Field kit

Mappings

MITRE ATT&CK & OWASP

Connect offensive techniques and web risk categories to OpsField tools and modules. Use this when writing findings or designing purple-team questions.

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

T1595
Reconnaissance

Active Scanning

Adversaries probe victim infrastructure for reachable hosts, ports, and services. In ethical assessments this maps to authorized discovery scans.

Detection: IDS/IPS volume spikes, connection attempts across many ports from one source, and unusual ARP traffic. Baseline internal scanners so SOC can distinguish authorized jobs.

T1592
Reconnaissance

Gather Victim Host Information

Collection of OS, software, and configuration details via banners, OSINT, or authenticated queries.

Detection: Repeated banner grabs, Shodan/Censys hits on public assets, and user-agent patterns from scanners. Reduce exposure with minimal banners and rate limiting.

T1046
Discovery

Network Service Discovery

Enumerating services on network hosts to identify remote access points and vulnerable software.

Detection: Sequential or randomized port sweeps, SYN floods to ephemeral ports, and NSE-like protocol probes. Network flow analytics help spot sweeps.

T1082
Discovery

System Information Discovery

After access, operators gather OS version, patches, hardware, and domain role to plan privilege escalation.

Detection: Burst of local commands (systeminfo, uname, whoami), PEAS script hashes, and unusual WMI queries. EDR process trees catch scripted enum.

T1087
Discovery

Account Discovery

Listing local or domain accounts to identify privileged identities and service principals.

Detection: LDAP enumeration volume, SAMR/NetSession queries, and Kerberos pre-auth failures during user enum. Monitor for bloodhound-python / SharpHound patterns.

T1135
Discovery

Network Share Discovery

Identifying SMB/NFS shares and permissions that may expose sensitive files or paths to lateral movement.

Detection: Tree connects to IPC$ and many shares, null session attempts, and sudden access to rarely used file servers.

T1018
Discovery

Remote System Discovery

Mapping other systems on the network from a foothold using ping sweeps, ARP, or directory data.

Detection: Internal host discovery from non-scanner systems, sudden ICMP/ARP from workstations, and AD computer object bulk reads.

T1059
Execution

Command and Scripting Interpreter

Abuse of shells and interpreters (bash, PowerShell, Python, cmd) to run attacker-controlled commands.

Detection: Encoded PowerShell, unusual parent/child process trees, script block logging, and interpreters launched by office apps or web servers.

T1059.001
Execution

PowerShell

PowerShell used for remote admin, download cradles, and in-memory tooling on Windows estates.

Detection: Script Block Logging (4104), AMSI hits, constrained language mode bypass attempts, and powershell.exe -enc patterns.

T1203
Execution

Exploitation for Client Execution

Exploiting client applications (browsers, readers) to run code — less common in pure network pentests but relevant to phishing labs.

Detection: Exploit kit domains, abnormal child processes from browsers, and sandbox detonation of email attachments.

T1190
Initial Access

Exploit Public-Facing Application

Exploiting vulnerabilities in internet-facing web apps, VPNs, or appliances to gain a foothold.

Detection: WAF blocks, exploit path hits in access logs, nuclei/user-agent signatures, and sudden RCE process spawn from web workers.

T1078
Initial Access

Valid Accounts

Using legitimate credentials obtained via phish, spray, purchase, or reuse to access systems.

Detection: Impossible travel, password spray patterns (many users, few passwords), and logons from unusual subnets. MFA reduces impact.

T1110
Credential Access

Brute Force

Password guessing against online services or offline cracking of captured hashes.

Detection: Account lockouts, authentication failures bursts, and GPU cracking is offline (look for prior dump events). Rate-limit and MFA are primary controls.

T1110.001
Credential Access

Password Guessing

Interactive or automated guessing of a single account password (classic brute force).

Detection: High failure rate on one principal, source IP reputation, and protocol-specific attempt counters (SSH, RDP, HTTP forms).

T1110.003
Credential Access

Password Spraying

Trying a small set of common passwords across many accounts to avoid lockouts.

Detection: Distributed low-and-slow failures across many accounts from one source; Azure/AD smart lockout and SIEM correlation help.

T1003
Credential Access

OS Credential Dumping

Extracting credentials from OS stores such as LSASS, SAM, NTDS, or /etc/shadow.

Detection: LSASS access, procdump, secretsdump LDAP/DRSUAPI patterns, and unexpected volume shadow copy use. Credential Guard raises the bar.

T1558.003
Credential Access

Kerberoasting

Requesting Kerberos service tickets for SPN accounts and offline-cracking the ticket encryption material.

Detection: Unusual TGS requests for many SPNs from one user, RC4 ticket encryption, and Event 4769 anomalies. Prefer AES and strong service account passwords or gMSA.

T1558.004
Credential Access

AS-REP Roasting

Requesting AS-REP for accounts without Kerberos pre-authentication and cracking the encrypted material offline.

Detection: AS-REQ without pre-auth (4768) for accounts that should require it. Disable DONT_REQ_PREAUTH unless justified.

T1557
Credential Access

Adversary-in-the-Middle

Intercepting or relaying authentication and traffic via ARP spoof, LLMNR/NBT-NS poison, or proxy tools.

Detection: Duplicate IP/MAC conflicts, LLMNR/NBT-NS response spoofing, unexpected WPAD, and NTLM relay to SMB/LDAP. Disable legacy name resolution; enforce SMB signing and LDAP channel binding.

T1021
Lateral Movement

Remote Services

Moving laterally with legitimate remote services such as RDP, SMB, WinRM, and SSH using valid credentials.

Detection: New admin logons across many hosts, Impacket tool default pipe names, and unusual WinRM from workstations. Tiered admin and just-in-time access reduce blast radius.

T1021.002
Lateral Movement

SMB/Windows Admin Shares

Using C$, ADMIN$, or other admin shares to transfer tools and execute remotely.

Detection: Admin share access outside jump hosts, service creation after file drop, and lateral tool transfer patterns.

T1068
Privilege Escalation

Exploitation for Privilege Escalation

Exploiting local vulnerabilities or misconfigurations to gain higher privileges on a host.

Detection: Local exploit process trees, unusual SUID execution, token manipulation, and kernel exploit IOCs. Patch management and least privilege are primary defenses.

T1548
Privilege Escalation

Abuse Elevation Control Mechanism

Bypassing UAC, sudo misconfig, SUID binaries, or setuid/setgid programs to elevate.

Detection: sudoers changes, unexpected SUID binaries, and UAC bypass child processes. Audit elevated rights regularly.

T1055
Defense Evasion

Process Injection

Injecting code into legitimate processes to hide and inherit trust.

Detection: Cross-process memory writes, unbacked executable memory, and EDR behavioral detections for classic injection APIs.

T1027
Defense Evasion

Obfuscated Files or Information

Encoding, packing, or encrypting payloads and scripts to evade static detection.

Detection: High-entropy scripts, multi-layer base64, and AMSI bypass patterns. Behavioral detection outperforms signatures alone.

T1005
Collection

Data from Local System

Searching local files and databases for credentials, secrets, and sensitive business data.

Detection: Bulk file reads of user profiles, browser DB access, and secret scanners on endpoints. DLP and least privilege limit exposure.

T1041
Exfiltration

Exfiltration Over C2 Channel

Sending collected data out through the same channel used for command and control.

Detection: Long-lived unusual beacons, large outbound transfers to rare domains, and encrypted tunnels from servers that should not call out.

T1090
Command and Control

Proxy

Using proxies, tunnels, and pivots to route traffic through compromised hosts.

Detection: Unexpected listening ports, reverse tunnel patterns, and multi-hop connections. Monitor for new SOCKS listeners on endpoints.

T1053
Persistence

Scheduled Task/Job

Creating scheduled tasks or cron jobs for persistence and execution.

Detection: New scheduled tasks in non-standard paths, cron writes by web users, and Event 4698 on Windows.

T1098
Persistence

Account Manipulation

Modifying accounts, group membership, or credentials (including cloud roles) to maintain access.

Detection: Unexpected group adds (Domain Admins), new API keys, and password resets outside helpdesk workflows.