Attack Patterns
Use this page to search and filter attack patterns.
| Value↑ | External Ref | ||
|---|---|---|---|
| 2FA bypass via real-time OTP relay | |||
| Abuse Elevation Control Mechanism | ATT&CK Enterprise | ||
| Abuse of AWS STS and IAM tokens (AKIA/ASIA) for persistence | |||
| Account Discovery | ATT&CK Enterprise | ||
| Acquire Access | ATT&CK Enterprise | ||
| Adversary-in-the-Middle | ATT&CK Enterprise | ||
| Adversary-in-the-Middle (AiTM) Phishing | |||
| AI-assisted malicious content generation | |||
| AI-driven social engineering (deepfake voice, localized content) | |||
| AI-powered impersonation | |||
| AMSI and ETW bypass | |||
| Application Layer Protocol | ATT&CK Enterprise | ||
| Asymmetric Cryptography | ATT&CK Enterprise | ||
| Authentication bypass | |||
| Automated AI-powered ransom negotiation/chatbot | |||
| Browser Data Theft | |||
| Browser Information Discovery | ATT&CK Enterprise | ||
| Brute Force | |||
| Brute Force | ATT&CK Enterprise | ||
| Brute force attacks against remote access (default/weak credentials) | |||
| Brute Force Password Cracking | |||
| Bypass User Account Control | ATT&CK Enterprise | ||
| Certificate-based Password Generation | |||
| Cloned and fake retail websites | |||
| Cloud Accounts | ATT&CK Enterprise | ||
| Command and Scripting Interpreter | ATT&CK Enterprise | ||
| Command injection in web components | |||
| Connectivity check via PING before download | |||
| Content Spoofer | |||
| Coordinated social media amplification | |||
| Credential abuse / Valid account misuse | |||
| Credential brute-force against VPN/OWA/RDWeb | |||
| Credential dumping from MySQL database | |||
| Credential exfiltration to C2 | |||
| Credential harvesting | |||
| Credential harvesting from browsers and collaboration apps | |||
| Credential harvesting via fake e-commerce forms | |||
| Credential harvesting via phishing links | |||
| Credential harvesting via phishing pages | |||
| Credential reuse / password reuse | |||
| Credentials from Web Browsers | ATT&CK Enterprise | ||
| Credentials In Files | ATT&CK Enterprise | ||
| Credentials in Registry | ATT&CK Enterprise | ||
| Credential Stuffing | ATT&CK Enterprise | ||
| Credential Stuffing | |||
| Credential Theft via Infostealer | |||
| Cross-platform MIPS-targeting botnet infection | |||
| Cyber espionage | |||
| Data Encrypted for Impact | ATT&CK Enterprise | ||
| Data exfiltration to attacker-controlled server |
