{"data":{"id":"CA-07","name":"Continuous Monitoring","family":"CA","family_name":"Security Assessment and Authorization","withdrawn":false,"description":"Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitoring strategy that includes:\na. Establishing the following system-level metrics to be monitored: [Assignment: organization-defined system-level metrics];\nb. Establishing [Assignment: organization-defined frequencies] for monitoring and [Assignment: organization-defined frequencies] for assessment of control effectiveness;\nc. Ongoing control assessments in accordance with the continuous monitoring strategy;\nd. Ongoing monitoring of system and organization-defined metrics in accordance with the continuous monitoring strategy;\ne. Correlation and analysis of information generated by control assessments and monitoring;\nf. Response actions to address results of the analysis of control assessment and monitoring information; and\ng. Reporting the security and privacy status of the system to [Assignment: organization-defined personnel or roles] [Assignment: organization-defined frequency].","supplemental_guidance":"Continuous monitoring at the system level facilitates ongoing awareness of the system security and privacy posture to support organizational risk management decisions. The terms \"continuous\" and \"ongoing\" imply that organizations assess and monitor their controls and risks at a frequency sufficient to support risk-based decisions. Different types of controls may require different monitoring frequencies. The results of continuous monitoring generate risk response actions by organizations. When monitoring the effectiveness of multiple controls that have been grouped into capabilities, a root-cause analysis may be needed to determine the specific control that has failed. Continuous monitoring programs allow organizations to maintain the authorizations of systems and common controls in highly dynamic environments of operation with changing mission and business needs, threats, vulnerabilities, and technologies. Having access to security and privacy information on a continuing basis through reports and dashboards gives organizational officials the ability to make effective and timely risk management decisions, including ongoing authorization decisions.\n\nAutomation supports more frequent updates to hardware, software, and firmware inventories, authorization packages, and other system information. Effectiveness is further enhanced when continuous monitoring outputs are formatted to provide information that is specific, measurable, actionable, relevant, and timely. Continuous monitoring activities are scaled in accordance with the security categories of systems. Monitoring requirements, including the need for specific monitoring, may be referenced in other controls and control enhancements, such as AC-02g, AC-02(07), AC-02(12)(a), AC-02(07)(b), AC-02(07)(c), AC-17(01), AT-04a, AU-13, AU-13(01), AU-13(02), CM-03f, CM-06d, CM-11c, IR-05, MA-02b, MA-03a, MA-04a, PE-03d, PE-06, PE-14b, PE-16, PE-20, PM-06, PM-23, PM-31, PS-07e, SA-09c, SR-04, SC-05(03)(b), SC-07a, SC-07(24)(b), SC-18b, SC-43b, and SI-04.","enhancements":[{"id":"CA-07(01)","name":"Independent Assessment","statement":"Employ independent assessors or assessment teams to monitor the controls in the system on an ongoing basis.","baselines":["moderate","high"]},{"id":"CA-07(02)","name":"Types of Assessments","withdrawn":true,"incorporated_into":["CA-02"]},{"id":"CA-07(03)","name":"Trend Analyses","statement":"Employ trend analyses to determine if control implementations, the frequency of continuous monitoring activities, and the types of activities used in the continuous monitoring process need to be modified based on empirical data.","baselines":[]},{"id":"CA-07(04)","name":"Risk Monitoring","statement":"Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following:\na. Effectiveness monitoring;\nb. Compliance monitoring; and\nc. Change monitoring.","baselines":["low","moderate","high","privacy"]},{"id":"CA-07(05)","name":"Consistency Analysis","statement":"Employ the following actions to validate that policies are established and implemented controls are operating in a consistent manner: [Assignment: organization-defined actions].","baselines":[]},{"id":"CA-07(06)","name":"Automation Support for Monitoring","statement":"Ensure the accuracy, currency, and availability of monitoring results for the system using [Assignment: organization-defined automated mechanisms].","baselines":[]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"CA-07","name":"Continuous Monitoring","description":"Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitoring strategy that includes:\na. Establishing the following system-level metrics to be monitored: [Assignment: organization-defined system-level metrics];\nb. Establishing [Assignment: organization-defined frequencies] for monitoring and [Assignment: organization-defined frequencies] for assessment of control effectiveness;\nc. Ongoing control assessments in accordance with the continuous monitoring strategy;\nd. Ongoing monitoring of system and organization-defined metrics in accordance with the continuous monitoring strategy;\ne. Correlation and analysis of information generated by control assessments and monitoring;\nf. Response actions to address results of the analysis of control assessment and monitoring information; and\ng. Reporting the security and privacy status of the system to [Assignment: organization-defined personnel or roles] [Assignment: organization-defined frequency].","discussion":"Continuous monitoring at the system level facilitates ongoing awareness of the system security and privacy posture to support organizational risk management decisions. The terms \"continuous\" and \"ongoing\" imply that organizations assess and monitor their controls and risks at a frequency sufficient to support risk-based decisions. Different types of controls may require different monitoring frequencies. The results of continuous monitoring generate risk response actions by organizations. When monitoring the effectiveness of multiple controls that have been grouped into capabilities, a root-cause analysis may be needed to determine the specific control that has failed. Continuous monitoring programs allow organizations to maintain the authorizations of systems and common controls in highly dynamic environments of operation with changing mission and business needs, threats, vulnerabilities, and technologies. Having access to security and privacy information on a continuing basis through reports and dashboards gives organizational officials the ability to make effective and timely risk management decisions, including ongoing authorization decisions.\n\nAutomation supports more frequent updates to hardware, software, and firmware inventories, authorization packages, and other system information. Effectiveness is further enhanced when continuous monitoring outputs are formatted to provide information that is specific, measurable, actionable, relevant, and timely. Continuous monitoring activities are scaled in accordance with the security categories of systems. Monitoring requirements, including the need for specific monitoring, may be referenced in other controls and control enhancements, such as AC-02g, AC-02(07), AC-02(12)(a), AC-02(07)(b), AC-02(07)(c), AC-17(01), AT-04a, AU-13, AU-13(01), AU-13(02), CM-03f, CM-06d, CM-11c, IR-05, MA-02b, MA-03a, MA-04a, PE-03d, PE-06, PE-14b, PE-16, PE-20, PM-06, PM-23, PM-31, PS-07e, SA-09c, SR-04, SC-05(03)(b), SC-07a, SC-07(24)(b), SC-18b, SC-43b, and SI-04.","related_controls":["AC-02","AC-06","AC-17","AT-04","AU-06","AU-13","CA-02","CA-05","CA-06","CM-03","CM-04","CM-06","CM-11","IA-05","IR-05","MA-02","MA-03","MA-04","PE-03","PE-06","PE-14","PE-16","PE-20","PL-02","PM-04","PM-06","PM-09","PM-10","PM-12","PM-14","PM-23","PM-28","PM-31","PS-07","PT-07","RA-03","RA-05","RA-07","RA-10","SA-08","SA-09","SA-11","SC-05","SC-07","SC-18","SC-38","SC-43","SI-03","SI-04","SI-12","SR-06"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":true,"new_in_rev5":false,"changes_from_rev4":"Control text changes 'metrics' to 'system-level metrics' Parameter changes 'metrics' to 'system-level metrics' Discussion expanded"}},"compliance_mappings":{"iso_27001_2022":["9.1","9.2","9.3","10.1","A.5.22","A.5.35","A.5.36","A.8.16"],"iso_27002_2022":["5.22","5.35","5.36","8.16"],"cobit_2019":["APO13","DSS01","MEA01","MEA02","MEA04"],"pci_dss_v4":["12.4"],"nist_csf_2":["DE.AE-02","DE.AE-03","DE.CM-01","DE.CM-02","DE.CM-03","DE.CM-06","DE.CM-09","GV.OV-01","GV.OV-03","GV.PO-02","ID.IM-01","ID.IM-02","ID.IM-03","ID.RA-01","ID.RA-07","PR.PS-04","RC.RP-05"],"cis_controls_v8":["CIS 7","CIS 13","CIS 15.6"],"soc2_tsc":["CC1.1","CC1.1-POF3","CC2.2","CC2.3","CC4.2-POF1","CC4.2-POF2"],"finos_ccc":["CCC-C08"],"iso_42001_2023":["A.2.4","A.6.2.6"],"iec_62443":["3-3 SR 6.2"],"asd_e8":[],"nis2":["Art. 21(2)(f)","Art. 32"],"apra_cps_234":[],"mas_trm":["7","12"],"pra_op_resilience":["SS1/21-7.1","SS2/21-7.1"],"bsi_grundschutz":["DER.1"],"anssi":["Hygiene.3","Hygiene.29","Hygiene.31","Hygiene.39","SecNumCloud.13.7","SecNumCloud.19.2"],"osfi_b13":["B-13.1.3","B-13.3.3","B-13.4.2"],"finma_circular":["IV.C(66)","IV.C(67)","IV.C(68)","IV.D(75)","IV.D(76)"],"gdpr":["Art.32(1)(d)","Art.35(11)"],"dora":["Art.6(4)","Art.10(1)","Art.10(2)","Art.24(1)"],"bio2":["5.22","5.35","5.36","8.16"],"rbi_csf":["Annex1.21","ITGRCA.21","ITGRCA.30"],"fisc":["FISC.O2","FISC.O7"],"lgpd_bcb":["BCB.Art.6","BCB.Art.10","BCB.Art.19","LGPD.Art.50"],"hkma_tme1":["TME1.2.6","TME1.5.2","TME1.12.3"],"mlps_2":["8.1.5.3","8.1.7.2","8.1.9.6"],"dnb_good_practice":["DNB.14.1","DNB.16.1","DNB.16.2"],"cra":[],"swift_cscf":[],"cbb_tm":["TM-5","TM-12","TM-16"],"cbuae":["CR-3","CR-10","CR-14"],"nca_ecc":["1-7","1-8","2-12","5-1"],"qatar_nia":["GV","OS","RM"],"sama_csf":["1.3","1.9","2.2"],"uae_ia":["T7"],"bog_cisd":["CISD-COMP","CISD-II","CISD-III","CISD-ISMS","CISD-IV","CISD-VII"],"bom_ctrm":["1.5","3.1","4.2","5.3","5.4"],"cbe_csf":["CD-1","GOV-3","OVM-3"],"cbn_csf":["Part2.2","Part2.3","Part3.5","Part6.1","Part6.2","Part7.2"],"popia":["s19"],"sa_js2":["JS2-7.3","JS2-7.6","JS2-7.7","JS2-9"],"bcbs_239":["Principle 7","Principle 8","Principle 10","Principle 12"],"bot_cyber":["Ch1.3","Ch3.1","Ch6.1","Ch10.1"],"cpmi_pfmi":["CG.DE","CG.LE","PFMI.P3","PFMI.P17"],"eba_ict":["3.3.5","3.3.6","3.4.5","3.4.6"],"ecb_croe":["CROE.2.2.1","CROE.2.4","CROE.2.8.1"],"ffiec_is":["II.A","II.A.2","II.C.4","II.D","III.A","III.B","IV.A","IV.A.3"],"hipaa_sr":["§164.308(a)(1)(i)","§164.308(a)(1)(ii)(A)","§164.308(a)(1)(ii)(B)","§164.308(a)(1)(ii)(D)","§164.308(a)(7)(ii)(D)","§164.308(a)(8)","§164.316(b)(2)(iii)"],"iosco_cyber":["DET-1","DET-2","LE-1","LE-2","SA-3","TEST-1"],"nydfs_500":["500.2"],"sebi_cscrf":["AUDIT","CCI","DE.CM","GV.OV","RS.IM","SOC"],"cmmc_2":["CA"],"nerc_cip":["CIP-015-1"],"nrc_73_54":["73.54(d)","RG5.71-C-CA"],"tsa_psd":["SD-2 Sec C"],"ieee_1686":[],"ferc_cip":["Order 881","Order 893"],"doe_c2m2":["SITUATION"],"api_1164":["Sec 9","Sec 15"],"awia":["AWWA Sec 4","AWWA Sec 5"],"iaea_nss":["Sec 5.5","Sec 11"],"pci_pts":[],"fips_140":[],"cbest":["CBEST.5","CBEST.7","CBEST.10"],"tiber_eu":["TIBER.BT","TIBER.REM"],"pci_hsm":["10"],"common_criteria":["CEM"],"isae_3402":["Clause 2","Clause 5","Clause 6","Clause 10"],"fca_sysc_13":["SYSC 13.5.3","SYSC 13.7.5","SYSC 13.9.3","SYSC 13.G.3"],"fda_21_cfr_11":["§11.10(a)"],"fda_cyber":["524B-2","524B-4"],"hitrust_csf":["00.b","00.c","03.b","04.b","06.c","11.b","12.c"],"iso_27799":["5.2","18.3"],"lloyds_ms":["MS8.12","MS10.2"],"naic_ds":["4","4-monitoring","4A","4E","5","7"],"nhs_dspt":["NDG-5.1","NDG-7.3","NDG-9.9"],"pra_ss1_23":["P4.1","P5.2"],"solvency_ii":["Art.45","Art.46","Art.47","EIOPA-ICT-4.2"],"owasp_masvs_v2":[],"csa_ccm_v4":["AA-02","AIS-03","LOG-03","LOG-10","SEF-05","STA-11","TVM-09","TVM-10"],"csa_aicm":["A&A-02","AIS-03","AIS-12","GRC-12","GRC-15","LOG-03","LOG-10","LOG-15","MDS-05","SEF-05","STA-11","TVM-09","TVM-10","TVM-13"],"ccss_v9":["2.01.1","2.01.3"],"mica":["Art.34(5)","Art.43(1)","Art.62(1)","Art.94(1)"],"basel_sco60":["SCO60.5","SCO60.13","SCO60.23","SCO60.50","SCO60.51","SCO60.65","SCO60.71","SCO60.72","SCO60.73","SCO60.74"],"bssc":["GSP-15","NOS-10"],"sec_custody_digital":["SEC-CD-10","SEC-CD-13","SEC-CD-14"],"dpdpa":["Act.8(4)","Act.10(2)(c)","Rules.6(1)(g)","Rules.13(1)-(2)","Rules.Sch1.B.12"]},"attack_techniques":[{"id":"T1001","name":"Data Obfuscation","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of network traffic baselines enables detection of data obfuscation in C2 channels by identifying deviations from normal communication patterns, entropy anomalies, and protocol irregularities that indicate adversary attempts to conceal command traffic."},{"id":"T1003","name":"OS Credential Dumping","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Ongoing assessment of security controls governing credential storage and access—combined with monitoring for anomalous authentication events—enables detection of credential-dumping activity by correlating suspicious process behavior with deviations from established baselines."},{"id":"T1008","name":"Fallback Channels","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of network communication patterns can detect the establishment of fallback C2 channels by identifying new or unusual outbound connections that activate when primary communication paths are disrupted."},{"id":"T1029","name":"Scheduled Transfer","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of data-transfer patterns enables detection of scheduled exfiltration by establishing normal transfer baselines and alerting on periodic, automated data movements that deviate from expected user and system behavior."},{"id":"T1030","name":"Data Transfer Size Limits","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of network traffic volumes and patterns can detect size-limited exfiltration by correlating multiple small data transfers to the same destination that collectively represent significant unauthorized data movement."},{"id":"T1036","name":"Masquerading","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Ongoing security assessment of system binaries and file integrity enables detection of masquerading by identifying files whose names, locations, or metadata do not match the organization's authorized software inventory."},{"id":"T1037","name":"Boot or Logon Initialization Scripts","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of boot and logon processes can detect unauthorized initialization scripts by establishing baselines of legitimate startup configurations and alerting on additions or modifications to logon scripts."},{"id":"T1041","name":"Exfiltration Over C2 Channel","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of C2 channel traffic volumes and patterns enables detection of data exfiltration piggybacked onto command-and-control communications by identifying anomalous data volumes within established C2 sessions."},{"id":"T1046","name":"Network Service Discovery","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of internal network traffic can detect network service discovery scans by identifying port-scanning patterns, unusual service-enumeration queries, and reconnaissance activity that deviates from normal network behavior."},{"id":"T1048","name":"Exfiltration Over Alternative Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Ongoing network monitoring enables detection of exfiltration over alternative protocols by establishing baselines for protocol usage and alerting on unexpected DNS, ICMP, or other non-standard protocol traffic carrying data payloads."},{"id":"T1052","name":"Exfiltration Over Physical Medium","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of endpoint activity—including removable media connections—can detect data staging and exfiltration to physical media by alerting on unusual file-copy operations to USB devices or other removable storage."},{"id":"T1059","name":"Command and Scripting Interpreter","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of script execution and command-line activity across endpoints enables detection of adversary use of scripting interpreters by identifying unusual PowerShell, Python, bash, and other interpreter invocations."},{"id":"T1068","name":"Exploitation for Privilege Escalation","tactics":["privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of system behavior and security control effectiveness can detect exploitation for privilege escalation by identifying anomalous process elevation, unexpected privilege changes, and exploitation indicators."},{"id":"T1070","name":"Indicator Removal","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of log integrity and availability enables detection of indicator-removal attempts by alerting when log files are unexpectedly truncated, deleted, or modified, or when logging services are stopped."},{"id":"T1071","name":"Application Layer Protocol","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of application-layer protocol traffic enables detection of C2 channels disguised within HTTP, DNS, SMTP, and other standard protocols by identifying anomalous request patterns and suspicious payload characteristics."},{"id":"T1072","name":"Software Deployment Tools","tactics":["execution","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of software deployment infrastructure can detect adversary abuse of deployment tools by identifying unauthorized software distributions, unexpected push operations, and anomalous deployment activity."},{"id":"T1078","name":"Valid Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of authentication events and account activity can detect adversary use of valid accounts by identifying anomalous logon patterns, impossible-travel scenarios, and authentication from unusual sources or at unusual times."},{"id":"T1080","name":"Taint Shared Content","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of shared content repositories can detect tainted files by tracking file modifications, identifying unexpected content changes, and alerting on files that deviate from known-good baselines in shared locations."},{"id":"T1090","name":"Proxy","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of network traffic can detect proxy-based C2 by identifying unexpected proxy connections, unusual relay patterns, and internal systems acting as network intermediaries without authorization."},{"id":"T1095","name":"Non-Application Layer Protocol","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of non-application-layer protocol traffic enables detection of covert C2 channels using ICMP, raw sockets, or custom protocols by establishing normal baseline usage and alerting on anomalous patterns."},{"id":"T1102","name":"Web Service","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of outbound web service connections can detect C2 over legitimate web services by identifying unusual API interactions with cloud storage, social media, and other web platforms used for adversary command relay."},{"id":"T1104","name":"Multi-Stage Channels","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of network connection sequences can detect multi-stage C2 channels by identifying the characteristic pattern of initial callback followed by secondary channel establishment to separate infrastructure."},{"id":"T1105","name":"Ingress Tool Transfer","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of file downloads and network transfers enables detection of ingress tool transfer by alerting on unexpected binary downloads, unusual file-transfer activity, and tools not present in the authorized software baseline."},{"id":"T1110","name":"Brute Force","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of authentication events can detect brute-force attacks by identifying high volumes of failed authentication attempts, credential-stuffing patterns, and password-spraying activity across multiple accounts."},{"id":"T1111","name":"Multi-Factor Authentication Interception","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of authentication processes can detect MFA interception by identifying anomalous authentication flows, unexpected MFA token usage patterns, and suspicious man-in-the-middle positioning in authentication sessions."},{"id":"T1132","name":"Data Encoding","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of network traffic can detect encoded C2 data by identifying Base64, XOR, or custom encoding in protocol fields where such encoding is unexpected, flagging deviations from normal protocol data formats."},{"id":"T1176","name":"Browser Extensions","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of browser configurations can detect malicious extensions by tracking installed extensions against approved baselines and alerting on unauthorized additions or modifications to browser extension lists."},{"id":"T1185","name":"Browser Session Hijacking","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of browser process behavior can detect session hijacking by identifying unexpected browser process interactions, suspicious API hooks, and anomalous session-token access patterns."},{"id":"T1187","name":"Forced Authentication","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of authentication traffic can detect forced authentication attempts—such as coerced NTLM authentication—by identifying unexpected SMB, WebDAV, or other authentication requests to adversary-controlled infrastructure."},{"id":"T1189","name":"Drive-by Compromise","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of web browsing activity and endpoint behavior can detect drive-by compromises by identifying unexpected code execution following web browsing, anomalous browser child processes, and exploitation indicators."},{"id":"T1190","name":"Exploit Public-Facing Application","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of public-facing application logs and behavior enables detection of exploitation attempts by identifying anomalous request patterns, error conditions, and unexpected application behavior indicative of active exploitation."},{"id":"T1195","name":"Supply Chain Compromise","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of software integrity and supply chain indicators can detect compromised software by comparing installed binaries against trusted baselines and identifying unauthorized modifications to software packages."},{"id":"T1197","name":"BITS Jobs","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of BITS transfer activity can detect adversary abuse of Background Intelligent Transfer Service by identifying unexpected BITS jobs, unusual download sources, and persistence through BITS notification commands."},{"id":"T1201","name":"Password Policy Discovery","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of system enumeration commands can detect password policy discovery by identifying unusual queries to domain controllers for password-policy information and suspicious use of net accounts or similar commands."},{"id":"T1203","name":"Exploitation for Client Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of client application behavior can detect exploitation for code execution by identifying unexpected child processes spawned by browsers, document readers, and office suites following suspicious content rendering."},{"id":"T1204","name":"User Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of user execution events enables detection of social engineering success by identifying when users launch unusual executables, open suspicious files, or interact with malicious content."},{"id":"T1205","name":"Traffic Signaling","tactics":["command-and-control","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of network traffic can detect traffic signaling techniques—including port knocking sequences—by identifying unusual patterns of connection attempts that precede the activation of hidden services."},{"id":"T1210","name":"Exploitation of Remote Services","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of internal network services can detect exploitation of remote services by identifying anomalous service interactions, unexpected protocol behavior, and exploitation indicators targeting internal systems."},{"id":"T1211","name":"Exploitation for Defense Evasion","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of security control integrity can detect exploitation for defense evasion by identifying when defensive mechanisms are unexpectedly disabled, modified, or bypassed through software exploitation."},{"id":"T1212","name":"Exploitation for Credential Access","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of credential-storage systems and authentication infrastructure can detect exploitation for credential access by identifying anomalous access patterns and exploitation indicators targeting authentication services."},{"id":"T1213","name":"Data from Information Repositories","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of information repository access can detect unauthorized data collection from SharePoint, Confluence, wikis, and other knowledge bases by identifying anomalous access patterns and bulk data retrieval."},{"id":"T1218","name":"System Binary Proxy Execution","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of system binary execution can detect proxy execution by identifying unusual invocations of signed binaries (LOLBins) with suspicious command-line arguments or execution contexts."},{"id":"T1219","name":"Remote Access Software","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of installed software and network connections can detect unauthorized remote access tools by identifying new remote-administration software and unexpected outbound connections to remote-access infrastructure."},{"id":"T1221","name":"Template Injection","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of document template loading can detect template injection by identifying Office documents that retrieve remote templates from unusual or unauthorized external sources during document opening."},{"id":"T1222","name":"File and Directory Permissions Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of file permission changes can detect unauthorized modifications to access controls by identifying bulk permission changes, DACL modifications, and chmod/icacls operations that weaken file protections."},{"id":"T1489","name":"Service Stop","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of service availability can detect adversary service-stop operations by alerting when critical services are unexpectedly terminated, identifying the characteristic pattern of pre-ransomware service disruption."},{"id":"T1498","name":"Network Denial of Service","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of network traffic volumes and patterns enables early detection of network denial-of-service attacks by identifying traffic spikes, unusual source distributions, and flood patterns targeting organizational infrastructure."},{"id":"T1499","name":"Endpoint Denial of Service","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of endpoint and service health metrics can detect endpoint DoS attacks by identifying resource exhaustion, application crashes, and service degradation indicative of targeted denial-of-service activity."},{"id":"T1528","name":"Steal Application Access Token","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of OAuth token usage and application authorization events can detect stolen application access tokens by identifying token use from unexpected locations, devices, or outside normal usage patterns."},{"id":"T1530","name":"Data from Cloud Storage","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of cloud storage access logs can detect unauthorized data retrieval by identifying anomalous access patterns, bulk downloads, and data access from unexpected IP addresses or user accounts."},{"id":"T1537","name":"Transfer Data to Cloud Account","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of cloud account activity can detect data transfer to adversary-controlled cloud accounts by identifying unexpected cross-account data copies and unusual cloud storage API operations."},{"id":"T1539","name":"Steal Web Session Cookie","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of browser storage access and cookie usage can detect session-cookie theft by identifying unusual cookie extraction patterns and session-token use from unexpected network locations."},{"id":"T1543","name":"Create or Modify System Process","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of system process configurations can detect creation or modification of system services by alerting on new service installations, daemon registrations, and changes to existing service definitions."},{"id":"T1548","name":"Abuse Elevation Control Mechanism","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of privilege elevation events can detect abuse of elevation control mechanisms by identifying unusual UAC bypasses, sudo abuse patterns, and setuid/setgid manipulation."},{"id":"T1552","name":"Unsecured Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of credential storage locations can detect exposure of unsecured credentials by identifying plaintext passwords in files, scripts, or configuration repositories through regular scanning and access monitoring."},{"id":"T1555","name":"Credentials from Password Stores","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of password-store access can detect credential theft from password managers, keychains, and browser credential stores by identifying unusual access patterns to these sensitive repositories."},{"id":"T1556","name":"Modify Authentication Process","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of authentication process integrity can detect modifications to authentication mechanisms—such as patched authentication libraries or modified PAM modules—by comparing against known-good baselines."},{"id":"T1557","name":"Adversary-in-the-Middle","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of network traffic can detect adversary-in-the-middle positioning by identifying ARP anomalies, LLMNR/NBT-NS poisoning, DHCP irregularities, and unexpected traffic-interception patterns."},{"id":"T1558","name":"Steal or Forge Kerberos Tickets","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of Kerberos authentication events can detect ticket theft and forgery by identifying unusual TGS requests, anomalous service-ticket patterns, and Kerberos authentication from unexpected sources."},{"id":"T1562","name":"Impair Defenses","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of security tool health and availability is a direct countermeasure to defense impairment, alerting when anti-malware services stop, logging is disabled, or firewall rules are modified without authorization."},{"id":"T1565","name":"Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of data integrity—through checksums, hash verification, and database integrity checks—enables detection of data manipulation by identifying unauthorized changes to stored or runtime data."},{"id":"T1566","name":"Phishing","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of email traffic and user behavior enables detection of phishing attempts by identifying suspicious inbound messages, tracking user interactions with potential phishing content, and correlating IOCs across mail flows."},{"id":"T1567","name":"Exfiltration Over Web Service","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of outbound web traffic can detect exfiltration to web services by identifying unusual data uploads to cloud storage, code repositories, or paste sites that deviate from normal user behavior."},{"id":"T1568","name":"Dynamic Resolution","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of DNS resolution patterns can detect dynamic resolution techniques by identifying DGA-generated domains, fast-flux behavior, and unusual DNS query patterns characteristic of adversary infrastructure."},{"id":"T1569","name":"System Services","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of service execution events can detect adversary use of system services by identifying unexpected service-creation events, unusual service-execution commands, and anomalous service behaviors."},{"id":"T1570","name":"Lateral Tool Transfer","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of internal file transfers can detect lateral tool movement by identifying unusual file-copy operations between systems, particularly transfers of executables and scripts to systems where they are not expected."},{"id":"T1571","name":"Non-Standard Port","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of network connections can detect C2 on non-standard ports by establishing port-usage baselines and alerting when protocols are observed on ports where they are not expected."},{"id":"T1572","name":"Protocol Tunneling","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of protocol behavior can detect tunneling by identifying protocol-within-protocol patterns—such as DNS tunneling or HTTP encapsulation—that indicate covert channel establishment."},{"id":"T1573","name":"Encrypted Channel","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of encrypted network connections can detect suspicious encrypted C2 channels by analyzing certificate attributes, connection durations, data volumes, and TLS fingerprints for anomalous patterns."},{"id":"T1574","name":"Hijack Execution Flow","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of library loading and execution paths can detect hijack execution flow by identifying unexpected DLL loads, modified library paths, and execution redirection through search-order manipulation."},{"id":"T1598","name":"Phishing for Information","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of inbound communications can detect phishing-for-information campaigns by identifying reconnaissance-focused social engineering messages and correlating targeting patterns across the organization."},{"id":"T1599","name":"Network Boundary Bridging","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of network boundary device configurations and traffic flow can detect network boundary bridging by identifying unauthorized route changes, NAT modifications, and traffic bypassing segmentation controls."},{"id":"T1602","name":"Data from Configuration Repository","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of network device management interfaces can detect unauthorized configuration extraction by identifying anomalous SNMP queries, unexpected management-protocol sessions, and bulk configuration downloads."},{"id":"T1622","name":"Debugger Evasion","tactics":["defense-evasion","discovery"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of process behavior and analysis-tool interactions can detect debugger evasion by identifying malware that checks for debugging environments, virtual machines, or analysis sandboxes before executing."},{"id":"T1647","name":"Plist File Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of plist file modifications on macOS systems can detect unauthorized configuration changes by establishing baselines for critical property-list files and alerting on unexpected modifications."},{"id":"T1001.001","name":"Junk Data","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of network traffic patterns can detect junk-data padding in C2 communications by identifying statistically anomalous packet sizes and payload characteristics that deviate from established protocol baselines."},{"id":"T1001.002","name":"Steganography","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of file transfers and network traffic enables detection of steganographic C2 by identifying unusual volumes of media-file transfers and anomalous data patterns within image, audio, or video content."},{"id":"T1001.003","name":"Protocol or Service Impersonation","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring with deep protocol analysis can detect protocol impersonation by identifying C2 traffic that mimics legitimate services but exhibits subtle deviations in protocol compliance, timing, and structure."},{"id":"T1003.001","name":"LSASS Memory","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of LSASS process access can detect credential-dumping attempts by alerting when unauthorized processes read LSASS memory, open LSASS handles, or create LSASS memory dumps."},{"id":"T1003.002","name":"Security Account Manager","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of registry access patterns can detect SAM database extraction by identifying suspicious access to the SAM hive, particularly through volume shadow copies or registry save operations."},{"id":"T1003.003","name":"NTDS","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of Active Directory operations can detect NTDS.dit extraction by alerting on volume shadow copy creation on domain controllers, ntdsutil usage, and suspicious database file access."},{"id":"T1003.004","name":"LSA Secrets","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of registry access can detect LSA secret extraction by identifying unauthorized reads of the LSA Secrets registry keys and suspicious use of tools that query encrypted credential stores."},{"id":"T1003.005","name":"Cached Domain Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of credential cache access can detect extraction of cached domain credentials by identifying suspicious registry reads targeting cached logon data and DCC2 hash locations."},{"id":"T1003.006","name":"DCSync","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of Active Directory replication events can detect DCSync attacks by identifying directory replication requests from non-domain-controller systems using the MS-DRSR protocol."},{"id":"T1003.007","name":"Proc Filesystem","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of /proc filesystem access can detect credential extraction on Linux by alerting when processes read memory maps of authentication-related processes through /proc/[pid]/maps and /proc/[pid]/mem."},{"id":"T1003.008","name":"/etc/passwd and /etc/shadow","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of file access to /etc/passwd and /etc/shadow can detect credential harvesting by alerting on unauthorized read operations targeting these critical authentication files."},{"id":"T1021.002","name":"SMB/Windows Admin Shares","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of SMB session establishment can detect lateral movement via admin shares by identifying unusual SMB connections to C$, ADMIN$, and IPC$ shares, particularly from non-administrative workstations."},{"id":"T1021.005","name":"VNC","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of remote access connections can detect unauthorized VNC usage by identifying VNC protocol traffic from unexpected sources and VNC server processes on systems where they are not authorized."},{"id":"T1036.003","name":"Rename System Utilities","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of system binary integrity can detect renamed utilities by comparing file hashes at monitored paths against known-good values, alerting when legitimate tool names correspond to unauthorized binaries."},{"id":"T1036.005","name":"Match Legitimate Name or Location","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of file metadata and locations can detect masquerading by identifying executables whose names match legitimate software but whose hashes, signatures, or behavioral profiles differ from authorized versions."},{"id":"T1036.007","name":"Double File Extension","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of file-naming patterns can detect double file extension tricks by identifying files with deceptive extensions like .pdf.exe or .doc.scr that attempt to mislead users about true file types."},{"id":"T1037.002","name":"Login Hook","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of macOS login configuration can detect malicious login hooks by alerting on changes to the LoginHook and LogoutHook settings that trigger script execution at user authentication events."},{"id":"T1037.003","name":"Network Logon Script","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of Group Policy objects and SYSVOL can detect malicious network logon scripts by identifying new or modified scripts in NETLOGON shares that execute across domain-joined systems at logon."},{"id":"T1037.004","name":"RC Scripts","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of system initialization configurations on Unix systems can detect malicious RC scripts by alerting on modifications to boot-time script directories and init.d configurations."},{"id":"T1037.005","name":"Startup Items","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of macOS LaunchDaemons and LaunchAgents directories can detect malicious startup items by alerting on new plist entries and unauthorized executables registered for startup execution."},{"id":"T1048.001","name":"Exfiltration Over Symmetric Encrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of encrypted outbound connections can detect exfiltration over symmetric-encrypted non-C2 protocols by identifying unusual encrypted sessions to unrecognized destinations outside normal business patterns."},{"id":"T1048.002","name":"Exfiltration Over Asymmetric Encrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of TLS/SSH connections can detect exfiltration over asymmetric-encrypted channels by identifying unusual certificate usage, unexpected encrypted connections, and anomalous data volumes to external hosts."},{"id":"T1048.003","name":"Exfiltration Over Unencrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of unencrypted outbound traffic can detect plaintext exfiltration by identifying suspicious FTP, HTTP, DNS, or raw-socket data transfers to unauthorized external destinations."},{"id":"T1052.001","name":"Exfiltration over USB","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of USB device connections and file-copy operations can detect exfiltration over USB by alerting on large file transfers to removable media, particularly involving sensitive data classifications."},{"id":"T1053.006","name":"Systemd Timers","tactics":["execution","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of systemd timer configurations can detect malicious scheduled tasks on Linux by identifying new or modified timer units that trigger unauthorized command execution at specified intervals."},{"id":"T1055.009","name":"Proc Memory","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of /proc/[pid]/mem write access can detect proc-memory injection on Linux by alerting when processes write executable code to other processes' memory spaces through the proc filesystem."},{"id":"T1056.002","name":"GUI Input Capture","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of GUI window creation can detect fake input-capture dialogs by identifying unauthorized overlay windows mimicking authentication prompts that harvest user credentials."},{"id":"T1059.005","name":"Visual Basic","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of Visual Basic execution can detect malicious VBS/VBA by identifying suspicious script launches, encoded VB payloads, and macro-enabled document execution patterns associated with initial-access campaigns."},{"id":"T1059.007","name":"JavaScript","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of JavaScript execution can detect malicious JS by identifying suspicious wscript/cscript invocations, encoded JavaScript payloads, and browser-based script execution anomalies."},{"id":"T1059.010","name":"AutoHotKey & AutoIT","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of automation tool execution can detect malicious AutoHotKey and AutoIT by identifying compiled AHK/AU3 scripts, suspicious automation patterns, and keystroke-recording behaviors."},{"id":"T1070.001","name":"Clear Windows Event Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of Windows Event Log integrity enables detection of log-clearing by alerting on Event ID 1102 (audit log cleared), unexpected wevtutil invocations, and gaps in expected log sequences."},{"id":"T1070.002","name":"Clear Linux or Mac System Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of syslog integrity on Unix/macOS systems enables detection of log tampering by alerting on unexpected log truncation, deletion, and modification of system log files."},{"id":"T1070.003","name":"Clear Command History","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of command-history file integrity can detect history clearing by alerting on truncation or deletion of .bash_history, .zsh_history, and PSReadLine files."},{"id":"T1070.007","name":"Clear Network Connection History and Configurations","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of network configuration state can detect clearing of connection history by identifying unexpected deletion of WiFi profiles, ARP table flushes, and DNS cache clearing events."},{"id":"T1070.008","name":"Clear Mailbox Data","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of mailbox activity can detect bulk email deletion by alerting on unusual mass-delete operations that may indicate adversary attempts to remove evidence from email systems."},{"id":"T1070.009","name":"Clear Persistence","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of persistence mechanism integrity can detect adversary cleanup by alerting when registry keys, scheduled tasks, services, or other persistence artifacts are unexpectedly removed."},{"id":"T1071.001","name":"Web Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of HTTP/HTTPS traffic patterns enables detection of web-protocol C2 by identifying abnormal request frequencies, unusual URL patterns, suspicious header values, and beaconing behavior."},{"id":"T1071.002","name":"File Transfer Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of file-transfer protocol usage can detect FTP/FTPS-based C2 by identifying unexpected FTP sessions, anomalous transfer patterns, and connections to unauthorized file-transfer servers."},{"id":"T1071.003","name":"Mail Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of mail-protocol traffic can detect SMTP/IMAP/POP3-based C2 by identifying unusual mail-server connections, abnormal message patterns, and email-based command-and-control activity."},{"id":"T1071.004","name":"DNS","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of DNS query patterns enables detection of DNS-based C2 by identifying high-entropy subdomains, unusual query volumes, TXT record abuse, and other DNS tunneling indicators."},{"id":"T1078.001","name":"Default Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of default account usage can detect adversary exploitation by alerting on authentication events from known default accounts that should be disabled, renamed, or restricted."},{"id":"T1078.003","name":"Local Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of local account authentication can detect adversary use of compromised local accounts by identifying logon events from unusual sources, at unusual times, or following dormancy periods."},{"id":"T1078.004","name":"Cloud Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of cloud account activity can detect adversary use of compromised cloud accounts by identifying anomalous API calls, unusual resource access patterns, and authentication from unexpected locations."},{"id":"T1090.001","name":"Internal Proxy","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of internal network connections can detect adversary-deployed internal proxies by identifying systems relaying traffic to other internal systems in patterns inconsistent with authorized proxy services."},{"id":"T1090.002","name":"External Proxy","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of outbound connections can detect external proxy usage by identifying connections to known proxy infrastructure, unusual SOCKS/HTTP proxy patterns, and connections through anonymization services."},{"id":"T1090.003","name":"Multi-hop Proxy","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of network connection chains can detect multi-hop proxy configurations by identifying traffic that traverses multiple intermediary systems, characteristic of adversary connection obfuscation."},{"id":"T1102.001","name":"Dead Drop Resolver","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of web-service API interactions can detect dead-drop resolver usage by identifying unusual polling patterns to social media, paste sites, or cloud storage for C2 address resolution."},{"id":"T1102.002","name":"Bidirectional Communication","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of web-service data exchanges can detect bidirectional C2 through legitimate platforms by identifying persistent, unusual data flows with cloud services characteristic of command relay."},{"id":"T1102.003","name":"One-Way Communication","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of outbound web requests can detect one-way C2 communication by identifying periodic retrieval of content from web services that matches known C2 command-retrieval patterns."},{"id":"T1110.001","name":"Password Guessing","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of authentication failures can detect password guessing by identifying high volumes of failed login attempts against specific accounts, particularly from unusual source addresses."},{"id":"T1110.002","name":"Password Cracking","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of credential-related events can detect password-cracking activity by identifying offline cracking indicators—such as bulk hash extraction—and correlating with subsequent successful authentications."},{"id":"T1110.003","name":"Password Spraying","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of authentication events across accounts can detect password spraying by identifying patterns where the same password is tried against multiple accounts within a short time window."},{"id":"T1110.004","name":"Credential Stuffing","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of login attempts can detect credential stuffing by identifying authentication attempts using known-breached credential pairs, particularly from distributed sources or automated tooling."},{"id":"T1132.001","name":"Standard Encoding","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of network traffic can detect standard-encoding in C2 by identifying Base64, URL-encoding, or other standard encoding in protocol contexts where plaintext is expected."},{"id":"T1132.002","name":"Non-Standard Encoding","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of network traffic entropy can detect non-standard encoding in C2 by identifying data with unusual encoding characteristics that do not match known standard encoding schemes."},{"id":"T1195.001","name":"Compromise Software Dependencies and Development Tools","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of software dependencies can detect compromised development tools by tracking dependency changes, verifying package integrity, and alerting on unexpected modifications to build-chain components."},{"id":"T1195.002","name":"Compromise Software Supply Chain","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of software supply chain integrity can detect compromised software distributions by verifying code signatures, comparing binaries against trusted repositories, and alerting on unauthorized modifications."},{"id":"T1204.001","name":"Malicious Link","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of user browsing and link-click activity can detect successful social engineering by identifying when users navigate to malicious URLs and correlating with subsequent endpoint compromise indicators."},{"id":"T1204.002","name":"Malicious File","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of file execution events can detect user execution of malicious files by identifying when users launch unexpected executables, open suspicious document types, or trigger macro-enabled content."},{"id":"T1204.003","name":"Malicious Image","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of container image deployments can detect execution of malicious images by identifying unauthorized container launches, images from untrusted registries, and containers with unexpected behaviors."},{"id":"T1205.001","name":"Port Knocking","tactics":["command-and-control","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of network traffic can detect port-knocking sequences by identifying specific patterns of connection attempts across multiple ports that precede the activation of hidden services."},{"id":"T1213.001","name":"Confluence","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of Confluence access logs can detect unauthorized data collection by identifying unusual page-access volumes, bulk content downloads, and access from compromised accounts."},{"id":"T1213.002","name":"Sharepoint","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of SharePoint access patterns can detect data harvesting by identifying anomalous document-library access, bulk file downloads, and unauthorized search queries across SharePoint sites."},{"id":"T1213.003","name":"Code Repositories","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of code repository access can detect unauthorized data collection by identifying unusual clone operations, bulk file downloads, and access to repositories outside a user's normal scope."},{"id":"T1213.004","name":"Customer Relationship Management Software","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of CRM system access can detect unauthorized data collection by identifying unusual query patterns, bulk record exports, and access to customer data outside normal business workflows."},{"id":"T1213.005","name":"Messaging Applications","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of messaging application usage can detect unauthorized data harvesting by identifying unusual message-search patterns, bulk message exports, and anomalous access to messaging archives."},{"id":"T1218.002","name":"Control Panel","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of Control Panel item execution can detect proxy execution through malicious .cpl files by identifying unusual control-panel loads and unexpected DLL execution through the Control Panel interface."},{"id":"T1218.010","name":"Regsvr32","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of regsvr32.exe execution can detect proxy execution by identifying regsvr32 invocations loading DLLs from unusual locations, with suspicious command-line arguments, or using the /s /n /u /i flags for scriptlet execution."},{"id":"T1218.011","name":"Rundll32","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of rundll32.exe execution can detect proxy execution by identifying rundll32 loading DLLs from unexpected paths, with anomalous export-function arguments, or spawning suspicious child processes."},{"id":"T1218.012","name":"Verclsid","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of verclsid.exe execution can detect proxy execution by identifying unusual COM class verification events that trigger loading of malicious DLLs through CLSID resolution."},{"id":"T1218.015","name":"Electron Applications","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of Electron application behavior can detect malicious code execution through modified Electron apps by identifying unexpected Node.js operations, suspicious IPC calls, and anomalous file-system access."},{"id":"T1222.001","name":"Windows File and Directory Permissions Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of Windows file permission changes can detect unauthorized ACL modifications by alerting on bulk DACL changes, icacls/cacls usage, and permission weakening on sensitive directories."},{"id":"T1222.002","name":"Linux and Mac File and Directory Permissions Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of Unix/Linux file permissions can detect unauthorized chmod/chown operations by alerting on permission changes to sensitive files, directories, and system binaries."},{"id":"T1498.001","name":"Direct Network Flood","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of inbound traffic volumes enables early detection of direct network floods by identifying sudden traffic spikes from single or distributed sources targeting organizational network infrastructure."},{"id":"T1498.002","name":"Reflection Amplification","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of network traffic can detect reflection-amplification attacks by identifying asymmetric traffic patterns where small queries generate disproportionately large responses from third-party services."},{"id":"T1499.001","name":"OS Exhaustion Flood","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of operating system resource utilization can detect OS exhaustion floods by identifying abnormal connection-table consumption, socket exhaustion, and kernel-resource depletion patterns."},{"id":"T1499.002","name":"Service Exhaustion Flood","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of service health metrics can detect service exhaustion floods by identifying unusual connection rates, request volumes, and resource consumption targeting specific services."},{"id":"T1499.003","name":"Application Exhaustion Flood","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of application performance can detect application exhaustion floods by identifying abnormal request patterns that consume excessive application-level resources such as memory, CPU, or database connections."},{"id":"T1499.004","name":"Application or System Exploitation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of application behavior can detect denial-of-service through exploitation by identifying crash patterns, unexpected restarts, and exploitation indicators targeting application vulnerabilities."},{"id":"T1542.004","name":"ROMMONkit","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of network device firmware integrity can detect ROMMONkit implants by comparing boot ROM images against known-good baselines and alerting on unauthorized firmware modifications."},{"id":"T1542.005","name":"TFTP Boot","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of network boot configurations can detect TFTP boot manipulation by identifying unauthorized changes to boot server settings and unexpected TFTP boot image downloads."},{"id":"T1543.002","name":"Systemd Service","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of systemd service configurations can detect malicious service creation by alerting on new unit files, unauthorized ExecStart modifications, and suspicious service registrations on Linux systems."},{"id":"T1546.003","name":"Windows Management Instrumentation Event Subscription","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of WMI event subscriptions can detect malicious persistence by alerting on new permanent event consumers, FilterToConsumerBindings, and suspicious WMI subscription activity."},{"id":"T1546.004","name":"Unix Shell Configuration Modification","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of shell configuration files (.bashrc, .profile, .zshrc) can detect persistence through unauthorized modifications that execute adversary code at every interactive shell session."},{"id":"T1546.013","name":"PowerShell Profile","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of PowerShell profile file integrity can detect persistence by alerting on unauthorized modifications to profile scripts that execute code at every PowerShell session startup."},{"id":"T1546.016","name":"Installer Packages","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of software installation events can detect malicious installer packages by identifying unauthorized installations, suspicious pre/post-install scripts, and unexpected package sources."},{"id":"T1547.003","name":"Time Providers","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of Windows Time Service configuration can detect malicious time providers by identifying unauthorized DLLs registered as W32Time providers that load with the time service."},{"id":"T1547.013","name":"XDG Autostart Entries","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of XDG autostart directories on Linux systems can detect persistence by alerting on new or modified .desktop files that configure unauthorized executables to launch at user login."},{"id":"T1548.003","name":"Sudo and Sudo Caching","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of sudo usage and sudoers configuration can detect privilege escalation by identifying unusual sudo invocations, sudoers modifications, and sudo-caching exploitation patterns."},{"id":"T1548.006","name":"TCC Manipulation","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of macOS TCC database integrity can detect TCC manipulation by alerting on unauthorized modifications to the TCC.db that grant permissions without user consent."},{"id":"T1550.003","name":"Pass the Ticket","tactics":["defense-evasion","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of Kerberos ticket usage can detect pass-the-ticket attacks by identifying ticket use from systems different from those that originally requested the tickets."},{"id":"T1552.001","name":"Credentials In Files","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring and scanning of file systems can detect unsecured credentials in files by identifying plaintext passwords, API keys, and secrets stored in configuration files, scripts, and documents."},{"id":"T1552.002","name":"Credentials in Registry","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of Windows registry can detect credentials stored in registry by identifying sensitive authentication material in registry keys that should not contain plaintext credential data."},{"id":"T1552.004","name":"Private Keys","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of private key storage locations can detect unauthorized access to cryptographic keys by alerting on unusual read operations targeting .pem, .pfx, and SSH private key files."},{"id":"T1552.005","name":"Cloud Instance Metadata API","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of cloud instance metadata API access can detect credential harvesting by identifying unusual requests to instance metadata endpoints from applications that should not need temporary credentials."},{"id":"T1553.003","name":"SIP and Trust Provider Hijacking","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of SIP and trust provider registry entries can detect hijacking attempts by alerting on modifications to Subject Interface Package DLLs and trust-verification configurations."},{"id":"T1555.001","name":"Keychain","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of macOS Keychain access can detect credential theft by identifying unusual keychain unlock events, bulk secret retrieval, and access from unauthorized applications."},{"id":"T1555.002","name":"Securityd Memory","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of securityd process memory access can detect credential extraction by identifying unauthorized processes reading macOS security daemon memory to harvest cached credentials."},{"id":"T1556.001","name":"Domain Controller Authentication","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of domain controller authentication libraries can detect modifications by alerting on changes to LSASS-loaded authentication DLLs and password-filter modules on domain controllers."},{"id":"T1557.001","name":"LLMNR/NBT-NS Poisoning and SMB Relay","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of LLMNR and NBT-NS traffic can detect poisoning attacks by identifying rogue responses to name-resolution broadcasts and unexpected SMB relay activity on the network."},{"id":"T1557.002","name":"ARP Cache Poisoning","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of ARP tables and traffic can detect cache poisoning by identifying gratuitous ARP anomalies, MAC-address conflicts, and sudden ARP-table changes indicating man-in-the-middle positioning."},{"id":"T1557.003","name":"DHCP Spoofing","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of DHCP traffic can detect spoofing by identifying rogue DHCP servers, conflicting lease offers, and unauthorized gateway/DNS settings pushed to network clients."},{"id":"T1557.004","name":"Evil Twin","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of wireless network environments can detect evil twin access points by identifying rogue SSIDs, signal-strength anomalies, and duplicate wireless network names in the environment."},{"id":"T1558.002","name":"Silver Ticket","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of Kerberos service-ticket usage can detect silver ticket attacks by identifying forged service tickets that bypass the KDC, correlating tickets with expected issuance records."},{"id":"T1558.003","name":"Kerberoasting","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of TGS request patterns can detect kerberoasting by identifying unusual volumes of service-ticket requests—particularly for service accounts with SPNs—followed by offline cracking indicators."},{"id":"T1558.004","name":"AS-REP Roasting","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of AS-REP responses can detect AS-REP roasting by identifying accounts receiving responses without pre-authentication and correlating with unusual TGT request patterns."},{"id":"T1558.005","name":"Ccache Files","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of ccache file access on Linux/macOS can detect Kerberos ticket theft by alerting on unauthorized reads of /tmp/krb5cc_* and other credential cache locations."},{"id":"T1562.001","name":"Disable or Modify Tools","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of security tool health provides direct detection of defense impairment by alerting when anti-malware, EDR, or other security agents stop running, are uninstalled, or have their configurations modified."},{"id":"T1562.002","name":"Disable Windows Event Logging","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of Windows Event Logging status enables detection of logging disablement by alerting when audit policies are weakened, the EventLog service is stopped, or logging configurations are modified."},{"id":"T1562.004","name":"Disable or Modify System Firewall","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of firewall rule changes can detect defense impairment by alerting on unauthorized rule additions, deletions, or modifications that weaken network-level access controls."},{"id":"T1562.006","name":"Indicator Blocking","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of security-telemetry pipeline health can detect indicator blocking by alerting when ETW providers are disabled, AMSI is bypassed, or event-forwarding configurations are tampered with."},{"id":"T1563.001","name":"SSH Hijacking","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of SSH session activity can detect SSH hijacking by identifying unusual SSH connections reusing existing sessions, SSH agent forwarding abuse, and unauthorized session takeover patterns."},{"id":"T1564.004","name":"NTFS File Attributes","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of NTFS alternate data streams can detect hidden content by scanning for executable code stored in ADS, identifying a common technique for concealing malicious payloads in plain sight."},{"id":"T1564.010","name":"Process Argument Spoofing","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of process command-line arguments can detect argument spoofing by comparing initial command lines captured at process creation with runtime arguments that may have been modified post-launch."},{"id":"T1565.001","name":"Stored Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of stored data integrity can detect manipulation by comparing data checksums and database records against known-good baselines, alerting on unauthorized modifications to critical data stores."},{"id":"T1565.003","name":"Runtime Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of application behavior and data-processing results can detect runtime data manipulation by identifying output discrepancies and unexpected data transformations during processing."},{"id":"T1566.001","name":"Spearphishing Attachment","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of inbound email can detect spearphishing attachments by scanning all attachments at the gateway, sandboxing suspicious files, and correlating with threat intelligence on active campaigns."},{"id":"T1566.002","name":"Spearphishing Link","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of email URLs can detect spearphishing links by analyzing embedded URLs against threat intelligence, identifying newly registered domains, and blocking access to known phishing infrastructure."},{"id":"T1566.003","name":"Spearphishing via Service","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of messages through collaboration services can detect spearphishing via third-party platforms by scanning for malicious content delivered through Slack, Teams, social media, and similar services."},{"id":"T1568.002","name":"Domain Generation Algorithms","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of DNS resolution patterns can detect domain generation algorithms by identifying queries for domains with high entropy, no legitimate registration history, and characteristics of algorithmically generated names."},{"id":"T1569.002","name":"Service Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of Windows service creation events can detect malicious service execution by identifying new services with suspicious binary paths, unusual service names, or unexpected service-creation patterns."},{"id":"T1573.001","name":"Symmetric Cryptography","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of encrypted connection characteristics can detect symmetric-cryptography C2 channels by identifying unusual TLS session parameters, custom encryption indicators, and anomalous connection patterns."},{"id":"T1573.002","name":"Asymmetric Cryptography","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of TLS certificate usage can detect asymmetric-cryptography C2 channels by identifying self-signed certificates, unusual certificate authorities, and certificate attributes associated with adversary infrastructure."},{"id":"T1574.004","name":"Dylib Hijacking","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of dynamic library loading on macOS can detect dylib hijacking by identifying unexpected dylib loads from non-standard paths when legitimate applications execute."},{"id":"T1574.007","name":"Path Interception by PATH Environment Variable","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of PATH environment variable state and executable loading can detect path interception by identifying unexpected binaries being loaded from directories injected early in the PATH."},{"id":"T1574.008","name":"Path Interception by Search Order Hijacking","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of DLL and executable loading sequences can detect search-order hijacking by identifying instances where libraries are loaded from unexpected directories due to predictable search-order behavior."},{"id":"T1574.009","name":"Path Interception by Unquoted Path","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of service binary paths can detect unquoted-path exploitation by identifying services with unquoted paths and monitoring for executable placement at exploitable path segments."},{"id":"T1574.013","name":"KernelCallbackTable","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of process environment block integrity can detect KernelCallbackTable hijacking by identifying unauthorized modifications to the PEB's callback table pointer in running processes."},{"id":"T1574.014","name":"AppDomainManager","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of .NET application configuration can detect AppDomainManager hijacking by identifying unauthorized config files or assemblies that redirect CLR loading to adversary-controlled code."},{"id":"T1598.001","name":"Spearphishing Service","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of inbound messages through collaboration services can detect reconnaissance-stage spearphishing by identifying social engineering attempts that gather organizational information."},{"id":"T1598.002","name":"Spearphishing Attachment","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of inbound email can detect reconnaissance spearphishing attachments by scanning attachments for tracking mechanisms, information-gathering payloads, and credential-harvesting content."},{"id":"T1598.003","name":"Spearphishing Link","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of email URLs can detect reconnaissance spearphishing links by analyzing embedded URLs for credential-harvesting pages, tracking pixels, and information-gathering infrastructure."},{"id":"T1599.001","name":"Network Address Translation Traversal","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of NAT configurations on boundary devices can detect unauthorized NAT traversal by alerting on configuration changes that create paths bypassing network segmentation controls."},{"id":"T1602.001","name":"SNMP (MIB Dump)","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Ongoing monitoring of SNMP activity can detect MIB dump operations by identifying unusual SNMP walk/get-bulk queries targeting device configuration OIDs from unauthorized management stations."},{"id":"T1602.002","name":"Network Device Configuration Dump","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of network device management sessions can detect configuration dumps by identifying unauthorized connections to management interfaces and bulk configuration-retrieval operations."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: iso_27001_2022 A.5.36 added from NIST's SP 800-53 Rev 5 to ISO/IEC 27001:2022 crosswalk (OLIR entry 155), which OSA's mapping now takes as its base. 2026-10-03: nist_csf_2 DE.AE-02, DE.AE-03, DE.CM-02, DE.CM-03, DE.CM-09, ID.IM-02, ID.RA-01, ID.RA-07 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"detective","used_by_patterns":["SP-001","SP-002","SP-006","SP-007","SP-011","SP-013","SP-015","SP-017","SP-018","SP-023","SP-026","SP-027","SP-028","SP-029","SP-030","SP-031","SP-032","SP-034","SP-035","SP-036","SP-037","SP-038","SP-040","SP-041","SP-042","SP-043","SP-044","SP-045","SP-046","SP-047","SP-048","SP-049","SP-051","SP-053","SP-054"]}}