{ "Activate Firmware Update Mode": "inhibit response function", "Alarm Suppression": "inhibit response function", "Automated Collection": "collection", "Block Command Message": "inhibit response function", "Block Reporting Message": "inhibit response function", "Block Serial COM": "inhibit response function", "Brute Force I/O": "impair process control", "Change Operating Mode": "execution", "Command-Line Interface": "execution", "Commonly Used Port": "command and control", "Connection Proxy": "command and control", "Damage to Property": "impact", "Data Destruction": "inhibit response function", "Data from Information Repositories": "collection", "Default Credentials": "lateral movement", "Denial of Control": "impact", "Denial of Service": "inhibit response function", "Denial of View": "impact", "Detect Operating Mode": "collection", "Device Restart/Shutdown": "inhibit response function", "Drive-by Compromise": "initial access", "Execution through API": "execution", "Exploit Public-Facing Application": "initial access", "Exploitation for Evasion": "evasion", "Exploitation for Privilege Escalation": "privilege escalation", "Exploitation of Remote Services": "initial access", "External Remote Services": "initial access", "Graphical User Interface": "execution", "Hooking": "execution", "I/O Image": "collection", "Indicator Removal on Host": "evasion", "Internet Accessible Device": "initial access", "Lateral Tool Transfer": "lateral movement", "Loss of Availability": "impact", "Loss of Control": "impact", "Loss of Productivity and Revenue": "impact", "Loss of Protection": "impact", "Loss of Safety": "impact", "Loss of View": "impact", "Man in the Middle": "collection", "Manipulate I/O Image": "inhibit response function", "Manipulation of Control": "impact", "Manipulation of View": "impact", "Masquerading": "evasion", "Modify Alarm Settings": "inhibit response function", "Modify Controller Tasking": "execution", "Modify Parameter": "impair process control", "Modify Program": "persistence", "Module Firmware": "persistence", "Monitor Process State": "collection", "Native API": "execution", "Network Connection Enumeration": "discovery", "Network Sniffing": "discovery", "Point & Tag Identification": "collection", "Program Download": "lateral movement", "Program Upload": "collection", "Project File Infection": "persistence", "Remote Services": "initial access", "Remote System Discovery": "discovery", "Remote System Information Discovery": "discovery", "Replication Through Removable Media": "initial access", "Rogue Master": "initial access", "Rootkit": "evasion", "Screen Capture": "collection", "Scripting": "execution", "Service Stop": "inhibit response function", "Spearphishing Attachment": "initial access", "Spoof Reporting Message": "evasion", "Standard Application Layer Protocol": "command and control", "Supply Chain Compromise": "initial access", "System Firmware": "persistence", "Theft of Operational Information": "impact", "Transient Cyber Asset": "initial access", "Unauthorized Command Message": "impair process control", "User Execution": "execution", "Valid Accounts": "persistence", "Wireless Compromise": "initial access", "Wireless Sniffing": "discovery" }