ABOUT
Overview
Use Cases
Mapping Methodology
Scoring Rubric
Related Projects
ATT&CK OBJECTS
Matrix
Tactics
Techniques
MAPPING FRAMEWORKS
About Mappings
Amazon Web Services (AWS)
Azure
CVE
Google Cloud Platform (GCP)
NIST 800-53
M365
VERIS
You're currently viewing ATT&CK Version 8.2 Enterprise and Azure 06.29.2021.
Change versions here.
Home
Mapping Frameworks
Azure Home
Network Security Groups Capability Group
Azure
Network Security Groups
Capability Group
All Mappings
ATT&CK Version
8.2
ATT&CK Domain
Enterprise
Azure
06.29.2021
Change Versions
Capability ID
Capability Description
Category
Value
ATT&CK ID
ATT&CK Name
network_security_groups
Network Security Groups
protect
partial
T1199
Trusted Relationship
network_security_groups
Network Security Groups
protect
partial
T1557
Man-in-the-Middle
network_security_groups
Network Security Groups
protect
partial
T1602
Data from Configuration Repository
network_security_groups
Network Security Groups
protect
partial
T1602.002
Network Device Configuration Dump
network_security_groups
Network Security Groups
protect
partial
T1602.001
SNMP (MIB Dump)
network_security_groups
Network Security Groups
protect
minimal
T1542
Pre-OS Boot
network_security_groups
Network Security Groups
protect
partial
T1542.005
TFTP Boot
network_security_groups
Network Security Groups
protect
significant
T1048
Exfiltration Over Alternative Protocol
network_security_groups
Network Security Groups
protect
significant
T1048.003
Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol
network_security_groups
Network Security Groups
protect
significant
T1048.002
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
network_security_groups
Network Security Groups
protect
significant
T1048.001
Exfiltration Over Symmetric Encrypted Non-C2 Protocol
network_security_groups
Network Security Groups
protect
partial
T1210
Exploitation of Remote Services
network_security_groups
Network Security Groups
protect
partial
T1021
Remote Services
network_security_groups
Network Security Groups
protect
partial
T1021.006
Windows Remote Management
network_security_groups
Network Security Groups
protect
partial
T1021.005
VNC
network_security_groups
Network Security Groups
protect
partial
T1021.004
SSH
network_security_groups
Network Security Groups
protect
partial
T1021.003
Distributed Component Object Model
network_security_groups
Network Security Groups
protect
partial
T1021.002
SMB/Windows Admin Shares
network_security_groups
Network Security Groups
protect
partial
T1021.001
Remote Desktop Protocol
network_security_groups
Network Security Groups
protect
partial
T1072
Software Deployment Tools
network_security_groups
Network Security Groups
protect
partial
T1133
External Remote Services
network_security_groups
Network Security Groups
protect
partial
T1482
Domain Trust Discovery
network_security_groups
Network Security Groups
protect
partial
T1046
Network Service Scanning
network_security_groups
Network Security Groups
protect
partial
T1095
Non-Application Layer Protocol
network_security_groups
Network Security Groups
protect
significant
T1571
Non-Standard Port
network_security_groups
Network Security Groups
protect
partial
T1499
Endpoint Denial of Service
network_security_groups
Network Security Groups
protect
partial
T1499.003
Application Exhaustion Flood
network_security_groups
Network Security Groups
protect
partial
T1499.002
Service Exhaustion Flood
network_security_groups
Network Security Groups
protect
partial
T1499.001
OS Exhaustion Flood
network_security_groups
Network Security Groups
protect
partial
T1570
Lateral Tool Transfer
network_security_groups
Network Security Groups
protect
partial
T1498
Network Denial of Service
network_security_groups
Network Security Groups
protect
partial
T1090
Proxy
network_security_groups
Network Security Groups
protect
partial
T1090.003
Multi-hop Proxy
network_security_groups
Network Security Groups
protect
partial
T1090.002
External Proxy
network_security_groups
Network Security Groups
protect
partial
T1090.001
Internal Proxy
network_security_groups
Network Security Groups
protect
partial
T1219
Remote Access Software
network_security_groups
Network Security Groups
protect
partial
T1205
Traffic Signaling
network_security_groups
Network Security Groups
protect
significant
T1205.001
Port Knocking
Capabilities
ATT&CK Version
8.2
ATT&CK Domain
Enterprise
Azure
06.29.2021
Change Versions
Capability ID
Capability Name
Number of Mappings
network_security_groups
Network Security Groups
38