MITRE ATT&CK Quick Reference

Concept

MITRE ATT&CK Quick Reference

Most Common Techniques in Malware

Initial Access (TA0001)

  • T1566 – Phishing
  • T1189 – Drive-by Compromise

Execution (TA0002)

  • T1059.001 – PowerShell
  • T1059.003 – Windows Command Shell
  • T1204 – User Execution

Persistence (TA0003)

  • T1547.001 – Registry Run Keys
  • T1053.005 – Scheduled Task
  • T1543.003 – Windows Service

Defense Evasion (TA0005)

  • T1055 – Process Injection
  • T1027 – Obfuscated Files
  • T1140 – Deobfuscate/Decode

Discovery (TA0007)

  • T1082 – System Information Discovery
  • T1083 – File and Directory Discovery
  • T1057 – Process Discovery

Collection (TA0009)

  • T1056.001 – Keylogging
  • T1113 – Screen Capture
  • T1005 – Data from Local System

C2 (TA0011)

  • T1071.001 – Web Protocols (HTTP/S)
  • T1573 – Encrypted Channel
  • T1132 – Data Encoding

Exfiltration (TA0010)

  • T1041 – Exfiltration Over C2 Channel
  • T1048 – Exfiltration Over Alternative Protocol

How to Map Findings

  1. Observe the behavior (what did the malware do?)
  2. Find the matching tactic (why did it do it?)
  3. Select the specific technique and sub-technique
  4. Record evidence (IOC or behavioral observation)