Ransomware Intelligence

TTPs & Attack Vectors

Tactics, techniques, procedures, and vulnerability exploitation intelligence

MITRE ATT&CK Navigator — Ransomware Coverage

156 techniques across 9 tactics · all groups · cell = group count, color = intensity (log scale)

Low
Critical(log scale)
Execution
Persistence
Priv Esc
Def Evasion
Cred Access
Discovery
Lateral Mvmt
Collection
Impact

T1003.001

LSASS Memory

1

T1053.005

Scheduled Task

1

T1003

OS Credential Dumping

1

T1027

Obfuscated Files or Information

11

T1003

OS Credential Dumping

15

T1007

System Service Discovery

4

T1005

Data from Local System

1

T1005

Data from Local System

13

Linux / ESXi Variants

1

T1005.002

User Execution

1

T1071

Application Layer Protocol

1

T1055

Process Injection

1

T1027.002

Software Packing

7

T1003.001

LSASS Memory

17

T1010

Application Window Discovery

3

T1021

Remote Services

83

T1056

Input Capture

1

Data Theft / Double Extortion

1

T1027

Obfuscated Files or Information

1

T1078

Valid Accounts

82

T1055.003

Thread Execution Hijacking

1

T1027.005

Indicator Removal from Tools

5

T1056

Input Capture

4

T1012

Query Registry

3

T1021.001

Remote Desktop Protocol

89

T1071

Application Layer Protocol

4

T1485

Data Destruction

8

T1036

Masquerading

1

T1098

Account Manipulation

1

T1068

Exploitation for Privilege Escalation

3

T1027.009

Embedded Payloads

5

T1110

Brute Force

10

T1016

System Network Configuration Discovery

8

T1021.002

SMB/Windows Admin Shares

86

T1074

Data Staged

3

T1486

Data Encrypted for Impact

110

T1047

Windows Management Instrumentation

16

T1098.003

Additional Cloud Roles

1

T1078

Valid Accounts

1

T1036

Masquerading

14

T1555.003

Credentials from Web Browsers

2

T1018

Remote System Discovery

8

T1021.004

SSH

84

T1105

Ingress Tool Transfer

1

T1489

Service Stop

10

T1053

Scheduled Task/Job

3

T1112

Modify Registry

1

T1134.001

Token Impersonation/Theft

1

T1036.005

Match Legitimate Resource Name or Location

9

T1555

Credentials from Password Stores

1

T1046

Network Service Discovery

18

T1039

Data from Network Shared Drive

1

T1119

Automated Collection

4

T1490

Inhibit System Recovery

98

T1053.005

Scheduled Task

2

T1136

Create Account

6

T1484.001

Group Policy Modification

3

T1055.001

Dynamic-link Library Injection

1

T1558

Steal or Forge Kerberos Tickets

1

T1049

System Network Connections Discovery

2

T1074

Data Staged

1

T1213

Data from Information Repositories

2

T1491.001

Internal Defacement

1

T1059

Command and Scripting Interpreter

94

T1136.001

Local Account

5

T1543.003

Windows Service

2

T1055.003

Thread Execution Hijacking

1

T1558.003

Kerberoasting

1

T1057

Process Discovery

12

T1080

Taint Shared Content

42

T1219

Remote Access Tools

1

T1498

Network Denial of Service

1

T1059.001

PowerShell

85

T1136.002

Domain Account

4

T1547.001

Registry Run Keys / Startup Folder

2

T1055

Process Injection

2

T1063

Security Software Discovery

9

T1091

Replication Through Removable Media

1

T1560

Archive Collected Data

1

T1657

Financial Theft

2

T1059.003

Windows Command Shell

85

T1543.002

Systemd Service

1

T1547

Boot or Logon Autostart Execution

1

T1064

Scripting

2

T1069.001

Local Groups

1

T1570

Lateral Tool Transfer

5

T1560.001

Archive via Utility

4

T1059.004

Unix Shell

81

T1543.003

Windows Service

5

T1548

Abuse Elevation Control Mechanism

2

T1070

Indicator Removal

3

T1082

System Information Discovery

13

T1572

Protocol Tunneling

1

T1059.006

Python

81

T1547

Boot or Logon Autostart Execution

82

T1548.002

Bypass User Account Control

1

T1070.001

Clear Windows Event Logs

8

T1083

File and Directory Discovery

17

T1573

Encrypted Channel

1

T1064

Scripting

1

T1547.001

Registry Run Keys / Startup Folder

82

T1558.003

Kerberoasting

1

T1070.004

File Deletion

6

T1087

Account Discovery

2

T1070.001

Clear Windows Event Logs

1

T1574.001

DLL

1

T1574

Hijack Execution Flow

1

T1089

Disabling Security Tools

1

T1087.001

Local Account

1

T1072

Software Deployment Tools

3

T1574.001

DLL

1

T1112

Modify Registry

3

T1087.002

Domain Account

2

T1105

Ingress Tool Transfer

16

T1140

Deobfuscate/Decode Files or Information

2

T1120

Peripheral Device Discovery

1

T1106

Native API

8

T1202

Indirect Command Execution

5

T1135

Network Share Discovery

10

T1112

Modify Registry

1

T1218

System Binary Proxy Execution

3

T1482

Domain Trust Discovery

1

T1129

Shared Modules

7

T1218.010

Regsvr32

2

T1497

Virtualization/Sandbox Evasion

1

T1134.002

Create Process with Token

1

T1222

File and Directory Permissions Modification

2

T1518

Software Discovery

1

T1140

Deobfuscate/Decode Files or Information

3

T1480.001

Environmental Keying

1

T1538

Cloud Service Dashboard

1

T1204.002

Malicious File

1

T1484.001

Group Policy Modification

1

T1614

System Location Discovery

1

T1219

Remote Access Tools

1

T1497

Virtualization/Sandbox Evasion

4

T1614.001

System Language Discovery

1

T1497

Virtualization/Sandbox Evasion

1

T1550.001

Application Access Token

1

T1615

Group Policy Discovery

1

T1547

Boot or Logon Autostart Execution

1

T1562

Impair Defenses

83

T1548.002

Bypass User Account Control

1

T1562.001

Disable or Modify Tools

93

T1552

Unsecured Credentials

1

T1562.002

Disable Windows Event Logging

83

T1555

Credentials from Password Stores

1

T1562.004

Disable or Modify System Firewall

84

T1562.001

Disable or Modify Tools

1

T1562.009

Safe Mode Boot

83

T1569.002

Service Execution

4

T1564

Hide Artifacts

1

T1564.003

Hidden Window

1

T1564.004

NTFS File Attributes

1

T1620

Reflective Code Loading

1

T1622

Debugger Evasion

2