TA0001 2
Initial Access
T1078Valid Accounts
T1566.001Phishing: Spearphishing Attachment
TA0002 1
Execution
T1059.001Command and Scripting Interpreter: PowerShell
TA0004 0
Privilege Escalation
TA0005 2
Defense Evasion
T1036Masquerading
T1562.001Disable or Modify Tools
TA0006 1
Credential Access
T1003.001OS Credential Dumping: LSASS Memory
TA0007 2
Discovery
T1012Query Registry
T1082System Information Discovery
TA0008 1
Lateral Movement
T1021.001Remote Services: Remote Desktop Protocol
TA0010 1
Exfiltration
T1567.002Exfiltration Over Web Service: Exfiltration to Cloud Storage
TA0011 1
Command & Control
T1071.001Application Layer Protocol: Web Protocols
TA0040 2
Impact
T1486Data Encrypted for Impact
T1490Inhibit System Recovery