File Execution Options Injection ✓T1546.013 · PowerShell Profile ✓T1546.014 · Emond ✓T1546.015 · Component Object Model Hijacking ✓T1547 · Boot or Logon Autostart Execution ✓T1547.001 · Registry Run Keys / Startup Folder ✓T1547.002 · Authentication Package ✓T1547.003 · Time Providers ✓T1547.004 · Winlogon Helper DLL ✓T1547.005 · Security Support Provider ✓T1547.006 · Kernel Modules and Extensions ✓T1547.008 · LSASS Driver ✓T1547.009 · Shortcut Modification ✓T1547.010 · Port Monitors ✓T1547.014 · Active Setup ✓T1547.015 · Login Items ✓T1554 · Compromise Host Software Binary ✓T1556 · Modify Authentication Process ✓T1556.002 · Password Filter DLL ✓T1556.004 · Network Device Authentication ✓T1556.006 · Multi-Factor Authentication ✓T1653 · Power Settings ✓

Privilege Escalation

70/96 covered · 72%
T1037.002 · Login HookT1037.003 · Network Logon ScriptT1037.004 · RC ScriptsT1053.006 · Systemd TimersT1053.007 · Container Orchestration JobT1055.002 · Portable Executable InjectionT1055.004 · Asynchronous Procedure CallT1055.005 · Thread Local StorageT1055.013 · Process DoppelgängingT1055.014 · VDSO HijackingT1055.015 · ListPlantingT1098.002 · Additional Email Delegate PermissionsT1098.006 · Additional Container Cluster RolesT1098.007 · Additional Local or Domain GroupsT1543.005 · Container ServiceT1546.005 · TrapT1546.006 · LC_LOAD_DYLIB AdditionT1546.016 · Installer PackagesT1546.017 · Udev RulesT1546.018 · Python Startup HooksT1547.007 · Re-opened ApplicationsT1547.012 · Print ProcessorsT1547.013 · XDG Autostart EntriesT1548.004 · Elevated Execution with PromptT1548.005 · Temporary Elevated Cloud AccessT1548.006 · TCC ManipulationT1037 · Boot or Logon Initialization Scripts ✓T1037.001 · Logon Script (Windows) ✓T1037.005 · Startup Items ✓T1053 · Scheduled Task/Job ✓T1053.002 · At ✓T1053.003 · Cron ✓T1053.005 · Scheduled Task ✓T1055 · Process Injection ✓T1055.001 · Dynamic-link Library Injection ✓T1055.003 · Thread Execution Hijacking ✓T1055.008 · Ptrace System Calls ✓T1055.009 · Proc Memory ✓T1055.011 · Extra Window Memory Injection ✓T1055.012 · Process Hollowing ✓T1068 · Exploitation for Privilege Escalation ✓T1078 · Valid Accounts ✓T1078.001 · Default Accounts ✓T1078.002 · Domain Accounts ✓T1078.003 · Local Accounts ✓T1078.004 · Cloud Accounts ✓T1098 · Account Manipulation ✓T1098.001 · Additional Cloud Credentials ✓T1098.003 · Additional Cloud Roles ✓T1098.004 · SSH Authorized Keys ✓T1098.005 · Device Registration ✓T1134 · Access Token Manipulation ✓T1134.001 · Token Impersonation/Theft ✓T1134.002 · Create Process with Token ✓T1134.003 · Make and Impersonate Token ✓T1134.004 · Parent PID Spoofing ✓T1134.005 · SID-History Injection ✓T1484 · Domain or Tenant Policy Modification ✓T1484.001 · Group Policy Modification ✓T1484.002 · Trust Modification ✓T1543 · Create or Modify System Process ✓T1543.001 · Launch Agent ✓T1543.002 · Systemd Service ✓T1543.003 · Windows Service ✓T1543.004 · Launch Daemon ✓T1546 · Event Triggered Execution ✓T1546.001 · Change Default File Association ✓T1546.002 · Screensaver ✓T1546.003 · Windows Management Instrumentation Event Subscription ✓T1546.004 · Unix Shell Configuration Modification ✓T1546.007 · Netsh Helper DLL ✓T1546.008 · Accessibility Features ✓T1546.009 · AppCert DLLs ✓T1546.010 · AppInit DLLs ✓T1546.011 · Application Shimming ✓T1546.012 · Image File Execution Options Injection ✓T1546.013 · PowerShell Profile ✓T1546.014 · Emond ✓T1546.015 · Component Object Model Hijacking ✓T1547 · Boot or Logon Autostart Execution ✓T1547.001 · Registry Run Keys / Startup Folder ✓T1547.002 · Authentication Package ✓T1547.003 · Time Providers ✓T1547.004 · Winlogon Helper DLL ✓T1547.005 · Security Support Provider ✓T1547.006 · Kernel Modules and Extensions ✓T1547.008 · LSASS Driver ✓T1547.009 · Shortcut Modification ✓T1547.010 · Port Monitors ✓T1547.014 · Active Setup ✓T1547.015 · Login Items ✓T1548 · Abuse Elevation Control Mechanism ✓T1548.001 · Setuid and Setgid ✓T1548.002 · Bypass User Account Control ✓T1548.003 · Sudo and Sudo Caching ✓T1611 · Escape to Host ✓

Credential Access

45/67 covered · 67%
T1003.007 · Proc FilesystemT1003.008 · /etc/passwd and /etc/shadowT1056.003 · Web Portal CaptureT1056.004 · Credential API HookingT1110.003 · Password SprayingT1110.004 · Credential StuffingT1111 · Multi-Factor Authentication InterceptionT1552.008 · Chat MessagesT1555.002 · Securityd MemoryT1555.006 · Cloud Secrets Management StoresT1556.001 · Domain Controller AuthenticationT1556.003 · Pluggable Authentication ModulesT1556.005 · Reversible EncryptionT1556.007 · Hybrid IdentityT1556.008 · Network Provider DLLT1556.009 · Conditional Access PoliciesT1557.004 · Evil TwinT1558.001 · Golden TicketT1558.002 · Silver TicketT1558.004 · AS-REP RoastingT1558.005 · Ccache FilesT1606.001 · Web CookiesT1003 · OS Credential Dumping ✓T1003.001 · LSASS Memory ✓T1003.002 · Security Account Manager ✓T1003.003 · NTDS ✓T1003.004 · LSA Secrets ✓T1003.005 · Cached Domain Credentials ✓T1003.006 · DCSync ✓T1040 · Network Sniffing ✓T1056 · Input Capture ✓T1056.001 · Keylogging ✓T1056.002 · GUI Input Capture ✓T1110 · Brute Force ✓T1110.001 · Password Guessing ✓T1110.002 · Password Cracking ✓T1187 · Forced Authentication ✓T1212 · Exploitation for Credential Access ✓T1528 · Steal Application Access Token ✓T1539 · Steal Web Session Cookie ✓T1552 · Unsecured Credentials ✓T1552.001 · Credentials In Files ✓T1552.002 · Credentials in Registry ✓T1552.003 · Shell History ✓T1552.004 · Private Keys ✓T1552.005 · Cloud Instance Metadata API ✓T1552.006 · Group Policy Preferences ✓T1552.007 · Container API ✓T1555 · Credentials from Password Stores ✓T1555.001 · Keychain ✓T1555.003 · Credentials from Web Browsers ✓T1555.004 · Windows Credential Manager ✓T1555.005 · Password Managers ✓T1556 · Modify Authentication Process ✓T1556.002 · Password Filter DLL ✓T1556.004 · Network Device Authentication ✓T1556.006 · Multi-Factor Authentication ✓T1557 · Adversary-in-the-Middle ✓T1557.001 · Name Resolution Poisoning and SMB Relay ✓T1557.002 · ARP Cache Poisoning ✓T1557.003 · DHCP Spoofing ✓T1558 · Steal or Forge Kerberos Tickets ✓T1558.003 · Kerberoasting ✓T1606 · Forge Web Credentials ✓T1606.002 · SAML Tokens ✓T1621 · Multi-Factor Authentication Request Generation ✓T1649 · Steal or Forge Authentication Certificates ✓

Discovery

37/49 covered · 75%
T1016.001 · Internet Connection DiscoveryT1016.002 · Wi-Fi DiscoveryT1087.003 · Email AccountT1497 · Virtualization/Sandbox EvasionT1497.002 · User Activity Based ChecksT1497.003 · Time Based ChecksT1518.002 · Backup Software DiscoveryT1538 · Cloud Service DashboardT1652 · Device Driver DiscoveryT1654 · Log EnumerationT1673 · Virtual Machine DiscoveryT1680 · Local Storage DiscoveryT1007 · System Service Discovery ✓T1010 · Application Window Discovery ✓T1012 · Query Registry ✓T1016 · System Network Configuration Discovery ✓T1018 · Remote System Discovery ✓T1033 · System Owner/User Discovery ✓T1040 · Network Sniffing ✓T1046 · Network Service Discovery ✓T1049 · System Network Connections Discovery ✓T1057 · Process Discovery ✓T1069 · Permission Groups Discovery ✓T1069.001 · Local Groups ✓T1069.002 · Domain Groups ✓T1069.003 · Cloud Groups ✓T1082 · System Information Discovery ✓T1083 · File and Directory Discovery ✓T1087 · Account Discovery ✓T1087.001 · Local Account ✓T1087.002 · Domain Account ✓T1087.004 · Cloud Account ✓T1120 · Peripheral Device Discovery ✓T1124 · System Time Discovery ✓T1135 · Network Share Discovery ✓T1201 · Password Policy Discovery ✓T1217 · Browser Information Discovery ✓T1482 · Domain Trust Discovery ✓T1497.001 · System Checks ✓T1518 · Software Discovery ✓T1518.001 · Security Software Discovery ✓T1526 · Cloud Service Discovery ✓T1580 · Cloud Infrastructure Discovery ✓T1613 · Container and Resource Discovery ✓T1614 · System Location Discovery ✓T1614.001 · System Language Discovery ✓T1615 · Group Policy Discovery ✓T1619 · Cloud Storage Object Discovery ✓T1622 · Debugger Evasion ✓

Defense Impairment

32/56 covered · 57%
T1553.006 · Code Signing Policy ModificationT1556.001 · Domain Controller AuthenticationT1556.003 · Pluggable Authentication ModulesT1556.005 · Reversible EncryptionT1556.007 · Hybrid IdentityT1556.008 · Network Provider DLLT1556.009 · Conditional Access PoliciesT1578.001 · Create SnapshotT1578.002 · Create Cloud InstanceT1578.004 · Revert Cloud InstanceT1578.005 · Modify Cloud Compute ConfigurationsT1599 · Network Boundary BridgingT1600 · Weaken EncryptionT1600.001 · Reduce Key SpaceT1600.002 · Disable Crypto HardwareT1601 · Modify System ImageT1601.001 · Patch System ImageT1601.002 · Downgrade System ImageT1647 · Plist File ModificationT1666 · Modify Cloud Resource HierarchyT1685.003 · Modify or Spoof Tool UIT1686.002 · Network Device FirewallT1687 · Exploitation for Defense ImpairmentT1688 · Safe Mode BootT1112 · Modify Registry ✓T1207 · Rogue Domain Controller ✓T1222 · File and Directory Permissions Modification ✓T1222.001 · Windows Permissions ✓T1222.002 · Linux and Mac Permissions ✓T1484 · Domain or Tenant Policy Modification ✓T1484.001 · Group Policy Modification ✓T1484.002 · Trust Modification ✓T1553 · Subvert Trust Controls ✓T1553.001 · Gatekeeper Bypass ✓T1553.002 · Code Signing ✓T1553.003 · SIP and Trust Provider Hijacking ✓T1553.004 · Install Root Certificate ✓T1553.005 · Mark-of-the-Web Bypass ✓T1556 · Modify Authentication Process ✓T1556.002 · Password Filter DLL ✓T1556.004 · Network Device Authentication ✓T1556.006 · Multi-Factor Authentication ✓T1578 · Modify Cloud Compute Infrastructure ✓T1578.003 · Delete Cloud Instance ✓T1599.001 · Network Address Translation Traversal ✓T1685 · Disable or Modify Tools ✓T1685.001 · Disable or Modify Windows Event Log ✓T1685.002 · Disable or Modify Cloud Log ✓T1685.004 · Disable or Modify Linux Audit System Log ✓T1685.005 · Clear Windows Event Logs ✓T1685.006 · Clear Linux or Mac System Logs ✓T1686 · Disable or Modify System Firewall ✓T1686.001 · Cloud Firewall ✓T1686.003 · Windows Host Firewall ✓T1689 · Downgrade Attack ✓T1690 · Prevent Command History Logging ✓

Stealth

85/148 covered · 57%
T1027.006 · HTML SmugglingT1027.007 · Dynamic API ResolutionT1027.008 · Stripped PayloadsT1027.011 · Fileless StorageT1027.012 · LNK Icon SmugglingT1027.013 · Encrypted/Encoded FileT1027.014 · Polymorphic CodeT1027.015 · CompressionT1027.016 · Junk Code InsertionT1027.017 · SVG SmugglingT1027.018 · Invisible UnicodeT1036.001 · Invalid Code SignatureT1036.008 · Masquerade File TypeT1036.009 · Break Process TreesT1036.010 · Masquerade Account NameT1036.011 · Overwrite Process ArgumentsT1036.012 · Browser FingerprintT1055.002 · Portable Executable InjectionT1055.004 · Asynchronous Procedure CallT1055.005 · Thread Local StorageT1055.013 · Process DoppelgängingT1055.014 · VDSO HijackingT1055.015 · ListPlantingT1070.007 · Clear Network Connection History and ConfigurationsT1070.008 · Clear Mailbox DataT1070.009 · Clear PersistenceT1070.010 · Relocate MalwareT1127.002 · ClickOnceT1127.003 · JamPlusT1205.002 · Socket FiltersT1216.002 · SyncAppvPublishingServerT1218.004 · InstallUtilT1218.012 · VerclsidT1218.015 · Electron ApplicationsT1480 · Execution GuardrailsT1480.001 · Environmental KeyingT1480.002 · Mutual ExclusionT1497 · Virtualization/Sandbox EvasionT1497.002 · User Activity Based ChecksT1497.003 · Time Based ChecksT1535 · Unused/Unsupported Cloud RegionsT1542 · Pre-OS BootT1542.002 · Component FirmwareT1542.004 · ROMMONkitT1542.005 · TFTP BootT1564.005 · Hidden File SystemT1564.007 · VBA StompingT1564.008 · Email Hiding RulesT1564.009 · Resource ForkingT1564.010 · Process Argument SpoofingT1564.011 · Ignore Process InterruptsT1564.012 · File/Path ExclusionsT1564.013 · Bind MountsT1564.014 · Extended AttributesT1574.004 · Dylib HijackingT1574.013 · KernelCallbackTableT1574.014 · AppDomainManagerT1612 · Build Image on HostT1678 · Delay ExecutionT1679 · Selective ExclusionT1684 · Social EngineeringT1684.001 · ImpersonationT1684.002 · Email SpoofingT1006 · Direct Volume Access ✓T1014 · Rootkit ✓T1027 · Obfuscated Files or Information ✓T1027.001 · Binary Padding ✓T1027.002 · Software Packing ✓T1027.003 · Steganography ✓T1027.004 · Compile After Delivery ✓T1027.005 · Indicator Removal from Tools ✓T1027.009 · Embedded Payloads ✓T1027.010 · Command Obfuscation ✓T1036 · Masquerading ✓T1036.002 · Right-to-Left Override ✓T1036.003 · Rename Legitimate Utilities ✓T1036.004 · Masquerade Task or Service ✓T1036.005 · Match Legitimate Resource Name or Location ✓T1036.006 · Space after Filename ✓T1036.007 · Double File Extension ✓T1055 · Process Injection ✓T1055.001 · Dynamic-link Library Injection ✓T1055.003 · Thread Execution Hijacking ✓T1055.008 · Ptrace System Calls ✓T1055.009 · Proc Memory ✓T1055.011 · Extra Window Memory Injection ✓T1055.012 · Process Hollowing ✓T1070 · Indicator Removal ✓T1070.003 · Clear Command History ✓T1070.004 · File Deletion ✓T1070.005 · Network Share Connection Removal ✓T1070.006 · Timestomp ✓T1078 · Valid Accounts ✓T1078.001 · Default Accounts ✓T1078.002 · Domain Accounts ✓T1078.003 · Local Accounts ✓T1078.004 · Cloud Accounts ✓T1127 · Trusted Developer Utilities Proxy Execution ✓T1127.001 · MSBuild ✓T1134 · Access Token Manipulation ✓T1134.001 · Token Impersonation/Theft ✓T1134.002 · Create Process with Token ✓T1134.003 · Make and Impersonate Token ✓T1134.004 · Parent PID Spoofing ✓T1134.005 · SID-History Injection ✓T1140 · Deobfuscate/Decode Files or Information ✓T1197 · BITS Jobs ✓T1202 · Indirect Command Execution ✓T1205 · Traffic Signaling ✓T1205.001 · Port Knocking ✓T1211 · Exploitation for Stealth ✓T1216 · System Script Proxy Execution ✓T1216.001 · PubPrn ✓T1218 · System Binary Proxy Execution ✓T1218.001 · Compiled HTML File ✓T1218.002 · Control Panel ✓T1218.003 · CMSTP ✓T1218.005 · Mshta ✓T1218.007 · Msiexec ✓T1218.008 · Odbcconf ✓T1218.009 · Regsvcs/Regasm ✓T1218.010 · Regsvr32 ✓T1218.011 · Rundll32 ✓T1218.013 · Mavinject ✓T1218.014 · MMC ✓T1220 · XSL Script Processing ✓T1221 · Template Injection ✓T1497.001 · System Checks ✓T1542.001 · System Firmware ✓T1542.003 · Bootkit ✓T1564 · Hide Artifacts ✓T1564.001 · Hidden Files and Directories ✓T1564.002 · Hidden Users ✓T1564.003 · Hidden Window ✓T1564.004 · NTFS File Attributes ✓T1564.006 · Run Virtual Instance ✓T1574 · Hijack Execution Flow ✓T1574.001 · DLL ✓T1574.005 · Executable Installer File Permissions Weakness ✓T1574.006 · Dynamic Linker Hijacking ✓T1574.007 · Path Interception by PATH Environment Variable ✓T1574.008 · Path Interception by Search Order Hijacking ✓T1574.009 · Path Interception by Unquoted Path ✓T1574.010 · Services File Permissions Weakness ✓T1574.011 · Services Registry Permissions Weakness ✓T1574.012 · COR_PROFILER ✓T1620 · Reflective Code Loading ✓T1622 · Debugger Evasion ✓
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin