Top 15 Tactics (MITRE)

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/14

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 8:47 PM on 8/6/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

15 Terms

1
New cards

Reconnaissance

Attacker gathers information about the target environment (org, users, tech stack) to plan operations and identify weaknesses

2
New cards

Resource Development

Attacker acquires, builds, or compromises infrastructure (domains, hosting, VPS, malware, tooling, accounts) that will be used in later stages of the attack

3
New cards

Initial Access

Attacker gains a foothold in the environment (phishing, exploiting public‑facing apps, abusing valid accounts, supply chain, drive‑by compromise)

4
New cards

Execution

Attacker runs malicious code or commands (scripts, binaries, macros, LOLBins) on a system to perform actions or deploy payloads

5
New cards

Persistence

Attacker sets up mechanisms to keep access across reboots, logoffs, and password changes (scheduled tasks, services, startup items, accounts)

6
New cards

Privilege Escalation

Attacker obtains higher‑level permissions (local admin, domain admin, system) by exploiting vulnerabilities, misconfigurations, or credentials

7
New cards

Stealth

Attacker evades detection by hiding activity, blending with normal behavior, and minimizing noise (living off the land, timestomping, log evasion)

8
New cards

Defense Impairment

Attacker disables, bypasses, or tampers with security controls and telemetry (EDR, AV, logging, SIEM, mail security, policies)

9
New cards

Credential Access

Attacker steals or harvests credentials and tokens (keylogging, LSASS dump, password spraying, brute force, phishing, token theft)

10
New cards

Discovery

Attacker maps systems, users, groups, shares, network paths, and directory structure to understand where valuable assets and paths exist

11
New cards

Lateral Movement

Attacker uses existing access and credentials to move to additional hosts, accounts, or segments (RDP, SMB, WinRM, remote services)

12
New cards

Collection

Attacker gathers and stages data of interest (files, emails, databases, screenshots, keylogs) in preparation for exfiltration or impact

13
New cards

Command and Control

Attacker maintains communication with compromised systems using C2 channels (HTTP/S, DNS, TLS, cloud services, custom protocols)

14
New cards

Exfiltration

Attacker moves collected data out of the environment (direct to attacker infrastructure, cloud storage, staged archives, covert channels)

15
New cards

Impact

Attacker disrupts, encrypts, corrupts, or destroys systems and data (ransomware, data wiping, service disruption, business operations damage