Created
June 3, 2025 01:55
-
-
Save hisashiyamaguchi/1e8fb1a16e90245f24064611d31a85c8 to your computer and use it in GitHub Desktop.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| { | |
| "name": "heatmap example", | |
| "versions": { | |
| "attack": "17", | |
| "navigator": "5.1.0", | |
| "layer": "4.5" | |
| }, | |
| "domain": "enterprise-attack", | |
| "description": "An example layer where all techniques have a randomized score", | |
| "filters": { | |
| "platforms": [ | |
| "Windows", | |
| "Linux", | |
| "macOS", | |
| "Network Devices", | |
| "ESXi", | |
| "PRE", | |
| "Containers", | |
| "IaaS", | |
| "SaaS", | |
| "Office Suite", | |
| "Identity Provider" | |
| ] | |
| }, | |
| "sorting": 3, | |
| "layout": { | |
| "layout": "side", | |
| "aggregateFunction": "average", | |
| "showID": false, | |
| "showName": true, | |
| "showAggregateScores": false, | |
| "countUnscored": false, | |
| "expandedSubtechniques": "none" | |
| }, | |
| "hideDisabled": false, | |
| "techniques": [ | |
| { | |
| "techniqueID": "T1546.004", | |
| "tactic": "privilege-escalation", | |
| "score": 20, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.004", | |
| "tactic": "persistence", | |
| "score": 20, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1003.008", | |
| "tactic": "credential-access", | |
| "score": 46, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1548", | |
| "tactic": "privilege-escalation", | |
| "score": 77, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1548", | |
| "tactic": "defense-evasion", | |
| "score": 77, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1134", | |
| "tactic": "defense-evasion", | |
| "score": 44, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1134", | |
| "tactic": "privilege-escalation", | |
| "score": 44, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.008", | |
| "tactic": "privilege-escalation", | |
| "score": 57, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.008", | |
| "tactic": "persistence", | |
| "score": 57, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1531", | |
| "tactic": "impact", | |
| "score": 37, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1087", | |
| "tactic": "discovery", | |
| "score": 7, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1098", | |
| "tactic": "persistence", | |
| "score": 17, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1098", | |
| "tactic": "privilege-escalation", | |
| "score": 17, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1098.003", | |
| "tactic": "persistence", | |
| "score": 8, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1098.003", | |
| "tactic": "privilege-escalation", | |
| "score": 8, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1137.006", | |
| "tactic": "persistence", | |
| "score": 1, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1098.001", | |
| "tactic": "persistence", | |
| "score": 22, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1098.001", | |
| "tactic": "privilege-escalation", | |
| "score": 22, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.009", | |
| "tactic": "privilege-escalation", | |
| "score": 97, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.009", | |
| "tactic": "persistence", | |
| "score": 97, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.010", | |
| "tactic": "privilege-escalation", | |
| "score": 7, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.010", | |
| "tactic": "persistence", | |
| "score": 7, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1059.002", | |
| "tactic": "execution", | |
| "score": 87, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1550.001", | |
| "tactic": "defense-evasion", | |
| "score": 25, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1550.001", | |
| "tactic": "lateral-movement", | |
| "score": 25, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1499.003", | |
| "tactic": "impact", | |
| "score": 52, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1071", | |
| "tactic": "command-and-control", | |
| "score": 41, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.011", | |
| "tactic": "privilege-escalation", | |
| "score": 46, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.011", | |
| "tactic": "persistence", | |
| "score": 46, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1010", | |
| "tactic": "discovery", | |
| "score": 84, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1499.004", | |
| "tactic": "impact", | |
| "score": 55, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1560", | |
| "tactic": "collection", | |
| "score": 37, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1560.003", | |
| "tactic": "collection", | |
| "score": 49, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1560.002", | |
| "tactic": "collection", | |
| "score": 47, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1560.001", | |
| "tactic": "collection", | |
| "score": 80, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1573.002", | |
| "tactic": "command-and-control", | |
| "score": 85, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1055.004", | |
| "tactic": "defense-evasion", | |
| "score": 68, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1055.004", | |
| "tactic": "privilege-escalation", | |
| "score": 68, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1053.002", | |
| "tactic": "execution", | |
| "score": 13, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1053.002", | |
| "tactic": "persistence", | |
| "score": 13, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1053.002", | |
| "tactic": "privilege-escalation", | |
| "score": 13, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1123", | |
| "tactic": "collection", | |
| "score": 5, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1547.002", | |
| "tactic": "persistence", | |
| "score": 42, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1547.002", | |
| "tactic": "privilege-escalation", | |
| "score": 42, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1119", | |
| "tactic": "collection", | |
| "score": 66, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1020", | |
| "tactic": "exfiltration", | |
| "score": 85, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1197", | |
| "tactic": "defense-evasion", | |
| "score": 54, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1197", | |
| "tactic": "persistence", | |
| "score": 54, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1552.003", | |
| "tactic": "credential-access", | |
| "score": 70, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1102.002", | |
| "tactic": "command-and-control", | |
| "score": 79, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1027.001", | |
| "tactic": "defense-evasion", | |
| "score": 40, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1547", | |
| "tactic": "persistence", | |
| "score": 49, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1547", | |
| "tactic": "privilege-escalation", | |
| "score": 49, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1037", | |
| "tactic": "persistence", | |
| "score": 43, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1037", | |
| "tactic": "privilege-escalation", | |
| "score": 43, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1542.003", | |
| "tactic": "persistence", | |
| "score": 63, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1542.003", | |
| "tactic": "defense-evasion", | |
| "score": 63, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1217", | |
| "tactic": "discovery", | |
| "score": 3, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1176", | |
| "tactic": "persistence", | |
| "score": 78, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1110", | |
| "tactic": "credential-access", | |
| "score": 95, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1548.002", | |
| "tactic": "privilege-escalation", | |
| "score": 95, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1548.002", | |
| "tactic": "defense-evasion", | |
| "score": 95, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1218.003", | |
| "tactic": "defense-evasion", | |
| "score": 90, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.012", | |
| "tactic": "persistence", | |
| "score": 40, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.012", | |
| "tactic": "privilege-escalation", | |
| "score": 40, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.012", | |
| "tactic": "defense-evasion", | |
| "score": 40, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1003.005", | |
| "tactic": "credential-access", | |
| "score": 5, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.001", | |
| "tactic": "privilege-escalation", | |
| "score": 90, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.001", | |
| "tactic": "persistence", | |
| "score": 90, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1070.003", | |
| "tactic": "defense-evasion", | |
| "score": 100, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1070.002", | |
| "tactic": "defense-evasion", | |
| "score": 87, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1070.001", | |
| "tactic": "defense-evasion", | |
| "score": 43, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1115", | |
| "tactic": "collection", | |
| "score": 15, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1136.003", | |
| "tactic": "persistence", | |
| "score": 28, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1087.004", | |
| "tactic": "discovery", | |
| "score": 55, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1078.004", | |
| "tactic": "defense-evasion", | |
| "score": 12, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1078.004", | |
| "tactic": "persistence", | |
| "score": 12, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1078.004", | |
| "tactic": "privilege-escalation", | |
| "score": 12, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1078.004", | |
| "tactic": "initial-access", | |
| "score": 12, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1069.003", | |
| "tactic": "discovery", | |
| "score": 31, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1552.005", | |
| "tactic": "credential-access", | |
| "score": 38, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1538", | |
| "tactic": "discovery", | |
| "score": 15, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1526", | |
| "tactic": "discovery", | |
| "score": 72, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1553.002", | |
| "tactic": "defense-evasion", | |
| "score": 75, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1059", | |
| "tactic": "execution", | |
| "score": 99, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1092", | |
| "tactic": "command-and-control", | |
| "score": 94, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1027.004", | |
| "tactic": "defense-evasion", | |
| "score": 43, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1218.001", | |
| "tactic": "defense-evasion", | |
| "score": 28, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1542.002", | |
| "tactic": "persistence", | |
| "score": 28, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1542.002", | |
| "tactic": "defense-evasion", | |
| "score": 28, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1559.001", | |
| "tactic": "execution", | |
| "score": 70, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.015", | |
| "tactic": "privilege-escalation", | |
| "score": 1, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.015", | |
| "tactic": "persistence", | |
| "score": 1, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1554", | |
| "tactic": "persistence", | |
| "score": 94, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1195.003", | |
| "tactic": "initial-access", | |
| "score": 67, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1195.001", | |
| "tactic": "initial-access", | |
| "score": 58, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1195.002", | |
| "tactic": "initial-access", | |
| "score": 46, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1213.001", | |
| "tactic": "collection", | |
| "score": 63, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1218.002", | |
| "tactic": "defense-evasion", | |
| "score": 97, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1136", | |
| "tactic": "persistence", | |
| "score": 99, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1578.002", | |
| "tactic": "defense-evasion", | |
| "score": 99, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1134.002", | |
| "tactic": "defense-evasion", | |
| "score": 82, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1134.002", | |
| "tactic": "privilege-escalation", | |
| "score": 82, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1578.001", | |
| "tactic": "defense-evasion", | |
| "score": 28, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1543", | |
| "tactic": "persistence", | |
| "score": 100, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1543", | |
| "tactic": "privilege-escalation", | |
| "score": 100, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1056.004", | |
| "tactic": "collection", | |
| "score": 94, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1056.004", | |
| "tactic": "credential-access", | |
| "score": 94, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1110.004", | |
| "tactic": "credential-access", | |
| "score": 77, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1552.001", | |
| "tactic": "credential-access", | |
| "score": 26, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1555", | |
| "tactic": "credential-access", | |
| "score": 100, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1555.003", | |
| "tactic": "credential-access", | |
| "score": 2, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1552.002", | |
| "tactic": "credential-access", | |
| "score": 40, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1053.003", | |
| "tactic": "execution", | |
| "score": 62, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1053.003", | |
| "tactic": "persistence", | |
| "score": 62, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1053.003", | |
| "tactic": "privilege-escalation", | |
| "score": 62, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1003.006", | |
| "tactic": "credential-access", | |
| "score": 79, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.001", | |
| "tactic": "persistence", | |
| "score": 49, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.001", | |
| "tactic": "privilege-escalation", | |
| "score": 49, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.001", | |
| "tactic": "defense-evasion", | |
| "score": 49, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1071.004", | |
| "tactic": "command-and-control", | |
| "score": 43, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1568.003", | |
| "tactic": "command-and-control", | |
| "score": 18, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1485", | |
| "tactic": "impact", | |
| "score": 75, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1132", | |
| "tactic": "command-and-control", | |
| "score": 52, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1486", | |
| "tactic": "impact", | |
| "score": 60, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1565", | |
| "tactic": "impact", | |
| "score": 40, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1001", | |
| "tactic": "command-and-control", | |
| "score": 19, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1074", | |
| "tactic": "collection", | |
| "score": 54, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1030", | |
| "tactic": "exfiltration", | |
| "score": 17, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1530", | |
| "tactic": "collection", | |
| "score": 17, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1213", | |
| "tactic": "collection", | |
| "score": 36, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1005", | |
| "tactic": "collection", | |
| "score": 18, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1039", | |
| "tactic": "collection", | |
| "score": 29, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1025", | |
| "tactic": "collection", | |
| "score": 16, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1102.001", | |
| "tactic": "command-and-control", | |
| "score": 94, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1491", | |
| "tactic": "impact", | |
| "score": 13, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1078.001", | |
| "tactic": "defense-evasion", | |
| "score": 96, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1078.001", | |
| "tactic": "persistence", | |
| "score": 96, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1078.001", | |
| "tactic": "privilege-escalation", | |
| "score": 96, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1078.001", | |
| "tactic": "initial-access", | |
| "score": 96, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1578.003", | |
| "tactic": "defense-evasion", | |
| "score": 60, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1140", | |
| "tactic": "defense-evasion", | |
| "score": 67, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1498.001", | |
| "tactic": "impact", | |
| "score": 54, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1006", | |
| "tactic": "defense-evasion", | |
| "score": 60, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1562.002", | |
| "tactic": "defense-evasion", | |
| "score": 31, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1562.007", | |
| "tactic": "defense-evasion", | |
| "score": 2, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1562.004", | |
| "tactic": "defense-evasion", | |
| "score": 84, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1562.001", | |
| "tactic": "defense-evasion", | |
| "score": 74, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1561.001", | |
| "tactic": "impact", | |
| "score": 40, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1561.002", | |
| "tactic": "impact", | |
| "score": 26, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1561", | |
| "tactic": "impact", | |
| "score": 11, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1021.003", | |
| "tactic": "lateral-movement", | |
| "score": 54, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1136.002", | |
| "tactic": "persistence", | |
| "score": 92, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1087.002", | |
| "tactic": "discovery", | |
| "score": 5, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1078.002", | |
| "tactic": "defense-evasion", | |
| "score": 63, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1078.002", | |
| "tactic": "persistence", | |
| "score": 63, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1078.002", | |
| "tactic": "privilege-escalation", | |
| "score": 63, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1078.002", | |
| "tactic": "initial-access", | |
| "score": 63, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1556.001", | |
| "tactic": "credential-access", | |
| "score": 45, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1556.001", | |
| "tactic": "defense-evasion", | |
| "score": 45, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1556.001", | |
| "tactic": "persistence", | |
| "score": 45, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1090.004", | |
| "tactic": "command-and-control", | |
| "score": 4, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1568.002", | |
| "tactic": "command-and-control", | |
| "score": 40, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1069.002", | |
| "tactic": "discovery", | |
| "score": 16, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1482", | |
| "tactic": "discovery", | |
| "score": 85, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1189", | |
| "tactic": "initial-access", | |
| "score": 33, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.004", | |
| "tactic": "persistence", | |
| "score": 23, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.004", | |
| "tactic": "privilege-escalation", | |
| "score": 23, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.004", | |
| "tactic": "defense-evasion", | |
| "score": 23, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1559.002", | |
| "tactic": "execution", | |
| "score": 64, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1568", | |
| "tactic": "command-and-control", | |
| "score": 22, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1055.001", | |
| "tactic": "defense-evasion", | |
| "score": 23, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1055.001", | |
| "tactic": "privilege-escalation", | |
| "score": 23, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1548.004", | |
| "tactic": "privilege-escalation", | |
| "score": 86, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1548.004", | |
| "tactic": "defense-evasion", | |
| "score": 86, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1087.003", | |
| "tactic": "discovery", | |
| "score": 37, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1114", | |
| "tactic": "collection", | |
| "score": 72, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1114.003", | |
| "tactic": "collection", | |
| "score": 77, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.014", | |
| "tactic": "privilege-escalation", | |
| "score": 95, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.014", | |
| "tactic": "persistence", | |
| "score": 95, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1573", | |
| "tactic": "command-and-control", | |
| "score": 60, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1499", | |
| "tactic": "impact", | |
| "score": 26, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1480.001", | |
| "tactic": "defense-evasion", | |
| "score": 99, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546", | |
| "tactic": "privilege-escalation", | |
| "score": 43, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546", | |
| "tactic": "persistence", | |
| "score": 43, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1098.002", | |
| "tactic": "persistence", | |
| "score": 92, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1098.002", | |
| "tactic": "privilege-escalation", | |
| "score": 92, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.005", | |
| "tactic": "persistence", | |
| "score": 7, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.005", | |
| "tactic": "privilege-escalation", | |
| "score": 7, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.005", | |
| "tactic": "defense-evasion", | |
| "score": 7, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1480", | |
| "tactic": "defense-evasion", | |
| "score": 4, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1048", | |
| "tactic": "exfiltration", | |
| "score": 16, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1048.002", | |
| "tactic": "exfiltration", | |
| "score": 98, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1011.001", | |
| "tactic": "exfiltration", | |
| "score": 40, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1041", | |
| "tactic": "exfiltration", | |
| "score": 18, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1011", | |
| "tactic": "exfiltration", | |
| "score": 100, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1052", | |
| "tactic": "exfiltration", | |
| "score": 97, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1048.001", | |
| "tactic": "exfiltration", | |
| "score": 40, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1048.003", | |
| "tactic": "exfiltration", | |
| "score": 46, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1567", | |
| "tactic": "exfiltration", | |
| "score": 18, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1052.001", | |
| "tactic": "exfiltration", | |
| "score": 99, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1567.002", | |
| "tactic": "exfiltration", | |
| "score": 75, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1567.001", | |
| "tactic": "exfiltration", | |
| "score": 27, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1190", | |
| "tactic": "initial-access", | |
| "score": 39, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1203", | |
| "tactic": "execution", | |
| "score": 99, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1212", | |
| "tactic": "credential-access", | |
| "score": 47, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1211", | |
| "tactic": "defense-evasion", | |
| "score": 57, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1068", | |
| "tactic": "privilege-escalation", | |
| "score": 89, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1210", | |
| "tactic": "lateral-movement", | |
| "score": 59, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1491.002", | |
| "tactic": "impact", | |
| "score": 28, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1090.002", | |
| "tactic": "command-and-control", | |
| "score": 20, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1133", | |
| "tactic": "persistence", | |
| "score": 52, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1133", | |
| "tactic": "initial-access", | |
| "score": 52, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1055.011", | |
| "tactic": "defense-evasion", | |
| "score": 61, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1055.011", | |
| "tactic": "privilege-escalation", | |
| "score": 61, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1008", | |
| "tactic": "command-and-control", | |
| "score": 57, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1568.001", | |
| "tactic": "command-and-control", | |
| "score": 73, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1070.004", | |
| "tactic": "defense-evasion", | |
| "score": 78, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1071.002", | |
| "tactic": "command-and-control", | |
| "score": 12, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1083", | |
| "tactic": "discovery", | |
| "score": 84, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1222", | |
| "tactic": "defense-evasion", | |
| "score": 56, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1495", | |
| "tactic": "impact", | |
| "score": 5, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1187", | |
| "tactic": "credential-access", | |
| "score": 53, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1056.002", | |
| "tactic": "collection", | |
| "score": 11, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1056.002", | |
| "tactic": "credential-access", | |
| "score": 11, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1553.001", | |
| "tactic": "defense-evasion", | |
| "score": 67, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1558.001", | |
| "tactic": "credential-access", | |
| "score": 62, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1484", | |
| "tactic": "defense-evasion", | |
| "score": 94, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1484", | |
| "tactic": "privilege-escalation", | |
| "score": 94, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1552.006", | |
| "tactic": "credential-access", | |
| "score": 61, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1562.003", | |
| "tactic": "defense-evasion", | |
| "score": 4, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1200", | |
| "tactic": "initial-access", | |
| "score": 30, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1564.005", | |
| "tactic": "defense-evasion", | |
| "score": 97, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1564.001", | |
| "tactic": "defense-evasion", | |
| "score": 17, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1564.002", | |
| "tactic": "defense-evasion", | |
| "score": 84, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1564.003", | |
| "tactic": "defense-evasion", | |
| "score": 78, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1564", | |
| "tactic": "defense-evasion", | |
| "score": 98, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574", | |
| "tactic": "persistence", | |
| "score": 58, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574", | |
| "tactic": "privilege-escalation", | |
| "score": 58, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574", | |
| "tactic": "defense-evasion", | |
| "score": 58, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.012", | |
| "tactic": "privilege-escalation", | |
| "score": 14, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.012", | |
| "tactic": "persistence", | |
| "score": 14, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1562", | |
| "tactic": "defense-evasion", | |
| "score": 32, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1525", | |
| "tactic": "persistence", | |
| "score": 12, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1562.006", | |
| "tactic": "defense-evasion", | |
| "score": 68, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1027.005", | |
| "tactic": "defense-evasion", | |
| "score": 24, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1070", | |
| "tactic": "defense-evasion", | |
| "score": 60, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1202", | |
| "tactic": "defense-evasion", | |
| "score": 76, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1105", | |
| "tactic": "command-and-control", | |
| "score": 44, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1490", | |
| "tactic": "impact", | |
| "score": 90, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1056", | |
| "tactic": "collection", | |
| "score": 5, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1056", | |
| "tactic": "credential-access", | |
| "score": 5, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1553.004", | |
| "tactic": "defense-evasion", | |
| "score": 69, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1218.004", | |
| "tactic": "defense-evasion", | |
| "score": 4, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1559", | |
| "tactic": "execution", | |
| "score": 96, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1491.001", | |
| "tactic": "impact", | |
| "score": 82, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1090.001", | |
| "tactic": "command-and-control", | |
| "score": 15, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1534", | |
| "tactic": "lateral-movement", | |
| "score": 11, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1036.001", | |
| "tactic": "defense-evasion", | |
| "score": 86, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1059.007", | |
| "tactic": "execution", | |
| "score": 84, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1001.001", | |
| "tactic": "command-and-control", | |
| "score": 63, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1558.003", | |
| "tactic": "credential-access", | |
| "score": 12, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1547.006", | |
| "tactic": "persistence", | |
| "score": 63, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1547.006", | |
| "tactic": "privilege-escalation", | |
| "score": 63, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1555.001", | |
| "tactic": "credential-access", | |
| "score": 88, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1056.001", | |
| "tactic": "collection", | |
| "score": 87, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1056.001", | |
| "tactic": "credential-access", | |
| "score": 87, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.006", | |
| "tactic": "privilege-escalation", | |
| "score": 53, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.006", | |
| "tactic": "persistence", | |
| "score": 53, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.006", | |
| "tactic": "persistence", | |
| "score": 84, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.006", | |
| "tactic": "privilege-escalation", | |
| "score": 84, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.006", | |
| "tactic": "defense-evasion", | |
| "score": 84, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1557.001", | |
| "tactic": "credential-access", | |
| "score": 70, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1557.001", | |
| "tactic": "collection", | |
| "score": 70, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1003.004", | |
| "tactic": "credential-access", | |
| "score": 55, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1547.008", | |
| "tactic": "persistence", | |
| "score": 12, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1547.008", | |
| "tactic": "privilege-escalation", | |
| "score": 12, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1003.001", | |
| "tactic": "credential-access", | |
| "score": 49, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1570", | |
| "tactic": "lateral-movement", | |
| "score": 88, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1543.001", | |
| "tactic": "persistence", | |
| "score": 97, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1543.001", | |
| "tactic": "privilege-escalation", | |
| "score": 97, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1543.004", | |
| "tactic": "persistence", | |
| "score": 47, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1543.004", | |
| "tactic": "privilege-escalation", | |
| "score": 47, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1569.001", | |
| "tactic": "execution", | |
| "score": 36, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1222.002", | |
| "tactic": "defense-evasion", | |
| "score": 67, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1136.001", | |
| "tactic": "persistence", | |
| "score": 12, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1087.001", | |
| "tactic": "discovery", | |
| "score": 97, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1078.003", | |
| "tactic": "defense-evasion", | |
| "score": 41, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1078.003", | |
| "tactic": "persistence", | |
| "score": 41, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1078.003", | |
| "tactic": "privilege-escalation", | |
| "score": 41, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1078.003", | |
| "tactic": "initial-access", | |
| "score": 41, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1074.001", | |
| "tactic": "collection", | |
| "score": 10, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1114.001", | |
| "tactic": "collection", | |
| "score": 12, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1069.001", | |
| "tactic": "discovery", | |
| "score": 33, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1037.002", | |
| "tactic": "persistence", | |
| "score": 73, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1037.002", | |
| "tactic": "privilege-escalation", | |
| "score": 73, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1037.001", | |
| "tactic": "persistence", | |
| "score": 51, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1037.001", | |
| "tactic": "privilege-escalation", | |
| "score": 51, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1127.001", | |
| "tactic": "defense-evasion", | |
| "score": 53, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1071.003", | |
| "tactic": "command-and-control", | |
| "score": 26, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1134.003", | |
| "tactic": "defense-evasion", | |
| "score": 78, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1134.003", | |
| "tactic": "privilege-escalation", | |
| "score": 78, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1204.002", | |
| "tactic": "execution", | |
| "score": 14, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1204.001", | |
| "tactic": "execution", | |
| "score": 21, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1185", | |
| "tactic": "collection", | |
| "score": 54, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1557", | |
| "tactic": "credential-access", | |
| "score": 90, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1557", | |
| "tactic": "collection", | |
| "score": 90, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1036.004", | |
| "tactic": "defense-evasion", | |
| "score": 94, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1036", | |
| "tactic": "defense-evasion", | |
| "score": 3, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1036.005", | |
| "tactic": "defense-evasion", | |
| "score": 53, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1556", | |
| "tactic": "credential-access", | |
| "score": 50, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1556", | |
| "tactic": "defense-evasion", | |
| "score": 50, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1556", | |
| "tactic": "persistence", | |
| "score": 50, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1578", | |
| "tactic": "defense-evasion", | |
| "score": 90, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1112", | |
| "tactic": "defense-evasion", | |
| "score": 36, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1112", | |
| "tactic": "persistence", | |
| "score": 36, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1218.005", | |
| "tactic": "defense-evasion", | |
| "score": 86, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1218.007", | |
| "tactic": "defense-evasion", | |
| "score": 62, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1104", | |
| "tactic": "command-and-control", | |
| "score": 94, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1090.003", | |
| "tactic": "command-and-control", | |
| "score": 35, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1003.003", | |
| "tactic": "credential-access", | |
| "score": 13, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1564.004", | |
| "tactic": "defense-evasion", | |
| "score": 59, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1106", | |
| "tactic": "execution", | |
| "score": 41, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.007", | |
| "tactic": "privilege-escalation", | |
| "score": 82, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.007", | |
| "tactic": "persistence", | |
| "score": 82, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1498", | |
| "tactic": "impact", | |
| "score": 27, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1037.003", | |
| "tactic": "persistence", | |
| "score": 28, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1037.003", | |
| "tactic": "privilege-escalation", | |
| "score": 28, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1046", | |
| "tactic": "discovery", | |
| "score": 20, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1070.005", | |
| "tactic": "defense-evasion", | |
| "score": 95, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1135", | |
| "tactic": "discovery", | |
| "score": 96, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1040", | |
| "tactic": "credential-access", | |
| "score": 66, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1040", | |
| "tactic": "discovery", | |
| "score": 66, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1095", | |
| "tactic": "command-and-control", | |
| "score": 11, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1132.002", | |
| "tactic": "command-and-control", | |
| "score": 86, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1571", | |
| "tactic": "command-and-control", | |
| "score": 17, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1003", | |
| "tactic": "credential-access", | |
| "score": 87, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1499.001", | |
| "tactic": "impact", | |
| "score": 45, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1027", | |
| "tactic": "defense-evasion", | |
| "score": 52, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1218.008", | |
| "tactic": "defense-evasion", | |
| "score": 73, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1137", | |
| "tactic": "persistence", | |
| "score": 74, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1137.001", | |
| "tactic": "persistence", | |
| "score": 64, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1137.002", | |
| "tactic": "persistence", | |
| "score": 81, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1102.003", | |
| "tactic": "command-and-control", | |
| "score": 17, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1137.003", | |
| "tactic": "persistence", | |
| "score": 69, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1137.004", | |
| "tactic": "persistence", | |
| "score": 13, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1137.005", | |
| "tactic": "persistence", | |
| "score": 70, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1134.004", | |
| "tactic": "defense-evasion", | |
| "score": 25, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1134.004", | |
| "tactic": "privilege-escalation", | |
| "score": 25, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1550.002", | |
| "tactic": "defense-evasion", | |
| "score": 46, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1550.002", | |
| "tactic": "lateral-movement", | |
| "score": 46, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1550.003", | |
| "tactic": "defense-evasion", | |
| "score": 100, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1550.003", | |
| "tactic": "lateral-movement", | |
| "score": 100, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1110.002", | |
| "tactic": "credential-access", | |
| "score": 79, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1556.002", | |
| "tactic": "credential-access", | |
| "score": 79, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1556.002", | |
| "tactic": "defense-evasion", | |
| "score": 79, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1556.002", | |
| "tactic": "persistence", | |
| "score": 79, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1110.001", | |
| "tactic": "credential-access", | |
| "score": 66, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1201", | |
| "tactic": "discovery", | |
| "score": 95, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1110.003", | |
| "tactic": "credential-access", | |
| "score": 14, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.007", | |
| "tactic": "persistence", | |
| "score": 51, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.007", | |
| "tactic": "privilege-escalation", | |
| "score": 51, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.007", | |
| "tactic": "defense-evasion", | |
| "score": 51, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.008", | |
| "tactic": "persistence", | |
| "score": 40, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.008", | |
| "tactic": "privilege-escalation", | |
| "score": 40, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.008", | |
| "tactic": "defense-evasion", | |
| "score": 40, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.009", | |
| "tactic": "persistence", | |
| "score": 26, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.009", | |
| "tactic": "privilege-escalation", | |
| "score": 26, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.009", | |
| "tactic": "defense-evasion", | |
| "score": 26, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1120", | |
| "tactic": "discovery", | |
| "score": 55, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1069", | |
| "tactic": "discovery", | |
| "score": 26, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1566", | |
| "tactic": "initial-access", | |
| "score": 6, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1556.003", | |
| "tactic": "credential-access", | |
| "score": 49, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1556.003", | |
| "tactic": "defense-evasion", | |
| "score": 49, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1556.003", | |
| "tactic": "persistence", | |
| "score": 49, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1205.001", | |
| "tactic": "defense-evasion", | |
| "score": 51, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1205.001", | |
| "tactic": "persistence", | |
| "score": 51, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1205.001", | |
| "tactic": "command-and-control", | |
| "score": 51, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1547.010", | |
| "tactic": "persistence", | |
| "score": 59, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1547.010", | |
| "tactic": "privilege-escalation", | |
| "score": 59, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1055.002", | |
| "tactic": "defense-evasion", | |
| "score": 86, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1055.002", | |
| "tactic": "privilege-escalation", | |
| "score": 86, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1059.001", | |
| "tactic": "execution", | |
| "score": 77, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.013", | |
| "tactic": "privilege-escalation", | |
| "score": 44, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.013", | |
| "tactic": "persistence", | |
| "score": 44, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1542", | |
| "tactic": "defense-evasion", | |
| "score": 53, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1542", | |
| "tactic": "persistence", | |
| "score": 53, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1552.004", | |
| "tactic": "credential-access", | |
| "score": 48, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1003.007", | |
| "tactic": "credential-access", | |
| "score": 11, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1055.009", | |
| "tactic": "defense-evasion", | |
| "score": 51, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1055.009", | |
| "tactic": "privilege-escalation", | |
| "score": 51, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1057", | |
| "tactic": "discovery", | |
| "score": 72, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1055.013", | |
| "tactic": "defense-evasion", | |
| "score": 57, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1055.013", | |
| "tactic": "privilege-escalation", | |
| "score": 57, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1055.012", | |
| "tactic": "defense-evasion", | |
| "score": 16, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1055.012", | |
| "tactic": "privilege-escalation", | |
| "score": 16, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1055", | |
| "tactic": "defense-evasion", | |
| "score": 86, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1055", | |
| "tactic": "privilege-escalation", | |
| "score": 86, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1001.003", | |
| "tactic": "command-and-control", | |
| "score": 4, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1572", | |
| "tactic": "command-and-control", | |
| "score": 69, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1090", | |
| "tactic": "command-and-control", | |
| "score": 54, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1055.008", | |
| "tactic": "defense-evasion", | |
| "score": 61, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1055.008", | |
| "tactic": "privilege-escalation", | |
| "score": 61, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1216.001", | |
| "tactic": "defense-evasion", | |
| "score": 23, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1059.006", | |
| "tactic": "execution", | |
| "score": 4, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1012", | |
| "tactic": "discovery", | |
| "score": 100, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1563.002", | |
| "tactic": "lateral-movement", | |
| "score": 61, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1037.004", | |
| "tactic": "persistence", | |
| "score": 25, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1037.004", | |
| "tactic": "privilege-escalation", | |
| "score": 25, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1547.007", | |
| "tactic": "persistence", | |
| "score": 20, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1547.007", | |
| "tactic": "privilege-escalation", | |
| "score": 20, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1498.002", | |
| "tactic": "impact", | |
| "score": 85, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1547.001", | |
| "tactic": "persistence", | |
| "score": 50, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1547.001", | |
| "tactic": "privilege-escalation", | |
| "score": 50, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1218.009", | |
| "tactic": "defense-evasion", | |
| "score": 40, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1218.010", | |
| "tactic": "defense-evasion", | |
| "score": 21, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1219", | |
| "tactic": "command-and-control", | |
| "score": 21, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1074.002", | |
| "tactic": "collection", | |
| "score": 14, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1021.001", | |
| "tactic": "lateral-movement", | |
| "score": 80, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1114.002", | |
| "tactic": "collection", | |
| "score": 97, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1563", | |
| "tactic": "lateral-movement", | |
| "score": 8, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1021", | |
| "tactic": "lateral-movement", | |
| "score": 79, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1018", | |
| "tactic": "discovery", | |
| "score": 97, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1036.003", | |
| "tactic": "defense-evasion", | |
| "score": 8, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1091", | |
| "tactic": "lateral-movement", | |
| "score": 59, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1091", | |
| "tactic": "initial-access", | |
| "score": 59, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1496", | |
| "tactic": "impact", | |
| "score": 3, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1578.004", | |
| "tactic": "defense-evasion", | |
| "score": 99, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1036.002", | |
| "tactic": "defense-evasion", | |
| "score": 56, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1207", | |
| "tactic": "defense-evasion", | |
| "score": 73, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1014", | |
| "tactic": "defense-evasion", | |
| "score": 91, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1564.006", | |
| "tactic": "defense-evasion", | |
| "score": 64, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1218.011", | |
| "tactic": "defense-evasion", | |
| "score": 20, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1565.003", | |
| "tactic": "impact", | |
| "score": 53, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1134.005", | |
| "tactic": "defense-evasion", | |
| "score": 45, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1134.005", | |
| "tactic": "privilege-escalation", | |
| "score": 45, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1553.003", | |
| "tactic": "defense-evasion", | |
| "score": 14, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1021.002", | |
| "tactic": "lateral-movement", | |
| "score": 25, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1505.001", | |
| "tactic": "persistence", | |
| "score": 95, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1021.004", | |
| "tactic": "lateral-movement", | |
| "score": 70, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1098.004", | |
| "tactic": "persistence", | |
| "score": 63, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1098.004", | |
| "tactic": "privilege-escalation", | |
| "score": 63, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1563.001", | |
| "tactic": "lateral-movement", | |
| "score": 83, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1053.005", | |
| "tactic": "execution", | |
| "score": 26, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1053.005", | |
| "tactic": "persistence", | |
| "score": 26, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1053.005", | |
| "tactic": "privilege-escalation", | |
| "score": 26, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1053", | |
| "tactic": "execution", | |
| "score": 68, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1053", | |
| "tactic": "persistence", | |
| "score": 68, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1053", | |
| "tactic": "privilege-escalation", | |
| "score": 68, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1029", | |
| "tactic": "exfiltration", | |
| "score": 40, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1113", | |
| "tactic": "collection", | |
| "score": 36, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.002", | |
| "tactic": "privilege-escalation", | |
| "score": 100, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.002", | |
| "tactic": "persistence", | |
| "score": 100, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1003.002", | |
| "tactic": "credential-access", | |
| "score": 11, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1518.001", | |
| "tactic": "discovery", | |
| "score": 55, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1547.005", | |
| "tactic": "persistence", | |
| "score": 74, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1547.005", | |
| "tactic": "privilege-escalation", | |
| "score": 74, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1555.002", | |
| "tactic": "credential-access", | |
| "score": 99, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1505", | |
| "tactic": "persistence", | |
| "score": 45, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1569.002", | |
| "tactic": "execution", | |
| "score": 34, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1499.002", | |
| "tactic": "impact", | |
| "score": 10, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1489", | |
| "tactic": "impact", | |
| "score": 23, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.010", | |
| "tactic": "persistence", | |
| "score": 7, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.010", | |
| "tactic": "privilege-escalation", | |
| "score": 7, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.010", | |
| "tactic": "defense-evasion", | |
| "score": 7, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.011", | |
| "tactic": "persistence", | |
| "score": 89, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.011", | |
| "tactic": "privilege-escalation", | |
| "score": 89, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1574.011", | |
| "tactic": "defense-evasion", | |
| "score": 89, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1548.001", | |
| "tactic": "privilege-escalation", | |
| "score": 99, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1548.001", | |
| "tactic": "defense-evasion", | |
| "score": 99, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1129", | |
| "tactic": "execution", | |
| "score": 64, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1213.002", | |
| "tactic": "collection", | |
| "score": 55, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1547.009", | |
| "tactic": "persistence", | |
| "score": 55, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1547.009", | |
| "tactic": "privilege-escalation", | |
| "score": 55, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1218", | |
| "tactic": "defense-evasion", | |
| "score": 96, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1216", | |
| "tactic": "defense-evasion", | |
| "score": 85, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1558.002", | |
| "tactic": "credential-access", | |
| "score": 7, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1072", | |
| "tactic": "execution", | |
| "score": 100, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1072", | |
| "tactic": "lateral-movement", | |
| "score": 100, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1518", | |
| "tactic": "discovery", | |
| "score": 28, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1027.002", | |
| "tactic": "defense-evasion", | |
| "score": 93, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1036.006", | |
| "tactic": "defense-evasion", | |
| "score": 66, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1566.001", | |
| "tactic": "initial-access", | |
| "score": 99, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1566.002", | |
| "tactic": "initial-access", | |
| "score": 22, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1566.003", | |
| "tactic": "initial-access", | |
| "score": 40, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1132.001", | |
| "tactic": "command-and-control", | |
| "score": 57, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1037.005", | |
| "tactic": "persistence", | |
| "score": 41, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1037.005", | |
| "tactic": "privilege-escalation", | |
| "score": 41, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1528", | |
| "tactic": "credential-access", | |
| "score": 23, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1539", | |
| "tactic": "credential-access", | |
| "score": 12, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1558", | |
| "tactic": "credential-access", | |
| "score": 40, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1027.003", | |
| "tactic": "defense-evasion", | |
| "score": 67, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1001.002", | |
| "tactic": "command-and-control", | |
| "score": 62, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1565.001", | |
| "tactic": "impact", | |
| "score": 62, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1553", | |
| "tactic": "defense-evasion", | |
| "score": 55, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1548.003", | |
| "tactic": "privilege-escalation", | |
| "score": 94, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1548.003", | |
| "tactic": "defense-evasion", | |
| "score": 94, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1195", | |
| "tactic": "initial-access", | |
| "score": 12, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1573.001", | |
| "tactic": "command-and-control", | |
| "score": 58, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1497.001", | |
| "tactic": "defense-evasion", | |
| "score": 36, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1497.001", | |
| "tactic": "discovery", | |
| "score": 36, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1542.001", | |
| "tactic": "persistence", | |
| "score": 11, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1542.001", | |
| "tactic": "defense-evasion", | |
| "score": 11, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1082", | |
| "tactic": "discovery", | |
| "score": 100, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1016", | |
| "tactic": "discovery", | |
| "score": 33, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1049", | |
| "tactic": "discovery", | |
| "score": 12, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1033", | |
| "tactic": "discovery", | |
| "score": 49, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1007", | |
| "tactic": "discovery", | |
| "score": 29, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1569", | |
| "tactic": "execution", | |
| "score": 53, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1529", | |
| "tactic": "impact", | |
| "score": 7, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1124", | |
| "tactic": "discovery", | |
| "score": 99, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1543.002", | |
| "tactic": "persistence", | |
| "score": 81, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1543.002", | |
| "tactic": "privilege-escalation", | |
| "score": 81, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1080", | |
| "tactic": "lateral-movement", | |
| "score": 26, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1221", | |
| "tactic": "defense-evasion", | |
| "score": 71, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1055.003", | |
| "tactic": "defense-evasion", | |
| "score": 71, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1055.003", | |
| "tactic": "privilege-escalation", | |
| "score": 71, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1055.005", | |
| "tactic": "defense-evasion", | |
| "score": 3, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1055.005", | |
| "tactic": "privilege-escalation", | |
| "score": 3, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1497.003", | |
| "tactic": "defense-evasion", | |
| "score": 58, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1497.003", | |
| "tactic": "discovery", | |
| "score": 58, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1547.003", | |
| "tactic": "persistence", | |
| "score": 95, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1547.003", | |
| "tactic": "privilege-escalation", | |
| "score": 95, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1070.006", | |
| "tactic": "defense-evasion", | |
| "score": 38, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1134.001", | |
| "tactic": "defense-evasion", | |
| "score": 49, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1134.001", | |
| "tactic": "privilege-escalation", | |
| "score": 49, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1205", | |
| "tactic": "defense-evasion", | |
| "score": 90, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1205", | |
| "tactic": "persistence", | |
| "score": 90, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1205", | |
| "tactic": "command-and-control", | |
| "score": 90, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1537", | |
| "tactic": "exfiltration", | |
| "score": 51, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1565.002", | |
| "tactic": "impact", | |
| "score": 48, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1505.002", | |
| "tactic": "persistence", | |
| "score": 95, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.005", | |
| "tactic": "privilege-escalation", | |
| "score": 34, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.005", | |
| "tactic": "persistence", | |
| "score": 34, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1127", | |
| "tactic": "defense-evasion", | |
| "score": 67, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1199", | |
| "tactic": "initial-access", | |
| "score": 13, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1111", | |
| "tactic": "credential-access", | |
| "score": 87, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1059.004", | |
| "tactic": "execution", | |
| "score": 43, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1552", | |
| "tactic": "credential-access", | |
| "score": 94, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1535", | |
| "tactic": "defense-evasion", | |
| "score": 11, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1550", | |
| "tactic": "defense-evasion", | |
| "score": 52, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1550", | |
| "tactic": "lateral-movement", | |
| "score": 52, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1497.002", | |
| "tactic": "defense-evasion", | |
| "score": 46, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1497.002", | |
| "tactic": "discovery", | |
| "score": 46, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1204", | |
| "tactic": "execution", | |
| "score": 11, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1055.014", | |
| "tactic": "defense-evasion", | |
| "score": 36, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1055.014", | |
| "tactic": "privilege-escalation", | |
| "score": 36, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1021.005", | |
| "tactic": "lateral-movement", | |
| "score": 74, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1078", | |
| "tactic": "defense-evasion", | |
| "score": 73, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1078", | |
| "tactic": "persistence", | |
| "score": 73, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1078", | |
| "tactic": "privilege-escalation", | |
| "score": 73, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1078", | |
| "tactic": "initial-access", | |
| "score": 73, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1125", | |
| "tactic": "collection", | |
| "score": 53, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1497", | |
| "tactic": "defense-evasion", | |
| "score": 77, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1497", | |
| "tactic": "discovery", | |
| "score": 77, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1059.005", | |
| "tactic": "execution", | |
| "score": 99, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1056.003", | |
| "tactic": "collection", | |
| "score": 90, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1056.003", | |
| "tactic": "credential-access", | |
| "score": 90, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1071.001", | |
| "tactic": "command-and-control", | |
| "score": 12, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1102", | |
| "tactic": "command-and-control", | |
| "score": 74, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1550.004", | |
| "tactic": "defense-evasion", | |
| "score": 26, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1550.004", | |
| "tactic": "lateral-movement", | |
| "score": 26, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1505.003", | |
| "tactic": "persistence", | |
| "score": 75, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1059.003", | |
| "tactic": "execution", | |
| "score": 96, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1222.001", | |
| "tactic": "defense-evasion", | |
| "score": 10, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1047", | |
| "tactic": "execution", | |
| "score": 69, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.003", | |
| "tactic": "privilege-escalation", | |
| "score": 81, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1546.003", | |
| "tactic": "persistence", | |
| "score": 81, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1021.006", | |
| "tactic": "lateral-movement", | |
| "score": 87, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1543.003", | |
| "tactic": "persistence", | |
| "score": 2, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1543.003", | |
| "tactic": "privilege-escalation", | |
| "score": 2, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1547.004", | |
| "tactic": "persistence", | |
| "score": 21, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1547.004", | |
| "tactic": "privilege-escalation", | |
| "score": 21, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| }, | |
| { | |
| "techniqueID": "T1220", | |
| "tactic": "defense-evasion", | |
| "score": 74, | |
| "color": "", | |
| "comment": "", | |
| "enabled": true, | |
| "metadata": [], | |
| "links": [], | |
| "showSubtechniques": false | |
| } | |
| ], | |
| "gradient": { | |
| "colors": [ | |
| "#ff6666ff", | |
| "#ffe766ff", | |
| "#8ec843ff" | |
| ], | |
| "minValue": 0, | |
| "maxValue": 100 | |
| }, | |
| "legendItems": [], | |
| "metadata": [], | |
| "links": [], | |
| "showTacticRowBackground": false, | |
| "tacticRowBackground": "#dddddd", | |
| "selectTechniquesAcrossTactics": true, | |
| "selectSubtechniquesWithParent": false, | |
| "selectVisibleTechniques": false | |
| } |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment