Skip to content
COOEY

◄ SIGNAL FUSION

ATT&CK MATRIX

Reference · MITRE

The full MITRE ATT&CK Enterprise kill chain — every tactic column and technique cell, collected fresh from MITRE's public STIX. Cell intensity = how many tracked threat groups use the technique; = cited in advisories we collect. Click a technique for detail; filter by group to see one actor's playbook.

MATRIX_DOMAIN ENTERPRISE MOBILE ICS ⇩ EXPORT_JSON
TECHNIQUE · T1584.005 — Botnet
resource development PRE SUB-TECHNIQUE of T1584 MITRE page ↗

Adversaries may compromise numerous third-party systems to form a botnet that can be used during targeting. A botnet is a network of compromised systems that can be instructed to perform coordinated tasks.(Citation: Norton Botnet) Instead of purchasing/renting a botnet from a booter/stresser service, adversaries may build their own botnet by compromising numerous third-party systems.(Citation: Imperva DDoS for Hire) Adversaries may also conduct a takeover of an existing botnet, such as redirecting bots to adversary-controlled C2 servers.(Citation: Dell Dridex Oct 2015) With a botnet at their disposal, adversaries may perform follow-on activity such as large-scale [Phishing](https://attack.mi…

Threat groups using it · 5
Reconnaissance
TA0043 · 12
Resource Development
TA0042 · 9
Initial Access
TA0001 · 11
Execution
TA0002 · 20
Persistence
TA0003 · 22
Privilege Escalation
TA0004 · 13
Stealth
TA0005 · 30
Defense Impairment
TA0112 · 18
Credential Access
TA0006 · 17
Discovery
TA0007 · 34
Lateral Movement
TA0008 · 9
Collection
TA0009 · 17
Command and Control
TA0011 · 18
Exfiltration
TA0010 · 9
Impact
TA0040 · 15
Heat · group adoption: ≤ median > median top quartile top decile ◆ n = cited in n of our collected advisories Source: MITRE ATT&CK Enterprise · attack-stix-data · group adoption = STIX “uses” edges