Meta tags:
Headings (most frequently used words):
application, attack, matrix,
Text of the page (most frequently used words):
exploitation (29), service (28), data (24), injection (23), #application (20), and (18), for (15), code (15), manipulation (14), mapping (12), remote (12), execution (12), api (11), analysis (9), resource (9), capabilities (9), matrix (8), techniques (8), source (8), the (8), tactics (8), hijacking (8), internal (8), harvesting (8), standard (8), services (8), access (8), discovery (8), abuse (7), software (7), dependency (7), protocols (7), build (7), security (6), accounts (6), compromise (6), poisoning (6), dependencies (6), control (6), top (5), attacks (5), mitre (5), owasp (5), valid (5), image (5), supply (5), chain (5), public (5), external (5), configuration (5), destruction (5), credential (5), runtime (5), content (5), cloud (5), flow (5), att (4), enterprise (4), 2025 (4), frameworks (4), financial (4), theft (4), defacement (4), server (4), component (4), scheduled (4), task (4), business (4), logic (4), masquerading (4), exfiltration (4), implant (4), reverse (4), engineering (4), encryption (4), trust (4), privilege (4), escalation (4), request (4), forgery (4), third (4), party (4), artifacts (4), defense (4), evasion (4), obtain (4), gather (4), information (4), disable (4), protection (4), exploitations (4), develop (4), disruption (4), over (4), app (4), using (4), applicative (4), authentication (4), bypass (4), compromised (4), signing (4), infrastructure (4), specification (4), impact (4), development (4), memory (4), index (3), bybit (3), campaign (3), technique (3), web (3), traffic (3), expanding (3), deepening (3), payload (3), gain (3), reconnaissance (3), intrusion (3), file (3), tampering (3), sql (3), with (2), not (2), derived (2), from (2), explicit (2), field (2), full (2), inverse (2), risk (2), this (2), procedures (2), attack (2), contributors (2), about (2), deletion (2), system (2), extraction (2), tokens (2), open (2), tools (2), container (2), exposed (2), apis (2), protocol (2), man (2), side (2), registry (2), exploits (2), malware (2), metadata (2), manifest (2), inspection (2), made, material, mkdocs, next, back, original, layer, yet, present, either, framework, published, real, world, incident, see, that, originate, extend, originated, pages, carry, foundational, taxonomy, cells, badge, map, primarily, class, every, sub, page, carries, are, cross, referenced, community, initiative, educate, readers, potential, level, ttps, teach, how, weaponize, specifically, them, disclaimer, network, post, pre, website, replacement, transmitted, cryptomining, compute, bandwidth, lifecycle, triggered, database, record, corruption, via, overwriting, backup, flooding, shutdown, reboot, starvation, denial, dos, token, replay, reuse, overprivileged, account, misconfiguration, stealing, based, listing, shell, stored, match, legitimate, name, location, break, process, trees, transfer, dns, termination, downgrade, bypassing, hooks, systemd, timers, orchestration, job, cron, thread, reflective, loading, shared, library, ptrace, calls, proc, toctou, symlink, suid, guid, kernel, cpu, gpu, jndi, serialized, linking, ssrf, csrf, expression, language, nosql, template, crlf, ognl, xxe, xml, ldap, arbitrary, write, command, insecure, deserialization, pointer, buffer, overflow, dynamic, evaluation, race, condition, password, brute, forcing, oauth, unauthenticated, administration, interfaces, ssh, kubernetes, gateway, default, middle, update, environment, acquisition, stolen, keys, credentials, vulnerabilities, tool, typosquatting, confusion, backdoored, libraries, script, pipeline, binary, disassembly, static, repository, fingerprinting, feature, flag, sbom, query, package, scraping, opensource, enumeration, client, commercial, vendor, sniffing, schema, fuzzing, endpoints, documentation, initializing, search,
Text of the page (random words):
index application security tactics techniques matrix application security tactics techniques matrix index initializing search tactics bybit campaign attacks frameworks about contributors application security tactics techniques matrix tactics tactics reconnaissance reconnaissance application api specification harvesting application api specification harvesting application api specification harvesting api documentation analysis fuzzing api endpoints schema extraction traffic sniffing application dependencies mapping application dependencies mapping application dependencies mapping client side commercial vendor discovery image metadata inspection manifest inspection opensource dependency enumeration package manifest scraping registry metadata query sbom analysis gather application configuration information gather application configuration information gather application configuration information feature flag discovery fingerprinting public source code and artifacts analysis public source code and artifacts analysis public source code and artifacts analysis public repository discovery static code analysis reverse engineering reverse engineering reverse engineering binary disassembly protocol analysis resource development resource development compromised code signing and build infrastructure compromised code signing and build infrastructure compromised code signing and build infrastructure build pipeline manipulation build script tampering third party dependency poisoning third party dependency poisoning third party dependency poisoning backdoored open source libraries dependency confusion typosquatting dependencies develop capabilities develop capabilities develop capabilities malware exploits obtain capabilities obtain capabilities obtain capabilities malware exploits tool vulnerabilities acquisition of stolen keys credentials gain access gain access supply chain compromise supply chain compromise supply chain compromise build environment poisoning compromise software dependencies and development tools compromise software supply chain container registry poisoning dependency hijacking software update manipulation content injection content injection content injection man on the side injection man in the middle injection protocol exploitation service standard apis service standard apis service standard api valid accounts valid accounts valid accounts cloud accounts default accounts valid tokens external remote services external remote services external remote services exposed gateway exposed kubernetes api ssh access unauthenticated administration interfaces authentication bypass authentication bypass authentication bypass oauth flow manipulation password brute forcing race condition exploitation sql injection payload execution payload execution remote code execution exploitation remote code execution exploitation remote code execution exploitation dynamic code evaluation memory buffer overflow memory pointer manipulation insecure deserialization exploitation execution using standard applicative flow execution using standard applicative flow execution using standard applicative flow injection exploitations injection exploitations injection exploitations os command injection arbitrary file write exploitation ldap injection xml injection xxe injection ognl injection crlf injection template injection sql injection nosql injection expression language injection request forgery request forgery request forgery csrf ssrf serialized data external linking jndi injection deepening control deepening control exploitation for privilege escalation exploitation for privilege escalation exploitation for privilege escalation capabilities abuse cpu and gpu exploitation kernel exploitation suid and guid abuse symlink attack toctou exploitation for defense evasion exploitation for defense evasion exploitation for defense evasion hijacking injection proc memory ptrace system calls shared library reflective code loading thread execution scheduled task scheduled task scheduled task at container cron orchestration job systemd timers disable runtime protection service disable runtime protection service disable runtime protection service bypassing security hooks configuration tampering service downgrade service termination c2 over app protocols c2 over app protocols c2 over app protocols dns protocols file transfer protocols web protocols masquerading masquerading masquerading break process trees match legitimate name or location implant internal image implant internal image implant internal image server software component server software component server software component sql stored procedures web shell expanding control expanding control cloud service discovery cloud service discovery cloud service discovery api based resource listing open source discovery tools exploitation for credential access exploitation for credential access exploitation for credential access stealing tokens memory exploitation for credential extraction exploitation of remote services exploitation of remote services exploitation of remote services api misconfiguration exploitation internal data harvesting internal data harvesting internal data harvesting service to service trust abuse service to service trust abuse service to service trust abuse overprivileged service account exploitation token replay or reuse attacks impact impact service disruption service disruption service disruption denial of service dos attacks resource starvation system shutdown and reboot traffic flooding data destruction data destruction data destruction backup destruction or tampering data corruption via overwriting file or database record deletion lifecycle triggered deletion data encryption data encryption data encryption data exfiltration data exfiltration data exfiltration business logic manipulation business logic manipulation business logic manipulation resource hijacking resource hijacking resource hijacking bandwidth hijacking compute hijacking cryptomining data manipulation data manipulation data manipulation runtime data manipulation transmitted data manipulation defacement defacement defacement replacement website content financial theft financial theft financial theft bybit campaign attacks frameworks frameworks owasp top 10 2025 mapping mitre att ck enterprise mapping about contributors application attack matrix pre intrusion intrusion post intrusion impact reconnaissance resource development gain access payload execution deepening control expanding control impact application api specification harvesting compromised code signing and build infrastructure authentication bypass execution using standard applicative flow c2 over app protocols cloud service discovery service disruption application dependencies mapping develop capabilities content injection network traffic injection exploitations disable runtime protection service exploitation for credential access data destruction gather application configuration information obtain capabilities external remote services remote code execution exploitation exploitation for defense evasion exploitation of remote services data manipulation public source code and artifacts analysis third party dependency poisoning service standard api request forgery exploitation for privilege escalation service to service trust abuse data encryption reverse engineering supply chain compromise implant internal image internal data harvesting data exfiltration valid accounts masquerading business logic manipulation scheduled task resource hijacking server software component defacement financial theft disclaimer application security tactics techniques matrix is a community initiative to educate readers on the potential of application level tactics techniques and procedures ttps it is not to teach how to weaponize or specifically abuse them source frameworks techniques in this matrix are derived from and cross referenced to owasp top 10 2025 the foundational web application security risk taxonomy cells with this badge map primarily to an owasp top 10 2025 risk class every technique and sub technique page carries an explicit owasp mapping field and the full inverse mapping is in owasp top 10 2025 mapping mitre att ck enterprise for techniques that originate in or extend the att ck enterprise matrix mitre originated technique pages carry an explicit mitre mapping field and the full inverse mapping is in mitre att ck enterprise mapping matrix original application layer techniques not yet present in either source framework derived from published real world incident analysis see attacks and the bybit campaign back to top next index made with material for mkdocs
|