{
  "schemaVersion": 1,
  "license": {
    "id": "CC0-1.0",
    "name": "CC0 1.0 Universal",
    "url": "https://creativecommons.org/publicdomain/zero/1.0/",
    "scope": "NOSIBLE-authored explanatory definitions, computed statistics, compilation structure and release files, only to the extent NOSIBLE owns or controls the applicable rights.",
    "exclusions": [
      "Underlying upstream ontology terms, codes and hierarchy",
      "Cited third-party publications and source content",
      "Third-party trademarks and database rights"
    ]
  },
  "ontology": {
    "id": "mitre_attack",
    "slug": "mitre-attack",
    "name": "MITRE ATT&CK Enterprise",
    "shortName": "MITRE ATT&CK",
    "field": "mitre_attack",
    "description": "The Enterprise ATT&CK hierarchy of adversary tactics, techniques and sub-techniques.",
    "structure": "Sourced from MITRE ATT&CK STIX 2.1 bundle for Enterprise matrix v16.1. Mobile and ICS bundles are excluded per\nStuart's directive. Each row is a (tactic, technique, subtechnique) triple. A technique that has no sub-techniques\nappears as a row with subtechnique=null. A technique that participates in multiple tactics (kill-chain phases) appears\nonce per tactic. Revoked and deprecated techniques are excluded.",
    "levels": [
      "tactic",
      "technique",
      "subtechnique"
    ],
    "apiFacets": [
      "mitre_attack_tactic",
      "mitre_attack_technique",
      "mitre_attack_subtechnique"
    ],
    "ontologyVersion": 1,
    "bundleVersion": 2,
    "released": "2026-04-29",
    "upstreamRelease": "ATT&CK v16.1 (Oct 2024) — Enterprise matrix only",
    "sourceUrl": "https://github.com/mitre-attack/attack-stix-data/blob/master/enterprise-attack/enterprise-attack-16.1.json",
    "sourcePath": "shared-utils/src/shared_utils/onto_utils/data/13_mitre_attack.yaml",
    "sourceSha256": "edd0a5615e100ef5b582e93601207650b6c63665846050bc0c10d32df3507ee3",
    "nodesFile": "nodes/mitre-attack.json",
    "nodeCount": 866,
    "leafCount": 731,
    "rootCount": 14,
    "maxDepth": 2
  },
  "dataset": {
    "name": "NOSIBLE World",
    "version": "1.2",
    "startDate": "2015-01-01",
    "endDate": "2026-07-01",
    "events": 15311040
  },
  "generatedAt": "2026-07-18T12:58:59.906Z",
  "methodology": {
    "unit": "One canonical event in events_map.ipc",
    "assignment": "Counts use the single top-ranked classification stored for each ontology level in the immutable World V1.2 event map.",
    "nullability": "Ontology paths are nullable. Coverage is measured from the first level, which is required whenever that ontology is assigned.",
    "duplicateLabels": "Where the same label occurs in more than one path at the same level, the public facet count aggregates that label across those paths and is marked label-across-paths.",
    "query": "Batched metadata filters recover complete value distributions beyond the API's 100-row facet display cap."
  },
  "statistics": {
    "assignedEvents": 1488001,
    "unclassifiedEvents": 13823039,
    "datasetShare": 0.09718484178736389,
    "roots": [
      {
        "id": "tactic-resource-development-ce56343a",
        "code": "Resource Development",
        "name": "Resource Development",
        "count": 321865,
        "assignedShare": 0.21630697828832104,
        "datasetShare": 0.021021759462453236
      },
      {
        "id": "tactic-impact-62036a70",
        "code": "Impact",
        "name": "Impact",
        "count": 226586,
        "assignedShare": 0.1522754352987666,
        "datasetShare": 0.014798864087612598
      },
      {
        "id": "tactic-reconnaissance-a9f8c2a8",
        "code": "Reconnaissance",
        "name": "Reconnaissance",
        "count": 216312,
        "assignedShare": 0.1453708700464583,
        "datasetShare": 0.014127845005956487
      },
      {
        "id": "tactic-defense-evasion-f44f34a8",
        "code": "Defense Evasion",
        "name": "Defense Evasion",
        "count": 194517,
        "assignedShare": 0.13072370247063006,
        "datasetShare": 0.012704362342466613
      },
      {
        "id": "tactic-collection-30c54a96",
        "code": "Collection",
        "name": "Collection",
        "count": 87454,
        "assignedShare": 0.05877280996450943,
        "datasetShare": 0.005711826237799653
      },
      {
        "id": "tactic-discovery-3b3290c7",
        "code": "Discovery",
        "name": "Discovery",
        "count": 75435,
        "assignedShare": 0.05069553044655212,
        "datasetShare": 0.004926837105774657
      },
      {
        "id": "tactic-persistence-4782469e",
        "code": "Persistence",
        "name": "Persistence",
        "count": 65742,
        "assignedShare": 0.04418142192108742,
        "datasetShare": 0.004293764499341652
      },
      {
        "id": "tactic-credential-access-9c65f4e0",
        "code": "Credential Access",
        "name": "Credential Access",
        "count": 53921,
        "assignedShare": 0.03623720682983412,
        "datasetShare": 0.003521707212573411
      },
      {
        "id": "tactic-command-and-control-6b4265ca",
        "code": "Command and Control",
        "name": "Command and Control",
        "count": 51281,
        "assignedShare": 0.0344630144737806,
        "datasetShare": 0.003349282609149999
      },
      {
        "id": "tactic-execution-6d525b71",
        "code": "Execution",
        "name": "Execution",
        "count": 46109,
        "assignedShare": 0.030987210358057553,
        "datasetShare": 0.003011487136079587
      },
      {
        "id": "tactic-initial-access-a0f45034",
        "code": "Initial Access",
        "name": "Initial Access",
        "count": 42947,
        "assignedShare": 0.028862211786147993,
        "datasetShare": 0.002804969486070182
      },
      {
        "id": "tactic-lateral-movement-4cec3f1f",
        "code": "Lateral Movement",
        "name": "Lateral Movement",
        "count": 40528,
        "assignedShare": 0.02723654083565804,
        "datasetShare": 0.0026469789119485023
      },
      {
        "id": "tactic-privilege-escalation-dc3564ae",
        "code": "Privilege Escalation",
        "name": "Privilege Escalation",
        "count": 35908,
        "assignedShare": 0.024131704212564373,
        "datasetShare": 0.002345235855957531
      },
      {
        "id": "tactic-exfiltration-fcb9fccc",
        "code": "Exfiltration",
        "name": "Exfiltration",
        "count": 29396,
        "assignedShare": 0.019755363067632346,
        "datasetShare": 0.0019199218341797815
      }
    ],
    "nodes": {
      "tactic-execution-6d525b71": {
        "count": 46109,
        "datasetShare": 0.003011487136079587,
        "assignedShare": 0.030987210358057553,
        "countScope": "exact-term"
      },
      "technique-windows-management-instrumentation-2216c5b9": {
        "count": 3078,
        "datasetShare": 0.00020103141262775096,
        "assignedShare": 0.0020685469969442226,
        "countScope": "exact-term"
      },
      "tactic-collection-30c54a96": {
        "count": 87454,
        "datasetShare": 0.005711826237799653,
        "assignedShare": 0.05877280996450943,
        "countScope": "exact-term"
      },
      "technique-screen-capture-b2992026": {
        "count": 908,
        "datasetShare": 0.00005930361360168872,
        "assignedShare": 0.0006102146436729545,
        "countScope": "exact-term"
      },
      "tactic-persistence-4782469e": {
        "count": 65742,
        "datasetShare": 0.004293764499341652,
        "assignedShare": 0.04418142192108742,
        "countScope": "exact-term"
      },
      "technique-boot-or-logon-initialization-scripts-4c5c694a": {
        "count": 2263,
        "datasetShare": 0.00014780184755575063,
        "assignedShare": 0.001520832311268608,
        "countScope": "label-across-paths"
      },
      "subtechnique-rc-scripts-aae4e32e": {
        "count": 1490,
        "datasetShare": 0.0000973154011745773,
        "assignedShare": 0.0010013434130756633,
        "countScope": "label-across-paths"
      },
      "subtechnique-logon-script-windows-7d7b2761": {
        "count": 14,
        "datasetShare": 9.14372896942337e-7,
        "assignedShare": 0.000009408595827556568,
        "countScope": "label-across-paths"
      },
      "subtechnique-network-logon-script-145db784": {
        "count": 71,
        "datasetShare": 0.0000046371768344932805,
        "assignedShare": 0.000047715021696894023,
        "countScope": "label-across-paths"
      },
      "subtechnique-startup-items-e5db1b40": {
        "count": 555,
        "datasetShare": 0.0000362483541287855,
        "assignedShare": 0.0003729836203067068,
        "countScope": "label-across-paths"
      },
      "subtechnique-login-hook-1482aeb1": {
        "count": 133,
        "datasetShare": 0.000008686542520952202,
        "assignedShare": 0.00008938166036178739,
        "countScope": "label-across-paths"
      },
      "tactic-privilege-escalation-dc3564ae": {
        "count": 35908,
        "datasetShare": 0.002345235855957531,
        "assignedShare": 0.024131704212564373,
        "countScope": "exact-term"
      },
      "technique-boot-or-logon-initialization-scripts-c8380360": {
        "count": 2263,
        "datasetShare": 0.00014780184755575063,
        "assignedShare": 0.001520832311268608,
        "countScope": "label-across-paths"
      },
      "subtechnique-rc-scripts-43d8e865": {
        "count": 1490,
        "datasetShare": 0.0000973154011745773,
        "assignedShare": 0.0010013434130756633,
        "countScope": "label-across-paths"
      },
      "subtechnique-logon-script-windows-148b27d3": {
        "count": 14,
        "datasetShare": 9.14372896942337e-7,
        "assignedShare": 0.000009408595827556568,
        "countScope": "label-across-paths"
      },
      "subtechnique-network-logon-script-5504302f": {
        "count": 71,
        "datasetShare": 0.0000046371768344932805,
        "assignedShare": 0.000047715021696894023,
        "countScope": "label-across-paths"
      },
      "subtechnique-startup-items-06973959": {
        "count": 555,
        "datasetShare": 0.0000362483541287855,
        "assignedShare": 0.0003729836203067068,
        "countScope": "label-across-paths"
      },
      "subtechnique-login-hook-81421812": {
        "count": 133,
        "datasetShare": 0.000008686542520952202,
        "assignedShare": 0.00008938166036178739,
        "countScope": "label-across-paths"
      },
      "tactic-credential-access-9c65f4e0": {
        "count": 53921,
        "datasetShare": 0.003521707212573411,
        "assignedShare": 0.03623720682983412,
        "countScope": "exact-term"
      },
      "technique-adversary-in-the-middle-2f2f0c73": {
        "count": 4173,
        "datasetShare": 0.000272548435638598,
        "assignedShare": 0.0028044335991709683,
        "countScope": "label-across-paths"
      },
      "subtechnique-dhcp-spoofing-86139cc7": {
        "count": 33,
        "datasetShare": 0.0000021553075427926517,
        "assignedShare": 0.000022177404450669053,
        "countScope": "label-across-paths"
      },
      "subtechnique-arp-cache-poisoning-b34c9789": {
        "count": 1202,
        "datasetShare": 0.0000785054444374778,
        "assignedShare": 0.0008077951560516425,
        "countScope": "label-across-paths"
      },
      "subtechnique-llmnr-nbt-ns-poisoning-and-smb-relay-fa4f5c97": {
        "count": 226,
        "datasetShare": 0.000014760591050640584,
        "assignedShare": 0.00015188161835912744,
        "countScope": "label-across-paths"
      },
      "subtechnique-evil-twin-d39f6b76": {
        "count": 2011,
        "datasetShare": 0.00013134313541078856,
        "assignedShare": 0.0013514775863725898,
        "countScope": "label-across-paths"
      },
      "technique-adversary-in-the-middle-c2fbcddf": {
        "count": 4173,
        "datasetShare": 0.000272548435638598,
        "assignedShare": 0.0028044335991709683,
        "countScope": "label-across-paths"
      },
      "subtechnique-dhcp-spoofing-189f29ee": {
        "count": 33,
        "datasetShare": 0.0000021553075427926517,
        "assignedShare": 0.000022177404450669053,
        "countScope": "label-across-paths"
      },
      "subtechnique-arp-cache-poisoning-dcaf9ec4": {
        "count": 1202,
        "datasetShare": 0.0000785054444374778,
        "assignedShare": 0.0008077951560516425,
        "countScope": "label-across-paths"
      },
      "subtechnique-llmnr-nbt-ns-poisoning-and-smb-relay-75a9f7a8": {
        "count": 226,
        "datasetShare": 0.000014760591050640584,
        "assignedShare": 0.00015188161835912744,
        "countScope": "label-across-paths"
      },
      "subtechnique-evil-twin-24fdbf4c": {
        "count": 2011,
        "datasetShare": 0.00013134313541078856,
        "assignedShare": 0.0013514775863725898,
        "countScope": "label-across-paths"
      },
      "tactic-discovery-3b3290c7": {
        "count": 75435,
        "datasetShare": 0.004926837105774657,
        "assignedShare": 0.05069553044655212,
        "countScope": "exact-term"
      },
      "technique-system-owner-user-discovery-56fc7185": {
        "count": 251,
        "datasetShare": 0.000016393399795180472,
        "assignedShare": 0.00016868268233690702,
        "countScope": "exact-term"
      },
      "tactic-resource-development-ce56343a": {
        "count": 321865,
        "datasetShare": 0.021021759462453236,
        "assignedShare": 0.21630697828832104,
        "countScope": "exact-term"
      },
      "technique-acquire-infrastructure-b8c1a911": {
        "count": 78850,
        "datasetShare": 0.005149878780278805,
        "assignedShare": 0.05299055578591681,
        "countScope": "exact-term"
      },
      "subtechnique-malvertising-89015553": {
        "count": 14164,
        "datasetShare": 0.0009250841223065187,
        "assignedShare": 0.009518810807250802,
        "countScope": "exact-term"
      },
      "subtechnique-domains-7c272a5d": {
        "count": 1875,
        "datasetShare": 0.00012246065584049158,
        "assignedShare": 0.0012600797983334689,
        "countScope": "label-across-paths"
      },
      "subtechnique-botnet-6aa46a89": {
        "count": 800,
        "datasetShare": 0.0000522498798252764,
        "assignedShare": 0.0005376340472889467,
        "countScope": "label-across-paths"
      },
      "subtechnique-server-3ef7db01": {
        "count": 1230,
        "datasetShare": 0.00008033419023136246,
        "assignedShare": 0.0008266123477067555,
        "countScope": "label-across-paths"
      },
      "subtechnique-dns-server-2bdd9ccd": {
        "count": 81,
        "datasetShare": 0.0000052903003323092356,
        "assignedShare": 0.00005443544728800585,
        "countScope": "label-across-paths"
      },
      "subtechnique-virtual-private-server-780da84d": {
        "count": 4268,
        "datasetShare": 0.0002787531088678496,
        "assignedShare": 0.0028682776422865306,
        "countScope": "label-across-paths"
      },
      "subtechnique-serverless-967f2454": {
        "count": 505,
        "datasetShare": 0.000032982736639705726,
        "assignedShare": 0.0003393814923511476,
        "countScope": "label-across-paths"
      },
      "subtechnique-web-services-ba0f6d30": {
        "count": 1285,
        "datasetShare": 0.00008392636946935022,
        "assignedShare": 0.0008635746884578707,
        "countScope": "label-across-paths"
      },
      "technique-container-and-resource-discovery-44fbb23f": {
        "count": 2662,
        "datasetShare": 0.00017386147511860723,
        "assignedShare": 0.0017889772923539702,
        "countScope": "exact-term"
      },
      "tactic-reconnaissance-a9f8c2a8": {
        "count": 216312,
        "datasetShare": 0.014127845005956487,
        "assignedShare": 0.1453708700464583,
        "countScope": "exact-term"
      },
      "technique-gather-victim-host-information-b12a5a67": {
        "count": 4380,
        "datasetShare": 0.0002860680920433883,
        "assignedShare": 0.0029435464089069834,
        "countScope": "exact-term"
      },
      "subtechnique-hardware-d96120d6": {
        "count": 2706,
        "datasetShare": 0.00017673521850899743,
        "assignedShare": 0.0018185471649548623,
        "countScope": "exact-term"
      },
      "subtechnique-firmware-d4a05a59": {
        "count": 540,
        "datasetShare": 0.00003526866888206157,
        "assignedShare": 0.00036290298192003906,
        "countScope": "exact-term"
      },
      "subtechnique-software-5d085403": {
        "count": 987,
        "datasetShare": 0.00006446328923443477,
        "assignedShare": 0.000663306005842738,
        "countScope": "exact-term"
      },
      "subtechnique-client-configurations-4788a301": {
        "count": 27,
        "datasetShare": 0.0000017634334441030785,
        "assignedShare": 0.000018145149096001953,
        "countScope": "exact-term"
      },
      "technique-os-credential-dumping-2757c39e": {
        "count": 8971,
        "datasetShare": 0.0005859170898906932,
        "assignedShare": 0.006028893797786426,
        "countScope": "exact-term"
      },
      "subtechnique-security-account-manager-6dfa5dd5": {
        "count": 971,
        "datasetShare": 0.00006341829163792923,
        "assignedShare": 0.0006525533248969591,
        "countScope": "exact-term"
      },
      "subtechnique-lsa-secrets-9aa59673": {
        "count": 1901,
        "datasetShare": 0.00012415877693481306,
        "assignedShare": 0.0012775529048703596,
        "countScope": "exact-term"
      },
      "subtechnique-dcsync-5a70819c": {
        "count": 2576,
        "datasetShare": 0.00016824461303739001,
        "assignedShare": 0.0017311816322704084,
        "countScope": "exact-term"
      },
      "subtechnique-proc-filesystem-641da49a": {
        "count": 261,
        "datasetShare": 0.000017046523292996425,
        "assignedShare": 0.00017540310792801887,
        "countScope": "exact-term"
      },
      "subtechnique-ntds-0f913da5": {
        "count": 2146,
        "datasetShare": 0.00014016030263130395,
        "assignedShare": 0.0014422033318525996,
        "countScope": "exact-term"
      },
      "subtechnique-cached-domain-credentials-7a88e6bd": {
        "count": 46,
        "datasetShare": 0.000003004368089953393,
        "assignedShare": 0.000030913957719114436,
        "countScope": "exact-term"
      },
      "subtechnique-lsass-memory-33d6a73a": {
        "count": 1004,
        "datasetShare": 0.00006557359918072189,
        "assignedShare": 0.0006747307293476281,
        "countScope": "exact-term"
      },
      "subtechnique-etc-passwd-and-etc-shadow-8fa81e56": {
        "count": 10,
        "datasetShare": 6.53123497815955e-7,
        "assignedShare": 0.000006720425591111834,
        "countScope": "exact-term"
      },
      "technique-shared-modules-f15c54ba": {
        "count": 109,
        "datasetShare": 0.00000711904612619391,
        "assignedShare": 0.00007325263894311899,
        "countScope": "exact-term"
      },
      "technique-data-from-configuration-repository-f3e55c57": {
        "count": 868,
        "datasetShare": 0.000056691119610424894,
        "assignedShare": 0.0005833329413085072,
        "countScope": "exact-term"
      },
      "subtechnique-network-device-configuration-dump-55930ddb": {
        "count": 79,
        "datasetShare": 0.000005159675632746045,
        "assignedShare": 0.000053091362169783486,
        "countScope": "exact-term"
      },
      "subtechnique-snmp-mib-dump-a1222935": {
        "count": 718,
        "datasetShare": 0.00004689426714318557,
        "assignedShare": 0.00048252655744182967,
        "countScope": "exact-term"
      },
      "tactic-defense-evasion-f44f34a8": {
        "count": 194517,
        "datasetShare": 0.012704362342466613,
        "assignedShare": 0.13072370247063006,
        "countScope": "exact-term"
      },
      "technique-direct-volume-access-70bb7293": {
        "count": 6194,
        "datasetShare": 0.00040454469454720253,
        "assignedShare": 0.00416263161113467,
        "countScope": "exact-term"
      },
      "technique-modify-cloud-resource-hierarchy-298faf0b": {
        "count": 1482,
        "datasetShare": 0.00009679290237632453,
        "assignedShare": 0.0009959670726027738,
        "countScope": "exact-term"
      },
      "technique-rootkit-5554f781": {
        "count": 116,
        "datasetShare": 0.000007576232574665079,
        "assignedShare": 0.00007795693685689727,
        "countScope": "exact-term"
      },
      "technique-audio-capture-5394e32f": {
        "count": 8496,
        "datasetShare": 0.0005548937237444354,
        "assignedShare": 0.005709673582208614,
        "countScope": "exact-term"
      },
      "technique-create-or-modify-system-process-e6e35751": {
        "count": 2666,
        "datasetShare": 0.00017412272451773362,
        "assignedShare": 0.001791665462590415,
        "countScope": "label-across-paths"
      },
      "subtechnique-launch-daemon-f03dad3d": {
        "count": 38,
        "datasetShare": 0.0000024818692917006292,
        "assignedShare": 0.00002553761724622497,
        "countScope": "label-across-paths"
      },
      "subtechnique-container-service-fea1ca40": {
        "count": 918,
        "datasetShare": 0.00005995673709950467,
        "assignedShare": 0.0006169350692640664,
        "countScope": "label-across-paths"
      },
      "subtechnique-launch-agent-dc06ea3f": {
        "count": 1461,
        "datasetShare": 0.00009542134303091103,
        "assignedShare": 0.000981854178861439,
        "countScope": "label-across-paths"
      },
      "subtechnique-systemd-service-9bdb3cff": {
        "count": 53,
        "datasetShare": 0.0000034615545384245618,
        "assignedShare": 0.00003561825563289272,
        "countScope": "label-across-paths"
      },
      "subtechnique-windows-service-4552c119": {
        "count": 170,
        "datasetShare": 0.000011103099462871235,
        "assignedShare": 0.00011424723504890118,
        "countScope": "label-across-paths"
      },
      "technique-create-or-modify-system-process-8acecde9": {
        "count": 2666,
        "datasetShare": 0.00017412272451773362,
        "assignedShare": 0.001791665462590415,
        "countScope": "label-across-paths"
      },
      "subtechnique-launch-daemon-11226145": {
        "count": 38,
        "datasetShare": 0.0000024818692917006292,
        "assignedShare": 0.00002553761724622497,
        "countScope": "label-across-paths"
      },
      "subtechnique-container-service-9f0decf5": {
        "count": 918,
        "datasetShare": 0.00005995673709950467,
        "assignedShare": 0.0006169350692640664,
        "countScope": "label-across-paths"
      },
      "subtechnique-launch-agent-56ae830c": {
        "count": 1461,
        "datasetShare": 0.00009542134303091103,
        "assignedShare": 0.000981854178861439,
        "countScope": "label-across-paths"
      },
      "subtechnique-systemd-service-35e4e1a2": {
        "count": 53,
        "datasetShare": 0.0000034615545384245618,
        "assignedShare": 0.00003561825563289272,
        "countScope": "label-across-paths"
      },
      "subtechnique-windows-service-1e81e36c": {
        "count": 170,
        "datasetShare": 0.000011103099462871235,
        "assignedShare": 0.00011424723504890118,
        "countScope": "label-across-paths"
      },
      "technique-external-remote-services-b3a0298f": {
        "count": 2853,
        "datasetShare": 0.00018633613392689196,
        "assignedShare": 0.0019173374211442062,
        "countScope": "label-across-paths"
      },
      "tactic-initial-access-a0f45034": {
        "count": 42947,
        "datasetShare": 0.002804969486070182,
        "assignedShare": 0.028862211786147993,
        "countScope": "exact-term"
      },
      "technique-external-remote-services-c1cf383e": {
        "count": 2853,
        "datasetShare": 0.00018633613392689196,
        "assignedShare": 0.0019173374211442062,
        "countScope": "label-across-paths"
      },
      "technique-steal-web-session-cookie-182e98f8": {
        "count": 72,
        "datasetShare": 0.000004702489184274876,
        "assignedShare": 0.0000483870642560052,
        "countScope": "exact-term"
      },
      "technique-modify-cloud-compute-infrastructure-eb012695": {
        "count": 2323,
        "datasetShare": 0.00015172058854264636,
        "assignedShare": 0.001561154864815279,
        "countScope": "exact-term"
      },
      "subtechnique-create-snapshot-7b80e524": {
        "count": 412,
        "datasetShare": 0.000026908688110017348,
        "assignedShare": 0.00027688153435380755,
        "countScope": "exact-term"
      },
      "subtechnique-delete-cloud-instance-39653554": {
        "count": 220,
        "datasetShare": 0.00001436871695195101,
        "assignedShare": 0.00014784936300446034,
        "countScope": "exact-term"
      },
      "subtechnique-revert-cloud-instance-8eba2536": {
        "count": 775,
        "datasetShare": 0.00005061707108073651,
        "assignedShare": 0.0005208329833111671,
        "countScope": "exact-term"
      },
      "subtechnique-create-cloud-instance-ffa237a8": {
        "count": 748,
        "datasetShare": 0.000048853637636633437,
        "assignedShare": 0.0005026878342151652,
        "countScope": "exact-term"
      },
      "subtechnique-modify-cloud-compute-configurations-00804d92": {
        "count": 100,
        "datasetShare": 0.00000653123497815955,
        "assignedShare": 0.00006720425591111834,
        "countScope": "exact-term"
      },
      "technique-permission-groups-discovery-c743a238": {
        "count": 6460,
        "datasetShare": 0.0004219177795891069,
        "assignedShare": 0.004341394931858244,
        "countScope": "exact-term"
      },
      "subtechnique-cloud-groups-48240375": {
        "count": 1463,
        "datasetShare": 0.00009555196773047423,
        "assignedShare": 0.0009831982639796613,
        "countScope": "exact-term"
      },
      "subtechnique-domain-groups-cfa2b50c": {
        "count": 2353,
        "datasetShare": 0.0001536799590360942,
        "assignedShare": 0.0015813161415886145,
        "countScope": "exact-term"
      },
      "subtechnique-local-groups-c98a39b9": {
        "count": 1356,
        "datasetShare": 0.0000885635463038435,
        "assignedShare": 0.0009112897101547647,
        "countScope": "exact-term"
      },
      "technique-email-collection-3b87353f": {
        "count": 3964,
        "datasetShare": 0.0002588981545342446,
        "assignedShare": 0.002663976704316731,
        "countScope": "exact-term"
      },
      "subtechnique-remote-email-collection-4699daad": {
        "count": 705,
        "datasetShare": 0.00004604520659602483,
        "assignedShare": 0.00047379000417338427,
        "countScope": "exact-term"
      },
      "subtechnique-email-forwarding-rule-3e847434": {
        "count": 289,
        "datasetShare": 0.000018875269086881102,
        "assignedShare": 0.000194220299583132,
        "countScope": "exact-term"
      },
      "subtechnique-local-email-collection-a9bdee9e": {
        "count": 585,
        "datasetShare": 0.00003820772462223337,
        "assignedShare": 0.0003931448970800423,
        "countScope": "exact-term"
      },
      "technique-search-victim-owned-websites-4c4e1a49": {
        "count": 1267,
        "datasetShare": 0.0000827507471732815,
        "assignedShare": 0.0008514779223938694,
        "countScope": "exact-term"
      },
      "tactic-impact-62036a70": {
        "count": 226586,
        "datasetShare": 0.014798864087612598,
        "assignedShare": 0.1522754352987666,
        "countScope": "exact-term"
      },
      "technique-disk-wipe-497a81db": {
        "count": 1378,
        "datasetShare": 0.0000900004179990386,
        "assignedShare": 0.0009260746464552107,
        "countScope": "exact-term"
      },
      "subtechnique-disk-structure-wipe-8e83ac46": {
        "count": 199,
        "datasetShare": 0.000012997157606537506,
        "assignedShare": 0.0001337364692631255,
        "countScope": "exact-term"
      },
      "subtechnique-disk-content-wipe-8544a0b9": {
        "count": 330,
        "datasetShare": 0.000021553075427926517,
        "assignedShare": 0.0002217740445066905,
        "countScope": "exact-term"
      },
      "technique-group-policy-discovery-e275c46c": {
        "count": 2293,
        "datasetShare": 0.00014976121804919848,
        "assignedShare": 0.0015409935880419435,
        "countScope": "exact-term"
      },
      "technique-data-from-removable-media-e652f3d6": {
        "count": 420,
        "datasetShare": 0.00002743118690827011,
        "assignedShare": 0.00028225787482669704,
        "countScope": "exact-term"
      },
      "technique-boot-or-logon-autostart-execution-80350d80": {
        "count": 9634,
        "datasetShare": 0.0006292191777958911,
        "assignedShare": 0.006474458014477141,
        "countScope": "label-across-paths"
      },
      "subtechnique-shortcut-modification-e46c079e": {
        "count": 97,
        "datasetShare": 0.000006335297928814764,
        "assignedShare": 0.00006518812823378478,
        "countScope": "label-across-paths"
      },
      "subtechnique-kernel-modules-and-extensions-8286f74e": {
        "count": 501,
        "datasetShare": 0.000032721487240579345,
        "assignedShare": 0.00033669332211470285,
        "countScope": "label-across-paths"
      },
      "subtechnique-re-opened-applications-4dd4df07": {
        "count": 1529,
        "datasetShare": 0.00009986258281605952,
        "assignedShare": 0.0010275530728809995,
        "countScope": "label-across-paths"
      },
      "subtechnique-winlogon-helper-dll-a4209b4f": {
        "count": 16,
        "datasetShare": 0.000001044997596505528,
        "assignedShare": 0.000010752680945778935,
        "countScope": "label-across-paths"
      },
      "subtechnique-security-support-provider-1e5bf227": {
        "count": 530,
        "datasetShare": 0.00003461554538424562,
        "assignedShare": 0.0003561825563289272,
        "countScope": "label-across-paths"
      },
      "subtechnique-registry-run-keys-startup-folder-e19d0d32": {
        "count": 33,
        "datasetShare": 0.0000021553075427926517,
        "assignedShare": 0.000022177404450669053,
        "countScope": "label-across-paths"
      },
      "subtechnique-lsass-driver-f5181d15": {
        "count": 1274,
        "datasetShare": 0.00008320793362175267,
        "assignedShare": 0.0008561822203076476,
        "countScope": "label-across-paths"
      },
      "subtechnique-print-processors-a44db66b": {
        "count": 2602,
        "datasetShare": 0.0001699427341317115,
        "assignedShare": 0.0017486547388072993,
        "countScope": "label-across-paths"
      },
      "subtechnique-active-setup-5dcd9e5b": {
        "count": 18,
        "datasetShare": 0.000001175622296068719,
        "assignedShare": 0.0000120967660640013,
        "countScope": "label-across-paths"
      },
      "subtechnique-login-items-1cc9210b": {
        "count": 89,
        "datasetShare": 0.000005812799130562,
        "assignedShare": 0.00005981178776089532,
        "countScope": "label-across-paths"
      },
      "subtechnique-xdg-autostart-entries-e0be6b6a": {
        "count": 32,
        "datasetShare": 0.000002089995193011056,
        "assignedShare": 0.00002150536189155787,
        "countScope": "label-across-paths"
      },
      "subtechnique-time-providers-cbf22b74": {
        "count": 852,
        "datasetShare": 0.00005564612201391937,
        "assignedShare": 0.0005725802603627283,
        "countScope": "label-across-paths"
      },
      "subtechnique-authentication-package-cceda209": {
        "count": 89,
        "datasetShare": 0.000005812799130562,
        "assignedShare": 0.00005981178776089532,
        "countScope": "label-across-paths"
      },
      "subtechnique-port-monitors-50a61849": {
        "count": 1714,
        "datasetShare": 0.00011194536752565468,
        "assignedShare": 0.0011518809463165684,
        "countScope": "label-across-paths"
      },
      "technique-boot-or-logon-autostart-execution-dd82f72e": {
        "count": 9634,
        "datasetShare": 0.0006292191777958911,
        "assignedShare": 0.006474458014477141,
        "countScope": "label-across-paths"
      },
      "subtechnique-shortcut-modification-39bf8a9e": {
        "count": 97,
        "datasetShare": 0.000006335297928814764,
        "assignedShare": 0.00006518812823378478,
        "countScope": "label-across-paths"
      },
      "subtechnique-kernel-modules-and-extensions-df8f6d02": {
        "count": 501,
        "datasetShare": 0.000032721487240579345,
        "assignedShare": 0.00033669332211470285,
        "countScope": "label-across-paths"
      },
      "subtechnique-re-opened-applications-0c51c6fb": {
        "count": 1529,
        "datasetShare": 0.00009986258281605952,
        "assignedShare": 0.0010275530728809995,
        "countScope": "label-across-paths"
      },
      "subtechnique-winlogon-helper-dll-80cf92b3": {
        "count": 16,
        "datasetShare": 0.000001044997596505528,
        "assignedShare": 0.000010752680945778935,
        "countScope": "label-across-paths"
      },
      "subtechnique-security-support-provider-c42c948b": {
        "count": 530,
        "datasetShare": 0.00003461554538424562,
        "assignedShare": 0.0003561825563289272,
        "countScope": "label-across-paths"
      },
      "subtechnique-registry-run-keys-startup-folder-3a3ddac9": {
        "count": 33,
        "datasetShare": 0.0000021553075427926517,
        "assignedShare": 0.000022177404450669053,
        "countScope": "label-across-paths"
      },
      "subtechnique-lsass-driver-8f1f9e1e": {
        "count": 1274,
        "datasetShare": 0.00008320793362175267,
        "assignedShare": 0.0008561822203076476,
        "countScope": "label-across-paths"
      },
      "subtechnique-print-processors-9fb44c2a": {
        "count": 2602,
        "datasetShare": 0.0001699427341317115,
        "assignedShare": 0.0017486547388072993,
        "countScope": "label-across-paths"
      },
      "subtechnique-active-setup-e8634ac0": {
        "count": 18,
        "datasetShare": 0.000001175622296068719,
        "assignedShare": 0.0000120967660640013,
        "countScope": "label-across-paths"
      },
      "subtechnique-login-items-5510b413": {
        "count": 89,
        "datasetShare": 0.000005812799130562,
        "assignedShare": 0.00005981178776089532,
        "countScope": "label-across-paths"
      },
      "subtechnique-xdg-autostart-entries-dd59968e": {
        "count": 32,
        "datasetShare": 0.000002089995193011056,
        "assignedShare": 0.00002150536189155787,
        "countScope": "label-across-paths"
      },
      "subtechnique-time-providers-a0a44179": {
        "count": 852,
        "datasetShare": 0.00005564612201391937,
        "assignedShare": 0.0005725802603627283,
        "countScope": "label-across-paths"
      },
      "subtechnique-authentication-package-0876ea70": {
        "count": 89,
        "datasetShare": 0.000005812799130562,
        "assignedShare": 0.00005981178776089532,
        "countScope": "label-across-paths"
      },
      "subtechnique-port-monitors-f5d43242": {
        "count": 1714,
        "datasetShare": 0.00011194536752565468,
        "assignedShare": 0.0011518809463165684,
        "countScope": "label-across-paths"
      },
      "technique-weaken-encryption-a355f204": {
        "count": 12490,
        "datasetShare": 0.0008157512487721279,
        "assignedShare": 0.008393811563298681,
        "countScope": "exact-term"
      },
      "subtechnique-reduce-key-space-ede5be8b": {
        "count": 837,
        "datasetShare": 0.00005466643676719544,
        "assignedShare": 0.0005624996219760605,
        "countScope": "exact-term"
      },
      "subtechnique-disable-crypto-hardware-93223394": {
        "count": 10471,
        "datasetShare": 0.0006838856145630865,
        "assignedShare": 0.007036957636453202,
        "countScope": "exact-term"
      },
      "technique-service-stop-45014210": {
        "count": 7856,
        "datasetShare": 0.0005130938198842143,
        "assignedShare": 0.0052795663443774565,
        "countScope": "exact-term"
      },
      "technique-device-driver-discovery-593fa833": {
        "count": 3404,
        "datasetShare": 0.00022232323865655108,
        "assignedShare": 0.002287632871214468,
        "countScope": "exact-term"
      },
      "technique-hide-artifacts-29bd3ec0": {
        "count": 8010,
        "datasetShare": 0.00052315192175058,
        "assignedShare": 0.005383060898480579,
        "countScope": "exact-term"
      },
      "subtechnique-hidden-window-cab7d74a": {
        "count": 245,
        "datasetShare": 0.000016001525696490897,
        "assignedShare": 0.00016465042698223992,
        "countScope": "exact-term"
      },
      "subtechnique-ignore-process-interrupts-e0bfdaa5": {
        "count": 214,
        "datasetShare": 0.000013976842853261438,
        "assignedShare": 0.00014381710764979324,
        "countScope": "exact-term"
      },
      "subtechnique-hidden-users-cc599c13": {
        "count": 129,
        "datasetShare": 0.00000842529312182582,
        "assignedShare": 0.00008669349012534266,
        "countScope": "exact-term"
      },
      "subtechnique-file-path-exclusions-ebf51372": {
        "count": 469,
        "datasetShare": 0.00003063149204756829,
        "assignedShare": 0.000315187960223145,
        "countScope": "exact-term"
      },
      "subtechnique-email-hiding-rules-2ed94928": {
        "count": 1280,
        "datasetShare": 0.00008359980772044224,
        "assignedShare": 0.0008602144756623148,
        "countScope": "exact-term"
      },
      "subtechnique-resource-forking-dfd5b1ff": {
        "count": 221,
        "datasetShare": 0.000014434029301732606,
        "assignedShare": 0.00014852140556357153,
        "countScope": "exact-term"
      },
      "subtechnique-run-virtual-instance-dc4a7e46": {
        "count": 1390,
        "datasetShare": 0.00009078416619641774,
        "assignedShare": 0.0009341391571645449,
        "countScope": "exact-term"
      },
      "subtechnique-process-argument-spoofing-f60ede45": {
        "count": 60,
        "datasetShare": 0.00000391874098689573,
        "assignedShare": 0.000040322553546671,
        "countScope": "exact-term"
      },
      "subtechnique-hidden-files-and-directories-308f2db0": {
        "count": 389,
        "datasetShare": 0.00002540650406504065,
        "assignedShare": 0.0002614245554942503,
        "countScope": "exact-term"
      },
      "subtechnique-ntfs-file-attributes-528257eb": {
        "count": 1245,
        "datasetShare": 0.0000813138754780864,
        "assignedShare": 0.0008366929860934233,
        "countScope": "exact-term"
      },
      "subtechnique-vba-stomping-e8af18f0": {
        "count": 275,
        "datasetShare": 0.000017960896189938765,
        "assignedShare": 0.00018481170375557544,
        "countScope": "exact-term"
      },
      "subtechnique-hidden-file-system-b7d5283b": {
        "count": 552,
        "datasetShare": 0.00003605241707944072,
        "assignedShare": 0.0003709674926293732,
        "countScope": "exact-term"
      },
      "tactic-lateral-movement-4cec3f1f": {
        "count": 40528,
        "datasetShare": 0.0026469789119485023,
        "assignedShare": 0.02723654083565804,
        "countScope": "exact-term"
      },
      "technique-taint-shared-content-c519fc67": {
        "count": 464,
        "datasetShare": 0.000030304930298660314,
        "assignedShare": 0.0003118277474275891,
        "countScope": "exact-term"
      },
      "technique-office-application-startup-7fb04d29": {
        "count": 5065,
        "datasetShare": 0.00033080705164378123,
        "assignedShare": 0.003403895561898144,
        "countScope": "exact-term"
      },
      "subtechnique-office-test-a2b19983": {
        "count": 1319,
        "datasetShare": 0.00008614698936192447,
        "assignedShare": 0.0008864241354676509,
        "countScope": "exact-term"
      },
      "subtechnique-office-template-macros-fbfd1ff5": {
        "count": 262,
        "datasetShare": 0.000017111835642778023,
        "assignedShare": 0.00017607515048713004,
        "countScope": "exact-term"
      },
      "subtechnique-outlook-home-page-6ed10121": {
        "count": 124,
        "datasetShare": 0.000008098731372917841,
        "assignedShare": 0.00008333327732978674,
        "countScope": "exact-term"
      },
      "subtechnique-outlook-forms-546be2f4": {
        "count": 300,
        "datasetShare": 0.00001959370493447865,
        "assignedShare": 0.00020161276773335502,
        "countScope": "exact-term"
      },
      "subtechnique-add-ins-7c9adb6e": {
        "count": 232,
        "datasetShare": 0.000015152465149330157,
        "assignedShare": 0.00015591387371379455,
        "countScope": "exact-term"
      },
      "subtechnique-outlook-rules-ffd6a386": {
        "count": 941,
        "datasetShare": 0.00006145892114448136,
        "assignedShare": 0.0006323920481236235,
        "countScope": "exact-term"
      },
      "technique-automated-collection-fa74ae4b": {
        "count": 598,
        "datasetShare": 0.00003905678516939411,
        "assignedShare": 0.00040188145034848765,
        "countScope": "exact-term"
      },
      "technique-clipboard-data-daedce20": {
        "count": 283,
        "datasetShare": 0.000018483394988191527,
        "assignedShare": 0.0001901880442284649,
        "countScope": "exact-term"
      },
      "technique-system-service-discovery-16499e28": {
        "count": 379,
        "datasetShare": 0.000024753380567224694,
        "assignedShare": 0.0002547041299031385,
        "countScope": "exact-term"
      },
      "technique-network-sniffing-a544397d": {
        "count": 444,
        "datasetShare": 0.000028998683303028403,
        "assignedShare": 0.00029838689624536545,
        "countScope": "label-across-paths"
      },
      "technique-network-sniffing-5c5068d8": {
        "count": 444,
        "datasetShare": 0.000028998683303028403,
        "assignedShare": 0.00029838689624536545,
        "countScope": "label-across-paths"
      },
      "technique-data-from-cloud-storage-9756a967": {
        "count": 2227,
        "datasetShare": 0.0001454506029636132,
        "assignedShare": 0.0014966387791406053,
        "countScope": "exact-term"
      },
      "technique-network-share-discovery-d8a94d5b": {
        "count": 2511,
        "datasetShare": 0.0001639993103015863,
        "assignedShare": 0.0016874988659281815,
        "countScope": "exact-term"
      },
      "technique-peripheral-device-discovery-6894379a": {
        "count": 973,
        "datasetShare": 0.00006354891633749243,
        "assignedShare": 0.0006538974100151815,
        "countScope": "exact-term"
      },
      "technique-system-information-discovery-3804b87e": {
        "count": 2221,
        "datasetShare": 0.00014505872886492362,
        "assignedShare": 0.0014926065237859383,
        "countScope": "exact-term"
      },
      "tactic-command-and-control-6b4265ca": {
        "count": 51281,
        "datasetShare": 0.003349282609149999,
        "assignedShare": 0.0344630144737806,
        "countScope": "exact-term"
      },
      "technique-application-layer-protocol-d078bda1": {
        "count": 6294,
        "datasetShare": 0.00041107592952536207,
        "assignedShare": 0.004229835867045788,
        "countScope": "exact-term"
      },
      "subtechnique-file-transfer-protocols-896894a9": {
        "count": 3364,
        "datasetShare": 0.00021971074466528727,
        "assignedShare": 0.002260751168850021,
        "countScope": "exact-term"
      },
      "subtechnique-dns-ee6bf5c6": {
        "count": 659,
        "datasetShare": 0.000043040838506071436,
        "assignedShare": 0.0004428760464542699,
        "countScope": "label-across-paths"
      },
      "subtechnique-publish-subscribe-protocols-ae9b9ca5": {
        "count": 498,
        "datasetShare": 0.00003252555019123456,
        "assignedShare": 0.00033467719443736933,
        "countScope": "exact-term"
      },
      "subtechnique-mail-protocols-c0976703": {
        "count": 937,
        "datasetShare": 0.00006119767174535498,
        "assignedShare": 0.0006297038778871789,
        "countScope": "exact-term"
      },
      "subtechnique-web-protocols-71edcc9c": {
        "count": 278,
        "datasetShare": 0.00001815683323928355,
        "assignedShare": 0.000186827831432909,
        "countScope": "exact-term"
      },
      "technique-scheduled-task-job-7019a73b": {
        "count": 4261,
        "datasetShare": 0.0002782959224193784,
        "assignedShare": 0.0028635733443727524,
        "countScope": "label-across-paths"
      },
      "subtechnique-cron-7fed3ee9": {
        "count": 507,
        "datasetShare": 0.00003311336133926892,
        "assignedShare": 0.00034072557746936996,
        "countScope": "label-across-paths"
      },
      "subtechnique-scheduled-task-521dff60": {
        "count": 332,
        "datasetShare": 0.000021683700127489708,
        "assignedShare": 0.0002231181296249129,
        "countScope": "label-across-paths"
      },
      "subtechnique-systemd-timers-2dbdf684": {
        "count": 89,
        "datasetShare": 0.000005812799130562,
        "assignedShare": 0.00005981178776089532,
        "countScope": "label-across-paths"
      },
      "subtechnique-container-orchestration-job-5544422a": {
        "count": 586,
        "datasetShare": 0.000038273036972014965,
        "assignedShare": 0.00039381693963915344,
        "countScope": "label-across-paths"
      },
      "subtechnique-at-ce08e866": {
        "count": 2704,
        "datasetShare": 0.00017660459380943423,
        "assignedShare": 0.00181720307983664,
        "countScope": "label-across-paths"
      },
      "technique-scheduled-task-job-5fe97a1a": {
        "count": 4261,
        "datasetShare": 0.0002782959224193784,
        "assignedShare": 0.0028635733443727524,
        "countScope": "label-across-paths"
      },
      "subtechnique-cron-d9d97f95": {
        "count": 507,
        "datasetShare": 0.00003311336133926892,
        "assignedShare": 0.00034072557746936996,
        "countScope": "label-across-paths"
      },
      "subtechnique-scheduled-task-9403fd7a": {
        "count": 332,
        "datasetShare": 0.000021683700127489708,
        "assignedShare": 0.0002231181296249129,
        "countScope": "label-across-paths"
      },
      "subtechnique-systemd-timers-7b0492ae": {
        "count": 89,
        "datasetShare": 0.000005812799130562,
        "assignedShare": 0.00005981178776089532,
        "countScope": "label-across-paths"
      },
      "subtechnique-container-orchestration-job-53d98e2c": {
        "count": 586,
        "datasetShare": 0.000038273036972014965,
        "assignedShare": 0.00039381693963915344,
        "countScope": "label-across-paths"
      },
      "subtechnique-at-94ebca8f": {
        "count": 2704,
        "datasetShare": 0.00017660459380943423,
        "assignedShare": 0.00181720307983664,
        "countScope": "label-across-paths"
      },
      "technique-scheduled-task-job-14efe773": {
        "count": 4261,
        "datasetShare": 0.0002782959224193784,
        "assignedShare": 0.0028635733443727524,
        "countScope": "label-across-paths"
      },
      "subtechnique-cron-332953c7": {
        "count": 507,
        "datasetShare": 0.00003311336133926892,
        "assignedShare": 0.00034072557746936996,
        "countScope": "label-across-paths"
      },
      "subtechnique-scheduled-task-65c86c29": {
        "count": 332,
        "datasetShare": 0.000021683700127489708,
        "assignedShare": 0.0002231181296249129,
        "countScope": "label-across-paths"
      },
      "subtechnique-systemd-timers-f7b9ec41": {
        "count": 89,
        "datasetShare": 0.000005812799130562,
        "assignedShare": 0.00005981178776089532,
        "countScope": "label-across-paths"
      },
      "subtechnique-container-orchestration-job-602e8b87": {
        "count": 586,
        "datasetShare": 0.000038273036972014965,
        "assignedShare": 0.00039381693963915344,
        "countScope": "label-across-paths"
      },
      "subtechnique-at-2414a762": {
        "count": 2704,
        "datasetShare": 0.00017660459380943423,
        "assignedShare": 0.00181720307983664,
        "countScope": "label-across-paths"
      },
      "technique-browser-extensions-69ec2fb1": {
        "count": 2102,
        "datasetShare": 0.00013728655924091375,
        "assignedShare": 0.0014126334592517076,
        "countScope": "exact-term"
      },
      "technique-native-api-859a3d94": {
        "count": 945,
        "datasetShare": 0.00006172017054360774,
        "assignedShare": 0.0006350802183600683,
        "countScope": "exact-term"
      },
      "technique-indirect-command-execution-7b5dfd43": {
        "count": 174,
        "datasetShare": 0.000011364348861997617,
        "assignedShare": 0.00011693540528534591,
        "countScope": "exact-term"
      },
      "technique-replication-through-removable-media-466b3c75": {
        "count": 1272,
        "datasetShare": 0.00008307730892218948,
        "assignedShare": 0.0008548381351894253,
        "countScope": "label-across-paths"
      },
      "technique-replication-through-removable-media-81251dcf": {
        "count": 1272,
        "datasetShare": 0.00008307730892218948,
        "assignedShare": 0.0008548381351894253,
        "countScope": "label-across-paths"
      },
      "technique-data-from-local-system-23b39bfa": {
        "count": 249,
        "datasetShare": 0.00001626277509561728,
        "assignedShare": 0.00016733859721868466,
        "countScope": "exact-term"
      },
      "technique-deobfuscate-decode-files-or-information-0c3fcac3": {
        "count": 237,
        "datasetShare": 0.000015479026898238135,
        "assignedShare": 0.00015927408650935046,
        "countScope": "exact-term"
      },
      "technique-impair-defenses-640d2708": {
        "count": 25831,
        "datasetShare": 0.0016870833072083935,
        "assignedShare": 0.017359531344400977,
        "countScope": "exact-term"
      },
      "subtechnique-impair-command-history-logging-c691cb6a": {
        "count": 63,
        "datasetShare": 0.000004114678036240517,
        "assignedShare": 0.000042338681224004554,
        "countScope": "exact-term"
      },
      "subtechnique-disable-or-modify-system-firewall-ff82b0a9": {
        "count": 423,
        "datasetShare": 0.0000276271239576149,
        "assignedShare": 0.00028427400250403056,
        "countScope": "exact-term"
      },
      "subtechnique-disable-windows-event-logging-e07507f8": {
        "count": 37,
        "datasetShare": 0.0000024165569419190336,
        "assignedShare": 0.000024865574687113784,
        "countScope": "exact-term"
      },
      "subtechnique-disable-or-modify-tools-fa3b0365": {
        "count": 358,
        "datasetShare": 0.00002338182122181119,
        "assignedShare": 0.00024059123616180364,
        "countScope": "exact-term"
      },
      "subtechnique-indicator-blocking-228effa4": {
        "count": 15681,
        "datasetShare": 0.0010241629569251991,
        "assignedShare": 0.010538299369422468,
        "countScope": "exact-term"
      },
      "subtechnique-disable-or-modify-linux-audit-system-e382c24c": {
        "count": 675,
        "datasetShare": 0.000044085836102576966,
        "assignedShare": 0.0004536287274000488,
        "countScope": "exact-term"
      },
      "subtechnique-spoof-security-alerting-6f9ee07d": {
        "count": 3375,
        "datasetShare": 0.00022042918051288482,
        "assignedShare": 0.002268143637000244,
        "countScope": "exact-term"
      },
      "subtechnique-disable-or-modify-cloud-logs-0c892062": {
        "count": 475,
        "datasetShare": 0.00003102336614625786,
        "assignedShare": 0.0003192202155778121,
        "countScope": "exact-term"
      },
      "subtechnique-downgrade-attack-ed74ca5e": {
        "count": 538,
        "datasetShare": 0.00003513804418249838,
        "assignedShare": 0.00036155889680181667,
        "countScope": "exact-term"
      },
      "subtechnique-disable-or-modify-cloud-firewall-bf7bacda": {
        "count": 1945,
        "datasetShare": 0.00012703252032520327,
        "assignedShare": 0.0013071227774712516,
        "countScope": "exact-term"
      },
      "subtechnique-safe-mode-boot-68a05d7d": {
        "count": 622,
        "datasetShare": 0.0000406242815641524,
        "assignedShare": 0.00041801047176715607,
        "countScope": "exact-term"
      },
      "technique-supply-chain-compromise-de18596d": {
        "count": 28191,
        "datasetShare": 0.0018412204526929588,
        "assignedShare": 0.01894555178390337,
        "countScope": "exact-term"
      },
      "subtechnique-compromise-software-dependencies-and-development-tools-fb146886": {
        "count": 362,
        "datasetShare": 0.000023643070620937572,
        "assignedShare": 0.0002432794063982484,
        "countScope": "exact-term"
      },
      "subtechnique-compromise-software-supply-chain-3ded2ec7": {
        "count": 651,
        "datasetShare": 0.000042518339707818674,
        "assignedShare": 0.0004374997059813804,
        "countScope": "exact-term"
      },
      "subtechnique-compromise-hardware-supply-chain-a945cb00": {
        "count": 15093,
        "datasetShare": 0.000985759295253621,
        "assignedShare": 0.010143138344665091,
        "countScope": "exact-term"
      },
      "technique-exploit-public-facing-application-90be72ec": {
        "count": 1069,
        "datasetShare": 0.0000698189019165256,
        "assignedShare": 0.000718413495689855,
        "countScope": "exact-term"
      },
      "technique-steal-or-forge-kerberos-tickets-81a56c26": {
        "count": 8782,
        "datasetShare": 0.0005735730557819717,
        "assignedShare": 0.005901877754114412,
        "countScope": "exact-term"
      },
      "subtechnique-kerberoasting-cb47421f": {
        "count": 41,
        "datasetShare": 0.0000026778063410454154,
        "assignedShare": 0.00002755374492355852,
        "countScope": "exact-term"
      },
      "subtechnique-silver-ticket-52864630": {
        "count": 3563,
        "datasetShare": 0.00023270790227182477,
        "assignedShare": 0.0023944876381131464,
        "countScope": "exact-term"
      },
      "subtechnique-ccache-files-2761af81": {
        "count": 709,
        "datasetShare": 0.00004630645599515121,
        "assignedShare": 0.00047647817440982904,
        "countScope": "exact-term"
      },
      "subtechnique-as-rep-roasting-c68c7512": {
        "count": 1877,
        "datasetShare": 0.00012259128054005475,
        "assignedShare": 0.0012614238834516912,
        "countScope": "exact-term"
      },
      "subtechnique-golden-ticket-354d0575": {
        "count": 2167,
        "datasetShare": 0.00014153186197671746,
        "assignedShare": 0.0014563162255939344,
        "countScope": "exact-term"
      },
      "technique-credentials-from-password-stores-a8a3590a": {
        "count": 3766,
        "datasetShare": 0.0002459663092774887,
        "assignedShare": 0.002530912277612717,
        "countScope": "exact-term"
      },
      "subtechnique-windows-credential-manager-c395eea9": {
        "count": 208,
        "datasetShare": 0.000013584968754571864,
        "assignedShare": 0.00013978485229512613,
        "countScope": "exact-term"
      },
      "subtechnique-keychain-e1c919c4": {
        "count": 653,
        "datasetShare": 0.000042648964407381864,
        "assignedShare": 0.0004388437910996028,
        "countScope": "exact-term"
      },
      "subtechnique-password-managers-e9ff79ae": {
        "count": 841,
        "datasetShare": 0.00005492768616632182,
        "assignedShare": 0.0005651877922125052,
        "countScope": "exact-term"
      },
      "subtechnique-cloud-secrets-management-stores-6c18d39c": {
        "count": 617,
        "datasetShare": 0.00004029771981524443,
        "assignedShare": 0.00041465025897160016,
        "countScope": "exact-term"
      },
      "subtechnique-credentials-from-web-browsers-de5710d0": {
        "count": 378,
        "datasetShare": 0.0000246880682174431,
        "assignedShare": 0.0002540320873440273,
        "countScope": "exact-term"
      },
      "subtechnique-securityd-memory-44ecaa7d": {
        "count": 1049,
        "datasetShare": 0.00006851265492089368,
        "assignedShare": 0.0007049726445076314,
        "countScope": "exact-term"
      },
      "tactic-exfiltration-fcb9fccc": {
        "count": 29396,
        "datasetShare": 0.0019199218341797815,
        "assignedShare": 0.019755363067632346,
        "countScope": "exact-term"
      },
      "technique-exfiltration-over-web-service-ee6f0f54": {
        "count": 8683,
        "datasetShare": 0.0005671071331535938,
        "assignedShare": 0.005835345540762406,
        "countScope": "exact-term"
      },
      "subtechnique-exfiltration-to-code-repository-d3a02a12": {
        "count": 130,
        "datasetShare": 0.000008490605471607415,
        "assignedShare": 0.00008736553268445384,
        "countScope": "exact-term"
      },
      "subtechnique-exfiltration-to-text-storage-sites-f3f5d305": {
        "count": 2832,
        "datasetShare": 0.00018496457458147845,
        "assignedShare": 0.0019032245274028714,
        "countScope": "exact-term"
      },
      "subtechnique-exfiltration-to-cloud-storage-9335df7e": {
        "count": 2678,
        "datasetShare": 0.00017490647271511275,
        "assignedShare": 0.001799729973299749,
        "countScope": "exact-term"
      },
      "subtechnique-exfiltration-over-webhook-14bfdd17": {
        "count": 1150,
        "datasetShare": 0.00007510920224883483,
        "assignedShare": 0.0007728489429778609,
        "countScope": "exact-term"
      },
      "technique-remote-access-software-4be83e78": {
        "count": 3364,
        "datasetShare": 0.00021971074466528727,
        "assignedShare": 0.002260751168850021,
        "countScope": "exact-term"
      },
      "technique-masquerading-cb5ea65c": {
        "count": 5492,
        "datasetShare": 0.0003586954250005225,
        "assignedShare": 0.003690857734638619,
        "countScope": "exact-term"
      },
      "subtechnique-masquerade-file-type-add4c558": {
        "count": 49,
        "datasetShare": 0.0000032003051392981795,
        "assignedShare": 0.00003293008539644799,
        "countScope": "exact-term"
      },
      "subtechnique-rename-system-utilities-6f5cdc03": {
        "count": 145,
        "datasetShare": 0.000009470290718331348,
        "assignedShare": 0.0000974461710711216,
        "countScope": "exact-term"
      },
      "subtechnique-space-after-filename-82ef6413": {
        "count": 36,
        "datasetShare": 0.000002351244592137438,
        "assignedShare": 0.0000241935321280026,
        "countScope": "exact-term"
      },
      "subtechnique-masquerade-task-or-service-146256e4": {
        "count": 616,
        "datasetShare": 0.00004023240746546283,
        "assignedShare": 0.00041397821641248896,
        "countScope": "exact-term"
      },
      "subtechnique-right-to-left-override-a9661269": {
        "count": 238,
        "datasetShare": 0.00001554433924801973,
        "assignedShare": 0.00015994612906846165,
        "countScope": "exact-term"
      },
      "subtechnique-match-legitimate-name-or-location-b4afedbb": {
        "count": 579,
        "datasetShare": 0.000037815850523543795,
        "assignedShare": 0.0003891126417253752,
        "countScope": "exact-term"
      },
      "subtechnique-double-file-extension-d3d2382e": {
        "count": 234,
        "datasetShare": 0.000015283089848893346,
        "assignedShare": 0.0001572579588320169,
        "countScope": "exact-term"
      },
      "subtechnique-masquerade-account-name-30f177e4": {
        "count": 1271,
        "datasetShare": 0.00008301199657240788,
        "assignedShare": 0.0008541660926303141,
        "countScope": "exact-term"
      },
      "subtechnique-invalid-code-signature-e5021b99": {
        "count": 116,
        "datasetShare": 0.000007576232574665079,
        "assignedShare": 0.00007795693685689727,
        "countScope": "exact-term"
      },
      "subtechnique-break-process-trees-191ccbdc": {
        "count": 1035,
        "datasetShare": 0.00006759828202395135,
        "assignedShare": 0.0006955640486800748,
        "countScope": "exact-term"
      },
      "technique-unsecured-credentials-a33ca172": {
        "count": 9600,
        "datasetShare": 0.0006269985579033168,
        "assignedShare": 0.006451608567467361,
        "countScope": "exact-term"
      },
      "subtechnique-group-policy-preferences-7ab6537c": {
        "count": 313,
        "datasetShare": 0.00002044276548163939,
        "assignedShare": 0.0002103493210018004,
        "countScope": "exact-term"
      },
      "subtechnique-private-keys-354623f9": {
        "count": 895,
        "datasetShare": 0.000058454553054527975,
        "assignedShare": 0.0006014780904045091,
        "countScope": "exact-term"
      },
      "subtechnique-container-api-2bb0acb2": {
        "count": 489,
        "datasetShare": 0.0000319377390432002,
        "assignedShare": 0.0003286288114053687,
        "countScope": "exact-term"
      },
      "subtechnique-credentials-in-files-26db0042": {
        "count": 176,
        "datasetShare": 0.000011494973561560808,
        "assignedShare": 0.00011827949040356828,
        "countScope": "exact-term"
      },
      "subtechnique-credentials-in-registry-0de5d850": {
        "count": 96,
        "datasetShare": 0.0000062699855790331685,
        "assignedShare": 0.0000645160856746736,
        "countScope": "exact-term"
      },
      "subtechnique-bash-history-81009e61": {
        "count": 436,
        "datasetShare": 0.00002847618450477564,
        "assignedShare": 0.00029301055577247596,
        "countScope": "exact-term"
      },
      "subtechnique-chat-messages-089476e0": {
        "count": 6545,
        "datasetShare": 0.00042746932932054255,
        "assignedShare": 0.004398518549382695,
        "countScope": "exact-term"
      },
      "subtechnique-cloud-instance-metadata-api-ca8fa0ca": {
        "count": 56,
        "datasetShare": 0.000003657491587769348,
        "assignedShare": 0.00003763438331022627,
        "countScope": "exact-term"
      },
      "technique-content-injection-77f4affd": {
        "count": 586,
        "datasetShare": 0.000038273036972014965,
        "assignedShare": 0.00039381693963915344,
        "countScope": "label-across-paths"
      },
      "technique-content-injection-a3d15cb2": {
        "count": 586,
        "datasetShare": 0.000038273036972014965,
        "assignedShare": 0.00039381693963915344,
        "countScope": "label-across-paths"
      },
      "technique-process-injection-380089e8": {
        "count": 5983,
        "datasetShare": 0.0003907637887432859,
        "assignedShare": 0.004020830631162211,
        "countScope": "label-across-paths"
      },
      "subtechnique-process-doppelg-nging-f337cb44": {
        "count": 262,
        "datasetShare": 0.000017111835642778023,
        "assignedShare": 0.00017607515048713004,
        "countScope": "label-across-paths"
      },
      "subtechnique-process-hollowing-593b7316": {
        "count": 157,
        "datasetShare": 0.000010254038915710493,
        "assignedShare": 0.00010551068178045579,
        "countScope": "label-across-paths"
      },
      "subtechnique-proc-memory-f8bb8227": {
        "count": 576,
        "datasetShare": 0.000037619913474199006,
        "assignedShare": 0.0003870965140480416,
        "countScope": "label-across-paths"
      },
      "subtechnique-listplanting-d5068325": {
        "count": 1473,
        "datasetShare": 0.00009620509122829017,
        "assignedShare": 0.000989918689570773,
        "countScope": "label-across-paths"
      },
      "subtechnique-vdso-hijacking-dceec9e5": {
        "count": 114,
        "datasetShare": 0.000007445607875101887,
        "assignedShare": 0.0000766128517386749,
        "countScope": "label-across-paths"
      },
      "subtechnique-thread-local-storage-bb388b35": {
        "count": 68,
        "datasetShare": 0.000004441239785148494,
        "assignedShare": 0.00004569889401956047,
        "countScope": "label-across-paths"
      },
      "subtechnique-extra-window-memory-injection-610d0208": {
        "count": 123,
        "datasetShare": 0.000008033419023136246,
        "assignedShare": 0.00008266123477067556,
        "countScope": "label-across-paths"
      },
      "subtechnique-dynamic-link-library-injection-86cb1835": {
        "count": 88,
        "datasetShare": 0.000005747486780780404,
        "assignedShare": 0.00005913974520178414,
        "countScope": "label-across-paths"
      },
      "subtechnique-thread-execution-hijacking-e6038e9a": {
        "count": 313,
        "datasetShare": 0.00002044276548163939,
        "assignedShare": 0.0002103493210018004,
        "countScope": "label-across-paths"
      },
      "subtechnique-ptrace-system-calls-9266b822": {
        "count": 706,
        "datasetShare": 0.00004611051894580642,
        "assignedShare": 0.00047446204673249546,
        "countScope": "label-across-paths"
      },
      "subtechnique-asynchronous-procedure-call-af58de42": {
        "count": 1047,
        "datasetShare": 0.0000683820302213305,
        "assignedShare": 0.000703628559389409,
        "countScope": "label-across-paths"
      },
      "subtechnique-portable-executable-injection-131af23f": {
        "count": 660,
        "datasetShare": 0.000043106150855853034,
        "assignedShare": 0.000443548089013381,
        "countScope": "label-across-paths"
      },
      "technique-process-injection-13f5700b": {
        "count": 5983,
        "datasetShare": 0.0003907637887432859,
        "assignedShare": 0.004020830631162211,
        "countScope": "label-across-paths"
      },
      "subtechnique-process-doppelg-nging-60a58e77": {
        "count": 262,
        "datasetShare": 0.000017111835642778023,
        "assignedShare": 0.00017607515048713004,
        "countScope": "label-across-paths"
      },
      "subtechnique-process-hollowing-c81068aa": {
        "count": 157,
        "datasetShare": 0.000010254038915710493,
        "assignedShare": 0.00010551068178045579,
        "countScope": "label-across-paths"
      },
      "subtechnique-proc-memory-f40789de": {
        "count": 576,
        "datasetShare": 0.000037619913474199006,
        "assignedShare": 0.0003870965140480416,
        "countScope": "label-across-paths"
      },
      "subtechnique-listplanting-d218c208": {
        "count": 1473,
        "datasetShare": 0.00009620509122829017,
        "assignedShare": 0.000989918689570773,
        "countScope": "label-across-paths"
      },
      "subtechnique-vdso-hijacking-77aa1789": {
        "count": 114,
        "datasetShare": 0.000007445607875101887,
        "assignedShare": 0.0000766128517386749,
        "countScope": "label-across-paths"
      },
      "subtechnique-thread-local-storage-6465b098": {
        "count": 68,
        "datasetShare": 0.000004441239785148494,
        "assignedShare": 0.00004569889401956047,
        "countScope": "label-across-paths"
      },
      "subtechnique-extra-window-memory-injection-75edf959": {
        "count": 123,
        "datasetShare": 0.000008033419023136246,
        "assignedShare": 0.00008266123477067556,
        "countScope": "label-across-paths"
      },
      "subtechnique-dynamic-link-library-injection-ea7670d8": {
        "count": 88,
        "datasetShare": 0.000005747486780780404,
        "assignedShare": 0.00005913974520178414,
        "countScope": "label-across-paths"
      },
      "subtechnique-thread-execution-hijacking-bee71ade": {
        "count": 313,
        "datasetShare": 0.00002044276548163939,
        "assignedShare": 0.0002103493210018004,
        "countScope": "label-across-paths"
      },
      "subtechnique-ptrace-system-calls-944f48e7": {
        "count": 706,
        "datasetShare": 0.00004611051894580642,
        "assignedShare": 0.00047446204673249546,
        "countScope": "label-across-paths"
      },
      "subtechnique-asynchronous-procedure-call-12586cc5": {
        "count": 1047,
        "datasetShare": 0.0000683820302213305,
        "assignedShare": 0.000703628559389409,
        "countScope": "label-across-paths"
      },
      "subtechnique-portable-executable-injection-e496b36d": {
        "count": 660,
        "datasetShare": 0.000043106150855853034,
        "assignedShare": 0.000443548089013381,
        "countScope": "label-across-paths"
      },
      "technique-traffic-signaling-9bad42cb": {
        "count": 4502,
        "datasetShare": 0.00029403619871674295,
        "assignedShare": 0.0030255356011185475,
        "countScope": "label-across-paths"
      },
      "subtechnique-port-knocking-73c6c74e": {
        "count": 435,
        "datasetShare": 0.000028410872154994042,
        "assignedShare": 0.00029233851321336477,
        "countScope": "label-across-paths"
      },
      "subtechnique-socket-filters-5bd35593": {
        "count": 829,
        "datasetShare": 0.00005414393796894267,
        "assignedShare": 0.000557123281503171,
        "countScope": "label-across-paths"
      },
      "technique-traffic-signaling-1c8ff468": {
        "count": 4502,
        "datasetShare": 0.00029403619871674295,
        "assignedShare": 0.0030255356011185475,
        "countScope": "label-across-paths"
      },
      "subtechnique-port-knocking-8e683c60": {
        "count": 435,
        "datasetShare": 0.000028410872154994042,
        "assignedShare": 0.00029233851321336477,
        "countScope": "label-across-paths"
      },
      "subtechnique-socket-filters-6a07cd05": {
        "count": 829,
        "datasetShare": 0.00005414393796894267,
        "assignedShare": 0.000557123281503171,
        "countScope": "label-across-paths"
      },
      "technique-traffic-signaling-23a2f1e3": {
        "count": 4502,
        "datasetShare": 0.00029403619871674295,
        "assignedShare": 0.0030255356011185475,
        "countScope": "label-across-paths"
      },
      "subtechnique-port-knocking-be0b42c7": {
        "count": 435,
        "datasetShare": 0.000028410872154994042,
        "assignedShare": 0.00029233851321336477,
        "countScope": "label-across-paths"
      },
      "subtechnique-socket-filters-d00b1870": {
        "count": 829,
        "datasetShare": 0.00005414393796894267,
        "assignedShare": 0.000557123281503171,
        "countScope": "label-across-paths"
      },
      "technique-system-binary-proxy-execution-1bb2ffbd": {
        "count": 10026,
        "datasetShare": 0.0006548216189102765,
        "assignedShare": 0.006737898697648724,
        "countScope": "exact-term"
      },
      "subtechnique-mshta-afda0921": {
        "count": 428,
        "datasetShare": 0.000027953685706522875,
        "assignedShare": 0.00028763421529958647,
        "countScope": "exact-term"
      },
      "subtechnique-mmc-a93c2f74": {
        "count": 1005,
        "datasetShare": 0.00006563891153050347,
        "assignedShare": 0.0006754027719067393,
        "countScope": "exact-term"
      },
      "subtechnique-odbcconf-b725f40d": {
        "count": 159,
        "datasetShare": 0.000010384663615273685,
        "assignedShare": 0.00010685476689867816,
        "countScope": "exact-term"
      },
      "subtechnique-electron-applications-104dd63a": {
        "count": 984,
        "datasetShare": 0.00006426735218508997,
        "assignedShare": 0.0006612898781654045,
        "countScope": "exact-term"
      },
      "subtechnique-verclsid-cd7efa17": {
        "count": 221,
        "datasetShare": 0.000014434029301732606,
        "assignedShare": 0.00014852140556357153,
        "countScope": "exact-term"
      },
      "subtechnique-mavinject-a2ae4d4e": {
        "count": 3785,
        "datasetShare": 0.000247207243923339,
        "assignedShare": 0.002543681086235829,
        "countScope": "exact-term"
      },
      "subtechnique-control-panel-2fb34067": {
        "count": 556,
        "datasetShare": 0.0000363136664785671,
        "assignedShare": 0.000373655662865818,
        "countScope": "exact-term"
      },
      "subtechnique-compiled-html-file-b24e009f": {
        "count": 40,
        "datasetShare": 0.00000261249399126382,
        "assignedShare": 0.000026881702364447336,
        "countScope": "exact-term"
      },
      "subtechnique-regsvr32-da2b97aa": {
        "count": 10,
        "datasetShare": 6.53123497815955e-7,
        "assignedShare": 0.000006720425591111834,
        "countScope": "exact-term"
      },
      "subtechnique-installutil-90d39344": {
        "count": 166,
        "datasetShare": 0.000010841850063744854,
        "assignedShare": 0.00011155906481245645,
        "countScope": "exact-term"
      },
      "subtechnique-rundll32-7f3ce67a": {
        "count": 55,
        "datasetShare": 0.0000035921792379877527,
        "assignedShare": 0.000036962340751115085,
        "countScope": "exact-term"
      },
      "subtechnique-regsvcs-regasm-1487fc44": {
        "count": 168,
        "datasetShare": 0.000010972474763308044,
        "assignedShare": 0.0001129031499306788,
        "countScope": "exact-term"
      },
      "subtechnique-cmstp-5b48fc85": {
        "count": 1310,
        "datasetShare": 0.00008555917821389011,
        "assignedShare": 0.0008803757524356502,
        "countScope": "exact-term"
      },
      "subtechnique-msiexec-3241da60": {
        "count": 1081,
        "datasetShare": 0.00007060265011390474,
        "assignedShare": 0.0007264780063991892,
        "countScope": "exact-term"
      },
      "technique-reflective-code-loading-9c67d9ea": {
        "count": 95,
        "datasetShare": 0.0000062046732292515724,
        "assignedShare": 0.00006384404311556242,
        "countScope": "exact-term"
      },
      "technique-escape-to-host-2edd844b": {
        "count": 893,
        "datasetShare": 0.000058323928354964785,
        "assignedShare": 0.0006001340052862868,
        "countScope": "exact-term"
      },
      "technique-application-window-discovery-f4c66239": {
        "count": 1360,
        "datasetShare": 0.00008882479570296988,
        "assignedShare": 0.0009139778803912094,
        "countScope": "exact-term"
      },
      "technique-scheduled-transfer-f3d702c0": {
        "count": 1119,
        "datasetShare": 0.00007308451940560537,
        "assignedShare": 0.0007520156236454143,
        "countScope": "exact-term"
      },
      "technique-implant-internal-image-0884e561": {
        "count": 1896,
        "datasetShare": 0.00012383221518590508,
        "assignedShare": 0.0012741926920748037,
        "countScope": "exact-term"
      },
      "technique-protocol-tunneling-187def8c": {
        "count": 2410,
        "datasetShare": 0.00015740276297364515,
        "assignedShare": 0.001619622567457952,
        "countScope": "exact-term"
      },
      "technique-use-alternate-authentication-material-7b996784": {
        "count": 11986,
        "datasetShare": 0.0007828338244822037,
        "assignedShare": 0.008055102113506645,
        "countScope": "label-across-paths"
      },
      "subtechnique-web-session-cookie-435d5d37": {
        "count": 260,
        "datasetShare": 0.00001698121094321483,
        "assignedShare": 0.00017473106536890768,
        "countScope": "label-across-paths"
      },
      "subtechnique-application-access-token-7f425aa5": {
        "count": 4610,
        "datasetShare": 0.0003010899324931553,
        "assignedShare": 0.0030981161975025553,
        "countScope": "label-across-paths"
      },
      "subtechnique-pass-the-ticket-c42bf0ba": {
        "count": 3642,
        "datasetShare": 0.00023786757790457083,
        "assignedShare": 0.00244757900028293,
        "countScope": "label-across-paths"
      },
      "subtechnique-pass-the-hash-ce05f0c9": {
        "count": 347,
        "datasetShare": 0.00002266338537421364,
        "assignedShare": 0.00023319876801158063,
        "countScope": "label-across-paths"
      },
      "technique-use-alternate-authentication-material-8d31c1ec": {
        "count": 11986,
        "datasetShare": 0.0007828338244822037,
        "assignedShare": 0.008055102113506645,
        "countScope": "label-across-paths"
      },
      "subtechnique-web-session-cookie-07363597": {
        "count": 260,
        "datasetShare": 0.00001698121094321483,
        "assignedShare": 0.00017473106536890768,
        "countScope": "label-across-paths"
      },
      "subtechnique-application-access-token-800a29ba": {
        "count": 4610,
        "datasetShare": 0.0003010899324931553,
        "assignedShare": 0.0030981161975025553,
        "countScope": "label-across-paths"
      },
      "subtechnique-pass-the-ticket-2ee8066b": {
        "count": 3642,
        "datasetShare": 0.00023786757790457083,
        "assignedShare": 0.00244757900028293,
        "countScope": "label-across-paths"
      },
      "subtechnique-pass-the-hash-cec30c57": {
        "count": 347,
        "datasetShare": 0.00002266338537421364,
        "assignedShare": 0.00023319876801158063,
        "countScope": "label-across-paths"
      },
      "technique-exfiltration-over-other-network-medium-ecc6fdba": {
        "count": 3683,
        "datasetShare": 0.00024054538424561622,
        "assignedShare": 0.0024751327452064886,
        "countScope": "exact-term"
      },
      "subtechnique-exfiltration-over-bluetooth-7ca41369": {
        "count": 2613,
        "datasetShare": 0.00017066116997930904,
        "assignedShare": 0.0017560472069575222,
        "countScope": "exact-term"
      },
      "technique-gather-victim-identity-information-24b677c1": {
        "count": 9978,
        "datasetShare": 0.0006516866261207599,
        "assignedShare": 0.006705640654811388,
        "countScope": "exact-term"
      },
      "subtechnique-employee-names-8cb0df73": {
        "count": 5137,
        "datasetShare": 0.0003355095408280561,
        "assignedShare": 0.003452282626154149,
        "countScope": "exact-term"
      },
      "subtechnique-email-addresses-0fe43f98": {
        "count": 946,
        "datasetShare": 0.00006178548289338934,
        "assignedShare": 0.0006357522609191794,
        "countScope": "exact-term"
      },
      "subtechnique-credentials-417dcf09": {
        "count": 174,
        "datasetShare": 0.000011364348861997617,
        "assignedShare": 0.00011693540528534591,
        "countScope": "exact-term"
      },
      "technique-archive-collected-data-b007f006": {
        "count": 2670,
        "datasetShare": 0.00017438397391686,
        "assignedShare": 0.0017943536328268598,
        "countScope": "exact-term"
      },
      "subtechnique-archive-via-library-6c8f26fc": {
        "count": 586,
        "datasetShare": 0.000038273036972014965,
        "assignedShare": 0.00039381693963915344,
        "countScope": "exact-term"
      },
      "subtechnique-archive-via-utility-b784ae89": {
        "count": 91,
        "datasetShare": 0.000005943423830125191,
        "assignedShare": 0.00006115587287911769,
        "countScope": "exact-term"
      },
      "subtechnique-archive-via-custom-method-b4291590": {
        "count": 246,
        "datasetShare": 0.000016066838046272492,
        "assignedShare": 0.0001653224695413511,
        "countScope": "exact-term"
      },
      "technique-browser-session-hijacking-e4c9f84d": {
        "count": 54,
        "datasetShare": 0.000003526866888206157,
        "assignedShare": 0.000036290298192003906,
        "countScope": "exact-term"
      },
      "technique-remote-services-fb7ac358": {
        "count": 29866,
        "datasetShare": 0.0019506186385771314,
        "assignedShare": 0.020071223070414604,
        "countScope": "exact-term"
      },
      "subtechnique-windows-remote-management-e9991986": {
        "count": 2424,
        "datasetShare": 0.0001583171358705875,
        "assignedShare": 0.0016290311632855086,
        "countScope": "exact-term"
      },
      "subtechnique-vnc-9a2b4f71": {
        "count": 3400,
        "datasetShare": 0.00022206198925742472,
        "assignedShare": 0.0022849447009780236,
        "countScope": "exact-term"
      },
      "subtechnique-smb-windows-admin-shares-5eace6c1": {
        "count": 569,
        "datasetShare": 0.00003716272702572784,
        "assignedShare": 0.0003823922161342633,
        "countScope": "exact-term"
      },
      "subtechnique-cloud-services-cfbc7c71": {
        "count": 14331,
        "datasetShare": 0.0009359912847200451,
        "assignedShare": 0.009631041914622369,
        "countScope": "exact-term"
      },
      "subtechnique-remote-desktop-protocol-58706437": {
        "count": 771,
        "datasetShare": 0.00005035582168161013,
        "assignedShare": 0.0005181448130747224,
        "countScope": "exact-term"
      },
      "subtechnique-distributed-component-object-model-c85d3d25": {
        "count": 6984,
        "datasetShare": 0.000456141450874663,
        "assignedShare": 0.0046935452328325045,
        "countScope": "exact-term"
      },
      "subtechnique-direct-cloud-vm-connections-4fb1346f": {
        "count": 1160,
        "datasetShare": 0.00007576232574665079,
        "assignedShare": 0.0007795693685689728,
        "countScope": "exact-term"
      },
      "subtechnique-ssh-13b5099f": {
        "count": 125,
        "datasetShare": 0.000008164043722699438,
        "assignedShare": 0.00008400531988889793,
        "countScope": "exact-term"
      },
      "technique-search-open-technical-databases-a4d67291": {
        "count": 13257,
        "datasetShare": 0.0008658458210546115,
        "assignedShare": 0.008909268206136958,
        "countScope": "exact-term"
      },
      "subtechnique-digital-certificates-443588c6": {
        "count": 2228,
        "datasetShare": 0.00014551591531339477,
        "assignedShare": 0.0014973108216997167,
        "countScope": "label-across-paths"
      },
      "subtechnique-scan-databases-3d6897dc": {
        "count": 1141,
        "datasetShare": 0.00007452139110080047,
        "assignedShare": 0.0007668005599458603,
        "countScope": "exact-term"
      },
      "subtechnique-dns-passive-dns-0655a6eb": {
        "count": 287,
        "datasetShare": 0.000018744644387317908,
        "assignedShare": 0.00019287621446490965,
        "countScope": "exact-term"
      },
      "subtechnique-cdns-6b4a8a59": {
        "count": 5833,
        "datasetShare": 0.00038096693627604654,
        "assignedShare": 0.003920024247295532,
        "countScope": "exact-term"
      },
      "subtechnique-whois-f24453a6": {
        "count": 1032,
        "datasetShare": 0.00006740234497460656,
        "assignedShare": 0.0006935479210027413,
        "countScope": "exact-term"
      },
      "technique-rogue-domain-controller-676a459e": {
        "count": 608,
        "datasetShare": 0.00003970990866721007,
        "assignedShare": 0.0004086018759395995,
        "countScope": "exact-term"
      },
      "technique-deploy-container-3b87d56b": {
        "count": 1071,
        "datasetShare": 0.00006994952661608878,
        "assignedShare": 0.0007197575808080774,
        "countScope": "label-across-paths"
      },
      "technique-deploy-container-deae6c00": {
        "count": 1071,
        "datasetShare": 0.00006994952661608878,
        "assignedShare": 0.0007197575808080774,
        "countScope": "label-across-paths"
      },
      "technique-modify-registry-69813e02": {
        "count": 301,
        "datasetShare": 0.000019659017284260245,
        "assignedShare": 0.0002022848102924662,
        "countScope": "exact-term"
      },
      "technique-cloud-infrastructure-discovery-08786460": {
        "count": 10429,
        "datasetShare": 0.0006811424958722595,
        "assignedShare": 0.007008731848970532,
        "countScope": "exact-term"
      },
      "technique-defacement-1987f5e9": {
        "count": 9411,
        "datasetShare": 0.0006146545237945952,
        "assignedShare": 0.006324592523795347,
        "countScope": "exact-term"
      },
      "subtechnique-external-defacement-811efdb5": {
        "count": 1883,
        "datasetShare": 0.00012298315463874434,
        "assignedShare": 0.0012654561388063584,
        "countScope": "exact-term"
      },
      "subtechnique-internal-defacement-d20cc91b": {
        "count": 1479,
        "datasetShare": 0.00009659696532697975,
        "assignedShare": 0.0009939509449254401,
        "countScope": "exact-term"
      },
      "technique-unused-unsupported-cloud-regions-da0c2168": {
        "count": 11944,
        "datasetShare": 0.0007800907057913767,
        "assignedShare": 0.008026876326023974,
        "countScope": "exact-term"
      },
      "technique-remote-service-session-hijacking-8d6bbf15": {
        "count": 1195,
        "datasetShare": 0.00007804825798900663,
        "assignedShare": 0.0008030908581378642,
        "countScope": "exact-term"
      },
      "subtechnique-rdp-hijacking-dcd2e554": {
        "count": 499,
        "datasetShare": 0.000032590862541016155,
        "assignedShare": 0.0003353492369964805,
        "countScope": "exact-term"
      },
      "subtechnique-ssh-hijacking-8e26c45c": {
        "count": 621,
        "datasetShare": 0.00004055896921437081,
        "assignedShare": 0.0004173384292080449,
        "countScope": "exact-term"
      },
      "technique-browser-information-discovery-4dd3fac4": {
        "count": 2365,
        "datasetShare": 0.00015446370723347337,
        "assignedShare": 0.0015893806522979488,
        "countScope": "exact-term"
      },
      "technique-communication-through-removable-media-c8f686d1": {
        "count": 856,
        "datasetShare": 0.00005590737141304575,
        "assignedShare": 0.0005752684305991729,
        "countScope": "exact-term"
      },
      "technique-file-and-directory-permissions-modification-fede7384": {
        "count": 706,
        "datasetShare": 0.00004611051894580642,
        "assignedShare": 0.00047446204673249546,
        "countScope": "exact-term"
      },
      "subtechnique-linux-and-mac-file-and-directory-permissions-modificat-0cb62b8c": {
        "count": 118,
        "datasetShare": 0.00000770685727422827,
        "assignedShare": 0.00007930102197511965,
        "countScope": "exact-term"
      },
      "subtechnique-windows-file-and-directory-permissions-modification-4b92859a": {
        "count": 64,
        "datasetShare": 0.000004179990386022112,
        "assignedShare": 0.00004301072378311574,
        "countScope": "exact-term"
      },
      "technique-active-scanning-7605d21c": {
        "count": 2284,
        "datasetShare": 0.00014917340690116413,
        "assignedShare": 0.0015349452050099428,
        "countScope": "exact-term"
      },
      "subtechnique-wordlist-scanning-070039ab": {
        "count": 242,
        "datasetShare": 0.00001580558864714611,
        "assignedShare": 0.00016263429930490637,
        "countScope": "exact-term"
      },
      "subtechnique-scanning-ip-blocks-6cb10bde": {
        "count": 512,
        "datasetShare": 0.000033439923088176897,
        "assignedShare": 0.0003440857902649259,
        "countScope": "exact-term"
      },
      "subtechnique-vulnerability-scanning-ba311061": {
        "count": 753,
        "datasetShare": 0.000049180199385541416,
        "assignedShare": 0.0005060480470107211,
        "countScope": "exact-term"
      },
      "technique-abuse-elevation-control-mechanism-7f054bf5": {
        "count": 10558,
        "datasetShare": 0.0006895677889940853,
        "assignedShare": 0.0070954253390958745,
        "countScope": "label-across-paths"
      },
      "subtechnique-setuid-and-setgid-1152b884": {
        "count": 237,
        "datasetShare": 0.000015479026898238135,
        "assignedShare": 0.00015927408650935046,
        "countScope": "label-across-paths"
      },
      "subtechnique-temporary-elevated-cloud-access-f9d1bd9e": {
        "count": 3280,
        "datasetShare": 0.00021422450728363326,
        "assignedShare": 0.0022042995938846817,
        "countScope": "label-across-paths"
      },
      "subtechnique-bypass-user-account-control-7326ba26": {
        "count": 545,
        "datasetShare": 0.00003559523063096955,
        "assignedShare": 0.00036626319471559497,
        "countScope": "label-across-paths"
      },
      "subtechnique-elevated-execution-with-prompt-7536d0a1": {
        "count": 218,
        "datasetShare": 0.00001423809225238782,
        "assignedShare": 0.00014650527788623798,
        "countScope": "label-across-paths"
      },
      "subtechnique-sudo-and-sudo-caching-3b5f63ef": {
        "count": 94,
        "datasetShare": 0.000006139360879469977,
        "assignedShare": 0.00006317200055645124,
        "countScope": "label-across-paths"
      },
      "subtechnique-tcc-manipulation-a4a4aa9b": {
        "count": 4329,
        "datasetShare": 0.0002827371622045269,
        "assignedShare": 0.002909272238392313,
        "countScope": "label-across-paths"
      },
      "technique-abuse-elevation-control-mechanism-1b9179b0": {
        "count": 10558,
        "datasetShare": 0.0006895677889940853,
        "assignedShare": 0.0070954253390958745,
        "countScope": "label-across-paths"
      },
      "subtechnique-setuid-and-setgid-2e279e12": {
        "count": 237,
        "datasetShare": 0.000015479026898238135,
        "assignedShare": 0.00015927408650935046,
        "countScope": "label-across-paths"
      },
      "subtechnique-temporary-elevated-cloud-access-fdaf3921": {
        "count": 3280,
        "datasetShare": 0.00021422450728363326,
        "assignedShare": 0.0022042995938846817,
        "countScope": "label-across-paths"
      },
      "subtechnique-bypass-user-account-control-7ac10c0f": {
        "count": 545,
        "datasetShare": 0.00003559523063096955,
        "assignedShare": 0.00036626319471559497,
        "countScope": "label-across-paths"
      },
      "subtechnique-elevated-execution-with-prompt-8c37f36a": {
        "count": 218,
        "datasetShare": 0.00001423809225238782,
        "assignedShare": 0.00014650527788623798,
        "countScope": "label-across-paths"
      },
      "subtechnique-sudo-and-sudo-caching-bb1d6449": {
        "count": 94,
        "datasetShare": 0.000006139360879469977,
        "assignedShare": 0.00006317200055645124,
        "countScope": "label-across-paths"
      },
      "subtechnique-tcc-manipulation-776597c5": {
        "count": 4329,
        "datasetShare": 0.0002827371622045269,
        "assignedShare": 0.002909272238392313,
        "countScope": "label-across-paths"
      },
      "technique-video-capture-7549323f": {
        "count": 17101,
        "datasetShare": 0.0011169064936150646,
        "assignedShare": 0.011492599803360348,
        "countScope": "exact-term"
      },
      "technique-system-network-configuration-discovery-a64a1a16": {
        "count": 7698,
        "datasetShare": 0.0005027744686187222,
        "assignedShare": 0.00517338362003789,
        "countScope": "exact-term"
      },
      "subtechnique-wi-fi-discovery-4c25fb54": {
        "count": 6164,
        "datasetShare": 0.00040258532405375465,
        "assignedShare": 0.004142470334361334,
        "countScope": "exact-term"
      },
      "subtechnique-internet-connection-discovery-f632287e": {
        "count": 1259,
        "datasetShare": 0.00008222824837502874,
        "assignedShare": 0.0008461015819209799,
        "countScope": "exact-term"
      },
      "technique-account-discovery-58d85413": {
        "count": 1787,
        "datasetShare": 0.00011671316905971117,
        "assignedShare": 0.0012009400531316848,
        "countScope": "exact-term"
      },
      "subtechnique-email-account-c1e73e9d": {
        "count": 469,
        "datasetShare": 0.00003063149204756829,
        "assignedShare": 0.000315187960223145,
        "countScope": "exact-term"
      },
      "subtechnique-cloud-account-ef010e91": {
        "count": 326,
        "datasetShare": 0.000021291826028800133,
        "assignedShare": 0.0002190858742702458,
        "countScope": "label-across-paths"
      },
      "subtechnique-domain-account-a46cbfd3": {
        "count": 25,
        "datasetShare": 0.0000016328087445398876,
        "assignedShare": 0.000016801063977779584,
        "countScope": "label-across-paths"
      },
      "subtechnique-local-account-475fd0d9": {
        "count": 238,
        "datasetShare": 0.00001554433924801973,
        "assignedShare": 0.00015994612906846165,
        "countScope": "label-across-paths"
      },
      "technique-proxy-ebd03951": {
        "count": 2321,
        "datasetShare": 0.00015158996384308316,
        "assignedShare": 0.0015598107796970567,
        "countScope": "exact-term"
      },
      "subtechnique-internal-proxy-fe655827": {
        "count": 43,
        "datasetShare": 0.0000028084310406086067,
        "assignedShare": 0.000028897830041780884,
        "countScope": "exact-term"
      },
      "subtechnique-multi-hop-proxy-030150d0": {
        "count": 253,
        "datasetShare": 0.000016524024494743663,
        "assignedShare": 0.0001700267674551294,
        "countScope": "exact-term"
      },
      "subtechnique-domain-fronting-fd95775f": {
        "count": 1559,
        "datasetShare": 0.00010182195330950738,
        "assignedShare": 0.001047714349654335,
        "countScope": "exact-term"
      },
      "subtechnique-external-proxy-d9cf6487": {
        "count": 33,
        "datasetShare": 0.0000021553075427926517,
        "assignedShare": 0.000022177404450669053,
        "countScope": "exact-term"
      },
      "technique-command-and-scripting-interpreter-e72bca61": {
        "count": 17838,
        "datasetShare": 0.0011650416954041005,
        "assignedShare": 0.01198789516942529,
        "countScope": "exact-term"
      },
      "subtechnique-visual-basic-3bb411b2": {
        "count": 127,
        "datasetShare": 0.000008294668422262629,
        "assignedShare": 0.00008534940500712029,
        "countScope": "exact-term"
      },
      "subtechnique-applescript-4a7a2ba6": {
        "count": 1935,
        "datasetShare": 0.0001263793968273873,
        "assignedShare": 0.0013004023518801398,
        "countScope": "exact-term"
      },
      "subtechnique-windows-command-shell-d2b879da": {
        "count": 79,
        "datasetShare": 0.000005159675632746045,
        "assignedShare": 0.000053091362169783486,
        "countScope": "exact-term"
      },
      "subtechnique-unix-shell-d0300b78": {
        "count": 2307,
        "datasetShare": 0.00015067559094614083,
        "assignedShare": 0.0015504021838695001,
        "countScope": "exact-term"
      },
      "subtechnique-autohotkey-autoit-4c4106f0": {
        "count": 4360,
        "datasetShare": 0.0002847618450477564,
        "assignedShare": 0.0029301055577247597,
        "countScope": "exact-term"
      },
      "subtechnique-network-device-cli-e45b0635": {
        "count": 1147,
        "datasetShare": 0.00007491326519949005,
        "assignedShare": 0.0007708328153005273,
        "countScope": "exact-term"
      },
      "subtechnique-python-43ab5b6c": {
        "count": 487,
        "datasetShare": 0.00003180711434363701,
        "assignedShare": 0.0003272847262871463,
        "countScope": "exact-term"
      },
      "subtechnique-powershell-83ec0796": {
        "count": 236,
        "datasetShare": 0.00001541371454845654,
        "assignedShare": 0.0001586020439502393,
        "countScope": "exact-term"
      },
      "subtechnique-cloud-api-8c8c81fc": {
        "count": 5485,
        "datasetShare": 0.0003582382385520513,
        "assignedShare": 0.003686153436724841,
        "countScope": "exact-term"
      },
      "subtechnique-lua-dd386e10": {
        "count": 1278,
        "datasetShare": 0.00008346918302087905,
        "assignedShare": 0.0008588703905440924,
        "countScope": "exact-term"
      },
      "subtechnique-javascript-aaa670dc": {
        "count": 325,
        "datasetShare": 0.000021226513679018537,
        "assignedShare": 0.0002184138317111346,
        "countScope": "exact-term"
      },
      "technique-domain-trust-discovery-1d66a1c8": {
        "count": 2892,
        "datasetShare": 0.00018888331556837418,
        "assignedShare": 0.0019435470809495423,
        "countScope": "exact-term"
      },
      "technique-automated-exfiltration-fc9e50be": {
        "count": 2476,
        "datasetShare": 0.00016171337805923048,
        "assignedShare": 0.0016639773763592902,
        "countScope": "exact-term"
      },
      "subtechnique-traffic-duplication-9f033867": {
        "count": 492,
        "datasetShare": 0.000032133676092544985,
        "assignedShare": 0.0003306449390827022,
        "countScope": "exact-term"
      },
      "technique-indicator-removal-635b032d": {
        "count": 13939,
        "datasetShare": 0.0009103888436056598,
        "assignedShare": 0.009367601231450785,
        "countScope": "exact-term"
      },
      "subtechnique-file-deletion-4ff24c75": {
        "count": 225,
        "datasetShare": 0.000014695278700858989,
        "assignedShare": 0.00015120957580001625,
        "countScope": "exact-term"
      },
      "subtechnique-timestomp-ecd98044": {
        "count": 613,
        "datasetShare": 0.00004003647041611804,
        "assignedShare": 0.00041196208873515544,
        "countScope": "exact-term"
      },
      "subtechnique-clear-mailbox-data-26ee7480": {
        "count": 1875,
        "datasetShare": 0.00012246065584049158,
        "assignedShare": 0.0012600797983334689,
        "countScope": "exact-term"
      },
      "subtechnique-clear-linux-or-mac-system-logs-bbbb9500": {
        "count": 274,
        "datasetShare": 0.000017895583840157166,
        "assignedShare": 0.00018413966119646425,
        "countScope": "exact-term"
      },
      "subtechnique-clear-windows-event-logs-1b522ea3": {
        "count": 389,
        "datasetShare": 0.00002540650406504065,
        "assignedShare": 0.0002614245554942503,
        "countScope": "exact-term"
      },
      "subtechnique-clear-persistence-f9e78a1e": {
        "count": 1952,
        "datasetShare": 0.00012748970677367442,
        "assignedShare": 0.00131182707538503,
        "countScope": "exact-term"
      },
      "subtechnique-clear-command-history-99881ec2": {
        "count": 134,
        "datasetShare": 0.000008751854870733797,
        "assignedShare": 0.00009005370292089857,
        "countScope": "exact-term"
      },
      "subtechnique-relocate-malware-59b62083": {
        "count": 1122,
        "datasetShare": 0.00007328045645495015,
        "assignedShare": 0.0007540317513227478,
        "countScope": "exact-term"
      },
      "subtechnique-clear-network-connection-history-and-configurations-8087427d": {
        "count": 142,
        "datasetShare": 0.000009274353668986561,
        "assignedShare": 0.00009543004339378805,
        "countScope": "exact-term"
      },
      "subtechnique-network-share-connection-removal-47db769e": {
        "count": 1116,
        "datasetShare": 0.00007288858235626058,
        "assignedShare": 0.0007499994959680806,
        "countScope": "exact-term"
      },
      "technique-container-administration-command-ed26b98e": {
        "count": 827,
        "datasetShare": 0.00005401331326937948,
        "assignedShare": 0.0005557791963849486,
        "countScope": "exact-term"
      },
      "technique-file-and-directory-discovery-5b2c317b": {
        "count": 520,
        "datasetShare": 0.00003396242188642966,
        "assignedShare": 0.00034946213073781536,
        "countScope": "exact-term"
      },
      "technique-dynamic-resolution-37ec35d3": {
        "count": 12484,
        "datasetShare": 0.0008153593746734382,
        "assignedShare": 0.008389779307944014,
        "countScope": "exact-term"
      },
      "subtechnique-fast-flux-dns-c54240a6": {
        "count": 887,
        "datasetShare": 0.000057932054256275213,
        "assignedShare": 0.0005961017499316197,
        "countScope": "exact-term"
      },
      "subtechnique-domain-generation-algorithms-a62da9b4": {
        "count": 6034,
        "datasetShare": 0.00039409471858214723,
        "assignedShare": 0.004055104801676881,
        "countScope": "exact-term"
      },
      "subtechnique-dns-calculation-94bcbcb7": {
        "count": 703,
        "datasetShare": 0.00004591458189646164,
        "assignedShare": 0.00047244591905516194,
        "countScope": "exact-term"
      },
      "technique-plist-file-modification-55426bfb": {
        "count": 642,
        "datasetShare": 0.00004193052855978431,
        "assignedShare": 0.00043145132294937976,
        "countScope": "exact-term"
      },
      "technique-data-staged-d92b28d1": {
        "count": 2964,
        "datasetShare": 0.00019358580475264907,
        "assignedShare": 0.0019919341452055476,
        "countScope": "exact-term"
      },
      "subtechnique-local-data-staging-905375fb": {
        "count": 439,
        "datasetShare": 0.000028672121554120426,
        "assignedShare": 0.0002950266834498095,
        "countScope": "exact-term"
      },
      "subtechnique-remote-data-staging-26869a34": {
        "count": 797,
        "datasetShare": 0.000052053942775931614,
        "assignedShare": 0.0005356179196116132,
        "countScope": "exact-term"
      },
      "technique-steal-or-forge-authentication-certificates-1c74ddbb": {
        "count": 3767,
        "datasetShare": 0.00024603162162727024,
        "assignedShare": 0.0025315843201718278,
        "countScope": "exact-term"
      },
      "technique-system-network-connections-discovery-62c2a20d": {
        "count": 213,
        "datasetShare": 0.000013911530503479842,
        "assignedShare": 0.00014314506509068207,
        "countScope": "exact-term"
      },
      "technique-compromise-infrastructure-ebdf07bf": {
        "count": 9429,
        "datasetShare": 0.000615830146090664,
        "assignedShare": 0.006336689289859348,
        "countScope": "exact-term"
      },
      "subtechnique-virtual-private-server-f5bc76fd": {
        "count": 4268,
        "datasetShare": 0.0002787531088678496,
        "assignedShare": 0.0028682776422865306,
        "countScope": "label-across-paths"
      },
      "subtechnique-dns-server-fdf8d18b": {
        "count": 81,
        "datasetShare": 0.0000052903003323092356,
        "assignedShare": 0.00005443544728800585,
        "countScope": "label-across-paths"
      },
      "subtechnique-web-services-5b45c076": {
        "count": 1285,
        "datasetShare": 0.00008392636946935022,
        "assignedShare": 0.0008635746884578707,
        "countScope": "label-across-paths"
      },
      "subtechnique-serverless-06ad674e": {
        "count": 505,
        "datasetShare": 0.000032982736639705726,
        "assignedShare": 0.0003393814923511476,
        "countScope": "label-across-paths"
      },
      "subtechnique-botnet-514ce9e9": {
        "count": 800,
        "datasetShare": 0.0000522498798252764,
        "assignedShare": 0.0005376340472889467,
        "countScope": "label-across-paths"
      },
      "subtechnique-server-8a9277c2": {
        "count": 1230,
        "datasetShare": 0.00008033419023136246,
        "assignedShare": 0.0008266123477067555,
        "countScope": "label-across-paths"
      },
      "subtechnique-network-devices-20521dc3": {
        "count": 2651,
        "datasetShare": 0.00017314303927100968,
        "assignedShare": 0.0017815848242037473,
        "countScope": "exact-term"
      },
      "subtechnique-domains-95341a77": {
        "count": 1875,
        "datasetShare": 0.00012246065584049158,
        "assignedShare": 0.0012600797983334689,
        "countScope": "label-across-paths"
      },
      "technique-pre-os-boot-56a45b48": {
        "count": 13637,
        "datasetShare": 0.0008906645139716179,
        "assignedShare": 0.009164644378599207,
        "countScope": "label-across-paths"
      },
      "subtechnique-bootkit-121ea25b": {
        "count": 754,
        "datasetShare": 0.00004924551173532301,
        "assignedShare": 0.0005067200895698322,
        "countScope": "label-across-paths"
      },
      "subtechnique-tftp-boot-9feba90c": {
        "count": 910,
        "datasetShare": 0.00005943423830125191,
        "assignedShare": 0.0006115587287911769,
        "countScope": "label-across-paths"
      },
      "subtechnique-component-firmware-04be26ce": {
        "count": 7199,
        "datasetShare": 0.00047018360607770603,
        "assignedShare": 0.004838034383041409,
        "countScope": "label-across-paths"
      },
      "subtechnique-rommonkit-a087dd2d": {
        "count": 3128,
        "datasetShare": 0.00020429703011683073,
        "assignedShare": 0.0021021491248997817,
        "countScope": "label-across-paths"
      },
      "subtechnique-system-firmware-e5ba2ee1": {
        "count": 720,
        "datasetShare": 0.00004702489184274876,
        "assignedShare": 0.00048387064256005206,
        "countScope": "label-across-paths"
      },
      "technique-pre-os-boot-8ac046ef": {
        "count": 13637,
        "datasetShare": 0.0008906645139716179,
        "assignedShare": 0.009164644378599207,
        "countScope": "label-across-paths"
      },
      "subtechnique-bootkit-bda15246": {
        "count": 754,
        "datasetShare": 0.00004924551173532301,
        "assignedShare": 0.0005067200895698322,
        "countScope": "label-across-paths"
      },
      "subtechnique-tftp-boot-945c0b7d": {
        "count": 910,
        "datasetShare": 0.00005943423830125191,
        "assignedShare": 0.0006115587287911769,
        "countScope": "label-across-paths"
      },
      "subtechnique-component-firmware-cfd5695a": {
        "count": 7199,
        "datasetShare": 0.00047018360607770603,
        "assignedShare": 0.004838034383041409,
        "countScope": "label-across-paths"
      },
      "subtechnique-rommonkit-7edcb86b": {
        "count": 3128,
        "datasetShare": 0.00020429703011683073,
        "assignedShare": 0.0021021491248997817,
        "countScope": "label-across-paths"
      },
      "subtechnique-system-firmware-4f742895": {
        "count": 720,
        "datasetShare": 0.00004702489184274876,
        "assignedShare": 0.00048387064256005206,
        "countScope": "label-across-paths"
      },
      "technique-build-image-on-host-f97173c0": {
        "count": 66,
        "datasetShare": 0.000004310615085585303,
        "assignedShare": 0.000044354808901338106,
        "countScope": "exact-term"
      },
      "technique-compromise-accounts-3ecba145": {
        "count": 37167,
        "datasetShare": 0.0024274641043325602,
        "assignedShare": 0.024977805794485355,
        "countScope": "exact-term"
      },
      "subtechnique-cloud-accounts-7528bf86": {
        "count": 1366,
        "datasetShare": 0.00008921666980165946,
        "assignedShare": 0.0009180101357458765,
        "countScope": "label-across-paths"
      },
      "subtechnique-email-accounts-6f59bb57": {
        "count": 2438,
        "datasetShare": 0.00015923150876752984,
        "assignedShare": 0.0016384397591130652,
        "countScope": "label-across-paths"
      },
      "subtechnique-social-media-accounts-b75c08b8": {
        "count": 38843,
        "datasetShare": 0.002536927602566514,
        "assignedShare": 0.026104149123555697,
        "countScope": "label-across-paths"
      },
      "technique-virtualization-sandbox-evasion-914620df": {
        "count": 10323,
        "datasetShare": 0.0006742193867954104,
        "assignedShare": 0.006937495337704746,
        "countScope": "label-across-paths"
      },
      "subtechnique-user-activity-based-checks-f4cd02a8": {
        "count": 5349,
        "datasetShare": 0.0003493557589817543,
        "assignedShare": 0.00359475564868572,
        "countScope": "label-across-paths"
      },
      "subtechnique-system-checks-7cb04a7e": {
        "count": 1367,
        "datasetShare": 0.00008928198215144106,
        "assignedShare": 0.0009186821783049877,
        "countScope": "label-across-paths"
      },
      "subtechnique-time-based-evasion-5a74ae99": {
        "count": 2028,
        "datasetShare": 0.00013245344535707567,
        "assignedShare": 0.0013629023098774798,
        "countScope": "label-across-paths"
      },
      "technique-virtualization-sandbox-evasion-179f3170": {
        "count": 10323,
        "datasetShare": 0.0006742193867954104,
        "assignedShare": 0.006937495337704746,
        "countScope": "label-across-paths"
      },
      "subtechnique-user-activity-based-checks-9fb10b4d": {
        "count": 5349,
        "datasetShare": 0.0003493557589817543,
        "assignedShare": 0.00359475564868572,
        "countScope": "label-across-paths"
      },
      "subtechnique-system-checks-2c68e7d8": {
        "count": 1367,
        "datasetShare": 0.00008928198215144106,
        "assignedShare": 0.0009186821783049877,
        "countScope": "label-across-paths"
      },
      "subtechnique-time-based-evasion-599cdb55": {
        "count": 2028,
        "datasetShare": 0.00013245344535707567,
        "assignedShare": 0.0013629023098774798,
        "countScope": "label-across-paths"
      },
      "technique-web-service-56e8e7bb": {
        "count": 1391,
        "datasetShare": 0.00009084947854619934,
        "assignedShare": 0.0009348111997236561,
        "countScope": "exact-term"
      },
      "subtechnique-one-way-communication-a7dcdac5": {
        "count": 349,
        "datasetShare": 0.00002279401007377683,
        "assignedShare": 0.000234542853129803,
        "countScope": "exact-term"
      },
      "subtechnique-dead-drop-resolver-833c9389": {
        "count": 479,
        "datasetShare": 0.00003128461554538424,
        "assignedShare": 0.0003219083858142568,
        "countScope": "exact-term"
      },
      "subtechnique-bidirectional-communication-7ed0a389": {
        "count": 437,
        "datasetShare": 0.000028541496854557236,
        "assignedShare": 0.00029368259833158715,
        "countScope": "exact-term"
      },
      "technique-stage-capabilities-20b37f0f": {
        "count": 15732,
        "datasetShare": 0.0010274938867640604,
        "assignedShare": 0.010572573539937137,
        "countScope": "exact-term"
      },
      "subtechnique-drive-by-target-31d1d693": {
        "count": 2626,
        "datasetShare": 0.00017151023052646978,
        "assignedShare": 0.0017647837602259675,
        "countScope": "exact-term"
      },
      "subtechnique-link-target-488e0539": {
        "count": 67,
        "datasetShare": 0.000004375927435366899,
        "assignedShare": 0.000045026851460449285,
        "countScope": "exact-term"
      },
      "subtechnique-seo-poisoning-ce759e92": {
        "count": 2401,
        "datasetShare": 0.0001568149518256108,
        "assignedShare": 0.0016135741844259513,
        "countScope": "exact-term"
      },
      "subtechnique-install-digital-certificate-77cbd1c9": {
        "count": 1505,
        "datasetShare": 0.00009829508642130123,
        "assignedShare": 0.001011424051462331,
        "countScope": "exact-term"
      },
      "subtechnique-upload-tool-1e1d4936": {
        "count": 723,
        "datasetShare": 0.000047220828892093545,
        "assignedShare": 0.0004858867702373856,
        "countScope": "exact-term"
      },
      "subtechnique-upload-malware-9ef0b2f1": {
        "count": 79,
        "datasetShare": 0.000005159675632746045,
        "assignedShare": 0.000053091362169783486,
        "countScope": "exact-term"
      },
      "technique-multi-stage-channels-8d3779f6": {
        "count": 453,
        "datasetShare": 0.000029586494451062763,
        "assignedShare": 0.0003044352792773661,
        "countScope": "exact-term"
      },
      "technique-financial-theft-b30e07b0": {
        "count": 134572,
        "datasetShare": 0.00878921353480887,
        "assignedShare": 0.09043811126471017,
        "countScope": "exact-term"
      },
      "technique-execution-guardrails-a9b4394e": {
        "count": 5031,
        "datasetShare": 0.00032858643175120696,
        "assignedShare": 0.0033810461148883635,
        "countScope": "exact-term"
      },
      "subtechnique-environmental-keying-7b89e6c7": {
        "count": 3416,
        "datasetShare": 0.00022310698685393024,
        "assignedShare": 0.0022956973819238027,
        "countScope": "exact-term"
      },
      "subtechnique-mutual-exclusion-c8e3a2c1": {
        "count": 501,
        "datasetShare": 0.000032721487240579345,
        "assignedShare": 0.00033669332211470285,
        "countScope": "exact-term"
      },
      "technique-cloud-storage-object-discovery-ac8dcbfd": {
        "count": 2290,
        "datasetShare": 0.0001495652809998537,
        "assignedShare": 0.00153897746036461,
        "countScope": "exact-term"
      },
      "technique-log-enumeration-dffba045": {
        "count": 1586,
        "datasetShare": 0.00010358538675361047,
        "assignedShare": 0.0010658594987503368,
        "countScope": "exact-term"
      },
      "technique-steal-application-access-token-0f42cbcf": {
        "count": 373,
        "datasetShare": 0.000024361506468535123,
        "assignedShare": 0.0002506718745484714,
        "countScope": "exact-term"
      },
      "technique-user-execution-1853a523": {
        "count": 3188,
        "datasetShare": 0.00020821577110372646,
        "assignedShare": 0.0021424716784464526,
        "countScope": "exact-term"
      },
      "subtechnique-malicious-file-eefe1151": {
        "count": 143,
        "datasetShare": 0.000009339666018768156,
        "assignedShare": 0.00009610208595289923,
        "countScope": "exact-term"
      },
      "subtechnique-malicious-image-09a3d463": {
        "count": 512,
        "datasetShare": 0.000033439923088176897,
        "assignedShare": 0.0003440857902649259,
        "countScope": "exact-term"
      },
      "subtechnique-malicious-link-09342658": {
        "count": 1683,
        "datasetShare": 0.00010992068468242524,
        "assignedShare": 0.0011310476269841216,
        "countScope": "exact-term"
      },
      "technique-process-discovery-a94f4a8e": {
        "count": 374,
        "datasetShare": 0.000024426818818316718,
        "assignedShare": 0.0002513439171075826,
        "countScope": "exact-term"
      },
      "technique-software-deployment-tools-41e5c451": {
        "count": 5406,
        "datasetShare": 0.0003530785629193053,
        "assignedShare": 0.0036330620745550573,
        "countScope": "label-across-paths"
      },
      "technique-software-deployment-tools-dd2225b3": {
        "count": 5406,
        "datasetShare": 0.0003530785629193053,
        "assignedShare": 0.0036330620745550573,
        "countScope": "label-across-paths"
      },
      "technique-exfiltration-over-c2-channel-c9ee09fc": {
        "count": 2075,
        "datasetShare": 0.00013552312579681065,
        "assignedShare": 0.0013944883101557055,
        "countScope": "exact-term"
      },
      "technique-gather-victim-org-information-fc2636a2": {
        "count": 67873,
        "datasetShare": 0.004432945116726232,
        "assignedShare": 0.04561354461455335,
        "countScope": "exact-term"
      },
      "subtechnique-business-relationships-6faa6bb0": {
        "count": 43067,
        "datasetShare": 0.0028128069680439737,
        "assignedShare": 0.028942856893241335,
        "countScope": "exact-term"
      },
      "subtechnique-determine-physical-locations-f24912d0": {
        "count": 2927,
        "datasetShare": 0.00019116924781073004,
        "assignedShare": 0.001967068570518434,
        "countScope": "exact-term"
      },
      "subtechnique-identify-roles-e8b48108": {
        "count": 1492,
        "datasetShare": 0.00009744602587414049,
        "assignedShare": 0.0010026874981938856,
        "countScope": "exact-term"
      },
      "subtechnique-identify-business-tempo-767c4f2b": {
        "count": 17445,
        "datasetShare": 0.0011393739419399336,
        "assignedShare": 0.011723782443694594,
        "countScope": "exact-term"
      },
      "technique-forge-web-credentials-9fecd025": {
        "count": 3703,
        "datasetShare": 0.00024185163124124814,
        "assignedShare": 0.0024885735963887123,
        "countScope": "exact-term"
      },
      "subtechnique-web-cookies-f559ef45": {
        "count": 642,
        "datasetShare": 0.00004193052855978431,
        "assignedShare": 0.00043145132294937976,
        "countScope": "exact-term"
      },
      "subtechnique-saml-tokens-d192b032": {
        "count": 2772,
        "datasetShare": 0.00018104583359458272,
        "assignedShare": 0.0018629019738562005,
        "countScope": "exact-term"
      },
      "technique-multi-factor-authentication-request-generation-86631075": {
        "count": 1159,
        "datasetShare": 0.00007569701339686919,
        "assignedShare": 0.0007788973260098615,
        "countScope": "exact-term"
      },
      "technique-compromise-host-software-binary-0cd0494f": {
        "count": 23,
        "datasetShare": 0.0000015021840449766965,
        "assignedShare": 0.000015456978859557218,
        "countScope": "exact-term"
      },
      "technique-exploitation-for-credential-access-6da2cbff": {
        "count": 34,
        "datasetShare": 0.000002220619892574247,
        "assignedShare": 0.000022849447009780236,
        "countScope": "exact-term"
      },
      "technique-gather-victim-network-information-a466798e": {
        "count": 18780,
        "datasetShare": 0.0012265659288983636,
        "assignedShare": 0.012620959260108025,
        "countScope": "exact-term"
      },
      "subtechnique-domain-properties-5478beab": {
        "count": 2438,
        "datasetShare": 0.00015923150876752984,
        "assignedShare": 0.0016384397591130652,
        "countScope": "exact-term"
      },
      "subtechnique-dns-f0091d4e": {
        "count": 659,
        "datasetShare": 0.000043040838506071436,
        "assignedShare": 0.0004428760464542699,
        "countScope": "label-across-paths"
      },
      "subtechnique-ip-addresses-ca050764": {
        "count": 208,
        "datasetShare": 0.000013584968754571864,
        "assignedShare": 0.00013978485229512613,
        "countScope": "exact-term"
      },
      "subtechnique-network-trust-dependencies-c10aa085": {
        "count": 1415,
        "datasetShare": 0.00009241697494095764,
        "assignedShare": 0.0009509402211423244,
        "countScope": "exact-term"
      },
      "subtechnique-network-topology-876fb0e8": {
        "count": 2628,
        "datasetShare": 0.00017164085522603298,
        "assignedShare": 0.00176612784534419,
        "countScope": "exact-term"
      },
      "subtechnique-network-security-appliances-fe030271": {
        "count": 10598,
        "datasetShare": 0.0006921802829853492,
        "assignedShare": 0.007122307041460322,
        "countScope": "exact-term"
      },
      "technique-exploitation-of-remote-services-cef14ab7": {
        "count": 364,
        "datasetShare": 0.000023773695320500762,
        "assignedShare": 0.00024462349151647077,
        "countScope": "exact-term"
      },
      "technique-internal-spearphishing-dfd80bd6": {
        "count": 626,
        "datasetShare": 0.00004088553096327878,
        "assignedShare": 0.0004206986420036008,
        "countScope": "exact-term"
      },
      "technique-trusted-relationship-d65e062a": {
        "count": 3499,
        "datasetShare": 0.00022852791188580267,
        "assignedShare": 0.002351476914330031,
        "countScope": "exact-term"
      },
      "technique-search-open-websites-domains-a4410470": {
        "count": 20475,
        "datasetShare": 0.001337270361778168,
        "assignedShare": 0.01376007139780148,
        "countScope": "exact-term"
      },
      "subtechnique-search-engines-100a7328": {
        "count": 4329,
        "datasetShare": 0.0002827371622045269,
        "assignedShare": 0.002909272238392313,
        "countScope": "exact-term"
      },
      "subtechnique-code-repositories-c9df8c0a": {
        "count": 2123,
        "datasetShare": 0.00013865811858632725,
        "assignedShare": 0.0014267463529930424,
        "countScope": "label-across-paths"
      },
      "subtechnique-social-media-b416e32e": {
        "count": 12985,
        "datasetShare": 0.0008480808619140176,
        "assignedShare": 0.008726472630058716,
        "countScope": "exact-term"
      },
      "technique-account-manipulation-2ea50fd0": {
        "count": 6833,
        "datasetShare": 0.0004462792860576421,
        "assignedShare": 0.004592066806406716,
        "countScope": "label-across-paths"
      },
      "subtechnique-additional-cloud-credentials-14a4fdea": {
        "count": 172,
        "datasetShare": 0.000011233724162434427,
        "assignedShare": 0.00011559132016712354,
        "countScope": "label-across-paths"
      },
      "subtechnique-additional-email-delegate-permissions-e037a350": {
        "count": 1469,
        "datasetShare": 0.00009594384182916379,
        "assignedShare": 0.0009872305193343283,
        "countScope": "label-across-paths"
      },
      "subtechnique-additional-cloud-roles-13415b8e": {
        "count": 820,
        "datasetShare": 0.000053556126820908315,
        "assignedShare": 0.0005510748984711704,
        "countScope": "label-across-paths"
      },
      "subtechnique-device-registration-79b3617e": {
        "count": 2448,
        "datasetShare": 0.0001598846322653458,
        "assignedShare": 0.001645160184704177,
        "countScope": "label-across-paths"
      },
      "subtechnique-additional-container-cluster-roles-dc690cbe": {
        "count": 143,
        "datasetShare": 0.000009339666018768156,
        "assignedShare": 0.00009610208595289923,
        "countScope": "label-across-paths"
      },
      "subtechnique-ssh-authorized-keys-d0272e79": {
        "count": 366,
        "datasetShare": 0.000023904320020063953,
        "assignedShare": 0.0002459675766346931,
        "countScope": "label-across-paths"
      },
      "subtechnique-additional-local-or-domain-groups-ee6d0d28": {
        "count": 313,
        "datasetShare": 0.00002044276548163939,
        "assignedShare": 0.0002103493210018004,
        "countScope": "label-across-paths"
      },
      "technique-account-manipulation-d73acdac": {
        "count": 6833,
        "datasetShare": 0.0004462792860576421,
        "assignedShare": 0.004592066806406716,
        "countScope": "label-across-paths"
      },
      "subtechnique-additional-cloud-credentials-23a21964": {
        "count": 172,
        "datasetShare": 0.000011233724162434427,
        "assignedShare": 0.00011559132016712354,
        "countScope": "label-across-paths"
      },
      "subtechnique-additional-email-delegate-permissions-af816fa2": {
        "count": 1469,
        "datasetShare": 0.00009594384182916379,
        "assignedShare": 0.0009872305193343283,
        "countScope": "label-across-paths"
      },
      "subtechnique-additional-cloud-roles-ff6acf10": {
        "count": 820,
        "datasetShare": 0.000053556126820908315,
        "assignedShare": 0.0005510748984711704,
        "countScope": "label-across-paths"
      },
      "subtechnique-device-registration-4f6d4a2b": {
        "count": 2448,
        "datasetShare": 0.0001598846322653458,
        "assignedShare": 0.001645160184704177,
        "countScope": "label-across-paths"
      },
      "subtechnique-additional-container-cluster-roles-8c9039ab": {
        "count": 143,
        "datasetShare": 0.000009339666018768156,
        "assignedShare": 0.00009610208595289923,
        "countScope": "label-across-paths"
      },
      "subtechnique-ssh-authorized-keys-3a1134cc": {
        "count": 366,
        "datasetShare": 0.000023904320020063953,
        "assignedShare": 0.0002459675766346931,
        "countScope": "label-across-paths"
      },
      "subtechnique-additional-local-or-domain-groups-cc8cecdb": {
        "count": 313,
        "datasetShare": 0.00002044276548163939,
        "assignedShare": 0.0002103493210018004,
        "countScope": "label-across-paths"
      },
      "technique-exfiltration-over-alternative-protocol-2c89aa68": {
        "count": 4971,
        "datasetShare": 0.00032466769076431126,
        "assignedShare": 0.0033407235613416926,
        "countScope": "exact-term"
      },
      "subtechnique-exfiltration-over-asymmetric-encrypted-non-c2-protocol-5dde3620": {
        "count": 1326,
        "datasetShare": 0.00008660417581039563,
        "assignedShare": 0.0008911284333814292,
        "countScope": "exact-term"
      },
      "subtechnique-exfiltration-over-unencrypted-non-c2-protocol-77f59d8e": {
        "count": 165,
        "datasetShare": 0.000010776537713963259,
        "assignedShare": 0.00011088702225334525,
        "countScope": "exact-term"
      },
      "subtechnique-exfiltration-over-symmetric-encrypted-non-c2-protocol-d8c00c2d": {
        "count": 775,
        "datasetShare": 0.00005061707108073651,
        "assignedShare": 0.0005208329833111671,
        "countScope": "exact-term"
      },
      "technique-search-closed-sources-8339bec9": {
        "count": 62260,
        "datasetShare": 0.004066346897402136,
        "assignedShare": 0.04184136973026228,
        "countScope": "exact-term"
      },
      "subtechnique-threat-intel-vendors-381369e8": {
        "count": 31651,
        "datasetShare": 0.0020672011829372793,
        "assignedShare": 0.021270819038428066,
        "countScope": "exact-term"
      },
      "subtechnique-purchase-technical-data-eac21f69": {
        "count": 20399,
        "datasetShare": 0.0013323066231947667,
        "assignedShare": 0.01370899616330903,
        "countScope": "exact-term"
      },
      "technique-phishing-121549d9": {
        "count": 7869,
        "datasetShare": 0.000513942880431375,
        "assignedShare": 0.005288302897645902,
        "countScope": "exact-term"
      },
      "subtechnique-spearphishing-link-a6b8552f": {
        "count": 939,
        "datasetShare": 0.00006132829644491818,
        "assignedShare": 0.0006310479630054013,
        "countScope": "label-across-paths"
      },
      "subtechnique-spearphishing-attachment-bf8f688d": {
        "count": 177,
        "datasetShare": 0.000011560285911342403,
        "assignedShare": 0.00011895153296267946,
        "countScope": "label-across-paths"
      },
      "subtechnique-spearphishing-voice-d60f9645": {
        "count": 4752,
        "datasetShare": 0.0003103642861621418,
        "assignedShare": 0.0031935462408963435,
        "countScope": "label-across-paths"
      },
      "subtechnique-spearphishing-via-service-9af1e791": {
        "count": 275,
        "datasetShare": 0.000017960896189938765,
        "assignedShare": 0.00018481170375557544,
        "countScope": "exact-term"
      },
      "technique-brute-force-c2c2819a": {
        "count": 1953,
        "datasetShare": 0.00012755501912345603,
        "assignedShare": 0.0013124991179441412,
        "countScope": "exact-term"
      },
      "subtechnique-credential-stuffing-4f11f0d9": {
        "count": 669,
        "datasetShare": 0.00004369396200388739,
        "assignedShare": 0.0004495964720453817,
        "countScope": "exact-term"
      },
      "subtechnique-password-cracking-8b1c6450": {
        "count": 215,
        "datasetShare": 0.000014042155203043033,
        "assignedShare": 0.00014448915020890443,
        "countScope": "exact-term"
      },
      "subtechnique-password-guessing-2cca892b": {
        "count": 175,
        "datasetShare": 0.000011429661211779213,
        "assignedShare": 0.00011760744784445709,
        "countScope": "exact-term"
      },
      "subtechnique-password-spraying-cc928813": {
        "count": 527,
        "datasetShare": 0.00003441960833490083,
        "assignedShare": 0.00035416642865159366,
        "countScope": "exact-term"
      },
      "technique-data-manipulation-f5f9eeca": {
        "count": 3436,
        "datasetShare": 0.00022441323384956216,
        "assignedShare": 0.0023091382331060263,
        "countScope": "exact-term"
      },
      "subtechnique-transmitted-data-manipulation-195e007c": {
        "count": 866,
        "datasetShare": 0.0000565604949108617,
        "assignedShare": 0.0005819888561902848,
        "countScope": "exact-term"
      },
      "subtechnique-runtime-data-manipulation-0da5f10b": {
        "count": 181,
        "datasetShare": 0.000011821535310468786,
        "assignedShare": 0.0001216397031991242,
        "countScope": "exact-term"
      },
      "subtechnique-stored-data-manipulation-a7ec50bc": {
        "count": 317,
        "datasetShare": 0.000020704014880765775,
        "assignedShare": 0.00021303749123824514,
        "countScope": "exact-term"
      },
      "technique-inter-process-communication-f483eb45": {
        "count": 10039,
        "datasetShare": 0.0006556706794574373,
        "assignedShare": 0.00674663525091717,
        "countScope": "exact-term"
      },
      "subtechnique-xpc-services-16245188": {
        "count": 1457,
        "datasetShare": 0.00009516009363178465,
        "assignedShare": 0.0009791660086249942,
        "countScope": "exact-term"
      },
      "subtechnique-dynamic-data-exchange-e6c295d8": {
        "count": 5540,
        "datasetShare": 0.0003618304177900391,
        "assignedShare": 0.003723115777475956,
        "countScope": "exact-term"
      },
      "subtechnique-component-object-model-24e79569": {
        "count": 1646,
        "datasetShare": 0.0001075041277405062,
        "assignedShare": 0.001106182052297008,
        "countScope": "exact-term"
      },
      "technique-data-obfuscation-b208a91c": {
        "count": 2569,
        "datasetShare": 0.00016778742658891884,
        "assignedShare": 0.0017264773343566302,
        "countScope": "exact-term"
      },
      "subtechnique-junk-data-0aaa0a73": {
        "count": 1247,
        "datasetShare": 0.00008144450017764958,
        "assignedShare": 0.0008380370712116457,
        "countScope": "exact-term"
      },
      "subtechnique-protocol-or-service-impersonation-8321c192": {
        "count": 129,
        "datasetShare": 0.00000842529312182582,
        "assignedShare": 0.00008669349012534266,
        "countScope": "exact-term"
      },
      "subtechnique-steganography-e87e6143": {
        "count": 520,
        "datasetShare": 0.00003396242188642966,
        "assignedShare": 0.00034946213073781536,
        "countScope": "label-across-paths"
      },
      "technique-data-from-network-shared-drive-15d02dc9": {
        "count": 563,
        "datasetShare": 0.000036770852927038264,
        "assignedShare": 0.0003783599607795963,
        "countScope": "exact-term"
      },
      "technique-modify-system-image-39d3645f": {
        "count": 1975,
        "datasetShare": 0.00012899189081865112,
        "assignedShare": 0.001327284054244587,
        "countScope": "exact-term"
      },
      "subtechnique-downgrade-system-image-dc0dc212": {
        "count": 517,
        "datasetShare": 0.000033766484837084876,
        "assignedShare": 0.00034744600306048183,
        "countScope": "exact-term"
      },
      "subtechnique-patch-system-image-be0ec764": {
        "count": 1419,
        "datasetShare": 0.00009267822434008402,
        "assignedShare": 0.0009536283913787692,
        "countScope": "exact-term"
      },
      "technique-hijack-execution-flow-e920f269": {
        "count": 2404,
        "datasetShare": 0.0001570108888749556,
        "assignedShare": 0.001615590312103285,
        "countScope": "label-across-paths"
      },
      "subtechnique-services-file-permissions-weakness-0884afc5": {
        "count": 76,
        "datasetShare": 0.0000049637385834012585,
        "assignedShare": 0.00005107523449244994,
        "countScope": "label-across-paths"
      },
      "subtechnique-kernelcallbacktable-a2aa82dd": {
        "count": 19,
        "datasetShare": 0.0000012409346458503146,
        "assignedShare": 0.000012768808623112485,
        "countScope": "label-across-paths"
      },
      "subtechnique-path-interception-by-path-environment-variable-201e63e2": {
        "count": 279,
        "datasetShare": 0.000018222145589065146,
        "assignedShare": 0.00018749987399202016,
        "countScope": "label-across-paths"
      },
      "subtechnique-executable-installer-file-permissions-weakness-1bfc825b": {
        "count": 39,
        "datasetShare": 0.0000025471816414822245,
        "assignedShare": 0.000026209659805336153,
        "countScope": "label-across-paths"
      },
      "subtechnique-dll-side-loading-a8374216": {
        "count": 639,
        "datasetShare": 0.000041734591510439524,
        "assignedShare": 0.0004294351952720462,
        "countScope": "label-across-paths"
      },
      "subtechnique-path-interception-by-unquoted-path-e26ceb7a": {
        "count": 479,
        "datasetShare": 0.00003128461554538424,
        "assignedShare": 0.0003219083858142568,
        "countScope": "label-across-paths"
      },
      "subtechnique-dylib-hijacking-47276478": {
        "count": 78,
        "datasetShare": 0.000005094363282964449,
        "assignedShare": 0.000052419319610672306,
        "countScope": "label-across-paths"
      },
      "subtechnique-dynamic-linker-hijacking-b1aaa3ae": {
        "count": 96,
        "datasetShare": 0.0000062699855790331685,
        "assignedShare": 0.0000645160856746736,
        "countScope": "label-across-paths"
      },
      "subtechnique-appdomainmanager-a4b62c41": {
        "count": 43,
        "datasetShare": 0.0000028084310406086067,
        "assignedShare": 0.000028897830041780884,
        "countScope": "label-across-paths"
      },
      "subtechnique-dll-search-order-hijacking-4076ee45": {
        "count": 85,
        "datasetShare": 0.000005551549731435617,
        "assignedShare": 0.00005712361752445059,
        "countScope": "label-across-paths"
      },
      "subtechnique-path-interception-by-search-order-hijacking-cb65f091": {
        "count": 171,
        "datasetShare": 0.000011168411812652832,
        "assignedShare": 0.00011491927760801236,
        "countScope": "label-across-paths"
      },
      "subtechnique-services-registry-permissions-weakness-c7924d0c": {
        "count": 233,
        "datasetShare": 0.000015217777499111752,
        "assignedShare": 0.00015658591627290574,
        "countScope": "label-across-paths"
      },
      "subtechnique-cor-profiler-00f089dd": {
        "count": 124,
        "datasetShare": 0.000008098731372917841,
        "assignedShare": 0.00008333327732978674,
        "countScope": "label-across-paths"
      },
      "technique-hijack-execution-flow-515a1a7e": {
        "count": 2404,
        "datasetShare": 0.0001570108888749556,
        "assignedShare": 0.001615590312103285,
        "countScope": "label-across-paths"
      },
      "subtechnique-services-file-permissions-weakness-884dae36": {
        "count": 76,
        "datasetShare": 0.0000049637385834012585,
        "assignedShare": 0.00005107523449244994,
        "countScope": "label-across-paths"
      },
      "subtechnique-kernelcallbacktable-fa662efc": {
        "count": 19,
        "datasetShare": 0.0000012409346458503146,
        "assignedShare": 0.000012768808623112485,
        "countScope": "label-across-paths"
      },
      "subtechnique-path-interception-by-path-environment-variable-90048ef8": {
        "count": 279,
        "datasetShare": 0.000018222145589065146,
        "assignedShare": 0.00018749987399202016,
        "countScope": "label-across-paths"
      },
      "subtechnique-executable-installer-file-permissions-weakness-ccf02010": {
        "count": 39,
        "datasetShare": 0.0000025471816414822245,
        "assignedShare": 0.000026209659805336153,
        "countScope": "label-across-paths"
      },
      "subtechnique-dll-side-loading-8d423cb6": {
        "count": 639,
        "datasetShare": 0.000041734591510439524,
        "assignedShare": 0.0004294351952720462,
        "countScope": "label-across-paths"
      },
      "subtechnique-path-interception-by-unquoted-path-d007a75d": {
        "count": 479,
        "datasetShare": 0.00003128461554538424,
        "assignedShare": 0.0003219083858142568,
        "countScope": "label-across-paths"
      },
      "subtechnique-dylib-hijacking-e6b13a2f": {
        "count": 78,
        "datasetShare": 0.000005094363282964449,
        "assignedShare": 0.000052419319610672306,
        "countScope": "label-across-paths"
      },
      "subtechnique-dynamic-linker-hijacking-7c1286c8": {
        "count": 96,
        "datasetShare": 0.0000062699855790331685,
        "assignedShare": 0.0000645160856746736,
        "countScope": "label-across-paths"
      },
      "subtechnique-appdomainmanager-db587557": {
        "count": 43,
        "datasetShare": 0.0000028084310406086067,
        "assignedShare": 0.000028897830041780884,
        "countScope": "label-across-paths"
      },
      "subtechnique-dll-search-order-hijacking-604f24be": {
        "count": 85,
        "datasetShare": 0.000005551549731435617,
        "assignedShare": 0.00005712361752445059,
        "countScope": "label-across-paths"
      },
      "subtechnique-path-interception-by-search-order-hijacking-ee7ba67a": {
        "count": 171,
        "datasetShare": 0.000011168411812652832,
        "assignedShare": 0.00011491927760801236,
        "countScope": "label-across-paths"
      },
      "subtechnique-services-registry-permissions-weakness-440d278c": {
        "count": 233,
        "datasetShare": 0.000015217777499111752,
        "assignedShare": 0.00015658591627290574,
        "countScope": "label-across-paths"
      },
      "subtechnique-cor-profiler-9c9e3eac": {
        "count": 124,
        "datasetShare": 0.000008098731372917841,
        "assignedShare": 0.00008333327732978674,
        "countScope": "label-across-paths"
      },
      "technique-hijack-execution-flow-ddc9c128": {
        "count": 2404,
        "datasetShare": 0.0001570108888749556,
        "assignedShare": 0.001615590312103285,
        "countScope": "label-across-paths"
      },
      "subtechnique-services-file-permissions-weakness-3aeb40b7": {
        "count": 76,
        "datasetShare": 0.0000049637385834012585,
        "assignedShare": 0.00005107523449244994,
        "countScope": "label-across-paths"
      },
      "subtechnique-kernelcallbacktable-2677cc36": {
        "count": 19,
        "datasetShare": 0.0000012409346458503146,
        "assignedShare": 0.000012768808623112485,
        "countScope": "label-across-paths"
      },
      "subtechnique-path-interception-by-path-environment-variable-e2bcee2b": {
        "count": 279,
        "datasetShare": 0.000018222145589065146,
        "assignedShare": 0.00018749987399202016,
        "countScope": "label-across-paths"
      },
      "subtechnique-executable-installer-file-permissions-weakness-7cdadfa9": {
        "count": 39,
        "datasetShare": 0.0000025471816414822245,
        "assignedShare": 0.000026209659805336153,
        "countScope": "label-across-paths"
      },
      "subtechnique-dll-side-loading-24061d4a": {
        "count": 639,
        "datasetShare": 0.000041734591510439524,
        "assignedShare": 0.0004294351952720462,
        "countScope": "label-across-paths"
      },
      "subtechnique-path-interception-by-unquoted-path-bba5e854": {
        "count": 479,
        "datasetShare": 0.00003128461554538424,
        "assignedShare": 0.0003219083858142568,
        "countScope": "label-across-paths"
      },
      "subtechnique-dylib-hijacking-2bfa7e6d": {
        "count": 78,
        "datasetShare": 0.000005094363282964449,
        "assignedShare": 0.000052419319610672306,
        "countScope": "label-across-paths"
      },
      "subtechnique-dynamic-linker-hijacking-702f00c6": {
        "count": 96,
        "datasetShare": 0.0000062699855790331685,
        "assignedShare": 0.0000645160856746736,
        "countScope": "label-across-paths"
      },
      "subtechnique-appdomainmanager-8af8660a": {
        "count": 43,
        "datasetShare": 0.0000028084310406086067,
        "assignedShare": 0.000028897830041780884,
        "countScope": "label-across-paths"
      },
      "subtechnique-dll-search-order-hijacking-599f796c": {
        "count": 85,
        "datasetShare": 0.000005551549731435617,
        "assignedShare": 0.00005712361752445059,
        "countScope": "label-across-paths"
      },
      "subtechnique-path-interception-by-search-order-hijacking-f5ee88c3": {
        "count": 171,
        "datasetShare": 0.000011168411812652832,
        "assignedShare": 0.00011491927760801236,
        "countScope": "label-across-paths"
      },
      "subtechnique-services-registry-permissions-weakness-3ac1c5f5": {
        "count": 233,
        "datasetShare": 0.000015217777499111752,
        "assignedShare": 0.00015658591627290574,
        "countScope": "label-across-paths"
      },
      "subtechnique-cor-profiler-fc7974b7": {
        "count": 124,
        "datasetShare": 0.000008098731372917841,
        "assignedShare": 0.00008333327732978674,
        "countScope": "label-across-paths"
      },
      "technique-valid-accounts-ba0c0e17": {
        "count": 1576,
        "datasetShare": 0.0001029322632557945,
        "assignedShare": 0.001059139073159225,
        "countScope": "label-across-paths"
      },
      "subtechnique-cloud-accounts-41d0e4b1": {
        "count": 1366,
        "datasetShare": 0.00008921666980165946,
        "assignedShare": 0.0009180101357458765,
        "countScope": "label-across-paths"
      },
      "subtechnique-domain-accounts-37695f9a": {
        "count": 143,
        "datasetShare": 0.000009339666018768156,
        "assignedShare": 0.00009610208595289923,
        "countScope": "label-across-paths"
      },
      "subtechnique-local-accounts-356d8ca5": {
        "count": 27,
        "datasetShare": 0.0000017634334441030785,
        "assignedShare": 0.000018145149096001953,
        "countScope": "label-across-paths"
      },
      "subtechnique-default-accounts-97875944": {
        "count": 317,
        "datasetShare": 0.000020704014880765775,
        "assignedShare": 0.00021303749123824514,
        "countScope": "label-across-paths"
      },
      "technique-valid-accounts-10d9be63": {
        "count": 1576,
        "datasetShare": 0.0001029322632557945,
        "assignedShare": 0.001059139073159225,
        "countScope": "label-across-paths"
      },
      "subtechnique-cloud-accounts-619d764f": {
        "count": 1366,
        "datasetShare": 0.00008921666980165946,
        "assignedShare": 0.0009180101357458765,
        "countScope": "label-across-paths"
      },
      "subtechnique-domain-accounts-af767978": {
        "count": 143,
        "datasetShare": 0.000009339666018768156,
        "assignedShare": 0.00009610208595289923,
        "countScope": "label-across-paths"
      },
      "subtechnique-local-accounts-318dff04": {
        "count": 27,
        "datasetShare": 0.0000017634334441030785,
        "assignedShare": 0.000018145149096001953,
        "countScope": "label-across-paths"
      },
      "subtechnique-default-accounts-53f13216": {
        "count": 317,
        "datasetShare": 0.000020704014880765775,
        "assignedShare": 0.00021303749123824514,
        "countScope": "label-across-paths"
      },
      "technique-valid-accounts-834cfe8d": {
        "count": 1576,
        "datasetShare": 0.0001029322632557945,
        "assignedShare": 0.001059139073159225,
        "countScope": "label-across-paths"
      },
      "subtechnique-cloud-accounts-93fd217d": {
        "count": 1366,
        "datasetShare": 0.00008921666980165946,
        "assignedShare": 0.0009180101357458765,
        "countScope": "label-across-paths"
      },
      "subtechnique-domain-accounts-e2a077ad": {
        "count": 143,
        "datasetShare": 0.000009339666018768156,
        "assignedShare": 0.00009610208595289923,
        "countScope": "label-across-paths"
      },
      "subtechnique-local-accounts-15302ff8": {
        "count": 27,
        "datasetShare": 0.0000017634334441030785,
        "assignedShare": 0.000018145149096001953,
        "countScope": "label-across-paths"
      },
      "subtechnique-default-accounts-bef5f626": {
        "count": 317,
        "datasetShare": 0.000020704014880765775,
        "assignedShare": 0.00021303749123824514,
        "countScope": "label-across-paths"
      },
      "technique-valid-accounts-cc1653b4": {
        "count": 1576,
        "datasetShare": 0.0001029322632557945,
        "assignedShare": 0.001059139073159225,
        "countScope": "label-across-paths"
      },
      "subtechnique-cloud-accounts-aab233c0": {
        "count": 1366,
        "datasetShare": 0.00008921666980165946,
        "assignedShare": 0.0009180101357458765,
        "countScope": "label-across-paths"
      },
      "subtechnique-domain-accounts-afc0a9f1": {
        "count": 143,
        "datasetShare": 0.000009339666018768156,
        "assignedShare": 0.00009610208595289923,
        "countScope": "label-across-paths"
      },
      "subtechnique-local-accounts-eeaed214": {
        "count": 27,
        "datasetShare": 0.0000017634334441030785,
        "assignedShare": 0.000018145149096001953,
        "countScope": "label-across-paths"
      },
      "subtechnique-default-accounts-dd3e06dd": {
        "count": 317,
        "datasetShare": 0.000020704014880765775,
        "assignedShare": 0.00021303749123824514,
        "countScope": "label-across-paths"
      },
      "technique-non-standard-port-871c10ca": {
        "count": 1251,
        "datasetShare": 0.00008170574957677598,
        "assignedShare": 0.0008407252414480904,
        "countScope": "exact-term"
      },
      "technique-exploitation-for-privilege-escalation-83b16723": {
        "count": 198,
        "datasetShare": 0.00001293184525675591,
        "assignedShare": 0.0001330644267040143,
        "countScope": "exact-term"
      },
      "technique-account-access-removal-8efec6e5": {
        "count": 6407,
        "datasetShare": 0.0004184562250506824,
        "assignedShare": 0.004305776676225352,
        "countScope": "exact-term"
      },
      "technique-obfuscated-files-or-information-3bacaee6": {
        "count": 7856,
        "datasetShare": 0.0005130938198842143,
        "assignedShare": 0.0052795663443774565,
        "countScope": "exact-term"
      },
      "subtechnique-indicator-removal-from-tools-8f2de5a5": {
        "count": 787,
        "datasetShare": 0.00005140081927811566,
        "assignedShare": 0.0005288974940205013,
        "countScope": "exact-term"
      },
      "subtechnique-embedded-payloads-189a2b29": {
        "count": 49,
        "datasetShare": 0.0000032003051392981795,
        "assignedShare": 0.00003293008539644799,
        "countScope": "exact-term"
      },
      "subtechnique-encrypted-encoded-file-5aace75a": {
        "count": 258,
        "datasetShare": 0.00001685058624365164,
        "assignedShare": 0.00017338698025068532,
        "countScope": "exact-term"
      },
      "subtechnique-lnk-icon-smuggling-9d331dbe": {
        "count": 556,
        "datasetShare": 0.0000363136664785671,
        "assignedShare": 0.000373655662865818,
        "countScope": "exact-term"
      },
      "subtechnique-html-smuggling-b01cad85": {
        "count": 63,
        "datasetShare": 0.000004114678036240517,
        "assignedShare": 0.000042338681224004554,
        "countScope": "exact-term"
      },
      "subtechnique-fileless-storage-3cd9950b": {
        "count": 653,
        "datasetShare": 0.000042648964407381864,
        "assignedShare": 0.0004388437910996028,
        "countScope": "exact-term"
      },
      "subtechnique-polymorphic-code-6f9bcaaa": {
        "count": 775,
        "datasetShare": 0.00005061707108073651,
        "assignedShare": 0.0005208329833111671,
        "countScope": "exact-term"
      },
      "subtechnique-command-obfuscation-e779d514": {
        "count": 392,
        "datasetShare": 0.000025602441114385436,
        "assignedShare": 0.0002634406831715839,
        "countScope": "exact-term"
      },
      "subtechnique-compile-after-delivery-b18a7cdd": {
        "count": 280,
        "datasetShare": 0.00001828745793884674,
        "assignedShare": 0.00018817191655113135,
        "countScope": "exact-term"
      },
      "subtechnique-dynamic-api-resolution-98e9c284": {
        "count": 613,
        "datasetShare": 0.00004003647041611804,
        "assignedShare": 0.00041196208873515544,
        "countScope": "exact-term"
      },
      "subtechnique-steganography-a103eae3": {
        "count": 520,
        "datasetShare": 0.00003396242188642966,
        "assignedShare": 0.00034946213073781536,
        "countScope": "label-across-paths"
      },
      "subtechnique-stripped-payloads-0dd5cd75": {
        "count": 80,
        "datasetShare": 0.00000522498798252764,
        "assignedShare": 0.00005376340472889467,
        "countScope": "exact-term"
      },
      "subtechnique-software-packing-9d5b2ca5": {
        "count": 2768,
        "datasetShare": 0.00018078458419545636,
        "assignedShare": 0.0018602138036197557,
        "countScope": "exact-term"
      },
      "subtechnique-binary-padding-fd01faa1": {
        "count": 112,
        "datasetShare": 0.000007314983175538696,
        "assignedShare": 0.00007526876662045254,
        "countScope": "exact-term"
      },
      "technique-password-policy-discovery-3c966f77": {
        "count": 52,
        "datasetShare": 0.000003396242188642966,
        "assignedShare": 0.00003494621307378153,
        "countScope": "exact-term"
      },
      "technique-event-triggered-execution-9242c22a": {
        "count": 8629,
        "datasetShare": 0.0005635802662653876,
        "assignedShare": 0.005799055242570401,
        "countScope": "label-across-paths"
      },
      "subtechnique-screensaver-8e36a327": {
        "count": 78,
        "datasetShare": 0.000005094363282964449,
        "assignedShare": 0.000052419319610672306,
        "countScope": "label-across-paths"
      },
      "subtechnique-powershell-profile-6f3fcff7": {
        "count": 27,
        "datasetShare": 0.0000017634334441030785,
        "assignedShare": 0.000018145149096001953,
        "countScope": "label-across-paths"
      },
      "subtechnique-installer-packages-49067b4f": {
        "count": 267,
        "datasetShare": 0.000017438397391686,
        "assignedShare": 0.00017943536328268598,
        "countScope": "label-across-paths"
      },
      "subtechnique-windows-management-instrumentation-event-subscription-fbec55b1": {
        "count": 423,
        "datasetShare": 0.0000276271239576149,
        "assignedShare": 0.00028427400250403056,
        "countScope": "label-across-paths"
      },
      "subtechnique-lc-load-dylib-addition-ab7cd091": {
        "count": 90,
        "datasetShare": 0.000005878111480343595,
        "assignedShare": 0.00006048383032000651,
        "countScope": "label-across-paths"
      },
      "subtechnique-application-shimming-445720bf": {
        "count": 630,
        "datasetShare": 0.00004114678036240516,
        "assignedShare": 0.00042338681224004556,
        "countScope": "label-across-paths"
      },
      "subtechnique-component-object-model-hijacking-93355b97": {
        "count": 47,
        "datasetShare": 0.0000030696804397349886,
        "assignedShare": 0.00003158600027822562,
        "countScope": "label-across-paths"
      },
      "subtechnique-unix-shell-configuration-modification-6f05a764": {
        "count": 59,
        "datasetShare": 0.000003853428637114135,
        "assignedShare": 0.00003965051098755982,
        "countScope": "label-across-paths"
      },
      "subtechnique-appinit-dlls-fe4e7d2d": {
        "count": 223,
        "datasetShare": 0.000014564654001295797,
        "assignedShare": 0.0001498654906817939,
        "countScope": "label-across-paths"
      },
      "subtechnique-trap-bd02d0d2": {
        "count": 536,
        "datasetShare": 0.00003500741948293519,
        "assignedShare": 0.0003602148116835943,
        "countScope": "label-across-paths"
      },
      "subtechnique-netsh-helper-dll-90207899": {
        "count": 222,
        "datasetShare": 0.000014499341651514201,
        "assignedShare": 0.00014919344812268273,
        "countScope": "label-across-paths"
      },
      "subtechnique-image-file-execution-options-injection-abed6033": {
        "count": 1719,
        "datasetShare": 0.00011227192927456266,
        "assignedShare": 0.0011552411591121243,
        "countScope": "label-across-paths"
      },
      "subtechnique-change-default-file-association-d104ae38": {
        "count": 85,
        "datasetShare": 0.000005551549731435617,
        "assignedShare": 0.00005712361752445059,
        "countScope": "label-across-paths"
      },
      "subtechnique-appcert-dlls-055504aa": {
        "count": 99,
        "datasetShare": 0.000006465922628377955,
        "assignedShare": 0.00006653221335200716,
        "countScope": "label-across-paths"
      },
      "subtechnique-udev-rules-f78dcae6": {
        "count": 141,
        "datasetShare": 0.000009209041319204966,
        "assignedShare": 0.00009475800083467685,
        "countScope": "label-across-paths"
      },
      "subtechnique-emond-2d917bbc": {
        "count": 1893,
        "datasetShare": 0.0001236362781365603,
        "assignedShare": 0.0012721765643974702,
        "countScope": "label-across-paths"
      },
      "subtechnique-accessibility-features-9310e55c": {
        "count": 761,
        "datasetShare": 0.00004970269818379418,
        "assignedShare": 0.0005114243874836105,
        "countScope": "label-across-paths"
      },
      "technique-event-triggered-execution-d431f16f": {
        "count": 8629,
        "datasetShare": 0.0005635802662653876,
        "assignedShare": 0.005799055242570401,
        "countScope": "label-across-paths"
      },
      "subtechnique-screensaver-0de201c2": {
        "count": 78,
        "datasetShare": 0.000005094363282964449,
        "assignedShare": 0.000052419319610672306,
        "countScope": "label-across-paths"
      },
      "subtechnique-powershell-profile-bbdbef02": {
        "count": 27,
        "datasetShare": 0.0000017634334441030785,
        "assignedShare": 0.000018145149096001953,
        "countScope": "label-across-paths"
      },
      "subtechnique-installer-packages-28be017f": {
        "count": 267,
        "datasetShare": 0.000017438397391686,
        "assignedShare": 0.00017943536328268598,
        "countScope": "label-across-paths"
      },
      "subtechnique-windows-management-instrumentation-event-subscription-282d5bb8": {
        "count": 423,
        "datasetShare": 0.0000276271239576149,
        "assignedShare": 0.00028427400250403056,
        "countScope": "label-across-paths"
      },
      "subtechnique-lc-load-dylib-addition-4f05daa2": {
        "count": 90,
        "datasetShare": 0.000005878111480343595,
        "assignedShare": 0.00006048383032000651,
        "countScope": "label-across-paths"
      },
      "subtechnique-application-shimming-cfb3bb23": {
        "count": 630,
        "datasetShare": 0.00004114678036240516,
        "assignedShare": 0.00042338681224004556,
        "countScope": "label-across-paths"
      },
      "subtechnique-component-object-model-hijacking-e7c9dc37": {
        "count": 47,
        "datasetShare": 0.0000030696804397349886,
        "assignedShare": 0.00003158600027822562,
        "countScope": "label-across-paths"
      },
      "subtechnique-unix-shell-configuration-modification-f876daa0": {
        "count": 59,
        "datasetShare": 0.000003853428637114135,
        "assignedShare": 0.00003965051098755982,
        "countScope": "label-across-paths"
      },
      "subtechnique-appinit-dlls-032ee3a9": {
        "count": 223,
        "datasetShare": 0.000014564654001295797,
        "assignedShare": 0.0001498654906817939,
        "countScope": "label-across-paths"
      },
      "subtechnique-trap-ec1dfdfc": {
        "count": 536,
        "datasetShare": 0.00003500741948293519,
        "assignedShare": 0.0003602148116835943,
        "countScope": "label-across-paths"
      },
      "subtechnique-netsh-helper-dll-94467527": {
        "count": 222,
        "datasetShare": 0.000014499341651514201,
        "assignedShare": 0.00014919344812268273,
        "countScope": "label-across-paths"
      },
      "subtechnique-image-file-execution-options-injection-cae6a6f6": {
        "count": 1719,
        "datasetShare": 0.00011227192927456266,
        "assignedShare": 0.0011552411591121243,
        "countScope": "label-across-paths"
      },
      "subtechnique-change-default-file-association-2158e759": {
        "count": 85,
        "datasetShare": 0.000005551549731435617,
        "assignedShare": 0.00005712361752445059,
        "countScope": "label-across-paths"
      },
      "subtechnique-appcert-dlls-3c104fc0": {
        "count": 99,
        "datasetShare": 0.000006465922628377955,
        "assignedShare": 0.00006653221335200716,
        "countScope": "label-across-paths"
      },
      "subtechnique-udev-rules-30eff310": {
        "count": 141,
        "datasetShare": 0.000009209041319204966,
        "assignedShare": 0.00009475800083467685,
        "countScope": "label-across-paths"
      },
      "subtechnique-emond-78ffe1dd": {
        "count": 1893,
        "datasetShare": 0.0001236362781365603,
        "assignedShare": 0.0012721765643974702,
        "countScope": "label-across-paths"
      },
      "subtechnique-accessibility-features-0e7148e1": {
        "count": 761,
        "datasetShare": 0.00004970269818379418,
        "assignedShare": 0.0005114243874836105,
        "countScope": "label-across-paths"
      },
      "technique-forced-authentication-80e9ad10": {
        "count": 38,
        "datasetShare": 0.0000024818692917006292,
        "assignedShare": 0.00002553761724622497,
        "countScope": "exact-term"
      },
      "technique-network-boundary-bridging-ab144e28": {
        "count": 14035,
        "datasetShare": 0.0009166588291846929,
        "assignedShare": 0.009432117317125458,
        "countScope": "exact-term"
      },
      "subtechnique-network-address-translation-traversal-58c112af": {
        "count": 3616,
        "datasetShare": 0.00023616945681024934,
        "assignedShare": 0.002430105893746039,
        "countScope": "exact-term"
      },
      "technique-data-encrypted-for-impact-fec80113": {
        "count": 8445,
        "datasetShare": 0.000551562793905574,
        "assignedShare": 0.005675399411693944,
        "countScope": "exact-term"
      },
      "technique-subvert-trust-controls-09c1546c": {
        "count": 7681,
        "datasetShare": 0.0005016641586724351,
        "assignedShare": 0.005161958896532999,
        "countScope": "exact-term"
      },
      "subtechnique-mark-of-the-web-bypass-e42d3ed6": {
        "count": 331,
        "datasetShare": 0.000021618387777708112,
        "assignedShare": 0.0002224460870658017,
        "countScope": "exact-term"
      },
      "subtechnique-code-signing-429c5bc9": {
        "count": 1651,
        "datasetShare": 0.00010783068948941417,
        "assignedShare": 0.0011095422650925638,
        "countScope": "exact-term"
      },
      "subtechnique-install-root-certificate-df041733": {
        "count": 201,
        "datasetShare": 0.000013127782306100696,
        "assignedShare": 0.00013508055438134786,
        "countScope": "exact-term"
      },
      "subtechnique-sip-and-trust-provider-hijacking-de65aecb": {
        "count": 237,
        "datasetShare": 0.000015479026898238135,
        "assignedShare": 0.00015927408650935046,
        "countScope": "exact-term"
      },
      "subtechnique-code-signing-policy-modification-571570d9": {
        "count": 4749,
        "datasetShare": 0.00031016834911279704,
        "assignedShare": 0.00319153011321901,
        "countScope": "exact-term"
      },
      "subtechnique-gatekeeper-bypass-4d63b820": {
        "count": 410,
        "datasetShare": 0.000026778063410454157,
        "assignedShare": 0.0002755374492355852,
        "countScope": "exact-term"
      },
      "technique-encrypted-channel-1d9900c2": {
        "count": 5329,
        "datasetShare": 0.00034804951198612246,
        "assignedShare": 0.0035813147975034963,
        "countScope": "exact-term"
      },
      "subtechnique-asymmetric-cryptography-41ee5ec7": {
        "count": 3291,
        "datasetShare": 0.0002149429431312308,
        "assignedShare": 0.0022116920620349045,
        "countScope": "exact-term"
      },
      "subtechnique-symmetric-cryptography-bf25e50d": {
        "count": 562,
        "datasetShare": 0.00003670554057725667,
        "assignedShare": 0.0003776879182204851,
        "countScope": "exact-term"
      },
      "technique-input-capture-12983960": {
        "count": 4463,
        "datasetShare": 0.0002914890170752607,
        "assignedShare": 0.0029993259413132116,
        "countScope": "label-across-paths"
      },
      "subtechnique-keylogging-8b858b2b": {
        "count": 803,
        "datasetShare": 0.000052445816874621185,
        "assignedShare": 0.0005396501749662803,
        "countScope": "label-across-paths"
      },
      "subtechnique-gui-input-capture-ae4bcf3f": {
        "count": 624,
        "datasetShare": 0.00004075490626371559,
        "assignedShare": 0.00041935455688537845,
        "countScope": "label-across-paths"
      },
      "subtechnique-credential-api-hooking-42eded59": {
        "count": 315,
        "datasetShare": 0.00002057339018120258,
        "assignedShare": 0.00021169340612002278,
        "countScope": "label-across-paths"
      },
      "subtechnique-web-portal-capture-cae8db3a": {
        "count": 2150,
        "datasetShare": 0.00014042155203043032,
        "assignedShare": 0.0014448915020890444,
        "countScope": "label-across-paths"
      },
      "technique-input-capture-0b45f177": {
        "count": 4463,
        "datasetShare": 0.0002914890170752607,
        "assignedShare": 0.0029993259413132116,
        "countScope": "label-across-paths"
      },
      "subtechnique-keylogging-bc77f43a": {
        "count": 803,
        "datasetShare": 0.000052445816874621185,
        "assignedShare": 0.0005396501749662803,
        "countScope": "label-across-paths"
      },
      "subtechnique-gui-input-capture-a1dae94f": {
        "count": 624,
        "datasetShare": 0.00004075490626371559,
        "assignedShare": 0.00041935455688537845,
        "countScope": "label-across-paths"
      },
      "subtechnique-credential-api-hooking-b1a89298": {
        "count": 315,
        "datasetShare": 0.00002057339018120258,
        "assignedShare": 0.00021169340612002278,
        "countScope": "label-across-paths"
      },
      "subtechnique-web-portal-capture-121ce073": {
        "count": 2150,
        "datasetShare": 0.00014042155203043032,
        "assignedShare": 0.0014448915020890444,
        "countScope": "label-across-paths"
      },
      "technique-exploitation-for-client-execution-85644d8c": {
        "count": 349,
        "datasetShare": 0.00002279401007377683,
        "assignedShare": 0.000234542853129803,
        "countScope": "exact-term"
      },
      "technique-lateral-tool-transfer-6002ccb2": {
        "count": 1256,
        "datasetShare": 0.00008203231132568395,
        "assignedShare": 0.0008440854542436463,
        "countScope": "exact-term"
      },
      "technique-non-application-layer-protocol-019c41a5": {
        "count": 261,
        "datasetShare": 0.000017046523292996425,
        "assignedShare": 0.00017540310792801887,
        "countScope": "exact-term"
      },
      "technique-query-registry-e8b0deba": {
        "count": 595,
        "datasetShare": 0.000038860848120049326,
        "assignedShare": 0.0003998653226711541,
        "countScope": "exact-term"
      },
      "technique-data-transfer-size-limits-6f09f71c": {
        "count": 1775,
        "datasetShare": 0.00011592942086233201,
        "assignedShare": 0.0011928755424223505,
        "countScope": "exact-term"
      },
      "technique-endpoint-denial-of-service-1e0dedc0": {
        "count": 14922,
        "datasetShare": 0.0009745908834409681,
        "assignedShare": 0.010028219067057078,
        "countScope": "exact-term"
      },
      "subtechnique-application-exhaustion-flood-e84e9d25": {
        "count": 662,
        "datasetShare": 0.000043236775555416225,
        "assignedShare": 0.0004448921741316034,
        "countScope": "exact-term"
      },
      "subtechnique-service-exhaustion-flood-46ed00dc": {
        "count": 8297,
        "datasetShare": 0.0005418965661378979,
        "assignedShare": 0.0055759371129454885,
        "countScope": "exact-term"
      },
      "subtechnique-application-or-system-exploitation-0213a922": {
        "count": 174,
        "datasetShare": 0.000011364348861997617,
        "assignedShare": 0.00011693540528534591,
        "countScope": "exact-term"
      },
      "subtechnique-os-exhaustion-flood-8833786d": {
        "count": 4930,
        "datasetShare": 0.0003219898844232658,
        "assignedShare": 0.003313169816418134,
        "countScope": "exact-term"
      },
      "technique-system-location-discovery-08b08973": {
        "count": 2432,
        "datasetShare": 0.00015883963466884027,
        "assignedShare": 0.001634407503758398,
        "countScope": "exact-term"
      },
      "subtechnique-system-language-discovery-9aa23f32": {
        "count": 1764,
        "datasetShare": 0.00011521098501473447,
        "assignedShare": 0.0011854830742721275,
        "countScope": "exact-term"
      },
      "technique-bits-jobs-2c639bcf": {
        "count": 5563,
        "datasetShare": 0.00036333260183501575,
        "assignedShare": 0.0037385727563355132,
        "countScope": "label-across-paths"
      },
      "technique-bits-jobs-e70dd281": {
        "count": 5563,
        "datasetShare": 0.00036333260183501575,
        "assignedShare": 0.0037385727563355132,
        "countScope": "label-across-paths"
      },
      "technique-impersonation-5b97d38a": {
        "count": 2157,
        "datasetShare": 0.0001408787384789015,
        "assignedShare": 0.0014495958000028226,
        "countScope": "exact-term"
      },
      "technique-data-encoding-eec67526": {
        "count": 1007,
        "datasetShare": 0.00006576953623006667,
        "assignedShare": 0.0006767468570249617,
        "countScope": "exact-term"
      },
      "subtechnique-standard-encoding-d01e710b": {
        "count": 10,
        "datasetShare": 6.53123497815955e-7,
        "assignedShare": 0.000006720425591111834,
        "countScope": "exact-term"
      },
      "subtechnique-non-standard-encoding-ad6edc29": {
        "count": 815,
        "datasetShare": 0.000053229565072000335,
        "assignedShare": 0.0005477146856756144,
        "countScope": "exact-term"
      },
      "technique-phishing-for-information-e4926b8a": {
        "count": 15758,
        "datasetShare": 0.0010291920078583819,
        "assignedShare": 0.010590046646474028,
        "countScope": "exact-term"
      },
      "subtechnique-spearphishing-voice-e46b8d5f": {
        "count": 4752,
        "datasetShare": 0.0003103642861621418,
        "assignedShare": 0.0031935462408963435,
        "countScope": "label-across-paths"
      },
      "subtechnique-spearphishing-service-39afac14": {
        "count": 9091,
        "datasetShare": 0.0005937545718644847,
        "assignedShare": 0.006109538904879769,
        "countScope": "exact-term"
      },
      "subtechnique-spearphishing-attachment-fc8b1fa7": {
        "count": 177,
        "datasetShare": 0.000011560285911342403,
        "assignedShare": 0.00011895153296267946,
        "countScope": "label-across-paths"
      },
      "subtechnique-spearphishing-link-25575c46": {
        "count": 939,
        "datasetShare": 0.00006132829644491818,
        "assignedShare": 0.0006310479630054013,
        "countScope": "label-across-paths"
      },
      "technique-resource-hijacking-1331c23e": {
        "count": 14093,
        "datasetShare": 0.0009204469454720254,
        "assignedShare": 0.009471095785553907,
        "countScope": "exact-term"
      },
      "subtechnique-compute-hijacking-f8769e8a": {
        "count": 943,
        "datasetShare": 0.00006158954584404456,
        "assignedShare": 0.0006337361332418459,
        "countScope": "exact-term"
      },
      "subtechnique-bandwidth-hijacking-cfe9c74b": {
        "count": 2248,
        "datasetShare": 0.0001468221623090267,
        "assignedShare": 0.0015107516728819403,
        "countScope": "exact-term"
      },
      "subtechnique-cloud-service-hijacking-5830bb35": {
        "count": 297,
        "datasetShare": 0.000019397767885133864,
        "assignedShare": 0.00019959664005602147,
        "countScope": "exact-term"
      },
      "subtechnique-sms-pumping-e52cf568": {
        "count": 8616,
        "datasetShare": 0.0005627312057182269,
        "assignedShare": 0.005790318689301956,
        "countScope": "exact-term"
      },
      "technique-establish-accounts-f4270122": {
        "count": 6234,
        "datasetShare": 0.00040715718853846637,
        "assignedShare": 0.004189513313499117,
        "countScope": "exact-term"
      },
      "subtechnique-cloud-accounts-9afd082e": {
        "count": 1366,
        "datasetShare": 0.00008921666980165946,
        "assignedShare": 0.0009180101357458765,
        "countScope": "label-across-paths"
      },
      "subtechnique-email-accounts-62d9fa1d": {
        "count": 2438,
        "datasetShare": 0.00015923150876752984,
        "assignedShare": 0.0016384397591130652,
        "countScope": "label-across-paths"
      },
      "subtechnique-social-media-accounts-26206b1c": {
        "count": 38843,
        "datasetShare": 0.002536927602566514,
        "assignedShare": 0.026104149123555697,
        "countScope": "label-across-paths"
      },
      "technique-obtain-capabilities-0eac3f32": {
        "count": 158750,
        "datasetShare": 0.010368335527828286,
        "assignedShare": 0.10668675625890037,
        "countScope": "exact-term"
      },
      "subtechnique-vulnerabilities-a6c4e894": {
        "count": 2273,
        "datasetShare": 0.0001484549710535666,
        "assignedShare": 0.0015275527368597199,
        "countScope": "exact-term"
      },
      "subtechnique-exploits-f1b90ca1": {
        "count": 1613,
        "datasetShare": 0.00010534882019771355,
        "assignedShare": 0.0010840046478463388,
        "countScope": "label-across-paths"
      },
      "subtechnique-artificial-intelligence-a3fc5df6": {
        "count": 147241,
        "datasetShare": 0.009616655694191904,
        "assignedShare": 0.09895221844608976,
        "countScope": "exact-term"
      },
      "subtechnique-digital-certificates-99f6b7e9": {
        "count": 2228,
        "datasetShare": 0.00014551591531339477,
        "assignedShare": 0.0014973108216997167,
        "countScope": "label-across-paths"
      },
      "subtechnique-tool-43e84de7": {
        "count": 1453,
        "datasetShare": 0.00009489884423265827,
        "assignedShare": 0.0009764778383885495,
        "countScope": "exact-term"
      },
      "subtechnique-code-signing-certificates-e397cc04": {
        "count": 4781,
        "datasetShare": 0.0003122583443058081,
        "assignedShare": 0.003213035475110568,
        "countScope": "label-across-paths"
      },
      "subtechnique-malware-6f8d9b9b": {
        "count": 2304,
        "datasetShare": 0.00015047965389679602,
        "assignedShare": 0.0015483860561921665,
        "countScope": "label-across-paths"
      },
      "technique-system-services-1a17bfc5": {
        "count": 543,
        "datasetShare": 0.00003546460593140636,
        "assignedShare": 0.0003649191095973726,
        "countScope": "exact-term"
      },
      "subtechnique-service-execution-43b968bb": {
        "count": 369,
        "datasetShare": 0.000024100257069408742,
        "assignedShare": 0.0002479837043120267,
        "countScope": "exact-term"
      },
      "subtechnique-launchctl-a5fc707f": {
        "count": 135,
        "datasetShare": 0.000008817167220515393,
        "assignedShare": 0.00009072574548000976,
        "countScope": "exact-term"
      },
      "technique-acquire-access-8ccb99e7": {
        "count": 4063,
        "datasetShare": 0.0002653640771626225,
        "assignedShare": 0.0027305089176687383,
        "countScope": "exact-term"
      },
      "technique-data-from-information-repositories-d11d98f7": {
        "count": 42328,
        "datasetShare": 0.0027645411415553743,
        "assignedShare": 0.02844621744205817,
        "countScope": "exact-term"
      },
      "subtechnique-code-repositories-d9cb58a0": {
        "count": 2123,
        "datasetShare": 0.00013865811858632725,
        "assignedShare": 0.0014267463529930424,
        "countScope": "label-across-paths"
      },
      "subtechnique-messaging-applications-6274feb0": {
        "count": 16897,
        "datasetShare": 0.0011035827742596192,
        "assignedShare": 0.011355503121301666,
        "countScope": "exact-term"
      },
      "subtechnique-customer-relationship-management-software-7efb83bd": {
        "count": 17343,
        "datasetShare": 0.0011327120822622108,
        "assignedShare": 0.011655234102665253,
        "countScope": "exact-term"
      },
      "subtechnique-sharepoint-152be8c6": {
        "count": 1779,
        "datasetShare": 0.00011619067026145839,
        "assignedShare": 0.0011955637126587952,
        "countScope": "exact-term"
      },
      "subtechnique-confluence-2276c030": {
        "count": 2235,
        "datasetShare": 0.00014597310176186595,
        "assignedShare": 0.0015020151196134949,
        "countScope": "exact-term"
      },
      "technique-hardware-additions-d52beb17": {
        "count": 706,
        "datasetShare": 0.00004611051894580642,
        "assignedShare": 0.00047446204673249546,
        "countScope": "exact-term"
      },
      "technique-server-software-component-0dcfa055": {
        "count": 9737,
        "datasetShare": 0.0006359463498233954,
        "assignedShare": 0.0065436783980655925,
        "countScope": "exact-term"
      },
      "subtechnique-transport-agent-c1d48bf1": {
        "count": 8247,
        "datasetShare": 0.0005386309486488181,
        "assignedShare": 0.005542334984989929,
        "countScope": "exact-term"
      },
      "subtechnique-iis-components-dea40b36": {
        "count": 366,
        "datasetShare": 0.000023904320020063953,
        "assignedShare": 0.0002459675766346931,
        "countScope": "exact-term"
      },
      "subtechnique-web-shell-32d6d2c6": {
        "count": 285,
        "datasetShare": 0.000018614019687754717,
        "assignedShare": 0.00019153212934668726,
        "countScope": "exact-term"
      },
      "subtechnique-terminal-services-dll-dfae5393": {
        "count": 522,
        "datasetShare": 0.00003409304658599285,
        "assignedShare": 0.00035080621585603774,
        "countScope": "exact-term"
      },
      "subtechnique-sql-stored-procedures-4354d301": {
        "count": 43,
        "datasetShare": 0.0000028084310406086067,
        "assignedShare": 0.000028897830041780884,
        "countScope": "exact-term"
      },
      "technique-data-destruction-8e3db81c": {
        "count": 5506,
        "datasetShare": 0.00035960979789746483,
        "assignedShare": 0.003700266330466176,
        "countScope": "exact-term"
      },
      "subtechnique-lifecycle-triggered-deletion-238f0e2f": {
        "count": 909,
        "datasetShare": 0.00005936892595147031,
        "assignedShare": 0.0006108866862320657,
        "countScope": "exact-term"
      },
      "technique-transfer-data-to-cloud-account-0a3157c4": {
        "count": 546,
        "datasetShare": 0.00003566054298075114,
        "assignedShare": 0.00036693523727470616,
        "countScope": "exact-term"
      },
      "technique-drive-by-compromise-64213ae2": {
        "count": 181,
        "datasetShare": 0.000011821535310468786,
        "assignedShare": 0.0001216397031991242,
        "countScope": "exact-term"
      },
      "technique-network-denial-of-service-b5b71c02": {
        "count": 11499,
        "datasetShare": 0.0007510267101385667,
        "assignedShare": 0.0077278173872194975,
        "countScope": "exact-term"
      },
      "subtechnique-reflection-amplification-009c2467": {
        "count": 3173,
        "datasetShare": 0.00020723608585700252,
        "assignedShare": 0.002132391040059785,
        "countScope": "exact-term"
      },
      "subtechnique-direct-network-flood-539cd191": {
        "count": 5073,
        "datasetShare": 0.00033132955044203397,
        "assignedShare": 0.0034092719023710335,
        "countScope": "exact-term"
      },
      "technique-cloud-administration-command-070e7c7c": {
        "count": 1815,
        "datasetShare": 0.00011854191485359584,
        "assignedShare": 0.001219757244786798,
        "countScope": "exact-term"
      },
      "technique-template-injection-66b1ee78": {
        "count": 60,
        "datasetShare": 0.00000391874098689573,
        "assignedShare": 0.000040322553546671,
        "countScope": "exact-term"
      },
      "technique-access-token-manipulation-75b97fad": {
        "count": 2819,
        "datasetShare": 0.0001841155140343177,
        "assignedShare": 0.001894487974134426,
        "countScope": "label-across-paths"
      },
      "subtechnique-token-impersonation-theft-c78fc679": {
        "count": 1163,
        "datasetShare": 0.00007595826279599557,
        "assignedShare": 0.0007815854962463063,
        "countScope": "label-across-paths"
      },
      "subtechnique-parent-pid-spoofing-a3f9021f": {
        "count": 186,
        "datasetShare": 0.000012148097059376764,
        "assignedShare": 0.0001249999159946801,
        "countScope": "label-across-paths"
      },
      "subtechnique-sid-history-injection-fcc14d6c": {
        "count": 564,
        "datasetShare": 0.00003683616527681986,
        "assignedShare": 0.0003790320033387074,
        "countScope": "label-across-paths"
      },
      "subtechnique-create-process-with-token-32c7960c": {
        "count": 279,
        "datasetShare": 0.000018222145589065146,
        "assignedShare": 0.00018749987399202016,
        "countScope": "label-across-paths"
      },
      "subtechnique-make-and-impersonate-token-ca277e2f": {
        "count": 67,
        "datasetShare": 0.000004375927435366899,
        "assignedShare": 0.000045026851460449285,
        "countScope": "label-across-paths"
      },
      "technique-access-token-manipulation-cee4caaf": {
        "count": 2819,
        "datasetShare": 0.0001841155140343177,
        "assignedShare": 0.001894487974134426,
        "countScope": "label-across-paths"
      },
      "subtechnique-token-impersonation-theft-267c3ead": {
        "count": 1163,
        "datasetShare": 0.00007595826279599557,
        "assignedShare": 0.0007815854962463063,
        "countScope": "label-across-paths"
      },
      "subtechnique-parent-pid-spoofing-dc23c338": {
        "count": 186,
        "datasetShare": 0.000012148097059376764,
        "assignedShare": 0.0001249999159946801,
        "countScope": "label-across-paths"
      },
      "subtechnique-sid-history-injection-a6c75f2d": {
        "count": 564,
        "datasetShare": 0.00003683616527681986,
        "assignedShare": 0.0003790320033387074,
        "countScope": "label-across-paths"
      },
      "subtechnique-create-process-with-token-11eff85b": {
        "count": 279,
        "datasetShare": 0.000018222145589065146,
        "assignedShare": 0.00018749987399202016,
        "countScope": "label-across-paths"
      },
      "subtechnique-make-and-impersonate-token-f4beb076": {
        "count": 67,
        "datasetShare": 0.000004375927435366899,
        "assignedShare": 0.000045026851460449285,
        "countScope": "label-across-paths"
      },
      "technique-multi-factor-authentication-interception-147d87aa": {
        "count": 499,
        "datasetShare": 0.000032590862541016155,
        "assignedShare": 0.0003353492369964805,
        "countScope": "exact-term"
      },
      "technique-create-account-9f77e746": {
        "count": 659,
        "datasetShare": 0.000043040838506071436,
        "assignedShare": 0.0004428760464542699,
        "countScope": "exact-term"
      },
      "subtechnique-cloud-account-788540dd": {
        "count": 326,
        "datasetShare": 0.000021291826028800133,
        "assignedShare": 0.0002190858742702458,
        "countScope": "label-across-paths"
      },
      "subtechnique-local-account-daf4bb91": {
        "count": 238,
        "datasetShare": 0.00001554433924801973,
        "assignedShare": 0.00015994612906846165,
        "countScope": "label-across-paths"
      },
      "subtechnique-domain-account-c546a592": {
        "count": 25,
        "datasetShare": 0.0000016328087445398876,
        "assignedShare": 0.000016801063977779584,
        "countScope": "label-across-paths"
      },
      "technique-cloud-service-discovery-3f4c589f": {
        "count": 921,
        "datasetShare": 0.00006015267414884946,
        "assignedShare": 0.0006189511969413999,
        "countScope": "exact-term"
      },
      "technique-remote-system-discovery-1f9c706c": {
        "count": 212,
        "datasetShare": 0.000013846218153698247,
        "assignedShare": 0.00014247302253157088,
        "countScope": "exact-term"
      },
      "technique-network-service-discovery-e54c331a": {
        "count": 2953,
        "datasetShare": 0.00019286736890505152,
        "assignedShare": 0.0019845416770553244,
        "countScope": "exact-term"
      },
      "technique-software-discovery-294fb901": {
        "count": 5028,
        "datasetShare": 0.0003283904947018622,
        "assignedShare": 0.00337902998721103,
        "countScope": "exact-term"
      },
      "subtechnique-security-software-discovery-c167ca80": {
        "count": 3858,
        "datasetShare": 0.00025197504545739543,
        "assignedShare": 0.0025927401930509455,
        "countScope": "exact-term"
      },
      "technique-cloud-service-dashboard-8d64fd58": {
        "count": 3232,
        "datasetShare": 0.00021108951449411666,
        "assignedShare": 0.002172041551047345,
        "countScope": "exact-term"
      },
      "technique-debugger-evasion-2c4f5aee": {
        "count": 400,
        "datasetShare": 0.0000261249399126382,
        "assignedShare": 0.00026881702364447334,
        "countScope": "label-across-paths"
      },
      "technique-debugger-evasion-ce401e35": {
        "count": 400,
        "datasetShare": 0.0000261249399126382,
        "assignedShare": 0.00026881702364447334,
        "countScope": "label-across-paths"
      },
      "technique-exfiltration-over-physical-medium-dc304148": {
        "count": 4068,
        "datasetShare": 0.0002656906389115305,
        "assignedShare": 0.002733869130464294,
        "countScope": "exact-term"
      },
      "subtechnique-exfiltration-over-usb-ec7aa357": {
        "count": 2815,
        "datasetShare": 0.00018385426463519134,
        "assignedShare": 0.0018917998038979812,
        "countScope": "exact-term"
      },
      "technique-ingress-tool-transfer-e788c3a5": {
        "count": 4561,
        "datasetShare": 0.0002978896273538571,
        "assignedShare": 0.0030651861121061075,
        "countScope": "exact-term"
      },
      "technique-serverless-execution-a4e48b75": {
        "count": 875,
        "datasetShare": 0.000057148306058896064,
        "assignedShare": 0.0005880372392222854,
        "countScope": "exact-term"
      },
      "technique-power-settings-434a7ef4": {
        "count": 12457,
        "datasetShare": 0.0008135959412293352,
        "assignedShare": 0.008371634158848012,
        "countScope": "exact-term"
      },
      "technique-hide-infrastructure-5724cf67": {
        "count": 1370,
        "datasetShare": 0.00008947791920078584,
        "assignedShare": 0.0009206983059823213,
        "countScope": "exact-term"
      },
      "technique-domain-or-tenant-policy-modification-35bc7061": {
        "count": 8625,
        "datasetShare": 0.0005633190168662612,
        "assignedShare": 0.005796367072333957,
        "countScope": "label-across-paths"
      },
      "subtechnique-trust-modification-28998903": {
        "count": 3226,
        "datasetShare": 0.0002106976403954271,
        "assignedShare": 0.0021680092956926776,
        "countScope": "label-across-paths"
      },
      "subtechnique-group-policy-modification-c7decf31": {
        "count": 2056,
        "datasetShare": 0.00013428219115096035,
        "assignedShare": 0.001381719501532593,
        "countScope": "label-across-paths"
      },
      "technique-domain-or-tenant-policy-modification-585164d7": {
        "count": 8625,
        "datasetShare": 0.0005633190168662612,
        "assignedShare": 0.005796367072333957,
        "countScope": "label-across-paths"
      },
      "subtechnique-trust-modification-7e766c78": {
        "count": 3226,
        "datasetShare": 0.0002106976403954271,
        "assignedShare": 0.0021680092956926776,
        "countScope": "label-across-paths"
      },
      "subtechnique-group-policy-modification-a365c397": {
        "count": 2056,
        "datasetShare": 0.00013428219115096035,
        "assignedShare": 0.001381719501532593,
        "countScope": "label-across-paths"
      },
      "technique-xsl-script-processing-604f2c66": {
        "count": 313,
        "datasetShare": 0.00002044276548163939,
        "assignedShare": 0.0002103493210018004,
        "countScope": "exact-term"
      },
      "technique-develop-capabilities-d6c711e3": {
        "count": 11640,
        "datasetShare": 0.0007602357514577716,
        "assignedShare": 0.007822575388054174,
        "countScope": "exact-term"
      },
      "subtechnique-code-signing-certificates-a160076b": {
        "count": 4781,
        "datasetShare": 0.0003122583443058081,
        "assignedShare": 0.003213035475110568,
        "countScope": "label-across-paths"
      },
      "subtechnique-digital-certificates-e89af41c": {
        "count": 2228,
        "datasetShare": 0.00014551591531339477,
        "assignedShare": 0.0014973108216997167,
        "countScope": "label-across-paths"
      },
      "subtechnique-exploits-e4705241": {
        "count": 1613,
        "datasetShare": 0.00010534882019771355,
        "assignedShare": 0.0010840046478463388,
        "countScope": "label-across-paths"
      },
      "subtechnique-malware-d2c8e50b": {
        "count": 2304,
        "datasetShare": 0.00015047965389679602,
        "assignedShare": 0.0015483860561921665,
        "countScope": "label-across-paths"
      },
      "technique-fallback-channels-3886ad61": {
        "count": 3898,
        "datasetShare": 0.00025458753944865927,
        "assignedShare": 0.002619621895415393,
        "countScope": "exact-term"
      },
      "technique-system-time-discovery-636625d9": {
        "count": 1071,
        "datasetShare": 0.00006994952661608878,
        "assignedShare": 0.0007197575808080774,
        "countScope": "exact-term"
      },
      "technique-modify-authentication-process-8a522cc2": {
        "count": 19305,
        "datasetShare": 0.0012608549125337012,
        "assignedShare": 0.012973781603641396,
        "countScope": "label-across-paths"
      },
      "subtechnique-network-device-authentication-2dc1879d": {
        "count": 916,
        "datasetShare": 0.00005982611239994148,
        "assignedShare": 0.000615590984145844,
        "countScope": "label-across-paths"
      },
      "subtechnique-domain-controller-authentication-2422e648": {
        "count": 292,
        "datasetShare": 0.000019071206136225887,
        "assignedShare": 0.00019623642726046556,
        "countScope": "label-across-paths"
      },
      "subtechnique-conditional-access-policies-20c90326": {
        "count": 6358,
        "datasetShare": 0.0004152559199113842,
        "assignedShare": 0.004272846590828904,
        "countScope": "label-across-paths"
      },
      "subtechnique-network-provider-dll-8c507f92": {
        "count": 1174,
        "datasetShare": 0.00007667669864359311,
        "assignedShare": 0.0007889779643965293,
        "countScope": "label-across-paths"
      },
      "subtechnique-password-filter-dll-13db8b61": {
        "count": 74,
        "datasetShare": 0.000004833113883838067,
        "assignedShare": 0.00004973114937422757,
        "countScope": "label-across-paths"
      },
      "subtechnique-multi-factor-authentication-0cfd8002": {
        "count": 3727,
        "datasetShare": 0.00024341912763600643,
        "assignedShare": 0.0025047026178073805,
        "countScope": "label-across-paths"
      },
      "subtechnique-hybrid-identity-7b948aac": {
        "count": 3286,
        "datasetShare": 0.00021461638138232282,
        "assignedShare": 0.0022083318492393486,
        "countScope": "label-across-paths"
      },
      "subtechnique-reversible-encryption-7538f686": {
        "count": 1979,
        "datasetShare": 0.0001292531402177775,
        "assignedShare": 0.0013299722244810319,
        "countScope": "label-across-paths"
      },
      "subtechnique-pluggable-authentication-modules-88a2309f": {
        "count": 697,
        "datasetShare": 0.00004552270779777206,
        "assignedShare": 0.00046841366370049483,
        "countScope": "label-across-paths"
      },
      "technique-modify-authentication-process-c874c873": {
        "count": 19305,
        "datasetShare": 0.0012608549125337012,
        "assignedShare": 0.012973781603641396,
        "countScope": "label-across-paths"
      },
      "subtechnique-network-device-authentication-fc4c5421": {
        "count": 916,
        "datasetShare": 0.00005982611239994148,
        "assignedShare": 0.000615590984145844,
        "countScope": "label-across-paths"
      },
      "subtechnique-domain-controller-authentication-d25fa69b": {
        "count": 292,
        "datasetShare": 0.000019071206136225887,
        "assignedShare": 0.00019623642726046556,
        "countScope": "label-across-paths"
      },
      "subtechnique-conditional-access-policies-69b8928c": {
        "count": 6358,
        "datasetShare": 0.0004152559199113842,
        "assignedShare": 0.004272846590828904,
        "countScope": "label-across-paths"
      },
      "subtechnique-network-provider-dll-7f1897b5": {
        "count": 1174,
        "datasetShare": 0.00007667669864359311,
        "assignedShare": 0.0007889779643965293,
        "countScope": "label-across-paths"
      },
      "subtechnique-password-filter-dll-e0f0b6c3": {
        "count": 74,
        "datasetShare": 0.000004833113883838067,
        "assignedShare": 0.00004973114937422757,
        "countScope": "label-across-paths"
      },
      "subtechnique-multi-factor-authentication-4d8d0b33": {
        "count": 3727,
        "datasetShare": 0.00024341912763600643,
        "assignedShare": 0.0025047026178073805,
        "countScope": "label-across-paths"
      },
      "subtechnique-hybrid-identity-e7080cc4": {
        "count": 3286,
        "datasetShare": 0.00021461638138232282,
        "assignedShare": 0.0022083318492393486,
        "countScope": "label-across-paths"
      },
      "subtechnique-reversible-encryption-1491511d": {
        "count": 1979,
        "datasetShare": 0.0001292531402177775,
        "assignedShare": 0.0013299722244810319,
        "countScope": "label-across-paths"
      },
      "subtechnique-pluggable-authentication-modules-5c13d74a": {
        "count": 697,
        "datasetShare": 0.00004552270779777206,
        "assignedShare": 0.00046841366370049483,
        "countScope": "label-across-paths"
      },
      "technique-modify-authentication-process-b2865f0f": {
        "count": 19305,
        "datasetShare": 0.0012608549125337012,
        "assignedShare": 0.012973781603641396,
        "countScope": "label-across-paths"
      },
      "subtechnique-network-device-authentication-2fc0fb9b": {
        "count": 916,
        "datasetShare": 0.00005982611239994148,
        "assignedShare": 0.000615590984145844,
        "countScope": "label-across-paths"
      },
      "subtechnique-domain-controller-authentication-9a0a210c": {
        "count": 292,
        "datasetShare": 0.000019071206136225887,
        "assignedShare": 0.00019623642726046556,
        "countScope": "label-across-paths"
      },
      "subtechnique-conditional-access-policies-65069418": {
        "count": 6358,
        "datasetShare": 0.0004152559199113842,
        "assignedShare": 0.004272846590828904,
        "countScope": "label-across-paths"
      },
      "subtechnique-network-provider-dll-48163a08": {
        "count": 1174,
        "datasetShare": 0.00007667669864359311,
        "assignedShare": 0.0007889779643965293,
        "countScope": "label-across-paths"
      },
      "subtechnique-password-filter-dll-b1ac5fb2": {
        "count": 74,
        "datasetShare": 0.000004833113883838067,
        "assignedShare": 0.00004973114937422757,
        "countScope": "label-across-paths"
      },
      "subtechnique-multi-factor-authentication-15bc9610": {
        "count": 3727,
        "datasetShare": 0.00024341912763600643,
        "assignedShare": 0.0025047026178073805,
        "countScope": "label-across-paths"
      },
      "subtechnique-hybrid-identity-f053b685": {
        "count": 3286,
        "datasetShare": 0.00021461638138232282,
        "assignedShare": 0.0022083318492393486,
        "countScope": "label-across-paths"
      },
      "subtechnique-reversible-encryption-8dc9fd09": {
        "count": 1979,
        "datasetShare": 0.0001292531402177775,
        "assignedShare": 0.0013299722244810319,
        "countScope": "label-across-paths"
      },
      "subtechnique-pluggable-authentication-modules-5edbb077": {
        "count": 697,
        "datasetShare": 0.00004552270779777206,
        "assignedShare": 0.00046841366370049483,
        "countScope": "label-across-paths"
      },
      "technique-firmware-corruption-fe88161f": {
        "count": 1324,
        "datasetShare": 0.00008647355111083245,
        "assignedShare": 0.0008897843482632068,
        "countScope": "exact-term"
      },
      "technique-inhibit-system-recovery-ac92307c": {
        "count": 1416,
        "datasetShare": 0.00009248228729073923,
        "assignedShare": 0.0009516122637014357,
        "countScope": "exact-term"
      },
      "technique-system-script-proxy-execution-d2cebc43": {
        "count": 920,
        "datasetShare": 0.00006008736179906786,
        "assignedShare": 0.0006182791543822888,
        "countScope": "exact-term"
      },
      "subtechnique-pubprn-c65184d4": {
        "count": 569,
        "datasetShare": 0.00003716272702572784,
        "assignedShare": 0.0003823922161342633,
        "countScope": "exact-term"
      },
      "subtechnique-syncappvpublishingserver-a6f7a423": {
        "count": 307,
        "datasetShare": 0.00002005089138294982,
        "assignedShare": 0.0002063170656471333,
        "countScope": "exact-term"
      },
      "technique-exploitation-for-defense-evasion-117d065b": {
        "count": 5382,
        "datasetShare": 0.000351511066524547,
        "assignedShare": 0.003616933053136389,
        "countScope": "exact-term"
      },
      "technique-trusted-developer-utilities-proxy-execution-bbcfa948": {
        "count": 2206,
        "datasetShare": 0.00014407904361819968,
        "assignedShare": 0.0014825258853992706,
        "countScope": "exact-term"
      },
      "subtechnique-msbuild-bb7cd535": {
        "count": 1088,
        "datasetShare": 0.0000710598365623759,
        "assignedShare": 0.0007311823043129675,
        "countScope": "exact-term"
      },
      "subtechnique-clickonce-ed15fc77": {
        "count": 302,
        "datasetShare": 0.000019724329634041843,
        "assignedShare": 0.00020295685285157738,
        "countScope": "exact-term"
      },
      "technique-system-shutdown-reboot-80b70aef": {
        "count": 6321,
        "datasetShare": 0.00041283936296946516,
        "assignedShare": 0.00424798101614179,
        "countScope": "exact-term"
      }
    }
  },
  "caseStudy": {
    "schemaVersion": 3,
    "dataset": "World V1.2",
    "from": "2020-12-13",
    "to": "2021-04-30",
    "cohortRule": "English canonical events explicitly naming SolarWinds, SUNBURST or SUNSPOT malware.",
    "memoryRule": "The attention chart pools the current day and 13 preceding days. No future observations are used.",
    "markers": [
      {
        "date": "2020-12-13",
        "label": "Public disclosure"
      },
      {
        "date": "2021-01-05",
        "label": "US attribution"
      },
      {
        "date": "2021-04-15",
        "label": "US sanctions"
      }
    ],
    "phases": {
      "disclosure": {
        "from": "2020-12-13",
        "to": "2021-01-15",
        "events": 46,
        "assigned": 46,
        "perMillion": 1135.550124663655,
        "tacticShares": {
          "Initial Access": 0.17391304347826086,
          "Reconnaissance": 0.2608695652173913,
          "Impact": 0.021739130434782608,
          "Resource Development": 0.13043478260869565,
          "Discovery": 0.10869565217391304,
          "Collection": 0.10869565217391304,
          "Defense Evasion": 0.10869565217391304,
          "Lateral Movement": 0.043478260869565216,
          "Persistence": 0.021739130434782608,
          "Execution": 0.021739130434782608
        },
        "techniqueShares": {
          "Supply Chain Compromise": 0.17391304347826086,
          "Search Closed Sources": 0.13043478260869565,
          "Resource Hijacking": 0.021739130434782608,
          "Gather Victim Network Information": 0.06521739130434782,
          "Obtain Capabilities": 0.043478260869565216,
          "Software Discovery": 0.06521739130434782,
          "Email Collection": 0.043478260869565216,
          "Impair Defenses": 0.043478260869565216,
          "Remote Services": 0.043478260869565216,
          "Indicator Removal": 0.043478260869565216,
          "Server Software Component": 0.021739130434782608,
          "Compromise Accounts": 0.043478260869565216,
          "Valid Accounts": 0.021739130434782608,
          "System Information Discovery": 0.021739130434782608,
          "Search Open Technical Databases": 0.021739130434782608,
          "Search Open Websites/Domains": 0.043478260869565216,
          "System Time Discovery": 0.021739130434782608,
          "Data from Information Repositories": 0.06521739130434782,
          "Stage Capabilities": 0.021739130434782608,
          "Software Deployment Tools": 0.021739130434782608,
          "Develop Capabilities": 0.021739130434782608
        }
      },
      "investigation": {
        "from": "2021-01-16",
        "to": "2021-04-30",
        "events": 55,
        "assigned": 50,
        "perMillion": 368.0234464392059,
        "tacticShares": {
          "Resource Development": 0.22,
          "Initial Access": 0.26,
          "Reconnaissance": 0.18,
          "Defense Evasion": 0.02,
          "Discovery": 0.06,
          "Execution": 0.06,
          "Collection": 0.06,
          "Credential Access": 0.02,
          "Lateral Movement": 0.06,
          "Persistence": 0.04,
          "Privilege Escalation": 0.02
        },
        "techniqueShares": {
          "Establish Accounts": 0.02,
          "Supply Chain Compromise": 0.24,
          "Develop Capabilities": 0.06,
          "Gather Victim Network Information": 0.1,
          "Obtain Capabilities": 0.04,
          "Search Closed Sources": 0.04,
          "Execution Guardrails": 0.02,
          "Software Discovery": 0.06,
          "System Services": 0.06,
          "Data from Information Repositories": 0.04,
          "Gather Victim Org Information": 0.02,
          "Compromise Accounts": 0.1,
          "Search Open Technical Databases": 0.02,
          "Brute Force": 0.02,
          "Exploitation of Remote Services": 0.02,
          "Server Software Component": 0.02,
          "Remote Services": 0.04,
          "Email Collection": 0.02,
          "Domain or Tenant Policy Modification": 0.02,
          "Phishing": 0.02,
          "Modify Authentication Process": 0.02
        }
      }
    },
    "observations": [
      {
        "date": "2020-12-13",
        "englishWorldEvents": 538,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2020-12-14",
        "englishWorldEvents": 1472,
        "events": 2,
        "tactics": {
          "Initial Access": 1,
          "Reconnaissance": 1
        },
        "techniques": {
          "Supply Chain Compromise": 1,
          "Search Closed Sources": 1
        }
      },
      {
        "date": "2020-12-15",
        "englishWorldEvents": 1760,
        "events": 1,
        "tactics": {
          "Impact": 1
        },
        "techniques": {
          "Resource Hijacking": 1
        }
      },
      {
        "date": "2020-12-16",
        "englishWorldEvents": 1718,
        "events": 4,
        "tactics": {
          "Reconnaissance": 2,
          "Resource Development": 1,
          "Discovery": 1
        },
        "techniques": {
          "Search Closed Sources": 1,
          "Gather Victim Network Information": 1,
          "Obtain Capabilities": 1,
          "Software Discovery": 1
        }
      },
      {
        "date": "2020-12-17",
        "englishWorldEvents": 1701,
        "events": 4,
        "tactics": {
          "Initial Access": 1,
          "Collection": 1,
          "Defense Evasion": 1,
          "Discovery": 1
        },
        "techniques": {
          "Supply Chain Compromise": 1,
          "Email Collection": 1,
          "Impair Defenses": 1,
          "Software Discovery": 1
        }
      },
      {
        "date": "2020-12-18",
        "englishWorldEvents": 1358,
        "events": 3,
        "tactics": {
          "Lateral Movement": 1,
          "Initial Access": 1,
          "Defense Evasion": 1
        },
        "techniques": {
          "Remote Services": 1,
          "Supply Chain Compromise": 1,
          "Indicator Removal": 1
        }
      },
      {
        "date": "2020-12-19",
        "englishWorldEvents": 588,
        "events": 2,
        "tactics": {
          "Initial Access": 1,
          "Persistence": 1
        },
        "techniques": {
          "Supply Chain Compromise": 1,
          "Server Software Component": 1
        }
      },
      {
        "date": "2020-12-20",
        "englishWorldEvents": 571,
        "events": 2,
        "tactics": {
          "Lateral Movement": 1,
          "Initial Access": 1
        },
        "techniques": {
          "Remote Services": 1,
          "Supply Chain Compromise": 1
        }
      },
      {
        "date": "2020-12-21",
        "englishWorldEvents": 1371,
        "events": 3,
        "tactics": {
          "Defense Evasion": 1,
          "Reconnaissance": 1,
          "Resource Development": 1
        },
        "techniques": {
          "Impair Defenses": 1,
          "Gather Victim Network Information": 1,
          "Compromise Accounts": 1
        }
      },
      {
        "date": "2020-12-22",
        "englishWorldEvents": 1454,
        "events": 1,
        "tactics": {
          "Reconnaissance": 1
        },
        "techniques": {
          "Search Closed Sources": 1
        }
      },
      {
        "date": "2020-12-23",
        "englishWorldEvents": 1377,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2020-12-24",
        "englishWorldEvents": 859,
        "events": 2,
        "tactics": {
          "Reconnaissance": 1,
          "Defense Evasion": 1
        },
        "techniques": {
          "Gather Victim Network Information": 1,
          "Valid Accounts": 1
        }
      },
      {
        "date": "2020-12-25",
        "englishWorldEvents": 415,
        "events": 1,
        "tactics": {
          "Defense Evasion": 1
        },
        "techniques": {
          "Indicator Removal": 1
        }
      },
      {
        "date": "2020-12-26",
        "englishWorldEvents": 429,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2020-12-27",
        "englishWorldEvents": 465,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2020-12-28",
        "englishWorldEvents": 1037,
        "events": 1,
        "tactics": {
          "Initial Access": 1
        },
        "techniques": {
          "Supply Chain Compromise": 1
        }
      },
      {
        "date": "2020-12-29",
        "englishWorldEvents": 1090,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2020-12-30",
        "englishWorldEvents": 1153,
        "events": 2,
        "tactics": {
          "Discovery": 1,
          "Reconnaissance": 1
        },
        "techniques": {
          "System Information Discovery": 1,
          "Search Open Technical Databases": 1
        }
      },
      {
        "date": "2020-12-31",
        "englishWorldEvents": 957,
        "events": 2,
        "tactics": {
          "Reconnaissance": 1,
          "Discovery": 1
        },
        "techniques": {
          "Search Open Websites/Domains": 1,
          "System Time Discovery": 1
        }
      },
      {
        "date": "2021-01-01",
        "englishWorldEvents": 586,
        "events": 1,
        "tactics": {
          "Collection": 1
        },
        "techniques": {
          "Data from Information Repositories": 1
        }
      },
      {
        "date": "2021-01-02",
        "englishWorldEvents": 501,
        "events": 1,
        "tactics": {
          "Collection": 1
        },
        "techniques": {
          "Data from Information Repositories": 1
        }
      },
      {
        "date": "2021-01-03",
        "englishWorldEvents": 524,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-01-04",
        "englishWorldEvents": 1485,
        "events": 2,
        "tactics": {
          "Collection": 1,
          "Reconnaissance": 1
        },
        "techniques": {
          "Data from Information Repositories": 1,
          "Search Open Websites/Domains": 1
        }
      },
      {
        "date": "2021-01-05",
        "englishWorldEvents": 1622,
        "events": 1,
        "tactics": {
          "Reconnaissance": 1
        },
        "techniques": {
          "Search Closed Sources": 1
        }
      },
      {
        "date": "2021-01-06",
        "englishWorldEvents": 1604,
        "events": 3,
        "tactics": {
          "Reconnaissance": 1,
          "Resource Development": 1,
          "Initial Access": 1
        },
        "techniques": {
          "Search Closed Sources": 1,
          "Compromise Accounts": 1,
          "Supply Chain Compromise": 1
        }
      },
      {
        "date": "2021-01-07",
        "englishWorldEvents": 1661,
        "events": 1,
        "tactics": {
          "Collection": 1
        },
        "techniques": {
          "Email Collection": 1
        }
      },
      {
        "date": "2021-01-08",
        "englishWorldEvents": 1481,
        "events": 1,
        "tactics": {
          "Resource Development": 1
        },
        "techniques": {
          "Stage Capabilities": 1
        }
      },
      {
        "date": "2021-01-09",
        "englishWorldEvents": 636,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-01-10",
        "englishWorldEvents": 611,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-01-11",
        "englishWorldEvents": 1839,
        "events": 2,
        "tactics": {
          "Resource Development": 1,
          "Execution": 1
        },
        "techniques": {
          "Obtain Capabilities": 1,
          "Software Deployment Tools": 1
        }
      },
      {
        "date": "2021-01-12",
        "englishWorldEvents": 2066,
        "events": 3,
        "tactics": {
          "Discovery": 1,
          "Resource Development": 1,
          "Initial Access": 1
        },
        "techniques": {
          "Software Discovery": 1,
          "Develop Capabilities": 1,
          "Supply Chain Compromise": 1
        }
      },
      {
        "date": "2021-01-13",
        "englishWorldEvents": 1983,
        "events": 1,
        "tactics": {
          "Reconnaissance": 1
        },
        "techniques": {
          "Search Closed Sources": 1
        }
      },
      {
        "date": "2021-01-14",
        "englishWorldEvents": 1976,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-01-15",
        "englishWorldEvents": 1621,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-01-16",
        "englishWorldEvents": 654,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-01-17",
        "englishWorldEvents": 601,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-01-18",
        "englishWorldEvents": 1343,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-01-19",
        "englishWorldEvents": 1939,
        "events": 2,
        "tactics": {
          "Resource Development": 1,
          "Initial Access": 1
        },
        "techniques": {
          "Establish Accounts": 1,
          "Supply Chain Compromise": 1
        }
      },
      {
        "date": "2021-01-20",
        "englishWorldEvents": 1707,
        "events": 1,
        "tactics": {
          "Resource Development": 1
        },
        "techniques": {
          "Develop Capabilities": 1
        }
      },
      {
        "date": "2021-01-21",
        "englishWorldEvents": 1780,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-01-22",
        "englishWorldEvents": 1505,
        "events": 1,
        "tactics": {
          "Resource Development": 1
        },
        "techniques": {
          "Develop Capabilities": 1
        }
      },
      {
        "date": "2021-01-23",
        "englishWorldEvents": 682,
        "events": 1,
        "tactics": {
          "Reconnaissance": 1
        },
        "techniques": {
          "Gather Victim Network Information": 1
        }
      },
      {
        "date": "2021-01-24",
        "englishWorldEvents": 575,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-01-25",
        "englishWorldEvents": 1693,
        "events": 1,
        "tactics": {
          "Initial Access": 1
        },
        "techniques": {
          "Supply Chain Compromise": 1
        }
      },
      {
        "date": "2021-01-26",
        "englishWorldEvents": 1756,
        "events": 1,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-01-27",
        "englishWorldEvents": 1986,
        "events": 1,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-01-28",
        "englishWorldEvents": 2050,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-01-29",
        "englishWorldEvents": 1590,
        "events": 2,
        "tactics": {
          "Initial Access": 1
        },
        "techniques": {
          "Supply Chain Compromise": 1
        }
      },
      {
        "date": "2021-01-30",
        "englishWorldEvents": 694,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-01-31",
        "englishWorldEvents": 582,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-02-01",
        "englishWorldEvents": 1644,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-02-02",
        "englishWorldEvents": 1873,
        "events": 1,
        "tactics": {
          "Resource Development": 1
        },
        "techniques": {
          "Develop Capabilities": 1
        }
      },
      {
        "date": "2021-02-03",
        "englishWorldEvents": 1823,
        "events": 2,
        "tactics": {
          "Initial Access": 1,
          "Resource Development": 1
        },
        "techniques": {
          "Supply Chain Compromise": 1,
          "Obtain Capabilities": 1
        }
      },
      {
        "date": "2021-02-04",
        "englishWorldEvents": 1920,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-02-05",
        "englishWorldEvents": 1547,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-02-06",
        "englishWorldEvents": 629,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-02-07",
        "englishWorldEvents": 552,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-02-08",
        "englishWorldEvents": 1748,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-02-09",
        "englishWorldEvents": 1903,
        "events": 1,
        "tactics": {
          "Reconnaissance": 1
        },
        "techniques": {
          "Gather Victim Network Information": 1
        }
      },
      {
        "date": "2021-02-10",
        "englishWorldEvents": 1775,
        "events": 2,
        "tactics": {
          "Resource Development": 1,
          "Reconnaissance": 1
        },
        "techniques": {
          "Obtain Capabilities": 1,
          "Search Closed Sources": 1
        }
      },
      {
        "date": "2021-02-11",
        "englishWorldEvents": 1764,
        "events": 1,
        "tactics": {
          "Reconnaissance": 1
        },
        "techniques": {
          "Gather Victim Network Information": 1
        }
      },
      {
        "date": "2021-02-12",
        "englishWorldEvents": 1453,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-02-13",
        "englishWorldEvents": 613,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-02-14",
        "englishWorldEvents": 539,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-02-15",
        "englishWorldEvents": 1292,
        "events": 1,
        "tactics": {
          "Initial Access": 1
        },
        "techniques": {
          "Supply Chain Compromise": 1
        }
      },
      {
        "date": "2021-02-16",
        "englishWorldEvents": 1860,
        "events": 1,
        "tactics": {
          "Defense Evasion": 1
        },
        "techniques": {
          "Execution Guardrails": 1
        }
      },
      {
        "date": "2021-02-17",
        "englishWorldEvents": 1829,
        "events": 2,
        "tactics": {
          "Initial Access": 1,
          "Discovery": 1
        },
        "techniques": {
          "Supply Chain Compromise": 1,
          "Software Discovery": 1
        }
      },
      {
        "date": "2021-02-18",
        "englishWorldEvents": 1822,
        "events": 1,
        "tactics": {
          "Initial Access": 1
        },
        "techniques": {
          "Supply Chain Compromise": 1
        }
      },
      {
        "date": "2021-02-19",
        "englishWorldEvents": 1497,
        "events": 3,
        "tactics": {
          "Execution": 1,
          "Collection": 1,
          "Discovery": 1
        },
        "techniques": {
          "System Services": 1,
          "Data from Information Repositories": 1,
          "Software Discovery": 1
        }
      },
      {
        "date": "2021-02-20",
        "englishWorldEvents": 681,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-02-21",
        "englishWorldEvents": 598,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-02-22",
        "englishWorldEvents": 1672,
        "events": 2,
        "tactics": {
          "Reconnaissance": 1,
          "Resource Development": 1
        },
        "techniques": {
          "Gather Victim Org Information": 1,
          "Compromise Accounts": 1
        }
      },
      {
        "date": "2021-02-23",
        "englishWorldEvents": 1930,
        "events": 2,
        "tactics": {
          "Resource Development": 1,
          "Execution": 1
        },
        "techniques": {
          "Compromise Accounts": 1,
          "System Services": 1
        }
      },
      {
        "date": "2021-02-24",
        "englishWorldEvents": 1867,
        "events": 2,
        "tactics": {
          "Execution": 1,
          "Reconnaissance": 1
        },
        "techniques": {
          "System Services": 1,
          "Gather Victim Network Information": 1
        }
      },
      {
        "date": "2021-02-25",
        "englishWorldEvents": 1854,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-02-26",
        "englishWorldEvents": 1512,
        "events": 1,
        "tactics": {
          "Reconnaissance": 1
        },
        "techniques": {
          "Search Open Technical Databases": 1
        }
      },
      {
        "date": "2021-02-27",
        "englishWorldEvents": 653,
        "events": 1,
        "tactics": {
          "Credential Access": 1
        },
        "techniques": {
          "Brute Force": 1
        }
      },
      {
        "date": "2021-02-28",
        "englishWorldEvents": 580,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-03-01",
        "englishWorldEvents": 1683,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-03-02",
        "englishWorldEvents": 2041,
        "events": 1,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-03-03",
        "englishWorldEvents": 1852,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-03-04",
        "englishWorldEvents": 1907,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-03-05",
        "englishWorldEvents": 1559,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-03-06",
        "englishWorldEvents": 643,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-03-07",
        "englishWorldEvents": 592,
        "events": 1,
        "tactics": {
          "Resource Development": 1
        },
        "techniques": {
          "Compromise Accounts": 1
        }
      },
      {
        "date": "2021-03-08",
        "englishWorldEvents": 1602,
        "events": 1,
        "tactics": {
          "Reconnaissance": 1
        },
        "techniques": {
          "Search Closed Sources": 1
        }
      },
      {
        "date": "2021-03-09",
        "englishWorldEvents": 1899,
        "events": 2,
        "tactics": {
          "Lateral Movement": 1,
          "Persistence": 1
        },
        "techniques": {
          "Exploitation of Remote Services": 1,
          "Server Software Component": 1
        }
      },
      {
        "date": "2021-03-10",
        "englishWorldEvents": 1873,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-03-11",
        "englishWorldEvents": 1796,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-03-12",
        "englishWorldEvents": 1465,
        "events": 1,
        "tactics": {
          "Lateral Movement": 1
        },
        "techniques": {
          "Remote Services": 1
        }
      },
      {
        "date": "2021-03-13",
        "englishWorldEvents": 652,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-03-14",
        "englishWorldEvents": 580,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-03-15",
        "englishWorldEvents": 1830,
        "events": 1,
        "tactics": {
          "Discovery": 1
        },
        "techniques": {
          "Software Discovery": 1
        }
      },
      {
        "date": "2021-03-16",
        "englishWorldEvents": 2021,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-03-17",
        "englishWorldEvents": 1913,
        "events": 1,
        "tactics": {
          "Initial Access": 1
        },
        "techniques": {
          "Supply Chain Compromise": 1
        }
      },
      {
        "date": "2021-03-18",
        "englishWorldEvents": 1910,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-03-19",
        "englishWorldEvents": 1564,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-03-20",
        "englishWorldEvents": 665,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-03-21",
        "englishWorldEvents": 603,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-03-22",
        "englishWorldEvents": 1816,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-03-23",
        "englishWorldEvents": 1956,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-03-24",
        "englishWorldEvents": 1895,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-03-25",
        "englishWorldEvents": 1874,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-03-26",
        "englishWorldEvents": 1576,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-03-27",
        "englishWorldEvents": 621,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-03-28",
        "englishWorldEvents": 563,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-03-29",
        "englishWorldEvents": 1515,
        "events": 1,
        "tactics": {
          "Resource Development": 1
        },
        "techniques": {
          "Compromise Accounts": 1
        }
      },
      {
        "date": "2021-03-30",
        "englishWorldEvents": 1948,
        "events": 1,
        "tactics": {
          "Resource Development": 1
        },
        "techniques": {
          "Compromise Accounts": 1
        }
      },
      {
        "date": "2021-03-31",
        "englishWorldEvents": 1892,
        "events": 1,
        "tactics": {
          "Collection": 1
        },
        "techniques": {
          "Email Collection": 1
        }
      },
      {
        "date": "2021-04-01",
        "englishWorldEvents": 1786,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-04-02",
        "englishWorldEvents": 1048,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-04-03",
        "englishWorldEvents": 608,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-04-04",
        "englishWorldEvents": 515,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-04-05",
        "englishWorldEvents": 1317,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-04-06",
        "englishWorldEvents": 1864,
        "events": 1,
        "tactics": {
          "Reconnaissance": 1
        },
        "techniques": {
          "Gather Victim Network Information": 1
        }
      },
      {
        "date": "2021-04-07",
        "englishWorldEvents": 2015,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-04-08",
        "englishWorldEvents": 1934,
        "events": 1,
        "tactics": {
          "Privilege Escalation": 1
        },
        "techniques": {
          "Domain or Tenant Policy Modification": 1
        }
      },
      {
        "date": "2021-04-09",
        "englishWorldEvents": 1458,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-04-10",
        "englishWorldEvents": 599,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-04-11",
        "englishWorldEvents": 567,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-04-12",
        "englishWorldEvents": 1634,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-04-13",
        "englishWorldEvents": 1868,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-04-14",
        "englishWorldEvents": 1859,
        "events": 1,
        "tactics": {
          "Initial Access": 1
        },
        "techniques": {
          "Supply Chain Compromise": 1
        }
      },
      {
        "date": "2021-04-15",
        "englishWorldEvents": 1979,
        "events": 1,
        "tactics": {
          "Lateral Movement": 1
        },
        "techniques": {
          "Remote Services": 1
        }
      },
      {
        "date": "2021-04-16",
        "englishWorldEvents": 1466,
        "events": 1,
        "tactics": {
          "Initial Access": 1
        },
        "techniques": {
          "Supply Chain Compromise": 1
        }
      },
      {
        "date": "2021-04-17",
        "englishWorldEvents": 586,
        "events": 1,
        "tactics": {
          "Initial Access": 1
        },
        "techniques": {
          "Supply Chain Compromise": 1
        }
      },
      {
        "date": "2021-04-18",
        "englishWorldEvents": 596,
        "events": 1,
        "tactics": {
          "Collection": 1
        },
        "techniques": {
          "Data from Information Repositories": 1
        }
      },
      {
        "date": "2021-04-19",
        "englishWorldEvents": 1739,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-04-20",
        "englishWorldEvents": 1874,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-04-21",
        "englishWorldEvents": 1745,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-04-22",
        "englishWorldEvents": 1940,
        "events": 1,
        "tactics": {
          "Initial Access": 1
        },
        "techniques": {
          "Phishing": 1
        }
      },
      {
        "date": "2021-04-23",
        "englishWorldEvents": 1478,
        "events": 1,
        "tactics": {
          "Persistence": 1
        },
        "techniques": {
          "Modify Authentication Process": 1
        }
      },
      {
        "date": "2021-04-24",
        "englishWorldEvents": 628,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-04-25",
        "englishWorldEvents": 538,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-04-26",
        "englishWorldEvents": 1654,
        "events": 1,
        "tactics": {
          "Initial Access": 1
        },
        "techniques": {
          "Supply Chain Compromise": 1
        }
      },
      {
        "date": "2021-04-27",
        "englishWorldEvents": 1928,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-04-28",
        "englishWorldEvents": 1968,
        "events": 1,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-04-29",
        "englishWorldEvents": 1849,
        "events": 0,
        "tactics": {},
        "techniques": {}
      },
      {
        "date": "2021-04-30",
        "englishWorldEvents": 1534,
        "events": 0,
        "tactics": {},
        "techniques": {}
      }
    ],
    "generatedAt": "2026-07-19"
  },
  "nodes": [
    {
      "id": "tactic-execution-6d525b71",
      "code": "Execution",
      "value": "Execution",
      "name": "Execution",
      "definition": "Adversaries execute code or commands on target systems.",
      "level": "tactic",
      "depth": 0,
      "path": [
        "Execution"
      ],
      "parentId": null,
      "synthetic": false,
      "childCount": 14,
      "leaf": false
    },
    {
      "id": "technique-windows-management-instrumentation-2216c5b9",
      "code": "Windows Management Instrumentation",
      "value": "Windows Management Instrumentation",
      "name": "Windows Management Instrumentation",
      "definition": "Text about Windows Management Instrumentation pertains to the exploitation of the Windows administrative infrastructure to execute unauthorized scripts, maintain persistence, and move laterally by leveraging native operating system command capabilities.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Execution",
        "Windows Management Instrumentation"
      ],
      "parentId": "tactic-execution-6d525b71",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "tactic-collection-30c54a96",
      "code": "Collection",
      "value": "Collection",
      "name": "Collection",
      "definition": "Text about the aggregation of high-value intelligence, user data, or technical configuration files from targeted endpoints and server infrastructure, facilitating subsequent unauthorized access or data removal from the victim network.",
      "level": "tactic",
      "depth": 0,
      "path": [
        "Collection"
      ],
      "parentId": null,
      "synthetic": false,
      "childCount": 17,
      "leaf": false
    },
    {
      "id": "technique-screen-capture-b2992026",
      "code": "Screen Capture",
      "value": "Screen Capture",
      "name": "Screen Capture",
      "definition": "Text about adversaries clandestinely recording visual information from a compromised host by capturing screen frames, leveraging system capabilities to persistantly monitor the displayed output of a targeted user's graphical interface.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Collection",
        "Screen Capture"
      ],
      "parentId": "tactic-collection-30c54a96",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "tactic-persistence-4782469e",
      "code": "Persistence",
      "value": "Persistence",
      "name": "Persistence",
      "definition": "Text about Persistence describes adversarial activities focused on establishing and maintaining reliable, long-term access to compromised infrastructure, ensuring continued control regardless of system reboots or common defensive interruptions.",
      "level": "tactic",
      "depth": 0,
      "path": [
        "Persistence"
      ],
      "parentId": null,
      "synthetic": false,
      "childCount": 20,
      "leaf": false
    },
    {
      "id": "technique-boot-or-logon-initialization-scripts-4c5c694a",
      "code": "Boot or Logon Initialization Scripts",
      "value": "Boot or Logon Initialization Scripts",
      "name": "Boot or Logon Initialization Scripts",
      "definition": "Text about adversaries inserting malicious scripts into designated system locations that trigger during automated boot or logon sequences, ensuring continuous execution of payloads without requiring further interaction from valid authorized users.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Persistence",
        "Boot or Logon Initialization Scripts"
      ],
      "parentId": "tactic-persistence-4782469e",
      "synthetic": false,
      "childCount": 5,
      "leaf": false
    },
    {
      "id": "subtechnique-rc-scripts-aae4e32e",
      "code": "RC Scripts",
      "value": "RC Scripts",
      "name": "RC Scripts",
      "definition": "Text about RC scripts involves adversaries leveraging Resource Configuration files to execute arbitrary commands, maintain persistence, or facilitate execution flow during illicit operations within compromised target systems and specified environments.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Boot or Logon Initialization Scripts",
        "RC Scripts"
      ],
      "parentId": "technique-boot-or-logon-initialization-scripts-4c5c694a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-logon-script-windows-7d7b2761",
      "code": "Logon Script (Windows)",
      "value": "Logon Script (Windows)",
      "name": "Logon Script (Windows)",
      "definition": "Text about adversaries executing malicious code by modifying Windows logon scripts, which automatically trigger when a user initiates a session, facilitating persistent access or other actions within the targeted environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Boot or Logon Initialization Scripts",
        "Logon Script (Windows)"
      ],
      "parentId": "technique-boot-or-logon-initialization-scripts-4c5c694a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-network-logon-script-145db784",
      "code": "Network Logon Script",
      "value": "Network Logon Script",
      "name": "Network Logon Script",
      "definition": "Text about the unauthorized alteration or implantation of logon scripts designed to execute malicious commands automatically when users authenticate, thereby establishing persistent access and code execution within a networked environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Boot or Logon Initialization Scripts",
        "Network Logon Script"
      ],
      "parentId": "technique-boot-or-logon-initialization-scripts-4c5c694a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-startup-items-e5db1b40",
      "code": "Startup Items",
      "value": "Startup Items",
      "name": "Startup Items",
      "definition": "Text about adversaries leveraging operating system startup folder locations, directing the execution of malicious programs or scripts upon user logon to achieve persistence by exploiting predictable automated launch processes during boot.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Boot or Logon Initialization Scripts",
        "Startup Items"
      ],
      "parentId": "technique-boot-or-logon-initialization-scripts-4c5c694a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-login-hook-1482aeb1",
      "code": "Login Hook",
      "value": "Login Hook",
      "name": "Login Hook",
      "definition": "Text about adversaries exploiting the macOS login window process to run unauthorized code by modifying configuration files that automatically trigger specified applications or scripts upon user session initialization for persistent access.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Boot or Logon Initialization Scripts",
        "Login Hook"
      ],
      "parentId": "technique-boot-or-logon-initialization-scripts-4c5c694a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "tactic-privilege-escalation-dc3564ae",
      "code": "Privilege Escalation",
      "value": "Privilege Escalation",
      "name": "Privilege Escalation",
      "definition": "Text about adversaries acquiring higher access levels than initially obtained by exploiting vulnerabilities, misconfigurations, or software weaknesses to manipulate system integrity while maintaining unauthorized control over administrative or root-level accounts.",
      "level": "tactic",
      "depth": 0,
      "path": [
        "Privilege Escalation"
      ],
      "parentId": null,
      "synthetic": false,
      "childCount": 14,
      "leaf": false
    },
    {
      "id": "technique-boot-or-logon-initialization-scripts-c8380360",
      "code": "Boot or Logon Initialization Scripts",
      "value": "Boot or Logon Initialization Scripts",
      "name": "Boot or Logon Initialization Scripts",
      "definition": "Text about adversaries inserting malicious scripts into designated system locations that trigger during automated boot or logon sequences, ensuring continuous execution of payloads without requiring further interaction from valid authorized users.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Privilege Escalation",
        "Boot or Logon Initialization Scripts"
      ],
      "parentId": "tactic-privilege-escalation-dc3564ae",
      "synthetic": false,
      "childCount": 5,
      "leaf": false
    },
    {
      "id": "subtechnique-rc-scripts-43d8e865",
      "code": "RC Scripts",
      "value": "RC Scripts",
      "name": "RC Scripts",
      "definition": "Text about RC scripts involves adversaries leveraging Resource Configuration files to execute arbitrary commands, maintain persistence, or facilitate execution flow during illicit operations within compromised target systems and specified environments.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Boot or Logon Initialization Scripts",
        "RC Scripts"
      ],
      "parentId": "technique-boot-or-logon-initialization-scripts-c8380360",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-logon-script-windows-148b27d3",
      "code": "Logon Script (Windows)",
      "value": "Logon Script (Windows)",
      "name": "Logon Script (Windows)",
      "definition": "Text about adversaries executing malicious code by modifying Windows logon scripts, which automatically trigger when a user initiates a session, facilitating persistent access or other actions within the targeted environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Boot or Logon Initialization Scripts",
        "Logon Script (Windows)"
      ],
      "parentId": "technique-boot-or-logon-initialization-scripts-c8380360",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-network-logon-script-5504302f",
      "code": "Network Logon Script",
      "value": "Network Logon Script",
      "name": "Network Logon Script",
      "definition": "Text about the unauthorized alteration or implantation of logon scripts designed to execute malicious commands automatically when users authenticate, thereby establishing persistent access and code execution within a networked environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Boot or Logon Initialization Scripts",
        "Network Logon Script"
      ],
      "parentId": "technique-boot-or-logon-initialization-scripts-c8380360",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-startup-items-06973959",
      "code": "Startup Items",
      "value": "Startup Items",
      "name": "Startup Items",
      "definition": "Text about adversaries leveraging operating system startup folder locations, directing the execution of malicious programs or scripts upon user logon to achieve persistence by exploiting predictable automated launch processes during boot.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Boot or Logon Initialization Scripts",
        "Startup Items"
      ],
      "parentId": "technique-boot-or-logon-initialization-scripts-c8380360",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-login-hook-81421812",
      "code": "Login Hook",
      "value": "Login Hook",
      "name": "Login Hook",
      "definition": "Text about adversaries exploiting the macOS login window process to run unauthorized code by modifying configuration files that automatically trigger specified applications or scripts upon user session initialization for persistent access.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Boot or Logon Initialization Scripts",
        "Login Hook"
      ],
      "parentId": "technique-boot-or-logon-initialization-scripts-c8380360",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "tactic-credential-access-9c65f4e0",
      "code": "Credential Access",
      "value": "Credential Access",
      "name": "Credential Access",
      "definition": "Text about Credential Access details the strategic objective of acquiring authentic account credentials, including passwords and cryptographic hashes, to enable unauthorized system navigation and elevated permissions within compromised enterprise network environments.",
      "level": "tactic",
      "depth": 0,
      "path": [
        "Credential Access"
      ],
      "parentId": null,
      "synthetic": false,
      "childCount": 17,
      "leaf": false
    },
    {
      "id": "technique-adversary-in-the-middle-2f2f0c73",
      "code": "Adversary-in-the-Middle",
      "value": "Adversary-in-the-Middle",
      "name": "Adversary-in-the-Middle",
      "definition": "Text about Adversary-in-the-Middle characterizes techniques where an attacker establishes an intercept point between network hosts to stealthily access communication streams, extract authentication credentials, or alter transactional data without detection.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Credential Access",
        "Adversary-in-the-Middle"
      ],
      "parentId": "tactic-credential-access-9c65f4e0",
      "synthetic": false,
      "childCount": 4,
      "leaf": false
    },
    {
      "id": "subtechnique-dhcp-spoofing-86139cc7",
      "code": "DHCP Spoofing",
      "value": "DHCP Spoofing",
      "name": "DHCP Spoofing",
      "definition": "Text about exploiting the trust inherent in the DHCP protocol where adversaries provide unauthorized server responses to configuration requests, effectively hijacking network settings to intercept, monitor, or manipulate sensitive client traffic.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Adversary-in-the-Middle",
        "DHCP Spoofing"
      ],
      "parentId": "technique-adversary-in-the-middle-2f2f0c73",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-arp-cache-poisoning-b34c9789",
      "code": "ARP Cache Poisoning",
      "value": "ARP Cache Poisoning",
      "name": "ARP Cache Poisoning",
      "definition": "Text about ARP cache poisoning involves adversaries injecting malicious ARP packets into a local area network, corrupting device mapping tables to redirect data flows through unauthorized systems controlled by the threat actor.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Adversary-in-the-Middle",
        "ARP Cache Poisoning"
      ],
      "parentId": "technique-adversary-in-the-middle-2f2f0c73",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-llmnr-nbt-ns-poisoning-and-smb-relay-fa4f5c97",
      "code": "LLMNR/NBT-NS Poisoning and SMB Relay",
      "value": "LLMNR/NBT-NS Poisoning and SMB Relay",
      "name": "LLMNR/NBT-NS Poisoning and SMB Relay",
      "definition": "Text about LLMNR or NBT-NS poisoning and SMB relay covers techniques exploiting broadcast name resolution protocols to intercept network authentication attempts, subsequently relaying those captured credentials to unauthorized internal services.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Adversary-in-the-Middle",
        "LLMNR/NBT-NS Poisoning and SMB Relay"
      ],
      "parentId": "technique-adversary-in-the-middle-2f2f0c73",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-evil-twin-d39f6b76",
      "code": "Evil Twin",
      "value": "Evil Twin",
      "name": "Evil Twin",
      "definition": "Text about the adversarial creation of fraudulent wireless access points using cloned network identifiers to masquerade as trusted connectivity points, thereby compromising client traffic and credential security through unsolicited association.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Adversary-in-the-Middle",
        "Evil Twin"
      ],
      "parentId": "technique-adversary-in-the-middle-2f2f0c73",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-adversary-in-the-middle-c2fbcddf",
      "code": "Adversary-in-the-Middle",
      "value": "Adversary-in-the-Middle",
      "name": "Adversary-in-the-Middle",
      "definition": "Text about Adversary-in-the-Middle characterizes techniques where an attacker establishes an intercept point between network hosts to stealthily access communication streams, extract authentication credentials, or alter transactional data without detection.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Collection",
        "Adversary-in-the-Middle"
      ],
      "parentId": "tactic-collection-30c54a96",
      "synthetic": false,
      "childCount": 4,
      "leaf": false
    },
    {
      "id": "subtechnique-dhcp-spoofing-189f29ee",
      "code": "DHCP Spoofing",
      "value": "DHCP Spoofing",
      "name": "DHCP Spoofing",
      "definition": "Text about exploiting the trust inherent in the DHCP protocol where adversaries provide unauthorized server responses to configuration requests, effectively hijacking network settings to intercept, monitor, or manipulate sensitive client traffic.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Collection",
        "Adversary-in-the-Middle",
        "DHCP Spoofing"
      ],
      "parentId": "technique-adversary-in-the-middle-c2fbcddf",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-arp-cache-poisoning-dcaf9ec4",
      "code": "ARP Cache Poisoning",
      "value": "ARP Cache Poisoning",
      "name": "ARP Cache Poisoning",
      "definition": "Text about ARP cache poisoning involves adversaries injecting malicious ARP packets into a local area network, corrupting device mapping tables to redirect data flows through unauthorized systems controlled by the threat actor.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Collection",
        "Adversary-in-the-Middle",
        "ARP Cache Poisoning"
      ],
      "parentId": "technique-adversary-in-the-middle-c2fbcddf",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-llmnr-nbt-ns-poisoning-and-smb-relay-75a9f7a8",
      "code": "LLMNR/NBT-NS Poisoning and SMB Relay",
      "value": "LLMNR/NBT-NS Poisoning and SMB Relay",
      "name": "LLMNR/NBT-NS Poisoning and SMB Relay",
      "definition": "Text about LLMNR or NBT-NS poisoning and SMB relay covers techniques exploiting broadcast name resolution protocols to intercept network authentication attempts, subsequently relaying those captured credentials to unauthorized internal services.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Collection",
        "Adversary-in-the-Middle",
        "LLMNR/NBT-NS Poisoning and SMB Relay"
      ],
      "parentId": "technique-adversary-in-the-middle-c2fbcddf",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-evil-twin-24fdbf4c",
      "code": "Evil Twin",
      "value": "Evil Twin",
      "name": "Evil Twin",
      "definition": "Text about the adversarial creation of fraudulent wireless access points using cloned network identifiers to masquerade as trusted connectivity points, thereby compromising client traffic and credential security through unsolicited association.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Collection",
        "Adversary-in-the-Middle",
        "Evil Twin"
      ],
      "parentId": "technique-adversary-in-the-middle-c2fbcddf",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "tactic-discovery-3b3290c7",
      "code": "Discovery",
      "value": "Discovery",
      "name": "Discovery",
      "definition": "Text about intruders gaining comprehensive visibility into targeted systems by querying environment variables, listing installed software, identifying active network connections, and mapping internal resources to optimize their tactical approach.",
      "level": "tactic",
      "depth": 0,
      "path": [
        "Discovery"
      ],
      "parentId": null,
      "synthetic": false,
      "childCount": 32,
      "leaf": false
    },
    {
      "id": "technique-system-owner-user-discovery-56fc7185",
      "code": "System Owner/User Discovery",
      "value": "System Owner/User Discovery",
      "name": "System Owner/User Discovery",
      "definition": "Text about threat actors querying local system information and directory services to map specific organizational personnel tasked with managing, administering, or utilizing the compromised host within the target network environment.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "System Owner/User Discovery"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "tactic-resource-development-ce56343a",
      "code": "Resource Development",
      "value": "Resource Development",
      "name": "Resource Development",
      "definition": "Text about the intentional acquisition and configuration of backend infrastructure, clandestine communication channels, and identity resources necessary to support the execution of planned cyber operations against a designated target.",
      "level": "tactic",
      "depth": 0,
      "path": [
        "Resource Development"
      ],
      "parentId": null,
      "synthetic": false,
      "childCount": 8,
      "leaf": false
    },
    {
      "id": "technique-acquire-infrastructure-b8c1a911",
      "code": "Acquire Infrastructure",
      "value": "Acquire Infrastructure",
      "name": "Acquire Infrastructure",
      "definition": "Text about the systematic procurement of digital infrastructure assets, including network space and registered identifiers, specifically intended to facilitate subsequent hostile operations, command channels, and malicious campaign utility.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Resource Development",
        "Acquire Infrastructure"
      ],
      "parentId": "tactic-resource-development-ce56343a",
      "synthetic": false,
      "childCount": 8,
      "leaf": false
    },
    {
      "id": "subtechnique-malvertising-89015553",
      "code": "Malvertising",
      "value": "Malvertising",
      "name": "Malvertising",
      "definition": "Text about Malvertising involves adversaries injecting malicious code into legitimate digital advertising networks to distribute malware or redirect unsuspecting users to compromised websites when they interact with the displayed advertisements.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Acquire Infrastructure",
        "Malvertising"
      ],
      "parentId": "technique-acquire-infrastructure-b8c1a911",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-domains-7c272a5d",
      "code": "Domains",
      "value": "Domains",
      "name": "Domains",
      "definition": "Text about adversaries acquiring domains by registering new domain names or purchasing existing ones to support operations such as command and control, phishing, and staging of malicious infrastructure.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Acquire Infrastructure",
        "Domains"
      ],
      "parentId": "technique-acquire-infrastructure-b8c1a911",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-botnet-6aa46a89",
      "code": "Botnet",
      "value": "Botnet",
      "name": "Botnet",
      "definition": "Text about adversaries recruiting infected systems into a centrally managed network architecture for executing simultaneous commands, distributing malware payloads, or performing large-scale malicious operations to disrupt or exfiltrate target data.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Acquire Infrastructure",
        "Botnet"
      ],
      "parentId": "technique-acquire-infrastructure-b8c1a911",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-server-3ef7db01",
      "code": "Server",
      "value": "Server",
      "name": "Server",
      "definition": "Text about Server subtechnique category refers to malicious infrastructure assets procured, leased, or seized by adversaries to host command and control listeners, staging repositories, or redirectors critical for executing operational objectives.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Acquire Infrastructure",
        "Server"
      ],
      "parentId": "technique-acquire-infrastructure-b8c1a911",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-dns-server-2bdd9ccd",
      "code": "DNS Server",
      "value": "DNS Server",
      "name": "DNS Server",
      "definition": "Text about adversaries deploying malicious DNS server configurations to intercept internal network name resolution, facilitating man-in-the-middle attacks or data exfiltration by redirecting traffic to attacker-controlled endpoints for further exploitation.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Acquire Infrastructure",
        "DNS Server"
      ],
      "parentId": "technique-acquire-infrastructure-b8c1a911",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-virtual-private-server-780da84d",
      "code": "Virtual Private Server",
      "value": "Virtual Private Server",
      "name": "Virtual Private Server",
      "definition": "Text about adversaries leveraging virtual private server environments to deploy and manage malicious infrastructure, enabling them to execute command and control, store payloads, and obfuscate network traffic routing.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Acquire Infrastructure",
        "Virtual Private Server"
      ],
      "parentId": "technique-acquire-infrastructure-b8c1a911",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-serverless-967f2454",
      "code": "Serverless",
      "value": "Serverless",
      "name": "Serverless",
      "definition": "Text about serverless addresses the exploitation of serverless computing platforms where adversaries manipulate function code, dependencies, or IAM roles to gain unauthorized access or execute commands within managed, stateless cloud runtime environments.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Acquire Infrastructure",
        "Serverless"
      ],
      "parentId": "technique-acquire-infrastructure-b8c1a911",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-web-services-ba0f6d30",
      "code": "Web Services",
      "value": "Web Services",
      "name": "Web Services",
      "definition": "Text about threat actors repurposing legitimate web-accessible applications and cloud APIs to act as command and control intermediaries, enabling stealthy remote management of compromised systems over standard web traffic channels.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Acquire Infrastructure",
        "Web Services"
      ],
      "parentId": "technique-acquire-infrastructure-b8c1a911",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-container-and-resource-discovery-44fbb23f",
      "code": "Container and Resource Discovery",
      "value": "Container and Resource Discovery",
      "name": "Container and Resource Discovery",
      "definition": "Text about adversaries inspecting container runtime states and orchestrator API responses to determine inventory breadth, discover connected resources, and facilitate efficient targeting of specific components within the compromised IT ecosystem.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "Container and Resource Discovery"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "tactic-reconnaissance-a9f8c2a8",
      "code": "Reconnaissance",
      "value": "Reconnaissance",
      "name": "Reconnaissance",
      "definition": "Text about systematic efforts by adversaries to acquire intelligence on potential target environments, encompassing network topology mapping, email address harvesting, and identifying public-facing assets to inform future offensive operations.",
      "level": "tactic",
      "depth": 0,
      "path": [
        "Reconnaissance"
      ],
      "parentId": null,
      "synthetic": false,
      "childCount": 10,
      "leaf": false
    },
    {
      "id": "technique-gather-victim-host-information-b12a5a67",
      "code": "Gather Victim Host Information",
      "value": "Gather Victim Host Information",
      "name": "Gather Victim Host Information",
      "definition": "Text about adversaries systematically identifying specific hardware, software, or configuration details associated with a target network infrastructure to better understand the environment before executing subsequent stages of an intrusion operation.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Reconnaissance",
        "Gather Victim Host Information"
      ],
      "parentId": "tactic-reconnaissance-a9f8c2a8",
      "synthetic": false,
      "childCount": 4,
      "leaf": false
    },
    {
      "id": "subtechnique-hardware-d96120d6",
      "code": "Hardware",
      "value": "Hardware",
      "name": "Hardware",
      "definition": "Text about Hardware subtechniques addresses adversarial operations specifically targeting physical infrastructure, including circuit-level alterations, malicious firmware implants, and unauthorized modifications to computing peripherals to achieve defined tactical objectives.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Gather Victim Host Information",
        "Hardware"
      ],
      "parentId": "technique-gather-victim-host-information-b12a5a67",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-firmware-d4a05a59",
      "code": "Firmware",
      "value": "Firmware",
      "name": "Firmware",
      "definition": "Text about the installation of malicious software into hardware components, granting adversaries control over peripheral devices or core system processes while effectively bypassing established security boundaries within the target computing architecture.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Gather Victim Host Information",
        "Firmware"
      ],
      "parentId": "technique-gather-victim-host-information-b12a5a67",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-software-5d085403",
      "code": "Software",
      "value": "Software",
      "name": "Software",
      "definition": "Text about adversaries gathering information about the software installed on a victim's hosts, including applications, versions, and operating environment details that inform targeting and later stages of an operation.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Gather Victim Host Information",
        "Software"
      ],
      "parentId": "technique-gather-victim-host-information-b12a5a67",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-client-configurations-4788a301",
      "code": "Client Configurations",
      "value": "Client Configurations",
      "name": "Client Configurations",
      "definition": "Text about adversaries gathering information about the client configurations of a victim's hosts, such as operating system, language, hardware, and administrative or network settings that reveal the operating environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Gather Victim Host Information",
        "Client Configurations"
      ],
      "parentId": "technique-gather-victim-host-information-b12a5a67",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-os-credential-dumping-2757c39e",
      "code": "OS Credential Dumping",
      "value": "OS Credential Dumping",
      "name": "OS Credential Dumping",
      "definition": "Text about OS Credential Dumping describes the illicit retrieval of account credentials, including cleartext passwords and hashes, stored within the operating system memory or filesystem by adversaries seeking unauthorized access.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Credential Access",
        "OS Credential Dumping"
      ],
      "parentId": "tactic-credential-access-9c65f4e0",
      "synthetic": false,
      "childCount": 8,
      "leaf": false
    },
    {
      "id": "subtechnique-security-account-manager-6dfa5dd5",
      "code": "Security Account Manager",
      "value": "Security Account Manager",
      "name": "Security Account Manager",
      "definition": "Text about adversaries targeting the Security Account Manager database to extract password hashes stored locally, facilitating subsequent attempts to crack those credentials and gain unauthorized access to authenticated system accounts.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "OS Credential Dumping",
        "Security Account Manager"
      ],
      "parentId": "technique-os-credential-dumping-2757c39e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-lsa-secrets-9aa59673",
      "code": "LSA Secrets",
      "value": "LSA Secrets",
      "name": "LSA Secrets",
      "definition": "Text about attackers targeting the Local Security Authority service to pull cached domain credentials and security secrets from volatile memory, effectively compromising authentication mechanisms across systems within a networked environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "OS Credential Dumping",
        "LSA Secrets"
      ],
      "parentId": "technique-os-credential-dumping-2757c39e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-dcsync-5a70819c",
      "code": "DCSync",
      "value": "DCSync",
      "name": "DCSync",
      "definition": "Text about DCSync entails the unauthorized mimicry of domain replication synchronization processes, allowing adversaries to illicitly solicit and exfiltrate credential materials directly from a targeted organization's Active Directory environment database.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "OS Credential Dumping",
        "DCSync"
      ],
      "parentId": "technique-os-credential-dumping-2757c39e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-proc-filesystem-641da49a",
      "code": "Proc Filesystem",
      "value": "Proc Filesystem",
      "name": "Proc Filesystem",
      "definition": "Text about adversaries leveraging inherent access to the proc filesystem to read volatile system data, identify active processes, or map memory structures that reveal underlying operational security configurations on compromised hosts.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "OS Credential Dumping",
        "Proc Filesystem"
      ],
      "parentId": "technique-os-credential-dumping-2757c39e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-ntds-0f913da5",
      "code": "NTDS",
      "value": "NTDS",
      "name": "NTDS",
      "definition": "Text about the clandestine seizure of the central Active Directory database, enabling adversaries to decrypt stored credentials and obtain sensitive authentication data necessary to impersonate users across the entire domain.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "OS Credential Dumping",
        "NTDS"
      ],
      "parentId": "technique-os-credential-dumping-2757c39e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-cached-domain-credentials-7a88e6bd",
      "code": "Cached Domain Credentials",
      "value": "Cached Domain Credentials",
      "name": "Cached Domain Credentials",
      "definition": "Text about adversaries extracting stored domain password hashes from operating system volatile memory or local registry structures to facilitate credential access and subsequent lateral movement or privilege escalation within trusted networks.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "OS Credential Dumping",
        "Cached Domain Credentials"
      ],
      "parentId": "technique-os-credential-dumping-2757c39e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-lsass-memory-33d6a73a",
      "code": "LSASS Memory",
      "value": "LSASS Memory",
      "name": "LSASS Memory",
      "definition": "Text about attackers reading memory segments of the Local Security Authority Subsystem Service process to capture credentials, passwords, or authentication hashes stored by the operating system for malicious account impersonation.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "OS Credential Dumping",
        "LSASS Memory"
      ],
      "parentId": "technique-os-credential-dumping-2757c39e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-etc-passwd-and-etc-shadow-8fa81e56",
      "code": "/etc/passwd and /etc/shadow",
      "value": "/etc/passwd and /etc/shadow",
      "name": "/etc/passwd and /etc/shadow",
      "definition": "Text about the clandestine retrieval of local system account information and encrypted authentication credentials from core configuration files to enable offline password cracking or lateral movement within compromised Linux environments.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "OS Credential Dumping",
        "/etc/passwd and /etc/shadow"
      ],
      "parentId": "technique-os-credential-dumping-2757c39e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-shared-modules-f15c54ba",
      "code": "Shared Modules",
      "value": "Shared Modules",
      "name": "Shared Modules",
      "definition": "Text about adversaries manipulating the module loading process to execute malicious instructions by leveraging pre-installed shared libraries, effectively using trusted system components to mask unauthorized activities on the host.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Execution",
        "Shared Modules"
      ],
      "parentId": "tactic-execution-6d525b71",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-data-from-configuration-repository-f3e55c57",
      "code": "Data from Configuration Repository",
      "value": "Data from Configuration Repository",
      "name": "Data from Configuration Repository",
      "definition": "Text about threat actors leveraging authorized or unauthorized access to centralized repositories containing hardware or software configuration manifests to illicitly acquire operational intelligence, network architecture details, and embedded service account credentials.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Collection",
        "Data from Configuration Repository"
      ],
      "parentId": "tactic-collection-30c54a96",
      "synthetic": false,
      "childCount": 2,
      "leaf": false
    },
    {
      "id": "subtechnique-network-device-configuration-dump-55930ddb",
      "code": "Network Device Configuration Dump",
      "value": "Network Device Configuration Dump",
      "name": "Network Device Configuration Dump",
      "definition": "Text about threat actors interacting with network infrastructure management interfaces to download complete configuration data, allowing for unauthorized discovery of system secrets, routing protocols, and internal security mechanisms used by organizations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Collection",
        "Data from Configuration Repository",
        "Network Device Configuration Dump"
      ],
      "parentId": "technique-data-from-configuration-repository-f3e55c57",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-snmp-mib-dump-a1222935",
      "code": "SNMP (MIB Dump)",
      "value": "SNMP (MIB Dump)",
      "name": "SNMP (MIB Dump)",
      "definition": "Text about adversaries executing targeted SNMP protocol operations to dump Management Information Base data, translating raw object identifiers into actionable intelligence concerning network hardware, software versions, and active system processes.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Collection",
        "Data from Configuration Repository",
        "SNMP (MIB Dump)"
      ],
      "parentId": "technique-data-from-configuration-repository-f3e55c57",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "tactic-defense-evasion-f44f34a8",
      "code": "Defense Evasion",
      "value": "Defense Evasion",
      "name": "Defense Evasion",
      "definition": "Text about Defense Evasion entails the specific adversary methods used to actively avoid detection, manipulate system configurations, and subvert security monitoring mechanisms while maintaining uninterrupted control during a network intrusion.",
      "level": "tactic",
      "depth": 0,
      "path": [
        "Defense Evasion"
      ],
      "parentId": null,
      "synthetic": false,
      "childCount": 44,
      "leaf": false
    },
    {
      "id": "technique-direct-volume-access-70bb7293",
      "code": "Direct Volume Access",
      "value": "Direct Volume Access",
      "name": "Direct Volume Access",
      "definition": "Text about the technique of directly engaging with raw disk volumes to circumvent standard access control mechanisms, facilitating data exfiltration or unauthorized system alteration by reading blocks beneath the file system.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Direct Volume Access"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-modify-cloud-resource-hierarchy-298faf0b",
      "code": "Modify Cloud Resource Hierarchy",
      "value": "Modify Cloud Resource Hierarchy",
      "name": "Modify Cloud Resource Hierarchy",
      "definition": "Text about adversaries reconfiguring the hierarchical structures of cloud accounts, folders, or organizational units to bypass access controls, circumvent policy inheritance models, or facilitate unauthorized movement between segmented environments.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Modify Cloud Resource Hierarchy"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-rootkit-5554f781",
      "code": "Rootkit",
      "value": "Rootkit",
      "name": "Rootkit",
      "definition": "Text about malicious software capabilities designed to modify operating system internals, enabling attackers to gain unauthorized privileged access, persist undetected across reboots, and manipulate system reporting tools to conceal activity.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Rootkit"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-audio-capture-5394e32f",
      "code": "Audio Capture",
      "value": "Audio Capture",
      "name": "Audio Capture",
      "definition": "Text about the clandestine activation of microphone hardware by malicious actors to intercept audio signals from the victim's surroundings, enabling the unauthorized acquisition of sensitive spoken communications and acoustic intelligence.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Collection",
        "Audio Capture"
      ],
      "parentId": "tactic-collection-30c54a96",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-create-or-modify-system-process-e6e35751",
      "code": "Create or Modify System Process",
      "value": "Create or Modify System Process",
      "name": "Create or Modify System Process",
      "definition": "Text about adversaries executing unauthorized operations by illicitly generating new background services or altering existing task configurations to ensure persistent execution and clandestine control over compromised operating system execution environments.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Persistence",
        "Create or Modify System Process"
      ],
      "parentId": "tactic-persistence-4782469e",
      "synthetic": false,
      "childCount": 5,
      "leaf": false
    },
    {
      "id": "subtechnique-launch-daemon-f03dad3d",
      "code": "Launch Daemon",
      "value": "Launch Daemon",
      "name": "Launch Daemon",
      "definition": "Text about adversaries installing or modifying property list files in systemic configuration directories to leverage operating system boot sequences for automatic, persistent execution of their background-dwelling malicious software components.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Create or Modify System Process",
        "Launch Daemon"
      ],
      "parentId": "technique-create-or-modify-system-process-e6e35751",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-container-service-fea1ca40",
      "code": "Container Service",
      "value": "Container Service",
      "name": "Container Service",
      "definition": "Text about Container Service involves adversarial exploitation of managed container management systems to execute unauthorized commands, manipulate orchestration settings, or establish persistent control over containerized applications hosted in cloud environments.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Create or Modify System Process",
        "Container Service"
      ],
      "parentId": "technique-create-or-modify-system-process-e6e35751",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-launch-agent-dc06ea3f",
      "code": "Launch Agent",
      "value": "Launch Agent",
      "name": "Launch Agent",
      "definition": "Text about adversaries executing malicious payloads by configuring persistence mechanisms that automatically trigger specific program executions upon user login to ensure continued process activity within the compromised host operating environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Create or Modify System Process",
        "Launch Agent"
      ],
      "parentId": "technique-create-or-modify-system-process-e6e35751",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-systemd-service-9bdb3cff",
      "code": "Systemd Service",
      "value": "Systemd Service",
      "name": "Systemd Service",
      "definition": "Text about adversaries deploying malicious systemd service files to automate the execution of unauthorized tasks or payloads during the Linux boot sequence to facilitate long-term persistent system access.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Create or Modify System Process",
        "Systemd Service"
      ],
      "parentId": "technique-create-or-modify-system-process-e6e35751",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-windows-service-4552c119",
      "code": "Windows Service",
      "value": "Windows Service",
      "name": "Windows Service",
      "definition": "Text about Windows Service refers to techniques centered on exploiting the Windows Service Control Manager to trigger or sustain the execution of malicious code integrated into system-level background processes for unauthorized activity.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Create or Modify System Process",
        "Windows Service"
      ],
      "parentId": "technique-create-or-modify-system-process-e6e35751",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-create-or-modify-system-process-8acecde9",
      "code": "Create or Modify System Process",
      "value": "Create or Modify System Process",
      "name": "Create or Modify System Process",
      "definition": "Text about adversaries executing unauthorized operations by illicitly generating new background services or altering existing task configurations to ensure persistent execution and clandestine control over compromised operating system execution environments.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Privilege Escalation",
        "Create or Modify System Process"
      ],
      "parentId": "tactic-privilege-escalation-dc3564ae",
      "synthetic": false,
      "childCount": 5,
      "leaf": false
    },
    {
      "id": "subtechnique-launch-daemon-11226145",
      "code": "Launch Daemon",
      "value": "Launch Daemon",
      "name": "Launch Daemon",
      "definition": "Text about adversaries installing or modifying property list files in systemic configuration directories to leverage operating system boot sequences for automatic, persistent execution of their background-dwelling malicious software components.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Create or Modify System Process",
        "Launch Daemon"
      ],
      "parentId": "technique-create-or-modify-system-process-8acecde9",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-container-service-9f0decf5",
      "code": "Container Service",
      "value": "Container Service",
      "name": "Container Service",
      "definition": "Text about Container Service involves adversarial exploitation of managed container management systems to execute unauthorized commands, manipulate orchestration settings, or establish persistent control over containerized applications hosted in cloud environments.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Create or Modify System Process",
        "Container Service"
      ],
      "parentId": "technique-create-or-modify-system-process-8acecde9",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-launch-agent-56ae830c",
      "code": "Launch Agent",
      "value": "Launch Agent",
      "name": "Launch Agent",
      "definition": "Text about adversaries executing malicious payloads by configuring persistence mechanisms that automatically trigger specific program executions upon user login to ensure continued process activity within the compromised host operating environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Create or Modify System Process",
        "Launch Agent"
      ],
      "parentId": "technique-create-or-modify-system-process-8acecde9",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-systemd-service-35e4e1a2",
      "code": "Systemd Service",
      "value": "Systemd Service",
      "name": "Systemd Service",
      "definition": "Text about adversaries deploying malicious systemd service files to automate the execution of unauthorized tasks or payloads during the Linux boot sequence to facilitate long-term persistent system access.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Create or Modify System Process",
        "Systemd Service"
      ],
      "parentId": "technique-create-or-modify-system-process-8acecde9",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-windows-service-1e81e36c",
      "code": "Windows Service",
      "value": "Windows Service",
      "name": "Windows Service",
      "definition": "Text about Windows Service refers to techniques centered on exploiting the Windows Service Control Manager to trigger or sustain the execution of malicious code integrated into system-level background processes for unauthorized activity.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Create or Modify System Process",
        "Windows Service"
      ],
      "parentId": "technique-create-or-modify-system-process-8acecde9",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-external-remote-services-b3a0298f",
      "code": "External Remote Services",
      "value": "External Remote Services",
      "name": "External Remote Services",
      "definition": "Text about adversaries utilizing externally facing services such as VPNs, RDP, or SSH to gain unauthorized initial access into a targeted enterprise environment by leveraging valid credentials or exploiting known configurations.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Persistence",
        "External Remote Services"
      ],
      "parentId": "tactic-persistence-4782469e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "tactic-initial-access-a0f45034",
      "code": "Initial Access",
      "value": "Initial Access",
      "name": "Initial Access",
      "definition": "Text about adversaries attempting to enter a targeted network environment by exploiting vulnerabilities in external-facing services or utilizing social engineering vectors to gain their first foothold within the organization.",
      "level": "tactic",
      "depth": 0,
      "path": [
        "Initial Access"
      ],
      "parentId": null,
      "synthetic": false,
      "childCount": 10,
      "leaf": false
    },
    {
      "id": "technique-external-remote-services-c1cf383e",
      "code": "External Remote Services",
      "value": "External Remote Services",
      "name": "External Remote Services",
      "definition": "Text about adversaries utilizing externally facing services such as VPNs, RDP, or SSH to gain unauthorized initial access into a targeted enterprise environment by leveraging valid credentials or exploiting known configurations.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Initial Access",
        "External Remote Services"
      ],
      "parentId": "tactic-initial-access-a0f45034",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-steal-web-session-cookie-182e98f8",
      "code": "Steal Web Session Cookie",
      "value": "Steal Web Session Cookie",
      "name": "Steal Web Session Cookie",
      "definition": "Text about malicious entities illicitly accessing session cookies stored within browser file systems or memory to emulate active web sessions, effectively bypassing account login requirements for the targeted remote services.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Credential Access",
        "Steal Web Session Cookie"
      ],
      "parentId": "tactic-credential-access-9c65f4e0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-modify-cloud-compute-infrastructure-eb012695",
      "code": "Modify Cloud Compute Infrastructure",
      "value": "Modify Cloud Compute Infrastructure",
      "name": "Modify Cloud Compute Infrastructure",
      "definition": "Text about unauthorized changes to cloud compute infrastructure components, such as instances or virtual machine configurations, enacted by adversaries to manipulate resource availability, maintain persistent access, or subvert standard operational controls.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Modify Cloud Compute Infrastructure"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 5,
      "leaf": false
    },
    {
      "id": "subtechnique-create-snapshot-7b80e524",
      "code": "Create Snapshot",
      "value": "Create Snapshot",
      "name": "Create Snapshot",
      "definition": "Text about invoking snapshot functionality within virtualization or cloud infrastructure to isolate system states, granting adversaries mechanisms to preserve data integrity for subsequent exfiltration or rapid system state rollbacks.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Modify Cloud Compute Infrastructure",
        "Create Snapshot"
      ],
      "parentId": "technique-modify-cloud-compute-infrastructure-eb012695",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-delete-cloud-instance-39653554",
      "code": "Delete Cloud Instance",
      "value": "Delete Cloud Instance",
      "name": "Delete Cloud Instance",
      "definition": "Text about attackers using legitimate or stolen cloud credentials to instruct the infrastructure provider to delete specific virtual instances, effectively disabling the targeted services and destroying the associated computing environment permanently.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Modify Cloud Compute Infrastructure",
        "Delete Cloud Instance"
      ],
      "parentId": "technique-modify-cloud-compute-infrastructure-eb012695",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-revert-cloud-instance-8eba2536",
      "code": "Revert Cloud Instance",
      "value": "Revert Cloud Instance",
      "name": "Revert Cloud Instance",
      "definition": "Text about adversaries utilizing cloud service snapshot features to restore an instance to a previous configuration state, thereby reverting unauthorized modifications or erasing traces of malicious activity within an environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Modify Cloud Compute Infrastructure",
        "Revert Cloud Instance"
      ],
      "parentId": "technique-modify-cloud-compute-infrastructure-eb012695",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-create-cloud-instance-ffa237a8",
      "code": "Create Cloud Instance",
      "value": "Create Cloud Instance",
      "name": "Create Cloud Instance",
      "definition": "Text about malicious actors initiating the creation of new virtual server instances within a controlled cloud provider tenancy to obtain dedicated computing assets for conducting unauthorized operations or expanding adversary operational footprint.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Modify Cloud Compute Infrastructure",
        "Create Cloud Instance"
      ],
      "parentId": "technique-modify-cloud-compute-infrastructure-eb012695",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-modify-cloud-compute-configurations-00804d92",
      "code": "Modify Cloud Compute Configurations",
      "value": "Modify Cloud Compute Configurations",
      "name": "Modify Cloud Compute Configurations",
      "definition": "Text about adversaries altering the operational parameters of virtualized compute instances to bypass security controls, facilitate unauthorized access, or modify the execution environment behavior within cloud-based infrastructure provider systems.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Modify Cloud Compute Infrastructure",
        "Modify Cloud Compute Configurations"
      ],
      "parentId": "technique-modify-cloud-compute-infrastructure-eb012695",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-permission-groups-discovery-c743a238",
      "code": "Permission Groups Discovery",
      "value": "Permission Groups Discovery",
      "name": "Permission Groups Discovery",
      "definition": "Text about an adversary gathering intelligence on local and domain-level permission groups to determine account access hierarchies, thereby enabling the focused targeting of accounts possessing sensitive or administrative rights within networks.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "Permission Groups Discovery"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 3,
      "leaf": false
    },
    {
      "id": "subtechnique-cloud-groups-48240375",
      "code": "Cloud Groups",
      "value": "Cloud Groups",
      "name": "Cloud Groups",
      "definition": "Text about Cloud Groups concerns the adversarial exploitation of identity and access management structures, specifically leveraging grouped permissions to facilitate unauthorized lateral movement or privilege escalation within cloud infrastructure.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Discovery",
        "Permission Groups Discovery",
        "Cloud Groups"
      ],
      "parentId": "technique-permission-groups-discovery-c743a238",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-domain-groups-cfa2b50c",
      "code": "Domain Groups",
      "value": "Domain Groups",
      "name": "Domain Groups",
      "definition": "Text about adversaries enumerating domain-level permission groups and their members within a directory service such as Active Directory, mapping account access and privilege relationships across the domain.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Discovery",
        "Permission Groups Discovery",
        "Domain Groups"
      ],
      "parentId": "technique-permission-groups-discovery-c743a238",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-local-groups-c98a39b9",
      "code": "Local Groups",
      "value": "Local Groups",
      "name": "Local Groups",
      "definition": "Text about adversaries leveraging system APIs or command-line tools to enumerate, create, or modify local groups on target endpoints, directly manipulating authorization protocols to facilitate continued access or privilege elevation.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Discovery",
        "Permission Groups Discovery",
        "Local Groups"
      ],
      "parentId": "technique-permission-groups-discovery-c743a238",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-email-collection-3b87353f",
      "code": "Email Collection",
      "value": "Email Collection",
      "name": "Email Collection",
      "definition": "Text about the retrieval of sensitive communication data from email repositories, focusing on the unauthorized collection of stored messages, attachments, and metadata from user accounts within an enterprise environment.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Collection",
        "Email Collection"
      ],
      "parentId": "tactic-collection-30c54a96",
      "synthetic": false,
      "childCount": 3,
      "leaf": false
    },
    {
      "id": "subtechnique-remote-email-collection-4699daad",
      "code": "Remote Email Collection",
      "value": "Remote Email Collection",
      "name": "Remote Email Collection",
      "definition": "Text about adversaries gaining unauthorized access to electronic message repositories by leveraging direct network connections to remote mail servers for the purpose of siphoning sensitive user communication data.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Collection",
        "Email Collection",
        "Remote Email Collection"
      ],
      "parentId": "technique-email-collection-3b87353f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-email-forwarding-rule-3e847434",
      "code": "Email Forwarding Rule",
      "value": "Email Forwarding Rule",
      "name": "Email Forwarding Rule",
      "definition": "Text about malicious configuration of server-side email rules designed to automatically forward incoming messages to address spaces controlled by attackers, facilitating covert data exfiltration and ongoing collection of email content.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Collection",
        "Email Collection",
        "Email Forwarding Rule"
      ],
      "parentId": "technique-email-collection-3b87353f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-local-email-collection-a9bdee9e",
      "code": "Local Email Collection",
      "value": "Local Email Collection",
      "name": "Local Email Collection",
      "definition": "Text about the unauthorized extraction of email content stored on a local machine, targeting mail client databases and cached configuration files to steal user communications and associated message attachments.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Collection",
        "Email Collection",
        "Local Email Collection"
      ],
      "parentId": "technique-email-collection-3b87353f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-search-victim-owned-websites-4c4e1a49",
      "code": "Search Victim-Owned Websites",
      "value": "Search Victim-Owned Websites",
      "name": "Search Victim-Owned Websites",
      "definition": "Text about adversaries performing targeted queries against web pages owned by the victim to extract sensitive infrastructure details, organizational structures, or exposed data points necessary for subsequent intrusion planning activities.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Reconnaissance",
        "Search Victim-Owned Websites"
      ],
      "parentId": "tactic-reconnaissance-a9f8c2a8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "tactic-impact-62036a70",
      "code": "Impact",
      "value": "Impact",
      "name": "Impact",
      "definition": "Text about malicious activities directed at damaging system availability, integrity, or network infrastructure, serving to sabotage an organization through the manipulation, destruction, or paralysis of critical digital assets and environments.",
      "level": "tactic",
      "depth": 0,
      "path": [
        "Impact"
      ],
      "parentId": null,
      "synthetic": false,
      "childCount": 14,
      "leaf": false
    },
    {
      "id": "technique-disk-wipe-497a81db",
      "code": "Disk Wipe",
      "value": "Disk Wipe",
      "name": "Disk Wipe",
      "definition": "Text about adversaries overwriting data on storage devices to permanently render information unrecoverable, thereby causing operational disruption and preventing forensic analysis or system restoration during a deliberate malicious cyber campaign.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Impact",
        "Disk Wipe"
      ],
      "parentId": "tactic-impact-62036a70",
      "synthetic": false,
      "childCount": 2,
      "leaf": false
    },
    {
      "id": "subtechnique-disk-structure-wipe-8e83ac46",
      "code": "Disk Structure Wipe",
      "value": "Disk Structure Wipe",
      "name": "Disk Structure Wipe",
      "definition": "Text about Disk Structure Wipe entails the adversary-driven removal or corruption of master boot records and partition table entries, resulting in the immediate unavailability of the targeted host's storage volumes.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Impact",
        "Disk Wipe",
        "Disk Structure Wipe"
      ],
      "parentId": "technique-disk-wipe-497a81db",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-disk-content-wipe-8544a0b9",
      "code": "Disk Content Wipe",
      "value": "Disk Content Wipe",
      "name": "Disk Content Wipe",
      "definition": "Text about the adversarial manipulation of storage media to clear file systems or overwrite master boot records, intentionally ensuring the permanent loss of all data stored on the targeted device.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Impact",
        "Disk Wipe",
        "Disk Content Wipe"
      ],
      "parentId": "technique-disk-wipe-497a81db",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-group-policy-discovery-e275c46c",
      "code": "Group Policy Discovery",
      "value": "Group Policy Discovery",
      "name": "Group Policy Discovery",
      "definition": "Text about systematic efforts by an adversary to locate and read network Group Policy Objects to uncover administrative configurations, script paths, or operational limitations enforced on hosts and domains.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "Group Policy Discovery"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-data-from-removable-media-e652f3d6",
      "code": "Data from Removable Media",
      "value": "Data from Removable Media",
      "name": "Data from Removable Media",
      "definition": "Text about the unauthorized acquisition of data processed from attached storage hardware, where intruders extract information by interacting with physical drives connected directly to the compromised computer workstation platform.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Collection",
        "Data from Removable Media"
      ],
      "parentId": "tactic-collection-30c54a96",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-boot-or-logon-autostart-execution-80350d80",
      "code": "Boot or Logon Autostart Execution",
      "value": "Boot or Logon Autostart Execution",
      "name": "Boot or Logon Autostart Execution",
      "definition": "Text about Boot or Logon Autostart Execution describes strategies where adversaries modify specific operating system startup locations to facilitate the automatic execution of malware during subsequent system boots or user sessions.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Persistence",
        "Boot or Logon Autostart Execution"
      ],
      "parentId": "tactic-persistence-4782469e",
      "synthetic": false,
      "childCount": 14,
      "leaf": false
    },
    {
      "id": "subtechnique-shortcut-modification-e46c079e",
      "code": "Shortcut Modification",
      "value": "Shortcut Modification",
      "name": "Shortcut Modification",
      "definition": "Text about adversaries targeting shortcut files to redirect their execution paths toward malicious payloads, enabling the automatic launching of unauthorized code whenever a legitimate shortcut is activated by the user.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Boot or Logon Autostart Execution",
        "Shortcut Modification"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-80350d80",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-kernel-modules-and-extensions-8286f74e",
      "code": "Kernel Modules and Extensions",
      "value": "Kernel Modules and Extensions",
      "name": "Kernel Modules and Extensions",
      "definition": "Text about the clandestine insertion of unauthorized loadable kernel modules or device drivers into an operating system to manipulate core functionality, intercept data, and establish deep persistence within targeted environments.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Boot or Logon Autostart Execution",
        "Kernel Modules and Extensions"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-80350d80",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-re-opened-applications-4dd4df07",
      "code": "Re-opened Applications",
      "value": "Re-opened Applications",
      "name": "Re-opened Applications",
      "definition": "Text about the persistence mechanism where adversaries ensure unauthorized code executes by leveraging platform features designed to re-open applications or windows previously active during a prior authenticated user session.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Boot or Logon Autostart Execution",
        "Re-opened Applications"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-80350d80",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-winlogon-helper-dll-a4209b4f",
      "code": "Winlogon Helper DLL",
      "value": "Winlogon Helper DLL",
      "name": "Winlogon Helper DLL",
      "definition": "Text about Winlogon Helper DLL involves adversaries modifying Windows registry keys to load malicious dynamic link libraries during the user login process, thereby achieving system persistence and privilege execution upon system startup.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Boot or Logon Autostart Execution",
        "Winlogon Helper DLL"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-80350d80",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-security-support-provider-1e5bf227",
      "code": "Security Support Provider",
      "value": "Security Support Provider",
      "name": "Security Support Provider",
      "definition": "Text about Security Support Provider manipulation refers to the unauthorized installation of malicious service libraries into the local authentication authority, facilitating immediate interception and exfiltration of clear-text credentials during system login events.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Boot or Logon Autostart Execution",
        "Security Support Provider"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-80350d80",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-registry-run-keys-startup-folder-e19d0d32",
      "code": "Registry Run Keys / Startup Folder",
      "value": "Registry Run Keys / Startup Folder",
      "name": "Registry Run Keys / Startup Folder",
      "definition": "Text about adversaries achieving persistence by modifying specific Windows Registry locations and system startup directories, ensuring their malicious programs execute automatically whenever an operating system user logs into the affected host.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Boot or Logon Autostart Execution",
        "Registry Run Keys / Startup Folder"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-80350d80",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-lsass-driver-f5181d15",
      "code": "LSASS Driver",
      "value": "LSASS Driver",
      "name": "LSASS Driver",
      "definition": "Text about the deployment of malicious kernel-mode drivers designed to bypass security protections while extracting credential material directly from the Local Security Authority Subsystem Service process memory on compromised systems.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Boot or Logon Autostart Execution",
        "LSASS Driver"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-80350d80",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-print-processors-a44db66b",
      "code": "Print Processors",
      "value": "Print Processors",
      "name": "Print Processors",
      "definition": "Text about the unauthorized alteration of print processor configurations to execute persistent payloads, leveraging the inherent service privileges of the Windows print spooler whenever documents are passed to the subsystem.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Boot or Logon Autostart Execution",
        "Print Processors"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-80350d80",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-active-setup-5dcd9e5b",
      "code": "Active Setup",
      "value": "Active Setup",
      "name": "Active Setup",
      "definition": "Text about Active Setup involves the exploitation of a persistent startup mechanism where attackers modify registry values to ensure their malicious code executes automatically during the initialization of user-mode system components.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Boot or Logon Autostart Execution",
        "Active Setup"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-80350d80",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-login-items-1cc9210b",
      "code": "Login Items",
      "value": "Login Items",
      "name": "Login Items",
      "definition": "Text about adversaries configuring operating system startup processes to execute malicious files automatically upon user login, thereby establishing persistent access to the compromised machine across subsequent reboots or user sessions.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Boot or Logon Autostart Execution",
        "Login Items"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-80350d80",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-xdg-autostart-entries-e0be6b6a",
      "code": "XDG Autostart Entries",
      "value": "XDG Autostart Entries",
      "name": "XDG Autostart Entries",
      "definition": "Text about adversaries persisting by placing desktop entry files within specific XDG standard directories, causing malicious applications to execute automatically when a user logs into a Linux desktop environment session.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Boot or Logon Autostart Execution",
        "XDG Autostart Entries"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-80350d80",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-time-providers-cbf22b74",
      "code": "Time Providers",
      "value": "Time Providers",
      "name": "Time Providers",
      "definition": "Text about malicious abuse of registered system components responsible for time synchronization, specifically dynamic link libraries, to alter system clocks and bypass security controls dependent on accurate timekeeping.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Boot or Logon Autostart Execution",
        "Time Providers"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-80350d80",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-authentication-package-cceda209",
      "code": "Authentication Package",
      "value": "Authentication Package",
      "name": "Authentication Package",
      "definition": "Text about authentication packages refers to the exploitation of system-level DLL registration mechanisms enabling adversaries to inject malicious logic into the Local Security Authority process for capturing credentials or maintaining stealthy persistence.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Boot or Logon Autostart Execution",
        "Authentication Package"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-80350d80",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-port-monitors-50a61849",
      "code": "Port Monitors",
      "value": "Port Monitors",
      "name": "Port Monitors",
      "definition": "Text about Port Monitors describes cyber adversaries installing malicious print processor or monitor files to hook the Windows spooler, establishing a persistent method for capturing or modifying data sent to printers.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Boot or Logon Autostart Execution",
        "Port Monitors"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-80350d80",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-boot-or-logon-autostart-execution-dd82f72e",
      "code": "Boot or Logon Autostart Execution",
      "value": "Boot or Logon Autostart Execution",
      "name": "Boot or Logon Autostart Execution",
      "definition": "Text about Boot or Logon Autostart Execution describes strategies where adversaries modify specific operating system startup locations to facilitate the automatic execution of malware during subsequent system boots or user sessions.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Privilege Escalation",
        "Boot or Logon Autostart Execution"
      ],
      "parentId": "tactic-privilege-escalation-dc3564ae",
      "synthetic": false,
      "childCount": 14,
      "leaf": false
    },
    {
      "id": "subtechnique-shortcut-modification-39bf8a9e",
      "code": "Shortcut Modification",
      "value": "Shortcut Modification",
      "name": "Shortcut Modification",
      "definition": "Text about adversaries targeting shortcut files to redirect their execution paths toward malicious payloads, enabling the automatic launching of unauthorized code whenever a legitimate shortcut is activated by the user.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Boot or Logon Autostart Execution",
        "Shortcut Modification"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-dd82f72e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-kernel-modules-and-extensions-df8f6d02",
      "code": "Kernel Modules and Extensions",
      "value": "Kernel Modules and Extensions",
      "name": "Kernel Modules and Extensions",
      "definition": "Text about the clandestine insertion of unauthorized loadable kernel modules or device drivers into an operating system to manipulate core functionality, intercept data, and establish deep persistence within targeted environments.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Boot or Logon Autostart Execution",
        "Kernel Modules and Extensions"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-dd82f72e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-re-opened-applications-0c51c6fb",
      "code": "Re-opened Applications",
      "value": "Re-opened Applications",
      "name": "Re-opened Applications",
      "definition": "Text about the persistence mechanism where adversaries ensure unauthorized code executes by leveraging platform features designed to re-open applications or windows previously active during a prior authenticated user session.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Boot or Logon Autostart Execution",
        "Re-opened Applications"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-dd82f72e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-winlogon-helper-dll-80cf92b3",
      "code": "Winlogon Helper DLL",
      "value": "Winlogon Helper DLL",
      "name": "Winlogon Helper DLL",
      "definition": "Text about Winlogon Helper DLL involves adversaries modifying Windows registry keys to load malicious dynamic link libraries during the user login process, thereby achieving system persistence and privilege execution upon system startup.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Boot or Logon Autostart Execution",
        "Winlogon Helper DLL"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-dd82f72e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-security-support-provider-c42c948b",
      "code": "Security Support Provider",
      "value": "Security Support Provider",
      "name": "Security Support Provider",
      "definition": "Text about Security Support Provider manipulation refers to the unauthorized installation of malicious service libraries into the local authentication authority, facilitating immediate interception and exfiltration of clear-text credentials during system login events.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Boot or Logon Autostart Execution",
        "Security Support Provider"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-dd82f72e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-registry-run-keys-startup-folder-3a3ddac9",
      "code": "Registry Run Keys / Startup Folder",
      "value": "Registry Run Keys / Startup Folder",
      "name": "Registry Run Keys / Startup Folder",
      "definition": "Text about adversaries achieving persistence by modifying specific Windows Registry locations and system startup directories, ensuring their malicious programs execute automatically whenever an operating system user logs into the affected host.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Boot or Logon Autostart Execution",
        "Registry Run Keys / Startup Folder"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-dd82f72e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-lsass-driver-8f1f9e1e",
      "code": "LSASS Driver",
      "value": "LSASS Driver",
      "name": "LSASS Driver",
      "definition": "Text about the deployment of malicious kernel-mode drivers designed to bypass security protections while extracting credential material directly from the Local Security Authority Subsystem Service process memory on compromised systems.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Boot or Logon Autostart Execution",
        "LSASS Driver"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-dd82f72e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-print-processors-9fb44c2a",
      "code": "Print Processors",
      "value": "Print Processors",
      "name": "Print Processors",
      "definition": "Text about the unauthorized alteration of print processor configurations to execute persistent payloads, leveraging the inherent service privileges of the Windows print spooler whenever documents are passed to the subsystem.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Boot or Logon Autostart Execution",
        "Print Processors"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-dd82f72e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-active-setup-e8634ac0",
      "code": "Active Setup",
      "value": "Active Setup",
      "name": "Active Setup",
      "definition": "Text about Active Setup involves the exploitation of a persistent startup mechanism where attackers modify registry values to ensure their malicious code executes automatically during the initialization of user-mode system components.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Boot or Logon Autostart Execution",
        "Active Setup"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-dd82f72e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-login-items-5510b413",
      "code": "Login Items",
      "value": "Login Items",
      "name": "Login Items",
      "definition": "Text about adversaries configuring operating system startup processes to execute malicious files automatically upon user login, thereby establishing persistent access to the compromised machine across subsequent reboots or user sessions.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Boot or Logon Autostart Execution",
        "Login Items"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-dd82f72e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-xdg-autostart-entries-dd59968e",
      "code": "XDG Autostart Entries",
      "value": "XDG Autostart Entries",
      "name": "XDG Autostart Entries",
      "definition": "Text about adversaries persisting by placing desktop entry files within specific XDG standard directories, causing malicious applications to execute automatically when a user logs into a Linux desktop environment session.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Boot or Logon Autostart Execution",
        "XDG Autostart Entries"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-dd82f72e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-time-providers-a0a44179",
      "code": "Time Providers",
      "value": "Time Providers",
      "name": "Time Providers",
      "definition": "Text about malicious abuse of registered system components responsible for time synchronization, specifically dynamic link libraries, to alter system clocks and bypass security controls dependent on accurate timekeeping.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Boot or Logon Autostart Execution",
        "Time Providers"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-dd82f72e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-authentication-package-0876ea70",
      "code": "Authentication Package",
      "value": "Authentication Package",
      "name": "Authentication Package",
      "definition": "Text about authentication packages refers to the exploitation of system-level DLL registration mechanisms enabling adversaries to inject malicious logic into the Local Security Authority process for capturing credentials or maintaining stealthy persistence.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Boot or Logon Autostart Execution",
        "Authentication Package"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-dd82f72e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-port-monitors-f5d43242",
      "code": "Port Monitors",
      "value": "Port Monitors",
      "name": "Port Monitors",
      "definition": "Text about Port Monitors describes cyber adversaries installing malicious print processor or monitor files to hook the Windows spooler, establishing a persistent method for capturing or modifying data sent to printers.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Boot or Logon Autostart Execution",
        "Port Monitors"
      ],
      "parentId": "technique-boot-or-logon-autostart-execution-dd82f72e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-weaken-encryption-a355f204",
      "code": "Weaken Encryption",
      "value": "Weaken Encryption",
      "name": "Weaken Encryption",
      "definition": "Text about malicious modifications or configurations intended to downgrade the security provided by encryption standards, allowing adversaries to bypass data protection measures and gain unauthorized visibility into communications.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Weaken Encryption"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 2,
      "leaf": false
    },
    {
      "id": "subtechnique-reduce-key-space-ede5be8b",
      "code": "Reduce Key Space",
      "value": "Reduce Key Space",
      "name": "Reduce Key Space",
      "definition": "Text about techniques where attackers force a target system to utilize weaker, predictable keys, essentially narrowing the possible key space to allow brute-force methods to achieve successful adversarial outcomes.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Weaken Encryption",
        "Reduce Key Space"
      ],
      "parentId": "technique-weaken-encryption-a355f204",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-disable-crypto-hardware-93223394",
      "code": "Disable Crypto Hardware",
      "value": "Disable Crypto Hardware",
      "name": "Disable Crypto Hardware",
      "definition": "Text about the strategic disabling of specialized hardware security modules or cryptographic accelerators, directly hindering the system capability to perform secure hashing, signing, or encryption tasks during malicious operational impact.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Weaken Encryption",
        "Disable Crypto Hardware"
      ],
      "parentId": "technique-weaken-encryption-a355f204",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-service-stop-45014210",
      "code": "Service Stop",
      "value": "Service Stop",
      "name": "Service Stop",
      "definition": "Text about malicious actors forcing the cessation of active operating system services to interfere with security monitoring capabilities, degrade system reliability, or render critical software components unavailable to users.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Impact",
        "Service Stop"
      ],
      "parentId": "tactic-impact-62036a70",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-device-driver-discovery-593fa833",
      "code": "Device Driver Discovery",
      "value": "Device Driver Discovery",
      "name": "Device Driver Discovery",
      "definition": "Text about adversaries reconnaissance activities focused on identifying presence, versions, and configurations of installed device drivers to determine susceptibility to known kernel-level exploits or potential pathways for unauthorized system control.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "Device Driver Discovery"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-hide-artifacts-29bd3ec0",
      "code": "Hide Artifacts",
      "value": "Hide Artifacts",
      "name": "Hide Artifacts",
      "definition": "Text about the intentional concealment of artifacts, including registry keys and temporary files, that document a threat actor’s unauthorized presence or operational movements within a compromised enterprise computing environment.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Hide Artifacts"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 12,
      "leaf": false
    },
    {
      "id": "subtechnique-hidden-window-cab7d74a",
      "code": "Hidden Window",
      "value": "Hidden Window",
      "name": "Hidden Window",
      "definition": "Text about Hidden Window refers to attackers concealing the operational interface of malicious software, ensuring GUI elements remain invisible to user detection while background processes continue to perform unauthorized operations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Hide Artifacts",
        "Hidden Window"
      ],
      "parentId": "technique-hide-artifacts-29bd3ec0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-ignore-process-interrupts-e0bfdaa5",
      "code": "Ignore Process Interrupts",
      "value": "Ignore Process Interrupts",
      "name": "Ignore Process Interrupts",
      "definition": "Text about malicious software deliberately ignoring hardware or software interrupt signals to maintain execution continuity, specifically designed to resist standard termination procedures invoked by operating systems or security monitoring software.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Hide Artifacts",
        "Ignore Process Interrupts"
      ],
      "parentId": "technique-hide-artifacts-29bd3ec0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-hidden-users-cc599c13",
      "code": "Hidden Users",
      "value": "Hidden Users",
      "name": "Hidden Users",
      "definition": "Text about adversaries leveraging account concealment methods to mask unauthorized user profiles from legitimate administrative oversight, thereby maintaining persistent access within a compromised system without triggering established user management alerts.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Hide Artifacts",
        "Hidden Users"
      ],
      "parentId": "technique-hide-artifacts-29bd3ec0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-file-path-exclusions-ebf51372",
      "code": "File/Path Exclusions",
      "value": "File/Path Exclusions",
      "name": "File/Path Exclusions",
      "definition": "Text about the manipulation of security software exclusion policies by actors to prevent endpoint protection mechanisms from scanning specific directories, enabling the silent operation of malicious tools and persistent payloads.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Hide Artifacts",
        "File/Path Exclusions"
      ],
      "parentId": "technique-hide-artifacts-29bd3ec0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-email-hiding-rules-2ed94928",
      "code": "Email Hiding Rules",
      "value": "Email Hiding Rules",
      "name": "Email Hiding Rules",
      "definition": "Text about threat actors manipulating automated sorting and handling rules within email applications to hide, archive, or immediately delete incoming messages, suppressing awareness of unauthorized activity within the compromised account.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Hide Artifacts",
        "Email Hiding Rules"
      ],
      "parentId": "technique-hide-artifacts-29bd3ec0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-resource-forking-dfd5b1ff",
      "code": "Resource Forking",
      "value": "Resource Forking",
      "name": "Resource Forking",
      "definition": "Text about adversaries utilizing legitimate system resource forks to store malicious code or data within a file, allowing the hidden payload to execute while leaving the primary file appearing untouched.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Hide Artifacts",
        "Resource Forking"
      ],
      "parentId": "technique-hide-artifacts-29bd3ec0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-run-virtual-instance-dc4a7e46",
      "code": "Run Virtual Instance",
      "value": "Run Virtual Instance",
      "name": "Run Virtual Instance",
      "definition": "Text about adversaries leveraging virtualization technology to instantiate isolated operating system environments for executing malicious code, providing a layer of abstraction that complicates forensic analysis and security monitoring efforts.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Hide Artifacts",
        "Run Virtual Instance"
      ],
      "parentId": "technique-hide-artifacts-29bd3ec0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-process-argument-spoofing-f60ede45",
      "code": "Process Argument Spoofing",
      "value": "Process Argument Spoofing",
      "name": "Process Argument Spoofing",
      "definition": "Text about Process Argument Spoofing explains the method of supplying misleading command line arguments to a target process, causing security monitoring tools to misinterpret the operational nature of the executed system task.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Hide Artifacts",
        "Process Argument Spoofing"
      ],
      "parentId": "technique-hide-artifacts-29bd3ec0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-hidden-files-and-directories-308f2db0",
      "code": "Hidden Files and Directories",
      "value": "Hidden Files and Directories",
      "name": "Hidden Files and Directories",
      "definition": "Text about adversaries marking files or directories as hidden from the operating system user interface to evade detection and prevent discovery of malicious artifacts lingering within the targeted file system structure.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Hide Artifacts",
        "Hidden Files and Directories"
      ],
      "parentId": "technique-hide-artifacts-29bd3ec0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-ntfs-file-attributes-528257eb",
      "code": "NTFS File Attributes",
      "value": "NTFS File Attributes",
      "name": "NTFS File Attributes",
      "definition": "Text about NTFS File Attributes covers the adversarial exploitation of specialized file stream features to store hidden, persistent payloads that circumvent standard file inspection mechanisms within the operating environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Hide Artifacts",
        "NTFS File Attributes"
      ],
      "parentId": "technique-hide-artifacts-29bd3ec0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-vba-stomping-e8af18f0",
      "code": "VBA Stomping",
      "value": "VBA Stomping",
      "name": "VBA Stomping",
      "definition": "Text about VBA Stomping identifies a technique where malicious actors decouple the visible VBA source code from the functional P-code within Office files, specifically designed to bypass static signature-based detection and reverse-engineering.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Hide Artifacts",
        "VBA Stomping"
      ],
      "parentId": "technique-hide-artifacts-29bd3ec0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-hidden-file-system-b7d5283b",
      "code": "Hidden File System",
      "value": "Hidden File System",
      "name": "Hidden File System",
      "definition": "Text about adversaries creating hidden storage partitions or utilizing undocumented file system features to maintain persistent, undetected access to sensitive files and executable content separate from the primary, visible logical drive.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Hide Artifacts",
        "Hidden File System"
      ],
      "parentId": "technique-hide-artifacts-29bd3ec0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "tactic-lateral-movement-4cec3f1f",
      "code": "Lateral Movement",
      "value": "Lateral Movement",
      "name": "Lateral Movement",
      "definition": "Text about adversaries methodically expanding their control across internal network segments, utilizing intercepted authentication tokens and remote management protocols to traverse systems from an initial point of network compromise.",
      "level": "tactic",
      "depth": 0,
      "path": [
        "Lateral Movement"
      ],
      "parentId": null,
      "synthetic": false,
      "childCount": 9,
      "leaf": false
    },
    {
      "id": "technique-taint-shared-content-c519fc67",
      "code": "Taint Shared Content",
      "value": "Taint Shared Content",
      "name": "Taint Shared Content",
      "definition": "Text about exploiting shared access mechanisms to inject malicious payloads or data into common files or repositories, forcing downstream systems or users to execute compromised content during routine operational workflows.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Lateral Movement",
        "Taint Shared Content"
      ],
      "parentId": "tactic-lateral-movement-4cec3f1f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-office-application-startup-7fb04d29",
      "code": "Office Application Startup",
      "value": "Office Application Startup",
      "name": "Office Application Startup",
      "definition": "Text about adversaries manipulating the inherent startup routines of office productivity software to execute malicious code, ensuring that attacker-controlled payloads activate whenever the user opens specific desktop productivity suite applications.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Persistence",
        "Office Application Startup"
      ],
      "parentId": "tactic-persistence-4782469e",
      "synthetic": false,
      "childCount": 6,
      "leaf": false
    },
    {
      "id": "subtechnique-office-test-a2b19983",
      "code": "Office Test",
      "value": "Office Test",
      "name": "Office Test",
      "definition": "Text about adversaries abusing the undocumented Office Test registry key to load a malicious DLL that executes automatically whenever an Office application starts, thereby establishing persistence on the compromised host.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Office Application Startup",
        "Office Test"
      ],
      "parentId": "technique-office-application-startup-7fb04d29",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-office-template-macros-fbfd1ff5",
      "code": "Office Template Macros",
      "value": "Office Template Macros",
      "name": "Office Template Macros",
      "definition": "Text about adversaries utilizing manipulated document templates to automatically execute embedded malicious code upon opening, thereby bypassing standard security controls associated with traditional standalone macro-enabled documents during the initial execution phase.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Office Application Startup",
        "Office Template Macros"
      ],
      "parentId": "technique-office-application-startup-7fb04d29",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-outlook-home-page-6ed10121",
      "code": "Outlook Home Page",
      "value": "Outlook Home Page",
      "name": "Outlook Home Page",
      "definition": "Text about adversaries modifying the Outlook home page configuration to execute malicious code remotely upon application startup, ensuring persistence through the inherent rendering capabilities of the Outlook folder home page feature.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Office Application Startup",
        "Outlook Home Page"
      ],
      "parentId": "technique-office-application-startup-7fb04d29",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-outlook-forms-546be2f4",
      "code": "Outlook Forms",
      "value": "Outlook Forms",
      "name": "Outlook Forms",
      "definition": "Text about attackers leveraging the extensibility of Microsoft Outlook forms to attach malicious scripts that execute automatically upon opening or rendering, facilitating unauthorized code execution within the legitimate email client environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Office Application Startup",
        "Outlook Forms"
      ],
      "parentId": "technique-office-application-startup-7fb04d29",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-add-ins-7c9adb6e",
      "code": "Add-ins",
      "value": "Add-ins",
      "name": "Add-ins",
      "definition": "Text about adversaries exploiting application architecture by deploying unauthorized plug-ins or extensions to execute malicious commands, ensure persistent access, and manipulate host application activities without altering the primary system or user.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Office Application Startup",
        "Add-ins"
      ],
      "parentId": "technique-office-application-startup-7fb04d29",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-outlook-rules-ffd6a386",
      "code": "Outlook Rules",
      "value": "Outlook Rules",
      "name": "Outlook Rules",
      "definition": "Text about an adversary exploiting legitimate Outlook email rule functionality to autonomously redirect incoming messages to external accounts, delete specific communications, or move items to hidden folders for persistence.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Office Application Startup",
        "Outlook Rules"
      ],
      "parentId": "technique-office-application-startup-7fb04d29",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-automated-collection-fa74ae4b",
      "code": "Automated Collection",
      "value": "Automated Collection",
      "name": "Automated Collection",
      "definition": "Text about Automated Collection refers to the unauthorized execution of scripts or software tools tasked with systematically searching, copying, and staging sensitive data from file systems for subsequent exfiltration.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Collection",
        "Automated Collection"
      ],
      "parentId": "tactic-collection-30c54a96",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-clipboard-data-daedce20",
      "code": "Clipboard Data",
      "value": "Clipboard Data",
      "name": "Clipboard Data",
      "definition": "Text about adversaries gaining access to the shared system clipboard to exfiltrate sensitive data, passwords, or proprietary information that has been temporarily copied into memory buffers by active users.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Collection",
        "Clipboard Data"
      ],
      "parentId": "tactic-collection-30c54a96",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-system-service-discovery-16499e28",
      "code": "System Service Discovery",
      "value": "System Service Discovery",
      "name": "System Service Discovery",
      "definition": "Text about the enumeration of system-level services to map out the host's background operations, allowing attackers to identify targets for manipulation or exploitation within the compromised computing infrastructure.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "System Service Discovery"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-network-sniffing-a544397d",
      "code": "Network Sniffing",
      "value": "Network Sniffing",
      "name": "Network Sniffing",
      "definition": "Text about adversaries employing sniffing tools to listen to network traffic, allowing them to capture unencrypted data packets transmitted between systems, thereby obtaining sensitive information traveling across the compromised network environment.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Credential Access",
        "Network Sniffing"
      ],
      "parentId": "tactic-credential-access-9c65f4e0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-network-sniffing-5c5068d8",
      "code": "Network Sniffing",
      "value": "Network Sniffing",
      "name": "Network Sniffing",
      "definition": "Text about adversaries employing sniffing tools to listen to network traffic, allowing them to capture unencrypted data packets transmitted between systems, thereby obtaining sensitive information traveling across the compromised network environment.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "Network Sniffing"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-data-from-cloud-storage-9756a967",
      "code": "Data from Cloud Storage",
      "value": "Data from Cloud Storage",
      "name": "Data from Cloud Storage",
      "definition": "Text about malicious actors exploiting misconfigured or compromised cloud storage repositories to locate, gather, and exfiltrate specific data objects directly from the providers hosting the organization's enterprise information assets.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Collection",
        "Data from Cloud Storage"
      ],
      "parentId": "tactic-collection-30c54a96",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-network-share-discovery-d8a94d5b",
      "code": "Network Share Discovery",
      "value": "Network Share Discovery",
      "name": "Network Share Discovery",
      "definition": "Text about adversary activity involving the query and discovery of mapped or accessible network file shares across an infrastructure to determine resource topography, access permissions, and potential targets for unauthorized data retrieval.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "Network Share Discovery"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-peripheral-device-discovery-6894379a",
      "code": "Peripheral Device Discovery",
      "value": "Peripheral Device Discovery",
      "name": "Peripheral Device Discovery",
      "definition": "Text about malicious entities identifying various peripheral hardware connected to a victim system, assessing the inventory of external interfaces and devices available for data exfiltration or potential further exploitation.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "Peripheral Device Discovery"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-system-information-discovery-3804b87e",
      "code": "System Information Discovery",
      "value": "System Information Discovery",
      "name": "System Information Discovery",
      "definition": "Text about unauthorized actors scanning host operating systems for specific version strings, hardware capabilities, and configured security controls to refine their tactical decisions regarding future malicious activity execution.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "System Information Discovery"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "tactic-command-and-control-6b4265ca",
      "code": "Command and Control",
      "value": "Command and Control",
      "name": "Command and Control",
      "definition": "Text about methods used by threat actors to create and sustain covert communication paths for issuing specific commands to malware or compromised systems while evading detection by standard network security mechanisms.",
      "level": "tactic",
      "depth": 0,
      "path": [
        "Command and Control"
      ],
      "parentId": null,
      "synthetic": false,
      "childCount": 18,
      "leaf": false
    },
    {
      "id": "technique-application-layer-protocol-d078bda1",
      "code": "Application Layer Protocol",
      "value": "Application Layer Protocol",
      "name": "Application Layer Protocol",
      "definition": "Text about adversaries directing malicious traffic through standard application protocols to establish communication channels, effectively masking data exfiltration or command directives within authorized service flows to bypass network security monitoring.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Command and Control",
        "Application Layer Protocol"
      ],
      "parentId": "tactic-command-and-control-6b4265ca",
      "synthetic": false,
      "childCount": 5,
      "leaf": false
    },
    {
      "id": "subtechnique-file-transfer-protocols-896894a9",
      "code": "File Transfer Protocols",
      "value": "File Transfer Protocols",
      "name": "File Transfer Protocols",
      "definition": "Text about adversaries executing unauthorized data exfiltration or movement operations by manipulating common network protocols designed for file transfers, effectively bypassing standard security monitoring controls through permitted organizational communication channels.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Command and Control",
        "Application Layer Protocol",
        "File Transfer Protocols"
      ],
      "parentId": "technique-application-layer-protocol-d078bda1",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-dns-ee6bf5c6",
      "code": "DNS",
      "value": "DNS",
      "name": "DNS",
      "definition": "Text about adversaries leveraging the Domain Name System protocol to facilitate command and control, data exfiltration, or infrastructure communications by embedding malicious traffic within standard network domain resolution queries and responses.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Command and Control",
        "Application Layer Protocol",
        "DNS"
      ],
      "parentId": "technique-application-layer-protocol-d078bda1",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-publish-subscribe-protocols-ae9b9ca5",
      "code": "Publish/Subscribe Protocols",
      "value": "Publish/Subscribe Protocols",
      "name": "Publish/Subscribe Protocols",
      "definition": "Text about exploiting distributed messaging frameworks by publishing malicious payloads to subscriber channels, allowing unauthorized actors to direct operations and transfer stolen information across network segments using standard message protocols.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Command and Control",
        "Application Layer Protocol",
        "Publish/Subscribe Protocols"
      ],
      "parentId": "technique-application-layer-protocol-d078bda1",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-mail-protocols-c0976703",
      "code": "Mail Protocols",
      "value": "Mail Protocols",
      "name": "Mail Protocols",
      "definition": "Text about adversaries who manipulate electronic mail transport protocols to establish undisclosed communication paths, facilitating remote command execution and unauthorized data extraction within compromised systems by leveraging legitimate mail server transit.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Command and Control",
        "Application Layer Protocol",
        "Mail Protocols"
      ],
      "parentId": "technique-application-layer-protocol-d078bda1",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-web-protocols-71edcc9c",
      "code": "Web Protocols",
      "value": "Web Protocols",
      "name": "Web Protocols",
      "definition": "Text about the strategic misuse of widely adopted application-level standards to facilitate persistent unauthorized communication within compromised environments, camouflaging malicious data exfiltration as routine, expected network service queries.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Command and Control",
        "Application Layer Protocol",
        "Web Protocols"
      ],
      "parentId": "technique-application-layer-protocol-d078bda1",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-scheduled-task-job-7019a73b",
      "code": "Scheduled Task/Job",
      "value": "Scheduled Task/Job",
      "name": "Scheduled Task/Job",
      "definition": "Text about malicious actors utilizing system-level job scheduling features to trigger the execution of unauthorized scripts, binaries, or commands at specific intervals, ensuring persistence or facilitating ongoing operational objectives.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Execution",
        "Scheduled Task/Job"
      ],
      "parentId": "tactic-execution-6d525b71",
      "synthetic": false,
      "childCount": 5,
      "leaf": false
    },
    {
      "id": "subtechnique-cron-7fed3ee9",
      "code": "Cron",
      "value": "Cron",
      "name": "Cron",
      "definition": "Text about Cron involves leveraging standard Unix job scheduling utilities to execute malicious scripts or commands periodically, allowing attackers to maintain a foothold and perform recurring operations on systems.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Execution",
        "Scheduled Task/Job",
        "Cron"
      ],
      "parentId": "technique-scheduled-task-job-7019a73b",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-scheduled-task-521dff60",
      "code": "Scheduled Task",
      "value": "Scheduled Task",
      "name": "Scheduled Task",
      "definition": "Text about malicious entities leveraging integrated operating system job scheduling capabilities to ensure designated payloads execute automatically at recurring time intervals or in response to specific system state change events.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Execution",
        "Scheduled Task/Job",
        "Scheduled Task"
      ],
      "parentId": "technique-scheduled-task-job-7019a73b",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-systemd-timers-2dbdf684",
      "code": "Systemd Timers",
      "value": "Systemd Timers",
      "name": "Systemd Timers",
      "definition": "Text about adversaries utilizing Linux systemd timer units to configure scheduled execution of persistent malicious tasks by defining specific temporal triggers within service unit files to maintain ongoing system access.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Execution",
        "Scheduled Task/Job",
        "Systemd Timers"
      ],
      "parentId": "technique-scheduled-task-job-7019a73b",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-container-orchestration-job-5544422a",
      "code": "Container Orchestration Job",
      "value": "Container Orchestration Job",
      "name": "Container Orchestration Job",
      "definition": "Text about malicious actors exploiting container orchestration job scheduling features to deploy and execute crafted container images, allowing unauthorized code or persistence mechanisms within an targeted containerized server environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Execution",
        "Scheduled Task/Job",
        "Container Orchestration Job"
      ],
      "parentId": "technique-scheduled-task-job-7019a73b",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-at-ce08e866",
      "code": "At",
      "value": "At",
      "name": "At",
      "definition": "Text about adversaries abusing the at utility (at or at.exe) to schedule the execution of programs or scripts at a specified time, enabling execution, persistence, or privilege escalation.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Execution",
        "Scheduled Task/Job",
        "At"
      ],
      "parentId": "technique-scheduled-task-job-7019a73b",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-scheduled-task-job-5fe97a1a",
      "code": "Scheduled Task/Job",
      "value": "Scheduled Task/Job",
      "name": "Scheduled Task/Job",
      "definition": "Text about malicious actors utilizing system-level job scheduling features to trigger the execution of unauthorized scripts, binaries, or commands at specific intervals, ensuring persistence or facilitating ongoing operational objectives.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Persistence",
        "Scheduled Task/Job"
      ],
      "parentId": "tactic-persistence-4782469e",
      "synthetic": false,
      "childCount": 5,
      "leaf": false
    },
    {
      "id": "subtechnique-cron-d9d97f95",
      "code": "Cron",
      "value": "Cron",
      "name": "Cron",
      "definition": "Text about Cron involves leveraging standard Unix job scheduling utilities to execute malicious scripts or commands periodically, allowing attackers to maintain a foothold and perform recurring operations on systems.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Scheduled Task/Job",
        "Cron"
      ],
      "parentId": "technique-scheduled-task-job-5fe97a1a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-scheduled-task-9403fd7a",
      "code": "Scheduled Task",
      "value": "Scheduled Task",
      "name": "Scheduled Task",
      "definition": "Text about malicious entities leveraging integrated operating system job scheduling capabilities to ensure designated payloads execute automatically at recurring time intervals or in response to specific system state change events.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Scheduled Task/Job",
        "Scheduled Task"
      ],
      "parentId": "technique-scheduled-task-job-5fe97a1a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-systemd-timers-7b0492ae",
      "code": "Systemd Timers",
      "value": "Systemd Timers",
      "name": "Systemd Timers",
      "definition": "Text about adversaries utilizing Linux systemd timer units to configure scheduled execution of persistent malicious tasks by defining specific temporal triggers within service unit files to maintain ongoing system access.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Scheduled Task/Job",
        "Systemd Timers"
      ],
      "parentId": "technique-scheduled-task-job-5fe97a1a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-container-orchestration-job-53d98e2c",
      "code": "Container Orchestration Job",
      "value": "Container Orchestration Job",
      "name": "Container Orchestration Job",
      "definition": "Text about malicious actors exploiting container orchestration job scheduling features to deploy and execute crafted container images, allowing unauthorized code or persistence mechanisms within an targeted containerized server environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Scheduled Task/Job",
        "Container Orchestration Job"
      ],
      "parentId": "technique-scheduled-task-job-5fe97a1a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-at-94ebca8f",
      "code": "At",
      "value": "At",
      "name": "At",
      "definition": "Text about adversaries abusing the at utility (at or at.exe) to schedule the execution of programs or scripts at a specified time, enabling execution, persistence, or privilege escalation.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Scheduled Task/Job",
        "At"
      ],
      "parentId": "technique-scheduled-task-job-5fe97a1a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-scheduled-task-job-14efe773",
      "code": "Scheduled Task/Job",
      "value": "Scheduled Task/Job",
      "name": "Scheduled Task/Job",
      "definition": "Text about malicious actors utilizing system-level job scheduling features to trigger the execution of unauthorized scripts, binaries, or commands at specific intervals, ensuring persistence or facilitating ongoing operational objectives.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Privilege Escalation",
        "Scheduled Task/Job"
      ],
      "parentId": "tactic-privilege-escalation-dc3564ae",
      "synthetic": false,
      "childCount": 5,
      "leaf": false
    },
    {
      "id": "subtechnique-cron-332953c7",
      "code": "Cron",
      "value": "Cron",
      "name": "Cron",
      "definition": "Text about Cron involves leveraging standard Unix job scheduling utilities to execute malicious scripts or commands periodically, allowing attackers to maintain a foothold and perform recurring operations on systems.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Scheduled Task/Job",
        "Cron"
      ],
      "parentId": "technique-scheduled-task-job-14efe773",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-scheduled-task-65c86c29",
      "code": "Scheduled Task",
      "value": "Scheduled Task",
      "name": "Scheduled Task",
      "definition": "Text about malicious entities leveraging integrated operating system job scheduling capabilities to ensure designated payloads execute automatically at recurring time intervals or in response to specific system state change events.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Scheduled Task/Job",
        "Scheduled Task"
      ],
      "parentId": "technique-scheduled-task-job-14efe773",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-systemd-timers-f7b9ec41",
      "code": "Systemd Timers",
      "value": "Systemd Timers",
      "name": "Systemd Timers",
      "definition": "Text about adversaries utilizing Linux systemd timer units to configure scheduled execution of persistent malicious tasks by defining specific temporal triggers within service unit files to maintain ongoing system access.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Scheduled Task/Job",
        "Systemd Timers"
      ],
      "parentId": "technique-scheduled-task-job-14efe773",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-container-orchestration-job-602e8b87",
      "code": "Container Orchestration Job",
      "value": "Container Orchestration Job",
      "name": "Container Orchestration Job",
      "definition": "Text about malicious actors exploiting container orchestration job scheduling features to deploy and execute crafted container images, allowing unauthorized code or persistence mechanisms within an targeted containerized server environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Scheduled Task/Job",
        "Container Orchestration Job"
      ],
      "parentId": "technique-scheduled-task-job-14efe773",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-at-2414a762",
      "code": "At",
      "value": "At",
      "name": "At",
      "definition": "Text about adversaries abusing the at utility (at or at.exe) to schedule the execution of programs or scripts at a specified time, enabling execution, persistence, or privilege escalation.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Scheduled Task/Job",
        "At"
      ],
      "parentId": "technique-scheduled-task-job-14efe773",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-browser-extensions-69ec2fb1",
      "code": "Browser Extensions",
      "value": "Browser Extensions",
      "name": "Browser Extensions",
      "definition": "Text about adversaries installing or modifying malicious browser extensions to gain persistent access, intercept data, capture user credentials, or execute unauthorized code within the context of a compromised web browser session.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Persistence",
        "Browser Extensions"
      ],
      "parentId": "tactic-persistence-4782469e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-native-api-859a3d94",
      "code": "Native API",
      "value": "Native API",
      "name": "Native API",
      "definition": "Text about executing malicious processes via direct invocation of privileged system service interfaces, circumventing standard API layers to perform covert actions that remain invisible to conventional security oversight mechanisms.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Execution",
        "Native API"
      ],
      "parentId": "tactic-execution-6d525b71",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-indirect-command-execution-7b5dfd43",
      "code": "Indirect Command Execution",
      "value": "Indirect Command Execution",
      "name": "Indirect Command Execution",
      "definition": "Text about threat actors leveraging existing system interpreters or utilities to execute unauthorized commands, effectively abusing these legitimate components to facilitate malicious code execution while bypassing common behavioral detection security controls.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Indirect Command Execution"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-replication-through-removable-media-466b3c75",
      "code": "Replication Through Removable Media",
      "value": "Replication Through Removable Media",
      "name": "Replication Through Removable Media",
      "definition": "Text about adversaries utilizing portable storage devices to propagate malicious software across isolated or air-gapped segments by automatically executing payload components or manipulating file associations when connected to target systems.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Lateral Movement",
        "Replication Through Removable Media"
      ],
      "parentId": "tactic-lateral-movement-4cec3f1f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-replication-through-removable-media-81251dcf",
      "code": "Replication Through Removable Media",
      "value": "Replication Through Removable Media",
      "name": "Replication Through Removable Media",
      "definition": "Text about adversaries utilizing portable storage devices to propagate malicious software across isolated or air-gapped segments by automatically executing payload components or manipulating file associations when connected to target systems.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Initial Access",
        "Replication Through Removable Media"
      ],
      "parentId": "tactic-initial-access-a0f45034",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-data-from-local-system-23b39bfa",
      "code": "Data from Local System",
      "value": "Data from Local System",
      "name": "Data from Local System",
      "definition": "Text about adversaries gathering sensitive information residing on a compromised host, capturing critical files, databases, or user data directly from the local file system to achieve unauthorized collection of valuable intelligence assets.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Collection",
        "Data from Local System"
      ],
      "parentId": "tactic-collection-30c54a96",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-deobfuscate-decode-files-or-information-0c3fcac3",
      "code": "Deobfuscate/Decode Files or Information",
      "value": "Deobfuscate/Decode Files or Information",
      "name": "Deobfuscate/Decode Files or Information",
      "definition": "Text about adversaries converting obfuscated or encoded malicious artifacts back to plaintext or executable machine code, facilitating the recovery of essential command-and-control instructions or secret system configuration parameters.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Deobfuscate/Decode Files or Information"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-impair-defenses-640d2708",
      "code": "Impair Defenses",
      "value": "Impair Defenses",
      "name": "Impair Defenses",
      "definition": "Text about the strategic manipulation or disabling of system-level security controls, monitoring services, and auditing configurations, intended to create operational gaps that adversaries exploit to successfully execute further malicious activities.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Impair Defenses"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 11,
      "leaf": false
    },
    {
      "id": "subtechnique-impair-command-history-logging-c691cb6a",
      "code": "Impair Command History Logging",
      "value": "Impair Command History Logging",
      "name": "Impair Command History Logging",
      "definition": "Text about attackers disabling, modifying, or clearing the persistent logging of terminal command history files and environment variables to obscure malicious activity and prevent forensic reconstruction of specific operator behavioral patterns.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Impair Defenses",
        "Impair Command History Logging"
      ],
      "parentId": "technique-impair-defenses-640d2708",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-disable-or-modify-system-firewall-ff82b0a9",
      "code": "Disable or Modify System Firewall",
      "value": "Disable or Modify System Firewall",
      "name": "Disable or Modify System Firewall",
      "definition": "Text about the intentional deactivation or re-configuration of system-level firewall software by threat actors, aiming to bypass established security enforcement points and maintain reliable network access during operations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Impair Defenses",
        "Disable or Modify System Firewall"
      ],
      "parentId": "technique-impair-defenses-640d2708",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-disable-windows-event-logging-e07507f8",
      "code": "Disable Windows Event Logging",
      "value": "Disable Windows Event Logging",
      "name": "Disable Windows Event Logging",
      "definition": "Text about attackers suppressing the operational functions of the Windows Event Log service to prevent the persistent recording of security-relevant system activity, effectively masking their ongoing presence and maneuverings.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Impair Defenses",
        "Disable Windows Event Logging"
      ],
      "parentId": "technique-impair-defenses-640d2708",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-disable-or-modify-tools-fa3b0365",
      "code": "Disable or Modify Tools",
      "value": "Disable or Modify Tools",
      "name": "Disable or Modify Tools",
      "definition": "Text about adversaries targeting specific security software to disable or alter its configuration, directly degrading the visibility of defenders and preventing the detection or disruption of unauthorized system-level behaviors.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Impair Defenses",
        "Disable or Modify Tools"
      ],
      "parentId": "technique-impair-defenses-640d2708",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-indicator-blocking-228effa4",
      "code": "Indicator Blocking",
      "value": "Indicator Blocking",
      "name": "Indicator Blocking",
      "definition": "Text about unauthorized interference with automated security systems by silencing alerts, dropping suspicious network packets, or withholding indicator data to ensure cyberattack operations remain undetected by defensive analysis software.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Impair Defenses",
        "Indicator Blocking"
      ],
      "parentId": "technique-impair-defenses-640d2708",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-disable-or-modify-linux-audit-system-e382c24c",
      "code": "Disable or Modify Linux Audit System",
      "value": "Disable or Modify Linux Audit System",
      "name": "Disable or Modify Linux Audit System",
      "definition": "Text about the unauthorized alteration or suppression of Linux audit subsystem functionality by threat actors to prevent the recording of system-level activities and security events throughout a compromised environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Impair Defenses",
        "Disable or Modify Linux Audit System"
      ],
      "parentId": "technique-impair-defenses-640d2708",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-spoof-security-alerting-6f9ee07d",
      "code": "Spoof Security Alerting",
      "value": "Spoof Security Alerting",
      "name": "Spoof Security Alerting",
      "definition": "Text about adversaries spoofing security tools into reporting false benign or healthy status messages to defenders, masking the impairment of protections and concealing malicious activity from monitoring personnel.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Impair Defenses",
        "Spoof Security Alerting"
      ],
      "parentId": "technique-impair-defenses-640d2708",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-disable-or-modify-cloud-logs-0c892062",
      "code": "Disable or Modify Cloud Logs",
      "value": "Disable or Modify Cloud Logs",
      "name": "Disable or Modify Cloud Logs",
      "definition": "Text about the unauthorized alteration or deactivation of cloud-based logging mechanisms by adversaries aiming to obstruct visibility, manipulate captured telemetry data, or erase forensic artifacts related to their operational activities.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Impair Defenses",
        "Disable or Modify Cloud Logs"
      ],
      "parentId": "technique-impair-defenses-640d2708",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-downgrade-attack-ed74ca5e",
      "code": "Downgrade Attack",
      "value": "Downgrade Attack",
      "name": "Downgrade Attack",
      "definition": "Text about adversaries manipulating system settings or protocol handshakes to bypass modern security enhancements, compelling a transition to insecure operational modes that align with outdated, vulnerable versions of targeted software components.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Impair Defenses",
        "Downgrade Attack"
      ],
      "parentId": "technique-impair-defenses-640d2708",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-disable-or-modify-cloud-firewall-bf7bacda",
      "code": "Disable or Modify Cloud Firewall",
      "value": "Disable or Modify Cloud Firewall",
      "name": "Disable or Modify Cloud Firewall",
      "definition": "Text about the unauthorized modification or complete cessation of cloud firewall rules intended to weaken network perimeters and allow malicious traffic patterns to permeate protected cloud-hosted service infrastructures.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Impair Defenses",
        "Disable or Modify Cloud Firewall"
      ],
      "parentId": "technique-impair-defenses-640d2708",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-safe-mode-boot-68a05d7d",
      "code": "Safe Mode Boot",
      "value": "Safe Mode Boot",
      "name": "Safe Mode Boot",
      "definition": "Text about exploiting configuration settings to initiate a restricted diagnostic boot sequence that suppresses security control execution, allowing adversaries to modify system files and ensure persistence without triggering defensive alerts.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Impair Defenses",
        "Safe Mode Boot"
      ],
      "parentId": "technique-impair-defenses-640d2708",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-supply-chain-compromise-de18596d",
      "code": "Supply Chain Compromise",
      "value": "Supply Chain Compromise",
      "name": "Supply Chain Compromise",
      "definition": "Text about exploiting established pathways between vendors and organizations to subvert software updates, source code, or hardware production pipelines, enabling the distribution of malware to unsuspecting downstream customer network environments.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Initial Access",
        "Supply Chain Compromise"
      ],
      "parentId": "tactic-initial-access-a0f45034",
      "synthetic": false,
      "childCount": 3,
      "leaf": false
    },
    {
      "id": "subtechnique-compromise-software-dependencies-and-development-tools-fb146886",
      "code": "Compromise Software Dependencies and Development Tools",
      "value": "Compromise Software Dependencies and Development Tools",
      "name": "Compromise Software Dependencies and Development Tools",
      "definition": "Text about attackers gaining unauthorized access to code repositories, build systems, or package managers to alter source materials or supply chains, ensuring that compiled software inevitably contains malicious, covert functionality.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Initial Access",
        "Supply Chain Compromise",
        "Compromise Software Dependencies and Development Tools"
      ],
      "parentId": "technique-supply-chain-compromise-de18596d",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-compromise-software-supply-chain-3ded2ec7",
      "code": "Compromise Software Supply Chain",
      "value": "Compromise Software Supply Chain",
      "name": "Compromise Software Supply Chain",
      "definition": "Text about compromising the integrity of supplier software distributions to facilitate unauthorized access, centering on the injection of malicious code into products before deployment within the end user's systems.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Initial Access",
        "Supply Chain Compromise",
        "Compromise Software Supply Chain"
      ],
      "parentId": "technique-supply-chain-compromise-de18596d",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-compromise-hardware-supply-chain-a945cb00",
      "code": "Compromise Hardware Supply Chain",
      "value": "Compromise Hardware Supply Chain",
      "name": "Compromise Hardware Supply Chain",
      "definition": "Text about illicitly altering the hardware fabrication process or supply logistics to introduce unauthorized circuitry or compromised firmware, creating systemic vulnerabilities that persist once the compromised hardware becomes operational.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Initial Access",
        "Supply Chain Compromise",
        "Compromise Hardware Supply Chain"
      ],
      "parentId": "technique-supply-chain-compromise-de18596d",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-exploit-public-facing-application-90be72ec",
      "code": "Exploit Public-Facing Application",
      "value": "Exploit Public-Facing Application",
      "name": "Exploit Public-Facing Application",
      "definition": "Text about exploiting critical vulnerabilities inside public-facing enterprise applications to gain initial unauthorized network access, enabling adversaries to conduct further malicious actions by leveraging these flawed entry points for system compromise.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Initial Access",
        "Exploit Public-Facing Application"
      ],
      "parentId": "tactic-initial-access-a0f45034",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-steal-or-forge-kerberos-tickets-81a56c26",
      "code": "Steal or Forge Kerberos Tickets",
      "value": "Steal or Forge Kerberos Tickets",
      "name": "Steal or Forge Kerberos Tickets",
      "definition": "Text about attackers bypassing authentication controls by stealing legitimate Kerberos tickets or forging fake tickets through compromised KDC secrets to deceive domain infrastructure and gain unauthorized access to network-connected host resources.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Credential Access",
        "Steal or Forge Kerberos Tickets"
      ],
      "parentId": "tactic-credential-access-9c65f4e0",
      "synthetic": false,
      "childCount": 5,
      "leaf": false
    },
    {
      "id": "subtechnique-kerberoasting-cb47421f",
      "code": "Kerberoasting",
      "value": "Kerberoasting",
      "name": "Kerberoasting",
      "definition": "Text about Kerberoasting refers to adversaries targeting service accounts by requesting Kerberos service tickets, which are subsequently subjected to offline attacks to recover the plaintext passwords associated with those particular accounts.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Steal or Forge Kerberos Tickets",
        "Kerberoasting"
      ],
      "parentId": "technique-steal-or-forge-kerberos-tickets-81a56c26",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-silver-ticket-52864630",
      "code": "Silver Ticket",
      "value": "Silver Ticket",
      "name": "Silver Ticket",
      "definition": "Text about adversaries utilizing stolen service account hashes to forge Kerberos service tickets, enabling unauthorized access to specific services by deceiving the service into accepting illegitimate authentication requests.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Steal or Forge Kerberos Tickets",
        "Silver Ticket"
      ],
      "parentId": "technique-steal-or-forge-kerberos-tickets-81a56c26",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-ccache-files-2761af81",
      "code": "Ccache Files",
      "value": "Ccache Files",
      "name": "Ccache Files",
      "definition": "Text about Ccache Files describes the malicious retrieval of local Kerberos credential cache files that hold authentication data, enabling adversaries to leverage stored tickets to impersonate valid users within authenticated network environments.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Steal or Forge Kerberos Tickets",
        "Ccache Files"
      ],
      "parentId": "technique-steal-or-forge-kerberos-tickets-81a56c26",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-as-rep-roasting-c68c7512",
      "code": "AS-REP Roasting",
      "value": "AS-REP Roasting",
      "name": "AS-REP Roasting",
      "definition": "Text about an intrusion activity involving the discovery of accounts without pre-authentication, obtaining the associated encrypted authentication response from the domain controller, and cracking that offline to reveal user credentials.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Steal or Forge Kerberos Tickets",
        "AS-REP Roasting"
      ],
      "parentId": "technique-steal-or-forge-kerberos-tickets-81a56c26",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-golden-ticket-354d0575",
      "code": "Golden Ticket",
      "value": "Golden Ticket",
      "name": "Golden Ticket",
      "definition": "Text about attackers exploiting the Key Distribution Center service account to generate fraudulent Kerberos Ticket Granting Tickets, which provide indefinite, administrative-level access permissions across the entire compromised Active Directory infrastructure.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Steal or Forge Kerberos Tickets",
        "Golden Ticket"
      ],
      "parentId": "technique-steal-or-forge-kerberos-tickets-81a56c26",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-credentials-from-password-stores-a8a3590a",
      "code": "Credentials from Password Stores",
      "value": "Credentials from Password Stores",
      "name": "Credentials from Password Stores",
      "definition": "Text about the unauthorized recovery of stored credentials directly from local system files, application-specific databases, or integrated password managers used by software to maintain authentication tokens for recurring user access sessions.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Credential Access",
        "Credentials from Password Stores"
      ],
      "parentId": "tactic-credential-access-9c65f4e0",
      "synthetic": false,
      "childCount": 6,
      "leaf": false
    },
    {
      "id": "subtechnique-windows-credential-manager-c395eea9",
      "code": "Windows Credential Manager",
      "value": "Windows Credential Manager",
      "name": "Windows Credential Manager",
      "definition": "Text about Windows Credential Manager concerns the exploitation of built-in credential vaulting mechanisms to harvest stored usernames and passwords, enabling continued access to sensitive information or network resources post-compromise.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Credentials from Password Stores",
        "Windows Credential Manager"
      ],
      "parentId": "technique-credentials-from-password-stores-a8a3590a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-keychain-e1c919c4",
      "code": "Keychain",
      "value": "Keychain",
      "name": "Keychain",
      "definition": "Text about adversaries manipulating the native macOS Keychain infrastructure to programmatically harvest stored sensitive credentials, including passwords and encryption keys, which facilitates privilege escalation and unauthorized access to various encrypted data.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Credentials from Password Stores",
        "Keychain"
      ],
      "parentId": "technique-credentials-from-password-stores-a8a3590a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-password-managers-e9ff79ae",
      "code": "Password Managers",
      "value": "Password Managers",
      "name": "Password Managers",
      "definition": "Text about unauthorized access to configuration files, vault databases, or active session memory utilized by password manager applications to harvest stored credentials from the underlying operating system of compromised hosts.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Credentials from Password Stores",
        "Password Managers"
      ],
      "parentId": "technique-credentials-from-password-stores-a8a3590a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-cloud-secrets-management-stores-6c18d39c",
      "code": "Cloud Secrets Management Stores",
      "value": "Cloud Secrets Management Stores",
      "name": "Cloud Secrets Management Stores",
      "definition": "Text about attackers exploiting the configuration or access controls of cloud-based secrets management stores to exfiltrate database credentials, encryption keys, or service identities necessary for maintaining unauthorized command over target cloud infrastructures.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Credentials from Password Stores",
        "Cloud Secrets Management Stores"
      ],
      "parentId": "technique-credentials-from-password-stores-a8a3590a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-credentials-from-web-browsers-de5710d0",
      "code": "Credentials from Web Browsers",
      "value": "Credentials from Web Browsers",
      "name": "Credentials from Web Browsers",
      "definition": "Text about the unauthorized acquisition of sensitive authentication data retained within the internal storage mechanisms of web browsers, which adversaries harvest to enable account takeover and subsequent network exploitation.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Credentials from Password Stores",
        "Credentials from Web Browsers"
      ],
      "parentId": "technique-credentials-from-password-stores-a8a3590a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-securityd-memory-44ecaa7d",
      "code": "Securityd Memory",
      "value": "Securityd Memory",
      "name": "Securityd Memory",
      "definition": "Text about adversaries manipulating the internal memory state of the macOS securityd daemon to subvert legitimate authentication workflows, enabling credential theft or unauthorized elevation of privileges by modifying system response behaviors.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Credentials from Password Stores",
        "Securityd Memory"
      ],
      "parentId": "technique-credentials-from-password-stores-a8a3590a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "tactic-exfiltration-fcb9fccc",
      "code": "Exfiltration",
      "value": "Exfiltration",
      "name": "Exfiltration",
      "definition": "Text about Exfiltration involves adversaries moving sensitive data from compromised victim systems to an external infrastructure under their control while attempting to evade detection during the unauthorized transfer process.",
      "level": "tactic",
      "depth": 0,
      "path": [
        "Exfiltration"
      ],
      "parentId": null,
      "synthetic": false,
      "childCount": 9,
      "leaf": false
    },
    {
      "id": "technique-exfiltration-over-web-service-ee6f0f54",
      "code": "Exfiltration Over Web Service",
      "value": "Exfiltration Over Web Service",
      "name": "Exfiltration Over Web Service",
      "definition": "Text about exfiltrating sensitive organizational data by uploading stolen records to remote web-based storage or collaboration platforms, effectively concealing transfer activities within the traffic of approved, trusted internet-based services.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Exfiltration",
        "Exfiltration Over Web Service"
      ],
      "parentId": "tactic-exfiltration-fcb9fccc",
      "synthetic": false,
      "childCount": 4,
      "leaf": false
    },
    {
      "id": "subtechnique-exfiltration-to-code-repository-d3a02a12",
      "code": "Exfiltration to Code Repository",
      "value": "Exfiltration to Code Repository",
      "name": "Exfiltration to Code Repository",
      "definition": "Text about attackers abusing code repository services by injecting stolen data into version control systems, allowing for the discreet removal and subsequent retrieval of sensitive materials from the internal network.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Exfiltration",
        "Exfiltration Over Web Service",
        "Exfiltration to Code Repository"
      ],
      "parentId": "technique-exfiltration-over-web-service-ee6f0f54",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-exfiltration-to-text-storage-sites-f3f5d305",
      "code": "Exfiltration to Text Storage Sites",
      "value": "Exfiltration to Text Storage Sites",
      "name": "Exfiltration to Text Storage Sites",
      "definition": "Text about adversaries uploading stolen sensitive data to publicly accessible online text repository services to clandestinely stage information for later retrieval while bypassing standard network security monitoring controls and egress filters.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Exfiltration",
        "Exfiltration Over Web Service",
        "Exfiltration to Text Storage Sites"
      ],
      "parentId": "technique-exfiltration-over-web-service-ee6f0f54",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-exfiltration-to-cloud-storage-9335df7e",
      "code": "Exfiltration to Cloud Storage",
      "value": "Exfiltration to Cloud Storage",
      "name": "Exfiltration to Cloud Storage",
      "definition": "Text about malicious actors bypassing security controls by uploading sensitive corporate data to external, adversary-controlled cloud storage platforms to complete the exfiltration phase of an ongoing unauthorized system intrusion event.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Exfiltration",
        "Exfiltration Over Web Service",
        "Exfiltration to Cloud Storage"
      ],
      "parentId": "technique-exfiltration-over-web-service-ee6f0f54",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-exfiltration-over-webhook-14bfdd17",
      "code": "Exfiltration Over Webhook",
      "value": "Exfiltration Over Webhook",
      "name": "Exfiltration Over Webhook",
      "definition": "Text about the clandestine removal of stolen data by abusing automated webhook mechanisms embedded within legitimate collaborative or messaging applications to route information packets directly to adversary-controlled destination servers.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Exfiltration",
        "Exfiltration Over Web Service",
        "Exfiltration Over Webhook"
      ],
      "parentId": "technique-exfiltration-over-web-service-ee6f0f54",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-remote-access-software-4be83e78",
      "code": "Remote Access Software",
      "value": "Remote Access Software",
      "name": "Remote Access Software",
      "definition": "Text about adversaries utilizing legitimate remote administration tools, monitoring utilities, or third-party desktop sharing applications to maintain persistent, unauthorized, interactive control over compromised systems within a targeted enterprise network environment.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Command and Control",
        "Remote Access Software"
      ],
      "parentId": "tactic-command-and-control-6b4265ca",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-masquerading-cb5ea65c",
      "code": "Masquerading",
      "value": "Masquerading",
      "name": "Masquerading",
      "definition": "Text about adversaries manipulating the names, locations, or properties of malicious files, processes, or entities to appear as legitimate components, thereby deceiving users and security controls within a compromised system.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Masquerading"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 10,
      "leaf": false
    },
    {
      "id": "subtechnique-masquerade-file-type-add4c558",
      "code": "Masquerade File Type",
      "value": "Masquerade File Type",
      "name": "Masquerade File Type",
      "definition": "Text about adversaries deceptively styling malicious files with mismatched extensions or file signatures, effectively bypassing file type restrictions and system inspection controls meant to identify and block unauthorized executables.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Masquerading",
        "Masquerade File Type"
      ],
      "parentId": "technique-masquerading-cb5ea65c",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-rename-system-utilities-6f5cdc03",
      "code": "Rename System Utilities",
      "value": "Rename System Utilities",
      "name": "Rename System Utilities",
      "definition": "Text about malicious actors renaming native operating system binaries to appear as legitimate files, thereby evading security mechanisms and standard monitoring tools while maintaining persistence or executing unauthorized operations silently.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Masquerading",
        "Rename System Utilities"
      ],
      "parentId": "technique-masquerading-cb5ea65c",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-space-after-filename-82ef6413",
      "code": "Space after Filename",
      "value": "Space after Filename",
      "name": "Space after Filename",
      "definition": "Text about evading detection through trailing spaces added to malicious filenames, which exploits specific path resolution mechanisms in operating systems to prioritize unauthorized binary execution over actual legitimate system file requests.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Masquerading",
        "Space after Filename"
      ],
      "parentId": "technique-masquerading-cb5ea65c",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-masquerade-task-or-service-146256e4",
      "code": "Masquerade Task or Service",
      "value": "Masquerade Task or Service",
      "name": "Masquerade Task or Service",
      "definition": "Text about adversaries masquerading malicious tasks or services by adopting the identifiers of legitimate system processes, causing security tools and analysts to overlook the unauthorized execution within the host environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Masquerading",
        "Masquerade Task or Service"
      ],
      "parentId": "technique-masquerading-cb5ea65c",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-right-to-left-override-a9661269",
      "code": "Right-to-Left Override",
      "value": "Right-to-Left Override",
      "name": "Right-to-Left Override",
      "definition": "Text about Right-to-Left Override describes the manipulation of software interfaces through Unicode control characters, enabling adversaries to visually mask file extensions, thereby deceiving users into executing malicious code unknowingly.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Masquerading",
        "Right-to-Left Override"
      ],
      "parentId": "technique-masquerading-cb5ea65c",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-match-legitimate-name-or-location-b4afedbb",
      "code": "Match Legitimate Name or Location",
      "value": "Match Legitimate Name or Location",
      "name": "Match Legitimate Name or Location",
      "definition": "Text about adversaries masking harmful executables by adopting identical naming attributes or directory placement as authorized system processes, ensuring the malicious activity remains undetected within verified system operational workflows.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Masquerading",
        "Match Legitimate Name or Location"
      ],
      "parentId": "technique-masquerading-cb5ea65c",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-double-file-extension-d3d2382e",
      "code": "Double File Extension",
      "value": "Double File Extension",
      "name": "Double File Extension",
      "definition": "Text about adversaries utilizing deceptive naming conventions, specifically redundant file extensions, to bypass user scrutiny and conceal executable malicious code, effectively masquerading the harmful file as a standard document.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Masquerading",
        "Double File Extension"
      ],
      "parentId": "technique-masquerading-cb5ea65c",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-masquerade-account-name-30f177e4",
      "code": "Masquerade Account Name",
      "value": "Masquerade Account Name",
      "name": "Masquerade Account Name",
      "definition": "Text about the deceptive practice of adversaries configuring account names to closely resemble trusted or existing system accounts, facilitating unauthorized access while attempting to evade detection during network security monitoring.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Masquerading",
        "Masquerade Account Name"
      ],
      "parentId": "technique-masquerading-cb5ea65c",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-invalid-code-signature-e5021b99",
      "code": "Invalid Code Signature",
      "value": "Invalid Code Signature",
      "name": "Invalid Code Signature",
      "definition": "Text about exploiting the inadequate verification of digital signatures on malicious executables, enabling adversaries to successfully launch unauthorized code in environments that attempt to restrict execution to verified software.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Masquerading",
        "Invalid Code Signature"
      ],
      "parentId": "technique-masquerading-cb5ea65c",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-break-process-trees-191ccbdc",
      "code": "Break Process Trees",
      "value": "Break Process Trees",
      "name": "Break Process Trees",
      "definition": "Text about Break Process Trees refers to the tactical manipulation of parent-child process relationships to orphan malicious code and evade security monitoring tools that rely on tracing lineage for detection.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Masquerading",
        "Break Process Trees"
      ],
      "parentId": "technique-masquerading-cb5ea65c",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-unsecured-credentials-a33ca172",
      "code": "Unsecured Credentials",
      "value": "Unsecured Credentials",
      "name": "Unsecured Credentials",
      "definition": "Text about attackers exploiting insecure storage of credentials within operating systems, targeting plain text passwords, password hashes, or security tokens located in process memory or local stored configuration data.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Credential Access",
        "Unsecured Credentials"
      ],
      "parentId": "tactic-credential-access-9c65f4e0",
      "synthetic": false,
      "childCount": 8,
      "leaf": false
    },
    {
      "id": "subtechnique-group-policy-preferences-7ab6537c",
      "code": "Group Policy Preferences",
      "value": "Group Policy Preferences",
      "name": "Group Policy Preferences",
      "definition": "Text about adversaries targeting the insecure implementation of Group Policy Preferences, specifically identifying improperly secured credentials within policy files to gain elevated access or persistence on target networked Windows endpoints.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Unsecured Credentials",
        "Group Policy Preferences"
      ],
      "parentId": "technique-unsecured-credentials-a33ca172",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-private-keys-354623f9",
      "code": "Private Keys",
      "value": "Private Keys",
      "name": "Private Keys",
      "definition": "Text about the unauthorized acquisition of private cryptographic keys directly from local filesystems, which adversaries leverage to decrypt protected information, bypass encryption mechanisms, or impersonate legitimate identities across secured network environments.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Unsecured Credentials",
        "Private Keys"
      ],
      "parentId": "technique-unsecured-credentials-a33ca172",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-container-api-2bb0acb2",
      "code": "Container API",
      "value": "Container API",
      "name": "Container API",
      "definition": "Text about unauthorized manipulation of container management services whereby an adversary leverages exposed administrative endpoints to gain control over containerised applications, modify container images, or extract secrets from the orchestration layer.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Unsecured Credentials",
        "Container API"
      ],
      "parentId": "technique-unsecured-credentials-a33ca172",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-credentials-in-files-26db0042",
      "code": "Credentials In Files",
      "value": "Credentials In Files",
      "name": "Credentials In Files",
      "definition": "Text about adversaries scanning local or network filesystem contents to harvest improperly secured credentials contained within configuration files, deployment scripts, or user documentation to facilitate unauthorized account takeover activities.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Unsecured Credentials",
        "Credentials In Files"
      ],
      "parentId": "technique-unsecured-credentials-a33ca172",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-credentials-in-registry-0de5d850",
      "code": "Credentials in Registry",
      "value": "Credentials in Registry",
      "name": "Credentials in Registry",
      "definition": "Text about adversaries leveraging unauthorized access to the Windows Registry to locate and capture stored credentials, which are often retained by system software or services for subsequent authentication and persistence.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Unsecured Credentials",
        "Credentials in Registry"
      ],
      "parentId": "technique-unsecured-credentials-a33ca172",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-bash-history-81009e61",
      "code": "Bash History",
      "value": "Bash History",
      "name": "Bash History",
      "definition": "Text about the unauthorized management of local shell history configurations where threat actors purge or obfuscate past command invocations to prevent reconstruction of their malicious actions during forensic system analysis.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Unsecured Credentials",
        "Bash History"
      ],
      "parentId": "technique-unsecured-credentials-a33ca172",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-chat-messages-089476e0",
      "code": "Chat Messages",
      "value": "Chat Messages",
      "name": "Chat Messages",
      "definition": "Text about the process where malicious actors monitor, capture, or exfiltrate sensitive content circulating within real-time messaging applications to gain unauthorized information about system configurations, project workflows, or employee credentials.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Unsecured Credentials",
        "Chat Messages"
      ],
      "parentId": "technique-unsecured-credentials-a33ca172",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-cloud-instance-metadata-api-ca8fa0ca",
      "code": "Cloud Instance Metadata API",
      "value": "Cloud Instance Metadata API",
      "name": "Cloud Instance Metadata API",
      "definition": "Text about adversaries leveraging the locally accessible metadata endpoint to programmatically query instance-level configuration information, including security credentials and network attributes, to gain unauthorized insight into the hosted cloud environment's architecture.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Unsecured Credentials",
        "Cloud Instance Metadata API"
      ],
      "parentId": "technique-unsecured-credentials-a33ca172",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-content-injection-77f4affd",
      "code": "Content Injection",
      "value": "Content Injection",
      "name": "Content Injection",
      "definition": "Text about inserting arbitrary data into legitimate resources or communications to falsify information presented to users or automated systems, facilitating unauthorized actions through the compromise of expected integrity.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Initial Access",
        "Content Injection"
      ],
      "parentId": "tactic-initial-access-a0f45034",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-content-injection-a3d15cb2",
      "code": "Content Injection",
      "value": "Content Injection",
      "name": "Content Injection",
      "definition": "Text about inserting arbitrary data into legitimate resources or communications to falsify information presented to users or automated systems, facilitating unauthorized actions through the compromise of expected integrity.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Command and Control",
        "Content Injection"
      ],
      "parentId": "tactic-command-and-control-6b4265ca",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-process-injection-380089e8",
      "code": "Process Injection",
      "value": "Process Injection",
      "name": "Process Injection",
      "definition": "Text about Process Injection denotes techniques where attackers force a running process to execute malicious code, allowing for evasion of defenses, persistence maintenance, or privilege escalation within the compromised operating environment.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Process Injection"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 12,
      "leaf": false
    },
    {
      "id": "subtechnique-process-doppelg-nging-f337cb44",
      "code": "Process Doppelgänging",
      "value": "Process Doppelgänging",
      "name": "Process Doppelgänging",
      "definition": "Text about Process Doppelgänging centers on utilizing NTFS transactions to overwrite legitimate file data temporarily, allowing the execution of malicious code while mimicking the behavior of a benign system process.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Process Injection",
        "Process Doppelgänging"
      ],
      "parentId": "technique-process-injection-380089e8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-process-hollowing-593b7316",
      "code": "Process Hollowing",
      "value": "Process Hollowing",
      "name": "Process Hollowing",
      "definition": "Text about Process Hollowing describes the malicious injection of executable code into a suspended legitimate process’s memory space, replacing its original instructions to execute unauthorized code while preserving the parent process identity.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Process Injection",
        "Process Hollowing"
      ],
      "parentId": "technique-process-injection-380089e8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-proc-memory-f8bb8227",
      "code": "Proc Memory",
      "value": "Proc Memory",
      "name": "Proc Memory",
      "definition": "Text about Process Memory, involving the unauthorized injection of code components directly into the memory address space of a target process to hide malicious operations under the guise of legitimate application execution.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Process Injection",
        "Proc Memory"
      ],
      "parentId": "technique-process-injection-380089e8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-listplanting-d5068325",
      "code": "ListPlanting",
      "value": "ListPlanting",
      "name": "ListPlanting",
      "definition": "Text about inserting malicious files into strategic application directories, causing the targeted software to automatically load and execute the attacker’s code when it initializes its standard file and library lists.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Process Injection",
        "ListPlanting"
      ],
      "parentId": "technique-process-injection-380089e8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-vdso-hijacking-dceec9e5",
      "code": "VDSO Hijacking",
      "value": "VDSO Hijacking",
      "name": "VDSO Hijacking",
      "definition": "Text about VDSO Hijacking pertains to adversaries intercepting and modifying the Virtual Dynamic Shared Object, a mechanism intended to accelerate system calls, to surreptitiously inject commands or redirect execution logic effectively.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Process Injection",
        "VDSO Hijacking"
      ],
      "parentId": "technique-process-injection-380089e8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-thread-local-storage-bb388b35",
      "code": "Thread Local Storage",
      "value": "Thread Local Storage",
      "name": "Thread Local Storage",
      "definition": "Text about Thread Local Storage concerns the abuse of legitimate TLS callback functions to achieve unauthorized execution of payload code by redirecting the operating system loader during process initialization.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Process Injection",
        "Thread Local Storage"
      ],
      "parentId": "technique-process-injection-380089e8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-extra-window-memory-injection-610d0208",
      "code": "Extra Window Memory Injection",
      "value": "Extra Window Memory Injection",
      "name": "Extra Window Memory Injection",
      "definition": "Text about Extra Window Memory Injection entails the unauthorized modification of extra byte memory structures within an existing window object to hijack execution flow and facilitate arbitrary code execution processes.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Process Injection",
        "Extra Window Memory Injection"
      ],
      "parentId": "technique-process-injection-380089e8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-dynamic-link-library-injection-86cb1835",
      "code": "Dynamic-link Library Injection",
      "value": "Dynamic-link Library Injection",
      "name": "Dynamic-link Library Injection",
      "definition": "Text about adversaries hijacking process execution flows by directing a victim process to load and execute a malicious library module, effectively running unauthorized code within the targeted process's legitimate memory.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Process Injection",
        "Dynamic-link Library Injection"
      ],
      "parentId": "technique-process-injection-380089e8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-thread-execution-hijacking-e6038e9a",
      "code": "Thread Execution Hijacking",
      "value": "Thread Execution Hijacking",
      "name": "Thread Execution Hijacking",
      "definition": "Text about adversaries who hijack the execution flow of specific threads in a target process, forcing the application to run malicious code while maintaining the privileges of the original, legitimate thread.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Process Injection",
        "Thread Execution Hijacking"
      ],
      "parentId": "technique-process-injection-380089e8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-ptrace-system-calls-9266b822",
      "code": "Ptrace System Calls",
      "value": "Ptrace System Calls",
      "name": "Ptrace System Calls",
      "definition": "Text about the manipulation of the ptrace system call to gain restricted process access, which enables adversaries to monitor, alter, and potentially compromise the integrity of active, running software processes.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Process Injection",
        "Ptrace System Calls"
      ],
      "parentId": "technique-process-injection-380089e8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-asynchronous-procedure-call-af58de42",
      "code": "Asynchronous Procedure Call",
      "value": "Asynchronous Procedure Call",
      "name": "Asynchronous Procedure Call",
      "definition": "Text about adversaries injecting malicious code into victim processes by forcing those processes to execute specific functions via queued asynchronous procedure calls, facilitating code execution within the context of the target environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Process Injection",
        "Asynchronous Procedure Call"
      ],
      "parentId": "technique-process-injection-380089e8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-portable-executable-injection-131af23f",
      "code": "Portable Executable Injection",
      "value": "Portable Executable Injection",
      "name": "Portable Executable Injection",
      "definition": "Text about Portable Executable Injection refers to adversaries inserting malicious executable content directly into the memory of a currently running process to execute commands covertly and bypass file-based security scrutiny.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Process Injection",
        "Portable Executable Injection"
      ],
      "parentId": "technique-process-injection-380089e8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-process-injection-13f5700b",
      "code": "Process Injection",
      "value": "Process Injection",
      "name": "Process Injection",
      "definition": "Text about Process Injection denotes techniques where attackers force a running process to execute malicious code, allowing for evasion of defenses, persistence maintenance, or privilege escalation within the compromised operating environment.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Privilege Escalation",
        "Process Injection"
      ],
      "parentId": "tactic-privilege-escalation-dc3564ae",
      "synthetic": false,
      "childCount": 12,
      "leaf": false
    },
    {
      "id": "subtechnique-process-doppelg-nging-60a58e77",
      "code": "Process Doppelgänging",
      "value": "Process Doppelgänging",
      "name": "Process Doppelgänging",
      "definition": "Text about Process Doppelgänging centers on utilizing NTFS transactions to overwrite legitimate file data temporarily, allowing the execution of malicious code while mimicking the behavior of a benign system process.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Process Injection",
        "Process Doppelgänging"
      ],
      "parentId": "technique-process-injection-13f5700b",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-process-hollowing-c81068aa",
      "code": "Process Hollowing",
      "value": "Process Hollowing",
      "name": "Process Hollowing",
      "definition": "Text about Process Hollowing describes the malicious injection of executable code into a suspended legitimate process’s memory space, replacing its original instructions to execute unauthorized code while preserving the parent process identity.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Process Injection",
        "Process Hollowing"
      ],
      "parentId": "technique-process-injection-13f5700b",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-proc-memory-f40789de",
      "code": "Proc Memory",
      "value": "Proc Memory",
      "name": "Proc Memory",
      "definition": "Text about Process Memory, involving the unauthorized injection of code components directly into the memory address space of a target process to hide malicious operations under the guise of legitimate application execution.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Process Injection",
        "Proc Memory"
      ],
      "parentId": "technique-process-injection-13f5700b",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-listplanting-d218c208",
      "code": "ListPlanting",
      "value": "ListPlanting",
      "name": "ListPlanting",
      "definition": "Text about inserting malicious files into strategic application directories, causing the targeted software to automatically load and execute the attacker’s code when it initializes its standard file and library lists.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Process Injection",
        "ListPlanting"
      ],
      "parentId": "technique-process-injection-13f5700b",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-vdso-hijacking-77aa1789",
      "code": "VDSO Hijacking",
      "value": "VDSO Hijacking",
      "name": "VDSO Hijacking",
      "definition": "Text about VDSO Hijacking pertains to adversaries intercepting and modifying the Virtual Dynamic Shared Object, a mechanism intended to accelerate system calls, to surreptitiously inject commands or redirect execution logic effectively.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Process Injection",
        "VDSO Hijacking"
      ],
      "parentId": "technique-process-injection-13f5700b",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-thread-local-storage-6465b098",
      "code": "Thread Local Storage",
      "value": "Thread Local Storage",
      "name": "Thread Local Storage",
      "definition": "Text about Thread Local Storage concerns the abuse of legitimate TLS callback functions to achieve unauthorized execution of payload code by redirecting the operating system loader during process initialization.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Process Injection",
        "Thread Local Storage"
      ],
      "parentId": "technique-process-injection-13f5700b",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-extra-window-memory-injection-75edf959",
      "code": "Extra Window Memory Injection",
      "value": "Extra Window Memory Injection",
      "name": "Extra Window Memory Injection",
      "definition": "Text about Extra Window Memory Injection entails the unauthorized modification of extra byte memory structures within an existing window object to hijack execution flow and facilitate arbitrary code execution processes.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Process Injection",
        "Extra Window Memory Injection"
      ],
      "parentId": "technique-process-injection-13f5700b",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-dynamic-link-library-injection-ea7670d8",
      "code": "Dynamic-link Library Injection",
      "value": "Dynamic-link Library Injection",
      "name": "Dynamic-link Library Injection",
      "definition": "Text about adversaries hijacking process execution flows by directing a victim process to load and execute a malicious library module, effectively running unauthorized code within the targeted process's legitimate memory.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Process Injection",
        "Dynamic-link Library Injection"
      ],
      "parentId": "technique-process-injection-13f5700b",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-thread-execution-hijacking-bee71ade",
      "code": "Thread Execution Hijacking",
      "value": "Thread Execution Hijacking",
      "name": "Thread Execution Hijacking",
      "definition": "Text about adversaries who hijack the execution flow of specific threads in a target process, forcing the application to run malicious code while maintaining the privileges of the original, legitimate thread.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Process Injection",
        "Thread Execution Hijacking"
      ],
      "parentId": "technique-process-injection-13f5700b",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-ptrace-system-calls-944f48e7",
      "code": "Ptrace System Calls",
      "value": "Ptrace System Calls",
      "name": "Ptrace System Calls",
      "definition": "Text about the manipulation of the ptrace system call to gain restricted process access, which enables adversaries to monitor, alter, and potentially compromise the integrity of active, running software processes.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Process Injection",
        "Ptrace System Calls"
      ],
      "parentId": "technique-process-injection-13f5700b",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-asynchronous-procedure-call-12586cc5",
      "code": "Asynchronous Procedure Call",
      "value": "Asynchronous Procedure Call",
      "name": "Asynchronous Procedure Call",
      "definition": "Text about adversaries injecting malicious code into victim processes by forcing those processes to execute specific functions via queued asynchronous procedure calls, facilitating code execution within the context of the target environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Process Injection",
        "Asynchronous Procedure Call"
      ],
      "parentId": "technique-process-injection-13f5700b",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-portable-executable-injection-e496b36d",
      "code": "Portable Executable Injection",
      "value": "Portable Executable Injection",
      "name": "Portable Executable Injection",
      "definition": "Text about Portable Executable Injection refers to adversaries inserting malicious executable content directly into the memory of a currently running process to execute commands covertly and bypass file-based security scrutiny.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Process Injection",
        "Portable Executable Injection"
      ],
      "parentId": "technique-process-injection-13f5700b",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-traffic-signaling-9bad42cb",
      "code": "Traffic Signaling",
      "value": "Traffic Signaling",
      "name": "Traffic Signaling",
      "definition": "Text about Traffic Signaling refers to the utilization of specific network packet sequences to remotely activate dormant listening mechanisms on compromised endpoints, effectively bypassing conventional security monitoring of typical connection attempts.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Traffic Signaling"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 2,
      "leaf": false
    },
    {
      "id": "subtechnique-port-knocking-73c6c74e",
      "code": "Port Knocking",
      "value": "Port Knocking",
      "name": "Port Knocking",
      "definition": "Text about Port Knocking, describing the tactical manipulation of network traffic patterns where specific sequences of connection attempts unlock restricted port access for further exploitation or persistence within a network.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Traffic Signaling",
        "Port Knocking"
      ],
      "parentId": "technique-traffic-signaling-9bad42cb",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-socket-filters-5bd35593",
      "code": "Socket Filters",
      "value": "Socket Filters",
      "name": "Socket Filters",
      "definition": "Text about adversaries utilizing kernel-level socket filtering capabilities to intercept, inspect, or modify network traffic, enabling covert communication channels or data exfiltration while bypassing standard user-space monitoring tools effectively.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Traffic Signaling",
        "Socket Filters"
      ],
      "parentId": "technique-traffic-signaling-9bad42cb",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-traffic-signaling-1c8ff468",
      "code": "Traffic Signaling",
      "value": "Traffic Signaling",
      "name": "Traffic Signaling",
      "definition": "Text about Traffic Signaling refers to the utilization of specific network packet sequences to remotely activate dormant listening mechanisms on compromised endpoints, effectively bypassing conventional security monitoring of typical connection attempts.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Persistence",
        "Traffic Signaling"
      ],
      "parentId": "tactic-persistence-4782469e",
      "synthetic": false,
      "childCount": 2,
      "leaf": false
    },
    {
      "id": "subtechnique-port-knocking-8e683c60",
      "code": "Port Knocking",
      "value": "Port Knocking",
      "name": "Port Knocking",
      "definition": "Text about Port Knocking, describing the tactical manipulation of network traffic patterns where specific sequences of connection attempts unlock restricted port access for further exploitation or persistence within a network.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Traffic Signaling",
        "Port Knocking"
      ],
      "parentId": "technique-traffic-signaling-1c8ff468",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-socket-filters-6a07cd05",
      "code": "Socket Filters",
      "value": "Socket Filters",
      "name": "Socket Filters",
      "definition": "Text about adversaries utilizing kernel-level socket filtering capabilities to intercept, inspect, or modify network traffic, enabling covert communication channels or data exfiltration while bypassing standard user-space monitoring tools effectively.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Traffic Signaling",
        "Socket Filters"
      ],
      "parentId": "technique-traffic-signaling-1c8ff468",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-traffic-signaling-23a2f1e3",
      "code": "Traffic Signaling",
      "value": "Traffic Signaling",
      "name": "Traffic Signaling",
      "definition": "Text about Traffic Signaling refers to the utilization of specific network packet sequences to remotely activate dormant listening mechanisms on compromised endpoints, effectively bypassing conventional security monitoring of typical connection attempts.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Command and Control",
        "Traffic Signaling"
      ],
      "parentId": "tactic-command-and-control-6b4265ca",
      "synthetic": false,
      "childCount": 2,
      "leaf": false
    },
    {
      "id": "subtechnique-port-knocking-be0b42c7",
      "code": "Port Knocking",
      "value": "Port Knocking",
      "name": "Port Knocking",
      "definition": "Text about Port Knocking, describing the tactical manipulation of network traffic patterns where specific sequences of connection attempts unlock restricted port access for further exploitation or persistence within a network.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Command and Control",
        "Traffic Signaling",
        "Port Knocking"
      ],
      "parentId": "technique-traffic-signaling-23a2f1e3",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-socket-filters-d00b1870",
      "code": "Socket Filters",
      "value": "Socket Filters",
      "name": "Socket Filters",
      "definition": "Text about adversaries utilizing kernel-level socket filtering capabilities to intercept, inspect, or modify network traffic, enabling covert communication channels or data exfiltration while bypassing standard user-space monitoring tools effectively.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Command and Control",
        "Traffic Signaling",
        "Socket Filters"
      ],
      "parentId": "technique-traffic-signaling-23a2f1e3",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-system-binary-proxy-execution-1bb2ffbd",
      "code": "System Binary Proxy Execution",
      "value": "System Binary Proxy Execution",
      "name": "System Binary Proxy Execution",
      "definition": "Text about adversaries conducting malicious operations by abusing legitimate system binaries as proxies, enabling the execution of arbitrary commands or scripts while inheriting the permissions and trust associated with those binaries.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "System Binary Proxy Execution"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 14,
      "leaf": false
    },
    {
      "id": "subtechnique-mshta-afda0921",
      "code": "Mshta",
      "value": "Mshta",
      "name": "Mshta",
      "definition": "Text about Mshta defines the adversarial practice of executing malicious payloads via the Microsoft HTML Application utility, which runs scripts within a trusted Windows context to circumvent endpoint security defenses.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "System Binary Proxy Execution",
        "Mshta"
      ],
      "parentId": "technique-system-binary-proxy-execution-1bb2ffbd",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-mmc-a93c2f74",
      "code": "MMC",
      "value": "MMC",
      "name": "MMC",
      "definition": "Text about executing unauthorized malicious code by manipulating Microsoft Management Console configuration files, allowing adversaries to bypass application execution restrictions while leveraging trusted binaries for persistent command and control operations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "System Binary Proxy Execution",
        "MMC"
      ],
      "parentId": "technique-system-binary-proxy-execution-1bb2ffbd",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-odbcconf-b725f40d",
      "code": "Odbcconf",
      "value": "Odbcconf",
      "name": "Odbcconf",
      "definition": "Text about odbcconf involves the exploitation of this legitimate Windows configuration utility to execute unauthorized code by invoking command-line instructions that force the loading of malicious dynamic link libraries.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "System Binary Proxy Execution",
        "Odbcconf"
      ],
      "parentId": "technique-system-binary-proxy-execution-1bb2ffbd",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-electron-applications-104dd63a",
      "code": "Electron Applications",
      "value": "Electron Applications",
      "name": "Electron Applications",
      "definition": "Text about Electron Applications covers the abuse of desktop software frameworks combining web rendering and Node.js environments, allowing adversaries to execute arbitrary code, manipulate system resources, and establish persistent threat operations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "System Binary Proxy Execution",
        "Electron Applications"
      ],
      "parentId": "technique-system-binary-proxy-execution-1bb2ffbd",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-verclsid-cd7efa17",
      "code": "Verclsid",
      "value": "Verclsid",
      "name": "Verclsid",
      "definition": "Text about Verclsid concerns the exploitation of the Windows verclsid.exe binary to execute arbitrary code hidden within COM objects, allowing malicious actors to circumvent signature-based application control and security policy mechanisms.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "System Binary Proxy Execution",
        "Verclsid"
      ],
      "parentId": "technique-system-binary-proxy-execution-1bb2ffbd",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-mavinject-a2ae4d4e",
      "code": "Mavinject",
      "value": "Mavinject",
      "name": "Mavinject",
      "definition": "Text about Mavinject constitutes a technique where attackers abuse the legitimate mavinject.exe tool to insert and execute malicious payloads within the runtime memory of other processes to evade system security controls.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "System Binary Proxy Execution",
        "Mavinject"
      ],
      "parentId": "technique-system-binary-proxy-execution-1bb2ffbd",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-control-panel-2fb34067",
      "code": "Control Panel",
      "value": "Control Panel",
      "name": "Control Panel",
      "definition": "Text about Control Panel items pertains to the tactical abuse of system configuration applets to execute unauthorized code, enabling actors to bypass security controls by repurposing trusted administrative tools for malicious operations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "System Binary Proxy Execution",
        "Control Panel"
      ],
      "parentId": "technique-system-binary-proxy-execution-1bb2ffbd",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-compiled-html-file-b24e009f",
      "code": "Compiled HTML File",
      "value": "Compiled HTML File",
      "name": "Compiled HTML File",
      "definition": "Text about adversaries utilizing Microsoft Compiled HTML Help files containing malicious scripts or payloads to execute arbitrary code on victim systems, typically facilitating initial intrusion through deceitful file attachments.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "System Binary Proxy Execution",
        "Compiled HTML File"
      ],
      "parentId": "technique-system-binary-proxy-execution-1bb2ffbd",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-regsvr32-da2b97aa",
      "code": "Regsvr32",
      "value": "Regsvr32",
      "name": "Regsvr32",
      "definition": "Text about Regsvr32 constitutes the exploitation of a native Windows utility, designed for OLE control registration, to execute malicious binary code while remaining masked as a trusted signed process.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "System Binary Proxy Execution",
        "Regsvr32"
      ],
      "parentId": "technique-system-binary-proxy-execution-1bb2ffbd",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-installutil-90d39344",
      "code": "InstallUtil",
      "value": "InstallUtil",
      "name": "InstallUtil",
      "definition": "Text about leveraging the Microsoft InstallUtil binary to execute malicious executable files or assemblies, thereby enabling adversaries to run arbitrary code while masquerading as legitimate software installation or administration tasks.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "System Binary Proxy Execution",
        "InstallUtil"
      ],
      "parentId": "technique-system-binary-proxy-execution-1bb2ffbd",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-rundll32-7f3ce67a",
      "code": "Rundll32",
      "value": "Rundll32",
      "name": "Rundll32",
      "definition": "Text about attackers abusing rundll32.exe to proxy the execution of malicious payloads stored in dynamic link libraries, leveraging this standard component to bypass defensive controls and execute arbitrary system commands.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "System Binary Proxy Execution",
        "Rundll32"
      ],
      "parentId": "technique-system-binary-proxy-execution-1bb2ffbd",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-regsvcs-regasm-1487fc44",
      "code": "Regsvcs/Regasm",
      "value": "Regsvcs/Regasm",
      "name": "Regsvcs/Regasm",
      "definition": "Text about abusing native system utilities intended for .NET assembly registration to proxy the execution of malicious payloads, enabling adversaries to execute code while maintaining an appearance of legitimate system operations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "System Binary Proxy Execution",
        "Regsvcs/Regasm"
      ],
      "parentId": "technique-system-binary-proxy-execution-1bb2ffbd",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-cmstp-5b48fc85",
      "code": "CMSTP",
      "value": "CMSTP",
      "name": "CMSTP",
      "definition": "Text about adversaries executing malicious code by leveraging the Connection Manager Profile Installer, a Microsoft signed binary, to bypass application control policies via the loading of malicious INF files.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "System Binary Proxy Execution",
        "CMSTP"
      ],
      "parentId": "technique-system-binary-proxy-execution-1bb2ffbd",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-msiexec-3241da60",
      "code": "Msiexec",
      "value": "Msiexec",
      "name": "Msiexec",
      "definition": "Text about Msiexec comprises the strategic use of the Microsoft Installer command-line interface to execute harmful software packages, leveraging native system utilities to camouflage adversarial operations and deploy malicious code.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "System Binary Proxy Execution",
        "Msiexec"
      ],
      "parentId": "technique-system-binary-proxy-execution-1bb2ffbd",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-reflective-code-loading-9c67d9ea",
      "code": "Reflective Code Loading",
      "value": "Reflective Code Loading",
      "name": "Reflective Code Loading",
      "definition": "Text about adversaries loading malicious code directly into a host application's memory without touching the disk, effectively bypassing standard operating system loaders to execute payloads while avoiding detection by file-based scanning mechanisms.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Reflective Code Loading"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-escape-to-host-2edd844b",
      "code": "Escape to Host",
      "value": "Escape to Host",
      "name": "Escape to Host",
      "definition": "Text about malicious actions facilitating unauthorized traversal from an isolated virtual machine or container into the infrastructure managing that virtualized environment, effectively compromising the integrity of the host server itself.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Privilege Escalation",
        "Escape to Host"
      ],
      "parentId": "tactic-privilege-escalation-dc3564ae",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-application-window-discovery-f4c66239",
      "code": "Application Window Discovery",
      "value": "Application Window Discovery",
      "name": "Application Window Discovery",
      "definition": "Text about the methodical identification of visible application windows via system calls, allowing adversaries to capture window titles and process details essential for fingerprinting user activity and monitoring specialized software.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "Application Window Discovery"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-scheduled-transfer-f3d702c0",
      "code": "Scheduled Transfer",
      "value": "Scheduled Transfer",
      "name": "Scheduled Transfer",
      "definition": "Text about adversaries leveraging automated task scheduling capabilities to trigger the periodic transfer of stolen data from a compromised network to an external endpoint according to predefined timeframes.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Exfiltration",
        "Scheduled Transfer"
      ],
      "parentId": "tactic-exfiltration-fcb9fccc",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-implant-internal-image-0884e561",
      "code": "Implant Internal Image",
      "value": "Implant Internal Image",
      "name": "Implant Internal Image",
      "definition": "Text about adversaries implanting malicious virtual machine or container images into an internal registry or environment, ensuring that deployment of the tainted image executes attacker code and maintains persistence.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Persistence",
        "Implant Internal Image"
      ],
      "parentId": "tactic-persistence-4782469e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-protocol-tunneling-187def8c",
      "code": "Protocol Tunneling",
      "value": "Protocol Tunneling",
      "name": "Protocol Tunneling",
      "definition": "Text about adversaries utilizing protocol encapsulation methods to hide unauthorized traffic inside allowed communication streams, thereby invalidating standard perimeter defense inspections and securing tunnels for command, control, and data exfiltration.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Command and Control",
        "Protocol Tunneling"
      ],
      "parentId": "tactic-command-and-control-6b4265ca",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-use-alternate-authentication-material-7b996784",
      "code": "Use Alternate Authentication Material",
      "value": "Use Alternate Authentication Material",
      "name": "Use Alternate Authentication Material",
      "definition": "Text about adversaries bypassing normal authentication flows by employing previously stolen session cookies, application-specific passwords, or other secondary authentication tokens to masquerade as valid users within secured enterprise environments.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Use Alternate Authentication Material"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 4,
      "leaf": false
    },
    {
      "id": "subtechnique-web-session-cookie-435d5d37",
      "code": "Web Session Cookie",
      "value": "Web Session Cookie",
      "name": "Web Session Cookie",
      "definition": "Text about the unauthorized acquisition of browser-based session cookies to conduct session hijacking, enabling persistent, authenticated access to web platforms while successfully bypassing multi-factor authentication and standard login procedures.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Use Alternate Authentication Material",
        "Web Session Cookie"
      ],
      "parentId": "technique-use-alternate-authentication-material-7b996784",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-application-access-token-7f425aa5",
      "code": "Application Access Token",
      "value": "Application Access Token",
      "name": "Application Access Token",
      "definition": "Text about malicious actors obtaining legitimate authentication tokens to access cloud services or web applications, thereby bypassing standard authentication processes by presenting stolen tokens as valid user sessions.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Use Alternate Authentication Material",
        "Application Access Token"
      ],
      "parentId": "technique-use-alternate-authentication-material-7b996784",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-pass-the-ticket-c42bf0ba",
      "code": "Pass the Ticket",
      "value": "Pass the Ticket",
      "name": "Pass the Ticket",
      "definition": "Text about an adversary manipulating Kerberos session tickets to gain unauthorized system entry by injecting stolen tokens into memory, effectively bypassing authentication protocols for persistent access within environments.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Use Alternate Authentication Material",
        "Pass the Ticket"
      ],
      "parentId": "technique-use-alternate-authentication-material-7b996784",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-pass-the-hash-ce05f0c9",
      "code": "Pass the Hash",
      "value": "Pass the Hash",
      "name": "Pass the Hash",
      "definition": "Text about Pass the Hash refers to a credential theft exploitation mechanism where authentication secrets are reused directly against network resources, permitting unauthorized access without needing to recover original user passwords.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Use Alternate Authentication Material",
        "Pass the Hash"
      ],
      "parentId": "technique-use-alternate-authentication-material-7b996784",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-use-alternate-authentication-material-8d31c1ec",
      "code": "Use Alternate Authentication Material",
      "value": "Use Alternate Authentication Material",
      "name": "Use Alternate Authentication Material",
      "definition": "Text about adversaries bypassing normal authentication flows by employing previously stolen session cookies, application-specific passwords, or other secondary authentication tokens to masquerade as valid users within secured enterprise environments.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Lateral Movement",
        "Use Alternate Authentication Material"
      ],
      "parentId": "tactic-lateral-movement-4cec3f1f",
      "synthetic": false,
      "childCount": 4,
      "leaf": false
    },
    {
      "id": "subtechnique-web-session-cookie-07363597",
      "code": "Web Session Cookie",
      "value": "Web Session Cookie",
      "name": "Web Session Cookie",
      "definition": "Text about the unauthorized acquisition of browser-based session cookies to conduct session hijacking, enabling persistent, authenticated access to web platforms while successfully bypassing multi-factor authentication and standard login procedures.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Lateral Movement",
        "Use Alternate Authentication Material",
        "Web Session Cookie"
      ],
      "parentId": "technique-use-alternate-authentication-material-8d31c1ec",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-application-access-token-800a29ba",
      "code": "Application Access Token",
      "value": "Application Access Token",
      "name": "Application Access Token",
      "definition": "Text about malicious actors obtaining legitimate authentication tokens to access cloud services or web applications, thereby bypassing standard authentication processes by presenting stolen tokens as valid user sessions.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Lateral Movement",
        "Use Alternate Authentication Material",
        "Application Access Token"
      ],
      "parentId": "technique-use-alternate-authentication-material-8d31c1ec",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-pass-the-ticket-2ee8066b",
      "code": "Pass the Ticket",
      "value": "Pass the Ticket",
      "name": "Pass the Ticket",
      "definition": "Text about an adversary manipulating Kerberos session tickets to gain unauthorized system entry by injecting stolen tokens into memory, effectively bypassing authentication protocols for persistent access within environments.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Lateral Movement",
        "Use Alternate Authentication Material",
        "Pass the Ticket"
      ],
      "parentId": "technique-use-alternate-authentication-material-8d31c1ec",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-pass-the-hash-cec30c57",
      "code": "Pass the Hash",
      "value": "Pass the Hash",
      "name": "Pass the Hash",
      "definition": "Text about Pass the Hash refers to a credential theft exploitation mechanism where authentication secrets are reused directly against network resources, permitting unauthorized access without needing to recover original user passwords.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Lateral Movement",
        "Use Alternate Authentication Material",
        "Pass the Hash"
      ],
      "parentId": "technique-use-alternate-authentication-material-8d31c1ec",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-exfiltration-over-other-network-medium-ecc6fdba",
      "code": "Exfiltration Over Other Network Medium",
      "value": "Exfiltration Over Other Network Medium",
      "name": "Exfiltration Over Other Network Medium",
      "definition": "Text about the strategic use of unconventional network protocols or communication mediums to transport stolen data externally, allowing adversaries to circumvent routine perimeter defenses by leveraging hidden or overlooked transit paths.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Exfiltration",
        "Exfiltration Over Other Network Medium"
      ],
      "parentId": "tactic-exfiltration-fcb9fccc",
      "synthetic": false,
      "childCount": 1,
      "leaf": false
    },
    {
      "id": "subtechnique-exfiltration-over-bluetooth-7ca41369",
      "code": "Exfiltration Over Bluetooth",
      "value": "Exfiltration Over Bluetooth",
      "name": "Exfiltration Over Bluetooth",
      "definition": "Text about attackers leveraging local Bluetooth connectivity capabilities to facilitate the exfiltration of sensitive information from a compromised target system to an external device within local wireless range.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Exfiltration",
        "Exfiltration Over Other Network Medium",
        "Exfiltration Over Bluetooth"
      ],
      "parentId": "technique-exfiltration-over-other-network-medium-ecc6fdba",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-gather-victim-identity-information-24b677c1",
      "code": "Gather Victim Identity Information",
      "value": "Gather Victim Identity Information",
      "name": "Gather Victim Identity Information",
      "definition": "Text about the acquisition of specific victim identity attributes, including email addresses, usernames, roles, and organizational hierarchies, used by adversaries to prepare for follow-on actions like phishing or account exploitation.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Reconnaissance",
        "Gather Victim Identity Information"
      ],
      "parentId": "tactic-reconnaissance-a9f8c2a8",
      "synthetic": false,
      "childCount": 3,
      "leaf": false
    },
    {
      "id": "subtechnique-employee-names-8cb0df73",
      "code": "Employee Names",
      "value": "Employee Names",
      "name": "Employee Names",
      "definition": "Text about collecting employee names to support adversary operational planning, allowing threat actors to map personnel to specific departments or roles, increasing the legitimacy and effectiveness of targeted malicious communications.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Gather Victim Identity Information",
        "Employee Names"
      ],
      "parentId": "technique-gather-victim-identity-information-24b677c1",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-email-addresses-0fe43f98",
      "code": "Email Addresses",
      "value": "Email Addresses",
      "name": "Email Addresses",
      "definition": "Text about discovering and utilizing email addresses to support the adversary's efforts in targeting specific individuals or organizations through methods such as phishing, spoofing, or launching credential-based secondary attacks.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Gather Victim Identity Information",
        "Email Addresses"
      ],
      "parentId": "technique-gather-victim-identity-information-24b677c1",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-credentials-417dcf09",
      "code": "Credentials",
      "value": "Credentials",
      "name": "Credentials",
      "definition": "Text about methods adversaries employ to illicitly acquire authentication data, such as usernames, passwords, or cryptographic tokens, enabling continued system access, privilege escalation, or lateral movement within compromised infrastructures.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Gather Victim Identity Information",
        "Credentials"
      ],
      "parentId": "technique-gather-victim-identity-information-24b677c1",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-archive-collected-data-b007f006",
      "code": "Archive Collected Data",
      "value": "Archive Collected Data",
      "name": "Archive Collected Data",
      "definition": "Text about adversaries aggregating selected sensitive information within compressed archives to prepare for unauthorized transfer, ensuring that the volume of stolen data remains manageable while minimizing detection of exfiltration.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Collection",
        "Archive Collected Data"
      ],
      "parentId": "tactic-collection-30c54a96",
      "synthetic": false,
      "childCount": 3,
      "leaf": false
    },
    {
      "id": "subtechnique-archive-via-library-6c8f26fc",
      "code": "Archive via Library",
      "value": "Archive via Library",
      "name": "Archive via Library",
      "definition": "Text about leveraging native system libraries to programmatically archive and compress sensitive data, allowing threat actors to aggregate collected material into manageable files preparatory to unauthorized data transmission from systems.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Collection",
        "Archive Collected Data",
        "Archive via Library"
      ],
      "parentId": "technique-archive-collected-data-b007f006",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-archive-via-utility-b784ae89",
      "code": "Archive via Utility",
      "value": "Archive via Utility",
      "name": "Archive via Utility",
      "definition": "Text about threat actors leveraging standard system command-line utilities to bundle and compress sensitive information into distinct archive formats, preparing the data for stealthy removal from the victim host.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Collection",
        "Archive Collected Data",
        "Archive via Utility"
      ],
      "parentId": "technique-archive-collected-data-b007f006",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-archive-via-custom-method-b4291590",
      "code": "Archive via Custom Method",
      "value": "Archive via Custom Method",
      "name": "Archive via Custom Method",
      "definition": "Text about the implementation of unique, proprietary compression or obfuscation methods to prepare stolen data for exfiltration, intended to bypass security controls that focus on identifying specific, known file archive structures.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Collection",
        "Archive Collected Data",
        "Archive via Custom Method"
      ],
      "parentId": "technique-archive-collected-data-b007f006",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-browser-session-hijacking-e4c9f84d",
      "code": "Browser Session Hijacking",
      "value": "Browser Session Hijacking",
      "name": "Browser Session Hijacking",
      "definition": "Text about the unauthorized extraction of active web session tokens or cookies from browser memory or storage, allowing attackers to assume valid user identities and bypass multi-factor authentication controls indefinitely.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Collection",
        "Browser Session Hijacking"
      ],
      "parentId": "tactic-collection-30c54a96",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-remote-services-fb7ac358",
      "code": "Remote Services",
      "value": "Remote Services",
      "name": "Remote Services",
      "definition": "Text about Remote Services encompasses adversarial exploitation of standard communication protocols designed for administrative access, allowing threat actors to connect to and manipulate enterprise systems from environments located outside internal perimeters.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Lateral Movement",
        "Remote Services"
      ],
      "parentId": "tactic-lateral-movement-4cec3f1f",
      "synthetic": false,
      "childCount": 8,
      "leaf": false
    },
    {
      "id": "subtechnique-windows-remote-management-e9991986",
      "code": "Windows Remote Management",
      "value": "Windows Remote Management",
      "name": "Windows Remote Management",
      "definition": "Text about the exploitation of native Windows Remote Management mechanisms to facilitate unauthorized remote code execution and system administration, enabling adversaries to control targeted computers within enterprise environments.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Lateral Movement",
        "Remote Services",
        "Windows Remote Management"
      ],
      "parentId": "technique-remote-services-fb7ac358",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-vnc-9a2b4f71",
      "code": "VNC",
      "value": "VNC",
      "name": "VNC",
      "definition": "Text about attackers configuring or compromising Virtual Network Computing services to gain persistent, interactive remote graphical access, enabling direct control over victim systems for covert post-compromise manipulation and operations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Lateral Movement",
        "Remote Services",
        "VNC"
      ],
      "parentId": "technique-remote-services-fb7ac358",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-smb-windows-admin-shares-5eace6c1",
      "code": "SMB/Windows Admin Shares",
      "value": "SMB/Windows Admin Shares",
      "name": "SMB/Windows Admin Shares",
      "definition": "Text about adversaries leveraging inherent Server Message Block administrative shares to execute remote code, move laterally across network segments, and access filesystems on compromised Windows hosts without authenticating to individual services.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Lateral Movement",
        "Remote Services",
        "SMB/Windows Admin Shares"
      ],
      "parentId": "technique-remote-services-fb7ac358",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-cloud-services-cfbc7c71",
      "code": "Cloud Services",
      "value": "Cloud Services",
      "name": "Cloud Services",
      "definition": "Text about attackers procuring or hijacking cloud service accounts for deploying malicious assets, thereby utilizing native global infrastructure to facilitate unauthorized access or data exfiltration operations stealthily.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Lateral Movement",
        "Remote Services",
        "Cloud Services"
      ],
      "parentId": "technique-remote-services-fb7ac358",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-remote-desktop-protocol-58706437",
      "code": "Remote Desktop Protocol",
      "value": "Remote Desktop Protocol",
      "name": "Remote Desktop Protocol",
      "definition": "Text about Remote Desktop Protocol identifies the adversarial misuse of widely implemented Microsoft remote desktop services to facilitate unauthorized remote connection into systems, enabling command execution and lateral network traversal activities.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Lateral Movement",
        "Remote Services",
        "Remote Desktop Protocol"
      ],
      "parentId": "technique-remote-services-fb7ac358",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-distributed-component-object-model-c85d3d25",
      "code": "Distributed Component Object Model",
      "value": "Distributed Component Object Model",
      "name": "Distributed Component Object Model",
      "definition": "Text about Distributed Component Object Model identifies a method where adversaries leverage the proprietary Windows interface for object communication to gain remote execution capabilities, manipulate services, and traverse compromised network systems silently.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Lateral Movement",
        "Remote Services",
        "Distributed Component Object Model"
      ],
      "parentId": "technique-remote-services-fb7ac358",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-direct-cloud-vm-connections-4fb1346f",
      "code": "Direct Cloud VM Connections",
      "value": "Direct Cloud VM Connections",
      "name": "Direct Cloud VM Connections",
      "definition": "Text about adversaries establishing unauthorized remote access sessions directly to virtual machine instances via cloud service provider management consoles or dedicated interfaces, bypassing standard perimeter security controls and public-facing network paths.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Lateral Movement",
        "Remote Services",
        "Direct Cloud VM Connections"
      ],
      "parentId": "technique-remote-services-fb7ac358",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-ssh-13b5099f",
      "code": "SSH",
      "value": "SSH",
      "name": "SSH",
      "definition": "Text about SSH subtechnique pertains to the illicit use of remote login protocols to establish persistent connections, manipulate host configurations, or authenticate between systems using compromised credentials or encryption keys.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Lateral Movement",
        "Remote Services",
        "SSH"
      ],
      "parentId": "technique-remote-services-fb7ac358",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-search-open-technical-databases-a4d67291",
      "code": "Search Open Technical Databases",
      "value": "Search Open Technical Databases",
      "name": "Search Open Technical Databases",
      "definition": "Text about exploiting publicly searchable repositories that index technical artifacts like digital certificates, DNS records, or WHOIS data to identify target infrastructure configurations and potential attack vectors against organizations.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Reconnaissance",
        "Search Open Technical Databases"
      ],
      "parentId": "tactic-reconnaissance-a9f8c2a8",
      "synthetic": false,
      "childCount": 5,
      "leaf": false
    },
    {
      "id": "subtechnique-digital-certificates-443588c6",
      "code": "Digital Certificates",
      "value": "Digital Certificates",
      "name": "Digital Certificates",
      "definition": "Text about threat actors leveraging illicitly obtained, forged, or intercepted digital certificates to sign malicious payloads, ensuring they appear authentic and trusted by security software and host operating systems.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Search Open Technical Databases",
        "Digital Certificates"
      ],
      "parentId": "technique-search-open-technical-databases-a4d67291",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-scan-databases-3d6897dc",
      "code": "Scan Databases",
      "value": "Scan Databases",
      "name": "Scan Databases",
      "definition": "Text about systematic network activity directed at database management systems to identify exposed interfaces, default credentials, version information, or unpatched software vulnerabilities facilitating unauthorized data discovery and subsequent compromise attempts.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Search Open Technical Databases",
        "Scan Databases"
      ],
      "parentId": "technique-search-open-technical-databases-a4d67291",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-dns-passive-dns-0655a6eb",
      "code": "DNS/Passive DNS",
      "value": "DNS/Passive DNS",
      "name": "DNS/Passive DNS",
      "definition": "Text about aggregating historical domain name resolution data to map adversarial infrastructure, revealing victim network configurations, server affiliations, and communication patterns by analyzing long-term records mapping queries to resolved addresses.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Search Open Technical Databases",
        "DNS/Passive DNS"
      ],
      "parentId": "technique-search-open-technical-databases-a4d67291",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-cdns-6b4a8a59",
      "code": "CDNs",
      "value": "CDNs",
      "name": "CDNs",
      "definition": "Text about adversaries leveraging commercial content delivery network infrastructure to host malicious payloads, command-and-control communications, or redirect traffic, thereby obfuscating the ultimate destination of network traffic and evading detection mechanisms.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Search Open Technical Databases",
        "CDNs"
      ],
      "parentId": "technique-search-open-technical-databases-a4d67291",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-whois-f24453a6",
      "code": "WHOIS",
      "value": "WHOIS",
      "name": "WHOIS",
      "definition": "Text about adversaries querying public registry databases to retrieve registration details, ownership contacts, and technical infrastructure information associated with victim-controlled domain names to assist in targeting and planning subsequent malicious operations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Search Open Technical Databases",
        "WHOIS"
      ],
      "parentId": "technique-search-open-technical-databases-a4d67291",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-rogue-domain-controller-676a459e",
      "code": "Rogue Domain Controller",
      "value": "Rogue Domain Controller",
      "name": "Rogue Domain Controller",
      "definition": "Text about attackers deploying a rogue server configured to operate as an illegitimate domain controller, facilitating the unauthorized replication of Active Directory objects and compromise of enterprise authentication and identity services.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Rogue Domain Controller"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-deploy-container-3b87d56b",
      "code": "Deploy Container",
      "value": "Deploy Container",
      "name": "Deploy Container",
      "definition": "Text about adversaries deploying localized container runtime instances to execute malicious software, manipulating orchestrator configurations or orchestration APIs to launch unauthorized containers that facilitate persistent access or isolate adversarial operational activities.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Deploy Container"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-deploy-container-deae6c00",
      "code": "Deploy Container",
      "value": "Deploy Container",
      "name": "Deploy Container",
      "definition": "Text about adversaries deploying localized container runtime instances to execute malicious software, manipulating orchestrator configurations or orchestration APIs to launch unauthorized containers that facilitate persistent access or isolate adversarial operational activities.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Execution",
        "Deploy Container"
      ],
      "parentId": "tactic-execution-6d525b71",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-modify-registry-69813e02",
      "code": "Modify Registry",
      "value": "Modify Registry",
      "name": "Modify Registry",
      "definition": "Text about the unauthorized modification of Windows Registry entries to manipulate system settings, automate code execution, hide malicious processes, or bypass system integrity protections during an active cyber intrusion.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Modify Registry"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-cloud-infrastructure-discovery-08786460",
      "code": "Cloud Infrastructure Discovery",
      "value": "Cloud Infrastructure Discovery",
      "name": "Cloud Infrastructure Discovery",
      "definition": "Text about adversarial efforts to locate and catalog cloud-hosted assets, including database clusters, network security groups, and identity management configurations, to establish a detailed blueprint of the compromised cloud environment architecture.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "Cloud Infrastructure Discovery"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-defacement-1987f5e9",
      "code": "Defacement",
      "value": "Defacement",
      "name": "Defacement",
      "definition": "Text about adversaries altering the visual content, source code, or functional integrity of publicly accessible websites or digital assets to cause reputational harm, broadcast messaging, or disrupt organizational operations.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Impact",
        "Defacement"
      ],
      "parentId": "tactic-impact-62036a70",
      "synthetic": false,
      "childCount": 2,
      "leaf": false
    },
    {
      "id": "subtechnique-external-defacement-811efdb5",
      "code": "External Defacement",
      "value": "External Defacement",
      "name": "External Defacement",
      "definition": "Text about the unauthorized modification of public-facing website content, where adversaries replace original information or graphics with their own materials, ultimately leveraging the modified presence to cause reputational or operational damage.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Impact",
        "Defacement",
        "External Defacement"
      ],
      "parentId": "technique-defacement-1987f5e9",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-internal-defacement-d20cc91b",
      "code": "Internal Defacement",
      "value": "Internal Defacement",
      "name": "Internal Defacement",
      "definition": "Text about compromised access leading to the unauthorized modification of internal system interfaces or hosted content to distribute false messaging intended to influence or mislead authorized organizational personnel.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Impact",
        "Defacement",
        "Internal Defacement"
      ],
      "parentId": "technique-defacement-1987f5e9",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-unused-unsupported-cloud-regions-da0c2168",
      "code": "Unused/Unsupported Cloud Regions",
      "value": "Unused/Unsupported Cloud Regions",
      "name": "Unused/Unsupported Cloud Regions",
      "definition": "Text about adversaries utilizing cloud compute resources located in geographical regions outside of an organization’s documented operational footprint, effectively bypassing region-specific security monitoring tools and preventing detection by defensive personnel.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Unused/Unsupported Cloud Regions"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-remote-service-session-hijacking-8d6bbf15",
      "code": "Remote Service Session Hijacking",
      "value": "Remote Service Session Hijacking",
      "name": "Remote Service Session Hijacking",
      "definition": "Text about adversaries commandeering active remote sessions to bypass authentication requirements, gaining unauthorized access by interacting directly with established communication channels to perform system operations within compromised network environments.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Lateral Movement",
        "Remote Service Session Hijacking"
      ],
      "parentId": "tactic-lateral-movement-4cec3f1f",
      "synthetic": false,
      "childCount": 2,
      "leaf": false
    },
    {
      "id": "subtechnique-rdp-hijacking-dcd2e554",
      "code": "RDP Hijacking",
      "value": "RDP Hijacking",
      "name": "RDP Hijacking",
      "definition": "Text about the clandestine seizure of an active Remote Desktop Protocol session, allowing malicious actors to bypass standard authentication mechanisms by utilizing an existing, validated session token on a target system.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Lateral Movement",
        "Remote Service Session Hijacking",
        "RDP Hijacking"
      ],
      "parentId": "technique-remote-service-session-hijacking-8d6bbf15",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-ssh-hijacking-8e26c45c",
      "code": "SSH Hijacking",
      "value": "SSH Hijacking",
      "name": "SSH Hijacking",
      "definition": "Text about malicious actors seizing control of an established secure shell session to execute arbitrary operations, which effectively allows unauthorized command execution via the existing encrypted and authenticated remote connection stream.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Lateral Movement",
        "Remote Service Session Hijacking",
        "SSH Hijacking"
      ],
      "parentId": "technique-remote-service-session-hijacking-8d6bbf15",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-browser-information-discovery-4dd3fac4",
      "code": "Browser Information Discovery",
      "value": "Browser Information Discovery",
      "name": "Browser Information Discovery",
      "definition": "Text about unauthorized actors targeting locally stored files and registry entries associated with web browsers to harvest credentials, session tokens, sensitive data, and user activity logs for post-compromise objectives.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "Browser Information Discovery"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-communication-through-removable-media-c8f686d1",
      "code": "Communication Through Removable Media",
      "value": "Communication Through Removable Media",
      "name": "Communication Through Removable Media",
      "definition": "Text about adversaries leveraging plug-and-play storage hardware as a covert transport mechanism to transmit instructions or extract sensitive data across network segment boundaries without relying on established internet connectivity.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Command and Control",
        "Communication Through Removable Media"
      ],
      "parentId": "tactic-command-and-control-6b4265ca",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-file-and-directory-permissions-modification-fede7384",
      "code": "File and Directory Permissions Modification",
      "value": "File and Directory Permissions Modification",
      "name": "File and Directory Permissions Modification",
      "definition": "Text about threat actors manipulating existing file system permissions, ownership, or access control lists to modify security policies governing object accessibility, ensuring continued operations or elevated access to critical system assets.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "File and Directory Permissions Modification"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 2,
      "leaf": false
    },
    {
      "id": "subtechnique-linux-and-mac-file-and-directory-permissions-modificat-0cb62b8c",
      "code": "Linux and Mac File and Directory Permissions Modification",
      "value": "Linux and Mac File and Directory Permissions Modification",
      "name": "Linux and Mac File and Directory Permissions Modification",
      "definition": "Text about the unauthorized modification of file system permission bits and ownership attributes on Linux or macOS systems to bypass access restrictions, obscure malicious activity, or escalate system privileges during operations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "File and Directory Permissions Modification",
        "Linux and Mac File and Directory Permissions Modification"
      ],
      "parentId": "technique-file-and-directory-permissions-modification-fede7384",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-windows-file-and-directory-permissions-modification-4b92859a",
      "code": "Windows File and Directory Permissions Modification",
      "value": "Windows File and Directory Permissions Modification",
      "name": "Windows File and Directory Permissions Modification",
      "definition": "Text about malicious Windows file and directory permissions modification which involves programmatically changing user authorizations to facilitate unauthorized data access or hinder remediation efforts during an ongoing security incident.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "File and Directory Permissions Modification",
        "Windows File and Directory Permissions Modification"
      ],
      "parentId": "technique-file-and-directory-permissions-modification-fede7384",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-active-scanning-7605d21c",
      "code": "Active Scanning",
      "value": "Active Scanning",
      "name": "Active Scanning",
      "definition": "Text about Active Scanning refers to adversarial activities involving the direct interrogation of victim infrastructure, forcing systems to disclose information about their network presence, service availability, and potential software vulnerabilities.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Reconnaissance",
        "Active Scanning"
      ],
      "parentId": "tactic-reconnaissance-a9f8c2a8",
      "synthetic": false,
      "childCount": 3,
      "leaf": false
    },
    {
      "id": "subtechnique-wordlist-scanning-070039ab",
      "code": "Wordlist Scanning",
      "value": "Wordlist Scanning",
      "name": "Wordlist Scanning",
      "definition": "Text about adversaries deploying automated mechanisms to flood authentication endpoints with dense volumes of credential permutations sourced from prepared lists, aiming to derive active account access via exhaustive verification attempts.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Active Scanning",
        "Wordlist Scanning"
      ],
      "parentId": "technique-active-scanning-7605d21c",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-scanning-ip-blocks-6cb10bde",
      "code": "Scanning IP Blocks",
      "value": "Scanning IP Blocks",
      "name": "Scanning IP Blocks",
      "definition": "Text about adversaries performing systematic sweeps of address ranges to identify active network endpoints, map system availability, and catalog viable targets for exploitation within a designated organizational or cloud infrastructure.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Active Scanning",
        "Scanning IP Blocks"
      ],
      "parentId": "technique-active-scanning-7605d21c",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-vulnerability-scanning-ba311061",
      "code": "Vulnerability Scanning",
      "value": "Vulnerability Scanning",
      "name": "Vulnerability Scanning",
      "definition": "Text about the active use of specialized scanning software to probe network infrastructure for known weaknesses, unpatched security vulnerabilities, or exposed administrative interfaces leveraged to inform targeted attack planning and execution.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Active Scanning",
        "Vulnerability Scanning"
      ],
      "parentId": "technique-active-scanning-7605d21c",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-abuse-elevation-control-mechanism-7f054bf5",
      "code": "Abuse Elevation Control Mechanism",
      "value": "Abuse Elevation Control Mechanism",
      "name": "Abuse Elevation Control Mechanism",
      "definition": "Text about attackers exploiting built-in administrative safeguards or configuration controls meant to oversee privilege boundaries, effectively overriding these protective barriers to acquire elevated access levels unauthorized within the target system.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Privilege Escalation",
        "Abuse Elevation Control Mechanism"
      ],
      "parentId": "tactic-privilege-escalation-dc3564ae",
      "synthetic": false,
      "childCount": 6,
      "leaf": false
    },
    {
      "id": "subtechnique-setuid-and-setgid-1152b884",
      "code": "Setuid and Setgid",
      "value": "Setuid and Setgid",
      "name": "Setuid and Setgid",
      "definition": "Text about adversaries exploiting binary permission settings that enable programs to execute with escalated privileges tied to the file owner or group rather than the user invoking the process.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Abuse Elevation Control Mechanism",
        "Setuid and Setgid"
      ],
      "parentId": "technique-abuse-elevation-control-mechanism-7f054bf5",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-temporary-elevated-cloud-access-f9d1bd9e",
      "code": "Temporary Elevated Cloud Access",
      "value": "Temporary Elevated Cloud Access",
      "name": "Temporary Elevated Cloud Access",
      "definition": "Text about the process where malicious actors secure brief, heightened authority within cloud environments by exploiting automated permission provisioning workflows to perform intrusive actions without permanent credential compromise.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Abuse Elevation Control Mechanism",
        "Temporary Elevated Cloud Access"
      ],
      "parentId": "technique-abuse-elevation-control-mechanism-7f054bf5",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-bypass-user-account-control-7326ba26",
      "code": "Bypass User Account Control",
      "value": "Bypass User Account Control",
      "name": "Bypass User Account Control",
      "definition": "Text about attackers exploiting system mechanisms designed to prevent unauthorized elevation by subverting process integrity levels, thereby executing malicious code with administrative access permissions without explicitly prompting the legitimate user.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Abuse Elevation Control Mechanism",
        "Bypass User Account Control"
      ],
      "parentId": "technique-abuse-elevation-control-mechanism-7f054bf5",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-elevated-execution-with-prompt-7536d0a1",
      "code": "Elevated Execution with Prompt",
      "value": "Elevated Execution with Prompt",
      "name": "Elevated Execution with Prompt",
      "definition": "Text about adversarial tactics utilizing system-generated authentication prompts to coerce users into inadvertently approving elevated execution of unauthorized code, thereby bypassing standard security restrictions during valid operational system workflows.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Abuse Elevation Control Mechanism",
        "Elevated Execution with Prompt"
      ],
      "parentId": "technique-abuse-elevation-control-mechanism-7f054bf5",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-sudo-and-sudo-caching-3b5f63ef",
      "code": "Sudo and Sudo Caching",
      "value": "Sudo and Sudo Caching",
      "name": "Sudo and Sudo Caching",
      "definition": "Text about adversaries misusing the sudo caching mechanism to sustain administrative access, facilitating the unauthorized execution of privileged operations by consuming valid session credentials immediately after legitimate user authentication.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Abuse Elevation Control Mechanism",
        "Sudo and Sudo Caching"
      ],
      "parentId": "technique-abuse-elevation-control-mechanism-7f054bf5",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-tcc-manipulation-a4a4aa9b",
      "code": "TCC Manipulation",
      "value": "TCC Manipulation",
      "name": "TCC Manipulation",
      "definition": "Text about TCC Manipulation describes the specific exploitation of the macOS permission framework where actors directly corrupt or alter the system database to bypass operational restrictions on accessing sensitive device features.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Abuse Elevation Control Mechanism",
        "TCC Manipulation"
      ],
      "parentId": "technique-abuse-elevation-control-mechanism-7f054bf5",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-abuse-elevation-control-mechanism-1b9179b0",
      "code": "Abuse Elevation Control Mechanism",
      "value": "Abuse Elevation Control Mechanism",
      "name": "Abuse Elevation Control Mechanism",
      "definition": "Text about attackers exploiting built-in administrative safeguards or configuration controls meant to oversee privilege boundaries, effectively overriding these protective barriers to acquire elevated access levels unauthorized within the target system.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Abuse Elevation Control Mechanism"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 6,
      "leaf": false
    },
    {
      "id": "subtechnique-setuid-and-setgid-2e279e12",
      "code": "Setuid and Setgid",
      "value": "Setuid and Setgid",
      "name": "Setuid and Setgid",
      "definition": "Text about adversaries exploiting binary permission settings that enable programs to execute with escalated privileges tied to the file owner or group rather than the user invoking the process.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Abuse Elevation Control Mechanism",
        "Setuid and Setgid"
      ],
      "parentId": "technique-abuse-elevation-control-mechanism-1b9179b0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-temporary-elevated-cloud-access-fdaf3921",
      "code": "Temporary Elevated Cloud Access",
      "value": "Temporary Elevated Cloud Access",
      "name": "Temporary Elevated Cloud Access",
      "definition": "Text about the process where malicious actors secure brief, heightened authority within cloud environments by exploiting automated permission provisioning workflows to perform intrusive actions without permanent credential compromise.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Abuse Elevation Control Mechanism",
        "Temporary Elevated Cloud Access"
      ],
      "parentId": "technique-abuse-elevation-control-mechanism-1b9179b0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-bypass-user-account-control-7ac10c0f",
      "code": "Bypass User Account Control",
      "value": "Bypass User Account Control",
      "name": "Bypass User Account Control",
      "definition": "Text about attackers exploiting system mechanisms designed to prevent unauthorized elevation by subverting process integrity levels, thereby executing malicious code with administrative access permissions without explicitly prompting the legitimate user.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Abuse Elevation Control Mechanism",
        "Bypass User Account Control"
      ],
      "parentId": "technique-abuse-elevation-control-mechanism-1b9179b0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-elevated-execution-with-prompt-8c37f36a",
      "code": "Elevated Execution with Prompt",
      "value": "Elevated Execution with Prompt",
      "name": "Elevated Execution with Prompt",
      "definition": "Text about adversarial tactics utilizing system-generated authentication prompts to coerce users into inadvertently approving elevated execution of unauthorized code, thereby bypassing standard security restrictions during valid operational system workflows.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Abuse Elevation Control Mechanism",
        "Elevated Execution with Prompt"
      ],
      "parentId": "technique-abuse-elevation-control-mechanism-1b9179b0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-sudo-and-sudo-caching-bb1d6449",
      "code": "Sudo and Sudo Caching",
      "value": "Sudo and Sudo Caching",
      "name": "Sudo and Sudo Caching",
      "definition": "Text about adversaries misusing the sudo caching mechanism to sustain administrative access, facilitating the unauthorized execution of privileged operations by consuming valid session credentials immediately after legitimate user authentication.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Abuse Elevation Control Mechanism",
        "Sudo and Sudo Caching"
      ],
      "parentId": "technique-abuse-elevation-control-mechanism-1b9179b0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-tcc-manipulation-776597c5",
      "code": "TCC Manipulation",
      "value": "TCC Manipulation",
      "name": "TCC Manipulation",
      "definition": "Text about TCC Manipulation describes the specific exploitation of the macOS permission framework where actors directly corrupt or alter the system database to bypass operational restrictions on accessing sensitive device features.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Abuse Elevation Control Mechanism",
        "TCC Manipulation"
      ],
      "parentId": "technique-abuse-elevation-control-mechanism-1b9179b0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-video-capture-7549323f",
      "code": "Video Capture",
      "value": "Video Capture",
      "name": "Video Capture",
      "definition": "Text about malicious actors leveraging software to commandeer native camera interfaces on compromised endpoints, enabling the continuous acquisition of video streams for the purpose of espionage and unauthorized visual telemetry.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Collection",
        "Video Capture"
      ],
      "parentId": "tactic-collection-30c54a96",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-system-network-configuration-discovery-a64a1a16",
      "code": "System Network Configuration Discovery",
      "value": "System Network Configuration Discovery",
      "name": "System Network Configuration Discovery",
      "definition": "Text about adversaries investigating the local network stack, routing information, and interface settings to discern the internal connectivity topology and relevant protocols present on a target system during unauthorized operations.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "System Network Configuration Discovery"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 2,
      "leaf": false
    },
    {
      "id": "subtechnique-wi-fi-discovery-4c25fb54",
      "code": "Wi-Fi Discovery",
      "value": "Wi-Fi Discovery",
      "name": "Wi-Fi Discovery",
      "definition": "Text about systematic enumeration of wireless network parameters including service set identifiers, broadcast frequencies, and security protocols by threat actors seeking to compromise or traverse local network infrastructure environments.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Discovery",
        "System Network Configuration Discovery",
        "Wi-Fi Discovery"
      ],
      "parentId": "technique-system-network-configuration-discovery-a64a1a16",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-internet-connection-discovery-f632287e",
      "code": "Internet Connection Discovery",
      "value": "Internet Connection Discovery",
      "name": "Internet Connection Discovery",
      "definition": "Text about adversaries executing commands to determine the presence, reachability, configuration, or status of an internet connection from a compromised host to facilitate further network-based malicious operations or data exfiltration activities.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Discovery",
        "System Network Configuration Discovery",
        "Internet Connection Discovery"
      ],
      "parentId": "technique-system-network-configuration-discovery-a64a1a16",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-account-discovery-58d85413",
      "code": "Account Discovery",
      "value": "Account Discovery",
      "name": "Account Discovery",
      "definition": "Text about Account Discovery details the technical methods employed by attackers to inventory user accounts, uncover administrator privileges, and list account attributes within enterprise systems to facilitate unauthorized access or privilege escalation.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "Account Discovery"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 4,
      "leaf": false
    },
    {
      "id": "subtechnique-email-account-c1e73e9d",
      "code": "Email Account",
      "value": "Email Account",
      "name": "Email Account",
      "definition": "Text about adversaries leveraging compromised legitimate email accounts to bypass authentication mechanisms, manipulate communication flows, or blend malicious activities within standard organizational workflows for unauthorized data access.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Discovery",
        "Account Discovery",
        "Email Account"
      ],
      "parentId": "technique-account-discovery-58d85413",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-cloud-account-ef010e91",
      "code": "Cloud Account",
      "value": "Cloud Account",
      "name": "Cloud Account",
      "definition": "Text about unauthorized actors acquiring control over cloud-based identity entities to establish persistence or facilitate continued malicious operations within a victim entity’s hosted computing or storage resource environments.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Discovery",
        "Account Discovery",
        "Cloud Account"
      ],
      "parentId": "technique-account-discovery-58d85413",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-domain-account-a46cbfd3",
      "code": "Domain Account",
      "value": "Domain Account",
      "name": "Domain Account",
      "definition": "Text about adversaries enumerating or gaining information on compromised domain accounts to map directory services, identify privileged users, or ascertain organizational structure before proceeding with further malicious network activities.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Discovery",
        "Account Discovery",
        "Domain Account"
      ],
      "parentId": "technique-account-discovery-58d85413",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-local-account-475fd0d9",
      "code": "Local Account",
      "value": "Local Account",
      "name": "Local Account",
      "definition": "Text about unauthorized actors configuring local system accounts to bypass domain-level restrictions, ensuring persistent entry or escalated authority by manipulating the host's native user repository and authentication configurations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Discovery",
        "Account Discovery",
        "Local Account"
      ],
      "parentId": "technique-account-discovery-58d85413",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-proxy-ebd03951",
      "code": "Proxy",
      "value": "Proxy",
      "name": "Proxy",
      "definition": "Text about malicious entities leveraging external servers or compromised hosts as conduits for relaying network traffic, effectively hiding the source IP address and complicating attribution for compromised organizational network environments.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Command and Control",
        "Proxy"
      ],
      "parentId": "tactic-command-and-control-6b4265ca",
      "synthetic": false,
      "childCount": 4,
      "leaf": false
    },
    {
      "id": "subtechnique-internal-proxy-fe655827",
      "code": "Internal Proxy",
      "value": "Internal Proxy",
      "name": "Internal Proxy",
      "definition": "Text about adversaries leveraging a compromised internal host to act as a pivot point, relaying unsolicited or malicious traffic to other internal systems, effectively obscuring the true origin point.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Command and Control",
        "Proxy",
        "Internal Proxy"
      ],
      "parentId": "technique-proxy-ebd03951",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-multi-hop-proxy-030150d0",
      "code": "Multi-hop Proxy",
      "value": "Multi-hop Proxy",
      "name": "Multi-hop Proxy",
      "definition": "Text about threat actors deploying multi-stage proxy relay chains to obscure the source of malicious connections, making it difficult for investigators to identify the origin of hostile traffic.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Command and Control",
        "Proxy",
        "Multi-hop Proxy"
      ],
      "parentId": "technique-proxy-ebd03951",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-domain-fronting-fd95775f",
      "code": "Domain Fronting",
      "value": "Domain Fronting",
      "name": "Domain Fronting",
      "definition": "Text about Domain Fronting entails abusing the discrepancy between the Server Name Indication field and the HTTP 'Host' header to tunnel command and control traffic through legitimate, highly reputable content delivery network infrastructure.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Command and Control",
        "Proxy",
        "Domain Fronting"
      ],
      "parentId": "technique-proxy-ebd03951",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-external-proxy-d9cf6487",
      "code": "External Proxy",
      "value": "External Proxy",
      "name": "External Proxy",
      "definition": "Text about an adversary routing malicious traffic through internet-facing intermediary servers to deceive defensive systems by misrepresenting the source of connection attempts aiming to access internal organizational network assets.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Command and Control",
        "Proxy",
        "External Proxy"
      ],
      "parentId": "technique-proxy-ebd03951",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-command-and-scripting-interpreter-e72bca61",
      "code": "Command and Scripting Interpreter",
      "value": "Command and Scripting Interpreter",
      "name": "Command and Scripting Interpreter",
      "definition": "Text about attackers directing system execution flows through installed command-line processors or scripting engines to manipulate operating system functions, execute unauthorized binaries, or orchestrate complex multi-stage attack workflows on target hosts.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Execution",
        "Command and Scripting Interpreter"
      ],
      "parentId": "tactic-execution-6d525b71",
      "synthetic": false,
      "childCount": 11,
      "leaf": false
    },
    {
      "id": "subtechnique-visual-basic-3bb411b2",
      "code": "Visual Basic",
      "value": "Visual Basic",
      "name": "Visual Basic",
      "definition": "Text about Visual Basic involving the misuse of the Visual Basic scripting engine to execute malicious operations, enabling adversaries to run code and issue commands within the target operating system environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Execution",
        "Command and Scripting Interpreter",
        "Visual Basic"
      ],
      "parentId": "technique-command-and-scripting-interpreter-e72bca61",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-applescript-4a7a2ba6",
      "code": "AppleScript",
      "value": "AppleScript",
      "name": "AppleScript",
      "definition": "Text about cyber adversaries leveraging the AppleScript scripting interface on macOS to execute unauthorized commands, control desktop applications, or perform automated system manipulations for persistent or invasive operational activity.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Execution",
        "Command and Scripting Interpreter",
        "AppleScript"
      ],
      "parentId": "technique-command-and-scripting-interpreter-e72bca61",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-windows-command-shell-d2b879da",
      "code": "Windows Command Shell",
      "value": "Windows Command Shell",
      "name": "Windows Command Shell",
      "definition": "Text about adversaries employing the Windows command shell processing utility to input and execute system-level commands, allowing manual execution of malicious logic and interaction with underlying operating system functionality.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Execution",
        "Command and Scripting Interpreter",
        "Windows Command Shell"
      ],
      "parentId": "technique-command-and-scripting-interpreter-e72bca61",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-unix-shell-d0300b78",
      "code": "Unix Shell",
      "value": "Unix Shell",
      "name": "Unix Shell",
      "definition": "Text about the adversarial reliance on Unix shell interpreter functionalities to execute commands across enterprise environments, facilitating unauthorized access, control, and manipulation of host-level resources during various stages of attack.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Execution",
        "Command and Scripting Interpreter",
        "Unix Shell"
      ],
      "parentId": "technique-command-and-scripting-interpreter-e72bca61",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-autohotkey-autoit-4c4106f0",
      "code": "AutoHotKey & AutoIT",
      "value": "AutoHotKey & AutoIT",
      "name": "AutoHotKey & AutoIT",
      "definition": "Text about AutoHotKey & AutoIT sub-technique refers to executing malicious scripts within authorized automation environments to control system processes, manipulate windows, or perform unauthorized administrative actions without deploying traditional binary-based malware files.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Execution",
        "Command and Scripting Interpreter",
        "AutoHotKey & AutoIT"
      ],
      "parentId": "technique-command-and-scripting-interpreter-e72bca61",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-network-device-cli-e45b0635",
      "code": "Network Device CLI",
      "value": "Network Device CLI",
      "name": "Network Device CLI",
      "definition": "Text about attackers utilizing the native command-line interface of network hardware like routers or switches to perform unauthorized administrative actions, facilitating persistence, situational awareness, and potential disruption of critical network infrastructure.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Execution",
        "Command and Scripting Interpreter",
        "Network Device CLI"
      ],
      "parentId": "technique-command-and-scripting-interpreter-e72bca61",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-python-43ab5b6c",
      "code": "Python",
      "value": "Python",
      "name": "Python",
      "definition": "Text about Python within procedural frameworks identifies the reliance on standardized scripting environments by threat actors to execute modular, cross-platform code capable of performing reconnaissance, unauthorized modifications, or command control.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Execution",
        "Command and Scripting Interpreter",
        "Python"
      ],
      "parentId": "technique-command-and-scripting-interpreter-e72bca61",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-powershell-83ec0796",
      "code": "PowerShell",
      "value": "PowerShell",
      "name": "PowerShell",
      "definition": "Text about PowerShell denotes the abuse of the command-line shell and associated scripting language to execute arbitrary commands, facilitate remote access, perform lateral movement, or conduct unauthorized system administration tasks during attacks.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Execution",
        "Command and Scripting Interpreter",
        "PowerShell"
      ],
      "parentId": "technique-command-and-scripting-interpreter-e72bca61",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-cloud-api-8c8c81fc",
      "code": "Cloud API",
      "value": "Cloud API",
      "name": "Cloud API",
      "definition": "Text about threat actors leveraging application programming interfaces provided by cloud services to issue commands, alter infrastructure management settings, or access protected data stores through authorized but misused operational communication channels.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Execution",
        "Command and Scripting Interpreter",
        "Cloud API"
      ],
      "parentId": "technique-command-and-scripting-interpreter-e72bca61",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-lua-dd386e10",
      "code": "Lua",
      "value": "Lua",
      "name": "Lua",
      "definition": "Text about the employment of Lua scripts by malicious actors to perform arbitrary code execution, automate system interaction, or bypass security restrictions within targeted environments during computer network exploitation operations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Execution",
        "Command and Scripting Interpreter",
        "Lua"
      ],
      "parentId": "technique-command-and-scripting-interpreter-e72bca61",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-javascript-aaa670dc",
      "code": "JavaScript",
      "value": "JavaScript",
      "name": "JavaScript",
      "definition": "Text about the use of JavaScript engines to process malicious scripts, allowing adversaries to execute arbitrary commands locally or remotely, facilitating stealthy system compromise and persistent control within target organizational environments.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Execution",
        "Command and Scripting Interpreter",
        "JavaScript"
      ],
      "parentId": "technique-command-and-scripting-interpreter-e72bca61",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-domain-trust-discovery-1d66a1c8",
      "code": "Domain Trust Discovery",
      "value": "Domain Trust Discovery",
      "name": "Domain Trust Discovery",
      "definition": "Text about adversaries obtaining configuration details regarding domain trusts to pinpoint strategic pivot points where authentication boundaries weaken, enabling cross-domain access and deeper infiltration across an interconnected network ecosystem.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "Domain Trust Discovery"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-automated-exfiltration-fc9e50be",
      "code": "Automated Exfiltration",
      "value": "Automated Exfiltration",
      "name": "Automated Exfiltration",
      "definition": "Text about Automated Exfiltration concerns the programmatic transfer of sensitive victim data from compromised network environments to adversary-controlled infrastructure using scripts or tools configured for autonomous, scalable, and systematic execution.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Exfiltration",
        "Automated Exfiltration"
      ],
      "parentId": "tactic-exfiltration-fcb9fccc",
      "synthetic": false,
      "childCount": 1,
      "leaf": false
    },
    {
      "id": "subtechnique-traffic-duplication-9f033867",
      "code": "Traffic Duplication",
      "value": "Traffic Duplication",
      "name": "Traffic Duplication",
      "definition": "Text about Traffic Duplication describes adversarial actions involving the cloning of network communications to mirror sensitive data or traffic streams to external or unauthorized systems for exfiltration and monitoring purposes.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Exfiltration",
        "Automated Exfiltration",
        "Traffic Duplication"
      ],
      "parentId": "technique-automated-exfiltration-fc9e50be",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-indicator-removal-635b032d",
      "code": "Indicator Removal",
      "value": "Indicator Removal",
      "name": "Indicator Removal",
      "definition": "Text about deliberate actions taken by attackers to remove, overwrite, or hide evidence of their presence within a compromised system by purging logs, clearing event caches, and sanitizing volatile memory traces.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Indicator Removal"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 10,
      "leaf": false
    },
    {
      "id": "subtechnique-file-deletion-4ff24c75",
      "code": "File Deletion",
      "value": "File Deletion",
      "name": "File Deletion",
      "definition": "Text about the removal of files from a compromised endpoint, which enables adversaries to conceal the presence of unauthorized tools, delete generated logs, and successfully hinder efforts to analyze intrusion scope.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Indicator Removal",
        "File Deletion"
      ],
      "parentId": "technique-indicator-removal-635b032d",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-timestomp-ecd98044",
      "code": "Timestomp",
      "value": "Timestomp",
      "name": "Timestomp",
      "definition": "Text about Timestomp entails methods used by adversaries to modify file metadata fields, specifically timestamp data, to obscure the true chronology of their activities and hinder effective forensic incident reconstruction.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Indicator Removal",
        "Timestomp"
      ],
      "parentId": "technique-indicator-removal-635b032d",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-clear-mailbox-data-26ee7480",
      "code": "Clear Mailbox Data",
      "value": "Clear Mailbox Data",
      "name": "Clear Mailbox Data",
      "definition": "Text about malicious actors programmatically purging email logs, messages, and attachments from a compromised mailbox environment to destroy evidence of their activities and hinder incident response forensic analysis efforts.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Indicator Removal",
        "Clear Mailbox Data"
      ],
      "parentId": "technique-indicator-removal-635b032d",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-clear-linux-or-mac-system-logs-bbbb9500",
      "code": "Clear Linux or Mac System Logs",
      "value": "Clear Linux or Mac System Logs",
      "name": "Clear Linux or Mac System Logs",
      "definition": "Text about the removal or corruption of stored system log entries on macOS or Linux systems by unauthorized actors seeking to minimize their footprint and disrupt log-based detection capabilities.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Indicator Removal",
        "Clear Linux or Mac System Logs"
      ],
      "parentId": "technique-indicator-removal-635b032d",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-clear-windows-event-logs-1b522ea3",
      "code": "Clear Windows Event Logs",
      "value": "Clear Windows Event Logs",
      "name": "Clear Windows Event Logs",
      "definition": "Text about the deliberate purging of Windows Event Log records to disrupt incident response efforts, hinder attribution, and avoid detection by security monitoring tools after executing unauthorized system modifications.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Indicator Removal",
        "Clear Windows Event Logs"
      ],
      "parentId": "technique-indicator-removal-635b032d",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-clear-persistence-f9e78a1e",
      "code": "Clear Persistence",
      "value": "Clear Persistence",
      "name": "Clear Persistence",
      "definition": "Text about the deliberate removal of persistent modules, services, or registry modifications that enabled sustained system access, aimed at sanitizing the compromise footprint and reducing discoverability of the previous intrusion.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Indicator Removal",
        "Clear Persistence"
      ],
      "parentId": "technique-indicator-removal-635b032d",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-clear-command-history-99881ec2",
      "code": "Clear Command History",
      "value": "Clear Command History",
      "name": "Clear Command History",
      "definition": "Text about threat actors eliminating entries from persistent shell command history files to thwart post-incident review and analysis of the specific methodologies employed during illicit access to a target system.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Indicator Removal",
        "Clear Command History"
      ],
      "parentId": "technique-indicator-removal-635b032d",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-relocate-malware-59b62083",
      "code": "Relocate Malware",
      "value": "Relocate Malware",
      "name": "Relocate Malware",
      "definition": "Text about the strategic shifting of malicious executable files across distinct directories or storage volumes to achieve persistence and circumvent local security controls through unauthorized code relocation on target systems.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Indicator Removal",
        "Relocate Malware"
      ],
      "parentId": "technique-indicator-removal-635b032d",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-clear-network-connection-history-and-configurations-8087427d",
      "code": "Clear Network Connection History and Configurations",
      "value": "Clear Network Connection History and Configurations",
      "name": "Clear Network Connection History and Configurations",
      "definition": "Text about the specific adversarial behavior of clearing historical logs and modifying network configuration data to erase evidence of connectivity, thereby complicating efforts by defenders to identify past malicious communication channels.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Indicator Removal",
        "Clear Network Connection History and Configurations"
      ],
      "parentId": "technique-indicator-removal-635b032d",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-network-share-connection-removal-47db769e",
      "code": "Network Share Connection Removal",
      "value": "Network Share Connection Removal",
      "name": "Network Share Connection Removal",
      "definition": "Text about adversaries intentionally severing established network share relationships to limit investigative visibility, preventing defenders from easily identifying the source of unauthorized resource access during post-compromise incident analysis activities.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Indicator Removal",
        "Network Share Connection Removal"
      ],
      "parentId": "technique-indicator-removal-635b032d",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-container-administration-command-ed26b98e",
      "code": "Container Administration Command",
      "value": "Container Administration Command",
      "name": "Container Administration Command",
      "definition": "Text about Container Administration Command encompasses the adversarial action of leveraging administrative interfaces within container orchestration systems to execute unauthorized management commands that alter, deploy, or manage containerized application components.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Execution",
        "Container Administration Command"
      ],
      "parentId": "tactic-execution-6d525b71",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-file-and-directory-discovery-5b2c317b",
      "code": "File and Directory Discovery",
      "value": "File and Directory Discovery",
      "name": "File and Directory Discovery",
      "definition": "Text about adversaries enumerating information concerning files or directories residing on compromised systems to identify sensitive data, configuration files, or potential targets for subsequent operations within the compromised network environment.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "File and Directory Discovery"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-dynamic-resolution-37ec35d3",
      "code": "Dynamic Resolution",
      "value": "Dynamic Resolution",
      "name": "Dynamic Resolution",
      "definition": "Text about adversaries leveraging flexible infrastructure resolution to reassign network locations during campaigns, thereby preventing the identification of infrastructure by security systems relying exclusively upon static domain or address resolution records.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Command and Control",
        "Dynamic Resolution"
      ],
      "parentId": "tactic-command-and-control-6b4265ca",
      "synthetic": false,
      "childCount": 3,
      "leaf": false
    },
    {
      "id": "subtechnique-fast-flux-dns-c54240a6",
      "code": "Fast Flux DNS",
      "value": "Fast Flux DNS",
      "name": "Fast Flux DNS",
      "definition": "Text about attackers utilizing a network of compromised hosts as proxies to rapidly change DNS record mappings for malicious domains, effectively masking the true location of command and control servers.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Command and Control",
        "Dynamic Resolution",
        "Fast Flux DNS"
      ],
      "parentId": "technique-dynamic-resolution-37ec35d3",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-domain-generation-algorithms-a62da9b4",
      "code": "Domain Generation Algorithms",
      "value": "Domain Generation Algorithms",
      "name": "Domain Generation Algorithms",
      "definition": "Text about adversaries utilizing computed pseudo-random domain names to bypass static network defenses, enabling persistent communication sessions between compromised devices and their remotely operated command and control server infrastructure.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Command and Control",
        "Dynamic Resolution",
        "Domain Generation Algorithms"
      ],
      "parentId": "technique-dynamic-resolution-37ec35d3",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-dns-calculation-94bcbcb7",
      "code": "DNS Calculation",
      "value": "DNS Calculation",
      "name": "DNS Calculation",
      "definition": "Text about the practice of adversaries using mathematical formulas to compute domain names in real-time for command and control connectivity, which effectively automates the rotation of infrastructure to bypass static sensor detection.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Command and Control",
        "Dynamic Resolution",
        "DNS Calculation"
      ],
      "parentId": "technique-dynamic-resolution-37ec35d3",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-plist-file-modification-55426bfb",
      "code": "Plist File Modification",
      "value": "Plist File Modification",
      "name": "Plist File Modification",
      "definition": "Text about the process where attackers modify specific property list files to redefine application launch behaviors, manipulate system service configurations, or establish long-term persistence mechanisms within the targeted Apple ecosystem.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Plist File Modification"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-data-staged-d92b28d1",
      "code": "Data Staged",
      "value": "Data Staged",
      "name": "Data Staged",
      "definition": "Text about gathering and structuring stolen data into specific locations on a compromised host, preparing the consolidated payload for efficient egress procedures or further manipulation by unauthorized system operators.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Collection",
        "Data Staged"
      ],
      "parentId": "tactic-collection-30c54a96",
      "synthetic": false,
      "childCount": 2,
      "leaf": false
    },
    {
      "id": "subtechnique-local-data-staging-905375fb",
      "code": "Local Data Staging",
      "value": "Local Data Staging",
      "name": "Local Data Staging",
      "definition": "Text about hostile actors creating staging areas or repositories on a local compromised system to collect and organize data before performing exfiltration or other unauthorized processing of the stolen materials.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Collection",
        "Data Staged",
        "Local Data Staging"
      ],
      "parentId": "technique-data-staged-d92b28d1",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-remote-data-staging-26869a34",
      "code": "Remote Data Staging",
      "value": "Remote Data Staging",
      "name": "Remote Data Staging",
      "definition": "Text about Remote Data Staging refers to adversaries collecting and aggregating victim data within a remote system or network location to facilitate exfiltration from a compromised environment to external control servers.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Collection",
        "Data Staged",
        "Remote Data Staging"
      ],
      "parentId": "technique-data-staged-d92b28d1",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-steal-or-forge-authentication-certificates-1c74ddbb",
      "code": "Steal or Forge Authentication Certificates",
      "value": "Steal or Forge Authentication Certificates",
      "name": "Steal or Forge Authentication Certificates",
      "definition": "Text about adversaries stealing existing valid cryptographic certificates or creating forged alternatives to subvert identity verification protocols, enabling unauthorized access by successfully mimicking trusted network entities or authorized users.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Credential Access",
        "Steal or Forge Authentication Certificates"
      ],
      "parentId": "tactic-credential-access-9c65f4e0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-system-network-connections-discovery-62c2a20d",
      "code": "System Network Connections Discovery",
      "value": "System Network Connections Discovery",
      "name": "System Network Connections Discovery",
      "definition": "Text about adversaries gathering information regarding existing network connections to identify active communication flows, established socket states, and listening processes on a compromised host to map internal infrastructure layouts and configurations.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "System Network Connections Discovery"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-compromise-infrastructure-ebdf07bf",
      "code": "Compromise Infrastructure",
      "value": "Compromise Infrastructure",
      "name": "Compromise Infrastructure",
      "definition": "Text about malicious entities illicitly obtaining, modifying, or repurposing external digital infrastructure to execute command and control, facilitate data staging, or support other phases of unauthorized network access and exploitation.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Resource Development",
        "Compromise Infrastructure"
      ],
      "parentId": "tactic-resource-development-ce56343a",
      "synthetic": false,
      "childCount": 8,
      "leaf": false
    },
    {
      "id": "subtechnique-virtual-private-server-f5bc76fd",
      "code": "Virtual Private Server",
      "value": "Virtual Private Server",
      "name": "Virtual Private Server",
      "definition": "Text about adversaries leveraging virtual private server environments to deploy and manage malicious infrastructure, enabling them to execute command and control, store payloads, and obfuscate network traffic routing.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Compromise Infrastructure",
        "Virtual Private Server"
      ],
      "parentId": "technique-compromise-infrastructure-ebdf07bf",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-dns-server-fdf8d18b",
      "code": "DNS Server",
      "value": "DNS Server",
      "name": "DNS Server",
      "definition": "Text about adversaries deploying malicious DNS server configurations to intercept internal network name resolution, facilitating man-in-the-middle attacks or data exfiltration by redirecting traffic to attacker-controlled endpoints for further exploitation.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Compromise Infrastructure",
        "DNS Server"
      ],
      "parentId": "technique-compromise-infrastructure-ebdf07bf",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-web-services-5b45c076",
      "code": "Web Services",
      "value": "Web Services",
      "name": "Web Services",
      "definition": "Text about threat actors repurposing legitimate web-accessible applications and cloud APIs to act as command and control intermediaries, enabling stealthy remote management of compromised systems over standard web traffic channels.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Compromise Infrastructure",
        "Web Services"
      ],
      "parentId": "technique-compromise-infrastructure-ebdf07bf",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-serverless-06ad674e",
      "code": "Serverless",
      "value": "Serverless",
      "name": "Serverless",
      "definition": "Text about serverless addresses the exploitation of serverless computing platforms where adversaries manipulate function code, dependencies, or IAM roles to gain unauthorized access or execute commands within managed, stateless cloud runtime environments.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Compromise Infrastructure",
        "Serverless"
      ],
      "parentId": "technique-compromise-infrastructure-ebdf07bf",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-botnet-514ce9e9",
      "code": "Botnet",
      "value": "Botnet",
      "name": "Botnet",
      "definition": "Text about adversaries recruiting infected systems into a centrally managed network architecture for executing simultaneous commands, distributing malware payloads, or performing large-scale malicious operations to disrupt or exfiltrate target data.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Compromise Infrastructure",
        "Botnet"
      ],
      "parentId": "technique-compromise-infrastructure-ebdf07bf",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-server-8a9277c2",
      "code": "Server",
      "value": "Server",
      "name": "Server",
      "definition": "Text about Server subtechnique category refers to malicious infrastructure assets procured, leased, or seized by adversaries to host command and control listeners, staging repositories, or redirectors critical for executing operational objectives.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Compromise Infrastructure",
        "Server"
      ],
      "parentId": "technique-compromise-infrastructure-ebdf07bf",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-network-devices-20521dc3",
      "code": "Network Devices",
      "value": "Network Devices",
      "name": "Network Devices",
      "definition": "Text about adversaries gaining unauthorized access to critical network infrastructure interfaces to modify routing tables, intercept communications, or establish hidden command and control channels within the targeted enterprise communication ecosystem.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Compromise Infrastructure",
        "Network Devices"
      ],
      "parentId": "technique-compromise-infrastructure-ebdf07bf",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-domains-95341a77",
      "code": "Domains",
      "value": "Domains",
      "name": "Domains",
      "definition": "Text about adversaries acquiring domains by registering new domain names or purchasing existing ones to support operations such as command and control, phishing, and staging of malicious infrastructure.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Compromise Infrastructure",
        "Domains"
      ],
      "parentId": "technique-compromise-infrastructure-ebdf07bf",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-pre-os-boot-56a45b48",
      "code": "Pre-OS Boot",
      "value": "Pre-OS Boot",
      "name": "Pre-OS Boot",
      "definition": "Text about unauthorized modifications to system firmware or boot sequence components that insert adversarial code into the execution path well before the primary operating system kernel starts, maintaining long-term clandestine access.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Pre-OS Boot"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 5,
      "leaf": false
    },
    {
      "id": "subtechnique-bootkit-121ea25b",
      "code": "Bootkit",
      "value": "Bootkit",
      "name": "Bootkit",
      "definition": "Text about the alteration of system firmware or boot sector components, granting adversaries control over the startup execution chain to maintain presence below the level of the operating system.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Pre-OS Boot",
        "Bootkit"
      ],
      "parentId": "technique-pre-os-boot-56a45b48",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-tftp-boot-9feba90c",
      "code": "TFTP Boot",
      "value": "TFTP Boot",
      "name": "TFTP Boot",
      "definition": "Text about TFTP Boot entails the compromise of device integrity by supplying malicious boot loaders via the Trivial File Transfer Protocol, exploiting standard PXE or firmware update mechanisms during startup.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Pre-OS Boot",
        "TFTP Boot"
      ],
      "parentId": "technique-pre-os-boot-56a45b48",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-component-firmware-04be26ce",
      "code": "Component Firmware",
      "value": "Component Firmware",
      "name": "Component Firmware",
      "definition": "Text about utilizing peripheral firmware modification to insert adversarial implants directly into hardware component storage, ensuring malicious code persists across reboots and remains invisible to standard kernel-level security monitoring tools.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Pre-OS Boot",
        "Component Firmware"
      ],
      "parentId": "technique-pre-os-boot-56a45b48",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-rommonkit-a087dd2d",
      "code": "ROMMONkit",
      "value": "ROMMONkit",
      "name": "ROMMONkit",
      "definition": "Text about adversaries leveraging the Read-Only Memory Monitor to execute malicious firmware modifications on networking hardware, enabling persistent, long-term unauthorized access that remains hidden from standard operating system level security assessments.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Pre-OS Boot",
        "ROMMONkit"
      ],
      "parentId": "technique-pre-os-boot-56a45b48",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-system-firmware-e5ba2ee1",
      "code": "System Firmware",
      "value": "System Firmware",
      "name": "System Firmware",
      "definition": "Text about attackers gaining unauthorized access to and modifying system firmware to execute malicious instructions during the boot process, thereby establishing persistence at a privilege level higher than the installed operating system.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Pre-OS Boot",
        "System Firmware"
      ],
      "parentId": "technique-pre-os-boot-56a45b48",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-pre-os-boot-8ac046ef",
      "code": "Pre-OS Boot",
      "value": "Pre-OS Boot",
      "name": "Pre-OS Boot",
      "definition": "Text about unauthorized modifications to system firmware or boot sequence components that insert adversarial code into the execution path well before the primary operating system kernel starts, maintaining long-term clandestine access.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Persistence",
        "Pre-OS Boot"
      ],
      "parentId": "tactic-persistence-4782469e",
      "synthetic": false,
      "childCount": 5,
      "leaf": false
    },
    {
      "id": "subtechnique-bootkit-bda15246",
      "code": "Bootkit",
      "value": "Bootkit",
      "name": "Bootkit",
      "definition": "Text about the alteration of system firmware or boot sector components, granting adversaries control over the startup execution chain to maintain presence below the level of the operating system.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Pre-OS Boot",
        "Bootkit"
      ],
      "parentId": "technique-pre-os-boot-8ac046ef",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-tftp-boot-945c0b7d",
      "code": "TFTP Boot",
      "value": "TFTP Boot",
      "name": "TFTP Boot",
      "definition": "Text about TFTP Boot entails the compromise of device integrity by supplying malicious boot loaders via the Trivial File Transfer Protocol, exploiting standard PXE or firmware update mechanisms during startup.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Pre-OS Boot",
        "TFTP Boot"
      ],
      "parentId": "technique-pre-os-boot-8ac046ef",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-component-firmware-cfd5695a",
      "code": "Component Firmware",
      "value": "Component Firmware",
      "name": "Component Firmware",
      "definition": "Text about utilizing peripheral firmware modification to insert adversarial implants directly into hardware component storage, ensuring malicious code persists across reboots and remains invisible to standard kernel-level security monitoring tools.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Pre-OS Boot",
        "Component Firmware"
      ],
      "parentId": "technique-pre-os-boot-8ac046ef",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-rommonkit-7edcb86b",
      "code": "ROMMONkit",
      "value": "ROMMONkit",
      "name": "ROMMONkit",
      "definition": "Text about adversaries leveraging the Read-Only Memory Monitor to execute malicious firmware modifications on networking hardware, enabling persistent, long-term unauthorized access that remains hidden from standard operating system level security assessments.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Pre-OS Boot",
        "ROMMONkit"
      ],
      "parentId": "technique-pre-os-boot-8ac046ef",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-system-firmware-4f742895",
      "code": "System Firmware",
      "value": "System Firmware",
      "name": "System Firmware",
      "definition": "Text about attackers gaining unauthorized access to and modifying system firmware to execute malicious instructions during the boot process, thereby establishing persistence at a privilege level higher than the installed operating system.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Pre-OS Boot",
        "System Firmware"
      ],
      "parentId": "technique-pre-os-boot-8ac046ef",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-build-image-on-host-f97173c0",
      "code": "Build Image on Host",
      "value": "Build Image on Host",
      "name": "Build Image on Host",
      "definition": "Text about adversaries constructing virtualized or containerized software images directly on a compromised system to facilitate the subsequent deployment and execution of unauthorized tools, malicious services, or persistent backdoor components.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Build Image on Host"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-compromise-accounts-3ecba145",
      "code": "Compromise Accounts",
      "value": "Compromise Accounts",
      "name": "Compromise Accounts",
      "definition": "Text about threat actors attaining unauthorized access by seizing legitimate credentials, allowing them to impersonate valid users and utilize established permissions to perform actions across the targeted network environment.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Resource Development",
        "Compromise Accounts"
      ],
      "parentId": "tactic-resource-development-ce56343a",
      "synthetic": false,
      "childCount": 3,
      "leaf": false
    },
    {
      "id": "subtechnique-cloud-accounts-7528bf86",
      "code": "Cloud Accounts",
      "value": "Cloud Accounts",
      "name": "Cloud Accounts",
      "definition": "Text about Cloud Accounts identifies the use of compromised or illicitly obtained credentials specific to cloud platform ecosystems, enabling attackers to perform malicious actions while masquerading as authorized system entities.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Compromise Accounts",
        "Cloud Accounts"
      ],
      "parentId": "technique-compromise-accounts-3ecba145",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-email-accounts-6f59bb57",
      "code": "Email Accounts",
      "value": "Email Accounts",
      "name": "Email Accounts",
      "definition": "Text about attackers exploiting or procuring email accounts to impersonate users, distribute malware, or illicitly access sensitive data while appearing as authenticated participants within the targeted organization's internal and external communications.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Compromise Accounts",
        "Email Accounts"
      ],
      "parentId": "technique-compromise-accounts-3ecba145",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-social-media-accounts-b75c08b8",
      "code": "Social Media Accounts",
      "value": "Social Media Accounts",
      "name": "Social Media Accounts",
      "definition": "Text about adversaries manipulating externally hosted user profiles to obtain sensitive intelligence, cultivate undue influence over targeted individuals, or distribute malicious communications while disguising operational intent within public digital platforms.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Compromise Accounts",
        "Social Media Accounts"
      ],
      "parentId": "technique-compromise-accounts-3ecba145",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-virtualization-sandbox-evasion-914620df",
      "code": "Virtualization/Sandbox Evasion",
      "value": "Virtualization/Sandbox Evasion",
      "name": "Virtualization/Sandbox Evasion",
      "definition": "Text about methods adversaries utilize for detecting the presence of virtualized, sandboxed, or emulated systems, enabling malicious payloads to modify behavior and avoid exposure to automated security analysis tools.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Virtualization/Sandbox Evasion"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 3,
      "leaf": false
    },
    {
      "id": "subtechnique-user-activity-based-checks-f4cd02a8",
      "code": "User Activity Based Checks",
      "value": "User Activity Based Checks",
      "name": "User Activity Based Checks",
      "definition": "Text about user activity based checks involves the systematic inspection of session-specific interactions to determine if the generated activity strictly conforms to standard operational patterns of authorized personnel accounts.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Virtualization/Sandbox Evasion",
        "User Activity Based Checks"
      ],
      "parentId": "technique-virtualization-sandbox-evasion-914620df",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-system-checks-7cb04a7e",
      "code": "System Checks",
      "value": "System Checks",
      "name": "System Checks",
      "definition": "Text about attackers running diagnostic inquiries on compromised hosts to discern active security mechanisms, hardware specifications, or software patch levels, confirming environmental readiness for the deployment of additional malicious code modules.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Virtualization/Sandbox Evasion",
        "System Checks"
      ],
      "parentId": "technique-virtualization-sandbox-evasion-914620df",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-time-based-evasion-5a74ae99",
      "code": "Time Based Evasion",
      "value": "Time Based Evasion",
      "name": "Time Based Evasion",
      "definition": "Text about adversaries stalling execution or altering behavioral patterns using deliberate temporal delays to avoid detection mechanisms, bypass automated malware analysis, or frustrate security analysts attempting to observe procedural activity.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Virtualization/Sandbox Evasion",
        "Time Based Evasion"
      ],
      "parentId": "technique-virtualization-sandbox-evasion-914620df",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-virtualization-sandbox-evasion-179f3170",
      "code": "Virtualization/Sandbox Evasion",
      "value": "Virtualization/Sandbox Evasion",
      "name": "Virtualization/Sandbox Evasion",
      "definition": "Text about methods adversaries utilize for detecting the presence of virtualized, sandboxed, or emulated systems, enabling malicious payloads to modify behavior and avoid exposure to automated security analysis tools.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "Virtualization/Sandbox Evasion"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 3,
      "leaf": false
    },
    {
      "id": "subtechnique-user-activity-based-checks-9fb10b4d",
      "code": "User Activity Based Checks",
      "value": "User Activity Based Checks",
      "name": "User Activity Based Checks",
      "definition": "Text about user activity based checks involves the systematic inspection of session-specific interactions to determine if the generated activity strictly conforms to standard operational patterns of authorized personnel accounts.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Discovery",
        "Virtualization/Sandbox Evasion",
        "User Activity Based Checks"
      ],
      "parentId": "technique-virtualization-sandbox-evasion-179f3170",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-system-checks-2c68e7d8",
      "code": "System Checks",
      "value": "System Checks",
      "name": "System Checks",
      "definition": "Text about attackers running diagnostic inquiries on compromised hosts to discern active security mechanisms, hardware specifications, or software patch levels, confirming environmental readiness for the deployment of additional malicious code modules.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Discovery",
        "Virtualization/Sandbox Evasion",
        "System Checks"
      ],
      "parentId": "technique-virtualization-sandbox-evasion-179f3170",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-time-based-evasion-599cdb55",
      "code": "Time Based Evasion",
      "value": "Time Based Evasion",
      "name": "Time Based Evasion",
      "definition": "Text about adversaries stalling execution or altering behavioral patterns using deliberate temporal delays to avoid detection mechanisms, bypass automated malware analysis, or frustrate security analysts attempting to observe procedural activity.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Discovery",
        "Virtualization/Sandbox Evasion",
        "Time Based Evasion"
      ],
      "parentId": "technique-virtualization-sandbox-evasion-179f3170",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-web-service-56e8e7bb",
      "code": "Web Service",
      "value": "Web Service",
      "name": "Web Service",
      "definition": "Text about the abuse of web service architectures to instantiate command and control channels, allowing adversaries to relay instructions through standard server-side application logic while mimicking typical legitimate network traffic.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Command and Control",
        "Web Service"
      ],
      "parentId": "tactic-command-and-control-6b4265ca",
      "synthetic": false,
      "childCount": 3,
      "leaf": false
    },
    {
      "id": "subtechnique-one-way-communication-a7dcdac5",
      "code": "One-Way Communication",
      "value": "One-Way Communication",
      "name": "One-Way Communication",
      "definition": "Text about clandestine data transfer processes where compromised nodes push serialized information outbound to adversary-operated listeners without establishing full session state or expecting return acknowledgments, inherently evading defensive visibility.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Command and Control",
        "Web Service",
        "One-Way Communication"
      ],
      "parentId": "technique-web-service-56e8e7bb",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-dead-drop-resolver-833c9389",
      "code": "Dead Drop Resolver",
      "value": "Dead Drop Resolver",
      "name": "Dead Drop Resolver",
      "definition": "Text about adversaries utilizing public sites or platforms to retrieve command and control configuration data, typically hosted in seemingly innocuous media or comments, to dynamically locate their malicious infrastructure addresses.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Command and Control",
        "Web Service",
        "Dead Drop Resolver"
      ],
      "parentId": "technique-web-service-56e8e7bb",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-bidirectional-communication-7ed0a389",
      "code": "Bidirectional Communication",
      "value": "Bidirectional Communication",
      "name": "Bidirectional Communication",
      "definition": "Text about Bidirectional Communication characterizes the exploitation method of establishing persistent, two-way signaling channels that allow an adversary to monitor system status while issuing real-time control directives to the compromised host.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Command and Control",
        "Web Service",
        "Bidirectional Communication"
      ],
      "parentId": "technique-web-service-56e8e7bb",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-stage-capabilities-20b37f0f",
      "code": "Stage Capabilities",
      "value": "Stage Capabilities",
      "name": "Stage Capabilities",
      "definition": "Text about operations that threat actors execute to source, weaponize, and ready essential software or infrastructure components required to advance their malicious objectives throughout an intrusion campaign against target networks.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Resource Development",
        "Stage Capabilities"
      ],
      "parentId": "tactic-resource-development-ce56343a",
      "synthetic": false,
      "childCount": 6,
      "leaf": false
    },
    {
      "id": "subtechnique-drive-by-target-31d1d693",
      "code": "Drive-by Target",
      "value": "Drive-by Target",
      "name": "Drive-by Target",
      "definition": "Text about the clandestine compromise of websites to serve malicious content, forcing the automatic execution of harmful software payloads on the systems of unsuspecting users who interact with the page.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Stage Capabilities",
        "Drive-by Target"
      ],
      "parentId": "technique-stage-capabilities-20b37f0f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-link-target-488e0539",
      "code": "Link Target",
      "value": "Link Target",
      "name": "Link Target",
      "definition": "Text about modification of shortcut file internal pathways and execution arguments to redirect a victim’s interaction with a legitimate-appearing link toward the clandestine initiation of unauthorized or malicious processes.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Stage Capabilities",
        "Link Target"
      ],
      "parentId": "technique-stage-capabilities-20b37f0f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-seo-poisoning-ce759e92",
      "code": "SEO Poisoning",
      "value": "SEO Poisoning",
      "name": "SEO Poisoning",
      "definition": "Text about exploiting search engine optimization signals to boost the visibility of attacker-managed domains, serving as a primary mechanism to attract victims towards malicious downloads or deceptive landing pages.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Stage Capabilities",
        "SEO Poisoning"
      ],
      "parentId": "technique-stage-capabilities-20b37f0f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-install-digital-certificate-77cbd1c9",
      "code": "Install Digital Certificate",
      "value": "Install Digital Certificate",
      "name": "Install Digital Certificate",
      "definition": "Text about attackers deploying arbitrary or self-signed digital certificates to target host systems, enabling the authentication of malicious payloads or interception of protected communications while masquerading as verified software publishers.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Stage Capabilities",
        "Install Digital Certificate"
      ],
      "parentId": "technique-stage-capabilities-20b37f0f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-upload-tool-1e1d4936",
      "code": "Upload Tool",
      "value": "Upload Tool",
      "name": "Upload Tool",
      "definition": "Text about an adversary exploiting permitted file upload interfaces within enterprise software platforms to clandestinely transport malicious code onto a target system for the advancement of their operational mission.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Stage Capabilities",
        "Upload Tool"
      ],
      "parentId": "technique-stage-capabilities-20b37f0f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-upload-malware-9ef0b2f1",
      "code": "Upload Malware",
      "value": "Upload Malware",
      "name": "Upload Malware",
      "definition": "Text about Upload Malware entails the adversarial activity of copying malicious code to destination systems by exploiting open ports, administrative interfaces, or file transfer utilities to support internal unauthorized operations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Stage Capabilities",
        "Upload Malware"
      ],
      "parentId": "technique-stage-capabilities-20b37f0f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-multi-stage-channels-8d3779f6",
      "code": "Multi-Stage Channels",
      "value": "Multi-Stage Channels",
      "name": "Multi-Stage Channels",
      "definition": "Text about utilizing multi-tiered communication relays where adversaries route malicious traffic through diverse intermediary systems sequentially to camouflage the true source of command and control network operations.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Command and Control",
        "Multi-Stage Channels"
      ],
      "parentId": "tactic-command-and-control-6b4265ca",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-financial-theft-b30e07b0",
      "code": "Financial Theft",
      "value": "Financial Theft",
      "name": "Financial Theft",
      "definition": "Text about adversaries executing unauthorized manipulations of payment systems, banking interfaces, or cryptocurrency wallets to illicitly redirect fiscal assets, currency, or monetary value from compromised accounts or networked infrastructure platforms.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Impact",
        "Financial Theft"
      ],
      "parentId": "tactic-impact-62036a70",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-execution-guardrails-a9b4394e",
      "code": "Execution Guardrails",
      "value": "Execution Guardrails",
      "name": "Execution Guardrails",
      "definition": "Text about controlled execution parameters adversaries embed within their software to ensure malicious logic only activates upon successful verification of specific host characteristics, avoiding execution within unauthorized or non-target system environments.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Execution Guardrails"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 2,
      "leaf": false
    },
    {
      "id": "subtechnique-environmental-keying-7b89e6c7",
      "code": "Environmental Keying",
      "value": "Environmental Keying",
      "name": "Environmental Keying",
      "definition": "Text about Environmental Keying pertains to configuring malware to derive decryption keys from unique internal host conditions, thereby ensuring code execution occurs exclusively on targets explicitly recognized by the attacker.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Execution Guardrails",
        "Environmental Keying"
      ],
      "parentId": "technique-execution-guardrails-a9b4394e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-mutual-exclusion-c8e3a2c1",
      "code": "Mutual Exclusion",
      "value": "Mutual Exclusion",
      "name": "Mutual Exclusion",
      "definition": "Text about malicious software employing system synchronization objects to restrict execution to one process, thereby preventing redundant infections or resource contention whilst maintaining persistence within a targeted environment across reboots.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Execution Guardrails",
        "Mutual Exclusion"
      ],
      "parentId": "technique-execution-guardrails-a9b4394e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-cloud-storage-object-discovery-ac8dcbfd",
      "code": "Cloud Storage Object Discovery",
      "value": "Cloud Storage Object Discovery",
      "name": "Cloud Storage Object Discovery",
      "definition": "Text about adversaries enumerating cloud-hosted storage buckets and their contained data objects to identify potentially sensitive files, configurations, or credentials accessible within a compromised cloud environment's permission structure.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "Cloud Storage Object Discovery"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-log-enumeration-dffba045",
      "code": "Log Enumeration",
      "value": "Log Enumeration",
      "name": "Log Enumeration",
      "definition": "Text about adversaries performing deliberate reconnaissance on specific filesystem directories to inventory active logging mechanisms, identifying critical data storage locations that record administrative actions or security-relevant system event information.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "Log Enumeration"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-steal-application-access-token-0f42cbcf",
      "code": "Steal Application Access Token",
      "value": "Steal Application Access Token",
      "name": "Steal Application Access Token",
      "definition": "Text about the unauthorized acquisition of session-based access tokens by compromising application states, enabling threat actors to bypass multi-factor authentication and maintain persistent access to protected cloud-based service resources.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Credential Access",
        "Steal Application Access Token"
      ],
      "parentId": "tactic-credential-access-9c65f4e0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-user-execution-1853a523",
      "code": "User Execution",
      "value": "User Execution",
      "name": "User Execution",
      "definition": "Text about the category of adversarial actions that fundamentally rely on the deliberate or accidental participation of a person to instantiate malicious code execution within a securely managed corporate environment.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Execution",
        "User Execution"
      ],
      "parentId": "tactic-execution-6d525b71",
      "synthetic": false,
      "childCount": 3,
      "leaf": false
    },
    {
      "id": "subtechnique-malicious-file-eefe1151",
      "code": "Malicious File",
      "value": "Malicious File",
      "name": "Malicious File",
      "definition": "Text about Malicious File addresses the deployment of files containing obscured payloads designed to exploit vulnerabilities in security inspection engines or to evade detection by relying on specific file format structures.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Execution",
        "User Execution",
        "Malicious File"
      ],
      "parentId": "technique-user-execution-1853a523",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-malicious-image-09a3d463",
      "code": "Malicious Image",
      "value": "Malicious Image",
      "name": "Malicious Image",
      "definition": "Text about the strategic use of crafted image files designed to infiltrate computing environments by exploiting vulnerabilities inherent in how applications or operating systems parse, decode, and render malicious image data.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Execution",
        "User Execution",
        "Malicious Image"
      ],
      "parentId": "technique-user-execution-1853a523",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-malicious-link-09342658",
      "code": "Malicious Link",
      "value": "Malicious Link",
      "name": "Malicious Link",
      "definition": "Text about exploiting user interaction with hyperlinks contained in digital messages, which redirect traffic to adversarial web destinations specifically architected to leverage vulnerabilities or harvest credentials from the unsuspecting target.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Execution",
        "User Execution",
        "Malicious Link"
      ],
      "parentId": "technique-user-execution-1853a523",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-process-discovery-a94f4a8e",
      "code": "Process Discovery",
      "value": "Process Discovery",
      "name": "Process Discovery",
      "definition": "Text about the systematic collection of information regarding running applications and tasks on a host, enabling adversaries to map system activity and identify targets for subsequent injection or manipulation steps.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "Process Discovery"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-software-deployment-tools-41e5c451",
      "code": "Software Deployment Tools",
      "value": "Software Deployment Tools",
      "name": "Software Deployment Tools",
      "definition": "Text about malicious actors exploiting centralized software distribution and management infrastructures to disseminate unauthorized code, execute arbitrary commands, and maintain operational control throughout compromised enterprise network environment endpoints.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Execution",
        "Software Deployment Tools"
      ],
      "parentId": "tactic-execution-6d525b71",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-software-deployment-tools-dd2225b3",
      "code": "Software Deployment Tools",
      "value": "Software Deployment Tools",
      "name": "Software Deployment Tools",
      "definition": "Text about malicious actors exploiting centralized software distribution and management infrastructures to disseminate unauthorized code, execute arbitrary commands, and maintain operational control throughout compromised enterprise network environment endpoints.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Lateral Movement",
        "Software Deployment Tools"
      ],
      "parentId": "tactic-lateral-movement-4cec3f1f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-exfiltration-over-c2-channel-c9ee09fc",
      "code": "Exfiltration Over C2 Channel",
      "value": "Exfiltration Over C2 Channel",
      "name": "Exfiltration Over C2 Channel",
      "definition": "Text about attackers repurposing existing command and control infrastructure to clandestinely transfer sensitive organizational data, ensuring illicit traffic mimics legitimate management traffic to bypass perimeter defenses during the exfiltration operation.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Exfiltration",
        "Exfiltration Over C2 Channel"
      ],
      "parentId": "tactic-exfiltration-fcb9fccc",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-gather-victim-org-information-fc2636a2",
      "code": "Gather Victim Org Information",
      "value": "Gather Victim Org Information",
      "name": "Gather Victim Org Information",
      "definition": "Text about adversaries systematically collecting publicly available data regarding an organization's structure, physical locations, key personnel, and operational relationships to facilitate subsequent stages of a planned cyber intrusion campaign.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Reconnaissance",
        "Gather Victim Org Information"
      ],
      "parentId": "tactic-reconnaissance-a9f8c2a8",
      "synthetic": false,
      "childCount": 4,
      "leaf": false
    },
    {
      "id": "subtechnique-business-relationships-6faa6bb0",
      "code": "Business Relationships",
      "value": "Business Relationships",
      "name": "Business Relationships",
      "definition": "Text about leveraging institutional trust resulting from formal business partnerships or collaborative vendor agreements to facilitate unauthorized network access through the interconnected digital gateways connecting those specific organizational entities.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Gather Victim Org Information",
        "Business Relationships"
      ],
      "parentId": "technique-gather-victim-org-information-fc2636a2",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-determine-physical-locations-f24912d0",
      "code": "Determine Physical Locations",
      "value": "Determine Physical Locations",
      "name": "Determine Physical Locations",
      "definition": "Text about malicious entities identifying the specific real-world geographical coordinates or building locations of a target's offices, data centers, or remote workforce assets to plan physical or network-based operational actions.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Gather Victim Org Information",
        "Determine Physical Locations"
      ],
      "parentId": "technique-gather-victim-org-information-fc2636a2",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-identify-roles-e8b48108",
      "code": "Identify Roles",
      "value": "Identify Roles",
      "name": "Identify Roles",
      "definition": "Text about adversaries enumerating organizational structures, personnel titles, or responsibilities within a targeted entity to discern key individuals for focused social engineering, lateral movement, or unauthorized privilege escalation during operations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Gather Victim Org Information",
        "Identify Roles"
      ],
      "parentId": "technique-gather-victim-org-information-fc2636a2",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-identify-business-tempo-767c4f2b",
      "code": "Identify Business Tempo",
      "value": "Identify Business Tempo",
      "name": "Identify Business Tempo",
      "definition": "Text about adversaries observing, tracking, and documenting the typical workflow patterns, shift changes, network traffic spikes, and internal communication cadence to align offensive operations with periods of reduced vigilance.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Gather Victim Org Information",
        "Identify Business Tempo"
      ],
      "parentId": "technique-gather-victim-org-information-fc2636a2",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-forge-web-credentials-9fecd025",
      "code": "Forge Web Credentials",
      "value": "Forge Web Credentials",
      "name": "Forge Web Credentials",
      "definition": "Text about attackers crafting synthetic authentication tokens to subvert standard login procedures, permitting persistent, unauthorized interaction with secure web services by mimicking the properties of genuine, pre-authenticated user sessions.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Credential Access",
        "Forge Web Credentials"
      ],
      "parentId": "tactic-credential-access-9c65f4e0",
      "synthetic": false,
      "childCount": 2,
      "leaf": false
    },
    {
      "id": "subtechnique-web-cookies-f559ef45",
      "code": "Web Cookies",
      "value": "Web Cookies",
      "name": "Web Cookies",
      "definition": "Text about adversaries stealing session cookies from browser data files to bypass session management protections and masquerade as valid users within hijacked web sessions, enabling direct access to unauthorized resources.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Forge Web Credentials",
        "Web Cookies"
      ],
      "parentId": "technique-forge-web-credentials-9fecd025",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-saml-tokens-d192b032",
      "code": "SAML Tokens",
      "value": "SAML Tokens",
      "name": "SAML Tokens",
      "definition": "Text about unauthorized actors creating malicious or modified Security Assertion Markup Language tokens to spoof user identities, facilitating lateral movement and privilege escalation across federated architectures and cloud platforms.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Forge Web Credentials",
        "SAML Tokens"
      ],
      "parentId": "technique-forge-web-credentials-9fecd025",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-multi-factor-authentication-request-generation-86631075",
      "code": "Multi-Factor Authentication Request Generation",
      "value": "Multi-Factor Authentication Request Generation",
      "name": "Multi-Factor Authentication Request Generation",
      "definition": "Text about methods where malicious actors force the generation of multi-factor authentication requests, aiming to manipulate authorized users into approving access attempts for unauthorized accounts or unauthorized sessions.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Credential Access",
        "Multi-Factor Authentication Request Generation"
      ],
      "parentId": "tactic-credential-access-9c65f4e0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-compromise-host-software-binary-0cd0494f",
      "code": "Compromise Host Software Binary",
      "value": "Compromise Host Software Binary",
      "name": "Compromise Host Software Binary",
      "definition": "Text about the insertion of malicious code into authorized host software files, where adversaries tamper with binary executables to facilitate persistent or secondary execution of harmful payloads during standard software operation.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Persistence",
        "Compromise Host Software Binary"
      ],
      "parentId": "tactic-persistence-4782469e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-exploitation-for-credential-access-6da2cbff",
      "code": "Exploitation for Credential Access",
      "value": "Exploitation for Credential Access",
      "name": "Exploitation for Credential Access",
      "definition": "Text about adversaries leveraging vulnerabilities within software components, services, or system processes to bypass security controls and subsequently extract functional authentication credentials stored within the compromised environment's memory, files, or configurations.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Credential Access",
        "Exploitation for Credential Access"
      ],
      "parentId": "tactic-credential-access-9c65f4e0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-gather-victim-network-information-a466798e",
      "code": "Gather Victim Network Information",
      "value": "Gather Victim Network Information",
      "name": "Gather Victim Network Information",
      "definition": "Text about adversaries systematically identifying internal topology, security configurations, domain structures, and reachable assets within a target environment to map the operational landscape before executing subsequent high-impact exploitation or lateral movement activities.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Reconnaissance",
        "Gather Victim Network Information"
      ],
      "parentId": "tactic-reconnaissance-a9f8c2a8",
      "synthetic": false,
      "childCount": 6,
      "leaf": false
    },
    {
      "id": "subtechnique-domain-properties-5478beab",
      "code": "Domain Properties",
      "value": "Domain Properties",
      "name": "Domain Properties",
      "definition": "Text about Domain Properties constitutes granular technical specifications regarding digital infrastructure registration, metadata, and reputation settings that adversaries modify to evade detection mechanisms and establish authoritative control over their operational environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Gather Victim Network Information",
        "Domain Properties"
      ],
      "parentId": "technique-gather-victim-network-information-a466798e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-dns-f0091d4e",
      "code": "DNS",
      "value": "DNS",
      "name": "DNS",
      "definition": "Text about adversaries leveraging the Domain Name System protocol to facilitate command and control, data exfiltration, or infrastructure communications by embedding malicious traffic within standard network domain resolution queries and responses.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Gather Victim Network Information",
        "DNS"
      ],
      "parentId": "technique-gather-victim-network-information-a466798e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-ip-addresses-ca050764",
      "code": "IP Addresses",
      "value": "IP Addresses",
      "name": "IP Addresses",
      "definition": "Text about IP Addresses as a sub-technique covers the tactical employment of assigned network-layer addresses by threat actors to route malicious traffic between compromised systems and external command and control infrastructure.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Gather Victim Network Information",
        "IP Addresses"
      ],
      "parentId": "technique-gather-victim-network-information-a466798e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-network-trust-dependencies-c10aa085",
      "code": "Network Trust Dependencies",
      "value": "Network Trust Dependencies",
      "name": "Network Trust Dependencies",
      "definition": "Text about adversaries capitalizing on insecure trust relationships inherent in network environments where interconnected services or applications accept commands from trusted sources without implementing rigorous access control validation processes.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Gather Victim Network Information",
        "Network Trust Dependencies"
      ],
      "parentId": "technique-gather-victim-network-information-a466798e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-network-topology-876fb0e8",
      "code": "Network Topology",
      "value": "Network Topology",
      "name": "Network Topology",
      "definition": "Text about adversaries gathering intelligence on internal network structures, including device interconnectivity, segment boundaries, and communication paths, to map critical assets and identify potential pathways for lateral movement within a compromised ecosystem.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Gather Victim Network Information",
        "Network Topology"
      ],
      "parentId": "technique-gather-victim-network-information-a466798e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-network-security-appliances-fe030271",
      "code": "Network Security Appliances",
      "value": "Network Security Appliances",
      "name": "Network Security Appliances",
      "definition": "Text about exploiting vulnerabilities or misconfigurations within critical infrastructure hardware that perform defensive functions, allowing threat actors to manipulate traffic flows, monitor network activity, or maintain covert operations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Gather Victim Network Information",
        "Network Security Appliances"
      ],
      "parentId": "technique-gather-victim-network-information-a466798e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-exploitation-of-remote-services-cef14ab7",
      "code": "Exploitation of Remote Services",
      "value": "Exploitation of Remote Services",
      "name": "Exploitation of Remote Services",
      "definition": "Text about adversaries actively compromising accessible remote services by exploiting software vulnerabilities, allowing for the unauthorized execution of code, authentication bypass, or lateral traversal across targeted network infrastructures.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Lateral Movement",
        "Exploitation of Remote Services"
      ],
      "parentId": "tactic-lateral-movement-4cec3f1f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-internal-spearphishing-dfd80bd6",
      "code": "Internal Spearphishing",
      "value": "Internal Spearphishing",
      "name": "Internal Spearphishing",
      "definition": "Text about malicious entities utilizing compromised internal accounts to send deceptive direct communications, exploiting inherent trust in internal communication channels to compromise additional targets or gain broader control within the network.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Lateral Movement",
        "Internal Spearphishing"
      ],
      "parentId": "tactic-lateral-movement-4cec3f1f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-trusted-relationship-d65e062a",
      "code": "Trusted Relationship",
      "value": "Trusted Relationship",
      "name": "Trusted Relationship",
      "definition": "Text about adversaries infiltrating systems by exploiting the established, authorized access granted to partners, managed service providers, or supply chain vendors, thereby circumventing restrictive perimeter defenses through recognized, legitimate connection points.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Initial Access",
        "Trusted Relationship"
      ],
      "parentId": "tactic-initial-access-a0f45034",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-search-open-websites-domains-a4410470",
      "code": "Search Open Websites/Domains",
      "value": "Search Open Websites/Domains",
      "name": "Search Open Websites/Domains",
      "definition": "Text about systematic information gathering performed by adversaries by querying publicly accessible web content, social platforms, and domain registries to delineate target attack surfaces and identify potential vulnerabilities or entry points.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Reconnaissance",
        "Search Open Websites/Domains"
      ],
      "parentId": "tactic-reconnaissance-a9f8c2a8",
      "synthetic": false,
      "childCount": 3,
      "leaf": false
    },
    {
      "id": "subtechnique-search-engines-100a7328",
      "code": "Search Engines",
      "value": "Search Engines",
      "name": "Search Engines",
      "definition": "Text about threat actors querying public search indexing services to uncover undocumented administrative interfaces, exposed sensitive operational data, or specific developer information useful for downstream targeting and exploitation attempts.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Search Open Websites/Domains",
        "Search Engines"
      ],
      "parentId": "technique-search-open-websites-domains-a4410470",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-code-repositories-c9df8c0a",
      "code": "Code Repositories",
      "value": "Code Repositories",
      "name": "Code Repositories",
      "definition": "Text about the unauthorized access and exploitation of source code management platforms to facilitate the theft of intellectual property, discovery of operational secrets, and manipulation of software builds via code injection.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Search Open Websites/Domains",
        "Code Repositories"
      ],
      "parentId": "technique-search-open-websites-domains-a4410470",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-social-media-b416e32e",
      "code": "Social Media",
      "value": "Social Media",
      "name": "Social Media",
      "definition": "Text about adversaries monitoring social media activity to extract sensitive operational or personnel data used to craft convincing phishing lures or manipulate trust relationships during initial access phases.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Search Open Websites/Domains",
        "Social Media"
      ],
      "parentId": "technique-search-open-websites-domains-a4410470",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-account-manipulation-2ea50fd0",
      "code": "Account Manipulation",
      "value": "Account Manipulation",
      "name": "Account Manipulation",
      "definition": "Text about Account Manipulation signifies adversarial activities targeting the modification of existing credentials or administrative rights to secure persistent access and enable expanded operational control within a compromised infrastructure.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Persistence",
        "Account Manipulation"
      ],
      "parentId": "tactic-persistence-4782469e",
      "synthetic": false,
      "childCount": 7,
      "leaf": false
    },
    {
      "id": "subtechnique-additional-cloud-credentials-14a4fdea",
      "code": "Additional Cloud Credentials",
      "value": "Additional Cloud Credentials",
      "name": "Additional Cloud Credentials",
      "definition": "Text about adversaries gathering sensitive authentication material stored within cloud environments, such as service account keys or stored tokens, to maintain persistent access or escalate privileges within the compromised infrastructure.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Account Manipulation",
        "Additional Cloud Credentials"
      ],
      "parentId": "technique-account-manipulation-2ea50fd0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-additional-email-delegate-permissions-e037a350",
      "code": "Additional Email Delegate Permissions",
      "value": "Additional Email Delegate Permissions",
      "name": "Additional Email Delegate Permissions",
      "definition": "Text about adversaries manipulating email system settings to permit unauthorized accounts to act as delegates for a target mailbox, thereby enabling the silent interception and review of incoming electronic correspondence.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Account Manipulation",
        "Additional Email Delegate Permissions"
      ],
      "parentId": "technique-account-manipulation-2ea50fd0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-additional-cloud-roles-13415b8e",
      "code": "Additional Cloud Roles",
      "value": "Additional Cloud Roles",
      "name": "Additional Cloud Roles",
      "definition": "Text about adversaries adding novel cloud identity roles with distinct permission scopes to compromised environments, facilitating privilege escalation and ongoing operational control over critical cloud-native service architectures.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Account Manipulation",
        "Additional Cloud Roles"
      ],
      "parentId": "technique-account-manipulation-2ea50fd0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-device-registration-79b3617e",
      "code": "Device Registration",
      "value": "Device Registration",
      "name": "Device Registration",
      "definition": "Text about device registration concerns the adversarial technique of adding rogue hardware components to an authorized device management ecosystem, effectively granting the attacker persistent access and authenticated network communication privileges.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Account Manipulation",
        "Device Registration"
      ],
      "parentId": "technique-account-manipulation-2ea50fd0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-additional-container-cluster-roles-dc690cbe",
      "code": "Additional Container Cluster Roles",
      "value": "Additional Container Cluster Roles",
      "name": "Additional Container Cluster Roles",
      "definition": "Text about attackers establishing supplementary cluster roles in container orchestration systems to acquire administrative privileges that exceed initial access levels, thereby simplifying unauthorized control over cluster infrastructure and sensitive service account tokens.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Account Manipulation",
        "Additional Container Cluster Roles"
      ],
      "parentId": "technique-account-manipulation-2ea50fd0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-ssh-authorized-keys-d0272e79",
      "code": "SSH Authorized Keys",
      "value": "SSH Authorized Keys",
      "name": "SSH Authorized Keys",
      "definition": "Text about the strategic modification of SSH authentication files using injected public keys to secure persistent remote access, enabling adversaries to authenticate directly without interaction during subsequent phases of the operation.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Account Manipulation",
        "SSH Authorized Keys"
      ],
      "parentId": "technique-account-manipulation-2ea50fd0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-additional-local-or-domain-groups-ee6d0d28",
      "code": "Additional Local or Domain Groups",
      "value": "Additional Local or Domain Groups",
      "name": "Additional Local or Domain Groups",
      "definition": "Text about unauthorized actors intentionally modifying user group memberships to include their persistent accounts within local or domain administrative categories, thereby surreptitiously securing elevated privileges across the targeted system architecture.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Account Manipulation",
        "Additional Local or Domain Groups"
      ],
      "parentId": "technique-account-manipulation-2ea50fd0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-account-manipulation-d73acdac",
      "code": "Account Manipulation",
      "value": "Account Manipulation",
      "name": "Account Manipulation",
      "definition": "Text about Account Manipulation signifies adversarial activities targeting the modification of existing credentials or administrative rights to secure persistent access and enable expanded operational control within a compromised infrastructure.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Privilege Escalation",
        "Account Manipulation"
      ],
      "parentId": "tactic-privilege-escalation-dc3564ae",
      "synthetic": false,
      "childCount": 7,
      "leaf": false
    },
    {
      "id": "subtechnique-additional-cloud-credentials-23a21964",
      "code": "Additional Cloud Credentials",
      "value": "Additional Cloud Credentials",
      "name": "Additional Cloud Credentials",
      "definition": "Text about adversaries gathering sensitive authentication material stored within cloud environments, such as service account keys or stored tokens, to maintain persistent access or escalate privileges within the compromised infrastructure.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Account Manipulation",
        "Additional Cloud Credentials"
      ],
      "parentId": "technique-account-manipulation-d73acdac",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-additional-email-delegate-permissions-af816fa2",
      "code": "Additional Email Delegate Permissions",
      "value": "Additional Email Delegate Permissions",
      "name": "Additional Email Delegate Permissions",
      "definition": "Text about adversaries manipulating email system settings to permit unauthorized accounts to act as delegates for a target mailbox, thereby enabling the silent interception and review of incoming electronic correspondence.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Account Manipulation",
        "Additional Email Delegate Permissions"
      ],
      "parentId": "technique-account-manipulation-d73acdac",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-additional-cloud-roles-ff6acf10",
      "code": "Additional Cloud Roles",
      "value": "Additional Cloud Roles",
      "name": "Additional Cloud Roles",
      "definition": "Text about adversaries adding novel cloud identity roles with distinct permission scopes to compromised environments, facilitating privilege escalation and ongoing operational control over critical cloud-native service architectures.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Account Manipulation",
        "Additional Cloud Roles"
      ],
      "parentId": "technique-account-manipulation-d73acdac",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-device-registration-4f6d4a2b",
      "code": "Device Registration",
      "value": "Device Registration",
      "name": "Device Registration",
      "definition": "Text about device registration concerns the adversarial technique of adding rogue hardware components to an authorized device management ecosystem, effectively granting the attacker persistent access and authenticated network communication privileges.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Account Manipulation",
        "Device Registration"
      ],
      "parentId": "technique-account-manipulation-d73acdac",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-additional-container-cluster-roles-8c9039ab",
      "code": "Additional Container Cluster Roles",
      "value": "Additional Container Cluster Roles",
      "name": "Additional Container Cluster Roles",
      "definition": "Text about attackers establishing supplementary cluster roles in container orchestration systems to acquire administrative privileges that exceed initial access levels, thereby simplifying unauthorized control over cluster infrastructure and sensitive service account tokens.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Account Manipulation",
        "Additional Container Cluster Roles"
      ],
      "parentId": "technique-account-manipulation-d73acdac",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-ssh-authorized-keys-3a1134cc",
      "code": "SSH Authorized Keys",
      "value": "SSH Authorized Keys",
      "name": "SSH Authorized Keys",
      "definition": "Text about the strategic modification of SSH authentication files using injected public keys to secure persistent remote access, enabling adversaries to authenticate directly without interaction during subsequent phases of the operation.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Account Manipulation",
        "SSH Authorized Keys"
      ],
      "parentId": "technique-account-manipulation-d73acdac",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-additional-local-or-domain-groups-cc8cecdb",
      "code": "Additional Local or Domain Groups",
      "value": "Additional Local or Domain Groups",
      "name": "Additional Local or Domain Groups",
      "definition": "Text about unauthorized actors intentionally modifying user group memberships to include their persistent accounts within local or domain administrative categories, thereby surreptitiously securing elevated privileges across the targeted system architecture.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Account Manipulation",
        "Additional Local or Domain Groups"
      ],
      "parentId": "technique-account-manipulation-d73acdac",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-exfiltration-over-alternative-protocol-2c89aa68",
      "code": "Exfiltration Over Alternative Protocol",
      "value": "Exfiltration Over Alternative Protocol",
      "name": "Exfiltration Over Alternative Protocol",
      "definition": "Text about the clandestine movement of stolen data from a target environment using non-standard communication protocols, effectively leveraging channels that network security monitoring tools often overlook during routine traffic analysis.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Exfiltration",
        "Exfiltration Over Alternative Protocol"
      ],
      "parentId": "tactic-exfiltration-fcb9fccc",
      "synthetic": false,
      "childCount": 3,
      "leaf": false
    },
    {
      "id": "subtechnique-exfiltration-over-asymmetric-encrypted-non-c2-protocol-5dde3620",
      "code": "Exfiltration Over Asymmetric Encrypted Non-C2 Protocol",
      "value": "Exfiltration Over Asymmetric Encrypted Non-C2 Protocol",
      "name": "Exfiltration Over Asymmetric Encrypted Non-C2 Protocol",
      "definition": "Text about exfiltrating captured data via asymmetric encryption techniques implemented over network protocols unrelated to command and control activities, complicating detection by wrapping sensitive content in verifiable, encrypted tunnels.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Exfiltration",
        "Exfiltration Over Alternative Protocol",
        "Exfiltration Over Asymmetric Encrypted Non-C2 Protocol"
      ],
      "parentId": "technique-exfiltration-over-alternative-protocol-2c89aa68",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-exfiltration-over-unencrypted-non-c2-protocol-77f59d8e",
      "code": "Exfiltration Over Unencrypted Non-C2 Protocol",
      "value": "Exfiltration Over Unencrypted Non-C2 Protocol",
      "name": "Exfiltration Over Unencrypted Non-C2 Protocol",
      "definition": "Text about stealing data by funneling information through unencrypted network protocols that do not serve operational command-and-control functions, facilitating unauthorized egress while lacking secure cryptographic protection for data transit.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Exfiltration",
        "Exfiltration Over Alternative Protocol",
        "Exfiltration Over Unencrypted Non-C2 Protocol"
      ],
      "parentId": "technique-exfiltration-over-alternative-protocol-2c89aa68",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-exfiltration-over-symmetric-encrypted-non-c2-protocol-d8c00c2d",
      "code": "Exfiltration Over Symmetric Encrypted Non-C2 Protocol",
      "value": "Exfiltration Over Symmetric Encrypted Non-C2 Protocol",
      "name": "Exfiltration Over Symmetric Encrypted Non-C2 Protocol",
      "definition": "Text about adversaries transferring stolen data through standard symmetric encryption protocols that are not dedicated command and control channels, effectively bypassing security inspection mechanisms by disguising outgoing traffic as legitimate network operations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Exfiltration",
        "Exfiltration Over Alternative Protocol",
        "Exfiltration Over Symmetric Encrypted Non-C2 Protocol"
      ],
      "parentId": "technique-exfiltration-over-alternative-protocol-2c89aa68",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-search-closed-sources-8339bec9",
      "code": "Search Closed Sources",
      "value": "Search Closed Sources",
      "name": "Search Closed Sources",
      "definition": "Text about adversaries acquiring sensitive information by accessing restricted, non-indexed, or subscription-based data sources, including hacked proprietary databases, to conduct reconnaissance on specific entities and facilitate subsequent malicious operational activities.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Reconnaissance",
        "Search Closed Sources"
      ],
      "parentId": "tactic-reconnaissance-a9f8c2a8",
      "synthetic": false,
      "childCount": 2,
      "leaf": false
    },
    {
      "id": "subtechnique-threat-intel-vendors-381369e8",
      "code": "Threat Intel Vendors",
      "value": "Threat Intel Vendors",
      "name": "Threat Intel Vendors",
      "definition": "Text about adversaries utilizing specialized third-party intelligence services to acquire privileged data concerning a target organization’s defensive posture, unpatched software vulnerabilities, compromised credentials, or exposed internal network infrastructure components.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Search Closed Sources",
        "Threat Intel Vendors"
      ],
      "parentId": "technique-search-closed-sources-8339bec9",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-purchase-technical-data-eac21f69",
      "code": "Purchase Technical Data",
      "value": "Purchase Technical Data",
      "name": "Purchase Technical Data",
      "definition": "Text about adversaries securing proprietary or confidential technical data via commercial channels, where attackers pay for access to leaked credentials, sensitive system diagrams, or vulnerability information to advance their operational objectives.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Search Closed Sources",
        "Purchase Technical Data"
      ],
      "parentId": "technique-search-closed-sources-8339bec9",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-phishing-121549d9",
      "code": "Phishing",
      "value": "Phishing",
      "name": "Phishing",
      "definition": "Text about exploiting human trust through electronic messages designed to deceive recipients into revealing authentication credentials or facilitating the execution of malicious code, thereby compromising secure enterprise network environments.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Initial Access",
        "Phishing"
      ],
      "parentId": "tactic-initial-access-a0f45034",
      "synthetic": false,
      "childCount": 4,
      "leaf": false
    },
    {
      "id": "subtechnique-spearphishing-link-a6b8552f",
      "code": "Spearphishing Link",
      "value": "Spearphishing Link",
      "name": "Spearphishing Link",
      "definition": "Text about an intrusion vector involving targeted electronic messages containing malicious hyperlinks that redirect unsuspecting users to web-based platforms used for privilege escalation, credential theft, or malware distribution campaigns.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Initial Access",
        "Phishing",
        "Spearphishing Link"
      ],
      "parentId": "technique-phishing-121549d9",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-spearphishing-attachment-bf8f688d",
      "code": "Spearphishing Attachment",
      "value": "Spearphishing Attachment",
      "name": "Spearphishing Attachment",
      "definition": "Text about the delivery of harmful software components embedded within email attachments, specifically designed to deceive recipients into executing them, thereby facilitating unauthorized initial access to protected enterprise network systems.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Initial Access",
        "Phishing",
        "Spearphishing Attachment"
      ],
      "parentId": "technique-phishing-121549d9",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-spearphishing-voice-d60f9645",
      "code": "Spearphishing Voice",
      "value": "Spearphishing Voice",
      "name": "Spearphishing Voice",
      "definition": "Text about fraudulent voice communications initiated by threat actors targeting specific individuals to elicit sensitive information or manipulate the recipient into performing actions that subvert existing organizational cybersecurity safety measures.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Initial Access",
        "Phishing",
        "Spearphishing Voice"
      ],
      "parentId": "technique-phishing-121549d9",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-spearphishing-via-service-9af1e791",
      "code": "Spearphishing via Service",
      "value": "Spearphishing via Service",
      "name": "Spearphishing via Service",
      "definition": "Text about adversaries employing external platform-based messaging channels to conduct targeted social engineering attacks, aiming to deceive recipients into facilitating unauthorized system ingress through clicked links or downloaded attachments.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Initial Access",
        "Phishing",
        "Spearphishing via Service"
      ],
      "parentId": "technique-phishing-121549d9",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-brute-force-c2c2819a",
      "code": "Brute Force",
      "value": "Brute Force",
      "name": "Brute Force",
      "definition": "Text about adversaries performing high-frequency, iterative authentication requests against target systems to discover valid credentials by systematically testing exhaustive combinations of potential passwords, keys, or passphrase variations until success.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Credential Access",
        "Brute Force"
      ],
      "parentId": "tactic-credential-access-9c65f4e0",
      "synthetic": false,
      "childCount": 4,
      "leaf": false
    },
    {
      "id": "subtechnique-credential-stuffing-4f11f0d9",
      "code": "Credential Stuffing",
      "value": "Credential Stuffing",
      "name": "Credential Stuffing",
      "definition": "Text about Credential Stuffing refers to using large volumes of stolen authentication credentials, obtained from third-party breaches, to automatically attempt unauthorized logins across multiple services to compromise user account integrity.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Brute Force",
        "Credential Stuffing"
      ],
      "parentId": "technique-brute-force-c2c2819a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-password-cracking-8b1c6450",
      "code": "Password Cracking",
      "value": "Password Cracking",
      "name": "Password Cracking",
      "definition": "Text about exploiting stored cryptographic hashes to derive original plaintext passwords through intensive computational efforts meant to facilitate continued illicit access to secured host systems and enterprise authentication services.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Brute Force",
        "Password Cracking"
      ],
      "parentId": "technique-brute-force-c2c2819a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-password-guessing-2cca892b",
      "code": "Password Guessing",
      "value": "Password Guessing",
      "name": "Password Guessing",
      "definition": "Text about cyber adversaries engaging in the repetitive submission of predicted or likely password strings against authentication portals to identify correct credentials and facilitate unauthorized access to compromised system accounts.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Brute Force",
        "Password Guessing"
      ],
      "parentId": "technique-brute-force-c2c2819a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-password-spraying-cc928813",
      "code": "Password Spraying",
      "value": "Password Spraying",
      "name": "Password Spraying",
      "definition": "Text about password spraying concerns the tactical approach of attempting a specific password across multiple user accounts simultaneously, facilitating credential access while minimizing the likelihood of triggering defensive account lockouts.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Brute Force",
        "Password Spraying"
      ],
      "parentId": "technique-brute-force-c2c2819a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-data-manipulation-f5f9eeca",
      "code": "Data Manipulation",
      "value": "Data Manipulation",
      "name": "Data Manipulation",
      "definition": "Text about adversaries systematically altering data repositories or information streams to bypass security controls, corrupt analytical insights, or induce incorrect behaviors in automated processes relying upon the validity of that data.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Impact",
        "Data Manipulation"
      ],
      "parentId": "tactic-impact-62036a70",
      "synthetic": false,
      "childCount": 3,
      "leaf": false
    },
    {
      "id": "subtechnique-transmitted-data-manipulation-195e007c",
      "code": "Transmitted Data Manipulation",
      "value": "Transmitted Data Manipulation",
      "name": "Transmitted Data Manipulation",
      "definition": "Text about adversaries injecting, modifying, or deleting data fragments during network transmission to manipulate established communication protocols, undermine security validations, or disrupt operational traffic patterns to achieve unauthorized system behavior objectives.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Impact",
        "Data Manipulation",
        "Transmitted Data Manipulation"
      ],
      "parentId": "technique-data-manipulation-f5f9eeca",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-runtime-data-manipulation-0da5f10b",
      "code": "Runtime Data Manipulation",
      "value": "Runtime Data Manipulation",
      "name": "Runtime Data Manipulation",
      "definition": "Text about the modification of runtime-accessible data or process memory, allowing malicious actors to alter control flow paths and evade detection by subverting how applications process sensitive operational information.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Impact",
        "Data Manipulation",
        "Runtime Data Manipulation"
      ],
      "parentId": "technique-data-manipulation-f5f9eeca",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-stored-data-manipulation-a7ec50bc",
      "code": "Stored Data Manipulation",
      "value": "Stored Data Manipulation",
      "name": "Stored Data Manipulation",
      "definition": "Text about adversaries injecting changes into persistently stored information to invalidate the accuracy of managed records, cause system malfunctions, or compromise the operational reliability of stored digital assets and configurations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Impact",
        "Data Manipulation",
        "Stored Data Manipulation"
      ],
      "parentId": "technique-data-manipulation-f5f9eeca",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-inter-process-communication-f483eb45",
      "code": "Inter-Process Communication",
      "value": "Inter-Process Communication",
      "name": "Inter-Process Communication",
      "definition": "Text about threat actors abusing legitimate operating system primitives designed for data exchange to facilitate stealthy interaction between distinct processes, enabling coordinated malicious actions without triggering standard security alerts.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Execution",
        "Inter-Process Communication"
      ],
      "parentId": "tactic-execution-6d525b71",
      "synthetic": false,
      "childCount": 3,
      "leaf": false
    },
    {
      "id": "subtechnique-xpc-services-16245188",
      "code": "XPC Services",
      "value": "XPC Services",
      "name": "XPC Services",
      "definition": "Text about adversaries exploiting the inherent trust within the macOS XPC messaging system to execute unauthorized code in privileged contexts, effectively bypassing security controls by mimicking legitimate inter-process communication requests.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Execution",
        "Inter-Process Communication",
        "XPC Services"
      ],
      "parentId": "technique-inter-process-communication-f483eb45",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-dynamic-data-exchange-e6c295d8",
      "code": "Dynamic Data Exchange",
      "value": "Dynamic Data Exchange",
      "name": "Dynamic Data Exchange",
      "definition": "Text about Dynamic Data Exchange involves the weaponization of an inter-process communication protocol designed for data sharing, allowing adversaries to execute arbitrary malicious commands through legitimate software functionality embedded within compromised files.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Execution",
        "Inter-Process Communication",
        "Dynamic Data Exchange"
      ],
      "parentId": "technique-inter-process-communication-f483eb45",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-component-object-model-24e79569",
      "code": "Component Object Model",
      "value": "Component Object Model",
      "name": "Component Object Model",
      "definition": "Text about Component Object Model exploitation details the process where adversaries leverage Windows object interfaces to facilitate lateral movement, execute payloads, or hook application functionality by registering and activating malicious binary components.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Execution",
        "Inter-Process Communication",
        "Component Object Model"
      ],
      "parentId": "technique-inter-process-communication-f483eb45",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-data-obfuscation-b208a91c",
      "code": "Data Obfuscation",
      "value": "Data Obfuscation",
      "name": "Data Obfuscation",
      "definition": "Text about adversaries utilizing obfuscation to cloak their activities by modifying data representation, thereby confusing threat detection systems, complicating forensic investigation, and preventing accurate identification of the underlying malicious payload.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Command and Control",
        "Data Obfuscation"
      ],
      "parentId": "tactic-command-and-control-6b4265ca",
      "synthetic": false,
      "childCount": 3,
      "leaf": false
    },
    {
      "id": "subtechnique-junk-data-0aaa0a73",
      "code": "Junk Data",
      "value": "Junk Data",
      "name": "Junk Data",
      "definition": "Text about Junk Data covers the systematic population of legitimate log files or memory buffers with synthetic, irrelevant information to dilute forensic evidence and sabotage the accuracy of security telemetry monitoring.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Command and Control",
        "Data Obfuscation",
        "Junk Data"
      ],
      "parentId": "technique-data-obfuscation-b208a91c",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-protocol-or-service-impersonation-8321c192",
      "code": "Protocol or Service Impersonation",
      "value": "Protocol or Service Impersonation",
      "name": "Protocol or Service Impersonation",
      "definition": "Text about adversaries mimicking known service interfaces or protocol standards to conceal command and control channels, embedding malicious instructions within seemingly authentic communication structures to bypass network security inspections.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Command and Control",
        "Data Obfuscation",
        "Protocol or Service Impersonation"
      ],
      "parentId": "technique-data-obfuscation-b208a91c",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-steganography-e87e6143",
      "code": "Steganography",
      "value": "Steganography",
      "name": "Steganography",
      "definition": "Text about leveraging digital file structures to hide covert data, allowing adversaries to transmit unauthorized information past security boundaries by masking malicious content within standard, seemingly routine file transmission operations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Command and Control",
        "Data Obfuscation",
        "Steganography"
      ],
      "parentId": "technique-data-obfuscation-b208a91c",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-data-from-network-shared-drive-15d02dc9",
      "code": "Data from Network Shared Drive",
      "value": "Data from Network Shared Drive",
      "name": "Data from Network Shared Drive",
      "definition": "Text about attackers discovering and accessing file shares or networked storage repositories from compromised systems to copy specific data assets, thereby enabling unauthorized retrieval and exposure of sensitive corporate information.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Collection",
        "Data from Network Shared Drive"
      ],
      "parentId": "tactic-collection-30c54a96",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-modify-system-image-39d3645f",
      "code": "Modify System Image",
      "value": "Modify System Image",
      "name": "Modify System Image",
      "definition": "Text about modifying critical system-level images to embed persistent malicious functionality, effectively subverting the standard operating system boot process to maintain access despite system restarts or security updates.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Modify System Image"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 2,
      "leaf": false
    },
    {
      "id": "subtechnique-downgrade-system-image-dc0dc212",
      "code": "Downgrade System Image",
      "value": "Downgrade System Image",
      "name": "Downgrade System Image",
      "definition": "Text about compromising system integrity through the deliberate installation of outdated system images, effectively rolling back security mitigations to regain access to legacy vulnerabilities within the targeted host environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Modify System Image",
        "Downgrade System Image"
      ],
      "parentId": "technique-modify-system-image-39d3645f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-patch-system-image-be0ec764",
      "code": "Patch System Image",
      "value": "Patch System Image",
      "name": "Patch System Image",
      "definition": "Text about modifying on-disk system image files to inject persistent malicious instructions, enabling attackers to ensure execution within the compromised environment upon subsequent system startup or specific boot events.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Modify System Image",
        "Patch System Image"
      ],
      "parentId": "technique-modify-system-image-39d3645f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-hijack-execution-flow-e920f269",
      "code": "Hijack Execution Flow",
      "value": "Hijack Execution Flow",
      "name": "Hijack Execution Flow",
      "definition": "Text about adversaries manipulation of operating system processes via side-loading, library preloading, or modifying search orders to force the execution of malicious code instead of an intended legitimate program or service.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Persistence",
        "Hijack Execution Flow"
      ],
      "parentId": "tactic-persistence-4782469e",
      "synthetic": false,
      "childCount": 13,
      "leaf": false
    },
    {
      "id": "subtechnique-services-file-permissions-weakness-0884afc5",
      "code": "Services File Permissions Weakness",
      "value": "Services File Permissions Weakness",
      "name": "Services File Permissions Weakness",
      "definition": "Text about illicitly modifying service binary files or configuration paths due to overly permissive access controls, allowing adversaries to execute arbitrary code with the elevated privileges assigned to the targeted service.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Hijack Execution Flow",
        "Services File Permissions Weakness"
      ],
      "parentId": "technique-hijack-execution-flow-e920f269",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-kernelcallbacktable-a2aa82dd",
      "code": "KernelCallbackTable",
      "value": "KernelCallbackTable",
      "name": "KernelCallbackTable",
      "definition": "Text about the unauthorized modification of stored function pointers within the process environment block kernel callback table used by adversaries to redirect code execution for gaining persistence or executing malicious payloads stealthily.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Hijack Execution Flow",
        "KernelCallbackTable"
      ],
      "parentId": "technique-hijack-execution-flow-e920f269",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-path-interception-by-path-environment-variable-201e63e2",
      "code": "Path Interception by PATH Environment Variable",
      "value": "Path Interception by PATH Environment Variable",
      "name": "Path Interception by PATH Environment Variable",
      "definition": "Text about leveraging the PATH environment variable search logic to intercept execution attempts, forcing the operating system to load a malicious binary located in an attacker-controlled directory ahead of expected files.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Hijack Execution Flow",
        "Path Interception by PATH Environment Variable"
      ],
      "parentId": "technique-hijack-execution-flow-e920f269",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-executable-installer-file-permissions-weakness-1bfc825b",
      "code": "Executable Installer File Permissions Weakness",
      "value": "Executable Installer File Permissions Weakness",
      "name": "Executable Installer File Permissions Weakness",
      "definition": "Text about inadequate security settings on installer binaries permitting unauthorized write access, which adversaries exploit to modify or substitute the executable, facilitating the execution of arbitrary code during installation.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Hijack Execution Flow",
        "Executable Installer File Permissions Weakness"
      ],
      "parentId": "technique-hijack-execution-flow-e920f269",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-dll-side-loading-a8374216",
      "code": "DLL Side-Loading",
      "value": "DLL Side-Loading",
      "name": "DLL Side-Loading",
      "definition": "Text about DLL side-loading identifies the practice where attackers replace legitimate dynamic link libraries with compromised files inside application directories, forcing trusted executables to execute malicious payloads upon normal system operation.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Hijack Execution Flow",
        "DLL Side-Loading"
      ],
      "parentId": "technique-hijack-execution-flow-e920f269",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-path-interception-by-unquoted-path-e26ceb7a",
      "code": "Path Interception by Unquoted Path",
      "value": "Path Interception by Unquoted Path",
      "name": "Path Interception by Unquoted Path",
      "definition": "Text about Path Interception by Unquoted Path concerns the unauthorized hijacking of execution flow by exploiting Windows service configuration errors where unquoted file paths permit the interception of service startup commands by adversaries.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Hijack Execution Flow",
        "Path Interception by Unquoted Path"
      ],
      "parentId": "technique-hijack-execution-flow-e920f269",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-dylib-hijacking-47276478",
      "code": "Dylib Hijacking",
      "value": "Dylib Hijacking",
      "name": "Dylib Hijacking",
      "definition": "Text about an adversary manipulating macOS dependency resolution processes by supplying malicious dylib files that override legitimate libraries, resulting in code execution within the targeted application's operating memory space.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Hijack Execution Flow",
        "Dylib Hijacking"
      ],
      "parentId": "technique-hijack-execution-flow-e920f269",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-dynamic-linker-hijacking-b1aaa3ae",
      "code": "Dynamic Linker Hijacking",
      "value": "Dynamic Linker Hijacking",
      "name": "Dynamic Linker Hijacking",
      "definition": "Text about compromising the dynamic linker to redirect library resolution, forcing loaded programs to execute malicious shared objects through the strategic modification of runtime configuration or system paths.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Hijack Execution Flow",
        "Dynamic Linker Hijacking"
      ],
      "parentId": "technique-hijack-execution-flow-e920f269",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-appdomainmanager-a4b62c41",
      "code": "AppDomainManager",
      "value": "AppDomainManager",
      "name": "AppDomainManager",
      "definition": "Text about adversaries manipulating the .NET process initialization routine by configuring a malicious AppDomainManager to execute arbitrary code within the context of a legitimate process via side-loaded assembly configurations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Hijack Execution Flow",
        "AppDomainManager"
      ],
      "parentId": "technique-hijack-execution-flow-e920f269",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-dll-search-order-hijacking-4076ee45",
      "code": "DLL Search Order Hijacking",
      "value": "DLL Search Order Hijacking",
      "name": "DLL Search Order Hijacking",
      "definition": "Text about DLL Search Order Hijacking refers to the practice of weaponizing the library resolution process, where adversaries inject malicious code into applications by prioritizing compromised files during the system search sequence.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Hijack Execution Flow",
        "DLL Search Order Hijacking"
      ],
      "parentId": "technique-hijack-execution-flow-e920f269",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-path-interception-by-search-order-hijacking-cb65f091",
      "code": "Path Interception by Search Order Hijacking",
      "value": "Path Interception by Search Order Hijacking",
      "name": "Path Interception by Search Order Hijacking",
      "definition": "Text about exploiting the search path resolution logic by inserting malicious files into high-priority locations, compelling the operating system to execute them ahead of the intended legitimate binaries or libraries.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Hijack Execution Flow",
        "Path Interception by Search Order Hijacking"
      ],
      "parentId": "technique-hijack-execution-flow-e920f269",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-services-registry-permissions-weakness-c7924d0c",
      "code": "Services Registry Permissions Weakness",
      "value": "Services Registry Permissions Weakness",
      "name": "Services Registry Permissions Weakness",
      "definition": "Text about the security vulnerability where restrictive permissions are absent on registry keys governing service configurations, permitting illegitimate modification of service-related registry entries to redirect execution flows to adversarial binaries.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Hijack Execution Flow",
        "Services Registry Permissions Weakness"
      ],
      "parentId": "technique-hijack-execution-flow-e920f269",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-cor-profiler-00f089dd",
      "code": "COR_PROFILER",
      "value": "COR_PROFILER",
      "name": "COR_PROFILER",
      "definition": "Text about COR_PROFILER characterises the malicious exploitation of the .NET runtime profiler API, forcing the loading of attacker-controlled libraries into managed processes via manipulated environment variables upon application process initialization.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Hijack Execution Flow",
        "COR_PROFILER"
      ],
      "parentId": "technique-hijack-execution-flow-e920f269",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-hijack-execution-flow-515a1a7e",
      "code": "Hijack Execution Flow",
      "value": "Hijack Execution Flow",
      "name": "Hijack Execution Flow",
      "definition": "Text about adversaries manipulation of operating system processes via side-loading, library preloading, or modifying search orders to force the execution of malicious code instead of an intended legitimate program or service.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Privilege Escalation",
        "Hijack Execution Flow"
      ],
      "parentId": "tactic-privilege-escalation-dc3564ae",
      "synthetic": false,
      "childCount": 13,
      "leaf": false
    },
    {
      "id": "subtechnique-services-file-permissions-weakness-884dae36",
      "code": "Services File Permissions Weakness",
      "value": "Services File Permissions Weakness",
      "name": "Services File Permissions Weakness",
      "definition": "Text about illicitly modifying service binary files or configuration paths due to overly permissive access controls, allowing adversaries to execute arbitrary code with the elevated privileges assigned to the targeted service.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Hijack Execution Flow",
        "Services File Permissions Weakness"
      ],
      "parentId": "technique-hijack-execution-flow-515a1a7e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-kernelcallbacktable-fa662efc",
      "code": "KernelCallbackTable",
      "value": "KernelCallbackTable",
      "name": "KernelCallbackTable",
      "definition": "Text about the unauthorized modification of stored function pointers within the process environment block kernel callback table used by adversaries to redirect code execution for gaining persistence or executing malicious payloads stealthily.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Hijack Execution Flow",
        "KernelCallbackTable"
      ],
      "parentId": "technique-hijack-execution-flow-515a1a7e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-path-interception-by-path-environment-variable-90048ef8",
      "code": "Path Interception by PATH Environment Variable",
      "value": "Path Interception by PATH Environment Variable",
      "name": "Path Interception by PATH Environment Variable",
      "definition": "Text about leveraging the PATH environment variable search logic to intercept execution attempts, forcing the operating system to load a malicious binary located in an attacker-controlled directory ahead of expected files.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Hijack Execution Flow",
        "Path Interception by PATH Environment Variable"
      ],
      "parentId": "technique-hijack-execution-flow-515a1a7e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-executable-installer-file-permissions-weakness-ccf02010",
      "code": "Executable Installer File Permissions Weakness",
      "value": "Executable Installer File Permissions Weakness",
      "name": "Executable Installer File Permissions Weakness",
      "definition": "Text about inadequate security settings on installer binaries permitting unauthorized write access, which adversaries exploit to modify or substitute the executable, facilitating the execution of arbitrary code during installation.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Hijack Execution Flow",
        "Executable Installer File Permissions Weakness"
      ],
      "parentId": "technique-hijack-execution-flow-515a1a7e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-dll-side-loading-8d423cb6",
      "code": "DLL Side-Loading",
      "value": "DLL Side-Loading",
      "name": "DLL Side-Loading",
      "definition": "Text about DLL side-loading identifies the practice where attackers replace legitimate dynamic link libraries with compromised files inside application directories, forcing trusted executables to execute malicious payloads upon normal system operation.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Hijack Execution Flow",
        "DLL Side-Loading"
      ],
      "parentId": "technique-hijack-execution-flow-515a1a7e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-path-interception-by-unquoted-path-d007a75d",
      "code": "Path Interception by Unquoted Path",
      "value": "Path Interception by Unquoted Path",
      "name": "Path Interception by Unquoted Path",
      "definition": "Text about Path Interception by Unquoted Path concerns the unauthorized hijacking of execution flow by exploiting Windows service configuration errors where unquoted file paths permit the interception of service startup commands by adversaries.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Hijack Execution Flow",
        "Path Interception by Unquoted Path"
      ],
      "parentId": "technique-hijack-execution-flow-515a1a7e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-dylib-hijacking-e6b13a2f",
      "code": "Dylib Hijacking",
      "value": "Dylib Hijacking",
      "name": "Dylib Hijacking",
      "definition": "Text about an adversary manipulating macOS dependency resolution processes by supplying malicious dylib files that override legitimate libraries, resulting in code execution within the targeted application's operating memory space.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Hijack Execution Flow",
        "Dylib Hijacking"
      ],
      "parentId": "technique-hijack-execution-flow-515a1a7e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-dynamic-linker-hijacking-7c1286c8",
      "code": "Dynamic Linker Hijacking",
      "value": "Dynamic Linker Hijacking",
      "name": "Dynamic Linker Hijacking",
      "definition": "Text about compromising the dynamic linker to redirect library resolution, forcing loaded programs to execute malicious shared objects through the strategic modification of runtime configuration or system paths.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Hijack Execution Flow",
        "Dynamic Linker Hijacking"
      ],
      "parentId": "technique-hijack-execution-flow-515a1a7e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-appdomainmanager-db587557",
      "code": "AppDomainManager",
      "value": "AppDomainManager",
      "name": "AppDomainManager",
      "definition": "Text about adversaries manipulating the .NET process initialization routine by configuring a malicious AppDomainManager to execute arbitrary code within the context of a legitimate process via side-loaded assembly configurations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Hijack Execution Flow",
        "AppDomainManager"
      ],
      "parentId": "technique-hijack-execution-flow-515a1a7e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-dll-search-order-hijacking-604f24be",
      "code": "DLL Search Order Hijacking",
      "value": "DLL Search Order Hijacking",
      "name": "DLL Search Order Hijacking",
      "definition": "Text about DLL Search Order Hijacking refers to the practice of weaponizing the library resolution process, where adversaries inject malicious code into applications by prioritizing compromised files during the system search sequence.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Hijack Execution Flow",
        "DLL Search Order Hijacking"
      ],
      "parentId": "technique-hijack-execution-flow-515a1a7e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-path-interception-by-search-order-hijacking-ee7ba67a",
      "code": "Path Interception by Search Order Hijacking",
      "value": "Path Interception by Search Order Hijacking",
      "name": "Path Interception by Search Order Hijacking",
      "definition": "Text about exploiting the search path resolution logic by inserting malicious files into high-priority locations, compelling the operating system to execute them ahead of the intended legitimate binaries or libraries.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Hijack Execution Flow",
        "Path Interception by Search Order Hijacking"
      ],
      "parentId": "technique-hijack-execution-flow-515a1a7e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-services-registry-permissions-weakness-440d278c",
      "code": "Services Registry Permissions Weakness",
      "value": "Services Registry Permissions Weakness",
      "name": "Services Registry Permissions Weakness",
      "definition": "Text about the security vulnerability where restrictive permissions are absent on registry keys governing service configurations, permitting illegitimate modification of service-related registry entries to redirect execution flows to adversarial binaries.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Hijack Execution Flow",
        "Services Registry Permissions Weakness"
      ],
      "parentId": "technique-hijack-execution-flow-515a1a7e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-cor-profiler-9c9e3eac",
      "code": "COR_PROFILER",
      "value": "COR_PROFILER",
      "name": "COR_PROFILER",
      "definition": "Text about COR_PROFILER characterises the malicious exploitation of the .NET runtime profiler API, forcing the loading of attacker-controlled libraries into managed processes via manipulated environment variables upon application process initialization.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Hijack Execution Flow",
        "COR_PROFILER"
      ],
      "parentId": "technique-hijack-execution-flow-515a1a7e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-hijack-execution-flow-ddc9c128",
      "code": "Hijack Execution Flow",
      "value": "Hijack Execution Flow",
      "name": "Hijack Execution Flow",
      "definition": "Text about adversaries manipulation of operating system processes via side-loading, library preloading, or modifying search orders to force the execution of malicious code instead of an intended legitimate program or service.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Hijack Execution Flow"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 13,
      "leaf": false
    },
    {
      "id": "subtechnique-services-file-permissions-weakness-3aeb40b7",
      "code": "Services File Permissions Weakness",
      "value": "Services File Permissions Weakness",
      "name": "Services File Permissions Weakness",
      "definition": "Text about illicitly modifying service binary files or configuration paths due to overly permissive access controls, allowing adversaries to execute arbitrary code with the elevated privileges assigned to the targeted service.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Hijack Execution Flow",
        "Services File Permissions Weakness"
      ],
      "parentId": "technique-hijack-execution-flow-ddc9c128",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-kernelcallbacktable-2677cc36",
      "code": "KernelCallbackTable",
      "value": "KernelCallbackTable",
      "name": "KernelCallbackTable",
      "definition": "Text about the unauthorized modification of stored function pointers within the process environment block kernel callback table used by adversaries to redirect code execution for gaining persistence or executing malicious payloads stealthily.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Hijack Execution Flow",
        "KernelCallbackTable"
      ],
      "parentId": "technique-hijack-execution-flow-ddc9c128",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-path-interception-by-path-environment-variable-e2bcee2b",
      "code": "Path Interception by PATH Environment Variable",
      "value": "Path Interception by PATH Environment Variable",
      "name": "Path Interception by PATH Environment Variable",
      "definition": "Text about leveraging the PATH environment variable search logic to intercept execution attempts, forcing the operating system to load a malicious binary located in an attacker-controlled directory ahead of expected files.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Hijack Execution Flow",
        "Path Interception by PATH Environment Variable"
      ],
      "parentId": "technique-hijack-execution-flow-ddc9c128",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-executable-installer-file-permissions-weakness-7cdadfa9",
      "code": "Executable Installer File Permissions Weakness",
      "value": "Executable Installer File Permissions Weakness",
      "name": "Executable Installer File Permissions Weakness",
      "definition": "Text about inadequate security settings on installer binaries permitting unauthorized write access, which adversaries exploit to modify or substitute the executable, facilitating the execution of arbitrary code during installation.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Hijack Execution Flow",
        "Executable Installer File Permissions Weakness"
      ],
      "parentId": "technique-hijack-execution-flow-ddc9c128",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-dll-side-loading-24061d4a",
      "code": "DLL Side-Loading",
      "value": "DLL Side-Loading",
      "name": "DLL Side-Loading",
      "definition": "Text about DLL side-loading identifies the practice where attackers replace legitimate dynamic link libraries with compromised files inside application directories, forcing trusted executables to execute malicious payloads upon normal system operation.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Hijack Execution Flow",
        "DLL Side-Loading"
      ],
      "parentId": "technique-hijack-execution-flow-ddc9c128",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-path-interception-by-unquoted-path-bba5e854",
      "code": "Path Interception by Unquoted Path",
      "value": "Path Interception by Unquoted Path",
      "name": "Path Interception by Unquoted Path",
      "definition": "Text about Path Interception by Unquoted Path concerns the unauthorized hijacking of execution flow by exploiting Windows service configuration errors where unquoted file paths permit the interception of service startup commands by adversaries.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Hijack Execution Flow",
        "Path Interception by Unquoted Path"
      ],
      "parentId": "technique-hijack-execution-flow-ddc9c128",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-dylib-hijacking-2bfa7e6d",
      "code": "Dylib Hijacking",
      "value": "Dylib Hijacking",
      "name": "Dylib Hijacking",
      "definition": "Text about an adversary manipulating macOS dependency resolution processes by supplying malicious dylib files that override legitimate libraries, resulting in code execution within the targeted application's operating memory space.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Hijack Execution Flow",
        "Dylib Hijacking"
      ],
      "parentId": "technique-hijack-execution-flow-ddc9c128",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-dynamic-linker-hijacking-702f00c6",
      "code": "Dynamic Linker Hijacking",
      "value": "Dynamic Linker Hijacking",
      "name": "Dynamic Linker Hijacking",
      "definition": "Text about compromising the dynamic linker to redirect library resolution, forcing loaded programs to execute malicious shared objects through the strategic modification of runtime configuration or system paths.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Hijack Execution Flow",
        "Dynamic Linker Hijacking"
      ],
      "parentId": "technique-hijack-execution-flow-ddc9c128",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-appdomainmanager-8af8660a",
      "code": "AppDomainManager",
      "value": "AppDomainManager",
      "name": "AppDomainManager",
      "definition": "Text about adversaries manipulating the .NET process initialization routine by configuring a malicious AppDomainManager to execute arbitrary code within the context of a legitimate process via side-loaded assembly configurations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Hijack Execution Flow",
        "AppDomainManager"
      ],
      "parentId": "technique-hijack-execution-flow-ddc9c128",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-dll-search-order-hijacking-599f796c",
      "code": "DLL Search Order Hijacking",
      "value": "DLL Search Order Hijacking",
      "name": "DLL Search Order Hijacking",
      "definition": "Text about DLL Search Order Hijacking refers to the practice of weaponizing the library resolution process, where adversaries inject malicious code into applications by prioritizing compromised files during the system search sequence.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Hijack Execution Flow",
        "DLL Search Order Hijacking"
      ],
      "parentId": "technique-hijack-execution-flow-ddc9c128",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-path-interception-by-search-order-hijacking-f5ee88c3",
      "code": "Path Interception by Search Order Hijacking",
      "value": "Path Interception by Search Order Hijacking",
      "name": "Path Interception by Search Order Hijacking",
      "definition": "Text about exploiting the search path resolution logic by inserting malicious files into high-priority locations, compelling the operating system to execute them ahead of the intended legitimate binaries or libraries.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Hijack Execution Flow",
        "Path Interception by Search Order Hijacking"
      ],
      "parentId": "technique-hijack-execution-flow-ddc9c128",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-services-registry-permissions-weakness-3ac1c5f5",
      "code": "Services Registry Permissions Weakness",
      "value": "Services Registry Permissions Weakness",
      "name": "Services Registry Permissions Weakness",
      "definition": "Text about the security vulnerability where restrictive permissions are absent on registry keys governing service configurations, permitting illegitimate modification of service-related registry entries to redirect execution flows to adversarial binaries.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Hijack Execution Flow",
        "Services Registry Permissions Weakness"
      ],
      "parentId": "technique-hijack-execution-flow-ddc9c128",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-cor-profiler-fc7974b7",
      "code": "COR_PROFILER",
      "value": "COR_PROFILER",
      "name": "COR_PROFILER",
      "definition": "Text about COR_PROFILER characterises the malicious exploitation of the .NET runtime profiler API, forcing the loading of attacker-controlled libraries into managed processes via manipulated environment variables upon application process initialization.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Hijack Execution Flow",
        "COR_PROFILER"
      ],
      "parentId": "technique-hijack-execution-flow-ddc9c128",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-valid-accounts-ba0c0e17",
      "code": "Valid Accounts",
      "value": "Valid Accounts",
      "name": "Valid Accounts",
      "definition": "Text about adversaries leveraging compromised or fabricated credentials to masquerade as legitimate users within target systems, effectively bypassing security controls while conducting various actions during the course of intrusions.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Valid Accounts"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 4,
      "leaf": false
    },
    {
      "id": "subtechnique-cloud-accounts-41d0e4b1",
      "code": "Cloud Accounts",
      "value": "Cloud Accounts",
      "name": "Cloud Accounts",
      "definition": "Text about Cloud Accounts identifies the use of compromised or illicitly obtained credentials specific to cloud platform ecosystems, enabling attackers to perform malicious actions while masquerading as authorized system entities.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Valid Accounts",
        "Cloud Accounts"
      ],
      "parentId": "technique-valid-accounts-ba0c0e17",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-domain-accounts-37695f9a",
      "code": "Domain Accounts",
      "value": "Domain Accounts",
      "name": "Domain Accounts",
      "definition": "Text about adversaries gathering credentials and account details from domain controllers to identify high-value targets, map network structure, and facilitate unauthorized access within a compromised corporate identity management system environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Valid Accounts",
        "Domain Accounts"
      ],
      "parentId": "technique-valid-accounts-ba0c0e17",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-local-accounts-356d8ca5",
      "code": "Local Accounts",
      "value": "Local Accounts",
      "name": "Local Accounts",
      "definition": "Text about adversaries creating new, unauthorized local user accounts on compromised systems to facilitate continued access and persistence without requiring interaction with central domain or enterprise identity services.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Valid Accounts",
        "Local Accounts"
      ],
      "parentId": "technique-valid-accounts-ba0c0e17",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-default-accounts-97875944",
      "code": "Default Accounts",
      "value": "Default Accounts",
      "name": "Default Accounts",
      "definition": "Text about attackers exploiting insecurely configured systems by utilizing known, vendor-specified default authentication accounts that were left active by administrators, thereby permitting unauthorized entry into the targeted enterprise network environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Valid Accounts",
        "Default Accounts"
      ],
      "parentId": "technique-valid-accounts-ba0c0e17",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-valid-accounts-10d9be63",
      "code": "Valid Accounts",
      "value": "Valid Accounts",
      "name": "Valid Accounts",
      "definition": "Text about adversaries leveraging compromised or fabricated credentials to masquerade as legitimate users within target systems, effectively bypassing security controls while conducting various actions during the course of intrusions.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Persistence",
        "Valid Accounts"
      ],
      "parentId": "tactic-persistence-4782469e",
      "synthetic": false,
      "childCount": 4,
      "leaf": false
    },
    {
      "id": "subtechnique-cloud-accounts-619d764f",
      "code": "Cloud Accounts",
      "value": "Cloud Accounts",
      "name": "Cloud Accounts",
      "definition": "Text about Cloud Accounts identifies the use of compromised or illicitly obtained credentials specific to cloud platform ecosystems, enabling attackers to perform malicious actions while masquerading as authorized system entities.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Valid Accounts",
        "Cloud Accounts"
      ],
      "parentId": "technique-valid-accounts-10d9be63",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-domain-accounts-af767978",
      "code": "Domain Accounts",
      "value": "Domain Accounts",
      "name": "Domain Accounts",
      "definition": "Text about adversaries gathering credentials and account details from domain controllers to identify high-value targets, map network structure, and facilitate unauthorized access within a compromised corporate identity management system environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Valid Accounts",
        "Domain Accounts"
      ],
      "parentId": "technique-valid-accounts-10d9be63",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-local-accounts-318dff04",
      "code": "Local Accounts",
      "value": "Local Accounts",
      "name": "Local Accounts",
      "definition": "Text about adversaries creating new, unauthorized local user accounts on compromised systems to facilitate continued access and persistence without requiring interaction with central domain or enterprise identity services.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Valid Accounts",
        "Local Accounts"
      ],
      "parentId": "technique-valid-accounts-10d9be63",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-default-accounts-53f13216",
      "code": "Default Accounts",
      "value": "Default Accounts",
      "name": "Default Accounts",
      "definition": "Text about attackers exploiting insecurely configured systems by utilizing known, vendor-specified default authentication accounts that were left active by administrators, thereby permitting unauthorized entry into the targeted enterprise network environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Valid Accounts",
        "Default Accounts"
      ],
      "parentId": "technique-valid-accounts-10d9be63",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-valid-accounts-834cfe8d",
      "code": "Valid Accounts",
      "value": "Valid Accounts",
      "name": "Valid Accounts",
      "definition": "Text about adversaries leveraging compromised or fabricated credentials to masquerade as legitimate users within target systems, effectively bypassing security controls while conducting various actions during the course of intrusions.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Privilege Escalation",
        "Valid Accounts"
      ],
      "parentId": "tactic-privilege-escalation-dc3564ae",
      "synthetic": false,
      "childCount": 4,
      "leaf": false
    },
    {
      "id": "subtechnique-cloud-accounts-93fd217d",
      "code": "Cloud Accounts",
      "value": "Cloud Accounts",
      "name": "Cloud Accounts",
      "definition": "Text about Cloud Accounts identifies the use of compromised or illicitly obtained credentials specific to cloud platform ecosystems, enabling attackers to perform malicious actions while masquerading as authorized system entities.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Valid Accounts",
        "Cloud Accounts"
      ],
      "parentId": "technique-valid-accounts-834cfe8d",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-domain-accounts-e2a077ad",
      "code": "Domain Accounts",
      "value": "Domain Accounts",
      "name": "Domain Accounts",
      "definition": "Text about adversaries gathering credentials and account details from domain controllers to identify high-value targets, map network structure, and facilitate unauthorized access within a compromised corporate identity management system environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Valid Accounts",
        "Domain Accounts"
      ],
      "parentId": "technique-valid-accounts-834cfe8d",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-local-accounts-15302ff8",
      "code": "Local Accounts",
      "value": "Local Accounts",
      "name": "Local Accounts",
      "definition": "Text about adversaries creating new, unauthorized local user accounts on compromised systems to facilitate continued access and persistence without requiring interaction with central domain or enterprise identity services.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Valid Accounts",
        "Local Accounts"
      ],
      "parentId": "technique-valid-accounts-834cfe8d",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-default-accounts-bef5f626",
      "code": "Default Accounts",
      "value": "Default Accounts",
      "name": "Default Accounts",
      "definition": "Text about attackers exploiting insecurely configured systems by utilizing known, vendor-specified default authentication accounts that were left active by administrators, thereby permitting unauthorized entry into the targeted enterprise network environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Valid Accounts",
        "Default Accounts"
      ],
      "parentId": "technique-valid-accounts-834cfe8d",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-valid-accounts-cc1653b4",
      "code": "Valid Accounts",
      "value": "Valid Accounts",
      "name": "Valid Accounts",
      "definition": "Text about adversaries leveraging compromised or fabricated credentials to masquerade as legitimate users within target systems, effectively bypassing security controls while conducting various actions during the course of intrusions.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Initial Access",
        "Valid Accounts"
      ],
      "parentId": "tactic-initial-access-a0f45034",
      "synthetic": false,
      "childCount": 4,
      "leaf": false
    },
    {
      "id": "subtechnique-cloud-accounts-aab233c0",
      "code": "Cloud Accounts",
      "value": "Cloud Accounts",
      "name": "Cloud Accounts",
      "definition": "Text about Cloud Accounts identifies the use of compromised or illicitly obtained credentials specific to cloud platform ecosystems, enabling attackers to perform malicious actions while masquerading as authorized system entities.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Initial Access",
        "Valid Accounts",
        "Cloud Accounts"
      ],
      "parentId": "technique-valid-accounts-cc1653b4",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-domain-accounts-afc0a9f1",
      "code": "Domain Accounts",
      "value": "Domain Accounts",
      "name": "Domain Accounts",
      "definition": "Text about adversaries gathering credentials and account details from domain controllers to identify high-value targets, map network structure, and facilitate unauthorized access within a compromised corporate identity management system environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Initial Access",
        "Valid Accounts",
        "Domain Accounts"
      ],
      "parentId": "technique-valid-accounts-cc1653b4",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-local-accounts-eeaed214",
      "code": "Local Accounts",
      "value": "Local Accounts",
      "name": "Local Accounts",
      "definition": "Text about adversaries creating new, unauthorized local user accounts on compromised systems to facilitate continued access and persistence without requiring interaction with central domain or enterprise identity services.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Initial Access",
        "Valid Accounts",
        "Local Accounts"
      ],
      "parentId": "technique-valid-accounts-cc1653b4",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-default-accounts-dd3e06dd",
      "code": "Default Accounts",
      "value": "Default Accounts",
      "name": "Default Accounts",
      "definition": "Text about attackers exploiting insecurely configured systems by utilizing known, vendor-specified default authentication accounts that were left active by administrators, thereby permitting unauthorized entry into the targeted enterprise network environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Initial Access",
        "Valid Accounts",
        "Default Accounts"
      ],
      "parentId": "technique-valid-accounts-cc1653b4",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-non-standard-port-871c10ca",
      "code": "Non-Standard Port",
      "value": "Non-Standard Port",
      "name": "Non-Standard Port",
      "definition": "Text about adversaries intentionally directing network traffic through non-standard port numbers to subvert standardized security policies, avoid scrutiny by intrusion detection systems, and facilitate covert communication channels across the network.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Command and Control",
        "Non-Standard Port"
      ],
      "parentId": "tactic-command-and-control-6b4265ca",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-exploitation-for-privilege-escalation-83b16723",
      "code": "Exploitation for Privilege Escalation",
      "value": "Exploitation for Privilege Escalation",
      "name": "Exploitation for Privilege Escalation",
      "definition": "Text about exploitation for privilege escalation denotes the process of using vulnerable internal components to bypass standard security controls, successfully obtaining higher administrative rights or unrestricted system access during an ongoing intrusion.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Privilege Escalation",
        "Exploitation for Privilege Escalation"
      ],
      "parentId": "tactic-privilege-escalation-dc3564ae",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-account-access-removal-8efec6e5",
      "code": "Account Access Removal",
      "value": "Account Access Removal",
      "name": "Account Access Removal",
      "definition": "Text about Account Access Removal denotes adversaries identifying and actively eliminating, disabling, or modifying authorized user accounts, significantly hindering legitimate security teams from regaining control over compromised network infrastructure components.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Impact",
        "Account Access Removal"
      ],
      "parentId": "tactic-impact-62036a70",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-obfuscated-files-or-information-3bacaee6",
      "code": "Obfuscated Files or Information",
      "value": "Obfuscated Files or Information",
      "name": "Obfuscated Files or Information",
      "definition": "Text about adversaries manipulating code, scripts, or data objects to hide their functionality from defensive security layers, ensuring malicious components remain undetected during delivery, execution, or persistence on a victim.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Obfuscated Files or Information"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 14,
      "leaf": false
    },
    {
      "id": "subtechnique-indicator-removal-from-tools-8f2de5a5",
      "code": "Indicator Removal from Tools",
      "value": "Indicator Removal from Tools",
      "name": "Indicator Removal from Tools",
      "definition": "Text about the deliberate modification or removal of internal data fields and file attributes belonging to malicious software components to hinder security analysts from identifying the underlying origin or specific provenance.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Obfuscated Files or Information",
        "Indicator Removal from Tools"
      ],
      "parentId": "technique-obfuscated-files-or-information-3bacaee6",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-embedded-payloads-189a2b29",
      "code": "Embedded Payloads",
      "value": "Embedded Payloads",
      "name": "Embedded Payloads",
      "definition": "Text about attackers embedding persistent or transient malicious code segments into standard file formats, allowing the hidden payload to remain dormant until specific execution conditions trigger its unauthorized runtime behavior.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Obfuscated Files or Information",
        "Embedded Payloads"
      ],
      "parentId": "technique-obfuscated-files-or-information-3bacaee6",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-encrypted-encoded-file-5aace75a",
      "code": "Encrypted/Encoded File",
      "value": "Encrypted/Encoded File",
      "name": "Encrypted/Encoded File",
      "definition": "Text about adversaries utilizing file-level encryption or encoding transformations to evade automated security inspections and static analysis, allowing hidden malicious content to reside undetected within target systems.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Obfuscated Files or Information",
        "Encrypted/Encoded File"
      ],
      "parentId": "technique-obfuscated-files-or-information-3bacaee6",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-lnk-icon-smuggling-9d331dbe",
      "code": "LNK Icon Smuggling",
      "value": "LNK Icon Smuggling",
      "name": "LNK Icon Smuggling",
      "definition": "Text about exploiting LNK file icon resolution features to force network traffic toward remote, attacker-controlled infrastructure, enabling the delivery and subsequent execution of malicious activities through standard desktop shortcut initialization.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Obfuscated Files or Information",
        "LNK Icon Smuggling"
      ],
      "parentId": "technique-obfuscated-files-or-information-3bacaee6",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-html-smuggling-b01cad85",
      "code": "HTML Smuggling",
      "value": "HTML Smuggling",
      "name": "HTML Smuggling",
      "definition": "Text about adversaries utilizing encoded payloads within HTML blobs, which are then constructed into malicious files locally by client-side browser scripts, effectively bypassing network perimeter security controls during delivery phases.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Obfuscated Files or Information",
        "HTML Smuggling"
      ],
      "parentId": "technique-obfuscated-files-or-information-3bacaee6",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-fileless-storage-3cd9950b",
      "code": "Fileless Storage",
      "value": "Fileless Storage",
      "name": "Fileless Storage",
      "definition": "Text about adversaries persisting malicious tools or configuration data within non-file system locations, specifically leveraging system memory, registry keys, or environment variables to maintain operational access without traditional disk-based file artifacts.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Obfuscated Files or Information",
        "Fileless Storage"
      ],
      "parentId": "technique-obfuscated-files-or-information-3bacaee6",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-polymorphic-code-6f9bcaaa",
      "code": "Polymorphic Code",
      "value": "Polymorphic Code",
      "name": "Polymorphic Code",
      "definition": "Text about polymorphic code denotes a technique where adversaries integrate automated mechanisms to unpredictably change the appearance of malicious files and payloads, successfully bypassing static signature-based detection systems during execution.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Obfuscated Files or Information",
        "Polymorphic Code"
      ],
      "parentId": "technique-obfuscated-files-or-information-3bacaee6",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-command-obfuscation-e779d514",
      "code": "Command Obfuscation",
      "value": "Command Obfuscation",
      "name": "Command Obfuscation",
      "definition": "Text about adversaries altering command syntax or structure to evade signature-based detection mechanisms and analysis tools while executing malicious operations within a comprised system's command-line interface or scripting environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Obfuscated Files or Information",
        "Command Obfuscation"
      ],
      "parentId": "technique-obfuscated-files-or-information-3bacaee6",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-compile-after-delivery-b18a7cdd",
      "code": "Compile After Delivery",
      "value": "Compile After Delivery",
      "name": "Compile After Delivery",
      "definition": "Text about attackers transmitting source code payloads to a compromised host, subsequently utilizing local build tools or interpreters to perform compilation or execution rather than deploying already compiled binary files.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Obfuscated Files or Information",
        "Compile After Delivery"
      ],
      "parentId": "technique-obfuscated-files-or-information-3bacaee6",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-dynamic-api-resolution-98e9c284",
      "code": "Dynamic API Resolution",
      "value": "Dynamic API Resolution",
      "name": "Dynamic API Resolution",
      "definition": "Text about adversaries resolving API function addresses at runtime via operating system loaders and internal mechanisms to execute malicious payloads without relying on static imports within the compiled program code.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Obfuscated Files or Information",
        "Dynamic API Resolution"
      ],
      "parentId": "technique-obfuscated-files-or-information-3bacaee6",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-steganography-a103eae3",
      "code": "Steganography",
      "value": "Steganography",
      "name": "Steganography",
      "definition": "Text about leveraging digital file structures to hide covert data, allowing adversaries to transmit unauthorized information past security boundaries by masking malicious content within standard, seemingly routine file transmission operations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Obfuscated Files or Information",
        "Steganography"
      ],
      "parentId": "technique-obfuscated-files-or-information-3bacaee6",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-stripped-payloads-0dd5cd75",
      "code": "Stripped Payloads",
      "value": "Stripped Payloads",
      "name": "Stripped Payloads",
      "definition": "Text about omitting internal symbol tables and compilation artifacts from malicious binaries, thereby masking execution paths and data structures required for successful reverse engineering and signature-based detection by defenders.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Obfuscated Files or Information",
        "Stripped Payloads"
      ],
      "parentId": "technique-obfuscated-files-or-information-3bacaee6",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-software-packing-9d5b2ca5",
      "code": "Software Packing",
      "value": "Software Packing",
      "name": "Software Packing",
      "definition": "Text about attackers bundling malicious code into a compressed or encrypted format to obfuscate core functionalities, bypass security scanners, and thwart static analysis by security tools monitoring executable files on networks.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Obfuscated Files or Information",
        "Software Packing"
      ],
      "parentId": "technique-obfuscated-files-or-information-3bacaee6",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-binary-padding-fd01faa1",
      "code": "Binary Padding",
      "value": "Binary Padding",
      "name": "Binary Padding",
      "definition": "Text about Binary Padding denotes the tactical addition of meaningless code or raw data to an existing malicious file to alter its file signature, thereby preventing identification by automated signature-based detection software.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Obfuscated Files or Information",
        "Binary Padding"
      ],
      "parentId": "technique-obfuscated-files-or-information-3bacaee6",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-password-policy-discovery-3c966f77",
      "code": "Password Policy Discovery",
      "value": "Password Policy Discovery",
      "name": "Password Policy Discovery",
      "definition": "Text about adversaries extracting password policy settings from local or network directories to understand complexity constraints and lockout triggers, which informs the design of brute-force and credential stuffing attack vectors.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "Password Policy Discovery"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-event-triggered-execution-9242c22a",
      "code": "Event Triggered Execution",
      "value": "Event Triggered Execution",
      "name": "Event Triggered Execution",
      "definition": "Text about event triggered execution characterizes techniques where attackers programmatically configure system components to automatically run malicious payloads upon the occurrence of specific, predictable events within the operating environment.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Privilege Escalation",
        "Event Triggered Execution"
      ],
      "parentId": "tactic-privilege-escalation-dc3564ae",
      "synthetic": false,
      "childCount": 17,
      "leaf": false
    },
    {
      "id": "subtechnique-screensaver-8e36a327",
      "code": "Screensaver",
      "value": "Screensaver",
      "name": "Screensaver",
      "definition": "Text about adversaries modifying or replacing legitimate screensaver executable files to execute malicious code automatically when the screensaver activates, thereby achieving persistence or establishing control on a compromised host system.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Event Triggered Execution",
        "Screensaver"
      ],
      "parentId": "technique-event-triggered-execution-9242c22a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-powershell-profile-6f3fcff7",
      "code": "PowerShell Profile",
      "value": "PowerShell Profile",
      "name": "PowerShell Profile",
      "definition": "Text about the unauthorized modification of PowerShell profile scripts to facilitate code execution during session initialization, providing a persistent foothold that activates whenever a PowerShell instance launches on the targeted system.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Event Triggered Execution",
        "PowerShell Profile"
      ],
      "parentId": "technique-event-triggered-execution-9242c22a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-installer-packages-49067b4f",
      "code": "Installer Packages",
      "value": "Installer Packages",
      "name": "Installer Packages",
      "definition": "Text about installer packages concerns methods where adversaries utilize legitimate installation file formats to conceal malicious payloads, ensuring code execution occurs during the routine software deployment process on centralized systems.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Event Triggered Execution",
        "Installer Packages"
      ],
      "parentId": "technique-event-triggered-execution-9242c22a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-windows-management-instrumentation-event-subscription-fbec55b1",
      "code": "Windows Management Instrumentation Event Subscription",
      "value": "Windows Management Instrumentation Event Subscription",
      "name": "Windows Management Instrumentation Event Subscription",
      "definition": "Text about WMI event subscriptions involves attackers configuring WMI event filters and consumers to trigger malicious payloads automatically upon specific system events, thereby establishing persistence without needing constantly running malware processes.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Event Triggered Execution",
        "Windows Management Instrumentation Event Subscription"
      ],
      "parentId": "technique-event-triggered-execution-9242c22a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-lc-load-dylib-addition-ab7cd091",
      "code": "LC_LOAD_DYLIB Addition",
      "value": "LC_LOAD_DYLIB Addition",
      "name": "LC_LOAD_DYLIB Addition",
      "definition": "Text about the malicious modification of Mach-O binary structures through command insertion, ensuring that a target system loader automatically maps and executes an unauthorized dynamic library file whenever the binary starts executing.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Event Triggered Execution",
        "LC_LOAD_DYLIB Addition"
      ],
      "parentId": "technique-event-triggered-execution-9242c22a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-application-shimming-445720bf",
      "code": "Application Shimming",
      "value": "Application Shimming",
      "name": "Application Shimming",
      "definition": "Text about adversaries deploying malicious shim files to alter how Windows applications interface with system libraries, enabling persistent execution of unauthorized code whenever the targeted application processes start.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Event Triggered Execution",
        "Application Shimming"
      ],
      "parentId": "technique-event-triggered-execution-9242c22a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-component-object-model-hijacking-93355b97",
      "code": "Component Object Model Hijacking",
      "value": "Component Object Model Hijacking",
      "name": "Component Object Model Hijacking",
      "definition": "Text about the malicious alteration of Component Object Model registry keys to hijack legitimate software execution paths, causing applications to inadvertently load and run adversary-controlled libraries instead of original system files.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Event Triggered Execution",
        "Component Object Model Hijacking"
      ],
      "parentId": "technique-event-triggered-execution-9242c22a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-unix-shell-configuration-modification-6f05a764",
      "code": "Unix Shell Configuration Modification",
      "value": "Unix Shell Configuration Modification",
      "name": "Unix Shell Configuration Modification",
      "definition": "Text about attackers gaining sustained access by modifying shell initialization files or environment setup scripts to ensure execution of malicious functions or commands whenever a user opens a shell.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Event Triggered Execution",
        "Unix Shell Configuration Modification"
      ],
      "parentId": "technique-event-triggered-execution-9242c22a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-appinit-dlls-fe4e7d2d",
      "code": "AppInit DLLs",
      "value": "AppInit DLLs",
      "name": "AppInit DLLs",
      "definition": "Text about AppInit DLLs involves adversaries modifying Registry values to force malicious dynamic link libraries to load into any process that loads User32.dll, thereby facilitating persistent and covert code execution.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Event Triggered Execution",
        "AppInit DLLs"
      ],
      "parentId": "technique-event-triggered-execution-9242c22a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-trap-bd02d0d2",
      "code": "Trap",
      "value": "Trap",
      "name": "Trap",
      "definition": "Text about adversaries abusing the Unix shell trap command to register commands that execute when the shell receives specified signals or interrupts, achieving event-triggered execution or persistence.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Event Triggered Execution",
        "Trap"
      ],
      "parentId": "technique-event-triggered-execution-9242c22a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-netsh-helper-dll-90207899",
      "code": "Netsh Helper DLL",
      "value": "Netsh Helper DLL",
      "name": "Netsh Helper DLL",
      "definition": "Text about threat actors hijacking the netsh helper mechanism, requiring the registration of malignant dynamic link libraries that the utility automatically loads, effectively gaining persistent privilege and execution within system processes.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Event Triggered Execution",
        "Netsh Helper DLL"
      ],
      "parentId": "technique-event-triggered-execution-9242c22a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-image-file-execution-options-injection-abed6033",
      "code": "Image File Execution Options Injection",
      "value": "Image File Execution Options Injection",
      "name": "Image File Execution Options Injection",
      "definition": "Text about abusing the Image File Execution Options registry key to redirect program launching, enabling the persistent execution of malicious binaries by attaching them to legitimate process startups on Windows systems.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Event Triggered Execution",
        "Image File Execution Options Injection"
      ],
      "parentId": "technique-event-triggered-execution-9242c22a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-change-default-file-association-d104ae38",
      "code": "Change Default File Association",
      "value": "Change Default File Association",
      "name": "Change Default File Association",
      "definition": "Text about modifying registry keys or system configurations to alter which executable program launches when specific file types are opened, facilitating the execution of malicious code upon user interaction with files.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Event Triggered Execution",
        "Change Default File Association"
      ],
      "parentId": "technique-event-triggered-execution-9242c22a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-appcert-dlls-055504aa",
      "code": "AppCert DLLs",
      "value": "AppCert DLLs",
      "name": "AppCert DLLs",
      "definition": "Text about AppCert DLLs entails leveraging specific registry configurations to force the persistent execution of injected malicious dynamic link libraries, whenever a new process is spawned by the host operating system.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Event Triggered Execution",
        "AppCert DLLs"
      ],
      "parentId": "technique-event-triggered-execution-9242c22a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-udev-rules-f78dcae6",
      "code": "Udev Rules",
      "value": "Udev Rules",
      "name": "Udev Rules",
      "definition": "Text about attackers leveraging the Linux device configuration subsystem to create persistent backdoors by associating malicious executable commands with specific hardware attachment events detected by the system's udev daemon.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Event Triggered Execution",
        "Udev Rules"
      ],
      "parentId": "technique-event-triggered-execution-9242c22a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-emond-2d917bbc",
      "code": "Emond",
      "value": "Emond",
      "name": "Emond",
      "definition": "Text about Emond details the abuse of the native macOS event monitoring service, enabling attackers to bind malicious command execution to specific system triggers for persistence and subsequent unauthorized activity.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Event Triggered Execution",
        "Emond"
      ],
      "parentId": "technique-event-triggered-execution-9242c22a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-accessibility-features-9310e55c",
      "code": "Accessibility Features",
      "value": "Accessibility Features",
      "name": "Accessibility Features",
      "definition": "Text about exploiting configuration flaws in operating system accessibility tools where attackers replace standard system binaries with malicious counterparts, facilitating unauthorized execution of arbitrary commands with elevated permissions upon user interaction.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Event Triggered Execution",
        "Accessibility Features"
      ],
      "parentId": "technique-event-triggered-execution-9242c22a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-event-triggered-execution-d431f16f",
      "code": "Event Triggered Execution",
      "value": "Event Triggered Execution",
      "name": "Event Triggered Execution",
      "definition": "Text about event triggered execution characterizes techniques where attackers programmatically configure system components to automatically run malicious payloads upon the occurrence of specific, predictable events within the operating environment.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Persistence",
        "Event Triggered Execution"
      ],
      "parentId": "tactic-persistence-4782469e",
      "synthetic": false,
      "childCount": 17,
      "leaf": false
    },
    {
      "id": "subtechnique-screensaver-0de201c2",
      "code": "Screensaver",
      "value": "Screensaver",
      "name": "Screensaver",
      "definition": "Text about adversaries modifying or replacing legitimate screensaver executable files to execute malicious code automatically when the screensaver activates, thereby achieving persistence or establishing control on a compromised host system.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Event Triggered Execution",
        "Screensaver"
      ],
      "parentId": "technique-event-triggered-execution-d431f16f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-powershell-profile-bbdbef02",
      "code": "PowerShell Profile",
      "value": "PowerShell Profile",
      "name": "PowerShell Profile",
      "definition": "Text about the unauthorized modification of PowerShell profile scripts to facilitate code execution during session initialization, providing a persistent foothold that activates whenever a PowerShell instance launches on the targeted system.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Event Triggered Execution",
        "PowerShell Profile"
      ],
      "parentId": "technique-event-triggered-execution-d431f16f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-installer-packages-28be017f",
      "code": "Installer Packages",
      "value": "Installer Packages",
      "name": "Installer Packages",
      "definition": "Text about installer packages concerns methods where adversaries utilize legitimate installation file formats to conceal malicious payloads, ensuring code execution occurs during the routine software deployment process on centralized systems.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Event Triggered Execution",
        "Installer Packages"
      ],
      "parentId": "technique-event-triggered-execution-d431f16f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-windows-management-instrumentation-event-subscription-282d5bb8",
      "code": "Windows Management Instrumentation Event Subscription",
      "value": "Windows Management Instrumentation Event Subscription",
      "name": "Windows Management Instrumentation Event Subscription",
      "definition": "Text about WMI event subscriptions involves attackers configuring WMI event filters and consumers to trigger malicious payloads automatically upon specific system events, thereby establishing persistence without needing constantly running malware processes.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Event Triggered Execution",
        "Windows Management Instrumentation Event Subscription"
      ],
      "parentId": "technique-event-triggered-execution-d431f16f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-lc-load-dylib-addition-4f05daa2",
      "code": "LC_LOAD_DYLIB Addition",
      "value": "LC_LOAD_DYLIB Addition",
      "name": "LC_LOAD_DYLIB Addition",
      "definition": "Text about the malicious modification of Mach-O binary structures through command insertion, ensuring that a target system loader automatically maps and executes an unauthorized dynamic library file whenever the binary starts executing.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Event Triggered Execution",
        "LC_LOAD_DYLIB Addition"
      ],
      "parentId": "technique-event-triggered-execution-d431f16f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-application-shimming-cfb3bb23",
      "code": "Application Shimming",
      "value": "Application Shimming",
      "name": "Application Shimming",
      "definition": "Text about adversaries deploying malicious shim files to alter how Windows applications interface with system libraries, enabling persistent execution of unauthorized code whenever the targeted application processes start.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Event Triggered Execution",
        "Application Shimming"
      ],
      "parentId": "technique-event-triggered-execution-d431f16f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-component-object-model-hijacking-e7c9dc37",
      "code": "Component Object Model Hijacking",
      "value": "Component Object Model Hijacking",
      "name": "Component Object Model Hijacking",
      "definition": "Text about the malicious alteration of Component Object Model registry keys to hijack legitimate software execution paths, causing applications to inadvertently load and run adversary-controlled libraries instead of original system files.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Event Triggered Execution",
        "Component Object Model Hijacking"
      ],
      "parentId": "technique-event-triggered-execution-d431f16f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-unix-shell-configuration-modification-f876daa0",
      "code": "Unix Shell Configuration Modification",
      "value": "Unix Shell Configuration Modification",
      "name": "Unix Shell Configuration Modification",
      "definition": "Text about attackers gaining sustained access by modifying shell initialization files or environment setup scripts to ensure execution of malicious functions or commands whenever a user opens a shell.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Event Triggered Execution",
        "Unix Shell Configuration Modification"
      ],
      "parentId": "technique-event-triggered-execution-d431f16f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-appinit-dlls-032ee3a9",
      "code": "AppInit DLLs",
      "value": "AppInit DLLs",
      "name": "AppInit DLLs",
      "definition": "Text about AppInit DLLs involves adversaries modifying Registry values to force malicious dynamic link libraries to load into any process that loads User32.dll, thereby facilitating persistent and covert code execution.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Event Triggered Execution",
        "AppInit DLLs"
      ],
      "parentId": "technique-event-triggered-execution-d431f16f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-trap-ec1dfdfc",
      "code": "Trap",
      "value": "Trap",
      "name": "Trap",
      "definition": "Text about adversaries abusing the Unix shell trap command to register commands that execute when the shell receives specified signals or interrupts, achieving event-triggered execution or persistence.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Event Triggered Execution",
        "Trap"
      ],
      "parentId": "technique-event-triggered-execution-d431f16f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-netsh-helper-dll-94467527",
      "code": "Netsh Helper DLL",
      "value": "Netsh Helper DLL",
      "name": "Netsh Helper DLL",
      "definition": "Text about threat actors hijacking the netsh helper mechanism, requiring the registration of malignant dynamic link libraries that the utility automatically loads, effectively gaining persistent privilege and execution within system processes.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Event Triggered Execution",
        "Netsh Helper DLL"
      ],
      "parentId": "technique-event-triggered-execution-d431f16f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-image-file-execution-options-injection-cae6a6f6",
      "code": "Image File Execution Options Injection",
      "value": "Image File Execution Options Injection",
      "name": "Image File Execution Options Injection",
      "definition": "Text about abusing the Image File Execution Options registry key to redirect program launching, enabling the persistent execution of malicious binaries by attaching them to legitimate process startups on Windows systems.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Event Triggered Execution",
        "Image File Execution Options Injection"
      ],
      "parentId": "technique-event-triggered-execution-d431f16f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-change-default-file-association-2158e759",
      "code": "Change Default File Association",
      "value": "Change Default File Association",
      "name": "Change Default File Association",
      "definition": "Text about modifying registry keys or system configurations to alter which executable program launches when specific file types are opened, facilitating the execution of malicious code upon user interaction with files.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Event Triggered Execution",
        "Change Default File Association"
      ],
      "parentId": "technique-event-triggered-execution-d431f16f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-appcert-dlls-3c104fc0",
      "code": "AppCert DLLs",
      "value": "AppCert DLLs",
      "name": "AppCert DLLs",
      "definition": "Text about AppCert DLLs entails leveraging specific registry configurations to force the persistent execution of injected malicious dynamic link libraries, whenever a new process is spawned by the host operating system.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Event Triggered Execution",
        "AppCert DLLs"
      ],
      "parentId": "technique-event-triggered-execution-d431f16f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-udev-rules-30eff310",
      "code": "Udev Rules",
      "value": "Udev Rules",
      "name": "Udev Rules",
      "definition": "Text about attackers leveraging the Linux device configuration subsystem to create persistent backdoors by associating malicious executable commands with specific hardware attachment events detected by the system's udev daemon.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Event Triggered Execution",
        "Udev Rules"
      ],
      "parentId": "technique-event-triggered-execution-d431f16f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-emond-78ffe1dd",
      "code": "Emond",
      "value": "Emond",
      "name": "Emond",
      "definition": "Text about Emond details the abuse of the native macOS event monitoring service, enabling attackers to bind malicious command execution to specific system triggers for persistence and subsequent unauthorized activity.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Event Triggered Execution",
        "Emond"
      ],
      "parentId": "technique-event-triggered-execution-d431f16f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-accessibility-features-0e7148e1",
      "code": "Accessibility Features",
      "value": "Accessibility Features",
      "name": "Accessibility Features",
      "definition": "Text about exploiting configuration flaws in operating system accessibility tools where attackers replace standard system binaries with malicious counterparts, facilitating unauthorized execution of arbitrary commands with elevated permissions upon user interaction.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Event Triggered Execution",
        "Accessibility Features"
      ],
      "parentId": "technique-event-triggered-execution-d431f16f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-forced-authentication-80e9ad10",
      "code": "Forced Authentication",
      "value": "Forced Authentication",
      "name": "Forced Authentication",
      "definition": "Text about Forced Authentication identifies methods where attackers induce target systems to perform unauthorized credential exchanges or authentication handshakes with malicious entities by spoofing or manipulating underlying network protocols.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Credential Access",
        "Forced Authentication"
      ],
      "parentId": "tactic-credential-access-9c65f4e0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-network-boundary-bridging-ab144e28",
      "code": "Network Boundary Bridging",
      "value": "Network Boundary Bridging",
      "name": "Network Boundary Bridging",
      "definition": "Text about adversaries establishing unauthorized communication paths between segregated network compartments, leveraging internal bridging infrastructure to bypass security controls that were implemented to isolate distinct enterprise network architectural segments.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Network Boundary Bridging"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 1,
      "leaf": false
    },
    {
      "id": "subtechnique-network-address-translation-traversal-58c112af",
      "code": "Network Address Translation Traversal",
      "value": "Network Address Translation Traversal",
      "name": "Network Address Translation Traversal",
      "definition": "Text about adversaries utilizing specific NAT traversal mechanisms to subvert restrictive gateway configurations, thereby enabling inbound communication flows to compromised internal hosts without altering established perimeter firewall security access control lists.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Network Boundary Bridging",
        "Network Address Translation Traversal"
      ],
      "parentId": "technique-network-boundary-bridging-ab144e28",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-data-encrypted-for-impact-fec80113",
      "code": "Data Encrypted for Impact",
      "value": "Data Encrypted for Impact",
      "name": "Data Encrypted for Impact",
      "definition": "Text about malicious actors utilizing strong encryption algorithms on sensitive corporate files, databases, or systems to permanently deny legitimate user access, thereby obstructing business operations and causing significant data unavailability.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Impact",
        "Data Encrypted for Impact"
      ],
      "parentId": "tactic-impact-62036a70",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-subvert-trust-controls-09c1546c",
      "code": "Subvert Trust Controls",
      "value": "Subvert Trust Controls",
      "name": "Subvert Trust Controls",
      "definition": "Text about adversaries manipulating or compromising security components responsible for validating digital integrity, such as code signing, certificate validation, or trusted platform modules, to establish unauthorized and stealthy execution capabilities.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Subvert Trust Controls"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 6,
      "leaf": false
    },
    {
      "id": "subtechnique-mark-of-the-web-bypass-e42d3ed6",
      "code": "Mark-of-the-Web Bypass",
      "value": "Mark-of-the-Web Bypass",
      "name": "Mark-of-the-Web Bypass",
      "definition": "Text about adversaries utilizing specific techniques to circumvent zone identifier security annotations applied by operating systems, ensuring downloaded files evade protective execution restrictions typically triggered by these critical metadata flags.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Subvert Trust Controls",
        "Mark-of-the-Web Bypass"
      ],
      "parentId": "technique-subvert-trust-controls-09c1546c",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-code-signing-429c5bc9",
      "code": "Code Signing",
      "value": "Code Signing",
      "name": "Code Signing",
      "definition": "Text about actors obtaining or forging trusted digital certificates to sign malicious binaries, successfully deceiving host security verification mechanisms that require valid signatures before allowing software execution within a targeted infrastructure.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Subvert Trust Controls",
        "Code Signing"
      ],
      "parentId": "technique-subvert-trust-controls-09c1546c",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-install-root-certificate-df041733",
      "code": "Install Root Certificate",
      "value": "Install Root Certificate",
      "name": "Install Root Certificate",
      "definition": "Text about unauthorized installation of root certificates into an endpoint's certification authority store, enabling adversaries to establish persistent trust for malicious applications or inspect encrypted traffic by subverting established validation chains.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Subvert Trust Controls",
        "Install Root Certificate"
      ],
      "parentId": "technique-subvert-trust-controls-09c1546c",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-sip-and-trust-provider-hijacking-de65aecb",
      "code": "SIP and Trust Provider Hijacking",
      "value": "SIP and Trust Provider Hijacking",
      "name": "SIP and Trust Provider Hijacking",
      "definition": "Text about SIP and Trust Provider Hijacking identifies the adversarial compromise of trust provider mechanisms designed to verify signatures, facilitating the execution of unauthorized or malicious code by bypassing native checks.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Subvert Trust Controls",
        "SIP and Trust Provider Hijacking"
      ],
      "parentId": "technique-subvert-trust-controls-09c1546c",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-code-signing-policy-modification-571570d9",
      "code": "Code Signing Policy Modification",
      "value": "Code Signing Policy Modification",
      "name": "Code Signing Policy Modification",
      "definition": "Text about adversaries altering system configurations or registry keys to disable, weaken, or bypass signature validation requirements, allowing the execution of unsigned or unverifiable software code on target systems.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Subvert Trust Controls",
        "Code Signing Policy Modification"
      ],
      "parentId": "technique-subvert-trust-controls-09c1546c",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-gatekeeper-bypass-4d63b820",
      "code": "Gatekeeper Bypass",
      "value": "Gatekeeper Bypass",
      "name": "Gatekeeper Bypass",
      "definition": "Text about Gatekeeper Bypass explains the subversion of macOS native security mechanisms tasked with scanning downloaded software, enabling the execution of malicious binaries that lack required developer identification and certification.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Subvert Trust Controls",
        "Gatekeeper Bypass"
      ],
      "parentId": "technique-subvert-trust-controls-09c1546c",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-encrypted-channel-1d9900c2",
      "code": "Encrypted Channel",
      "value": "Encrypted Channel",
      "name": "Encrypted Channel",
      "definition": "Text about utilizing encrypted communication tunnels to obscure malicious command and control data, preventing defensive systems from detecting, decoding, or inspecting the content of adversary-to-victim network interactions effectively.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Command and Control",
        "Encrypted Channel"
      ],
      "parentId": "tactic-command-and-control-6b4265ca",
      "synthetic": false,
      "childCount": 2,
      "leaf": false
    },
    {
      "id": "subtechnique-asymmetric-cryptography-41ee5ec7",
      "code": "Asymmetric Cryptography",
      "value": "Asymmetric Cryptography",
      "name": "Asymmetric Cryptography",
      "definition": "Text about the intentional misuse of asymmetric encryption mechanisms by threat actors for the purpose of maintaining stealthy, encrypted command and control over compromised infrastructure or securing stolen digital information.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Command and Control",
        "Encrypted Channel",
        "Asymmetric Cryptography"
      ],
      "parentId": "technique-encrypted-channel-1d9900c2",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-symmetric-cryptography-bf25e50d",
      "code": "Symmetric Cryptography",
      "value": "Symmetric Cryptography",
      "name": "Symmetric Cryptography",
      "definition": "Text about leveraging symmetric algorithms to obfuscate malicious files, commands, or protocol traffic, necessitating specific key possession for decryption and allowing attackers to bypass signature-based detection mechanisms during active intrusions.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Command and Control",
        "Encrypted Channel",
        "Symmetric Cryptography"
      ],
      "parentId": "technique-encrypted-channel-1d9900c2",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-input-capture-12983960",
      "code": "Input Capture",
      "value": "Input Capture",
      "name": "Input Capture",
      "definition": "Text about unauthorized monitoring of data streams from input devices or software APIs to harvest sensitive information, including user credentials or keystrokes, directly from the targeted system's operating environment.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Collection",
        "Input Capture"
      ],
      "parentId": "tactic-collection-30c54a96",
      "synthetic": false,
      "childCount": 4,
      "leaf": false
    },
    {
      "id": "subtechnique-keylogging-8b858b2b",
      "code": "Keylogging",
      "value": "Keylogging",
      "name": "Keylogging",
      "definition": "Text about Keylogging encompasses the systematic recording of user keystrokes on compromised hardware, allowing adversaries to covertly intercept and exfiltrate credentials, system commands, and personal information during an intrusion.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Collection",
        "Input Capture",
        "Keylogging"
      ],
      "parentId": "technique-input-capture-12983960",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-gui-input-capture-ae4bcf3f",
      "code": "GUI Input Capture",
      "value": "GUI Input Capture",
      "name": "GUI Input Capture",
      "definition": "Text about adversaries programmatically intercepting data entered through graphical user interface components by hooking system APIs, capturing keystrokes, or recording mouse movements to exfiltrate credentials and sensitive user information during operations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Collection",
        "Input Capture",
        "GUI Input Capture"
      ],
      "parentId": "technique-input-capture-12983960",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-credential-api-hooking-42eded59",
      "code": "Credential API Hooking",
      "value": "Credential API Hooking",
      "name": "Credential API Hooking",
      "definition": "Text about exploiting API hooking mechanisms to intercept function arguments or return values, specifically targeting authentication routines to exfiltrate valid credentials used during local or remote user login events.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Collection",
        "Input Capture",
        "Credential API Hooking"
      ],
      "parentId": "technique-input-capture-12983960",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-web-portal-capture-cae8db3a",
      "code": "Web Portal Capture",
      "value": "Web Portal Capture",
      "name": "Web Portal Capture",
      "definition": "Text about unauthorized modification of web portal authentication components to facilitate the interception and harvesting of user login credentials, session identifiers, or other sensitive authentication assertions during the login process.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Collection",
        "Input Capture",
        "Web Portal Capture"
      ],
      "parentId": "technique-input-capture-12983960",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-input-capture-0b45f177",
      "code": "Input Capture",
      "value": "Input Capture",
      "name": "Input Capture",
      "definition": "Text about unauthorized monitoring of data streams from input devices or software APIs to harvest sensitive information, including user credentials or keystrokes, directly from the targeted system's operating environment.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Credential Access",
        "Input Capture"
      ],
      "parentId": "tactic-credential-access-9c65f4e0",
      "synthetic": false,
      "childCount": 4,
      "leaf": false
    },
    {
      "id": "subtechnique-keylogging-bc77f43a",
      "code": "Keylogging",
      "value": "Keylogging",
      "name": "Keylogging",
      "definition": "Text about Keylogging encompasses the systematic recording of user keystrokes on compromised hardware, allowing adversaries to covertly intercept and exfiltrate credentials, system commands, and personal information during an intrusion.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Input Capture",
        "Keylogging"
      ],
      "parentId": "technique-input-capture-0b45f177",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-gui-input-capture-a1dae94f",
      "code": "GUI Input Capture",
      "value": "GUI Input Capture",
      "name": "GUI Input Capture",
      "definition": "Text about adversaries programmatically intercepting data entered through graphical user interface components by hooking system APIs, capturing keystrokes, or recording mouse movements to exfiltrate credentials and sensitive user information during operations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Input Capture",
        "GUI Input Capture"
      ],
      "parentId": "technique-input-capture-0b45f177",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-credential-api-hooking-b1a89298",
      "code": "Credential API Hooking",
      "value": "Credential API Hooking",
      "name": "Credential API Hooking",
      "definition": "Text about exploiting API hooking mechanisms to intercept function arguments or return values, specifically targeting authentication routines to exfiltrate valid credentials used during local or remote user login events.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Input Capture",
        "Credential API Hooking"
      ],
      "parentId": "technique-input-capture-0b45f177",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-web-portal-capture-121ce073",
      "code": "Web Portal Capture",
      "value": "Web Portal Capture",
      "name": "Web Portal Capture",
      "definition": "Text about unauthorized modification of web portal authentication components to facilitate the interception and harvesting of user login credentials, session identifiers, or other sensitive authentication assertions during the login process.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Input Capture",
        "Web Portal Capture"
      ],
      "parentId": "technique-input-capture-0b45f177",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-exploitation-for-client-execution-85644d8c",
      "code": "Exploitation for Client Execution",
      "value": "Exploitation for Client Execution",
      "name": "Exploitation for Client Execution",
      "definition": "Text about adversaries exploiting critical vulnerabilities in client-side software to execute malicious code, allowing attackers to establish unauthorized access or control over an internal system by compromising the local environment.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Execution",
        "Exploitation for Client Execution"
      ],
      "parentId": "tactic-execution-6d525b71",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-lateral-tool-transfer-6002ccb2",
      "code": "Lateral Tool Transfer",
      "value": "Lateral Tool Transfer",
      "name": "Lateral Tool Transfer",
      "definition": "Text about attackers moving specialized utility binaries or custom scripts between compromised network endpoints to enable further offensive actions, successfully transitioning operational assets across systems within the targeted enterprise perimeter.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Lateral Movement",
        "Lateral Tool Transfer"
      ],
      "parentId": "tactic-lateral-movement-4cec3f1f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-non-application-layer-protocol-019c41a5",
      "code": "Non-Application Layer Protocol",
      "value": "Non-Application Layer Protocol",
      "name": "Non-Application Layer Protocol",
      "definition": "Text about adversaries utilizing lower-level network layer protocols for command and control or data exfiltration, bypassing standard application-level restrictions by embedding malicious communication directly within network infrastructure transport mechanisms.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Command and Control",
        "Non-Application Layer Protocol"
      ],
      "parentId": "tactic-command-and-control-6b4265ca",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-query-registry-e8b0deba",
      "code": "Query Registry",
      "value": "Query Registry",
      "name": "Query Registry",
      "definition": "Text about accessing sensitive, non-volatile system configuration databases where adversaries query specific registry hives to identify installed services, startup applications, and other system-level parameters critical to ongoing malicious activity efforts.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "Query Registry"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-data-transfer-size-limits-6f09f71c",
      "code": "Data Transfer Size Limits",
      "value": "Data Transfer Size Limits",
      "name": "Data Transfer Size Limits",
      "definition": "Text about threat actors transmitting stolen information in broken-down, smaller portions to circumvent data loss prevention solutions or flow control systems that specifically limit large single-session data transfers.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Exfiltration",
        "Data Transfer Size Limits"
      ],
      "parentId": "tactic-exfiltration-fcb9fccc",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-endpoint-denial-of-service-1e0dedc0",
      "code": "Endpoint Denial of Service",
      "value": "Endpoint Denial of Service",
      "name": "Endpoint Denial of Service",
      "definition": "Text about the deliberate interruption of normal device operations through local resource depletion, causing the host to stop responding to commands or providing services required by legitimate system users.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Impact",
        "Endpoint Denial of Service"
      ],
      "parentId": "tactic-impact-62036a70",
      "synthetic": false,
      "childCount": 4,
      "leaf": false
    },
    {
      "id": "subtechnique-application-exhaustion-flood-e84e9d25",
      "code": "Application Exhaustion Flood",
      "value": "Application Exhaustion Flood",
      "name": "Application Exhaustion Flood",
      "definition": "Text about an adversary activity that targets application-level interfaces with intense request floods, aiming to exhaust server resource limits and degrade system performance until the application becomes entirely unresponsive.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Impact",
        "Endpoint Denial of Service",
        "Application Exhaustion Flood"
      ],
      "parentId": "technique-endpoint-denial-of-service-1e0dedc0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-service-exhaustion-flood-46ed00dc",
      "code": "Service Exhaustion Flood",
      "value": "Service Exhaustion Flood",
      "name": "Service Exhaustion Flood",
      "definition": "Text about service exhaustion flood encompasses adversarial disruption activities that deplete limited server resources through high-volume, concurrent request generation, causing service unavailability for expected traffic and legitimate network operations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Impact",
        "Endpoint Denial of Service",
        "Service Exhaustion Flood"
      ],
      "parentId": "technique-endpoint-denial-of-service-1e0dedc0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-application-or-system-exploitation-0213a922",
      "code": "Application or System Exploitation",
      "value": "Application or System Exploitation",
      "name": "Application or System Exploitation",
      "definition": "Text about exploiting software vulnerabilities in targeted applications or operating systems to execute arbitrary code, escalate privileges, or manipulate intended functionality to advance unauthorized access within a compromised network environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Impact",
        "Endpoint Denial of Service",
        "Application or System Exploitation"
      ],
      "parentId": "technique-endpoint-denial-of-service-1e0dedc0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-os-exhaustion-flood-8833786d",
      "code": "OS Exhaustion Flood",
      "value": "OS Exhaustion Flood",
      "name": "OS Exhaustion Flood",
      "definition": "Text about OS Exhaustion Flood encompasses attacks that disrupt system availability by overwhelming operating system networking components, causing resource depletion that severely limits the host's ability to facilitate standard service communications.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Impact",
        "Endpoint Denial of Service",
        "OS Exhaustion Flood"
      ],
      "parentId": "technique-endpoint-denial-of-service-1e0dedc0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-system-location-discovery-08b08973",
      "code": "System Location Discovery",
      "value": "System Location Discovery",
      "name": "System Location Discovery",
      "definition": "Text about System Location Discovery identifies how adversaries query system-level locale settings, keyboard layouts, or network configurations to pinpoint the precise environmental and regional context of the compromised host.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "System Location Discovery"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 1,
      "leaf": false
    },
    {
      "id": "subtechnique-system-language-discovery-9aa23f32",
      "code": "System Language Discovery",
      "value": "System Language Discovery",
      "name": "System Language Discovery",
      "definition": "Text about the systematic collection of operating system language settings or regional locale data from a compromised host to help adversaries verify the target environment or optimize subsequent malicious operations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Discovery",
        "System Location Discovery",
        "System Language Discovery"
      ],
      "parentId": "technique-system-location-discovery-08b08973",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-bits-jobs-2c639bcf",
      "code": "BITS Jobs",
      "value": "BITS Jobs",
      "name": "BITS Jobs",
      "definition": "Text about the exploitation of Background Intelligent Transfer Service functionality to persistently execute arbitrary code or transfer files by manipulating job queues within the system infrastructure for malicious purposes.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "BITS Jobs"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-bits-jobs-e70dd281",
      "code": "BITS Jobs",
      "value": "BITS Jobs",
      "name": "BITS Jobs",
      "definition": "Text about the exploitation of Background Intelligent Transfer Service functionality to persistently execute arbitrary code or transfer files by manipulating job queues within the system infrastructure for malicious purposes.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Persistence",
        "BITS Jobs"
      ],
      "parentId": "tactic-persistence-4782469e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-impersonation-5b97d38a",
      "code": "Impersonation",
      "value": "Impersonation",
      "name": "Impersonation",
      "definition": "Text about adversaries mimicking known entities, roles, or communication patterns to mislead automated defenses and personnel, securing unauthorized advantages by projecting an aura of legitimacy within the targeted infrastructure.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Impersonation"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-data-encoding-eec67526",
      "code": "Data Encoding",
      "value": "Data Encoding",
      "name": "Data Encoding",
      "definition": "Text about data encoding involves the transformation of information into a non-plain format to impede analysis or detection by security tools as attackers maintain persistence or command and control operations.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Command and Control",
        "Data Encoding"
      ],
      "parentId": "tactic-command-and-control-6b4265ca",
      "synthetic": false,
      "childCount": 2,
      "leaf": false
    },
    {
      "id": "subtechnique-standard-encoding-d01e710b",
      "code": "Standard Encoding",
      "value": "Standard Encoding",
      "name": "Standard Encoding",
      "definition": "Text about Standard Encoding describes techniques where malicious actors encode data into commonplace formats, which successfully hides the presence of unauthorized commands within otherwise legitimate-looking stream of system data.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Command and Control",
        "Data Encoding",
        "Standard Encoding"
      ],
      "parentId": "technique-data-encoding-eec67526",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-non-standard-encoding-ad6edc29",
      "code": "Non-Standard Encoding",
      "value": "Non-Standard Encoding",
      "name": "Non-Standard Encoding",
      "definition": "Text about adversaries deploying distinct, non-canonical data transformation routines to hide malicious communications, requiring security analysts to manually decode traffic because automated systems cannot inherently parse the unique formatting scheme.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Command and Control",
        "Data Encoding",
        "Non-Standard Encoding"
      ],
      "parentId": "technique-data-encoding-eec67526",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-phishing-for-information-e4926b8a",
      "code": "Phishing for Information",
      "value": "Phishing for Information",
      "name": "Phishing for Information",
      "definition": "Text about adversaries directly querying targeted users or administrators to extract sensitive internal information, utilizing deceptive electronic correspondence to bypass defenses and gain knowledge crucial for advancing malicious cyber operations.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Reconnaissance",
        "Phishing for Information"
      ],
      "parentId": "tactic-reconnaissance-a9f8c2a8",
      "synthetic": false,
      "childCount": 4,
      "leaf": false
    },
    {
      "id": "subtechnique-spearphishing-voice-e46b8d5f",
      "code": "Spearphishing Voice",
      "value": "Spearphishing Voice",
      "name": "Spearphishing Voice",
      "definition": "Text about fraudulent voice communications initiated by threat actors targeting specific individuals to elicit sensitive information or manipulate the recipient into performing actions that subvert existing organizational cybersecurity safety measures.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Phishing for Information",
        "Spearphishing Voice"
      ],
      "parentId": "technique-phishing-for-information-e4926b8a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-spearphishing-service-39afac14",
      "code": "Spearphishing Service",
      "value": "Spearphishing Service",
      "name": "Spearphishing Service",
      "definition": "Text about the acquisition and deployment of specialized third-party services that streamline the creation and delivery of targeted, socially engineered email messages used to infiltrate specific victim enterprise networks.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Phishing for Information",
        "Spearphishing Service"
      ],
      "parentId": "technique-phishing-for-information-e4926b8a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-spearphishing-attachment-fc8b1fa7",
      "code": "Spearphishing Attachment",
      "value": "Spearphishing Attachment",
      "name": "Spearphishing Attachment",
      "definition": "Text about the delivery of harmful software components embedded within email attachments, specifically designed to deceive recipients into executing them, thereby facilitating unauthorized initial access to protected enterprise network systems.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Phishing for Information",
        "Spearphishing Attachment"
      ],
      "parentId": "technique-phishing-for-information-e4926b8a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-spearphishing-link-25575c46",
      "code": "Spearphishing Link",
      "value": "Spearphishing Link",
      "name": "Spearphishing Link",
      "definition": "Text about an intrusion vector involving targeted electronic messages containing malicious hyperlinks that redirect unsuspecting users to web-based platforms used for privilege escalation, credential theft, or malware distribution campaigns.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Reconnaissance",
        "Phishing for Information",
        "Spearphishing Link"
      ],
      "parentId": "technique-phishing-for-information-e4926b8a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-resource-hijacking-1331c23e",
      "code": "Resource Hijacking",
      "value": "Resource Hijacking",
      "name": "Resource Hijacking",
      "definition": "Text about unauthorized actors commandeering technical assets like processing power, memory, or network bandwidth within an organization’s environment to execute illicit operations, effectively hijacking infrastructure capacity for their own external computing requirements.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Impact",
        "Resource Hijacking"
      ],
      "parentId": "tactic-impact-62036a70",
      "synthetic": false,
      "childCount": 4,
      "leaf": false
    },
    {
      "id": "subtechnique-compute-hijacking-f8769e8a",
      "code": "Compute Hijacking",
      "value": "Compute Hijacking",
      "name": "Compute Hijacking",
      "definition": "Text about Compute Hijacking denotes the unauthorized commandeering of system resources, specifically processing power, to execute adversarial objectives, often involving the misappropriation of cloud or local server capacities for clandestine operations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Impact",
        "Resource Hijacking",
        "Compute Hijacking"
      ],
      "parentId": "technique-resource-hijacking-1331c23e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-bandwidth-hijacking-cfe9c74b",
      "code": "Bandwidth Hijacking",
      "value": "Bandwidth Hijacking",
      "name": "Bandwidth Hijacking",
      "definition": "Text about attackers exploiting network infrastructures to usurp available bandwidth for their own malicious communication channels, effectively covertly routing traffic through compromised hosts to obscure their operational infrastructure and intent.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Impact",
        "Resource Hijacking",
        "Bandwidth Hijacking"
      ],
      "parentId": "technique-resource-hijacking-1331c23e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-cloud-service-hijacking-5830bb35",
      "code": "Cloud Service Hijacking",
      "value": "Cloud Service Hijacking",
      "name": "Cloud Service Hijacking",
      "definition": "Text about attackers exploiting stolen credentials to seize control of cloud-based service accounts, thereby enabling unauthorized manipulation of the cloud environment's settings, data access, or resource provisioning capabilities through legitimate interfaces.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Impact",
        "Resource Hijacking",
        "Cloud Service Hijacking"
      ],
      "parentId": "technique-resource-hijacking-1331c23e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-sms-pumping-e52cf568",
      "code": "SMS Pumping",
      "value": "SMS Pumping",
      "name": "SMS Pumping",
      "definition": "Text about the unauthorized exploitation of messaging endpoints to drive artificial delivery volumes, generating significant financial impact by leveraging standard communication protocols to facilitate systemic fraud and revenue depletion.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Impact",
        "Resource Hijacking",
        "SMS Pumping"
      ],
      "parentId": "technique-resource-hijacking-1331c23e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-establish-accounts-f4270122",
      "code": "Establish Accounts",
      "value": "Establish Accounts",
      "name": "Establish Accounts",
      "definition": "Text about adversaries registering new accounts within enterprise systems, enabling them to establish, maintain, or elevate access levels while leveraging these newly created identities for unauthorized navigation and malicious activities.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Resource Development",
        "Establish Accounts"
      ],
      "parentId": "tactic-resource-development-ce56343a",
      "synthetic": false,
      "childCount": 3,
      "leaf": false
    },
    {
      "id": "subtechnique-cloud-accounts-9afd082e",
      "code": "Cloud Accounts",
      "value": "Cloud Accounts",
      "name": "Cloud Accounts",
      "definition": "Text about Cloud Accounts identifies the use of compromised or illicitly obtained credentials specific to cloud platform ecosystems, enabling attackers to perform malicious actions while masquerading as authorized system entities.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Establish Accounts",
        "Cloud Accounts"
      ],
      "parentId": "technique-establish-accounts-f4270122",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-email-accounts-62d9fa1d",
      "code": "Email Accounts",
      "value": "Email Accounts",
      "name": "Email Accounts",
      "definition": "Text about attackers exploiting or procuring email accounts to impersonate users, distribute malware, or illicitly access sensitive data while appearing as authenticated participants within the targeted organization's internal and external communications.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Establish Accounts",
        "Email Accounts"
      ],
      "parentId": "technique-establish-accounts-f4270122",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-social-media-accounts-26206b1c",
      "code": "Social Media Accounts",
      "value": "Social Media Accounts",
      "name": "Social Media Accounts",
      "definition": "Text about adversaries manipulating externally hosted user profiles to obtain sensitive intelligence, cultivate undue influence over targeted individuals, or distribute malicious communications while disguising operational intent within public digital platforms.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Establish Accounts",
        "Social Media Accounts"
      ],
      "parentId": "technique-establish-accounts-f4270122",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-obtain-capabilities-0eac3f32",
      "code": "Obtain Capabilities",
      "value": "Obtain Capabilities",
      "name": "Obtain Capabilities",
      "definition": "Text about adversaries acquiring the critical software, malicious tools, or infrastructure resources needed to facilitate unauthorized access, data exfiltration, or system manipulation during the execution of a cyber security incident.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Resource Development",
        "Obtain Capabilities"
      ],
      "parentId": "tactic-resource-development-ce56343a",
      "synthetic": false,
      "childCount": 7,
      "leaf": false
    },
    {
      "id": "subtechnique-vulnerabilities-a6c4e894",
      "code": "Vulnerabilities",
      "value": "Vulnerabilities",
      "name": "Vulnerabilities",
      "definition": "Text about exploiting unpatched weaknesses in software or hardware configurations which adversaries leverage to gain unauthorized access, execute malicious code, or elevate privileges within a targeted enterprise network environment.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Obtain Capabilities",
        "Vulnerabilities"
      ],
      "parentId": "technique-obtain-capabilities-0eac3f32",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-exploits-f1b90ca1",
      "code": "Exploits",
      "value": "Exploits",
      "name": "Exploits",
      "definition": "Text about exploitation describes operations where adversaries leverage software, hardware, or firmware bugs to gain unauthorized control, elevate privileges, or execute arbitrary code within a targeted environment's digital infrastructure.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Obtain Capabilities",
        "Exploits"
      ],
      "parentId": "technique-obtain-capabilities-0eac3f32",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-artificial-intelligence-a3fc5df6",
      "code": "Artificial Intelligence",
      "value": "Artificial Intelligence",
      "name": "Artificial Intelligence",
      "definition": "Text about malicious entities leveraging integrated computational intelligence frameworks to programmatically identify weaknesses, generate deceptive traffic, or modify attack vectors to achieve unauthorized objectives within complex, high-security technical environments.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Obtain Capabilities",
        "Artificial Intelligence"
      ],
      "parentId": "technique-obtain-capabilities-0eac3f32",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-digital-certificates-99f6b7e9",
      "code": "Digital Certificates",
      "value": "Digital Certificates",
      "name": "Digital Certificates",
      "definition": "Text about threat actors leveraging illicitly obtained, forged, or intercepted digital certificates to sign malicious payloads, ensuring they appear authentic and trusted by security software and host operating systems.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Obtain Capabilities",
        "Digital Certificates"
      ],
      "parentId": "technique-obtain-capabilities-0eac3f32",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-tool-43e84de7",
      "code": "Tool",
      "value": "Tool",
      "name": "Tool",
      "definition": "Text about Tool sub-techniques encompasses specific software or custom-developed utilities utilized by adversaries to facilitate malicious activities, automate operational tasks, or achieve strategic objectives throughout various stages of an intrusion.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Obtain Capabilities",
        "Tool"
      ],
      "parentId": "technique-obtain-capabilities-0eac3f32",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-code-signing-certificates-e397cc04",
      "code": "Code Signing Certificates",
      "value": "Code Signing Certificates",
      "name": "Code Signing Certificates",
      "definition": "Text about threat actors leveraging valid, stolen, or forged code signing certificates to digitally sign malicious code, enabling bypass of signature-based trust policies that govern the execution of software within networks.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Obtain Capabilities",
        "Code Signing Certificates"
      ],
      "parentId": "technique-obtain-capabilities-0eac3f32",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-malware-6f8d9b9b",
      "code": "Malware",
      "value": "Malware",
      "name": "Malware",
      "definition": "Text about malicious software artifacts engineered by attackers to execute specific operational commands, facilitating unauthorized access, system degradation, or information theft within targets identified during the broader phases of digital compromise.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Obtain Capabilities",
        "Malware"
      ],
      "parentId": "technique-obtain-capabilities-0eac3f32",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-system-services-1a17bfc5",
      "code": "System Services",
      "value": "System Services",
      "name": "System Services",
      "definition": "Text about attackers modifying service configurations or creating new service entries within the operating system to execute unauthorized code, thereby establishing persistence and ensuring malicious payloads run during system operations.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Execution",
        "System Services"
      ],
      "parentId": "tactic-execution-6d525b71",
      "synthetic": false,
      "childCount": 2,
      "leaf": false
    },
    {
      "id": "subtechnique-service-execution-43b968bb",
      "code": "Service Execution",
      "value": "Service Execution",
      "name": "Service Execution",
      "definition": "Text about utilizing specialized administrative service controls to force the execution of malicious payloads, where attackers register or manipulate service parameters to trigger unauthorized code during routine system background operations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Execution",
        "System Services",
        "Service Execution"
      ],
      "parentId": "technique-system-services-1a17bfc5",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-launchctl-a5fc707f",
      "code": "Launchctl",
      "value": "Launchctl",
      "name": "Launchctl",
      "definition": "Text about abusing the Apple macOS launchctl command-line tool to manipulate service agents and daemons, allowing adversaries to achieve persistent execution by defining new or modifying existing scheduled tasks and processes.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Execution",
        "System Services",
        "Launchctl"
      ],
      "parentId": "technique-system-services-1a17bfc5",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-acquire-access-8ccb99e7",
      "code": "Acquire Access",
      "value": "Acquire Access",
      "name": "Acquire Access",
      "definition": "Text about adversaries obtaining the necessary credentials, permissions, or system entry points required to interact with targeted infrastructure, thereby bypassing authentication mechanisms to establish an initial foothold within a network environment.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Resource Development",
        "Acquire Access"
      ],
      "parentId": "tactic-resource-development-ce56343a",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-data-from-information-repositories-d11d98f7",
      "code": "Data from Information Repositories",
      "value": "Data from Information Repositories",
      "name": "Data from Information Repositories",
      "definition": "Text about unauthorized actors exploiting internal document repositories or collaborative platforms to harvest sensitive institutional knowledge, proprietary research, project plans, and critical operational data stored within the target organization.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Collection",
        "Data from Information Repositories"
      ],
      "parentId": "tactic-collection-30c54a96",
      "synthetic": false,
      "childCount": 5,
      "leaf": false
    },
    {
      "id": "subtechnique-code-repositories-d9cb58a0",
      "code": "Code Repositories",
      "value": "Code Repositories",
      "name": "Code Repositories",
      "definition": "Text about the unauthorized access and exploitation of source code management platforms to facilitate the theft of intellectual property, discovery of operational secrets, and manipulation of software builds via code injection.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Collection",
        "Data from Information Repositories",
        "Code Repositories"
      ],
      "parentId": "technique-data-from-information-repositories-d11d98f7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-messaging-applications-6274feb0",
      "code": "Messaging Applications",
      "value": "Messaging Applications",
      "name": "Messaging Applications",
      "definition": "Text about adversaries leveraging capabilities within instant messaging applications to orchestrate command and control activities, deploy malicious scripts, or exfiltrate sensitive data streams via established, encrypted user communication tunnels.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Collection",
        "Data from Information Repositories",
        "Messaging Applications"
      ],
      "parentId": "technique-data-from-information-repositories-d11d98f7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-customer-relationship-management-software-7efb83bd",
      "code": "Customer Relationship Management Software",
      "value": "Customer Relationship Management Software",
      "name": "Customer Relationship Management Software",
      "definition": "Text about exploiting vulnerabilities or credentials specifically associated with enterprise-grade platforms designed for customer tracking, sales pipelines, and relationship management to weaponize, exfiltrate, or alter stored organizational data assets.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Collection",
        "Data from Information Repositories",
        "Customer Relationship Management Software"
      ],
      "parentId": "technique-data-from-information-repositories-d11d98f7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-sharepoint-152be8c6",
      "code": "Sharepoint",
      "value": "Sharepoint",
      "name": "Sharepoint",
      "definition": "Text about SharePoint refers to adversaries leveraging the collaborative features, document libraries, and access permissions within Microsoft SharePoint environments to facilitate unauthorized data access, persistence, lateral movement, or malicious file staging.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Collection",
        "Data from Information Repositories",
        "Sharepoint"
      ],
      "parentId": "technique-data-from-information-repositories-d11d98f7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-confluence-2276c030",
      "code": "Confluence",
      "value": "Confluence",
      "name": "Confluence",
      "definition": "Text about attackers leveraging specific weaknesses or misconfigurations within Atlassian Confluence enterprise software to bypass security controls, execute unauthorized scripts, or establish long-term clandestine access across the host server.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Collection",
        "Data from Information Repositories",
        "Confluence"
      ],
      "parentId": "technique-data-from-information-repositories-d11d98f7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-hardware-additions-d52beb17",
      "code": "Hardware Additions",
      "value": "Hardware Additions",
      "name": "Hardware Additions",
      "definition": "Text about attackers successfully gaining physical access to network conduits or internal system ports to install unauthorized electronic hardware components that enable unauthorized monitoring, data exfiltration, or secondary system control.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Initial Access",
        "Hardware Additions"
      ],
      "parentId": "tactic-initial-access-a0f45034",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-server-software-component-0dcfa055",
      "code": "Server Software Component",
      "value": "Server Software Component",
      "name": "Server Software Component",
      "definition": "Text about adversaries installing or modifying server-side software, including modules, plugins, or extensions, to intercept, manipulate, or intercept data flowing through institutional application services after gaining initial access to systems.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Persistence",
        "Server Software Component"
      ],
      "parentId": "tactic-persistence-4782469e",
      "synthetic": false,
      "childCount": 5,
      "leaf": false
    },
    {
      "id": "subtechnique-transport-agent-c1d48bf1",
      "code": "Transport Agent",
      "value": "Transport Agent",
      "name": "Transport Agent",
      "definition": "Text about adversaries embedding malicious transport agents into email server configurations to intercept communication traffic, allowing for the discrete exfiltration of sensitive information or the persistent alteration of legitimate data streams.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Server Software Component",
        "Transport Agent"
      ],
      "parentId": "technique-server-software-component-0dcfa055",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-iis-components-dea40b36",
      "code": "IIS Components",
      "value": "IIS Components",
      "name": "IIS Components",
      "definition": "Text about adversaries leveraging Internet Information Services module loading mechanisms to execute malicious code, intercept web requests, and establish persistent access by replacing or augmenting legitimate server extensions.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Server Software Component",
        "IIS Components"
      ],
      "parentId": "technique-server-software-component-0dcfa055",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-web-shell-32d6d2c6",
      "code": "Web Shell",
      "value": "Web Shell",
      "name": "Web Shell",
      "definition": "Text about malicious actors uploading or installing server-side scripts to a compromised web server, enabling remote command execution, persistent unauthorized access, and interaction with the underlying host operating system.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Server Software Component",
        "Web Shell"
      ],
      "parentId": "technique-server-software-component-0dcfa055",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-terminal-services-dll-dfae5393",
      "code": "Terminal Services DLL",
      "value": "Terminal Services DLL",
      "name": "Terminal Services DLL",
      "definition": "Text about an abuse vector involving the unauthorized replacement or modification of dynamic link libraries loaded by Terminal Services to gain persistent code execution within the context of the service process.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Server Software Component",
        "Terminal Services DLL"
      ],
      "parentId": "technique-server-software-component-0dcfa055",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-sql-stored-procedures-4354d301",
      "code": "SQL Stored Procedures",
      "value": "SQL Stored Procedures",
      "name": "SQL Stored Procedures",
      "definition": "Text about adversaries manipulating database stored procedures to execute arbitrary code or commands directly within the database environment, thereby achieving unauthorized persistence, escalation, or unauthorized access to the database infrastructure.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Server Software Component",
        "SQL Stored Procedures"
      ],
      "parentId": "technique-server-software-component-0dcfa055",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-data-destruction-8e3db81c",
      "code": "Data Destruction",
      "value": "Data Destruction",
      "name": "Data Destruction",
      "definition": "Text about the technical process of wiping, corrupting, or wiping out electronic records on targeted systems, executed by adversaries to force system downtime and degrade the victim organization’s mission critical capabilities.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Impact",
        "Data Destruction"
      ],
      "parentId": "tactic-impact-62036a70",
      "synthetic": false,
      "childCount": 1,
      "leaf": false
    },
    {
      "id": "subtechnique-lifecycle-triggered-deletion-238f0e2f",
      "code": "Lifecycle-Triggered Deletion",
      "value": "Lifecycle-Triggered Deletion",
      "name": "Lifecycle-Triggered Deletion",
      "definition": "Text about automated cleanup routines where attackers configure malicious payloads to erase incriminating files, logs, or evidence automatically upon the completion of a specific operational objective or lifecycle time duration.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Impact",
        "Data Destruction",
        "Lifecycle-Triggered Deletion"
      ],
      "parentId": "technique-data-destruction-8e3db81c",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-transfer-data-to-cloud-account-0a3157c4",
      "code": "Transfer Data to Cloud Account",
      "value": "Transfer Data to Cloud Account",
      "name": "Transfer Data to Cloud Account",
      "definition": "Text about adversaries bypassing security boundaries by uploading stolen sensitive data from internal network segments directly into a cloud-based account managed by the attacker to facilitate unauthorized access and removal.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Exfiltration",
        "Transfer Data to Cloud Account"
      ],
      "parentId": "tactic-exfiltration-fcb9fccc",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-drive-by-compromise-64213ae2",
      "code": "Drive-by Compromise",
      "value": "Drive-by Compromise",
      "name": "Drive-by Compromise",
      "definition": "Text about leveraging compromised websites as delivery mechanisms to execute exploits that target web browser vulnerabilities, ultimately resulting in unauthorized code execution on the visitor's machine during routine activity.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Initial Access",
        "Drive-by Compromise"
      ],
      "parentId": "tactic-initial-access-a0f45034",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-network-denial-of-service-b5b71c02",
      "code": "Network Denial of Service",
      "value": "Network Denial of Service",
      "name": "Network Denial of Service",
      "definition": "Text about cyber adversaries intentionally impeding network communications by overwhelming bandwidth or disrupting routing pathways, thereby preventing legitimate traffic flow to and from targeted systems within the compromised environment.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Impact",
        "Network Denial of Service"
      ],
      "parentId": "tactic-impact-62036a70",
      "synthetic": false,
      "childCount": 2,
      "leaf": false
    },
    {
      "id": "subtechnique-reflection-amplification-009c2467",
      "code": "Reflection Amplification",
      "value": "Reflection Amplification",
      "name": "Reflection Amplification",
      "definition": "Text about exploiting exposed networking services to generate amplified response traffic directed toward a target server, thereby depleting network bandwidth and service availability via involuntary intermediaries during distributed denial-of-service attacks.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Impact",
        "Network Denial of Service",
        "Reflection Amplification"
      ],
      "parentId": "technique-network-denial-of-service-b5b71c02",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-direct-network-flood-539cd191",
      "code": "Direct Network Flood",
      "value": "Direct Network Flood",
      "name": "Direct Network Flood",
      "definition": "Text about Direct Network Flood entails adversaries exhausting network bandwidth by overwhelming a targeted infrastructure with a high volume of traffic, aiming to render network services unreachable for legitimate users.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Impact",
        "Network Denial of Service",
        "Direct Network Flood"
      ],
      "parentId": "technique-network-denial-of-service-b5b71c02",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-cloud-administration-command-070e7c7c",
      "code": "Cloud Administration Command",
      "value": "Cloud Administration Command",
      "name": "Cloud Administration Command",
      "definition": "Text about unauthorized actors operating through cloud-native administrative interfaces to issue commands that alter infrastructure settings, thereby enabling extensive modification of the target environment's management and operational status.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Execution",
        "Cloud Administration Command"
      ],
      "parentId": "tactic-execution-6d525b71",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-template-injection-66b1ee78",
      "code": "Template Injection",
      "value": "Template Injection",
      "name": "Template Injection",
      "definition": "Text about Template Injection refers to the exploitation of server-side template engines by injecting malicious directives into data inputs, subsequently triggering the execution of unauthorized instructions during the document rendering process.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Template Injection"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-access-token-manipulation-75b97fad",
      "code": "Access Token Manipulation",
      "value": "Access Token Manipulation",
      "name": "Access Token Manipulation",
      "definition": "Text about adversaries injecting or modifying access tokens to impersonate another user or system entity, effectively subverting access controls by adopting the security identity of a process with higher privileges.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Access Token Manipulation"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 5,
      "leaf": false
    },
    {
      "id": "subtechnique-token-impersonation-theft-c78fc679",
      "code": "Token Impersonation/Theft",
      "value": "Token Impersonation/Theft",
      "name": "Token Impersonation/Theft",
      "definition": "Text about the process of commandeering valid session tokens to facilitate identity impersonation, allowing unauthorized actors to perform operations with the same permissions and scope as the legitimately authenticated user.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Access Token Manipulation",
        "Token Impersonation/Theft"
      ],
      "parentId": "technique-access-token-manipulation-75b97fad",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-parent-pid-spoofing-a3f9021f",
      "code": "Parent PID Spoofing",
      "value": "Parent PID Spoofing",
      "name": "Parent PID Spoofing",
      "definition": "Text about the manipulation of parent process identifiers by attackers to disguise the initiation of secondary processes, ensuring that malicious behavior appears linked to innocuous and trusted system utilities.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Access Token Manipulation",
        "Parent PID Spoofing"
      ],
      "parentId": "technique-access-token-manipulation-75b97fad",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-sid-history-injection-fcc14d6c",
      "code": "SID-History Injection",
      "value": "SID-History Injection",
      "name": "SID-History Injection",
      "definition": "Text about the malicious modification of account SID-History attributes to enable privilege escalation by inheriting the access rights of higher-privileged entities, thereby subverting domain access controls during an intrusion operation.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Access Token Manipulation",
        "SID-History Injection"
      ],
      "parentId": "technique-access-token-manipulation-75b97fad",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-create-process-with-token-32c7960c",
      "code": "Create Process with Token",
      "value": "Create Process with Token",
      "name": "Create Process with Token",
      "definition": "Text about the manipulation of process creation mechanisms to launch programs using stolen security tokens, effectively impersonating targeted users to bypass standard authentication controls and maintain operational persistent access.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Access Token Manipulation",
        "Create Process with Token"
      ],
      "parentId": "technique-access-token-manipulation-75b97fad",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-make-and-impersonate-token-ca277e2f",
      "code": "Make and Impersonate Token",
      "value": "Make and Impersonate Token",
      "name": "Make and Impersonate Token",
      "definition": "Text about hijacking the security context of a specific account through token duplication, enabling unauthorized actors to interact with protected system resources by assuming the verified identity of that user.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Access Token Manipulation",
        "Make and Impersonate Token"
      ],
      "parentId": "technique-access-token-manipulation-75b97fad",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-access-token-manipulation-cee4caaf",
      "code": "Access Token Manipulation",
      "value": "Access Token Manipulation",
      "name": "Access Token Manipulation",
      "definition": "Text about adversaries injecting or modifying access tokens to impersonate another user or system entity, effectively subverting access controls by adopting the security identity of a process with higher privileges.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Privilege Escalation",
        "Access Token Manipulation"
      ],
      "parentId": "tactic-privilege-escalation-dc3564ae",
      "synthetic": false,
      "childCount": 5,
      "leaf": false
    },
    {
      "id": "subtechnique-token-impersonation-theft-267c3ead",
      "code": "Token Impersonation/Theft",
      "value": "Token Impersonation/Theft",
      "name": "Token Impersonation/Theft",
      "definition": "Text about the process of commandeering valid session tokens to facilitate identity impersonation, allowing unauthorized actors to perform operations with the same permissions and scope as the legitimately authenticated user.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Access Token Manipulation",
        "Token Impersonation/Theft"
      ],
      "parentId": "technique-access-token-manipulation-cee4caaf",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-parent-pid-spoofing-dc23c338",
      "code": "Parent PID Spoofing",
      "value": "Parent PID Spoofing",
      "name": "Parent PID Spoofing",
      "definition": "Text about the manipulation of parent process identifiers by attackers to disguise the initiation of secondary processes, ensuring that malicious behavior appears linked to innocuous and trusted system utilities.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Access Token Manipulation",
        "Parent PID Spoofing"
      ],
      "parentId": "technique-access-token-manipulation-cee4caaf",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-sid-history-injection-a6c75f2d",
      "code": "SID-History Injection",
      "value": "SID-History Injection",
      "name": "SID-History Injection",
      "definition": "Text about the malicious modification of account SID-History attributes to enable privilege escalation by inheriting the access rights of higher-privileged entities, thereby subverting domain access controls during an intrusion operation.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Access Token Manipulation",
        "SID-History Injection"
      ],
      "parentId": "technique-access-token-manipulation-cee4caaf",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-create-process-with-token-11eff85b",
      "code": "Create Process with Token",
      "value": "Create Process with Token",
      "name": "Create Process with Token",
      "definition": "Text about the manipulation of process creation mechanisms to launch programs using stolen security tokens, effectively impersonating targeted users to bypass standard authentication controls and maintain operational persistent access.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Access Token Manipulation",
        "Create Process with Token"
      ],
      "parentId": "technique-access-token-manipulation-cee4caaf",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-make-and-impersonate-token-f4beb076",
      "code": "Make and Impersonate Token",
      "value": "Make and Impersonate Token",
      "name": "Make and Impersonate Token",
      "definition": "Text about hijacking the security context of a specific account through token duplication, enabling unauthorized actors to interact with protected system resources by assuming the verified identity of that user.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Access Token Manipulation",
        "Make and Impersonate Token"
      ],
      "parentId": "technique-access-token-manipulation-cee4caaf",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-multi-factor-authentication-interception-147d87aa",
      "code": "Multi-Factor Authentication Interception",
      "value": "Multi-Factor Authentication Interception",
      "name": "Multi-Factor Authentication Interception",
      "definition": "Text about adversaries obstructing or diverting multi-factor authentication communication streams to harvest temporary validation secrets, thereby enabling unauthorized masquerading as authenticated users within compromised target networks.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Credential Access",
        "Multi-Factor Authentication Interception"
      ],
      "parentId": "tactic-credential-access-9c65f4e0",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-create-account-9f77e746",
      "code": "Create Account",
      "value": "Create Account",
      "name": "Create Account",
      "definition": "Text about adversaries establishing unauthorized access by generating new user or administrative accounts within a target environment, facilitating persistent or elevated presence across compromised systems and network resources thereafter.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Persistence",
        "Create Account"
      ],
      "parentId": "tactic-persistence-4782469e",
      "synthetic": false,
      "childCount": 3,
      "leaf": false
    },
    {
      "id": "subtechnique-cloud-account-788540dd",
      "code": "Cloud Account",
      "value": "Cloud Account",
      "name": "Cloud Account",
      "definition": "Text about unauthorized actors acquiring control over cloud-based identity entities to establish persistence or facilitate continued malicious operations within a victim entity’s hosted computing or storage resource environments.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Create Account",
        "Cloud Account"
      ],
      "parentId": "technique-create-account-9f77e746",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-local-account-daf4bb91",
      "code": "Local Account",
      "value": "Local Account",
      "name": "Local Account",
      "definition": "Text about unauthorized actors configuring local system accounts to bypass domain-level restrictions, ensuring persistent entry or escalated authority by manipulating the host's native user repository and authentication configurations.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Create Account",
        "Local Account"
      ],
      "parentId": "technique-create-account-9f77e746",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-domain-account-c546a592",
      "code": "Domain Account",
      "value": "Domain Account",
      "name": "Domain Account",
      "definition": "Text about adversaries enumerating or gaining information on compromised domain accounts to map directory services, identify privileged users, or ascertain organizational structure before proceeding with further malicious network activities.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Create Account",
        "Domain Account"
      ],
      "parentId": "technique-create-account-9f77e746",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-cloud-service-discovery-3f4c589f",
      "code": "Cloud Service Discovery",
      "value": "Cloud Service Discovery",
      "name": "Cloud Service Discovery",
      "definition": "Text about adversaries systematically probing cloud provider interfaces to identify active service deployments, mapping the extent of organizational resources available for exploitation during the initial phases of network compromise.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "Cloud Service Discovery"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-remote-system-discovery-1f9c706c",
      "code": "Remote System Discovery",
      "value": "Remote System Discovery",
      "name": "Remote System Discovery",
      "definition": "Text about adversaries actively identifying networked computers and services reachable within a compromised environment to build a map of internal resources, potential lateral movement targets, and accessible infrastructure for subsequent operations.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "Remote System Discovery"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-network-service-discovery-e54c331a",
      "code": "Network Service Discovery",
      "value": "Network Service Discovery",
      "name": "Network Service Discovery",
      "definition": "Text about an adversary activity focused on scanning IP addresses and ports to inventory available services, determine application versions, and identify network topography to enable effective post-compromise navigation and exploitation.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "Network Service Discovery"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-software-discovery-294fb901",
      "code": "Software Discovery",
      "value": "Software Discovery",
      "name": "Software Discovery",
      "definition": "Text about adversaries gathering operational intelligence by querying installed applications on a compromised system to identify security tools, development environments, or configurations facilitating further exploitation and progression within the network.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "Software Discovery"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 1,
      "leaf": false
    },
    {
      "id": "subtechnique-security-software-discovery-c167ca80",
      "code": "Security Software Discovery",
      "value": "Security Software Discovery",
      "name": "Security Software Discovery",
      "definition": "Text about the identification of existing security software and defensive configurations across a targeted system, allowing attackers to gauge defensive coverage and modify tactical procedures to maintain persistence and stealth.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Discovery",
        "Software Discovery",
        "Security Software Discovery"
      ],
      "parentId": "technique-software-discovery-294fb901",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-cloud-service-dashboard-8d64fd58",
      "code": "Cloud Service Dashboard",
      "value": "Cloud Service Dashboard",
      "name": "Cloud Service Dashboard",
      "definition": "Text about the exploitation of cloud service dashboards, involving the unauthorized manipulation of hosted infrastructure, identification of sensitive resources, and reconfiguration of security postures via official cloud provider management interfaces.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "Cloud Service Dashboard"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-debugger-evasion-2c4f5aee",
      "code": "Debugger Evasion",
      "value": "Debugger Evasion",
      "name": "Debugger Evasion",
      "definition": "Text about debugger evasion focuses on the adversarial practice of embedding code that detects the active hook or attachment of analysis tools, preserving malware integrity by circumventing attempts at step-by-step execution analysis.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Debugger Evasion"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-debugger-evasion-ce401e35",
      "code": "Debugger Evasion",
      "value": "Debugger Evasion",
      "name": "Debugger Evasion",
      "definition": "Text about debugger evasion focuses on the adversarial practice of embedding code that detects the active hook or attachment of analysis tools, preserving malware integrity by circumventing attempts at step-by-step execution analysis.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "Debugger Evasion"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-exfiltration-over-physical-medium-dc304148",
      "code": "Exfiltration Over Physical Medium",
      "value": "Exfiltration Over Physical Medium",
      "name": "Exfiltration Over Physical Medium",
      "definition": "Text about the clandestine transfer of sensitive information onto physical storage devices connected to compromised systems, enabling data removal by bypassing traditional digital surveillance mechanisms through manual hardware transport.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Exfiltration",
        "Exfiltration Over Physical Medium"
      ],
      "parentId": "tactic-exfiltration-fcb9fccc",
      "synthetic": false,
      "childCount": 1,
      "leaf": false
    },
    {
      "id": "subtechnique-exfiltration-over-usb-ec7aa357",
      "code": "Exfiltration over USB",
      "value": "Exfiltration over USB",
      "name": "Exfiltration over USB",
      "definition": "Text about the unauthorized egress of sensitive host data using physically connected removable mass storage devices via universal serial bus ports to bypass standard network-level monitoring and filtering defensive controls.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Exfiltration",
        "Exfiltration Over Physical Medium",
        "Exfiltration over USB"
      ],
      "parentId": "technique-exfiltration-over-physical-medium-dc304148",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-ingress-tool-transfer-e788c3a5",
      "code": "Ingress Tool Transfer",
      "value": "Ingress Tool Transfer",
      "name": "Ingress Tool Transfer",
      "definition": "Text about the deliberate movement of specialized software assets from external attacker-controlled infrastructure into a targeted network environment to provide capabilities necessary for executing advanced post-compromise malicious operations.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Command and Control",
        "Ingress Tool Transfer"
      ],
      "parentId": "tactic-command-and-control-6b4265ca",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-serverless-execution-a4e48b75",
      "code": "Serverless Execution",
      "value": "Serverless Execution",
      "name": "Serverless Execution",
      "definition": "Text about operations where adversaries utilize serverless cloud functions to execute arbitrary commands, bypassing standard infrastructure management and traditional perimeter controls to maintain execution within ephemeral, managed cloud service providers.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Execution",
        "Serverless Execution"
      ],
      "parentId": "tactic-execution-6d525b71",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-power-settings-434a7ef4",
      "code": "Power Settings",
      "value": "Power Settings",
      "name": "Power Settings",
      "definition": "Text about Power Settings describes the adversarial manipulation of system power schemas and global energy configurations to bypass sleep timers, ensuring remote access remains viable during extended idle periods.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Persistence",
        "Power Settings"
      ],
      "parentId": "tactic-persistence-4782469e",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-hide-infrastructure-5724cf67",
      "code": "Hide Infrastructure",
      "value": "Hide Infrastructure",
      "name": "Hide Infrastructure",
      "definition": "Text about leveraging methods to disguise the origin, purpose, and ownership of command and control servers, ensuring that these backend assets remain hidden from forensic analysis and network security monitoring.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Command and Control",
        "Hide Infrastructure"
      ],
      "parentId": "tactic-command-and-control-6b4265ca",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-domain-or-tenant-policy-modification-35bc7061",
      "code": "Domain or Tenant Policy Modification",
      "value": "Domain or Tenant Policy Modification",
      "name": "Domain or Tenant Policy Modification",
      "definition": "Text about adversaries altering domain or tenant-wide policy configurations to weaken security controls, manipulate user or system access permissions, or bypass organizational governance during active cyber intrusion operations.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Domain or Tenant Policy Modification"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 2,
      "leaf": false
    },
    {
      "id": "subtechnique-trust-modification-28998903",
      "code": "Trust Modification",
      "value": "Trust Modification",
      "name": "Trust Modification",
      "definition": "Text about Trust Modification involves adversaries subverting system security safeguards by manipulating established trust models, such as code signing or certificate validation processes, to execute unauthorized, potentially malicious, software components.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Domain or Tenant Policy Modification",
        "Trust Modification"
      ],
      "parentId": "technique-domain-or-tenant-policy-modification-35bc7061",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-group-policy-modification-c7decf31",
      "code": "Group Policy Modification",
      "value": "Group Policy Modification",
      "name": "Group Policy Modification",
      "definition": "Text about the unauthorized manipulation of Group Policy Objects to enforce system-wide changes, facilitating persistent access, credential theft, or the execution of unauthorized scripts on domain-joined systems within enterprise networks.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Domain or Tenant Policy Modification",
        "Group Policy Modification"
      ],
      "parentId": "technique-domain-or-tenant-policy-modification-35bc7061",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-domain-or-tenant-policy-modification-585164d7",
      "code": "Domain or Tenant Policy Modification",
      "value": "Domain or Tenant Policy Modification",
      "name": "Domain or Tenant Policy Modification",
      "definition": "Text about adversaries altering domain or tenant-wide policy configurations to weaken security controls, manipulate user or system access permissions, or bypass organizational governance during active cyber intrusion operations.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Privilege Escalation",
        "Domain or Tenant Policy Modification"
      ],
      "parentId": "tactic-privilege-escalation-dc3564ae",
      "synthetic": false,
      "childCount": 2,
      "leaf": false
    },
    {
      "id": "subtechnique-trust-modification-7e766c78",
      "code": "Trust Modification",
      "value": "Trust Modification",
      "name": "Trust Modification",
      "definition": "Text about Trust Modification involves adversaries subverting system security safeguards by manipulating established trust models, such as code signing or certificate validation processes, to execute unauthorized, potentially malicious, software components.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Domain or Tenant Policy Modification",
        "Trust Modification"
      ],
      "parentId": "technique-domain-or-tenant-policy-modification-585164d7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-group-policy-modification-a365c397",
      "code": "Group Policy Modification",
      "value": "Group Policy Modification",
      "name": "Group Policy Modification",
      "definition": "Text about the unauthorized manipulation of Group Policy Objects to enforce system-wide changes, facilitating persistent access, credential theft, or the execution of unauthorized scripts on domain-joined systems within enterprise networks.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Privilege Escalation",
        "Domain or Tenant Policy Modification",
        "Group Policy Modification"
      ],
      "parentId": "technique-domain-or-tenant-policy-modification-585164d7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-xsl-script-processing-604f2c66",
      "code": "XSL Script Processing",
      "value": "XSL Script Processing",
      "name": "XSL Script Processing",
      "definition": "Text about attackers utilizing extensible stylesheet language transformation processing capabilities to execute malicious code, leveraging built-in features that allow scripting logic within transformations to facilitate undetected payload execution.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "XSL Script Processing"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-develop-capabilities-d6c711e3",
      "code": "Develop Capabilities",
      "value": "Develop Capabilities",
      "name": "Develop Capabilities",
      "definition": "Text about adversaries performing the technical creation of malicious scripts, customized network implants, and adaptive exploit frameworks necessary to conduct sophisticated cyber intrusion activities across hardened target organizational digital infrastructures.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Resource Development",
        "Develop Capabilities"
      ],
      "parentId": "tactic-resource-development-ce56343a",
      "synthetic": false,
      "childCount": 4,
      "leaf": false
    },
    {
      "id": "subtechnique-code-signing-certificates-a160076b",
      "code": "Code Signing Certificates",
      "value": "Code Signing Certificates",
      "name": "Code Signing Certificates",
      "definition": "Text about threat actors leveraging valid, stolen, or forged code signing certificates to digitally sign malicious code, enabling bypass of signature-based trust policies that govern the execution of software within networks.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Develop Capabilities",
        "Code Signing Certificates"
      ],
      "parentId": "technique-develop-capabilities-d6c711e3",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-digital-certificates-e89af41c",
      "code": "Digital Certificates",
      "value": "Digital Certificates",
      "name": "Digital Certificates",
      "definition": "Text about threat actors leveraging illicitly obtained, forged, or intercepted digital certificates to sign malicious payloads, ensuring they appear authentic and trusted by security software and host operating systems.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Develop Capabilities",
        "Digital Certificates"
      ],
      "parentId": "technique-develop-capabilities-d6c711e3",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-exploits-e4705241",
      "code": "Exploits",
      "value": "Exploits",
      "name": "Exploits",
      "definition": "Text about exploitation describes operations where adversaries leverage software, hardware, or firmware bugs to gain unauthorized control, elevate privileges, or execute arbitrary code within a targeted environment's digital infrastructure.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Develop Capabilities",
        "Exploits"
      ],
      "parentId": "technique-develop-capabilities-d6c711e3",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-malware-d2c8e50b",
      "code": "Malware",
      "value": "Malware",
      "name": "Malware",
      "definition": "Text about malicious software artifacts engineered by attackers to execute specific operational commands, facilitating unauthorized access, system degradation, or information theft within targets identified during the broader phases of digital compromise.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Resource Development",
        "Develop Capabilities",
        "Malware"
      ],
      "parentId": "technique-develop-capabilities-d6c711e3",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-fallback-channels-3886ad61",
      "code": "Fallback Channels",
      "value": "Fallback Channels",
      "name": "Fallback Channels",
      "definition": "Text about adversaries maintaining stealthy, low-profile secondary communication streams, which remain dormant until primary operational channels are detected or disabled, enabling immediate restoration of control over the target network infrastructure.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Command and Control",
        "Fallback Channels"
      ],
      "parentId": "tactic-command-and-control-6b4265ca",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-system-time-discovery-636625d9",
      "code": "System Time Discovery",
      "value": "System Time Discovery",
      "name": "System Time Discovery",
      "definition": "Text about System Time Discovery characterizes an adversary retrieving the clock time of a compromised system to synchronize automated tasks, identify time-zone differences between hosts, or circumvent time-based network security policy constraints.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Discovery",
        "System Time Discovery"
      ],
      "parentId": "tactic-discovery-3b3290c7",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-modify-authentication-process-8a522cc2",
      "code": "Modify Authentication Process",
      "value": "Modify Authentication Process",
      "name": "Modify Authentication Process",
      "definition": "Text about adversaries modifying the functional code or configuration files of authentication modules to circumvent standard security checks, allowing unauthorized identity verification through tailored, attacker-controlled authentication pathways or flows.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Credential Access",
        "Modify Authentication Process"
      ],
      "parentId": "tactic-credential-access-9c65f4e0",
      "synthetic": false,
      "childCount": 9,
      "leaf": false
    },
    {
      "id": "subtechnique-network-device-authentication-2dc1879d",
      "code": "Network Device Authentication",
      "value": "Network Device Authentication",
      "name": "Network Device Authentication",
      "definition": "Text about adversaries exploiting flaws in the implementation of secure identity verification mechanisms on networking hardware to bypass authentication controls and illegitimately obtain administrative access to critical infrastructure components.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Modify Authentication Process",
        "Network Device Authentication"
      ],
      "parentId": "technique-modify-authentication-process-8a522cc2",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-domain-controller-authentication-2422e648",
      "code": "Domain Controller Authentication",
      "value": "Domain Controller Authentication",
      "name": "Domain Controller Authentication",
      "definition": "Text about illicit activities directed at the authentication functionality of domain controllers, specifically involving the abuse of identity verification protocols to bypass security checks or compromise user account legitimacy effectively.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Modify Authentication Process",
        "Domain Controller Authentication"
      ],
      "parentId": "technique-modify-authentication-process-8a522cc2",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-conditional-access-policies-20c90326",
      "code": "Conditional Access Policies",
      "value": "Conditional Access Policies",
      "name": "Conditional Access Policies",
      "definition": "Text about Conditional Access Policies involves adversaries altering identity provider configurations to circumvent established security controls, thereby granting unauthorized users or compromised accounts access to sensitive enterprise environment resources and data.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Modify Authentication Process",
        "Conditional Access Policies"
      ],
      "parentId": "technique-modify-authentication-process-8a522cc2",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-network-provider-dll-8c507f92",
      "code": "Network Provider DLL",
      "value": "Network Provider DLL",
      "name": "Network Provider DLL",
      "definition": "Text about malicious actors manipulating the Windows Network Provider order registry key to load unauthorized dynamic link libraries whenever the system initializes, thereby achieving persistence through the legitimate network logon interface.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Modify Authentication Process",
        "Network Provider DLL"
      ],
      "parentId": "technique-modify-authentication-process-8a522cc2",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-password-filter-dll-13db8b61",
      "code": "Password Filter DLL",
      "value": "Password Filter DLL",
      "name": "Password Filter DLL",
      "definition": "Text about the malicious placement of custom dynamic link libraries within the local security authority subsystem to intercept and exfiltrate plaintext credentials during standard user authentication and password change events on Windows.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Modify Authentication Process",
        "Password Filter DLL"
      ],
      "parentId": "technique-modify-authentication-process-8a522cc2",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-multi-factor-authentication-0cfd8002",
      "code": "Multi-Factor Authentication",
      "value": "Multi-Factor Authentication",
      "name": "Multi-Factor Authentication",
      "definition": "Text about techniques involving the unauthorized modification of authentication service parameters to bypass multi-factor authentication, effectively reducing security constraints and enabling illicit access to accounts normally protected by tiered verification methods.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Modify Authentication Process",
        "Multi-Factor Authentication"
      ],
      "parentId": "technique-modify-authentication-process-8a522cc2",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-hybrid-identity-7b948aac",
      "code": "Hybrid Identity",
      "value": "Hybrid Identity",
      "name": "Hybrid Identity",
      "definition": "Text about Hybrid Identity identifies the exploitation of mechanisms that replicate local directory objects to cloud environments, allowing attackers to maintain compromised access through persistent synchronization of credential management infrastructure.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Modify Authentication Process",
        "Hybrid Identity"
      ],
      "parentId": "technique-modify-authentication-process-8a522cc2",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-reversible-encryption-7538f686",
      "code": "Reversible Encryption",
      "value": "Reversible Encryption",
      "name": "Reversible Encryption",
      "definition": "Text about Reversible Encryption pertains to adversaries utilizing reversible cryptographic routines to protect unauthorized data exfiltration channels or obfuscate command-and-control payloads while maintaining the ability to decipher original content later.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Modify Authentication Process",
        "Reversible Encryption"
      ],
      "parentId": "technique-modify-authentication-process-8a522cc2",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-pluggable-authentication-modules-88a2309f",
      "code": "Pluggable Authentication Modules",
      "value": "Pluggable Authentication Modules",
      "name": "Pluggable Authentication Modules",
      "definition": "Text about adversaries altering the Pluggable Authentication Modules configurations on Linux systems to facilitate persistent unauthorized access or credential theft by modifying the standard behavior of local authentication service stacks.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Credential Access",
        "Modify Authentication Process",
        "Pluggable Authentication Modules"
      ],
      "parentId": "technique-modify-authentication-process-8a522cc2",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-modify-authentication-process-c874c873",
      "code": "Modify Authentication Process",
      "value": "Modify Authentication Process",
      "name": "Modify Authentication Process",
      "definition": "Text about adversaries modifying the functional code or configuration files of authentication modules to circumvent standard security checks, allowing unauthorized identity verification through tailored, attacker-controlled authentication pathways or flows.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Modify Authentication Process"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 9,
      "leaf": false
    },
    {
      "id": "subtechnique-network-device-authentication-fc4c5421",
      "code": "Network Device Authentication",
      "value": "Network Device Authentication",
      "name": "Network Device Authentication",
      "definition": "Text about adversaries exploiting flaws in the implementation of secure identity verification mechanisms on networking hardware to bypass authentication controls and illegitimately obtain administrative access to critical infrastructure components.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Modify Authentication Process",
        "Network Device Authentication"
      ],
      "parentId": "technique-modify-authentication-process-c874c873",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-domain-controller-authentication-d25fa69b",
      "code": "Domain Controller Authentication",
      "value": "Domain Controller Authentication",
      "name": "Domain Controller Authentication",
      "definition": "Text about illicit activities directed at the authentication functionality of domain controllers, specifically involving the abuse of identity verification protocols to bypass security checks or compromise user account legitimacy effectively.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Modify Authentication Process",
        "Domain Controller Authentication"
      ],
      "parentId": "technique-modify-authentication-process-c874c873",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-conditional-access-policies-69b8928c",
      "code": "Conditional Access Policies",
      "value": "Conditional Access Policies",
      "name": "Conditional Access Policies",
      "definition": "Text about Conditional Access Policies involves adversaries altering identity provider configurations to circumvent established security controls, thereby granting unauthorized users or compromised accounts access to sensitive enterprise environment resources and data.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Modify Authentication Process",
        "Conditional Access Policies"
      ],
      "parentId": "technique-modify-authentication-process-c874c873",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-network-provider-dll-7f1897b5",
      "code": "Network Provider DLL",
      "value": "Network Provider DLL",
      "name": "Network Provider DLL",
      "definition": "Text about malicious actors manipulating the Windows Network Provider order registry key to load unauthorized dynamic link libraries whenever the system initializes, thereby achieving persistence through the legitimate network logon interface.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Modify Authentication Process",
        "Network Provider DLL"
      ],
      "parentId": "technique-modify-authentication-process-c874c873",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-password-filter-dll-e0f0b6c3",
      "code": "Password Filter DLL",
      "value": "Password Filter DLL",
      "name": "Password Filter DLL",
      "definition": "Text about the malicious placement of custom dynamic link libraries within the local security authority subsystem to intercept and exfiltrate plaintext credentials during standard user authentication and password change events on Windows.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Modify Authentication Process",
        "Password Filter DLL"
      ],
      "parentId": "technique-modify-authentication-process-c874c873",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-multi-factor-authentication-4d8d0b33",
      "code": "Multi-Factor Authentication",
      "value": "Multi-Factor Authentication",
      "name": "Multi-Factor Authentication",
      "definition": "Text about techniques involving the unauthorized modification of authentication service parameters to bypass multi-factor authentication, effectively reducing security constraints and enabling illicit access to accounts normally protected by tiered verification methods.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Modify Authentication Process",
        "Multi-Factor Authentication"
      ],
      "parentId": "technique-modify-authentication-process-c874c873",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-hybrid-identity-e7080cc4",
      "code": "Hybrid Identity",
      "value": "Hybrid Identity",
      "name": "Hybrid Identity",
      "definition": "Text about Hybrid Identity identifies the exploitation of mechanisms that replicate local directory objects to cloud environments, allowing attackers to maintain compromised access through persistent synchronization of credential management infrastructure.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Modify Authentication Process",
        "Hybrid Identity"
      ],
      "parentId": "technique-modify-authentication-process-c874c873",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-reversible-encryption-1491511d",
      "code": "Reversible Encryption",
      "value": "Reversible Encryption",
      "name": "Reversible Encryption",
      "definition": "Text about Reversible Encryption pertains to adversaries utilizing reversible cryptographic routines to protect unauthorized data exfiltration channels or obfuscate command-and-control payloads while maintaining the ability to decipher original content later.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Modify Authentication Process",
        "Reversible Encryption"
      ],
      "parentId": "technique-modify-authentication-process-c874c873",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-pluggable-authentication-modules-5c13d74a",
      "code": "Pluggable Authentication Modules",
      "value": "Pluggable Authentication Modules",
      "name": "Pluggable Authentication Modules",
      "definition": "Text about adversaries altering the Pluggable Authentication Modules configurations on Linux systems to facilitate persistent unauthorized access or credential theft by modifying the standard behavior of local authentication service stacks.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Modify Authentication Process",
        "Pluggable Authentication Modules"
      ],
      "parentId": "technique-modify-authentication-process-c874c873",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-modify-authentication-process-b2865f0f",
      "code": "Modify Authentication Process",
      "value": "Modify Authentication Process",
      "name": "Modify Authentication Process",
      "definition": "Text about adversaries modifying the functional code or configuration files of authentication modules to circumvent standard security checks, allowing unauthorized identity verification through tailored, attacker-controlled authentication pathways or flows.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Persistence",
        "Modify Authentication Process"
      ],
      "parentId": "tactic-persistence-4782469e",
      "synthetic": false,
      "childCount": 9,
      "leaf": false
    },
    {
      "id": "subtechnique-network-device-authentication-2fc0fb9b",
      "code": "Network Device Authentication",
      "value": "Network Device Authentication",
      "name": "Network Device Authentication",
      "definition": "Text about adversaries exploiting flaws in the implementation of secure identity verification mechanisms on networking hardware to bypass authentication controls and illegitimately obtain administrative access to critical infrastructure components.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Modify Authentication Process",
        "Network Device Authentication"
      ],
      "parentId": "technique-modify-authentication-process-b2865f0f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-domain-controller-authentication-9a0a210c",
      "code": "Domain Controller Authentication",
      "value": "Domain Controller Authentication",
      "name": "Domain Controller Authentication",
      "definition": "Text about illicit activities directed at the authentication functionality of domain controllers, specifically involving the abuse of identity verification protocols to bypass security checks or compromise user account legitimacy effectively.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Modify Authentication Process",
        "Domain Controller Authentication"
      ],
      "parentId": "technique-modify-authentication-process-b2865f0f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-conditional-access-policies-65069418",
      "code": "Conditional Access Policies",
      "value": "Conditional Access Policies",
      "name": "Conditional Access Policies",
      "definition": "Text about Conditional Access Policies involves adversaries altering identity provider configurations to circumvent established security controls, thereby granting unauthorized users or compromised accounts access to sensitive enterprise environment resources and data.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Modify Authentication Process",
        "Conditional Access Policies"
      ],
      "parentId": "technique-modify-authentication-process-b2865f0f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-network-provider-dll-48163a08",
      "code": "Network Provider DLL",
      "value": "Network Provider DLL",
      "name": "Network Provider DLL",
      "definition": "Text about malicious actors manipulating the Windows Network Provider order registry key to load unauthorized dynamic link libraries whenever the system initializes, thereby achieving persistence through the legitimate network logon interface.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Modify Authentication Process",
        "Network Provider DLL"
      ],
      "parentId": "technique-modify-authentication-process-b2865f0f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-password-filter-dll-b1ac5fb2",
      "code": "Password Filter DLL",
      "value": "Password Filter DLL",
      "name": "Password Filter DLL",
      "definition": "Text about the malicious placement of custom dynamic link libraries within the local security authority subsystem to intercept and exfiltrate plaintext credentials during standard user authentication and password change events on Windows.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Modify Authentication Process",
        "Password Filter DLL"
      ],
      "parentId": "technique-modify-authentication-process-b2865f0f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-multi-factor-authentication-15bc9610",
      "code": "Multi-Factor Authentication",
      "value": "Multi-Factor Authentication",
      "name": "Multi-Factor Authentication",
      "definition": "Text about techniques involving the unauthorized modification of authentication service parameters to bypass multi-factor authentication, effectively reducing security constraints and enabling illicit access to accounts normally protected by tiered verification methods.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Modify Authentication Process",
        "Multi-Factor Authentication"
      ],
      "parentId": "technique-modify-authentication-process-b2865f0f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-hybrid-identity-f053b685",
      "code": "Hybrid Identity",
      "value": "Hybrid Identity",
      "name": "Hybrid Identity",
      "definition": "Text about Hybrid Identity identifies the exploitation of mechanisms that replicate local directory objects to cloud environments, allowing attackers to maintain compromised access through persistent synchronization of credential management infrastructure.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Modify Authentication Process",
        "Hybrid Identity"
      ],
      "parentId": "technique-modify-authentication-process-b2865f0f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-reversible-encryption-8dc9fd09",
      "code": "Reversible Encryption",
      "value": "Reversible Encryption",
      "name": "Reversible Encryption",
      "definition": "Text about Reversible Encryption pertains to adversaries utilizing reversible cryptographic routines to protect unauthorized data exfiltration channels or obfuscate command-and-control payloads while maintaining the ability to decipher original content later.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Modify Authentication Process",
        "Reversible Encryption"
      ],
      "parentId": "technique-modify-authentication-process-b2865f0f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-pluggable-authentication-modules-5edbb077",
      "code": "Pluggable Authentication Modules",
      "value": "Pluggable Authentication Modules",
      "name": "Pluggable Authentication Modules",
      "definition": "Text about adversaries altering the Pluggable Authentication Modules configurations on Linux systems to facilitate persistent unauthorized access or credential theft by modifying the standard behavior of local authentication service stacks.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Persistence",
        "Modify Authentication Process",
        "Pluggable Authentication Modules"
      ],
      "parentId": "technique-modify-authentication-process-b2865f0f",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-firmware-corruption-fe88161f",
      "code": "Firmware Corruption",
      "value": "Firmware Corruption",
      "name": "Firmware Corruption",
      "definition": "Text about unauthorized alterations to device microcode or firmware images, designed to facilitate persistent access, enable hardware-level backdoors, or compromise the integrity of the platform boot sequence and initialization.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Impact",
        "Firmware Corruption"
      ],
      "parentId": "tactic-impact-62036a70",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-inhibit-system-recovery-ac92307c",
      "code": "Inhibit System Recovery",
      "value": "Inhibit System Recovery",
      "name": "Inhibit System Recovery",
      "definition": "Text about actions taken to destroy or obstruct access to system restoration utilities and backup repositories, rendering it impossible to revert affected hosts to previous states following malicious activity.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Impact",
        "Inhibit System Recovery"
      ],
      "parentId": "tactic-impact-62036a70",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-system-script-proxy-execution-d2cebc43",
      "code": "System Script Proxy Execution",
      "value": "System Script Proxy Execution",
      "name": "System Script Proxy Execution",
      "definition": "Text about attackers leveraging signed system utilities capable of interpreting scripts to run malicious code, allowing distinct operations to proceed by masquerading unauthorized activity as legitimate system administration tasks or processes.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "System Script Proxy Execution"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 2,
      "leaf": false
    },
    {
      "id": "subtechnique-pubprn-c65184d4",
      "code": "PubPrn",
      "value": "PubPrn",
      "name": "PubPrn",
      "definition": "Text about threat actors hijacking the pubprn.vbs native script to execute signed but malicious binary payloads, effectively leveraging the associated COM interface to achieve persistent code execution on targeted Windows systems.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "System Script Proxy Execution",
        "PubPrn"
      ],
      "parentId": "technique-system-script-proxy-execution-d2cebc43",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-syncappvpublishingserver-a6f7a423",
      "code": "SyncAppvPublishingServer",
      "value": "SyncAppvPublishingServer",
      "name": "SyncAppvPublishingServer",
      "definition": "Text about SyncAppvPublishingServer explains the exploitation of a Microsoft-signed executable designed for App-V management to proxy execution of arbitrary code, allowing adversaries to bypass application whitelisting and execute unauthorized software.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "System Script Proxy Execution",
        "SyncAppvPublishingServer"
      ],
      "parentId": "technique-system-script-proxy-execution-d2cebc43",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-exploitation-for-defense-evasion-117d065b",
      "code": "Exploitation for Defense Evasion",
      "value": "Exploitation for Defense Evasion",
      "name": "Exploitation for Defense Evasion",
      "definition": "Text about adversaries utilizing specific software vulnerabilities to manipulate security tools, impair defensive monitoring capabilities, or bypass access controls to maintain stealth while operating within compromised network environments during intrusion operations.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Exploitation for Defense Evasion"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-trusted-developer-utilities-proxy-execution-bbcfa948",
      "code": "Trusted Developer Utilities Proxy Execution",
      "value": "Trusted Developer Utilities Proxy Execution",
      "name": "Trusted Developer Utilities Proxy Execution",
      "definition": "Text about the exploitation of signed programming utilities to facilitate the execution of unverified payloads, allowing adversaries to masquerade as benign build processes within compromised environments to maintain persistent stealth.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Defense Evasion",
        "Trusted Developer Utilities Proxy Execution"
      ],
      "parentId": "tactic-defense-evasion-f44f34a8",
      "synthetic": false,
      "childCount": 2,
      "leaf": false
    },
    {
      "id": "subtechnique-msbuild-bb7cd535",
      "code": "MSBuild",
      "value": "MSBuild",
      "name": "MSBuild",
      "definition": "Text about the misuse of the legitimate Microsoft Build Engine platform, whereby adversaries leverage its inherent XML project file processing capabilities to facilitate the execution of arbitrary, malicious source code payloads.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Trusted Developer Utilities Proxy Execution",
        "MSBuild"
      ],
      "parentId": "technique-trusted-developer-utilities-proxy-execution-bbcfa948",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "subtechnique-clickonce-ed15fc77",
      "code": "ClickOnce",
      "value": "ClickOnce",
      "name": "ClickOnce",
      "definition": "Text about ClickOnce refers to the abuse of the Microsoft deployment framework that enables adversaries to distribute malicious software via URL-triggered installations, leveraging trusted mechanisms to facilitate stealthy, persistent application execution.",
      "level": "subtechnique",
      "depth": 2,
      "path": [
        "Defense Evasion",
        "Trusted Developer Utilities Proxy Execution",
        "ClickOnce"
      ],
      "parentId": "technique-trusted-developer-utilities-proxy-execution-bbcfa948",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    },
    {
      "id": "technique-system-shutdown-reboot-80b70aef",
      "code": "System Shutdown/Reboot",
      "value": "System Shutdown/Reboot",
      "name": "System Shutdown/Reboot",
      "definition": "Text about malicious actors invoking system-level control functions to immediately cease operations or trigger a reboot, causing operational disruption, service downtime, and potentially forcing the system into insecure startup configurations.",
      "level": "technique",
      "depth": 1,
      "path": [
        "Impact",
        "System Shutdown/Reboot"
      ],
      "parentId": "tactic-impact-62036a70",
      "synthetic": false,
      "childCount": 0,
      "leaf": true
    }
  ]
}
