Skip to content

Explore

One catalog. Two ways to explore.

Find the evidence you’re looking for.

Explore adversary behavior in the map, or look up an API in the event list. Your filters follow you between views.

262catalog events
41techniques
12tactics
Cloud providers

Explore tactics

Select a tactic to focus the map

250 events · 41 techniques · 12 tactics

01

The adversary is trying to get into your network.

7 events
02

Execution

TA0002

The adversary is trying to run malicious code.

13 events
03

The adversary is trying to maintain their foothold.

77 events
T1098

Account Manipulation

32 events AWSAzureGCP
T1098.003

Additional Cloud Roles

12 events AWSAzureGCP
T1098.001

Additional Cloud Credentials

7 events AWSAzureGCP
T1098.004

SSH Authorized Keys

6 events AWSGCP
T1136.003

Cloud Account

6 events AWSAzure
T1546

Event Triggered Execution

4 events AWSAzure
T1556.006

Multi-Factor Authentication

4 events AWSAzure
T1078.004

Cloud Accounts

3 events AWS
T1556

Modify Authentication Process

2 events AWS
T1053

Scheduled Task/Job

1 event AWS
T1098.005

Device Registration

1 event AWS
T1525

Implant Internal Image

1 event AWS
04

The adversary is trying to gain higher-level permissions.

70 events
T1098

Account Manipulation

32 events AWSAzureGCP
T1098.003

Additional Cloud Roles

14 events AWSAzureGCP
T1078.004

Cloud Accounts

6 events AWS
T1548

Abuse Elevation Control Mechanism

5 events AWS
T1098.001

Additional Cloud Credentials

4 events AWSAzureGCP
T1548.005

Temporary Elevated Cloud Access

4 events GCP
T1484.002

Trust Modification

3 events AWS
T1098.004

SSH Authorized Keys

2 events AWS
T1098.005

Device Registration

1 event AWS
05

Stealth

TA0005

The adversary is trying to hide and conceal their actions, appearing as normal behavior.

9 events
06

The adversary is trying to break security mechanisms, pipelines, and tooling so defenders can’t see or trust what’s happening.

73 events
T1685

Disable or Modify Tools

27 events AWSAzureGCP
Technique context
T1685.002

Disable or Modify Cloud Log

21 events AWSAzureGCP
T1686.001

Cloud Firewall

14 events AWSAzureGCP
T1484.002

Trust Modification

3 events AWS
T1556.006

Multi-Factor Authentication

3 events AWSAzure
T1556

Modify Authentication Process

2 events AWS
T1556.009

Conditional Access Policies

2 events Azure
T1578

Modify Cloud Compute Infrastructure

1 event AWS
T1578.003

Delete Cloud Instance

1 event Azure
T1599

Network Boundary Bridging

1 event Azure
07

The adversary is trying to steal account names and passwords.

16 events
08

Discovery

TA0007

The adversary is trying to figure out your environment.

0 events
09

The adversary is trying to move through your environment.

10 events
10

The adversary is trying to gather data of interest to their goal.

17 events
11

The adversary is trying to steal data.

13 events
12

Impact

TA0040

The adversary is trying to manipulate, interrupt, or destroy your systems and data.

38 events
T1485

Data Destruction

27 events AWSAzureGCP
T1531

Account Access Removal

10 events AWSAzureGCP
T1490

Inhibit System Recovery

3 events AWSAzure
T1489

Service Stop

1 event AWS