Detection Playbook: Data Destruction (T1485)

T1485 · 2026-07-27 Data Destruction Impact Containers ESXi IaaS Linux MITRE ATT&CK → Technique Data Destruction (T1485) Tactic Impact Platforms Containers, ESXi, IaaS, Linux, macOS, Windows Overview Data Destruction (T1485) is an impact-phase technique where adversaries deliberately overwrite, corrupt, or permanently delete files and data to make recovery impossible — going beyond simple deletion by … Read more

Detection Playbook: External Remote Services (T1133)

T1133 · 2026-07-26 External Remote Services Persistence Containers Linux macOS Windows MITRE ATT&CK → Technique External Remote Services (T1133) Tactic Persistence Platforms Containers, Linux, macOS, Windows Overview External Remote Services (T1133) describes adversaries abusing legitimate remote access mechanisms — VPNs, Citrix, RDP gateways, SSH, VNC, exposed APIs, and similar services — to gain or maintain … Read more

Detection Playbook: Malicious File (T1204.002)

T1204.002 · 2026-07-25 Malicious File Execution Linux macOS Windows MITRE ATT&CK → Technique Malicious File (T1204.002) Tactic Execution Platforms Linux, macOS, Windows Overview Malicious File (T1204.002) describes an attacker tricking a user into opening a weaponized file — such as a macro-enabled Office document, a disguised executable, a malicious PDF, or a container file like … Read more

Detection Playbook: JavaScript (T1059.007)

T1059.007 · 2026-07-24 JavaScript Execution Linux macOS Windows MITRE ATT&CK → Technique JavaScript (T1059.007) Tactic Execution Platforms Linux, macOS, Windows Overview T1059.007 covers adversary abuse of JavaScript and its runtime variants — including JScript on Windows, Node.js across platforms, and JavaScript for Automation (JXA) on macOS — to execute malicious code. Attackers use these scripting … Read more

Detection Playbook: Match Legitimate Resource Name or Location (T1036.005)

T1036.005 · 2026-07-23 Match Legitimate Resource Name or Location Stealth Containers ESXi Linux macOS MITRE ATT&CK → Technique Match Legitimate Resource Name or Location (T1036.005) Tactic Stealth Platforms Containers, ESXi, Linux, macOS, Windows Overview Match Legitimate Resource Name or Location (T1036.005) is a masquerading technique where adversaries rename malicious executables, scripts, or other resources to … Read more

Detection Playbook: Modify Registry (T1112)

T1112 · 2026-07-22 Modify Registry Defense Impairment Windows MITRE ATT&CK → Technique Modify Registry (T1112) Tactic Defense Impairment Platforms Windows Overview Modify Registry (T1112) describes adversary interactions with the Windows Registry to achieve defense evasion, persistence, or execution. Attackers use registry modifications to disable security tooling, store encoded payloads, enable dangerous features like plaintext credential … Read more

Detection Playbook: File and Directory Discovery (T1083)

T1083 · 2026-07-21 File and Directory Discovery Discovery ESXi Linux macOS Network Devices MITRE ATT&CK → Technique File and Directory Discovery (T1083) Tactic Discovery Platforms ESXi, Linux, macOS, Network Devices, Windows Overview File and Directory Discovery (T1083) refers to adversaries actively enumerating the file system — listing directories, searching for specific file types, and mapping … Read more

Detection Playbook: Process Discovery (T1057)

T1057 · 2026-07-20 Process Discovery Discovery ESXi Linux macOS Network Devices MITRE ATT&CK → Technique Process Discovery (T1057) Tactic Discovery Platforms ESXi, Linux, macOS, Network Devices, Windows Overview Process Discovery (T1057) is a reconnaissance technique where adversaries enumerate running processes on a compromised system to understand what software is active, what security tools are present, … Read more

Detection Playbook: System Owner/User Discovery (T1033)

T1033 · 2026-07-19 System Owner/User Discovery Discovery Linux macOS Network Devices Windows MITRE ATT&CK → Technique System Owner/User Discovery (T1033) Tactic Discovery Platforms Linux, macOS, Network Devices, Windows Overview System Owner/User Discovery (T1033) is a reconnaissance technique where adversaries enumerate the current user, active sessions, and account listings on a compromised host. Attackers use this … Read more

Detection Playbook: System Network Configuration Discovery (T1016)

T1016 · 2026-07-18 System Network Configuration Discovery Discovery ESXi Linux macOS Network Devices MITRE ATT&CK → Technique System Network Configuration Discovery (T1016) Tactic Discovery Platforms ESXi, Linux, macOS, Network Devices, Windows Overview System Network Configuration Discovery (T1016) is a technique where adversaries enumerate network settings on a compromised host — collecting IP addresses, MAC addresses, … Read more