MITRE ATT&CK Enterprise techniques: tactics, mitigations and adversary use
Value-added panel of the official MITRE ATT&CK Enterprise knowledge base (keyless STIX 2.1 bundle, royalty-free commercial license with attribution): one row per technique — top-level and sub-techniques, revoked/deprecated flagged — with its tactics, platforms, mitigations, detection strategy, and how many malware families, tools, intrusion sets and campaigns are recorded as using it. The technique taxonomy join key for detection-coverage gap analysis: join security-control coverage on technique_id to find techniques with heavy adversary use and no coverage.
Les titres et les descriptions proviennent des sources de données, en anglais.
- Lignes
- 858
- Colonnes
- 26
- Cadence de la source
- Trimestrielle
- Dernière actualisation
- 3 oct. 2026
- Thème
- technology
| Colonne | Type | Description |
|---|---|---|
| technique_id | string | MITRE ATT&CK technique identifier (T####; sub-techniques T####.###). |
| technique_name | string | Official technique name. |
| technique_url | string | Canonical technique page on attack.mitre.org. |
| is_subtechnique | boolean | True when the row is a sub-technique (x_mitre_is_subtechnique). |
| parent_technique_id | string | Owning top-level technique for sub-techniques; null otherwise. |
| tactics | string | Pipe-joined ATT&CK tactic shortnames from the technique's kill-chain phases (e.g. execution|defense-evasion). |
| tactic_count | integer | Number of tactics the technique spans. (unit: count) |
| platforms | string | Pipe-joined platforms (x_mitre_platforms: Windows, Linux, macOS, Containers, ...). |
| platform_count | integer | Number of platforms. (unit: count) |
| description | string | MITRE's technique description. |
| mitigation_ids | string | Pipe-joined mitigation identifiers resolving the bundle's mitigates relationships (legacy T#### and current M#### ids). |
| mitigation_count | integer | Number of mitigations. (unit: count) |
| detection_strategy_name | string | Name of the bundle's x-mitre-detection-strategy linked by the detects relationship (exactly one per active technique). |
| has_detection_strategy | boolean | True when a detection strategy is linked. |
| malware_use_count | integer | Number of malware objects recorded as using the technique. (unit: count) |
| tool_use_count | integer | Number of tool objects recorded as using the technique. (unit: count) |
| group_use_count | integer | Number of intrusion sets (threat groups) recorded as using the technique. (unit: count) |
| campaign_use_count | integer | Number of campaigns recorded as using the technique. (unit: count) |
| is_revoked | boolean | True when MITRE revoked the technique (superseded). |
| is_deprecated | boolean | True when MITRE deprecated the technique (x_mitre_deprecated). |
| superseded_by_id | string | Replacement technique for revoked techniques (revoked-by relationship); null otherwise. |
| attack_version | string | Technique object version (x_mitre_version). |
| created_date | string | Technique object creation date. (unit: date) |
| modified_date | string | Technique object last-modified date. (unit: date) |
| collection_version | string | ATT&CK Enterprise release the bundle was built from (x-mitre-collection). |
| row_hash | string | Deterministic 12-hex row identity hash (technique_id). |
10 premières lignes d’exemple — un aperçu, pas le jeu de données complet.
| technique_id | technique_name | technique_url | is_subtechnique | parent_technique_id | tactics | tactic_count | platforms | platform_count | description | mitigation_ids | mitigation_count | detection_strategy_name | has_detection_strategy | malware_use_count | tool_use_count | group_use_count | campaign_use_count | is_revoked | is_deprecated | superseded_by_id | attack_version | created_date | modified_date | collection_version | row_hash |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| T1055.011 | Extra Window Memory Injection | https://attack.mitre.org/techniques/T1055/011 | true | T1055 | privilege-escalation|stealth | 2 | Windows | 1 | Adversaries may inject malicious code into process via Extra Window Memory (EWM) in order to evade process-based defenses as well as possibly elevate privileges. EWM injection is a method of executing arbitrary code in the address space of a separate live process. Before creating a window, graphical Windows-based processes must prescribe to or register a windows class, which stipulate appearance and behavior (via windows procedures, which are functions that handle input/output of data).(Citation: Microsoft Window Classes) Registration of new windows classes can include a request for up to 40 bytes of EWM to be appended to the allocated memory of each instance of that class. This EWM is intended to store data specific to that window and has specific application programming interface (API) functions to set and get its value. (Citation: Microsoft GetWindowLong function) (Citation: Microsoft SetWindowLong function) Although small, the EWM is large enough to store a 32-bit pointer and is often used to point to a windows procedure. Malware may possibly utilize this memory location in part of an attack chain that includes writing code to shared sections of the process’s memory, placing a pointer to the code in EWM, then invoking execution by returning execution control to the address in the process’s EWM. Execution granted through EWM injection may allow access to both the target process's memory and possibly elevated privileges. Writing payloads to shared sections also avoids the use of highly monitored API calls such as <code>WriteProcessMemory</code> and <code>CreateRemoteThread</code>.(Citation: Elastic Process Injection July 2017) More sophisticated malware samples may also potentially bypass protection mechanisms such as data execution prevention (DEP) by triggering a combination of windows procedures and other system functions that will rewrite the malicious payload inside an executable portion of the target process. (Citation: MalwareTech Power Loader Aug 2013) (Citation: WeLiveSecurity Gapz and Redyms Mar 2013) Running code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via EWM injection may also evade detection from security products since the execution is masked under a legitimate process. | M1040 | 1 | Detection Strategy for Extra Window Memory (EWM) Injection on Windows | true | 2 | 0 | 0 | 0 | false | false | — | 2.0 | 2020-01-14 | 2026-05-12 | Enterprise ATT&CK 19.2 | 2446db24db96 |
| T1053.005 | Scheduled Task | https://attack.mitre.org/techniques/T1053/005 | true | T1053 | execution|persistence|privilege-escalation | 3 | Windows | 1 | Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The [schtasks](https://attack.mitre.org/software/S0111) utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel.(Citation: Stack Overflow) In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and [Windows Management Instrumentation](https://attack.mitre.org/techniques/T1047) (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.(Citation: Red Canary - Atomic Red Team) An adversary may use Windows Task Scheduler to execute programs at system startup or on a scheduled basis for persistence. The Windows Task Scheduler can also be abused to conduct remote Execution as part of Lateral Movement and/or to run a process under the context of a specified account (such as SYSTEM). Similar to [System Binary Proxy Execution](https://attack.mitre.org/techniques/T1218), adversaries have also abused the Windows Task Scheduler to potentially mask one-time execution under signed/trusted system processes.(Citation: ProofPoint Serpent) Adversaries may also create "hidden" scheduled tasks (i.e. [Hide Artifacts](https://attack.mitre.org/techniques/T1564)) that may not be visible to defender tools and manual queries used to enumerate tasks. Specifically, an adversary may hide a task from `schtasks /query` and the Task Scheduler by deleting the associated Security Descriptor (SD) registry value (where deletion of this value must be completed using SYSTEM permissions).(Citation: SigmaHQ)(Citation: Tarrask scheduled task) Adversaries may also employ alternate methods to hide tasks, such as altering the metadata (e.g., `Index` value) within associated registry keys.(Citation: Defending Against Scheduled Task Attacks in Windows Environments) | M1018|M1026|M1028|M1047 | 4 | Detection of Suspicious Scheduled Task Creation and Execution on Windows | true | 115 | 9 | 54 | 12 | false | false | — | 1.8 | 2019-11-27 | 2026-05-12 | Enterprise ATT&CK 19.2 | 3a8fba3c655e |
| T1205.002 | Socket Filters | https://attack.mitre.org/techniques/T1205/002 | true | T1205 | command-and-control|persistence|stealth | 3 | Linux|Windows|macOS | 3 | Adversaries may attach filters to a network socket to monitor then activate backdoors used for persistence or command and control. With elevated permissions, adversaries can use features such as the `libpcap` library to open sockets and install filters to allow or disallow certain types of data to come through the socket. The filter may apply to all traffic passing through the specified network interface (or every interface if not specified). When the network interface receives a packet matching the filter criteria, additional actions can be triggered on the host, such as activation of a reverse shell. To establish a connection, an adversary sends a crafted packet to the targeted host that matches the installed filter criteria.(Citation: haking9 libpcap network sniffing) Adversaries have used these socket filters to trigger the installation of implants, conduct ping backs, and to invoke command shells. Communication with these socket filters may also be used in conjunction with [Protocol Tunneling](https://attack.mitre.org/techniques/T1572).(Citation: exatrack bpf filters passive backdoors)(Citation: Leonardo Turla Penquin May 2020) Filters can be installed on any Unix-like platform with `libpcap` installed or on Windows hosts using `Winpcap`. Adversaries may use either `libpcap` with `pcap_setfilter` or the standard library function `setsockopt` with `SO_ATTACH_FILTER` options. Since the socket connection is not active until the packet is received, this behavior may be difficult to detect due to the lack of activity on a host, low CPU overhead, and limited visibility into raw socket usage. | M1037 | 1 | Socket-filter trigger → on-host raw-socket activity → reverse connection (T1205.002) | true | 4 | 0 | 0 | 0 | false | false | — | 2.0 | 2022-09-30 | 2026-05-12 | Enterprise ATT&CK 19.2 | 80e31428472a |
| T1066 | Indicator Removal from Tools | https://attack.mitre.org/techniques/T1066 | false | — | stealth | 1 | Linux|Windows|macOS | 3 | If a malicious tool is detected and quarantined or otherwise curtailed, an adversary may be able to determine why the malicious tool was detected (the indicator), modify the tool by removing the indicator, and use the updated version that is no longer detected by the target's defensive systems or subsequent targets that may use similar systems. A good example of this is when malware is detected with a file signature and quarantined by anti-virus software. An adversary who can determine that the malware was quarantined because of its file signature may use [Software Packing](https://attack.mitre.org/techniques/T1045) or otherwise modify the file so it has a different signature, and then re-use the malware. | — | 0 | — | false | 0 | 0 | 0 | 0 | true | false | T1027.005 | 1.1 | 2017-05-31 | 2026-04-14 | Enterprise ATT&CK 19.2 | a4aa6cf6d885 |
| T1560.001 | Archive via Utility | https://attack.mitre.org/techniques/T1560/001 | true | T1560 | collection | 1 | Linux|Windows|macOS | 3 | Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration. Many utilities include functionalities to compress, encrypt, or otherwise package data into a format that is easier/more secure to transport. Adversaries may abuse various utilities to compress or encrypt data before exfiltration. Some third party utilities may be preinstalled, such as <code>tar</code> on Linux and macOS or <code>zip</code> on Windows systems. On Windows, <code>diantz</code> or <code> makecab</code> may be used to package collected files into a cabinet (.cab) file. <code>diantz</code> may also be used to download and compress files from remote locations (i.e. [Remote Data Staging](https://attack.mitre.org/techniques/T1074/002)).(Citation: diantz.exe_lolbas) <code>xcopy</code> on Windows can copy files and directories with a variety of options. Additionally, adversaries may use [certutil](https://attack.mitre.org/software/S0160) to Base64 encode collected data before exfiltration. Adversaries may use also third party utilities, such as 7-Zip, WinRAR, and WinZip, to perform similar activities.(Citation: 7zip Homepage)(Citation: WinRAR Homepage)(Citation: WinZip Homepage) | M1047 | 1 | Detect Archiving via Utility (T1560.001) | true | 31 | 5 | 39 | 11 | false | false | — | 1.3 | 2020-02-20 | 2026-05-12 | Enterprise ATT&CK 19.2 | 3cf5adba2b05 |
| T1021.005 | VNC | https://attack.mitre.org/techniques/T1021/005 | true | T1021 | lateral-movement | 1 | Linux|Windows|macOS | 3 | Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to remotely control machines using Virtual Network Computing (VNC). VNC is a platform-independent desktop sharing system that uses the RFB (“remote framebuffer”) protocol to enable users to remotely control another computer’s display by relaying the screen, mouse, and keyboard inputs over the network.(Citation: The Remote Framebuffer Protocol) VNC differs from [Remote Desktop Protocol](https://attack.mitre.org/techniques/T1021/001) as VNC is screen-sharing software rather than resource-sharing software. By default, VNC uses the system's authentication, but it can be configured to use credentials specific to VNC.(Citation: MacOS VNC software for Remote Desktop)(Citation: VNC Authentication) Adversaries may abuse VNC to perform malicious actions as the logged-on user such as opening documents, downloading files, and running arbitrary commands. An adversary could use VNC to remotely control and monitor a system to collect data and information to pivot to other systems within the network. Specific VNC libraries/implementations have also been susceptible to brute force attacks and memory usage exploitation.(Citation: Hijacking VNC)(Citation: macOS root VNC login without authentication)(Citation: VNC Vulnerabilities)(Citation: Offensive Security VNC Authentication Check)(Citation: Attacking VNC Servers PentestLab)(Citation: Havana authentication bug) | M1033|M1037|M1042|M1047 | 4 | Behavioral Detection of Unauthorized VNC Remote Control Sessions | true | 7 | 0 | 4 | 0 | false | false | — | 1.2 | 2020-02-11 | 2025-10-24 | Enterprise ATT&CK 19.2 | f41fa925144b |
| T1047 | Windows Management Instrumentation | https://attack.mitre.org/techniques/T1047 | false | — | execution | 1 | Windows | 1 | Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems.(Citation: WMI 1-3) WMI is an administration feature that provides a uniform environment to access Windows system components. The WMI service enables both local and remote access, though the latter is facilitated by [Remote Services](https://attack.mitre.org/techniques/T1021) such as [Distributed Component Object Model](https://attack.mitre.org/techniques/T1021/003) and [Windows Remote Management](https://attack.mitre.org/techniques/T1021/006).(Citation: WMI 1-3) Remote WMI over DCOM operates using port 135, whereas WMI over WinRM operates over port 5985 when using HTTP and 5986 for HTTPS.(Citation: WMI 1-3) (Citation: Mandiant WMI) An adversary can use WMI to interact with local and remote systems and use it as a means to execute various behaviors, such as gathering information for [Discovery](https://attack.mitre.org/tactics/TA0007) as well as [Execution](https://attack.mitre.org/tactics/TA0002) of commands and payloads.(Citation: Mandiant WMI) For example, `wmic.exe` can be abused by an adversary to delete shadow copies with the command `wmic.exe Shadowcopy Delete` (i.e., [Inhibit System Recovery](https://attack.mitre.org/techniques/T1490)).(Citation: WMI 6) **Note:** `wmic.exe` is deprecated as of January of 2024, with the WMIC feature being “disabled by default” on Windows 11+. WMIC will be removed from subsequent Windows releases and replaced by [PowerShell](https://attack.mitre.org/techniques/T1059/001) as the primary WMI interface.(Citation: WMI 7,8) In addition to PowerShell and tools like `wbemtool.exe`, COM APIs can also be used to programmatically interact with WMI via C++, .NET, VBScript, etc.(Citation: WMI 7,8) | M1018|M1026|M1038|M1040 | 4 | Behavioral Detection Strategy for WMI Execution Abuse on Windows | true | 84 | 9 | 42 | 12 | false | false | — | 1.6 | 2017-05-31 | 2026-05-12 | Enterprise ATT&CK 19.2 | 820fc77932c2 |
| T1687 | Exploitation for Defense Impairment | https://attack.mitre.org/techniques/T1687 | false | — | defense-impairment | 1 | IaaS|Linux|SaaS|Windows|macOS | 5 | Adversaries may exploit vulnerabilities in security software, infrastructure, or defensive components to degrade, disable, or otherwise continue to impair their ability to prevent, detect, or respond to malicious activity. Adversaries may exploit a system or application vulnerability to directly interfere with defensive mechanisms. Exploitation occurs when an adversary takes advantage of a programming error in software, services, or the operating system to execute adversary-controlled code, often with the goal of weakening or disabling protections. Vulnerabilities may exist in security tools such as antivirus, endpoint detection and response (EDR), firewalls, or other monitoring solutions. Adversaries may use prior reconnaissance or perform discovery activities (e.g., [Software Discovery](https://attack.mitre.org/techniques/T1518)) to identify defensive tools present in an environment and target them for exploitation. Successful exploitation may allow adversaries to terminate security processes, disable protections, bypass enforcement mechanisms, or reduce the effectiveness of defensive controls. In some cases, vulnerabilities in cloud-based or SaaS infrastructure may also be leveraged to bypass built-in security boundaries or disrupt visibility and enforcement across environments.(Citation: Salesforce zero-day in facebook phishing attack) | — | 0 | Detection of Defense Impairment | true | 0 | 0 | 0 | 0 | false | false | — | 1.0 | 2026-04-14 | 2026-05-12 | Enterprise ATT&CK 19.2 | 1e01eca26c25 |
| T1156 | Malicious Shell Modification | https://attack.mitre.org/techniques/T1156 | false | — | persistence | 1 | Linux|macOS | 2 | Adversaries may establish persistence through executing malicious commands triggered by a user’s shell. User shells execute several configuration scripts at different points throughout the session based on events. For example, when a user opens a command line interface or remotely logs in (such as SSH) a login shell is initiated. The login shell executes scripts from the system (/etc) and the user’s home directory (~/) to configure the environment. All login shells on a system use <code>/etc/profile</code> when initiated. These configuration scripts run at the permission level of their directory and are often used to set environment variables, create aliases, and customize the user’s environment. When the shell exits or terminates, additional shell scripts are executed to ensure the shell exits appropriately. Adversaries may attempt to establish persistence by inserting commands into scripts automatically executed by shells. Using bash as an example, the default shell for most GNU/Linux systems, adversaries may add commands that launch malicious binaries into the <code>/etc/profile</code> and <code>/etc/profile.d</code> files (Citation: intezer-kaiji-malware). These files require root permissions and are executed each time any shell on a system launches. For user level permissions, adversaries can insert malicious commands into <code>~/.bash_profile</code>, <code>~/.bash_login</code>, or <code>~/.profile</code> (Rocke) which are sourced when a user opens a command line interface or connects remotely. Adversaries often use ~/.bash_profile since the system only executes the first file that exists in the listed order. Adversaries have also leveraged the <code>~/.bashrc</code> file (Tsunami, Rocke, Linux Rabbit, Magento) which is additionally executed if the connection is established remotely or an additional interactive shell is opened, such as a new tab in the command line interface. Some malware targets the termination of a program to trigger execution (Cannon), adversaries can use the <code>~/.bash_logout</code> file to execute malicious commands at the end of a session(Pearl_shellbot). For macOS, the functionality of this technique is similar but leverages zsh, the default shell for macOS 10.15+. When the Terminal.app is opened, the application launches a zsh login shell and a zsh interactive shell. The login shell configures the system environment using <code>/etc/profile</code>, <code>/etc/zshenv</code>, <code>/etc/zprofile</code>, and <code>/etc/zlogin</code>. The login shell then configures the user environment with <code>~/.zprofile</code> and <code>~/.zlogin</code>. The interactive shell uses the <code>~/.zshrc<code> to configure the user environment. Upon exiting, <code>/etc/zlogout</code> and <code>~/.zlogout</code> are executed. For legacy programs, macOS executes <code>/etc/bashrc</code> on startup. | — | 0 | — | false | 0 | 0 | 0 | 0 | true | false | T1546.004 | 1.2 | 2017-12-14 | 2025-10-24 | Enterprise ATT&CK 19.2 | cc32cf1d26aa |
| T1113 | Screen Capture | https://attack.mitre.org/techniques/T1113 | false | — | collection | 1 | Linux|Windows|macOS | 3 | Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as <code>CopyFromScreen</code>, <code>xwd</code>, or <code>screencapture</code>.(Citation: CopyFromScreen .NET)(Citation: Antiquated Mac Malware) | — | 0 | Detect Screen Capture via Commands and API Calls | true | 139 | 12 | 19 | 1 | false | false | — | 1.1 | 2017-05-31 | 2026-05-12 | Enterprise ATT&CK 19.2 | 49dd598cb25a |
- Actuelle
20261003T162147Z-03d6a74507db · sha256 03d6a74507db…
858 lignes · premier instantané
Dirigez n’importe quel LLM vers le point d’accès des métadonnées — la documentation ci-dessus est aussi lisible par machine (JSON-LD + Croissant).
curl "https://datazimuts.com/v1/datasets/mitre_attack_intel/attack_techniques_enterprise" | jq '{title, rows, columns_count, license}'import requests
ds = requests.get("https://datazimuts.com/v1/datasets/mitre_attack_intel/attack_techniques_enterprise").json()
print(ds["title"], ds["rows"], "rows")
# Sample rows for an LLM context window
for row in ds.get("sample_rows", [])[:5]:
print(row)Point d’accès API : https://datazimuts.com/v1/datasets/mitre_attack_intel/attack_techniques_enterprise
Astuce : récupérez /llms.txt pour le catalogue complet lisible par machine.
D’où viennent ces données et ce qui en a été fait. Le travail des autres apparaît sous forme de décomptes ; seuls les projets partagés sont nommés.
Citer cet instantané
Épinglé à l’instantané 20261003T162147Z-03d6a74507db et à son empreinte, pour que vos lecteurs obtiennent exactement les données utilisées.
MITRE ATT&CK Enterprise intelligence. (2026). MITRE ATT&CK Enterprise techniques: tactics, mitigations and adversary use [Data set, snapshot 20261003T162147Z-03d6a74507db, sha256 03d6a74507db]. Datazimuts. Retrieved 2026-10-05, from https://datazimuts.com/fr/datasets/mitre_attack_intel/attack_techniques_enterprise?snapshot=20261003T162147Z-03d6a74507db
@misc{dz_mitre_attack_intel_attack_techniques_ent_03d6a745,
title = {{MITRE ATT\&CK Enterprise techniques: tactics, mitigations and adversary use}},
author = {{MITRE ATT\&CK Enterprise intelligence}},
year = {2026},
publisher = {Datazimuts},
howpublished = {\url{https://datazimuts.com/fr/datasets/mitre_attack_intel/attack_techniques_enterprise?snapshot=20261003T162147Z-03d6a74507db}},
note = {Snapshot 20261003T162147Z-03d6a74507db, sha256 03d6a74507dbe6f4d0aaa1fea3392f51834332ff603fc334976f732db712ebd2; accessed 2026-10-05}
}Intégrer un tableau ou un graphique
Collez ce code dans n’importe quelle page. L’intégration est épinglée au même instantané, suit le thème clair ou sombre du lecteur et affiche toujours la source, la licence et un lien de retour.
<iframe src="https://datazimuts.com/embed/chart?dataset=mitre_attack_intel%2Fattack_techniques_enterprise&lang=fr&theme=auto&snapshot=20261003T162147Z-03d6a74507db&x=created_date&y=tactic_count&agg=avg" title="MITRE ATT&CK Enterprise techniques: tactics, mitigations and adversary use" width="100%" height="380" style="border:0" loading="lazy"></iframe>
Posez une question sur ce jeu de données. Les réponses viennent uniquement de sa fiche, de son profil mesuré et de son historique, et citent les faits utilisés.