> For the complete documentation index, see [llms.txt](https://dmcxblue.gitbook.io/red-team-notes-2-0/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques.md).

# Red Team Techniques

- [Initial Access](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access.md): The Adversary is trying to get into your Network
- [T1659: Content Injection](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/t1659-content-injection.md)
- [T1190: Exploit Public-Facing Applications](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/t1190-exploit-public-facing-applications.md)
- [Rejetto HTTP File Server (HFS) 2.3](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/t1190-exploit-public-facing-applications/rejetto-http-file-server-hfs-2.3.md)
- [T1133: External Remote Services](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/untitled.md)
- [SMB/Windows Admin Shares](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/untitled/smb-windows-admin-shares.md)
- [RDP Service](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/untitled/rdp-service.md)
- [T1566: Phishing](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/t1566-phishing.md)
- [Phishing: Spearphishing via Service](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/t1566-phishing/phishing-spearphishing-via-service.md)
- [Phishing: Spearphishing Link](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/t1566-phishing/phishing-spearphishing-link.md)
- [Links: Social Engineering Toolkit](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/t1566-phishing/phishing-spearphishing-link/links-social-engineering-toolkit.md)
- [Links: Binaries](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/t1566-phishing/phishing-spearphishing-link/links-binaries.md)
- [Links: HTA Files](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/t1566-phishing/phishing-spearphishing-link/links-hta-files.md)
- [Phishing: Spearphishing Attachment](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/t1566-phishing/phishing-spearphishing-attachment.md)
- [Attachments: LNK Files](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/t1566-phishing/phishing-spearphishing-attachment/attachments-lnk-files.md)
- [Attachments: SCR Files](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/t1566-phishing/phishing-spearphishing-attachment/attachments-scr-files.md)
- [Attachments: Dynamic Data Exchange](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/t1566-phishing/phishing-spearphishing-attachment/attachments-dynamic-data-exchange.md)
- [Attachments: Macros](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/t1566-phishing/phishing-spearphishing-attachment/attachments-macros.md)
- [Attachments: Macros - Linux](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/t1566-phishing/phishing-spearphishing-attachment/attachments-macros-linux.md)
- [Attachments: Scripting Files](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/t1566-phishing/phishing-spearphishing-attachment/attachments-scripting-files.md)
- [Attachments: Desktop Files](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/t1566-phishing/phishing-spearphishing-attachment/attachments-desktop-files.md)
- [T1195: Supply Chain Compromise](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/t1195-supply-chain-compromise.md)
- [Compromise Hardware Supply Chain](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/t1195-supply-chain-compromise/compromise-hardware-supply-chain.md)
- [Compromise Software Supply Chain](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/t1195-supply-chain-compromise/compromise-software-supply-chain.md)
- [Compromise Software Dependencies and Development Tools](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/t1195-supply-chain-compromise/compromise-software-dependencies-and-development-tools.md)
- [T1078: Valid Accounts](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/t1078-valid-accounts.md)
- [Local Accounts](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/t1078-valid-accounts/local-accounts.md)
- [Domain Accounts](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/t1078-valid-accounts/domain-accounts.md)
- [Default Accounts](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/t1078-valid-accounts/default-accounts.md)
- [T1199: Trusted Relationship](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/initial-access/t1199-trusted-relationship.md)
- [Execution](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution.md)
- [T1047:Windows Management Instrumentation](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution/t1047-windows-management-instrumentation.md)
- [T1204: User Execution](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution/t1204-user-execution.md)
- [Malicious File](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution/t1204-user-execution/malicious-file.md)
- [Malicious Link](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution/t1204-user-execution/malicious-link.md)
- [T1569: Service Execution](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution/t1569-service-execution.md)
- [T1053: Scheduled Tasks/Job](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution/t1053-scheduled-tasks-job.md)
- [Shared Modules](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution/t1053-scheduled-tasks-job/shared-modules.md)
- [Scheduled Task](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution/t1053-scheduled-tasks-job/scheduled-task.md)
- [At (Windows)](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution/t1053-scheduled-tasks-job/at-windows.md)
- [T1106: Native API](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution/t1106-native-api.md)
- [T1559: Inter-Process Communication](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution/t1559-inter-process-communication.md)
- [Dynamic Data Exchange](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution/t1559-inter-process-communication/dynamic-data-exchange.md)
- [Component Object Model](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution/t1559-inter-process-communication/component-object-model.md)
- [T1203: Exploitation for Client Execution](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution/t1203-exploitation-for-client-execution.md)
- [Common Third-Party Applications](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution/t1203-exploitation-for-client-execution/common-third-party-applications.md)
- [Office Applications](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution/t1203-exploitation-for-client-execution/office-applications.md)
- [T1059: Command and Scripting Interpreter](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution/t1059-command-and-scripting-interpreter.md)
- [Network Device CLI](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution/t1059-command-and-scripting-interpreter/network-device-cli.md)
- [JavaScript/JScript](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution/t1059-command-and-scripting-interpreter/javascript-jscript.md)
- [Python](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution/t1059-command-and-scripting-interpreter/python.md)
- [Visual Basic](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution/t1059-command-and-scripting-interpreter/visual-basic.md)
- [Unix Shell](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution/t1059-command-and-scripting-interpreter/unix-shell.md)
- [Windows Command Shell](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution/t1059-command-and-scripting-interpreter/windows-command-shell.md)
- [PowerShell](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution/t1059-command-and-scripting-interpreter/powershell.md)
- [AutoHotKey & AutoIT](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution/t1059-command-and-scripting-interpreter/autohotkey-and-autoit.md)
- [Deploy Container](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution/t1059-command-and-scripting-interpreter/deploy-container.md)
- [Native API - Linux](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/execution/t1059-command-and-scripting-interpreter/native-api-linux.md)
- [Persistence](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence.md)
- [T1574: Hijack Execution Flow](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1574-hijack-execution-flow.md)
- [Service File permissions Weakness](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1574-hijack-execution-flow/service-file-permissions-weakness.md)
- [Path Interception by Unquoted Path](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1574-hijack-execution-flow/path-interception-by-unquoted-path.md)
- [Path Interception by Search Order Hijacking](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1574-hijack-execution-flow/path-interception-by-search-order-hijacking.md)
- [Path Interception by PATH Environment Variable](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1574-hijack-execution-flow/path-interception-by-path-environment-variable.md)
- [Executable Installer File Permissions Weakness](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1574-hijack-execution-flow/executable-installer-file-permissions-weakness.md)
- [DLL Side-Loading](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1574-hijack-execution-flow/dll-side-loading.md)
- [DLL Search Order Hijacking](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1574-hijack-execution-flow/dll-search-order-hijacking.md)
- [Dynamic Linker Hijacking](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1574-hijack-execution-flow/dynamic-linker-hijacking.md)
- [T1133:External Remote Services](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1133-external-remote-services.md)
- [SMB/Windows Admin Shares](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1133-external-remote-services/smb-windows-admin-shares.md)
- [RDP Service](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1133-external-remote-services/rdp-service.md)
- [T1546:Event Triggered Execution](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1546-event-triggered-execution.md)
- [Component Object Model Hijacking](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1546-event-triggered-execution/component-object-model-hijacking.md)
- [PowerShell Profile](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1546-event-triggered-execution/powershell-profile.md)
- [Application Shimming](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1546-event-triggered-execution/application-shimming.md)
- [Accessibility Features](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1546-event-triggered-execution/accessibility-features.md)
- [Netsh Helper DLL](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1546-event-triggered-execution/netsh-helper-dll.md)
- [Screensaver](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1546-event-triggered-execution/screensaver.md)
- [Default File Association](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1546-event-triggered-execution/default-file-association.md)
- [Unix Shell Configuration Modification](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1546-event-triggered-execution/unix-shell-configuration-modification.md)
- [Trap](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1546-event-triggered-execution/trap.md)
- [Installer Packages](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1546-event-triggered-execution/installer-packages.md)
- [T1543:Create or Modify System Process](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1543-create-or-modify-system-process.md)
- [Windows Services](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1543-create-or-modify-system-process/windows-services.md)
- [Systemd Service](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1543-create-or-modify-system-process/systemd-service.md)
- [T1136: Create Account](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1136-create-account.md)
- [Domain Account](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1136-create-account/domain-account.md)
- [Local Account](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1136-create-account/local-account.md)
- [T1554:Compromise Client Software Binary](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1554-compromise-client-software-binary.md)
- [T1547:Boot or Logon AutoStart Execution](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1547-boot-or-logon-autostart-execution.md)
- [Shortcut Modification](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1547-boot-or-logon-autostart-execution/shortcut-modification.md)
- [Winlogon Helper DLL](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1547-boot-or-logon-autostart-execution/winlogon-helper-dll.md)
- [Time Providers](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1547-boot-or-logon-autostart-execution/time-providers.md)
- [Registry Run Keys / Startup Folder](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1547-boot-or-logon-autostart-execution/registry-run-keys-startup-folder.md)
- [T1037:  Boot or Logon Initialization Scripts](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1037-boot-or-logon-initialization-scripts.md)
- [RC Scripts](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1037-boot-or-logon-initialization-scripts/rc-scripts.md)
- [T1197: BITS Jobs](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1197-bits-jobs.md)
- [T1053: Scheduled Tasks/Job](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1053-scheduled-tasks-job.md)
- [Shared Modules](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1053-scheduled-tasks-job/shared-modules.md)
- [Scheduled Task](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1053-scheduled-tasks-job/scheduled-task.md)
- [At (Windows)](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1053-scheduled-tasks-job/at-windows.md)
- [Cron](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1053-scheduled-tasks-job/cron.md)
- [Systemd Timers](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1053-scheduled-tasks-job/systemd-timers.md)
- [T1098: Account Manipulation](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1098-account-manipulation.md)
- [SSH Authorized Keys](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1098-account-manipulation/ssh-authorized-keys.md)
- [T1556: Modify Authentication Process](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1556-modify-authentication-process.md)
- [Pluggable Authentication Modules](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1556-modify-authentication-process/pluggable-authentication-modules.md)
- [T1653: Power Settingss](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1653-power-settingss.md)
- [T1505:  Server Software Component](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1505-server-software-component.md)
- [WebShell](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/persistence/t1505-server-software-component/webshell.md)
- [Privilege Escalation](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation.md)
- [T1546:Event Triggered Execution](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3.md)
- [PowerShell Profile](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/powershell-profile.md)
- [Component Object Model Hijacking](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/component-object-model-hijacking.md)
- [Application Shimming](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/application-shimming.md)
- [Accessibility Features](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/accessibility-features.md)
- [Screensaver](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/screensaver.md)
- [Default File Association](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-3/default-file-association.md)
- [T1612: Build Image on Host](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/t1612-build-image-on-host.md)
- [T1574: Hijack Execution Flow](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-2.md)
- [Service File permissions Weakness](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-2/service-file-permissions-weakness.md)
- [Path Interception by Unquoted Path](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-2/path-interception-by-unquoted-path.md)
- [Path Interception by Search Order Hijacking](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-2/path-interception-by-search-order-hijacking.md)
- [Path Interception by PATH Environment Variable](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-2/path-interception-by-path-environment-variable.md)
- [Executable Installer File Permissions Weakness](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-2/executable-installer-file-permissions-weakness.md)
- [DLL Side-Loading](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-2/dll-side-loading.md)
- [DLL Search Order Hijacking](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-2/dll-search-order-hijacking.md)
- [T1543:Create or Modify System Process](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-1.md)
- [Windows Services](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled-1/windows-services.md)
- [T1547:Boot or Logon AutoStart Execution](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled.md)
- [Winlogon Helper DLL](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled/winlogon-helper-dll.md)
- [Shortcut Modification](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled/shortcut-modification.md)
- [Time Providers](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled/time-providers.md)
- [Registry Run Keys / Startup Folder](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/untitled/registry-run-keys-startup-folder.md)
- [T1134: Access Token Manipulation](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/t1134-access-token-manipulation.md)
- [Parent PID Spoofing](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/t1134-access-token-manipulation/parent-pid-spoofing.md)
- [Make and Impersonate Token](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/t1134-access-token-manipulation/make-and-impersonate-token.md)
- [Create Process with Token](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/t1134-access-token-manipulation/create-process-with-token.md)
- [Token Impersonation/Theft](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/t1134-access-token-manipulation/token-impersonation-theft.md)
- [T1548: Abuse Elevation Control Mechanism](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/t1548-abuse-elevation-control-mechanism.md)
- [Bypass User Account Control](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/t1548-abuse-elevation-control-mechanism/bypass-user-account-control.md)
- [Setuid and Setgid](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/t1548-abuse-elevation-control-mechanism/setuid-and-setgid.md)
- [Sudo and Sudo Caching](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/t1548-abuse-elevation-control-mechanism/sudo-and-sudo-caching.md)
- [T1611: Escape to Host](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/privilege-escalation/t1611-escape-to-host.md)
- [Defense Evasion](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion.md)
- [T1497: Virtualization/Sandbox Evasion](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1497-virtualization-sandbox-evasion.md)
- [Time Based Evasion](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1497-virtualization-sandbox-evasion/time-based-evasion.md)
- [User Activity Based Checks](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1497-virtualization-sandbox-evasion/user-activity-based-checks.md)
- [System Checks](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1497-virtualization-sandbox-evasion/system-checks.md)
- [T1550: Use Alternate Authentication Material](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1550-use-alternate-authentication-material.md)
- [Pass the Ticket](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1550-use-alternate-authentication-material/pass-the-ticket.md)
- [Pass the Hash](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1550-use-alternate-authentication-material/pass-the-hash.md)
- [T1127: Trusted Developer Utilities Proxy Execution](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1127-trusted-developer-utilities-proxy-execution.md)
- [MSBuild](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1127-trusted-developer-utilities-proxy-execution/msbuild.md)
- [T1221: Template Injection](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1221-template-injection.md)
- [T1553: Subvert Trust Controls](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1553-subvert-trust-controls.md)
- [SIP and Trust Provider Hijacking](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1553-subvert-trust-controls/sip-and-trust-provider-hijacking.md)
- [Code Signing](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1553-subvert-trust-controls/code-signing.md)
- [T1216: Signed Script Proxy Execution](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1216-signed-script-proxy-execution.md)
- [T1218: Signed Binary Proxy Execution](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1218-signed-binary-proxy-execution.md)
- [Compiled HTML File](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1218-signed-binary-proxy-execution/untitled-10.md)
- [Control Panel](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1218-signed-binary-proxy-execution/untitled-9.md)
- [CMSTP](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1218-signed-binary-proxy-execution/untitled-8.md)
- [InstallUtil](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1218-signed-binary-proxy-execution/untitled-7.md)
- [MSHTA](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1218-signed-binary-proxy-execution/untitled-6.md)
- [MSIEXEC](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1218-signed-binary-proxy-execution/untitled-5.md)
- [ODBCCONF](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1218-signed-binary-proxy-execution/untitled-4.md)
- [Regsvcs/Regasm](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1218-signed-binary-proxy-execution/untitled-3.md)
- [Regsvr32](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1218-signed-binary-proxy-execution/untitled-2.md)
- [Rundll32](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1218-signed-binary-proxy-execution/untitled-1.md)
- [Verclsid](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1218-signed-binary-proxy-execution/untitled.md)
- [T1055: Process Injection](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1055-process-injection.md)
- [Dynamic-Link Library Injection](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1055-process-injection/dynamic-link-library-injection.md)
- [Portable Execution Injection](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1055-process-injection/portable-execution-injection.md)
- [Thread Execution Hijacking](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1055-process-injection/thread-execution-hijacking.md)
- [Asynchronous Procedure Call](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1055-process-injection/asynchronous-procedure-call.md)
- [Thread Local Storage](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1055-process-injection/thread-local-storage.md)
- [Extra Window Memory Injection](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1055-process-injection/extra-window-memory-injection.md)
- [Process Hollowing](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1055-process-injection/process-hollowing.md)
- [Process Doppelganging](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1055-process-injection/process-doppelganging.md)
- [T0127: Obfuscated Files or Information](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t0127-obfuscated-files-or-information.md)
- [Binary Padding](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t0127-obfuscated-files-or-information/binary-padding.md)
- [Software Packing](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t0127-obfuscated-files-or-information/software-packing.md)
- [Steganography](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t0127-obfuscated-files-or-information/steganography.md)
- [Compile After Delivery](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t0127-obfuscated-files-or-information/compile-after-delivery.md)
- [Indicator Removal from Tools](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t0127-obfuscated-files-or-information/indicator-removal-from-tools.md)
- [T1036: Masquerading](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1036-masquerading.md)
- [Invalid Code Signature](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1036-masquerading/invalid-code-signature.md)
- [Right-to-Left-Override](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1036-masquerading/right-to-left-override.md)
- [Rename System Utilities](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1036-masquerading/rename-system-utilities.md)
- [Masquerade Task or Service](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1036-masquerading/masquerade-task-or-service.md)
- [Match Legitimate Name or location](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1036-masquerading/match-legitimate-name-or-location.md)
- [T1202: Indirect Command Execution](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1202-indirect-command-execution.md)
- [T1562: Impair Defenses](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1562-impair-defenses.md)
- [Disable or Modify Tools](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1562-impair-defenses/disable-or-modify-tools.md)
- [Disable Windows Event Logging](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1562-impair-defenses/disable-windows-event-logging.md)
- [Impair Command History Logging](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1562-impair-defenses/impair-command-history-logging.md)
- [Disable or Modify System Firewall](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1562-impair-defenses/disable-or-modify-system-firewall.md)
- [Disable or Modify Linux Audit System](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1562-impair-defenses/disable-or-modify-linux-audit-system.md)
- [Indicator Blocking](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1562-impair-defenses/indicator-blocking.md)
- [T1070: Indicator Removal on Host](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1070-indicator-removal-on-host.md)
- [Clear Windows Event Logs](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1070-indicator-removal-on-host/clear-windows-event-logs.md)
- [Clear Command History](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1070-indicator-removal-on-host/clear-command-history.md)
- [File Deletion](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1070-indicator-removal-on-host/file-deletion.md)
- [Network Share Connection Removal](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1070-indicator-removal-on-host/network-share-connection-removal.md)
- [TimeStomping](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1070-indicator-removal-on-host/timestomping.md)
- [T1574: Hijack Execution Flow](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/untitled-5.md)
- [Path Interception by Unquoted Path](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/untitled-5/path-interception-by-unquoted-path.md)
- [Service File permissions Weakness](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/untitled-5/service-file-permissions-weakness.md)
- [Path Interception by Search Order Hijacking](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/untitled-5/path-interception-by-search-order-hijacking.md)
- [Path Interception by PATH Environment Variable](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/untitled-5/path-interception-by-path-environment-variable.md)
- [Executable Installer File Permissions Weakness](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/untitled-5/executable-installer-file-permissions-weakness.md)
- [DLL Side-Loading](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/untitled-5/dll-side-loading.md)
- [DLL Search Order Hijacking](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/untitled-5/dll-search-order-hijacking.md)
- [T1564: Hide Artifacts](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1564-hide-artifacts.md)
- [VBA Stomping](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1564-hide-artifacts/vba-stomping.md)
- [Run Virtual Instance](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1564-hide-artifacts/run-virtual-instance.md)
- [NTFS File Attributes](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1564-hide-artifacts/ntfs-file-attributes.md)
- [Hidden Window](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1564-hide-artifacts/hidden-window.md)
- [Hidden File System](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1564-hide-artifacts/hidden-file-system.md)
- [Hidden Users](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1564-hide-artifacts/hidden-users.md)
- [Ignore Process Interrupts](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1564-hide-artifacts/ignore-process-interrupts.md)
- [File/Path Exclusions](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1564-hide-artifacts/file-path-exclusions.md)
- [Hidden Files and Directories](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/t1564-hide-artifacts/hidden-files-and-directories.md)
- [T1222: File Directory Permissions Modification](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/untitled-4.md)
- [Linux and Mac File and Directory Permissions Modification](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/untitled-4/linux-and-mac-file-and-directory-permissions-modification.md)
- [Windows File and Directory Permissions Modification](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/untitled-4/windows-file-and-directory-permissions-modification.md)
- [T1480: Execution Guardrails](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/untitled-3.md)
- [Environmental Keying Linux](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/untitled-3/environmental-keying-linux.md)
- [Environmental Keying](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/untitled-3/environmental-keyring.md)
- [T1197: BITS Jobs](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/untitled-2.md)
- [T1134: Access Token Manipulation](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/untitled-1.md)
- [Parent PID Spoofing](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/untitled-1/parent-pid-spoofing.md)
- [Make and Impersonate Token](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/untitled-1/make-and-impersonate-token.md)
- [Create Process with Token](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/untitled-1/create-process-with-token.md)
- [Token Impersonation/Theft](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/untitled-1/token-impersonation-theft.md)
- [T1548: Abuse Elevation Control Mechanism](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/untitled.md)
- [Bypass User Account Control](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/untitled/bypass-user-account-control.md)
- [De-obfuscate/Decode Files or Information](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/defense-evasion/de-obfuscate-decode-files-or-information.md)
- [Credential Access](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access.md)
- [T1552: Unsecured Credentials](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1552-unsecured-credentials.md)
- [Group Policy Preferences](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1552-unsecured-credentials/group-policy-preferences.md)
- [Private Keys](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1552-unsecured-credentials/private-keys.md)
- [Credentials in Registry](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1552-unsecured-credentials/credentials-in-registry.md)
- [Credentials in Files](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1552-unsecured-credentials/credentials-in-files.md)
- [T1558: Steal or Forge Kerberos Tickets](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1558-steal-or-forge-kerberos-tickets.md)
- [AS-REP Roasting](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1558-steal-or-forge-kerberos-tickets/as-rep-roasting.md)
- [Kerberoasting](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1558-steal-or-forge-kerberos-tickets/kerberoasting.md)
- [Silver Ticket](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1558-steal-or-forge-kerberos-tickets/silver-ticket.md)
- [Golden Ticket](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1558-steal-or-forge-kerberos-tickets/golden-ticket.md)
- [T1003: OS Credential Dumping](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1003-os-credential-dumping.md)
- [DCSync](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1003-os-credential-dumping/dcsync.md)
- [Cached Domain Credentials](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1003-os-credential-dumping/cached-domain-credentials.md)
- [LSA Secrets](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1003-os-credential-dumping/lsa-secrets.md)
- [NTDS](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1003-os-credential-dumping/ntds.md)
- [Security Account Manager](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1003-os-credential-dumping/security-account-manager.md)
- [LSASS Memory](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1003-os-credential-dumping/lsass-memory.md)
- [T1040: Network Sniffing](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1040-network-sniffing.md)
- [T1556: Modify Authentication Process](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1556-modify-authentication-process.md)
- [Password Filter DLL](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1556-modify-authentication-process/password-filter-dll.md)
- [Domain Controller Authentication](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1556-modify-authentication-process/domain-controller-authentication.md)
- [T1557: Man-in-the-Middle](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1557-man-in-the-middle.md)
- [Arp Cache Poisoning](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1557-man-in-the-middle/arp-cache-poisoning.md)
- [LLMNR/NBT-NS Poisoning and SMB Relay](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1557-man-in-the-middle/untitled.md)
- [T1056: Input Capture](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1056-input-capture.md)
- [Web Portal Capture](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1056-input-capture/web-portal-capture.md)
- [GUI Input Capture](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1056-input-capture/gui-input-capture.md)
- [Keylogging](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1056-input-capture/keylogging.md)
- [T1187: Forced Authentication](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1187-forced-authentication.md)
- [T1555: Credentials from Password Stores](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1555-credentials-from-password-stores.md)
- [Credentials from Web Browsers](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1555-credentials-from-password-stores/credentials-from-web-browsers.md)
- [T1110: Brute Force](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1110-brute-force.md)
- [Credential Stuffing](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1110-brute-force/credential-stuffing.md)
- [Password Spraying](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1110-brute-force/password-spraying.md)
- [Password Cracking](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1110-brute-force/password-cracking.md)
- [Password Guessing](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/credential-access/t1110-brute-force/password-guessing.md)
- [Discovery](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/discovery.md): The Adversary is trying to figure out your environment
- [T1124: System Time Discovery](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/discovery/t1124-system-time-discovery.md)
- [T1007: System Service Disvcovery](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/discovery/t1007-system-service-disvcovery.md)
- [T1033: System Owner/User Directory](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/discovery/t1033-system-owner-user-directory.md)
- [T1049: System Network Connections Discovery](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/discovery/t1049-system-network-connections-discovery.md)
- [T1016: System Network Configuration Discovery](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/discovery/t1016-system-network-configuration-discovery.md)
- [T1082: System Information Discovery](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/discovery/t1082-system-information-discovery.md)
- [T1518: Software Discovery](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/discovery/t1518-software-discovery.md)
- [Security Software Discovery](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/discovery/t1518-software-discovery/security-software-discovery.md)
- [T1018: Remote System Discovery](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/discovery/t1018-remote-system-discovery.md)
- [T1012: Query Registry](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/discovery/t1012-query-registry.md)
- [T1057: Process Discovery](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/discovery/t1057-process-discovery.md)
- [T1069: Permissions Groups Discovery](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/discovery/t1069-permissions-groups-discovery.md)
- [Local Groups](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/discovery/t1069-permissions-groups-discovery/local-groups.md)
- [Domain Groups](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/discovery/t1069-permissions-groups-discovery/domain-groups.md)
- [T1120: Peripheral Device Discovery](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/discovery/t1120-peripheral-device-discovery.md)
- [T1201: Password Policy Discovery](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/discovery/t1201-password-policy-discovery.md)
- [T1040: Network Sniffing](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/discovery/t1040-network-sniffing.md)
- [T1135: Network Share Discovery](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/discovery/t1135-network-share-discovery.md)
- [T1046: Network Servie Scanning](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/discovery/t1046-network-servie-scanning.md)
- [T1083: File and Directory Discovery](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/discovery/t1083-file-and-directory-discovery.md)
- [T1486: Domain Trust Discovery](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/discovery/t1486-domain-trust-discovery.md)
- [T1217: Browser Bookmark Discovery](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/discovery/t1217-browser-bookmark-discovery.md)
- [T1010: Application Window Discovery](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/discovery/t1010-application-window-discovery.md)
- [T1087: Account Discovery](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/discovery/t1087-account-discovery.md)
- [Domain Account](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/discovery/t1087-account-discovery/domain-account.md)
- [Local Account](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/discovery/t1087-account-discovery/local-account.md)
- [Lateral Movement](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/lateral-movement.md): The adversary is trying to move through your environment
- [T1080: Taint Shared Content](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/lateral-movement/t1080-taint-shared-content.md)
- [T1072: Software Deployment Tools](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/lateral-movement/t1072-software-deployment-tools.md)
- [T1021: Remote Services](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/lateral-movement/t1021-remote-services.md)
- [Windows Remote Management](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/lateral-movement/t1021-remote-services/windows-remote-management.md)
- [VNC](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/lateral-movement/t1021-remote-services/vnc.md)
- [Distributed Component Object Model](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/lateral-movement/t1021-remote-services/distributed-component-object-model.md)
- [SMB/Windows Admin Shares](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/lateral-movement/t1021-remote-services/smb-windows-admin-shares.md)
- [Remote Desktop Protocol](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/lateral-movement/t1021-remote-services/remote-desktop-protocol.md)
- [T1563: Remote Service Session Hijacking](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/lateral-movement/t1563-remote-service-session-hijacking.md)
- [RDP Hijacking](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/lateral-movement/t1563-remote-service-session-hijacking/rdp-hijacking.md)
- [T1570: Lateral Tool Transfer](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/lateral-movement/t1570-lateral-tool-transfer.md)
- [T1534: Internal Spearphishing](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/lateral-movement/t1534-internal-spearphishing.md)
- [T1210: Exploitation of Remote Services](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/lateral-movement/t1210-exploitation-of-remote-services.md)
- [T1550 Use Alternate Authentication Material](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/lateral-movement/t1550-use-alternate-authentication-material.md)
- [Pass the Ticket](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/lateral-movement/t1550-use-alternate-authentication-material/pass-the-ticket.md)
- [Pass the Hash](https://dmcxblue.gitbook.io/red-team-notes-2-0/red-team-techniques/lateral-movement/t1550-use-alternate-authentication-material/pass-the-hash.md)
