MITRE ATT&CK Quick Reference
Most Common Techniques in Malware
Initial Access (TA0001)
- T1566 – Phishing
- T1189 – Drive-by Compromise
Execution (TA0002)
- T1059.001 – PowerShell
- T1059.003 – Windows Command Shell
- T1204 – User Execution
Persistence (TA0003)
- T1547.001 – Registry Run Keys
- T1053.005 – Scheduled Task
- T1543.003 – Windows Service
Defense Evasion (TA0005)
- T1055 – Process Injection
- T1027 – Obfuscated Files
- T1140 – Deobfuscate/Decode
Discovery (TA0007)
- T1082 – System Information Discovery
- T1083 – File and Directory Discovery
- T1057 – Process Discovery
Collection (TA0009)
- T1056.001 – Keylogging
- T1113 – Screen Capture
- T1005 – Data from Local System
C2 (TA0011)
- T1071.001 – Web Protocols (HTTP/S)
- T1573 – Encrypted Channel
- T1132 – Data Encoding
Exfiltration (TA0010)
- T1041 – Exfiltration Over C2 Channel
- T1048 – Exfiltration Over Alternative Protocol
How to Map Findings
- Observe the behavior (what did the malware do?)
- Find the matching tactic (why did it do it?)
- Select the specific technique and sub-technique
- Record evidence (IOC or behavioral observation)
