Interactive research piece
ATT&CK coverage
Where my projects and papers sit on the MITRE ATT&CK Enterprise matrix. Each cell is a technique; a darker cell means more of my work touches it, and the letters say how: D detects, M mitigates, S studies. Select a technique to see the work behind it.
The mappings are my own reading of what each project or paper detects, mitigates, or studies. They are not an assessment by MITRE. Enterprise ATT&CK v19.2.
5 techniques across 4 of 15 tactics, from 3 works.
- 1 work
- 2 works
- 3 or more
- Ddetects
- Mmitigates
- Sstudies
Scroll inside the box to move around the matrix; Shift + wheel scrolls sideways.
Reconnaissance0 of 12
- Active Scanning
- Gather Victim Host Information
- Gather Victim Identity Information
- Gather Victim Network Information
- Gather Victim Org Information
- Phishing for Information
- Query Public AI Services
- Search Closed Sources
- Search Open Technical Databases
- Search Open Websites/Domains
- Search Threat Vendor Data
- Search Victim-Owned Websites
Resource Development0 of 9
- Acquire Access
- Acquire Infrastructure
- Compromise Accounts
- Compromise Infrastructure
- Develop Capabilities
- Establish Accounts
- Generate Content
- Obtain Capabilities
- Stage Capabilities
Initial Access2 of 11
- Content Injection
- Drive-by Compromise
- External Remote Services
- Hardware Additions
- Replication Through Removable Media
- Supply Chain Compromise
- Trusted Relationship
- Valid Accounts
- Wi-Fi Networks
Execution0 of 20
- BITS Jobs
- Cloud Administration Command
- Command and Scripting Interpreter
- Container Administration Command
- Deploy Container
- ESXi Administration Command
- Exploitation for Client Execution
- Hijack Execution Flow
- Input Injection
- Inter-Process Communication
- Native API
- Poisoned Pipeline Execution
- Scheduled Task/Job
- Serverless Execution
- Shared Modules
- Software Deployment Tools
- System Services
- Trusted Developer Utilities Proxy Execution
- User Execution
- Windows Management Instrumentation
Persistence0 of 22
- Account Manipulation
- BITS Jobs
- Boot or Logon Autostart Execution
- Boot or Logon Initialization Scripts
- Cloud Application Integration
- Compromise Host Software Binary
- Create Account
- Create or Modify System Process
- Event Triggered Execution
- Exclusive Control
- External Remote Services
- Implant Internal Image
- Modify Authentication Process
- Modify Registry
- Office Application Startup
- Power Settings
- Pre-OS Boot
- Scheduled Task/Job
- Server Software Component
- Software Extensions
- Traffic Signaling
- Valid Accounts
Privilege Escalation0 of 13
- Abuse Elevation Control Mechanism
- Access Token Manipulation
- Account Manipulation
- Boot or Logon Autostart Execution
- Boot or Logon Initialization Scripts
- Create or Modify System Process
- Domain or Tenant Policy Modification
- Escape to Host
- Event Triggered Execution
- Exploitation for Privilege Escalation
- Process Injection
- Scheduled Task/Job
- Valid Accounts
Stealth0 of 30
- Access Token Manipulation
- BITS Jobs
- Build Image on Host
- Debugger Evasion
- Delay Execution
- Deobfuscate/Decode Files or Information
- Direct Volume Access
- Execution Guardrails
- Exploitation for Stealth
- Hide Artifacts
- Hijack Execution Flow
- Indicator Removal
- Indirect Command Execution
- Masquerading
- Obfuscated Files or Information
- Pre-OS Boot
- Process Injection
- Reflective Code Loading
- Rootkit
- Selective Exclusion
- Social Engineering
- System Binary Proxy Execution
- System Script Proxy Execution
- Template Injection
- Traffic Signaling
- Trusted Developer Utilities Proxy Execution
- Unused/Unsupported Cloud Regions
- Valid Accounts
- Virtualization/Sandbox Evasion
- XSL Script Processing
Defense Impairment0 of 18
- Disable or Modify System Firewall
- Disable or Modify Tools
- Domain or Tenant Policy Modification
- Downgrade Attack
- Exploitation for Defense Impairment
- File and Directory Permissions Modification
- Modify Authentication Process
- Modify Cloud Compute Infrastructure
- Modify Cloud Resource Hierarchy
- Modify Registry
- Modify System Image
- Network Boundary Bridging
- Plist File Modification
- Prevent Command History Logging
- Rogue Domain Controller
- Safe Mode Boot
- Subvert Trust Controls
- Weaken Encryption
Credential Access1 of 17
- Adversary-in-the-Middle
- Credentials from Password Stores
- Exploitation for Credential Access
- Forced Authentication
- Forge Web Credentials
- Input Capture
- Modify Authentication Process
- Multi-Factor Authentication Interception
- Multi-Factor Authentication Request Generation
- Network Sniffing
- OS Credential Dumping
- Steal Application Access Token
- Steal or Forge Authentication Certificates
- Steal or Forge Kerberos Tickets
- Steal Web Session Cookie
- Unsecured Credentials
Discovery1 of 34
- Account Discovery
- Application Window Discovery
- Browser Information Discovery
- Cloud Infrastructure Discovery
- Cloud Service Dashboard
- Cloud Service Discovery
- Cloud Storage Object Discovery
- Container and Resource Discovery
- Debugger Evasion
- Device Driver Discovery
- Domain Trust Discovery
- File and Directory Discovery
- Group Policy Discovery
- Local Storage Discovery
- Log Enumeration
- Network Share Discovery
- Network Sniffing
- Password Policy Discovery
- Peripheral Device Discovery
- Permission Groups Discovery
- Process Discovery
- Query Registry
- Remote System Discovery
- Software Discovery
- System Information Discovery
- System Location Discovery
- System Network Configuration Discovery
- System Network Connections Discovery
- System Owner/User Discovery
- System Service Discovery
- System Time Discovery
- Virtual Machine Discovery
- Virtualization/Sandbox Evasion
Lateral Movement0 of 9
- Exploitation of Remote Services
- Internal Spearphishing
- Lateral Tool Transfer
- Remote Service Session Hijacking
- Remote Services
- Replication Through Removable Media
- Software Deployment Tools
- Taint Shared Content
- Use Alternate Authentication Material
Collection0 of 17
- Adversary-in-the-Middle
- Archive Collected Data
- Audio Capture
- Automated Collection
- Browser Session Hijacking
- Clipboard Data
- Data from Cloud Storage
- Data from Configuration Repository
- Data from Information Repositories
- Data from Local System
- Data from Network Shared Drive
- Data from Removable Media
- Data Staged
- Email Collection
- Input Capture
- Screen Capture
- Video Capture
Command and Control0 of 18
- Application Layer Protocol
- Communication Through Removable Media
- Content Injection
- Data Encoding
- Data Obfuscation
- Dynamic Resolution
- Encrypted Channel
- Fallback Channels
- Hide Infrastructure
- Ingress Tool Transfer
- Multi-Stage Channels
- Non-Application Layer Protocol
- Non-Standard Port
- Protocol Tunneling
- Proxy
- Remote Access Tools
- Traffic Signaling
- Web Service
Exfiltration0 of 9
- Automated Exfiltration
- Data Transfer Size Limits
- Exfiltration Over Alternative Protocol
- Exfiltration Over C2 Channel
- Exfiltration Over Other Network Medium
- Exfiltration Over Physical Medium
- Exfiltration Over Web Service
- Scheduled Transfer
- Transfer Data to Cloud Account
Impact1 of 15
- Account Access Removal
- Data Destruction
- Data Encrypted for Impact
- Data Manipulation
- Defacement
- Disk Wipe
- Email Bombing
- Endpoint Denial of Service
- Financial Theft
- Firmware Corruption
- Inhibit System Recovery
- Resource Hijacking
- Service Stop
- System Shutdown/Reboot
Coverage as a table (8 links)
| Technique | Tactics | Work | Type | Relation |
|---|---|---|---|---|
| T1046 Network Service Discovery | Discovery | Federated Learning for Cross-Silo Intrusion Detection (2026) | Research | detects |
| T1046 Network Service Discovery | Discovery | HDSE-IDS: Heterogeneous Deep Stacked Ensemble for Intrusion Detection (2026) | Research | detects |
| T1110 Brute Force | Credential Access | Federated Learning for Cross-Silo Intrusion Detection (2026) | Research | detects |
| T1110 Brute Force | Credential Access | HDSE-IDS: Heterogeneous Deep Stacked Ensemble for Intrusion Detection (2026) | Research | detects |
| T1190 Exploit Public-Facing Application | Initial Access | HDSE-IDS: Heterogeneous Deep Stacked Ensemble for Intrusion Detection (2026) | Research | detects |
| T1498 Network Denial of Service | Impact | Federated Learning for Cross-Silo Intrusion Detection (2026) | Research | detects |
| T1498 Network Denial of Service | Impact | HDSE-IDS: Heterogeneous Deep Stacked Ensemble for Intrusion Detection (2026) | Research | detects |
| T1566 Phishing | Initial Access | Automated Threat Report Pipeline (2023) | Engineering | studies |
Why map research to ATT&CK
TODO(Q): write the real explanation here.
Technique data from MITRE ATT&CK Enterprise v19.2. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. This site is not affiliated with or endorsed by MITRE.