Name that Technique
Name that Tactic
Know your IDs
Mitre Mystery
100

An attacker sends a malicious email to trick a victim into clicking a link or opening an attachment.

What is Phishing?

100

The attacker is trying to gain their first foothold inside the victim's environment.

  • What is Initial Access?
100

T1598

What is Phishing for Information?

100

I describe why an adversary is performing an action, such as Credential Access, Discovery, or Collection. What am I?

What is a Tactic?

200

An attacker tries many common passwords against accounts to gain access.

What is Brute Force?

200

The attacker attempts to remain hidden while conducting malicious activity in the environment.

  • What is Stealth?
200

T1078

What is Valid Accounts?

200

I describe how an adversary accomplishes an objective and normally start with the letter T followed by numbers.

What is a Technique?

300

An attacker creates a new account so they can maintain access to a compromised environment.

  • What is Create Account?
300

The attacker attempts to prevent security tools and defenders from detecting their activity.

  • What is Defense Evasion
300

T1667

  • Email Bombing
300

An analyst maps malicious PowerShell activity to T1059.001. The “.001” tells you that PowerShell is this type of ATT&CK behavior.

What is a Sub-technique?

400

An attacker creates or modifies a scheduled task so that malicious code runs automatically.

  • What is Scheduled Task/Job?
400

The attacker gathers information such as files, emails, screenshots, or other data before stealing it.

  • What is Collection
400

T1686

  • Disable or Modify System Firewall
400

An attacker dumps credentials from LSASS. Name both the tactic and sub-technique.

What are Credential Access + OS Credential Dumping: LSASS Memory (T1003.001)?

500

After compromising an employee account, an attacker successfully signs into the company's VPN using that employee's username and password.

  • What is Valid Accounts
500

An attacker researches a company's employees, domains, and internet-facing systems before attempting to compromise it.

  • What is Reconnaissance?
500

T1621

  • Multi-Factor Authentication Request Generation
500

An attacker uses stolen credentials to remotely access another system. This is tricky because T1078 (Valid Accounts) can be associated with multiple tactics. Name two ATT&CK tactics associated with Valid Accounts.

Any two applicable mappings, such as Initial Access, Persistence, Privilege Escalation, or Defense Evasion.

M
e
n
u