Technique List

Technique Name Technique ID's Categories Has Snippet(s) Has Rules(s) Creation Date
Deobfuscate/Decode Files or Information T1140 Defense Evasion [Mitre] 1 month, 3 weeks
Debugger Evasion T1622 Defense Evasion [Mitre] 1 month, 3 weeks
BITS Jobs T1197 Defense Evasion [Mitre] 1 month, 3 weeks
Hijack Execution Flow: KernelCallbackTable T1574.013 Defense Evasion [Mitre] 1 month, 3 weeks
Hijack Execution Flow: COR_PROFILER T1574.012 Defense Evasion [Mitre] 1 month, 3 weeks
Hijack Execution Flow: Services Registry Permissions Weakness T1574.011 Defense Evasion [Mitre] 1 month, 3 weeks
Hijack Execution Flow: Services File Permissions Weakness T1574.010 Defense Evasion [Mitre] 1 month, 3 weeks
Hijack Execution Flow: Path Interception by Unquoted Path T1574.009 Defense Evasion [Mitre] 1 month, 3 weeks
Hijack Execution Flow: Path Interception by Search Order Hijacking T1574.008 Defense Evasion [Mitre] 1 month, 3 weeks
Hijack Execution Flow: Path Interception by PATH Environment Variable T1574.007 Defense Evasion [Mitre] 1 month, 3 weeks
Hijack Execution Flow: Executable Installer File Permissions Weakness T1574.005 Defense Evasion [Mitre] 1 month, 3 weeks
Hijack Execution Flow: DLL Side-Loading T1574.002 Defense Evasion [Mitre] 1 month, 3 weeks
Hide Artifacts: Process Argument Spoofing T1564.010 Defense Evasion [Mitre] 1 month, 3 weeks
Hide Artifacts: Email Hiding Rules T1564.008 Defense Evasion [Mitre] 1 month, 3 weeks
Hide Artifacts: VBA Stomping T1564.007 Defense Evasion [Mitre] 1 month, 3 weeks
Hide Artifacts: Run Virtual Instance T1564.006 Defense Evasion [Mitre] 1 month, 3 weeks
Hide Artifacts: Hidden File System T1564.005 Defense Evasion [Mitre] 1 month, 3 weeks
Hide Artifacts: NTFS File Attributes T1564.004 Defense Evasion [Mitre] 1 month, 3 weeks
Hide Artifacts: Hidden Window T1564.003 Defense Evasion [Mitre] 1 month, 3 weeks
Hide Artifacts: Hidden Users T1564.002 Defense Evasion [Mitre] 1 month, 3 weeks
Hide Artifacts: Hidden Files and Directories T1564.001 Defense Evasion [Mitre] 1 month, 3 weeks
Windows File and Directory Permissions Modification T1222.001 Defense Evasion [Mitre] 1 month, 3 weeks
Domain Member U1341 Sandbox Evasion 1 month, 3 weeks
CPU Counting U1340 Sandbox Evasion 1 month, 3 weeks
Return Address Spoofing U0518 Antivirus/EDR Evasion 1 month, 3 weeks
Avoiding Memory Scanners (Yara, Pe-sieve...) U1009 Others 1 month, 3 weeks
Domain Policy Modification: Domain Trust Modification T1484.002 Defense Evasion [Mitre] 1 month, 4 weeks
Domain Policy Modification: Group Policy Modification T1484.001 Defense Evasion [Mitre] 1 month, 4 weeks
Access Token Manipulation: SID-History Injection T1134.005 Defense Evasion [Mitre] 1 month, 4 weeks
Access Token Manipulation: Make and Impersonate Token T1134.003 Defense Evasion [Mitre] 1 month, 4 weeks

Filter