Detection Playbook: Valid Accounts (T1078)

T1078 · 2026-07-07 Valid Accounts Stealth Containers ESXi IaaS Identity Provider MITRE ATT&CK → Technique Valid Accounts (T1078) Tactic Stealth Platforms Containers, ESXi, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows Overview Valid Accounts (T1078) describes adversaries using legitimate, existing credentials — stolen, purchased, phished, or brute-forced — to access systems and … Read more

Detection Playbook: Spearphishing Link (T1566.002)

T1566.002 · 2026-07-06 Spearphishing Link Initial Access Identity Provider Linux macOS Office Suite MITRE ATT&CK → Technique Spearphishing Link (T1566.002) Tactic Initial Access Platforms Identity Provider, Linux, macOS, Office Suite, SaaS, Windows Overview Spearphishing Link (T1566.002) is a targeted email attack where adversaries send carefully crafted messages containing malicious URLs to specific individuals. When the … Read more

Detection Playbook: Spearphishing Attachment (T1566.001)

T1566.001 · 2026-07-05 Spearphishing Attachment Initial Access Linux macOS Windows MITRE ATT&CK → Technique Spearphishing Attachment (T1566.001) Tactic Initial Access Platforms Linux, macOS, Windows Overview Spearphishing Attachment (T1566.001) is a targeted email-based attack where an adversary sends a crafted email to a specific individual, company, or industry with a malicious file attached — commonly an … Read more

Detection Playbook: Service Execution (T1569.002)

T1569.002 · 2026-07-04 Service Execution Execution Windows MITRE ATT&CK → Technique Service Execution (T1569.002) Tactic Execution Platforms Windows Overview Service Execution (T1569.002) describes how adversaries abuse the Windows Service Control Manager (SCM) to run malicious commands or payloads — either by creating a new service, modifying an existing one, or using tools like sc.exe, net.exe, … Read more

Detection Playbook: SMB/Windows Admin Shares (T1021.002)

T1021.002 · 2026-07-03 SMB/Windows Admin Shares Lateral Movement Windows MITRE ATT&CK → Technique SMB/Windows Admin Shares (T1021.002) Tactic Lateral Movement Platforms Windows Overview SMB/Windows Admin Shares (T1021.002) is a lateral movement technique where attackers use valid credentials — stolen, brute-forced, or obtained through credential dumping — to access hidden administrative network shares such as C$, … Read more

Detection Playbook: Remote Desktop Protocol (T1021.001)

T1021.001 · 2026-07-02 Remote Desktop Protocol Lateral Movement Windows MITRE ATT&CK → Technique Remote Desktop Protocol (T1021.001) Tactic Lateral Movement Platforms Windows Overview Remote Desktop Protocol (RDP) lateral movement occurs when an adversary uses valid credentials to interactively log into a remote Windows system via port 3389, gaining a full graphical desktop session as the … Read more

Detection Playbook: System Information Discovery (T1082)

T1082 · 2026-07-01 System Information Discovery Discovery ESXi IaaS Linux macOS MITRE ATT&CK → Technique System Information Discovery (T1082) Tactic Discovery Platforms ESXi, IaaS, Linux, macOS, Network Devices, Windows Overview System Information Discovery (T1082) is a technique where adversaries enumerate detailed information about a target system — including OS version, patch level, architecture, hostname, and … Read more

Detection Playbook: Domain Groups (T1069.002)

T1069.002 · 2026-06-30 Domain Groups Discovery Linux macOS Windows MITRE ATT&CK → Technique Domain Groups (T1069.002) Tactic Discovery Platforms Linux, macOS, Windows Overview Domain Groups enumeration (T1069.002) is the act of querying Active Directory or a domain controller to map out domain-level groups and their memberships. Attackers use this information to identify high-value targets — … Read more

Detection Playbook: Domain Account (T1087.002)

T1087.002 · 2026-06-29 Domain Account Discovery Linux macOS Windows MITRE ATT&CK → Technique Domain Account (T1087.002) Tactic Discovery Platforms Linux, macOS, Windows Overview Domain Account Discovery (T1087.002) is a technique where adversaries enumerate domain user accounts and groups to map out the Active Directory environment. Attackers use this information to identify high-value targets — domain … Read more

Detection Playbook: Network Service Discovery (T1046)

T1046 · 2026-06-28 Network Service Discovery Discovery Containers IaaS Linux macOS MITRE ATT&CK → Technique Network Service Discovery (T1046) Tactic Discovery Platforms Containers, IaaS, Linux, macOS, Network Devices, Windows Overview Network Service Discovery (T1046) is a reconnaissance technique where adversaries scan local and remote systems to enumerate running services, open ports, and potentially vulnerable software. … Read more