| ID | Name | Tactic |
|---|---|---|
| T1078 | Valid Accounts | persistence |
| T1053 | Scheduled Task/Job | persistence |
| T1566 | Phishing | initial-access |
| T1190 | Exploit Public-Facing Application | initial-access |
| T1059 | Command and Scripting Interpreter | execution |
| T1204 | User Execution | execution |
| T1055 | Process Injection | privilege-escalation |
| T1548 | Abuse Elevation Control Mechanism | privilege-escalation |
| T1003 | OS Credential Dumping | credential-access |
| T1110 | Brute Force | credential-access |
| T1021 | Remote Services | lateral-movement |
| T1570 | Lateral Tool Transfer | lateral-movement |