NIST Special Publication 800-171 Revision 2

Date Published: January 28th, 2021

Withdrawn on May 14, 2024. Superseded by SP 800-171 Rev. 3

Author(s): Ron Ross (NIST), Victoria Pillitteri (NIST), Kelley Dempsey (NIST), Mark Riddle (NARA), Gary Guissanie (IDA)

Note: A Class Deviation is in effect as of May 2, 2024 (DEVIATION 2024O0013). The deviation clause requires contractors, who are subject to 252.204-7012, to comply with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-171 Revision 2, instead of the version of NIST SP 800-171 in effect at the time the solicitation is issued or as authorized by the contracting officer. Click Here

3.4.1 Establish and maintain baseline configurations and inventories of organizational systems (including hardware, software, firmware, and documentation) throughout the respective system development life cycles.

Control Family: Configuration Management

Control Type: Basic

SPRS Value: 5

SPRS Supplemental Guidance: N/A

CMMC Level(s):

CM.L2-3.4.1

DIBCAC HIGH Failure Rate (OTS):

10th of 110

Referenced in:

DFARS 252.204-7012

Derived From: NIST SP 800-53r4

  • CM-2

  • CM-6

  • CM-8

  • CM-8(1)

NIST Supplemental Guidance:

[SP 800-128]

CSF v1.1:

  • ID.AM-1

  • ID.AM-2

  • PR.DS-3

  • PR.IP-1

NIST SP 800-171r2 Control 3.4.1 → MITRE ATT&CK 14.1

NIST SP 800-171r2 Control 3.4.1 → MITRE ATT&CK 14.1

Mapping note: MITRE ATT&CK 14.1 techniques are derived through the NIST SP 800-53 Rev. 4 controls mapped to each NIST SP 800-171 Rev. 2 requirement.

Summary

  • Total mappings: 679
  • Families: 3
  • Outer ring: Technique ID + name
  • MITRE ATT&CK version: 14.1

Family counts

  • Baseline Configuration: 259 techniques
  • Configuration Settings: 326 techniques
  • Information System Component Inventory: 94 techniques

Usage notes

  • Click a family or technique to zoom in.
  • Click the center to zoom back out.
  • Hover to view technique details.

Discussion:

Baseline configurations are documented, formally reviewed, and agreed-upon specifications for systems or configuration items within those systems. Baseline configurations serve as a basis for future builds, releases, and changes to systems. Baseline configurations include information about system components (e.g., standard software packages installed on workstations, notebook computers, servers, network components, or mobile devices; current version numbers and update and patch information on operating systems and applications; and configuration settings and parameters), network topology, and the logical placement of those components within the system architecture. Baseline configurations of systems also reflect the current enterprise architecture. Maintaining effective baseline configurations requires creating new baselines as organizational systems change over time. Baseline configuration maintenance includes reviewing and updating the baseline configuration when changes are made based on security risks and deviations from the established baseline configuration

Organizations can implement centralized system component inventories that include components from multiple organizational systems. In such situations, organizations ensure that the resulting inventories include system-specific information required for proper component accountability (e.g., system association, system owner). Information deemed necessary for effective accountability of system components includes hardware inventory specifications, software license information, software version numbers, component owners, and for networked components or devices, machine names and network addresses. Inventory specifications include manufacturer, device type, model, serial number, and physical location.

[SP 800-128] provides guidance on security-focused configuration management.

Determining Statements (NIST SP 800-171Ar2)

3.4.1[a] a baseline configuration is established.
3.4.1[b] the baseline configuration includes hardware, software, firmware, and
documentation.
3.4.1[c] the baseline configuration is maintained (reviewed and updated) throughout
the system development life cycle.
3.4.1[d] a system inventory is established.
3.4.1[e] the system inventory includes hardware, software, firmware, and
documentation.
3.4.1[f] the inventory is maintained (reviewed and updated) throughout the system
development life cycle.

Assessors are instructed to-

Examine: [SELECT FROM: Configuration management policy; procedures addressing the baseline configuration of the system; procedures addressing system inventory; system security plan; configuration management plan; system inventory records; inventory review and update records; enterprise architecture documentation; system design documentation; system architecture and configuration documentation; system configuration settings and associated documentation; change control records; system component installation records; system component removal records; other relevant documents or records].

Interview: [SELECT FROM: Personnel with configuration management responsibilities; personnel with responsibilities for establishing the system inventory; personnel with responsibilities for updating the system inventory; personnel with information security responsibilities; system or network administrators].

Test: [SELECT FROM: Organizational processes for managing baseline configurations; mechanisms supporting configuration control of the baseline configuration; organizational processes for developing and documenting an inventory of system components; organizational processes for updating inventory of system components; mechanisms supporting or implementing the system inventory; mechanisms implementing updating of the system inventory].

FURTHER DISCUSSION

An effective cybersecurity program depends on consistent, secure system and component configuration and management. Build and configure systems from a known, secure, and approved configuration baseline. This includes:

  • documenting the software and configuration settings of a system;

  • placement within the network; and

  • other specifications as required by the organization.

Example

You are in charge of upgrading the computer operating systems of your office’s computers. Some of these computers process, store, or transmit CUI. You research how to set up and configure a workstation with the least functionality and highest security and use that as the framework for creating a configuration that minimizes functionality while still allowing users to do their tasks. After testing the new baseline on a single workstation, you document this configuration and apply it to the other computers [a]. You then check to make sure that the software changes are accurately reflected in your master system inventory [e]. Finally, you set a calendar reminder to review the baseline in three months [f].

Potential Assessment Considerations

  • Do baseline configurations include software versions and patch level, configuration parameters, network information, and communications with connected systems [a,b]?

  • Are baseline configurations updated as needed to accommodate security risks or software changes [c]?

ISO/IEC 27001:2013

A.8.1.1 Inventory of assets

A.8.1.2 Ownership of assets

NIST SP 800-171r2 Control 3.4.1 → MITRE ATT&CK
MITRE ATT&CK v14.1

NIST SP 800-171r2 Control 3.4.1 → MITRE ATT&CK

Total Mappings

679
technique references

Families

3
Baseline Configuration, Configuration Settings, Information System Component Inventory

Control

3.4.1
CM.L2-3.4.1

Baseline Configuration 259 techniques

  • T1001Data Obfuscation
  • T1001.001Junk Data
  • T1001.002Steganography
  • T1001.003Protocol Impersonation
  • T1003OS Credential Dumping
  • T1003.001LSASS Memory
  • T1003.002Security Account Manager
  • T1003.003NTDS
  • T1003.004LSA Secrets
  • T1003.005Cached Domain Credentials
  • T1003.006DCSync
  • T1003.007Proc Filesystem
  • T1003.008/etc/passwd and /etc/shadow
  • T1008Fallback Channels
  • T1011.001Exfiltration Over Bluetooth
  • T1020.001Traffic Duplication
  • T1021.001Remote Desktop Protocol
  • T1021.002SMB/Windows Admin Shares
  • T1021.003Distributed Component Object Model
  • T1021.004SSH
  • T1021.005VNC
  • T1021.006Windows Remote Management
  • T1027Obfuscated Files or Information
  • T1029Scheduled Transfer
  • T1030Data Transfer Size Limits
  • T1036Masquerading
  • T1036.001Invalid Code Signature
  • T1036.003Rename System Utilities
  • T1036.005Match Legitimate Name or Location
  • T1036.007Double File Extension
  • T1037Boot or Logon Initialization Scripts
  • T1037.002Logon Script (Mac)
  • T1037.003Network Logon Script
  • T1037.004RC Scripts
  • T1037.005Startup Items
  • T1046Network Service Scanning
  • T1047Windows Management Instrumentation
  • T1048Exfiltration Over Alternative Protocol
  • T1048.001Exfiltration Over Symmetric Encrypted Non-C2 Protocol
  • T1048.002Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
  • T1048.003Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • T1052Exfiltration Over Physical Medium
  • T1052.001Exfiltration over USB
  • T1053Scheduled Task/Job
  • T1053.002At (Windows)
  • T1053.005Scheduled Task
  • T1059Command and Scripting Interpreter
  • T1059.001PowerShell
  • T1059.002AppleScript
  • T1059.003Windows Command Shell
  • T1059.004Unix Shell
  • T1059.005Visual Basic
  • T1059.006Python
  • T1059.007JavaScript
  • T1059.008Network Device CLI
  • T1068Exploitation for Privilege Escalation
  • T1070Indicator Removal on Host
  • T1070.001Clear Windows Event Logs
  • T1070.002Clear Linux or Mac System Logs
  • T1070.003Clear Command History
  • T1070.007Clear Network Connection History and Configurations
  • T1070.008Clear Mailbox Data
  • T1070.009Clear Persistence
  • T1071Application Layer Protocol
  • T1071.001Web Protocols
  • T1071.002File Transfer Protocols
  • T1071.003Mail Protocols
  • T1071.004DNS
  • T1072Software Deployment Tools
  • T1080Taint Shared Content
  • T1090Proxy
  • T1090.001Internal Proxy
  • T1090.002External Proxy
  • T1091Replication Through Removable Media
  • T1092Communication Through Removable Media
  • T1095Non-Application Layer Protocol
  • T1098.004SSH Authorized Keys
  • T1102Web Service
  • T1102.001Dead Drop Resolver
  • T1102.002Bidirectional Communication
  • T1102.003One-Way Communication
  • T1104Multi-Stage Channels
  • T1105Ingress Tool Transfer
  • T1106Native API
  • T1110Brute Force
  • T1110.001Password Guessing
  • T1110.002Password Cracking
  • T1110.003Password Spraying
  • T1110.004Credential Stuffing
  • T1111Two-Factor Authentication Interception
  • T1114Email Collection
  • T1114.002Remote Email Collection
  • T1119Automated Collection
  • T1127Trusted Developer Utilities Proxy Execution
  • T1127.001MSBuild
  • T1129Shared Modules
  • T1132Data Encoding
  • T1132.001Standard Encoding
  • T1132.002Non-Standard Encoding
  • T1133External Remote Services
  • T1134.005SID-History Injection
  • T1137Office Application Startup
  • T1137.001Office Template Macros
  • T1137.002Office Test
  • T1137.003Outlook Forms
  • T1137.004Outlook Home Page
  • T1137.005Outlook Rules
  • T1137.006Add-ins
  • T1176Browser Extensions
  • T1185Browser Session Hijacking
  • T1187Forced Authentication
  • T1189Drive-by Compromise
  • T1201Password Policy Discovery
  • T1204User Execution
  • T1204.001Malicious Link
  • T1204.002Malicious File
  • T1204.003Malicious Image
  • T1205Traffic Signaling
  • T1210Exploitation of Remote Services
  • T1211Exploitation for Defense Evasion
  • T1212Exploitation for Credential Access
  • T1213Data from Information Repositories
  • T1213.001Confluence
  • T1213.002Sharepoint
  • T1216Signed Script Proxy Execution
  • T1216.001PubPrn
  • T1218Signed Binary Proxy Execution
  • T1218.001Compiled HTML File
  • T1218.002Control Panel
  • T1218.003CMSTP
  • T1218.004InstallUtil
  • T1218.005Mshta
  • T1218.007Msiexec
  • T1218.008Odbcconf
  • T1218.009Regsvcs/Regasm
  • T1218.012Verclsid
  • T1218.013Mavinject
  • T1218.014MMC
  • T1219Remote Access Software
  • T1220XSL Script Processing
  • T1221Template Injection
  • T1484Domain Policy Modification
  • T1485Data Destruction
  • T1486Data Encrypted for Impact
  • T1490Inhibit System Recovery
  • T1491Defacement
  • T1491.001Internal Defacement
  • T1491.002External Defacement
  • T1505Server Software Component
  • T1505.001SQL Stored Procedures
  • T1505.002Transport Agent
  • T1505.003Web Shell
  • T1505.004IIS Components
  • T1505.005Terminal Services DLL
  • T1525Implant Internal Image
  • T1528Steal Application Access Token
  • T1530Data from Cloud Storage Object
  • T1539Steal Web Session Cookie
  • T1542.004ROMMONkit
  • T1542.005TFTP Boot
  • T1543Create or Modify System Process
  • T1543.001Launch Agent
  • T1543.002Systemd Service
  • T1543.003Windows Service
  • T1543.004Launch Daemon
  • T1546Event Triggered Execution
  • T1546.002Screensaver
  • T1546.003Windows Management Instrumentation Event Subscription
  • T1546.004Unix Shell Configuration Modification
  • T1546.006LC_LOAD_DYLIB Addition
  • T1546.010AppInit DLLs
  • T1546.013PowerShell Profile
  • T1546.014Emond
  • T1547.003Time Providers
  • T1547.007Re-opened Applications
  • T1547.008LSASS Driver
  • T1547.013XDG Autostart Entries
  • T1548Abuse Elevation Control Mechanism
  • T1548.002Bypass User Account Control
  • T1548.003Sudo and Sudo Caching
  • T1548.004Elevated Execution with Prompt
  • T1550.001Application Access Token
  • T1550.003Pass the Ticket
  • T1552Unsecured Credentials
  • T1552.001Credentials In Files
  • T1552.004Private Keys
  • T1552.006Group Policy Preferences
  • T1553Subvert Trust Controls
  • T1553.001Gatekeeper Bypass
  • T1553.003SIP and Trust Provider Hijacking
  • T1553.005Mark-of-the-Web Bypass
  • T1554Compromise Client Software Binary
  • T1555.004Windows Credential Manager
  • T1555.005Password Managers
  • T1556Modify Authentication Process
  • T1556.004Network Device Authentication
  • T1557Adversary-in-the-Middle
  • T1557.001LLMNR/NBT-NS Poisoning and SMB Relay
  • T1557.002ARP Cache Poisoning
  • T1557.003DHCP Spoofing
  • T1558Steal or Forge Kerberos Tickets
  • T1558.001Golden Ticket
  • T1558.002Silver Ticket
  • T1558.003Kerberoasting
  • T1558.004AS-REP Roasting
  • T1559Inter-Process Communication
  • T1559.001Component Object Model
  • T1559.002Dynamic Data Exchange
  • T1561Disk Wipe
  • T1561.001Disk Content Wipe
  • T1561.002Disk Structure Wipe
  • T1562Impair Defenses
  • T1562.001Disable or Modify Tools
  • T1562.002Disable Windows Event Logging
  • T1562.003Impair Command History Logging
  • T1562.004Disable or Modify System Firewall
  • T1562.006Indicator Blocking
  • T1562.010Downgrade Attack
  • T1563Remote Service Session Hijacking
  • T1563.001SSH Hijacking
  • T1563.002RDP Hijacking
  • T1564.006Run Virtual Instance
  • T1564.007VBA Stomping
  • T1564.009Resource Forking
  • T1565Data Manipulation
  • T1565.001Stored Data Manipulation
  • T1565.002Transmitted Data Manipulation
  • T1566Phishing
  • T1566.001Spearphishing Attachment
  • T1566.002Spearphishing Link
  • T1569System Services
  • T1569.002Service Execution
  • T1570Lateral Tool Transfer
  • T1571Non-Standard Port
  • T1572Protocol Tunneling
  • T1573Encrypted Channel
  • T1573.001Symmetric Cryptography
  • T1573.002Asymmetric Cryptography
  • T1574Hijack Execution Flow
  • T1574.001DLL Search Order Hijacking
  • T1574.004Dylib Hijacking
  • T1574.005Executable Installer File Permissions Weakness
  • T1574.007Path Interception by PATH Environment Variable
  • T1574.008Path Interception by Search Order Hijacking
  • T1574.009Path Interception by Unquoted Path
  • T1574.010Services File Permissions Weakness
  • T1598Phishing for Information
  • T1598.002Spearphishing Attachment
  • T1598.003Spearphishing Link
  • T1599Network Boundary Bridging
  • T1599.001Network Address Translation Traversal
  • T1601Modify System Image
  • T1601.001Patch System Image
  • T1601.002Downgrade System Image
  • T1602Data from Configuration Repository
  • T1602.001SNMP (MIB Dump)
  • T1602.002Network Device Configuration Dump
  • T1622Debugger Evasion
  • T1647Plist File Modification

Configuration Settings 326 techniques

  • T1001Data Obfuscation
  • T1001.001Junk Data
  • T1001.002Steganography
  • T1001.003Protocol Impersonation
  • T1003OS Credential Dumping
  • T1003.001LSASS Memory
  • T1003.002Security Account Manager
  • T1003.003NTDS
  • T1003.004LSA Secrets
  • T1003.005Cached Domain Credentials
  • T1003.006DCSync
  • T1003.007Proc Filesystem
  • T1003.008/etc/passwd and /etc/shadow
  • T1008Fallback Channels
  • T1011Exfiltration Over Other Network Medium
  • T1011.001Exfiltration Over Bluetooth
  • T1020.001Traffic Duplication
  • T1021Remote Services
  • T1021.001Remote Desktop Protocol
  • T1021.002SMB/Windows Admin Shares
  • T1021.003Distributed Component Object Model
  • T1021.004SSH
  • T1021.005VNC
  • T1021.006Windows Remote Management
  • T1027Obfuscated Files or Information
  • T1029Scheduled Transfer
  • T1030Data Transfer Size Limits
  • T1036Masquerading
  • T1036.001Invalid Code Signature
  • T1036.003Rename System Utilities
  • T1036.005Match Legitimate Name or Location
  • T1036.007Double File Extension
  • T1037Boot or Logon Initialization Scripts
  • T1037.002Logon Script (Mac)
  • T1037.003Network Logon Script
  • T1037.004RC Scripts
  • T1037.005Startup Items
  • T1046Network Service Scanning
  • T1047Windows Management Instrumentation
  • T1048Exfiltration Over Alternative Protocol
  • T1048.001Exfiltration Over Symmetric Encrypted Non-C2 Protocol
  • T1048.002Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
  • T1048.003Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
  • T1052Exfiltration Over Physical Medium
  • T1052.001Exfiltration over USB
  • T1053Scheduled Task/Job
  • T1053.002At (Windows)
  • T1053.005Scheduled Task
  • T1053.006Systemd Timers
  • T1053.007Container Orchestration Job
  • T1055Process Injection
  • T1055.008Ptrace System Calls
  • T1056.003Web Portal Capture
  • T1059Command and Scripting Interpreter
  • T1059.001PowerShell
  • T1059.002AppleScript
  • T1059.003Windows Command Shell
  • T1059.004Unix Shell
  • T1059.005Visual Basic
  • T1059.006Python
  • T1059.007JavaScript
  • T1059.008Network Device CLI
  • T1068Exploitation for Privilege Escalation
  • T1070Indicator Removal on Host
  • T1070.001Clear Windows Event Logs
  • T1070.002Clear Linux or Mac System Logs
  • T1070.003Clear Command History
  • T1070.007Clear Network Connection History and Configurations
  • T1070.008Clear Mailbox Data
  • T1070.009Clear Persistence
  • T1071Application Layer Protocol
  • T1071.001Web Protocols
  • T1071.002File Transfer Protocols
  • T1071.003Mail Protocols
  • T1071.004DNS
  • T1072Software Deployment Tools
  • T1078Valid Accounts
  • T1078.002Domain Accounts
  • T1078.003Local Accounts
  • T1078.004Cloud Accounts
  • T1087Account Discovery
  • T1087.001Local Account
  • T1087.002Domain Account
  • T1090Proxy
  • T1090.001Internal Proxy
  • T1090.002External Proxy
  • T1090.003Multi-hop Proxy
  • T1091Replication Through Removable Media
  • T1092Communication Through Removable Media
  • T1095Non-Application Layer Protocol
  • T1098Account Manipulation
  • T1098.001Additional Cloud Credentials
  • T1098.002Exchange Email Delegate Permissions
  • T1098.003Add Office 365 Global Administrator Role
  • T1098.004SSH Authorized Keys
  • T1098.005Device Registration
  • T1102Web Service
  • T1102.001Dead Drop Resolver
  • T1102.002Bidirectional Communication
  • T1102.003One-Way Communication
  • T1104Multi-Stage Channels
  • T1105Ingress Tool Transfer
  • T1106Native API
  • T1110Brute Force
  • T1110.001Password Guessing
  • T1110.002Password Cracking
  • T1110.003Password Spraying
  • T1110.004Credential Stuffing
  • T1111Two-Factor Authentication Interception
  • T1114Email Collection
  • T1114.002Remote Email Collection
  • T1114.003Email Forwarding Rule
  • T1119Automated Collection
  • T1127Trusted Developer Utilities Proxy Execution
  • T1127.001MSBuild
  • T1132Data Encoding
  • T1132.001Standard Encoding
  • T1132.002Non-Standard Encoding
  • T1133External Remote Services
  • T1134Access Token Manipulation
  • T1134.001Token Impersonation/Theft
  • T1134.002Create Process with Token
  • T1134.003Make and Impersonate Token
  • T1134.005SID-History Injection
  • T1135Network Share Discovery
  • T1136Create Account
  • T1136.001Local Account
  • T1136.002Domain Account
  • T1136.003Cloud Account
  • T1137Office Application Startup
  • T1137.001Office Template Macros
  • T1137.002Office Test
  • T1137.003Outlook Forms
  • T1137.004Outlook Home Page
  • T1137.005Outlook Rules
  • T1137.006Add-ins
  • T1176Browser Extensions
  • T1187Forced Authentication
  • T1189Drive-by Compromise
  • T1190Exploit Public-Facing Application
  • T1197BITS Jobs
  • T1199Trusted Relationship
  • T1201Password Policy Discovery
  • T1204User Execution
  • T1204.001Malicious Link
  • T1204.002Malicious File
  • T1204.003Malicious Image
  • T1205Traffic Signaling
  • T1205.001Port Knocking
  • T1210Exploitation of Remote Services
  • T1211Exploitation for Defense Evasion
  • T1212Exploitation for Credential Access
  • T1213Data from Information Repositories
  • T1213.001Confluence
  • T1213.002Sharepoint
  • T1216Signed Script Proxy Execution
  • T1216.001PubPrn
  • T1218Signed Binary Proxy Execution
  • T1218.001Compiled HTML File
  • T1218.002Control Panel
  • T1218.003CMSTP
  • T1218.004InstallUtil
  • T1218.005Mshta
  • T1218.007Msiexec
  • T1218.008Odbcconf
  • T1218.009Regsvcs/Regasm
  • T1218.012Verclsid
  • T1218.013Mavinject
  • T1218.014MMC
  • T1219Remote Access Software
  • T1220XSL Script Processing
  • T1221Template Injection
  • T1222File and Directory Permissions Modification
  • T1222.001Windows File and Directory Permissions Modification
  • T1222.002Linux and Mac File and Directory Permissions Modification
  • T1482Domain Trust Discovery
  • T1484Domain Policy Modification
  • T1489Service Stop
  • T1490Inhibit System Recovery
  • T1495Firmware Corruption
  • T1498Network Denial of Service
  • T1498.001Direct Network Flood
  • T1498.002Reflection Amplification
  • T1499Endpoint Denial of Service
  • T1499.001OS Exhaustion Flood
  • T1499.002Service Exhaustion Flood
  • T1499.003Application Exhaustion Flood
  • T1499.004Application or System Exploitation
  • T1505Server Software Component
  • T1505.001SQL Stored Procedures
  • T1505.002Transport Agent
  • T1505.003Web Shell
  • T1505.004IIS Components
  • T1505.005Terminal Services DLL
  • T1525Implant Internal Image
  • T1528Steal Application Access Token
  • T1530Data from Cloud Storage Object
  • T1537Transfer Data to Cloud Account
  • T1539Steal Web Session Cookie
  • T1542Pre-OS Boot
  • T1542.001System Firmware
  • T1542.003Bootkit
  • T1542.004ROMMONkit
  • T1542.005TFTP Boot
  • T1543Create or Modify System Process
  • T1543.002Systemd Service
  • T1543.003Windows Service
  • T1543.004Launch Daemon
  • T1546Event Triggered Execution
  • T1546.002Screensaver
  • T1546.003Windows Management Instrumentation Event Subscription
  • T1546.004Unix Shell Configuration Modification
  • T1546.006LC_LOAD_DYLIB Addition
  • T1546.008Accessibility Features
  • T1546.013PowerShell Profile
  • T1546.014Emond
  • T1546.016Installer Packages
  • T1547.002Authentication Package
  • T1547.003Time Providers
  • T1547.005Security Support Provider
  • T1547.006Kernel Modules and Extensions
  • T1547.007Re-opened Applications
  • T1547.008LSASS Driver
  • T1547.013XDG Autostart Entries
  • T1548Abuse Elevation Control Mechanism
  • T1548.001Setuid and Setgid
  • T1548.002Bypass User Account Control
  • T1548.003Sudo and Sudo Caching
  • T1548.004Elevated Execution with Prompt
  • T1550Use Alternate Authentication Material
  • T1550.001Application Access Token
  • T1550.002Pass the Hash
  • T1550.003Pass the Ticket
  • T1552Unsecured Credentials
  • T1552.001Credentials In Files
  • T1552.002Credentials in Registry
  • T1552.003Bash History
  • T1552.004Private Keys
  • T1552.005Cloud Instance Metadata API
  • T1552.006Group Policy Preferences
  • T1552.007Container API
  • T1553Subvert Trust Controls
  • T1553.001Gatekeeper Bypass
  • T1553.003SIP and Trust Provider Hijacking
  • T1553.004Install Root Certificate
  • T1553.005Mark-of-the-Web Bypass
  • T1553.006Code Signing Policy Modification
  • T1554Compromise Client Software Binary
  • T1555.004Windows Credential Manager
  • T1555.005Password Managers
  • T1556Modify Authentication Process
  • T1556.001Domain Controller Authentication
  • T1556.002Password Filter DLL
  • T1556.003Pluggable Authentication Modules
  • T1556.004Network Device Authentication
  • T1557Adversary-in-the-Middle
  • T1557.001LLMNR/NBT-NS Poisoning and SMB Relay
  • T1557.002ARP Cache Poisoning
  • T1557.003DHCP Spoofing
  • T1558Steal or Forge Kerberos Tickets
  • T1558.001Golden Ticket
  • T1558.002Silver Ticket
  • T1558.003Kerberoasting
  • T1558.004AS-REP Roasting
  • T1559Inter-Process Communication
  • T1559.001Component Object Model
  • T1559.002Dynamic Data Exchange
  • T1559.003XPC Services
  • T1562Impair Defenses
  • T1562.001Disable or Modify Tools
  • T1562.002Disable Windows Event Logging
  • T1562.003Impair Command History Logging
  • T1562.004Disable or Modify System Firewall
  • T1562.006Indicator Blocking
  • T1562.009Safe Mode Boot
  • T1562.010Downgrade Attack
  • T1563Remote Service Session Hijacking
  • T1563.001SSH Hijacking
  • T1563.002RDP Hijacking
  • T1564.002Hidden Users
  • T1564.006Run Virtual Instance
  • T1564.007VBA Stomping
  • T1564.009Resource Forking
  • T1565Data Manipulation
  • T1565.001Stored Data Manipulation
  • T1565.002Transmitted Data Manipulation
  • T1565.003Runtime Data Manipulation
  • T1566Phishing
  • T1566.001Spearphishing Attachment
  • T1566.002Spearphishing Link
  • T1569System Services
  • T1569.002Service Execution
  • T1570Lateral Tool Transfer
  • T1571Non-Standard Port
  • T1572Protocol Tunneling
  • T1573Encrypted Channel
  • T1573.001Symmetric Cryptography
  • T1573.002Asymmetric Cryptography
  • T1574Hijack Execution Flow
  • T1574.001DLL Search Order Hijacking
  • T1574.004Dylib Hijacking
  • T1574.005Executable Installer File Permissions Weakness
  • T1574.006Dynamic Linker Hijacking
  • T1574.007Path Interception by PATH Environment Variable
  • T1574.008Path Interception by Search Order Hijacking
  • T1574.009Path Interception by Unquoted Path
  • T1574.010Services File Permissions Weakness
  • T1598Phishing for Information
  • T1598.002Spearphishing Attachment
  • T1598.003Spearphishing Link
  • T1599Network Boundary Bridging
  • T1599.001Network Address Translation Traversal
  • T1601Modify System Image
  • T1601.001Patch System Image
  • T1601.002Downgrade System Image
  • T1602Data from Configuration Repository
  • T1602.001SNMP (MIB Dump)
  • T1602.002Network Device Configuration Dump
  • T1609Container Administration Command
  • T1610Deploy Container
  • T1611Escape to Host
  • T1612Build Image on Host
  • T1613Container and Resource Discovery
  • T1622Debugger Evasion
  • T1647Plist File Modification
  • T1648Serverless Execution

Information System Component Inventory 94 techniques

  • T1011.001Exfiltration Over Bluetooth
  • T1020.001Traffic Duplication
  • T1021.001Remote Desktop Protocol
  • T1021.003Distributed Component Object Model
  • T1021.004SSH
  • T1021.005VNC
  • T1021.006Windows Remote Management
  • T1046Network Service Scanning
  • T1052Exfiltration Over Physical Medium
  • T1052.001Exfiltration over USB
  • T1053Scheduled Task/Job
  • T1053.002At (Windows)
  • T1053.005Scheduled Task
  • T1059Command and Scripting Interpreter
  • T1059.001PowerShell
  • T1059.005Visual Basic
  • T1059.007JavaScript
  • T1068Exploitation for Privilege Escalation
  • T1072Software Deployment Tools
  • T1091Replication Through Removable Media
  • T1092Communication Through Removable Media
  • T1098.004SSH Authorized Keys
  • T1119Automated Collection
  • T1127Trusted Developer Utilities Proxy Execution
  • T1127.001MSBuild
  • T1133External Remote Services
  • T1137Office Application Startup
  • T1137.001Office Template Macros
  • T1189Drive-by Compromise
  • T1190Exploit Public-Facing Application
  • T1195.003Compromise Hardware Supply Chain
  • T1203Exploitation for Client Execution
  • T1210Exploitation of Remote Services
  • T1211Exploitation for Defense Evasion
  • T1212Exploitation for Credential Access
  • T1213Data from Information Repositories
  • T1213.001Confluence
  • T1213.002Sharepoint
  • T1218Signed Binary Proxy Execution
  • T1218.003CMSTP
  • T1218.004InstallUtil
  • T1218.005Mshta
  • T1218.008Odbcconf
  • T1218.009Regsvcs/Regasm
  • T1218.012Verclsid
  • T1218.013Mavinject
  • T1218.014MMC
  • T1221Template Injection
  • T1495Firmware Corruption
  • T1505Server Software Component
  • T1505.001SQL Stored Procedures
  • T1505.002Transport Agent
  • T1505.004IIS Components
  • T1530Data from Cloud Storage Object
  • T1542Pre-OS Boot
  • T1542.001System Firmware
  • T1542.003Bootkit
  • T1542.004ROMMONkit
  • T1542.005TFTP Boot
  • T1546.002Screensaver
  • T1546.006LC_LOAD_DYLIB Addition
  • T1546.014Emond
  • T1547.007Re-opened Applications
  • T1548Abuse Elevation Control Mechanism
  • T1548.004Elevated Execution with Prompt
  • T1553Subvert Trust Controls
  • T1553.006Code Signing Policy Modification
  • T1557Adversary-in-the-Middle
  • T1557.001LLMNR/NBT-NS Poisoning and SMB Relay
  • T1557.002ARP Cache Poisoning
  • T1557.003DHCP Spoofing
  • T1559Inter-Process Communication
  • T1559.002Dynamic Data Exchange
  • T1563Remote Service Session Hijacking
  • T1563.001SSH Hijacking
  • T1563.002RDP Hijacking
  • T1564.006Run Virtual Instance
  • T1564.007VBA Stomping
  • T1565Data Manipulation
  • T1565.001Stored Data Manipulation
  • T1565.002Transmitted Data Manipulation
  • T1574Hijack Execution Flow
  • T1574.004Dylib Hijacking
  • T1574.007Path Interception by PATH Environment Variable
  • T1574.008Path Interception by Search Order Hijacking
  • T1574.009Path Interception by Unquoted Path
  • T1593.003Code Repositories
  • T1601Modify System Image
  • T1601.001Patch System Image
  • T1601.002Downgrade System Image
  • T1602Data from Configuration Repository
  • T1602.001SNMP (MIB Dump)
  • T1602.002Network Device Configuration Dump
  • T1622Debugger Evasion

Frameworks & Controls