MITRE ATT&CK Lifecycle
Tactic-level overview of the ATT&CK enterprise matrix.
Rendering…
Make it your own.
mindmap
root((ATT&CK))
Initial Access
Phishing
Valid accounts
Public-facing app exploit
Execution
Command-line interface
PowerShell
Scheduled task
Persistence
Registry run keys
Cron job
Account creation
Privilege Escalation
Token manipulation
Sudo + sudo caching
Process injection
Defense Evasion
Obfuscation
Masquerading
Disable security tools
Credential Access
Brute force
OS credential dumping
Kerberoasting
Discovery
Network service scan
Account discovery
Lateral Movement
Pass-the-hash
Remote services
SMB
Collection
Email collection
Data from shared drives
Exfiltration
Encrypted channel
DNS tunnelling
Impact
Ransomware encryption
Data destruction