provides the latest coverage of MITRE techniques and sub-techniques.
Intelligent Sandbox 5.2.2
Intelligent Sandbox 5.2.2 includes these techniques.
ID | MITRE techniques and sub-techniques |
|---|---|
T1559.001 | Inter-Process Communication: Component Object Model |
T1059.001 | Command and Scripting Interpreter: PowerShell |
T1547.001 | Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder |
T1112 | Modify Registry |
T1562.001 | Impair Defenses: Disable or Modify Tools |
T1480.001 | Execution Guardrails: Environmental Keying |
T1105 | Ingress Tool Transfer |
T1553.006 | Subvert Trust Controls: Code Signing Policy Modification |
T1562.006 | Impair Defenses: Indicator Blocking |
T1573.001 | Encrypted Channel: Symmetric Cryptography |
T1486 | Data Encrypted for Impact |
T1124 | System Time Discovery |
T1574.008 | Hijack Execution Flow: Path Interception by Search Order Hijacking |
T1037 | Boot or Logon Initialization Scripts: Logon Script (Windows) |
T1070.003 | Indicator Removal on Host: Clear Command History |
T1110.003 | Brute Force: Password Spraying |
T1569.002 | System Services: Service Execution |
T1106 | Native API |
T1553.004 | Subvert Trust Controls: Install Root Certificate |
T1546.003 | Event Triggered Execution: Windows Management Instrumentation Event Subscription |
T1027 | Obfuscated Files or Information |
T1547.009 | Boot or Logon AutoStart Execution: Shortcut Modification |
T1559.001 | Inter-Process Communication: Component Object Model |
T1053 | Scheduled Task/Job |
T1070.001 | Indicator Removal on Host: Clear Windows Event Logs |
T1056.001 | Input Capture: Keylogging |
T1059.005 | Command and Scripting Interpreter: Visual Basic |
T1021.002 | Remote Services: SMB/Windows Admin Shares |
T1546.013 | Event Triggered Execution: PowerShell Profile |
T1546.015 | Event Triggered Execution: Component Object Model Hijacking |
T1560.002 | Archive Collected Data: Archive via Library |
T1560.001 | Archive Collected Data: Archive via Utility |
T1543.003 | Create or Modify System Process: Windows Service |
T1069.002 | Discovery: Domain Groups |
T1482 | Domain Trust Discovery |
T1078.001 | Valid Accounts: Default Accounts |
T1135 | Network Share Discovery |
T1047 | Windows Management Instrumentation |
T1007 | System Service Discovery |
Intelligent Sandbox 5.2
Intelligent Sandbox 5.2 includes these techniques.
ID | MITRE techniques and sub-techniques |
|---|---|
T1102 | Web Service |
T1102.002 | Bidirectional Communication |
T1614.001 | System Location Discovery: System Language Discovery |
T1218.014 | System Binary Proxy Execution: MMC |
T1546.001 | Event Triggered Execution: Change Default File Association |
T1562.010 | Impair Defenses: Downgrade Attack |
T1562.002 | Disable Windows Event Logging |
T1222.001 | Windows File and Directory Permissions Modification |
T1574.001 | Hijack Execution Flow: DLL Side-Loading |
T1218.013 | Mavinject |
T1505.005 | Server Software Component: Terminal Services DLL |