Interactive research piece

ATT&CK coverage

Where my projects and papers sit on the MITRE ATT&CK Enterprise matrix. Each cell is a technique; a darker cell means more of my work touches it, and the letters say how: D detects, M mitigates, S studies. Select a technique to see the work behind it.

The mappings are my own reading of what each project or paper detects, mitigates, or studies. They are not an assessment by MITRE. Enterprise ATT&CK v19.2.

Relation
Work type
View

5 techniques across 4 of 15 tactics, from 3 works.

Scroll inside the box to move around the matrix; Shift + wheel scrolls sideways.

Reconnaissance0 of 12

  • Active ScanningT1595
  • Gather Victim Host InformationT1592
  • Gather Victim Identity InformationT1589
  • Gather Victim Network InformationT1590
  • Gather Victim Org InformationT1591
  • Phishing for InformationT1598
  • Query Public AI ServicesT1682
  • Search Closed SourcesT1597
  • Search Open Technical DatabasesT1596
  • Search Open Websites/DomainsT1593
  • Search Threat Vendor DataT1681
  • Search Victim-Owned WebsitesT1594

Resource Development0 of 9

  • Acquire AccessT1650
  • Acquire InfrastructureT1583
  • Compromise AccountsT1586
  • Compromise InfrastructureT1584
  • Develop CapabilitiesT1587
  • Establish AccountsT1585
  • Generate ContentT1683
  • Obtain CapabilitiesT1588
  • Stage CapabilitiesT1608

Initial Access2 of 11

  • Content InjectionT1659
  • Drive-by CompromiseT1189
  • External Remote ServicesT1133
  • Hardware AdditionsT1200
  • Replication Through Removable MediaT1091
  • Supply Chain CompromiseT1195
  • Trusted RelationshipT1199
  • Valid AccountsT1078
  • Wi-Fi NetworksT1669

Execution0 of 20

  • BITS JobsT1197
  • Cloud Administration CommandT1651
  • Command and Scripting InterpreterT1059
  • Container Administration CommandT1609
  • Deploy ContainerT1610
  • ESXi Administration CommandT1675
  • Exploitation for Client ExecutionT1203
  • Hijack Execution FlowT1574
  • Input InjectionT1674
  • Inter-Process CommunicationT1559
  • Native APIT1106
  • Poisoned Pipeline ExecutionT1677
  • Scheduled Task/JobT1053
  • Serverless ExecutionT1648
  • Shared ModulesT1129
  • Software Deployment ToolsT1072
  • System ServicesT1569
  • Trusted Developer Utilities Proxy ExecutionT1127
  • User ExecutionT1204
  • Windows Management InstrumentationT1047

Persistence0 of 22

  • Account ManipulationT1098
  • BITS JobsT1197
  • Boot or Logon Autostart ExecutionT1547
  • Boot or Logon Initialization ScriptsT1037
  • Cloud Application IntegrationT1671
  • Compromise Host Software BinaryT1554
  • Create AccountT1136
  • Create or Modify System ProcessT1543
  • Event Triggered ExecutionT1546
  • Exclusive ControlT1668
  • External Remote ServicesT1133
  • Implant Internal ImageT1525
  • Modify Authentication ProcessT1556
  • Modify RegistryT1112
  • Office Application StartupT1137
  • Power SettingsT1653
  • Pre-OS BootT1542
  • Scheduled Task/JobT1053
  • Server Software ComponentT1505
  • Software ExtensionsT1176
  • Traffic SignalingT1205
  • Valid AccountsT1078

Privilege Escalation0 of 13

  • Abuse Elevation Control MechanismT1548
  • Access Token ManipulationT1134
  • Account ManipulationT1098
  • Boot or Logon Autostart ExecutionT1547
  • Boot or Logon Initialization ScriptsT1037
  • Create or Modify System ProcessT1543
  • Domain or Tenant Policy ModificationT1484
  • Escape to HostT1611
  • Event Triggered ExecutionT1546
  • Exploitation for Privilege EscalationT1068
  • Process InjectionT1055
  • Scheduled Task/JobT1053
  • Valid AccountsT1078

Stealth0 of 30

  • Access Token ManipulationT1134
  • BITS JobsT1197
  • Build Image on HostT1612
  • Debugger EvasionT1622
  • Delay ExecutionT1678
  • Deobfuscate/Decode Files or InformationT1140
  • Direct Volume AccessT1006
  • Execution GuardrailsT1480
  • Exploitation for StealthT1211
  • Hide ArtifactsT1564
  • Hijack Execution FlowT1574
  • Indicator RemovalT1070
  • Indirect Command ExecutionT1202
  • MasqueradingT1036
  • Obfuscated Files or InformationT1027
  • Pre-OS BootT1542
  • Process InjectionT1055
  • Reflective Code LoadingT1620
  • RootkitT1014
  • Selective ExclusionT1679
  • Social EngineeringT1684
  • System Binary Proxy ExecutionT1218
  • System Script Proxy ExecutionT1216
  • Template InjectionT1221
  • Traffic SignalingT1205
  • Trusted Developer Utilities Proxy ExecutionT1127
  • Unused/Unsupported Cloud RegionsT1535
  • Valid AccountsT1078
  • Virtualization/Sandbox EvasionT1497
  • XSL Script ProcessingT1220

Defense Impairment0 of 18

  • Disable or Modify System FirewallT1686
  • Disable or Modify ToolsT1685
  • Domain or Tenant Policy ModificationT1484
  • Downgrade AttackT1689
  • Exploitation for Defense ImpairmentT1687
  • File and Directory Permissions ModificationT1222
  • Modify Authentication ProcessT1556
  • Modify Cloud Compute InfrastructureT1578
  • Modify Cloud Resource HierarchyT1666
  • Modify RegistryT1112
  • Modify System ImageT1601
  • Network Boundary BridgingT1599
  • Plist File ModificationT1647
  • Prevent Command History LoggingT1690
  • Rogue Domain ControllerT1207
  • Safe Mode BootT1688
  • Subvert Trust ControlsT1553
  • Weaken EncryptionT1600

Credential Access1 of 17

  • Adversary-in-the-MiddleT1557
  • Credentials from Password StoresT1555
  • Exploitation for Credential AccessT1212
  • Forced AuthenticationT1187
  • Forge Web CredentialsT1606
  • Input CaptureT1056
  • Modify Authentication ProcessT1556
  • Multi-Factor Authentication InterceptionT1111
  • Multi-Factor Authentication Request GenerationT1621
  • Network SniffingT1040
  • OS Credential DumpingT1003
  • Steal Application Access TokenT1528
  • Steal or Forge Authentication CertificatesT1649
  • Steal or Forge Kerberos TicketsT1558
  • Steal Web Session CookieT1539
  • Unsecured CredentialsT1552

Discovery1 of 34

  • Account DiscoveryT1087
  • Application Window DiscoveryT1010
  • Browser Information DiscoveryT1217
  • Cloud Infrastructure DiscoveryT1580
  • Cloud Service DashboardT1538
  • Cloud Service DiscoveryT1526
  • Cloud Storage Object DiscoveryT1619
  • Container and Resource DiscoveryT1613
  • Debugger EvasionT1622
  • Device Driver DiscoveryT1652
  • Domain Trust DiscoveryT1482
  • File and Directory DiscoveryT1083
  • Group Policy DiscoveryT1615
  • Local Storage DiscoveryT1680
  • Log EnumerationT1654
  • Network Share DiscoveryT1135
  • Network SniffingT1040
  • Password Policy DiscoveryT1201
  • Peripheral Device DiscoveryT1120
  • Permission Groups DiscoveryT1069
  • Process DiscoveryT1057
  • Query RegistryT1012
  • Remote System DiscoveryT1018
  • Software DiscoveryT1518
  • System Information DiscoveryT1082
  • System Location DiscoveryT1614
  • System Network Configuration DiscoveryT1016
  • System Network Connections DiscoveryT1049
  • System Owner/User DiscoveryT1033
  • System Service DiscoveryT1007
  • System Time DiscoveryT1124
  • Virtual Machine DiscoveryT1673
  • Virtualization/Sandbox EvasionT1497

Lateral Movement0 of 9

  • Exploitation of Remote ServicesT1210
  • Internal SpearphishingT1534
  • Lateral Tool TransferT1570
  • Remote Service Session HijackingT1563
  • Remote ServicesT1021
  • Replication Through Removable MediaT1091
  • Software Deployment ToolsT1072
  • Taint Shared ContentT1080
  • Use Alternate Authentication MaterialT1550

Collection0 of 17

  • Adversary-in-the-MiddleT1557
  • Archive Collected DataT1560
  • Audio CaptureT1123
  • Automated CollectionT1119
  • Browser Session HijackingT1185
  • Clipboard DataT1115
  • Data from Cloud StorageT1530
  • Data from Configuration RepositoryT1602
  • Data from Information RepositoriesT1213
  • Data from Local SystemT1005
  • Data from Network Shared DriveT1039
  • Data from Removable MediaT1025
  • Data StagedT1074
  • Email CollectionT1114
  • Input CaptureT1056
  • Screen CaptureT1113
  • Video CaptureT1125

Command and Control0 of 18

  • Application Layer ProtocolT1071
  • Communication Through Removable MediaT1092
  • Content InjectionT1659
  • Data EncodingT1132
  • Data ObfuscationT1001
  • Dynamic ResolutionT1568
  • Encrypted ChannelT1573
  • Fallback ChannelsT1008
  • Hide InfrastructureT1665
  • Ingress Tool TransferT1105
  • Multi-Stage ChannelsT1104
  • Non-Application Layer ProtocolT1095
  • Non-Standard PortT1571
  • Protocol TunnelingT1572
  • ProxyT1090
  • Remote Access ToolsT1219
  • Traffic SignalingT1205
  • Web ServiceT1102

Exfiltration0 of 9

  • Automated ExfiltrationT1020
  • Data Transfer Size LimitsT1030
  • Exfiltration Over Alternative ProtocolT1048
  • Exfiltration Over C2 ChannelT1041
  • Exfiltration Over Other Network MediumT1011
  • Exfiltration Over Physical MediumT1052
  • Exfiltration Over Web ServiceT1567
  • Scheduled TransferT1029
  • Transfer Data to Cloud AccountT1537

Impact1 of 15

  • Account Access RemovalT1531
  • Data DestructionT1485
  • Data Encrypted for ImpactT1486
  • Data ManipulationT1565
  • DefacementT1491
  • Disk WipeT1561
  • Email BombingT1667
  • Endpoint Denial of ServiceT1499
  • Financial TheftT1657
  • Firmware CorruptionT1495
  • Inhibit System RecoveryT1490
  • Resource HijackingT1496
  • Service StopT1489
  • System Shutdown/RebootT1529
Coverage as a table (8 links)
TechniqueTacticsWorkTypeRelation
T1046 Network Service DiscoveryDiscoveryFederated Learning for Cross-Silo Intrusion Detection (2026)Researchdetects
T1046 Network Service DiscoveryDiscoveryHDSE-IDS: Heterogeneous Deep Stacked Ensemble for Intrusion Detection (2026)Researchdetects
T1110 Brute ForceCredential AccessFederated Learning for Cross-Silo Intrusion Detection (2026)Researchdetects
T1110 Brute ForceCredential AccessHDSE-IDS: Heterogeneous Deep Stacked Ensemble for Intrusion Detection (2026)Researchdetects
T1190 Exploit Public-Facing ApplicationInitial AccessHDSE-IDS: Heterogeneous Deep Stacked Ensemble for Intrusion Detection (2026)Researchdetects
T1498 Network Denial of ServiceImpactFederated Learning for Cross-Silo Intrusion Detection (2026)Researchdetects
T1498 Network Denial of ServiceImpactHDSE-IDS: Heterogeneous Deep Stacked Ensemble for Intrusion Detection (2026)Researchdetects
T1566 PhishingInitial AccessAutomated Threat Report Pipeline (2023)Engineeringstudies

Why map research to ATT&CK

TODO(Q): write the real explanation here.

Technique data from MITRE ATT&CK Enterprise v19.2. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. This site is not affiliated with or endorsed by MITRE.