FYP
a simple guide on how to use the threat hunting tool
Guide
According to MITRE ATT&CK Frameworks, there are a lot of TTP can be used by attacker.
Below are the description and what to search for.
Reconnaissance - TA0043
Initial Access - TA0001
Valid Accounts - T1078
Execution - TA0002
Command and Scripting Interpreter - T1059
Scheduled Task/Job - T1053
Persistence - TA0003
Create Account - T1136
Privilege Escalation - TA0004
Abuse Elevation Control Mechanism - T1548
Credential Access - TA0006
Brute Force - T1110
Last updated