| 1 | T1105 | Ingress Tool Transfer | Command & Control | 88 |
| 2 | T1204.002 | Malicious File | Execution | 86 |
| 3 | T1059.001 | PowerShell | Execution | 85 |
| 4 | T1588.002 | Tool | Resource Development | 82 |
| 5 | T1566.001 | Spearphishing Attachment | Initial Access | 78 |
| 6 | T1059.003 | Windows Command Shell | Execution | 73 |
| 7 | T1036.005 | Match Legitimate Resource Name or Location | Stealth | 63 |
| 8 | T1082 | System Information Discovery | Discovery | 58 |
| 9 | T1071.001 | Web Protocols | Command & Control | 57 |
| 10 | T1547.001 | Registry Run Keys / Startup Folder | PersistencePrivilege Escalation | 57 |
| 11 | T1053.005 | Scheduled Task | ExecutionPersistencePrivilege Escalation | 54 |
| 12 | T1083 | File and Directory Discovery | Discovery | 52 |
| 13 | T1204.001 | Malicious Link | Execution | 49 |
| 14 | T1070.004 | File Deletion | Stealth | 47 |
| 15 | T1078 | Valid Accounts | Initial AccessPersistencePrivilege EscalationStealth | 47 |
| 16 | T1059.005 | Visual Basic | Execution | 46 |
| 17 | T1583.001 | Domains | Resource Development | 46 |
| 18 | T1005 | Data from Local System | Collection | 46 |
| 19 | T1190 | Exploit Public-Facing Application | Initial Access | 46 |
| 20 | T1566.002 | Spearphishing Link | Initial Access | 46 |
| 21 | T1003.001 | LSASS Memory | Credential Access | 44 |
| 22 | T1016 | System Network Configuration Discovery | Discovery | 44 |
| 23 | T1047 | Windows Management Instrumentation | Execution | 42 |
| 24 | T1203 | Exploitation for Client Execution | Execution | 42 |
| 25 | T1057 | Process Discovery | Discovery | 41 |
| 26 | T1018 | Remote System Discovery | Discovery | 41 |
| 27 | T1033 | System Owner/User Discovery | Discovery | 40 |
| 28 | T1027.013 | Encrypted/Encoded File | Stealth | 40 |
| 29 | T1560.001 | Archive via Utility | Collection | 39 |
| 30 | T1140 | Deobfuscate/Decode Files or Information | Stealth | 38 |
| 31 | T1021.001 | Remote Desktop Protocol | Lateral Movement | 37 |
| 32 | T1574.001 | DLL | ExecutionStealth | 35 |
| 33 | T1049 | System Network Connections Discovery | Discovery | 32 |
| 34 | T1685 | Disable or Modify Tools | Defence Impairment | 32 |
| 35 | T1189 | Drive-by Compromise | Initial Access | 31 |
| 36 | T1505.003 | Web Shell | Persistence | 31 |
| 37 | T1046 | Network Service Discovery | Discovery | 31 |
| 38 | T1112 | Modify Registry | Defence ImpairmentPersistence | 29 |
| 39 | T1087.002 | Domain Account | Discovery | 29 |
| 40 | T1027.010 | Command Obfuscation | Stealth | 29 |
| 41 | T1074.001 | Local Data Staging | Collection | 28 |
| 42 | T1059.007 | JavaScript | Execution | 28 |
| 43 | T1608.001 | Upload Malware | Resource Development | 28 |
| 44 | T1553.002 | Code Signing | Defence Impairment | 28 |
| 45 | T1133 | External Remote Services | Initial AccessPersistence | 28 |
| 46 | T1518.001 | Security Software Discovery | Discovery | 27 |
| 47 | T1041 | Exfiltration Over C2 Channel | Exfiltration | 27 |
| 48 | T1021.002 | SMB/Windows Admin Shares | Lateral Movement | 27 |
| 49 | T1583.006 | Web Services | Resource Development | 27 |
| 50 | T1056.001 | Keylogging | CollectionCredential Access | 26 |
| 51 | T1543.003 | Windows Service | PersistencePrivilege Escalation | 26 |
| 52 | T1218.011 | Rundll32 | Stealth | 26 |
| 53 | T1587.001 | Malware | Resource Development | 26 |
| 54 | T1567.002 | Exfiltration to Cloud Storage | Exfiltration | 25 |
| 55 | T1027.002 | Software Packing | Stealth | 23 |
| 56 | T1555.003 | Credentials from Web Browsers | Credential Access | 23 |
| 57 | T1036.004 | Masquerade Task or Service | Stealth | 23 |
| 58 | T1068 | Exploitation for Privilege Escalation | Privilege Escalation | 22 |
| 59 | T1119 | Automated Collection | Collection | 21 |
| 60 | T1106 | Native API | Execution | 20 |
| 61 | T1078.002 | Domain Accounts | Initial AccessPersistencePrivilege EscalationStealth | 20 |
| 62 | T1585.002 | Email Accounts | Resource Development | 20 |
| 63 | T1036 | Masquerading | Stealth | 20 |
| 64 | T1486 | Data Encrypted for Impact | Impact | 19 |
| 65 | T1012 | Query Registry | Discovery | 19 |
| 66 | T1021.004 | SSH | Lateral Movement | 19 |
| 67 | T1570 | Lateral Tool Transfer | Lateral Movement | 19 |
| 68 | T1585.001 | Social Media Accounts | Resource Development | 19 |
| 69 | T1113 | Screen Capture | Collection | 19 |
| 70 | T1059.006 | Python | Execution | 19 |
| 71 | T1090 | Proxy | Command & Control | 19 |
| 72 | T1027 | Obfuscated Files or Information | Stealth | 18 |
| 73 | T1564.003 | Hidden Window | Stealth | 18 |
| 74 | T1087.001 | Local Account | Discovery | 18 |
| 75 | T1003.003 | NTDS | Credential Access | 18 |
| 76 | T1588.001 | Malware | Resource Development | 18 |
| 77 | T1218.005 | Mshta | Stealth | 17 |
| 78 | T1657 | Financial Theft | Impact | 17 |
| 79 | T1059 | Command and Scripting Interpreter | Execution | 17 |
| 80 | T1571 | Non-Standard Port | Command & Control | 17 |
| 81 | T1110 | Brute Force | Credential Access | 16 |
| 82 | T1135 | Network Share Discovery | Discovery | 16 |
| 83 | T1569.002 | Service Execution | Execution | 16 |
| 84 | T1583.003 | Virtual Private Server | Resource Development | 16 |
| 85 | T1684.001 | Impersonation | Stealth | 16 |
| 86 | T1102.002 | Bidirectional Communication | Command & Control | 16 |
| 87 | T1598.003 | Spearphishing Link | Reconnaissance | 16 |
| 88 | T1055 | Process Injection | Privilege EscalationStealth | 15 |
| 89 | T1007 | System Service Discovery | Discovery | 15 |
| 90 | T1552.001 | Credentials In Files | Credential Access | 15 |
| 91 | T1102 | Web Service | Command & Control | 15 |
| 92 | T1595.002 | Vulnerability Scanning | Reconnaissance | 15 |
| 93 | T1572 | Protocol Tunneling | Command & Control | 15 |
| 94 | T1685.005 | Clear Windows Event Logs | Defence Impairment | 14 |
| 95 | T1136.001 | Local Account | Persistence | 14 |
| 96 | T1003.002 | Security Account Manager | Credential Access | 14 |
| 97 | T1586.002 | Email Accounts | Resource Development | 14 |
| 98 | T1589.002 | Email Addresses | Reconnaissance | 14 |
| 99 | T1124 | System Time Discovery | Discovery | 14 |
| 100 | T1566.003 | Spearphishing via Service | Initial Access | 14 |
| 101 | T1573.001 | Symmetric Cryptography | Command & Control | 14 |
| 102 | T1686 | Disable or Modify System Firewall | Defence Impairment | 13 |
| 103 | T1560 | Archive Collected Data | Collection | 13 |
| 104 | T1219 | Remote Access Tools | Command & Control | 13 |
| 105 | T1003 | OS Credential Dumping | Credential Access | 13 |
| 106 | T1114.002 | Remote Email Collection | Collection | 13 |
| 107 | T1069.002 | Domain Groups | Discovery | 13 |
| 108 | T1564.001 | Hidden Files and Directories | Stealth | 13 |
| 109 | T1095 | Non-Application Layer Protocol | Command & Control | 12 |
| 110 | T1078.003 | Local Accounts | Initial AccessPersistencePrivilege EscalationStealth | 12 |
| 111 | T1555 | Credentials from Password Stores | Credential Access | 12 |
| 112 | T1090.003 | Multi-hop Proxy | Command & Control | 12 |
| 113 | T1210 | Exploitation of Remote Services | Lateral Movement | 12 |
| 114 | T1199 | Trusted Relationship | Initial Access | 12 |
| 115 | T1078.004 | Cloud Accounts | Initial AccessPersistencePrivilege EscalationStealth | 12 |
| 116 | T1573.002 | Asymmetric Cryptography | Command & Control | 12 |
| 117 | T1548.002 | Bypass User Account Control | Privilege Escalation | 11 |
| 118 | T1070.006 | Timestomp | Stealth | 11 |
| 119 | T1518 | Software Discovery | Discovery | 11 |
| 120 | T1090.002 | External Proxy | Command & Control | 11 |
| 121 | T1550.002 | Pass the Hash | Lateral Movement | 11 |
| 122 | T1219.002 | Remote Desktop Software | Command & Control | 11 |
| 123 | T1218.010 | Regsvr32 | Stealth | 11 |
| 124 | T1059.004 | Unix Shell | Execution | 11 |
| 125 | T1016.001 | Internet Connection Discovery | Discovery | 11 |
| 126 | T1132.001 | Standard Encoding | Command & Control | 11 |
| 127 | T1559.002 | Dynamic Data Exchange | Execution | 11 |
| 128 | T1071.004 | DNS | Command & Control | 11 |
| 129 | T1048.003 | Exfiltration Over Unencrypted Non-C2 Protocol | Exfiltration | 11 |
| 130 | T1074.002 | Remote Data Staging | Collection | 11 |
| 131 | T1110.003 | Password Spraying | Credential Access | 11 |
| 132 | T1584.004 | Server | Resource Development | 10 |
| 133 | T1482 | Domain Trust Discovery | Discovery | 10 |
| 134 | T1055.001 | Dynamic-link Library Injection | Privilege EscalationStealth | 10 |
| 135 | T1027.015 | Compression | Stealth | 10 |
| 136 | T1680 | Local Storage Discovery | Discovery | 10 |
| 137 | T1589 | Gather Victim Identity Information | Reconnaissance | 10 |
| 138 | T1003.004 | LSA Secrets | Credential Access | 10 |
| 139 | T1027.003 | Steganography | Stealth | 10 |
| 140 | T1546.003 | Windows Management Instrumentation Event Subscription | PersistencePrivilege Escalation | 10 |
| 141 | T1583 | Acquire Infrastructure | Resource Development | 9 |
| 142 | T1583.004 | Server | Resource Development | 9 |
| 143 | T1090.001 | Internal Proxy | Command & Control | 9 |
| 144 | T1120 | Peripheral Device Discovery | Discovery | 9 |
| 145 | T1195.002 | Compromise Software Supply Chain | Initial Access | 9 |
| 146 | T1485 | Data Destruction | Impact | 8 |
| 147 | T1055.012 | Process Hollowing | Privilege EscalationStealth | 8 |
| 148 | T1608.004 | Drive-by Target | Resource Development | 8 |
| 149 | T1566 | Phishing | Initial Access | 8 |
| 150 | T1040 | Network Sniffing | Credential AccessDiscovery | 8 |
| 151 | T1539 | Steal Web Session Cookie | Credential Access | 8 |
| 152 | T1568 | Dynamic Resolution | Command & Control | 8 |
| 153 | T1027.001 | Binary Padding | Stealth | 8 |
| 154 | T1070.003 | Clear Command History | Stealth | 8 |
| 155 | T1221 | Template Injection | Stealth | 8 |
| 156 | T1039 | Data from Network Shared Drive | Collection | 8 |
| 157 | T1072 | Software Deployment Tools | ExecutionLateral Movement | 8 |
| 158 | T1091 | Replication Through Removable Media | Initial AccessLateral Movement | 8 |
| 159 | T1114.001 | Local Email Collection | Collection | 8 |
| 160 | T1217 | Browser Information Discovery | Discovery | 7 |
| 161 | T1555.005 | Password Managers | Credential Access | 7 |
| 162 | T1489 | Service Stop | Impact | 7 |
| 163 | T1490 | Inhibit System Recovery | Impact | 7 |
| 164 | T1027.005 | Indicator Removal from Tools | Stealth | 7 |
| 165 | T1098.007 | Additional Local or Domain Groups | PersistencePrivilege Escalation | 7 |
| 166 | T1020 | Automated Exfiltration | Exfiltration | 7 |
| 167 | T1552.004 | Private Keys | Credential Access | 7 |
| 168 | T1591 | Gather Victim Org Information | Reconnaissance | 7 |
| 169 | T1560.003 | Archive via Custom Method | Collection | 7 |
| 170 | T1497.001 | System Checks | DiscoveryStealth | 7 |
| 171 | T1588.003 | Code Signing Certificates | Resource Development | 7 |
| 172 | T1069.001 | Local Groups | Discovery | 7 |
| 173 | T1213.002 | Sharepoint | Collection | 7 |
| 174 | T1588.004 | Digital Certificates | Resource Development | 7 |
| 175 | T1561.002 | Disk Structure Wipe | Impact | 6 |
| 176 | T1036.003 | Rename Legitimate Utilities | Stealth | 6 |
| 177 | T1218.007 | Msiexec | Stealth | 6 |
| 178 | T1584.001 | Domains | Resource Development | 6 |
| 179 | T1546.008 | Accessibility Features | PersistencePrivilege Escalation | 6 |
| 180 | T1069 | Permission Groups Discovery | Discovery | 6 |
| 181 | T1598 | Phishing for Information | Reconnaissance | 6 |
| 182 | T1534 | Internal Spearphishing | Lateral Movement | 6 |
| 183 | T1594 | Search Victim-Owned Websites | Reconnaissance | 6 |
| 184 | T1027.016 | Junk Code Insertion | Stealth | 6 |
| 185 | T1071.003 | Mail Protocols | Command & Control | 6 |
| 186 | T1102.001 | Dead Drop Resolver | Command & Control | 6 |
| 187 | T1593 | Search Open Websites/Domains | Reconnaissance | 6 |
| 188 | T1014 | Rootkit | Stealth | 6 |
| 189 | T1530 | Data from Cloud Storage | Collection | 6 |
| 190 | T1686.003 | Windows Host Firewall | Defence Impairment | 6 |
| 191 | T1589.001 | Credentials | Reconnaissance | 6 |
| 192 | T1218.001 | Compiled HTML File | Stealth | 5 |
| 193 | T1484.001 | Group Policy Modification | Defence ImpairmentPrivilege Escalation | 5 |
| 194 | T1614.001 | System Language Discovery | Discovery | 5 |
| 195 | T1136.002 | Domain Account | Persistence | 5 |
| 196 | T1567 | Exfiltration Over Web Service | Exfiltration | 5 |
| 197 | T1585 | Establish Accounts | Resource Development | 5 |
| 198 | T1114.003 | Email Forwarding Rule | Collection | 5 |
| 199 | T1071.002 | File Transfer Protocols | Command & Control | 5 |
| 200 | T1074 | Data Staged | Collection | 5 |
| 201 | T1584.005 | Botnet | Resource Development | 5 |
| 202 | T1654 | Log Enumeration | Discovery | 5 |
| 203 | T1197 | BITS Jobs | ExecutionPersistenceStealth | 5 |
| 204 | T1008 | Fallback Channels | Command & Control | 5 |
| 205 | T1030 | Data Transfer Size Limits | Exfiltration | 5 |
| 206 | T1098 | Account Manipulation | PersistencePrivilege Escalation | 5 |
| 207 | T1213.006 | Databases | Collection | 5 |
| 208 | T1080 | Taint Shared Content | Lateral Movement | 5 |
| 209 | T1071 | Application Layer Protocol | Command & Control | 5 |
| 210 | T1036.002 | Right-to-Left Override | Stealth | 5 |
| 211 | T1021.006 | Windows Remote Management | Lateral Movement | 5 |
| 212 | T1529 | System Shutdown/Reboot | Impact | 4 |
| 213 | T1690 | Prevent Command History Logging | Defence Impairment | 4 |
| 214 | T1115 | Clipboard Data | Collection | 4 |
| 215 | T1036.008 | Masquerade File Type | Stealth | 4 |
| 216 | T1491.001 | Internal Defacement | Impact | 4 |
| 217 | T1480 | Execution Guardrails | Stealth | 4 |
| 218 | T1598.002 | Spearphishing Attachment | Reconnaissance | 4 |
| 219 | T1104 | Multi-Stage Channels | Command & Control | 4 |
| 220 | T1110.002 | Password Cracking | Credential Access | 4 |
| 221 | T1036.010 | Masquerade Account Name | Stealth | 4 |
| 222 | T1021.005 | VNC | Lateral Movement | 4 |
| 223 | T1559.001 | Component Object Model | Execution | 4 |
| 224 | T1620 | Reflective Code Loading | Stealth | 4 |
| 225 | T1111 | Multi-Factor Authentication Interception | Credential Access | 4 |
| 226 | T1591.004 | Identify Roles | Reconnaissance | 4 |
| 227 | T1584.008 | Network Devices | Resource Development | 4 |
| 228 | T1587.004 | Exploits | Resource Development | 4 |
| 229 | T1590.004 | Network Topology | Reconnaissance | 4 |
| 230 | T1037 | Boot or Logon Initialization Scripts | PersistencePrivilege Escalation | 4 |
| 231 | T1496.001 | Compute Hijacking | Impact | 4 |
| 232 | T1213.003 | Code Repositories | Collection | 4 |
| 233 | T1685.006 | Clear Linux or Mac System Logs | Defence Impairment | 4 |
| 234 | T1547.009 | Shortcut Modification | PersistencePrivilege Escalation | 4 |
| 235 | T1593.003 | Code Repositories | Reconnaissance | 4 |
| 236 | T1550.001 | Application Access Token | Lateral Movement | 4 |
| 237 | T1027.004 | Compile After Delivery | Stealth | 4 |
| 238 | T1003.005 | Cached Domain Credentials | Credential Access | 4 |
| 239 | T1025 | Data from Removable Media | Collection | 4 |
| 240 | T1587.003 | Digital Certificates | Resource Development | 4 |
| 241 | T1048.002 | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol | Exfiltration | 4 |
| 242 | T1543.002 | Systemd Service | PersistencePrivilege Escalation | 4 |
| 243 | T1059.009 | Cloud API | Execution | 4 |
| 244 | T1125 | Video Capture | Collection | 4 |
| 245 | T1087.003 | Email Account | Discovery | 4 |
| 246 | T1584.006 | Web Services | Resource Development | 4 |
| 247 | T1070 | Indicator Removal | Stealth | 4 |
| 248 | T1003.006 | DCSync | Credential Access | 4 |
| 249 | T1114 | Email Collection | Collection | 4 |
| 250 | T1078.001 | Default Accounts | Initial AccessPersistencePrivilege EscalationStealth | 4 |
| 251 | T1555.004 | Windows Credential Manager | Credential Access | 4 |
| 252 | T1573 | Encrypted Channel | Command & Control | 4 |
| 253 | T1528 | Steal Application Access Token | Credential Access | 4 |
| 254 | T1553.005 | Mark-of-the-Web Bypass | Defence Impairment | 3 |
| 255 | T1053.003 | Cron | ExecutionPersistencePrivilege Escalation | 3 |
| 256 | T1136 | Create Account | Persistence | 3 |
| 257 | T1590 | Gather Victim Network Information | Reconnaissance | 3 |
| 258 | T1558.003 | Kerberoasting | Credential Access | 3 |
| 259 | T1204.004 | Malicious Copy and Paste | Execution | 3 |
| 260 | T1587 | Develop Capabilities | Resource Development | 3 |
| 261 | T1593.001 | Social Media | Reconnaissance | 3 |
| 262 | T1027.007 | Dynamic API Resolution | Stealth | 3 |
| 263 | T1589.003 | Employee Names | Reconnaissance | 3 |
| 264 | T1027.012 | LNK Icon Smuggling | Stealth | 3 |
| 265 | T1557 | Adversary-in-the-Middle | CollectionCredential Access | 3 |
| 266 | T1564.011 | Ignore Process Interrupts | Stealth | 3 |
| 267 | T1205 | Traffic Signaling | Command & ControlPersistenceStealth | 3 |
| 268 | T1027.009 | Embedded Payloads | Stealth | 3 |
| 269 | T1010 | Application Window Discovery | Discovery | 3 |
| 270 | T1588.006 | Vulnerabilities | Resource Development | 3 |
| 271 | T1587.002 | Code Signing Certificates | Resource Development | 3 |
| 272 | T1542.003 | Bootkit | PersistenceStealth | 3 |
| 273 | T1574.006 | Dynamic Linker Hijacking | ExecutionStealth | 3 |
| 274 | T1098.004 | SSH Authorized Keys | PersistencePrivilege Escalation | 3 |
| 275 | T1591.002 | Business Relationships | Reconnaissance | 3 |
| 276 | T1568.001 | Fast Flux DNS | Command & Control | 3 |
| 277 | T1552.002 | Credentials in Registry | Credential Access | 3 |
| 278 | T1222.002 | Linux and Mac Permissions | Defence Impairment | 3 |
| 279 | T1550.003 | Pass the Ticket | Lateral Movement | 3 |
| 280 | T1583.005 | Botnet | Resource Development | 3 |
| 281 | T1555.006 | Cloud Secrets Management Stores | Credential Access | 3 |
| 282 | T1590.005 | IP Addresses | Reconnaissance | 3 |
| 283 | T1556.002 | Password Filter DLL | Credential AccessDefence ImpairmentPersistence | 3 |
| 284 | T1134 | Access Token Manipulation | Privilege EscalationStealth | 3 |
| 285 | T1561.001 | Disk Content Wipe | Impact | 3 |
| 286 | T1056 | Input Capture | CollectionCredential Access | 3 |
| 287 | T1608.005 | Link Target | Resource Development | 3 |
| 288 | T1592.002 | Software | Reconnaissance | 3 |
| 289 | T1195 | Supply Chain Compromise | Initial Access | 3 |
| 290 | T1053.002 | At | ExecutionPersistencePrivilege Escalation | 3 |
| 291 | T1001.003 | Protocol or Service Impersonation | Command & Control | 3 |
| 292 | T1580 | Cloud Infrastructure Discovery | Discovery | 3 |
| 293 | T1087 | Account Discovery | Discovery | 3 |
| 294 | T1098.003 | Additional Cloud Roles | PersistencePrivilege Escalation | 3 |
| 295 | T1621 | Multi-Factor Authentication Request Generation | Credential Access | 3 |
| 296 | T1213.005 | Messaging Applications | Collection | 3 |
| 297 | T1021.007 | Cloud Services | Lateral Movement | 3 |
| 298 | T1037.004 | RC Scripts | PersistencePrivilege Escalation | 3 |
| 299 | T1497 | Virtualization/Sandbox Evasion | DiscoveryStealth | 3 |
| 300 | T1683.001 | Written Content | Resource Development | 3 |
| 301 | T1588.007 | Artificial Intelligence | Resource Development | 3 |
| 302 | T1201 | Password Policy Discovery | Discovery | 3 |
| 303 | T1547.004 | Winlogon Helper DLL | PersistencePrivilege Escalation | 3 |
| 304 | T1583.002 | DNS Server | Resource Development | 3 |
| 305 | T1021 | Remote Services | Lateral Movement | 3 |
| 306 | T1537 | Transfer Data to Cloud Account | Exfiltration | 3 |
| 307 | T1110.001 | Password Guessing | Credential Access | 3 |
| 308 | T1098.002 | Additional Email Delegate Permissions | PersistencePrivilege Escalation | 3 |
| 309 | T1560.002 | Archive via Library | Collection | 3 |
| 310 | T1480.002 | Mutual Exclusion | Stealth | 2 |
| 311 | T1134.003 | Make and Impersonate Token | Privilege EscalationStealth | 2 |
| 312 | T1614 | System Location Discovery | Discovery | 2 |
| 313 | T1678 | Delay Execution | Stealth | 2 |
| 314 | T1056.003 | Web Portal Capture | CollectionCredential Access | 2 |
| 315 | T1564.002 | Hidden Users | Stealth | 2 |
| 316 | T1596 | Search Open Technical Databases | Reconnaissance | 2 |
| 317 | T1588.005 | Exploits | Resource Development | 2 |
| 318 | T1682 | Query Public AI Services | Reconnaissance | 2 |
| 319 | T1036.007 | Double File Extension | Stealth | 2 |
| 320 | T1218 | System Binary Proxy Execution | Stealth | 2 |
| 321 | T1584.003 | Virtual Private Server | Resource Development | 2 |
| 322 | T1006 | Direct Volume Access | Stealth | 2 |
| 323 | T1596.005 | Scan Databases | Reconnaissance | 2 |
| 324 | T1070.007 | Clear Network Connection History and Configurations | Stealth | 2 |
| 325 | T1595.003 | Wordlist Scanning | Reconnaissance | 2 |
| 326 | T1480.001 | Environmental Keying | Stealth | 2 |
| 327 | T1568.002 | Domain Generation Algorithms | Command & Control | 2 |
| 328 | T1187 | Forced Authentication | Credential Access | 2 |
| 329 | T1055.002 | Portable Executable Injection | Privilege EscalationStealth | 2 |
| 330 | T1218.004 | InstallUtil | Stealth | 2 |
| 331 | T1027.011 | Fileless Storage | Stealth | 2 |
| 332 | T1137 | Office Application Startup | Persistence | 2 |
| 333 | T1218.003 | CMSTP | Stealth | 2 |
| 334 | T1564.005 | Hidden File System | Stealth | 2 |
| 335 | T1102.003 | One-Way Communication | Command & Control | 2 |
| 336 | T1222.001 | Windows Permissions | Defence Impairment | 2 |
| 337 | T1048 | Exfiltration Over Alternative Protocol | Exfiltration | 2 |
| 338 | T1059.013 | Container CLI/API | Execution | 2 |
| 339 | T1595.001 | Scanning IP Blocks | Reconnaissance | 2 |
| 340 | T1497.002 | User Activity Based Checks | DiscoveryStealth | 2 |
| 341 | T1586.001 | Social Media Accounts | Resource Development | 2 |
| 342 | T1491.002 | External Defacement | Impact | 2 |
| 343 | T1176.002 | IDE Extensions | Persistence | 2 |
| 344 | T1052.001 | Exfiltration over USB | Exfiltration | 2 |
| 345 | T1665 | Hide Infrastructure | Command & Control | 2 |
| 346 | T1556.009 | Conditional Access Policies | Credential AccessDefence ImpairmentPersistence | 2 |
| 347 | T1484.002 | Trust Modification | Defence ImpairmentPrivilege Escalation | 2 |
| 348 | T1204 | User Execution | Execution | 2 |
| 349 | T1598.004 | Spearphishing Voice | Reconnaissance | 2 |
| 350 | T1070.008 | Clear Mailbox Data | Stealth | 2 |
| 351 | T1578.002 | Create Cloud Instance | Defence Impairment | 2 |
| 352 | T1564.008 | Email Hiding Rules | Stealth | 2 |
| 353 | T1553.006 | Code Signing Policy Modification | Defence Impairment | 2 |
| 354 | T1681 | Search Threat Vendor Data | Reconnaissance | 2 |
| 355 | T1554 | Compromise Host Software Binary | Persistence | 2 |
| 356 | T1205.001 | Port Knocking | Command & ControlPersistenceStealth | 2 |
| 357 | T1683.002 | Audio-Visual Content | Resource Development | 2 |
| 358 | T1531 | Account Access Removal | Impact | 2 |
| 359 | T1036.001 | Invalid Code Signature | Stealth | 2 |
| 360 | T1123 | Audio Capture | Collection | 2 |
| 361 | T1220 | XSL Script Processing | Stealth | 2 |
| 362 | T1584.002 | DNS Server | Resource Development | 2 |
| 363 | T1134.002 | Create Process with Token | Privilege EscalationStealth | 2 |
| 364 | T1087.004 | Cloud Account | Discovery | 2 |
| 365 | T1578.003 | Delete Cloud Instance | Defence Impairment | 2 |
| 366 | T1056.002 | GUI Input Capture | CollectionCredential Access | 2 |
| 367 | T1202 | Indirect Command Execution | Stealth | 2 |
| 368 | T1136.003 | Cloud Account | Persistence | 2 |
| 369 | T1651 | Cloud Administration Command | Execution | 2 |
| 370 | T1586.003 | Cloud Accounts | Resource Development | 2 |
| 371 | T1110.004 | Credential Stuffing | Credential Access | 2 |
| 372 | T1557.002 | ARP Cache Poisoning | CollectionCredential Access | 2 |
| 373 | T1608.002 | Upload Tool | Resource Development | 2 |
| 374 | T1037.001 | Logon Script (Windows) | PersistencePrivilege Escalation | 2 |
| 375 | T1134.001 | Token Impersonation/Theft | Privilege EscalationStealth | 2 |
| 376 | T1211 | Exploitation for Stealth | Stealth | 2 |
| 377 | T1557.001 | Name Resolution Poisoning and SMB Relay | CollectionCredential Access | 2 |
| 378 | T1552.006 | Group Policy Preferences | Credential Access | 2 |
| 379 | T1685.001 | Disable or Modify Windows Event Log | Defence Impairment | 2 |
| 380 | T1195.001 | Compromise Software Dependencies and Development Tools | Initial Access | 2 |
| 381 | T1565.002 | Transmitted Data Manipulation | Impact | 1 |
| 382 | T1686.002 | Network Device Firewall | Defence Impairment | 1 |
| 383 | T1565.003 | Runtime Data Manipulation | Impact | 1 |
| 384 | T1565.001 | Stored Data Manipulation | Impact | 1 |
| 385 | T1036.006 | Space after Filename | Stealth | 1 |
| 386 | T1583.008 | Malvertising | Resource Development | 1 |
| 387 | T1608.006 | SEO Poisoning | Resource Development | 1 |
| 388 | T1176.001 | Browser Extensions | Persistence | 1 |
| 389 | T1185 | Browser Session Hijacking | Collection | 1 |
| 390 | T1546.001 | Change Default File Association | PersistencePrivilege Escalation | 1 |
| 391 | T1132.002 | Non-Standard Encoding | Command & Control | 1 |
| 392 | T1593.002 | Search Engines | Reconnaissance | 1 |
| 393 | T1597 | Search Closed Sources | Reconnaissance | 1 |
| 394 | T1592 | Gather Victim Host Information | Reconnaissance | 1 |
| 395 | T1552 | Unsecured Credentials | Credential Access | 1 |
| 396 | T1590.006 | Network Security Appliances | Reconnaissance | 1 |
| 397 | T1599 | Network Boundary Bridging | Defence Impairment | 1 |
| 398 | T1602.002 | Network Device Configuration Dump | Collection | 1 |
| 399 | T1564.004 | NTFS File Attributes | Stealth | 1 |
| 400 | T1216.001 | PubPrn | Stealth | 1 |
| 401 | T1592.004 | Client Configurations | Reconnaissance | 1 |
| 402 | T1137.001 | Office Template Macros | Persistence | 1 |
| 403 | T1137.006 | Add-ins | Persistence | 1 |
| 404 | T1001 | Data Obfuscation | Command & Control | 1 |
| 405 | T1585.003 | Cloud Accounts | Resource Development | 1 |
| 406 | T1667 | Email Bombing | Impact | 1 |
| 407 | T1566.004 | Spearphishing Voice | Initial Access | 1 |
| 408 | T1055.013 | Process Doppelgänging | Privilege EscalationStealth | 1 |
| 409 | T1569.003 | Systemctl | Execution | 1 |
| 410 | T1609 | Container Administration Command | Execution | 1 |
| 411 | T1613 | Container and Resource Discovery | Discovery | 1 |
| 412 | T1552.005 | Cloud Instance Metadata API | Credential Access | 1 |
| 413 | T1204.003 | Malicious Image | Execution | 1 |
| 414 | T1611 | Escape to Host | Privilege Escalation | 1 |
| 415 | T1610 | Deploy Container | Execution | 1 |
| 416 | T1546.011 | Application Shimming | PersistencePrivilege Escalation | 1 |
| 417 | T1674 | Input Injection | Execution | 1 |
| 418 | T1590.001 | Domain Properties | Reconnaissance | 1 |
| 419 | T1499 | Endpoint Denial of Service | Impact | 1 |
| 420 | T1219.001 | IDE Tunneling | Command & Control | 1 |
| 421 | T1129 | Shared Modules | Execution | 1 |
| 422 | T1574.005 | Executable Installer File Permissions Weakness | ExecutionStealth | 1 |
| 423 | T1608 | Stage Capabilities | Resource Development | 1 |
| 424 | T1622 | Debugger Evasion | DiscoveryStealth | 1 |
| 425 | T1538 | Cloud Service Dashboard | Discovery | 1 |
| 426 | T1556.006 | Multi-Factor Authentication | Credential AccessDefence ImpairmentPersistence | 1 |
| 427 | T1546.010 | AppInit DLLs | PersistencePrivilege Escalation | 1 |
| 428 | T1059.010 | AutoHotKey & AutoIT | Execution | 1 |
| 429 | T1059.012 | Hypervisor CLI | Execution | 1 |
| 430 | T1673 | Virtual Machine Discovery | Discovery | 1 |
| 431 | T1212 | Exploitation for Credential Access | Credential Access | 1 |
| 432 | T1675 | ESXi Administration Command | Execution | 1 |
| 433 | T1548 | Abuse Elevation Control Mechanism | Privilege Escalation | 1 |
| 434 | T1505.006 | vSphere Installation Bundles | Persistence | 1 |
| 435 | T1555.001 | Keychain | Credential Access | 1 |
| 436 | T1204.005 | Malicious Library | Execution | 1 |
| 437 | T1546.004 | Unix Shell Configuration Modification | PersistencePrivilege Escalation | 1 |
| 438 | T1547.013 | XDG Autostart Entries | PersistencePrivilege Escalation | 1 |
| 439 | T1543.001 | Launch Agent | PersistencePrivilege Escalation | 1 |
| 440 | T1558 | Steal or Forge Kerberos Tickets | Credential Access | 1 |
| 441 | T1137.004 | Outlook Home Page | Persistence | 1 |
| 442 | T1029 | Scheduled Transfer | Exfiltration | 1 |
| 443 | T1608.003 | Install Digital Certificate | Resource Development | 1 |
| 444 | T1558.001 | Golden Ticket | Credential Access | 1 |
| 445 | T1659 | Content Injection | Command & ControlInitial Access | 1 |
| 446 | T1574.012 | COR_PROFILER | ExecutionStealth | 1 |
| 447 | T1546.013 | PowerShell Profile | PersistencePrivilege Escalation | 1 |
| 448 | T1615 | Group Policy Discovery | Discovery | 1 |
| 449 | T1564.012 | File/Path Exclusions | Stealth | 1 |
| 450 | T1526 | Cloud Service Discovery | Discovery | 1 |
| 451 | T1098.001 | Additional Cloud Credentials | PersistencePrivilege Escalation | 1 |
| 452 | T1200 | Hardware Additions | Initial Access | 1 |
| 453 | T1090.004 | Domain Fronting | Command & Control | 1 |
| 454 | T1098.005 | Device Registration | PersistencePrivilege Escalation | 1 |
| 455 | T1027.006 | HTML Smuggling | Stealth | 1 |
| 456 | T1556.007 | Hybrid Identity | Credential AccessDefence ImpairmentPersistence | 1 |
| 457 | T1685.002 | Disable or Modify Cloud Log | Defence Impairment | 1 |
| 458 | T1649 | Steal or Forge Authentication Certificates | Credential Access | 1 |
| 459 | T1556.001 | Domain Controller Authentication | Credential AccessDefence ImpairmentPersistence | 1 |
| 460 | T1650 | Acquire Access | Resource Development | 1 |
| 461 | T1218.014 | MMC | Stealth | 1 |
| 462 | T1652 | Device Driver Discovery | Discovery | 1 |
| 463 | T1542.002 | Component Firmware | PersistenceStealth | 1 |
| 464 | T1550.004 | Web Session Cookie | Lateral Movement | 1 |
| 465 | T1553 | Subvert Trust Controls | Defence Impairment | 1 |
| 466 | T1563.002 | RDP Hijacking | Lateral Movement | 1 |
| 467 | T1001.002 | Steganography | Command & Control | 1 |
| 468 | T1669 | Wi-Fi Networks | Initial Access | 1 |
| 469 | T1546.015 | Component Object Model Hijacking | PersistencePrivilege Escalation | 1 |
| 470 | T1557.004 | Evil Twin | CollectionCredential Access | 1 |
| 471 | T1498 | Network Denial of Service | Impact | 1 |
| 472 | T1213 | Data from Information Repositories | Collection | 1 |
| 473 | T1092 | Communication Through Removable Media | Command & Control | 1 |
| 474 | T1137.002 | Office Test | Persistence | 1 |
| 475 | T1001.001 | Junk Data | Command & Control | 1 |
| 476 | T1547 | Boot or Logon Autostart Execution | PersistencePrivilege Escalation | 1 |
| 477 | T1568.003 | DNS Calculation | Command & Control | 1 |
| 478 | T1574.013 | KernelCallbackTable | ExecutionStealth | 1 |
| 479 | T1547.012 | Print Processors | PersistencePrivilege Escalation | 1 |
| 480 | T1213.001 | Confluence | Collection | 1 |
| 481 | T1552.008 | Chat Messages | Credential Access | 1 |
| 482 | T1597.002 | Purchase Technical Data | Reconnaissance | 1 |
| 483 | T1218.008 | Odbcconf | Stealth | 1 |
| 484 | T1518.002 | Backup Software Discovery | Discovery | 1 |
| 485 | T1132 | Data Encoding | Command & Control | 1 |
| 486 | T1679 | Selective Exclusion | Stealth | 1 |
| 487 | T1056.004 | Credential API Hooking | CollectionCredential Access | 1 |
| 488 | T1016.002 | Wi-Fi Discovery | Discovery | 1 |
| 489 | T1591.001 | Determine Physical Locations | Reconnaissance | 1 |
| 490 | T1070.005 | Network Share Connection Removal | Stealth | 1 |
| 491 | T1055.004 | Asynchronous Procedure Call | Privilege EscalationStealth | 1 |
| 492 | T1565 | Data Manipulation | Impact | 1 |
| 493 | T1556 | Modify Authentication Process | Credential AccessDefence ImpairmentPersistence | 1 |
| 494 | T1546.016 | Installer Packages | PersistencePrivilege Escalation | 1 |
| 495 | T1677 | Poisoned Pipeline Execution | Execution | 1 |
| 496 | T1684 | Social Engineering | Stealth | 1 |
| 497 | T1619 | Cloud Storage Object Discovery | Discovery | 1 |
| 498 | T1069.003 | Cloud Groups | Discovery | 1 |