ATT&CK Detection Rule Coverage
16127 detection rules mapped to 655 MITRE ATT&CK techniques and sub-techniques. Click a technique to see every rule written for it, grouped by vendor for easy comparison. Use the vendor chips to show or hide each rule source.
Execution 17
DLL (173) Dylib Hijacking (1) Executable Installer File Permissions Weakness (2) Dynamic Linker Hijacking (26) Path Interception by PATH Environment Variable (12) Path Interception by Search Order Hijacking (6) Path Interception by Unquoted Path (4) Services File Permissions Weakness (6) Services Registry Permissions Weakness (17) COR_PROFILER (2) KernelCallbackTable (2) AppDomainManager (1)
Discovery 33
Privilege Escalation 13
Registry Run Keys / Startup Folder (115) Authentication Package (9) Time Providers (3) Winlogon Helper DLL (9) Security Support Provider (8) Kernel Modules and Extensions (38) LSASS Driver (4) Shortcut Modification (15) Port Monitors (11) Print Processors (8) XDG Autostart Entries (5) Active Setup (4) Login Items (2)
Change Default File Association (8) Screensaver (9) Windows Management Instrumentation Event Subscription (24) Unix Shell Configuration Modification (17) Trap (1) Netsh Helper DLL (7) Accessibility Features (22) AppCert DLLs (6) AppInit DLLs (3) Application Shimming (11) Image File Execution Options Injection (12) PowerShell Profile (4) Emond (4) Component Object Model Hijacking (27) Installer Packages (15) Udev Rules (3) Python Startup Hooks (2)
Persistence 21
Registry Run Keys / Startup Folder (115) Authentication Package (9) Time Providers (3) Winlogon Helper DLL (9) Security Support Provider (8) Kernel Modules and Extensions (38) LSASS Driver (4) Shortcut Modification (15) Port Monitors (11) Print Processors (8) XDG Autostart Entries (5) Active Setup (4) Login Items (2)
Change Default File Association (8) Screensaver (9) Windows Management Instrumentation Event Subscription (24) Unix Shell Configuration Modification (17) Trap (1) Netsh Helper DLL (7) Accessibility Features (22) AppCert DLLs (6) AppInit DLLs (3) Application Shimming (11) Image File Execution Options Injection (12) PowerShell Profile (4) Emond (4) Component Object Model Hijacking (27) Installer Packages (15) Udev Rules (3) Python Startup Hooks (2)
Stealth 28
DLL (173) Dylib Hijacking (1) Executable Installer File Permissions Weakness (2) Dynamic Linker Hijacking (26) Path Interception by PATH Environment Variable (12) Path Interception by Search Order Hijacking (6) Path Interception by Unquoted Path (4) Services File Permissions Weakness (6) Services Registry Permissions Weakness (17) COR_PROFILER (2) KernelCallbackTable (2) AppDomainManager (1)
Collection 16
Impact 14
MITRE ATT&CK Mobile
Network Effects 0
No techniques tracked.
Remote Service Effects 0
No techniques tracked.