Exfiltration Over Alternative Protocol - T1048 (a19e86f8-1c0a-4fea-8407-23b73d615776) |
Attack Pattern |
AADInternals - S0677 (2c5281dd-b5fd-4531-8aea-c1bf8a0f8756) |
mitre-tool |
1 |
AADInternals - S0677 (2c5281dd-b5fd-4531-8aea-c1bf8a0f8756) |
mitre-tool |
Device Registration - T1098.005 (7decb26c-715c-40cf-b7e0-026f7d7cc215) |
Attack Pattern |
1 |
AADInternals - S0677 (2c5281dd-b5fd-4531-8aea-c1bf8a0f8756) |
mitre-tool |
Steal Application Access Token - T1528 (890c9858-598c-401d-a4d5-c67ebcdd703a) |
Attack Pattern |
1 |
Domain Properties - T1590.001 (e3b168bd-fcd7-439e-9382-2e6c2f63514d) |
Attack Pattern |
AADInternals - S0677 (2c5281dd-b5fd-4531-8aea-c1bf8a0f8756) |
mitre-tool |
1 |
AADInternals - S0677 (2c5281dd-b5fd-4531-8aea-c1bf8a0f8756) |
mitre-tool |
Multi-Factor Authentication - T1556.006 (b4409cd8-0da9-46e1-a401-a241afd4d1cc) |
Attack Pattern |
1 |
Spearphishing Link - T1598.003 (2d3f5b3c-54ca-4f4d-bb1f-849346d31230) |
Attack Pattern |
AADInternals - S0677 (2c5281dd-b5fd-4531-8aea-c1bf8a0f8756) |
mitre-tool |
1 |
PowerShell - T1059.001 (970a3432-3237-47ad-bcca-7d8cbb217736) |
Attack Pattern |
AADInternals - S0677 (2c5281dd-b5fd-4531-8aea-c1bf8a0f8756) |
mitre-tool |
1 |
AADInternals - S0677 (2c5281dd-b5fd-4531-8aea-c1bf8a0f8756) |
mitre-tool |
Trust Modification - T1484.002 (24769ab5-14bd-4f4e-a752-cfb185da53ee) |
Attack Pattern |
1 |
Private Keys - T1552.004 (60b508a1-6a5e-46b1-821a-9f7b78752abf) |
Attack Pattern |
AADInternals - S0677 (2c5281dd-b5fd-4531-8aea-c1bf8a0f8756) |
mitre-tool |
1 |
AADInternals - S0677 (2c5281dd-b5fd-4531-8aea-c1bf8a0f8756) |
mitre-tool |
SAML Tokens - T1606.002 (1f9c2bae-b441-4f66-a8af-b65946ee72f2) |
Attack Pattern |
1 |
Cloud Account - T1136.003 (a009cb25-4801-4116-9105-80a91cf15c1b) |
Attack Pattern |
AADInternals - S0677 (2c5281dd-b5fd-4531-8aea-c1bf8a0f8756) |
mitre-tool |
1 |
Modify Registry - T1112 (57340c81-c025-4189-8fa0-fc7ede51bae4) |
Attack Pattern |
AADInternals - S0677 (2c5281dd-b5fd-4531-8aea-c1bf8a0f8756) |
mitre-tool |
1 |
Silver Ticket - T1558.002 (d273434a-448e-4598-8e14-607f4a0d5e27) |
Attack Pattern |
AADInternals - S0677 (2c5281dd-b5fd-4531-8aea-c1bf8a0f8756) |
mitre-tool |
1 |
AADInternals - S0677 (2c5281dd-b5fd-4531-8aea-c1bf8a0f8756) |
mitre-tool |
Hybrid Identity - T1556.007 (54ca26f3-c172-4231-93e5-ccebcac2161f) |
Attack Pattern |
1 |
AADInternals - S0677 (2c5281dd-b5fd-4531-8aea-c1bf8a0f8756) |
mitre-tool |
Cloud Service Discovery - T1526 (e24fcba8-2557-4442-a139-1ee2f2e784db) |
Attack Pattern |
1 |
Spearphishing Link - T1566.002 (2b742742-28c3-4e1b-bab7-8350d6300fa7) |
Attack Pattern |
AADInternals - S0677 (2c5281dd-b5fd-4531-8aea-c1bf8a0f8756) |
mitre-tool |
1 |
AADInternals - S0677 (2c5281dd-b5fd-4531-8aea-c1bf8a0f8756) |
mitre-tool |
LSA Secrets - T1003.004 (1ecfdab8-7d59-4c98-95d4-dc41970f57fc) |
Attack Pattern |
1 |
Email Addresses - T1589.002 (69f897fd-12a9-4c89-ad6a-46d2f3c38262) |
Attack Pattern |
AADInternals - S0677 (2c5281dd-b5fd-4531-8aea-c1bf8a0f8756) |
mitre-tool |
1 |
AADInternals - S0677 (2c5281dd-b5fd-4531-8aea-c1bf8a0f8756) |
mitre-tool |
Cloud Groups - T1069.003 (16e94db9-b5b1-4cd0-b851-f38fbd0a70f2) |
Attack Pattern |
1 |
AADInternals - S0677 (2c5281dd-b5fd-4531-8aea-c1bf8a0f8756) |
mitre-tool |
Data from Cloud Storage - T1530 (3298ce88-1628-43b1-87d9-0b5336b193d7) |
Attack Pattern |
1 |
AADInternals - S0677 (2c5281dd-b5fd-4531-8aea-c1bf8a0f8756) |
mitre-tool |
Cloud Administration Command - T1651 (d94b3ae9-8059-4989-8e9f-ea0f601f80a7) |
Attack Pattern |
1 |
Cloud Account - T1087.004 (8f104855-e5b7-4077-b1f5-bc3103b41abe) |
Attack Pattern |
AADInternals - S0677 (2c5281dd-b5fd-4531-8aea-c1bf8a0f8756) |
mitre-tool |
1 |
Steal or Forge Authentication Certificates - T1649 (7de1f7ac-5d0c-4c9c-8873-627202205331) |
Attack Pattern |
AADInternals - S0677 (2c5281dd-b5fd-4531-8aea-c1bf8a0f8756) |
mitre-tool |
1 |
AADInternals - S0677 (2c5281dd-b5fd-4531-8aea-c1bf8a0f8756) |
mitre-tool |
Credentials In Files - T1552.001 (837f9164-50af-4ac0-8219-379d8a74cefc) |
Attack Pattern |
1 |
Account Manipulation - T1098 (a10641f4-87b4-45a3-a906-92a149cb2c27) |
Attack Pattern |
Device Registration - T1098.005 (7decb26c-715c-40cf-b7e0-026f7d7cc215) |
Attack Pattern |
2 |
Domain Properties - T1590.001 (e3b168bd-fcd7-439e-9382-2e6c2f63514d) |
Attack Pattern |
Gather Victim Network Information - T1590 (9d48cab2-7929-4812-ad22-f536665f0109) |
Attack Pattern |
2 |
Modify Authentication Process - T1556 (f4c1826f-a322-41cd-9557-562100848c84) |
Attack Pattern |
Multi-Factor Authentication - T1556.006 (b4409cd8-0da9-46e1-a401-a241afd4d1cc) |
Attack Pattern |
2 |
Spearphishing Link - T1598.003 (2d3f5b3c-54ca-4f4d-bb1f-849346d31230) |
Attack Pattern |
Phishing for Information - T1598 (cca0ccb6-a068-4574-a722-b1556f86833a) |
Attack Pattern |
2 |
PowerShell - T1059.001 (970a3432-3237-47ad-bcca-7d8cbb217736) |
Attack Pattern |
Command and Scripting Interpreter - T1059 (7385dfaf-6886-4229-9ecd-6fd678040830) |
Attack Pattern |
2 |
Domain or Tenant Policy Modification - T1484 (ebb42bbe-62d7-47d7-a55f-3b08b61d792d) |
Attack Pattern |
Trust Modification - T1484.002 (24769ab5-14bd-4f4e-a752-cfb185da53ee) |
Attack Pattern |
2 |
Unsecured Credentials - T1552 (435dfb86-2697-4867-85b5-2fef496c0517) |
Attack Pattern |
Private Keys - T1552.004 (60b508a1-6a5e-46b1-821a-9f7b78752abf) |
Attack Pattern |
2 |
Forge Web Credentials - T1606 (94cb00a4-b295-4d06-aa2b-5653b9c1be9c) |
Attack Pattern |
SAML Tokens - T1606.002 (1f9c2bae-b441-4f66-a8af-b65946ee72f2) |
Attack Pattern |
2 |
Cloud Account - T1136.003 (a009cb25-4801-4116-9105-80a91cf15c1b) |
Attack Pattern |
Create Account - T1136 (e01be9c5-e763-4caf-aeb7-000b416aef67) |
Attack Pattern |
2 |
Silver Ticket - T1558.002 (d273434a-448e-4598-8e14-607f4a0d5e27) |
Attack Pattern |
Steal or Forge Kerberos Tickets - T1558 (3fc01293-ef5e-41c6-86ce-61f10706b64a) |
Attack Pattern |
2 |
Modify Authentication Process - T1556 (f4c1826f-a322-41cd-9557-562100848c84) |
Attack Pattern |
Hybrid Identity - T1556.007 (54ca26f3-c172-4231-93e5-ccebcac2161f) |
Attack Pattern |
2 |
Spearphishing Link - T1566.002 (2b742742-28c3-4e1b-bab7-8350d6300fa7) |
Attack Pattern |
Phishing - T1566 (a62a8db3-f23a-4d8f-afd6-9dbc77e7813b) |
Attack Pattern |
2 |
LSA Secrets - T1003.004 (1ecfdab8-7d59-4c98-95d4-dc41970f57fc) |
Attack Pattern |
OS Credential Dumping - T1003 (0a3ead4e-6d47-4ccb-854c-a6a4f9d96b22) |
Attack Pattern |
2 |
Email Addresses - T1589.002 (69f897fd-12a9-4c89-ad6a-46d2f3c38262) |
Attack Pattern |
Gather Victim Identity Information - T1589 (5282dd9a-d26d-4e16-88b7-7c0f4553daf4) |
Attack Pattern |
2 |
Cloud Groups - T1069.003 (16e94db9-b5b1-4cd0-b851-f38fbd0a70f2) |
Attack Pattern |
Permission Groups Discovery - T1069 (15dbf668-795c-41e6-8219-f0447c0e64ce) |
Attack Pattern |
2 |
Cloud Account - T1087.004 (8f104855-e5b7-4077-b1f5-bc3103b41abe) |
Attack Pattern |
Account Discovery - T1087 (72b74d71-8169-42aa-92e0-e7b04b9f5a08) |
Attack Pattern |
2 |
Unsecured Credentials - T1552 (435dfb86-2697-4867-85b5-2fef496c0517) |
Attack Pattern |
Credentials In Files - T1552.001 (837f9164-50af-4ac0-8219-379d8a74cefc) |
Attack Pattern |
2 |