- T1546.004 .bash_profile and .bashrc
- Atomic Test #1: Add command to .bash_profile [macos, linux]
- Atomic Test #2: Add command to .bashrc [macos, linux]
- T1548 Abuse Elevation Control Mechanism CONTRIBUTE A TEST
- T1053.001 At (Linux)
- Atomic Test #1: At - Schedule a job [linux]
- T1547 Boot or Logon Autostart Execution CONTRIBUTE A TEST
- T1037 Boot or Logon Initialization Scripts CONTRIBUTE A TEST
- T1078.004 Cloud Accounts CONTRIBUTE A TEST
- T1543 Create or Modify System Process CONTRIBUTE A TEST
- T1053.003 Cron
- Atomic Test #1: Cron - Replace crontab with referenced file [macos, linux]
- Atomic Test #2: Cron - Add script to all cron subfolders [macos, linux]
- Atomic Test #3: Cron - Add script to /var/spool/cron/crontabs/ folder [linux]
- T1078.001 Default Accounts CONTRIBUTE A TEST
- T1078.002 Domain Accounts CONTRIBUTE A TEST
- T1546 Event Triggered Execution CONTRIBUTE A TEST
- T1068 Exploitation for Privilege Escalation CONTRIBUTE A TEST
- T1574 Hijack Execution Flow CONTRIBUTE A TEST
- T1547.006 Kernel Modules and Extensions
- Atomic Test #1: Linux - Load Kernel Module via insmod [linux]
- T1574.006 LD_PRELOAD
- Atomic Test #1: Shared Library Injection via /etc/ld.so.preload [linux]
- Atomic Test #2: Shared Library Injection via LD_PRELOAD [linux]
- T1078.003 Local Accounts CONTRIBUTE A TEST
- T1055.009 Proc Memory CONTRIBUTE A TEST
- T1055 Process Injection CONTRIBUTE A TEST
- T1055.008 Ptrace System Calls CONTRIBUTE A TEST
- T1053 Scheduled Task/Job CONTRIBUTE A TEST
- T1548.001 Setuid and Setgid
- Atomic Test #1: Make and modify binary from C source [macos, linux]
- Atomic Test #2: Set a SetUID flag on file [macos, linux]
- Atomic Test #3: Set a SetGID flag on file [macos, linux]
- T1548.003 Sudo and Sudo Caching
- Atomic Test #1: Sudo usage [macos, linux]
- Atomic Test #2: Unlimited sudo cache timeout [macos, linux]
- Atomic Test #3: Disable tty_tickets for sudo caching [macos, linux]
- T1543.002 Systemd Service
- Atomic Test #1: Create Systemd Service [linux]
- T1053.006 Systemd Timers CONTRIBUTE A TEST
- T1546.005 Trap
- Atomic Test #1: Trap [macos, linux]
- T1055.014 VDSO Hijacking CONTRIBUTE A TEST
- T1078 Valid Accounts CONTRIBUTE A TEST
- T1546.004 .bash_profile and .bashrc
- Atomic Test #1: Add command to .bash_profile [macos, linux]
- Atomic Test #2: Add command to .bashrc [macos, linux]
- T1098 Account Manipulation CONTRIBUTE A TEST
- T1098.003 Add Office 365 Global Administrator Role CONTRIBUTE A TEST
- T1137.006 Add-ins CONTRIBUTE A TEST
- T1098.001 Additional Cloud Credentials CONTRIBUTE A TEST
- T1053.001 At (Linux)
- Atomic Test #1: At - Schedule a job [linux]
- T1547 Boot or Logon Autostart Execution CONTRIBUTE A TEST
- T1037 Boot or Logon Initialization Scripts CONTRIBUTE A TEST
- T1542.003 Bootkit CONTRIBUTE A TEST
- T1176 Browser Extensions
- Atomic Test #1: Chrome (Developer Mode) [linux, windows, macos]
- Atomic Test #2: Chrome (Chrome Web Store) [linux, windows, macos]
- Atomic Test #3: Firefox [linux, windows, macos]
- T1136.003 Cloud Account CONTRIBUTE A TEST
- T1078.004 Cloud Accounts CONTRIBUTE A TEST
- T1554 Compromise Client Software Binary CONTRIBUTE A TEST
- T1136 Create Account CONTRIBUTE A TEST
- T1543 Create or Modify System Process CONTRIBUTE A TEST
- T1053.003 Cron
- Atomic Test #1: Cron - Replace crontab with referenced file [macos, linux]
- Atomic Test #2: Cron - Add script to all cron subfolders [macos, linux]
- Atomic Test #3: Cron - Add script to /var/spool/cron/crontabs/ folder [linux]
- T1078.001 Default Accounts CONTRIBUTE A TEST
- T1136.002 Domain Account CONTRIBUTE A TEST
- T1078.002 Domain Accounts CONTRIBUTE A TEST
- T1546 Event Triggered Execution CONTRIBUTE A TEST
- T1098.002 Exchange Email Delegate Permissions CONTRIBUTE A TEST
- T1133 External Remote Services CONTRIBUTE A TEST
- T1574 Hijack Execution Flow CONTRIBUTE A TEST
- T1525 Implant Container Image CONTRIBUTE A TEST
- T1547.006 Kernel Modules and Extensions
- Atomic Test #1: Linux - Load Kernel Module via insmod [linux]
- T1574.006 LD_PRELOAD
- Atomic Test #1: Shared Library Injection via /etc/ld.so.preload [linux]
- Atomic Test #2: Shared Library Injection via LD_PRELOAD [linux]
- T1136.001 Local Account
- Atomic Test #1: Create a user account on a Linux system [linux]
- Atomic Test #5: Create a new user in Linux with
root
UID and GID. [linux]
- T1078.003 Local Accounts CONTRIBUTE A TEST
- T1137 Office Application Startup CONTRIBUTE A TEST
- T1137.001 Office Template Macros CONTRIBUTE A TEST
- T1137.002 Office Test CONTRIBUTE A TEST
- T1137.003 Outlook Forms CONTRIBUTE A TEST
- T1137.004 Outlook Home Page CONTRIBUTE A TEST
- T1137.005 Outlook Rules CONTRIBUTE A TEST
- T1205.001 Port Knocking CONTRIBUTE A TEST
- T1542 Pre-OS Boot CONTRIBUTE A TEST
- T1542.004 ROMMONkit CONTRIBUTE A TEST
- T1108 Redundant Access CONTRIBUTE A TEST
- T1505.001 SQL Stored Procedures CONTRIBUTE A TEST
- T1098.004 SSH Authorized Keys
- Atomic Test #1: Modify SSH Authorized Keys [macos, linux]
- T1053 Scheduled Task/Job CONTRIBUTE A TEST
- T1505 Server Software Component CONTRIBUTE A TEST
- T1543.002 Systemd Service
- Atomic Test #1: Create Systemd Service [linux]
- T1053.006 Systemd Timers CONTRIBUTE A TEST
- T1542.005 TFTP Boot CONTRIBUTE A TEST
- T1205 Traffic Signaling CONTRIBUTE A TEST
- T1505.002 Transport Agent CONTRIBUTE A TEST
- T1546.005 Trap
- Atomic Test #1: Trap [macos, linux]
- T1078 Valid Accounts CONTRIBUTE A TEST
- T1505.003 Web Shell CONTRIBUTE A TEST
- T1003.008 /etc/passwd and /etc/shadow
- Atomic Test #1: Access /etc/shadow (Local) [linux]
- Atomic Test #2: Access /etc/passwd (Local) [linux]
- T1557.002 ARP Cache Poisoning CONTRIBUTE A TEST
- T1552.003 Bash History
- Atomic Test #1: Search Through Bash History [linux, macos]
- T1110 Brute Force CONTRIBUTE A TEST
- T1552.005 Cloud Instance Metadata API CONTRIBUTE A TEST
- T1110.004 Credential Stuffing CONTRIBUTE A TEST
- T1552.001 Credentials In Files
- Atomic Test #2: Extract passwords with grep [macos, linux]
- T1555 Credentials from Password Stores CONTRIBUTE A TEST
- T1555.003 Credentials from Web Browsers CONTRIBUTE A TEST
- T1212 Exploitation for Credential Access CONTRIBUTE A TEST
- T1056 Input Capture CONTRIBUTE A TEST
- T1056.001 Keylogging
- Atomic Test #2: Living off the land Terminal Input Capture on Linux with pam.d [linux]
- T1557 Man-in-the-Middle CONTRIBUTE A TEST
- T1556 Modify Authentication Process CONTRIBUTE A TEST
- T1556.004 Network Device Authentication CONTRIBUTE A TEST
- T1040 Network Sniffing
- Atomic Test #1: Packet Capture Linux [linux]
- T1003 OS Credential Dumping CONTRIBUTE A TEST
- T1110.002 Password Cracking CONTRIBUTE A TEST
- T1110.001 Password Guessing CONTRIBUTE A TEST
- T1110.003 Password Spraying CONTRIBUTE A TEST
- T1556.003 Pluggable Authentication Modules CONTRIBUTE A TEST
- T1552.004 Private Keys
- Atomic Test #2: Discover Private SSH Keys [macos, linux]
- Atomic Test #3: Copy Private SSH Keys with CP [linux]
- Atomic Test #4: Copy Private SSH Keys with rsync [macos, linux]
- T1003.007 Proc Filesystem CONTRIBUTE A TEST
- T1555.002 Securityd Memory CONTRIBUTE A TEST
- T1528 Steal Application Access Token CONTRIBUTE A TEST
- T1539 Steal Web Session Cookie CONTRIBUTE A TEST
- T1111 Two-Factor Authentication Interception CONTRIBUTE A TEST
- T1552 Unsecured Credentials CONTRIBUTE A TEST
- T1056.003 Web Portal Capture CONTRIBUTE A TEST
- T1557.002 ARP Cache Poisoning CONTRIBUTE A TEST
- T1560 Archive Collected Data CONTRIBUTE A TEST
- T1560.003 Archive via Custom Method CONTRIBUTE A TEST
- T1560.002 Archive via Library CONTRIBUTE A TEST
- T1560.001 Archive via Utility
- Atomic Test #5: Data Compressed - nix - zip [linux, macos]
- Atomic Test #6: Data Compressed - nix - gzip Single File [linux, macos]
- Atomic Test #7: Data Compressed - nix - tar Folder or File [linux, macos]
- Atomic Test #8: Data Encrypted with zip and gpg symmetric [macos, linux]
- T1123 Audio Capture CONTRIBUTE A TEST
- T1119 Automated Collection CONTRIBUTE A TEST
- T1115 Clipboard Data CONTRIBUTE A TEST
- T1213.001 Confluence CONTRIBUTE A TEST
- T1074 Data Staged CONTRIBUTE A TEST
- T1530 Data from Cloud Storage Object CONTRIBUTE A TEST
- T1602 Data from Configuration Repository CONTRIBUTE A TEST
- T1213 Data from Information Repositories CONTRIBUTE A TEST
- T1005 Data from Local System CONTRIBUTE A TEST
- T1039 Data from Network Shared Drive CONTRIBUTE A TEST
- T1025 Data from Removable Media CONTRIBUTE A TEST
- T1114 Email Collection CONTRIBUTE A TEST
- T1114.003 Email Forwarding Rule CONTRIBUTE A TEST
- T1056 Input Capture CONTRIBUTE A TEST
- T1056.001 Keylogging
- Atomic Test #2: Living off the land Terminal Input Capture on Linux with pam.d [linux]
- T1074.001 Local Data Staging
- Atomic Test #2: Stage data from Discovery.sh [linux, macos]
- T1557 Man-in-the-Middle CONTRIBUTE A TEST
- T1602.002 Network Device Configuration Dump CONTRIBUTE A TEST
- T1074.002 Remote Data Staging CONTRIBUTE A TEST
- T1114.002 Remote Email Collection CONTRIBUTE A TEST
- T1602.001 SNMP (MIB Dump) CONTRIBUTE A TEST
- T1113 Screen Capture
- Atomic Test #3: X Windows Capture [linux]
- Atomic Test #4: Capture Linux Desktop using Import Tool [linux]
- T1213.002 Sharepoint CONTRIBUTE A TEST
- T1056.003 Web Portal Capture CONTRIBUTE A TEST
- T1548 Abuse Elevation Control Mechanism CONTRIBUTE A TEST
- T1550.001 Application Access Token CONTRIBUTE A TEST
- T1027.001 Binary Padding
- Atomic Test #1: Pad Binary to Change Hash - Linux/macOS dd [macos, linux]
- T1542.003 Bootkit CONTRIBUTE A TEST
- T1070.003 Clear Command History
- Atomic Test #1: Clear Bash history (rm) [linux, macos]
- Atomic Test #2: Clear Bash history (echo) [linux, macos]
- Atomic Test #3: Clear Bash history (cat dev/null) [linux, macos]
- Atomic Test #4: Clear Bash history (ln dev/null) [linux, macos]
- Atomic Test #5: Clear Bash history (truncate) [linux]
- Atomic Test #6: Clear history of a bunch of shells [linux, macos]
- Atomic Test #7: Clear and Disable Bash History Logging [linux, macos]
- Atomic Test #8: Use Space Before Command to Avoid Logging to History [linux, macos]
- T1070.002 Clear Linux or Mac System Logs
- Atomic Test #1: rm -rf [macos, linux]
- Atomic Test #2: Overwrite Linux Mail Spool [linux]
- Atomic Test #3: Overwrite Linux Log [linux]
- T1078.004 Cloud Accounts CONTRIBUTE A TEST
- T1027.004 Compile After Delivery CONTRIBUTE A TEST
- T1578.002 Create Cloud Instance CONTRIBUTE A TEST
- T1578.001 Create Snapshot CONTRIBUTE A TEST
- T1078.001 Default Accounts CONTRIBUTE A TEST
- T1578.003 Delete Cloud Instance CONTRIBUTE A TEST
- T1140 Deobfuscate/Decode Files or Information CONTRIBUTE A TEST
- T1562.008 Disable Cloud Logs CONTRIBUTE A TEST
- T1600.002 Disable Crypto Hardware CONTRIBUTE A TEST
- T1562.007 Disable or Modify Cloud Firewall CONTRIBUTE A TEST
- T1562.004 Disable or Modify System Firewall
- Atomic Test #1: Disable iptables firewall [linux]
- T1562.001 Disable or Modify Tools
- Atomic Test #1: Disable syslog [linux]
- Atomic Test #2: Disable Cb Response [linux]
- Atomic Test #3: Disable SELinux [linux]
- Atomic Test #4: Stop Crowdstrike Falcon on Linux [linux]
- T1078.002 Domain Accounts CONTRIBUTE A TEST
- T1601.002 Downgrade System Image CONTRIBUTE A TEST
- T1480.001 Environmental Keying CONTRIBUTE A TEST
- T1480 Execution Guardrails CONTRIBUTE A TEST
- T1211 Exploitation for Defense Evasion CONTRIBUTE A TEST
- T1070.004 File Deletion
- Atomic Test #1: Delete a single file - Linux/macOS [linux, macos]
- Atomic Test #2: Delete an entire folder - Linux/macOS [linux, macos]
- Atomic Test #3: Overwrite and delete a file with shred [linux]
- Atomic Test #8: Delete Filesystem - Linux [linux]
- T1222 File and Directory Permissions Modification CONTRIBUTE A TEST
- T1564.005 Hidden File System CONTRIBUTE A TEST
- T1564.001 Hidden Files and Directories
- Atomic Test #1: Create a hidden file in a hidden directory [linux, macos]
- T1564 Hide Artifacts CONTRIBUTE A TEST
- T1574 Hijack Execution Flow CONTRIBUTE A TEST
- T1562.003 Impair Command History Logging
- Atomic Test #1: Disable history collection [linux, macos]
- Atomic Test #2: Mac HISTCONTROL [macos, linux]
- T1562 Impair Defenses CONTRIBUTE A TEST
- T1562.006 Indicator Blocking
- Atomic Test #1: Auditing Configuration Changes on Linux Host [linux]
- Atomic Test #2: Lgging Configuration Changes on Linux Host [linux]
- T1027.005 Indicator Removal from Tools CONTRIBUTE A TEST
- T1070 Indicator Removal on Host CONTRIBUTE A TEST
- T1553.004 Install Root Certificate
- Atomic Test #1: Install root CA on CentOS/RHEL [linux]
- Atomic Test #2: Install root CA on Debian/Ubuntu [linux]
- T1574.006 LD_PRELOAD
- Atomic Test #1: Shared Library Injection via /etc/ld.so.preload [linux]
- Atomic Test #2: Shared Library Injection via LD_PRELOAD [linux]
- T1222.002 Linux and Mac File and Directory Permissions Modification
- Atomic Test #1: chmod - Change file or folder mode (numeric mode) [macos, linux]
- Atomic Test #2: chmod - Change file or folder mode (symbolic mode) [macos, linux]
- Atomic Test #3: chmod - Change file or folder mode (numeric mode) recursively [macos, linux]
- Atomic Test #4: chmod - Change file or folder mode (symbolic mode) recursively [macos, linux]
- Atomic Test #5: chown - Change file or folder ownership and group [macos, linux]
- Atomic Test #6: chown - Change file or folder ownership and group recursively [macos, linux]
- Atomic Test #7: chown - Change file or folder mode ownership only [macos, linux]
- Atomic Test #8: chown - Change file or folder ownership recursively [macos, linux]
- Atomic Test #9: chattr - Remove immutable file attribute [macos, linux]
- T1078.003 Local Accounts CONTRIBUTE A TEST
- T1036.004 Masquerade Task or Service CONTRIBUTE A TEST
- T1036 Masquerading CONTRIBUTE A TEST
- T1036.005 Match Legitimate Name or Location CONTRIBUTE A TEST
- T1556 Modify Authentication Process CONTRIBUTE A TEST
- T1578 Modify Cloud Compute Infrastructure CONTRIBUTE A TEST
- T1601 Modify System Image CONTRIBUTE A TEST
- T1599.001 Network Address Translation Traversal CONTRIBUTE A TEST
- T1599 Network Boundary Bridging CONTRIBUTE A TEST
- T1556.004 Network Device Authentication CONTRIBUTE A TEST
- T1027 Obfuscated Files or Information
- Atomic Test #1: Decode base64 Data into Script [macos, linux]
- T1601.001 Patch System Image CONTRIBUTE A TEST
- T1556.003 Pluggable Authentication Modules CONTRIBUTE A TEST
- T1205.001 Port Knocking CONTRIBUTE A TEST
- T1542 Pre-OS Boot CONTRIBUTE A TEST
- T1055.009 Proc Memory CONTRIBUTE A TEST
- T1055 Process Injection CONTRIBUTE A TEST
- T1055.008 Ptrace System Calls CONTRIBUTE A TEST
- T1542.004 ROMMONkit CONTRIBUTE A TEST
- T1600.001 Reduce Key Space CONTRIBUTE A TEST
- T1108 Redundant Access CONTRIBUTE A TEST
- T1036.003 Rename System Utilities
- Atomic Test #2: Masquerading as Linux crond process. [linux]
- T1578.004 Revert Cloud Instance CONTRIBUTE A TEST
- T1036.002 Right-to-Left Override CONTRIBUTE A TEST
- T1014 Rootkit
- Atomic Test #1: Loadable Kernel Module based Rootkit [linux]
- Atomic Test #2: Loadable Kernel Module based Rootkit [linux]
- T1564.006 Run Virtual Instance CONTRIBUTE A TEST
- T1064 Scripting CONTRIBUTE A TEST
- T1548.001 Setuid and Setgid
- Atomic Test #1: Make and modify binary from C source [macos, linux]
- Atomic Test #2: Set a SetUID flag on file [macos, linux]
- Atomic Test #3: Set a SetGID flag on file [macos, linux]
- T1036.006 Space after Filename CONTRIBUTE A TEST
- T1027.003 Steganography CONTRIBUTE A TEST
- T1553 Subvert Trust Controls CONTRIBUTE A TEST
- T1548.003 Sudo and Sudo Caching
- Atomic Test #1: Sudo usage [macos, linux]
- Atomic Test #2: Unlimited sudo cache timeout [macos, linux]
- Atomic Test #3: Disable tty_tickets for sudo caching [macos, linux]
- T1497.001 System Checks
- Atomic Test #1: Detect Virtualization Environment (Linux) [linux]
- T1542.005 TFTP Boot CONTRIBUTE A TEST
- T1497.003 Time Based Evasion CONTRIBUTE A TEST
- T1070.006 Timestomp
- Atomic Test #1: Set a file's access timestamp [linux, macos]
- Atomic Test #2: Set a file's modification timestamp [linux, macos]
- Atomic Test #3: Set a file's creation timestamp [linux, macos]
- Atomic Test #4: Modify file timestamps using reference file [linux, macos]
- T1205 Traffic Signaling CONTRIBUTE A TEST
- T1535 Unused/Unsupported Cloud Regions CONTRIBUTE A TEST
- T1550 Use Alternate Authentication Material CONTRIBUTE A TEST
- T1497.002 User Activity Based Checks CONTRIBUTE A TEST
- T1564.007 VBA Stomping CONTRIBUTE A TEST
- T1055.014 VDSO Hijacking CONTRIBUTE A TEST
- T1078 Valid Accounts CONTRIBUTE A TEST
- T1497 Virtualization/Sandbox Evasion CONTRIBUTE A TEST
- T1600 Weaken Encryption CONTRIBUTE A TEST
- T1550.004 Web Session Cookie CONTRIBUTE A TEST
- T1531 Account Access Removal CONTRIBUTE A TEST
- T1499.003 Application Exhaustion Flood CONTRIBUTE A TEST
- T1499.004 Application or System Exploitation CONTRIBUTE A TEST
- T1485 Data Destruction
- Atomic Test #2: macOS/Linux - Overwrite file with DD [linux, macos]
- T1486 Data Encrypted for Impact CONTRIBUTE A TEST
- T1565 Data Manipulation CONTRIBUTE A TEST
- T1491 Defacement CONTRIBUTE A TEST
- T1498.001 Direct Network Flood CONTRIBUTE A TEST
- T1561.001 Disk Content Wipe CONTRIBUTE A TEST
- T1561.002 Disk Structure Wipe CONTRIBUTE A TEST
- T1561 Disk Wipe CONTRIBUTE A TEST
- T1499 Endpoint Denial of Service CONTRIBUTE A TEST
- T1491.002 External Defacement CONTRIBUTE A TEST
- T1495 Firmware Corruption CONTRIBUTE A TEST
- T1490 Inhibit System Recovery CONTRIBUTE A TEST
- T1491.001 Internal Defacement CONTRIBUTE A TEST
- T1498 Network Denial of Service CONTRIBUTE A TEST
- T1499.001 OS Exhaustion Flood CONTRIBUTE A TEST
- T1498.002 Reflection Amplification CONTRIBUTE A TEST
- T1496 Resource Hijacking
- Atomic Test #1: macOS/Linux - Simulate CPU Load with Yes [macos, linux]
- T1565.003 Runtime Data Manipulation CONTRIBUTE A TEST
- T1499.002 Service Exhaustion Flood CONTRIBUTE A TEST
- T1489 Service Stop CONTRIBUTE A TEST
- T1565.001 Stored Data Manipulation CONTRIBUTE A TEST
- T1529 System Shutdown/Reboot
- Atomic Test #3: Restart System via
shutdown
- macOS/Linux [macos, linux] - Atomic Test #4: Shutdown System via
shutdown
- macOS/Linux [macos, linux] - Atomic Test #5: Restart System via
reboot
- macOS/Linux [macos, linux] - Atomic Test #6: Shutdown System via
halt
- Linux [linux] - Atomic Test #7: Reboot System via
halt
- Linux [linux] - Atomic Test #8: Shutdown System via
poweroff
- Linux [linux] - Atomic Test #9: Reboot System via
poweroff
- Linux [linux]
- Atomic Test #3: Restart System via
- T1565.002 Transmitted Data Manipulation CONTRIBUTE A TEST
- T1087 Account Discovery CONTRIBUTE A TEST
- T1217 Browser Bookmark Discovery
- Atomic Test #1: List Mozilla Firefox Bookmark Database Files on Linux [linux]
- T1087.004 Cloud Account CONTRIBUTE A TEST
- T1069.003 Cloud Groups CONTRIBUTE A TEST
- T1580 Cloud Infrastructure Discovery CONTRIBUTE A TEST
- T1538 Cloud Service Dashboard CONTRIBUTE A TEST
- T1526 Cloud Service Discovery CONTRIBUTE A TEST
- T1087.002 Domain Account CONTRIBUTE A TEST
- T1069.002 Domain Groups CONTRIBUTE A TEST
- T1087.003 Email Account CONTRIBUTE A TEST
- T1083 File and Directory Discovery
- Atomic Test #3: Nix File and Diectory Discovery [macos, linux]
- Atomic Test #4: Nix File and Directory Discovery 2 [macos, linux]
- T1087.001 Local Account
- Atomic Test #1: Enumerate all accounts (Local) [linux]
- Atomic Test #2: View sudoers access [linux, macos]
- Atomic Test #3: View accounts with UID 0 [linux, macos]
- Atomic Test #4: List opened files by user [linux, macos]
- Atomic Test #5: Show if a user account has ever logged in remotely [linux]
- Atomic Test #6: Enumerate users and groups [linux, macos]
- T1069.001 Local Groups
- Atomic Test #1: Permission Groups Discovery (Local) [macos, linux]
- T1046 Network Service Scanning
- Atomic Test #1: Port Scan [linux, macos]
- Atomic Test #2: Port Scan Nmap [linux, macos]
- T1135 Network Share Discovery
- Atomic Test #1: Network Share Discovery [macos, linux]
- T1040 Network Sniffing
- Atomic Test #1: Packet Capture Linux [linux]
- T1201 Password Policy Discovery
- Atomic Test #1: Examine password complexity policy - Ubuntu [linux]
- Atomic Test #2: Examine password complexity policy - CentOS/RHEL 7.x [linux]
- Atomic Test #3: Examine password complexity policy - CentOS/RHEL 6.x [linux]
- Atomic Test #4: Examine password expiration policy - All Linux [linux]
- T1069 Permission Groups Discovery CONTRIBUTE A TEST
- T1057 Process Discovery
- Atomic Test #1: Process Discovery - ps [macos, linux]
- T1018 Remote System Discovery
- Atomic Test #6: Remote System Discovery - arp nix [linux, macos]
- Atomic Test #7: Remote System Discovery - sweep [linux, macos]
- T1518.001 Security Software Discovery
- Atomic Test #3: Security Software Discovery - ps [linux, macos]
- T1518 Software Discovery CONTRIBUTE A TEST
- T1497.001 System Checks
- Atomic Test #1: Detect Virtualization Environment (Linux) [linux]
- T1082 System Information Discovery
- Atomic Test #3: List OS Information [linux, macos]
- Atomic Test #4: Linux VM Check via Hardware [linux]
- Atomic Test #5: Linux VM Check via Kernel Modules [linux]
- Atomic Test #7: Hostname Discovery [linux, macos]
- T1016 System Network Configuration Discovery
- Atomic Test #3: System Network Configuration Discovery [macos, linux]
- T1049 System Network Connections Discovery
- Atomic Test #3: System Network Connections Discovery Linux & MacOS [linux, macos]
- T1033 System Owner/User Discovery
- Atomic Test #2: System Owner/User Discovery [linux, macos]
- T1497.003 Time Based Evasion CONTRIBUTE A TEST
- T1497.002 User Activity Based Checks CONTRIBUTE A TEST
- T1497 Virtualization/Sandbox Evasion CONTRIBUTE A TEST
- T1583 Acquire Infrastructure CONTRIBUTE A TEST
- T1583.005 Botnet CONTRIBUTE A TEST
- T1584.005 Botnet CONTRIBUTE A TEST
- T1587.002 Code Signing Certificates CONTRIBUTE A TEST
- T1588.003 Code Signing Certificates CONTRIBUTE A TEST
- T1586 Compromise Accounts CONTRIBUTE A TEST
- T1584 Compromise Infrastructure CONTRIBUTE A TEST
- T1583.002 DNS Server CONTRIBUTE A TEST
- T1584.002 DNS Server CONTRIBUTE A TEST
- T1587 Develop Capabilities CONTRIBUTE A TEST
- T1587.003 Digital Certificates CONTRIBUTE A TEST
- T1588.004 Digital Certificates CONTRIBUTE A TEST
- T1583.001 Domains CONTRIBUTE A TEST
- T1584.001 Domains CONTRIBUTE A TEST
- T1585.002 Email Accounts CONTRIBUTE A TEST
- T1586.002 Email Accounts CONTRIBUTE A TEST
- T1585 Establish Accounts CONTRIBUTE A TEST
- T1587.004 Exploits CONTRIBUTE A TEST
- T1588.005 Exploits CONTRIBUTE A TEST
- T1587.001 Malware CONTRIBUTE A TEST
- T1588.001 Malware CONTRIBUTE A TEST
- T1588 Obtain Capabilities CONTRIBUTE A TEST
- T1583.004 Server CONTRIBUTE A TEST
- T1584.004 Server CONTRIBUTE A TEST
- T1585.001 Social Media Accounts CONTRIBUTE A TEST
- T1586.001 Social Media Accounts CONTRIBUTE A TEST
- T1588.002 Tool CONTRIBUTE A TEST
- T1583.003 Virtual Private Server CONTRIBUTE A TEST
- T1584.003 Virtual Private Server CONTRIBUTE A TEST
- T1588.006 Vulnerabilities CONTRIBUTE A TEST
- T1583.006 Web Services CONTRIBUTE A TEST
- T1584.006 Web Services CONTRIBUTE A TEST
- T1595 Active Scanning CONTRIBUTE A TEST
- T1591.002 Business Relationships CONTRIBUTE A TEST
- T1596.004 CDNs CONTRIBUTE A TEST
- T1592.004 Client Configurations CONTRIBUTE A TEST
- T1589.001 Credentials CONTRIBUTE A TEST
- T1590.002 DNS CONTRIBUTE A TEST
- T1596.001 DNS/Passive DNS CONTRIBUTE A TEST
- T1591.001 Determine Physical Locations CONTRIBUTE A TEST
- T1596.003 Digital Certificates CONTRIBUTE A TEST
- T1590.001 Domain Properties CONTRIBUTE A TEST
- T1589.002 Email Addresses CONTRIBUTE A TEST
- T1589.003 Employee Names CONTRIBUTE A TEST
- T1592.003 Firmware CONTRIBUTE A TEST
- T1592 Gather Victim Host Information CONTRIBUTE A TEST
- T1589 Gather Victim Identity Information CONTRIBUTE A TEST
- T1590 Gather Victim Network Information CONTRIBUTE A TEST
- T1591 Gather Victim Org Information CONTRIBUTE A TEST
- T1592.001 Hardware CONTRIBUTE A TEST
- T1590.005 IP Addresses CONTRIBUTE A TEST
- T1591.003 Identify Business Tempo CONTRIBUTE A TEST
- T1591.004 Identify Roles CONTRIBUTE A TEST
- T1590.006 Network Security Appliances CONTRIBUTE A TEST
- T1590.004 Network Topology CONTRIBUTE A TEST
- T1590.003 Network Trust Dependencies CONTRIBUTE A TEST
- T1598 Phishing for Information CONTRIBUTE A TEST
- T1597.002 Purchase Technical Data CONTRIBUTE A TEST
- T1596.005 Scan Databases CONTRIBUTE A TEST
- T1595.001 Scanning IP Blocks CONTRIBUTE A TEST
- T1597 Search Closed Sources CONTRIBUTE A TEST
- T1593.002 Search Engines CONTRIBUTE A TEST
- T1596 Search Open Technical Databases CONTRIBUTE A TEST
- T1593 Search Open Websites/Domains CONTRIBUTE A TEST
- T1594 Search Victim-Owned Websites CONTRIBUTE A TEST
- T1593.001 Social Media CONTRIBUTE A TEST
- T1592.002 Software CONTRIBUTE A TEST
- T1598.002 Spearphishing Attachment CONTRIBUTE A TEST
- T1598.003 Spearphishing Link CONTRIBUTE A TEST
- T1598.001 Spearphishing Service CONTRIBUTE A TEST
- T1597.001 Threat Intel Vendors CONTRIBUTE A TEST
- T1595.002 Vulnerability Scanning CONTRIBUTE A TEST
- T1596.002 WHOIS CONTRIBUTE A TEST
- T1550.001 Application Access Token CONTRIBUTE A TEST
- T1210 Exploitation of Remote Services CONTRIBUTE A TEST
- T1534 Internal Spearphishing CONTRIBUTE A TEST
- T1570 Lateral Tool Transfer CONTRIBUTE A TEST
- T1563 Remote Service Session Hijacking CONTRIBUTE A TEST
- T1021 Remote Services CONTRIBUTE A TEST
- T1021.004 SSH CONTRIBUTE A TEST
- T1563.001 SSH Hijacking CONTRIBUTE A TEST
- T1072 Software Deployment Tools CONTRIBUTE A TEST
- T1550 Use Alternate Authentication Material CONTRIBUTE A TEST
- T1021.005 VNC CONTRIBUTE A TEST
- T1550.004 Web Session Cookie CONTRIBUTE A TEST
- T1071 Application Layer Protocol CONTRIBUTE A TEST
- T1573.002 Asymmetric Cryptography CONTRIBUTE A TEST
- T1102.002 Bidirectional Communication CONTRIBUTE A TEST
- T1043 Commonly Used Port CONTRIBUTE A TEST
- T1092 Communication Through Removable Media CONTRIBUTE A TEST
- T1071.004 DNS CONTRIBUTE A TEST
- T1568.003 DNS Calculation CONTRIBUTE A TEST
- T1132 Data Encoding CONTRIBUTE A TEST
- T1001 Data Obfuscation CONTRIBUTE A TEST
- T1102.001 Dead Drop Resolver CONTRIBUTE A TEST
- T1090.004 Domain Fronting CONTRIBUTE A TEST
- T1568.002 Domain Generation Algorithms CONTRIBUTE A TEST
- T1568 Dynamic Resolution CONTRIBUTE A TEST
- T1573 Encrypted Channel CONTRIBUTE A TEST
- T1090.002 External Proxy CONTRIBUTE A TEST
- T1008 Fallback Channels CONTRIBUTE A TEST
- T1568.001 Fast Flux DNS CONTRIBUTE A TEST
- T1071.002 File Transfer Protocols CONTRIBUTE A TEST
- T1105 Ingress Tool Transfer
- Atomic Test #1: rsync remote file copy (push) [linux, macos]
- Atomic Test #2: rsync remote file copy (pull) [linux, macos]
- Atomic Test #3: scp remote file copy (push) [linux, macos]
- Atomic Test #4: scp remote file copy (pull) [linux, macos]
- Atomic Test #5: sftp remote file copy (push) [linux, macos]
- Atomic Test #6: sftp remote file copy (pull) [linux, macos]
- T1090.001 Internal Proxy
- Atomic Test #1: Connection Proxy [macos, linux]
- T1001.001 Junk Data CONTRIBUTE A TEST
- T1071.003 Mail Protocols CONTRIBUTE A TEST
- T1104 Multi-Stage Channels CONTRIBUTE A TEST
- T1090.003 Multi-hop Proxy CONTRIBUTE A TEST
- T1026 Multiband Communication CONTRIBUTE A TEST
- T1095 Non-Application Layer Protocol CONTRIBUTE A TEST
- T1132.002 Non-Standard Encoding CONTRIBUTE A TEST
- T1571 Non-Standard Port
- Atomic Test #2: Testing usage of uncommonly used port [linux, macos]
- T1102.003 One-Way Communication CONTRIBUTE A TEST
- T1205.001 Port Knocking CONTRIBUTE A TEST
- T1001.003 Protocol Impersonation CONTRIBUTE A TEST
- T1572 Protocol Tunneling CONTRIBUTE A TEST
- T1090 Proxy CONTRIBUTE A TEST
- T1219 Remote Access Software CONTRIBUTE A TEST
- T1132.001 Standard Encoding
- Atomic Test #1: Base64 Encoded data. [macos, linux]
- T1001.002 Steganography CONTRIBUTE A TEST
- T1573.001 Symmetric Cryptography CONTRIBUTE A TEST
- T1205 Traffic Signaling CONTRIBUTE A TEST
- T1071.001 Web Protocols
- Atomic Test #3: Malicious User Agents - Nix [linux, macos]
- T1102 Web Service CONTRIBUTE A TEST
- T1053.001 At (Linux)
- Atomic Test #1: At - Schedule a job [linux]
- T1059 Command and Scripting Interpreter CONTRIBUTE A TEST
- T1053.003 Cron
- Atomic Test #1: Cron - Replace crontab with referenced file [macos, linux]
- Atomic Test #2: Cron - Add script to all cron subfolders [macos, linux]
- Atomic Test #3: Cron - Add script to /var/spool/cron/crontabs/ folder [linux]
- T1203 Exploitation for Client Execution CONTRIBUTE A TEST
- T1061 Graphical User Interface CONTRIBUTE A TEST
- T1059.007 JavaScript/JScript CONTRIBUTE A TEST
- T1204.002 Malicious File CONTRIBUTE A TEST
- T1204.001 Malicious Link CONTRIBUTE A TEST
- T1106 Native API CONTRIBUTE A TEST
- T1059.008 Network Device CLI CONTRIBUTE A TEST
- T1059.006 Python CONTRIBUTE A TEST
- T1053 Scheduled Task/Job CONTRIBUTE A TEST
- T1064 Scripting CONTRIBUTE A TEST
- T1072 Software Deployment Tools CONTRIBUTE A TEST
- T1153 Source CONTRIBUTE A TEST
- T1053.006 Systemd Timers CONTRIBUTE A TEST
- T1059.004 Unix Shell
- Atomic Test #1: Create and Execute Bash Shell Script [macos, linux]
- Atomic Test #2: Command-Line Interface [macos, linux]
- T1204 User Execution CONTRIBUTE A TEST
- T1059.005 Visual Basic CONTRIBUTE A TEST
- T1020 Automated Exfiltration CONTRIBUTE A TEST
- T1030 Data Transfer Size Limits
- Atomic Test #1: Data Transfer Size Limits [macos, linux]
- T1048 Exfiltration Over Alternative Protocol
- Atomic Test #1: Exfiltration Over Alternative Protocol - SSH [macos, linux]
- Atomic Test #2: Exfiltration Over Alternative Protocol - SSH [macos, linux]
- T1048.002 Exfiltration Over Asymmetric Encrypted Non-C2 Protocol CONTRIBUTE A TEST
- T1011.001 Exfiltration Over Bluetooth CONTRIBUTE A TEST
- T1041 Exfiltration Over C2 Channel CONTRIBUTE A TEST
- T1011 Exfiltration Over Other Network Medium CONTRIBUTE A TEST
- T1052 Exfiltration Over Physical Medium CONTRIBUTE A TEST
- T1048.001 Exfiltration Over Symmetric Encrypted Non-C2 Protocol CONTRIBUTE A TEST
- T1048.003 Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
- Atomic Test #1: Exfiltration Over Alternative Protocol - HTTP [macos, linux]
- Atomic Test #3: Exfiltration Over Alternative Protocol - DNS [linux]
- T1567 Exfiltration Over Web Service CONTRIBUTE A TEST
- T1052.001 Exfiltration over USB CONTRIBUTE A TEST
- T1567.002 Exfiltration to Cloud Storage CONTRIBUTE A TEST
- T1567.001 Exfiltration to Code Repository CONTRIBUTE A TEST
- T1029 Scheduled Transfer CONTRIBUTE A TEST
- T1020.001 Traffic Duplication CONTRIBUTE A TEST
- T1537 Transfer Data to Cloud Account CONTRIBUTE A TEST
- T1078.004 Cloud Accounts CONTRIBUTE A TEST
- T1195.003 Compromise Hardware Supply Chain CONTRIBUTE A TEST
- T1195.001 Compromise Software Dependencies and Development Tools CONTRIBUTE A TEST
- T1195.002 Compromise Software Supply Chain CONTRIBUTE A TEST
- T1078.001 Default Accounts CONTRIBUTE A TEST
- T1078.002 Domain Accounts CONTRIBUTE A TEST
- T1189 Drive-by Compromise CONTRIBUTE A TEST
- T1190 Exploit Public-Facing Application CONTRIBUTE A TEST
- T1133 External Remote Services CONTRIBUTE A TEST
- T1200 Hardware Additions CONTRIBUTE A TEST
- T1078.003 Local Accounts CONTRIBUTE A TEST
- T1566 Phishing CONTRIBUTE A TEST
- T1566.001 Spearphishing Attachment CONTRIBUTE A TEST
- T1566.002 Spearphishing Link CONTRIBUTE A TEST
- T1566.003 Spearphishing via Service CONTRIBUTE A TEST
- T1195 Supply Chain Compromise CONTRIBUTE A TEST
- T1199 Trusted Relationship CONTRIBUTE A TEST
- T1078 Valid Accounts CONTRIBUTE A TEST