IN · In — Initial Foothold 8
UKC-1
Reconnaissance
Researching, identifying and selecting targets using active or passive reconnaissance.
11 ATT&CK techniques · 227 catalogue controls mitigate this phase via Incident response · Patch & vulnerability management · Security awareness & training
UKC-2
Weaponization
Preparing the infrastructure and tooling (e.g. malware, payloads) used to conduct the attack.
8 ATT&CK techniques · 0 catalogue controls mitigate this phase
UKC-3
Delivery
Transmitting the weaponized object to the target environment.
11 ATT&CK techniques · 1,098 catalogue controls mitigate this phase via Access control / least privilege · Asset management & inventory · Boundary firewall & network protection · Cryptography & data protection · Data classification · Identity governance & IAM
UKC-4
Social Engineering
Manipulating people into performing actions that assist the attacker (e.g. phishing, pretexting).
11 ATT&CK techniques · 1,098 catalogue controls mitigate this phase via Access control / least privilege · Asset management & inventory · Boundary firewall & network protection · Cryptography & data protection · Data classification · Identity governance & IAM
UKC-5
Exploitation
Triggering a vulnerability or weakness to execute attacker-controlled code or actions.
17 ATT&CK techniques · 997 catalogue controls mitigate this phase via Access control / least privilege · Asset management & inventory · Boundary firewall & network protection · Data classification · Identity governance & IAM · Incident response
UKC-6
Persistence
Maintaining access to systems across restarts, credential changes and other interruptions.
23 ATT&CK techniques · 958 catalogue controls mitigate this phase via Access control / least privilege · Asset management & inventory · Boundary firewall & network protection · Cryptography & data protection · Data classification · Identity governance & IAM
UKC-7
Defense Evasion
Avoiding detection and bypassing security controls throughout the intrusion.
47 ATT&CK techniques · 1,069 catalogue controls mitigate this phase via Access control / least privilege · Asset management & inventory · Boundary firewall & network protection · Cryptography & data protection · Data classification · Identity governance & IAM
UKC-8
Command & Control
Establishing communication with compromised systems to remotely control them.
18 ATT&CK techniques · 580 catalogue controls mitigate this phase via Access control / least privilege · Asset management & inventory · Boundary firewall & network protection · Logging & monitoring · Malware protection / endpoint · Network segmentation
THR · Through — Network Propagation 6
UKC-9
Pivoting
Tunnelling through a compromised system to reach otherwise unreachable systems.
9 ATT&CK techniques · 915 catalogue controls mitigate this phase via Access control / least privilege · Asset management & inventory · Boundary firewall & network protection · Data classification · Identity governance & IAM · Logging & monitoring
UKC-10
Discovery
Acquiring knowledge of the internal environment, systems, accounts and data.
34 ATT&CK techniques · 867 catalogue controls mitigate this phase via Access control / least privilege · Asset management & inventory · Boundary firewall & network protection · Cryptography & data protection · Data classification · Identity governance & IAM
UKC-11
Privilege Escalation
Obtaining higher-level permissions on systems or within the domain.
14 ATT&CK techniques · 1,051 catalogue controls mitigate this phase via Access control / least privilege · Asset management & inventory · Boundary firewall & network protection · Cryptography & data protection · Data classification · Identity governance & IAM
UKC-12
Execution
Running attacker-controlled code on local or remote systems within the environment.
17 ATT&CK techniques · 997 catalogue controls mitigate this phase via Access control / least privilege · Asset management & inventory · Boundary firewall & network protection · Data classification · Identity governance & IAM · Incident response
UKC-13
Credential Access
Stealing account names, passwords, keys and other credentials.
17 ATT&CK techniques · 1,069 catalogue controls mitigate this phase via Access control / least privilege · Asset management & inventory · Boundary firewall & network protection · Cryptography & data protection · Data classification · Identity governance & IAM
UKC-14
Lateral Movement
Moving through the environment by using legitimate access and compromised credentials.
9 ATT&CK techniques · 915 catalogue controls mitigate this phase via Access control / least privilege · Asset management & inventory · Boundary firewall & network protection · Data classification · Identity governance & IAM · Logging & monitoring
OUT · Out — Action on Objectives 4
UKC-15
Collection
Gathering data of interest from the target environment in preparation for exfiltration.
17 ATT&CK techniques · 1,110 catalogue controls mitigate this phase via Access control / least privilege · Asset management & inventory · Boundary firewall & network protection · Cryptography & data protection · Data classification · Identity governance & IAM
UKC-16
Exfiltration
Stealing data by transferring it out of the target environment.
9 ATT&CK techniques · 608 catalogue controls mitigate this phase via Access control / least privilege · Asset management & inventory · Boundary firewall & network protection · Identity governance & IAM · Logging & monitoring · Malware protection / endpoint
UKC-17
Impact
Manipulating, interrupting or destroying systems and data (e.g. ransomware, sabotage).
15 ATT&CK techniques · 763 catalogue controls mitigate this phase via Access control / least privilege · Asset management & inventory · Boundary firewall & network protection · Cryptography & data protection · Data classification · Identity governance & IAM
UKC-18
Objectives
Achieving the strategic goal that motivated the attack (the attacker's end objective).
15 ATT&CK techniques · 763 catalogue controls mitigate this phase via Access control / least privilege · Asset management & inventory · Boundary firewall & network protection · Cryptography & data protection · Data classification · Identity governance & IAM