[
  {
    "id": "tech-t1078",
    "attack_id": "T1078",
    "name": "Valid Accounts",
    "tactic": "Defense Evasion",
    "short_description": "Adversaries obtain and misuse legitimate credentials of existing user accounts to maintain persistence and bypass controls.",
    "url": "https://attack.mitre.org/techniques/T1078/",
    "parent_attack_id": null,
    "case_count": 19,
    "case_slugs": [
      "lockbit-ransomware-takedown",
      "volt-typhoon-critical-infrastructure",
      "alphv-blackcat-change-healthcare",
      "colonial-pipeline-ransomware",
      "solarwinds-orion-supply-chain-compromise",
      "us-v-vachon-desjardins-netwalker",
      "us-v-baratov-yahoo-breach",
      "us-v-schulte-cia-vault-7",
      "us-v-thompson-capital-one-breach",
      "genesis-market-takedown-cookie-monster",
      "us-v-kriuchkov-tesla-ransomware",
      "us-v-nikulin-linkedin-dropbox",
      "us-v-irgc-cyberav3ngers-water",
      "us-v-firsov-deer-io",
      "us-v-medvedev-infraud-organization",
      "us-v-kulkov-try2check",
      "us-v-rhyne-insider-ransomware-extortion",
      "snowflake-multi-tenant-credential-attacks",
      "us-v-lichtenstein-bitfinex-heist-laundering"
    ]
  },
  {
    "id": "tech-t1190",
    "attack_id": "T1190",
    "name": "Exploit Public-Facing Application",
    "tactic": "Initial Access",
    "short_description": "Adversaries exploit vulnerabilities in internet-connected software such as web servers or VPN appliances.",
    "url": "https://attack.mitre.org/techniques/T1190/",
    "parent_attack_id": null,
    "case_count": 11,
    "case_slugs": [
      "sandworm-notpetya-olympic-destroyer",
      "lockbit-ransomware-takedown",
      "volt-typhoon-critical-infrastructure",
      "solarwinds-orion-supply-chain-compromise",
      "us-v-vasinskyi-kaseya-revil",
      "us-v-albert-gonzalez-tjx-heartland",
      "us-v-tyurin-jpmorgan-chase",
      "us-v-thompson-capital-one-breach",
      "us-v-vision-cardersmarket",
      "us-v-radchenko-sec-edgar-intrusion",
      "us-v-zhong-silk-road-bitcoin-seizure"
    ]
  },
  {
    "id": "tech-t1486",
    "attack_id": "T1486",
    "name": "Data Encrypted for Impact",
    "tactic": "Impact",
    "short_description": "Adversaries encrypt victim files and databases to disrupt business operations and demand financial extortion.",
    "url": "https://attack.mitre.org/techniques/T1486/",
    "parent_attack_id": null,
    "case_count": 10,
    "case_slugs": [
      "lockbit-ransomware-takedown",
      "alphv-blackcat-change-healthcare",
      "colonial-pipeline-ransomware",
      "us-v-yakubets-evil-corp-dridex",
      "us-v-park-jin-hyok-lazarus",
      "us-v-vachon-desjardins-netwalker",
      "us-v-vasinskyi-kaseya-revil",
      "us-v-witte-dunaev-trickbot",
      "us-v-kriuchkov-tesla-ransomware",
      "us-v-sikerin-polyanin-revil-affiliates"
    ]
  },
  {
    "id": "tech-t1041",
    "attack_id": "T1041",
    "name": "Exfiltration Over C2 Channel",
    "tactic": "Exfiltration",
    "short_description": "Adversaries transmit stolen data over existing command and control channels back to adversary servers.",
    "url": "https://attack.mitre.org/techniques/T1041/",
    "parent_attack_id": null,
    "case_count": 8,
    "case_slugs": [
      "alphv-blackcat-change-healthcare",
      "colonial-pipeline-ransomware",
      "us-v-hladyr-fin7-carbanak",
      "us-v-seleznev-track2",
      "us-v-sun-kailiang-pla-unit-61398",
      "us-v-albert-gonzalez-tjx-heartland",
      "us-v-tyurin-jpmorgan-chase",
      "snowflake-multi-tenant-credential-attacks"
    ]
  },
  {
    "id": "tech-t1566-001",
    "attack_id": "T1566.001",
    "name": "Spearphishing Attachment",
    "tactic": "Initial Access",
    "short_description": "Adversaries send spearphishing emails with malicious attachments to gain initial access to victim systems.",
    "url": "https://attack.mitre.org/techniques/T1566/001/",
    "parent_attack_id": "T1566",
    "case_count": 6,
    "case_slugs": [
      "sandworm-notpetya-olympic-destroyer",
      "us-v-hladyr-fin7-carbanak",
      "us-v-yakubets-evil-corp-dridex",
      "us-v-sun-kailiang-pla-unit-61398",
      "us-v-witte-dunaev-trickbot",
      "us-v-badin-german-bundestag-apt28"
    ]
  },
  {
    "id": "tech-t1090",
    "attack_id": "T1090",
    "name": "Proxy",
    "tactic": "Command and Control",
    "short_description": "Adversaries route network communications through intermediate proxy chains or Tor to hide origin IP addresses.",
    "url": "https://attack.mitre.org/techniques/T1090/",
    "parent_attack_id": null,
    "case_count": 6,
    "case_slugs": [
      "us-v-legkodymov-bitzlato",
      "us-v-nguyen-chipmixer",
      "us-v-barriss-serial-swatting",
      "us-v-siew-incognito-market",
      "us-v-boiko-qqaazz-laundering",
      "us-v-ross-ulbricht-silk-road"
    ]
  },
  {
    "id": "tech-t1566-002",
    "attack_id": "T1566.002",
    "name": "Spearphishing Link",
    "tactic": "Initial Access",
    "short_description": "Adversaries send spearphishing emails containing malicious hyperlinks to lure users into downloading payloads or entering credentials.",
    "url": "https://attack.mitre.org/techniques/T1566/002/",
    "parent_attack_id": "T1566",
    "case_count": 5,
    "case_slugs": [
      "us-v-park-jin-hyok-lazarus",
      "us-v-baratov-yahoo-breach",
      "us-v-nikulin-linkedin-dropbox",
      "us-v-netyksho-apt28-dnc",
      "us-v-johnson-shadowcrew"
    ]
  },
  {
    "id": "tech-t1555",
    "attack_id": "T1555",
    "name": "Credentials from Password Stores",
    "tactic": "Credential Access",
    "short_description": "Adversaries search local browser credential databases and keyrings for cached web passwords.",
    "url": "https://attack.mitre.org/techniques/T1555/",
    "parent_attack_id": null,
    "case_count": 4,
    "case_slugs": [
      "us-v-yakubets-evil-corp-dridex",
      "genesis-market-takedown-cookie-monster",
      "us-v-hutchins-kronos-malware",
      "us-v-brovko-botnet-logs"
    ]
  },
  {
    "id": "tech-t1003",
    "attack_id": "T1003",
    "name": "OS Credential Dumping",
    "tactic": "Credential Access",
    "short_description": "Adversaries dump plaintext passwords and hashes from operating system memory structures such as LSASS.",
    "url": "https://attack.mitre.org/techniques/T1003/",
    "parent_attack_id": null,
    "case_count": 3,
    "case_slugs": [
      "sandworm-notpetya-olympic-destroyer",
      "us-v-baratov-yahoo-breach",
      "us-v-witte-dunaev-trickbot"
    ]
  },
  {
    "id": "tech-t1485",
    "attack_id": "T1485",
    "name": "Data Destruction",
    "tactic": "Impact",
    "short_description": "Adversaries irreversibly overwrite storage media and files to destroy data rather than extort ransoms.",
    "url": "https://attack.mitre.org/techniques/T1485/",
    "parent_attack_id": null,
    "case_count": 3,
    "case_slugs": [
      "sandworm-notpetya-olympic-destroyer",
      "us-v-park-jin-hyok-lazarus",
      "us-v-irgc-cyberav3ngers-water"
    ]
  },
  {
    "id": "tech-t1584",
    "attack_id": "T1584",
    "name": "Compromise Infrastructure",
    "tactic": "Resource Development",
    "short_description": "Adversaries hijack third-party domains, servers, and routers to use as attack relay infrastructure.",
    "url": "https://attack.mitre.org/techniques/T1584/",
    "parent_attack_id": null,
    "case_count": 3,
    "case_slugs": [
      "volt-typhoon-critical-infrastructure",
      "us-v-levashov-kelihos-botnet",
      "us-v-khusyaynova-project-lakhta"
    ]
  },
  {
    "id": "tech-t1059-001",
    "attack_id": "T1059.001",
    "name": "PowerShell",
    "tactic": "Execution",
    "short_description": "Adversaries abuse the Windows PowerShell command environment to execute commands and download malicious payloads.",
    "url": "https://attack.mitre.org/techniques/T1059/001/",
    "parent_attack_id": "T1059",
    "case_count": 2,
    "case_slugs": [
      "us-v-hladyr-fin7-carbanak",
      "us-v-netyksho-apt28-dnc"
    ]
  },
  {
    "id": "tech-t1490",
    "attack_id": "T1490",
    "name": "Inhibit System Recovery",
    "tactic": "Impact",
    "short_description": "Adversaries delete volume shadow copies and system restore points to prevent recovery from ransomware.",
    "url": "https://attack.mitre.org/techniques/T1490/",
    "parent_attack_id": null,
    "case_count": 2,
    "case_slugs": [
      "lockbit-ransomware-takedown",
      "us-v-vachon-desjardins-netwalker"
    ]
  },
  {
    "id": "tech-t1567",
    "attack_id": "T1567",
    "name": "Exfiltration Over Web Service",
    "tactic": "Exfiltration",
    "short_description": "Adversaries exfiltrate sensitive files to legitimate cloud storage providers like Mega or Google Drive.",
    "url": "https://attack.mitre.org/techniques/T1567/",
    "parent_attack_id": null,
    "case_count": 2,
    "case_slugs": [
      "lockbit-ransomware-takedown",
      "alphv-blackcat-change-healthcare"
    ]
  },
  {
    "id": "tech-t1021-002",
    "attack_id": "T1021.002",
    "name": "SMB / Windows Admin Shares",
    "tactic": "Lateral Movement",
    "short_description": "Adversaries leverage Server Message Block (SMB) and administrative shares (C$, ADMIN$) for lateral spread.",
    "url": "https://attack.mitre.org/techniques/T1021/002/",
    "parent_attack_id": "T1021",
    "case_count": 2,
    "case_slugs": [
      "sandworm-notpetya-olympic-destroyer",
      "us-v-park-jin-hyok-lazarus"
    ]
  },
  {
    "id": "tech-t1059-003",
    "attack_id": "T1059.003",
    "name": "Windows Command Shell",
    "tactic": "Execution",
    "short_description": "Adversaries execute commands and batch scripts using the Windows cmd.exe command shell.",
    "url": "https://attack.mitre.org/techniques/T1059/003/",
    "parent_attack_id": "T1059",
    "case_count": 1,
    "case_slugs": [
      "volt-typhoon-critical-infrastructure"
    ]
  },
  {
    "id": "tech-t1021-001",
    "attack_id": "T1021.001",
    "name": "Remote Desktop Protocol",
    "tactic": "Lateral Movement",
    "short_description": "Adversaries use Remote Desktop Protocol (RDP) connections to log into target systems interactively.",
    "url": "https://attack.mitre.org/techniques/T1021/001/",
    "parent_attack_id": "T1021",
    "case_count": 1,
    "case_slugs": [
      "colonial-pipeline-ransomware"
    ]
  },
  {
    "id": "tech-t1070",
    "attack_id": "T1070",
    "name": "Indicator Removal",
    "tactic": "Defense Evasion",
    "short_description": "Adversaries delete event logs and temporary files to hinder incident response and forensic attribution.",
    "url": "https://attack.mitre.org/techniques/T1070/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "us-v-schulte-cia-vault-7"
    ]
  },
  {
    "id": "tech-t1562-001",
    "attack_id": "T1562.001",
    "name": "Disable or Modify Tools",
    "tactic": "Defense Evasion",
    "short_description": "Adversaries disable endpoint security software and antivirus services to prevent detection.",
    "url": "https://attack.mitre.org/techniques/T1562/001/",
    "parent_attack_id": "T1562",
    "case_count": 1,
    "case_slugs": [
      "lockbit-ransomware-takedown"
    ]
  },
  {
    "id": "tech-t1053-005",
    "attack_id": "T1053.005",
    "name": "Scheduled Task",
    "tactic": "Persistence",
    "short_description": "Adversaries abuse task scheduling utilities to execute malicious code at fixed intervals or system startup.",
    "url": "https://attack.mitre.org/techniques/T1053/005/",
    "parent_attack_id": "T1053",
    "case_count": 1,
    "case_slugs": [
      "us-v-yakubets-evil-corp-dridex"
    ]
  },
  {
    "id": "tech-t1082",
    "attack_id": "T1082",
    "name": "System Information Discovery",
    "tactic": "Discovery",
    "short_description": "Adversaries gather details about the operating system and architecture to guide further exploitation.",
    "url": "https://attack.mitre.org/techniques/T1082/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "us-v-vasinskyi-kaseya-revil"
    ]
  },
  {
    "id": "tech-t1087",
    "attack_id": "T1087",
    "name": "Account Discovery",
    "tactic": "Discovery",
    "short_description": "Adversaries enumerate domain and local user accounts to locate high-privilege targets.",
    "url": "https://attack.mitre.org/techniques/T1087/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "alphv-blackcat-change-healthcare"
    ]
  },
  {
    "id": "tech-t1083",
    "attack_id": "T1083",
    "name": "File and Directory Discovery",
    "tactic": "Discovery",
    "short_description": "Adversaries search file systems and shared drives for sensitive files and trade secrets.",
    "url": "https://attack.mitre.org/techniques/T1083/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "us-v-thompson-capital-one-breach"
    ]
  },
  {
    "id": "tech-t1027",
    "attack_id": "T1027",
    "name": "Obfuscated Files or Information",
    "tactic": "Defense Evasion",
    "short_description": "Adversaries encrypt or encode payload strings and executable code to conceal malicious contents.",
    "url": "https://attack.mitre.org/techniques/T1027/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "us-v-park-jin-hyok-lazarus"
    ]
  },
  {
    "id": "tech-t1547-001",
    "attack_id": "T1547.001",
    "name": "Registry Run Keys / Startup Folder",
    "tactic": "Persistence",
    "short_description": "Adversaries add program references to Windows registry run keys to execute malware on user logon.",
    "url": "https://attack.mitre.org/techniques/T1547/001/",
    "parent_attack_id": "T1547",
    "case_count": 1,
    "case_slugs": [
      "us-v-yakubets-evil-corp-dridex"
    ]
  },
  {
    "id": "tech-t1588-002",
    "attack_id": "T1588.002",
    "name": "Obtain Tool",
    "tactic": "Resource Development",
    "short_description": "Adversaries buy or download third-party commercial tools and exploits for intrusion operations.",
    "url": "https://attack.mitre.org/techniques/T1588/002/",
    "parent_attack_id": "T1588",
    "case_count": 1,
    "case_slugs": [
      "us-v-seleznev-track2"
    ]
  },
  {
    "id": "tech-t1071-001",
    "attack_id": "T1071.001",
    "name": "Web Protocols",
    "tactic": "Command and Control",
    "short_description": "Adversaries communicate using standard HTTP and HTTPS web protocols to blend with regular traffic.",
    "url": "https://attack.mitre.org/techniques/T1071/001/",
    "parent_attack_id": "T1071",
    "case_count": 1,
    "case_slugs": [
      "solarwinds-orion-supply-chain-compromise"
    ]
  },
  {
    "id": "tech-t1110",
    "attack_id": "T1110",
    "name": "Brute Force",
    "tactic": "Credential Access",
    "short_description": "Adversaries use automated credential guessing or password spraying against authentication portals.",
    "url": "https://attack.mitre.org/techniques/T1110/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "us-v-seleznev-track2"
    ]
  },
  {
    "id": "tech-t1574-002",
    "attack_id": "T1574.002",
    "name": "DLL Side-Loading",
    "tactic": "Persistence",
    "short_description": "Adversaries execute malicious dynamic-link libraries by placing them alongside signed, legitimate executables.",
    "url": "https://attack.mitre.org/techniques/T1574/002/",
    "parent_attack_id": "T1574",
    "case_count": 1,
    "case_slugs": [
      "us-v-vasinskyi-kaseya-revil"
    ]
  },
  {
    "id": "tech-t1057",
    "attack_id": "T1057",
    "name": "Process Discovery",
    "tactic": "Discovery",
    "short_description": "Adversaries enumerate running system processes to locate security agents and target software.",
    "url": "https://attack.mitre.org/techniques/T1057/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "volt-typhoon-critical-infrastructure"
    ]
  },
  {
    "id": "tech-t1133",
    "attack_id": "T1133",
    "name": "External Remote Services",
    "tactic": "Initial Access",
    "short_description": "Adversaries connect to external-facing VPNs, Citrix gateways, and portals using stolen credentials.",
    "url": "https://attack.mitre.org/techniques/T1133/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "alphv-blackcat-change-healthcare"
    ]
  },
  {
    "id": "tech-t1569-002",
    "attack_id": "T1569.002",
    "name": "Service Execution",
    "tactic": "Execution",
    "short_description": "Adversaries create and run Windows services to execute payloads with system privileges.",
    "url": "https://attack.mitre.org/techniques/T1569/002/",
    "parent_attack_id": "T1569",
    "case_count": 1,
    "case_slugs": [
      "us-v-vasinskyi-kaseya-revil"
    ]
  },
  {
    "id": "tech-t1046",
    "attack_id": "T1046",
    "name": "Network Service Discovery",
    "tactic": "Discovery",
    "short_description": "Adversaries scan network IP ranges to identify open ports, listening services, and exploitable servers.",
    "url": "https://attack.mitre.org/techniques/T1046/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "us-v-seleznev-track2"
    ]
  },
  {
    "id": "tech-t1570",
    "attack_id": "T1570",
    "name": "Lateral Tool Transfer",
    "tactic": "Lateral Movement",
    "short_description": "Adversaries copy binaries, scripts, and utilities from one internal host to another.",
    "url": "https://attack.mitre.org/techniques/T1570/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "volt-typhoon-critical-infrastructure"
    ]
  },
  {
    "id": "tech-t1560-001",
    "attack_id": "T1560.001",
    "name": "Archive via Utility",
    "tactic": "Collection",
    "short_description": "Adversaries compress and password-protect stolen files using tools like 7-Zip, WinRAR, or tar.",
    "url": "https://attack.mitre.org/techniques/T1560/001/",
    "parent_attack_id": "T1560",
    "case_count": 1,
    "case_slugs": [
      "us-v-schulte-cia-vault-7"
    ]
  },
  {
    "id": "tech-t1074-001",
    "attack_id": "T1074.001",
    "name": "Local Data Staging",
    "tactic": "Collection",
    "short_description": "Adversaries stage stolen documents in hidden directories before exfiltrating them.",
    "url": "https://attack.mitre.org/techniques/T1074/001/",
    "parent_attack_id": "T1074",
    "case_count": 1,
    "case_slugs": [
      "us-v-hladyr-fin7-carbanak"
    ]
  },
  {
    "id": "tech-t1583-001",
    "attack_id": "T1583.001",
    "name": "Domains",
    "tactic": "Resource Development",
    "short_description": "Adversaries register typo-squatted or deceptively named domain names for phishing campaigns.",
    "url": "https://attack.mitre.org/techniques/T1583/001/",
    "parent_attack_id": "T1583",
    "case_count": 1,
    "case_slugs": [
      "us-v-netyksho-apt28-dnc"
    ]
  },
  {
    "id": "tech-t1558-003",
    "attack_id": "T1558.003",
    "name": "Kerberoasting",
    "tactic": "Credential Access",
    "short_description": "Adversaries request Kerberos service tickets for accounts with Service Principal Names and crack hashes offline.",
    "url": "https://attack.mitre.org/techniques/T1558/003/",
    "parent_attack_id": "T1558",
    "case_count": 1,
    "case_slugs": [
      "lockbit-ransomware-takedown"
    ]
  },
  {
    "id": "tech-t1007",
    "attack_id": "T1007",
    "name": "System Service Discovery",
    "tactic": "Discovery",
    "short_description": "Adversaries list configured system services to find exploitable software paths and vulnerable configurations.",
    "url": "https://attack.mitre.org/techniques/T1007/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "us-v-vachon-desjardins-netwalker"
    ]
  },
  {
    "id": "tech-t1055",
    "attack_id": "T1055",
    "name": "Process Injection",
    "tactic": "Defense Evasion",
    "short_description": "Adversaries inject malicious code into processes to evade process-based defenses and elevate privileges.",
    "url": "https://attack.mitre.org/techniques/T1055/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "us-v-yakubets-evil-corp-dridex"
    ]
  },
  {
    "id": "tech-t1055-012",
    "attack_id": "T1055.012",
    "name": "Process Hollowing",
    "tactic": "Defense Evasion",
    "short_description": "Adversaries hollow out legitimate executables in memory and overwrite them with malicious payloads.",
    "url": "https://attack.mitre.org/techniques/T1055/012/",
    "parent_attack_id": "T1055",
    "case_count": 1,
    "case_slugs": [
      "sandworm-notpetya-olympic-destroyer"
    ]
  },
  {
    "id": "tech-t1036",
    "attack_id": "T1036",
    "name": "Masquerading",
    "tactic": "Defense Evasion",
    "short_description": "Adversaries manipulate features of their artifacts to make them appear legitimate or benign.",
    "url": "https://attack.mitre.org/techniques/T1036/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "solarwinds-orion-supply-chain-compromise"
    ]
  },
  {
    "id": "tech-t1036-005",
    "attack_id": "T1036.005",
    "name": "Match Legitimate Name or Location",
    "tactic": "Defense Evasion",
    "short_description": "Adversaries match or approximate the name or location of legitimate system files.",
    "url": "https://attack.mitre.org/techniques/T1036/005/",
    "parent_attack_id": "T1036",
    "case_count": 1,
    "case_slugs": [
      "sandworm-notpetya-olympic-destroyer"
    ]
  },
  {
    "id": "tech-t1132",
    "attack_id": "T1132",
    "name": "Data Encoding",
    "tactic": "Command and Control",
    "short_description": "Adversaries encode data with standard algorithms to make communications and metadata more difficult to inspect.",
    "url": "https://attack.mitre.org/techniques/T1132/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "solarwinds-orion-supply-chain-compromise"
    ]
  },
  {
    "id": "tech-t1047",
    "attack_id": "T1047",
    "name": "Windows Management Instrumentation",
    "tactic": "Execution",
    "short_description": "Adversaries abuse WMI to execute malicious commands and query administrative system details.",
    "url": "https://attack.mitre.org/techniques/T1047/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "lockbit-ransomware-takedown"
    ]
  },
  {
    "id": "tech-t1018",
    "attack_id": "T1018",
    "name": "Remote System Discovery",
    "tactic": "Discovery",
    "short_description": "Adversaries search for other systems on an internal network to identify lateral movement candidates.",
    "url": "https://attack.mitre.org/techniques/T1018/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "volt-typhoon-critical-infrastructure"
    ]
  },
  {
    "id": "tech-t1016",
    "attack_id": "T1016",
    "name": "System Network Configuration Discovery",
    "tactic": "Discovery",
    "short_description": "Adversaries search for network settings and IP configurations to understand internal network routing.",
    "url": "https://attack.mitre.org/techniques/T1016/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "volt-typhoon-critical-infrastructure"
    ]
  },
  {
    "id": "tech-t1033",
    "attack_id": "T1033",
    "name": "System Owner/User Discovery",
    "tactic": "Discovery",
    "short_description": "Adversaries identify the primary user or logged-on account on compromised hosts.",
    "url": "https://attack.mitre.org/techniques/T1033/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "volt-typhoon-critical-infrastructure"
    ]
  },
  {
    "id": "tech-t1112",
    "attack_id": "T1112",
    "name": "Modify Registry",
    "tactic": "Defense Evasion",
    "short_description": "Adversaries modify the Windows registry to hide artifacts and disable security controls.",
    "url": "https://attack.mitre.org/techniques/T1112/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "us-v-vachon-desjardins-netwalker"
    ]
  },
  {
    "id": "tech-t1543-003",
    "attack_id": "T1543.003",
    "name": "Windows Service",
    "tactic": "Persistence",
    "short_description": "Adversaries install or configure Windows services to maintain persistence and execute on system reboot.",
    "url": "https://attack.mitre.org/techniques/T1543/003/",
    "parent_attack_id": "T1543",
    "case_count": 1,
    "case_slugs": [
      "sandworm-notpetya-olympic-destroyer"
    ]
  },
  {
    "id": "tech-t1548-002",
    "attack_id": "T1548.002",
    "name": "Bypass User Account Control",
    "tactic": "Privilege Escalation",
    "short_description": "Adversaries bypass Windows UAC mechanisms to elevate process execution rights.",
    "url": "https://attack.mitre.org/techniques/T1548/002/",
    "parent_attack_id": "T1548",
    "case_count": 1,
    "case_slugs": [
      "us-v-vachon-desjardins-netwalker"
    ]
  },
  {
    "id": "tech-t1056-001",
    "attack_id": "T1056.001",
    "name": "Keylogging",
    "tactic": "Credential Access",
    "short_description": "Adversaries record keystrokes to harvest passwords and confidential communications.",
    "url": "https://attack.mitre.org/techniques/T1056/001/",
    "parent_attack_id": "T1056",
    "case_count": 1,
    "case_slugs": [
      "us-v-hladyr-fin7-carbanak"
    ]
  },
  {
    "id": "tech-t1113",
    "attack_id": "T1113",
    "name": "Screen Capture",
    "tactic": "Collection",
    "short_description": "Adversaries take screenshots of victim desktop sessions to collect sensitive information.",
    "url": "https://attack.mitre.org/techniques/T1113/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "us-v-hladyr-fin7-carbanak"
    ]
  },
  {
    "id": "tech-t1124",
    "attack_id": "T1124",
    "name": "System Time Discovery",
    "tactic": "Discovery",
    "short_description": "Adversaries check system time and timezone to synchronize distributed intrusion events.",
    "url": "https://attack.mitre.org/techniques/T1124/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "sandworm-notpetya-olympic-destroyer"
    ]
  },
  {
    "id": "tech-t1020",
    "attack_id": "T1020",
    "name": "Automated Exfiltration",
    "tactic": "Exfiltration",
    "short_description": "Adversaries use automated scripts to periodically transmit collected data out of the network.",
    "url": "https://attack.mitre.org/techniques/T1020/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "us-v-hladyr-fin7-carbanak"
    ]
  },
  {
    "id": "tech-t1001-002",
    "attack_id": "T1001.002",
    "name": "Steganography",
    "tactic": "Command and Control",
    "short_description": "Adversaries hide command payloads or stolen data within image or media files.",
    "url": "https://attack.mitre.org/techniques/T1001/002/",
    "parent_attack_id": "T1001",
    "case_count": 1,
    "case_slugs": [
      "us-v-park-jin-hyok-lazarus"
    ]
  },
  {
    "id": "tech-t1102",
    "attack_id": "T1102",
    "name": "Web Service: Dead Drop Resolver",
    "tactic": "Command and Control",
    "short_description": "Adversaries post command and control addresses on external forums or paste sites.",
    "url": "https://attack.mitre.org/techniques/T1102/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "us-v-yakubets-evil-corp-dridex"
    ]
  },
  {
    "id": "tech-t1571",
    "attack_id": "T1571",
    "name": "Non-Standard Port",
    "tactic": "Command and Control",
    "short_description": "Adversaries communicate using non-standard ports to bypass simple firewall rules.",
    "url": "https://attack.mitre.org/techniques/T1571/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "us-v-nguyen-chipmixer"
    ]
  },
  {
    "id": "tech-t1573",
    "attack_id": "T1573",
    "name": "Encrypted Channel",
    "tactic": "Command and Control",
    "short_description": "Adversaries encrypt C2 traffic using symmetric or asymmetric encryption to evade inspection.",
    "url": "https://attack.mitre.org/techniques/T1573/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "lockbit-ransomware-takedown"
    ]
  },
  {
    "id": "tech-t1071-004",
    "attack_id": "T1071.004",
    "name": "DNS Tunneling",
    "tactic": "Command and Control",
    "short_description": "Adversaries encode commands and data within DNS query and response packets.",
    "url": "https://attack.mitre.org/techniques/T1071/004/",
    "parent_attack_id": "T1071",
    "case_count": 1,
    "case_slugs": [
      "us-v-netyksho-apt28-dnc"
    ]
  },
  {
    "id": "tech-t1498",
    "attack_id": "T1498",
    "name": "Network Denial of Service",
    "tactic": "Impact",
    "short_description": "Adversaries flood network connections to exhaust bandwidth and disable internet access.",
    "url": "https://attack.mitre.org/techniques/T1498/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "us-v-kriuchkov-tesla-ransomware"
    ]
  },
  {
    "id": "tech-t1499",
    "attack_id": "T1499",
    "name": "Endpoint Denial of Service",
    "tactic": "Impact",
    "short_description": "Adversaries crash host services or exhaust local CPU and memory resources.",
    "url": "https://attack.mitre.org/techniques/T1499/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "sandworm-notpetya-olympic-destroyer"
    ]
  },
  {
    "id": "tech-t1068",
    "attack_id": "T1068",
    "name": "Exploitation for Privilege Escalation",
    "tactic": "Privilege Escalation",
    "short_description": "Adversaries exploit software vulnerabilities in operating systems to execute code with elevated system permissions.",
    "url": "https://attack.mitre.org/techniques/T1068/",
    "parent_attack_id": null,
    "case_count": 1,
    "case_slugs": [
      "us-v-park-jin-hyok-lazarus"
    ]
  },
  {
    "id": "tech-t1546-003",
    "attack_id": "T1546.003",
    "name": "Windows Management Instrumentation Event Subscription",
    "tactic": "Persistence",
    "short_description": "Adversaries create WMI event filters and consumers to trigger persistent payload execution upon system events.",
    "url": "https://attack.mitre.org/techniques/T1546/003/",
    "parent_attack_id": "T1546",
    "case_count": 1,
    "case_slugs": [
      "us-v-netyksho-apt28-dnc"
    ]
  },
  {
    "id": "tech-t1105",
    "attack_id": "T1105",
    "name": "Ingress Tool Transfer",
    "tactic": "Command and Control",
    "short_description": "Adversaries transfer tools and post-exploitation binaries from external infrastructure onto compromised hosts.",
    "url": "https://attack.mitre.org/techniques/T1105/",
    "parent_attack_id": null,
    "case_count": 0,
    "case_slugs": []
  }
]