// Technique Heatmap 30-Day Rolling · Updated June 2, 2026
Initial Access
T1566.001 ×14
T1566.002 ×8
T1190 ×8
T1078.004 ×11
Execution
T1059.001 ×9
T1059.007 ×5
T1204.002 ×7
Credential Access
T1111 ×9
T1539 ×7
T1528 ×6
T1621 ×4
Defense Evasion
T1036.005 ×6
T1027 ×7
T1564.008 ×5
Collection / Exfiltration
T1114.002 ×5
T1041 ×4
T1056.001 ×3
Command & Control
T1102 ×6
T1568.002 ×4
T1534 ×3
High (×9+)
Medium-High (×6–8)
Medium (×3–5)
Low (×1–2)
// Top 10 TTPs 30-Day Frequency Ranking
| Technique ID | Name | Tactic | Frequency | Trend |
|---|---|---|---|---|
| T1566.001 | Spearphishing Link | Initial Access | ×14 | ↑ |
| T1078.004 | Valid Cloud Accounts | Defense Evasion | ×11 | ↑ |
| T1111 | MFA Interception | Credential Access | ×9 | → |
| T1059.001 | PowerShell | Execution | ×9 | ↑ |
| T1190 | Exploit Public-Facing App | Initial Access | ×8 | ↑ |
| T1566.002 | Spearphishing via Service | Initial Access | ×8 | → |
| T1027 | Obfuscated Files | Defense Evasion | ×7 | ↑ |
| T1539 | Steal Web Session Cookie | Credential Access | ×7 | → |
| T1204.002 | Malicious File | Execution | ×7 | ↑ |
| T1528 | Steal Application Access Token | Credential Access | ×6 | ↓ |