| ID | Technique Name | Tactic | Sub-Techniques |
|---|
Reconnaissance (TA0043)
Gathering information to plan future adversary operations — scanning, phishing for info, OSINT. Maps to CIS Control 7 & CISSP Domain 6.
Resource Development (TA0042)
Establishing resources to support operations — acquiring infrastructure, malware development. Maps to CIS Control 4 & CISSP Domain 3.
Initial Access (TA0001)
Gaining a foothold in the network — phishing, exploiting public-facing apps, supply chain. Maps to CIS Controls 9,10 & CISSP Domain 4.
Execution (TA0002)
Running malicious code — scripts, WMI, scheduled tasks, user execution. Maps to CIS Controls 2,4 & CISSP Domain 7.
Persistence (TA0003)
Maintaining a foothold across restarts — boot/logon autostart, account manipulation. Maps to CIS Control 5 & CISSP Domain 5.
Privilege Escalation (TA0004)
Gaining higher-level permissions — abuse elevation control, process injection. Maps to CIS Control 6 & CISSP Domain 5.
Defense Evasion (TA0005)
Avoiding detection — obfuscation, disabling security tools, masquerading. Maps to CIS Controls 8,10 & CISSP Domain 7.
Credential Access (TA0006)
Stealing credentials — brute force, credential dumping, keylogging. Maps to CIS Controls 4,5 & CISSP Domain 5.
Discovery (TA0007)
Environment reconnaissance post-compromise — account discovery, network scanning. Maps to CIS Control 13 & CISSP Domain 4.
Lateral Movement (TA0008)
Pivoting through the environment — remote services, pass-the-hash. Maps to CIS Controls 4,13 & CISSP Domain 4.
Collection (TA0009)
Gathering data of interest — clipboard data, email, screen capture. Maps to CIS Controls 3,13 & CISSP Domain 2.
Command & Control (TA0011)
Communicating with compromised systems — encrypted channels, domain fronting. Maps to CIS Control 13 & CISSP Domain 4.
Exfiltration (TA0010)
Stealing data — over C2, cloud storage, physical medium. Maps to CIS Controls 3,13 & CISSP Domain 2.
Impact (TA0040)
Disrupting availability or integrity — ransomware, defacement, data destruction. Maps to CIS Control 11 & CISSP Domain 7.