markdived
/

File size: 3,368 Bytes
b7fa3e3
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
{
  "Activate Firmware Update Mode": "inhibit response function",
  "Alarm Suppression": "inhibit response function",
  "Automated Collection": "collection",
  "Block Command Message": "inhibit response function",
  "Block Reporting Message": "inhibit response function",
  "Block Serial COM": "inhibit response function",
  "Brute Force I/O": "impair process control",
  "Change Operating Mode": "execution",
  "Command-Line Interface": "execution",
  "Commonly Used Port": "command and control",
  "Connection Proxy": "command and control",
  "Damage to Property": "impact",
  "Data Destruction": "inhibit response function",
  "Data from Information Repositories": "collection",
  "Default Credentials": "lateral movement",
  "Denial of Control": "impact",
  "Denial of Service": "inhibit response function",
  "Denial of View": "impact",
  "Detect Operating Mode": "collection",
  "Device Restart/Shutdown": "inhibit response function",
  "Drive-by Compromise": "initial access",
  "Execution through API": "execution",
  "Exploit Public-Facing Application": "initial access",
  "Exploitation for Evasion": "evasion",
  "Exploitation for Privilege Escalation": "privilege escalation",
  "Exploitation of Remote Services": "initial access",
  "External Remote Services": "initial access",
  "Graphical User Interface": "execution",
  "Hooking": "execution",
  "I/O Image": "collection",
  "Indicator Removal on Host": "evasion",
  "Internet Accessible Device": "initial access",
  "Lateral Tool Transfer": "lateral movement",
  "Loss of Availability": "impact",
  "Loss of Control": "impact",
  "Loss of Productivity and Revenue": "impact",
  "Loss of Protection": "impact",
  "Loss of Safety": "impact",
  "Loss of View": "impact",
  "Man in the Middle": "collection",
  "Manipulate I/O Image": "inhibit response function",
  "Manipulation of Control": "impact",
  "Manipulation of View": "impact",
  "Masquerading": "evasion",
  "Modify Alarm Settings": "inhibit response function",
  "Modify Controller Tasking": "execution",
  "Modify Parameter": "impair process control",
  "Modify Program": "persistence",
  "Module Firmware": "persistence",
  "Monitor Process State": "collection",
  "Native API": "execution",
  "Network Connection Enumeration": "discovery",
  "Network Sniffing": "discovery",
  "Point & Tag Identification": "collection",
  "Program Download": "lateral movement",
  "Program Upload": "collection",
  "Project File Infection": "persistence",
  "Remote Services": "initial access",
  "Remote System Discovery": "discovery",
  "Remote System Information Discovery": "discovery",
  "Replication Through Removable Media": "initial access",
  "Rogue Master": "initial access",
  "Rootkit": "evasion",
  "Screen Capture": "collection",
  "Scripting": "execution",
  "Service Stop": "inhibit response function",
  "Spearphishing Attachment": "initial access",
  "Spoof Reporting Message": "evasion",
  "Standard Application Layer Protocol": "command and control",
  "Supply Chain Compromise": "initial access",
  "System Firmware": "persistence",
  "Theft of Operational Information": "impact",
  "Transient Cyber Asset": "initial access",
  "Unauthorized Command Message": "impair process control",
  "User Execution": "execution",
  "Valid Accounts": "persistence",
  "Wireless Compromise": "initial access",
  "Wireless Sniffing": "discovery"
}