ENTERPRISE FRAMEWORK
MITRE ATT&CK Technique Matrix
Adversary techniques substantiated with verbatim evidence excerpts from federal indictments, sentencing memorandums, and official government advisories.
Key Facts
- 65 MITRE ATT&CK techniques and sub-techniques cataloged.
- 64 techniques substantiated with verbatim primary evidence excerpts.
- Organized across enterprise tactics from Initial Access through Impact.
- Every mapped technique cites specific page numbers or paragraph locators in court filings.
Initial Access
4 techniquesExecution
4 techniquesPersistence
5 techniquesPrivilege Escalation
2 techniquesDefense Evasion
9 techniques T1078 19 cases
Valid Accounts
T1070 1 case
Indicator Removal
T1562.001 1 case
Disable or Modify Tools
T1027 1 case
Obfuscated Files or Information
T1055 1 case
Process Injection
T1055.012 1 case
Process Hollowing
T1036 1 case
Masquerading
T1036.005 1 case
Match Legitimate Name or Location
T1112 1 case
Modify Registry
Credential Access
5 techniquesDiscovery
10 techniques T1082 1 case
System Information Discovery
T1087 1 case
Account Discovery
T1083 1 case
File and Directory Discovery
T1057 1 case
Process Discovery
T1046 1 case
Network Service Discovery
T1007 1 case
System Service Discovery
T1018 1 case
Remote System Discovery
T1016 1 case
System Network Configuration Discovery
T1033 1 case
System Owner/User Discovery
T1124 1 case