Explore
One catalog. Two ways to explore.
Find the evidence you’re looking for.
Explore adversary behavior in the map, or look up an API in the event list. Your filters follow you between views.
Explore tactics
Select a tactic to focus the mapInitial Access
TA0001The adversary is trying to get into your network.
Execution
TA0002The adversary is trying to run malicious code.
T1651 Cloud Administration Command
T1059 Command and Scripting Interpreter
T1072 Software Deployment Tools
T1053 Scheduled Task/Job
T1648 Serverless Execution
Persistence
TA0003The adversary is trying to maintain their foothold.
T1098 Account Manipulation
T1098.003 Additional Cloud Roles
T1098.001 Additional Cloud Credentials
T1098.004 SSH Authorized Keys
T1136.003 Cloud Account
T1546 Event Triggered Execution
T1556.006 Multi-Factor Authentication
T1078.004 Cloud Accounts
T1556 Modify Authentication Process
T1053 Scheduled Task/Job
T1098.005 Device Registration
T1525 Implant Internal Image
Privilege Escalation
TA0004The adversary is trying to gain higher-level permissions.
T1098 Account Manipulation
T1098.003 Additional Cloud Roles
T1078.004 Cloud Accounts
T1548 Abuse Elevation Control Mechanism
T1098.001 Additional Cloud Credentials
T1548.005 Temporary Elevated Cloud Access
T1484.002 Trust Modification
T1098.004 SSH Authorized Keys
T1098.005 Device Registration
Stealth
TA0005The adversary is trying to hide and conceal their actions, appearing as normal behavior.
T1078.004 Cloud Accounts
T1070 Indicator Removal
T1535 Unused/Unsupported Cloud Regions
Defense Impairment
TA0112The adversary is trying to break security mechanisms, pipelines, and tooling so defenders can’t see or trust what’s happening.
T1685 Disable or Modify Tools
T1685.002 Disable or Modify Cloud Log
T1686.001 Cloud Firewall
T1484.002 Trust Modification
T1556.006 Multi-Factor Authentication
T1556 Modify Authentication Process
T1556.009 Conditional Access Policies
T1578 Modify Cloud Compute Infrastructure
T1578.003 Delete Cloud Instance
T1599 Network Boundary Bridging
Credential Access
TA0006The adversary is trying to steal account names and passwords.
T1552 Unsecured Credentials
T1555.006 Cloud Secrets Management Stores
T1528 Steal Application Access Token
Discovery
TA0007The adversary is trying to figure out your environment.
Lateral Movement
TA0008The adversary is trying to move through your environment.
T1021 Remote Services
T1021.004 SSH
T1550.001 Application Access Token
Collection
TA0009The adversary is trying to gather data of interest to their goal.
T1530 Data from Cloud Storage
Exfiltration
TA0010The adversary is trying to steal data.
T1537 Transfer Data to Cloud Account
Impact
TA0040The adversary is trying to manipulate, interrupt, or destroy your systems and data.
T1485 Data Destruction
T1531 Account Access Removal
T1490 Inhibit System Recovery
T1489 Service Stop
No matching evidence
Try a broader search or clear your provider and tactic filters.