Esc
Restore File
Artifact Relationships:
This defensive technique is related to specific artifacts. Click the artifact node for more information.
Technique Subclasses
There are 2 techniques in this category, Restore File.
| Name | ID | Definition | Synonyms |
|---|---|---|---|
| Restore File | D3-RF | Restoring a file for an entity to access. | |
| - Restore Email | D3-RE | Restoring an email for an entity to access. |
Related Offensive Techniques:
These mappings are inferred, experimental, and will improve as the
knowledge graph grows.
These offensive techniques are determined related because of the way this defensive technique,, .
Lateral Movement
Internal Spearphishing
Software Deployment Tools
Collection
Email Collection
Archive Collected Data
Automated Collection
Data Staged
Data from Local System
Credential Access
OS Credential Dumping
Modify Authentication Process
Unsecured Credentials
Credentials from Password Stores
Forced Authentication
Steal or Forge Authentication Certificates
Stealth
Process Injection
Obfuscated Files or Information
Deobfuscate/Decode Files or Information
Hijack Execution Flow
Masquerading
Indicator Removal
Rootkit
Hide Artifacts
XSL Script Processing
System Binary Proxy Execution
Impair Defenses
Trusted Developer Utilities Proxy Execution
Privilege Escalation
Process Injection
Abuse Elevation Control Mechanism
Event Triggered Execution
Boot or Logon Autostart Execution
Create or Modify System Process
Scheduled Task/Job
Boot or Logon Initialization Scripts
Execution
Command and Scripting Interpreter
User Execution
Hijack Execution Flow
Software Deployment Tools
Scheduled Task/Job
Trusted Developer Utilities Proxy Execution
Persistence
Event Triggered Execution
Boot or Logon Autostart Execution
Modify Authentication Process
Create or Modify System Process
Scheduled Task/Job
Boot or Logon Initialization Scripts
Server Software Component
Office Application Startup
Defense Impairment
Modify Authentication Process
Discovery
File and Directory Discovery
System Owner/User Discovery
Remote System Discovery
System Network Configuration Discovery
Command and Control
Encrypted Channel
Application Layer Protocol
Exfiltration
Exfiltration Over C2 Channel
Exfiltration Over Alternative Protocol
References
All
Guideline
The following references were used to develop the Restore File knowledge-base article.
(Note: the consideration of references does not imply specific functionality exists in an offering.)
Cybersecurity Incident & Vulnerability Response Playbooks
Reference Type: Guideline Organization: Cybersecurity and Infrastructure Security Agency Author: Cybersecurity and Infrastructure Security Agency