diff --git a/yfaq/mbc_matrix_with_ids.svg b/yfaq/mbc_matrix_with_ids.svg index 42dd8de..ab83324 100644 --- a/yfaq/mbc_matrix_with_ids.svg +++ b/yfaq/mbc_matrix_with_ids.svg @@ -1,2 +1,2 @@ -E1560: Archive Collected DataB0028: CryptocurrencyF0015: Hijack Execution FlowE1056: Input CaptureF0002: KeyloggingE1113: Screen CaptureE1560.m01: EncodingE1560.m04: Encoding - Custom AlgorithmE1560.m03: Encoding - Standard AlgorithmE1560.m02: EncryptionE1560.m06: Encryption - Custom AlgorithmE1560.m05: Encryption - Standard AlgorithmB0028.001: BitcoinB0028.002: EthereumB0028.003: ZcashF0015.006: Abuse Windows Function CallsF0015.001: Export Address Table HookingF0015.003: Import Address Table HookingF0015.002: Inline PatchingF0015.007: Procedure HookingF0015.004: ShadowSystem Service Dispatch Table HookingF0015.005:System Service Dispatch Table HookingE1056.m01: Mouse EventsF0002.001: Application HookF0002.002: PollingE1113.m01: WinAPICollectionE1020: Automated ExfiltrationE1020.m01:Exfiltrate via File Hosting ServiceExfiltrationE1105: Ingress Tool TransferB0026: Malicious Network DriverB0020: Send EmailB0021: Send Poisoned Text MessageE1195: Supply Chain CompromiseE1195.m01: Abuse Enterprise CertificatesE1195.m02: Exploit Private APIsLateral MovementF0015: Hijack Execution FlowF0016: Install CertificateF0010: Kernel Modules and ExtensionsF0011: Modify Existing ServiceE1055: Process InjectionF0015.006: Abuse Windows Function CallsF0015.001: Export Address Table HookingF0015.003: Import Address Table HookingF0015.002: Inline PatchingF0015.007: Procedure HookingF0015.004: ShadowSystem Service Dispatch Table HookingF0015.005:System Service Dispatch Table HookingF0010.001: Device DriverE1055.004: Asynchronous Procedure CallE1055.001: Dynamic-link Library InjectionE1055.011: Extra Window Memory InjectionE1055.m01:Hook Injection via SetWindowsHooksExE1055.m02: Injectionand Persistence via Registry ModificationE1055.m03: Injection using ShimsE1055.m05: Injection via Windows FibersE1055.m04: Patch Process Command LineE1055.002: Portable Executable InjectionE1055.012: Process HollowingE1055.003: Thread Execution HijackingPrivilege EscalationB0028: CryptocurrencyF0015: Hijack Execution FlowE1056: Input CaptureF0002: KeyloggingE1113: Screen CaptureB0028.001: BitcoinB0028.002: EthereumB0028.003: ZcashF0015.006: Abuse Windows Function CallsF0015.001: Export Address Table HookingF0015.003: Import Address Table HookingF0015.002: Inline PatchingF0015.007: Procedure HookingF0015.004: ShadowSystem Service Dispatch Table HookingF0015.005:System Service Dispatch Table HookingE1056.m01: Mouse EventsF0002.001: Application HookF0002.002: PollingE1113.m01: WinAPICredential AccessB0036: Capture EvasionB0025: Conditional ExecutionB0001: Debugger DetectionB0002: Debugger EvasionB0003: Dynamic Analysis EvasionB0004: Emulator DetectionB0005: Emulator EvasionB0008: Executable Code VirtualizationF0015: Hijack Execution FlowB0006: Memory Dump EvasionB0007: Sandbox DetectionF0001: Software PackingB0009: Virtual Machine DetectionB0036.002: Encrypted PayloadsB0036.001: Memory-only PayloadB0036.003: Multiple Stages of LoadersB0025.008: Deposited KeysB0025.002: Environmental KeysB0025.003: GetVolumeInformationB0025.004: Host Fingerprint CheckB0025.007: Runs as ServiceB0025.005: Secure TriggersB0025.001: Suicide ExitB0025.006: Token CheckB0001.034: Anti-debugging InstructionsB0001.001: API Hook DetectionB0001.038: Check ProcessesB0001.002: CheckRemoteDebuggerPresentB0001.003: CloseHandleB0001.004: Debugger ArtifactsB0001.005: Hardware BreakpointsB0001.006: InterruptionB0001.008: IsDebuggerPresentB0001.009: Memory BreakpointsB0001.010: Memory Write WatchingB0001.011: Monitoring ThreadB0001.012: NtQueryInformationProcessB0001.013: NtQueryObjectB0001.014: NtSetInformationThreadB0001.015: NtYieldExecution/SwitchToThreadB0001.016: OutputDebugStringB0001.017:Page Exception Breakpoint DetectionB0001.018: Parent ProcessB0001.019: Process Environment BlockB0001.035:Process Environment Block BeingDebuggedB0001.037:Process Environment Block IsDebuggedB0001.036:Process Environment Block NtGlobalFlagB0001.020: Process JobsB0001.021: ProcessHeapB0001.022: RtlAdjustPrivilegeB0001.023: SeDebugPrivilegeB0001.024: SetHandleInformationB0001.025: Software BreakpointsB0001.026: Stack CanaryB0001.027: TIB AwareB0001.028: Timing/Delay CheckB0001.032: Timing/Delay Check GetTickCountB0001.033:Timing/Delay Check QueryPerformanceCounterB0001.029: TLS CallbacksB0001.030: UnhandledExceptionFilterB0001.031: WudfIsAnyDebuggerPresentB0002.001: Block InterruptsB0002.002: Break Point ClearingB0002.003: Byte StealingB0002.004: Change SizeOfImageB0002.005: Code Integrity CheckB0002.006: Exception MisdirectionB0002.007: Get Base IndirectlyB0002.008: Guard PagesB0002.009: Hook InterruptB0002.010: Import ObfuscationB0002.011: InliningB0002.012: Loop EscapesB0002.013: Malloc UseB0002.014: Modify PE HeaderB0002.015: NanomitesB0002.016: Obfuscate Library UseB0002.017: Parallel ThreadsB0002.018: Pipeline MisdirectionB0002.019: Pre-DebugB0002.020: Relocate API CodeB0002.021: Return ObfuscationB0002.022: RtlAdjustPrivilegeB0002.023: Section MisalignmentB0002.024: Self-DebuggingB0002.025: Self-UnmappingB0002.026: Static LinkingB0002.027: Stolen API CodeB0002.028: TamperingB0002.029: Thread TimeoutB0002.030: Use InterruptsB0003.001: Alternative ntdll.dllB0003.012: API HammeringB0003.011: Code Integrity CheckB0003.002: Data FloodB0003.003: Delayed ExecutionB0003.004: Demo ModeB0003.005: Drop CodeB0003.006: Encode FileB0003.007: Hook File SystemB0003.008: Hook InterruptB0003.009: IllusionB0003.010: RestartB0004.003:Check Emulator-related Registry KeysB0004.001:Check for Emulator-related FilesB0004.002: Check for WINE VersionB0004.004: Failed Network ConnectionsB0005.001: Different Opcode SetsB0005.004: Extra Loops/Time LocksB0005.002:Undocumented/Unimplemented OpcodesB0005.003: Unusual/Undocumented API CallsB0008.001: Multiple VMsF0015.006: Abuse Windows Function CallsF0015.001: Export Address Table HookingF0015.003: Import Address Table HookingF0015.002: Inline PatchingF0015.007: Procedure HookingF0015.004: ShadowSystem Service Dispatch Table HookingF0015.005:System Service Dispatch Table HookingB0006.001: Code Encryption in MemoryB0006.002: Erase the PE headerB0006.008: Feed MisinformationB0006.009: Flow Opcode ObstructionB0006.006: Guard PagesB0006.003: Hide virtual memoryB0006.010: Hook memory mapping APIsB0006.007: On-the-Fly APIsB0006.011: Patch MmGetPhysicalMemoryRangesB0006.004: SizeOfImageB0006.005: TamperingB0007.001: Check Clipboard DataB0007.002: Check FilesB0007.003: Human User CheckB0007.004: Injected DLL TestingB0007.005: Product Key/ID TestingB0007.006: Screen Resolution TestingB0007.007: Self CheckB0007.010: Test API RoutinesB0007.008: Timing/Date CheckB0007.009: Timing/Uptime CheckF0001.012: ArmadilloF0001.013: ASPackF0001.009: ConfuserF0001.005: Custom CompressionF0001.006: Custom Compression of CodeF0001.007: Custom Compression of DataF0001.001: Nested PackingF0001.002: Standard CompressionF0001.003: Standard Compression of CodeF0001.004: Standard Compression of DataF0001.011: ThemidaF0001.008: UPXF0001.010: VMProtectB0009.001:Check File and Directory ArtifactsB0009.002: Check Memory ArtifactsB0009.003: Check Named System ObjectsB0009.004: Check ProcessesB0009.005: Check Registry KeysB0009.006: Check Running ServicesB0009.007: Check SoftwareB0009.008: Check Virtual DevicesB0009.009: Check WindowsB0009.022: Check Windows - Title barsB0009.021: Check Windows - Unique windowsB0009.020: Check Windows - Window sizeB0009.010: Guest Process TestingB0009.011: HTML5 Performance Object CheckB0009.012: Human User CheckB0009.029: Instruction TestingB0009.034: Instruction Testing - CPUIDB0009.035: Instruction Testing - INB0009.036: Instruction Testing - RDTSCB0009.031:Instruction Testing - SGDT/SLDT (no pill)B0009.030:Instruction Testing - SIDT (red pill)B0009.032: Instruction Testing - SMSWB0009.033: Instruction Testing - STRB0009.037: Instruction Testing - VMCPUIDB0009.038: Instruction Testing - VPCEXTB0009.013: Modern Specs CheckB0009.015: Modern Specs Check - Drive sizeB0009.019:Modern Specs Check - Keyboard layoutB0009.017: Modern Specs Check - PrinterB0009.018:Modern Specs Check - Processor countB0009.014:Modern Specs Check - Total physical memoryB0009.016: Modern Specs Check - USB driveB0009.023: Unique Hardware/Firmware CheckB0009.024:Unique Hardware/Firmware Check - BIOSB0009.027: UniqueHardware/Firmware Check - CPU LocationB0009.026:Unique Hardware/Firmware Check - CPU NameB0009.025: Unique Hardware/FirmwareCheck - I/O Communication PortB0009.028: UniqueHardware/Firmware Check - MAC AddressAnti-Behavioral AnalysisB0030: C2 CommunicationB0031: Domain Name GenerationE1105: Ingress Tool TransferB0030.011: AuthenticateB0030.005: Check for PayloadB0030.012: Directory ListingB0030.013: Execute FileB0030.014: Execute Shell CommandB0030.015: File searchB0030.004:Implant to Controller File TransferB0030.002: Receive DataB0030.008: Request CommandB0030.010: Request Email Address ListB0030.009: Request Email TemplateB0030.001: Send DataB0030.007: Send HeartbeatB0030.006: Send System InformationB0030.003: Server to Client File TransferB0030.016: Start Interactive ShellCommand and ControlF0013: BootkitF0009: Component FirmwareF0005: Hidden Files and DirectoriesE1564: Hide ArtifactsF0015: Hijack Execution FlowE1105: Ingress Tool TransferB0047:Install Insecure or Malicious ConfigurationF0010: Kernel Modules and ExtensionsB0026: Malicious Network DriverF0011: Modify Existing ServiceE1112: Modify RegistryF0012: Registry Run Keys / Startup FolderB0022: Remote AccessB0035: Shutdown EventF0009.001: Router FirmwareF0005.003: AttributeF0005.001: ExtensionF0005.002: LocationF0005.004: TimestampE1564.m02:Direct Kernel Object ManipulationE1564.m05: Hidden Kernel ModulesE1564.m03: Hidden ProcessesE1564.m04: Hidden ServicesE1564.m01: Hidden Userspace LibrariesF0015.006: Abuse Windows Function CallsF0015.001: Export Address Table HookingF0015.003: Import Address Table HookingF0015.002: Inline PatchingF0015.007: Procedure HookingF0015.004: ShadowSystem Service Dispatch Table HookingF0015.005:System Service Dispatch Table HookingF0010.001: Device DriverB0022.001: Reverse ShellPersistenceB0027: Alternative Installation LocationF0013: BootkitB0037: Bypass Data Execution PreventionF0009: Component FirmwareB0025: Conditional ExecutionB0040: Covert LocationF0004: Disable or Evade Security ToolsF0005: Hidden Files and DirectoriesE1564: Hide ArtifactsF0015: Hijack Execution FlowF0006: Indicator BlockingB0047:Install Insecure or Malicious ConfigurationE1112: Modify RegistryE1027: Obfuscated Files or InformationB0029: Polymorphic CodeE1055: Process InjectionE1014: RootkitF0007: Self DeletionF0001: Software PackingB0027.001: Fileless MalwareB0027.002: Registry InstallB0037.001: ROP ChainsF0009.001: Router FirmwareB0025.008: Deposited KeysB0025.002: Environmental KeysB0025.003: GetVolumeInformationB0025.004: Host Fingerprint CheckB0025.007: Runs as ServiceB0025.005: Secure TriggersB0025.001: Suicide ExitB0025.006: Token CheckB0040.001: Hide Data in RegistryB0040.002: SteganographyF0004.004: AMSI BypassF0004.007: Bypass Windows File ProtectionF0004.009: Disable Code IntegrityF0004.001: Disable Kernel Patch ProtectionF0004.002:Disable System File Overwrite ProtectionF0004.006: Force Lazy WritingF0004.008: Heavens GateF0004.005: Modify PolicyF0004.003: Unhook APIsF0005.003: AttributeF0005.001: ExtensionF0005.002: LocationF0005.004: TimestampE1564.m02:Direct Kernel Object ManipulationE1564.m05: Hidden Kernel ModulesE1564.m03: Hidden ProcessesE1564.m04: Hidden ServicesE1564.m01: Hidden Userspace LibrariesF0015.006: Abuse Windows Function CallsF0015.001: Export Address Table HookingF0015.003: Import Address Table HookingF0015.002: Inline PatchingF0015.007: Procedure HookingF0015.004: ShadowSystem Service Dispatch Table HookingF0015.005:System Service Dispatch Table HookingF0006.001: Remove SMS Warning MessagesE1027.m01: EncodingE1027.m03: Encoding - Custom AlgorithmE1027.m02: Encoding - Standard AlgorithmE1027.m04: EncryptionE1027.m08: Encryption - Custom AlgorithmE1027.m05: Encryption - Standard AlgorithmE1027.m06: Encryption of CodeE1027.m07: Encryption of DataB0029.002: Call IndirectionsB0029.003: Code ReorderingB0029.001: Packer StubE1055.004: Asynchronous Procedure CallE1055.001: Dynamic-link Library InjectionE1055.011: Extra Window Memory InjectionE1055.m01:Hook Injection via SetWindowsHooksExE1055.m02: Injectionand Persistence via Registry ModificationE1055.m03: Injection using ShimsE1055.m05: Injection via Windows FibersE1055.m04: Patch Process Command LineE1055.002: Portable Executable InjectionE1055.012: Process HollowingE1055.003: Thread Execution HijackingE1014.m12: Application RootkitE1014.m13: BootloaderE1014.m14: Hardware/Firmware RootkitE1014.m15: Hypervisor/Virtualized RootkitE1014.m16: Kernel Mode RootkitE1014.m17: Memory RootkitF0007.001: COMSPEC Environment VariableF0001.012: ArmadilloF0001.013: ASPackF0001.009: ConfuserF0001.005: Custom CompressionF0001.006: Custom Compression of CodeF0001.007: Custom Compression of DataF0001.001: Nested PackingF0001.002: Standard CompressionF0001.003: Standard Compression of CodeF0001.004: Standard Compression of DataF0001.011: ThemidaF0001.008: UPXF0001.010: VMProtectDefense EvasionC0033: ConsoleC0034: Environment VariableC0036: RegistryC0035: WallpaperC0034.001: Set VariableC0036.004: Create Registry KeyC0036.002: Delete Registry KeyC0036.007: Delete Registry ValueC0036.003: Open Registry KeyC0036.005: Query Registry KeyC0036.006: Query Registry ValueC0036.001: Set Registry ValueOperating System Micro-objectiveC0040: Allocate Thread Local StorageC0043: Check MutexC0042: Create MutexC0017: Create ProcessC0038: Create ThreadC0064: Enumerate ThreadsC0065: Open ProcessC0066: Open ThreadC0054: Resume ThreadC0072: Set Thread ContextC0041: Set Thread Local Storage ValueC0055: Suspend ThreadC0018: Terminate ProcessC0039: Terminate ThreadC0070: Unmap Section ViewC0071: Write Process MemoryC0017.001: Create Process via ShellcodeC0017.002: Create Process via WMIC0017.003: Create Suspended ProcessProcess Micro-objectiveC0037: Install DriverC0023: Load DriverC0057: Simulate HardwareC0037.001: MinifilterC0023.001: MinifilterC0057.001: Ctrl-Alt-DelC0057.002: Mouse ClickHardware Micro-objectiveC0068: Crypto AlgorithmC0069: Crypto ConstantC0059: Crypto LibraryC0029: Cryptographic HashC0031: Decrypt DataC0027: Encrypt DataC0028: Encryption KeyC0021: Generate Pseudo-random SequenceC0061: Hashed Message Authentication CodeC0059.001: API CallC0059.002: Static Public LibraryC0029.001: MD5C0029.002: SHA1C0029.004: SHA224C0029.003: SHA256C0029.006: SnefruC0029.005: TigerC0031.005: 3DESC0031.001: AESC0031.002: Block CipherC0031.003: BlowfishC0031.004: CamelliaC0031.006: HC-128C0031.007: HC-256C0031.008: RC4C0031.009: RC6C0031.010: RSAC0031.011: SkipjackC0031.012: SosemanukC0031.013: Stream CipherC0031.014: TwofishC0027.004: 3DESC0027.001: AESC0027.014: Block CipherC0027.002: BlowfishC0027.003: CamelliaC0027.006: HC-128C0027.007: HC-256C0027.009: RC4C0027.010: RC6C0027.011: RSAC0027.013: SkipjackC0027.008: SosemanukC0027.012: Stream CipherC0027.005: TwofishC0028.001: Import Public KeyC0028.002: RC4 KSAC0021.001: GetTickCountC0021.002: randC0021.004: RC4 PRGAC0021.003: Use APICryptography Micro-objectiveC0019: Check StringC0032: ChecksumC0024: Compress DataC0060: Compression LibraryC0053: Decode DataC0025: Decompress DataC0026: Encode DataC0058: ModuloC0030: Non-Cryptographic HashC0020: Use ConstantC0032.005: AdlerC0032.003: BSDC0032.001: CRC32C0032.002: LuhnC0024.002: IEncodingFilterFactoryC0024.001: QuickLZC0053.001: Base64C0053.002: XORC0025.003: aPLibC0025.002: IEncodingFilterFactoryC0025.001: QuickLZC0026.001: Base64C0026.002: XORC0030.004: dhashC0030.006: djb2C0030.003: Fast-HashC0030.005: FNVC0030.001: MurmurHashC0030.002: pHashData Micro-objectiveC0015: Alter File ExtensionC0045: Copy FileC0046: Create DirectoryC0016: Create FileC0048: Delete DirectoryC0047: Delete FileC0049: Get File AttributesC0063: Move FileC0051: Read FileC0056: Read Virtual DiskC0050: Set File AttributesC0052: Writes FileC0015.001: Append ExtensionC0016.001: Create Office DocumentC0016.002: Create Ransomware FileFile System Micro-objectiveC0011: DNS CommunicationC0004: FTP CommunicationC0002: HTTP CommunicationC0014: ICMP CommunicationC0003: Interprocess CommunicationC0012: SMTP CommunicationC0001: Socket CommunicationC0005: WinINetC0011.003: DDNS Domain ConnectC0011.001: ResolveC0011.005: Resolve Free Hosting DomainC0011.004: Resolve TLDC0011.002: Server ConnectC0004.001: Send FileC0004.002: WinINetC0002.002: ClientC0002.009: Connect to ServerC0002.012: Create RequestC0002.006: Download URLC0002.011: Extract BodyC0002.017: Get ResponseC0002.010: IWebBrowserC0002.004: Open URLC0002.014: Read HeaderC0002.015: Receive RequestC0002.005: Send DataC0002.003: Send RequestC0002.016: Send ResponseC0002.001: ServerC0002.013: Set HeaderC0002.018: Start ServerC0002.008: WinHTTPC0002.007: WinINetC0014.002: Echo RequestC0014.001: Generate TrafficC0003.002: Connect PipeC0003.001: Create PipeC0003.003: Read PipeC0003.004: Write PipeC0012.002: RequestC0012.001: Server ConnectC0001.004: Connect SocketC0001.003: Create SocketC0001.011: Create TCP SocketC0001.010: Create UDP SocketC0001.012: Get Socket StatusC0001.009: Initialize Winsock LibraryC0001.006: Receive DataC0001.016: Receive TCP DataC0001.017: Receive UDP DataC0001.007: Send DataC0001.014: Send TCP DataC0001.015: Send UDP DataC0001.001: Set Socket ConfigC0001.005: Start TCP ServerC0001.008: TCP ClientC0001.002: TCP ServerC0001.013: UDP ClientC0005.001: InternetConnectC0005.002: InternetOpenC0005.003: InternetOpenURLC0005.004: InternetReadFileC0005.005: InternetWriteFileCommunication Micro-objectiveC0007: Allocate MemoryC0008: Change Memory ProtectionC0044: Free MemoryC0006: Heap SprayC0010: Overflow BufferC0009: Stack PivotC0008.002: Executable HeapC0008.001: Executable StackMemory Micro-objectiveB0010: Call Graph Generation EvasionB0045: Data Flow Analysis EvasionB0012: Disassembler EvasionB0032: Executable Code ObfuscationB0034: Executable Code OptimizationB0008: Executable Code VirtualizationE1027: Obfuscated Files or InformationF0001: Software PackingB0010.002: InvokeNTDLL System Calls via Encoded TableB0010.003: Shadow Process CommunicationB0010.001: Two-layer Function ReturnB0045.003: Arbitrary Memory CorruptionB0045.001: Control DependenceB0045.002: Implicit FlowsB0012.001: Argument ObfuscationB0012.002: Conditional MisdirectionB0012.006:Desynchronizing Opaque PredicatesB0012.007: Fake FunctionB0012.003: Value Dependent JumpsB0012.005: VBA StompingB0032.001: API HashingB0032.020: Argument ObfuscationB0032.002: Code InsertionB0032.008: Data Value ObfuscationB0032.003: Dead Code InsertionB0032.009: Entry Point ObfuscationB0032.004: Fake Code InsertionB0032.010: Guard PagesB0032.011:Import Address Table ObfuscationB0032.012: Import CompressionB0032.013: Instruction OverlapB0032.014: Interleaving CodeB0032.005: Jump InsertionB0032.007: Junk Code InsertionB0032.019: Opaque PredicateB0032.017: Stack StringsB0032.016:Structured Exception Handling (SEH)B0032.018: Symbol ObfuscationB0032.006: Thunk Code InsertionB0032.021: Variable RecompositionB0034.001: Jump/Call Absolute AddressB0034.002: MinificationB0008.001: Multiple VMsE1027.m01: EncodingE1027.m03: Encoding - Custom AlgorithmE1027.m02: Encoding - Standard AlgorithmE1027.m04: EncryptionE1027.m08: Encryption - Custom AlgorithmE1027.m05: Encryption - Standard AlgorithmE1027.m06: Encryption of CodeE1027.m07: Encryption of DataF0001.012: ArmadilloF0001.013: ASPackF0001.009: ConfuserF0001.005: Custom CompressionF0001.006: Custom Compression of CodeF0001.007: Custom Compression of DataF0001.001: Nested PackingF0001.002: Standard CompressionF0001.003: Standard Compression of CodeF0001.004: Standard Compression of DataF0001.011: ThemidaF0001.008: UPXF0001.010: VMProtectAnti-Static AnalysisB0013: Analysis Tool DiscoveryE1010: Application Window DiscoveryB0046: Code DiscoveryE1083: File and Directory DiscoveryB0043: ReferencesB0038: Self DiscoveryB0014: SMTP Connection DiscoveryE1082: System Information DiscoveryB0013.008: Known File LocationB0013.009: Known WindowB0013.010: Known Windows Class NameB0013.001: Process detectionB0013.002: Process detection - DebuggersB0013.004:Process detection - PCAP UtilitiesB0013.006:Process detection - PE UtilitiesB0013.005:Process detection - Process UtilitiesB0013.007: Process detection - SandboxesB0013.003: Processdetection - SysInternals Suite ToolsE1010.m01: Window TextB0046.001: Enumerate PE SectionsB0046.002:Inspect Section Memory PermissionsB0046.003: Parse PE HeaderE1083.m02: Filter by ExtensionE1083.m01: Log FileB0038.002: Check Magic StringB0038.003: Check Section LengthB0038.001: Use HashquineE1082.m02: Enumerate Environment VariablesE1082.m01: Generate Windows ExceptionDiscoveryE1510: Clipboard ModificationF0009: Component FirmwareB0016: Compromise Data IntegrityE1485: Data DestructionE1486: Data Encrypted for ImpactB0033: Denial of ServiceB0017: Destroy HardwareF0014: Disk WipeE1190: Exploit KitE1203: Exploitation for Client ExecutionE1643: Generate Traffic from VictimB0019: Manipulate Network TrafficB0042: Modify HardwareB0022: Remote AccessB0018: Resource HijackingB0039: SpammingF0009.001: Router FirmwareE1485.m03: Delete Application/SoftwareE1485.m04: Delete Shadow CopiesE1485.m02: Empty Recycle BinE1486.001: Ransom NoteE1203.m03:File Transfer Protocol (FTP) ServersE1203.m02: Java-based Web ServersE1203.m04:Red Hat JBoss Enterprise ProductsE1203.m01: Remote Desktop ProtocolsE1203.m05: SysinternalsE1203.m06: Windows UtilitiesE1643.m02: Advertisement Replacement FraudE1643.m01: Click HijackingB0042.001: CDROMB0042.002: MouseB0042.003: PrinterB0022.001: Reverse ShellB0018.002: CryptojackingB0018.001: Password CrackingImpactE1059: Command and Scripting InterpreterB0025: Conditional ExecutionB0044: Execution DependencyE1203: Exploitation for Client ExecutionB0023: Install Additional ProgramB0024: Prevent Concurrent ExecutionB0011: Remote CommandsB0020: Send EmailB0021: Send Poisoned Text MessageE1569: System ServicesE1204: User ExecutionB0025.008: Deposited KeysB0025.002: Environmental KeysB0025.003: GetVolumeInformationB0025.004: Host Fingerprint CheckB0025.007: Runs as ServiceB0025.005: Secure TriggersB0025.001: Suicide ExitB0025.006: Token CheckE1203.m03:File Transfer Protocol (FTP) ServersE1203.m02: Java-based Web ServersE1203.m04:Red Hat JBoss Enterprise ProductsE1203.m01: Remote Desktop ProtocolsE1203.m05: SysinternalsE1203.m06: Windows UtilitiesB0011.001: Delete FileB0011.002: Download FileB0011.003: ExecuteB0011.004: ShutdownB0011.005: SleepB0011.006: UninstallB0011.007: Upload FileE1569.m01: MSDTCExecution \ No newline at end of file +B0036: Capture EvasionB0025: Conditional ExecutionB0001: Debugger DetectionB0002: Debugger EvasionB0003: Dynamic Analysis EvasionB0004: Emulator DetectionB0005: Emulator EvasionB0008: Executable Code VirtualizationF0015: Hijack Execution FlowB0006: Memory Dump EvasionB0007: Sandbox DetectionF0001: Software PackingB0009: Virtual Machine DetectionB0036.002: Encrypted PayloadsB0036.001: Memory-only PayloadB0036.003: Multiple Stages of LoadersB0025.008: Deposited KeysB0025.002: Environmental KeysB0025.003: GetVolumeInformationB0025.004: Host Fingerprint CheckB0025.007: Runs as ServiceB0025.005: Secure TriggersB0025.001: Suicide ExitB0025.006: Token CheckB0001.034: Anti-debugging InstructionsB0001.001: API Hook DetectionB0001.038: Check ProcessesB0001.002: CheckRemoteDebuggerPresentB0001.003: CloseHandleB0001.004: Debugger ArtifactsB0001.005: Hardware BreakpointsB0001.006: InterruptionB0001.008: IsDebuggerPresentB0001.009: Memory BreakpointsB0001.010: Memory Write WatchingB0001.011: Monitoring ThreadB0001.012: NtQueryInformationProcessB0001.013: NtQueryObjectB0001.014: NtSetInformationThreadB0001.015:NtYieldExecution/SwitchToThreadB0001.016: OutputDebugStringB0001.017:Page Exception Breakpoint DetectionB0001.018: Parent ProcessB0001.019: Process Environment BlockB0001.035: ProcessEnvironment Block BeingDebuggedB0001.037:Process Environment Block IsDebuggedB0001.036:Process Environment Block NtGlobalFlagB0001.020: Process JobsB0001.021: ProcessHeapB0001.022: RtlAdjustPrivilegeB0001.023: SeDebugPrivilegeB0001.024: SetHandleInformationB0001.025: Software BreakpointsB0001.026: Stack CanaryB0001.027: TIB AwareB0001.028: Timing/Delay CheckB0001.032:Timing/Delay Check GetTickCountB0001.033: Timing/DelayCheck QueryPerformanceCounterB0001.029: TLS CallbacksB0001.030: UnhandledExceptionFilterB0001.031: WudfIsAnyDebuggerPresentB0002.001: Block InterruptsB0002.002: Break Point ClearingB0002.003: Byte StealingB0002.004: Change SizeOfImageB0002.005: Code Integrity CheckB0002.006: Exception MisdirectionB0002.007: Get Base IndirectlyB0002.008: Guard PagesB0002.009: Hook InterruptB0002.010: Import ObfuscationB0002.011: InliningB0002.012: Loop EscapesB0002.013: Malloc UseB0002.014: Modify PE HeaderB0002.015: NanomitesB0002.016: Obfuscate Library UseB0002.017: Parallel ThreadsB0002.018: Pipeline MisdirectionB0002.019: Pre-DebugB0002.020: Relocate API CodeB0002.021: Return ObfuscationB0002.022: RtlAdjustPrivilegeB0002.023: Section MisalignmentB0002.024: Self-DebuggingB0002.025: Self-UnmappingB0002.026: Static LinkingB0002.027: Stolen API CodeB0002.028: TamperingB0002.029: Thread TimeoutB0002.030: Use InterruptsB0003.001: Alternative ntdll.dllB0003.012: API HammeringB0003.011: Code Integrity CheckB0003.002: Data FloodB0003.003: Delayed ExecutionB0003.004: Demo ModeB0003.005: Drop CodeB0003.006: Encode FileB0003.007: Hook File SystemB0003.008: Hook InterruptB0003.009: IllusionB0003.010: RestartB0004.003:Check Emulator-related Registry KeysB0004.001:Check for Emulator-related FilesB0004.002: Check for WINE VersionB0004.004: Failed Network ConnectionsB0005.001: Different Opcode SetsB0005.004: Extra Loops/Time LocksB0005.002:Undocumented/Unimplemented OpcodesB0005.003:Unusual/Undocumented API CallsB0008.001: Multiple VMsF0015.006:Abuse Windows Function CallsF0015.001:Export Address Table HookingF0015.003:Import Address Table HookingF0015.002: Inline PatchingF0015.007: Procedure HookingF0015.004: ShadowSystem Service Dispatch Table HookingF0015.005:System Service Dispatch Table HookingB0006.001: Code Encryption in MemoryB0006.002: Erase the PE headerB0006.008: Feed MisinformationB0006.009: Flow Opcode ObstructionB0006.006: Guard PagesB0006.003: Hide virtual memoryB0006.010: Hook memory mapping APIsB0006.007: On-the-Fly APIsB0006.011:Patch MmGetPhysicalMemoryRangesB0006.004: SizeOfImageB0006.005: TamperingB0007.001: Check Clipboard DataB0007.002: Check FilesB0007.003: Human User CheckB0007.004: Injected DLL TestingB0007.005: Product Key/ID TestingB0007.006: Screen Resolution TestingB0007.007: Self CheckB0007.010: Test API RoutinesB0007.008: Timing/Date CheckB0007.009: Timing/Uptime CheckF0001.012: ArmadilloF0001.013: ASPackF0001.009: ConfuserF0001.005: Custom CompressionF0001.006: Custom Compression of CodeF0001.007: Custom Compression of DataF0001.001: Nested PackingF0001.002: Standard CompressionF0001.003:Standard Compression of CodeF0001.004:Standard Compression of DataF0001.011: ThemidaF0001.008: UPXF0001.010: VMProtectB0009.001:Check File and Directory ArtifactsB0009.002: Check Memory ArtifactsB0009.003: Check Named System ObjectsB0009.004: Check ProcessesB0009.005: Check Registry KeysB0009.006: Check Running ServicesB0009.007: Check SoftwareB0009.008: Check Virtual DevicesB0009.009: Check WindowsB0009.022: Check Windows - Title barsB0009.021:Check Windows - Unique windowsB0009.020: Check Windows - Window sizeB0009.010: Guest Process TestingB0009.011:HTML5 Performance Object CheckB0009.012: Human User CheckB0009.029: Instruction TestingB0009.034: Instruction Testing - CPUIDB0009.035: Instruction Testing - INB0009.036: Instruction Testing - RDTSCB0009.031: InstructionTesting - SGDT/SLDT (no pill)B0009.030:Instruction Testing - SIDT (red pill)B0009.032: Instruction Testing - SMSWB0009.033: Instruction Testing - STRB0009.037:Instruction Testing - VMCPUIDB0009.038:Instruction Testing - VPCEXTB0009.013: Modern Specs CheckB0009.015:Modern Specs Check - Drive sizeB0009.019:Modern Specs Check - Keyboard layoutB0009.017:Modern Specs Check - PrinterB0009.018:Modern Specs Check - Processor countB0009.014: ModernSpecs Check - Total physical memoryB0009.016:Modern Specs Check - USB driveB0009.023:Unique Hardware/Firmware CheckB0009.024:Unique Hardware/Firmware Check - BIOSB0009.027: UniqueHardware/Firmware Check - CPU LocationB0009.026: UniqueHardware/Firmware Check - CPU NameB0009.025: Unique Hardware/FirmwareCheck - I/O Communication PortB0009.028: UniqueHardware/Firmware Check - MAC AddressAnti-Behavioral AnalysisB0010: Call Graph Generation EvasionB0045: Data Flow Analysis EvasionB0012: Disassembler EvasionB0032: Executable Code ObfuscationB0034: Executable Code OptimizationB0008: Executable Code VirtualizationE1027: Obfuscated Files or InformationF0001: Software PackingB0010.002: InvokeNTDLL System Calls via Encoded TableB0010.003:Shadow Process CommunicationB0010.001: Two-layer Function ReturnB0045.003: Arbitrary Memory CorruptionB0045.001: Control DependenceB0045.002: Implicit FlowsB0012.001: Argument ObfuscationB0012.002: Conditional MisdirectionB0012.006:Desynchronizing Opaque PredicatesB0012.007: Fake FunctionB0012.003: Value Dependent JumpsB0012.005: VBA StompingB0032.001: API HashingB0032.020: Argument ObfuscationB0032.002: Code InsertionB0032.008: Data Value ObfuscationB0032.003: Dead Code InsertionB0032.009: Entry Point ObfuscationB0032.004: Fake Code InsertionB0032.010: Guard PagesB0032.011:Import Address Table ObfuscationB0032.012: Import CompressionB0032.013: Instruction OverlapB0032.014: Interleaving CodeB0032.005: Jump InsertionB0032.007: Junk Code InsertionB0032.019: Opaque PredicateB0032.017: Stack StringsB0032.016:Structured Exception Handling (SEH)B0032.018: Symbol ObfuscationB0032.006: Thunk Code InsertionB0032.021: Variable RecompositionB0034.001: Jump/Call Absolute AddressB0034.002: MinificationB0008.001: Multiple VMsE1027.m01: EncodingE1027.m03: Encoding - Custom AlgorithmE1027.m02:Encoding - Standard AlgorithmE1027.m04: EncryptionE1027.m08:Encryption - Custom AlgorithmE1027.m05:Encryption - Standard AlgorithmE1027.m06: Encryption of CodeE1027.m07: Encryption of DataF0001.012: ArmadilloF0001.013: ASPackF0001.009: ConfuserF0001.005: Custom CompressionF0001.006: Custom Compression of CodeF0001.007: Custom Compression of DataF0001.001: Nested PackingF0001.002: Standard CompressionF0001.003:Standard Compression of CodeF0001.004:Standard Compression of DataF0001.011: ThemidaF0001.008: UPXF0001.010: VMProtectAnti-Static AnalysisE1560: Archive Collected DataB0028: CryptocurrencyF0015: Hijack Execution FlowE1056: Input CaptureF0002: KeyloggingE1113: Screen CaptureE1560.m01: EncodingE1560.m04: Encoding - Custom AlgorithmE1560.m03:Encoding - Standard AlgorithmE1560.m02: EncryptionE1560.m06:Encryption - Custom AlgorithmE1560.m05:Encryption - Standard AlgorithmB0028.001: BitcoinB0028.002: EthereumB0028.003: ZcashF0015.006:Abuse Windows Function CallsF0015.001:Export Address Table HookingF0015.003:Import Address Table HookingF0015.002: Inline PatchingF0015.007: Procedure HookingF0015.004: ShadowSystem Service Dispatch Table HookingF0015.005:System Service Dispatch Table HookingE1056.m01: Mouse EventsF0002.001: Application HookF0002.002: PollingE1113.m01: WinAPICollectionB0030: C2 CommunicationB0031: Domain Name GenerationE1105: Ingress Tool TransferB0030.011: AuthenticateB0030.005: Check for PayloadB0030.012: Directory ListingB0030.013: Execute FileB0030.014: Execute Shell CommandB0030.015: File searchB0030.004:Implant to Controller File TransferB0030.002: Receive DataB0030.008: Request CommandB0030.010: Request Email Address ListB0030.009: Request Email TemplateB0030.001: Send DataB0030.007: Send HeartbeatB0030.006: Send System InformationB0030.003:Server to Client File TransferB0030.016: Start Interactive ShellCommand and ControlC0011: DNS CommunicationC0004: FTP CommunicationC0002: HTTP CommunicationC0014: ICMP CommunicationC0003: Interprocess CommunicationC0012: SMTP CommunicationC0001: Socket CommunicationC0005: WinINetC0011.003: DDNS Domain ConnectC0011.001: ResolveC0011.005: Resolve Free Hosting DomainC0011.004: Resolve TLDC0011.002: Server ConnectC0004.001: Send FileC0004.002: WinINetC0002.002: ClientC0002.009: Connect to ServerC0002.012: Create RequestC0002.006: Download URLC0002.011: Extract BodyC0002.017: Get ResponseC0002.010: IWebBrowserC0002.004: Open URLC0002.014: Read HeaderC0002.015: Receive RequestC0002.005: Send DataC0002.003: Send RequestC0002.016: Send ResponseC0002.001: ServerC0002.013: Set HeaderC0002.018: Start ServerC0002.008: WinHTTPC0002.007: WinINetC0014.002: Echo RequestC0014.001: Generate TrafficC0003.002: Connect PipeC0003.001: Create PipeC0003.003: Read PipeC0003.004: Write PipeC0012.002: RequestC0012.001: Server ConnectC0001.004: Connect SocketC0001.003: Create SocketC0001.011: Create TCP SocketC0001.010: Create UDP SocketC0001.012: Get Socket StatusC0001.009: Initialize Winsock LibraryC0001.006: Receive DataC0001.016: Receive TCP DataC0001.017: Receive UDP DataC0001.007: Send DataC0001.014: Send TCP DataC0001.015: Send UDP DataC0001.001: Set Socket ConfigC0001.005: Start TCP ServerC0001.008: TCP ClientC0001.002: TCP ServerC0001.013: UDP ClientC0005.001: InternetConnectC0005.002: InternetOpenC0005.003: InternetOpenURLC0005.004: InternetReadFileC0005.005: InternetWriteFileCommunication Micro-objectiveB0028: CryptocurrencyF0015: Hijack Execution FlowE1056: Input CaptureF0002: KeyloggingE1113: Screen CaptureB0028.001: BitcoinB0028.002: EthereumB0028.003: ZcashF0015.006:Abuse Windows Function CallsF0015.001:Export Address Table HookingF0015.003:Import Address Table HookingF0015.002: Inline PatchingF0015.007: Procedure HookingF0015.004: ShadowSystem Service Dispatch Table HookingF0015.005:System Service Dispatch Table HookingE1056.m01: Mouse EventsF0002.001: Application HookF0002.002: PollingE1113.m01: WinAPICredential AccessC0068: Crypto AlgorithmC0069: Crypto ConstantC0059: Crypto LibraryC0029: Cryptographic HashC0031: Decrypt DataC0027: Encrypt DataC0028: Encryption KeyC0021: Generate Pseudo-random SequenceC0061: Hashed Message Authentication CodeC0059.001: API CallC0059.002: Static Public LibraryC0029.001: MD5C0029.002: SHA1C0029.004: SHA224C0029.003: SHA256C0029.006: SnefruC0029.005: TigerC0031.005: 3DESC0031.001: AESC0031.002: Block CipherC0031.003: BlowfishC0031.004: CamelliaC0031.006: HC-128C0031.007: HC-256C0031.008: RC4C0031.009: RC6C0031.010: RSAC0031.011: SkipjackC0031.012: SosemanukC0031.013: Stream CipherC0031.014: TwofishC0027.004: 3DESC0027.001: AESC0027.014: Block CipherC0027.002: BlowfishC0027.003: CamelliaC0027.006: HC-128C0027.007: HC-256C0027.009: RC4C0027.010: RC6C0027.011: RSAC0027.013: SkipjackC0027.008: SosemanukC0027.012: Stream CipherC0027.005: TwofishC0028.001: Import Public KeyC0028.002: RC4 KSAC0021.001: GetTickCountC0021.002: randC0021.004: RC4 PRGAC0021.003: Use APICryptography Micro-objectiveC0019: Check StringC0032: ChecksumC0024: Compress DataC0060: Compression LibraryC0053: Decode DataC0025: Decompress DataC0026: Encode DataC0058: ModuloC0030: Non-Cryptographic HashC0020: Use ConstantC0032.005: AdlerC0032.003: BSDC0032.001: CRC32C0032.002: LuhnC0024.002: IEncodingFilterFactoryC0024.001: QuickLZC0053.001: Base64C0053.002: XORC0025.003: aPLibC0025.002: IEncodingFilterFactoryC0025.001: QuickLZC0026.001: Base64C0026.002: XORC0030.004: dhashC0030.006: djb2C0030.003: Fast-HashC0030.005: FNVC0030.001: MurmurHashC0030.002: pHashData Micro-objectiveB0027: Alternative Installation LocationF0013: BootkitB0037: Bypass Data Execution PreventionF0009: Component FirmwareB0025: Conditional ExecutionB0040: Covert LocationF0004: Disable or Evade Security ToolsF0005: Hidden Files and DirectoriesE1564: Hide ArtifactsF0015: Hijack Execution FlowF0006: Indicator BlockingB0047: InstallInsecure or Malicious ConfigurationE1112: Modify RegistryE1027: Obfuscated Files or InformationB0029: Polymorphic CodeE1055: Process InjectionE1014: RootkitF0007: Self DeletionF0001: Software PackingB0027.001: Fileless MalwareB0027.002: Registry InstallB0037.001: ROP ChainsF0009.001: Router FirmwareB0025.008: Deposited KeysB0025.002: Environmental KeysB0025.003: GetVolumeInformationB0025.004: Host Fingerprint CheckB0025.007: Runs as ServiceB0025.005: Secure TriggersB0025.001: Suicide ExitB0025.006: Token CheckB0040.001: Hide Data in RegistryB0040.002: SteganographyF0004.004: AMSI BypassF0004.007:Bypass Windows File ProtectionF0004.009: Disable Code IntegrityF0004.001:Disable Kernel Patch ProtectionF0004.002: DisableSystem File Overwrite ProtectionF0004.006: Force Lazy WritingF0004.008: Heavens GateF0004.005: Modify PolicyF0004.003: Unhook APIsF0005.003: AttributeF0005.001: ExtensionF0005.002: LocationF0005.004: TimestampE1564.m02:Direct Kernel Object ManipulationE1564.m05: Hidden Kernel ModulesE1564.m03: Hidden ProcessesE1564.m04: Hidden ServicesE1564.m01: Hidden Userspace LibrariesF0015.006:Abuse Windows Function CallsF0015.001:Export Address Table HookingF0015.003:Import Address Table HookingF0015.002: Inline PatchingF0015.007: Procedure HookingF0015.004: ShadowSystem Service Dispatch Table HookingF0015.005:System Service Dispatch Table HookingF0006.001: Remove SMS Warning MessagesE1027.m01: EncodingE1027.m03: Encoding - Custom AlgorithmE1027.m02:Encoding - Standard AlgorithmE1027.m04: EncryptionE1027.m08:Encryption - Custom AlgorithmE1027.m05:Encryption - Standard AlgorithmE1027.m06: Encryption of CodeE1027.m07: Encryption of DataB0029.002: Call IndirectionsB0029.003: Code ReorderingB0029.001: Packer StubE1055.004: Asynchronous Procedure CallE1055.001:Dynamic-link Library InjectionE1055.011:Extra Window Memory InjectionE1055.m01:Hook Injection via SetWindowsHooksExE1055.m02: Injection andPersistence via Registry ModificationE1055.m03: Injection using ShimsE1055.m05:Injection via Windows FibersE1055.m04: Patch Process Command LineE1055.002:Portable Executable InjectionE1055.012: Process HollowingE1055.003: Thread Execution HijackingE1014.m12: Application RootkitE1014.m13: BootloaderE1014.m14: Hardware/Firmware RootkitE1014.m15:Hypervisor/Virtualized RootkitE1014.m16: Kernel Mode RootkitE1014.m17: Memory RootkitF0007.001:COMSPEC Environment VariableF0001.012: ArmadilloF0001.013: ASPackF0001.009: ConfuserF0001.005: Custom CompressionF0001.006: Custom Compression of CodeF0001.007: Custom Compression of DataF0001.001: Nested PackingF0001.002: Standard CompressionF0001.003:Standard Compression of CodeF0001.004:Standard Compression of DataF0001.011: ThemidaF0001.008: UPXF0001.010: VMProtectDefense EvasionB0013: Analysis Tool DiscoveryE1010: Application Window DiscoveryB0046: Code DiscoveryE1083: File and Directory DiscoveryB0043: ReferencesB0038: Self DiscoveryB0014: SMTP Connection DiscoveryE1082: System Information DiscoveryB0013.008: Known File LocationB0013.009: Known WindowB0013.010: Known Windows Class NameB0013.001: Process detectionB0013.002:Process detection - DebuggersB0013.004:Process detection - PCAP UtilitiesB0013.006:Process detection - PE UtilitiesB0013.005:Process detection - Process UtilitiesB0013.007:Process detection - SandboxesB0013.003: Processdetection - SysInternals Suite ToolsE1010.m01: Window TextB0046.001: Enumerate PE SectionsB0046.002:Inspect Section Memory PermissionsB0046.003: Parse PE HeaderE1083.m02: Filter by ExtensionE1083.m01: Log FileB0038.002: Check Magic StringB0038.003: Check Section LengthB0038.001: Use HashquineE1082.m02:Enumerate Environment VariablesE1082.m01: Generate Windows ExceptionDiscoveryE1059: Command and Scripting InterpreterB0025: Conditional ExecutionB0044: Execution DependencyE1203: Exploitation for Client ExecutionB0023: Install Additional ProgramB0024: Prevent Concurrent ExecutionB0011: Remote CommandsB0020: Send EmailB0021: Send Poisoned Text MessageE1569: System ServicesE1204: User ExecutionB0025.008: Deposited KeysB0025.002: Environmental KeysB0025.003: GetVolumeInformationB0025.004: Host Fingerprint CheckB0025.007: Runs as ServiceB0025.005: Secure TriggersB0025.001: Suicide ExitB0025.006: Token CheckE1203.m03:File Transfer Protocol (FTP) ServersE1203.m02: Java-based Web ServersE1203.m04:Red Hat JBoss Enterprise ProductsE1203.m01: Remote Desktop ProtocolsE1203.m05: SysinternalsE1203.m06: Windows UtilitiesB0011.001: Delete FileB0011.002: Download FileB0011.003: ExecuteB0011.004: ShutdownB0011.005: SleepB0011.006: UninstallB0011.007: Upload FileE1569.m01: MSDTCExecutionE1020: Automated ExfiltrationE1020.m01:Exfiltrate via File Hosting ServiceExfiltrationC0015: Alter File ExtensionC0045: Copy FileC0046: Create DirectoryC0016: Create FileC0048: Delete DirectoryC0047: Delete FileC0049: Get File AttributesC0063: Move FileC0051: Read FileC0056: Read Virtual DiskC0050: Set File AttributesC0052: Writes FileC0015.001: Append ExtensionC0016.001: Create Office DocumentC0016.002: Create Ransomware FileFile System Micro-objectiveC0037: Install DriverC0023: Load DriverC0057: Simulate HardwareC0037.001: MinifilterC0023.001: MinifilterC0057.001: Ctrl-Alt-DelC0057.002: Mouse ClickHardware Micro-objectiveE1510: Clipboard ModificationF0009: Component FirmwareB0016: Compromise Data IntegrityE1485: Data DestructionE1486: Data Encrypted for ImpactB0033: Denial of ServiceB0017: Destroy HardwareF0014: Disk WipeE1190: Exploit KitE1203: Exploitation for Client ExecutionE1643: Generate Traffic from VictimB0019: Manipulate Network TrafficB0042: Modify HardwareB0022: Remote AccessB0018: Resource HijackingB0039: SpammingF0009.001: Router FirmwareE1485.m03: Delete Application/SoftwareE1485.m04: Delete Shadow CopiesE1485.m02: Empty Recycle BinE1486.001: Ransom NoteE1203.m03:File Transfer Protocol (FTP) ServersE1203.m02: Java-based Web ServersE1203.m04:Red Hat JBoss Enterprise ProductsE1203.m01: Remote Desktop ProtocolsE1203.m05: SysinternalsE1203.m06: Windows UtilitiesE1643.m02:Advertisement Replacement FraudE1643.m01: Click HijackingB0042.001: CDROMB0042.002: MouseB0042.003: PrinterB0022.001: Reverse ShellB0018.002: CryptojackingB0018.001: Password CrackingImpactE1105: Ingress Tool TransferB0026: Malicious Network DriverB0020: Send EmailB0021: Send Poisoned Text MessageE1195: Supply Chain CompromiseE1195.m01:Abuse Enterprise CertificatesE1195.m02: Exploit Private APIsLateral MovementC0007: Allocate MemoryC0008: Change Memory ProtectionC0044: Free MemoryC0006: Heap SprayC0010: Overflow BufferC0009: Stack PivotC0008.002: Executable HeapC0008.001: Executable StackMemory Micro-objectiveC0033: ConsoleC0034: Environment VariableC0036: RegistryC0035: WallpaperC0034.001: Set VariableC0036.004: Create Registry KeyC0036.002: Delete Registry KeyC0036.007: Delete Registry ValueC0036.003: Open Registry KeyC0036.005: Query Registry KeyC0036.006: Query Registry ValueC0036.001: Set Registry ValueOperating System Micro-objectiveF0013: BootkitF0009: Component FirmwareF0005: Hidden Files and DirectoriesE1564: Hide ArtifactsF0015: Hijack Execution FlowE1105: Ingress Tool TransferB0047: InstallInsecure or Malicious ConfigurationF0010: Kernel Modules and ExtensionsB0026: Malicious Network DriverF0011: Modify Existing ServiceE1112: Modify RegistryF0012: Registry Run Keys / Startup FolderB0022: Remote AccessB0035: Shutdown EventF0009.001: Router FirmwareF0005.003: AttributeF0005.001: ExtensionF0005.002: LocationF0005.004: TimestampE1564.m02:Direct Kernel Object ManipulationE1564.m05: Hidden Kernel ModulesE1564.m03: Hidden ProcessesE1564.m04: Hidden ServicesE1564.m01: Hidden Userspace LibrariesF0015.006:Abuse Windows Function CallsF0015.001:Export Address Table HookingF0015.003:Import Address Table HookingF0015.002: Inline PatchingF0015.007: Procedure HookingF0015.004: ShadowSystem Service Dispatch Table HookingF0015.005:System Service Dispatch Table HookingF0010.001: Device DriverB0022.001: Reverse ShellPersistenceF0015: Hijack Execution FlowF0016: Install CertificateF0010: Kernel Modules and ExtensionsF0011: Modify Existing ServiceE1055: Process InjectionF0015.006:Abuse Windows Function CallsF0015.001:Export Address Table HookingF0015.003:Import Address Table HookingF0015.002: Inline PatchingF0015.007: Procedure HookingF0015.004: ShadowSystem Service Dispatch Table HookingF0015.005:System Service Dispatch Table HookingF0010.001: Device DriverE1055.004: Asynchronous Procedure CallE1055.001:Dynamic-link Library InjectionE1055.011:Extra Window Memory InjectionE1055.m01:Hook Injection via SetWindowsHooksExE1055.m02: Injection andPersistence via Registry ModificationE1055.m03: Injection using ShimsE1055.m05:Injection via Windows FibersE1055.m04: Patch Process Command LineE1055.002:Portable Executable InjectionE1055.012: Process HollowingE1055.003: Thread Execution HijackingPrivilege EscalationC0040: Allocate Thread Local StorageC0043: Check MutexC0042: Create MutexC0017: Create ProcessC0038: Create ThreadC0064: Enumerate ThreadsC0065: Open ProcessC0066: Open ThreadC0054: Resume ThreadC0072: Set Thread ContextC0041: Set Thread Local Storage ValueC0055: Suspend ThreadC0018: Terminate ProcessC0039: Terminate ThreadC0070: Unmap Section ViewC0071: Write Process MemoryC0017.001:Create Process via ShellcodeC0017.002: Create Process via WMIC0017.003: Create Suspended ProcessProcess Micro-objective \ No newline at end of file diff --git a/yfaq/mbc_matrix_without_ids.svg b/yfaq/mbc_matrix_without_ids.svg index 1bad610..9d6f8b9 100644 --- a/yfaq/mbc_matrix_without_ids.svg +++ b/yfaq/mbc_matrix_without_ids.svg @@ -1,2 +1,2 @@ -Archive Collected DataCryptocurrencyHijack Execution FlowInput CaptureKeyloggingScreen CaptureEncodingEncoding - Custom AlgorithmEncoding - Standard AlgorithmEncryptionEncryption - Custom AlgorithmEncryption - Standard AlgorithmBitcoinEthereumZcashAbuse Windows Function CallsExport Address Table HookingImport Address Table HookingInline PatchingProcedure HookingShadow SystemService Dispatch Table HookingSystemService Dispatch Table HookingMouse EventsApplication HookPollingWinAPICollectionAutomated ExfiltrationExfiltratevia File Hosting ServiceExfiltrationIngress Tool TransferMalicious Network DriverSend EmailSend Poisoned Text MessageSupply Chain CompromiseAbuse Enterprise CertificatesExploit Private APIsLateral MovementHijack Execution FlowInstall CertificateKernel Modules and ExtensionsModify Existing ServiceProcess InjectionAbuse Windows Function CallsExport Address Table HookingImport Address Table HookingInline PatchingProcedure HookingShadow SystemService Dispatch Table HookingSystemService Dispatch Table HookingDevice DriverAsynchronous Procedure CallDynamic-link Library InjectionExtra Window Memory InjectionHookInjection via SetWindowsHooksExInjection and Persistencevia Registry ModificationInjection using ShimsInjection via Windows FibersPatch Process Command LinePortable Executable InjectionProcess HollowingThread Execution HijackingPrivilege EscalationCryptocurrencyHijack Execution FlowInput CaptureKeyloggingScreen CaptureBitcoinEthereumZcashAbuse Windows Function CallsExport Address Table HookingImport Address Table HookingInline PatchingProcedure HookingShadow SystemService Dispatch Table HookingSystemService Dispatch Table HookingMouse EventsApplication HookPollingWinAPICredential AccessCapture EvasionConditional ExecutionDebugger DetectionDebugger EvasionDynamic Analysis EvasionEmulator DetectionEmulator EvasionExecutable Code VirtualizationHijack Execution FlowMemory Dump EvasionSandbox DetectionSoftware PackingVirtual Machine DetectionEncrypted PayloadsMemory-only PayloadMultiple Stages of LoadersDeposited KeysEnvironmental KeysGetVolumeInformationHost Fingerprint CheckRuns as ServiceSecure TriggersSuicide ExitToken CheckAnti-debugging InstructionsAPI Hook DetectionCheck ProcessesCheckRemoteDebuggerPresentCloseHandleDebugger ArtifactsHardware BreakpointsInterruptionIsDebuggerPresentMemory BreakpointsMemory Write WatchingMonitoring ThreadNtQueryInformationProcessNtQueryObjectNtSetInformationThreadNtYieldExecution/SwitchToThreadOutputDebugStringPageException Breakpoint DetectionParent ProcessProcess Environment BlockProcessEnvironment Block BeingDebuggedProcessEnvironment Block IsDebuggedProcessEnvironment Block NtGlobalFlagProcess JobsProcessHeapRtlAdjustPrivilegeSeDebugPrivilegeSetHandleInformationSoftware BreakpointsStack CanaryTIB AwareTiming/Delay CheckTiming/Delay Check GetTickCountTiming/DelayCheck QueryPerformanceCounterTLS CallbacksUnhandledExceptionFilterWudfIsAnyDebuggerPresentBlock InterruptsBreak Point ClearingByte StealingChange SizeOfImageCode Integrity CheckException MisdirectionGet Base IndirectlyGuard PagesHook InterruptImport ObfuscationInliningLoop EscapesMalloc UseModify PE HeaderNanomitesObfuscate Library UseParallel ThreadsPipeline MisdirectionPre-DebugRelocate API CodeReturn ObfuscationRtlAdjustPrivilegeSection MisalignmentSelf-DebuggingSelf-UnmappingStatic LinkingStolen API CodeTamperingThread TimeoutUse InterruptsAlternative ntdll.dllAPI HammeringCode Integrity CheckData FloodDelayed ExecutionDemo ModeDrop CodeEncode FileHook File SystemHook InterruptIllusionRestartCheckEmulator-related Registry KeysCheck for Emulator-related FilesCheck for WINE VersionFailed Network ConnectionsDifferent Opcode SetsExtra Loops/Time LocksUndocumented/Unimplemented OpcodesUnusual/Undocumented API CallsMultiple VMsAbuse Windows Function CallsExport Address Table HookingImport Address Table HookingInline PatchingProcedure HookingShadow SystemService Dispatch Table HookingSystemService Dispatch Table HookingCode Encryption in MemoryErase the PE headerFeed MisinformationFlow Opcode ObstructionGuard PagesHide virtual memoryHook memory mapping APIsOn-the-Fly APIsPatch MmGetPhysicalMemoryRangesSizeOfImageTamperingCheck Clipboard DataCheck FilesHuman User CheckInjected DLL TestingProduct Key/ID TestingScreen Resolution TestingSelf CheckTest API RoutinesTiming/Date CheckTiming/Uptime CheckArmadilloASPackConfuserCustom CompressionCustom Compression of CodeCustom Compression of DataNested PackingStandard CompressionStandard Compression of CodeStandard Compression of DataThemidaUPXVMProtectCheck File and Directory ArtifactsCheck Memory ArtifactsCheck Named System ObjectsCheck ProcessesCheck Registry KeysCheck Running ServicesCheck SoftwareCheck Virtual DevicesCheck WindowsCheck Windows - Title barsCheck Windows - Unique windowsCheck Windows - Window sizeGuest Process TestingHTML5 Performance Object CheckHuman User CheckInstruction TestingInstruction Testing - CPUIDInstruction Testing - INInstruction Testing - RDTSCInstructionTesting - SGDT/SLDT (no pill)InstructionTesting - SIDT (red pill)Instruction Testing - SMSWInstruction Testing - STRInstruction Testing - VMCPUIDInstruction Testing - VPCEXTModern Specs CheckModern Specs Check - Drive sizeModernSpecs Check - Keyboard layoutModern Specs Check - PrinterModernSpecs Check - Processor countModern SpecsCheck - Total physical memoryModern Specs Check - USB driveUnique Hardware/Firmware CheckUniqueHardware/Firmware Check - BIOSUnique Hardware/FirmwareCheck - CPU LocationUniqueHardware/Firmware Check - CPU NameUnique Hardware/FirmwareCheck - I/O Communication PortUnique Hardware/FirmwareCheck - MAC AddressAnti-Behavioral AnalysisC2 CommunicationDomain Name GenerationIngress Tool TransferAuthenticateCheck for PayloadDirectory ListingExecute FileExecute Shell CommandFile searchImplantto Controller File TransferReceive DataRequest CommandRequest Email Address ListRequest Email TemplateSend DataSend HeartbeatSend System InformationServer to Client File TransferStart Interactive ShellCommand and ControlBootkitComponent FirmwareHidden Files and DirectoriesHide ArtifactsHijack Execution FlowIngress Tool TransferInstallInsecure or Malicious ConfigurationKernel Modules and ExtensionsMalicious Network DriverModify Existing ServiceModify RegistryRegistry Run Keys / Startup FolderRemote AccessShutdown EventRouter FirmwareAttributeExtensionLocationTimestampDirect Kernel Object ManipulationHidden Kernel ModulesHidden ProcessesHidden ServicesHidden Userspace LibrariesAbuse Windows Function CallsExport Address Table HookingImport Address Table HookingInline PatchingProcedure HookingShadow SystemService Dispatch Table HookingSystemService Dispatch Table HookingDevice DriverReverse ShellPersistenceAlternative Installation LocationBootkitBypass Data Execution PreventionComponent FirmwareConditional ExecutionCovert LocationDisable or Evade Security ToolsHidden Files and DirectoriesHide ArtifactsHijack Execution FlowIndicator BlockingInstallInsecure or Malicious ConfigurationModify RegistryObfuscated Files or InformationPolymorphic CodeProcess InjectionRootkitSelf DeletionSoftware PackingFileless MalwareRegistry InstallROP ChainsRouter FirmwareDeposited KeysEnvironmental KeysGetVolumeInformationHost Fingerprint CheckRuns as ServiceSecure TriggersSuicide ExitToken CheckHide Data in RegistrySteganographyAMSI BypassBypass Windows File ProtectionDisable Code IntegrityDisable Kernel Patch ProtectionDisableSystem File Overwrite ProtectionForce Lazy WritingHeavens GateModify PolicyUnhook APIsAttributeExtensionLocationTimestampDirect Kernel Object ManipulationHidden Kernel ModulesHidden ProcessesHidden ServicesHidden Userspace LibrariesAbuse Windows Function CallsExport Address Table HookingImport Address Table HookingInline PatchingProcedure HookingShadow SystemService Dispatch Table HookingSystemService Dispatch Table HookingRemove SMS Warning MessagesEncodingEncoding - Custom AlgorithmEncoding - Standard AlgorithmEncryptionEncryption - Custom AlgorithmEncryption - Standard AlgorithmEncryption of CodeEncryption of DataCall IndirectionsCode ReorderingPacker StubAsynchronous Procedure CallDynamic-link Library InjectionExtra Window Memory InjectionHookInjection via SetWindowsHooksExInjection and Persistencevia Registry ModificationInjection using ShimsInjection via Windows FibersPatch Process Command LinePortable Executable InjectionProcess HollowingThread Execution HijackingApplication RootkitBootloaderHardware/Firmware RootkitHypervisor/Virtualized RootkitKernel Mode RootkitMemory RootkitCOMSPEC Environment VariableArmadilloASPackConfuserCustom CompressionCustom Compression of CodeCustom Compression of DataNested PackingStandard CompressionStandard Compression of CodeStandard Compression of DataThemidaUPXVMProtectDefense EvasionConsoleEnvironment VariableRegistryWallpaperSet VariableCreate Registry KeyDelete Registry KeyDelete Registry ValueOpen Registry KeyQuery Registry KeyQuery Registry ValueSet Registry ValueOperating System Micro-objectiveAllocate Thread Local StorageCheck MutexCreate MutexCreate ProcessCreate ThreadEnumerate ThreadsOpen ProcessOpen ThreadResume ThreadSet Thread ContextSet Thread Local Storage ValueSuspend ThreadTerminate ProcessTerminate ThreadUnmap Section ViewWrite Process MemoryCreate Process via ShellcodeCreate Process via WMICreate Suspended ProcessProcess Micro-objectiveInstall DriverLoad DriverSimulate HardwareMinifilterMinifilterCtrl-Alt-DelMouse ClickHardware Micro-objectiveCrypto AlgorithmCrypto ConstantCrypto LibraryCryptographic HashDecrypt DataEncrypt DataEncryption KeyGenerate Pseudo-random SequenceHashed Message Authentication CodeAPI CallStatic Public LibraryMD5SHA1SHA224SHA256SnefruTiger3DESAESBlock CipherBlowfishCamelliaHC-128HC-256RC4RC6RSASkipjackSosemanukStream CipherTwofish3DESAESBlock CipherBlowfishCamelliaHC-128HC-256RC4RC6RSASkipjackSosemanukStream CipherTwofishImport Public KeyRC4 KSAGetTickCountrandRC4 PRGAUse APICryptography Micro-objectiveCheck StringChecksumCompress DataCompression LibraryDecode DataDecompress DataEncode DataModuloNon-Cryptographic HashUse ConstantAdlerBSDCRC32LuhnIEncodingFilterFactoryQuickLZBase64XORaPLibIEncodingFilterFactoryQuickLZBase64XORdhashdjb2Fast-HashFNVMurmurHashpHashData Micro-objectiveAlter File ExtensionCopy FileCreate DirectoryCreate FileDelete DirectoryDelete FileGet File AttributesMove FileRead FileRead Virtual DiskSet File AttributesWrites FileAppend ExtensionCreate Office DocumentCreate Ransomware FileFile System Micro-objectiveDNS CommunicationFTP CommunicationHTTP CommunicationICMP CommunicationInterprocess CommunicationSMTP CommunicationSocket CommunicationWinINetDDNS Domain ConnectResolveResolve Free Hosting DomainResolve TLDServer ConnectSend FileWinINetClientConnect to ServerCreate RequestDownload URLExtract BodyGet ResponseIWebBrowserOpen URLRead HeaderReceive RequestSend DataSend RequestSend ResponseServerSet HeaderStart ServerWinHTTPWinINetEcho RequestGenerate TrafficConnect PipeCreate PipeRead PipeWrite PipeRequestServer ConnectConnect SocketCreate SocketCreate TCP SocketCreate UDP SocketGet Socket StatusInitialize Winsock LibraryReceive DataReceive TCP DataReceive UDP DataSend DataSend TCP DataSend UDP DataSet Socket ConfigStart TCP ServerTCP ClientTCP ServerUDP ClientInternetConnectInternetOpenInternetOpenURLInternetReadFileInternetWriteFileCommunication Micro-objectiveAllocate MemoryChange Memory ProtectionFree MemoryHeap SprayOverflow BufferStack PivotExecutable HeapExecutable StackMemory Micro-objectiveCall Graph Generation EvasionData Flow Analysis EvasionDisassembler EvasionExecutable Code ObfuscationExecutable Code OptimizationExecutable Code VirtualizationObfuscated Files or InformationSoftware PackingInvoke NTDLLSystem Calls via Encoded TableShadow Process CommunicationTwo-layer Function ReturnArbitrary Memory CorruptionControl DependenceImplicit FlowsArgument ObfuscationConditional MisdirectionDesynchronizing Opaque PredicatesFake FunctionValue Dependent JumpsVBA StompingAPI HashingArgument ObfuscationCode InsertionData Value ObfuscationDead Code InsertionEntry Point ObfuscationFake Code InsertionGuard PagesImport Address Table ObfuscationImport CompressionInstruction OverlapInterleaving CodeJump InsertionJunk Code InsertionOpaque PredicateStack StringsStructuredException Handling (SEH)Symbol ObfuscationThunk Code InsertionVariable RecompositionJump/Call Absolute AddressMinificationMultiple VMsEncodingEncoding - Custom AlgorithmEncoding - Standard AlgorithmEncryptionEncryption - Custom AlgorithmEncryption - Standard AlgorithmEncryption of CodeEncryption of DataArmadilloASPackConfuserCustom CompressionCustom Compression of CodeCustom Compression of DataNested PackingStandard CompressionStandard Compression of CodeStandard Compression of DataThemidaUPXVMProtectAnti-Static AnalysisAnalysis Tool DiscoveryApplication Window DiscoveryCode DiscoveryFile and Directory DiscoveryReferencesSelf DiscoverySMTP Connection DiscoverySystem Information DiscoveryKnown File LocationKnown WindowKnown Windows Class NameProcess detectionProcess detection - DebuggersProcess detection - PCAP UtilitiesProcess detection - PE UtilitiesProcessdetection - Process UtilitiesProcess detection - SandboxesProcess detection- SysInternals Suite ToolsWindow TextEnumerate PE SectionsInspect Section Memory PermissionsParse PE HeaderFilter by ExtensionLog FileCheck Magic StringCheck Section LengthUse HashquineEnumerate Environment VariablesGenerate Windows ExceptionDiscoveryClipboard ModificationComponent FirmwareCompromise Data IntegrityData DestructionData Encrypted for ImpactDenial of ServiceDestroy HardwareDisk WipeExploit KitExploitation for Client ExecutionGenerate Traffic from VictimManipulate Network TrafficModify HardwareRemote AccessResource HijackingSpammingRouter FirmwareDelete Application/SoftwareDelete Shadow CopiesEmpty Recycle BinRansom NoteFileTransfer Protocol (FTP) ServersJava-based Web ServersRed Hat JBoss Enterprise ProductsRemote Desktop ProtocolsSysinternalsWindows UtilitiesAdvertisement Replacement FraudClick HijackingCDROMMousePrinterReverse ShellCryptojackingPassword CrackingImpactCommand and Scripting InterpreterConditional ExecutionExecution DependencyExploitation for Client ExecutionInstall Additional ProgramPrevent Concurrent ExecutionRemote CommandsSend EmailSend Poisoned Text MessageSystem ServicesUser ExecutionDeposited KeysEnvironmental KeysGetVolumeInformationHost Fingerprint CheckRuns as ServiceSecure TriggersSuicide ExitToken CheckFileTransfer Protocol (FTP) ServersJava-based Web ServersRed Hat JBoss Enterprise ProductsRemote Desktop ProtocolsSysinternalsWindows UtilitiesDelete FileDownload FileExecuteShutdownSleepUninstallUpload FileMSDTCExecution \ No newline at end of file +Capture EvasionConditional ExecutionDebugger DetectionDebugger EvasionDynamic Analysis EvasionEmulator DetectionEmulator EvasionExecutable Code VirtualizationHijack Execution FlowMemory Dump EvasionSandbox DetectionSoftware PackingVirtual Machine DetectionEncrypted PayloadsMemory-only PayloadMultiple Stages of LoadersDeposited KeysEnvironmental KeysGetVolumeInformationHost Fingerprint CheckRuns as ServiceSecure TriggersSuicide ExitToken CheckAnti-debugging InstructionsAPI Hook DetectionCheck ProcessesCheckRemoteDebuggerPresentCloseHandleDebugger ArtifactsHardware BreakpointsInterruptionIsDebuggerPresentMemory BreakpointsMemory Write WatchingMonitoring ThreadNtQueryInformationProcessNtQueryObjectNtSetInformationThreadNtYieldExecution/SwitchToThreadOutputDebugStringPage Exception Breakpoint DetectionParent ProcessProcess Environment BlockProcessEnvironment Block BeingDebuggedProcess Environment Block IsDebuggedProcess Environment Block NtGlobalFlagProcess JobsProcessHeapRtlAdjustPrivilegeSeDebugPrivilegeSetHandleInformationSoftware BreakpointsStack CanaryTIB AwareTiming/Delay CheckTiming/Delay Check GetTickCountTiming/DelayCheck QueryPerformanceCounterTLS CallbacksUnhandledExceptionFilterWudfIsAnyDebuggerPresentBlock InterruptsBreak Point ClearingByte StealingChange SizeOfImageCode Integrity CheckException MisdirectionGet Base IndirectlyGuard PagesHook InterruptImport ObfuscationInliningLoop EscapesMalloc UseModify PE HeaderNanomitesObfuscate Library UseParallel ThreadsPipeline MisdirectionPre-DebugRelocate API CodeReturn ObfuscationRtlAdjustPrivilegeSection MisalignmentSelf-DebuggingSelf-UnmappingStatic LinkingStolen API CodeTamperingThread TimeoutUse InterruptsAlternative ntdll.dllAPI HammeringCode Integrity CheckData FloodDelayed ExecutionDemo ModeDrop CodeEncode FileHook File SystemHook InterruptIllusionRestartCheck Emulator-related Registry KeysCheck for Emulator-related FilesCheck for WINE VersionFailed Network ConnectionsDifferent Opcode SetsExtra Loops/Time LocksUndocumented/Unimplemented OpcodesUnusual/Undocumented API CallsMultiple VMsAbuse Windows Function CallsExport Address Table HookingImport Address Table HookingInline PatchingProcedure HookingShadowSystem Service Dispatch Table HookingSystem Service Dispatch Table HookingCode Encryption in MemoryErase the PE headerFeed MisinformationFlow Opcode ObstructionGuard PagesHide virtual memoryHook memory mapping APIsOn-the-Fly APIsPatch MmGetPhysicalMemoryRangesSizeOfImageTamperingCheck Clipboard DataCheck FilesHuman User CheckInjected DLL TestingProduct Key/ID TestingScreen Resolution TestingSelf CheckTest API RoutinesTiming/Date CheckTiming/Uptime CheckArmadilloASPackConfuserCustom CompressionCustom Compression of CodeCustom Compression of DataNested PackingStandard CompressionStandard Compression of CodeStandard Compression of DataThemidaUPXVMProtectCheck File and Directory ArtifactsCheck Memory ArtifactsCheck Named System ObjectsCheck ProcessesCheck Registry KeysCheck Running ServicesCheck SoftwareCheck Virtual DevicesCheck WindowsCheck Windows - Title barsCheck Windows - Unique windowsCheck Windows - Window sizeGuest Process TestingHTML5 Performance Object CheckHuman User CheckInstruction TestingInstruction Testing - CPUIDInstruction Testing - INInstruction Testing - RDTSCInstructionTesting - SGDT/SLDT (no pill)Instruction Testing - SIDT (red pill)Instruction Testing - SMSWInstruction Testing - STRInstruction Testing - VMCPUIDInstruction Testing - VPCEXTModern Specs CheckModern Specs Check - Drive sizeModern Specs Check - Keyboard layoutModern Specs Check - PrinterModern Specs Check - Processor countModernSpecs Check - Total physical memoryModern Specs Check - USB driveUnique Hardware/Firmware CheckUnique Hardware/Firmware Check - BIOSUniqueHardware/Firmware Check - CPU LocationUniqueHardware/Firmware Check - CPU NameUnique Hardware/FirmwareCheck - I/O Communication PortUniqueHardware/Firmware Check - MAC AddressAnti-Behavioral AnalysisCall Graph Generation EvasionData Flow Analysis EvasionDisassembler EvasionExecutable Code ObfuscationExecutable Code OptimizationExecutable Code VirtualizationObfuscated Files or InformationSoftware PackingInvokeNTDLL System Calls via Encoded TableShadow Process CommunicationTwo-layer Function ReturnArbitrary Memory CorruptionControl DependenceImplicit FlowsArgument ObfuscationConditional MisdirectionDesynchronizing Opaque PredicatesFake FunctionValue Dependent JumpsVBA StompingAPI HashingArgument ObfuscationCode InsertionData Value ObfuscationDead Code InsertionEntry Point ObfuscationFake Code InsertionGuard PagesImport Address Table ObfuscationImport CompressionInstruction OverlapInterleaving CodeJump InsertionJunk Code InsertionOpaque PredicateStack StringsStructured Exception Handling (SEH)Symbol ObfuscationThunk Code InsertionVariable RecompositionJump/Call Absolute AddressMinificationMultiple VMsEncodingEncoding - Custom AlgorithmEncoding - Standard AlgorithmEncryptionEncryption - Custom AlgorithmEncryption - Standard AlgorithmEncryption of CodeEncryption of DataArmadilloASPackConfuserCustom CompressionCustom Compression of CodeCustom Compression of DataNested PackingStandard CompressionStandard Compression of CodeStandard Compression of DataThemidaUPXVMProtectAnti-Static AnalysisArchive Collected DataCryptocurrencyHijack Execution FlowInput CaptureKeyloggingScreen CaptureEncodingEncoding - Custom AlgorithmEncoding - Standard AlgorithmEncryptionEncryption - Custom AlgorithmEncryption - Standard AlgorithmBitcoinEthereumZcashAbuse Windows Function CallsExport Address Table HookingImport Address Table HookingInline PatchingProcedure HookingShadowSystem Service Dispatch Table HookingSystem Service Dispatch Table HookingMouse EventsApplication HookPollingWinAPICollectionC2 CommunicationDomain Name GenerationIngress Tool TransferAuthenticateCheck for PayloadDirectory ListingExecute FileExecute Shell CommandFile searchImplant to Controller File TransferReceive DataRequest CommandRequest Email Address ListRequest Email TemplateSend DataSend HeartbeatSend System InformationServer to Client File TransferStart Interactive ShellCommand and ControlDNS CommunicationFTP CommunicationHTTP CommunicationICMP CommunicationInterprocess CommunicationSMTP CommunicationSocket CommunicationWinINetDDNS Domain ConnectResolveResolve Free Hosting DomainResolve TLDServer ConnectSend FileWinINetClientConnect to ServerCreate RequestDownload URLExtract BodyGet ResponseIWebBrowserOpen URLRead HeaderReceive RequestSend DataSend RequestSend ResponseServerSet HeaderStart ServerWinHTTPWinINetEcho RequestGenerate TrafficConnect PipeCreate PipeRead PipeWrite PipeRequestServer ConnectConnect SocketCreate SocketCreate TCP SocketCreate UDP SocketGet Socket StatusInitialize Winsock LibraryReceive DataReceive TCP DataReceive UDP DataSend DataSend TCP DataSend UDP DataSet Socket ConfigStart TCP ServerTCP ClientTCP ServerUDP ClientInternetConnectInternetOpenInternetOpenURLInternetReadFileInternetWriteFileCommunication Micro-objectiveCryptocurrencyHijack Execution FlowInput CaptureKeyloggingScreen CaptureBitcoinEthereumZcashAbuse Windows Function CallsExport Address Table HookingImport Address Table HookingInline PatchingProcedure HookingShadowSystem Service Dispatch Table HookingSystem Service Dispatch Table HookingMouse EventsApplication HookPollingWinAPICredential AccessCrypto AlgorithmCrypto ConstantCrypto LibraryCryptographic HashDecrypt DataEncrypt DataEncryption KeyGenerate Pseudo-random SequenceHashed Message Authentication CodeAPI CallStatic Public LibraryMD5SHA1SHA224SHA256SnefruTiger3DESAESBlock CipherBlowfishCamelliaHC-128HC-256RC4RC6RSASkipjackSosemanukStream CipherTwofish3DESAESBlock CipherBlowfishCamelliaHC-128HC-256RC4RC6RSASkipjackSosemanukStream CipherTwofishImport Public KeyRC4 KSAGetTickCountrandRC4 PRGAUse APICryptography Micro-objectiveCheck StringChecksumCompress DataCompression LibraryDecode DataDecompress DataEncode DataModuloNon-Cryptographic HashUse ConstantAdlerBSDCRC32LuhnIEncodingFilterFactoryQuickLZBase64XORaPLibIEncodingFilterFactoryQuickLZBase64XORdhashdjb2Fast-HashFNVMurmurHashpHashData Micro-objectiveAlternative Installation LocationBootkitBypass Data Execution PreventionComponent FirmwareConditional ExecutionCovert LocationDisable or Evade Security ToolsHidden Files and DirectoriesHide ArtifactsHijack Execution FlowIndicator BlockingInstallInsecure or Malicious ConfigurationModify RegistryObfuscated Files or InformationPolymorphic CodeProcess InjectionRootkitSelf DeletionSoftware PackingFileless MalwareRegistry InstallROP ChainsRouter FirmwareDeposited KeysEnvironmental KeysGetVolumeInformationHost Fingerprint CheckRuns as ServiceSecure TriggersSuicide ExitToken CheckHide Data in RegistrySteganographyAMSI BypassBypass Windows File ProtectionDisable Code IntegrityDisable Kernel Patch ProtectionDisableSystem File Overwrite ProtectionForce Lazy WritingHeavens GateModify PolicyUnhook APIsAttributeExtensionLocationTimestampDirect Kernel Object ManipulationHidden Kernel ModulesHidden ProcessesHidden ServicesHidden Userspace LibrariesAbuse Windows Function CallsExport Address Table HookingImport Address Table HookingInline PatchingProcedure HookingShadowSystem Service Dispatch Table HookingSystem Service Dispatch Table HookingRemove SMS Warning MessagesEncodingEncoding - Custom AlgorithmEncoding - Standard AlgorithmEncryptionEncryption - Custom AlgorithmEncryption - Standard AlgorithmEncryption of CodeEncryption of DataCall IndirectionsCode ReorderingPacker StubAsynchronous Procedure CallDynamic-link Library InjectionExtra Window Memory InjectionHook Injection via SetWindowsHooksExInjection andPersistence via Registry ModificationInjection using ShimsInjection via Windows FibersPatch Process Command LinePortable Executable InjectionProcess HollowingThread Execution HijackingApplication RootkitBootloaderHardware/Firmware RootkitHypervisor/Virtualized RootkitKernel Mode RootkitMemory RootkitCOMSPEC Environment VariableArmadilloASPackConfuserCustom CompressionCustom Compression of CodeCustom Compression of DataNested PackingStandard CompressionStandard Compression of CodeStandard Compression of DataThemidaUPXVMProtectDefense EvasionAnalysis Tool DiscoveryApplication Window DiscoveryCode DiscoveryFile and Directory DiscoveryReferencesSelf DiscoverySMTP Connection DiscoverySystem Information DiscoveryKnown File LocationKnown WindowKnown Windows Class NameProcess detectionProcess detection - DebuggersProcess detection - PCAP UtilitiesProcess detection - PE UtilitiesProcess detection - Process UtilitiesProcess detection - SandboxesProcessdetection - SysInternals Suite ToolsWindow TextEnumerate PE SectionsInspect Section Memory PermissionsParse PE HeaderFilter by ExtensionLog FileCheck Magic StringCheck Section LengthUse HashquineEnumerate Environment VariablesGenerate Windows ExceptionDiscoveryCommand and Scripting InterpreterConditional ExecutionExecution DependencyExploitation for Client ExecutionInstall Additional ProgramPrevent Concurrent ExecutionRemote CommandsSend EmailSend Poisoned Text MessageSystem ServicesUser ExecutionDeposited KeysEnvironmental KeysGetVolumeInformationHost Fingerprint CheckRuns as ServiceSecure TriggersSuicide ExitToken CheckFile Transfer Protocol (FTP) ServersJava-based Web ServersRed Hat JBoss Enterprise ProductsRemote Desktop ProtocolsSysinternalsWindows UtilitiesDelete FileDownload FileExecuteShutdownSleepUninstallUpload FileMSDTCExecutionAutomated ExfiltrationExfiltrate via File Hosting ServiceExfiltrationAlter File ExtensionCopy FileCreate DirectoryCreate FileDelete DirectoryDelete FileGet File AttributesMove FileRead FileRead Virtual DiskSet File AttributesWrites FileAppend ExtensionCreate Office DocumentCreate Ransomware FileFile System Micro-objectiveInstall DriverLoad DriverSimulate HardwareMinifilterMinifilterCtrl-Alt-DelMouse ClickHardware Micro-objectiveClipboard ModificationComponent FirmwareCompromise Data IntegrityData DestructionData Encrypted for ImpactDenial of ServiceDestroy HardwareDisk WipeExploit KitExploitation for Client ExecutionGenerate Traffic from VictimManipulate Network TrafficModify HardwareRemote AccessResource HijackingSpammingRouter FirmwareDelete Application/SoftwareDelete Shadow CopiesEmpty Recycle BinRansom NoteFile Transfer Protocol (FTP) ServersJava-based Web ServersRed Hat JBoss Enterprise ProductsRemote Desktop ProtocolsSysinternalsWindows UtilitiesAdvertisement Replacement FraudClick HijackingCDROMMousePrinterReverse ShellCryptojackingPassword CrackingImpactIngress Tool TransferMalicious Network DriverSend EmailSend Poisoned Text MessageSupply Chain CompromiseAbuse Enterprise CertificatesExploit Private APIsLateral MovementAllocate MemoryChange Memory ProtectionFree MemoryHeap SprayOverflow BufferStack PivotExecutable HeapExecutable StackMemory Micro-objectiveConsoleEnvironment VariableRegistryWallpaperSet VariableCreate Registry KeyDelete Registry KeyDelete Registry ValueOpen Registry KeyQuery Registry KeyQuery Registry ValueSet Registry ValueOperating System Micro-objectiveBootkitComponent FirmwareHidden Files and DirectoriesHide ArtifactsHijack Execution FlowIngress Tool TransferInstallInsecure or Malicious ConfigurationKernel Modules and ExtensionsMalicious Network DriverModify Existing ServiceModify RegistryRegistry Run Keys / Startup FolderRemote AccessShutdown EventRouter FirmwareAttributeExtensionLocationTimestampDirect Kernel Object ManipulationHidden Kernel ModulesHidden ProcessesHidden ServicesHidden Userspace LibrariesAbuse Windows Function CallsExport Address Table HookingImport Address Table HookingInline PatchingProcedure HookingShadowSystem Service Dispatch Table HookingSystem Service Dispatch Table HookingDevice DriverReverse ShellPersistenceHijack Execution FlowInstall CertificateKernel Modules and ExtensionsModify Existing ServiceProcess InjectionAbuse Windows Function CallsExport Address Table HookingImport Address Table HookingInline PatchingProcedure HookingShadowSystem Service Dispatch Table HookingSystem Service Dispatch Table HookingDevice DriverAsynchronous Procedure CallDynamic-link Library InjectionExtra Window Memory InjectionHook Injection via SetWindowsHooksExInjection andPersistence via Registry ModificationInjection using ShimsInjection via Windows FibersPatch Process Command LinePortable Executable InjectionProcess HollowingThread Execution HijackingPrivilege EscalationAllocate Thread Local StorageCheck MutexCreate MutexCreate ProcessCreate ThreadEnumerate ThreadsOpen ProcessOpen ThreadResume ThreadSet Thread ContextSet Thread Local Storage ValueSuspend ThreadTerminate ProcessTerminate ThreadUnmap Section ViewWrite Process MemoryCreate Process via ShellcodeCreate Process via WMICreate Suspended ProcessProcess Micro-objective \ No newline at end of file