|
| 1 | +# v2025 |
| 2 | + |
| 3 | +## Phases |
| 4 | + |
| 5 | +### New |
| 6 | +- None |
| 7 | + |
| 8 | +### Updated |
| 9 | +- `Actions on the Objective`: Minor wording changes. |
| 10 | + |
| 11 | +### Retired |
| 12 | +- None |
| 13 | + |
| 14 | +## Tactics |
| 15 | + |
| 16 | +### New |
| 17 | +- `TAC-25 Accessibility Options Abuse` |
| 18 | +- `TAC-26 Impersonation` |
| 19 | +- `TAC-27 Session Manipulation` |
| 20 | +- `TAC-28 Queue Bypass` |
| 21 | +- `TAC-29 Session Transfer` |
| 22 | +- `TAC-30 Bonus Farming` |
| 23 | +- `TAC-31 AI Model Training` |
| 24 | +- `TAC-32 Geo-Location Spoofing` |
| 25 | +- `TAC-33 Device Emulation` |
| 26 | +- `TAC-34 Attack Surface Identification` |
| 27 | +- `TAC-35 Fake Credibility Generation` |
| 28 | +- `TAC-36 Specific Target Scraping` |
| 29 | +- `TAC-37 Loose Target Scraping` |
| 30 | +- `TAC-38 Identity Acquisition` |
| 31 | +- `TAC-39 Inventory Manipulation` |
| 32 | +- `TAC-40 Add to Cart` |
| 33 | +- `TAC-41 Account Enumeration` |
| 34 | +- `TAC-42 Payment Card Enumeration` |
| 35 | +- `TAC-43 Information Release` |
| 36 | + |
| 37 | + |
| 38 | +### Updated |
| 39 | +- `TAC-02 Credential Acquisition`: Minor wording changes. |
| 40 | +- `TAC-03 Infrastructure Acquisition`: Minor wording changes. |
| 41 | +- `TAC-04 Payment Detail Acquisition`: Minor wording changes. |
| 42 | +- `TAC-08 Mitigation Bypass` -> `TAC-08 CAPTCHA Bypass`: Renamed. |
| 43 | +- `TAC-10 Proxying`: Major wording changes. |
| 44 | +- `TAC-12 Account Creation`: Minor wording changes. |
| 45 | +- `TAC-15 Stock Purchase` -> `TAC-15 Purchase`: Major wording changes. Renamed. |
| 46 | +- `TAC-20 Transaction Redirect` -> `TAC-20 Cashout`: Major wording changes. Renamed. |
| 47 | +- `TAC-21 Exfiltration` -> `TAC-21 Data Extraction`: Renamed. |
| 48 | + |
| 49 | + |
| 50 | +### Retired |
| 51 | +- `TAC-06 Specific Target`: Replaced by `TAC-36 Specific Target Scraping` |
| 52 | +- `TAC-07 Loose Target`: Replaced by `TAC-37 Loose Target Scraping` |
| 53 | +- `TAC-16 Spinning` |
| 54 | +- `TAC-17 Sniping` |
| 55 | + |
| 56 | +## Techniques |
| 57 | + |
| 58 | +### New |
| 59 | +- `TEQ-081 Accessibility Downgrade` |
| 60 | +- `TEQ-082 Session Persistence` |
| 61 | +- `TEQ-083 Session Reassumption` |
| 62 | +- `TEQ-084 Queue Flooding` |
| 63 | +- `TEQ-085 Queue Position Tracking` |
| 64 | +- `TEQ-086 Queue Jumping` |
| 65 | +- `TEQ-087 Queue Evasion` |
| 66 | +- `TEQ-088 Session Spoofing` |
| 67 | +- `TEQ-089 Queue Position Transfer` |
| 68 | +- `TEQ-090 Referral Program Exploitation` |
| 69 | +- `TEQ-091 Clickjacking` |
| 70 | +- `TEQ-092 Bonus Clipping` |
| 71 | +- `TEQ-093 LLM Training Data` |
| 72 | +- `TEQ-094 LAM Training Data` |
| 73 | +- `TEQ-095 GPS Spoofing` |
| 74 | +- `TEQ-096 Mobile Network Spoofing` |
| 75 | +- `TEQ-097 Accept-Language Manipulation` |
| 76 | +- `TEQ-098 TLS Spoofing` |
| 77 | +- `TEQ-099 Header Spoofing` |
| 78 | +- `TEQ-100 Path Enumeration` |
| 79 | +- `TEQ-101 Endpoint Enumeration` |
| 80 | +- `TEQ-102 Fake Account Creation` |
| 81 | +- `TEQ-103 Queue Exhaustion` |
| 82 | +- `TEQ-104 Queue Entry` |
| 83 | +- `TEQ-105 Account Ageing` |
| 84 | +- `TEQ-106 Fuzzing` |
| 85 | +- `TEQ-107 Synthetic Account Creation` |
| 86 | +- `TEQ-108 Impersonated Account Creation` |
| 87 | +- `TEQ-109 Inventory Exhaustion` |
| 88 | +- `TEQ-110 Mass Add to Cart` |
| 89 | +- `TEQ-111 Loyalty Points Redemption` |
| 90 | +- `TEQ-112 Deepfakes` |
| 91 | +- `TEQ-113 Credit/Debit Card Cracking` |
| 92 | +- `TEQ-114 Gift Card Cracking` |
| 93 | +- `TEQ-115 Intellectual Property Leak` |
| 94 | +- `TEQ-116 Inventory Information Extraction` |
| 95 | +- `TEQ-117 Credential Extraction` |
| 96 | +- `TEQ-118 Payment Detail Extraction` |
| 97 | +- `TEQ-119 PII Extraction` |
| 98 | +- `TEQ-120 Intellectual Property Extraction` |
| 99 | + |
| 100 | +### Updated |
| 101 | +- `TEQ-002 URL Disguise`: Minor wording changes. |
| 102 | +- `TEQ-003 Data Dumps`: Added `TAC-38 Identity Acquisition` as parent. |
| 103 | +- `TEQ-004 Malware` -> `TEQ-004 Infostealer`: Major wording changes. Renamed. |
| 104 | +- `TEQ-005 Person in the Middle`: Minor wording changes. |
| 105 | +- `TEQ-008 Botnet`: Minor wording changes. Removed `TAC-10 Proxying` as parent. |
| 106 | +- `TEQ-011 Supply Chain Compromise` -> `TEQ-011 Trusted Infrastructure`: Major wording changes. Renamed. |
| 107 | +- `TEQ-015 Continual Content Scraping`: Removed `TAC-06 Specific Target` and `TAC-07 Loose Target` as parents and replaced with `TAC-36 Specific Target Scraping` and `TAC-37 Loose Target Scraping`. |
| 108 | +- `TEQ-018 CAPTCHA Farm`: Minor wording changes. |
| 109 | +- `TEQ-020 Token Bypass`: Removed `TAC-08 Mitigation Bypass` as parent and replaced with `TAC-27 Session Manipulation`. |
| 110 | +- `TEQ-021 Cookie Abuse`: Removed `TAC-08 Mitigation Bypass` as parent and replaced with `TAC-27 Session Manipulation`. |
| 111 | +- `TEQ-022 Accessibility Options Abuse` -> `TEQ-022 Accessibilty Feature Abuse`: Minor wording changes. Renamed. Removed `TAC-08 Mitigation Bypass`, `TAC-09 Human Emulation` and `TAC-14 Fake Interaction` as parents and replaced with `TAC-25 Accessibility Option Abuse`. |
| 112 | +- `TEQ-023 MFA Bypass`: Removed `TAC-08 Mitigation Bypass` as parent and replaced with `TAC-26 Impersonation`. |
| 113 | +- `TEQ-024 Credential Pinning`: Removed `TAC-08 Mitigation Bypass` as parent and replaced with `TAC-26 Impersonation`. |
| 114 | +- `TEQ-025 Certificate Abuse`: Removed `TAC-08 Mitigation Bypass` as parent and replaced with `TAC-27 Session Manipulation`. |
| 115 | +- `TEQ-027 User Agent Spoofing`: Minor wording changes. Removed `TAC-09 Human Emulation` and `TAC-10 Proxying` as parents and replaced with `TAC-33 Device Emulation`. |
| 116 | +- `TEQ-028 Device Fingerprint Emulation` -> `TEQ-028 Device Configuration Emulation`: Minor wording changes. Renamed. Removed `TAC-09 Human Emulation` as parent and replaced with `TAC-33 Device Emulation`. |
| 117 | +- `TEQ-029 Notification Hijack`: Removed `TAC-14 Fake Interaction` as parent. |
| 118 | +- `TEQ-030 IP Rotation`: Added `TAC-32 Geolocation Spoofing` as parent. |
| 119 | +- `TEQ-033 Smurfing` -> `TEQ-033 Multi-Accounting`: Renamed. |
| 120 | +- `TEQ-036 Social Media Creation`: Major wording changes. Removed `TAC-12 Account Creation` as parent and replaced with `TAC-38 Identity Acquisition`. |
| 121 | +- `TEQ-037 Email Generator`: Removed `TAC-12 Account Creation` as parent and replaced with `TAC-38 Identity Acquisition`. |
| 122 | +- `TEQ-038 Call/SMS Generator`: Removed `TAC-12 Account Creation` as parent and replaced with `TAC-38 Identity Acquisition`. |
| 123 | +- `TEQ-039 Virtual Wallet Creation`: Removed `TAC-12 Account Creation` as parent and replaced with `TAC-38 Identity Acquisition`. |
| 124 | +- `TEQ-040 Credential Cracking`: Minor wording changes. |
| 125 | +- `TEQ-041 Credential Stuffing`: Added `TAC-41 Account Enumeration` as parent. |
| 126 | +- `TEQ-045 Written Interaction` -> `TEQ-045 Content Posting`: Minor wording changes. Renamed. |
| 127 | +- `TEQ-047 Form Filling` -> `TEQ-047 Form Submission`: Major wording changes. Renamed. |
| 128 | +- `TEQ-049 Automated Add to Cart`: Removed `TAC-15 Stock Purchase`, `TAC-16 Spinning` and `TAC-10 Sniping` as parents and replaced with `TAC-40 Add to Cart`. |
| 129 | +- `TEQ-050 Automated Purchase`: Removed `TAC-16 Spinning` and `TAC-10 Sniping` as parents. |
| 130 | +- `TEQ-051 Stock Price Manipulation` -> `TEQ-051 Price Manipulation`: Minor wording changes. Renamed. |
| 131 | +- `TEQ-053 Inventory Hoarding`: Major wording changes. Removed `TAC-16 Spinning` as parent and replaced with `TAC-39 Inventory Manipulation`. |
| 132 | +- `TEQ-054 Transfer of Cart`: Removed `TAC-16 Spinning` as parent and replaced with `TAC-29 Session Transfer`. |
| 133 | +- `TEQ-055 Automated Sale`: Major wording changes. Removed `TAC-16 Spinning` and `TAC-17 Sniping` as parents. |
| 134 | +- `TEQ-056 Automated Bid`: Major wording changes. Removed `TAC-17 Sniping` as parent and replaced with `TAC-15 Purchase`. |
| 135 | +- `TEQ-061 Credit/Debit Card Abuse`: Minor wording changes. |
| 136 | +- `TEQ-062 Gift Card Abuse`: Major wording changes. |
| 137 | +- `TEQ-063 Loyalty Points Abuse`: Minor wording changes. |
| 138 | +- `TEQ-061 Buy Now Pay Later Abuse`: Major wording changes. |
| 139 | +- `TEQ-065 ATS Fraud` -> `TEQ-065 Bank Transfer`: Renamed. |
| 140 | +- `TEQ-066 Automated Advertisement of Stock` -> `TEQ-066 Inventory Information Release`: Minor wording changes. Renamed. Removed `TAC-21 Exfiltration` as parent and replaced with `TAC-43 Information Release` |
| 141 | +- `TEQ-067 Credential Dumping`: Major wording changes. Removed `TAC-21 Exfiltration` as parent and replaced with `TAC-43 Information Release` |
| 142 | +- `TEQ-069 Payment Detail Dumping`: Removed `TAC-21 Exfiltration` as parent and replaced with `TAC-43 Information Release` |
| 143 | +- `TEQ-070 PII Dumping`: Removed `TAC-21 Exfiltration` as parent and replaced with `TAC-43 Information Release` |
| 144 | +- `TEQ-072 Jigging` -> `TEQ-072 Address Manipulation`: Minor wording changes. Renamed. |
| 145 | +- `TEQ-074 Driver Intercept` -> `TEQ-074 Driver Redirect`: Major wording changes. Renamed. |
| 146 | +- `TEQ-076 Manual Sale`: Major wording changes. |
| 147 | +- `TEQ-078 Valid Accounts`: Minor wording changes. |
| 148 | +- `TEQ-079 Fund Withdrawal` -> `TEQ-079 Account Balance Withdrawal`: Renamed. |
| 149 | + |
| 150 | + |
| 151 | + |
| 152 | +### Retired |
| 153 | +- `TEQ-007 Fake Credibility Generation`: Replaced by `TAC-35 Fake Credibility Generation` |
| 154 | +- `TEQ-009 Command & Control` |
| 155 | +- `TEQ-017 Technical Reconnaissance`: Replaced by `TAC-34 Attack Surface Identification` and `TAC-44 Vulnerability Identification` |
| 156 | +- `TEQ-043 Comment Flooding`: Merged into `TEQ-045 Content Posting` |
| 157 | +- `TEQ-048 Overlay Attack` |
| 158 | +- `TEQ-052 Distributed Stock Purchase` |
| 159 | +- `TEQ-057 Pre-Release Buying` |
| 160 | +- `TEQ-068 API Information Flow Exfiltration` |
| 161 | + |
| 162 | +## Killchains |
| 163 | + |
| 164 | +### New |
| 165 | +- None |
| 166 | + |
| 167 | +### Updated |
| 168 | +- Updated all killchains to reflect the new and updated tactics and techniques |
| 169 | + |
| 170 | +### Retired |
| 171 | +- None |
| 172 | + |
| 173 | +## Website |
| 174 | +- Renamed framework from Business Logic *Attack* Definition Framework to Business Logic *Abuse* Definition Framework and updated terminology accordingly. The term attack could imply an immediate need for remediation and force a binary response, such as blocking or not blocking. In cases of business logic abuse, multiple levers could be pulled to assist companies facing these challenges. Customers often need to make a business decision, not just a security decision |
| 175 | +- Tactics and techniques in Matrix and Killchain views are now displayed in alphabetical order |
0 commit comments