Mappings
MITRE ATT&CK & OWASP
Connect offensive techniques and web risk categories to OpsField tools and modules. Use this when writing findings or designing purple-team questions.
Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.
Active Scanning
Adversaries probe victim infrastructure for reachable hosts, ports, and services. In ethical assessments this maps to authorized discovery scans.
Detection: IDS/IPS volume spikes, connection attempts across many ports from one source, and unusual ARP traffic. Baseline internal scanners so SOC can distinguish authorized jobs.
Gather Victim Host Information
Collection of OS, software, and configuration details via banners, OSINT, or authenticated queries.
Detection: Repeated banner grabs, Shodan/Censys hits on public assets, and user-agent patterns from scanners. Reduce exposure with minimal banners and rate limiting.
Network Service Discovery
Enumerating services on network hosts to identify remote access points and vulnerable software.
Detection: Sequential or randomized port sweeps, SYN floods to ephemeral ports, and NSE-like protocol probes. Network flow analytics help spot sweeps.
System Information Discovery
After access, operators gather OS version, patches, hardware, and domain role to plan privilege escalation.
Detection: Burst of local commands (systeminfo, uname, whoami), PEAS script hashes, and unusual WMI queries. EDR process trees catch scripted enum.
Account Discovery
Listing local or domain accounts to identify privileged identities and service principals.
Detection: LDAP enumeration volume, SAMR/NetSession queries, and Kerberos pre-auth failures during user enum. Monitor for bloodhound-python / SharpHound patterns.
Network Share Discovery
Identifying SMB/NFS shares and permissions that may expose sensitive files or paths to lateral movement.
Detection: Tree connects to IPC$ and many shares, null session attempts, and sudden access to rarely used file servers.
Remote System Discovery
Mapping other systems on the network from a foothold using ping sweeps, ARP, or directory data.
Detection: Internal host discovery from non-scanner systems, sudden ICMP/ARP from workstations, and AD computer object bulk reads.
Command and Scripting Interpreter
Abuse of shells and interpreters (bash, PowerShell, Python, cmd) to run attacker-controlled commands.
Detection: Encoded PowerShell, unusual parent/child process trees, script block logging, and interpreters launched by office apps or web servers.
PowerShell
PowerShell used for remote admin, download cradles, and in-memory tooling on Windows estates.
Detection: Script Block Logging (4104), AMSI hits, constrained language mode bypass attempts, and powershell.exe -enc patterns.
Exploitation for Client Execution
Exploiting client applications (browsers, readers) to run code — less common in pure network pentests but relevant to phishing labs.
Detection: Exploit kit domains, abnormal child processes from browsers, and sandbox detonation of email attachments.
Exploit Public-Facing Application
Exploiting vulnerabilities in internet-facing web apps, VPNs, or appliances to gain a foothold.
Detection: WAF blocks, exploit path hits in access logs, nuclei/user-agent signatures, and sudden RCE process spawn from web workers.
Valid Accounts
Using legitimate credentials obtained via phish, spray, purchase, or reuse to access systems.
Detection: Impossible travel, password spray patterns (many users, few passwords), and logons from unusual subnets. MFA reduces impact.
Brute Force
Password guessing against online services or offline cracking of captured hashes.
Detection: Account lockouts, authentication failures bursts, and GPU cracking is offline (look for prior dump events). Rate-limit and MFA are primary controls.
Password Guessing
Interactive or automated guessing of a single account password (classic brute force).
Detection: High failure rate on one principal, source IP reputation, and protocol-specific attempt counters (SSH, RDP, HTTP forms).
Password Spraying
Trying a small set of common passwords across many accounts to avoid lockouts.
Detection: Distributed low-and-slow failures across many accounts from one source; Azure/AD smart lockout and SIEM correlation help.
OS Credential Dumping
Extracting credentials from OS stores such as LSASS, SAM, NTDS, or /etc/shadow.
Detection: LSASS access, procdump, secretsdump LDAP/DRSUAPI patterns, and unexpected volume shadow copy use. Credential Guard raises the bar.
Kerberoasting
Requesting Kerberos service tickets for SPN accounts and offline-cracking the ticket encryption material.
Detection: Unusual TGS requests for many SPNs from one user, RC4 ticket encryption, and Event 4769 anomalies. Prefer AES and strong service account passwords or gMSA.
AS-REP Roasting
Requesting AS-REP for accounts without Kerberos pre-authentication and cracking the encrypted material offline.
Detection: AS-REQ without pre-auth (4768) for accounts that should require it. Disable DONT_REQ_PREAUTH unless justified.
Adversary-in-the-Middle
Intercepting or relaying authentication and traffic via ARP spoof, LLMNR/NBT-NS poison, or proxy tools.
Detection: Duplicate IP/MAC conflicts, LLMNR/NBT-NS response spoofing, unexpected WPAD, and NTLM relay to SMB/LDAP. Disable legacy name resolution; enforce SMB signing and LDAP channel binding.
Remote Services
Moving laterally with legitimate remote services such as RDP, SMB, WinRM, and SSH using valid credentials.
Detection: New admin logons across many hosts, Impacket tool default pipe names, and unusual WinRM from workstations. Tiered admin and just-in-time access reduce blast radius.
SMB/Windows Admin Shares
Using C$, ADMIN$, or other admin shares to transfer tools and execute remotely.
Detection: Admin share access outside jump hosts, service creation after file drop, and lateral tool transfer patterns.
Exploitation for Privilege Escalation
Exploiting local vulnerabilities or misconfigurations to gain higher privileges on a host.
Detection: Local exploit process trees, unusual SUID execution, token manipulation, and kernel exploit IOCs. Patch management and least privilege are primary defenses.
Abuse Elevation Control Mechanism
Bypassing UAC, sudo misconfig, SUID binaries, or setuid/setgid programs to elevate.
Detection: sudoers changes, unexpected SUID binaries, and UAC bypass child processes. Audit elevated rights regularly.
Process Injection
Injecting code into legitimate processes to hide and inherit trust.
Detection: Cross-process memory writes, unbacked executable memory, and EDR behavioral detections for classic injection APIs.
Obfuscated Files or Information
Encoding, packing, or encrypting payloads and scripts to evade static detection.
Detection: High-entropy scripts, multi-layer base64, and AMSI bypass patterns. Behavioral detection outperforms signatures alone.
Data from Local System
Searching local files and databases for credentials, secrets, and sensitive business data.
Detection: Bulk file reads of user profiles, browser DB access, and secret scanners on endpoints. DLP and least privilege limit exposure.
Exfiltration Over C2 Channel
Sending collected data out through the same channel used for command and control.
Detection: Long-lived unusual beacons, large outbound transfers to rare domains, and encrypted tunnels from servers that should not call out.
Proxy
Using proxies, tunnels, and pivots to route traffic through compromised hosts.
Detection: Unexpected listening ports, reverse tunnel patterns, and multi-hop connections. Monitor for new SOCKS listeners on endpoints.
Scheduled Task/Job
Creating scheduled tasks or cron jobs for persistence and execution.
Detection: New scheduled tasks in non-standard paths, cron writes by web users, and Event 4698 on Windows.
Account Manipulation
Modifying accounts, group membership, or credentials (including cloud roles) to maintain access.
Detection: Unexpected group adds (Domain Admins), new API keys, and password resets outside helpdesk workflows.