MITRE ATT&CK ATT&CK Enterprise v19.2(2026-05-12 リリース)の知識ベース(脅威グループ 174 / 技法 222)と、CISA KEV(悪用が確認された脆弱性)を組み合わせた脅威動向サマリ。各項目はマトリクスビューアの該当箇所にリンクします。
サイト更新 2026-08-16 / KEV カタログ 2026.08.14 版(1,665件、ランサム339件) / ATT&CK 知識ベースは v19.2 が現行最新
🔒 はランサムウェアでの悪用が確認されたもの。
出典: MITRE ATT&CK Enterprise v19.2(リリース 2026-05-12)。脅威グループ174 / 技法222。同リリースで多くのグループのmodified日付が2026-05-12に揃っています。
この技法を用いたことが報告された脅威グループ/キャンペーンの数。攻撃の「定番手口」を示す。
そのグループが使用したことが報告された技法の数。手口の幅広さ=活動の活発さの指標。
ATT&CK上で最近情報が更新された脅威グループ(更新日順)。最新の動きがあった示唆。
MITRE ATT&CK の各グループ解説に基づく帰属分類。数字は使用技法数。帰属には諸説ある場合があります。
| ID | 技法名 |
|---|---|
| T1608.001 | Upload Malware |
| T1583.006 | Web Services |
| T1585.002 | Email Accounts |
| T1586.002 | Email Accounts |
| T1588.003 | Code Signing Certificates |
| T1588.002 | Tool |
| T1588.004 | Digital Certificates |
| T1608 | Stage Capabilities |
| T1583.001 | Domains |
| T1587.001 | Malware |
| ID | 技法名 |
|---|---|
| T1047 | Windows Management Instrumentation |
| T1204.001 | Malicious Link |
| T1059.005 | Visual Basic |
| T1053.005 | Scheduled Task |
| T1072 | Software Deployment Tools |
| T1059.003 | Windows Command Shell |
| T1129 | Shared Modules |
| T1203 | Exploitation for Client Execution |
| T1106 | Native API |
| T1059 | Command and Scripting Interpreter |
| T1059.007 | JavaScript |
| T1059.001 | PowerShell |
| T1204.002 | Malicious File |
| ID | 技法名 |
|---|---|
| T1546.003 | Windows Management Instrumentation Event Subscription |
| ID | 技法名 |
|---|---|
| T1140 | Deobfuscate/Decode Files or Information |
| T1678 | Delay Execution |
| T1564.001 | Hidden Files and Directories |
| T1218.005 | Mshta |
| T1027.007 | Dynamic API Resolution |
| T1218.004 | InstallUtil |
| T1070 | Indicator Removal |
| T1070.004 | File Deletion |
| T1574.005 | Executable Installer File Permissions Weakness |
| T1622 | Debugger Evasion |
| T1574.001 | DLL |
| T1027 | Obfuscated Files or Information |
| T1027.016 | Junk Code Insertion |
| T1070.006 | Timestomp |
| T1036.008 | Masquerade File Type |
| T1036.007 | Double File Extension |
| T1205 | Traffic Signaling |
| T1036.005 | Match Legitimate Resource Name or Location |
| T1027.012 | LNK Icon Smuggling |
| ID | 技法名 |
|---|---|
| T1553.002 | Code Signing |
| ID | 技法名 |
|---|---|
| T1557 | Adversary-in-the-Middle |
| T1003.001 | LSASS Memory |
| T1003.003 | NTDS |
| T1003 | OS Credential Dumping |
| T1003.006 | DCSync |
| ID | 技法名 |
|---|---|
| T1016 | System Network Configuration Discovery |
| T1046 | Network Service Discovery |
| T1049 | System Network Connections Discovery |
| T1087.002 | Domain Account |
| T1018 | Remote System Discovery |
| T1069.002 | Domain Groups |
| T1057 | Process Discovery |
| T1082 | System Information Discovery |
| T1654 | Log Enumeration |
| T1083 | File and Directory Discovery |
| T1518 | Software Discovery |
| ID | 技法名 |
|---|---|
| T1091 | Replication Through Removable Media |
| ID | 技法名 |
|---|---|
| T1560.001 | Archive via Utility |
| T1560.003 | Archive via Custom Method |
| T1119 | Automated Collection |
| T1074.001 | Local Data Staging |
| ID | 技法名 |
|---|---|
| T1573.001 | Symmetric Cryptography |
| T1219.001 | IDE Tunneling |
| T1219.002 | Remote Desktop Software |
| T1071.001 | Web Protocols |
| T1001.003 | Protocol or Service Impersonation |
| T1095 | Non-Application Layer Protocol |
| T1105 | Ingress Tool Transfer |
| T1572 | Protocol Tunneling |
| T1102 | Web Service |
| ID | 技法名 |
|---|---|
| T1567.002 | Exfiltration to Cloud Storage |
| T1048.003 | Exfiltration Over Unencrypted Non-C2 Protocol |
| T1041 | Exfiltration Over C2 Channel |
| T1052.001 | Exfiltration over USB |
| ID | 技法名 |
|---|---|
| T1598 | Phishing for Information |
| T1593.001 | Social Media |
| T1589.003 | Employee Names |
| T1594 | Search Victim-Owned Websites |
| T1591 | Gather Victim Org Information |
| T1598.003 | Spearphishing Link |
| T1596 | Search Open Technical Databases |
| T1589.002 | Email Addresses |
| T1682 | Query Public AI Services |
| T1593.002 | Search Engines |
| ID | 技法名 |
|---|---|
| T1587.001 | Malware |
| T1583 | Acquire Infrastructure |
| T1585.002 | Email Accounts |
| T1588.002 | Tool |
| T1608.001 | Upload Malware |
| T1587 | Develop Capabilities |
| T1585 | Establish Accounts |
| T1583.004 | Server |
| T1583.001 | Domains |
| T1585.001 | Social Media Accounts |
| T1586.002 | Email Accounts |
| T1584.001 | Domains |
| T1588.005 | Exploits |
| T1583.006 | Web Services |
| T1588.003 | Code Signing Certificates |
| ID | 技法名 |
|---|---|
| T1566 | Phishing |
| T1566.002 | Spearphishing Link |
| T1190 | Exploit Public-Facing Application |
| T1566.001 | Spearphishing Attachment |
| ID | 技法名 |
|---|---|
| T1204.002 | Malicious File |
| T1204.004 | Malicious Copy and Paste |
| T1559.001 | Component Object Model |
| T1204.001 | Malicious Link |
| T1059.003 | Windows Command Shell |
| T1106 | Native API |
| T1059.007 | JavaScript |
| T1059.001 | PowerShell |
| T1053.005 | Scheduled Task |
| T1059.005 | Visual Basic |
| T1059.006 | Python |
| ID | 技法名 |
|---|---|
| T1176.001 | Browser Extensions |
| T1136.001 | Local Account |
| T1133 | External Remote Services |
| T1547.001 | Registry Run Keys / Startup Folder |
| T1543.003 | Windows Service |
| T1098.007 | Additional Local or Domain Groups |
| T1505.003 | Web Shell |
| ID | 技法名 |
|---|---|
| T1546.001 | Change Default File Association |
| ID | 技法名 |
|---|---|
| T1678 | Delay Execution |
| T1078.003 | Local Accounts |
| T1140 | Deobfuscate/Decode Files or Information |
| T1027.010 | Command Obfuscation |
| T1684.001 | Impersonation |
| T1036.004 | Masquerade Task or Service |
| T1027.007 | Dynamic API Resolution |
| T1027.013 | Encrypted/Encoded File |
| T1218.011 | Rundll32 |
| T1564.002 | Hidden Users |
| T1070.004 | File Deletion |
| T1620 | Reflective Code Loading |
| T1027.001 | Binary Padding |
| T1070.006 | Timestomp |
| T1027.012 | LNK Icon Smuggling |
| T1027.016 | Junk Code Insertion |
| T1218.005 | Mshta |
| T1564.011 | Ignore Process Interrupts |
| T1497.001 | System Checks |
| T1027 | Obfuscated Files or Information |
| T1027.002 | Software Packing |
| T1055.001 | Dynamic-link Library Injection |
| T1055 | Process Injection |
| T1218.010 | Regsvr32 |
| T1564.003 | Hidden Window |
| T1027.015 | Compression |
| T1480.002 | Mutual Exclusion |
| T1036.005 | Match Legitimate Resource Name or Location |
| T1036.007 | Double File Extension |
| T1055.012 | Process Hollowing |
| T1205 | Traffic Signaling |
| ID | 技法名 |
|---|---|
| T1685 | Disable or Modify Tools |
| T1553.002 | Code Signing |
| T1686 | Disable or Modify System Firewall |
| T1112 | Modify Registry |
| ID | 技法名 |
|---|---|
| T1040 | Network Sniffing |
| T1539 | Steal Web Session Cookie |
| T1552.004 | Private Keys |
| T1111 | Multi-Factor Authentication Interception |
| T1557 | Adversary-in-the-Middle |
| T1552.001 | Credentials In Files |
| T1555.003 | Credentials from Web Browsers |
| T1003.001 | LSASS Memory |
| ID | 技法名 |
|---|---|
| T1217 | Browser Information Discovery |
| T1012 | Query Registry |
| T1007 | System Service Discovery |
| T1518.001 | Security Software Discovery |
| T1082 | System Information Discovery |
| T1016 | System Network Configuration Discovery |
| T1057 | Process Discovery |
| T1083 | File and Directory Discovery |
| T1033 | System Owner/User Discovery |
| T1680 | Local Storage Discovery |
| T1124 | System Time Discovery |
| ID | 技法名 |
|---|---|
| T1005 | Data from Local System |
| T1056.003 | Web Portal Capture |
| T1115 | Clipboard Data |
| T1560.003 | Archive via Custom Method |
| T1185 | Browser Session Hijacking |
| T1074.001 | Local Data Staging |
| T1056.001 | Keylogging |
| T1560.001 | Archive via Utility |
| T1113 | Screen Capture |
| T1114.003 | Email Forwarding Rule |
| T1114.002 | Remote Email Collection |
| ID | 技法名 |
|---|---|
| T1105 | Ingress Tool Transfer |
| T1102.002 | Bidirectional Communication |
| T1219.002 | Remote Desktop Software |
| T1071.001 | Web Protocols |
| T1568 | Dynamic Resolution |
| T1071.003 | Mail Protocols |
| T1102.001 | Dead Drop Resolver |
| T1132.002 | Non-Standard Encoding |
| T1071.002 | File Transfer Protocols |
| ID | 技法名 |
|---|---|
| T1020 | Automated Exfiltration |
| T1567.002 | Exfiltration to Cloud Storage |
| T1041 | Exfiltration Over C2 Channel |
| ID | 技法名 |
|---|---|
| T1589.001 | Credentials |
| T1591 | Gather Victim Org Information |
| T1596 | Search Open Technical Databases |
| T1595.002 | Vulnerability Scanning |
| T1598 | Phishing for Information |
| T1598.003 | Spearphishing Link |
| ID | 技法名 |
|---|---|
| T1583.003 | Virtual Private Server |
| T1583.001 | Domains |
| T1586.002 | Email Accounts |
| T1584.008 | Network Devices |
| T1588.002 | Tool |
| T1583.006 | Web Services |
| T1588.007 | Artificial Intelligence |
| ID | 技法名 |
|---|---|
| T1566.001 | Spearphishing Attachment |
| T1190 | Exploit Public-Facing Application |
| T1669 | Wi-Fi Networks |
| T1189 | Drive-by Compromise |
| T1199 | Trusted Relationship |
| ID | 技法名 |
|---|---|
| T1059.001 | PowerShell |
| T1203 | Exploitation for Client Execution |
| T1059.003 | Windows Command Shell |
| T1559.002 | Dynamic Data Exchange |
| T1204.002 | Malicious File |
| T1204.001 | Malicious Link |
| ID | 技法名 |
|---|---|
| T1547.001 | Registry Run Keys / Startup Folder |
| T1505.003 | Web Shell |
| T1037.001 | Logon Script (Windows) |
| T1098.002 | Additional Email Delegate Permissions |
| T1137.002 | Office Test |
| T1133 | External Remote Services |
| ID | 技法名 |
|---|---|
| T1564.001 | Hidden Files and Directories |
| T1070.006 | Timestomp |
| T1027.013 | Encrypted/Encoded File |
| T1564.003 | Hidden Window |
| T1070.004 | File Deletion |
| T1036.005 | Match Legitimate Resource Name or Location |
| T1078.004 | Cloud Accounts |
| T1221 | Template Injection |
| T1078 | Valid Accounts |
| T1218.011 | Rundll32 |
| T1140 | Deobfuscate/Decode Files or Information |
| T1542.003 | Bootkit |
| T1036 | Masquerading |
| T1014 | Rootkit |
| T1134.001 | Token Impersonation/Theft |
| T1211 | Exploitation for Stealth |
| T1684.001 | Impersonation |
| ID | 技法名 |
|---|---|
| T1685.005 | Clear Windows Event Logs |
| ID | 技法名 |
|---|---|
| T1003.003 | NTDS |
| T1110.001 | Password Guessing |
| T1557.004 | Evil Twin |
| T1040 | Network Sniffing |
| T1528 | Steal Application Access Token |
| T1110.003 | Password Spraying |
| T1003.001 | LSASS Memory |
| T1110 | Brute Force |
| T1003 | OS Credential Dumping |
| ID | 技法名 |
|---|---|
| T1550.002 | Pass the Hash |
| T1550.001 | Application Access Token |
| T1091 | Replication Through Removable Media |
| T1021.002 | SMB/Windows Admin Shares |
| T1210 | Exploitation of Remote Services |
| ID | 技法名 |
|---|---|
| T1114.002 | Remote Email Collection |
| T1056.001 | Keylogging |
| T1039 | Data from Network Shared Drive |
| T1113 | Screen Capture |
| T1560 | Archive Collected Data |
| T1119 | Automated Collection |
| T1005 | Data from Local System |
| T1213.002 | Sharepoint |
| T1025 | Data from Removable Media |
| T1213 | Data from Information Repositories |
| T1560.001 | Archive via Utility |
| T1074.002 | Remote Data Staging |
| T1074.001 | Local Data Staging |
| ID | 技法名 |
|---|---|
| T1090.002 | External Proxy |
| T1090.003 | Multi-hop Proxy |
| T1105 | Ingress Tool Transfer |
| T1071.001 | Web Protocols |
| T1071.003 | Mail Protocols |
| T1092 | Communication Through Removable Media |
| T1102.002 | Bidirectional Communication |
| T1001.001 | Junk Data |
| T1573.001 | Symmetric Cryptography |
| ID | 技法名 |
|---|---|
| T1048.002 | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol |
| T1567 | Exfiltration Over Web Service |
| T1030 | Data Transfer Size Limits |
| ID | 技法名 |
|---|---|
| T1498 | Network Denial of Service |
| ID | 技法名 |
|---|---|
| T1589.001 | Credentials |
| T1591.001 | Determine Physical Locations |
| T1592.002 | Software |
| T1590.005 | IP Addresses |
| T1595.002 | Vulnerability Scanning |
| T1589.002 | Email Addresses |
| T1598.003 | Spearphishing Link |
| T1589 | Gather Victim Identity Information |
| ID | 技法名 |
|---|---|
| T1588.002 | Tool |
| T1584.001 | Domains |
| T1585.002 | Email Accounts |
| T1586.002 | Email Accounts |
| T1583.001 | Domains |
| T1585.001 | Social Media Accounts |
| T1583.006 | Web Services |
| ID | 技法名 |
|---|---|
| T1190 | Exploit Public-Facing Application |
| T1566.002 | Spearphishing Link |
| T1566.003 | Spearphishing via Service |
| T1189 | Drive-by Compromise |
| ID | 技法名 |
|---|---|
| T1059.001 | PowerShell |
| T1059.003 | Windows Command Shell |
| T1053.005 | Scheduled Task |
| T1204.002 | Malicious File |
| T1059.005 | Visual Basic |
| T1204.001 | Malicious Link |
| T1047 | Windows Management Instrumentation |
| ID | 技法名 |
|---|---|
| T1547.001 | Registry Run Keys / Startup Folder |
| T1098.002 | Additional Email Delegate Permissions |
| T1098.007 | Additional Local or Domain Groups |
| T1136.001 | Local Account |
| T1505.003 | Web Shell |
| ID | 技法名 |
|---|---|
| T1218.011 | Rundll32 |
| T1027.010 | Command Obfuscation |
| T1036.010 | Masquerade Account Name |
| T1070.004 | File Deletion |
| T1027.013 | Encrypted/Encoded File |
| T1078.001 | Default Accounts |
| T1036.005 | Match Legitimate Resource Name or Location |
| T1070.003 | Clear Command History |
| T1036.004 | Masquerade Task or Service |
| T1078.002 | Domain Accounts |
| T1564.003 | Hidden Window |
| ID | 技法名 |
|---|---|
| T1685.001 | Disable or Modify Windows Event Log |
| T1686.003 | Windows Host Firewall |
| T1112 | Modify Registry |
| T1685 | Disable or Modify Tools |
| ID | 技法名 |
|---|---|
| T1003.001 | LSASS Memory |
| ID | 技法名 |
|---|---|
| T1016.002 | Wi-Fi Discovery |
| T1016.001 | Internet Connection Discovery |
| T1046 | Network Service Discovery |
| T1033 | System Owner/User Discovery |
| T1083 | File and Directory Discovery |
| T1016 | System Network Configuration Discovery |
| T1049 | System Network Connections Discovery |
| T1057 | Process Discovery |
| T1082 | System Information Discovery |
| T1018 | Remote System Discovery |
| T1482 | Domain Trust Discovery |
| T1087.003 | Email Account |
| ID | 技法名 |
|---|---|
| T1056.001 | Keylogging |
| T1113 | Screen Capture |
| T1114 | Email Collection |
| T1114.002 | Remote Email Collection |
| T1114.001 | Local Email Collection |
| T1560.001 | Archive via Utility |
| T1005 | Data from Local System |
| ID | 技法名 |
|---|---|
| T1572 | Protocol Tunneling |
| T1071 | Application Layer Protocol |
| T1071.001 | Web Protocols |
| T1105 | Ingress Tool Transfer |
| T1573 | Encrypted Channel |
| T1102.002 | Bidirectional Communication |
| T1571 | Non-Standard Port |
| T1090 | Proxy |
| ID | 技法名 |
|---|---|
| T1567 | Exfiltration Over Web Service |
| ID | 技法名 |
|---|---|
| T1486 | Data Encrypted for Impact |
| ID | 技法名 |
|---|---|
| T1598.003 | Spearphishing Link |
| T1589 | Gather Victim Identity Information |
| T1589.002 | Email Addresses |
| ID | 技法名 |
|---|---|
| T1583.001 | Domains |
| T1608.004 | Drive-by Target |
| T1608.001 | Upload Malware |
| T1588.002 | Tool |
| T1583.006 | Web Services |
| T1585.001 | Social Media Accounts |
| ID | 技法名 |
|---|---|
| T1059.007 | JavaScript |
| T1047 | Windows Management Instrumentation |
| T1072 | Software Deployment Tools |
| T1059.003 | Windows Command Shell |
| T1059.001 | PowerShell |
| T1059 | Command and Scripting Interpreter |
| T1204.001 | Malicious Link |
| T1053.005 | Scheduled Task |
| T1569.002 | Service Execution |
| T1059.005 | Visual Basic |
| T1203 | Exploitation for Client Execution |
| T1204.002 | Malicious File |
| ID | 技法名 |
|---|---|
| T1543.003 | Windows Service |
| T1505.003 | Web Shell |
| T1137 | Office Application Startup |
| T1547.001 | Registry Run Keys / Startup Folder |
| ID | 技法名 |
|---|---|
| T1068 | Exploitation for Privilege Escalation |
| ID | 技法名 |
|---|---|
| T1036 | Masquerading |
| T1564.004 | NTFS File Attributes |
| T1055 | Process Injection |
| T1216.001 | PubPrn |
| T1027.010 | Command Obfuscation |
| T1574.001 | DLL |
| T1036.004 | Masquerade Task or Service |
| T1078.003 | Local Accounts |
| T1070.006 | Timestomp |
| T1218.011 | Rundll32 |
| T1036.005 | Match Legitimate Resource Name or Location |
| T1070.004 | File Deletion |
| T1027.011 | Fileless Storage |
| T1036.003 | Rename Legitimate Utilities |
| T1218.005 | Mshta |
| T1564.001 | Hidden Files and Directories |
| T1027.016 | Junk Code Insertion |
| T1564.003 | Hidden Window |
| T1027.013 | Encrypted/Encoded File |
| T1218.010 | Regsvr32 |
| ID | 技法名 |
|---|---|
| T1112 | Modify Registry |
| T1222.002 | Linux and Mac Permissions |
| T1685.005 | Clear Windows Event Logs |
| ID | 技法名 |
|---|---|
| T1135 | Network Share Discovery |
| T1033 | System Owner/User Discovery |
| T1082 | System Information Discovery |
| T1012 | Query Registry |
| T1087.001 | Local Account |
| T1046 | Network Service Discovery |
| T1018 | Remote System Discovery |
| T1083 | File and Directory Discovery |
| T1016 | System Network Configuration Discovery |
| T1049 | System Network Connections Discovery |
| ID | 技法名 |
|---|---|
| T1550.002 | Pass the Hash |
| T1570 | Lateral Tool Transfer |
| T1021.002 | SMB/Windows Admin Shares |
| T1550.003 | Pass the Ticket |
| ID | 技法名 |
|---|---|
| T1571 | Non-Standard Port |
| T1071.003 | Mail Protocols |
| T1071.001 | Web Protocols |
| T1105 | Ingress Tool Transfer |
| T1102 | Web Service |
| ID | 技法名 |
|---|---|
| T1048.003 | Exfiltration Over Unencrypted Non-C2 Protocol |
| T1041 | Exfiltration Over C2 Channel |
| ID | 技法名 |
|---|---|
| T1598.003 | Spearphishing Link |
| ID | 技法名 |
|---|---|
| T1059.005 | Visual Basic |
| T1053.005 | Scheduled Task |
| T1204.001 | Malicious Link |
| T1203 | Exploitation for Client Execution |
| T1204.002 | Malicious File |
| T1059.003 | Windows Command Shell |
| T1059.001 | PowerShell |
| T1559.002 | Dynamic Data Exchange |
| ID | 技法名 |
|---|---|
| T1547.001 | Registry Run Keys / Startup Folder |
| ID | 技法名 |
|---|---|
| T1548.002 | Bypass User Account Control |
| ID | 技法名 |
|---|---|
| T1574.001 | DLL |
| T1197 | BITS Jobs |
| T1027.005 | Indicator Removal from Tools |
| T1055.012 | Process Hollowing |
| T1036.005 | Match Legitimate Resource Name or Location |
| T1027.010 | Command Obfuscation |
| T1027.002 | Software Packing |
| T1070.004 | File Deletion |
| T1027.001 | Binary Padding |
| ID | 技法名 |
|---|---|
| T1555.003 | Credentials from Web Browsers |
| ID | 技法名 |
|---|---|
| T1083 | File and Directory Discovery |
| T1518.001 | Security Software Discovery |
| T1033 | System Owner/User Discovery |
| T1680 | Local Storage Discovery |
| T1082 | System Information Discovery |
| ID | 技法名 |
|---|---|
| T1021.001 | Remote Desktop Protocol |
| ID | 技法名 |
|---|---|
| T1560 | Archive Collected Data |
| T1074.001 | Local Data Staging |
| T1005 | Data from Local System |
| T1119 | Automated Collection |
| ID | 技法名 |
|---|---|
| T1566.001 | Spearphishing Attachment |
| ID | 技法名 |
|---|---|
| T1059.003 | Windows Command Shell |
| T1203 | Exploitation for Client Execution |
| T1204.002 | Malicious File |
| ID | 技法名 |
|---|---|
| T1547.001 | Registry Run Keys / Startup Folder |
| ID | 技法名 |
|---|---|
| T1497.002 | User Activity Based Checks |
| T1027.013 | Encrypted/Encoded File |
| T1140 | Deobfuscate/Decode Files or Information |
| T1497 | Virtualization/Sandbox Evasion |
| T1497.001 | System Checks |
| T1036.005 | Match Legitimate Resource Name or Location |
| ID | 技法名 |
|---|---|
| T1553.002 | Code Signing |
| ID | 技法名 |
|---|---|
| T1518.001 | Security Software Discovery |
| T1082 | System Information Discovery |
| T1057 | Process Discovery |
| T1124 | System Time Discovery |
| T1016 | System Network Configuration Discovery |
| T1083 | File and Directory Discovery |
| ID | 技法名 |
|---|---|
| T1056.001 | Keylogging |
| ID | 技法名 |
|---|---|
| T1189 | Drive-by Compromise |
| ID | 技法名 |
|---|---|
| T1204.002 | Malicious File |
| ID | 技法名 |
|---|---|
| T1078.003 | Local Accounts |
| T1036.005 | Match Legitimate Resource Name or Location |
| T1036.004 | Masquerade Task or Service |
| T1205.001 | Port Knocking |
| ID | 技法名 |
|---|---|
| T1553.002 | Code Signing |