{"data":{"id":"SI-04","name":"System Monitoring","family":"SI","family_name":"System and Information Integrity","withdrawn":false,"description":"a. Monitor the system to detect:\n1. Attacks and indicators of potential attacks in accordance with the following monitoring objectives: [Assignment: organization-defined monitoring objectives]; and\n2. Unauthorized local, network, and remote connections;\nb. Identify unauthorized use of the system through the following techniques and methods: [Assignment: organization-defined techniques and methods];\nc. Invoke internal monitoring capabilities or deploy monitoring devices:\n1. Strategically within the system to collect organization-determined essential information; and\n2. At ad hoc locations within the system to track specific types of transactions of interest to the organization;\nd. Analyze detected events and anomalies;\ne. Adjust the level of system monitoring activity when there is a change in risk to organizational operations and assets, individuals, other organizations, or the Nation;\nf. Obtain legal opinion regarding system monitoring activities; and\ng. Provide [Assignment: organization-defined system monitoring information] to [Assignment: organization-defined personnel or roles] [Selection (one or more): as needed; [Assignment: organization-defined frequency]].","supplemental_guidance":"System monitoring includes external and internal monitoring. External monitoring includes the observation of events occurring at external interfaces to the system. Internal monitoring includes the observation of events occurring within the system. Organizations monitor systems by observing audit activities in real time or by observing other system aspects such as access patterns, characteristics of access, and other actions. The monitoring objectives guide and inform the determination of the events. System monitoring capabilities are achieved through a variety of tools and techniques, including intrusion detection and prevention systems, malicious code protection software, scanning tools, audit record monitoring software, and network monitoring software.\n\nDepending on the security architecture, the distribution and configuration of monitoring devices may impact throughput at key internal and external boundaries as well as at other locations across a network due to the introduction of network throughput latency. If throughput management is needed, such devices are strategically located and deployed as part of an established organization-wide security architecture. Strategic locations for monitoring devices include selected perimeter locations and near key servers and server farms that support critical applications. Monitoring devices are typically employed at the managed interfaces associated with controls SC-07 and AC-17. The information collected is a function of the organizational monitoring objectives and the capability of systems to support such objectives. Specific types of transactions of interest include Hypertext Transfer Protocol (HTTP) traffic that bypasses HTTP proxies. System monitoring is an integral part of organizational continuous monitoring and incident response programs, and output from system monitoring serves as input to those programs. System monitoring requirements, including the need for specific types of system monitoring, may be referenced in other controls (e.g., AC-02g, AC-02(07), AC-02(12)(a), AC-17(01), AU-13, AU-13(01), AU-13(02), CM-03f, CM-06d, MA-03a, MA-04a, SC-05(03)(b), SC-07a, SC-07(24)(b), SC-18b, SC-43b). Adjustments to levels of system monitoring are based on law enforcement information, intelligence information, or other sources of information. The legality of system monitoring activities is based on applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.","enhancements":[{"id":"SI-04(01)","name":"System-wide Intrusion Detection System","statement":"Connect and configure individual intrusion detection tools into a system-wide intrusion detection system.","baselines":[]},{"id":"SI-04(02)","name":"Automated Tools and Mechanisms for Real-time Analysis","statement":"Employ automated tools and mechanisms to support near real-time analysis of events.","baselines":["moderate","high"]},{"id":"SI-04(03)","name":"Automated Tool and Mechanism Integration","statement":"Employ automated tools and mechanisms to integrate intrusion detection tools and mechanisms into access control and flow control mechanisms.","baselines":[]},{"id":"SI-04(04)","name":"Inbound and Outbound Communications Traffic","statement":"a. Determine criteria for unusual or unauthorized activities or conditions for inbound and outbound communications traffic;\nb. Monitor inbound and outbound communications traffic [Assignment: organization-defined frequency] for [Assignment: organization-defined unusual or unauthorized activities or conditions].","baselines":["moderate","high"]},{"id":"SI-04(05)","name":"System-generated Alerts","statement":"Alert [Assignment: organization-defined personnel or roles] when the following system-generated indications of compromise or potential compromise occur: [Assignment: organization-defined compromise indicators].","baselines":["moderate","high"]},{"id":"SI-04(06)","name":"Restrict Non-privileged Users","withdrawn":true,"incorporated_into":["AC-06(10)"]},{"id":"SI-04(07)","name":"Automated Response to Suspicious Events","statement":"a. Notify [Assignment: organization-defined incident response personnel (identified by name and/or by role)] of detected suspicious events; and\nb. Take the following actions upon detection: [Assignment: organization-defined least-disruptive actions to terminate suspicious events].","baselines":[]},{"id":"SI-04(08)","name":"Protection of Monitoring Information","withdrawn":true,"incorporated_into":["SI-04"]},{"id":"SI-04(09)","name":"Testing of Monitoring Tools and Mechanisms","statement":"Test intrusion-monitoring tools and mechanisms [Assignment: organization-defined frequency].","baselines":[]},{"id":"SI-04(10)","name":"Visibility of Encrypted Communications","statement":"Make provisions so that [Assignment: organization-defined encrypted communications traffic] is visible to [Assignment: organization-defined system monitoring tools and mechanisms].","baselines":["high"]},{"id":"SI-04(11)","name":"Analyze Communications Traffic Anomalies","statement":"Analyze outbound communications traffic at the external interfaces to the system and selected [Assignment: organization-defined interior points within the system] to discover anomalies.","baselines":[]},{"id":"SI-04(12)","name":"Automated Organization-generated Alerts","statement":"Alert [Assignment: organization-defined personnel or roles] using [Assignment: organization-defined automated mechanisms] when the following indications of inappropriate or unusual activities with security or privacy implications occur: [Assignment: organization-defined activities that trigger alerts].","baselines":["high"]},{"id":"SI-04(13)","name":"Analyze Traffic and Event Patterns","statement":"a. Analyze communications traffic and event patterns for the system;\nb. Develop profiles representing common traffic and event patterns; and\nc. Use the traffic and event profiles in tuning system-monitoring devices.","baselines":[]},{"id":"SI-04(14)","name":"Wireless Intrusion Detection","statement":"Employ a wireless intrusion detection system to identify rogue wireless devices and to detect attack attempts and potential compromises or breaches to the system.","baselines":["high"]},{"id":"SI-04(15)","name":"Wireless to Wireline Communications","statement":"Employ an intrusion detection system to monitor wireless communications traffic as the traffic passes from wireless to wireline networks.","baselines":[]},{"id":"SI-04(16)","name":"Correlate Monitoring Information","statement":"Correlate information from monitoring tools and mechanisms employed throughout the system.","baselines":[]},{"id":"SI-04(17)","name":"Integrated Situational Awareness","statement":"Correlate information from monitoring physical, cyber, and supply chain activities to achieve integrated, organization-wide situational awareness.","baselines":[]},{"id":"SI-04(18)","name":"Analyze Traffic and Covert Exfiltration","statement":"Analyze outbound communications traffic at external interfaces to the system and at the following interior points to detect covert exfiltration of information: [Assignment: organization-defined interior points within the system].","baselines":[]},{"id":"SI-04(19)","name":"Risk for Individuals","statement":"Implement [Assignment: organization-defined additional monitoring] of individuals who have been identified by [Assignment: organization-defined sources] as posing an increased level of risk.","baselines":[]},{"id":"SI-04(20)","name":"Privileged Users","statement":"Implement the following additional monitoring of privileged users: [Assignment: organization-defined additional monitoring].","baselines":["high"]},{"id":"SI-04(21)","name":"Probationary Periods","statement":"Implement the following additional monitoring of individuals during [Assignment: organization-defined probationary period]: [Assignment: organization-defined additional monitoring].","baselines":[]},{"id":"SI-04(22)","name":"Unauthorized Network Services","statement":"a. Detect network services that have not been authorized or approved by [Assignment: organization-defined authorization or approval processes]; and\nb. [Selection (one or more): Audit; Alert [Assignment: organization-defined personnel or roles]] when detected.","baselines":["high"]},{"id":"SI-04(23)","name":"Host-based Devices","statement":"Implement the following host-based monitoring mechanisms at [Assignment: organization-defined system components]: [Assignment: organization-defined host-based monitoring mechanisms].","baselines":[]},{"id":"SI-04(24)","name":"Indicators of Compromise","statement":"Discover, collect, and distribute to [Assignment: organization-defined personnel or roles], indicators of compromise provided by [Assignment: organization-defined sources].","baselines":[]},{"id":"SI-04(25)","name":"Optimize Network Traffic Analysis","statement":"Provide visibility into network traffic at external and key internal system interfaces to optimize the effectiveness of monitoring devices.","baselines":[]}],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"nist_800_53":{"rev5":{"id":"SI-04","name":"System Monitoring","description":"a. Monitor the system to detect:\n1. Attacks and indicators of potential attacks in accordance with the following monitoring objectives: [Assignment: organization-defined monitoring objectives]; and\n2. Unauthorized local, network, and remote connections;\nb. Identify unauthorized use of the system through the following techniques and methods: [Assignment: organization-defined techniques and methods];\nc. Invoke internal monitoring capabilities or deploy monitoring devices:\n1. Strategically within the system to collect organization-determined essential information; and\n2. At ad hoc locations within the system to track specific types of transactions of interest to the organization;\nd. Analyze detected events and anomalies;\ne. Adjust the level of system monitoring activity when there is a change in risk to organizational operations and assets, individuals, other organizations, or the Nation;\nf. Obtain legal opinion regarding system monitoring activities; and\ng. Provide [Assignment: organization-defined system monitoring information] to [Assignment: organization-defined personnel or roles] [Selection (one or more): as needed; [Assignment: organization-defined frequency]].","discussion":"System monitoring includes external and internal monitoring. External monitoring includes the observation of events occurring at external interfaces to the system. Internal monitoring includes the observation of events occurring within the system. Organizations monitor systems by observing audit activities in real time or by observing other system aspects such as access patterns, characteristics of access, and other actions. The monitoring objectives guide and inform the determination of the events. System monitoring capabilities are achieved through a variety of tools and techniques, including intrusion detection and prevention systems, malicious code protection software, scanning tools, audit record monitoring software, and network monitoring software.\n\nDepending on the security architecture, the distribution and configuration of monitoring devices may impact throughput at key internal and external boundaries as well as at other locations across a network due to the introduction of network throughput latency. If throughput management is needed, such devices are strategically located and deployed as part of an established organization-wide security architecture. Strategic locations for monitoring devices include selected perimeter locations and near key servers and server farms that support critical applications. Monitoring devices are typically employed at the managed interfaces associated with controls SC-07 and AC-17. The information collected is a function of the organizational monitoring objectives and the capability of systems to support such objectives. Specific types of transactions of interest include Hypertext Transfer Protocol (HTTP) traffic that bypasses HTTP proxies. System monitoring is an integral part of organizational continuous monitoring and incident response programs, and output from system monitoring serves as input to those programs. System monitoring requirements, including the need for specific types of system monitoring, may be referenced in other controls (e.g., AC-02g, AC-02(07), AC-02(12)(a), AC-17(01), AU-13, AU-13(01), AU-13(02), CM-03f, CM-06d, MA-03a, MA-04a, SC-05(03)(b), SC-07a, SC-07(24)(b), SC-18b, SC-43b). Adjustments to levels of system monitoring are based on law enforcement information, intelligence information, or other sources of information. The legality of system monitoring activities is based on applicable laws, executive orders, directives, regulations, policies, standards, and guidelines.","related_controls":["AC-02","AC-03","AC-04","AC-08","AC-17","AU-02","AU-06","AU-07","AU-09","AU-12","AU-13","AU-14","CA-07","CM-03","CM-06","CM-08","CM-11","IA-10","IR-04","MA-03","MA-04","PL-09","PM-12","RA-05","RA-10","SC-05","SC-07","SC-18","SC-26","SC-31","SC-35","SC-36","SC-37","SC-43","SI-03","SI-06","SI-07","SR-09","SR-10"],"baseline_low":true,"baseline_moderate":true,"baseline_high":true,"baseline_privacy":false,"new_in_rev5":false,"changes_from_rev4":"Title changed from 'Information System Monitoring' Control text replaces 'Protect information obtained from intrusion-monitoring tools from unauthorized access, modification, and deletion' with 'Analyze detected events and anomalies' and replaces 'Heightens' with 'Adjust' Discussion expanded with references to other controls"}},"compliance_mappings":{"iso_27001_2022":["9.1","A.8.12","A.8.16"],"iso_27002_2022":["5.25","8.12","8.16"],"cobit_2019":["DSS01","DSS05","MEA01"],"pci_dss_v4":["10.4","10.7","11.2","11.5","11.6"],"nist_csf_2":["DE.AE-02","DE.AE-03","DE.AE-04","DE.AE-06","DE.CM-01","DE.CM-03","DE.CM-06","DE.CM-09","ID.IM-01","ID.IM-02","ID.IM-03","ID.RA-01","PR.DS-01","PR.DS-02","PR.DS-10","RS.AN-03"],"cis_controls_v8":["CIS 1.4","CIS 3.13","CIS 8.7","CIS 8.9","CIS 10","CIS 10.7","CIS 13","CIS 13.1","CIS 13.2","CIS 13.3","CIS 13.6","CIS 13.7","CIS 13.8","CIS 13.10","CIS 13.11"],"soc2_tsc":["CC6.6","CC6.6-POF2","CC7.2","CC7.2-POF1","CC7.3"],"finos_ccc":["CCC-C08"],"iso_42001_2023":["A.6.2.6"],"iec_62443":["3-3 SR 6.2"],"asd_e8":[],"nis2":[],"apra_cps_234":["Para 22-23"],"mas_trm":["11","12"],"pra_op_resilience":["SS2/21-7.1"],"bsi_grundschutz":["DER.1"],"anssi":["Hygiene.29","Hygiene.39","SecNumCloud.13.7"],"osfi_b13":["B-13.3.3"],"finma_circular":["IV.C(66)","IV.C(67)","IV.C(68)","IV.C(69)"],"gdpr":["Art.32(1)(b)","Art.32(1)(d)"],"dora":["Art.10(1)","Art.10(2)"],"bio2":["5.25","8.12","8.16"],"rbi_csf":["Annex1.4","Annex1.13","Annex1.16","Annex1.20"],"fisc":["FISC.O2","FISC.O4"],"lgpd_bcb":["BCB.Art.3","BCB.Art.6","BCB.Art.7","BCB.PIX","LGPD.Art.46"],"hkma_tme1":["TME1.5.2","TME1.7.3","TME1.7.5","TME1.10.1","TME1.11.3"],"mlps_2":["8.1.3.3","8.1.4.4","8.1.4.5","8.1.5.4","8.1.10.5","8.2","8.3","8.4","8.5"],"dnb_good_practice":["DNB.16.1","DNB.19.1"],"cra":["CRA.I.2d","CRA.I.2i","CRA.I.2l"],"swift_cscf":["SWIFT.2.9","SWIFT.6.1","SWIFT.6.4","SWIFT.6.5A"],"cbb_tm":["TM-8","TM-12","TM-13"],"cbuae":["CR-3","CR-7"],"nca_ecc":["2-4","2-5","2-12","5-1"],"qatar_nia":["IM","OS"],"sama_csf":["3.3","3.6"],"uae_ia":["T7","T11"],"bog_cisd":["CISD-VI","CISD-VII"],"bom_ctrm":["3.2","4.1","4.2","5.1"],"cbe_csf":["CD-1","CTO-6","CTO-7","CTO-8"],"cbn_csf":["Part2.2","Part3.3","Part3.5","Part4"],"popia":["s19"],"sa_js2":["JS2-7.2","JS2-7.3","JS2-7.6","JS2-8.4"],"bcbs_239":["Principle 10"],"bot_cyber":["Ch2.6","Ch3.1","Ch8.2"],"cpmi_pfmi":["CG.DE","PFMI.P17"],"eba_ict":["3.4.5","3.5(c)","3.8(c)"],"ecb_croe":["CROE.2.3.5","CROE.2.4"],"ffiec_is":["II.C.9","II.C.12","II.C.16","II.D","III.A","III.B","III.C"],"hipaa_sr":["§164.308(a)(1)(ii)(D)","§164.308(a)(5)(ii)(B)","§164.308(a)(5)(ii)(C)","§164.308(a)(6)(ii)"],"iosco_cyber":["DET-1","DET-2","DET-3","DET-4"],"nydfs_500":["500.2","500.6","500.14"],"sebi_cscrf":["DE.CM","DE.DP","PR.NS","RS.AN","SOC"],"cmmc_2":["AU","SI"],"nerc_cip":["CIP-007-6","CIP-015-1"],"nrc_73_54":["RG5.71-A-AU","RG5.71-A-SI"],"tsa_psd":["SD-2 Sec C"],"ieee_1686":[],"ferc_cip":["Order 881"],"doe_c2m2":["SITUATION"],"api_1164":["Sec 9"],"awia":["AWWA Sec 4","AWWA Sec 5"],"iaea_nss":["Sec 5.5"],"pci_pts":["I","J","L"],"fips_140":[],"cbest":["CBEST.5"],"tiber_eu":["TIBER.BT"],"pci_hsm":[],"common_criteria":["CC Part 2 — FAU"],"isae_3402":["Clause 4"],"fca_sysc_13":["SYSC 13.7.5"],"fda_21_cfr_11":[],"fda_cyber":["MON-3","PU-3","SA-5"],"hitrust_csf":["09.c","09.e","09.g","11.a","11.c"],"iso_27799":["12.2","16.2"],"lloyds_ms":["MS2.1","MS8.5","MS8.10","MS8.12"],"naic_ds":["4","4-audit","4-monitoring","4B","5"],"nhs_dspt":["NDG-9.3","NDG-9.5","NDG-9.9"],"pra_ss1_23":["P5.2","P5.3"],"solvency_ii":["EIOPA-ICT-4.9"],"owasp_masvs_v2":["MASVS-RESILIENCE-4"],"csa_ccm_v4":["IVS-09","LOG-03","LOG-05","LOG-13","UEM-11"],"csa_aicm":["AIS-12","I&S-09","LOG-03","LOG-05","LOG-13","LOG-14","MDS-05","TVM-11","TVM-13","UEM-11"],"ccss_v9":["1.02.8","2.04.2","2.04.3"],"mica":["Art.62(5)","Art.62(8)","Art.68(1)","Art.88(1)","Art.92(1)"],"basel_sco60":["SCO60.13","SCO60.51","SCO60.55","SCO60.64","SCO60.65","SCO60.72"],"bssc":["GSP-12","NOS-06","TIS-05"],"sec_custody_digital":["SEC-CD-11","SEC-CD-16"],"dpdpa":["Act.8(5)","Rules.6(1)(c)","Rules.Sch1.B.7"]},"attack_techniques":[{"id":"T1001","name":"Data Obfuscation","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Continuous network monitoring with traffic analysis and anomaly detection enables identification of obfuscated command-and-control communications by flagging unusual encoding patterns, entropy anomalies, or protocol deviations that differ from established network baselines."},{"id":"T1003","name":"OS Credential Dumping","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Endpoint monitoring tools can detect credential dumping activities by alerting on suspicious process access to LSASS, SAM registry hives, or NTDS.dit files, as well as anomalous use of credential-extraction utilities such as Mimikatz or secretsdump."},{"id":"T1005","name":"Data from Local System","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Host-based monitoring with file integrity checking and data loss prevention sensors can detect anomalous bulk file access, staging of sensitive data in temporary directories, or unusual read operations against databases and document stores indicative of local data collection."},{"id":"T1008","name":"Fallback Channels","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network monitoring that baselines normal communication patterns can detect when compromised hosts switch to fallback C2 channels by identifying unexpected outbound connections to previously unseen infrastructure or sudden protocol changes."},{"id":"T1011","name":"Exfiltration Over Other Network Medium","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Monitoring network interfaces and wireless activity can detect unauthorized exfiltration over non-standard network media such as cellular, Bluetooth, or RF channels by alerting on unexpected network adapter activity or traffic on unmonitored interfaces."},{"id":"T1021","name":"Remote Services","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Monitoring authentication events and remote service connections—including RDP, SSH, SMB, and WinRM sessions—enables detection of lateral movement by flagging unusual source-destination pairs, off-hours access, or connections from previously unseen hosts."},{"id":"T1025","name":"Data from Removable Media","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Endpoint monitoring that tracks removable media mount events and file copy operations to external devices can detect adversary collection of sensitive data from USB drives, optical media, or other removable storage."},{"id":"T1027","name":"Obfuscated Files or Information","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Malware detection tools with static and dynamic analysis capabilities can identify obfuscated files through entropy analysis, behavioral sandboxing, and signature-based detection of known packing or encoding techniques used to evade traditional antivirus."},{"id":"T1029","name":"Scheduled Transfer","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Network monitoring that profiles normal data transfer patterns can detect scheduled exfiltration by identifying periodic outbound data flows at unusual times, consistent transfer sizes, or automated transmission patterns inconsistent with legitimate user behavior."},{"id":"T1030","name":"Data Transfer Size Limits","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Monitoring outbound data flows for size thresholds and transfer frequency enables detection of adversaries chunking exfiltrated data into small packets to evade volumetric alerts, particularly when cumulative transfers exceed normal baselines."},{"id":"T1036","name":"Masquerading","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Process and file monitoring can detect masquerading by comparing process names and file paths against known legitimate binaries, flagging executables running from unusual locations or with names closely resembling but not matching system utilities."},{"id":"T1037","name":"Boot or Logon Initialization Scripts","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring changes to boot and logon initialization scripts—including startup folders, login hooks, and logon scripts—enables detection of persistence mechanisms that execute adversary code during system startup or user authentication."},{"id":"T1040","name":"Network Sniffing","tactics":["credential-access","discovery"],"mapping_type":"mitigates","mapping_rationale":"Network monitoring and host-based sensors can detect unauthorized packet capture activity by identifying promiscuous mode interfaces, unexpected sniffing tools, or anomalous network adapter configurations on endpoints."},{"id":"T1041","name":"Exfiltration Over C2 Channel","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Monitoring C2 channel traffic for unusual data volumes, asymmetric upload-to-download ratios, or beaconing patterns with large payloads enables detection of adversaries exfiltrating stolen data over their existing command-and-control infrastructure."},{"id":"T1046","name":"Network Service Discovery","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"Network intrusion detection systems can identify port scanning and service discovery activity by detecting sequential connection attempts across multiple ports or hosts, SYN sweeps, and other network reconnaissance signatures."},{"id":"T1047","name":"Windows Management Instrumentation","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Monitoring WMI process creation events, WMI consumer registrations, and WMIC command-line invocations enables detection of adversaries leveraging Windows Management Instrumentation for remote code execution across the enterprise."},{"id":"T1048","name":"Exfiltration Over Alternative Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Network monitoring tools can detect exfiltration over alternative protocols by identifying unexpected outbound connections using protocols such as DNS, ICMP, or FTP that deviate from established traffic baselines or carry anomalous payload sizes."},{"id":"T1052","name":"Exfiltration Over Physical Medium","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Monitoring USB device connections, file transfer events to removable media, and physical port activity can detect adversary attempts to exfiltrate data by physically carrying it out of the environment on portable storage devices."},{"id":"T1053","name":"Scheduled Task/Job","tactics":["execution","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring scheduled task creation, modification, and execution—including Windows Task Scheduler events, cron job changes, and systemd timer registrations—enables detection of adversaries establishing persistence or executing payloads through job schedulers."},{"id":"T1055","name":"Process Injection","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Endpoint detection tools monitoring for suspicious memory allocation patterns, cross-process write operations, and anomalous thread creation can identify process injection techniques used to execute code within the address space of legitimate processes."},{"id":"T1059","name":"Command and Scripting Interpreter","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Monitoring command-line and script interpreter invocations—including PowerShell, cmd.exe, bash, and scripting engines—with logging of arguments and parent-child process relationships enables detection of adversary execution through scripting environments."},{"id":"T1068","name":"Exploitation for Privilege Escalation","tactics":["privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"System monitoring with exploit detection signatures, crash analysis, and abnormal privilege transitions can identify exploitation attempts targeting kernel or application vulnerabilities to escalate privileges beyond the user's authorized level."},{"id":"T1070","name":"Indicator Removal","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for log deletion events, timestamp modifications, and attempts to clear audit trails enables detection of adversary indicator removal, particularly when centralized log collection preserves records that attackers cannot access to delete."},{"id":"T1071","name":"Application Layer Protocol","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Continuous monitoring of network traffic with deep-packet inspection and anomaly detection enables identification of command-and-control channels disguised within standard application-layer protocols such as HTTP, DNS, or SMTP."},{"id":"T1072","name":"Software Deployment Tools","tactics":["execution","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Monitoring software deployment tool usage—including SCCM, Ansible, and similar platforms—for unauthorized package deployments, unexpected configuration pushes, or execution from non-standard accounts can detect lateral movement via trusted management infrastructure."},{"id":"T1078","name":"Valid Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring authentication logs for impossible travel, unusual login times, concurrent sessions from disparate locations, or access to atypical resources enables detection of adversaries operating with valid but compromised credentials."},{"id":"T1080","name":"Taint Shared Content","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Monitoring file integrity on shared network resources can detect adversaries tainting shared content with malicious payloads, particularly when files in commonly accessed directories are modified outside normal business workflows."},{"id":"T1087","name":"Account Discovery","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for enumeration commands such as net user, net group, or LDAP queries against Active Directory can detect adversary account discovery activity used to map available accounts for subsequent lateral movement or privilege escalation."},{"id":"T1090","name":"Proxy","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network monitoring can identify proxy-based C2 channels by detecting unusual traffic relay patterns, connections to known proxy services, or internal hosts forwarding traffic in ways inconsistent with their designated network roles."},{"id":"T1091","name":"Replication Through Removable Media","tactics":["initial-access","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Monitoring removable media insertion events and tracking autorun execution or file access patterns from external devices enables detection of malware propagation via USB drives or other portable media."},{"id":"T1092","name":"Communication Through Removable Media","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for removable media mount events correlated with unusual data writes or reads on air-gapped or restricted systems can detect adversaries using physical media as a covert C2 channel to bridge network isolation."},{"id":"T1095","name":"Non-Application Layer Protocol","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network monitoring with protocol analysis can detect non-application layer C2 channels by identifying anomalous ICMP, raw TCP, or UDP traffic patterns that do not conform to expected protocol behavior or carry encoded payloads."},{"id":"T1098","name":"Account Manipulation","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring account modification events—including privilege grants, group membership changes, and credential resets—enables detection of adversary persistence through unauthorized manipulation of existing accounts."},{"id":"T1102","name":"Web Service","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network monitoring can detect C2 channels leveraging legitimate web services by identifying unusual access patterns to cloud storage, social media APIs, or paste sites that correlate with beaconing behavior or data staging."},{"id":"T1104","name":"Multi-Stage Channels","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for sequential outbound connections to distinct infrastructure or changing C2 endpoints enables detection of multi-stage channel setups where adversaries progressively establish deeper access through staged communication relays."},{"id":"T1105","name":"Ingress Tool Transfer","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network and endpoint monitoring can detect ingress tool transfer by identifying downloads of executables, scripts, or archives from external sources, particularly when initiated by processes not typically associated with software retrieval."},{"id":"T1106","name":"Native API","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Monitoring API call sequences and system call patterns on endpoints can detect adversaries invoking native OS APIs directly to execute malicious code, bypass higher-level security controls, or interact with system resources in unauthorized ways."},{"id":"T1110","name":"Brute Force","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring authentication logs for rapid sequential login failures, distributed attempts across multiple accounts, or geographically impossible authentication patterns enables detection of brute force credential attacks in progress."},{"id":"T1111","name":"Multi-Factor Authentication Interception","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for anomalous MFA token usage, duplicate authentication factor presentations, or suspicious API calls to authentication services can detect adversary interception or replay of multi-factor authentication credentials."},{"id":"T1114","name":"Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Monitoring email access logs for unusual mailbox access patterns, bulk message downloads, or access from unexpected IP addresses enables detection of adversary email collection from compromised accounts or mail servers."},{"id":"T1119","name":"Automated Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Endpoint and network monitoring can detect automated collection scripts by identifying systematic file enumeration, bulk data staging, or scripted access patterns that traverse directories and gather data at machine speed."},{"id":"T1127","name":"Trusted Developer Utilities Proxy Execution","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring execution of developer utilities such as MSBuild, dnStar, and other trusted tools for unexpected invocations—particularly outside development environments—can detect adversaries proxying malicious code execution through signed Microsoft binaries."},{"id":"T1129","name":"Shared Modules","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Monitoring DLL load events and shared module registrations can detect adversaries executing malicious code through shared libraries by identifying unexpected module loads into legitimate processes or loads from unusual file paths."},{"id":"T1132","name":"Data Encoding","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network monitoring with payload inspection can detect data encoding in C2 traffic by identifying Base64, XOR, or custom encoding patterns in protocol headers or payloads that deviate from standard application behavior."},{"id":"T1133","name":"External Remote Services","tactics":["initial-access","persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring external remote service connections—including VPN, Citrix, and RDP gateways—for unusual source IPs, off-hours access, or anomalous authentication patterns enables detection of adversary initial access and persistence via remote services."},{"id":"T1135","name":"Network Share Discovery","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for network share enumeration commands such as net view, net share, or SMB browsing activity can detect adversary reconnaissance of available file shares used to identify targets for lateral movement or data collection."},{"id":"T1136","name":"Create Account","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring account creation events across local, domain, and cloud environments—including unexpected new accounts, accounts with elevated privileges, or accounts created outside normal provisioning workflows—enables detection of adversary persistence."},{"id":"T1137","name":"Office Application Startup","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring Office application startup locations—including templates, add-ins, and COM objects—for unauthorized modifications enables detection of persistence mechanisms that execute adversary code whenever Office applications are launched."},{"id":"T1176","name":"Browser Extensions","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Browser monitoring that tracks extension installations, updates, and permissions can detect unauthorized or malicious browser extensions used by adversaries to maintain persistence, steal credentials, or intercept browsing activity."},{"id":"T1185","name":"Browser Session Hijacking","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Monitoring browser process behavior for unexpected inter-process communication, memory injection, or proxy manipulation can detect browser session hijacking where adversaries inherit authenticated web sessions to access protected resources."},{"id":"T1187","name":"Forced Authentication","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Network monitoring can detect forced authentication attempts by identifying outbound SMB, WebDAV, or NTLMv2 traffic triggered by malicious links, documents, or file references designed to capture user credential hashes."},{"id":"T1189","name":"Drive-by Compromise","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Web traffic monitoring and URL reputation analysis can detect drive-by compromise attempts by identifying connections to known exploit kit infrastructure, suspicious redirects, or anomalous browser behavior following visits to compromised websites."},{"id":"T1190","name":"Exploit Public-Facing Application","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring public-facing application logs and web application firewalls for exploit signatures, anomalous input patterns, or unexpected server behavior enables detection of adversaries exploiting vulnerabilities in internet-exposed services."},{"id":"T1195","name":"Supply Chain Compromise","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring software integrity through hash verification, code signing validation, and behavioral analysis of newly installed components can detect supply chain compromises where legitimate software has been trojaned or tampered with during distribution."},{"id":"T1197","name":"BITS Jobs","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring BITS job creation and transfer activity can detect adversary abuse of the Background Intelligent Transfer Service for persistent file downloads or uploads that blend with legitimate Windows update traffic."},{"id":"T1201","name":"Password Policy Discovery","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for password policy enumeration commands such as net accounts or Get-ADDefaultDomainPasswordPolicy can detect adversary reconnaissance aimed at understanding password complexity requirements to optimize brute force attacks."},{"id":"T1203","name":"Exploitation for Client Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Endpoint monitoring with exploit detection capabilities—including behavioral analysis of application crashes, heap sprays, and ROP chain indicators—can detect client-side exploitation targeting vulnerabilities in browsers, Office applications, or PDF readers."},{"id":"T1204","name":"User Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Monitoring user execution events—including file opens, script launches, and link clicks—correlated with threat intelligence on malicious indicators enables detection of social engineering attacks that rely on user interaction to execute payloads."},{"id":"T1205","name":"Traffic Signaling","tactics":["command-and-control","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Network monitoring that tracks unusual packet sequences, malformed headers, or specific bit patterns in network traffic can detect traffic signaling techniques such as port knocking or wake-on-LAN used to activate dormant backdoors."},{"id":"T1210","name":"Exploitation of Remote Services","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Network monitoring for exploit signatures targeting remote services—including SMB, RDP, and SSH vulnerabilities—combined with anomalous lateral connection patterns enables detection of adversaries exploiting unpatched services to move between systems."},{"id":"T1211","name":"Exploitation for Defense Evasion","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for unexpected privilege changes, process crashes followed by elevated execution, or anomalous system behavior can detect exploitation of software vulnerabilities used to evade security controls and maintain undetected access."},{"id":"T1212","name":"Exploitation for Credential Access","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring authentication subsystems for anomalous behavior—including unexpected credential issuance, token generation without corresponding user action, or exploitation indicators in authentication services—enables detection of credential access exploits."},{"id":"T1213","name":"Data from Information Repositories","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Monitoring access to information repositories such as SharePoint, Confluence, and wikis for unusual query volumes, bulk downloads, or access from unauthorized accounts enables detection of adversary data collection from organizational knowledge bases."},{"id":"T1216","name":"System Script Proxy Execution","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring execution of system scripts like PubPrn.vbs and other signed script proxies for unexpected invocations or unusual parent processes can detect adversaries using trusted scripts to bypass application whitelisting controls."},{"id":"T1218","name":"System Binary Proxy Execution","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring execution of signed system binaries such as rundll32, regsvr32, mshta, and certutil for unusual command-line arguments or unexpected parent processes can detect proxy execution of malicious code through trusted Windows utilities."},{"id":"T1219","name":"Remote Access Software","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for installation and usage of remote access tools—including TeamViewer, AnyDesk, and similar software—that are not part of approved toolsets enables detection of adversary C2 channels established through legitimate remote support applications."},{"id":"T1220","name":"XSL Script Processing","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for XSLT processing by msxsl.exe or embedded XSL within XML documents can detect adversaries leveraging XSL script processing to execute arbitrary code while bypassing application control mechanisms."},{"id":"T1221","name":"Template Injection","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for Office documents fetching remote templates via HTTP or SMB at open time can detect template injection attacks where adversaries embed malicious macro-enabled templates referenced by seemingly benign documents."},{"id":"T1222","name":"File and Directory Permissions Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for file and directory permission changes—including icacls, chmod, and ACL modifications—can detect adversaries weakening access controls to enable broader access to sensitive files or to prepare for subsequent attack stages."},{"id":"T1484","name":"Domain or Tenant Policy Modification","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring domain and tenant policy changes—including Group Policy modifications and Azure AD policy updates—enables detection of adversaries manipulating trust relationships or security policies to weaken defenses and escalate privileges."},{"id":"T1485","name":"Data Destruction","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for mass file deletion events, unusual volume shadow copy removal, or bulk data destruction patterns enables detection of adversary data destruction attacks intended to cause operational disruption and data loss."},{"id":"T1486","name":"Data Encrypted for Impact","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for rapid file encryption activity, ransom note creation, and cryptographic API calls at anomalous rates enables early detection of ransomware execution before complete encryption of organizational data stores."},{"id":"T1489","name":"Service Stop","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for unexpected service stop commands, mass service termination, or disabling of critical system services enables detection of adversary disruption activities that precede ransomware deployment or destructive attacks."},{"id":"T1490","name":"Inhibit System Recovery","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for deletion of volume shadow copies, modification of recovery partitions, or disabling of Windows Recovery Environment enables detection of adversary actions to prevent system restoration after destructive attacks."},{"id":"T1491","name":"Defacement","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Monitoring web server file integrity and internal application content for unauthorized modifications enables detection of defacement attacks that alter visible content to damage organizational reputation or signal compromise."},{"id":"T1499","name":"Endpoint Denial of Service","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Monitoring system resource utilization, connection rates, and service availability metrics enables detection of endpoint denial-of-service attacks that exhaust CPU, memory, or network resources to disrupt service delivery."},{"id":"T1505","name":"Server Software Component","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring server software components—including web shells, IIS modules, and SQL stored procedures—for unauthorized additions or modifications enables detection of persistent backdoors installed in server infrastructure."},{"id":"T1525","name":"Implant Internal Image","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring container image registries for unauthorized image pushes, unexpected image modifications, or images with known malicious layers can detect adversary implantation of backdoored container images used for persistence."},{"id":"T1528","name":"Steal Application Access Token","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring OAuth token grants, API key usage, and application access patterns for anomalous requests or token theft indicators enables detection of adversaries stealing application access tokens to bypass normal authentication."},{"id":"T1530","name":"Data from Cloud Storage","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Monitoring cloud storage access logs for unusual download volumes, access from unexpected IP ranges, or queries to sensitive storage buckets enables detection of adversary data collection from misconfigured or compromised cloud storage."},{"id":"T1537","name":"Transfer Data to Cloud Account","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Monitoring cloud account activity for large data transfers to external accounts, cross-region replications, or unauthorized storage bucket sharing enables detection of exfiltration via cloud-to-cloud data transfer mechanisms."},{"id":"T1539","name":"Steal Web Session Cookie","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for anomalous cookie access, browser credential store reads, or unexpected session token usage can detect adversary theft of web session cookies used to hijack authenticated sessions without credentials."},{"id":"T1543","name":"Create or Modify System Process","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for creation or modification of system processes—including Windows services, systemd units, and launch daemons—enables detection of adversary persistence and privilege escalation through system-level process manipulation."},{"id":"T1548","name":"Abuse Elevation Control Mechanism","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for UAC bypass indicators, setuid/setgid changes, or sudo abuse patterns enables detection of adversaries exploiting elevation control mechanisms to gain higher privileges without proper authorization."},{"id":"T1552","name":"Unsecured Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring file access to known credential storage locations—including configuration files, registry keys, and cloud metadata endpoints—enables detection of adversary searches for unsecured credentials left in accessible locations."},{"id":"T1553","name":"Subvert Trust Controls","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for changes to code signing policies, certificate store modifications, or trust provider tampering enables detection of adversary attempts to subvert trust controls that validate software authenticity and integrity."},{"id":"T1555","name":"Credentials from Password Stores","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring access to password stores—including browser credential databases, keychains, and credential manager vaults—enables detection of adversary tools harvesting saved passwords for credential reuse across systems."},{"id":"T1556","name":"Modify Authentication Process","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring authentication process integrity—including DLL loads in authentication services, PAM module changes, and authentication filter modifications—enables detection of adversary tampering that creates backdoor access or captures credentials."},{"id":"T1557","name":"Adversary-in-the-Middle","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Network monitoring for ARP anomalies, LLMNR/NBT-NS poisoning, DHCP spoofing, and unexpected traffic redirection enables detection of adversary-in-the-middle attacks that intercept and manipulate network communications."},{"id":"T1558","name":"Steal or Forge Kerberos Tickets","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring Kerberos authentication traffic for anomalous ticket requests, encryption downgrade attempts, or ticket-granting ticket manipulation enables detection of adversaries forging or stealing Kerberos tickets for unauthorized access."},{"id":"T1559","name":"Inter-Process Communication","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Monitoring inter-process communication mechanisms—including COM, DDE, and XPC—for unexpected invocations or data exchanges between processes enables detection of adversary execution through legitimate IPC channels."},{"id":"T1560","name":"Archive Collected Data","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for compression and archiving tool execution—such as 7-Zip, WinRAR, or tar—particularly when targeting sensitive directories, enables detection of adversary data staging prior to exfiltration."},{"id":"T1561","name":"Disk Wipe","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for disk-level write operations targeting boot sectors, partition tables, or bulk sector overwrites enables detection of disk wipe attacks designed to render systems unrecoverable and cause maximum operational disruption."},{"id":"T1562","name":"Impair Defenses","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring the health and status of security tools, audit configurations, and firewall rules enables detection of adversary attempts to impair defenses by disabling antivirus, stopping logging services, or modifying security configurations."},{"id":"T1563","name":"Remote Service Session Hijacking","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for remote service session anomalies—including RDP session takeover indicators, SSH session multiplexing, or unexpected session transfers—enables detection of adversaries hijacking legitimate remote sessions for lateral movement."},{"id":"T1565","name":"Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Monitoring data integrity through checksums, database transaction logs, and runtime validation enables detection of adversary data manipulation that alters stored, transmitted, or runtime data to undermine business operations."},{"id":"T1566","name":"Phishing","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Email and web traffic monitoring with attachment sandboxing, URL analysis, and sender reputation scoring enables detection of phishing attacks delivering malicious payloads or credential-harvesting links to organizational users."},{"id":"T1567","name":"Exfiltration Over Web Service","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Monitoring outbound connections to cloud storage services, code repositories, and paste sites for unusual upload volumes or unauthorized access enables detection of exfiltration over legitimate web services."},{"id":"T1568","name":"Dynamic Resolution","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Monitoring DNS queries for high-entropy domain names, rapid domain resolution changes, or queries to known dynamic DNS providers enables detection of C2 infrastructure using dynamic resolution techniques like domain generation algorithms."},{"id":"T1569","name":"System Services","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Monitoring system service execution events—including service control manager logs and systemctl invocations—for unexpected service startups or execution of unknown binaries as services enables detection of adversary execution via system services."},{"id":"T1570","name":"Lateral Tool Transfer","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Monitoring internal file transfer activity—including SMB copies, PowerShell remoting transfers, and SCP operations between internal hosts—enables detection of adversaries moving tools and malware laterally across the network."},{"id":"T1571","name":"Non-Standard Port","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network monitoring that validates expected port-to-service mappings can detect C2 channels operating on non-standard ports by flagging protocol mismatches where, for example, HTTP traffic flows over unusual high-numbered ports."},{"id":"T1572","name":"Protocol Tunneling","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network monitoring with deep packet inspection can detect protocol tunneling by identifying encapsulated traffic within permitted protocols, such as SSH tunnels within HTTP or DNS tunneling for covert data transfer."},{"id":"T1573","name":"Encrypted Channel","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network monitoring for encrypted C2 channels focuses on detecting anomalous TLS certificate characteristics, unexpected encrypted sessions to non-standard endpoints, or encrypted traffic patterns inconsistent with legitimate application behavior."},{"id":"T1574","name":"Hijack Execution Flow","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring DLL load events, file path modifications, and service binary changes enables detection of execution flow hijacking where adversaries place malicious libraries or executables in locations that intercept legitimate application loading."},{"id":"T1578","name":"Modify Cloud Compute Infrastructure","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring cloud compute infrastructure for unauthorized instance creation, snapshot operations, or configuration changes enables detection of adversaries modifying cloud resources to evade detection or establish persistent access."},{"id":"T1598","name":"Phishing for Information","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Monitoring inbound communications for social engineering indicators—including suspicious email patterns, credential harvesting page references, and impersonation attempts—enables detection of phishing-for-information reconnaissance campaigns."},{"id":"T1599","name":"Network Boundary Bridging","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring network device configurations and routing tables for unauthorized changes that bridge segmented networks enables detection of adversary attempts to bypass network boundaries and access isolated environments."},{"id":"T1601","name":"Modify System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring network device firmware integrity through hash verification and boot process validation enables detection of adversary modifications to system images that persist backdoors or disable security features on network infrastructure."},{"id":"T1602","name":"Data from Configuration Repository","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Monitoring SNMP access, configuration management traffic, and network device CLI sessions for unauthorized queries or bulk configuration downloads enables detection of adversary collection of device configurations containing sensitive network architecture details."},{"id":"T1610","name":"Deploy Container","tactics":["defense-evasion","execution"],"mapping_type":"mitigates","mapping_rationale":"Monitoring container runtime environments for unauthorized container deployments, unexpected image pulls, or containers launched with elevated privileges enables detection of adversaries deploying malicious containers for execution or evasion."},{"id":"T1611","name":"Escape to Host","tactics":["privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring container escape indicators—including unexpected host namespace access, privileged system calls from containers, or container breakout exploit signatures—enables detection of adversaries escaping container isolation to compromise the host."},{"id":"T1612","name":"Build Image on Host","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring container build operations on hosts—including unexpected Docker build commands or Dockerfile creation outside CI/CD pipelines—enables detection of adversaries building malicious images locally to evade registry-based scanning."},{"id":"T1613","name":"Container and Resource Discovery","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for container and Kubernetes API enumeration commands—including kubectl get, docker ps, and API server queries—enables detection of adversary discovery activities mapping the container orchestration environment."},{"id":"T1622","name":"Debugger Evasion","tactics":["defense-evasion","discovery"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for debugger detection techniques—including IsDebuggerPresent checks, timing-based evasion, or anti-analysis behaviors—enables identification of malware actively evading sandbox and debugging environments."},{"id":"T1647","name":"Plist File Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring plist file modifications on macOS—particularly in LaunchAgent, LaunchDaemon, and application preference directories—enables detection of adversary persistence or defense evasion through property list manipulation."},{"id":"T1648","name":"Serverless Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Monitoring serverless function invocations, Lambda deployments, and cloud function logs for unauthorized execution or unexpected function creation enables detection of adversaries leveraging serverless compute for malicious execution."},{"id":"T1651","name":"Cloud Administration Command","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Monitoring cloud management APIs and administration commands—including AWS SSM, Azure Run Command, and GCP OS Config—for unauthorized execution enables detection of adversaries leveraging cloud administration tools for remote code execution."},{"id":"T1653","name":"Power Settings","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring changes to power management settings—including sleep timers, hibernate configurations, and wake schedules—enables detection of adversaries modifying power settings to maintain system availability for persistent access."},{"id":"T1001.001","name":"Junk Data","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Network monitoring with payload analysis can detect junk data injection in C2 traffic by identifying packets with anomalous padding, random byte sequences, or payload sizes inconsistent with the purported application protocol."},{"id":"T1001.002","name":"Steganography","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Deep content inspection and anomaly detection can identify steganographic C2 channels by flagging image, audio, or video files with statistical anomalies in least-significant bits or embedded data inconsistent with normal media files."},{"id":"T1001.003","name":"Protocol or Service Impersonation","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Protocol-aware network monitoring can detect service impersonation by comparing actual traffic behavior against expected protocol specifications, identifying C2 channels that mimic but imperfectly replicate legitimate services like HTTPS or DNS."},{"id":"T1003.001","name":"LSASS Memory","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Endpoint monitoring that tracks process access to lsass.exe—including suspicious OpenProcess calls, memory dumps, and credential extraction tool signatures—enables specific detection of LSASS memory credential dumping attempts."},{"id":"T1003.002","name":"Security Account Manager","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for registry access to SAM hive locations, volume shadow copy access for SAM extraction, and tools targeting the Security Account Manager database enables detection of local password hash harvesting on Windows systems."},{"id":"T1003.003","name":"NTDS","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for ntdsutil execution, volume shadow copy creation targeting NTDS.dit, or suspicious access to Active Directory database files enables detection of adversaries extracting the complete domain credential store from domain controllers."},{"id":"T1003.004","name":"LSA Secrets","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for registry access to HKLM\\SECURITY\\Policy\\Secrets and tools targeting LSA secret storage enables detection of adversary extraction of service account credentials, auto-logon passwords, and other secrets stored in LSA."},{"id":"T1003.005","name":"Cached Domain Credentials","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for access to cached credential storage locations and registry keys containing domain credential caches enables detection of adversaries harvesting cached logon credentials for offline cracking or pass-the-hash attacks."},{"id":"T1003.006","name":"DCSync","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring domain controller replication traffic for unauthorized DCSync requests—particularly GetNCChanges calls from non-domain controller sources—enables detection of adversaries remotely extracting password data via directory replication."},{"id":"T1003.007","name":"Proc Filesystem","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for access to /proc/*/maps, /proc/*/mem, and process memory reads on Linux systems enables detection of adversaries extracting credentials from running process memory through the proc filesystem interface."},{"id":"T1003.008","name":"/etc/passwd and /etc/shadow","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for unauthorized access to /etc/shadow, /etc/passwd, and attempts to use unshadow or john-the-ripper against these files enables detection of adversaries harvesting Linux user credentials for offline password cracking."},{"id":"T1011.001","name":"Exfiltration Over Bluetooth","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Monitoring Bluetooth adapter activation, pairing events, and file transfer operations can detect unauthorized data exfiltration over Bluetooth connections, particularly on systems where Bluetooth should be disabled by policy."},{"id":"T1020.001","name":"Traffic Duplication","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Monitoring network device configurations for unauthorized port mirroring, SPAN sessions, or traffic duplication rules enables detection of adversaries configuring network infrastructure to copy traffic for data collection or exfiltration."},{"id":"T1021.001","name":"Remote Desktop Protocol","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Monitoring RDP connection logs for unusual source IPs, concurrent sessions, or connections outside business hours enables detection of adversaries using Remote Desktop Protocol for lateral movement within the network."},{"id":"T1021.002","name":"SMB/Windows Admin Shares","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Monitoring SMB authentication events and administrative share access (C$, ADMIN$, IPC$) for unusual access patterns enables detection of adversaries using Windows administrative shares for lateral movement and remote file operations."},{"id":"T1021.003","name":"Distributed Component Object Model","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Monitoring DCOM activation events, remote object instantiation, and network connections on DCOM ports enables detection of adversaries leveraging Distributed COM for remote code execution across Windows systems."},{"id":"T1021.004","name":"SSH","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Monitoring SSH connection logs for key-based authentication anomalies, unusual source addresses, or connections to unexpected hosts enables detection of adversary lateral movement through compromised SSH credentials or keys."},{"id":"T1021.005","name":"VNC","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Monitoring VNC connection attempts, server process spawning, and authentication events enables detection of adversaries using Virtual Network Computing for remote graphical access and lateral movement."},{"id":"T1021.006","name":"Windows Remote Management","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Monitoring Windows Remote Management (WinRM) session creation, PowerShell remoting events, and WSMan traffic enables detection of adversaries using WinRM for remote command execution during lateral movement."},{"id":"T1021.008","name":"Direct Cloud VM Connections","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Monitoring direct cloud VM connections—including serial console access and cloud-native SSH/RDP—for unauthorized sessions enables detection of adversaries bypassing network security controls to access cloud instances directly."},{"id":"T1027.002","name":"Software Packing","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Endpoint monitoring with unpacking analysis and behavioral detection can identify software-packed executables by flagging binaries with high entropy sections, known packer signatures, or runtime unpacking behavior indicative of evasion."},{"id":"T1027.007","name":"Dynamic API Resolution","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for dynamic API resolution patterns—including GetProcAddress calls to suspicious APIs or runtime resolution of sensitive functions—enables detection of malware hiding its true capabilities from static analysis."},{"id":"T1027.008","name":"Stripped Payloads","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Behavioral monitoring can detect stripped payloads that have been stripped of debugging symbols and identifying information, by flagging executables lacking standard metadata that deviate from normal software distribution patterns."},{"id":"T1027.009","name":"Embedded Payloads","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for embedded payload extraction—including executables that drop or decode secondary payloads at runtime—enables detection of adversaries hiding malicious code within seemingly benign carrier files."},{"id":"T1027.010","name":"Command Obfuscation","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring command-line activity for heavily obfuscated commands—including character escaping, variable substitution, and encoding tricks in PowerShell, cmd, or bash—enables detection of adversary attempts to evade command logging and analysis."},{"id":"T1027.011","name":"Fileless Storage","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for data stored in registry keys, WMI repositories, or alternate data streams that serves as fileless malware storage enables detection of adversaries avoiding traditional file-based detection by persisting payloads in non-file locations."},{"id":"T1027.012","name":"LNK Icon Smuggling","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for LNK files with manipulated icon references pointing to external resources can detect icon smuggling techniques where adversaries use shortcut files to trigger outbound connections for payload delivery or credential capture."},{"id":"T1036.001","name":"Invalid Code Signature","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring code signature validation results and flagging executables with invalid, revoked, or mismatched digital signatures enables detection of adversaries using forged or copied signatures to masquerade as legitimate software."},{"id":"T1036.003","name":"Rename System Utilities","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for system utility execution from unexpected file paths or with unexpected file hashes enables detection of adversaries who rename malicious binaries to match legitimate system utilities to avoid suspicion."},{"id":"T1036.005","name":"Match Legitimate Name or Location","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for executables whose names match legitimate software but run from non-standard directories enables detection of adversaries placing malicious files in locations designed to exploit analyst assumptions about trusted file paths."},{"id":"T1036.007","name":"Double File Extension","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for files with double extensions (e.g., document.pdf.exe) or mismatched MIME types enables detection of adversaries using extension manipulation to trick users and file-type-based security controls into treating malicious files as benign."},{"id":"T1036.008","name":"Masquerade File Type","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for files where the actual file type differs from the displayed extension—such as executables disguised as documents—enables detection of adversaries manipulating file type indicators to bypass security controls."},{"id":"T1036.010","name":"Masquerade Account Name","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring account creation and naming patterns for accounts that mimic legitimate service accounts or administrative users enables detection of adversaries creating deceptively named accounts to blend in with normal account inventories."},{"id":"T1037.002","name":"Login Hook","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring macOS login hook configurations in /var/root/Library/Preferences/com.apple.loginwindow.plist for unauthorized modifications enables detection of adversaries establishing persistence through login-triggered script execution."},{"id":"T1037.003","name":"Network Logon Script","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring Group Policy logon script assignments and network logon script file modifications enables detection of adversaries inserting malicious commands into scripts that execute automatically during domain user authentication."},{"id":"T1037.004","name":"RC Scripts","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring RC script directories (/etc/rc.d/, /etc/init.d/) for unauthorized script additions or modifications enables detection of adversaries establishing persistence through system initialization scripts on Unix/Linux systems."},{"id":"T1037.005","name":"Startup Items","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring macOS StartupItems directories and legacy startup script locations for unauthorized additions enables detection of adversaries using deprecated but still functional startup mechanisms for persistence."},{"id":"T1048.001","name":"Exfiltration Over Symmetric Encrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Network monitoring can detect exfiltration over encrypted non-C2 channels by identifying unexpected outbound connections using symmetric encryption protocols to unusual destinations that deviate from established baseline traffic patterns."},{"id":"T1048.002","name":"Exfiltration Over Asymmetric Encrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Network monitoring for unexpected TLS/SSH connections to external hosts—particularly from servers or workstations without business justification—enables detection of exfiltration using asymmetric encrypted channels separate from C2 infrastructure."},{"id":"T1048.003","name":"Exfiltration Over Unencrypted Non-C2 Protocol","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Network monitoring for cleartext protocol usage carrying large or encoded payloads—such as FTP, HTTP, or DNS with anomalous query volumes—enables detection of exfiltration over unencrypted non-C2 channels."},{"id":"T1052.001","name":"Exfiltration over USB","tactics":["exfiltration"],"mapping_type":"mitigates","mapping_rationale":"Monitoring USB device connections, mass storage driver loads, and file copy events to removable drives enables specific detection of data exfiltration via USB storage devices being physically carried out of the environment."},{"id":"T1053.002","name":"At","tactics":["execution","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring at command execution and ATQ file creation enables detection of adversaries using the legacy AT scheduler for task execution and persistence, particularly on older Windows systems where this utility remains available."},{"id":"T1053.003","name":"Cron","tactics":["execution","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring crontab modifications, /etc/cron.d/ directory changes, and cron job execution logs enables detection of adversaries scheduling malicious commands through the Unix/Linux cron daemon for persistence and execution."},{"id":"T1053.005","name":"Scheduled Task","tactics":["execution","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring Windows Task Scheduler for new task registrations, particularly those with SYSTEM-level execution, encoded commands, or connections to external resources, enables detection of adversary persistence through scheduled tasks."},{"id":"T1053.006","name":"Systemd Timers","tactics":["execution","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring systemd timer creation and modification events—including new .timer unit files and systemctl timer operations—enables detection of adversaries using systemd timers as a persistence and execution mechanism on Linux systems."},{"id":"T1055.001","name":"Dynamic-link Library Injection","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for LoadLibrary calls with unusual DLL paths, CreateRemoteThread targeting other processes, or unexpected DLL loads in processes enables detection of dynamic-link library injection used to execute code in legitimate process contexts."},{"id":"T1055.002","name":"Portable Executable Injection","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for WriteProcessMemory followed by CreateRemoteThread in target processes enables detection of portable executable injection where adversaries inject entire PE images into the memory space of running processes."},{"id":"T1055.003","name":"Thread Execution Hijacking","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for SuspendThread, WriteProcessMemory, and SetThreadContext API sequences targeting remote processes enables detection of thread execution hijacking used to redirect legitimate thread execution to adversary code."},{"id":"T1055.004","name":"Asynchronous Procedure Call","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for QueueUserAPC calls targeting threads in remote processes—particularly in alertable wait states—enables detection of asynchronous procedure call injection used for stealthy code execution within legitimate processes."},{"id":"T1055.005","name":"Thread Local Storage","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for manipulation of thread local storage callback arrays in PE headers enables detection of TLS callback injection, where adversaries insert malicious code that executes during DLL load before the main entry point."},{"id":"T1055.008","name":"Ptrace System Calls","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for ptrace system calls targeting other processes on Linux—particularly PTRACE_ATTACH and PTRACE_POKETEXT operations—enables detection of adversaries injecting code into running processes via the debugging interface."},{"id":"T1055.009","name":"Proc Memory","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for reads and writes to /proc/[pid]/mem on Linux systems enables detection of adversaries performing process memory injection through the proc filesystem to execute code within other processes without using ptrace."},{"id":"T1055.011","name":"Extra Window Memory Injection","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for SetWindowLong/SetWindowLongPtr calls that modify extra window memory in combination with NtMapViewOfSection enables detection of extra window memory injection used to execute shellcode in GUI processes."},{"id":"T1055.012","name":"Process Hollowing","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for process creation in suspended state followed by NtUnmapViewOfSection and WriteProcessMemory enables detection of process hollowing, where adversaries replace a legitimate process's memory with malicious code."},{"id":"T1055.013","name":"Process Doppelgänging","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for NTFS transaction operations combined with process creation—particularly NtCreateTransaction followed by NtCreateSection—enables detection of process doppelganging used to execute malicious code through transacted file operations."},{"id":"T1055.014","name":"VDSO Hijacking","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for VDSO manipulation attempts on Linux—including writes to vDSO pages or syscall interception through virtual dynamic shared object modification—enables detection of this advanced process injection technique."},{"id":"T1056.002","name":"GUI Input Capture","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for fake dialog boxes, unexpected credential prompts, or GUI overlay activity that intercepts user input enables detection of adversaries using graphical input capture to steal credentials or sensitive information."},{"id":"T1059.001","name":"PowerShell","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Monitoring PowerShell execution with ScriptBlock logging, module logging, and transcription captures enables detection of adversary scripts by revealing decoded commands, downloaded payloads, and post-exploitation activities."},{"id":"T1059.002","name":"AppleScript","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Monitoring osascript invocations and AppleScript execution events for unexpected automation commands—particularly those accessing system resources or user data—enables detection of adversary execution through Apple's scripting framework."},{"id":"T1059.003","name":"Windows Command Shell","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Monitoring cmd.exe process creation, command-line arguments, and parent-child relationships enables detection of adversaries using the Windows command shell for execution, particularly when spawned from unusual parent processes like Office applications."},{"id":"T1059.004","name":"Unix Shell","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Monitoring bash, sh, and zsh execution with command-line argument logging enables detection of adversary Unix shell activity, particularly reverse shells, encoded commands, or commands spawned from web server processes."},{"id":"T1059.005","name":"Visual Basic","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for cscript.exe and wscript.exe invocations, VBScript file creation, and macro-enabled document execution enables detection of adversary use of Visual Basic scripting for payload delivery and execution."},{"id":"T1059.006","name":"Python","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Monitoring Python interpreter invocations—including python.exe, python3, and embedded Python runtimes—for unexpected execution contexts enables detection of adversaries leveraging Python for post-exploitation scripting and tool execution."},{"id":"T1059.007","name":"JavaScript","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for JavaScript execution through wscript, cscript, Node.js, or browser-based contexts outside normal development workflows enables detection of adversary use of JavaScript for payload execution and post-exploitation."},{"id":"T1059.008","name":"Network Device CLI","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Monitoring network device CLI sessions—including SSH, Telnet, and console connections to routers and switches—for unusual commands or unauthorized access enables detection of adversary execution on network infrastructure."},{"id":"T1059.009","name":"Cloud API","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Monitoring cloud API invocations through CLI tools (aws, az, gcloud) and SDK calls for unusual commands, unauthorized resource access, or execution from unexpected source IPs enables detection of adversary cloud API abuse."},{"id":"T1059.010","name":"AutoHotKey & AutoIT","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for AutoHotKey and AutoIT process creation, script compilation, and automated input patterns enables detection of adversary use of automation scripting tools for keylogging, GUI automation, or payload execution."},{"id":"T1059.011","name":"Lua","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for Lua interpreter invocations and embedded Lua script execution—particularly within applications that embed Lua engines—enables detection of adversary abuse of the Lua scripting environment for code execution."},{"id":"T1070.001","name":"Clear Windows Event Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for Windows event log clearing—including Event ID 1102 (audit log cleared) and wevtutil cl commands—enables detection of adversaries erasing security logs to cover their tracks after compromise."},{"id":"T1070.002","name":"Clear Linux or Mac System Logs","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for syslog deletion, /var/log file truncation, or journalctl vacuum commands on Linux and macOS enables detection of adversaries clearing system logs to remove evidence of their activities."},{"id":"T1070.003","name":"Clear Command History","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for .bash_history deletion, history command manipulation, or HISTSIZE=0 settings enables detection of adversaries clearing command history to prevent forensic analysis of executed commands."},{"id":"T1070.007","name":"Clear Network Connection History and Configurations","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for deletion of known_hosts files, Wi-Fi connection profiles, or network configuration history enables detection of adversaries removing network connection artifacts to conceal lateral movement and C2 communication patterns."},{"id":"T1070.008","name":"Clear Mailbox Data","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for bulk mailbox data deletion, inbox rule modifications that auto-delete messages, or Exchange purge operations enables detection of adversaries clearing email evidence of phishing campaigns or data exfiltration."},{"id":"T1070.009","name":"Clear Persistence","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for removal of registry run keys, scheduled task deletions, or service uninstallations that eliminate prior persistence mechanisms enables detection of adversaries cleaning up after achieving their objectives."},{"id":"T1070.010","name":"Relocate Malware","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for malware files being moved between directories, renamed, or relocated to evade path-based detection signatures enables detection of adversaries repositioning malicious payloads to avoid security tool scanning."},{"id":"T1071.001","name":"Web Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Monitoring HTTP/HTTPS traffic for anomalous request patterns, unusual user-agent strings, beaconing intervals, or connections to uncategorized domains enables specific detection of web protocol-based C2 channels."},{"id":"T1071.002","name":"File Transfer Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Monitoring FTP and SFTP traffic for unexpected file transfers, connections to unusual external servers, or transfers initiated by non-standard processes enables detection of C2 channels using file transfer protocols."},{"id":"T1071.003","name":"Mail Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Monitoring SMTP and IMAP traffic for unusual email patterns, automated message generation, or email-based data exfiltration enables detection of adversaries using mail protocols as covert C2 communication channels."},{"id":"T1071.004","name":"DNS","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Monitoring DNS queries for high-volume requests, TXT record queries with encoded payloads, unusual subdomain lengths, or queries to non-standard resolvers enables detection of DNS-based C2 tunneling and data exfiltration."},{"id":"T1071.005","name":"Publish/Subscribe Protocols","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Monitoring publish/subscribe protocol traffic—including MQTT and AMQP—for unexpected broker connections, anomalous message patterns, or unauthorized topic subscriptions enables detection of C2 channels leveraging messaging middleware."},{"id":"T1078.001","name":"Default Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring authentication logs for use of default credentials—including manufacturer passwords and well-known test accounts—enables detection of adversaries exploiting unchanged default accounts for initial access or persistence."},{"id":"T1078.002","name":"Domain Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring Active Directory authentication for anomalous domain account usage—including impossible travel, service account interactive logins, or access from untrusted endpoints—enables detection of compromised domain credentials."},{"id":"T1078.003","name":"Local Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring local account authentication events for unusual login patterns, concurrent local sessions, or local admin usage from unexpected sources enables detection of adversaries operating with compromised local credentials."},{"id":"T1078.004","name":"Cloud Accounts","tactics":["defense-evasion","initial-access","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring cloud identity provider logs for anomalous cloud account activity—including API calls from unusual locations, impossible travel, or access to atypical cloud resources—enables detection of compromised cloud credentials."},{"id":"T1087.001","name":"Local Account","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for local account enumeration commands such as net user, wmic useraccount, or /etc/passwd reads enables detection of adversary discovery activities mapping local user accounts for subsequent exploitation."},{"id":"T1087.002","name":"Domain Account","tactics":["discovery"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for domain account enumeration through LDAP queries, net group /domain commands, or PowerShell AD module usage enables detection of adversaries mapping Active Directory user accounts and group memberships."},{"id":"T1090.001","name":"Internal Proxy","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for internal hosts relaying traffic to other internal systems or acting as intermediary connection points enables detection of adversary-deployed internal proxies used to route C2 traffic through compromised infrastructure."},{"id":"T1090.002","name":"External Proxy","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for outbound connections to external proxy services, VPN endpoints, or anonymization networks enables detection of adversaries routing C2 traffic through external proxy infrastructure to obscure their true origin."},{"id":"T1098.001","name":"Additional Cloud Credentials","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring cloud IAM audit logs for additional credential creation—including new API keys, OAuth tokens, or certificate-based credentials—enables detection of adversaries establishing persistent access through additional cloud credentials."},{"id":"T1098.002","name":"Additional Email Delegate Permissions","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring Exchange and Microsoft 365 audit logs for mailbox delegation changes, forwarding rule additions, or send-as permission grants enables detection of adversaries adding email delegate permissions for persistent email access."},{"id":"T1098.003","name":"Additional Cloud Roles","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring cloud identity audit trails for role assignment changes, privilege escalations, or addition of administrative cloud roles enables detection of adversaries manipulating cloud IAM to gain elevated access."},{"id":"T1098.004","name":"SSH Authorized Keys","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring authorized_keys file modifications and SSH key management operations for unauthorized key additions enables detection of adversaries planting SSH keys for persistent passwordless access to Linux and Unix systems."},{"id":"T1098.007","name":"Additional Local or Domain Groups","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for unexpected local or domain group membership changes—including additions to Administrators, Domain Admins, or other privileged groups—enables detection of adversaries escalating privileges through group manipulation."},{"id":"T1102.001","name":"Dead Drop Resolver","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for DNS lookups and HTTP requests to known paste sites, social media platforms, or cloud services used as dead drop resolvers enables detection of adversaries retrieving C2 infrastructure addresses from public web services."},{"id":"T1102.002","name":"Bidirectional Communication","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for bidirectional data exchange with cloud services—where both upload and download patterns appear in traffic to platforms like GitHub, Dropbox, or Google Drive—enables detection of full-duplex C2 over web services."},{"id":"T1102.003","name":"One-Way Communication","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for periodic one-way data retrieval from web services—such as polling RSS feeds, cloud storage files, or social media posts for encoded instructions—enables detection of adversary command delivery through public platforms."},{"id":"T1110.001","name":"Password Guessing","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for sequential authentication failures against individual accounts from single or distributed sources enables detection of password guessing attacks attempting to discover valid credentials through systematic trial."},{"id":"T1110.002","name":"Password Cracking","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for extraction of password hashes followed by system resource utilization spikes or offline cracking tool execution enables detection of adversaries performing password cracking against captured hash databases."},{"id":"T1110.003","name":"Password Spraying","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for authentication failures distributed across many accounts from limited source IPs enables detection of password spraying attacks that test common passwords against multiple accounts to avoid lockout thresholds."},{"id":"T1110.004","name":"Credential Stuffing","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for authentication attempts using known breached credential pairs—detected through correlation with threat intelligence feeds—enables identification of credential stuffing attacks leveraging stolen credential databases."},{"id":"T1114.001","name":"Local Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for unusual local email file access—including PST, OST, or EML file reads by non-email processes—enables detection of adversaries collecting email data from local mail stores on compromised endpoints."},{"id":"T1114.002","name":"Remote Email Collection","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for remote email access via EWS, IMAP, or Graph API from unexpected IP addresses or user agents enables detection of adversaries remotely harvesting email content from compromised mailboxes."},{"id":"T1114.003","name":"Email Forwarding Rule","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for new email forwarding rule creation—including inbox rules that auto-forward to external addresses—enables detection of adversaries establishing persistent email collection through automated forwarding."},{"id":"T1127.001","name":"MSBuild","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for MSBuild.exe execution outside normal development contexts—particularly invocations loading custom project files or inline tasks—enables detection of adversaries using MSBuild to compile and execute malicious code."},{"id":"T1127.002","name":"ClickOnce","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for ClickOnce application deployment from unexpected sources or unsigned publishers enables detection of adversaries using .NET ClickOnce deployment mechanism to deliver and execute malicious applications on endpoints."},{"id":"T1132.001","name":"Standard Encoding","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for Base64 or other standard encoding patterns in C2 traffic—particularly in URL parameters, HTTP headers, or DNS queries—enables detection of adversaries using common encoding to obfuscate command-and-control data."},{"id":"T1132.002","name":"Non-Standard Encoding","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for custom or non-standard encoding patterns in network traffic—including character substitution ciphers, custom XOR schemes, or proprietary encoding—enables detection of bespoke C2 data obfuscation techniques."},{"id":"T1136.001","name":"Local Account","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for local account creation events—including net user /add commands and user creation API calls—enables detection of adversaries establishing local account persistence on compromised systems."},{"id":"T1136.002","name":"Domain Account","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring Active Directory for new account creation events, particularly outside normal provisioning processes or from unexpected source systems, enables detection of adversary domain account creation for persistence."},{"id":"T1136.003","name":"Cloud Account","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring cloud IAM logs for new user or service account creation outside established provisioning workflows enables detection of adversaries creating cloud accounts for persistent access to cloud environments."},{"id":"T1137.001","name":"Office Template Macros","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring Office template directories for unexpected .dotm or .xlsm file additions or modifications enables detection of adversaries planting macro-enabled templates that execute malicious code when Office applications start."},{"id":"T1195.001","name":"Compromise Software Dependencies and Development Tools","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring software dependency resolution and package manager activity for unexpected package sources, version anomalies, or dependency confusion indicators enables detection of compromised development tools and software dependencies."},{"id":"T1204.001","name":"Malicious Link","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for process creation following URL access—particularly browser child processes executing downloaded scripts or binaries—enables detection of user execution triggered by malicious links in phishing messages."},{"id":"T1204.002","name":"Malicious File","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for suspicious child process creation from document applications—such as Office spawning PowerShell, cmd.exe, or wscript—enables detection of malicious file execution triggered by user interaction with weaponized documents."},{"id":"T1204.003","name":"Malicious Image","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Monitoring container runtime for execution of malicious container images—including unexpected image pulls, containers with embedded malware, or images from untrusted registries—enables detection of adversary-crafted container execution."},{"id":"T1205.001","name":"Port Knocking","tactics":["command-and-control","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring network traffic for specific packet sequences targeting closed ports—particularly SYN packets to sequential ports or crafted ICMP messages—enables detection of port knocking techniques used to activate hidden services."},{"id":"T1205.002","name":"Socket Filters","tactics":["command-and-control","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for BPF/eBPF program loading, raw socket creation, or unexpected network filter installations enables detection of socket filter-based traffic signaling used to activate backdoors based on specially crafted packets."},{"id":"T1213.001","name":"Confluence","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Monitoring Confluence access logs for bulk page exports, automated API scraping, or access to sensitive spaces from unusual accounts enables detection of adversary data collection from organizational wikis."},{"id":"T1213.002","name":"Sharepoint","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Monitoring SharePoint access logs for mass document downloads, unusual search queries, or site collection access from unexpected accounts enables detection of adversary data harvesting from organizational document repositories."},{"id":"T1213.004","name":"Customer Relationship Management Software","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Monitoring CRM system access logs for bulk data exports, unusual query patterns, or API access from unexpected sources enables detection of adversaries extracting customer relationship data for espionage or financial gain."},{"id":"T1213.005","name":"Messaging Applications","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Monitoring messaging application logs—including Slack, Teams, and similar platforms—for bulk message exports, unusual API access, or channel enumeration enables detection of adversaries collecting sensitive communications."},{"id":"T1216.001","name":"PubPrn","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for PubPrn.vbs execution or similar signed script invocations with unusual parameters—particularly those referencing remote script locations—enables detection of adversary script proxy execution through trusted Microsoft utilities."},{"id":"T1218.001","name":"Compiled HTML File","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for hh.exe execution loading CHM files from unusual locations or with embedded scripts enables detection of adversaries using compiled HTML help files to execute arbitrary code through a trusted system binary."},{"id":"T1218.002","name":"Control Panel","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for control.exe invocations loading CPL files from non-system directories enables detection of adversaries using Control Panel item format to execute malicious DLLs through the trusted Windows control panel interface."},{"id":"T1218.003","name":"CMSTP","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for CMSTP.exe execution with INF files—particularly those containing ScriptBlock or RunPreSetupCommands entries—enables detection of adversary UAC bypass and code execution through the Connection Manager service."},{"id":"T1218.004","name":"InstallUtil","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for InstallUtil.exe invocations—especially those loading assemblies from temp directories or user-writable paths—enables detection of adversaries using the .NET installation utility to execute unmanaged code."},{"id":"T1218.005","name":"Mshta","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for mshta.exe execution with HTA files or inline script arguments enables detection of adversaries using the Microsoft HTML Application host to execute VBScript, JScript, or PowerShell through a trusted binary."},{"id":"T1218.008","name":"Odbcconf","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for odbcconf.exe execution with /A actions loading DLLs—particularly from non-standard paths—enables detection of adversary code execution proxied through the ODBC configuration utility."},{"id":"T1218.009","name":"Regsvcs/Regasm","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for regsvcs.exe and regasm.exe invocations loading assemblies with ComRegisterFunction attributes enables detection of adversaries using .NET COM registration utilities for code execution bypass."},{"id":"T1218.010","name":"Regsvr32","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for regsvr32.exe invocations—especially those using /s /n /i flags or loading remote scriptlets—enables detection of adversary DLL registration proxy execution, including the well-known squiblydoo bypass technique."},{"id":"T1218.011","name":"Rundll32","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for rundll32.exe execution with unusual DLL paths, exported function names, or command-line arguments enables detection of adversaries using the Windows DLL host to proxy execution of malicious dynamic libraries."},{"id":"T1218.012","name":"Verclsid","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for verclsid.exe invocations verifying unusual CLSIDs—particularly those loading DLLs from non-standard locations—enables detection of adversary code execution through the COM object verification utility."},{"id":"T1218.013","name":"Mavinject","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for mavinject.exe execution targeting process IDs with DLL injection payloads enables detection of adversaries using this Microsoft signed binary to inject malicious DLLs into running processes."},{"id":"T1218.014","name":"MMC","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for mmc.exe execution loading snap-in files from unusual locations or with embedded scripts enables detection of adversaries using Microsoft Management Console for proxy execution of malicious code."},{"id":"T1218.015","name":"Electron Applications","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for Electron application execution with tampered asar archives or debugging flags—particularly with --inspect or modified main.js—enables detection of adversaries abusing Electron-based applications for code execution."},{"id":"T1222.001","name":"Windows File and Directory Permissions Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for icacls, cacls, and takeown command execution or programmatic DACL modifications on Windows enables detection of adversaries weakening file and directory permissions to facilitate further attack operations."},{"id":"T1222.002","name":"Linux and Mac File and Directory Permissions Modification","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for chmod, chown, and setfacl commands on Linux and macOS—particularly those granting world-readable permissions to sensitive files—enables detection of adversary permission modification for defense evasion."},{"id":"T1491.001","name":"Internal Defacement","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Monitoring internal web application content, intranet pages, and shared resources for unauthorized modifications enables detection of internal defacement targeting organizational morale or operational communications."},{"id":"T1491.002","name":"External Defacement","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Monitoring public-facing website file integrity, DNS records, and web server content for unauthorized changes enables detection of external defacement attacks that damage organizational reputation."},{"id":"T1499.001","name":"OS Exhaustion Flood","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Monitoring operating system resource metrics—including TCP connection tables, socket exhaustion, and kernel resource counters—enables detection of OS-level exhaustion floods that overwhelm system networking stacks."},{"id":"T1499.002","name":"Service Exhaustion Flood","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Monitoring service-level performance metrics, request queues, and connection pools enables detection of service exhaustion floods that consume web server, database, or application service resources to cause denial of service."},{"id":"T1499.003","name":"Application Exhaustion Flood","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Monitoring application-layer request rates, error codes, and resource consumption per session enables detection of application exhaustion floods that exploit resource-intensive features to overwhelm application processing capacity."},{"id":"T1499.004","name":"Application or System Exploitation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for exploit-induced application crashes, memory corruption indicators, or anomalous process behavior can detect denial of service achieved through vulnerability exploitation that causes service failures."},{"id":"T1505.002","name":"Transport Agent","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring Exchange transport agent installations and mail flow configurations for unauthorized additions enables detection of adversaries deploying malicious transport agents for persistent email interception on mail servers."},{"id":"T1505.003","name":"Web Shell","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring web server directories for new script files (ASPX, PHP, JSP) and detecting web shell signatures—including command execution patterns and reverse shell connections—enables identification of deployed web shells."},{"id":"T1505.004","name":"IIS Components","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring IIS module registrations, ISAPI filter additions, and managed handler installations for unauthorized components enables detection of adversaries persisting through malicious IIS server components."},{"id":"T1505.005","name":"Terminal Services DLL","tactics":["persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring Terminal Services DLL registrations and RDP session host configurations for unexpected DLL loads enables detection of adversaries installing malicious Terminal Services components for persistent remote access."},{"id":"T1542.004","name":"ROMMONkit","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring ROMMON integrity on Cisco network devices through hash verification and boot process validation enables detection of adversaries installing persistent rootkits in the ROM monitor firmware."},{"id":"T1542.005","name":"TFTP Boot","tactics":["defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring TFTP boot configurations and network boot image integrity enables detection of adversaries manipulating network boot processes to load compromised operating system images on network devices."},{"id":"T1543.002","name":"Systemd Service","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for systemd unit file creation or modification in /etc/systemd/ and user-level systemd directories—particularly units with unusual ExecStart paths—enables detection of adversary persistence through systemd services."},{"id":"T1546.002","name":"Screensaver","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for screensaver registry modifications—including SCRNSAVE.EXE path changes—enables detection of adversaries configuring malicious screensaver executables that activate after idle periods for persistence."},{"id":"T1546.003","name":"Windows Management Instrumentation Event Subscription","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for WMI event subscription creation—including EventFilter, EventConsumer, and FilterToConsumerBinding objects—enables detection of adversary persistence through WMI event-triggered execution."},{"id":"T1546.004","name":"Unix Shell Configuration Modification","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for modifications to .bashrc, .bash_profile, .zshrc, and similar shell configuration files enables detection of adversaries inserting malicious commands that execute whenever a user opens a new shell session."},{"id":"T1546.006","name":"LC_LOAD_DYLIB Addition","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for LC_LOAD_DYLIB header additions to Mach-O binaries enables detection of adversaries injecting persistent code loading directives that force applications to load malicious dynamic libraries on macOS."},{"id":"T1546.008","name":"Accessibility Features","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for replacement or modification of accessibility feature binaries—including sethc.exe, utilman.exe, and osk.exe—enables detection of adversaries installing backdoors accessible from the Windows login screen."},{"id":"T1546.013","name":"PowerShell Profile","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for PowerShell profile file modifications across all profile paths enables detection of adversaries inserting malicious commands into profiles that execute automatically whenever PowerShell sessions are started."},{"id":"T1546.014","name":"Emond","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for emond rule file creation in /etc/emond.d/rules/ and emond daemon activity on macOS enables detection of adversaries leveraging the Event Monitor daemon for persistent event-triggered execution."},{"id":"T1546.016","name":"Installer Packages","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for installer package execution with embedded pre- or post-install scripts—particularly from untrusted sources—enables detection of adversaries using installer packages to execute code during software installation."},{"id":"T1547.002","name":"Authentication Package","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for Authentication Package registry modifications under HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa enables detection of adversaries loading malicious authentication packages for persistence and credential interception."},{"id":"T1547.003","name":"Time Providers","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for Time Provider DLL registrations under HKLM\\SYSTEM\\CurrentControlSet\\Services\\W32Time\\TimeProviders enables detection of adversaries using the Windows Time service as a persistence mechanism."},{"id":"T1547.004","name":"Winlogon Helper DLL","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for Winlogon Helper DLL registry modifications—including Notify, Userinit, and Shell value changes—enables detection of adversary persistence through code that executes during the Windows logon process."},{"id":"T1547.005","name":"Security Support Provider","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for SSP DLL additions to the Security Packages registry value or in-memory SSP loading via AddSecurityPackage enables detection of adversaries installing security support providers to capture plaintext credentials."},{"id":"T1547.006","name":"Kernel Modules and Extensions","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for kernel module loading events—including insmod, modprobe, and kextload on Linux/macOS—and flagging unsigned or unexpected modules enables detection of adversary persistence through kernel-level implants."},{"id":"T1547.007","name":"Re-opened Applications","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for modifications to LoginItems plist files, saved application state directories, or Re-opened Applications configurations on macOS enables detection of adversaries persisting through app restoration mechanisms."},{"id":"T1547.008","name":"LSASS Driver","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for LSASS driver registration changes and DLL loads into the LSASS process space enables detection of adversaries installing persistent credential-intercepting drivers in the local security authority subsystem."},{"id":"T1547.009","name":"Shortcut Modification","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for shortcut (.lnk) file modifications—particularly changes to target paths in startup folders or desktop shortcuts—enables detection of adversaries altering shortcuts to execute malicious payloads on user interaction."},{"id":"T1547.012","name":"Print Processors","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for print processor DLL registrations under the Print Spooler service enables detection of adversaries installing malicious print processors that execute code when the spooler service starts."},{"id":"T1547.013","name":"XDG Autostart Entries","tactics":["persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for new or modified .desktop files in XDG autostart directories (/etc/xdg/autostart/, ~/.config/autostart/) enables detection of adversary persistence through Linux desktop environment autostart entries."},{"id":"T1548.001","name":"Setuid and Setgid","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for setuid/setgid bit changes on Linux and macOS executables—particularly on scripts or binaries in user-writable directories—enables detection of adversaries elevating privileges through SUID/SGID abuse."},{"id":"T1548.002","name":"Bypass User Account Control","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for UAC bypass indicators—including known bypass registry modifications, auto-elevate executable abuse, and DLL side-loading in elevated contexts—enables detection of adversaries circumventing User Account Control."},{"id":"T1548.003","name":"Sudo and Sudo Caching","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring sudo command usage, sudoers file modifications, and sudo timestamp file access enables detection of adversaries exploiting sudo misconfigurations or cached credentials to escalate privileges on Unix systems."},{"id":"T1548.004","name":"Elevated Execution with Prompt","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for AppleScript-triggered privilege elevation prompts, AuthorizationExecuteWithPrivileges API calls, and unexpected system preference pane invocations enables detection of macOS privilege escalation through fake elevation dialogs."},{"id":"T1548.006","name":"TCC Manipulation","tactics":["defense-evasion","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for TCC database modifications, tccutil commands, or MDM profile manipulation on macOS enables detection of adversaries manipulating Transparency, Consent, and Control protections to gain unauthorized access."},{"id":"T1550.001","name":"Application Access Token","tactics":["defense-evasion","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for OAuth token usage from unexpected IP addresses, client applications, or with unusual scope patterns enables detection of adversaries using stolen application access tokens to authenticate without credentials."},{"id":"T1550.003","name":"Pass the Ticket","tactics":["defense-evasion","lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Monitoring Kerberos ticket usage for anomalies—including tickets with unusual lifetimes, forged PAC data, or service ticket requests from unexpected sources—enables detection of pass-the-ticket lateral movement."},{"id":"T1552.001","name":"Credentials In Files","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for file access to known credential storage locations—including web.config, wp-config.php, .env files, and shell history—enables detection of adversaries searching the filesystem for plaintext credentials."},{"id":"T1552.002","name":"Credentials in Registry","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring registry access to known credential storage locations—including RunAs stored credentials and application-specific password entries—enables detection of adversaries harvesting credentials from the Windows registry."},{"id":"T1552.003","name":"Bash History","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for reads of .bash_history, .zsh_history, and similar shell history files by non-interactive processes enables detection of adversaries mining command history for previously typed credentials or sensitive information."},{"id":"T1552.004","name":"Private Keys","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for access to private key files—including SSH keys, PEM files, and PFX certificates in user profile directories—enables detection of adversaries stealing private keys for unauthorized authentication or decryption."},{"id":"T1552.005","name":"Cloud Instance Metadata API","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for queries to cloud instance metadata APIs (169.254.169.254) from application processes enables detection of adversaries harvesting temporary credentials, API tokens, and configuration data from cloud metadata services."},{"id":"T1552.006","name":"Group Policy Preferences","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for access to SYSVOL Group Policy Preferences XML files containing cpassword attributes enables detection of adversaries extracting encrypted credentials from legacy GPP configurations that use reversible encryption."},{"id":"T1552.008","name":"Chat Messages","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for automated access to messaging platform APIs, bulk message retrieval, or search queries targeting credential-related keywords in chat applications enables detection of adversaries mining chat messages for credentials."},{"id":"T1553.001","name":"Gatekeeper Bypass","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for Gatekeeper bypass indicators on macOS—including xattr removal of quarantine attributes, special file attributes, or unsigned application execution—enables detection of adversary attempts to circumvent macOS trust controls."},{"id":"T1553.003","name":"SIP and Trust Provider Hijacking","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for modifications to Windows SIP and trust provider registry entries—including changes to CryptSIPDllGetSignedDataMsg—enables detection of adversaries hijacking code signing verification to validate malicious binaries."},{"id":"T1553.004","name":"Install Root Certificate","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring certificate store modifications for unauthorized root certificate installations—including certutil imports and programmatic certificate store writes—enables detection of adversaries installing rogue CA certificates."},{"id":"T1553.005","name":"Mark-of-the-Web Bypass","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for attempts to remove or manipulate Mark-of-the-Web attributes on downloaded files—including Zone.Identifier alternate data stream deletion—enables detection of adversaries bypassing web download security warnings."},{"id":"T1555.001","name":"Keychain","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for unauthorized access to macOS Keychain files and security CLI commands targeting keychain items enables detection of adversaries extracting stored credentials from Apple's credential management system."},{"id":"T1555.002","name":"Securityd Memory","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for process memory access targeting the securityd daemon on macOS—including debugging attachments and memory reads—enables detection of adversaries extracting decrypted Keychain credentials from securityd process memory."},{"id":"T1555.004","name":"Windows Credential Manager","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for VaultCmd.exe usage, Credential Manager file access, and programmatic queries to the Windows Credential Manager vault enables detection of adversaries harvesting stored credentials from the Windows credential store."},{"id":"T1555.005","name":"Password Managers","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for access to password manager databases, browser credential stores, and master key files enables detection of adversaries targeting password management applications to extract large collections of stored credentials."},{"id":"T1556.001","name":"Domain Controller Authentication","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for modifications to NTLM authentication DLLs, skeleton key indicators, or domain controller authentication process anomalies enables detection of adversaries backdooring Active Directory authentication mechanisms."},{"id":"T1556.002","name":"Password Filter DLL","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for password filter DLL registrations under HKLM\\SYSTEM\\CurrentControlSet\\Control\\Lsa\\Notification Packages enables detection of adversaries installing malicious filters that capture plaintext passwords during changes."},{"id":"T1556.003","name":"Pluggable Authentication Modules","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for PAM configuration file modifications and unusual shared library additions to PAM module directories enables detection of adversaries inserting malicious pluggable authentication modules for credential capture."},{"id":"T1556.004","name":"Network Device Authentication","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for changes to network device authentication configurations—including TACACS+, RADIUS, and local authentication settings—enables detection of adversaries modifying network device authentication for persistent access."},{"id":"T1556.008","name":"Network Provider DLL","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for Network Provider DLL registrations under HKLM\\SYSTEM\\CurrentControlSet\\Services and mpnotify.exe behavior enables detection of adversaries installing credential-harvesting network provider DLLs."},{"id":"T1556.009","name":"Conditional Access Policies","tactics":["credential-access","defense-evasion","persistence"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for Azure AD conditional access policy changes—including policy deletions, exemptions, or trust modifications—enables detection of adversaries weakening authentication requirements to facilitate unauthorized access."},{"id":"T1557.001","name":"LLMNR/NBT-NS Poisoning and SMB Relay","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for LLMNR and NBT-NS response traffic from unexpected hosts, SMB relay indicators, and NTLMv2 hash capture attempts enables detection of adversaries performing name resolution poisoning for credential interception."},{"id":"T1557.002","name":"ARP Cache Poisoning","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for gratuitous ARP packets, ARP table anomalies, and IP-MAC binding changes enables detection of ARP cache poisoning attacks used to redirect network traffic through adversary-controlled systems."},{"id":"T1557.003","name":"DHCP Spoofing","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for rogue DHCP server responses, unusual DHCP offer traffic, and DNS settings changes via DHCP enables detection of adversaries using DHCP spoofing to redirect client traffic through malicious infrastructure."},{"id":"T1557.004","name":"Evil Twin","tactics":["collection","credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for rogue wireless access points, unexpected SSID broadcasts matching organizational networks, and deauthentication frame floods enables detection of evil twin attacks targeting wireless network users."},{"id":"T1558.002","name":"Silver Ticket","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for anomalous Kerberos service ticket usage—including tickets with forged PAC data or service tickets for accounts that did not request TGTs—enables detection of silver ticket forgery attacks."},{"id":"T1558.003","name":"Kerberoasting","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for unusual TGS-REQ patterns targeting service accounts, particularly mass service ticket requests followed by offline activity, enables detection of Kerberoasting attacks extracting service account password hashes."},{"id":"T1558.004","name":"AS-REP Roasting","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for AS-REQ messages for accounts without pre-authentication requirements and subsequent offline cracking indicators enables detection of AS-REP roasting attacks targeting misconfigured Kerberos accounts."},{"id":"T1558.005","name":"Ccache Files","tactics":["credential-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for access to Kerberos credential cache files (/tmp/krb5cc_*) and ccache file manipulation by non-standard processes enables detection of adversaries stealing cached Kerberos tickets for authentication reuse."},{"id":"T1559.002","name":"Dynamic Data Exchange","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for DDE link activation in Office documents—including DDEAuto field codes and DDEEXEC registry keys—enables detection of adversaries exploiting Dynamic Data Exchange for remote code execution without macros."},{"id":"T1559.003","name":"XPC Services","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for suspicious XPC service connections on macOS—including unauthorized clients connecting to privileged XPC services—enables detection of adversaries abusing inter-process communication for privilege escalation."},{"id":"T1560.001","name":"Archive via Utility","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for archiving utility execution—including 7z.exe, WinRAR, and tar—targeting sensitive directories or creating encrypted archives enables detection of adversaries packaging collected data for efficient exfiltration."},{"id":"T1561.001","name":"Disk Content Wipe","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for low-level disk write operations, dd commands targeting block devices, or mass file overwrite patterns enables detection of adversaries performing disk content wipes to destroy data and hinder recovery."},{"id":"T1561.002","name":"Disk Structure Wipe","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for modifications to MBR, GPT partition tables, or boot sector writes enables detection of adversaries performing disk structure wipes that render storage devices unrecoverable at the structural level."},{"id":"T1562.001","name":"Disable or Modify Tools","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for security tool process termination, antivirus service stops, or EDR agent tampering enables detection of adversaries disabling or modifying endpoint protection tools to operate undetected."},{"id":"T1562.002","name":"Disable Windows Event Logging","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for Windows event logging configuration changes—including auditpol modifications, EventLog service stops, or ETW provider disabling—enables detection of adversaries silencing security event collection."},{"id":"T1562.003","name":"Impair Command History Logging","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for HISTCONTROL, HISTFILE, and Set-PSReadLineOption modifications that impair command history recording enables detection of adversaries disabling shell history to prevent forensic analysis of their commands."},{"id":"T1562.004","name":"Disable or Modify System Firewall","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for firewall rule modifications—including netsh advfirewall, iptables, or pfctl changes—that create unauthorized network access paths enables detection of adversary manipulation of host-based firewalls."},{"id":"T1562.006","name":"Indicator Blocking","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for ETW provider modifications, Sysmon configuration tampering, or event source deregistration enables detection of adversaries blocking security indicators from reaching monitoring and analysis tools."},{"id":"T1562.010","name":"Downgrade Attack","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for protocol downgrade indicators—including forced use of weaker authentication protocols, TLS version downgrades, or encryption cipher suite manipulation—enables detection of adversary attempts to weaken security controls."},{"id":"T1562.011","name":"Spoof Security Alerting","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for security alert spoofing—including fake antivirus notifications, forged SIEM alerts, or manipulated dashboard data—enables detection of adversaries creating deceptive security information to mislead defenders."},{"id":"T1562.012","name":"Disable or Modify Linux Audit System","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for auditd configuration changes, auditctl rule modifications, or audit daemon stop events enables detection of adversaries disabling the Linux audit system to eliminate forensic evidence collection."},{"id":"T1563.001","name":"SSH Hijacking","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for SSH session multiplexing, ControlMaster socket creation, or unauthorized SSH agent forwarding enables detection of adversaries hijacking existing SSH sessions to move laterally without re-authenticating."},{"id":"T1563.002","name":"RDP Hijacking","tactics":["lateral-movement"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for RDP session takeover indicators—including tscon.exe usage without disconnects, session shadow requests, or RDP hijacking through service manipulation—enables detection of adversaries stealing active RDP sessions."},{"id":"T1564.002","name":"Hidden Users","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for user account modifications that hide accounts from login screens—including UserID manipulation below 500 on macOS or Hide_From_User_List registry changes—enables detection of adversary-created hidden user accounts."},{"id":"T1564.004","name":"NTFS File Attributes","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for NTFS alternate data stream creation, extended attribute writes, and file attribute manipulation enables detection of adversaries hiding payloads in NTFS file attributes invisible to standard directory listings."},{"id":"T1564.006","name":"Run Virtual Instance","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for unexpected virtual machine creation or hypervisor execution—including VirtualBox, VMware, or QEMU processes started by unusual users—enables detection of adversaries running malware within hidden virtual instances."},{"id":"T1564.007","name":"VBA Stomping","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for VBA project binary modifications (VBA stomping) that remove source code while preserving compiled p-code enables detection of adversaries making macro analysis more difficult for security researchers."},{"id":"T1564.008","name":"Email Hiding Rules","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for email inbox rule creation that deletes, moves, or hides specific messages—particularly rules targeting security notification keywords—enables detection of adversaries concealing their activities within compromised mailboxes."},{"id":"T1564.009","name":"Resource Forking","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for macOS resource fork creation and extended attribute manipulation—particularly resource forks containing executable code—enables detection of adversaries hiding payloads in Apple filesystem metadata structures."},{"id":"T1564.010","name":"Process Argument Spoofing","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for process argument spoofing—where initial process creation arguments differ from runtime arguments due to PEB manipulation—enables detection of adversaries hiding their true command-line parameters from logging."},{"id":"T1565.001","name":"Stored Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Monitoring database integrity, file checksums, and data change audit trails for unauthorized modifications enables detection of adversaries manipulating stored data to undermine business processes or destroy evidence."},{"id":"T1565.002","name":"Transmitted Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Monitoring network traffic integrity through cryptographic verification and traffic analysis enables detection of adversaries manipulating data in transit to alter communications between systems."},{"id":"T1565.003","name":"Runtime Data Manipulation","tactics":["impact"],"mapping_type":"mitigates","mapping_rationale":"Monitoring application runtime behavior for unexpected data transformations, memory modifications, or output alterations enables detection of adversaries manipulating data during processing to affect business logic outcomes."},{"id":"T1566.001","name":"Spearphishing Attachment","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for emails with weaponized attachments—including malicious macros, embedded exploits, or polyglot files—through sandbox analysis and content inspection enables detection of spearphishing attachment delivery."},{"id":"T1566.002","name":"Spearphishing Link","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for emails containing suspicious URLs, newly registered domains, or known credential-harvesting pages enables detection of spearphishing link campaigns targeting organizational users for credential theft or malware delivery."},{"id":"T1566.003","name":"Spearphishing via Service","tactics":["initial-access"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for suspicious messages delivered through social media, messaging platforms, or other non-email services enables detection of spearphishing via alternative communication channels that bypass email security controls."},{"id":"T1568.002","name":"Domain Generation Algorithms","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Monitoring DNS query logs for algorithmically generated domain patterns—identified by high entropy, consistent length patterns, or bulk NXDOMAIN responses—enables detection of malware using domain generation algorithms for C2."},{"id":"T1569.002","name":"Service Execution","tactics":["execution"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for PsExec-style service creation, sc.exe execution commands, and Service Control Manager events for unexpected service installations enables detection of adversaries executing code through Windows service creation."},{"id":"T1573.001","name":"Symmetric Cryptography","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for encrypted C2 channels using symmetric cryptography—identified by traffic pattern analysis, key exchange indicators, or known malware encryption signatures—enables detection of symmetrically encrypted command channels."},{"id":"T1573.002","name":"Asymmetric Cryptography","tactics":["command-and-control"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for anomalous TLS/SSL sessions using self-signed certificates, unusual cipher suites, or certificate pinning bypass indicators enables detection of asymmetrically encrypted C2 channels that evade standard decryption."},{"id":"T1574.001","name":"DLL Search Order Hijacking","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for DLL loads from unexpected directories—particularly when applications load libraries from current working directories instead of system paths—enables detection of DLL search order hijacking attacks."},{"id":"T1574.004","name":"Dylib Hijacking","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for dylib loading from non-standard paths on macOS—particularly when applications load dynamic libraries from writable locations—enables detection of adversaries exploiting dylib search order for persistence."},{"id":"T1574.005","name":"Executable Installer File Permissions Weakness","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for DLL loads and executable writes in installer temporary directories with overly permissive file permissions enables detection of adversaries exploiting weak installer file permissions for privilege escalation."},{"id":"T1574.007","name":"Path Interception by PATH Environment Variable","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for creation of executables in PATH directories that shadow legitimate system utilities enables detection of adversaries placing malicious binaries in PATH locations to intercept command execution."},{"id":"T1574.008","name":"Path Interception by Search Order Hijacking","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for executable creation in directories that precede legitimate binary locations in search order enables detection of adversaries exploiting application search order to execute malicious binaries before intended targets."},{"id":"T1574.009","name":"Path Interception by Unquoted Path","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for executables placed in path segments of unquoted Windows service paths enables detection of adversaries exploiting unquoted path parsing to intercept service binary resolution for privilege escalation."},{"id":"T1574.010","name":"Services File Permissions Weakness","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for modifications to service binary paths and service DLL registrations—including changes to ImagePath values—enables detection of adversaries exploiting weak service file permissions to replace legitimate service components."},{"id":"T1574.013","name":"KernelCallbackTable","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for KernelCallbackTable modifications in process memory enables detection of adversaries hijacking kernel callback function pointers to redirect execution flow from legitimate processes to malicious code."},{"id":"T1574.014","name":"AppDomainManager","tactics":["defense-evasion","persistence","privilege-escalation"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for AppDomainManager entries in application .config files and unexpected .NET assembly loads enables detection of adversaries using the .NET AppDomainManager to inject code into managed applications."},{"id":"T1578.001","name":"Create Snapshot","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring cloud audit logs for unauthorized snapshot creation—particularly of running instances or volumes containing sensitive data—enables detection of adversaries creating snapshots to exfiltrate data or analyze system configurations."},{"id":"T1578.002","name":"Create Cloud Instance","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring cloud provider logs for unauthorized instance creation—including instances launched from public AMIs, suspicious regions, or with unusual configurations—enables detection of adversary cloud resource manipulation."},{"id":"T1578.003","name":"Delete Cloud Instance","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for unexpected cloud instance deletions—particularly of logging, monitoring, or security instances—enables detection of adversaries destroying cloud resources to cover tracks or impair defensive capabilities."},{"id":"T1598.001","name":"Spearphishing Service","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Monitoring inbound messages from social media, professional networks, and web services for social engineering patterns—including impersonation and information solicitation—enables detection of spearphishing for information via services."},{"id":"T1598.002","name":"Spearphishing Attachment","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for reconnaissance-stage emails with benign attachments designed to elicit responses containing organizational information enables detection of phishing-for-information campaigns using attachment-based pretexts."},{"id":"T1598.003","name":"Spearphishing Link","tactics":["reconnaissance"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for emails containing links to fake surveys, credential verification pages, or information harvesting sites enables detection of spearphishing link campaigns aimed at gathering organizational intelligence."},{"id":"T1599.001","name":"Network Address Translation Traversal","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring network device routing configurations for unauthorized NAT rules, static routes, or policy-based routing changes that traverse network boundaries enables detection of adversaries bridging segmented networks through NAT traversal."},{"id":"T1601.001","name":"Patch System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring network device firmware hashes against known-good baselines and alerting on discrepancies enables detection of adversaries who have patched system images with modified firmware containing backdoors or weakened security."},{"id":"T1601.002","name":"Downgrade System Image","tactics":["defense-evasion"],"mapping_type":"mitigates","mapping_rationale":"Monitoring for firmware version downgrades on network devices—including unexpected IOS or firmware version changes to older releases—enables detection of adversaries reverting to vulnerable system images to exploit known weaknesses."},{"id":"T1602.001","name":"SNMP (MIB Dump)","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Monitoring SNMP traffic for unauthorized MIB walks, bulk GET requests, or SNMP access from unexpected source IPs enables detection of adversaries using SNMP to extract device configuration and network topology information."},{"id":"T1602.002","name":"Network Device Configuration Dump","tactics":["collection"],"mapping_type":"mitigates","mapping_rationale":"Monitoring network management interfaces for unauthorized configuration export commands—including show running-config, tftp transfers, or API-based configuration retrieval—enables detection of adversary network device configuration dumping."}],"metadata":{"last_reviewed":"2026-10-03","review_notes":"2026-10-03: nist_csf_2 ID.IM-01, ID.IM-02, ID.RA-01, PR.DS-01, PR.DS-02, PR.DS-10 added from NIST's CSF 2.0 to SP 800-53 Rev 5.2.0 crosswalk (OLIR entry 186), which OSA's mapping now takes as its base.","mapping_status":"complete"},"function":"detective","used_by_patterns":["SP-001","SP-002","SP-011","SP-012","SP-015","SP-016","SP-017","SP-023","SP-025","SP-026","SP-027","SP-028","SP-029","SP-030","SP-031","SP-032","SP-035","SP-036","SP-037","SP-038","SP-043","SP-045","SP-046","SP-047","SP-048","SP-049"]}}