mirror of
https://github.com/hunters-forge/OSSEM
synced 2026-06-08 14:44:11 +00:00
247 lines
9.5 KiB
HTML
247 lines
9.5 KiB
HTML
|
|
|
|
<!DOCTYPE html>
|
|
|
|
<html xmlns="http://www.w3.org/1999/xhtml">
|
|
<head>
|
|
<meta charset="utf-8" />
|
|
<title>Windows — The OSSEM Project</title>
|
|
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/5.11.2/css/all.min.css" integrity="sha384-KA6wR/X5RY4zFAHpv/CnoG2UW1uogYfdnP67Uv7eULvTveboZJg0qUpmJZb5VqzN" crossorigin="anonymous">
|
|
<link href="../../_static/css/index.css" rel="stylesheet">
|
|
<link rel="stylesheet" href="../../_static/sphinx-book-theme.css" type="text/css" />
|
|
<link rel="stylesheet" href="../../_static/pygments.css" type="text/css" />
|
|
<link rel="stylesheet" type="text/css" href="../../_static/togglebutton.css" />
|
|
<link rel="stylesheet" type="text/css" href="../../_static/copybutton.css" />
|
|
<link rel="stylesheet" type="text/css" href="../../_static/mystnb.css" />
|
|
<link rel="stylesheet" type="text/css" href="../../_static/jupyter-sphinx.css" />
|
|
<script id="documentation_options" data-url_root="../../" src="../../_static/documentation_options.js"></script>
|
|
<script src="../../_static/sphinx-book-theme.js"></script>
|
|
<script src="../../_static/jquery.js"></script>
|
|
<script src="../../_static/underscore.js"></script>
|
|
<script src="../../_static/doctools.js"></script>
|
|
<script src="../../_static/language_data.js"></script>
|
|
<script src="../../_static/togglebutton.js"></script>
|
|
<script src="../../_static/clipboard.min.js"></script>
|
|
<script src="../../_static/copybutton.js"></script>
|
|
<script src="../../_static/mystnb.js"></script>
|
|
<script src="../../_static/sphinx-book-theme.js"></script>
|
|
<script >var togglebuttonSelector = '.toggle, .secondtoggle, .tag_hide_input div.cell_input, .tag_hide-input div.cell_input, .tag_hide_output div.cell_output, .tag_hide-output div.cell_output, .tag_hide_cell.cell, .tag_hide-cell.cell';</script>
|
|
<script src="https://unpkg.com/@jupyter-widgets/html-manager@^0.18.0/dist/embed.js"></script>
|
|
<script async="async" src="https://unpkg.com/thebelab@latest/lib/index.js"></script>
|
|
<script async="async" src="../../_static/thebelab.js"></script>
|
|
<link rel="canonical" href="https://ossemproject.com/attack/windows/intro.html" />
|
|
<link rel="shortcut icon" href="../../_static/favicon.ico"/>
|
|
<link rel="index" title="Index" href="../../genindex.html" />
|
|
<link rel="search" title="Search" href="../../search.html" />
|
|
<link rel="next" title="Data Modeling Table" href="ds_mapping_table.html" />
|
|
<link rel="prev" title="network_session" href="../../cdm/tables/network_session.html" />
|
|
|
|
<meta name="viewport" content="width=device-width, initial-scale=1">
|
|
<meta name="docsearch:language" content="en">
|
|
<!-- Put requirejs at the end so it's always after bootstrap -->
|
|
<!-- TODO: remove this once https://github.com/pandas-dev/pydata-sphinx-theme/pull/149 is merged -->
|
|
<script src="https://cdnjs.cloudflare.com/ajax/libs/require.js/2.3.6/require.min.js"></script>
|
|
|
|
|
|
<!-- Opengraph tags -->
|
|
<meta property="og:url" content="https://ossemproject.com/attack/windows/intro.html" />
|
|
<meta property="og:type" content="article" />
|
|
<meta property="og:title" content="Windows" />
|
|
<meta property="og:description" content="Windows " />
|
|
<meta property="og:image" content="https://ossemproject.com/_static/logo.png" />
|
|
|
|
<meta name="twitter:card" content="summary">
|
|
|
|
|
|
</head>
|
|
<body data-spy="scroll" data-target="#bd-toc-nav" data-offset="80">
|
|
|
|
|
|
<div class="container-xl">
|
|
<div class="row">
|
|
|
|
|
|
<div class="col-12 col-md-3 bd-sidebar site-navigation show" id="site-navigation">
|
|
<div class="navbar-brand-box">
|
|
<a class="navbar-brand text-wrap" href="../../index.html">
|
|
|
|
<img src="../../_static/logo.png" class="logo" alt="logo">
|
|
|
|
|
|
<h1 class="site-logo" id="site-title">The OSSEM Project</h1>
|
|
|
|
</a>
|
|
</div>
|
|
|
|
<form class="bd-search d-flex align-items-center" action="../../search.html" method="get">
|
|
<i class="icon fas fa-search"></i>
|
|
<input type="search" class="form-control" name="q" id="search-input" placeholder="Search this book..." aria-label="Search this book..." autocomplete="off" >
|
|
</form>
|
|
|
|
<nav class="bd-links" id="bd-docs-nav" aria-label="Main navigation">
|
|
|
|
<ul class="nav sidenav_l1">
|
|
<li class="navbar-special">
|
|
<p class="margin-caption">Data Dictionaries</p>
|
|
</li>
|
|
<li class="">
|
|
<a href="../../dd/intro.html">Introduction</a>
|
|
</li>
|
|
<li class="">
|
|
<a href="../../dd/guidelines/intro.html">Guidelines</a>
|
|
</li>
|
|
<li class="navbar-special">
|
|
<p class="margin-caption">Common Data Model</p>
|
|
</li>
|
|
<li class="">
|
|
<a href="../../cdm/intro.html">Introduction</a>
|
|
</li>
|
|
<li class="">
|
|
<a href="../../cdm/guidelines/intro.html">Guidelines</a>
|
|
</li>
|
|
<li class="">
|
|
<a href="../../cdm/entities/intro.html">Entities</a>
|
|
</li>
|
|
<li class="">
|
|
<a href="../../cdm/tables/intro.html">Tables</a>
|
|
</li>
|
|
<li class="navbar-special">
|
|
<p class="margin-caption">ATT&CK Data Sources</p>
|
|
</li>
|
|
<li class="active">
|
|
<a href="">Windows</a>
|
|
<ul class="nav sidenav_l2">
|
|
<li class="">
|
|
<a href="ds_mapping_table.html">Data Modeling Table</a>
|
|
</li>
|
|
<li class="">
|
|
<a href="../../notebooks/attack/windows/ds_mapping_techniques.html">Windows Events to ATT&CK Techniques</a>
|
|
</li>
|
|
</ul>
|
|
</li>
|
|
</ul>
|
|
</nav>
|
|
<p class="navbar_footer">Powered by <a href="https://jupyterbook.org">Jupyter Book</a></p>
|
|
</div>
|
|
|
|
|
|
|
|
|
|
|
|
|
|
<main class="col py-md-3 pl-md-4 bd-content overflow-auto" role="main">
|
|
|
|
<div class="row topbar fixed-top container-xl">
|
|
<div class="col-12 col-md-3 bd-topbar-whitespace site-navigation show">
|
|
</div>
|
|
<div class="col pl-2 topbar-main">
|
|
|
|
<button id="navbar-toggler" class="navbar-toggler ml-0" type="button" data-toggle="collapse" data-toggle="tooltip" data-placement="bottom" data-target=".site-navigation" aria-controls="navbar-menu" aria-expanded="true" aria-label="Toggle navigation" aria-controls="site-navigation" title="Toggle navigation" data-toggle="tooltip" data-placement="left">
|
|
<i class="fas fa-bars"></i>
|
|
<i class="fas fa-arrow-left"></i>
|
|
<i class="fas fa-arrow-up"></i>
|
|
</button>
|
|
<div class="dropdown-buttons-trigger">
|
|
<button id="dropdown-buttons-trigger" class="btn btn-secondary topbarbtn" aria-label="Download this page"><i class="fas fa-download"></i></button>
|
|
|
|
|
|
<div class="dropdown-buttons">
|
|
<!-- ipynb file if we had a myst markdown file -->
|
|
|
|
<!-- Download raw file -->
|
|
<a class="dropdown-buttons" href="../../_sources/attack/windows/intro.md.txt"><button type="button" class="btn btn-secondary topbarbtn" title="Download source file" data-toggle="tooltip" data-placement="left">.md</button></a>
|
|
<!-- Download PDF via print -->
|
|
<button type="button" id="download-print" class="btn btn-secondary topbarbtn" title="Print to PDF" onClick="window.print()" data-toggle="tooltip" data-placement="left">.pdf</button>
|
|
</div>
|
|
|
|
</div>
|
|
|
|
<!-- Edit this page -->
|
|
<a class="edit-button" href="https://github.com/hunters-forge/OSSEM/edit/master/docs/attack/windows/intro.md"><button type="button" class="btn btn-secondary topbarbtn" data-toggle="tooltip" data-placement="bottom" title="Edit this page"><i class="fas fa-pencil-alt"></i></button></a>
|
|
|
|
<!-- Full screen (wrap in <a> to have style consistency -->
|
|
<a class="full-screen-button"><button type="button" class="btn btn-secondary topbarbtn" data-toggle="tooltip" data-placement="bottom" onclick="toggleFullScreen()" title="Fullscreen mode"><i class="fas fa-expand"></i></button></a>
|
|
|
|
<!-- Launch buttons -->
|
|
|
|
|
|
|
|
</div>
|
|
<div class="d-none d-md-block col-md-2 bd-toc show">
|
|
|
|
<nav id="bd-toc-nav">
|
|
<ul class="nav section-nav flex-column">
|
|
|
|
</ul>
|
|
</nav>
|
|
|
|
|
|
|
|
<div class="tocsection editthispage">
|
|
<a href="https://github.com/hunters-forge/OSSEM/edit/master/docs/attack/windows/intro.md">
|
|
<i class="fas fa-pencil-alt"></i> Edit this page
|
|
</a>
|
|
</div>
|
|
|
|
</div>
|
|
</div>
|
|
<div id="main-content" class="row">
|
|
<div class="col-12 col-md-9 col-xxl-7 pl-md-3 pr-md-0">
|
|
|
|
<div>
|
|
|
|
<div class="section" id="windows">
|
|
<h1>Windows<a class="headerlink" href="#windows" title="Permalink to this headline">¶</a></h1>
|
|
<div class="toctree-wrapper compound">
|
|
</div>
|
|
</div>
|
|
|
|
<script type="text/x-thebe-config">
|
|
{
|
|
requestKernel: true,
|
|
binderOptions: {
|
|
repo: "hunters-forge/OSSEM",
|
|
ref: "master",
|
|
},
|
|
codeMirrorConfig: {
|
|
theme: "abcdef",
|
|
mode: "python"
|
|
},
|
|
kernelOptions: {
|
|
kernelName: "python3",
|
|
path: "attack/windows"
|
|
}
|
|
}
|
|
</script>
|
|
<script>kernelName = 'python3'</script>
|
|
|
|
</div>
|
|
|
|
</div>
|
|
</div>
|
|
|
|
|
|
<div class='prev-next-bottom'>
|
|
|
|
<a class='left-prev' id="prev-link" href="../../cdm/tables/network_session.html" title="previous page">network_session</a>
|
|
<a class='right-next' id="next-link" href="ds_mapping_table.html" title="next page">Data Modeling Table</a>
|
|
|
|
</div>
|
|
<footer class="footer mt-5 mt-md-0">
|
|
<div class="container">
|
|
<p>
|
|
© Copyright 2020.<br/>
|
|
Created using <a href="http://sphinx-doc.org/">Sphinx</a> 2.4.1.<br/>
|
|
</p>
|
|
</div>
|
|
</footer>
|
|
</main>
|
|
|
|
|
|
</div>
|
|
</div>
|
|
|
|
<script src="../../_static/js/index.js"></script>
|
|
|
|
</body>
|
|
</html> |