Esc
Restore Object
Definition
Restoring an object for an entity to access. This is the broadest class for object restoral.
Artifact Relationships:
This defensive technique is related to specific artifacts. Click the artifact node for more information.
Technique Subclasses
There are 7 techniques in this category, Restore Object.
| Name | ID | Definition | Synonyms |
|---|---|---|---|
| Restore Object | D3-RO | Restoring an object for an entity to access. This is the broadest class for object restoral. | |
| - Restore Software | D3-RS | Restoring software to a host. | |
| - Restore Configuration | D3-RC | Restoring an software configuration. | |
| - Restore Database | D3-RD | Restoring the data in a database. | |
| - Restore Email | D3-RE | Restoring an email for an entity to access. | |
| - Restore Disk Image | D3-RDI | Restoring a previously captured disk image a hard drive. | |
| - Restore File | D3-RF | Restoring a file for an entity to access. |
Related Offensive Techniques:
These mappings are inferred, experimental, and will improve as the
knowledge graph grows.
These offensive techniques are determined related because of the way this defensive technique,, , , and .
Privilege Escalation
Process Injection
Event Triggered Execution
Boot or Logon Autostart Execution
Abuse Elevation Control Mechanism
Access Token Manipulation
Domain or Tenant Policy Modification
Boot or Logon Initialization Scripts
Create or Modify System Process
Scheduled Task/Job
Impact
Inhibit System Recovery
Service Stop
Data Manipulation
Data Encrypted for Impact
Persistence
Compromise Host Software Binary
Pre-OS Boot
Event Triggered Execution
Office Application Startup
Software Extensions
Server Software Component
Boot or Logon Autostart Execution
Modify Authentication Process
Boot or Logon Initialization Scripts
Create or Modify System Process
Scheduled Task/Job
Modify Registry
Initial Access
Supply Chain Compromise
Phishing
Execution
Hijack Execution Flow
Trusted Developer Utilities Proxy Execution
Software Deployment Tools
Command and Scripting Interpreter
Scheduled Task/Job
User Execution
Stealth
Pre-OS Boot
Hijack Execution Flow
Rootkit
Trusted Developer Utilities Proxy Execution
Hide Artifacts
Virtualization/Sandbox Evasion
System Binary Proxy Execution
Impair Defenses
Access Token Manipulation
XSL Script Processing
Process Injection
Masquerading
Obfuscated Files or Information
Deobfuscate/Decode Files or Information
Indicator Removal
Collection
Input Capture
Data from Information Repositories
Email Collection
Archive Collected Data
Data from Local System
Automated Collection
Data Staged
Lateral Movement
Software Deployment Tools
Internal Spearphishing
Credential Access
Input Capture
Exploitation for Credential Access
Steal or Forge Authentication Certificates
Modify Authentication Process
Unsecured Credentials
Credentials from Password Stores
OS Credential Dumping
Forced Authentication
Discovery
Virtualization/Sandbox Evasion
Cloud Service Dashboard
Cloud Service Discovery
Group Policy Discovery
Software Discovery
System Location Discovery
System Network Configuration Discovery
System Owner/User Discovery
Remote System Discovery
File and Directory Discovery
Query Registry
Exfiltration
Exfiltration Over C2 Channel
Exfiltration Over Alternative Protocol
Defense Impairment
Modify Authentication Process
File and Directory Permissions Modification
Modify Cloud Compute Infrastructure
Modify Cloud Resource Hierarchy
Domain or Tenant Policy Modification
Subvert Trust Controls
Modify Registry
Rogue Domain Controller
Command and Control
Encrypted Channel
Application Layer Protocol