| T1003.002_Windows | OS Credential Dumping: Security Account Manager | Windows | Credential Access | MITRE ATT&CK |
| T1003.006 | DCSync | | Credential Access | MITRE ATT&CK |
| T1012_Windows | Query Registry | Windows | Discovery | MITRE ATT&CK |
| T1021.001 | Remote Desktop Protocol | | Lateral Movement | MITRE ATT&CK |
| T1021.007 | Cloud Services | | Lateral Movement | MITRE ATT&CK |
| T1040_Windows | Network Sniffing (Windows) | Windows | Credential Access, Discovery | MITRE ATT&CK |
| T1047_Windows | Windows Management Instrumentation | Windows | Execution | MITRE ATT&CK |
| T1053.005_Windows | Scheduled Task/Job: Scheduled Task | Windows | Execution, Persistence, Privilege Escalation | MITRE ATT&CK |
| T1059.004 | Unix Shell | | Execution | MITRE ATT&CK |
| T1059.005 | Windows Command Shell | | Execution | MITRE ATT&CK |
| T1083 | File and Directory Discovery | | Discovery | MITRE ATT&CK |
| T1110.004_Windows | Brute Force: Credential Stuffing (Windows) | Windows | Credential Access | MITRE ATT&CK |
| T1114.002 | Remote Email Collection | | Collection | MITRE ATT&CK |
| T1114.002_Windows | Remote Email Collection | Windows | Collection | MITRE ATT&CK |
| T1203_Windows | Exploitation for Client Execution (Windows) | Windows | Execution | MITRE ATT&CK |
| T1207 | Rogue Domain Controller | | Defense Evasion | MITRE ATT&CK |
| T1211_Windows | Exploitation for Defense Evasion (Windows) | Windows | Defense Evasion | MITRE ATT&CK |
| T1219 | Remote Access Software | | Command and Control | MITRE ATT&CK |
| T1484.001 | Group Policy Modification | | Defense Evasion, Privilege Escalation | MITRE ATT&CK |
| T1495_Windows | Firmware Corruption | Windows | Impact | MITRE ATT&CK |
| T1518.001_Windows | Software Discovery: Security Software Discovery | Windows | Discovery | MITRE ATT&CK |
| T1530 | Data from Cloud Storage | | Collection | MITRE ATT&CK |
| T1530_AWS | Data from Cloud Storage Object (AWS) | AWS | Collection | MITRE ATT&CK |
| T1537_AWS | Transfer Data to Cloud Account | AWS | Exfiltration | MITRE ATT&CK |
| T1547.002 | Authentication Package | | Persistence, Privilege Escalation | MITRE ATT&CK |
| T1547.005_Windows | Boot or Logon Autostart Execution: Security Support Provider | Windows | Persistence, Privilege Escalation | MITRE ATT&CK |
| T1552.002_Windows | Unsecured Credentials: Credentials in Registry
| Windows | Credential Access | MITRE ATT&CK |
| T1558.001 | Golden Ticket | | Credential Access | MITRE ATT&CK |
| T1558.004 | AS-REP Roasting | | | MITRE ATT&CK |
| T1574.009 | Path Interception by Unquoted Path | | Persistence, Privilege Escalation, Defense Evasion | MITRE ATT&CK |
| T1574.009_Windows | Path Interception by Unquoted Path | Windows | Persistence, Privilege Escalation, Defense Evasion | MITRE ATT&CK |
| T1574.011 | Services Registry Permissions Weakness | | Persistence, Privilege Escalation, Defense Evasion | MITRE ATT&CK |
| T1580_AWS | Cloud Infrastructure Discovery(AWS) | AWS | Discovery | MITRE ATT&CK |
| T1615 | Group Policy Discovery | | Discovery | MITRE ATT&CK |
| T1068 | Exploitation for Privilege Escalation | | Privilege Escalation | MITRE ATT&CK |
| T1134.005 | SID-History Injection | | Defense Evasion, Privilege Escalation | MITRE ATT&CK |
| T1210 | Exploitation of Remote Services | | Lateral Movement | MITRE ATT&CK |
| T1211 | Exploitation for Defense Evasion | | Defense Evasion | MITRE ATT&CK |
| T1499.004 | Application or System Exploitation | | Impact | MITRE ATT&CK |
| T1213 | Data from Information Repositories | | Collection | MITRE ATT&CK |
| T1518.001 | Security Software Discovery | | Discovery | MITRE ATT&CK |
| T1069.001 | Local Groups | | Discovery | MITRE ATT&CK |
| T1595.001_PRE | Active Scanning: Scanning IP Blocks | PRE | Reconnaissance | MITRE ATT&CK |
| T1592.002 | Software | | Reconnaissance | MITRE ATT&CK |
| T1595.001 | Scanning IP Blocks | | Reconnaissance | MITRE ATT&CK |
| T1069.003 | Cloud Groups | | Discovery | MITRE ATT&CK |