- T1053.003 Cron
- T1053.005 Scheduled Task
- T1078 Valid Accounts
- T1543 Create or Modify System Process
- T1543.003 Windows Service
- T1547.001 Registry Run Keys / Startup Folder
- T1548.003 Sudo and Sudo Caching
- T1037 Boot or Logon Initialization Scripts (index only)
- T1037.001 Logon Script (Windows) (index only)
- T1037.002 Login Hook (index only)
- T1037.003 Network Logon Script (index only)
- T1037.004 RC Scripts (index only)
- T1037.005 Startup Items (index only)
- T1053 Scheduled Task/Job (index only)
- T1053.002 At (index only)
- T1053.006 Systemd Timers (index only)
- T1053.007 Container Orchestration Job (index only)
- T1055 Process Injection (index only)
- T1055.001 Dynamic-link Library Injection (index only)
- T1055.002 Portable Executable Injection (index only)
- T1055.003 Thread Execution Hijacking (index only)
- T1055.004 Asynchronous Procedure Call (index only)
- T1055.005 Thread Local Storage (index only)
- T1055.008 Ptrace System Calls (index only)
- T1055.009 Proc Memory (index only)
- T1055.011 Extra Window Memory Injection (index only)
- T1055.012 Process Hollowing (index only)
- T1055.013 Process Doppelgänging (index only)
- T1055.014 VDSO Hijacking (index only)
- T1055.015 ListPlanting (index only)
- T1068 Exploitation for Privilege Escalation (index only)
- T1078.001 Default Accounts (index only)
- T1078.002 Domain Accounts (index only)
- T1078.003 Local Accounts (index only)
- T1078.004 Cloud Accounts (index only)
- T1098.001 Additional Cloud Credentials (index only)
- T1098.002 Additional Email Delegate Permissions (index only)
- T1098.003 Additional Cloud Roles (index only)
- T1098.004 SSH Authorized Keys (index only)
- T1098.005 Device Registration (index only)
- T1098.006 Additional Container Cluster Roles (index only)
- T1098.007 Additional Local or Domain Groups (index only)
- T1134 Access Token Manipulation (index only)
- T1134.001 Token Impersonation/Theft (index only)
- T1134.002 Create Process with Token (index only)
- T1134.003 Make and Impersonate Token (index only)
- T1134.004 Parent PID Spoofing (index only)
- T1134.005 SID-History Injection (index only)
- T1484 Domain or Tenant Policy Modification (index only)
- T1484.001 Group Policy Modification (index only)
- T1484.002 Trust Modification (index only)
- T1543.001 Launch Agent (index only)
- T1543.002 Systemd Service (index only)
- T1543.004 Launch Daemon (index only)
- T1543.005 Container Service (index only)
- T1546 Event Triggered Execution (index only)
- T1546.001 Change Default File Association (index only)
- T1546.002 Screensaver (index only)
- T1546.003 Windows Management Instrumentation Event Subscription (index only)
- T1546.004 Unix Shell Configuration Modification (index only)
- T1546.005 Trap (index only)
- T1546.006 LC_LOAD_DYLIB Addition (index only)
- T1546.007 Netsh Helper DLL (index only)
- T1546.008 Accessibility Features (index only)
- T1546.009 AppCert DLLs (index only)
- T1546.010 AppInit DLLs (index only)
- T1546.011 Application Shimming (index only)
- T1546.012 Image File Execution Options Injection (index only)
- T1546.013 PowerShell Profile (index only)
- T1546.014 Emond (index only)
- T1546.015 Component Object Model Hijacking (index only)
- T1546.016 Installer Packages (index only)
- T1546.017 Udev Rules (index only)
- T1546.018 Python Startup Hooks (index only)
- T1547 Boot or Logon Autostart Execution (index only)
- T1547.002 Authentication Package (index only)
- T1547.003 Time Providers (index only)
- T1547.004 Winlogon Helper DLL (index only)
- T1547.005 Security Support Provider (index only)
- T1547.006 Kernel Modules and Extensions (index only)
- T1547.007 Re-opened Applications (index only)
- T1547.008 LSASS Driver (index only)
- T1547.009 Shortcut Modification (index only)
- T1547.010 Port Monitors (index only)
- T1547.012 Print Processors (index only)
- T1547.013 XDG Autostart Entries (index only)
- T1547.014 Active Setup (index only)
- T1547.015 Login Items (index only)
- T1548 Abuse Elevation Control Mechanism (index only)
- T1548.001 Setuid and Setgid (index only)
- T1548.002 Bypass User Account Control (index only)
- T1548.004 Elevated Execution with Prompt (index only)
- T1548.005 Temporary Elevated Cloud Access (index only)
- T1548.006 TCC Manipulation (index only)
- T1611 Escape to Host (index only)