All frameworks
mitre-attack-enterpriseversion v18.1

MITRE ATT&CK Enterprise

Official source

691 controls.

ReferenceFamilyTitle
T1547.014n/aActive Setup
T1547.015n/aLogin Items
T1548n/aAbuse Elevation Control Mechanism
T1548.001n/aSetuid and Setgid
T1548.002n/aBypass User Account Control
T1548.003n/aSudo and Sudo Caching
T1548.004n/aElevated Execution with Prompt
T1548.005n/aTemporary Elevated Cloud Access
T1548.006n/aTCC Manipulation
T1550n/aUse Alternate Authentication Material
T1550.001n/aApplication Access Token
T1550.002n/aPass the Hash
T1550.003n/aPass the Ticket
T1550.004n/aWeb Session Cookie
T1552n/aUnsecured Credentials
T1552.001n/aCredentials In Files
T1552.002n/aCredentials in Registry
T1552.003n/aShell History
T1552.004n/aPrivate Keys
T1552.005n/aCloud Instance Metadata API
T1552.006n/aGroup Policy Preferences
T1552.007n/aContainer API
T1552.008n/aChat Messages
T1553n/aSubvert Trust Controls
T1553.001n/aGatekeeper Bypass
T1553.002n/aCode Signing
T1553.003n/aSIP and Trust Provider Hijacking
T1553.004n/aInstall Root Certificate
T1553.005n/aMark-of-the-Web Bypass
T1553.006n/aCode Signing Policy Modification
T1554n/aCompromise Host Software Binary
T1555n/aCredentials from Password Stores
T1555.001n/aKeychain
T1555.002n/aSecurityd Memory
T1555.003n/aCredentials from Web Browsers
T1555.004n/aWindows Credential Manager
T1555.005n/aPassword Managers
T1555.006n/aCloud Secrets Management Stores
T1556n/aModify Authentication Process
T1556.001n/aDomain Controller Authentication
T1556.002n/aPassword Filter DLL
T1556.003n/aPluggable Authentication Modules
T1556.004n/aNetwork Device Authentication
T1556.005n/aReversible Encryption
T1556.006n/aMulti-Factor Authentication
T1556.007n/aHybrid Identity
T1556.008n/aNetwork Provider DLL
T1556.009n/aConditional Access Policies
T1557n/aAdversary-in-the-Middle
T1557.001n/aLLMNR/NBT-NS Poisoning and SMB Relay

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.