04bb8e3d-1670-46ab-a3f1-5cee64da29b6 | T1001.002 | windows | powershell | Embedded Script in Image Execution via Extract-Invoke-PSImage |
c7921449-8b62-4c4d-8a83-d9281ac0190b | T1001.002 | windows | powershell | Steganographic Tarball Embedding |
0b207037-813c-4444-ac3f-b597cf280a67 | T1003 | windows | powershell | Send NTLM Hash with RPC Test Connection |
42510244-5019-48fa-a0e5-66c3b76e6049 | T1003 | windows | powershell | Retrieve Microsoft IIS Service Account Credentials Using AppCmd (using config) |
6c7a4fd3-5b0b-4b30-a93e-39411b25d889 | T1003 | windows | powershell | Retrieve Microsoft IIS Service Account Credentials Using AppCmd (using list) |
84113186-ed3c-4d0d-8a3c-8980c86c1f4a | T1003 | windows | powershell | Dump Credential Manager using keymgr.dll and rundll32.exe |
96345bfc-8ae7-4b6a-80b7-223200f24ef9 | T1003 | windows | command_prompt | Gsecdump |
9e2173c0-ba26-4cdf-b0ed-8c54b27e3ad6 | T1003 | windows | powershell | Credential Dumping with NPPSpy |
d400090a-d8ca-4be0-982e-c70598a23de9 | T1003 | windows | powershell | Dump svchost.exe to gather RDP credentials |
0be2230c-9ab3-4ac2-8826-3199b9a0ebf8 | T1003.001 | windows | command_prompt | Dump LSASS.exe Memory using ProcDump |
2536dee2-12fb-459a-8c37-971844fa73be | T1003.001 | windows | powershell | Dump LSASS.exe Memory using comsvcs.dll |
453acf13-1dbd-47d7-b28a-172ce9228023 | T1003.001 | windows | command_prompt | Offline Credential Theft With Mimikatz |
47a539d1-61b9-4364-bf49-a68bc2a95ef0 | T1003.001 | windows | powershell | Dump LSASS.exe using lolbin rdrleakdiag.exe |
6502c8f0-b775-4dbd-9193-1298f56b6781 | T1003.001 | windows | powershell | Dump LSASS.exe Memory using Out-Minidump.ps1 |
66fb0bc1-3c3f-47e9-a298-550ecfefacbc | T1003.001 | windows | powershell | Powershell Mimikatz |
7ae7102c-a099-45c8-b985-4c7a2d05790d | T1003.001 | windows | command_prompt | Dump LSASS.exe Memory using direct system calls and API unhooking |
7cede33f-0acd-44ef-9774-15511300b24b | T1003.001 | windows | command_prompt | Create Mini Dump of LSASS.exe using ProcDump |
86fc3f40-237f-4701-b155-81c01c48d697 | T1003.001 | windows | powershell | Dump LSASS.exe using imported Microsoft DLLs |
9d0072c8-7cca-45c4-bd14-f852cfa35cf0 | T1003.001 | windows | powershell | Dump LSASS with createdump.exe from .Net v5 |
c37bc535-5c62-4195-9cc3-0517673171d8 | T1003.001 | windows | command_prompt | LSASS read with pypykatz |
dddd4aca-bbed-46f0-984d-e4c5971c51ea | T1003.001 | windows | command_prompt | Dump LSASS.exe Memory using NanoDump |
eb5adf16-b601-4926-bca7-dad22adffb37 | T1003.001 | windows | command_prompt | Dump LSASS.exe Memory through Silent Process Exit |
0c0f5f06-166a-4f4d-bb4a-719df9a01dbb | T1003.002 | windows | powershell | WinPwn - Loot local Credentials - Dump SAM-File for NTLM Hashes |
21df41be-cdd8-4695-a650-c3981113aa3c | T1003.002 | windows | command_prompt | Dumping of SAM, creds, and secrets(Reg Export) |
5c2571d0-1572-416d-9676-812e64ca9f44 | T1003.002 | windows | command_prompt | Registry dump of SAM, creds, and secrets |
804f28fc-68fc-40da-b5a2-e9d0bce5c193 | T1003.002 | windows | powershell | PowerDump Hashes and Usernames from Registry |
9d77fed7-05f8-476e-a81b-8ff0472c64d0 | T1003.002 | windows | powershell | dump volume shadow copy hives with System.IO.File |
a90c2f4d-6726-444e-99d2-a00cd7c20480 | T1003.002 | windows | command_prompt | esentutl.exe SAM copy |
a96872b2-cbf3-46cf-8eb4-27e8c0e85263 | T1003.002 | windows | command_prompt | Registry parse with pypykatz |
eeb9751a-d598-42d3-b11c-c122d9c3f6c7 | T1003.002 | windows | command_prompt | dump volume shadow copy hives with certutil |
21748c28-2793-4284-9e07-d6d028b66702 | T1003.003 | windows | command_prompt | Create Symlink to Volume Shadow Copy |
21c7bf80-3e8b-40fa-8f9d-f5b194ff2865 | T1003.003 | windows | command_prompt | Create Volume Shadow Copy remotely (WMI) with esentutl |
224f7de0-8f0a-4a94-b5d8-989b036c86da | T1003.003 | windows | command_prompt | Create Volume Shadow Copy with WMI |
2364e33d-ceab-4641-8468-bfb1d7cc2723 | T1003.003 | windows | command_prompt | Dump Active Directory Database with NTDSUtil |
542bb97e-da53-436b-8e43-e0a7d31a6c24 | T1003.003 | windows | powershell | Create Volume Shadow Copy with Powershell |
b385996c-0e7d-4e27-95a4-aca046b119a7 | T1003.003 | windows | command_prompt | Create Volume Shadow Copy with diskshadow |
c6237146-9ea6-4711-85c9-c56d263a6b03 | T1003.003 | windows | command_prompt | Copy NTDS.dit from Volume Shadow Copy |
c7be89f7-5d06-4321-9f90-8676a77e0502 | T1003.003 | windows | powershell | Copy NTDS in low level NTFS acquisition via fsutil |
d893459f-71f0-484d-9808-ec83b2b64226 | T1003.003 | windows | command_prompt | Create Volume Shadow Copy remotely with WMI |
dcebead7-6c28-4b4b-bf3c-79deb1b1fc7f | T1003.003 | windows | command_prompt | Create Volume Shadow Copy with vssadmin |
f57cb283-c131-4e2f-8a6c-363d575748b2 | T1003.003 | windows | powershell | Copy NTDS in low level NTFS acquisition via MFT parsing |
2dfa3bff-9a27-46db-ab75-7faefdaca732 | T1003.004 | windows | powershell | Dump Kerberos Tickets from LSA using dumper.ps1 |
55295ab0-a703-433b-9ca4-ae13807de12f | T1003.004 | windows | command_prompt | Dumping LSA Secrets |
56506854-89d6-46a3-9804-b7fde90791f9 | T1003.005 | windows | command_prompt | Cached Credential Dump via Cmdkey |
129efd28-8497-4c87-a1b0-73b9a870ca3e | T1003.006 | windows | command_prompt | DCSync (Active Directory) |
a0bced08-3fc5-4d8b-93b7-e8344739376e | T1003.006 | windows | powershell | Run DSInternals Get-ADReplAccount |
cfb6d400-a269-4c06-a347-6d88d584d5f7 | T1005 | macos | sh | Copy Apple Notes database files using AppleScript |
d3d9af44-b8ad-4375-8b0a-4bff4b7e419c | T1005 | windows | powershell | Search files of interest and save them to a single zip file (Windows) |
88f6327e-51ec-4bbf-b2e8-3fea534eab8b | T1006 | windows | powershell | Read volume boot sector via DOS device path (PowerShell) |
51f17016-d8fa-4360-888a-df4bf92c4a04 | T1007 | windows | command_prompt | Get-Service Execution |
5f864a3f-8ce9-45c0-812c-bdf7d8aeacc3 | T1007 | windows | command_prompt | System Service Discovery - net.exe |
7cd7eaa3-9ccc-460d-96d2-c6fb13e6d58a | T1007 | windows | command_prompt | System Service Discovery - Windows Scheduled Tasks (schtasks) |
89676ba1-b1f8-47ee-b940-2e1a113ebc71 | T1007 | windows | command_prompt | System Service Discovery |
9b378962-a75e-4856-b117-2503d6dcebba | T1007 | macos | sh | System Service Discovery - macOS launchctl |
d70d82bd-bb00-4837-b146-b40d025551b2 | T1007 | windows | powershell | System Service Discovery - Services Registry Enumeration |
fe94a1c3-3e22-4dc9-9fdf-3a8bdbc10dc4 | T1010 | windows | command_prompt | List Process Main Windows - C# .NET |
0434d081-bb32-42ce-bcbb-3548e4f2628f | T1012 | windows | powershell | Query Registry with Powershell cmdlets |
0d80d088-a84c-4353-af1a-fc8b439f1564 | T1012 | windows | powershell | Enumerate COM Objects in Registry with Powershell |
5c784969-1d43-4ac7-8c3d-ed6d025ed10d | T1012 | windows | command_prompt | Check Software Inventory Logging (SIL) status via Registry |
6fb4c4c5-f949-4fd2-8af5-ddbc61595223 | T1012 | windows | command_prompt | Reg query for AlwaysInstallElevated status |
8f7578c4-9863-4d83-875c-a565573bbdf0 | T1012 | windows | command_prompt | Query Registry |
96257079-cdc1-4aba-8705-3146e94b6dce | T1012 | windows | command_prompt | Inspect SystemStartOptions Value in Registry |
038263cb-00f4-4b0a-98ae-0696c67e1752 | T1016 | windows | command_prompt | List Windows Firewall Rules |
121de5c6-5818-4868-b8a7-8fd07c455c1b | T1016 | windows | command_prompt | Qakbot Recon |
34557863-344a-468f-808b-a1bfb89b4fa9 | T1016 | windows | command_prompt | DNS Server Discovery Using nslookup |
4b467538-f102-491d-ace7-ed487b853bf5 | T1016 | windows | powershell | List Open Egress Ports |
970ab6a1-0157-4f3f-9a73-ec4166754b23 | T1016 | windows | command_prompt | System Network Configuration Discovery on Windows |
9bb45dd7-c466-4f93-83a1-be30e56033ee | T1016 | windows | command_prompt | Adfind - Enumerate Active Directory Subnet Objects |
c141bbdb-7fca-4254-9fd6-f47e79447e17 | T1016 | linux, macos | sh | System Network Configuration Discovery |
dafaf052-5508-402d-bf77-51e0700c02e2 | T1016 | windows | command_prompt | System Network Configuration Discovery (TrickBot Style) |
ff1d8c25-2aa4-4f18-a425-fede4a41ee88 | T1016 | macos | bash | List macOS Firewall Rules |
7c35779d-42ec-42ab-a283-6255b28e9d68 | T1016.001 | windows | powershell | Check internet connection using Test-NetConnection in PowerShell (TCP-HTTP) |
be8f4019-d8b6-434c-a814-53123cdcc11e | T1016.001 | linux, macos | bash | Check internet connection using ping freebsd, linux or macos |
d9c32b3b-7916-45ad-aca5-6c902da80319 | T1016.001 | windows | powershell | Check internet connection using Test-NetConnection in PowerShell (TCP-SMB) |
e184b6bd-fb28-48aa-9a59-13012e33d7dc | T1016.001 | windows | command_prompt | Check internet connection using ping Windows |
f8160cde-4e16-4c8b-8450-6042d5363eb0 | T1016.001 | windows | powershell | Check internet connection using Test-NetConnection in PowerShell (ICMP-Ping) |
53cf1903-0fa7-4177-ab14-f358ae809eec | T1016.002 | windows | command_prompt | Enumerate Stored Wi-Fi Profiles And Passwords via netsh |
2d5a61f5-0447-4be4-944a-1f8530ed6574 | T1018 | windows | command_prompt | Remote System Discovery - arp |
52ab5108-3f6f-42fb-8ba3-73bc054f22c8 | T1018 | windows | command_prompt | Remote System Discovery - nltest |
5838c31e-a0e2-4b9f-b60a-d79d2cb7995e | T1018 | windows | command_prompt | Adfind - Enumerate Active Directory Domain Controller Objects |
5843529a-5056-4bc1-9c13-a311e2af4ca0 | T1018 | windows | command_prompt | Remote System Discovery - net group Domain Controller |
64ede6ac-b57a-41c2-a7d1-32c6cd35397d | T1018 | windows | powershell | Enumerate Active Directory Computers with ADSISearcher |
6db1f57f-d1d5-4223-8a66-55c9c65a9592 | T1018 | windows | command_prompt | Remote System Discovery - ping sweep |
85321a9c-897f-4a60-9f20-29788e50bccd | T1018 | windows | command_prompt | Remote System Discovery - net |
95e19466-469e-4316-86d2-1dc401b5a959 | T1018 | windows | command_prompt | Remote System Discovery - adidnsdump |
962a6017-1c09-45a6-880b-adc9c57cb22e | T1018 | windows | powershell | Enumerate domain computers within Active Directory using DirectorySearcher |
96db2632-8417-4dbb-b8bb-a8b92ba391de | T1018 | linux, macos | sh | Remote System Discovery - sweep |
97e89d9e-e3f5-41b5-a90f-1e0825df0fdf | T1018 | windows | powershell | Enumerate Active Directory Computers with Get-AdComputer |
a889f5be-2d54-4050-bd05-884578748bb4 | T1018 | windows | command_prompt | Adfind - Enumerate Active Directory Computer Objects |
acb6b1ff-e2ad-4d64-806c-6c35fe73b951 | T1018 | linux, macos | sh | Remote System Discovery - arp nix |
b8147c9a-84db-4ec1-8eee-4e0da75f0de5 | T1018 | windows | powershell | Enumerate Remote Hosts with Netscan |
b9d2e8ca-5520-4737-8076-4f08913da2c4 | T1018 | windows | powershell | Get-DomainController with PowerView |
baa01aaa-5e13-45ec-8a0d-e46c93c9760f | T1018 | windows | powershell | Remote System Discovery - nslookup |
e3cf5123-f6c9-4375-bdf2-1bb3ba43a1ad | T1018 | windows | powershell | Get-WmiObject to Enumerate Domain Controllers |
f1bf6c8f-9016-4edf-aff9-80b65f5d711f | T1018 | windows | command_prompt | Remote System Discovery - net group Domain Computers |
5b380e96-b0ef-4072-8a8e-f194cb9eb9ac | T1020 | windows | powershell | Exfiltration via Encrypted FTP |
9c780d3d-3a14-4278-8ee5-faaeb2ccfbe0 | T1020 | windows | powershell | IcedID Botnet HTTP PUT |
01d1c6c0-faf0-408e-b368-752a02285cb2 | T1021.001 | windows | command_prompt | Disable NLA for RDP via Command Prompt |
2f840dd4-8a2e-4f44-beb3-6b2399ea3771 | T1021.001 | windows | powershell | Changing RDP Port to Non Standard Port via Powershell |
355d4632-8cb9-449d-91ce-b566d0253d3e | T1021.001 | windows | powershell | RDP to DomainController |
74ace21e-a31c-4f7d-b540-53e4eb6d1f73 | T1021.001 | windows | command_prompt | Changing RDP Port to Non Standard Port via Command_Prompt |
0eb03d41-79e4-4393-8e57-6344856be1cf | T1021.002 | windows | command_prompt | Copy and Execute File with PsExec |
3386975b-367a-4fbb-9d77-4dcf3639ffd3 | T1021.002 | windows | command_prompt | Map admin share |
514e9cd7-9207-4882-98b1-c8f791bae3c5 | T1021.002 | windows | powershell | Map Admin Share PowerShell |
d41aaab5-bdfe-431d-a3d5-c29e9136ff46 | T1021.002 | windows | command_prompt | Execute command writing output to local Admin Share |
505f24be-1c11-4694-b614-e01ae1cd2570 | T1021.003 | windows | powershell | PowerShell Lateral Movement Using Excel Application Object |
6dc74eb1-c9d6-4c53-b3b5-6f50ae339673 | T1021.003 | windows | powershell | PowerShell Lateral Movement using MMC20 |
280812c8-4dae-43e9-a74e-1d08ab997c0e | T1021.004 | windows | command_prompt | ESXi - Enable SSH via VIM-CMD |
8f6c14d1-f13d-4616-b7fc-98cc69fe56ec | T1021.004 | windows | powershell | ESXi - Enable SSH via PowerCLI |
8a930abe-841c-4d4f-a877-72e9fe90b9ea | T1021.005 | macos | sh | Enable Apple Remote Desktop Agent |
5295bd61-bd7e-4744-9d52-85962a4cf2d6 | T1021.006 | windows | powershell | Remote Code Execution with PS Credentials Using Invoke-Command |
9059e8de-3d7d-4954-a322-46161880b9cf | T1021.006 | windows | powershell | Enable Windows Remote Management |
efe86d95-44c4-4509-ae42-7bfd9d1f5b3d | T1021.006 | windows | powershell | WinRM Access with Evil-WinRM |
0b29f7e3-a050-44b7-bf05-9fb86af1ec2e | T1025 | windows | command_prompt | Identify Documents on USB and Removable Media via PowerShell |
129edb75-d7b8-42cd-a8ba-1f3db64ec4ad | T1027 | windows | powershell | DLP Evasion via Sensitive Data in VBA Macro over email |
450e7218-7915-4be4-8b9b-464a49eafcec | T1027 | windows | powershell | Execute base64-encoded PowerShell from Windows Registry |
6683baf0-6e77-4f58-b114-814184ea8150 | T1027 | windows | powershell | Obfuscated PowerShell Command via Character Array |
7e47ee60-9dd1-4269-9c4f-97953b183268 | T1027 | windows | powershell | Snake Malware Encrypted crmlog file |
8b3f4ed6-077b-4bdd-891c-2d237f19410f | T1027 | windows | powershell | Obfuscated Command in PowerShell |
a50d5a97-2531-499e-a1de-5544c74432c6 | T1027 | windows | powershell | Execute base64-encoded PowerShell |
e2d85e66-cb66-4ed7-93b1-833fc56c9319 | T1027 | windows | powershell | DLP Evasion via Sensitive Data in VBA Macro over HTTP |
f45df6be-2e1e-4136-a384-8f18ab3826fb | T1027 | linux, macos | sh | Decode base64 Data into Script |
f8c8a909-5f29-49ac-9244-413936ce6d1f | T1027 | windows | command_prompt | Execution from Compressed File |
fad04df1-5229-4185-b016-fb6010cd87ac | T1027 | windows | command_prompt | Execution from Compressed JScript File |
e22a9e89-69c7-410f-a473-e6c212cd2292 | T1027.001 | linux, macos | sh | Pad Binary to Change Hash using truncate command - Linux/macOS |
ffe2346c-abd5-4b45-a713-bf5f1ebd573a | T1027.001 | linux, macos | sh | Pad Binary to Change Hash - Linux/macOS dd |
4d46e16b-5765-4046-9f25-a600d3e65e4d | T1027.002 | macos | sh | Binary packed by UPX, with modified headers |
b16ef901-00bb-4dda-b4fc-a04db5067e20 | T1027.002 | macos | sh | Binary simply packed by UPX |
453614d8-3ba6-4147-acc0-7ec4b3e1faef | T1027.004 | windows | powershell | Dynamic C# Compile |
78bd3fa7-773c-449e-a978-dc1f1500bc52 | T1027.004 | linux, macos | sh | Go compile |
d0377aa6-850a-42b2-95f0-de558d80be57 | T1027.004 | linux, macos | sh | C compile |
da97bb11-d6d0-4fc1-b445-e443d1346efe | T1027.004 | linux, macos | sh | CC compile |
ffcdbd6a-b0e8-487d-927a-09127fe9a206 | T1027.004 | windows | command_prompt | Compile After Delivery using csc.exe |
30cbeda4-08d9-42f1-8685-197fad677734 | T1027.006 | windows | powershell | HTML Smuggling Remote Payload |
578025d5-faa9-4f6d-8390-aae739d507e1 | T1027.007 | windows | powershell | Dynamic API Resolution-Ninja-syscall |
7693ccaa-8d64-4043-92a5-a2eb70359535 | T1027.013 | linux, macos, windows | powershell | Decode Eicar File and Write to File |
b404caaa-12ce-43c7-9214-62a531c044f7 | T1027.013 | linux, macos, windows | powershell | Decrypt Eicar File and Write to File |
c2ca068a-eb1e-498f-9f93-3d554c455916 | T1027.013 | linux, macos | bash | Password-Protected ZIP Payload Extraction and Execution |
125b1b41-bcef-42c3-acaa-a44303e3ffc1 | T1027.018 | windows | powershell | Invisible Unicode in Environment Variables |
28e30460-ce18-4974-8e6a-5a2bb74e5c07 | T1027.018 | windows | powershell | Binary Masquerading via Invisible Unicode |
5917f0fd-c6d4-4af8-b89d-f3db06349c49 | T1027.018 | windows | powershell | File Masquerading with Zero-Width Space |
ab936c51-10f4-46ce-9144-e02137b2016a | T1030 | linux, macos | sh | Data Transfer Size Limits |
f0287b58-f4bc-40f6-87eb-692e126e7f8f | T1030 | windows | powershell | Network-Based Data Transfer in Small Chunks |
1392bd0f-5d5a-429e-81d9-eb9d4d4d5b3b | T1033 | windows | powershell | GetCurrent User with PowerShell Script |
29857f27-a36f-4f7e-8084-4557cd6207ca | T1033 | windows | powershell | Find computers where user has session - Stealth mode (PowerView) |
2a9b677d-a230-44f4-ad86-782df1ef108c | T1033 | linux, macos | sh | System Owner/User Discovery |
3d257a03-eb80-41c5-b744-bb37ac7f65c7 | T1033 | windows | powershell | System Discovery - SocGholish whoami |
4c4959bf-addf-4b4a-be86-8d09cc1857aa | T1033 | windows | command_prompt | System Owner/User Discovery |
ba38e193-37a6-4c41-b214-61b33277fe36 | T1033 | windows | command_prompt | System Owner/User Discovery Using Command Prompt |
dcb6cdee-1fb0-4087-8bf8-88cfd136ba51 | T1033 | windows | powershell | User Discovery With Env Vars PowerShell Script |
4449c89b-ec82-43a4-89c1-91e2f1abeecc | T1036 | windows | powershell | Malware Masquerading and Execution from Zip File |
51005ac7-52e2-45e0-bdab-d17c6d4916cd | T1036 | windows | powershell | System File Copied to Unusual Location |
d7c03c7e-31cd-43c7-859a-ec053f73b23a | T1036.002 | windows | powershell | Masquerading: Right-to-Left Override Batch File Creation and Execution |
dac81590-8b63-4769-8b82-310beedc4f09 | T1036.002 | windows | powershell | Masquerading: RTLO Masqueraded File Download and Execution |
24136435-c91a-4ede-9da1-8b284a1c1a23 | T1036.003 | windows | command_prompt | Masquerading - wscript.exe running as svchost.exe |
3a2a578b-0a01-46e4-92e3-62e2859b42f0 | T1036.003 | windows | command_prompt | Masquerading - cscript.exe running as notepad.exe |
5ba5a3d1-cf3c-4499-968a-a93155d1f717 | T1036.003 | windows | command_prompt | Masquerading as Windows LSASS process |
83810c46-f45e-4485-9ab6-8ed0e9e6ed7f | T1036.003 | windows | command_prompt | Malicious process Masquerading as LSM.exe |
ac9d0fc3-8aa8-4ab5-b11f-682cd63b40aa | T1036.003 | windows | command_prompt | Masquerading - powershell.exe running as taskhostw.exe |
bc15c13f-d121-4b1f-8c7d-28d95854d086 | T1036.003 | windows | powershell | Masquerading - non-windows exe running as windows exe |
c3d24a39-2bfe-4c6a-b064-90cd73896cb0 | T1036.003 | windows | powershell | Masquerading - windows exe running as different windows exe |
b721c6ef-472c-4263-a0d9-37f1f4ecff66 | T1036.004 | windows | command_prompt | Creating W32Time similar named service using sc |
f9f2fe59-96f7-4a7d-ba9f-a9783200d4c9 | T1036.004 | windows | command_prompt | Creating W32Time similar named service using schtasks |
03ae82a6-9fa0-465b-91df-124d8ca5c4e8 | T1036.005 | windows | powershell | Masquerading cmd.exe as VEDetector.exe |
35eb8d16-9820-4423-a2a1-90c4f5edd9ca | T1036.005 | windows | powershell | Masquerade as a built-in system executable |
812c3ab8-94b0-4698-a9bf-9420af23ce24 | T1036.005 | linux, macos | sh | Execute a process from a directory masquerading as the current parent directory |
b95ce2eb-a093-4cd8-938d-5258cef656ea | T1036.006 | linux, macos | sh | Space After Filename |
c7fa0c3b-b57f-4cba-9118-863bf4e653fc | T1036.007 | windows | command_prompt | File Extension Masquerading |
d6042746-07d4-4c92-9ad8-e644c114a231 | T1037.001 | windows | command_prompt | Logon Scripts |
97a48daa-8bca-4bc0-b1a9-c1d163e762de | T1037.004 | macos | bash | rc.common |
10cf5bec-49dd-4ebf-8077-8f47e420096f | T1037.005 | macos | bash | Add launch script to launch agent |
134627c3-75db-410e-bff8-7a920075f198 | T1037.005 | macos | sh | Add file to Local Library StartupItems |
fc369906-90c7-4a15-86fd-d37da624dde6 | T1037.005 | macos | bash | Add launch script to launch daemon |
6ed67921-1774-44ba-bac6-adb51ed60660 | T1039 | windows | command_prompt | Copy a sensitive File over Administrative share with copy |
7762e120-5879-44ff-97f8-008b401b9a98 | T1039 | windows | powershell | Copy a sensitive File over Administrative share with Powershell |
855fb8b4-b8ab-4785-ae77-09f5df7bff55 | T1040 | windows | command_prompt | Windows Internal pktmon set filter |
9c15a7de-de14-46c3-bc2a-6d94130986ae | T1040 | windows | powershell | PowerShell Network Sniffing |
9d04efee-eff5-4240-b8d2-07792b873608 | T1040 | macos | bash | Packet Capture macOS using tcpdump or tshark |
a5b2f6a0-24b4-493e-9590-c699f75723ca | T1040 | windows | command_prompt | Packet Capture Windows Command Prompt |
b5656f67-d67f-4de8-8e62-b5581630f528 | T1040 | windows | command_prompt | Windows Internal Packet Capture |
c67ba807-f48b-446e-b955-e4928cd1bf91 | T1040 | windows | command_prompt | Windows Internal pktmon capture |
e2480aee-23f3-4f34-80ce-de221e27cd19 | T1040 | macos | bash | Filtered Packet Capture macOS using /dev/bpfN with sudo |
e6fe5095-545d-4c8b-a0ae-e863914be3aa | T1040 | macos | bash | Packet Capture macOS using /dev/bpfN with sudo |
c9207f3e-213d-4cc7-ad2a-7697a7237df9 | T1041 | windows | powershell | Text Based Data Exfiltration using DNS subdomains |
d1253f6e-c29b-49dc-b466-2147a6191932 | T1041 | windows | powershell | C2 Data Exfiltration |
05df2a79-dba6-4088-a804-9ca0802ca8e4 | T1046 | windows | powershell | Port-Scanning /24 Subnet with PowerShell |
0d5a2b03-3a26-45e4-96ae-89485b4d1f97 | T1046 | linux, macos | sh | Port Scan using nmap (Port range) |
1cca5640-32a9-46e6-b8e0-fabbe2384a73 | T1046 | windows | powershell | WinPwn - bluekeep |
54574908-f1de-4356-9021-8053dd57439a | T1046 | windows | powershell | WinPwn - spoolvulnscan |
68e907da-2539-48f6-9fc9-257a78c05540 | T1046 | linux, macos | bash | Port Scan |
6ca45b04-9f15-4424-b9d3-84a217285a5c | T1046 | windows | powershell | Port Scan using python |
97585b04-5be2-40e9-8c31-82157b8af2d6 | T1046 | windows | powershell | WinPwn - MS17-10 |
9e55750e-4cbf-4013-9627-e9a045b541bf | T1046 | windows | powershell | Remote Desktop Services Discovery via PowerShell |
bb037826-cbe8-4a41-93ea-b94059d6bb98 | T1046 | windows | powershell | WinPwn - fruit |
d696a3cb-d7a8-4976-8eb5-5af4abf2e3df | T1046 | windows | powershell | Port Scan NMap for Windows |
00738d2a-4651-4d76-adf2-c43a41dfb243 | T1047 | windows | command_prompt | WMI Execute rundll32 |
0fd48ef7-d890-4e93-a533-f7dedd5191d3 | T1047 | windows | command_prompt | WMI Reconnaissance List Remote Services |
10447c83-fc38-462a-a936-5102363b1c43 | T1047 | windows | powershell | Create a Process using obfuscated Win32_Process |
5750aa16-0e59-4410-8b9a-8a47ca2788e2 | T1047 | windows | command_prompt | WMI Reconnaissance Processes |
718aebaa-d0e0-471a-8241-c5afa69c7414 | T1047 | windows | command_prompt | WMI Reconnaissance Software |
7db7a7f9-9531-4840-9b30-46220135441c | T1047 | windows | command_prompt | Create a Process using WMI Query and an Encoded Command |
9c8ef159-c666-472f-9874-90c8d60d136b | T1047 | windows | command_prompt | WMI Execute Remote Process |
b3bdfc91-b33e-4c6d-a5c8-d64bee0276b3 | T1047 | windows | command_prompt | WMI Execute Local Process |
c107778c-dcf5-47c5-af2e-1d058a3df3ea | T1047 | windows | command_prompt | WMI Reconnaissance Users |
c510d25b-1667-467d-8331-a56d3e9bc4ff | T1047 | windows | command_prompt | Application uninstall using WMIC |
7c3cb337-35ae-4d06-bf03-3032ed2ec268 | T1048 | linux, macos | sh | Exfiltration Over Alternative Protocol - SSH |
a27916da-05f2-4316-a3ee-feec67a437be | T1048 | linux, macos | bash | Exfiltrate Data using DNS Queries via dig |
c943d285-ada3-45ca-b3aa-7cd6500c6a48 | T1048 | windows | powershell | DNSExfiltration (doh) |
f6786cc8-beda-4915-a4d6-ac2f193bb988 | T1048 | linux, macos | sh | Exfiltration Over Alternative Protocol - SSH |
1cdf2fb0-51b6-4fd8-96af-77020d5f1bf0 | T1048.002 | windows | command_prompt | Exfiltrate data HTTPS using curl windows |
4a4f31e2-46ea-4c26-ad89-f09ad1d5fe01 | T1048.002 | linux, macos | bash | Exfiltrate data HTTPS using curl freebsd,linux or macos |
57799bc2-ad1e-4130-a793-fb0c385130ba | T1048.003 | windows | powershell | MAZE FTP Upload |
6aa58451-1121-4490-a8e9-1dada3f1c68c | T1048.003 | windows | powershell | Exfiltration Over Alternative Protocol - HTTP |
b854eb97-bf9b-45ab-a1b5-b94e4880c56b | T1048.003 | windows | powershell | Exfiltration Over Alternative Protocol - FTP - Rclone |
dd4b4421-2e25-4593-90ae-7021947ad12e | T1048.003 | windows | powershell | Exfiltration Over Alternative Protocol - ICMP |
ec3a835e-adca-4c7c-88d2-853b69c11bb9 | T1048.003 | windows | powershell | Exfiltration Over Alternative Protocol - SMTP |
0940a971-809a-48f1-9c4d-b1d785e96ee5 | T1049 | windows | command_prompt | System Network Connections Discovery |
96f974bb-a0da-4d87-a744-ff33e73367e9 | T1049 | windows | powershell | System Discovery using SharpView |
9ae28d3f-190f-4fa0-b023-c7bd3e0eabf2 | T1049 | linux, macos | sh | System Network Connections Discovery FreeBSD, Linux & MacOS |
b52c8233-8f71-4bd7-9928-49fec8215cf5 | T1049 | windows | powershell | System Network Connections Discovery via PowerShell (Process Mapping) |
bcf05343-ef1d-4052-8a27-b00c9be42b9f | T1049 | linux, macos | bash | System Network Connections Discovery via ss or lsof (Linux/MacOS) |
f069f0f1-baad-4831-aa2b-eddac4baac4a | T1049 | windows | powershell | System Network Connections Discovery with PowerShell |
4a6c0dc4-0f2a-4203-9298-a5a9bdc21ed8 | T1053.002 | windows | command_prompt | At.exe Scheduled task |
b7d42afa-9086-4c8a-b7b0-8ea3faa6ebb0 | T1053.003 | linux, macos | bash | Cron - Add script to all cron subfolders |
02124c37-767e-4b76-9383-c9fc366d9d4c | T1053.005 | windows | command_prompt | Scheduled Task Persistence via Eventviewer.msc |
2e5eac3e-327b-4a88-a0c0-c4057039a8dd | T1053.005 | windows | command_prompt | Scheduled task Remote |
42f53695-ad4a-4546-abb6-7d837f644a71 | T1053.005 | windows | command_prompt | Scheduled task Local |
704333ca-cc12-4bcf-9916-101844881f54 | T1053.005 | windows | command_prompt | Scheduled Task ("Ghost Task") via Registry Key Manipulation |
8fcfa3d5-ea7d-4e1c-bd3e-3c4ed315b7d2 | T1053.005 | windows | command_prompt | Scheduled Task Persistence via CompMgmt.msc |
af9fd58f-c4ac-4bf2-a9ba-224b71ff25fd | T1053.005 | windows | powershell | Powershell Cmdlet Scheduled Task |
cd925593-fbb4-486d-8def-16cbdf944bf4 | T1053.005 | windows | powershell | Import XML Schedule Task with Hidden Attribute |
dda6fc7b-c9a6-4c18-b98d-95ec6542af6d | T1053.005 | windows | powershell | PowerShell Modify A Scheduled Task |
e16b3b75-dc9e-4cde-a23d-dfa2d0507b3b | T1053.005 | windows | powershell | WMI Invoke-CimMethod Scheduled Task |
e895677d-4f06-49ab-91b6-ae3742d0a2ba | T1053.005 | windows | command_prompt | Scheduled Task Executing Base64 Encoded Commands From Registry |
ecd3fa21-7792-41a2-8726-2c5c673414d3 | T1053.005 | windows | powershell | Task Scheduler via VBA |
fec27f65-db86-4c2d-b66c-61945aee87c2 | T1053.005 | windows | command_prompt | Scheduled Task Startup Script |
0128e48e-8c1a-433a-a11a-a5304734f1e1 | T1055 | windows | powershell | UUID custom process Injection |
0128e48e-8c1a-433a-a11a-a5387384f1e1 | T1055 | windows | powershell | Read-Write-Execute process Injection |
1c91e740-1729-4329-b779-feba6e71d048 | T1055 | windows | powershell | Shellcode execution via VBA |
2315ce15-38b6-46ac-a3eb-5e21abef2545 | T1055 | windows | powershell | Process Injection with Go using UuidFromStringA WinAPI |
2871ed59-3837-4a52-9107-99500ebc87cb | T1055 | windows | powershell | Process Injection with Go using CreateThread WinAPI |
2a3c7035-d14f-467a-af94-933e49fe6786 | T1055 | windows | powershell | Process Injection with Go using CreateThread WinAPI (Natively) |
2a4ab5c1-97ad-4d6d-b5d3-13f3a6c94e39 | T1055 | windows | powershell | Remote Process Injection with Go using CreateRemoteThread WinAPI (Natively) |
3203ad24-168e-4bec-be36-f79b13ef8a83 | T1055 | windows | command_prompt | Remote Process Injection in LSASS via mimikatz |
49543237-25db-497b-90df-d0a0a6e8fe2c | T1055 | windows | powershell | Dirty Vanity process Injection |
69534efc-d5f5-4550-89e6-12c6457b9edd | T1055 | windows | powershell | Remote Process Injection with Go using CreateRemoteThread WinAPI |
7362ecef-6461-402e-8716-7410e1566400 | T1055 | windows | powershell | Process Injection with Go using EtwpCreateEtwThread WinAPI |
a0c1725f-abcd-40d6-baac-020f3cf94ecd | T1055 | windows | powershell | Remote Process Injection with Go using RtlCreateUserThread WinAPI |
c6952f41-6cf0-450a-b352-2ca8dae7c178 | T1055 | windows | powershell | Section View Injection |
74496461-11a1-4982-b439-4d87a550d254 | T1055.001 | windows | powershell | Process Injection via mavinject.exe |
8b56f787-73d9-4f1d-87e8-d07e89cbc7f5 | T1055.001 | windows | powershell | WinPwn - Get SYSTEM shell - Bind System Shell using UsoClient DLL load technique |
578025d5-faa9-4f6d-8390-aae739d503e1 | T1055.002 | windows | powershell | Portable Executable Injection |
578025d5-faa9-4f6d-8390-aae527d503e1 | T1055.003 | windows | powershell | Thread Execution Hijacking |
4cc571b1-f450-414a-850f-879baf36aa06 | T1055.004 | windows | powershell | Remote Process Injection with Go using NtQueueApcThreadEx WinAPI |
611b39b7-e243-4c81-87a4-7145a90358b1 | T1055.004 | windows | command_prompt | Process Injection via C# |
73785dd2-323b-4205-ab16-bb6f06677e14 | T1055.004 | windows | powershell | EarlyBird APC Queue Injection in Go |
93ca40d2-336c-446d-bcef-87f14d438018 | T1055.011 | windows | powershell | Process Injection via Extra Window Memory (EWM) x64 executable |
3ad4a037-1598-4136-837c-4027e4fa319b | T1055.012 | windows | powershell | RunPE via VBA |
562427b4-39ef-4e8c-af88-463a78e70b9c | T1055.012 | windows | powershell | Process Hollowing using PowerShell |
94903cc5-d462-498a-b919-b1e5ab155fee | T1055.012 | windows | powershell | Process Hollowing in Go using CreateProcessW and CreatePipe WinAPIs (T1055.012) |
c8f98fe1-c89b-4c49-a7e3-d60ee4bc2f5a | T1055.012 | windows | powershell | Process Hollowing in Go using CreateProcessW WinAPI |
4f3c7502-b111-4dfe-8a6e-529307891a59 | T1055.015 | windows | powershell | Process injection ListPlanting |
aee3a097-4c5c-4fff-bbd3-0a705867ae29 | T1056.001 | macos | bash | MacOS Swift Keylogger |
d9b633ca-8efb-45e6-b838-70f595c6ae26 | T1056.001 | windows | powershell | Input Capture |
2b162bfd-0928-4d4c-9ec3-4d9f88374b52 | T1056.002 | windows | powershell | PowerShell - Prompt User for Password |
76628574-0bc1-4646-8fe2-8f4427b47d15 | T1056.002 | macos | bash | AppleScript - Prompt User for Password |
b7037b89-947a-427a-ba29-e7e9f09bc045 | T1056.002 | macos | bash | AppleScript - Spoofing a credential prompt using osascript |
de1934ea-1fbf-425b-8795-65fb27dd7e33 | T1056.004 | windows | powershell | Hook PowerShell TLS Encrypt/Decrypt Messages |
11ba69ee-902e-4a0f-b3b6-418aed7d7ddb | T1057 | windows | command_prompt | Discover Specific Process - tasklist |
3b3809b6-a54b-4f5b-8aff-cb51f2e97b34 | T1057 | windows | powershell | Process Discovery - Get-Process |
4fd35378-39aa-481e-b7c4-e3bf49375c67 | T1057 | windows | command_prompt | Launch Taskmgr from cmd to View running processes |
4ff64f0b-aaf2-4866-b39d-38d9791407cc | T1057 | linux, macos | sh | Process Discovery - ps |
640cbf6d-659b-498b-ba53-f6dd1a1cc02c | T1057 | windows | command_prompt | Process Discovery - wmic process |
966f4c16-1925-4d9b-8ce0-01334ee0867d | T1057 | windows | powershell | Process Discovery - Process Hacker |
b4ca838d-d013-4461-bf2c-f7132617b409 | T1057 | windows | powershell | Process Discovery - PC Hunter |
b51239b4-0129-474f-a2b4-70f855b9f2c2 | T1057 | windows | powershell | Process Discovery - get-wmiObject |
c5806a4f-62b8-4900-980b-c7ec004e9908 | T1057 | windows | command_prompt | Process Discovery - tasklist |
a9b93f17-31cb-435d-a462-5e838a2a6026 | T1059 | windows | powershell | AutoIt Script Execution |
06a220b6-7e29-4bd8-9d07-5b4d86742372 | T1059.001 | windows | command_prompt | Invoke-AppPathBypass |
0d181431-ddf3-4826-8055-2dbf63ae848b | T1059.001 | windows | powershell | ATHPowerShellCommandLineParameter -EncodedCommand parameter variations with encoded arguments |
1289f78d-22d2-4590-ac76-166737e1811b | T1059.001 | windows | powershell | PowerUp Invoke-AllChecks |
1c0a870f-dc74-49cf-9afc-eccc45e58790 | T1059.001 | windows | powershell | ATHPowerShellCommandLineParameter -Command parameter variations with encoded arguments |
388a7340-dbc1-4c9d-8e59-b75ad8c6d5da | T1059.001 | windows | command_prompt | Powershell MsXml COM object - with prompt |
4099086c-1470-4223-8085-8186e1ed5948 | T1059.001 | windows | powershell | SOAPHound - Build Cache |
4396927f-e503-427b-b023-31049b9b09a6 | T1059.001 | windows | command_prompt | Powershell XML requests |
49eb9404-5e0f-4031-a179-b40f7be385e3 | T1059.001 | windows | powershell | PowerShell Invoke Known Malicious Cmdlets |
686a9785-f99b-41d4-90df-66ed515f81d7 | T1059.001 | windows | powershell | ATHPowerShellCommandLineParameter -Command parameter variations |
6a5b2a50-d037-4879-bf01-43d4d6cbf73f | T1059.001 | windows | powershell | SOAPHound - Dump BloodHound Data |
7c1acec2-78fa-4305-a3e0-db2a54cddecd | T1059.001 | windows | powershell | PowerShell Session Creation and Use |
86a43bad-12e3-4e85-b97c-4d5cf25b95c3 | T1059.001 | windows | powershell | ATHPowerShellCommandLineParameter -EncodedCommand parameter variations |
8a2ad40b-12c7-4b25-8521-2737b0a415af | T1059.001 | windows | command_prompt | Powershell invoke mshta.exe download |
8e5c5532-1181-4c1d-bb79-b3a9f5dbd680 | T1059.001 | windows | powershell | NTFS Alternate Data Stream Access |
999bff6d-dc15-44c9-9f5c-e1051bfc86e1 | T1059.001 | windows | powershell | Abuse Nslookup with DNS Records |
a21bb23e-e677-4ee7-af90-6931b57b6350 | T1059.001 | windows | powershell | Run BloodHound from local disk |
a538de64-1c74-46ed-aa60-b995ed302598 | T1059.001 | windows | command_prompt | PowerShell Command Execution |
af1800cf-9f9d-4fd1-a709-14b1e6de020d | T1059.001 | windows | powershell | Mimikatz - Cradlecraft PsSendKeys |
bf8c1441-4674-4dab-8e4e-39d93d08f9b7 | T1059.001 | windows | powershell | Run Bloodhound from Memory using Download Cradle |
f3132740-55bc-48c4-bcc0-758a459cd027 | T1059.001 | windows | command_prompt | Mimikatz |
fa050f5e-bc75-4230-af73-b6fd7852cd73 | T1059.001 | windows | powershell | PowerShell Fileless Script Execution |
3600d97d-81b9-4171-ab96-e4386506e2c2 | T1059.002 | macos | sh | AppleScript |
00682c9f-7df4-4df8-950b-6dcaaa3ad9af | T1059.003 | windows | command_prompt | Command prompt writing script to file then executes it |
127b4afe-2346-4192-815c-69042bec570e | T1059.003 | windows | command_prompt | Writes text to a file and displays it. |
6b2903ac-8f36-450d-9ad5-b220e8a2dcb9 | T1059.003 | windows | powershell | Simulate BlackByte Ransomware Print Bombing |
9e8894c0-50bd-4525-a96c-d4ac78ece388 | T1059.003 | windows | powershell | Create and Execute Batch Script |
d0eb3597-a1b3-4d65-b33b-2cda8d397f20 | T1059.003 | windows | command_prompt | Suspicious Execution via Windows Command Shell |
df81db1b-066c-4802-9bc8-b6d030c3ba8e | T1059.003 | windows | command_prompt | Command Prompt read contents from CMD file and execute |
7e7ac3ed-f795-4fa5-b711-09d6fbe9b873 | T1059.004 | linux, macos | sh | Create and Execute Bash Shell Script |
bcd4c2bc-490b-4f91-bd31-3709fe75bbdf | T1059.004 | linux, macos | sh | Creating shell using cpan command |
d0c88567-803d-4dca-99b4-7ce65e7b257c | T1059.004 | linux, macos | sh | Command-Line Interface |
e0742e38-6efe-4dd4-ba5c-2078095b6156 | T1059.004 | linux, macos | sh | emacs spawning an interactive system shell |
1620de42-160a-4fe5-bbaf-d3fef0181ce9 | T1059.005 | windows | powershell | Visual Basic script execution to gather local computer information |
8faff437-a114-4547-9a60-749652a03df6 | T1059.005 | windows | powershell | Extract Memory via VBA |
e8209d5f-e42d-45e6-9c2f-633ac4f1eefa | T1059.005 | windows | powershell | Encoded VBS code execution |
01d75adf-ca1b-4dd1-ac96-7c9550ad1035 | T1059.007 | windows | command_prompt | JScript execution to gather local computer information via cscript |
0709945e-4fec-4c49-9faf-c3c292a74484 | T1059.007 | windows | command_prompt | JScript execution to gather local computer information via wscript |
7b5d350e-f758-43cc-a761-8e3f6b052a03 | T1059.010 | windows | powershell | AutoHotKey script execution |
1f454dd6-e134-44df-bebb-67de70fb6cd8 | T1069.001 | windows | command_prompt | Basic Permission Groups Discovery Windows (Local) |
69119e58-96db-4110-ad27-954e48f3bb13 | T1069.001 | windows | powershell | WMIObject Group Discovery |
7413be50-be8e-430f-ad4d-07bf197884b2 | T1069.001 | windows | command_prompt | Wmic Group Discovery |
952931a4-af0b-4335-bbbe-73c8c5b327ae | T1069.001 | linux, macos | sh | Permission Groups Discovery (Local) |
a580462d-2c19-4bc7-8b9a-57a41b7d3ba4 | T1069.001 | windows | powershell | Permission Groups Discovery PowerShell (Local) |
e03ada14-0980-4107-aff1-7783b2b59bb1 | T1069.001 | windows | powershell | SharpHound3 - LocalAdmin |
0afb5163-8181-432e-9405-4322710c0c37 | T1069.002 | windows | command_prompt | Elevated group enumeration using net group (Domain) |
22cf8cb9-adb1-4e8c-80ca-7c723dfc8784 | T1069.002 | windows | command_prompt | Active Directory Enumeration with LDIFDE |
3d1fcd2a-e51c-4cbe-8d84-9a843bad8dc8 | T1069.002 | windows | powershell | Enumerate Active Directory Groups with Get-AdGroup |
43fa81fb-34bb-4b5f-867b-03c7dbe0e3d8 | T1069.002 | windows | powershell | Get-ADUser Enumeration using UserAccountControl flags (AS-REP Roasting) |
46352f40-f283-4fe5-b56d-d9a71750e145 | T1069.002 | windows | powershell | Get-DomainGroupMember with PowerView |
48ddc687-82af-40b7-8472-ff1e742e8274 | T1069.002 | windows | command_prompt | Adfind - Query Active Directory Groups |
5a8a181c-2c8e-478d-a943-549305a01230 | T1069.002 | windows | powershell | Get-DomainGroup with PowerView |
64fdb43b-5259-467a-b000-1b02c00e510a | T1069.002 | windows | powershell | Find Local Admins via Group Policy (PowerView) |
6d5d8c96-3d2a-4da9-9d6d-9a9d341899a7 | T1069.002 | windows | powershell | Permission Groups Discovery PowerShell (Domain) |
870ba71e-6858-4f6d-895c-bb6237f6121b | T1069.002 | windows | powershell | Enumerate Users Not Requiring Pre Auth (ASRepRoast) |
9f4e344b-8434-41b3-85b1-d38f29d148d0 | T1069.002 | windows | powershell | Enumerate Active Directory Groups with ADSISearcher |
a2d71eee-a353-4232-9f86-54f4288dd8c1 | T1069.002 | windows | powershell | Find machines where user has local admin access (PowerView) |
a5f0d9f8-d3c9-46c0-8378-846ddd6b1cbd | T1069.002 | windows | powershell | Find local admins on all machines in domain (PowerView) |
dd66d77d-8998-48c0-8024-df263dc2ce5d | T1069.002 | windows | command_prompt | Basic Permission Groups Discovery Windows (Domain) |
96e86706-6afd-45b6-95d6-108d23eaf2e9 | T1070 | windows | powershell | Indicator Manipulation using FSUtil |
b4115c7a-0e92-47f0-a61e-17e7218b2435 | T1070 | windows | command_prompt | Indicator Removal using FSUtil |
1d0d9aa6-6111-4f89-927b-53e8afae7f94 | T1070.003 | windows | powershell | Set Custom AddToHistoryHandler to Avoid History File Logging |
22c779cd-9445-4d3e-a136-f75adbf0315f | T1070.003 | windows | powershell | Clear PowerShell Session History |
23d348f3-cc5c-4ba9-bd0a-ae09069f0914 | T1070.003 | linux, macos | sh | Clear Bash history (ln dev/null) |
2f898b81-3e97-4abb-bc3f-a95138988370 | T1070.003 | windows | powershell | Prevent Powershell History Logging |
53b03a54-4529-4992-852d-a00b4b7215a6 | T1070.003 | linux, macos | sh | Use Space Before Command to Avoid Logging to History |
784e4011-bd1a-4ecd-a63a-8feb278512e6 | T1070.003 | linux, macos | bash | Clear and Disable Bash History Logging |
7e6721df-5f08-4370-9255-f06d8a77af4c | T1070.003 | linux, macos | sh | Clear history of a bunch of shells |
a934276e-2be5-4a36-93fd-98adbb5bd4fc | T1070.003 | linux, macos | sh | Clear Bash history (rm) |
b1251c35-dcd3-4ea1-86da-36d27b54f31f | T1070.003 | linux, macos | sh | Clear Bash history (cat dev/null) |
da75ae8d-26d6-4483-b0fe-700e4df4f037 | T1070.003 | windows | powershell | Clear Powershell History by Deleting History File |
36f96049-0ad7-4a5f-8418-460acaeb92fb | T1070.004 | windows | powershell | Delete Prefetch File |
562d737f-2fc6-4b09-8c2a-7f8ff0828480 | T1070.004 | linux, macos | sh | Delete a single file - FreeBSD/Linux/macOS |
69f50a5f-967c-4327-a5bb-e1a9a9983785 | T1070.004 | windows | powershell | Delete TeamViewer Log Files |
861ea0b4-708a-4d17-848d-186c9c7f17e3 | T1070.004 | windows | command_prompt | Delete a single file - Windows cmd |
9dee89bd-9a98-4c4f-9e2d-4256690b0e72 | T1070.004 | windows | powershell | Delete a single file - Windows PowerShell |
a415f17e-ce8d-4ce2-a8b4-83b674e7017e | T1070.004 | linux, macos | sh | Delete an entire folder - FreeBSD/Linux/macOS |
ded937c4-2add-42f7-9c2c-c742b7a98698 | T1070.004 | windows | command_prompt | Delete an entire folder - Windows cmd |
edd779e4-a509-4cba-8dfa-a112543dbfb1 | T1070.004 | windows | powershell | Delete an entire folder - Windows PowerShell |
f723d13d-48dc-4317-9990-cf43a9ac0bf2 | T1070.004 | windows | command_prompt | Clears Recycle bin via rd |
0512d214-9512-4d22-bde7-f37e058259b3 | T1070.005 | windows | powershell | Remove Network Share PowerShell |
09210ad5-1ef2-4077-9ad3-7351e13e9222 | T1070.005 | windows | command_prompt | Remove Network Share |
14c38f32-6509-46d8-ab43-d53e32d2b131 | T1070.005 | windows | command_prompt | Add Network Share |
4299eff5-90f1-4446-b2f3-7f4f5cfd5d62 | T1070.005 | windows | command_prompt | Remove Administrative Shares |
99c657aa-ebeb-4179-a665-69288fdd12b8 | T1070.005 | windows | command_prompt | Disable Administrative Share Creation at Startup |
20ef1523-8758-4898-b5a2-d026cc3d2c52 | T1070.006 | linux, macos | sh | Set a file's modification timestamp |
631ea661-d661-44b0-abdb-7a7f3fc08e50 | T1070.006 | linux, macos | sh | Modify file timestamps using reference file |
7bcf83bf-f5ef-425c-9d9a-71618ad9ed12 | T1070.006 | windows | powershell | Event Log Manipulations- Time slipping via Powershell |
8164a4a6-f99c-4661-ac4f-80f5e4e78d2b | T1070.006 | linux, macos | sh | Set a file's creation timestamp |
87fffff4-d371-4057-a539-e3b24c37e564 | T1070.006 | macos | sh | MacOS - Timestomp Date Modified |
b3b2c408-2ff0-4a33-b89b-1cb46a9e6a9c | T1070.006 | windows | powershell | Windows - Modify file creation timestamp with PowerShell |
d7512c33-3a75-4806-9893-69abc3ccdd43 | T1070.006 | windows | powershell | Windows - Timestomp a File |
da627f63-b9bd-4431-b6f8-c5b44d061a62 | T1070.006 | windows | powershell | Windows - Modify file last access timestamp with PowerShell |
f8f6634d-93e1-4238-8510-f8a90a20dcf2 | T1070.006 | windows | powershell | Windows - Modify file last modified timestamp with PowerShell |
3824130e-a6e4-4528-8091-3a52eeb540f6 | T1070.008 | macos | bash | Copy and Delete Mailbox Data on macOS |
8a0b1579-5a36-483a-9cde-0236983e1665 | T1070.008 | macos | bash | Copy and Modify Mailbox Data on macOS |
d29f01ea-ac72-4efc-8a15-bea64b77fabf | T1070.008 | windows | powershell | Copy and Delete Mailbox Data on Windows |
edddff85-fee0-499d-9501-7d4d2892e79b | T1070.008 | windows | powershell | Copy and Modify Mailbox Data on Windows |
3b0df731-030c-4768-b492-2a3216d90e53 | T1071 | windows | powershell | Telnet C2 |
2d7c471a-e887-4b78-b0dc-b0df1f2e0658 | T1071.001 | linux, macos | sh | Malicious User Agents - Nix |
81c13829-f6c9-45b8-85a6-053366d55297 | T1071.001 | windows | powershell | Malicious User Agents - Powershell |
dc3488b0-08c7-4fea-b585-905c83b48180 | T1071.001 | windows | command_prompt | Malicious User Agents - CMD |
1700f5d6-5a44-487b-84de-bc66f507b0a6 | T1071.004 | windows | powershell | DNS Large Query Volume |
3efc144e-1af8-46bb-8ca2-1376bb6db8b6 | T1071.004 | windows | powershell | DNS Regular Beaconing |
e7bf9802-2e78-4db9-93b5-181b7bcd37d7 | T1071.004 | windows | powershell | DNS C2 |
fef31710-223a-40ee-8462-a396d6b66978 | T1071.004 | windows | powershell | DNS Long Domain Query |
2169e8b0-2ee7-44cb-8a6e-d816a5db7d8a | T1072 | windows | powershell | Deploy 7-Zip Using Chocolatey |
b4988cad-6ed2-434d-ace5-ea2670782129 | T1072 | windows | command_prompt | Radmin Viewer Utility |
e447b83b-a698-4feb-bed1-a7aaf45c3443 | T1072 | windows | command_prompt | PDQ Deploy RAT |
107706a5-6f9f-451a-adae-bab8c667829f | T1074.001 | windows | powershell | Stage data from Discovery.bat |
39ce0303-ae16-4b9e-bb5b-4f53e8262066 | T1074.001 | linux, macos | sh | Stage data from Discovery.sh |
a57fbe4b-3440-452a-88a7-943531ac872a | T1074.001 | windows | powershell | Zip a Folder with PowerShell for Staging in Temp |
0315bdff-4178-47e9-81e4-f31a6d23f7e4 | T1078.001 | macos | sh | Enable Guest Account on macOS |
99747561-ed8d-47f2-9c91-1e5fde1ed6e0 | T1078.001 | windows | command_prompt | Enable Guest account with RDP capability and admin privileges |
aa6cb8c4-b582-4f8e-b677-37733914abda | T1078.001 | windows | command_prompt | Activate Guest Account |
191db57d-091a-47d5-99f3-97fde53de505 | T1078.003 | macos | bash | Create local account with admin privileges using sysadminctl utility - MacOS |
20b40ea9-0e17-4155-b8e6-244911a678ac | T1078.003 | macos | bash | Enable root account using dsenableroot utility - MacOS |
433842ba-e796-4fd5-a14f-95d3a1970875 | T1078.003 | macos | bash | Add a new/existing user to the admin group using dseditgroup utility - macOS |
6904235f-0f55-4039-8aed-41c300ff7733 | T1078.003 | windows | command_prompt | Use PsExec to elevate to NT Authority\SYSTEM account |
9e9fd066-453d-442f-88c1-ad7911d32912 | T1078.003 | windows | powershell | WinPwn - Loot local Credentials - powerhell kittie |
a524ce99-86de-4db6-b4f9-e08f35a47a15 | T1078.003 | windows | command_prompt | Create local account with admin privileges |
e9fdb899-a980-4ba4-934b-486ad22e22f4 | T1078.003 | windows | powershell | WinPwn - Loot local Credentials - Safetykatz |
f1275566-1c26-4b66-83e3-7f9f7f964daa | T1078.003 | macos | bash | Create local account with admin privileges - MacOS |
07b18a66-6304-47d2-bad0-ef421eb2e107 | T1082 | windows | powershell | WinPwn - PowerSharpPack - Watson searching for missing windows patches |
2040405c-eea6-4c1c-aef3-c2acc430fac9 | T1082 | windows | command_prompt | ESXi - VM Discovery using ESXCLI |
224b4daf-db44-404e-b6b2-f4d1f0126ef8 | T1082 | windows | command_prompt | Windows MachineGUID Discovery |
3278b2f6-f733-4875-9ef4-bfed34244f0a | T1082 | windows | powershell | WinPwn - Morerecon |
327cc050-9e99-4c8e-99b5-1d15f2fb6b96 | T1082 | macos | sh | Show System Integrity Protection status (MacOS) |
345cb8e4-d2de-4011-a580-619cf5a9e2d7 | T1082 | windows | powershell | WinPwn - Powersploits privesc checks |
3d256a2f-5e57-4003-8eb6-64d91b1da7ce | T1082 | windows | powershell | WinPwn - itm4nprivesc |
4060ee98-01ae-4c8e-8aad-af8300519cc7 | T1082 | windows | command_prompt | System Information Discovery |
486e88ea-4f56-470f-9b57-3f4d73f39133 | T1082 | linux, macos | sh | Hostname Discovery |
5b6f39a2-6ec7-4783-a5fd-2c54a55409ed | T1082 | windows | powershell | WinPwn - General privesc checks |
5c16ceb4-ba3a-43d7-b848-a13c1f216d95 | T1082 | windows | powershell | WinPwn - PowerSharpPack - Seatbelt |
66703791-c902-4560-8770-42b8a91f7667 | T1082 | windows | command_prompt | System Information Discovery |
69bd4abe-8759-49a6-8d21-0f15822d6370 | T1082 | windows | powershell | Griffon Recon |
70e13ef4-5a74-47e4-9d16-760b41b0e2db | T1082 | windows | powershell | operating system discovery |
7161b085-816a-491f-bab4-d68e974b7995 | T1082 | windows | command_prompt | Display volume shadow copies with "vssadmin" |
7804659b-fdbf-4cf6-b06a-c03e758590e8 | T1082 | windows | powershell | WinPwn - GeneralRecon |
85cfbf23-4a1e-4342-8792-007e004b975f | T1082 | windows | command_prompt | Hostname Discovery (Windows) |
8851b73a-3624-4bf7-8704-aa312411565c | T1082 | windows | command_prompt | System Information Discovery with WMIC |
96be6002-9200-47db-94cb-c3e27de1cb36 | T1082 | windows | command_prompt | Check computer location |
acfcd709-0013-4f1e-b9ee-bc1e7bafaaec | T1082 | windows | command_prompt | Discover OS Build Number via Registry |
be3b5fe3-a575-4fb8-83f6-ad4a68dd5ce7 | T1082 | windows | command_prompt | Discover OS Product Name via Registry |
c187c9bc-4511-40b3-aa10-487b2c70b6a5 | T1082 | windows | command_prompt | Enumerate Available Drives via gdr |
c8d40da9-31bd-47da-a497-11ea55d1ef6c | T1082 | macos | sh | sysctl to gather macOS hardware info |
cccb070c-df86-4216-a5bc-9fb60c74e27c | T1082 | linux, macos | sh | List OS Information |
ce479c1a-e8fa-42b2-812a-96b0f2f4d28a | T1082 | windows | command_prompt | Identify System Locale and Regional Settings with PowerShell |
dec6a0d8-bcaf-4c22-9d48-2aee59fb692b | T1082 | windows | powershell | WinPwn - RBCD-Check |
edff98ec-0f73-4f63-9890-6b117092aff6 | T1082 | macos | sh | System Information Discovery |
eea1d918-825e-47dd-acc2-814d6c58c0e1 | T1082 | windows | powershell | WinPwn - winPEAS |
efb79454-1101-4224-a4d0-30c9c8b29ffc | T1082 | windows | powershell | WinPwn - PowerSharpPack - Sharpup checking common Privesc vectors |
f2f91612-d904-49d7-87c2-6c165d23bead | T1082 | windows | command_prompt | BIOS Information Discovery through Registry |
f400d1c0-1804-4ff8-b069-ef5ddd2adbf3 | T1082 | windows | command_prompt | Environment variables discovery on windows |
f6ecb109-df24-4303-8d85-1987dbae6160 | T1082 | windows | command_prompt | Check OS version via "ver" command |
f89812e5-67d1-4f49-86fa-cbc6609ea86a | T1082 | windows | command_prompt | ESXi - Darkside system information discovery |
fcbdd43f-f4ad-42d5-98f3-0218097e2720 | T1082 | linux, macos | sh | Environment variables discovery on freebsd, macos and linux |
0e36303b-6762-4500-b003-127743b80ba6 | T1083 | windows | command_prompt | File and Directory Discovery (cmd.exe) |
13c5e1ae-605b-46c4-a79f-db28c77ff24e | T1083 | linux, macos | sh | Nix File and Directory Discovery 2 |
2158908e-b7ef-4c21-8a83-3ce4dd05a924 | T1083 | windows | powershell | File and Directory Discovery (PowerShell) |
4a233a40-caf7-4cf1-890a-c6331bbc72cf | T1083 | windows | command_prompt | ESXi - Enumerate VMDKs available on an ESXi Host |
95a21323-770d-434c-80cd-6f6fbf7af432 | T1083 | windows | powershell | Recursive Enumerate Files And Directories By Powershell |
c5bec457-43c9-4a18-9a24-fe151d8971b7 | T1083 | windows | powershell | Launch DirLister Executable |
c6c34f61-1c3e-40fb-8a58-d017d88286d8 | T1083 | windows | powershell | Simulating MAZE Directory Enumeration |
ffc8b249-372a-4b74-adcd-e4c0430842de | T1083 | linux, macos | sh | Nix File and Directory Discovery |
319e9f6c-7a9e-432e-8c62-9385c803b6f2 | T1087.001 | macos | sh | Enumerate users and groups |
7e46c7a5-0142-45be-a858-1a3ecb4fd3cb | T1087.001 | linux, macos | sh | List opened files by user |
80887bec-5a9b-4efc-a81d-f83eb2eb32ab | T1087.001 | windows | command_prompt | Enumerate all accounts on Windows (Local) |
9762ac6e-aa60-4449-a2f0-cbbd0e1fd22c | T1087.001 | windows | command_prompt | ESXi - Local Account Discovery via ESXCLI |
a138085e-bfe5-46ba-a242-74a6fb884af3 | T1087.001 | windows | command_prompt | Enumerate logged on users via CMD (Local) |
ae4b6361-b5f8-46cb-a3f9-9cf108ccfe7b | T1087.001 | windows | powershell | Enumerate all accounts via PowerShell (Local) |
c955a599-3653-4fe5-b631-f11c00eb0397 | T1087.001 | linux, macos | sh | View accounts with UID 0 |
e6f36545-dc1e-47f0-9f48-7f730f54a02e | T1087.001 | linux, macos | sh | Enumerate users and groups |
fed9be70-0186-4bde-9f8a-20945f9370c2 | T1087.001 | linux, macos | sh | View sudoers access |
00c652e2-0750-4ca6-82ff-0204684a6fe4 | T1087.002 | windows | powershell | Enumerate Root Domain linked policies Discovery |
02e8be5a-3065-4e54-8cc8-a14d138834d3 | T1087.002 | windows | powershell | Enumerate Active Directory Users with ADSISearcher |
161dcd85-d014-4f5e-900c-d3eaae82a0f7 | T1087.002 | windows | command_prompt | Enumerate logged on users via CMD (Domain) |
394012d9-2164-4d4f-b9e5-acf30ba933fe | T1087.002 | windows | powershell | Suspicious LAPS Attributes Query with Get-ADComputer all properties |
46f8dbe9-22a5-4770-8513-66119c5be63b | T1087.002 | windows | powershell | Enumerate Active Directory for Unconstrained Delegation |
51a98f96-0269-4e09-a10f-e307779a8b05 | T1087.002 | windows | powershell | Suspicious LAPS Attributes Query with adfind ms-Mcs-AdmPwd |
5e2938fb-f919-47b6-8b29-2f6a1f718e99 | T1087.002 | windows | command_prompt | Adfind - Enumerate Active Directory Exchange AD Objects |
6e85bdf9-7bc4-4259-ac0f-f0cb39964443 | T1087.002 | windows | powershell | Suspicious LAPS Attributes Query with Get-ADComputer ms-Mcs-AdmPwd property |
6fbc9e68-5ad7-444a-bd11-8bf3136c477e | T1087.002 | windows | command_prompt | Enumerate all accounts (Domain) |
736b4f53-f400-4c22-855d-1a6b5a551600 | T1087.002 | windows | command_prompt | Adfind -Listing password policy |
7ab0205a-34e4-4a44-9b04-e1541d1a57be | T1087.002 | windows | powershell | Enumerate Linked Policies In ADSISearcher Discovery |
8b8a6449-be98-4f42-afd2-dedddc7453b2 | T1087.002 | windows | powershell | Enumerate all accounts via PowerShell (Domain) |
93662494-5ed7-4454-a04c-8c8372808ac2 | T1087.002 | windows | powershell | Get-DomainUser with PowerView |
95018438-454a-468c-a0fa-59c800149b59 | T1087.002 | windows | powershell | Automated AD Recon (ADRecon) |
abf00f6c-9983-4d9a-afbc-6b1c6c6448e1 | T1087.002 | windows | powershell | Suspicious LAPS Attributes Query with adfind all properties |
b8a563d4-a836-4993-a74e-0a19b8481bfe | T1087.002 | windows | powershell | Wevtutil - Discover NTLM Users Remote |
b95fd967-4e62-4109-b48d-265edfd28c3a | T1087.002 | windows | command_prompt | Adfind - Enumerate Active Directory Admins |
c70ab9fd-19e2-4e02-a83c-9cfa8eaa8fef | T1087.002 | windows | command_prompt | Enumerate Default Domain Admin Details (Domain) |
ce483c35-c74b-45a7-a670-631d1e69db3d | T1087.002 | windows | powershell | WinPwn - generaldomaininfo |
e1ec8d20-509a-4b9a-b820-06c9b2da8eb7 | T1087.002 | windows | command_prompt | Adfind - Enumerate Active Directory User Objects |
f450461c-18d1-4452-9f0d-2c42c3f08624 | T1087.002 | windows | powershell | Kerbrute - userenum |
ffbcfd62-15d6-4989-a21a-80bfc8e58bb5 | T1087.002 | windows | powershell | Suspicious LAPS Attributes Query with Get-ADComputer all properties and SearchScope |
0ac21132-4485-4212-a681-349e8a6637cd | T1090.001 | linux, macos | sh | Connection Proxy |
648d68c1-8bcd-4486-9abe-71c6655b6a2c | T1090.001 | macos | sh | Connection Proxy for macOS UI |
b8223ea9-4be2-44a6-b50a-9657a3d4e72a | T1090.001 | windows | powershell | portproxy reg key |
12631354-fdbc-4164-92be-402527e748da | T1090.003 | macos | sh | Tor Proxy Usage - MacOS |
14d55ca0-920e-4b44-8425-37eedd72b173 | T1090.003 | windows | powershell | Psiphon |
7b9d85e5-c4ce-4434-8060-d3de83595e69 | T1090.003 | windows | powershell | Tor Proxy Usage - Windows |
d44b7297-622c-4be8-ad88-ec40d7563c75 | T1091 | windows | powershell | USB Malware Spread Simulation |
0268e63c-e244-42db-bef7-72a9e59fc1fc | T1095 | windows | powershell | ICMP C2 |
3e0e0e7f-6aa2-4a61-b61d-526c2cc9330e | T1095 | windows | powershell | Powercat C2 |
bcf0d1c1-3f6a-4847-b1c9-7ed4ea321f37 | T1095 | windows | powershell | Netcat C2 |
5598f7cb-cf43-455e-883a-f6008c5d46af | T1098 | windows | powershell | Admin Account Manipulate |
68190529-069b-4ffc-a942-919704158065 | T1098 | windows | powershell | Domain Password Policy Check: No Number in Password |
784d1349-5a26-4d20-af5e-d6af53bae460 | T1098 | windows | powershell | Domain Password Policy Check: Only Two Character Classes |
7d984ef2-2db2-4cec-b090-e637e1698f61 | T1098 | windows | powershell | Domain Password Policy Check: No Special Character in Password |
81959d03-c51f-49a1-bb24-23f1ec885578 | T1098 | windows | powershell | Domain Password Policy Check: Common Password Use |
945da11e-977e-4dab-85d2-f394d03c5887 | T1098 | windows | powershell | Domain Password Policy Check: No Lowercase Character in Password |
a55a22e9-a3d3-42ce-bd48-2653adb8f7a9 | T1098 | windows | powershell | Domain Account and Group Manipulate |
b299c120-44a7-4d68-b8e2-8ba5a28511ec | T1098 | windows | powershell | Domain Password Policy Check: No Uppercase Character in Password |
d5b886d9-d1c7-4b6e-a7b0-460041bf2823 | T1098 | windows | command_prompt | Password Change on Directory Service Restore Mode (DSRM) Account |
fc5f9414-bd67-4f5f-a08e-e5381e29cbd1 | T1098 | windows | powershell | Domain Password Policy Check: Short Password |
342cc723-127c-4d3a-8292-9c0c6b4ecadc | T1098.004 | linux, macos | sh | Modify SSH Authorized Keys |
1a02df58-09af-4064-a765-0babe1a0d1e2 | T1105 | windows | powershell | Download a file with IMEWDBLD.exe |
205e676e-0401-4bae-83a5-94b8c5daeb22 | T1105 | windows | powershell | Windows push file using sftp.exe |
2a4b0d29-e5dd-4b66-b729-07423ba1cd9d | T1105 | windows | powershell | Windows push file using scp.exe |
2b080b99-0deb-4d51-af0f-833d37c4ca6a | T1105 | windows | command_prompt | Curl Download File |
2ca61766-b456-4fcf-a35a-1233685e1cad | T1105 | windows | command_prompt | OSTAP Worming Activity |
3d25f1f2-55cb-4a41-a523-d17ad4cfba19 | T1105 | windows | powershell | Windows pull file using sftp.exe |
3dd6a6cf-9c78-462c-bd75-e9b54fc8925b | T1105 | windows | powershell | Download a file with OneDrive Standalone Updater |
401667dc-05a6-4da0-a2a7-acfe4819559c | T1105 | windows | powershell | Windows pull file using scp.exe |
42dc4460-9aa6-45d3-b1a6-3955d34e1fe8 | T1105 | windows | powershell | Windows - PowerShell Download |
49845fc1-7961-4590-a0f0-3dbcf065ae7e | T1105 | windows | command_prompt | Printer Migration Command-Line Tool UNC share folder into a zip file |
54782d65-12f0-47a5-b4c1-b70ee23de6df | T1105 | windows | command_prompt | Lolbas replace.exe use to copy file |
54a4daf1-71df-4383-9ba7-f1a295d8b6d2 | T1105 | windows | powershell | File Download via PowerShell |
5bcefe5f-3f30-4f1c-a61a-8d7db3f4450c | T1105 | macos | sh | File download via nscurl |
5f507e45-8411-4f99-84e7-e38530c45d01 | T1105 | windows | command_prompt | File download with finger.exe on Windows |
635c9a38-6cbf-47dc-8615-3810bc1167cf | T1105 | windows | command_prompt | Curl Upload File |
66ee226e-64cb-4dae-80e3-5bf5763e4a51 | T1105 | windows | command_prompt | Arbitrary file download using the Notepad++ GUP.exe binary |
6934c16e-0b3a-4e7f-ab8c-c414acd32181 | T1105 | windows | powershell | File Download with Sqlcmd.exe |
6fdaae87-c05b-42f8-842e-991a74e8376b | T1105 | windows | command_prompt | certreq download |
70f4d07c-5c3e-4d53-bb0a-cdf3ada14baf | T1105 | windows | powershell | MAZE Propagation Script |
815bef8b-bf91-4b67-be4c-abe4c2a94ccc | T1105 | windows | command_prompt | Download a File with Windows Defender MpCmdRun.exe |
97116a3f-efac-4b26-8336-b9cb18c45188 | T1105 | windows | command_prompt | Download a file using wscript |
a1921cd3-9a2d-47d5-a891-f1d0f2a7a31b | T1105 | windows | command_prompt | Windows - BITSAdmin BITS Download |
b1729c57-9384-4d1c-9b99-9b220afb384e | T1105 | windows | command_prompt | Nimgrab - Transfer Files |
c01cad7f-7a4c-49df-985e-b190dcf6a279 | T1105 | windows | command_prompt | iwr or Invoke Web-Request download |
c82b1e60-c549-406f-9b00-0a8ae31c9cfe | T1105 | windows | command_prompt | Remote File Copy using PSCP |
c99a829f-0bb8-4187-b2c6-d47d1df74cab | T1105 | linux, macos | sh | whois file download |
d239772b-88e2-4a2e-8473-897503401bcc | T1105 | windows | command_prompt | Download a file with Microsoft Connection Manager Auto-Download |
dd3b61dd-7bbc-48cd-ab51-49ad1a776df0 | T1105 | windows | command_prompt | certutil download (urlcache) |
ed0335ac-0354-400c-8148-f6151d20035a | T1105 | windows | command_prompt | Lolbas replace.exe use to copy UNC file |
fa5a2759-41d7-4e13-a19c-e8f28a53566f | T1105 | windows | command_prompt | svchost writing a file to a UNC path |
ffd492e3-0455-4518-9fb1-46527c9f241b | T1105 | windows | powershell | certutil download (verifyctl) |
7ec5b74e-8289-4ff2-a162-b6f286a33abd | T1106 | windows | powershell | WinPwn - Get SYSTEM shell - Bind System Shell using CreateProcess technique |
99be2089-c52d-4a4a-b5c3-261ee42c8b62 | T1106 | windows | command_prompt | Execution through API - CreateProcess |
ae56083f-28d0-417d-84da-df4242da1f7c | T1106 | windows | powershell | Run Shellcode via Syscall in Go |
ce4e76e6-de70-4392-9efe-b281fc2b4087 | T1106 | windows | powershell | WinPwn - Get SYSTEM shell - Pop System Shell using CreateProcess technique |
e1f93a06-1649-4f07-89a8-f57279a7d60e | T1106 | windows | powershell | WinPwn - Get SYSTEM shell - Pop System Shell using NamedPipe Impersonation technique |
09480053-2f98-4854-be6e-71ae5f672224 | T1110.001 | windows | command_prompt | Brute Force Credentials of single Active Directory domain users via SMB |
59dbeb1a-79a7-4c2a-baf4-46d0f4c761c4 | T1110.001 | windows | powershell | Password Brute User using Kerbrute Tool |
c2969434-672b-4ec8-8df0-bbb91f40e250 | T1110.001 | windows | powershell | Brute Force Credentials of single Active Directory domain user via LDAP against domain controller (NTLM or Kerberos) |
ed6c2c87-bba6-4a28-ac6e-c8af3d6c2ab5 | T1110.001 | windows | powershell | ESXi - Brute Force Until Account Lockout |
6d27df5d-69d4-4c91-bc33-5983ffe91692 | T1110.002 | windows | command_prompt | Password Cracking with Hashcat |
263ae743-515f-4786-ac7d-41ef3a0d4b2b | T1110.003 | windows | powershell | Password Spray (DomainPasswordSpray) |
5ccf4bbd-7bf6-43fc-83ac-d9e38aff1d82 | T1110.003 | windows | powershell | WinPwn - DomainPasswordSpray Attacks |
90bc2e54-6c84-47a5-9439-0a2a92b4b175 | T1110.003 | windows | command_prompt | Password Spray all Domain Users |
b15bc9a5-a4f3-4879-9304-ea0011ace63a | T1110.003 | windows | powershell | Password Spray Invoke-DomainPasswordSpray Light |
c6f25ec3-6475-47a9-b75d-09ac593c5ecb | T1110.003 | windows | powershell | Password Spray using Kerbrute Tool |
f14d956a-5b6e-4a93-847f-0c415142f07d | T1110.003 | windows | powershell | Password spray all Active Directory domain users with a single password via LDAP against domain controller (NTLM or Kerberos) |
4852c630-87a9-409b-bb5e-5dc12c9ebcde | T1110.004 | windows | powershell | Brute Force:Credential Stuffing using Kerbrute Tool |
d546a3d9-0be5-40c7-ad82-5a7d79e1b66b | T1110.004 | macos | bash | SSH Credential Stuffing From MacOS |
003f466a-6010-4b15-803a-cbb478a314d7 | T1112 | windows | command_prompt | Disable Windows Toast Notifications |
01b20ca8-c7a3-4d86-af59-059f15ed5474 | T1112 | windows | command_prompt | Disable Windows OS Auto Update |
02d8b9f7-1a51-4011-8901-2d55cca667f9 | T1112 | windows | command_prompt | Modify UseTPMKeyPIN Registry entry |
09147b61-40f6-4b2a-b6fb-9e73a3437c96 | T1112 | windows | command_prompt | Disabling ShowUI Settings of Windows Error Reporting (WER) |
0b79c06f-c788-44a2-8630-d69051f1123d | T1112 | windows | powershell | BlackByte Ransomware Registry Changes - Powershell |
10b33fb0-c58b-44cd-8599-b6da5ad6384c | T1112 | windows | command_prompt | Modify UseTPMPIN Registry entry |
12e03af7-79f9-4f95-af48-d3f12f28a260 | T1112 | windows | command_prompt | Disable Win Defender Notification |
12f50e15-dbc6-478b-a801-a746e8ba1723 | T1112 | windows | command_prompt | Activate Windows NoClose Group Policy Feature |
1324796b-d0f6-455a-b4ae-21ffee6aa6b9 | T1112 | windows | command_prompt | Modify Registry of Current User Profile - cmd |
15f44ea9-4571-4837-be9e-802431a7bfae | T1112 | windows | powershell | Javascript in registry |
16bdbe52-371c-4ccf-b708-79fba61f1db4 | T1112 | windows | command_prompt | Enable RDP via Registry (fDenyTSConnections) |
1dd59fb3-1cb3-4828-805d-cf80b4c3bbb5 | T1112 | windows | command_prompt | Windows Add Registry Value to Load Service in Safe Mode without Network |
20fc9daa-bd48-4325-9aff-81b967a84b1d | T1112 | windows | command_prompt | Activate Windows NoPropertiesMyDocuments Group Policy Feature |
26fc7375-a551-4336-90d7-3f2817564304 | T1112 | windows | command_prompt | Requires the BitLocker PIN for Pre-boot authentication |
282f929a-6bc5-42b8-bd93-960c3ba35afe | T1112 | windows | command_prompt | Modify Registry of Local Machine - cmd |
3235aafe-b49d-451b-a1f1-d979fa65ddaf | T1112 | windows | command_prompt | Abusing MyComputer Disk Fragmentation Path for Persistence |
335a6b15-b8d2-4a3f-a973-ad69aa2620d7 | T1112 | windows | command_prompt | Windows Auto Update Option to Notify before download |
3448824b-3c35-4a9e-a8f5-f887f68bea21 | T1112 | windows | command_prompt | Terminal Server Client Connection History Cleared |
35727d9e-7a7f-4d0c-a259-dc3906d6e8b9 | T1112 | windows | command_prompt | Mimic Ransomware - Allow Multiple RDP Sessions per User |
37950714-e923-4f92-8c7c-51e4b6fffbf6 | T1112 | windows | command_prompt | Allow Simultaneous Download Registry |
396f997b-c5f8-4a96-bb2c-3c8795cf459d | T1112 | windows | command_prompt | Disable Windows Auto Reboot for current logon user |
39f1f378-ba8a-42b3-96dc-2a6540cfc1e3 | T1112 | windows | command_prompt | Mimic Ransomware - Enable Multiple User Sessions |
3ac0b30f-532f-43c6-8f01-fb657aaed7e4 | T1112 | windows | command_prompt | Modify UsePIN Registry entry |
3b625eaa-c10d-4635-af96-3eae7d2a2f3c | T1112 | windows | command_prompt | Tamper Win Defender Protection |
3dacb0d2-46ee-4c27-ac1b-f9886bf91a56 | T1112 | windows | command_prompt | Disable Windows Lock Workstation Feature |
3e757ce7-eca0-411a-9583-1c33b8508d52 | T1112 | windows | command_prompt | Windows HideSCANetwork Group Policy Feature |
4469192c-2d2d-4a3a-9758-1f31d937a92b | T1112 | windows | command_prompt | Abusing Windows TelemetryController Registry Key for Persistence |
45914594-8df6-4ea9-b3cc-7eb9321a807e | T1112 | windows | command_prompt | Disable Windows Security Center Notifications |
4b81bcfa-fb0a-45e9-90c2-e3efe5160140 | T1112 | windows | command_prompt | Disable Remote Desktop Security Settings Through Registry |
4c4bf587-fe7f-448f-ba8d-1ecec9db88be | T1112 | windows | command_prompt | Enforce Smart Card Authentication Through Registry |
4d72d4b1-fa7b-4374-b423-0fe326da49d2 | T1112 | windows | command_prompt | Activate Windows NoTrayContextMenu Group Policy Feature |
4f4e2f9f-6209-4fcf-9b15-3b7455706f5b | T1112 | windows | command_prompt | BlackByte Ransomware Registry Changes - CMD |
573d15da-c34e-4c59-a7d2-18f20d92dfa3 | T1112 | windows | command_prompt | Adding custom paths for application execution |
599f3b5c-0323-44ed-bb63-4551623bf675 | T1112 | windows | command_prompt | Abusing MyComputer Disk Backup Path for Persistence |
5e27bdb4-7fd9-455d-a2b5-4b4b22c9dea4 | T1112 | windows | command_prompt | Activate Windows NoFileMenu Group Policy Feature |
5f8e36de-37ca-455e-b054-a2584f043c06 | T1112 | windows | command_prompt | Disable Windows Remote Desktop Protocol |
6174be7f-5153-4afd-92c5-e0c3b7cdb5ae | T1112 | windows | command_prompt | Event Viewer Registry Modification - Redirection URL |
61d35188-f113-4334-8245-8c6556d43909 | T1112 | windows | command_prompt | Disable Remote Desktop Anti-Alias Setting Through Registry |
65704cd4-6e36-4b90-b6c1-dc29a82c8e56 | T1112 | windows | command_prompt | NetWire RAT Registry Key Creation |
68254a85-aa42-4312-a695-38b7276307f8 | T1112 | windows | powershell | Use Powershell to Modify registry to store logon credentials |
6e0d1131-2d7e-4905-8ca5-d6172f05d03d | T1112 | windows | command_prompt | Disable Windows Shutdown Button |
71db768a-5a9c-4047-b5e7-59e01f188e84 | T1112 | windows | command_prompt | DisallowRun Execution Of Certain Applications |
795d3248-0394-4d4d-8e86-4e8df2a2693f | T1112 | windows | command_prompt | Windows Modify Show Compress Color And Info Tip Registry |
7979dd41-2045-48b2-a54e-b1bc2415c9da | T1112 | windows | command_prompt | Disable Windows Prefetch Through Registry |
7c8c7bd8-0a5c-4514-a6a3-0814c5a98cf0 | T1112 | windows | command_prompt | Modify UseTPM Registry entry |
7e7b62e9-5f83-477d-8935-48600f38a3c6 | T1112 | windows | command_prompt | RDP Authentication Level Override |
7f037590-b4c6-4f13-b3cc-e424c5ab8ade | T1112 | windows | command_prompt | Windows HideSCAVolume Group Policy Feature |
8023db1e-ad06-4966-934b-b6a0ae52689e | T1112 | windows | command_prompt | Hide Windows Clock Group Policy Feature |
81483501-b8a5-4225-8b32-52128e2f69db | T1112 | windows | command_prompt | Event Viewer Registry Modification - Redirection Program |
8318ad20-0488-4a64-98f4-72525a012f6b | T1112 | windows | powershell | Snake Malware Registry Blob |
86677d0e-0b5e-4a2b-b302-454175f9aa9e | T1112 | windows | command_prompt | Allow RDP Remote Assistance Feature |
8d85a5d8-702f-436f-bc78-fcd9119496fc | T1112 | windows | command_prompt | Windows HideSCAPower Group Policy Feature |
93386d41-525c-4a1b-8235-134a628dee17 | T1112 | windows | command_prompt | Activate Windows NoDesktop Group Policy Feature |
95b25212-91a7-42ff-9613-124aca6845a8 | T1112 | windows | command_prompt | Windows Powershell Logging Disabled |
a450e469-ba54-4de1-9deb-9023a6111690 | T1112 | windows | command_prompt | Activate Windows NoControlPanel Group Policy Feature |
a4637291-40b1-4a96-8c82-b28f1d73e54e | T1112 | windows | command_prompt | Windows HideSCAHealth Group Policy Feature |
ac34b0f7-0f85-4ac0-b93e-3ced2bc69bb8 | T1112 | windows | command_prompt | Disable Windows Registry Tool |
ac494fe5-81a4-4897-af42-e774cf005ecb | T1112 | windows | powershell | Setting Shadow key in Registry for RDP Shadowing |
af254e70-dd0e-4de6-9afe-a994d9ea8b62 | T1112 | windows | command_prompt | Disable Windows Task Manager application |
b1a4d687-ba52-4057-81ab-757c3dc0d3b5 | T1112 | windows | powershell | Modify Internet Zone Protocol Defaults in Current User Registry - PowerShell |
b5169fd5-85c8-4b2c-a9b6-64cc0b9febef | T1112 | windows | command_prompt | Modify UsePartialEncryptionKey Registry entry |
bacb3e73-8161-43a9-8204-a69fe0e4b482 | T1112 | windows | command_prompt | Modify EnableBDEWithNoTPM Registry entry |
c0413fb5-33e2-40b7-9b6f-60b29f4a7a18 | T1112 | windows | command_prompt | Modify registry to store logon credentials |
c0d6d67f-1f63-42cc-95c0-5fd6b20082ad | T1112 | windows | command_prompt | Disable Windows Notification Center |
c173c948-65e5-499c-afbe-433722ed5bd4 | T1112 | windows | command_prompt | Windows Add Registry Value to Load Service in Safe Mode with Network |
c26fb85a-fa50-4fab-a64a-c51f5dc538d5 | T1112 | windows | command_prompt | Activities To Disable Secondary Authentication Detected By Modified Registry Value. |
c30dada3-7777-4590-b970-dc890b8cf113 | T1112 | windows | command_prompt | Suppress Win Defender Notifications |
c375558d-7c25-45e9-bd64-7b23a97c1db0 | T1112 | windows | command_prompt | Ursnif Malware Registry Key Creation |
c691cee2-8d17-4395-b22f-00644c7f1c2d | T1112 | windows | command_prompt | Modify RDP-Tcp Initial Program Registry Entry |
c8480c83-a932-446e-a919-06a1fd1e512a | T1112 | windows | command_prompt | Modify UseTPMKey Registry entry |
c88ef166-50fa-40d5-a80c-e2b87d4180f7 | T1112 | windows | command_prompt | Modify Internet Zone Protocol Defaults in Current User Registry - cmd |
ca8ba39c-3c5a-459f-8e15-280aec65a910 | T1112 | windows | command_prompt | Scarab Ransomware Defense Evasion Activities |
cf447677-5a4e-4937-a82c-e47d254afd57 | T1112 | windows | powershell | Add domain to Trusted sites Zone |
d1de3767-99c2-4c6c-8c5a-4ba4586474c8 | T1112 | windows | command_prompt | Do Not Connect To Win Update |
d2561a6d-72bd-408c-b150-13efe1801c2a | T1112 | windows | powershell | Disable Windows CMD application |
d29b7faf-7355-4036-9ed3-719bd17951ed | T1112 | windows | command_prompt | Activate Windows NoSetTaskbar Group Policy Feature |
d2c9e41e-cd86-473d-980d-b6403562e3e1 | T1112 | windows | command_prompt | Disable Windows Error Reporting Settings |
d49ff3cc-8168-4123-b5b3-f057d9abbd55 | T1112 | windows | command_prompt | Activate Windows NoRun Group Policy Feature |
d4a6da40-618f-454d-9a9e-26af552aaeb0 | T1112 | windows | command_prompt | Disable Windows Change Password Feature |
d88a3d3b-d016-4939-a745-03638aafd21b | T1112 | windows | command_prompt | Set-Up Proxy Server |
e246578a-c24d-46a7-9237-0213ff86fb0c | T1112 | windows | command_prompt | Disable Windows LogOff Button |
e3ad8e83-3089-49ff-817f-e52f8c948090 | T1112 | windows | command_prompt | Enabling Remote Desktop Protocol via Remote Registry |
e672a340-a933-447c-954c-d68db38a09b1 | T1112 | windows | command_prompt | Modify EnableNonTPM Registry entry |
eb0ba433-63e5-4a8c-a9f0-27c4192e1336 | T1112 | windows | command_prompt | Enable Proxy Settings |
ecbd533e-b45d-4239-aeff-b857c6f6d68b | T1112 | windows | command_prompt | Flush Shimcache |
f2915249-4485-42e2-96b7-9bf34328d497 | T1112 | windows | command_prompt | Abusing MyComputer Disk Cleanup Path for Persistence |
f3a6cceb-06c9-48e5-8df8-8867a6814245 | T1112 | windows | powershell | Change Powershell Execution Policy to Bypass |
fe7974e5-5813-477b-a7bd-311d4f535e83 | T1112 | windows | command_prompt | Enabling Restricted Admin Mode via Command_Prompt |
ffbb407e-7f1d-4c95-b22e-548169db1fbd | T1112 | windows | command_prompt | Activate Windows NoFind Group Policy Feature |
ffeddced-bb9f-49c6-97f0-3d07a509bf94 | T1112 | windows | command_prompt | Activities To Disable Microsoft [FIDO Aka Fast IDentity Online] Authentication Detected By Modified Registry Value. |
0f47ceb1-720f-4275-96b8-21f0562217ac | T1113 | macos | bash | Screencapture |
3c898f62-626c-47d5-aad2-6de873d69153 | T1113 | windows | powershell | Windows Screencapture |
5a496325-0115-4274-8eb9-755b649ad0fb | T1113 | windows | powershell | Windows Recall Feature Enabled - DisableAIDataAnalysis Value Deleted |
98f19852-7348-4f99-9e15-6ff4320464c7 | T1113 | windows | powershell | RDP Bitmap Cache Extraction via bmc-tools |
deb7d358-5fbd-4dc4-aecc-ee0054d2d9a4 | T1113 | macos | bash | Screencapture (silent) |
e9313014-985a-48ef-80d9-cde604ffc187 | T1113 | windows | powershell | Windows Screen Capture (CopyFromScreen) |
3f1b5096-0139-4736-9b78-19bcb02bb1cb | T1114.001 | windows | powershell | Email Collection with PowerShell Get-Inbox |
0cd14633-58d4-4422-9ede-daa2c9474ae7 | T1115 | windows | command_prompt | Utilize Clipboard to store or execute commands from |
1ac2247f-65f8-4051-b51f-b0ccdfaaa5ff | T1115 | macos | bash | Execute commands from clipboard |
9c8d5a72-9c98-48d3-b9bf-da2cc43bdf52 | T1115 | windows | powershell | Collect Clipboard Data via VBA |
d6dc21af-bec9-4152-be86-326b6babd416 | T1115 | windows | powershell | Execute Commands from Clipboard using PowerShell |
634bd9b9-dc83-4229-b19f-7f83ba9ad313 | T1119 | windows | powershell | Automated Collection PowerShell |
aa1180e2-f329-4e1e-8625-2472ec0bfaf3 | T1119 | windows | command_prompt | Recon information for export with Command Prompt |
c3f6d794-50dd-482f-b640-0384fbb7db26 | T1119 | windows | powershell | Recon information for export with PowerShell |
cb379146-53f1-43e0-b884-7ce2c635ff5b | T1119 | windows | command_prompt | Automated Collection Command Prompt |
2cb4dbf2-2dca-4597-8678-4d39d207a3a5 | T1120 | windows | powershell | Win32_PnPEntity Hardware Inventory |
424e18fd-48b8-4201-8d3a-bf591523a686 | T1120 | windows | command_prompt | Peripheral Device Discovery via fsutil |
5c876daf-db1e-41cf-988d-139a7443ccd4 | T1120 | windows | powershell | Get Printer Device List via PowerShell Command |
cb6e76ca-861e-4a7f-be08-564caa3e6f75 | T1120 | windows | powershell | WinPwn - printercheck |
7a21cce2-6ada-4f7c-afd9-e1e9c481e44a | T1123 | windows | command_prompt | Registry artefact when application use microphone |
9c3ad250-b185-4444-b5a9-d69218a10c95 | T1123 | windows | powershell | using device audio capture commandlet |
c7a0bb71-70ce-4a53-b115-881f241b795b | T1123 | macos | sh | using Quicktime Player |
1d5711d6-655c-4a47-ae9c-6503c74fa877 | T1124 | windows | powershell | System Time Discovery - PowerShell |
20aba24b-e61f-4b26-b4ce-4784f763ca20 | T1124 | windows | command_prompt | System Time Discovery |
25c5d1f1-a24b-494a-a6c5-5f50a1ae7f47 | T1124 | windows | command_prompt | Discover System Time Zone via Registry |
53ead5db-7098-4111-bb3f-563be390e72e | T1124 | windows | command_prompt | System Time with Windows time Command |
d5d5a6b0-0f92-42d8-985d-47aafa2dd4db | T1124 | windows | command_prompt | System Time Discovery W32tm as a Delay |
f449c933-0891-407f-821e-7916a21a1a6f | T1124 | linux, macos | sh | System Time Discovery in FreeBSD/macOS |
6581e4a7-42e3-43c5-a0d2-5a0d62f9702a | T1125 | windows | command_prompt | Registry artefact when application use webcam |
1ec1c269-d6bd-49e7-b71b-a461f7fa7bc8 | T1127 | windows | command_prompt | Lolbin Jsc.exe compile javascript to exe |
3fc9fea2-871d-414d-8ef6-02e85e322b80 | T1127 | windows | command_prompt | Lolbin Jsc.exe compile javascript to dll |
58742c0f-cb01-44cd-a60b-fb26e8871c93 | T1127.001 | windows | command_prompt | MSBuild Bypass Using Inline Tasks (C#) |
ab042179-c0c5-402f-9bc8-42741f5ce359 | T1127.001 | windows | command_prompt | MSBuild Bypass Using Inline Tasks (VB) |
7f843046-abf2-443f-b880-07a83cf968ec | T1129 | windows | command_prompt | ESXi - Install a custom VIB on an ESXi host |
1164f70f-9a88-4dff-b9ff-dc70e7bf0c25 | T1132.001 | linux, macos | sh | Base64 Encoded data. |
c3ed6d2a-e3ad-400d-ad78-bbfdbfeacc08 | T1132.001 | windows | powershell | XOR Encoded data. |
4c8db261-a58b-42a6-a866-0a294deedde4 | T1133 | windows | powershell | Running Chrome VPN Extensions via the Registry 2 vpn extension |
34f0a430-9d04-4d98-bcb5-1989f14719f0 | T1134.001 | windows | powershell | `SeDebugPrivilege` token duplication |
7be1bc0f-d8e5-4345-9333-f5f67d742cb9 | T1134.001 | windows | powershell | Launch NSudo Executable |
90db9e27-8e7c-4c04-b602-a45927884966 | T1134.001 | windows | powershell | Named pipe client impersonation |
9c6d799b-c111-4749-a42f-ec2f8cb51448 | T1134.001 | windows | powershell | Bad Potato |
f095e373-b936-4eb4-8d22-f47ccbfbe64a | T1134.001 | windows | powershell | Juicy Potato |
ccf4ac39-ec93-42be-9035-90e2f26bcd92 | T1134.002 | windows | powershell | WinPwn - Get SYSTEM shell - Pop System Shell using Token Manipulation technique |
dbf4f5a9-b8e0-46a3-9841-9ad71247239e | T1134.002 | windows | powershell | Access Token Manipulation |
069258f4-2162-46e9-9a25-c9c6c56150d2 | T1134.004 | windows | powershell | Parent PID Spoofing using PowerShell |
14920ebd-1d61-491a-85e0-fe98efe37f25 | T1134.004 | windows | powershell | Parent PID Spoofing - Spawn from Current Process |
2988133e-561c-4e42-a15f-6281e6a9b2db | T1134.004 | windows | powershell | Parent PID Spoofing - Spawn from New Process |
cbbff285-9051-444a-9d17-c07cd2d230eb | T1134.004 | windows | powershell | Parent PID Spoofing - Spawn from Specified Process |
e9f2b777-3123-430b-805d-5cedc66ab591 | T1134.004 | windows | powershell | Parent PID Spoofing - Spawn from svchost.exe |
6bef32e5-9456-4072-8f14-35566fb85401 | T1134.005 | windows | command_prompt | Injection SID-History with mimikatz |
13daa2cf-195a-43df-a8bd-7dd5ffb607b5 | T1135 | windows | command_prompt | Network Share Discovery via dir command |
1b0814d1-bb24-402d-9615-1b20c50733fb | T1135 | windows | powershell | Network Share Discovery PowerShell |
20f1097d-81c1-405c-8380-32174d493bbb | T1135 | windows | command_prompt | Network Share Discovery command prompt |
987901d1-5b87-4558-a6d9-cffcabc638b8 | T1135 | windows | powershell | WinPwn - shareenumeration |
ab39a04f-0c93-4540-9ff2-83f862c385ae | T1135 | windows | command_prompt | View available share drives |
b1636f0a-ba82-435c-b699-0d78794d8bfd | T1135 | windows | powershell | Share Discovery with PowerView |
b19d74b7-5e72-450a-8499-82e49e379d1a | T1135 | windows | powershell | Enumerate All Network Shares with Snaffler |
d07e4cc1-98ae-447e-9d31-36cb430d28c4 | T1135 | windows | powershell | PowerView ShareFinder |
d1fa2a69-b0a2-4e8a-9112-529b00c19a41 | T1135 | windows | powershell | Enumerate All Network Shares with SharpShares |
f94b5ad9-911c-4eff-9718-fd21899db4f7 | T1135 | macos | sh | Network Share Discovery |
01993ba5-1da3-4e15-a719-b690d4f0f0b2 | T1136.001 | macos | bash | Create a user account on a MacOS system |
2170d9b5-bacd-4819-a952-da76dae0815f | T1136.001 | windows | powershell | Create a new Windows admin user via .NET |
6657864e-0323-4206-9344-ac9cd7265a4f | T1136.001 | windows | command_prompt | Create a new user in a command prompt |
bc8be0ac-475c-4fbf-9b1d-9fffd77afbde | T1136.001 | windows | powershell | Create a new user in PowerShell |
fda74566-a604-4581-a4cc-fbbe21d66559 | T1136.001 | windows | command_prompt | Create a new Windows admin user |
5a3497a4-1568-4663-b12a-d4a5ed70c7d7 | T1136.002 | windows | powershell | Create a new Domain Account using PowerShell |
dc7726d2-8ccb-4cc6-af22-0d5afb53a548 | T1136.002 | windows | command_prompt | Create a new account similar to ANONYMOUS LOGON |
fcec2963-9951-4173-9bfa-98d8b7834e62 | T1136.002 | windows | command_prompt | Create a new Windows domain admin user |
bfe6ac15-c50b-4c4f-a186-0fc6b8ba936c | T1137 | windows | command_prompt | Office Application Startup - Outlook as a C2 |
940db09e-80b6-4dd0-8d4d-7764f89b47a8 | T1137.001 | windows | powershell | Injecting a Macro into the Word Normal.dotm Template for Persistence via PowerShell |
c3e35b58-fe1c-480b-b540-7600fb612563 | T1137.002 | windows | powershell | Office Application Startup Test Persistence (HKCU) |
7a91ad51-e6d2-4d43-9471-f26362f5738e | T1137.004 | windows | command_prompt | Install Outlook Home Page Persistence |
5ff5249a-5807-480e-ab52-c430497a8a25 | T1137.005 | windows | powershell | Outlook Rules - Enumerate Existing Rules via PowerShell COM Object |
b0bd3d76-a57c-4699-83f4-8cd798dd09bd | T1137.005 | windows | powershell | Outlook Rule - Auto-Forward Emails to External Address via COM Object |
bddfd8d4-7687-4971-b611-50a537ab3ab4 | T1137.005 | windows | powershell | Outlook Rule - Sender Address Trigger with DeletePermanently Action via COM Object |
cb814cf8-24f2-41dc-a1cd-1c2073276d4a | T1137.005 | windows | powershell | Outlook Rule - Create Rule with Obfuscated Blank Name (MAPI Evasion) |
ffadc988-b682-4a68-bd7e-4803666be637 | T1137.005 | windows | powershell | Outlook Rule - Subject Trigger with DeletePermanently Action via COM Object |
082141ed-b048-4c86-99c7-2b8da5b5bf48 | T1137.006 | windows | powershell | Persistent Code Execution Via Excel VBA Add-in File (XLAM) |
441b1a0f-a771-428a-8af0-e99e4698cda3 | T1137.006 | windows | powershell | Code Executed Via Excel Add-in File (XLL) |
95408a99-4fa7-4cd6-a7ef-cb65f86351cf | T1137.006 | windows | powershell | Persistent Code Execution Via Word Add-in File (WLL) |
9c307886-9fef-41d5-b344-073a0f5b2f5f | T1137.006 | windows | powershell | Persistent Code Execution Via Excel Add-in File (XLL) |
f89e58f9-2b49-423b-ac95-1f3e7cfd8277 | T1137.006 | windows | powershell | Persistent Code Execution Via PowerPoint VBA Add-in File (PPAM) |
005943f9-8dd5-4349-8b46-0313c0a9f973 | T1140 | linux, macos | sh | Hex decoding with shell utilities |
356dc0e8-684f-4428-bb94-9313998ad608 | T1140 | linux, macos | sh | Base64 decoding with Python |
3a15c372-67c1-4430-ac8e-ec06d641ce4d | T1140 | linux, macos | sh | Linux Base64 Encoded Shebang in CLI |
6604d964-b9f6-4d4b-8ce8-499829a14d0a | T1140 | linux, macos | sh | Base64 decoding with Perl |
71abc534-3c05-4d0c-80f7-cbe93cb2aa94 | T1140 | windows | command_prompt | Certutil Rename and Decode |
9f8b1c54-cb76-4d5e-bb1f-2f5c0e8f5a11 | T1140 | windows | command_prompt | Expand CAB with expand.exe |
b4f6a567-a27a-41e5-b8ef-ac4b4008bb7e | T1140 | linux, macos | sh | Base64 decoding with shell utilities |
c3b65cd5-ee51-4e98-b6a3-6cbdec138efc | T1140 | linux, macos | bash | XOR decoding and command execution using Python |
dc6fe391-69e6-4506-bd06-ea5eeb4082f8 | T1140 | windows | command_prompt | Deobfuscate/Decode Files Or Information |
7a714703-9f6b-461c-b06d-e6aeac650f27 | T1176 | windows | powershell | Google Chrome Load Unpacked Extension With Command Line |
485ce873-2e65-4706-9c7e-ae3ab9e14213 | T1187 | windows | powershell | PetitPotam |
7f06b25c-799e-40f1-89db-999c9cc84317 | T1187 | windows | powershell | WinPwn - PowerSharpPack - Retrieving NTLM Hashes without Touching LSASS |
81cfdd7f-1f41-4cc5-9845-bb5149438e37 | T1187 | windows | powershell | Trigger an authenticated RPC call to a target server with no Sign flag set |
82a9f001-94c5-495e-9ed5-f530dbded5e2 | T1195 | windows | command_prompt | Octopus Scanner Malware Open Source Supply Chain |
3c73d728-75fb-4180-a12f-6712864d7421 | T1197 | windows | command_prompt | Bitsadmin Download (cmd) |
62a06ec5-5754-47d2-bcfc-123d8314c6ae | T1197 | windows | command_prompt | Persist, Download, & Execute |
afb5e09e-e385-4dee-9a94-6ee60979d114 | T1197 | windows | command_prompt | Bits download using desktopimgdownldr.exe (cmd) |
f63b8bc4-07e5-4112-acba-56f646f3f0bc | T1197 | windows | powershell | Bitsadmin Download (PowerShell) |
3177f4da-3d4b-4592-8bdc-aa23d0b2e843 | T1201 | windows | powershell | Get-DomainPolicy with PowerView |
4588d243-f24e-4549-b2e3-e627acc089f6 | T1201 | windows | command_prompt | Examine local password policy - Windows |
46c2c362-2679-4ef5-aec9-0e958e135be4 | T1201 | windows | command_prompt | Examine domain password policy - Windows |
4b7fa042-9482-45e1-b348-4b756b2a0742 | T1201 | macos | bash | Examine password policy - macOS |
510cc97f-56ac-4cd3-a198-d3218c23d889 | T1201 | windows | command_prompt | Use of SecEdit.exe to export the local security policy (including the password policy) |
b2698b33-984c-4a1c-93bb-e4ba72a0babb | T1201 | windows | powershell | Enumerate Active Directory Password Policy with get-addefaultdomainpasswordpolicy |
0fd14730-6226-4f5e-8d67-43c65f1be940 | T1202 | windows | powershell | Indirect Command Execution - Scriptrunner.exe |
8b34a448-40d9-4fc3-a8c8-4bb286faf7dc | T1202 | windows | command_prompt | Indirect Command Execution - forfiles.exe |
cecfea7a-5f03-4cdd-8bc8-6f7c22862440 | T1202 | windows | command_prompt | Indirect Command Execution - pcalua.exe |
cf3391e0-b482-4b02-87fc-ca8362269b29 | T1202 | windows | command_prompt | Indirect Command Execution - conhost.exe |
de323a93-2f18-4bd5-ba60-d6fca6aeff76 | T1202 | windows | powershell | Indirect Command Execution - RunMRU Dialog |
02f35d62-9fdc-4a97-b899-a5d9a876d295 | T1204.002 | windows | powershell | Potentially Unwanted Applications (PUA) |
0330a5d2-a45a-4272-a9ee-e364411c4b18 | T1204.002 | windows | powershell | Maldoc choice flags command execution |
22386853-f68d-4b50-a362-de235127c443 | T1204.002 | windows | powershell | Simulate Click-Fix via Downloaded BAT File |
24fd9719-7419-42dd-bce6-ab3463110b3c | T1204.002 | windows | powershell | Mirror Blast Emulation |
3f3120f0-7e50-4be2-88ae-54c61230cb9f | T1204.002 | windows | powershell | ClickFix Campaign - Abuse RunMRU to Launch mshta via PowerShell |
3f3af983-118a-4fa1-85d3-ba4daa739d80 | T1204.002 | windows | command_prompt | OSTap Payload Download |
4ea1fc97-8a46-4b4e-ba48-af43d2a98052 | T1204.002 | windows | powershell | Excel 4 Macro |
5202ee05-c420-4148-bf5e-fd7f7d24850c | T1204.002 | windows | powershell | Office Generic Payload Download |
581d7521-9c4b-420e-9695-2aec5241167f | T1204.002 | windows | powershell | LNK Payload Download |
8bebc690-18c7-4549-bc98-210f7019efff | T1204.002 | windows | powershell | OSTap Style Macro Execution |
9215ea92-1ded-41b7-9cd6-79f9a78397aa | T1204.002 | windows | powershell | Office launching .bat file from AppData |
a19ee671-ed98-4e9d-b19c-d1954a51585a | T1204.002 | windows | powershell | Headless Chrome code execution via VBA |
add560ef-20d6-4011-a937-2c340f930911 | T1204.002 | windows | powershell | OSTAP JS version |
e9795c8d-42aa-4ed4-ad80-551ed793d006 | T1204.003 | windows | powershell | Malicious Execution from Mounted ISO Image |
0f4c5eb0-98a0-4496-9c3d-656b4f2bc8f6 | T1207 | windows | powershell | DCShadow (Active Directory) |
275d963d-3f36-476c-8bef-a2a3960ee6eb | T1216 | windows | command_prompt | SyncAppvPublishingServer Signed Script PowerShell Command Execution |
2a8f2d3c-3dec-4262-99dd-150cb2a4d63a | T1216 | windows | command_prompt | manage-bde.wsf Signed Script Command Execution |
9dd29a1f-1e16-4862-be83-913b10a88f6c | T1216.001 | windows | command_prompt | PubPrn.vbs Signed Script Bypass |
1ca1f9c7-44bc-46bb-8c85-c50e2e94267b | T1217 | macos | sh | List Mozilla Firefox Bookmark Database Files on macOS |
4312cdbc-79fc-4a9c-becc-53d49c734bc5 | T1217 | windows | command_prompt | List Mozilla Firefox bookmarks on Windows with command prompt |
5fc528dd-79de-47f5-8188-25572b7fafe0 | T1217 | macos | sh | List Safari Bookmarks on MacOS |
727dbcdb-e495-4ab1-a6c4-80c7f77aef85 | T1217 | windows | command_prompt | List Internet Explorer Bookmarks using the command prompt |
74094120-e1f5-47c9-b162-a418a0f624d5 | T1217 | windows | powershell | Extract Edge Browsing History |
76f71e2f-480e-4bed-b61e-398fe17499d5 | T1217 | windows | command_prompt | List Google Chrome / Edge Chromium Bookmarks on Windows with command prompt |
b789d341-154b-4a42-a071-9111588be9bc | T1217 | macos | sh | List Google Chrome Bookmark JSON Files on macOS |
cfe6315c-4945-40f7-b5a4-48f7af2262af | T1217 | windows | powershell | Extract chrome Browsing History |
faab755e-4299-48ec-8202-fc7885eb6545 | T1217 | windows | powershell | List Google Chrome / Opera Bookmarks on Windows with powershell |
0e1483ba-8f0c-425d-b8c6-42736e058eaa | T1218 | windows | powershell | DiskShadow Command Execution |
13c0804e-615e-43ad-b223-2dfbacd0b0b3 | T1218 | windows | command_prompt | Lolbas ie4uinit.exe use as proxy |
49fbd548-49e9-4bb7-94a6-3769613912b8 | T1218 | windows | command_prompt | Load Arbitrary DLL via Wuauclt (Windows Update Client) |
4cc40fd7-87b8-4b16-b2d7-57534b86b911 | T1218 | windows | powershell | Renamed Microsoft.Workflow.Compiler.exe Payload Executions |
54ad7d5a-a1b5-472c-b6c4-f8090fb2daef | T1218 | windows | command_prompt | InfDefaultInstall.exe .inf Execution |
5bcda9cd-8e85-48fa-861d-b5a85d91d48c | T1218 | windows | command_prompt | Lolbin Gpscript logon option |
7816c252-b728-4ea6-a683-bd9441ca0b71 | T1218 | windows | powershell | System Binary Proxy Execution - Wlrmdr Lolbin |
7cbb0f26-a4c1-4f77-b180-a009aa05637e | T1218 | windows | powershell | Microsoft.Workflow.Compiler.exe Payload Execution |
9ebe7901-7edf-45c0-b5c7-8366300919db | T1218 | windows | powershell | Invoke-ATHRemoteFXvGPUDisablementCommand base test |
ab76e34f-28bf-441f-a39c-8db4835b89cc | T1218 | windows | command_prompt | Provlaunch.exe Executes Arbitrary Command via Registry Key |
ad2c17ed-f626-4061-b21e-b9804a6f3655 | T1218 | windows | command_prompt | Register-CimProvider - Execute evil dll |
b1eeb683-90bb-4365-bbc2-2689015782fe | T1218 | windows | powershell | LOLBAS CustomShellHost to Spawn Process |
c426dacf-575d-4937-8611-a148a86a5e61 | T1218 | windows | command_prompt | mavinject - Inject DLL into running process |
db020456-125b-4c8b-a4a7-487df8afb5a2 | T1218 | windows | command_prompt | ProtocolHandler.exe Downloaded a Suspicious File |
e5eedaed-ad42-4c1e-8783-19529738a349 | T1218 | windows | powershell | LOLBAS Msedge to Spawn Process |
f8da74bb-21b8-4af9-8d84-f2c8e4a220e3 | T1218 | windows | command_prompt | Lolbin Gpscript startup option |
0f8af516-9818-4172-922b-42986ef1e81d | T1218.001 | windows | command_prompt | Compiled HTML Help Remote Payload |
15756147-7470-4a83-87fb-bb5662526247 | T1218.001 | windows | powershell | Invoke CHM Shortcut Command with ITS and Help Topic |
20cb05e0-1fa5-406d-92c1-84da4ba01813 | T1218.001 | windows | command_prompt | Decompile Local CHM File |
29d6f0d7-be63-4482-8827-ea77126c1ef7 | T1218.001 | windows | powershell | Invoke CHM with default Shortcut Command Execution |
4f83adda-f5ec-406d-b318-9773c9ca92e5 | T1218.001 | windows | powershell | Invoke CHM with Script Engine and Help Topic |
5cb87818-0d7c-4469-b7ef-9224107aebe8 | T1218.001 | windows | command_prompt | Compiled HTML Help Local Payload |
5decef42-92b8-4a93-9eb2-877ddcb9401a | T1218.001 | windows | powershell | Invoke CHM Simulate Double click |
b4094750-5fc7-4e8e-af12-b4e36bf5e7f6 | T1218.001 | windows | powershell | Invoke CHM with InfoTech Storage Protocol Handler |
037e9d8a-9e46-4255-8b33-2ae3b545ca6f | T1218.002 | windows | command_prompt | Control Panel Items |
34e63321-9683-496b-bbc1-7566bc55e624 | T1218.003 | windows | command_prompt | CMSTP Executing Remote Scriptlet |
748cb4f6-2fb3-4e97-b7ad-b22635a09ab0 | T1218.003 | windows | command_prompt | CMSTP Executing UAC Bypass |
06d9deba-f732-48a8-af8e-bdd6e4d98c1d | T1218.004 | windows | powershell | InstallUtil Uninstall method call - '/installtype=notransaction /action=uninstall' variant |
34428cfa-8e38-41e5-aff4-9e1f8f3a7b4b | T1218.004 | windows | powershell | InstallUtil Uninstall method call - /U variant |
559e6d06-bb42-4307-bff7-3b95a8254bad | T1218.004 | windows | powershell | InstallUtil evasive invocation |
5a683850-1145-4326-a0e5-e91ced3c6022 | T1218.004 | windows | powershell | InstallUtil HelpText method call |
9b7a7cfc-dd2e-43f5-a885-c0a3c270dd93 | T1218.004 | windows | powershell | InstallUtil class constructor method call |
9f9968a6-601a-46ca-b7b7-6d4fe0f98f0b | T1218.004 | windows | powershell | InstallUtil Install method call |
d43a5bde-ae28-4c55-a850-3f4c80573503 | T1218.004 | windows | powershell | InstallHelper method call |
ffd9c807-d402-47d2-879d-f915cf2a3a94 | T1218.004 | windows | powershell | CheckIfInstallable method call |
007e5672-2088-4853-a562-7490ddc19447 | T1218.005 | windows | powershell | Invoke HTML Application - Jscript Engine over Local UNC Simulating Lateral Movement |
1483fab9-4f52-4217-a9ce-daa9d7747cae | T1218.005 | windows | command_prompt | Mshta executes JavaScript Scheme Fetch Remote Payload With GetObject |
39ceed55-f653-48ac-bd19-aceceaf525db | T1218.005 | windows | powershell | Invoke HTML Application - Direct download from URI |
58a193ec-131b-404e-b1ca-b35cf0b18c33 | T1218.005 | windows | powershell | Invoke HTML Application - Jscript Engine Simulating Double Click |
8707a805-2b76-4f32-b1c0-14e558205772 | T1218.005 | windows | command_prompt | Mshta used to Execute PowerShell |
906865c3-e05f-4acc-85c4-fbc185455095 | T1218.005 | windows | command_prompt | Mshta executes VBScript to execute malicious command |
b8a8bdb2-7eae-490d-8251-d5e0295b2362 | T1218.005 | windows | powershell | Invoke HTML Application - Simulate Lateral Movement over UNC Path |
c4b97eeb-5249-4455-a607-59f95485cb45 | T1218.005 | windows | powershell | Mshta Executes Remote HTML Application (HTA) |
d3eaaf6a-cdb1-44a9-9ede-b6c337d0d840 | T1218.005 | windows | powershell | Invoke HTML Application - JScript Engine with Inline Protocol Handler |
e7e3a525-7612-4d68-a5d3-c4649181b8af | T1218.005 | windows | powershell | Invoke HTML Application - JScript Engine with Rundll32 and Inline Protocol Handler |
0106ffa5-fab6-4c7d-82e3-e6b8867d5e5d | T1218.007 | windows | command_prompt | Msiexec.exe - Execute the DllRegisterServer function of a DLL |
32eb3861-30da-4993-897a-42737152f5f8 | T1218.007 | windows | powershell | WMI Win32_Product Class - Execute Local MSI file with an embedded DLL |
44a4bedf-ffe3-452e-bee4-6925ab125662 | T1218.007 | windows | command_prompt | Msiexec.exe - Execute Remote MSI file |
55080eb0-49ae-4f55-a440-4167b7974f79 | T1218.007 | windows | powershell | WMI Win32_Product Class - Execute Local MSI file with an embedded EXE |
628fa796-76c5-44c3-93aa-b9d8214fd568 | T1218.007 | windows | command_prompt | Msiexec.exe - Execute Local MSI file with an embedded DLL |
882082f0-27c6-4eec-a43c-9aa80bccdb30 | T1218.007 | windows | powershell | WMI Win32_Product Class - Execute Local MSI file with embedded JScript |
8d73c7b0-c2b1-4ac1-881a-4aa644f76064 | T1218.007 | windows | command_prompt | Msiexec.exe - Execute Local MSI file with embedded VBScript |
a059b6c4-e7d6-4b2e-bcd7-9b2b33191a04 | T1218.007 | windows | command_prompt | Msiexec.exe - Execute Local MSI file with embedded JScript |
ab09ec85-4955-4f9c-b8e0-6851baf4d47f | T1218.007 | windows | command_prompt | Msiexec.exe - Execute the DllUnregisterServer function of a DLL |
cf470d9a-58e7-43e5-b0d2-805dffc05576 | T1218.007 | windows | powershell | WMI Win32_Product Class - Execute Local MSI file with embedded VBScript |
ed3fa08a-ca18-4009-973e-03d13014d0e8 | T1218.007 | windows | command_prompt | Msiexec.exe - Execute Local MSI file with an embedded EXE |
2430498b-06c0-4b92-a448-8ad263c388e2 | T1218.008 | windows | command_prompt | Odbcconf.exe - Execute Arbitrary DLL |
331ce274-f9c9-440b-9f8c-a1006e1fce0b | T1218.008 | windows | command_prompt | Odbcconf.exe - Load Response File |
71bfbfac-60b1-4fc0-ac8b-2cedbbdcb112 | T1218.009 | windows | command_prompt | Regasm Uninstall Method Call Test |
fd3c1c6a-02d2-4b72-82d9-71c527abb126 | T1218.009 | windows | powershell | Regsvcs Uninstall Method Call Test |
08ffca73-9a3d-471a-aeb0-68b4aa3ab37b | T1218.010 | windows | command_prompt | Regsvr32 local DLL execution |
1ae5ea1f-0a4e-4e54-b2f5-4ac328a7f421 | T1218.010 | windows | command_prompt | Regsvr32 Registering Non DLL |
449aa403-6aba-47ce-8a37-247d21ef0306 | T1218.010 | windows | command_prompt | Regsvr32 local COM scriptlet execution |
9d71c492-ea2e-4c08-af16-c6994cdf029f | T1218.010 | windows | command_prompt | Regsvr32 Silent DLL Install Call DllRegisterServer |
c9d0c4ef-8a96-4794-a75b-3d3a5e6f2a36 | T1218.010 | windows | command_prompt | Regsvr32 remote COM scriptlet execution |
22cfde89-befe-4e15-9753-47306b37a6e3 | T1218.011 | windows | command_prompt | Execution of HTA and VBS Files using Rundll32 and URL.dll |
2d5029f0-ae20-446f-8811-e7511b58e8b6 | T1218.011 | windows | command_prompt | Running DLL with .init extension and function |
32d1cf1b-cbc2-4c09-8d05-07ec5c83a821 | T1218.011 | windows | command_prompt | Rundll32 execute VBscript command using Ordinal number |
41fa324a-3946-401e-bbdd-d7991c628125 | T1218.011 | windows | command_prompt | Rundll32 syssetup.dll Execution |
57ba4ce9-ee7a-4f27-9928-3c70c489b59d | T1218.011 | windows | command_prompt | Rundll32 execute JavaScript Remote Payload With GetObject |
5e46a58e-cbf6-45ef-a289-ed7754603df9 | T1218.011 | windows | command_prompt | Rundll32 ieadvpack.dll Execution |
638730e7-7aed-43dc-bf8c-8117f805f5bb | T1218.011 | windows | command_prompt | Rundll32 execute VBscript command |
71d771cd-d6b3-4f34-bc76-a63d47a10b19 | T1218.011 | windows | command_prompt | Rundll32 setupapi.dll Execution |
83a95136-a496-423c-81d3-1c6750133917 | T1218.011 | windows | command_prompt | Rundll32 with desk.cpl |
8a7f56ee-10e7-444c-a139-0109438288eb | T1218.011 | windows | powershell | Rundll32 execute payload by calling RouteTheCall |
9f5d081a-ee5a-42f9-a04e-b7bdc487e676 | T1218.011 | windows | command_prompt | Launches an executable using Rundll32 and pcwutl.dll |
9fd5a74b-ba89-482a-8a3e-a5feaa3697b0 | T1218.011 | windows | command_prompt | Rundll32 with Ordinal Value |
ae3a8605-b26e-457c-b6b3-2702fd335bac | T1218.011 | windows | powershell | Execution of non-dll using rundll32.exe |
d91cae26-7fc1-457b-a854-34c8aad48c89 | T1218.011 | windows | command_prompt | Rundll32 advpack.dll Execution |
e4c04b6f-c492-4782-82c7-3bf75eb8077e | T1218.011 | windows | command_prompt | Rundll32 with Control_RunDLL |
f3ad3c5b-1db1-45c1-81bf-d3370ebab6c8 | T1218.011 | windows | command_prompt | Rundll32 execute command via FileProtocolHandler |
0ae9e327-3251-465a-a53b-485d4e3f58fa | T1219 | windows | powershell | Ammyy Admin Software Execution |
19acf63b-55c4-4b6a-8552-00a8865105c8 | T1219 | windows | powershell | UltraViewer - RAT Execution |
1aea6d15-70f1-4b4e-8b02-397b5d5ffe75 | T1219 | windows | powershell | Microsoft App Quick Assist Execution |
1b72b3bd-72f8-4b63-a30b-84e91b9c3578 | T1219 | windows | powershell | GoToAssist Files Detected Test on Windows |
3e1858ee-3550-401c-86ec-5e70ed79295b | T1219 | windows | powershell | Splashtop Streamer Execution |
42e51815-a6cc-4c75-b970-3f0ff54b610e | T1219 | windows | powershell | UltraVNC Execution |
4a18cc4e-416f-4966-9a9d-75731c4684c0 | T1219 | windows | powershell | ScreenConnect Application Download and Install on Windows |
6b8b7391-5c0a-4f8c-baee-78d8ce0ce330 | T1219 | windows | powershell | AnyDesk Files Detected Test on Windows |
8ca3b96d-8983-4a7f-b125-fc98cc0a2aa0 | T1219 | windows | powershell | TeamViewer Files Detected Test on Windows |
b025c580-029e-4023-888d-a42710d76934 | T1219 | windows | powershell | Splashtop Execution |
b1b8128b-c5d4-4de9-bf70-e60419274562 | T1219 | windows | powershell | MSP360 Connect Execution |
d03683ec-aae0-42f9-9b4c-534780e0f8e1 | T1219 | windows | powershell | LogMeIn Files Detected Test on Windows |
ecca999b-e0c8-40e8-8416-ad320b146a75 | T1219 | windows | powershell | NetSupport - RAT Execution |
f1641ba9-919a-4323-b74f-33372333bf0e | T1219 | windows | powershell | RustDesk Files Detected Test on Windows |
fbff3f1f-b0bf-448e-840f-7e1687affdce | T1219 | windows | powershell | RemotePC Software Execution |
1b237334-3e21-4a0c-8178-b8c996124988 | T1220 | windows | command_prompt | WMIC bypass using local XSL file |
7f5be499-33be-4129-a560-66021f379b9b | T1220 | windows | command_prompt | WMIC bypass using remote XSL file |
a7c3ab07-52fb-49c8-ab6d-e9c6d4a0a985 | T1220 | windows | command_prompt | MSXSL Bypass using remote files |
ca23bfb2-023f-49c5-8802-e66997de462d | T1220 | windows | command_prompt | MSXSL Bypass using local files |
1489e08a-82c7-44ee-b769-51b72d03521d | T1221 | windows | command_prompt | WINWORD Remote Template Injection |
6c4ac96f-d4fa-44f4-83ca-56d8f4a55c02 | T1222 | windows | command_prompt | Enable Local and Remote Symbolic Links via fsutil |
6cd715aa-20ac-4be1-a8f1-dda7bae160bd | T1222 | windows | powershell | Enable Local and Remote Symbolic Links via Powershell |
78bef0d4-57fb-417d-a67a-b75ae02ea3ab | T1222 | windows | command_prompt | Enable Local and Remote Symbolic Links via reg.exe |
32b979da-7b68-42c9-9a99-0e39900fc36c | T1222.001 | windows | command_prompt | attrib - hide file |
98d34bb4-6e75-42ad-9c41-1dae7dc6a001 | T1222.001 | windows | command_prompt | Take ownership using takeown utility |
a8206bcc-f282-40a9-a389-05d9c0263485 | T1222.001 | windows | command_prompt | cacls - Grant permission to specified user or group recursively |
a8568b10-9ab9-4140-a523-1c72e0176924 | T1222.001 | windows | command_prompt | SubInAcl Execution |
ac7e6118-473d-41ec-9ac0-ef4f1d1ed2f6 | T1222.001 | windows | command_prompt | Grant Full Access to folder for Everyone - Ryuk Ransomware Style |
bec1e95c-83aa-492e-ab77-60c71bbd21b0 | T1222.001 | windows | command_prompt | attrib - Remove read-only attribute |
0451125c-b5f6-488f-993b-5a32b09f7d8f | T1222.002 | linux, macos | bash | chmod - Change file or folder mode (symbolic mode) recursively |
18592ba1-5f88-4e3c-abc8-ab1c6042e389 | T1222.002 | linux, macos | sh | Chown through c script |
34ca1464-de9d-40c6-8c77-690adf36a135 | T1222.002 | linux, macos | sh | chmod - Change file or folder mode (numeric mode) |
3b015515-b3d8-44e9-b8cd-6fa84faf30b2 | T1222.002 | linux, macos | bash | chown - Change file or folder ownership recursively |
967ba79d-f184-4e0e-8d09-6362b3162e99 | T1222.002 | linux, macos | sh | chown - Change file or folder mode ownership only |
973631cf-6680-4ffa-a053-045e1b6b67ab | T1222.002 | linux, macos | sh | Chmod through c script |
b78598be-ff39-448f-a463-adbf2a5b7848 | T1222.002 | linux, macos | bash | chown - Change file or folder ownership and group recursively |
d169e71b-85f9-44ec-8343-27093ff3dfc0 | T1222.002 | linux, macos | bash | chown - Change file or folder ownership and group |
e7469fe2-ad41-4382-8965-99b94dd3c13f | T1222.002 | linux, macos | sh | chattr - Remove immutable file attribute |
ea79f937-4a4d-4348-ace6-9916aec453a4 | T1222.002 | linux, macos | sh | chmod - Change file or folder mode (numeric mode) recursively |
fc9d6695-d022-4a80-91b1-381f5c35aff3 | T1222.002 | linux, macos | sh | chmod - Change file or folder mode (symbolic mode) |
15fe436d-e771-4ff3-b655-2dca9ba52834 | T1482 | windows | command_prompt | Adfind - Enumerate Active Directory Trusts |
2e22641d-0498-48d2-b9ff-c71e496ccdbe | T1482 | windows | command_prompt | Windows - Discover domain trusts with nltest |
4700a710-c821-4e17-a3ec-9e4c81d6845f | T1482 | windows | command_prompt | Windows - Discover domain trusts with dsquery |
58ed10e8-0738-4651-8408-3a3e9a526279 | T1482 | windows | powershell | Get-ForestTrust with PowerView |
c58fbc62-8a62-489e-8f2d-3565d7d96f30 | T1482 | windows | powershell | Powershell enumerate domains and forests |
d1c73b96-ab87-4031-bad8-0e1b3b8bf3ec | T1482 | windows | command_prompt | Adfind - Enumerate Active Directory OUs |
ea1b4f2d-5b82-4006-b64f-f2845608a3bf | T1482 | windows | command_prompt | TruffleSnout - Listing AD Infrastructure |
f974894c-5991-4b19-aaf5-7cc2fe298c5d | T1482 | windows | powershell | Get-DomainTrust with PowerView |
9ab80952-74ee-43da-a98c-1e740a985f28 | T1484.001 | windows | command_prompt | LockBit Black - Modify Group policy settings -cmd |
b51eae65-5441-4789-b8e8-64783c26c1d1 | T1484.001 | windows | powershell | LockBit Black - Modify Group policy settings -Powershell |
1207ddff-f25b-41b3-aa0e-7c26d2b546d1 | T1485 | windows | command_prompt | ESXi - Delete VM Snapshots |
321fd25e-0007-417f-adec-33232252be19 | T1485 | windows | command_prompt | Overwrite deleted data on C drive |
476419b5-aebf-4366-a131-ae3e8dae5fc2 | T1485 | windows | powershell | Windows - Overwrite file with SysInternals SDelete |
1a01f6b8-b1e8-418e-bbe3-78a6f822759e | T1486 | macos | sh | Encrypt files using openssl utility - macOS |
44b68e11-9da2-4d45-a0d9-893dabd60f30 | T1486 | windows | command_prompt | Data Encrypt Using DiskCryptor |
4541e2c2-33c8-44b1-be79-9161440f1718 | T1486 | windows | powershell | Data Encrypted with GPG4Win |
645f0f5a-ef09-48d8-b9bc-f0e24c642d72 | T1486 | macos | sh | Encrypt files using 7z utility - macOS |
649349c7-9abf-493b-a7a2-b1aa4d141528 | T1486 | windows | command_prompt | PureLocker Ransom Note |
ab3f793f-2dcc-4da5-9c71-34988307263f | T1486 | windows | powershell | Akira Ransomware drop Files with .akira Extension and Ransomnote |
21dfb440-830d-4c86-a3e5-2a491d5a8d04 | T1489 | windows | command_prompt | Windows - Stop service using Service Controller |
41274289-ec9c-4213-bea4-e43c4aa57954 | T1489 | windows | command_prompt | Windows - Stop service using net.exe |
f3191b84-c38b-400b-867e-3a217a27795f | T1489 | windows | command_prompt | Windows - Stop service by killing process |
1c68c68d-83a4-4981-974e-8993055fa034 | T1490 | windows | command_prompt | Windows - Disable the SR scheduled task |
263ba6cb-ea2b-41c9-9d4e-b652dadd002c | T1490 | windows | command_prompt | Windows - wbadmin Delete Windows Backup Catalog |
39a295ca-7059-4a88-86f6-09556c1211e7 | T1490 | windows | powershell | Windows - Delete Volume Shadow Copies via WMI with PowerShell |
42111a6f-7e7f-482c-9b1b-3cfd090b999c | T1490 | windows | powershell | Windows - Delete Volume Shadow Copies via Diskshadow |
43819286-91a9-4369-90ed-d31fb4da2c01 | T1490 | windows | command_prompt | Windows - Delete Volume Shadow Copies |
584331dd-75bc-4c02-9e0b-17f5fd81c748 | T1490 | windows | command_prompt | Windows - wbadmin Delete systemstatebackup |
66e647d1-8741-4e43-b7c1-334760c2047f | T1490 | windows | command_prompt | Disable System Restore Through Registry |
6a3ff8dd-f49c-4272-a658-11c2fe58bd88 | T1490 | windows | command_prompt | Windows - Delete Volume Shadow Copies via WMI |
6b1dbaf6-cc8a-4ea6-891f-6058569653bf | T1490 | windows | command_prompt | Windows - Delete Backup Files |
a4420f93-5386-4290-b780-f4f66abc7070 | T1490 | windows | command_prompt | Modify VSS Service Permissions |
cf21060a-80b3-4238-a595-22525de4ab81 | T1490 | windows | command_prompt | Windows - Disable Windows Recovery Console Repair |
da558b07-69ae-41b9-b9d4-4d98154a7049 | T1490 | windows | powershell | Windows - vssadmin Resize Shadowstorage Volume |
0eeb68ce-e64c-4420-8d53-ad5bdc6f86d5 | T1491.001 | windows | powershell | Windows - Display a simulated ransom note via Notepad (non-destructive) |
30558d53-9d76-41c4-9267-a7bd5184bed3 | T1491.001 | windows | powershell | Replace Desktop Wallpaper |
30905f21-34f3-4504-8b4c-f7a5e314b810 | T1491.001 | windows | command_prompt | ESXi - Change Welcome Message on Direct Console User Interface (DCUI) |
ffcbfaab-c9ff-470b-928c-f086b326089b | T1491.001 | windows | powershell | Configure LegalNoticeCaption and LegalNoticeText registry keys to display ransom message |
44315fb0-f78d-4cef-b10f-cf21c1fe2c75 | T1496 | windows | powershell | Windows - Simulate CPU Load with PowerShell |
904a5a0e-fb02-490d-9f8d-0e256eb37549 | T1496 | linux, macos | sh | FreeBSD/macOS/Linux - Simulate CPU Load with Yes |
2b73cd9b-b2fb-4357-b9d7-c73c41d9e945 | T1497.001 | macos | sh | Check if System Integrity Protection is enabled |
4a41089a-48e0-47aa-82cb-5b81a463bc78 | T1497.001 | windows | powershell | Detect Virtualization Environment via WMI Manufacturer/Model Listing (Windows) |
502a7dc4-9d6f-4d28-abf2-f0e84692562d | T1497.001 | windows | powershell | Detect Virtualization Environment (Windows) |
6beae646-eb4c-4730-95be-691a4094408c | T1497.001 | macos | sh | Detect Virtualization Environment using sysctl (hw.model) |
a960185f-aef6-4547-8350-d1ce16680d09 | T1497.001 | macos | sh | Detect Virtualization Environment via ioreg |
e04d2e89-de15-4d90-92f9-a335c7337f0f | T1497.001 | macos | sh | Detect Virtualization Environment using system_profiler |
8b87dd03-8204-478c-bac3-3959f6528de3 | T1497.003 | linux, macos | sh | Delay execution with ping |
43e92449-ff60-46e9-83a3-1a38089df94d | T1505.002 | windows | powershell | Install MS Exchange Transport Agent Persistence |
0a2ce662-1efa-496f-a472-2fe7b080db16 | T1505.003 | windows | command_prompt | Web Shell Written to Disk |
53adbdfa-8200-490c-871c-d3b1ab3324b2 | T1505.004 | windows | command_prompt | Install IIS Module using AppCmd.exe |
cc3381fb-4bd0-405c-a8e4-6cacfac3b06c | T1505.004 | windows | powershell | Install IIS Module using PowerShell Cmdlet New-WebGlobalModule |
0b2eadeb-4a64-4449-9d43-3d999f4a317b | T1505.005 | windows | powershell | Simulate Patching termsrv.dll |
18136e38-0530-49b2-b309-eed173787471 | T1505.005 | windows | powershell | Modify Terminal Services DLL Path |
0bb64470-582a-4155-bde2-d6003a95ed34 | T1518 | windows | powershell | WinPwn - powerSQL |
103d6533-fd2a-4d08-976a-4a598565280f | T1518 | macos | sh | Find and Display Safari Browser Version |
10ba02d0-ab76-4f80-940d-451633f24c5b | T1518 | windows | powershell | WinPwn - DotNet |
68981660-6670-47ee-a5fa-7e74806420a4 | T1518 | windows | command_prompt | Find and Display Internet Explorer Browser Version |
7e79a1b6-519e-433c-ad55-3ff293667101 | T1518 | windows | powershell | WinPwn - Dotnetsearch |
c49978f6-bd6e-4221-ad2c-9e3e30cc1e3b | T1518 | windows | powershell | Applications Installed |
015cd268-996e-4c32-8347-94c80c6286ee | T1518.001 | windows | command_prompt | Security Software Discovery - AV Discovery via Get-CimInstance and Get-WmiObject cmdlets |
1553252f-14ea-4d3b-8a08-d7a4211aa945 | T1518.001 | windows | command_prompt | Security Software Discovery - AV Discovery via WMI |
7f566051-f033-49fb-89de-b6bacab730f0 | T1518.001 | windows | powershell | Security Software Discovery - powershell |
9dca5a1d-f78c-4a8d-accb-d6de67cfed6b | T1518.001 | windows | powershell | Security Software Discovery - Windows Firewall Enumeration |
ba62ce11-e820-485f-9c17-6f3c857cd840 | T1518.001 | macos | sh | Security Software Discovery - ps (macOS) |
d3415a0e-66ef-429b-acf4-a768876954f6 | T1518.001 | windows | powershell | Security Software Discovery - Windows Defender Enumeration |
e31564c8-4c60-40cd-a8f4-9261307e8336 | T1518.001 | windows | command_prompt | Get Windows Defender exclusion settings using WMIC |
f92a380f-ced9-491f-b338-95a991418ce2 | T1518.001 | windows | command_prompt | Security Software Discovery |
fe613cf3-8009-4446-9a0f-bc78a15b66c9 | T1518.001 | windows | command_prompt | Security Software Discovery - Sysmon Service |
189f7d6e-9442-4160-9bc3-5e4104d93ece | T1529 | windows | command_prompt | ESXi - Avoslocker enumerates VMs and forcefully kills VMs |
3d8c25b5-7ff5-4c9d-b21f-85ebd06654a4 | T1529 | windows | command_prompt | Logoff System - Windows |
47d0b042-a918-40ab-8cf9-150ffe919027 | T1529 | linux, macos | sh | Restart System via `reboot` - FreeBSD/macOS/Linux |
4963a81e-a3ad-4f02-adda-812343b351de | T1529 | linux, macos | sh | Shutdown System via `shutdown` - FreeBSD/macOS/Linux |
622cc1a0-45e7-428c-aed7-c96dd605fbe6 | T1529 | windows | command_prompt | ESXi - vim-cmd Used to Power Off VMs |
6326dbc4-444b-4c04-88f4-27e94d0327cb | T1529 | linux, macos | sh | Restart System via `shutdown` - FreeBSD/macOS/Linux |
987c9b4d-a637-42db-b1cb-e9e242c3991b | T1529 | windows | command_prompt | ESXi - Terminates VMs using pkill |
ad254fa8-45c0-403b-8c77-e00b3d3e7a64 | T1529 | windows | command_prompt | Shutdown System - Windows |
f4648f0d-bf78-483c-bafc-3ec99cd1c302 | T1529 | windows | command_prompt | Restart System - Windows |
1b99ef28-f83c-4ec5-8a08-1a56263a5bb2 | T1531 | windows | command_prompt | Change User Password - Windows |
3c717bf3-2ecc-4d79-8ac8-0bfbf08fbce6 | T1531 | linux, macos | sh | Change User Password via passwd |
43f71395-6c37-498e-ab17-897d814a0947 | T1531 | windows | powershell | Remove Account From Domain Admin Group |
4d938c43-2fe8-4d70-a5b3-5bf239aa7846 | T1531 | macos | sh | Delete User via dscl utility |
d3812c4e-30ee-466a-a0aa-07e355b561d6 | T1531 | macos | sh | Delete User via sysadminctl utility |
f21a1d7d-a62f-442a-8c3a-2440d43b19e5 | T1531 | windows | command_prompt | Delete User - Windows |
26a6b840-4943-4965-8df5-ef1f9a282440 | T1539 | windows | powershell | Steal Chrome Cookies (Windows) |
4b437357-f4e9-4c84-9fa6-9bcee6f826aa | T1539 | windows | powershell | Steal Firefox Cookies (Windows) |
b647f4ee-88de-40ac-9419-f17fac9489a7 | T1539 | windows | powershell | Steal Chrome v127+ cookies via Remote Debugging (Windows) |
e43cfdaf-3fb8-4a45-8de0-7eee8741d072 | T1539 | macos | bash | Steal Chrome Cookies via Remote Debugging (Mac) |
e57ba07b-3a33-40cd-a892-748273b9b49a | T1539 | macos | sh | Copy Safari BinaryCookies files using AppleScript |
b8a49f03-e3c4-40f2-b7bb-9e8f8fdddbf1 | T1542.001 | windows | powershell | UEFI Persistence via Wpbbin.exe File Creation |
66774fa8-c562-4bae-a58d-5264a0dd9dd7 | T1543.001 | macos | bash | Launch Agent - Root Directory |
1f896ce4-8070-4959-8a25-2658856a70c9 | T1543.003 | windows | powershell | Modify Service to Run Arbitrary Binary (Powershell) |
491a4af6-a521-4b74-b23b-f7b3f1ee9e77 | T1543.003 | windows | powershell | Service Installation PowerShell |
981e2942-e433-44e9-afc1-8c957a1496b6 | T1543.003 | windows | command_prompt | Service Installation CMD |
ed366cde-7d12-49df-a833-671904770b9f | T1543.003 | windows | command_prompt | Modify Fax service to run PowerShell |
ef0581fd-528e-4662-87bc-4c2affb86940 | T1543.003 | windows | command_prompt | TinyTurla backdoor service w64time |
fb4151a2-db33-4f8c-b7f8-78ea8790f961 | T1543.003 | windows | command_prompt | Remote Service Installation CMD |
03ab8df5-3a6b-4417-b6bd-bb7a5cfd74cf | T1543.004 | macos | bash | Launch Daemon |
17d1a3cc-3373-495a-857a-e5dd005fb302 | T1546 | windows | command_prompt | Adding custom debugger for Windows Error Reporting |
2db7852e-5a32-4ec7-937f-f4e027881700 | T1546 | windows | command_prompt | Load custom DLL on mstsc execution |
36b8dbf9-59b1-4e9b-a3bb-36e80563ef01 | T1546 | windows | powershell | HKCU - Persistence using CommandProcessor AutoRun key (Without Elevation) |
547a4736-dd1c-4b48-b4fe-e916190bb2e7 | T1546 | windows | powershell | Persistence via ErrorHandler.cmd script execution |
a574dafe-a903-4cce-9701-14040f4f3532 | T1546 | windows | powershell | HKLM - Persistence using CommandProcessor AutoRun key (With Elevation) |
aca9ae16-7425-4b6d-8c30-cad306fdbd5b | T1546 | windows | powershell | Persistence with Custom AutodialDLL |
adae83d3-0df6-45e7-b2c3-575f91584577 | T1546 | windows | powershell | WMI Invoke-CimMethod Start Process |
b7fc4c3f-fe6e-479a-ba27-ef91b88536e3 | T1546 | windows | command_prompt | Persistence using automatic execution of custom DLL during RDP session |
f0027655-25ef-47b0-acaf-3d83d106156c | T1546 | windows | command_prompt | Persistence using STARTUP-PATH in MS-WORD |
10a08978-2045-4d62-8c42-1957bbbea102 | T1546.001 | windows | command_prompt | Change Default File Association |
281201e7-de41-4dc9-b73d-f288938cbb64 | T1546.002 | windows | command_prompt | Set Arbitrary Binary as Screensaver |
29786d7e-8916-4de6-9c55-be7b093b2706 | T1546.003 | windows | powershell | Windows MOFComp.exe Load MOF File |
3c64f177-28e2-49eb-a799-d767b24dd1e0 | T1546.003 | windows | powershell | Persistence via WMI Event Subscription - CommandLineEventConsumer |
fecd0dfd-fb55-45fa-a10b-6250272d0832 | T1546.003 | windows | powershell | Persistence via WMI Event Subscription - ActiveScriptEventConsumer |
94500ae1-7e31-47e3-886b-c328da46872f | T1546.004 | linux, macos | sh | Add command to .bash_profile |
14bd90b1-c3f3-4115-9861-cf0519a59654 | T1546.005 | linux, macos | bash | Trap DEBUG - Log All Shell Commands |
a547d1ba-1d7a-4cc5-a9cb-8d65e8809636 | T1546.005 | linux, macos | sh | Trap SIGINT |
a74b2e07-5952-4c03-8b56-56274b076b61 | T1546.005 | linux, macos | sh | Trap EXIT |
3244697d-5a3a-4dfc-941c-550f69f91a4d | T1546.007 | windows | command_prompt | Netsh Helper DLL Registration |
1db380da-3422-481d-a3c8-6d5770dba580 | T1546.008 | windows | command_prompt | Replace utilman.exe (Ease of Access Binary) with cmd.exe |
2002f5ea-cd13-4c82-bf73-e46722e5dc5e | T1546.008 | windows | command_prompt | Replace Narrator.exe (Narrator binary) with cmd.exe |
210be7ea-d841-40ec-b3e1-ff610bb62744 | T1546.008 | windows | command_prompt | Replace AtBroker.exe (App Switcher binary) with cmd.exe |
3309f53e-b22b-4eb6-8fd2-a6cf58b355a9 | T1546.008 | windows | powershell | Attaches Command Prompt as a Debugger to a List of Target Processes |
444ff124-4c83-4e28-8df6-6efd3ece6bd4 | T1546.008 | windows | command_prompt | Atbroker.exe (AT) Executes Arbitrary Command via Registry Key |
51ef369c-5e87-4f33-88cd-6d61be63edf2 | T1546.008 | windows | command_prompt | Create Symbolic Link From osk.exe to cmd.exe |
5e4fa70d-c789-470e-85e1-6992b92bb321 | T1546.008 | windows | command_prompt | Replace Magnify.exe (Magnifier binary) with cmd.exe |
7125eba8-7b30-426b-9147-781d152be6fb | T1546.008 | windows | command_prompt | Auto-start application on user logon |
825ba8ca-71cc-436b-b1dd-ea0d5e109086 | T1546.008 | windows | command_prompt | Replace DisplaySwitch.exe (Display Switcher binary) with cmd.exe |
934e90cf-29ca-48b3-863c-411737ad44e3 | T1546.008 | windows | command_prompt | Replace binary of sticky keys |
a5ad6104-5bab-4c43-b295-b4c44c7c6b05 | T1546.009 | windows | powershell | Create registry persistence via AppCert DLL |
a58d9386-3080-4242-ab5f-454c16503d18 | T1546.010 | windows | command_prompt | Install AppInit Shim |
9ab27e22-ee62-4211-962b-d36d9a0e6a18 | T1546.011 | windows | command_prompt | Application Shim Installation |
9b6a06f9-ab5e-4e8d-8289-1df4289db02f | T1546.011 | windows | powershell | Registry key creation and/or modification events for SDB |
aefd6866-d753-431f-a7a4-215ca7e3f13d | T1546.011 | windows | powershell | New shim database files created in the default shim database directory |
13117939-c9b2-4a43-999e-0a543df92f0d | T1546.012 | windows | powershell | GlobalFlags in Image File Execution Options |
46b1f278-c8ee-4aa5-acce-65e77b11f3c1 | T1546.012 | windows | command_prompt | IFEO Global Flags |
fdda2626-5234-4c90-b163-60849a24c0b8 | T1546.012 | windows | command_prompt | IFEO Add Debugger |
090e5aa5-32b6-473b-a49b-21e843a56896 | T1546.013 | windows | powershell | Append malicious start-process cmdlet |
23c9c127-322b-4c75-95ca-eff464906114 | T1546.014 | macos | sh | Persistance with Event Monitor - emond |
123520cc-e998-471b-a920-bd28e3feafa0 | T1546.015 | windows | powershell | COM Hijacking with RunDLL32 (Local Server Switch) |
33eacead-f117-4863-8eb0-5c6304fbfaa9 | T1546.015 | windows | powershell | COM hijacking via TreatAs |
48117158-d7be-441b-bc6a-d9e36e47b52b | T1546.015 | windows | powershell | COM Hijacking - InprocServer32 |
752191b1-7c71-445c-9dbe-21bb031b18eb | T1546.015 | windows | powershell | Powershell Execute COM Object |
05cc7a2c-ce32-46f2-a358-f27f76718c39 | T1546.018 | windows | powershell | Python Startup Hook - usercustomize.py (Windows) |
28ca4f81-fa96-47ff-8555-dde98017e89b | T1546.018 | macos | sh | Python Startup Hook - atomic_hook.pth (macOS) |
57289962-21dc-4501-b756-80cd30608d9f | T1546.018 | windows | powershell | Python Startup Hook - atomic_hook.pth (Windows) |
6e78084a-a433-4702-a838-cc7b765d87e8 | T1546.018 | linux, macos | sh | Python Startup Hook - usercustomize.py (Linux / MacOS) |
5cb0b071-8a5a-412f-839d-116beb2ed9f7 | T1547 | windows | powershell | Driver Installation Using pnputil.exe |
cb01b3da-b0e7-4e24-bf6d-de5223526785 | T1547 | windows | command_prompt | Add a driver |
fdd45306-74f6-4ade-9a97-0a4895961228 | T1547 | windows | command_prompt | Leverage Virtual Channels to execute custom DLL during successful RDP session |
14fdc3f1-6fc3-4556-8d36-aa89d9d42d02 | T1547.001 | windows | command_prompt | secedit used to create a Run key in the HKLM Hive |
1d958c61-09c6-4d9e-b26b-4130314e520e | T1547.001 | windows | powershell | HKLM - Modify default System Shell - Winlogon Shell KEY Value |
24e55612-85f6-4bd6-ae74-a73d02e3441d | T1547.001 | windows | powershell | Add Executable Shortcut Link to User Startup Folder |
2cb98256-625e-4da9-9d44-f2e5f90b8bd5 | T1547.001 | windows | powershell | Suspicious vbs file run from startup Folder |
554cbd88-cde1-4b56-8168-0be552eed9eb | T1547.001 | windows | command_prompt | Reg Key RunOnce |
5b6768e4-44d2-44f0-89da-a01d1430fd5e | T1547.001 | windows | powershell | Suspicious bat file run from startup Folder |
6e1666d5-3f2b-4b9a-80aa-f011322380d4 | T1547.001 | windows | command_prompt | Creating Boot Verification Program Key for application execution during successful boot |
8834b65a-f808-4ece-ad7e-2acdf647aafa | T1547.001 | windows | powershell | Change Startup Folder - HKCU Modify User Shell Folders Startup Value |
9dc7767b-30c1-4cc4-b999-50cab5e27891 | T1547.001 | windows | powershell | SystemBC Malware-as-a-Service Registry |
a70faea1-e206-4f6f-8d9a-67379be8f6f1 | T1547.001 | windows | powershell | HKCU - Policy Settings Explorer Run Key |
acfef903-7662-447e-a391-9c91c2f00f7b | T1547.001 | windows | powershell | Change Startup Folder - HKLM Modify User Shell Folders Common Startup Value |
b051b3c0-66e7-4a81-916d-e6383bd3a669 | T1547.001 | windows | command_prompt | Allowing custom application to execute during new RDP logon session |
b5c9a9bc-dda3-4ea0-b16a-add8e81ab75f | T1547.001 | windows | powershell | HKLM - Policy Settings Explorer Run Key |
bda6a3d6-7aa7-4e89-908b-306772e9662f | T1547.001 | windows | command_prompt | Add persistance via Recycle bin |
befc2b40-d487-4a5a-8813-c11085fb5672 | T1547.001 | windows | powershell | Modify BootExecute Value |
dade9447-791e-4c8f-b04b-3a35855dfa06 | T1547.001 | windows | powershell | Suspicious jse file run from startup Folder |
de47f4a0-2acb-416d-9a6b-cee584a4c4d1 | T1547.001 | windows | command_prompt | Add persistence via Windows Context Menu |
e55be3fd-3521-4610-9d1a-e210e42dcf05 | T1547.001 | windows | command_prompt | Reg Key Run |
eb44f842-0457-4ddc-9b92-c4caa144ac42 | T1547.001 | windows | powershell | PowerShell Registry RunOnce |
f7fab6cc-8ece-4ca7-a0f1-30a22fccd374 | T1547.001 | windows | powershell | HKLM - Append Command to Winlogon Userinit KEY Value |
be2590e8-4ac3-47ac-b4b5-945820f2fbe9 | T1547.002 | windows | powershell | Authentication Package |
29e0afca-8d1d-471a-8d34-25512fc48315 | T1547.003 | windows | powershell | Edit an existing time provider |
df1efab7-bc6d-4b88-8be9-91f55ae017aa | T1547.003 | windows | powershell | Create a new time provider |
95a3c42f-8c88-4952-ad60-13b81d929a9d | T1547.004 | windows | powershell | Winlogon HKLM Shell Key Persistence - PowerShell |
bf9f9d65-ee4d-4c3e-a843-777d04f19c38 | T1547.004 | windows | powershell | Winlogon Shell Key Persistence - PowerShell |
d40da266-e073-4e5a-bb8b-2b385023e5f9 | T1547.004 | windows | powershell | Winlogon Notify Key Logon Persistence - PowerShell |
f9b8daff-8fa7-4e6a-a1a7-7c14675a545b | T1547.004 | windows | powershell | Winlogon HKLM Userinit Key Persistence - PowerShell |
fb32c935-ee2e-454b-8fa3-1c46b42e8dfb | T1547.004 | windows | powershell | Winlogon Userinit Key Persistence - PowerShell |
afdfd7e3-8a0b-409f-85f7-886fdf249c9e | T1547.005 | windows | powershell | Modify HKLM:\System\CurrentControlSet\Control\Lsa Security Support Provider configuration in registry |
de3f8e74-3351-4fdb-a442-265dbf231738 | T1547.005 | windows | powershell | Modify HKLM:\System\CurrentControlSet\Control\Lsa\OSConfig Security Support Provider configuration in registry |
e5cb5564-cc7b-4050-86e8-f2d9eec1941f | T1547.006 | windows | powershell | Snake Malware Kernel Driver Comadmin |
f0007753-beb3-41ea-9948-760785e4c1e5 | T1547.006 | macos | bash | MacOS - Load Kernel Module via KextManagerLoadKextWithURL() |
f4391089-d3a5-4dd1-ab22-0419527f2672 | T1547.006 | macos | bash | MacOS - Load Kernel Module via kextload and kmutil |
5f5b71da-e03f-42e7-ac98-d63f9e0465cb | T1547.007 | macos | sh | Re-Opened Applications using LoginHook |
5fefd767-ef54-4ac6-84d3-751ab85e8aba | T1547.007 | macos | sh | Copy in loginwindow.plist for Re-Opened Applications |
766b6c3c-9353-4033-8b7e-38b309fa3a93 | T1547.007 | macos | sh | Append to existing loginwindow for Re-Opened Applications |
8ecef16d-d289-46b4-917b-0dba6dc81cf1 | T1547.008 | windows | powershell | Modify Registry to load Arbitrary DLL into LSASS - LsaDbExtPt |
ce4fc678-364f-4282-af16-2fb4c78005ce | T1547.009 | windows | command_prompt | Shortcut Modification |
cfdc954d-4bb0-4027-875b-a1893ce406f2 | T1547.009 | windows | powershell | Create shortcut to cmd in startup folders |
d34ef297-f178-4462-871e-9ce618d44e50 | T1547.010 | windows | command_prompt | Add Port Monitor persistence in Registry |
f7d38f47-c61b-47cc-a59d-fc0368f47ed0 | T1547.012 | windows | powershell | Print Processors |
04d55cef-f283-40ba-ae2a-316bc3b5e78c | T1547.014 | windows | powershell | HKLM - re-execute 'Internet Explorer Core Fonts' StubPath payload by decreasing version number |
39e417dd-4fed-4d9c-ae3a-ba433b4d0e9a | T1547.014 | windows | powershell | HKLM - Add malicious StubPath value to existing Active Setup Entry |
deff4586-0517-49c2-981d-bbea24d48d71 | T1547.014 | windows | powershell | HKLM - Add atomic_test key to launch executable as part of user setup |
716e756a-607b-41f3-8204-b214baf37c1d | T1547.015 | macos | bash | Add macOS LoginItem using Applescript |
ec5d76ef-82fe-48da-b931-bdb25a62bc65 | T1547.015 | windows | powershell | Persistence by modifying Windows Terminal profile |
896dfe97-ae43-4101-8e96-9a7996555d80 | T1548.001 | linux, macos | sh | Make and modify binary from C source |
db55f666-7cba-46c6-9fe6-205a05c3242c | T1548.001 | linux, macos | sh | Set a SetGID flag on file |
160a7c77-b00e-4111-9e45-7c2a44eda3fd | T1548.002 | windows | command_prompt | Disable UAC notification via registry keys |
1ed67900-66cd-4b09-b546-2a0ef4431a0c | T1548.002 | windows | powershell | WinPwn - UAC Bypass DiskCleanup technique |
235ec031-cd2d-465d-a7ae-68bab281e80e | T1548.002 | windows | command_prompt | UACME Bypass Method 56 |
251c5936-569f-42f4-9ac2-87a173b9e9b8 | T1548.002 | windows | powershell | Disable UAC admin consent prompt via ConsentPromptBehaviorAdmin registry key |
28104f8a-4ff1-4582-bcf6-699dce156608 | T1548.002 | windows | command_prompt | Bypass UAC using SilentCleanup task |
2b61977b-ae2d-4ae4-89cb-5c36c89586be | T1548.002 | windows | powershell | WinPwn - UAC Bypass DccwBypassUAC technique |
3b96673f-9c92-40f1-8a3e-ca060846f8d9 | T1548.002 | windows | powershell | UAC Bypass with WSReset Registry Modification |
3be891eb-4608-4173-87e8-78b494c029b7 | T1548.002 | windows | powershell | Bypass UAC using sdclt DelegateExecute |
3c51abf2-44bf-42d8-9111-dc96ff66750f | T1548.002 | windows | powershell | Bypass UAC using ComputerDefaults (PowerShell) |
3f627297-6c38-4e7d-a278-fc2563eaaeaa | T1548.002 | windows | powershell | Bypass UAC using Fodhelper - PowerShell |
5073adf8-9a50-4bd9-b298-a9bd2ead8af9 | T1548.002 | windows | command_prompt | Bypass UAC using Event Viewer (cmd) |
56163687-081f-47da-bb9c-7b231c5585cf | T1548.002 | windows | command_prompt | UACME Bypass Method 39 |
58f641ea-12e3-499a-b684-44dee46bd182 | T1548.002 | windows | command_prompt | Bypass UAC using Fodhelper |
695b2dac-423e-448e-b6ef-5b88e93011d6 | T1548.002 | windows | command_prompt | UACME Bypass Method 34 |
7825b576-744c-4555-856d-caf3460dc236 | T1548.002 | windows | command_prompt | UACME Bypass Method 61 |
85f3a526-4cfa-4fe7-98c1-dea99be025c7 | T1548.002 | windows | powershell | Disable UAC - Switch to the secure desktop when prompting for elevation via registry key |
8ceab7a2-563a-47d2-b5ba-0995211128d7 | T1548.002 | windows | command_prompt | UACME Bypass Method 23 |
964d8bf8-37bc-4fd3-ba36-ad13761ebbcc | T1548.002 | windows | powershell | WinPwn - UAC Magic |
9e8af564-53ec-407e-aaa8-3cb20c3af7f9 | T1548.002 | windows | command_prompt | Disable UAC using reg.exe |
a6ce9acf-842a-4af6-8f79-539be7608e2b | T1548.002 | windows | powershell | Bypass UAC using Event Viewer (PowerShell) |
a768aaa2-2442-475c-8990-69cf33af0f4e | T1548.002 | windows | command_prompt | Disable ConsentPromptBehaviorAdmin via registry keys |
b0f76240-9f33-4d34-90e8-3a7d501beb15 | T1548.002 | windows | command_prompt | UACME Bypass Method 31 |
b6f4645c-34ea-4c7c-98f2-d5a2747efb08 | T1548.002 | windows | command_prompt | UAC bypassed by Utilizing ProgIDs registry. |
dfb1b667-4bb8-4a63-a85e-29936ea75f29 | T1548.002 | windows | command_prompt | UACME Bypass Method 59 |
e514bb03-f71c-4b22-9092-9f961ec6fb03 | T1548.002 | windows | command_prompt | UACME Bypass Method 33 |
f3c145f9-3c8d-422c-bd99-296a17a8f567 | T1548.002 | windows | powershell | WinPwn - UAC Bypass ccmstp technique |
f7a35090-6f7f-4f64-bb47-d657bf5b10c1 | T1548.002 | windows | command_prompt | Bypass UAC by Mocking Trusted Directories |
eb05b028-16c8-4ad8-adea-6f5b219da9a9 | T1550.002 | windows | command_prompt | crackmapexec Pass the Hash |
ec23cef9-27d9-46e4-a68d-6f75f7b86908 | T1550.002 | windows | command_prompt | Mimikatz Pass the Hash |
f8757545-b00a-4e4e-8cfb-8cfb961ee713 | T1550.002 | windows | powershell | Invoke-WMIExec Pass the Hash |
a2fc4ec5-12c6-4fb4-b661-961f23f359cb | T1550.003 | windows | powershell | Rubeus Kerberos Pass The Ticket |
dbf38128-7ba7-4776-bedf-cc2eed432098 | T1550.003 | windows | command_prompt | Mimikatz Kerberos Ticket Attack |
a21118de-b11e-4ebd-b655-42f11142df0c | T1552 | iaas:aws, linux, macos | sh | AWS - Retrieve EC2 Password Data using stratus |
f9c3d0ab-479b-4019-945f-22ace2b1731a | T1552 | windows | powershell | Search for Passwords in Powershell History |
00e3e3c7-6c3c-455e-bd4b-461c7f0e7797 | T1552.001 | windows | powershell | WinPwn - passhunt |
0d4f2281-f720-4572-adc8-d5bb1618affe | T1552.001 | windows | powershell | List Credential Files via PowerShell |
0e56bf29-ff49-4ea5-9af4-3b81283fd513 | T1552.001 | windows | powershell | Extracting passwords with findstr |
114dd4e3-8d1c-4ea7-bb8d-8d8f6aca21f0 | T1552.001 | windows | powershell | WinPwn - sensitivefiles |
367d4004-5fc0-446d-823f-960c74ae52c3 | T1552.001 | windows | command_prompt | Access unattend.xml |
75f66e03-37d3-4704-9520-3210efbe33ce | T1552.001 | windows | powershell | WinPwn - powershellsensitive |
9e507bb8-1d30-4e3b-a49b-cb5727d7ea79 | T1552.001 | macos | bash | Extract Browser and System credentials with LaZagne |
aaa87b0e-5232-4649-ae5c-f1724a4b2798 | T1552.001 | windows | powershell | WinPwn - Loot local Credentials - AWS, Microsoft Azure, and Google Compute credentials |
b0cdacf6-8949-4ffe-9274-a9643a788e55 | T1552.001 | windows | command_prompt | List Credential Files via Command Prompt |
c9dc9de3-f961-4284-bd2d-f959c9f9fda5 | T1552.001 | windows | powershell | WinPwn - SessionGopher |
fdd0c913-714b-4c13-b40f-1824d6c015f2 | T1552.001 | windows | powershell | WinPwn - Snaffler |
af197fd7-e868-448e-9bd5-05d1bcd9d9e5 | T1552.002 | windows | command_prompt | Enumeration for PuTTY Credentials in Registry |
b6ec082c-7384-46b3-a111-9a9b8b14e5e7 | T1552.002 | windows | command_prompt | Enumeration for Credentials in Registry |
3cfde62b-7c33-4b26-a61e-755d6131c8ce | T1552.003 | linux, macos | sh | Search Through Bash History |
290df60e-4b5d-4a5e-b0c7-dc5348ea0c86 | T1552.004 | windows | command_prompt | Export Certificates with Mimikatz |
336b25bf-4514-4684-8924-474974f28137 | T1552.004 | windows | powershell | CertUtil ExportPFX |
520ce462-7ca7-441e-b5a5-f8347f632696 | T1552.004 | windows | command_prompt | Private Keys |
7617f689-bbd8-44bc-adcd-6f8968897848 | T1552.004 | windows | powershell | Export Root Certificate with Export-PFXCertificate |
78b274f8-acb0-428b-b1f7-7b0d0e73330a | T1552.004 | windows | powershell | Export Root Certificate with Export-Certificate |
78e95057-d429-4e66-8f82-0f060c1ac96f | T1552.004 | windows | powershell | ADFS token signing and encryption certificates theft - Local |
cab413d8-9e4a-4b8d-9b84-c985bd73a442 | T1552.004 | windows | powershell | ADFS token signing and encryption certificates theft - Remote |
870fe8fb-5e23-4f5f-b89d-dd7fe26f3b5f | T1552.006 | windows | command_prompt | GPP Passwords (findstr) |
e9584f82-322c-474a-b831-940fd8b4455c | T1552.006 | windows | powershell | GPP Passwords (Get-GPPPassword) |
fb3d46c6-9480-4803-8d7d-ce676e1f1a9b | T1553.001 | macos | sh | Gatekeeper Bypass |
e12f5d8d-574a-4e9d-8a84-c0e8b4a8a675 | T1553.003 | windows | command_prompt | SIP (Subject Interface Package) Hijacking via Custom DLL |
5fdb1a7a-a93c-4fbe-aa29-ddd9ef94ed1f | T1553.004 | windows | powershell | Install root CA on Windows with certutil |
76f49d86-5eb1-461a-a032-a480f86652f1 | T1553.004 | windows | powershell | Install root CA on Windows |
ca20a3f1-42b5-4e21-ad3f-1049199ec2e0 | T1553.004 | windows | powershell | Add Root Certificate to CurrentUser Certificate Store |
002cca30-4778-4891-878a-aaffcfa502fa | T1553.005 | windows | powershell | Mount ISO image |
42f22b00-0242-4afc-a61b-0da05041f9cc | T1553.005 | windows | powershell | Mount an ISO image and run executable from the ISO |
64b12afc-18b8-4d3f-9eab-7f6cae7c73f9 | T1553.005 | windows | powershell | Remove the Zone.Identifier alternate data stream |
c2587b8d-743d-4985-aa50-c83394eaeb68 | T1553.005 | windows | powershell | Execute LNK file from ISO |
bb6b51e1-ab92-45b5-aeea-e410d06405f8 | T1553.006 | windows | command_prompt | Code Signing Policy Modification |
079ee2e9-6f16-47ca-a635-14efcd994118 | T1555 | windows | powershell | WinPwn - Loot local Credentials - lazagne |
234f9b7c-b53d-4f32-897b-b880a6c9ea7b | T1555 | windows | powershell | Extract Windows Credential Manager via VBA |
36753ded-e5c4-4eb5-bc3c-e8fba236878d | T1555 | windows | powershell | Enumerate credentials from Windows Credential Manager using vaultcmd.exe [Windows Credentials] |
8fd5a296-6772-4766-9991-ff4e92af7240 | T1555 | windows | powershell | Dump credentials from Windows Credential Manager With PowerShell [web Credentials] |
afe369c2-b42e-447f-98a3-fb1f4e2b8552 | T1555 | windows | powershell | WinPwn - Loot local Credentials - Wifi Credentials |
bc071188-459f-44d5-901a-f8f2625b2d2e | T1555 | windows | powershell | Enumerate credentials from Windows Credential Manager using vaultcmd.exe [Web Credentials] |
c89becbe-1758-4e7d-a0f4-97d2188a23e3 | T1555 | windows | powershell | Dump credentials from Windows Credential Manager With PowerShell [windows Credentials] |
db965264-3117-4bad-b7b7-2523b7856b92 | T1555 | windows | powershell | WinPwn - Loot local Credentials - Decrypt Teamviewer Passwords |
1864fdec-ff86-4452-8c30-f12507582a93 | T1555.001 | macos | sh | Export Certificate Item(s) |
e544bbcb-c4e0-4bd0-b614-b92131635f59 | T1555.001 | macos | sh | Import Certificate Item(s) into Keychain |
28498c17-57e4-495a-b0be-cc1e36de408b | T1555.003 | windows | powershell | Simulating access to Opera Login Data |
3d111226-d09a-4911-8715-fe11664f960d | T1555.003 | windows | powershell | Simulating access to Chrome Login Data |
6f2c5c87-a4d5-4898-9bd1-47a55ecaf1dd | T1555.003 | windows | powershell | BrowserStealer (Chrome / Firefox / Microsoft Edge) |
70422253-8198-4019-b617-6be401b49fce | T1555.003 | windows | command_prompt | Dump Chrome Login Data with esentutl |
764ea176-fb71-494c-90ea-72e9d85dce76 | T1555.003 | windows | powershell | WinPwn - BrowserPwn |
8c05b133-d438-47ca-a630-19cc464c4622 | T1555.003 | windows | powershell | Run Chrome-password Collector |
9a2915b3-3954-4cce-8c76-00fbf4dbd014 | T1555.003 | windows | command_prompt | LaZagne - Credentials from Browser |
a6a5ec26-a2d1-4109-9d35-58b867689329 | T1555.003 | windows | powershell | Simulating access to Windows Edge Login Data |
dc9cd677-c70f-4df5-bd1c-f114af3c2381 | T1555.003 | windows | powershell | Decrypt Mozilla Passwords with Firepwd.py |
e359627f-2d90-4320-ba5e-b0f878155bbe | T1555.003 | windows | powershell | WebBrowserPassView - Credentials from Browser |
e5e3d639-6ea8-4408-9ecd-d5a286268ca0 | T1555.003 | windows | powershell | WinPwn - PowerSharpPack - Sharpweb for Browser Credentials |
eb8da98a-2e16-4551-b3dd-83de49baa14c | T1555.003 | windows | powershell | Simulating access to Windows Firefox Login Data |
ec1d0b37-f659-4186-869f-31a554891611 | T1555.003 | windows | powershell | WinPwn - Loot local Credentials - mimi-kittenz |
f543635c-1705-42c3-b180-efd6dc6e7ee7 | T1555.003 | windows | powershell | Stage Popular Credential Files for Exfiltration |
9c2dd36d-5c8b-4b29-8d72-a11b0d5d7439 | T1555.004 | windows | command_prompt | Access Saved Credentials via VaultCmd |
fa714db1-63dd-479e-a58e-7b2b52ca5997 | T1555.004 | windows | powershell | WinPwn - Loot local Credentials - Invoke-WCMDump |
0ee8081f-e9a7-4a2e-a23f-68473023184f | T1556.001 | windows | powershell | Skeleton Key via Mimikatz |
91580da6-bc6e-431b-8b88-ac77180005f2 | T1556.002 | windows | powershell | Install Additional Authentication Packages |
a7961770-beb5-4134-9674-83d7e1fa865c | T1556.002 | windows | powershell | Install and Register Password Filter DLL |
deecd55f-afe0-4a62-9fba-4d1ba2deb321 | T1557.001 | windows | powershell | LLMNR Poisoning with Inveigh (PowerShell) |
9726592a-dabc-4d4d-81cd-44070008b3af | T1558.001 | windows | powershell | Crafting Active Directory golden tickets with mimikatz |
e42d33cd-205c-4acf-ab59-a9f38f6bad9c | T1558.001 | windows | powershell | Crafting Active Directory golden tickets with Rubeus |
385e59aa-113e-4711-84d9-f637aef01f2c | T1558.002 | windows | powershell | Crafting Active Directory silver tickets with mimikatz |
14625569-6def-4497-99ac-8e7817105b55 | T1558.003 | windows | powershell | Rubeus kerberoast |
29094950-2c96-4cbd-b5e4-f7c65079678f | T1558.003 | windows | powershell | WinPwn - PowerSharpPack - Kerberoasting Using Rubeus |
3f987809-3681-43c8-bcd8-b3ff3a28533a | T1558.003 | windows | powershell | Request for service tickets |
78d10e20-c874-45f2-a9df-6fea0120ec27 | T1558.003 | windows | powershell | WinPwn - Kerberoasting |
902f4ed2-1aba-4133-90f2-cff6d299d6da | T1558.003 | windows | powershell | Request All Tickets via PowerShell |
988539bc-2ed7-4e62-aec6-7c5cf6680863 | T1558.003 | windows | powershell | Request A Single Ticket via PowerShell |
e6f4affd-d826-4871-9a62-6c9004b8fe06 | T1558.003 | windows | command_prompt | Extract all accounts in use as SPN using setspn |
615bd568-2859-41b5-9aed-61f6a88e48dd | T1558.004 | windows | powershell | Rubeus asreproast |
8c385f88-4d47-4c9a-814d-93d9deec8c71 | T1558.004 | windows | powershell | WinPwn - PowerSharpPack - Kerberoasting Using Rubeus |
d6139549-7b72-4e48-9ea1-324fc9bdf88a | T1558.004 | windows | powershell | Get-DomainUser with PowerView |
7a48f482-246f-4aeb-9837-21c271ebf244 | T1559 | windows | command_prompt | Cobalt Strike post-exploitation pipe (4.2 and later) |
830c8b6c-7a70-4f40-b975-8bbe74558acd | T1559 | windows | command_prompt | Cobalt Strike Lateral Movement (psexec_psh) pipe |
8dbfc15c-527b-4ab0-a272-019f469d367f | T1559 | windows | command_prompt | Cobalt Strike post-exploitation pipe (before 4.2) |
bd13b9fc-b758-496a-b81a-397462f82c72 | T1559 | windows | command_prompt | Cobalt Strike Artifact Kit pipe |
d1f72fa0-5bc2-4b4b-bd1e-43b6e8cfb2e6 | T1559 | windows | command_prompt | Cobalt Strike SSH (postex_ssh) pipe |
47c21fb6-085e-4b0d-b4d2-26d72c3830b3 | T1559.002 | windows | command_prompt | Execute PowerShell script via Word DDE |
41410c60-614d-4b9d-b66e-b0192dd9c597 | T1560 | windows | powershell | Compress Data for Exfiltration With PowerShell |
01df0353-d531-408d-a0c5-3161bf822134 | T1560.001 | windows | command_prompt | Compress Data and lock with password for Exfiltration with winzip |
0286eb44-e7ce-41a0-b109-3da516e05a5f | T1560.001 | linux, macos | sh | Data Encrypted with zip and gpg symmetric |
02ea31cb-3b4c-4a2d-9bf1-e4e70ebcf5d0 | T1560.001 | windows | command_prompt | Compress Data for Exfiltration With Rar |
05e8942e-f04f-460a-b560-f7781257feec | T1560.001 | windows | powershell | Copy and Compress AppData Folder |
2a7bc405-9555-4f49-ace2-b2ae2941d629 | T1560.001 | windows | command_prompt | Compress a File for Exfiltration using Makecab |
36c62584-d360-41d6-886f-d194654be7c2 | T1560.001 | windows | powershell | ESXi - Remove Syslog remote IP |
7af2b51e-ad1c-498c-aca8-d3290c19535a | T1560.001 | linux, macos | sh | Data Compressed - nix - tar Folder or File |
8dd61a55-44c6-43cc-af0c-8bdda276860c | T1560.001 | windows | command_prompt | Compress Data and lock with password for Exfiltration with winrar |
a743e3a6-e8b2-4a30-abe7-ca85d201b5d3 | T1560.001 | linux, macos | bash | Encrypts collected data with AES-256 and Base64 |
c51cec55-28dd-4ad2-9461-1eacbc82c3a0 | T1560.001 | linux, macos | bash | Data Compressed - nix - zip |
cde3c2af-3485-49eb-9c1f-0ed60e9cc0af | T1560.001 | linux, macos | sh | Data Compressed - nix - gzip Single File |
d1334303-59cb-4a03-8313-b3e24d02c198 | T1560.001 | windows | command_prompt | Compress Data and lock with password for Exfiltration with 7zip |
a37ac520-b911-458e-8aed-c5f1576d9f46 | T1563.002 | windows | command_prompt | RDP hijacking |
2748ab4a-1e0b-4cf2-a2b0-8ef765bec7be | T1564 | windows | powershell | Command Execution with NirCmd |
2ec63cc2-4975-41a6-bf09-dffdfb610778 | T1564 | windows | command_prompt | Create a Hidden User Called "$" |
333c7de0-6fbe-42aa-ac2b-c7e40b18246a | T1564 | windows | command_prompt | Create and Hide a Service with sc.exe |
5bb20389-39a5-4e99-9264-aeb92a55a85c | T1564 | windows | powershell | Create an "Administrator " user (with a space on the end) |
6afe288a-8a8b-4d33-a629-8d03ba9dad3a | T1564 | windows | powershell | Extract binary files via VBA |
3b7015f2-3144-4205-b799-b05580621379 | T1564.001 | macos | sh | Hidden files |
61a782e5-9a19-40b5-8ba4-69a4b9f3d7be | T1564.001 | linux, macos | sh | Create a hidden file in a hidden directory |
7f66d539-4fbe-4cfa-9a56-4a2bf660c58a | T1564.001 | windows | powershell | Create Windows Hidden File with powershell |
9a1ec7da-b892-449f-ad68-67066d04380c | T1564.001 | macos | sh | Show all hidden files |
b115ecaf-3b24-4ed2-aefe-2fcb9db913d3 | T1564.001 | macos | sh | Hide a Directory |
cddb9098-3b47-4e01-9d3b-6f5f323288a9 | T1564.001 | macos | sh | Mac Hidden file |
d380c318-0b34-45cb-9dad-828c11891e43 | T1564.001 | windows | powershell | Create Windows System File with powershell |
dadb792e-4358-4d8d-9207-b771faa0daa5 | T1564.001 | windows | command_prompt | Create Windows Hidden File with Attrib |
f650456b-bd49-4bc1-ae9d-271b5b9581e7 | T1564.001 | windows | command_prompt | Hide Files Through Registry |
f70974c8-c094-4574-b542-2c545af95a32 | T1564.001 | windows | command_prompt | Create Windows System File with Attrib |
173126b7-afe4-45eb-8680-fa9f6400431c | T1564.002 | windows | command_prompt | Create Hidden User in Registry |
4238a7f0-a980-4fff-98a2-dfc0a363d507 | T1564.002 | macos | sh | Create Hidden User using UniqueID < 500 |
de87ed7b-52c3-43fd-9554-730f695e7f31 | T1564.002 | macos | sh | Create Hidden User using IsHidden option |
0ad9ab92-c48c-4f08-9b20-9633277c4646 | T1564.003 | windows | command_prompt | Headless Browser Accessing Mockbin |
5510d22f-2595-4911-8456-4d630c978616 | T1564.003 | windows | powershell | Hidden Window-Conhost Execution |
f151ee37-9e2b-47e6-80e4-550b9f999b7a | T1564.003 | windows | powershell | Hidden Window |
0045ea16-ed3c-4d4c-a9ee-15e44d1560d1 | T1564.004 | windows | powershell | Create ADS PowerShell |
17e7637a-ddaf-4a82-8622-377e20de8fdb | T1564.004 | windows | command_prompt | Create ADS command prompt |
2ab75061-f5d5-4c1a-b666-ba2a50df5b02 | T1564.004 | windows | powershell | Store file in Alternate Data Stream (ADS) |
3e6791e7-232c-481c-a680-a52f86b83fdf | T1564.004 | windows | command_prompt | Create Hidden Directory via $index_allocation |
8822c3b0-d9f9-4daf-a043-49f4602364f4 | T1564.004 | windows | command_prompt | Alternate Data Streams (ADS) |
88b81702-a1c0-49a9-95b2-2dd53d755767 | T1564.006 | windows | command_prompt | Create and start VirtualBox virtual machine |
c59f246a-34f8-4e4d-9276-c295ef9ba0dd | T1564.006 | windows | command_prompt | Register Portable Virtualbox |
fb8d4d7e-f5a4-481c-8867-febf13f8b6d3 | T1564.006 | windows | powershell | Create and start Hyper-V virtual machine |
114ccff9-ae6d-4547-9ead-4cd69f687306 | T1566.001 | windows | powershell | Download Macro-Enabled Phishing Attachment |
cbb6799a-425c-4f83-9194-5447a909d67f | T1566.001 | windows | powershell | Word spawned a command shell and used an IP address in the command line |
bc177ef9-6a12-4ebc-a2ec-d41e19c2791d | T1566.002 | windows | powershell | Paste and run technique |
8529ee44-279a-4a19-80bf-b846a40dda58 | T1567.002 | windows | powershell | Exfiltrate data with rclone to cloud Storage - Mega (Windows) |
a4b74723-5cee-4300-91c3-5e34166909b4 | T1567.002 | linux, macos | powershell | Exfiltrate data with rclone to cloud Storage - AWS S3 |
c2e8ab6e-431e-460a-a2aa-3bc6a32022e3 | T1567.003 | windows | powershell | Exfiltrate data with HTTP POST to text storage sites - pastebin.com (Windows) |
35ad6590-2207-4b14-bf8f-9899470d7156 | T1567.004 | windows | powershell | Exfiltrate staged data to a Microsoft Teams webhook (PowerShell) |
40c44d16-bb49-4d14-aafa-f9ba7e6e6c5b | T1567.004 | linux, macos | bash | Exfiltrate staged file to a Discord webhook with curl (bash) |
c666acd6-6ff5-4d28-9490-195d89cd4337 | T1567.004 | linux, macos | sh | Exfiltrate staged data to a Slack webhook with curl (sh) |
f0057c81-24dc-4a2e-b658-5809c242180b | T1567.004 | windows | powershell | Exfiltrate staged data to a Discord webhook (PowerShell) |
6fb61988-724e-4755-a595-07743749d4e2 | T1569.001 | macos | bash | Launchctl |
004a5d68-627b-452d-af3d-43bd1fc75a3b | T1569.002 | windows | powershell | Pipe Creation - PsExec Tool Execution From Suspicious Locations |
2382dee2-a75f-49aa-9378-f52df6ed3fb1 | T1569.002 | windows | command_prompt | Execute a Command as a Service |
31eb7828-97d7-4067-9c1e-c6feb85edc4b | T1569.002 | windows | powershell | BlackCat pre-encryption cmds with Lateral Movement |
873106b7-cfed-454b-8680-fa9f6400431c | T1569.002 | windows | command_prompt | Use PsExec to execute a command on a remote host |
a5d8cdeb-be90-43a9-8b26-cc618deac1e0 | T1569.002 | windows | command_prompt | Use RemCom to execute a command on a remote host |
b8db787e-dbea-493c-96cb-9272296ddc49 | T1569.002 | windows | command_prompt | Snake Malware Service Create |
bf07f520-3909-4ef5-aa22-877a50f2f77b | T1569.002 | windows | command_prompt | Modifying ACL of Service Control Manager via SDET |
183235ca-8e6c-422c-88c2-3aa28c4825d9 | T1570 | windows | powershell | Exfiltration Over SMB over QUIC (NET USE) |
d8d13303-159e-4f33-89f4-9f07812d016f | T1570 | windows | powershell | Exfiltration Over SMB over QUIC (New-SmbMapping) |
21fe622f-8e53-4b31-ba83-6d333c2583f4 | T1571 | windows | powershell | Testing usage of uncommonly used port with PowerShell |
5db21e1d-dd9c-4a50-b885-b1e748912767 | T1571 | linux, macos | sh | Testing usage of uncommonly used port |
0c5f9705-c575-42a6-9609-cbbff4b2fc9b | T1572 | windows | powershell | DNS over HTTPS Regular Beaconing |
228c336a-2f79-4043-8aef-bfa453a611d5 | T1572 | linux, macos | sh | Cloudflare tunnels (Linux/macOS) |
4cdc9fc7-53fb-4894-9f0c-64836943ea60 | T1572 | windows | powershell | run ngrok |
748a73d5-cea4-4f34-84d8-839da5baa99c | T1572 | windows | powershell | DNS over HTTPS Long Domain Query |
9f94a112-1ce2-464d-a63b-83c1f465f801 | T1572 | linux, macos | bash | Microsoft Dev tunnels (Linux/macOS) |
ae9ef4b0-d8c1-49d4-8758-06206f19af0a | T1572 | windows | powershell | DNS over HTTPS Large Query Volume |
b877943f-0377-44f4-8477-f79db7f07c4d | T1572 | linux, macos | sh | VSCode tunnels (Linux/macOS) |
21caf58e-87ad-440c-a6b8-3ac259964003 | T1573 | windows | powershell | OpenSSL C2 |
46ed938b-c617-429a-88dc-d49b5c9ffedb | T1574.001 | windows | command_prompt | Phantom Dll Hijacking - WinAppXRT.dll |
5898902d-c5ad-479a-8545-6f5ab3cfc87f | T1574.001 | windows | command_prompt | Phantom Dll Hijacking - ualapi.dll |
65526037-7079-44a9-bda1-2cb624838040 | T1574.001 | windows | command_prompt | DLL Side-Loading using the Notepad++ GUP.exe binary |
8549ad4b-b5df-4a2d-a3d7-2aee9e7052a3 | T1574.001 | windows | command_prompt | DLL Search Order Hijacking - amsi.dll |
c095ad8e-4469-4d33-be9d-6f6d1fb21585 | T1574.001 | windows | powershell | DLL Search Order Hijacking,DLL Sideloading Of KeyScramblerIE.DLL Via KeyScrambler.EXE |
d322cdd7-7d60-46e3-9111-648848da7c02 | T1574.001 | windows | command_prompt | DLL Side-Loading using the dotnet startup hook environment variable |
e96b8105-d7f7-484e-8d81-2d0c7086971b | T1574.001 | windows | command_prompt | DLL Search Order Hijacking - ntprint |
4d66029d-7355-43fd-93a4-b63ba92ea1be | T1574.006 | macos | bash | Dylib Injection via DYLD_INSERT_LIBRARIES |
1561de08-0b4b-498e-8261-e922f3494aae | T1574.008 | windows | powershell | powerShell Persistence via hijacking default modules - Get-Variable.exe |
2770dea7-c50f-457b-84c4-c40a47460d9f | T1574.009 | windows | command_prompt | Execution of program.exe as service with unquoted service path |
f38e9eea-e1d7-4ba6-b716-584791963827 | T1574.011 | windows | command_prompt | Service ImagePath Change with reg.exe |
f7536d63-7fd4-466f-89da-7e48d550752a | T1574.011 | windows | powershell | Service Registry Permissions Weakness |
79d57242-bbef-41db-b301-9d01d9f6e817 | T1574.012 | windows | powershell | Registry-free process scope COR_PROFILER |
9d5f89dc-c3a5-4f8a-a4fc-a6ed02e7cb5a | T1574.012 | windows | powershell | User scope COR_PROFILER |
f373b482-48c8-4ce4-85ed-d40c8b3f7310 | T1574.012 | windows | powershell | System Scope COR_PROFILER |
99ee161b-dcb1-4276-8ecb-7cfdcb207820 | T1580 | iaas:aws, linux, macos | sh | AWS - EC2 Enumeration from Cloud Instance |
d430bf85-b656-40e7-b238-42db01df0183 | T1592.001 | windows | powershell | Enumerate PlugNPlay Camera |
89a83c3e-0b39-4c80-99f5-c2aa084098bd | T1595.003 | linux, macos, windows | powershell | Web Server Wordlist Scan |
552b4db3-8850-412c-abce-ab5cc8a86604 | T1614 | linux, macos | bash | Get geolocation info through IP-Lookup services using curl freebsd, linux or macos |
fe53e878-10a3-477b-963e-4367348f5af5 | T1614 | windows | command_prompt | Get geolocation info through IP-Lookup services using curl Windows |
1f23bfe8-36d4-49ce-903a-19a1e8c6631b | T1614.001 | windows | powershell | Discover System Language with Powershell |
4758003d-db14-4959-9c0f-9e87558ac69e | T1614.001 | windows | command_prompt | Discover System Language with WMIC |
631d4cf1-42c9-4209-8fe9-6bd4de9421be | T1614.001 | windows | command_prompt | Discover System Language by Registry Query |
69f625ba-938f-4900-bdff-82ada3df5d9c | T1614.001 | windows | command_prompt | Discover System Language with dism.exe |
d91473ca-944e-477a-b484-0e80217cd789 | T1614.001 | windows | command_prompt | Discover System Language with chcp |
e39b99e9-ce7f-4b24-9c88-0fbad069e6c6 | T1614.001 | windows | command_prompt | Discover System Language by Windows API Query |
0976990f-53b1-4d3f-a185-6df5be429d3b | T1615 | windows | command_prompt | Display group policy information via gpresult |
4e524c4e-0e02-49aa-8df5-93f3f7959b9f | T1615 | windows | powershell | Get-DomainGPO to display group policy information via PowerView |
52778a8f-a10b-41a4-9eae-52ddb74072bf | T1615 | windows | powershell | MSFT Get-GPO Cmdlet |
7230d01a-0a72-4bd5-9d7f-c6d472bc6a59 | T1615 | windows | powershell | WinPwn - GPORemoteAccessPolicy |
bc25c04b-841e-4965-855f-d1f645d7ab73 | T1615 | windows | powershell | WinPwn - GPOAudit |
56b9589c-9170-4682-8c3d-33b86ecb5119 | T1620 | windows | powershell | WinPwn - Reflectively load Mimik@tz into memory |
58bd8c8d-3a1a-4467-a69c-439c75469b07 | T1622 | windows | powershell | Detect a Debugger Presence in the Machine |
eb121494-82d1-4148-9e2b-e624e03fbf3d | T1649 | windows | powershell | Staging Local Certificates via Export-Certificate |
235b30a2-e5b1-441f-9705-be6231c88ddd | T1652 | windows | powershell | Device Driver Discovery |
71eab73d-5d7d-4681-9a72-7873489a5b85 | T1652 | macos | bash | List loaded kernel extensions (macOS) |
c63bbe52-6f17-4832-b221-f07ba8b1736f | T1652 | macos | bash | Find Kernel Extensions (macOS) |
a9030b20-dd4b-4405-875e-3462c6078fdc | T1654 | windows | powershell | Get-EventLog To Enumerate Windows Security Log |
fef0ace1-3550-4bf1-a075-9fea55a778dd | T1654 | windows | command_prompt | Enumerate Windows Security Log via WevtUtil |
9b360eaf-c778-4f07-a6e7-895c4f01ac1c | T1659 | linux, macos | bash | MITM Proxy Injection |
dcc2ca85-a21c-43a4-acc7-7314d4e5891c | T1659 | windows | powershell | MITM Proxy Injection (Windows) |
1c11a623-e783-4b2f-ad4a-0a62591e8f85 | T1680 | windows | command_prompt | Local Storage Discovery via wmic |
3a4d51bd-b0f5-4249-821c-ba8997c42c00 | T1680 | windows | powershell | Local Storage Discovery via PSDrive |
07f43b33-1e15-4e99-be70-bc094157c849 | T1685 | macos | sh | Disable OpenDNS Umbrella |
0b19f4ee-de90-4059-88cb-63c800c683ed | T1685 | windows | powershell | Tamper with Windows Defender Evade Scanning -Folder |
0e7b8a4b-2ca5-4743-a9f9-96051abb6e50 | T1685 | windows | powershell | Delete Microsoft Defender ASR Rules - GPO |
110b4281-43fe-405f-a184-5d8eaf228ebf | T1685 | windows | command_prompt | Disable .NET Event Tracing for Windows Via Environment Variable HKLM Registry - Cmd |
1174b5df-2c33-490f-8854-f5eb80c907ca | T1685 | windows | powershell | Block Cybersecurity communication by leveraging Windows Name Resolution Policy Table |
13f09b91-c953-438e-845b-b585e51cac9b | T1685 | windows | powershell | AMSI Bypass - Remove AMSI Provider Reg Key |
17538258-5699-4ff1-92d1-5ac9b0dc21f5 | T1685 | windows | command_prompt | AMSI Bypass - Override AMSI via COM |
19c07a45-452d-4620-90ed-4c34fffbe758 | T1685 | windows | powershell | Disable .NET Event Tracing for Windows Via Registry (powershell) |
1b3e0146-a1e5-4c5c-89fb-1bb2ffe8fc45 | T1685 | windows | powershell | Tamper with Windows Defender Registry |
1cac9b54-810e-495c-8aac-989e0076583b | T1685 | windows | command_prompt | Disable EventLog-Application ETW Provider Via Registry - Cmd |
1f6743da-6ecc-4a93-b03f-dc357e4b313f | T1685 | windows | command_prompt | Tamper with Windows Defender Registry - Reg.exe |
24a12b91-05a7-4deb-8d7f-035fa98591bc | T1685 | windows | powershell | Kill antimalware protected processes using Backstab |
2a821573-fb3f-4e71-92c3-daac7432f053 | T1685 | macos | sh | Disable macOS Gatekeeper |
315f4be6-2240-4552-b3e1-d1047f5eecea | T1685 | windows | powershell | Tamper with Windows Defender Evade Scanning -Extension |
3d47daaa-2f56-43e0-94cc-caf5d8d52a68 | T1685 | windows | command_prompt | Remove Windows Defender Definition Files |
40074085-dbc8-492b-90a3-11bcfc52fda8 | T1685 | linux, macos | sh | Tamper with Defender ATP on Linux/MacOS |
40075d5f-3a70-4c66-9125-f72bee87247d | T1685 | windows | command_prompt | Windows Disable LSA Protection |
4b841aa1-0d05-4b32-bbe7-7564346e7c76 | T1685 | windows | command_prompt | Delete Windows Defender Scheduled Tasks |
4d61779d-be7f-425c-b560-0cafb2522911 | T1685 | windows | powershell | Disable .NET Event Tracing for Windows Via Environment Variable HKLM Registry - PowerShell |
59d386fc-3a4b-41b8-850d-9e3eee24dfe4 | T1685 | windows | command_prompt | WMIC Tamper with Windows Defender Evade Scanning Folder |
5e27f36d-5132-4537-b43b-413b0d5eec9a | T1685 | windows | powershell | Lockbit Black - Use Registry Editor to turn on automatic logon -Powershell |
62155dd8-bb3d-4f32-b31c-6532ff3ac6a3 | T1685 | macos | sh | Disable LittleSnitch |
653c6e17-14a2-4849-851d-f1c0cc8ea9ab | T1685 | windows | command_prompt | Disable EventLog-Application Auto Logger Session Via Registry - Cmd |
695eed40-e949-40e5-b306-b4031e4154bd | T1685 | windows | powershell | AMSI Bypass - AMSI InitFailed |
69fc085b-5444-4879-8002-b24c8e1a3e02 | T1685 | windows | powershell | LockBit Black - Disable the ETW Provider of Windows Defender -Powershell |
6b8df440-51ec-4d53-bf83-899591c9b5d7 | T1685 | windows | powershell | Tamper with Windows Defender ATP PowerShell |
6f118276-121d-4c09-bb58-a8fb4a72ee84 | T1685 | windows | powershell | Disable Powershell ETW Provider - Windows |
6f5fb61b-4e56-4a3d-a8c3-82e13686c6d7 | T1685 | windows | powershell | Disable Microsoft Office Security Features |
70bd71e6-eba4-4e00-92f7-617911dbe020 | T1685 | windows | powershell | Disable Hypervisor-Enforced Code Integrity (HVCI) |
728eca7b-0444-4f6f-ac36-437e3d751dc0 | T1685 | windows | powershell | AMSI Bypass - Create AMSIEnable Reg Key |
7869d7a3-3a30-4d2c-a5d2-f1cd9c34ce66 | T1685 | windows | powershell | WinPwn - Kill the event log services for stealth |
7dd05b3e-0803-4852-9345-c494eb3e40fe | T1685 | windows | powershell | Throttle Cybersecurity Agent Network Traffic via QoS Policy |
811b3e76-c41b-430c-ac0d-e2380bfaa164 | T1685 | windows | command_prompt | Unload Sysmon Filter Driver |
81ce22fd-9612-4154-918e-8a1f285d214d | T1685 | windows | powershell | Disable Defender Using NirSoft AdvancedRun |
871438ac-7d6e-432a-b27d-3e7db69faf58 | T1685 | windows | command_prompt | Disable Windows Defender with DISM |
8a4c33be-a0d3-434a-bee6-315405edbd5b | T1685 | windows | command_prompt | Disable .NET Event Tracing for Windows Via Registry (cmd) |
8f907648-1ebf-4276-b0f0-e2678ca474f0 | T1685 | windows | powershell | Disable EventLog-Application ETW Provider Via Registry - PowerShell |
8fba7766-2d11-4b4a-979a-1e3d9cc9a88c | T1685 | macos | sh | Disable Carbon Black Response |
9719d0e1-4fe0-4b2e-9a72-7ad3ee8ddc70 | T1685 | windows | command_prompt | LockBit Black - Use Registry Editor to turn on automatic logon -cmd |
a1230893-56ac-4c81-b644-2108e982f8f5 | T1685 | windows | command_prompt | Disable Arbitrary Security Windows Service |
a123ce6a-3916-45d6-ba9c-7d4081315c27 | T1685 | windows | powershell | Tamper with Windows Defender Evade Scanning -Process |
a316fb2e-5344-470d-91c1-23e15c374edc | T1685 | windows | command_prompt | Uninstall Sysmon |
a72cfef8-d252-48b3-b292-635d332625c3 | T1685 | windows | powershell | Tamper with Windows Defender Registry - Powershell |
aa875ed4-8935-47e2-b2c5-6ec00ab220d2 | T1685 | windows | command_prompt | Tamper with Windows Defender Command Prompt |
ae753dda-0f15-4af6-a168-b9ba16143143 | T1685 | windows | powershell | Stop and Remove Arbitrary Security Windows Service |
b32b1ccf-f7c1-49bc-9ddd-7d7466a7b297 | T1685 | windows | powershell | Uninstall Crowdstrike Falcon on Windows |
b3e7510c-2d4c-4249-a33f-591a2bc83eef | T1685 | macos | sh | Stop and unload Crowdstrike Falcon on macOS |
b42c1f8c-399b-47ae-8fd8-763181395fee | T1685 | windows | powershell | Disable .NET Event Tracing for Windows Via Environment Variable HKCU Registry - PowerShell |
c531aa6e-9c97-4b29-afee-9b7be6fc8a64 | T1685 | windows | powershell | Tamper with Windows Defender ATP using Aliases - PowerShell |
cbb2573a-a6ad-4c87-aef8-6e175598559b | T1685 | windows | powershell | Freeze PPL-protected process with EDR-Freeze |
d6d22332-d07d-498f-aea0-6139ecb7850e | T1685 | windows | command_prompt | LockBit Black - Disable Privacy Settings Experience Using Registry -cmd |
d8c57eaa-497a-4a08-961e-bd5efd7c9374 | T1685 | windows | powershell | LockBit Black - Disable Privacy Settings Experience Using Registry -Powershell |
da86f239-9bd3-4e85-92ed-4a94ef111a1c | T1685 | windows | powershell | Disable EventLog-Application Auto Logger Session Via Registry - PowerShell |
eea0a6c2-84e9-4e8c-a242-ac585d28d0d1 | T1685 | windows | powershell | Delete Microsoft Defender ASR Rules - InTune |
f542ffd3-37b4-4528-837f-682874faa012 | T1685 | windows | powershell | Disable Windows Defender with PwSh Disable-WindowsOptionalFeature |
f6df0b8e-2c83-44c7-ba5e-0fa4386bec41 | T1685 | windows | command_prompt | LockBit Black - Disable the ETW Provider of Windows Defender -cmd |
fdac1f79-b833-4bab-b4a1-11b1ed676a4b | T1685 | windows | command_prompt | Disable .NET Event Tracing for Windows Via Environment Variable HKCU Registry - Cmd |
3ddf3d03-f5d6-462a-ad76-2c5ff7b6d741 | T1685.001 | windows | command_prompt | Makes Eventlog blind with Phant0m |
41ac52ba-5d5e-40c0-b267-573ed90489bd | T1685.001 | windows | powershell | Kill Event Log Service Threads |
5102a3a7-e2d7-4129-9e45-f483f2e0eea8 | T1685.001 | windows | command_prompt | Impair Windows Audit Log Policy |
69435dcf-c66f-4ec0-a8b1-82beb76b34db | T1685.001 | windows | powershell | Disable Windows IIS HTTP Logging |
85e6eff8-3ed4-4e03-ae50-aa6a404898a5 | T1685.001 | windows | powershell | Modify Event Log Channel Access Permissions via Registry 2 - PowerShell |
8e81d090-0cd6-4d46-863c-eec11311298f | T1685.001 | windows | powershell | Modify Event Log Channel Access Permissions via Registry - PowerShell |
913c0e4e-4b37-4b78-ad0b-90e7b25010f6 | T1685.001 | windows | command_prompt | Clear Windows Audit Policy Config |
a0cb81f8-44d0-4ac4-a8f3-c5c7f43a12c1 | T1685.001 | windows | powershell | Modify Event Log Access Permissions via Registry - PowerShell |
a957fb0f-1e85-49b2-a211-413366784b1e | T1685.001 | windows | powershell | Disable Windows IIS HTTP Logging via PowerShell |
b26a3340-dad7-4360-9176-706269c74103 | T1685.001 | windows | command_prompt | Disable Event Logging with wevtutil |
22d89a2f-d475-4895-b2d4-68626d49c029 | T1685.002 | iaas:aws, linux, macos | sh | AWS - CloudTrail Logs Impairment Through S3 Lifecycle Rule using Stratus |
93c150f5-ad7b-4ee3-8992-df06dec2ac79 | T1685.002 | iaas:aws, linux, macos | sh | AWS - Remove VPC Flow Logs using Stratus |
a27418de-bdce-4ebd-b655-38f11142bf0c | T1685.002 | iaas:aws, linux, macos | sh | AWS - Disable CloudTrail Logging Through Event Selectors using Stratus |
1b682d84-f075-4f93-9a89-8a8de19ffd6e | T1685.005 | windows | powershell | Clear Event Logs via VBA |
b13e9306-3351-4b4b-a6e8-477358b0b498 | T1685.005 | windows | powershell | Delete System Logs Using Clear-EventLog |
e6abb60e-26b8-41da-8aae-0c35174b0967 | T1685.005 | windows | command_prompt | Clear Logs |
0208ea60-98f1-4e8c-8052-930dce8f742c | T1685.006 | macos | sh | Overwrite macOS system log via echo utility |
03013b4b-01db-437d-909b-1fdaa5010ee8 | T1685.006 | macos | sh | Delete system log files via unlink utility |
6290f8a8-8ee9-4661-b9cf-390031bf6973 | T1685.006 | macos | sh | Truncate system log files via truncate utility |
653d39cd-bae7-499a-898c-9fb96b8b5cd1 | T1685.006 | macos | sh | Delete log files using built-in log utility |
810a465f-cd4f-47bc-b43e-d2de3b033ecc | T1685.006 | macos | sh | Delete system log files using OSAScript |
848e43b3-4c0a-4e4c-b4c9-d1e8cea9651c | T1685.006 | macos | sh | Real-time system log clearance/deletion |
86f0e4d5-3ca7-45fb-829d-4eda32b232bb | T1685.006 | macos | sh | Delete system log files using shred utility |
989cc1b1-3642-4260-a809-54f9dd559683 | T1685.006 | linux, macos | sh | rm -rf |
b0768a5e-0f32-4e75-ae5b-d036edcf96b6 | T1685.006 | macos | sh | Delete system log files using srm utility |
bc8eeb4a-cc3e-45ec-aa6e-41e973da2558 | T1685.006 | macos | sh | System log file deletion via find utility |
c23bdb88-928d-493e-b46d-df2906a50941 | T1685.006 | macos | sh | Delete log files via cat utility by appending /dev/null or /dev/zero |
e62f8694-cbc7-468f-862c-b10cd07e1757 | T1685.006 | macos | sh | Delete system log files using Applescript |
15e57006-79dd-46df-9bf9-31bc24fb5a80 | T1686 | windows | command_prompt | Opening ports for proxy - HARDRAIN |
6f5822d2-d38d-4f48-9bfc-916607ff6b8c | T1686 | windows | powershell | Allow Executable Through Firewall Located in Non-Standard Location |
80b453d1-eec5-4144-bf08-613a6c3ffe12 | T1686 | windows | powershell | LockBit Black - Unusual Windows firewall registry modification -Powershell |
88d05800-a5e4-407e-9b53-ece4174f197f | T1686 | windows | command_prompt | Disable Microsoft Defender Firewall |
91f348e6-3760-4997-a93b-2ceee7f254ee | T1686 | windows | command_prompt | Blackbit - Disable Windows Firewall using netsh firewall |
94be7646-25f6-467e-af23-585fb13000c8 | T1686 | windows | powershell | Set a firewall rule using New-NetFirewallRule |
9636dd6e-7599-40d2-8eee-ac16434f35ed | T1686 | windows | powershell | Open a local port through Windows Firewall to any profile |
a4651931-ebbb-4cde-9363-ddf3d66214cb | T1686 | windows | command_prompt | LockBit Black - Unusual Windows firewall registry modification -cmd |
a67e8aea-ea7c-4c3b-9b1b-8c2957c3091d | T1686 | windows | command_prompt | ESXi - Set Firewall to PASS Traffic |
afedc8c4-038c-4d82-b3e5-623a95f8a612 | T1686 | windows | command_prompt | Disable Microsoft Defender Firewall via Registry |
bac8a340-be64-4491-a0cc-0985cb227f5a | T1686 | windows | command_prompt | ESXi - Disable Firewall via Esxcli |
d9841bf8-f161-4c73-81e9-fd773a5ff8c1 | T1686 | windows | command_prompt | Allow SMB and RDP on Microsoft Defender Firewall |
2a78362e-b79a-4482-8e24-be397bce4d85 | T1688 | windows | command_prompt | Safe Mode Boot |
14d55b96-b2f5-428d-8fed-49dc4d9dd616 | T1689 | windows | command_prompt | ESXi - Change VIB acceptance level to CommunitySupported via ESXCLI |
47c96489-2f55-4774-a6df-39faff428f6f | T1689 | windows | powershell | PowerShell Version 2 Downgrade |
1329d5ab-e10e-4e5e-93d1-4d907eb656e5 | T1690 | windows | command_prompt | Disable Windows Command Line Auditing using reg.exe |
4eafdb45-0f79-4d66-aa86-a3e2c08791f5 | T1690 | linux, macos | sh | Disable history collection |
95f5c72f-6dfe-45f3-a8c1-d8faa07176fa | T1690 | windows | powershell | Disable Windows Command Line Auditing using Powershell Cmdlet |