An attacker sends a malicious email to trick a victim into clicking a link or opening an attachment.
What is Phishing?
The attacker is trying to gain their first foothold inside the victim's environment.
T1598
What is Phishing for Information?
I describe why an adversary is performing an action, such as Credential Access, Discovery, or Collection. What am I?
What is a Tactic?
An attacker tries many common passwords against accounts to gain access.
What is Brute Force?
The attacker attempts to remain hidden while conducting malicious activity in the environment.
T1078
What is Valid Accounts?
I describe how an adversary accomplishes an objective and normally start with the letter T followed by numbers.
What is a Technique?
An attacker creates a new account so they can maintain access to a compromised environment.
The attacker attempts to prevent security tools and defenders from detecting their activity.
T1667
An analyst maps malicious PowerShell activity to T1059.001. The “.001” tells you that PowerShell is this type of ATT&CK behavior.
What is a Sub-technique?
An attacker creates or modifies a scheduled task so that malicious code runs automatically.
The attacker gathers information such as files, emails, screenshots, or other data before stealing it.
T1686
An attacker dumps credentials from LSASS. Name both the tactic and sub-technique.
What are Credential Access + OS Credential Dumping: LSASS Memory (T1003.001)?
After compromising an employee account, an attacker successfully signs into the company's VPN using that employee's username and password.
An attacker researches a company's employees, domains, and internet-facing systems before attempting to compromise it.
T1621
An attacker uses stolen credentials to remotely access another system. This is tricky because T1078 (Valid Accounts) can be associated with multiple tactics. Name two ATT&CK tactics associated with Valid Accounts.
Any two applicable mappings, such as Initial Access, Persistence, Privilege Escalation, or Defense Evasion.