Security Command Center V2 API - Module Google::Cloud::SecurityCenter::V2::MitreAttack::Technique (v1.3.0)

Reference documentation and code samples for the Security Command Center V2 API module Google::Cloud::SecurityCenter::V2::MitreAttack::Technique.

MITRE ATT&CK techniques that can be referenced by Security Command Center findings. See: https://attack.mitre.org/techniques/enterprise/

Constants

TECHNIQUE_UNSPECIFIED

value: 0
Unspecified value.

DATA_OBFUSCATION

value: 70
T1001

DATA_OBFUSCATION_STEGANOGRAPHY

value: 71
T1001.002

OS_CREDENTIAL_DUMPING

value: 114
T1003

OS_CREDENTIAL_DUMPING_PROC_FILESYSTEM

value: 115
T1003.007

OS_CREDENTIAL_DUMPING_ETC_PASSWORD_AND_ETC_SHADOW

value: 122
T1003.008

DATA_FROM_LOCAL_SYSTEM

value: 117
T1005

AUTOMATED_EXFILTRATION

value: 68
T1020

OBFUSCATED_FILES_OR_INFO

value: 72
T1027

STEGANOGRAPHY

value: 73
T1027.003

COMPILE_AFTER_DELIVERY

value: 74
T1027.004

COMMAND_OBFUSCATION

value: 75
T1027.010

SCHEDULED_TRANSFER

value: 120
T1029

SYSTEM_OWNER_USER_DISCOVERY

value: 118
T1033

MASQUERADING

value: 49
T1036

MATCH_LEGITIMATE_NAME_OR_LOCATION

value: 50
T1036.005

BOOT_OR_LOGON_INITIALIZATION_SCRIPTS

value: 37
T1037

STARTUP_ITEMS

value: 38
T1037.005

NETWORK_SERVICE_DISCOVERY

value: 32
T1046

SCHEDULED_TASK_JOB

value: 89
T1053

SCHEDULED_TASK_JOB_CRON

value: 119
T1053.003

CONTAINER_ORCHESTRATION_JOB

value: 90
T1053.007

PROCESS_INJECTION

value: 93
T1055

INPUT_CAPTURE

value: 103
T1056

INPUT_CAPTURE_KEYLOGGING

value: 104
T1056.001

PROCESS_DISCOVERY

value: 56
T1057

COMMAND_AND_SCRIPTING_INTERPRETER

value: 6
T1059

UNIX_SHELL

value: 7
T1059.004

PYTHON

value: 59
T1059.006

EXPLOITATION_FOR_PRIVILEGE_ESCALATION

value: 63
T1068

PERMISSION_GROUPS_DISCOVERY

value: 18
T1069

CLOUD_GROUPS

value: 19
T1069.003

INDICATOR_REMOVAL

value: 123
T1070

INDICATOR_REMOVAL_CLEAR_LINUX_OR_MAC_SYSTEM_LOGS

value: 124
T1070.002

INDICATOR_REMOVAL_CLEAR_COMMAND_HISTORY

value: 125
T1070.003

INDICATOR_REMOVAL_FILE_DELETION

value: 64
T1070.004

INDICATOR_REMOVAL_TIMESTOMP

value: 128
T1070.006

INDICATOR_REMOVAL_CLEAR_MAILBOX_DATA

value: 126
T1070.008

APPLICATION_LAYER_PROTOCOL

value: 45
T1071

DNS

value: 46
T1071.004

SOFTWARE_DEPLOYMENT_TOOLS

value: 47
T1072

VALID_ACCOUNTS

value: 14
T1078

DEFAULT_ACCOUNTS

value: 35
T1078.001

LOCAL_ACCOUNTS

value: 15
T1078.003

CLOUD_ACCOUNTS

value: 16
T1078.004

FILE_AND_DIRECTORY_DISCOVERY

value: 121
T1083

ACCOUNT_DISCOVERY_LOCAL_ACCOUNT

value: 116
T1087.001

PROXY

value: 9
T1090

EXTERNAL_PROXY

value: 10
T1090.002

MULTI_HOP_PROXY

value: 11
T1090.003

ACCOUNT_MANIPULATION

value: 22
T1098

ADDITIONAL_CLOUD_CREDENTIALS

value: 40
T1098.001

ADDITIONAL_CLOUD_ROLES

value: 67
T1098.003

SSH_AUTHORIZED_KEYS

value: 23
T1098.004

ADDITIONAL_CONTAINER_CLUSTER_ROLES

value: 58
T1098.006

MULTI_STAGE_CHANNELS

value: 76
T1104

INGRESS_TOOL_TRANSFER

value: 3
T1105

NATIVE_API

value: 4
T1106

BRUTE_FORCE

value: 44
T1110

AUTOMATED_COLLECTION

value: 94
T1119

SHARED_MODULES

value: 5
T1129

DATA_ENCODING

value: 77
T1132

STANDARD_ENCODING

value: 78
T1132.001

ACCESS_TOKEN_MANIPULATION

value: 33
T1134

TOKEN_IMPERSONATION_OR_THEFT

value: 39
T1134.001

CREATE_ACCOUNT

value: 79
T1136

LOCAL_ACCOUNT

value: 80
T1136.001

DEOBFUSCATE_DECODE_FILES_OR_INFO

value: 95
T1140

EXPLOIT_PUBLIC_FACING_APPLICATION

value: 27
T1190

SUPPLY_CHAIN_COMPROMISE

value: 129
T1195

COMPROMISE_SOFTWARE_DEPENDENCIES_AND_DEVELOPMENT_TOOLS

value: 130
T1195.001

EXPLOITATION_FOR_CLIENT_EXECUTION

value: 134
T1203

USER_EXECUTION

value: 69
T1204

LINUX_AND_MAC_FILE_AND_DIRECTORY_PERMISSIONS_MODIFICATION

value: 135
T1222.002

DOMAIN_POLICY_MODIFICATION

value: 30
T1484

DATA_DESTRUCTION

value: 29
T1485

DATA_ENCRYPTED_FOR_IMPACT

value: 132
T1486

SERVICE_STOP

value: 52
T1489

INHIBIT_SYSTEM_RECOVERY

value: 36
T1490

FIRMWARE_CORRUPTION

value: 81
T1495

RESOURCE_HIJACKING

value: 8
T1496

NETWORK_DENIAL_OF_SERVICE

value: 17
T1498

CLOUD_SERVICE_DISCOVERY

value: 48
T1526

STEAL_APPLICATION_ACCESS_TOKEN

value: 42
T1528

ACCOUNT_ACCESS_REMOVAL

value: 51
T1531

TRANSFER_DATA_TO_CLOUD_ACCOUNT

value: 91
T1537

value: 25
T1539

CREATE_OR_MODIFY_SYSTEM_PROCESS

value: 24
T1543

EVENT_TRIGGERED_EXECUTION

value: 65
T1546

BOOT_OR_LOGON_AUTOSTART_EXECUTION

value: 82
T1547

KERNEL_MODULES_AND_EXTENSIONS

value: 83
T1547.006

SHORTCUT_MODIFICATION

value: 127
T1547.009

ABUSE_ELEVATION_CONTROL_MECHANISM

value: 34
T1548

ABUSE_ELEVATION_CONTROL_MECHANISM_SETUID_AND_SETGID

value: 136
T1548.001

ABUSE_ELEVATION_CONTROL_MECHANISM_SUDO_AND_SUDO_CACHING

value: 109
T1548.003

UNSECURED_CREDENTIALS

value: 13
T1552

CREDENTIALS_IN_FILES

value: 105
T1552.001

BASH_HISTORY

value: 96
T1552.003

PRIVATE_KEYS

value: 97
T1552.004

SUBVERT_TRUST_CONTROL

value: 106
T1553

INSTALL_ROOT_CERTIFICATE

value: 107
T1553.004

COMPROMISE_HOST_SOFTWARE_BINARY

value: 84
T1554

CREDENTIALS_FROM_PASSWORD_STORES

value: 98
T1555

MODIFY_AUTHENTICATION_PROCESS

value: 28
T1556

PLUGGABLE_AUTHENTICATION_MODULES

value: 108
T1556.003

MULTI_FACTOR_AUTHENTICATION

value: 137
T1556.006

IMPAIR_DEFENSES

value: 31
T1562

DISABLE_OR_MODIFY_TOOLS

value: 55
T1562.001

INDICATOR_BLOCKING

value: 110
T1562.006

DISABLE_OR_MODIFY_LINUX_AUDIT_SYSTEM

value: 111
T1562.012

HIDE_ARTIFACTS

value: 85
T1564

HIDDEN_FILES_AND_DIRECTORIES

value: 86
T1564.001

HIDDEN_USERS

value: 87
T1564.002

EXFILTRATION_OVER_WEB_SERVICE

value: 20
T1567

EXFILTRATION_TO_CLOUD_STORAGE

value: 21
T1567.002

DYNAMIC_RESOLUTION

value: 12
T1568

LATERAL_TOOL_TRANSFER

value: 41
T1570

HIJACK_EXECUTION_FLOW

value: 112
T1574

HIJACK_EXECUTION_FLOW_DYNAMIC_LINKER_HIJACKING

value: 113
T1574.006

MODIFY_CLOUD_COMPUTE_INFRASTRUCTURE

value: 26
T1578

CREATE_SNAPSHOT

value: 54
T1578.001

CLOUD_INFRASTRUCTURE_DISCOVERY

value: 53
T1580

DEVELOP_CAPABILITIES

value: 99
T1587

DEVELOP_CAPABILITIES_MALWARE

value: 100
T1587.001

OBTAIN_CAPABILITIES

value: 43
T1588

OBTAIN_CAPABILITIES_MALWARE

value: 101
T1588.001

OBTAIN_CAPABILITIES_VULNERABILITIES

value: 133
T1588.006

ACTIVE_SCANNING

value: 1
T1595

SCANNING_IP_BLOCKS

value: 2
T1595.001

STAGE_CAPABILITIES

value: 88
T1608

UPLOAD_MALWARE

value: 102
T1608.001

CONTAINER_ADMINISTRATION_COMMAND

value: 60
T1609

DEPLOY_CONTAINER

value: 66
T1610

ESCAPE_TO_HOST

value: 61
T1611

CONTAINER_AND_RESOURCE_DISCOVERY

value: 57
T1613

REFLECTIVE_CODE_LOADING

value: 92
T1620

STEAL_OR_FORGE_AUTHENTICATION_CERTIFICATES

value: 62
T1649

FINANCIAL_THEFT

value: 131
T1657