mirror of
https://github.com/mthcht/ThreatHunting-Keywords
synced 2026-06-08 16:12:28 +00:00
755048bf5e
very few additions and some corrections
209 KiB
209 KiB
| 1 | keyword | metadata_keyword_regex | metadata_keyword_type | metadata_tool | metadata_description | metadata_tool_techniques | metadata_tool_tactics | metadata_malwares_name | metadata_groups_name | metadata_category | metadata_link | metadata_enable_endpoint_detection | metadata_enable_proxy_detection | metadata_tags | metadata_comment | metadata_severity_score | metadata_popularity_score | metadata_github_stars | metadata_github_forks | metadata_github_updated_at | metadata_github_created_at | metadata_entry_id |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2 | * --stealth --secureldap* | .{0,1000}\s\-\-stealth\s\-\-secureldap.{0,1000} | signature_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | N/A | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 3406 |
| 3 | * Win64/NetTool.SoftPerfectNetscan* | .{0,1000}\sWin64\/NetTool\.SoftPerfectNetscan.{0,1000} | signature_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | #Avsignature | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 3712 |
| 4 | */AmsiTamper.* | .{0,1000}\/AmsiTamper\..{0,1000} | signature_keyword | AmsiBypass | bypassing Anti-Malware Scanning Interface (AMSI) features | T1548.002 | TA0005 | N/A | N/A | Defense Evasion | https://github.com/S3cur3Th1sSh1t/Amsi-Bypass-Powershell | 1 | 0 | #linux | image | 5 | 10 | 1890 | 311 | 2024-11-28T10:31:15Z | 2019-05-14T06:09:25Z | 5304 |
| 5 | */WinREG.KillAV* | .{0,1000}\/WinREG\.KillAV.{0,1000} | signature_keyword | windows-defender-remover | hacktool used to remove Windows Defender | T1089 - T1562.001 - T1562.004 | TA0005 - TA0040 | N/A | Black Basta | Defense Evasion | https://github.com/ionuttbara/windows-defender-remover | 1 | 0 | #Avsignature | N/A | 10 | 10 | 5266 | 354 | 2025-02-13T20:21:07Z | 2021-08-13T20:44:46Z | 12643 |
| 6 | *\Advanced_Port_Scanner_*.exe* | .{0,1000}\\Advanced_Port_Scanner_.{0,1000}\.exe.{0,1000} | signature_keyword | advanced port scanner | port scanner tool abused by ransomware actors | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | Dispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa Locker | Discovery | https://www.advanced-port-scanner.com/ | 1 | 0 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 13881 |
| 7 | *\Bat-Potato.bat* | .{0,1000}\\Bat\-Potato\.bat.{0,1000} | signature_keyword | Bat-Potato | Automating Juicy Potato Local Privilege Escalation CMD exploit for penetration testers | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/0x4xel/Bat-Potato | 1 | 0 | N/A | N/A | 10 | 1 | 42 | 11 | 2022-12-13T20:19:51Z | 2022-12-12T20:50:22Z | 14276 |
| 8 | *3f31295f3435ec6223bbd70a6c0d4620a344e2232c7255dd8fa84ed48aa7a59a* | .{0,1000}3f31295f3435ec6223bbd70a6c0d4620a344e2232c7255dd8fa84ed48aa7a59a.{0,1000} | signature_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | #filehash | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 25215 |
| 9 | *A Variant Of Java/Adwind.SN* | .{0,1000}A\sVariant\sOf\sJava\/Adwind\.SN.{0,1000} | signature_keyword | Adzok | RAT tool - a variant of Adwind abused by TA | T1219 - T1105 - T1027 - T1059 - T1204 | TA0011 - TA0005 - TA0002 - TA0008 | N/A | Packrat | Malware | https://sourceforge.net/projects/adzok/files/Adzok_Open_v1.0.0.2.jar/download | 1 | 0 | #Avsignature | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 32138 |
| 10 | *A Variant Of Win64/AddUser* | .{0,1000}A\sVariant\sOf\sWin64\/AddUser.{0,1000} | signature_keyword | SpoolFool | Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE) | T1068 - T1055 - T1059.003 | TA0004 - TA0005 - TA0003 | Dispossessor | Privilege Escalation | https://github.com/ly4k/SpoolFool | 1 | 0 | #Avsignature | N/A | 9 | 8 | 788 | 160 | 2022-02-09T16:54:09Z | 2022-02-08T17:25:44Z | 32139 | |
| 11 | *A Variant Of Win64/KillProc.V* | .{0,1000}A\sVariant\sOf\sWin64\/KillProc\.V.{0,1000} | signature_keyword | BadRentdrv2 | A vulnerable driver (BYOVD) capable of terminating several EDRs and antivirus software | T1562 - T1068 - T1210 - T1489 - T1496 | TA0005 - TA0004 - TA0040 | N/A | Agrius | Defense Evasion | https://github.com/keowu/BadRentdrv2 | 1 | 0 | #Avsignature | N/A | 10 | 1 | 95 | 20 | 2024-12-26T13:43:18Z | 2023-10-01T18:24:38Z | 32140 |
| 12 | *A Variant Of WinGo/Merlin.A* | .{0,1000}A\sVariant\sOf\sWinGo\/Merlin\.A.{0,1000} | signature_keyword | merlin-agent | Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT) | T1219 - T1105 - T1071 - T1090 - T1055 - T1047 | TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011 | N/A | N/A | C2 | https://github.com/Ne0nd0g/merlin-agent | 1 | 0 | #Avsignature | N/A | 10 | 10 | 193 | 62 | 2025-04-16T14:12:16Z | 2020-07-17T20:47:56Z | 32141 |
| 13 | *AdFind (PUA)* | .{0,1000}AdFind\s\(PUA\).{0,1000} | signature_keyword | adfind | adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers are abusing it to gather valuable information about the network environment | T1087 - T1016 - T1482 | TA0007 - TA0008 - TA0043 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 33405 |
| 14 | *Advanced Port Scanner (PUA)* | .{0,1000}Advanced\sPort\sScanner\s\(PUA\).{0,1000} | signature_keyword | advanced port scanner | port scanner tool abused by ransomware actors | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | Dispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa Locker | Discovery | https://www.advanced-port-scanner.com/ | 1 | 0 | #Avsignature | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 33498 |
| 15 | *Adware/Gsecdump* | .{0,1000}Adware\/Gsecdump.{0,1000} | signature_keyword | gsecdump | credential dumper used to obtain password hashes and LSA secrets from Windows operating systems | T1003.001 - T1003.002 - T1555.003 - T1555.001 | TA0006 - TA0008 | N/A | APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick | Credential Access | https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 33508 |
| 16 | *Adwind!jar* | .{0,1000}Adwind!jar.{0,1000} | signature_keyword | Adzok | RAT tool - a variant of Adwind abused by TA | T1219 - T1105 - T1027 - T1059 - T1204 | TA0011 - TA0005 - TA0002 - TA0008 | N/A | Packrat | Malware | https://sourceforge.net/projects/adzok/files/Adzok_Open_v1.0.0.2.jar/download | 1 | 0 | #Avsignature | N/A | 8 | 8 | N/A | N/A | N/A | N/A | 33509 |
| 17 | *Application.Hacktool.DisableDefender.F* | .{0,1000}Application\.Hacktool\.DisableDefender\.F.{0,1000} | signature_keyword | defender-control | disable windows defender permanently | T1562.001 - T1562.004 - T1089 | TA0005 - TA0002 | N/A | LockBit | Defense Evasion | https://www.sordum.org/9480/defender-control-v2-1/ | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 33986 |
| 18 | *Application.Hacktool.SessionGopher* | .{0,1000}Application\.Hacktool\.SessionGopher.{0,1000} | signature_keyword | SessionGopher | uses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally. | T1047 - T1003.008 - T1552.004 - T1555.003 | TA0006 | N/A | PYSA - DarkSide - Sphinx | Credential Access | https://github.com/Arvanaghi/SessionGopher | 1 | 0 | #Avsignature | N/A | 10 | 10 | 1255 | 173 | 2022-11-22T21:33:23Z | 2017-03-08T02:49:32Z | 33987 |
| 19 | *Application.RiskTool.TDSSKiller.A* | .{0,1000}Application\.RiskTool\.TDSSKiller\.A.{0,1000} | signature_keyword | TDSKiller | TDSKiller detect and remove malware - including rootkits but is also abused by attackers to disable antivirus | T1562 - T1055 - T1070 | TA0005 - TA0004 | N/A | LockBit - Avaddon | Defense Evasion | https://www.majorgeeks.com/files/details/kaspersky_tdsskiller.html | 1 | 0 | #Avsignature | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 33989 |
| 20 | *ATK/Adpeas-A* | .{0,1000}ATK\/Adpeas\-A.{0,1000} | signature_keyword | adPEAS | adPEAS is a Powershell tool to automate Active Directory enumeration - wrapper for PowerView - PoshADCS - BloodHound and others | T1016 - T1087.002 - T1482 - T1207 - T1069 | TA0007 - TA0008 | N/A | N/A | Discovery | https://github.com/61106960/adPEAS | 1 | 0 | #Avsignature | N/A | 8 | 10 | 1095 | 132 | 2025-04-01T16:16:15Z | 2020-12-23T08:10:19Z | 34180 |
| 21 | *ATK/BadPotato-A | .{0,1000}ATK\/BadPotato\-A | signature_keyword | BadPotato | Windows Privilege Escalation Exploit BadPotato | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | Ghost Ransomware | Earth Lusca | Privilege Escalation | https://github.com/BeichenDream/BadPotato | 1 | 0 | #Avsignature | N/A | 10 | 9 | 836 | 136 | 2020-05-10T15:42:21Z | 2020-05-10T10:01:20Z | 34181 |
| 22 | *ATK/BlockETW-A* | .{0,1000}ATK\/BlockETW\-A.{0,1000} | signature_keyword | BlockEtw | .Net Assembly to block ETW telemetry in current process | T1055.001 - T1562.001 | TA0005 | N/A | N/A | Defense Evasion | https://github.com/Soledge/BlockEtw | 1 | 0 | #Avsignature | N/A | 10 | 1 | 78 | 19 | 2020-05-14T19:24:49Z | 2020-05-14T02:40:50Z | 34182 |
| 23 | *ATK/BloodH-B* | .{0,1000}ATK\/BloodH\-B.{0,1000} | signature_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | #Avsignature | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 34183 |
| 24 | *ATK/JPotato-* | .{0,1000}ATK\/JPotato\-.{0,1000} | signature_keyword | Bat-Potato | Automating Juicy Potato Local Privilege Escalation CMD exploit for penetration testers | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/0x4xel/Bat-Potato | 1 | 0 | #Avsignature | N/A | 10 | 1 | 42 | 11 | 2022-12-13T20:19:51Z | 2022-12-12T20:50:22Z | 34184 |
| 25 | *ATK/LOLSpoof-A* | .{0,1000}ATK\/LOLSpoof\-A.{0,1000} | signature_keyword | LOLSpoof | An interactive shell to spoof some LOLBins command line | T1036.005 | TA0005 | N/A | N/A | Defense Evasion | https://github.com/itaymigdal/LOLSpoof | 1 | 0 | #Avsignature | N/A | 8 | 2 | 184 | 24 | 2024-01-27T05:43:59Z | 2024-01-16T20:15:38Z | 34185 |
| 26 | *ATK/MultiDump-* | .{0,1000}ATK\/MultiDump\-.{0,1000} | signature_keyword | DumpLSASS | Lsass dumping tool - 50 ways of dumping lsass | T1003.001 - T1055.001 - T1620 | TA0006 - TA0005 | N/A | N/A | Credential Access | https://github.com/elementalsouls/DumpLSASS | 1 | 0 | #Avsignature | N/A | 10 | 1 | 33 | 5 | 2024-02-27T11:25:11Z | 2023-04-09T12:11:10Z | 34186 |
| 27 | *ATK/PowSploit-A* | .{0,1000}ATK\/PowSploit\-A.{0,1000} | signature_keyword | powerview | PowerView is a PowerShell tool to gain network situational awareness on Windows domains | T1046 - T1087.001 - T1016 | TA0007 - TA0008 - TA0009 | N/A | Dispossessor - MAZE - Conti - XingLocker - Rhysida - BlackByte - Black Basta - MUSTANG PANDA | Discovery | https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1 | 1 | 0 | #Avsignature | N/A | 10 | 10 | 12274 | 4660 | 2020-08-17T23:19:49Z | 2012-05-26T16:08:48Z | 34187 |
| 28 | *ATK/ReVBShel-A* | .{0,1000}ATK\/ReVBShel\-A.{0,1000} | signature_keyword | revbshell | ReVBShell - Reverse VBS Shell | T1059.005 - T1573.001 - T1105 | TA0011 - TA0010 | N/A | N/A | C2 | https://github.com/bitsadmin/revbshell | 1 | 0 | #Avsignature | N/A | 10 | 10 | 81 | 27 | 2019-10-08T12:00:05Z | 2017-02-19T18:58:52Z | 34188 |
| 29 | *ATK/Sandman-A* | .{0,1000}ATK\/Sandman\-A.{0,1000} | signature_keyword | Sandman | Sandman is a NTP based backdoor for red team engagements in hardened networks. | T1105 - T1027 - T1071.001 | TA0011 - TA0005 | N/A | N/A | Persistence | https://github.com/Idov31/Sandman | 1 | 0 | #Avsignature | N/A | 10 | 8 | 785 | 108 | 2024-03-31T17:40:15Z | 2022-08-21T11:04:45Z | 34189 |
| 30 | *ATK/Seatbelt-A* | .{0,1000}ATK\/Seatbelt\-A.{0,1000} | signature_keyword | seatbelt | Seatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many others | T1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518 | TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011 | N/A | Dispossessor | Persistence | https://github.com/GhostPack/Seatbelt | 1 | 0 | #Avsignature | N/A | 10 | 10 | 4047 | 722 | 2025-01-10T20:12:49Z | 2018-07-24T17:38:51Z | 34190 |
| 31 | *ATK/SharpDump-A* | .{0,1000}ATK\/SharpDump\-A.{0,1000} | signature_keyword | SharpDump | SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality. | T1003 - T1055 - T1070 | TA0006 - TA0005 - TA0008 | N/A | Avaddon | Credential Access | https://github.com/GhostPack/SharpDump | 1 | 0 | #Avsignature | N/A | 10 | 7 | 664 | 130 | 2019-02-07T02:52:20Z | 2018-07-24T17:42:19Z | 34191 |
| 32 | *ATK/SpoolFool-A* | .{0,1000}ATK\/SpoolFool\-A.{0,1000} | signature_keyword | SpoolFool | Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE) | T1068 - T1055 - T1059.003 | TA0004 - TA0005 - TA0003 | Dispossessor | Privilege Escalation | https://github.com/ly4k/SpoolFool | 1 | 0 | #Avsignature | N/A | 9 | 8 | 788 | 160 | 2022-02-09T16:54:09Z | 2022-02-08T17:25:44Z | 34192 | |
| 33 | *Backdoor.ASP* | .{0,1000}Backdoor\.ASP.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | #Avsignature | backdoor signatures | 10 | 10 | N/A | N/A | N/A | N/A | 35164 |
| 34 | *Backdoor.ASP.FUZZSHELL.A* | .{0,1000}Backdoor\.ASP\.FUZZSHELL\.A.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 35165 |
| 35 | *Backdoor.ASP.WEBSHELL.* | .{0,1000}Backdoor\.ASP\.WEBSHELL\..{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 35166 |
| 36 | *Backdoor.ASP.WebShell.ez* | .{0,1000}Backdoor\.ASP\.WebShell\.ez.{0,1000} | signature_keyword | antSword | cross-platform website management toolkit - abused by attackers - supports the use of web shells | T1505.003 - T1059 - T1100 - T1027 - T1219 - T1071 | TA0002 - TA0003 - TA0005 - TA0011 | antSword webshell | APT41 - APT15 | C2 | https://github.com/AntSwordProject/antSword | 1 | 0 | #Avsignature | N/A | 10 | 10 | 4010 | 616 | 2025-01-20T12:48:42Z | 2016-03-11T09:28:00Z | 35167 |
| 37 | *Backdoor.ASP.WEBSHELL.THFBIBC* | .{0,1000}Backdoor\.ASP\.WEBSHELL\.THFBIBC.{0,1000} | signature_keyword | antSword | cross-platform website management toolkit - abused by attackers - supports the use of web shells | T1505.003 - T1059 - T1100 - T1027 - T1219 - T1071 | TA0002 - TA0003 - TA0005 - TA0011 | antSword webshell | APT41 - APT15 | C2 | https://github.com/AntSwordProject/antSword | 1 | 0 | #Avsignature | N/A | 10 | 10 | 4010 | 616 | 2025-01-20T12:48:42Z | 2016-03-11T09:28:00Z | 35168 |
| 38 | *Backdoor.Cobalt* | .{0,1000}Backdoor\.Cobalt.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | #Avsignature | backdoor signatures | 10 | 10 | N/A | N/A | N/A | N/A | 35170 |
| 39 | *Backdoor.JSP* | .{0,1000}Backdoor\.JSP.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | #Avsignature | backdoor signatures | 10 | 10 | N/A | N/A | N/A | N/A | 35172 |
| 40 | *Backdoor.Linux* | .{0,1000}Backdoor\.Linux.{0,1000} | signature_keyword | Antivirus Signature | AV signature of noodlerat malware | T1059.004 - T1078 - T1105 - T1100 - T1547.006 | TA0003 - TA0005 - TA0010 - TA0011 | N/A | N/A | Malware | N/A | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 35173 |
| 41 | *Backdoor.Linux.Spyssh.J* | .{0,1000}Backdoor\.Linux\.Spyssh\.J.{0,1000} | signature_keyword | sshdoor | Openssh backdoor | T1059.003 - T1105 - T1071.001 | TA0011 - TA0003 | N/A | FANCY BEAR | Persistence | https://web-assets.esetstatic.com/wls/2018/12/ESET-The_Dark_Side_of_the_ForSSHe.pdf | 1 | 0 | #Avsignature | N/A | 10 | 9 | N/A | N/A | N/A | N/A | 35174 |
| 42 | *Backdoor.Linux.Sshdkit* | .{0,1000}Backdoor\.Linux\.Sshdkit.{0,1000} | signature_keyword | sshdoor | Openssh backdoor | T1059.003 - T1105 - T1071.001 | TA0011 - TA0003 | N/A | FANCY BEAR | Persistence | https://web-assets.esetstatic.com/wls/2018/12/ESET-The_Dark_Side_of_the_ForSSHe.pdf | 1 | 0 | #Avsignature | N/A | 10 | 9 | N/A | N/A | N/A | N/A | 35175 |
| 43 | *Backdoor.Merlin* | .{0,1000}Backdoor\.Merlin.{0,1000} | signature_keyword | merlin-agent-dll | Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT) | T1219 - T1105 - T1071 - T1090 - T1055 - T1047 | TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011 | N/A | N/A | C2 | https://github.com/Ne0nd0g/merlin-agent-dll | 1 | 0 | N/A | N/A | 10 | 10 | 51 | 15 | 2025-04-17T14:01:36Z | 2021-04-17T16:58:24Z | 35176 |
| 44 | *Backdoor.MSIL.Sandman* | .{0,1000}Backdoor\.MSIL\.Sandman.{0,1000} | signature_keyword | Sandman | Sandman is a NTP based backdoor for red team engagements in hardened networks. | T1105 - T1027 - T1071.001 | TA0011 - TA0005 | N/A | N/A | Persistence | https://github.com/Idov31/Sandman | 1 | 0 | #Avsignature | N/A | 10 | 8 | 785 | 108 | 2024-03-31T17:40:15Z | 2022-08-21T11:04:45Z | 35177 |
| 45 | *Backdoor.PHP* | .{0,1000}Backdoor\.PHP.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | #Avsignature | backdoor signatures | 10 | 10 | N/A | N/A | N/A | N/A | 35179 |
| 46 | *Backdoor.PHP.WebShell.* | .{0,1000}Backdoor\.PHP\.WebShell\..{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 35180 |
| 47 | *Backdoor.Win32.CARBANAK.A* | .{0,1000}Backdoor\.Win32\.CARBANAK\.A.{0,1000} | signature_keyword | Carbanak | remote backdoor used by a group of the same name (Carbanak). It is intended for espionage - data exfiltration and providing remote access to infected machines | T1021.002 - T1071.001 - T1105 - T1059 - T1003 - T1078 - T1041 | TA0006 - TA0008 - TA0010 - TA0011 | Carbanak | FIN7 - Carbanak | Malware | https://github.com/0x25bit/Updated-Carbanak-Source-with-Plugins | 1 | 0 | #Avsignature | N/A | 10 | 4 | 396 | 223 | 2019-05-01T23:31:35Z | 2019-04-22T21:01:08Z | 35183 |
| 48 | *Backdoor/Win.* | .{0,1000}Backdoor\/Win\..{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 35185 |
| 49 | *Backdoor:ASP/Chopper.ZC!dha* | .{0,1000}Backdoor\:ASP\/Chopper\.ZC!dha.{0,1000} | signature_keyword | Godzilla | Webshell Manager Tool that provide request proxy, server info, RCE shell, terminal execution, memory shell, port forwarding, and MSF bind/reverse shell capabilities. | T1100 - T1018 - T1059 - T1090 - T1021 - T1205 - T1105 - T1568 | TA0001 - TA0002 - TA0003 - TA0011 | N/A | N/A | C2 | https://github.com/BeichenDream/Godzilla | 1 | 0 | N/A | N/A | 10 | 10 | 4096 | 551 | 2024-07-17T07:56:35Z | 2020-08-17T17:27:56Z | 35186 |
| 50 | *Backdoor:ASP/Dirtelti.HA* | .{0,1000}Backdoor\:ASP\/Dirtelti\.HA.{0,1000} | signature_keyword | antSword | cross-platform website management toolkit - abused by attackers - supports the use of web shells | T1505.003 - T1059 - T1100 - T1027 - T1219 - T1071 | TA0002 - TA0003 - TA0005 - TA0011 | antSword webshell | APT41 - APT15 | C2 | https://github.com/AntSwordProject/antSword | 1 | 0 | #Avsignature | N/A | 10 | 10 | 4010 | 616 | 2025-01-20T12:48:42Z | 2016-03-11T09:28:00Z | 35187 |
| 51 | *Backdoor:JS/* | .{0,1000}Backdoor\:JS\/.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | #Avsignature | backdoor signatures | 10 | 10 | N/A | N/A | N/A | N/A | 35188 |
| 52 | *Backdoor:Linux* | .{0,1000}Backdoor\:Linux.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | #Avsignature | backdoor signatures | 10 | 10 | N/A | N/A | N/A | N/A | 35189 |
| 53 | *Backdoor:MacOS* | .{0,1000}Backdoor\:MacOS.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 35190 |
| 54 | *Backdoor:MSIL/AsyncRat* | .{0,1000}Backdoor\:MSIL\/AsyncRat.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | APT-C-36 - Earth Berberoka - Operation Comando - TA2541 - TA558 | Exploitation tool | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 35191 |
| 55 | *Backdoor:MSIL/Quasar* | .{0,1000}Backdoor\:MSIL\/Quasar.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools for Quasar.exe | N/A | N/A | N/A | N/A | C2 | N/A | 1 | 0 | #Avsignature | backdoor signatures | 10 | 10 | N/A | N/A | N/A | N/A | 35192 |
| 56 | *Backdoor:MSIL/SectopRAT* | .{0,1000}Backdoor\:MSIL\/SectopRAT.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 35193 |
| 57 | *Backdoor:PHP/* | .{0,1000}Backdoor\:PHP\/.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | #Avsignature | backdoor signatures | 10 | 10 | N/A | N/A | N/A | N/A | 35194 |
| 58 | *Backdoor:Python* | .{0,1000}Backdoor\:Python.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | #Avsignature | backdoor signatures | 10 | 10 | N/A | N/A | N/A | N/A | 35195 |
| 59 | *Backdoor:Python/* | .{0,1000}Backdoor\:Python\/.{0,1000} | signature_keyword | Antivirus Signature | Antivirus signature - a tool used within a command-line interface on 64bit Windows computers to extract the NTLM (LanMan) hashes from LSASS.exe in memory. This tool may be used in conjunction with malware or other penetration testing tools to obtain credentials for use in Windows authentication systems | N/A | N/A | N/A | N/A | Credential Access | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 35196 |
| 60 | *Backdoor:Script/HustleCon.A* | .{0,1000}Backdoor\:Script\/HustleCon\.A.{0,1000} | signature_keyword | rdp | rdp file received in emails - abused by attackers | T1204 - T1566 - T1078 - T1105 | TA0001 - TA0002 - TA0010 - TA0011 | N/A | Midnight Blizzard - APT29 - UNC2452 - Cozy Bear | Phishing | https://www.microsoft.com/en-us/security/blog/2024/10/29/midnight-blizzard-conducts-large-scale-spear-phishing-campaign-using-rdp-files | 1 | 0 | #Avsignature | N/A | 9 | 8 | N/A | N/A | N/A | N/A | 35197 |
| 61 | *Backdoor:VBS/* | .{0,1000}Backdoor\:VBS\/.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | #Avsignature | backdoor signatures | 10 | 10 | N/A | N/A | N/A | N/A | 35198 |
| 62 | *Backdoor:Win32* | .{0,1000}Backdoor\:Win32.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | #Avsignature | backdoor signatures | 10 | 10 | N/A | N/A | N/A | N/A | 35199 |
| 63 | *Backdoor:Win64* | .{0,1000}Backdoor\:Win64.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | #Avsignature | backdoor signatures | 10 | 10 | N/A | N/A | N/A | N/A | 35200 |
| 64 | *Backdoor:Win64/CobaltStrike* | .{0,1000}Backdoor\:Win64\/CobaltStrike.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 35201 |
| 65 | *Backdoor:Win64/PortStarter* | .{0,1000}Backdoor\:Win64\/PortStarter.{0,1000} | signature_keyword | Invoke-SocksProxy | Socks proxy - and reverse socks server using powershell. | T1090 - T1021.001 - T1021.002 | TA0002 | PortStarter | Vice Society - Conti | C2 | https://github.com/p3nt4/Invoke-SocksProxy | 1 | 0 | #Avsignature | N/A | 10 | 10 | 788 | 169 | 2021-03-21T21:00:40Z | 2017-11-09T06:20:40Z | 35202 |
| 66 | *Backdoor:Win64/PortStarter* | .{0,1000}Backdoor\:Win64\/PortStarter.{0,1000} | signature_keyword | Invoke-SocksProxy | also known as PortStarter is a socks proxy and reverse socks server using powershell | T1090 - T1059.001 - T1102.003 | TA0011 - TA0010 - TA0005 - TA0003 | PortStarter | Vice Society - Conti | C2 | https://github.com/roadwy/DefenderYara/blob/9bbdb7f9fd3513ce30aa69cd1d88830e3cf596ca/Backdoor/Win64/PortStarter/Backdoor_Win64_PortStarter_B.yar#L8 | 1 | 0 | #Avsignature | N/A | 10 | 10 | 395 | 63 | 2025-02-24T12:25:27Z | 2024-02-05T13:57:05Z | 35203 |
| 67 | *BadPotato.Win32* | .{0,1000}BadPotato\.Win32.{0,1000} | signature_keyword | BadPotato | Windows Privilege Escalation Exploit BadPotato | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | Ghost Ransomware | Earth Lusca | Privilege Escalation | https://github.com/BeichenDream/BadPotato | 1 | 0 | #Avsignature | N/A | 10 | 9 | 836 | 136 | 2020-05-10T15:42:21Z | 2020-05-10T10:01:20Z | 35251 |
| 68 | *Behavior:Linux/SuspRcloneSpawn.A* | .{0,1000}Behavior\:Linux\/SuspRcloneSpawn\.A.{0,1000} | signature_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 0 | #Avsignature | interactive mode | 10 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 35785 |
| 69 | *Behavior:Linux/SuspRcloneSpawn.B* | .{0,1000}Behavior\:Linux\/SuspRcloneSpawn\.B.{0,1000} | signature_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 0 | #Avsignature | interactive mode | 10 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 35786 |
| 70 | *Behavior:Win32/BitsInject.A!attk* | .{0,1000}Behavior\:Win32\/BitsInject\.A!attk.{0,1000} | signature_keyword | BITSInject | A one-click tool to inject jobs into the BITS queue (Background Intelligent Transfer Service) allowing arbitrary program execution as the NT AUTHORITY/SYSTEM account | T1197 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/SafeBreach-Labs/BITSInject | 1 | 0 | #Avsignature | N/A | 8 | 1 | 99 | 18 | 2019-08-24T22:02:12Z | 2017-07-03T12:39:38Z | 35787 |
| 71 | *Behavior:Win32/CobaltStrike* | .{0,1000}Behavior\:Win32\/CobaltStrike.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 35788 |
| 72 | *Behavior:Win32/OFNRclone* | .{0,1000}Behavior\:Win32\/OFNRclone.{0,1000} | signature_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 0 | #Avsignature | interactive mode | 10 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 35789 |
| 73 | *Behavior:Win32/PShellRclone.SA* | .{0,1000}Behavior\:Win32\/PShellRclone\.SA.{0,1000} | signature_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 0 | #Avsignature | interactive mode | 10 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 35790 |
| 74 | *Behavior:Win32/RcloneConf.A* | .{0,1000}Behavior\:Win32\/RcloneConf\.A.{0,1000} | signature_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 0 | #Avsignature | interactive mode | 10 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 35791 |
| 75 | *Behavior:Win32/RcloneExfil.S* | .{0,1000}Behavior\:Win32\/RcloneExfil\.S.{0,1000} | signature_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 0 | #Avsignature | interactive mode | 10 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 35792 |
| 76 | *Behavior:Win32/RcloneExfil.SA* | .{0,1000}Behavior\:Win32\/RcloneExfil\.SA.{0,1000} | signature_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 0 | #Avsignature | interactive mode | 10 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 35793 |
| 77 | *Behavior:Win32/RcloneMega.SA!Ofn* | .{0,1000}Behavior\:Win32\/RcloneMega\.SA!Ofn.{0,1000} | signature_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 0 | #Avsignature | interactive mode | 10 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 35794 |
| 78 | *Behavior:Win32/RcloneMega.SA* | .{0,1000}Behavior\:Win32\/RcloneMega\.SA.{0,1000} | signature_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 0 | #Avsignature | interactive mode | 10 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 35795 |
| 79 | *Behavior:Win32/RcloneSusExec.A* | .{0,1000}Behavior\:Win32\/RcloneSusExec\.A.{0,1000} | signature_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 0 | #Avsignature | interactive mode | 10 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 35796 |
| 80 | *Behavior:Win32/RcloneSusTLD.A* | .{0,1000}Behavior\:Win32\/RcloneSusTLD\.A.{0,1000} | signature_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 0 | #Avsignature | interactive mode | 10 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 35797 |
| 81 | *Behavior:Win32/RcloneUAgent.A* | .{0,1000}Behavior\:Win32\/RcloneUAgent\.A.{0,1000} | signature_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 0 | #Avsignature | interactive mode | 10 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 35798 |
| 82 | *Behavior:Win32/RenamedToolRclone.SA* | .{0,1000}Behavior\:Win32\/RenamedToolRclone\.SA.{0,1000} | signature_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 0 | #Avsignature | interactive mode | 10 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 35799 |
| 83 | *Behavior:Win32/SuspRclone.A* | .{0,1000}Behavior\:Win32\/SuspRclone\.A.{0,1000} | signature_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 0 | #Avsignature | interactive mode | 10 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 35800 |
| 84 | *Behavior:Win32/SuspRclone.B* | .{0,1000}Behavior\:Win32\/SuspRclone\.B.{0,1000} | signature_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 0 | #Avsignature | interactive mode | 10 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 35801 |
| 85 | *Behavior:Win32/SuspRclone.C* | .{0,1000}Behavior\:Win32\/SuspRclone\.C.{0,1000} | signature_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 0 | #Avsignature | interactive mode | 10 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 35802 |
| 86 | *Behavior:Win32/SuspRclone.D* | .{0,1000}Behavior\:Win32\/SuspRclone\.D.{0,1000} | signature_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 0 | #Avsignature | interactive mode | 10 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 35803 |
| 87 | *BKDR_JSPSHELL.* | .{0,1000}BKDR_JSPSHELL\..{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 36000 |
| 88 | *BKDR_TERMITE.A* | .{0,1000}BKDR_TERMITE\.A.{0,1000} | signature_keyword | Termite | Termite rootit abused by threat actors | T1014 - T1069 - T1055 | TA0005 - TA0003 - TA0004 | Operation TunnelSnake | Whitefly | Persistence | https://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a4 | 1 | 0 | #Avsignature | N/A | 10 | 10 | 156 | 177 | 2021-01-26T23:16:49Z | 2019-01-03T05:01:20Z | 36001 |
| 89 | *Clearlogs* | .{0,1000}Clearlogs.{0,1000} | signature_keyword | Antivirus Signature | Antivirus signature_keyword for hacktool clearing logs | N/A | N/A | N/A | N/A | Defense Evasion | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 38310 |
| 90 | *cmd.exe /c arp -a > C:\windows\*.out 2>&1* | .{0,1000}cmd\.exe\s\/c\sarp\s\-a\s\>\sC\:\\windows\\.{0,1000}\.out\s2\>\&1.{0,1000} | signature_keyword | arp | observed used by lslsass sample (dump active logon session password hashes from the lsass process (old tool for vista and older)) | T1003.001 | TA0006 | N/A | APT1 | Credential Access | https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 38417 |
| 91 | *CobaltStrike.LJ!MTB* | .{0,1000}CobaltStrike\.LJ!MTB.{0,1000} | signature_keyword | Antivirus Signature | windows defender antivirus signature for UAC bypass | N/A | N/A | N/A | N/A | C2 | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 38553 |
| 92 | *ddbf3299675ffdd7e3475f8a4848f3ab6cdff8819348c75b9ac4d8fb76569a2c* | .{0,1000}ddbf3299675ffdd7e3475f8a4848f3ab6cdff8819348c75b9ac4d8fb76569a2c.{0,1000} | signature_keyword | SessionGopher | uses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally. | T1047 - T1003.008 - T1552.004 - T1555.003 | TA0006 | N/A | PYSA - DarkSide - Sphinx | Credential Access | https://github.com/Arvanaghi/SessionGopher | 1 | 0 | #filehash | N/A | 10 | 10 | 1255 | 173 | 2022-11-22T21:33:23Z | 2017-03-08T02:49:32Z | 40471 |
| 93 | *ELF:Earthworm-B* | .{0,1000}ELF\:Earthworm\-B.{0,1000} | signature_keyword | EarthWorm | SOCKS v5 proxy service used for data forwarding in complex network environments | T1090.002 - T1573.001 - T1095 | TA0010 - TA0008 - TA0011 | N/A | APT27 - APT15 - Calypso - Earth Lusca - Worok | C2 | https://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a4 | 1 | 0 | #Avsignature | N/A | 10 | 10 | 156 | 177 | 2021-01-26T23:16:49Z | 2019-01-03T05:01:20Z | 43063 |
| 94 | *Exp.CVE-2022-21999* | .{0,1000}Exp\.CVE\-2022\-21999.{0,1000} | signature_keyword | SpoolFool | Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE) | T1068 - T1055 - T1059.003 | TA0004 - TA0005 - TA0003 | Dispossessor | Privilege Escalation | https://github.com/ly4k/SpoolFool | 1 | 0 | #Avsignature | N/A | 9 | 8 | 788 | 160 | 2022-02-09T16:54:09Z | 2022-02-08T17:25:44Z | 43538 | |
| 95 | *Exploit.CVE202222718.MSIL* | .{0,1000}Exploit\.CVE202222718\.MSIL.{0,1000} | signature_keyword | SpoolFool | Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE) | T1068 - T1055 - T1059.003 | TA0004 - TA0005 - TA0003 | Dispossessor | Privilege Escalation | https://github.com/ly4k/SpoolFool | 1 | 0 | #Avsignature | N/A | 9 | 8 | 788 | 160 | 2022-02-09T16:54:09Z | 2022-02-08T17:25:44Z | 43550 | |
| 96 | *Exploit:Python/* | .{0,1000}Exploit\:Python\/.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 43567 |
| 97 | *Exploit:Win32/CVE-* | .{0,1000}Exploit\:Win32\/CVE\-.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword observed with meterpreter exploits | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 43568 |
| 98 | *Exploit:Win64/CVE-* | .{0,1000}Exploit\:Win64\/CVE\-.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword observed with meterpreter exploits | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 43569 |
| 99 | *Exploitable Hangzhou RentDrv Driver (PUA)* | .{0,1000}Exploitable\sHangzhou\sRentDrv\sDriver\s\(PUA\).{0,1000} | signature_keyword | BadRentdrv2 | A vulnerable driver (BYOVD) capable of terminating several EDRs and antivirus software | T1562 - T1068 - T1210 - T1489 - T1496 | TA0005 - TA0004 - TA0040 | N/A | Agrius | Defense Evasion | https://github.com/keowu/BadRentdrv2 | 1 | 0 | #Avsignature | N/A | 10 | 1 | 95 | 20 | 2024-12-26T13:43:18Z | 2023-10-01T18:24:38Z | 43577 |
| 100 | *Gen:Variant.Mimikatz* | .{0,1000}Gen\:Variant\.Mimikatz.{0,1000} | signature_keyword | mimikatz | Mimikatz AV signatures | T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003 | TA0004 - TA0006 - TA0003 - TA0008 - TA0009 | N/A | Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx | Exploitation tool | https://github.com/gentilkiwi/mimikatz | 1 | 0 | #Avsignature | N/A | 10 | 10 | 20094 | 3854 | 2024-07-05T17:42:58Z | 2014-04-06T18:30:02Z | 45545 |
| 101 | *Generic.Exploit.CVE-2022-22718.A.2798221A* | .{0,1000}Generic\.Exploit\.CVE\-2022\-22718\.A\.2798221A.{0,1000} | signature_keyword | SpoolFool | Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE) | T1068 - T1055 - T1059.003 | TA0004 - TA0005 - TA0003 | Dispossessor | Privilege Escalation | https://github.com/ly4k/SpoolFool | 1 | 0 | #Avsignature | N/A | 9 | 8 | 788 | 160 | 2022-02-09T16:54:09Z | 2022-02-08T17:25:44Z | 45598 | |
| 102 | *Generic.HookChain.A.88E059A3* | .{0,1000}Generic\.HookChain\.A\.88E059A3.{0,1000} | signature_keyword | hookchain | Bypassing EDR Solutions | T1055.011 - T1564.001 - T1070.004 - T1562.001 - T1222 | TA0005 | N/A | N/A | Defense Evasion | https://github.com/helviojunior/hookchain | 1 | 0 | #Avsignature | N/A | 9 | 6 | 513 | 85 | 2025-01-05T22:00:17Z | 2024-03-22T13:18:02Z | 45599 |
| 103 | *Generic.Linux.GonnaCryRansom* | .{0,1000}Generic\.Linux\.GonnaCryRansom.{0,1000} | signature_keyword | GonnaCry | a linux ransomware | T1486 - T1059 - T1020 - T1083 - T1070 | TA0040 - TA0005 - TA0009 - TA0010 | N/A | N/A | Ransomware | https://github.com/tarcisio-marinho/GonnaCry | 1 | 0 | #linux #Avsignature | N/A | 10 | 8 | 717 | 402 | 2025-01-24T13:39:57Z | 2017-05-12T23:46:28Z | 45600 |
| 104 | *hacktool* | .{0,1000}hacktool.{0,1000} | signature_keyword | Antivirus Signature | hacktool keyword. a repository could be named as such. o AV signature | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | #Avsignature | hacktool signatures | 10 | 10 | N/A | N/A | N/A | N/A | 46859 |
| 105 | *HackTool.ASP.*.* | .{0,1000}HackTool\.ASP\..{0,1000}\..{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 46860 |
| 106 | *HackTool.BadPotato* | .{0,1000}HackTool\.BadPotato.{0,1000} | signature_keyword | BadPotato | Windows Privilege Escalation Exploit BadPotato | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | Ghost Ransomware | Earth Lusca | Privilege Escalation | https://github.com/BeichenDream/BadPotato | 1 | 0 | #Avsignature | N/A | 10 | 9 | 836 | 136 | 2020-05-10T15:42:21Z | 2020-05-10T10:01:20Z | 46861 |
| 107 | *HackTool.DecryptRDCMan* | .{0,1000}HackTool\.DecryptRDCMan.{0,1000} | signature_keyword | Decrypt-RDCMan | decrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPI | T1003 - T1552 - T1081 - T1027 | TA0006 - TA0008 - TA0005 | N/A | N/A | Credential Access | https://github.com/vmamuaya/Powershell/blob/master/Decrypt-RDCMan.ps1 | 1 | 0 | #Avsignature | N/A | 9 | 1 | 1 | 1 | 2016-12-01T14:06:24Z | 2017-11-22T23:18:39Z | 46862 |
| 108 | *HackTool.EarthWorm* | .{0,1000}HackTool\.EarthWorm.{0,1000} | signature_keyword | EarthWorm | SOCKS v5 proxy service used for data forwarding in complex network environments | T1090.002 - T1573.001 - T1095 | TA0010 - TA0008 - TA0011 | N/A | APT27 - APT15 - Calypso - Earth Lusca - Worok | C2 | https://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a4 | 1 | 0 | #Avsignature | N/A | 10 | 10 | 156 | 177 | 2021-01-26T23:16:49Z | 2019-01-03T05:01:20Z | 46863 |
| 109 | *Hacktool.Earthworm* | .{0,1000}Hacktool\.Earthworm.{0,1000} | signature_keyword | EarthWorm | SOCKS v5 proxy service used for data forwarding in complex network environments | T1090.002 - T1573.001 - T1095 | TA0010 - TA0008 - TA0011 | N/A | APT27 - APT15 - Calypso - Earth Lusca - Worok | C2 | https://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a4 | 1 | 0 | #Avsignature | N/A | 10 | 10 | 156 | 177 | 2021-01-26T23:16:49Z | 2019-01-03T05:01:20Z | 46864 |
| 110 | *HackTool.Equation* | .{0,1000}HackTool\.Equation.{0,1000} | signature_keyword | Smbtouch-Scanner | Smbtouch detect whether the target is vulnerable of one of these vulnerabilities: ETERNALBLUE - ETERNALCHAMPION - ETERNALROMANCE - ETERNALSYNERGY | T1210 - T1046 - T1133 | TA0007 - TA0043 - TA0008 | N/A | APT15 - Turla | Lateral Movement | https://github.com/3gstudent/Smbtouch-Scanner | 1 | 0 | #Avsignature | N/A | 10 | 2 | 140 | 66 | 2021-04-17T01:42:06Z | 2017-04-21T01:38:55Z | 46865 |
| 111 | *Hacktool.Gsecdump* | .{0,1000}Hacktool\.Gsecdump.{0,1000} | signature_keyword | gsecdump | credential dumper used to obtain password hashes and LSA secrets from Windows operating systems | T1003.001 - T1003.002 - T1555.003 - T1555.001 | TA0006 - TA0008 | N/A | APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick | Credential Access | https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 46866 |
| 112 | *Hacktool.Hakc2* | .{0,1000}Hacktool\.Hakc2.{0,1000} | signature_keyword | hak5 cloudc2 | Cloud C2 makes it easy for pentesters and security teams to deploy and manage Hak5 gear from the cloud | T1021 - T1102 - T1213 | TA0002 - TA0003 - TA0006 - TA0010 - TA0011 | N/A | N/A | C2 | https://shop.hak5.org/products/c2? | 1 | 0 | #Avsignature | N/A | 10 | 9 | N/A | N/A | N/A | N/A | 46867 |
| 113 | *HackTool.HTML.*.** | .{0,1000}HackTool\.HTML\..{0,1000}\..{0,1000}.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 46868 |
| 114 | *Hacktool.HTran.* | .{0,1000}Hacktool\.HTran\..{0,1000} | signature_keyword | htran | proxies connections through intermediate hops and aids users in disguising their true geographical location. It can be used by adversaries to hide their location when interacting with the victim networks | T1055 - T1090 - T1014 | TA0003 - TA0005 - TA0011 | N/A | GALLIUM - APT10 - APT12 - Deep Panda - MenuPass | C2 | https://github.com/HiwinCN/Htran | 1 | 0 | #Avsignature | N/A | 9 | 10 | 256 | 88 | 2021-04-25T09:57:46Z | 2015-12-03T04:54:53Z | 46869 |
| 115 | *HackTool.Java.*.* | .{0,1000}HackTool\.Java\..{0,1000}\..{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 46870 |
| 116 | *HackTool.JuicyPotato* | .{0,1000}HackTool\.JuicyPotato.{0,1000} | signature_keyword | Bat-Potato | Automating Juicy Potato Local Privilege Escalation CMD exploit for penetration testers | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/0x4xel/Bat-Potato | 1 | 0 | #Avsignature | N/A | 10 | 1 | 42 | 11 | 2022-12-13T20:19:51Z | 2022-12-12T20:50:22Z | 46871 |
| 117 | *Hacktool.Lazagne* | .{0,1000}Hacktool\.Lazagne.{0,1000} | signature_keyword | LaZagne | The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software. | T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001 | TA0006 - TA0009 | N/A | Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT | Credential Access | https://github.com/AlessandroZ/LaZagne | 1 | 1 | #Avsignature | N/A | 10 | 10 | 9941 | 2062 | 2025-04-10T14:24:35Z | 2015-02-16T14:10:02Z | 46872 |
| 118 | *Hacktool.Linux* | .{0,1000}Hacktool\.Linux.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 46873 |
| 119 | *HackTool.Linux.EarthWorm* | .{0,1000}HackTool\.Linux\.EarthWorm.{0,1000} | signature_keyword | EarthWorm | SOCKS v5 proxy service used for data forwarding in complex network environments | T1090.002 - T1573.001 - T1095 | TA0010 - TA0008 - TA0011 | N/A | APT27 - APT15 - Calypso - Earth Lusca - Worok | C2 | https://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a4 | 1 | 0 | #Avsignature | N/A | 10 | 10 | 156 | 177 | 2021-01-26T23:16:49Z | 2019-01-03T05:01:20Z | 46874 |
| 120 | *HackTool.LsassDumper* | .{0,1000}HackTool\.LsassDumper.{0,1000} | signature_keyword | DumpLSASS | Lsass dumping tool - 50 ways of dumping lsass | T1003.001 - T1055.001 - T1620 | TA0006 - TA0005 | N/A | N/A | Credential Access | https://github.com/elementalsouls/DumpLSASS | 1 | 0 | #Avsignature | N/A | 10 | 1 | 33 | 5 | 2024-02-27T11:25:11Z | 2023-04-09T12:11:10Z | 46875 |
| 121 | *Hacktool.MEGAclient* | .{0,1000}Hacktool\.MEGAclient.{0,1000} | signature_keyword | MEGAcmd | Command Line Interactive and Scriptable Application to access MEGA (hosting service abused by attackers) | T1071 - T1041 - T1105 | TA0010 - TA0009 | N/A | Akira - Phobos - BlackCat - Karakurt - Scattered Spider* - LockBit - BianLian - Hive - Trigona - Quantum - INC Ransom - EvilCorp* - Avaddon - EMBER BEAR | Data Exfiltration | https://github.com/meganz/MEGAcmd | 1 | 0 | #Avsignature | N/A | 10 | 10 | 2022 | 410 | 2025-04-09T07:52:26Z | 2017-08-28T16:58:54Z | 46876 |
| 122 | *HackTool.Mimikatz* | .{0,1000}HackTool\.Mimikatz.{0,1000} | signature_keyword | mimikatz | Mimikatz AV signatures | T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003 | TA0004 - TA0006 - TA0003 - TA0008 - TA0009 | N/A | Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx | Exploitation tool | https://github.com/gentilkiwi/mimikatz | 1 | 0 | #Avsignature | N/A | 10 | 10 | 20094 | 3854 | 2024-07-05T17:42:58Z | 2014-04-06T18:30:02Z | 46877 |
| 123 | *HackTool.MSIL.Gropire.REDT* | .{0,1000}HackTool\.MSIL\.Gropire\.REDT.{0,1000} | signature_keyword | Group3r | Find vulnerabilities in AD Group Policy | T1484.002 - T1069.002 - T1087.002 | TA0007 - TA0040 | N/A | KNOTWEED | Discovery | https://github.com/Group3r/Group3r | 1 | 0 | #Avsignature | AD Enumeration | 7 | 8 | 781 | 68 | 2025-04-08T05:03:34Z | 2021-07-05T05:05:42Z | 46878 |
| 124 | *HackTool.MSIL.Seatbelt* | .{0,1000}HackTool\.MSIL\.Seatbelt.{0,1000} | signature_keyword | seatbelt | Seatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many others | T1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518 | TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011 | N/A | Dispossessor | Persistence | https://github.com/GhostPack/Seatbelt | 1 | 0 | #Avsignature | N/A | 10 | 10 | 4047 | 722 | 2025-01-10T20:12:49Z | 2018-07-24T17:38:51Z | 46880 |
| 125 | *HackTool.MSIL.SharpDump32.SM* | .{0,1000}HackTool\.MSIL\.SharpDump32\.SM.{0,1000} | signature_keyword | SharpDump | SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality. | T1003 - T1055 - T1070 | TA0006 - TA0005 - TA0008 | N/A | Avaddon | Credential Access | https://github.com/GhostPack/SharpDump | 1 | 0 | #Avsignature | N/A | 10 | 7 | 664 | 130 | 2019-02-07T02:52:20Z | 2018-07-24T17:42:19Z | 46881 |
| 126 | *HackTool.MSIL.SharpHound* | .{0,1000}HackTool\.MSIL\.SharpHound.{0,1000} | signature_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | #Avsignature | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 46882 |
| 127 | *HackTool.MSIL.SharpShares* | .{0,1000}HackTool\.MSIL\.SharpShares.{0,1000} | signature_keyword | SharpShares | Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain | T1046 - T1135 | TA0007 - TA0001 | N/A | BlackSuit - Royal - BianLian - Fog | Discovery | https://github.com/mitchmoser/SharpShares | 1 | 0 | #Avsignature | N/A | 10 | 4 | 351 | 49 | 2021-09-21T08:14:27Z | 2020-09-25T22:35:57Z | 46883 |
| 128 | *Hacktool.Msil.Telemetry* | .{0,1000}Hacktool\.Msil\.Telemetry.{0,1000} | signature_keyword | Telemetry | Abusing Windows Telemetry for persistence through registry modifications and scheduled tasks to execute arbitrary commands with system-level privileges. | T1053 - T1547 - T1059 | TA0003 - TA0005 - TA0004 | N/A | N/A | Privilege Escalation | https://github.com/Imanfeng/Telemetry | 1 | 0 | #Avsignature | N/A | 9 | 2 | 140 | 13 | 2020-07-02T09:41:27Z | 2020-06-24T16:30:44Z | 46884 |
| 129 | *HackTool.PasswordStealer* | .{0,1000}HackTool\.PasswordStealer.{0,1000} | signature_keyword | PwDump7 | pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format. | T1003.001 - T1555.003 - T1077 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://www.openwall.com/passwords/windows-pwdump | 1 | 0 | #Avsignature | N/A | 10 | 8 | N/A | N/A | N/A | N/A | 46885 |
| 130 | *HackTool.PHP.*.* | .{0,1000}HackTool\.PHP\..{0,1000}\..{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 46886 |
| 131 | *HackTool.PowerShell.PowerSploit* | .{0,1000}HackTool\.PowerShell\.PowerSploit.{0,1000} | signature_keyword | powerview | PowerView is a PowerShell tool to gain network situational awareness on Windows domains | T1046 - T1087.001 - T1016 | TA0007 - TA0008 - TA0009 | N/A | Dispossessor - MAZE - Conti - XingLocker - Rhysida - BlackByte - Black Basta - MUSTANG PANDA | Discovery | https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1 | 1 | 0 | #Avsignature | N/A | 10 | 10 | 12274 | 4660 | 2020-08-17T23:19:49Z | 2012-05-26T16:08:48Z | 46887 |
| 132 | *HackTool.PowerView* | .{0,1000}HackTool\.PowerView.{0,1000} | signature_keyword | powerview | PowerView is a PowerShell tool to gain network situational awareness on Windows domains | T1046 - T1087.001 - T1016 | TA0007 - TA0008 - TA0009 | N/A | Dispossessor - MAZE - Conti - XingLocker - Rhysida - BlackByte - Black Basta - MUSTANG PANDA | Discovery | https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1 | 1 | 0 | #Avsignature | N/A | 10 | 10 | 12274 | 4660 | 2020-08-17T23:19:49Z | 2012-05-26T16:08:48Z | 46888 |
| 133 | *HackTool.PS1.PowerSploit* | .{0,1000}HackTool\.PS1\.PowerSploit.{0,1000} | signature_keyword | LAPSToolkit | Functions written in PowerShell that leverage PowerView to audit and attack Active Directory environments that have deployed Microsofts Local Administrator Password Solution (LAPS). It includes finding groups specifically delegated by sysadmins. finding users with All Extended Rights that can view passwords. and viewing all computers with LAPS enabled | T1087.001 - T1069 - T1069.003 - T1069.007 - T1069.002 - T1069.001 | TA0007 - TA0008 - TA0009 | N/A | Scattered Spider* | Discovery | https://github.com/leoloobeek/LAPSToolkit | 1 | 0 | #Avsignature | N/A | 10 | 9 | 859 | 119 | 2018-01-31T14:45:35Z | 2016-04-27T00:06:20Z | 46889 |
| 134 | *HackTool.PS1.PowerSploit* | .{0,1000}HackTool\.PS1\.PowerSploit.{0,1000} | signature_keyword | powerview | PowerView is a PowerShell tool to gain network situational awareness on Windows domains | T1046 - T1087.001 - T1016 | TA0007 - TA0008 - TA0009 | N/A | Dispossessor - MAZE - Conti - XingLocker - Rhysida - BlackByte - Black Basta - MUSTANG PANDA | Discovery | https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1 | 1 | 0 | #Avsignature | N/A | 10 | 10 | 12274 | 4660 | 2020-08-17T23:19:49Z | 2012-05-26T16:08:48Z | 46890 |
| 135 | *HackTool.PS1.SessionGopher* | .{0,1000}HackTool\.PS1\.SessionGopher.{0,1000} | signature_keyword | SessionGopher | uses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally. | T1047 - T1003.008 - T1552.004 - T1555.003 | TA0006 | N/A | PYSA - DarkSide - Sphinx | Credential Access | https://github.com/Arvanaghi/SessionGopher | 1 | 0 | #Avsignature | N/A | 10 | 10 | 1255 | 173 | 2022-11-22T21:33:23Z | 2017-03-08T02:49:32Z | 46891 |
| 136 | *Hacktool.PTHToolkit* | .{0,1000}Hacktool\.PTHToolkit.{0,1000} | signature_keyword | lslsass | dump active logon session password hashes from the lsass process (old tool for vista and older) | T1003.001 | TA0006 | N/A | APT1 | Credential Access | https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 46892 |
| 137 | *HackTool.RdpThief* | .{0,1000}HackTool\.RdpThief.{0,1000} | signature_keyword | RdpThief | Extracting Clear Text Passwords from mstsc.exe using API Hooking. | T1056.004 - T1110 - T1563.002 | TA0006 - TA0043 | N/A | N/A | Credential Access | https://github.com/0x09AL/RdpThief | 1 | 0 | #Avsignature | N/A | 10 | 10 | 1311 | 361 | 2024-07-20T06:58:02Z | 2019-11-03T17:54:38Z | 46893 |
| 138 | *Hacktool.Seatbelt* | .{0,1000}Hacktool\.Seatbelt.{0,1000} | signature_keyword | seatbelt | Seatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many others | T1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518 | TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011 | N/A | Dispossessor | Persistence | https://github.com/GhostPack/Seatbelt | 1 | 0 | #Avsignature | N/A | 10 | 10 | 4047 | 722 | 2025-01-10T20:12:49Z | 2018-07-24T17:38:51Z | 46894 |
| 139 | *Hacktool.SharpDump* | .{0,1000}Hacktool\.SharpDump.{0,1000} | signature_keyword | SharpDump | SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality. | T1003 - T1055 - T1070 | TA0006 - TA0005 - TA0008 | N/A | Avaddon | Credential Access | https://github.com/GhostPack/SharpDump | 1 | 0 | #Avsignature | N/A | 10 | 7 | 664 | 130 | 2019-02-07T02:52:20Z | 2018-07-24T17:42:19Z | 46895 |
| 140 | *Hacktool.SharpHound* | .{0,1000}Hacktool\.SharpHound.{0,1000} | signature_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | #Avsignature | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 46896 |
| 141 | *Hacktool.Sharpshare* | .{0,1000}Hacktool\.Sharpshare.{0,1000} | signature_keyword | SharpShares | Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain | T1046 - T1135 | TA0007 - TA0001 | N/A | BlackSuit - Royal - BianLian - Fog | Discovery | https://github.com/mitchmoser/SharpShares | 1 | 0 | #Avsignature | N/A | 10 | 4 | 351 | 49 | 2021-09-21T08:14:27Z | 2020-09-25T22:35:57Z | 46897 |
| 142 | *Hacktool.SoftPerfectNetscan* | .{0,1000}Hacktool\.SoftPerfectNetscan.{0,1000} | signature_keyword | softperfect networkscanner | SoftPerfect Network Scanner can ping computers scan ports discover shared folders and retrieve practically any information about network devices via WMI SNMP HTTP SSH and PowerShell | T1046 - T1065 - T1135 | TA0007 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - LockBit - BianLian - Conti - BlackCat - Dagon Locker - Nokoyawa - Trigona - Hive - BlackByte - RansomHub - Cactus - Fog - Medusa - Avaddon - Cobalt Group - FIN7 - Anunak | Discovery | https://www.softperfect.com/products/networkscanner/ | 1 | 0 | #Avsignature | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 46898 |
| 143 | *HackTool.Stowaway* | .{0,1000}HackTool\.Stowaway.{0,1000} | signature_keyword | stowaway | Stowaway -- Multi-hop Proxy Tool for pentesters | T1021 - T1090 - T1071 - T1573 | TA0005 - TA0008 - TA0011 | N/A | N/A | C2 | https://github.com/ph4ntonn/Stowaway | 1 | 0 | N/A | N/A | 10 | 10 | 2989 | 422 | 2025-04-05T14:48:38Z | 2019-11-15T03:25:50Z | 46899 |
| 144 | *HackTool.VBS.WMIHACKER* | .{0,1000}HackTool\.VBS\.WMIHACKER.{0,1000} | signature_keyword | WMIHACKER | Bypass anti-virus software lateral movement command execution test tool - No need 445 Port | T1047 - T1569.002 - T1218 - T1036.005 | TA0008 - TA0002 - TA0005 | N/A | N/A | Lateral Movement | https://github.com/rootclay/WMIHACKER | 1 | 0 | #Avsignature | N/A | 9 | 10 | 1423 | 236 | 2025-01-20T15:37:28Z | 2020-07-02T06:57:25Z | 46900 |
| 145 | *HackTool.Win32.Earthworm* | .{0,1000}HackTool\.Win32\.Earthworm.{0,1000} | signature_keyword | EarthWorm | SOCKS v5 proxy service used for data forwarding in complex network environments | T1090.002 - T1573.001 - T1095 | TA0010 - TA0008 - TA0011 | N/A | APT27 - APT15 - Calypso - Earth Lusca - Worok | C2 | https://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a4 | 1 | 0 | #Avsignature | N/A | 10 | 10 | 156 | 177 | 2021-01-26T23:16:49Z | 2019-01-03T05:01:20Z | 46901 |
| 146 | *HackTool.Win32.JoeWare* | .{0,1000}HackTool\.Win32\.JoeWare.{0,1000} | signature_keyword | NetSess | Command line tool to enumerate NetBIOS sessions on a specified local or remote machine. | T1016 - T1046 - T1087 | TA0007 - TA0043 | N/A | MUSTANG PANDA | Discovery | https://www.joeware.net/freetools/tools/netsess/ | 1 | 0 | #Avsignature | N/A | 7 | 9 | N/A | N/A | N/A | N/A | 46902 |
| 147 | *HackTool.Win32.Mpacket* | .{0,1000}HackTool\.Win32\.Mpacket.{0,1000} | signature_keyword | impacket | Impacket is a collection of Python classes for working with network protocols. Impacket is focused on providing low-level programmatic access to the packets and for some protocols (e.g. SMB1-3 and MSRPC) the protocol implementation itself | T1557.001 - T1040 - T1003.001 - T1003.002 - T1003.003 - T1003.004 - T1558.003 - T1569.002 - T1047 | TA0001 - TA0003 - TA0004 - TA0005 - TA0006 - TA0008 - TA0011 | N/A | Akira - Bassterlord* - BianLian - Dragonfly - FIN8 - HAFNIUM - Hive - LockBit - Magic Hound - RansomHub - Rhysida - Sandworm Team - Scattered Spider* - Threat Group-3390 - Yanluowang - menuPass - Volt Typhoon - Cinnamon Tempest - Magic Hound - DAGGER PANDA - ENERGETIC BEAR - DEV-0270 - COZY BEAR - FANCY BEAR - EMBER BEAR - BERSERK BEAR - Dispossessor - Black Basta | Lateral Movement | https://github.com/fortra/impacket | 1 | 0 | #Avsignature | N/A | 10 | 10 | 14198 | 3681 | 2025-04-22T13:40:55Z | 2015-04-15T14:04:07Z | 46903 |
| 148 | *HackTool.Win32.NirsoftPT.SM* | .{0,1000}HackTool\.Win32\.NirsoftPT\.SM.{0,1000} | signature_keyword | webBrowserPassView | WebBrowserPassView is a password recovery tool that reveals the passwords stored by the following Web browsers: Internet Explorer (Version 4.0 - 11.0). Mozilla Firefox (All Versions). Google Chrome. Safari. and Opera. This tool can be used to recover your lost/forgotten password of any Website. including popular Web sites. like Facebook. Yahoo. Google. and GMail. as long as the password is stored by your Web Browser. | T1003 - T1555 - T1503 | TA0006 - TA0007 - TA0009 | N/A | Phobos - GoGoogle - 8BASE - Kimsuky - Dispossessor - Loki | Credential Access | https://www.nirsoft.net/utils/web_browser_password.html | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 46904 |
| 149 | *HackTool.Win32.PortScan.SWO* | .{0,1000}HackTool\.Win32\.PortScan\.SWO.{0,1000} | signature_keyword | advanced port scanner | port scanner tool abused by ransomware actors | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | Dispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa Locker | Discovery | https://www.advanced-port-scanner.com/ | 1 | 0 | #Avsignature | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 46905 |
| 150 | *HackTool.Win32.PWDump* | .{0,1000}HackTool\.Win32\.PWDump.{0,1000} | signature_keyword | PwDump7 | pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format. | T1003.001 - T1555.003 - T1077 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://www.openwall.com/passwords/windows-pwdump | 1 | 0 | #Avsignature | N/A | 10 | 8 | N/A | N/A | N/A | N/A | 46906 |
| 151 | *HackTool.Win32.PWDump* | .{0,1000}HackTool\.Win32\.PWDump.{0,1000} | signature_keyword | PwDump7 | pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format. | T1003.001 - T1555.003 - T1077 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://www.openwall.com/passwords/windows-pwdump | 1 | 0 | #Avsignature | N/A | 10 | 8 | N/A | N/A | N/A | N/A | 46907 |
| 152 | *HackTool.Win32.RouterScan* | .{0,1000}HackTool\.Win32\.RouterScan.{0,1000} | signature_keyword | RouterScan | a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces | T1110 | TA0006 - TA0007 | RouterScan | Conti | Credential Access | https://github.com/mustafashykh/router-scan | 1 | 0 | #Avsignature | N/A | 8 | 1 | 83 | 44 | 2019-02-24T14:31:16Z | 2019-02-24T07:52:22Z | 46908 |
| 153 | *HackTool.Win32.Sliver* | .{0,1000}HackTool\.Win32\.Sliver.{0,1000} | signature_keyword | sliver | Sliver is an open source cross-platform adversary emulation/red team framework | T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012 | TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043 | N/A | AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta | C2 | https://github.com/gsmith257-cyber/better-sliver | 1 | 0 | #Avsignature | N/A | 10 | 10 | 98 | 10 | 2024-07-22T12:32:16Z | 2023-12-12T02:04:36Z | 46909 |
| 154 | *HackTool.Win32.ToolPow* | .{0,1000}HackTool\.Win32\.ToolPow.{0,1000} | signature_keyword | Powertool | tool abused by threat actors to desactive Antivirus | T1562.001 - T1089 - T1562.009 | TA0005 | N/A | Play - Dispossessor | Defense Evasion | https://www.softpedia.com/get/Antivirus/Removal-Tools/ithurricane-PowerTool.shtml | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 46910 |
| 155 | *HackTool.Win64.JPotato* | .{0,1000}HackTool\.Win64\.JPotato.{0,1000} | signature_keyword | Bat-Potato | Automating Juicy Potato Local Privilege Escalation CMD exploit for penetration testers | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/0x4xel/Bat-Potato | 1 | 0 | #Avsignature | N/A | 10 | 1 | 42 | 11 | 2022-12-13T20:19:51Z | 2022-12-12T20:50:22Z | 46911 |
| 156 | *Hacktool.Windows* | .{0,1000}Hacktool\.Windows.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 46912 |
| 157 | *Hacktool.ZIP.HakC2* | .{0,1000}Hacktool\.ZIP\.HakC2.{0,1000} | signature_keyword | hak5 cloudc2 | Cloud C2 makes it easy for pentesters and security teams to deploy and manage Hak5 gear from the cloud | T1021 - T1102 - T1213 | TA0002 - TA0003 - TA0006 - TA0010 - TA0011 | N/A | N/A | C2 | https://shop.hak5.org/products/c2? | 1 | 0 | #Avsignature | N/A | 10 | 9 | N/A | N/A | N/A | N/A | 46913 |
| 158 | *HackTool/BadPotato* | .{0,1000}HackTool\/BadPotato.{0,1000} | signature_keyword | BadPotato | Windows Privilege Escalation Exploit BadPotato | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | Ghost Ransomware | Earth Lusca | Privilege Escalation | https://github.com/BeichenDream/BadPotato | 1 | 0 | #Avsignature | N/A | 10 | 9 | 836 | 136 | 2020-05-10T15:42:21Z | 2020-05-10T10:01:20Z | 46914 |
| 159 | *HackTool/Gsecdump* | .{0,1000}HackTool\/Gsecdump.{0,1000} | signature_keyword | gsecdump | credential dumper used to obtain password hashes and LSA secrets from Windows operating systems | T1003.001 - T1003.002 - T1555.003 - T1555.001 | TA0006 - TA0008 | N/A | APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick | Credential Access | https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 46915 |
| 160 | *HackTool/Mimikatz* | .{0,1000}HackTool\/Mimikatz.{0,1000} | signature_keyword | mimikatz | Mimikatz AV signatures | T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003 | TA0004 - TA0006 - TA0003 - TA0008 - TA0009 | N/A | Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx | Exploitation tool | https://github.com/gentilkiwi/mimikatz | 1 | 0 | #Avsignature | N/A | 10 | 10 | 20094 | 3854 | 2024-07-05T17:42:58Z | 2014-04-06T18:30:02Z | 46916 |
| 161 | *Hacktool/Win.* | .{0,1000}Hacktool\/Win\..{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 46917 |
| 162 | *HackTool/Win32.Earthworm* | .{0,1000}HackTool\/Win32\.Earthworm.{0,1000} | signature_keyword | EarthWorm | SOCKS v5 proxy service used for data forwarding in complex network environments | T1090.002 - T1573.001 - T1095 | TA0010 - TA0008 - TA0011 | N/A | APT27 - APT15 - Calypso - Earth Lusca - Worok | C2 | https://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a4 | 1 | 0 | #Avsignature | N/A | 10 | 10 | 156 | 177 | 2021-01-26T23:16:49Z | 2019-01-03T05:01:20Z | 46918 |
| 163 | *HackTool:Linux* | .{0,1000}HackTool\:Linux.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | #Avsignature | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 46919 |
| 164 | *HackTool:Linux/AuditdTamper* | .{0,1000}HackTool\:Linux\/AuditdTamper.{0,1000} | signature_keyword | auditd | disabling auditd | T1562.001 - T1070.004 | TA0005 | N/A | N/A | Defense Evasion | N/A | 1 | 0 | #linux #Avsignature | N/A | 10 | 8 | N/A | N/A | N/A | N/A | 46920 |
| 165 | *HackTool:Linux/CopyBashtoTemp* | .{0,1000}HackTool\:Linux\/CopyBashtoTemp.{0,1000} | signature_keyword | cp | copies the Bash binary to the /tmp/ directory | T1105 - T1036 - T1070 | TA0005 - TA0002 | N/A | N/A | Defense Evasion | N/A | 1 | 0 | #Avsignature | N/A | 8 | 7 | N/A | N/A | N/A | N/A | 46921 |
| 166 | *HackTool:Linux/EarthWorm* | .{0,1000}HackTool\:Linux\/EarthWorm.{0,1000} | signature_keyword | EarthWorm | SOCKS v5 proxy service used for data forwarding in complex network environments | T1090.002 - T1573.001 - T1095 | TA0010 - TA0008 - TA0011 | N/A | APT27 - APT15 - Calypso - Earth Lusca - Worok | C2 | https://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a4 | 1 | 0 | #Avsignature | N/A | 10 | 10 | 156 | 177 | 2021-01-26T23:16:49Z | 2019-01-03T05:01:20Z | 46922 |
| 167 | *HackTool:Linux/ExfiltrationNping.* | .{0,1000}HackTool\:Linux\/ExfiltrationNping\..{0,1000} | signature_keyword | nping | icmp exfiltration with nping (comes with nmap) | T1041 - T1095 | TA0010 - TA0011 | N/A | N/A | Data Exfiltration | http://nmap.org/nping/ | 1 | 0 | #Avsignature | N/A | 7 | 9 | N/A | N/A | N/A | N/A | 46923 |
| 168 | *HackTool:Linux/Fscan* | .{0,1000}HackTool\:Linux\/Fscan.{0,1000} | signature_keyword | fscan | Vulnerability scanner | T1595 | TA0042 - TA0007 | N/A | Earth Lusca | Reconnaissance | https://github.com/shadow1ng/fscan | 1 | 0 | #linux #Avsignature | N/A | 8 | 10 | 11931 | 1725 | 2025-04-20T11:30:29Z | 2020-11-13T16:35:20Z | 46924 |
| 169 | *HackTool:Linux/TorDownload* | .{0,1000}HackTool\:Linux\/TorDownload.{0,1000} | signature_keyword | tor | AV signature for tor binary | T1090 - T1134 - T1188 - T1307 - T1497 - T1560 | TA0005 - TA0010 - TA0011 | N/A | Dispossessor - APT28 - APT29 - Leviathan | Defense Evasion | N/A | 1 | 0 | #linux #Avsignature | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 46925 |
| 170 | *HackTool:MSIL* | .{0,1000}HackTool\:MSIL.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 46926 |
| 171 | *HackTool:MSIL/SharpDump* | .{0,1000}HackTool\:MSIL\/SharpDump.{0,1000} | signature_keyword | SharpDump | SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality. | T1003 - T1055 - T1070 | TA0006 - TA0005 - TA0008 | N/A | Avaddon | Credential Access | https://github.com/GhostPack/SharpDump | 1 | 0 | #Avsignature | N/A | 10 | 7 | 664 | 130 | 2019-02-07T02:52:20Z | 2018-07-24T17:42:19Z | 46927 |
| 172 | *HackTool:MSIL/Snaffler* | .{0,1000}HackTool\:MSIL\/Snaffler.{0,1000} | signature_keyword | Group3r | Find vulnerabilities in AD Group Policy | T1484.002 - T1069.002 - T1087.002 | TA0007 - TA0040 | N/A | KNOTWEED | Discovery | https://github.com/Group3r/Group3r | 1 | 0 | #Avsignature | AD Enumeration | 7 | 8 | 781 | 68 | 2025-04-08T05:03:34Z | 2021-07-05T05:05:42Z | 46928 |
| 173 | *HackTool:PowerShell* | .{0,1000}HackTool\:PowerShell.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 46929 |
| 174 | *HackTool:PowerShell/* | .{0,1000}HackTool\:PowerShell\/.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 46930 |
| 175 | *HackTool:PowerShell/ADRecon* | .{0,1000}HackTool\:PowerShell\/ADRecon.{0,1000} | signature_keyword | adrecon | ADRecon is a tool which gathers information about the Active Directory and generates a report which can provide a holistic picture of the current state of the target AD environment. | T1018 - T1087.001 - T1069.001 - T1003.002 - T1482 | TA0007 - TA0009 - TA0040 | N/A | Scattered Spider* | Discovery | https://github.com/adrecon/ADRecon | 1 | 0 | #Avsignature | AD Enumeration | 7 | 8 | 780 | 109 | 2024-10-15T03:41:29Z | 2018-12-15T13:00:09Z | 46931 |
| 176 | *HackTool:PowerShell/DecryptRDCMan* | .{0,1000}HackTool\:PowerShell\/DecryptRDCMan.{0,1000} | signature_keyword | Decrypt-RDCMan | decrypts passwords stored in Remote Desktop Connection Manager (RDCMan) using DPAPI | T1003 - T1552 - T1081 - T1027 | TA0006 - TA0008 - TA0005 | N/A | N/A | Credential Access | https://github.com/vmamuaya/Powershell/blob/master/Decrypt-RDCMan.ps1 | 1 | 0 | #Avsignature | N/A | 9 | 1 | 1 | 1 | 2016-12-01T14:06:24Z | 2017-11-22T23:18:39Z | 46932 |
| 177 | *HackTool:PowerShell/PowerView* | .{0,1000}HackTool\:PowerShell\/PowerView.{0,1000} | signature_keyword | powerview | PowerView is a PowerShell tool to gain network situational awareness on Windows domains | T1046 - T1087.001 - T1016 | TA0007 - TA0008 - TA0009 | N/A | Dispossessor - MAZE - Conti - XingLocker - Rhysida - BlackByte - Black Basta - MUSTANG PANDA | Discovery | https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1 | 1 | 0 | #Avsignature | N/A | 10 | 10 | 12274 | 4660 | 2020-08-17T23:19:49Z | 2012-05-26T16:08:48Z | 46933 |
| 178 | *HackTool:Python* | .{0,1000}HackTool\:Python.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 46934 |
| 179 | *HackTool:Python/* | .{0,1000}HackTool\:Python\/.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 46935 |
| 180 | *HackTool:Python/Empire.C!MTB* | .{0,1000}HackTool\:Python\/Empire\.C!MTB.{0,1000} | signature_keyword | linuxprivchecker | search for common privilege escalation vectors such as world writable files. misconfigurations. clear-text passwords and applicable exploits | T1210.001 - T1082 - T1088 - T1547.001 | TA0002 - TA0004 - TA0006 - TA0007 - TA0008 | N/A | N/A | Privilege Escalation | https://github.com/sleventyeleven/linuxprivchecker/blob/master/linuxprivchecker.py | 1 | 0 | #linux | N/A | 7 | 10 | 1645 | 524 | 2022-01-31T10:32:08Z | 2016-04-19T13:31:46Z | 46936 |
| 181 | *HackTool:Python/LaZagne.A!MTB* | .{0,1000}HackTool\:Python\/LaZagne\.A!MTB.{0,1000} | signature_keyword | Python-Rootkit | full undetectable python RAT which can bypass almost all antivirus and open a backdoor inside any windows machine which will establish a reverse https Metasploit connection to your listening machine | T1100 - T1027 - T1219 - T1560.001 - T1021.005 | TA0005 - TA0003 - TA0011 | N/A | N/A | C2 | https://github.com/0xIslamTaha/Python-Rootkit | 1 | 0 | N/A | N/A | 10 | 10 | 606 | 145 | 2024-10-29T16:56:39Z | 2016-06-09T10:49:54Z | 46937 |
| 182 | *Hacktool:Script/* | .{0,1000}Hacktool\:Script\/.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 46938 |
| 183 | *Hacktool:SH* | .{0,1000}Hacktool\:SH.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 46939 |
| 184 | *HackTool:SH/LinuxExploitSuggest* | .{0,1000}HackTool\:SH\/LinuxExploitSuggest.{0,1000} | signature_keyword | BeRoot | Privilege Escalation Project - Windows / Linux / Mac - signature observed with linux-exploit-suggester.sh | T1068 - T1055 - T1078 - T1548 - T1003 | TA0004 | N/A | N/A | Privilege Escalation | https://github.com/AlessandroZ/BeRoot | 1 | 1 | #linux | N/A | 10 | 10 | 2523 | 459 | 2024-10-04T11:54:01Z | 2017-04-14T12:47:31Z | 46940 |
| 185 | *Hacktool:VBA* | .{0,1000}Hacktool\:VBA.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 46941 |
| 186 | *HackTool:VBS* | .{0,1000}HackTool\:VBS.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 46942 |
| 187 | *HackTool:W32/SharpHound* | .{0,1000}HackTool\:W32\/SharpHound.{0,1000} | signature_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | #Avsignature | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 46943 |
| 188 | *HackTool:Win32* | .{0,1000}HackTool\:Win32.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 46944 |
| 189 | *HackTool:Win32* | .{0,1000}HackTool\:Win32.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 46945 |
| 190 | *HackTool:Win32/AdFind* | .{0,1000}HackTool\:Win32\/AdFind.{0,1000} | signature_keyword | adfind | adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers are abusing it to gather valuable information about the network environment | T1087 - T1016 - T1482 | TA0007 - TA0008 - TA0043 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 46946 |
| 191 | *HackTool:Win32/Badcastle!pz* | .{0,1000}HackTool\:Win32\/Badcastle!pz.{0,1000} | signature_keyword | BadPotato | Windows Privilege Escalation Exploit BadPotato | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | Ghost Ransomware | Earth Lusca | Privilege Escalation | https://github.com/BeichenDream/BadPotato | 1 | 0 | #Avsignature | N/A | 10 | 9 | 836 | 136 | 2020-05-10T15:42:21Z | 2020-05-10T10:01:20Z | 46947 |
| 192 | *HackTool:Win32/DefenderControl* | .{0,1000}HackTool\:Win32\/DefenderControl.{0,1000} | signature_keyword | defender-control | disable windows defender permanently | T1562.001 - T1562.004 - T1089 | TA0005 - TA0002 | N/A | LockBit | Defense Evasion | https://www.sordum.org/9480/defender-control-v2-1/ | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 46948 |
| 193 | *HackTool:Win32/Gmer* | .{0,1000}HackTool\:Win32\/Gmer.{0,1000} | signature_keyword | gmer | rootkit detector abused by attackers to disable security software | T1014 - T1562.001 | TA0005 | N/A | BlackSuit - Royal - PLAY - LockBit - Bassterlord* - Conti - 8BASE - TargetCompany - Hive - Avaddon | Defense Evasion | gmer.net | 1 | 0 | #Avsignature | N/A | 9 | 10 | N/A | N/A | N/A | N/A | 46949 |
| 194 | *HackTool:Win32/Gsecdump* | .{0,1000}HackTool\:Win32\/Gsecdump.{0,1000} | signature_keyword | gsecdump | credential dumper used to obtain password hashes and LSA secrets from Windows operating systems | T1003.001 - T1003.002 - T1555.003 - T1555.001 | TA0006 - TA0008 | N/A | APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick | Credential Access | https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 46950 |
| 195 | *HackTool:Win32/Htran* | .{0,1000}HackTool\:Win32\/Htran.{0,1000} | signature_keyword | htran | proxies connections through intermediate hops and aids users in disguising their true geographical location. It can be used by adversaries to hide their location when interacting with the victim networks | T1055 - T1090 - T1014 | TA0003 - TA0005 - TA0011 | N/A | GALLIUM - APT10 - APT12 - Deep Panda - MenuPass | C2 | https://github.com/HiwinCN/Htran | 1 | 0 | #Avsignature | N/A | 9 | 10 | 256 | 88 | 2021-04-25T09:57:46Z | 2015-12-03T04:54:53Z | 46951 |
| 196 | *HackTool:Win32/Mimilove* | .{0,1000}HackTool\:Win32\/Mimilove.{0,1000} | signature_keyword | mimikatz | Mimikatz AV signatures | T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003 | TA0004 - TA0006 - TA0003 - TA0008 - TA0009 | N/A | Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx | Exploitation tool | https://github.com/gentilkiwi/mimikatz | 1 | 0 | #Avsignature | N/A | 10 | 10 | 20094 | 3854 | 2024-07-05T17:42:58Z | 2014-04-06T18:30:02Z | 46953 |
| 197 | *HackTool:Win32/Netpasss.AB!MTB* | .{0,1000}HackTool\:Win32\/Netpasss\.AB!MTB.{0,1000} | signature_keyword | netpass | When you connect to a network share on your LAN or to your .NET Passport account. Windows allows you to save your password in order to use it in each time that you connect the remote server. This utility recovers all network passwords stored on your system for the current logged-on user. It can also recover the passwords stored in Credentials file of external drive. as long as you know the last log-on password. | T1081 - T1003 - T1555 | TA0006 - TA0009 | N/A | Kimsuky - XDSpy - TRAVELING SPIDER | Credential Access | https://www.nirsoft.net/utils/network_password_recovery.html | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 46954 |
| 198 | *HackTool:Win32/Passview!MSR* | .{0,1000}HackTool\:Win32\/Passview!MSR.{0,1000} | signature_keyword | bulletpassview | BulletsPassView is a password recovery tool that reveals the passwords stored behind the bullets in the standard password text-box of Windows operating system and Internet Explorer Web browser. After revealing the passwords. you can easily copy them to the clipboard or save them into text/html/csv/xml file. | T1040 - T1003 - T1078 - T1518 - T1555 | TA0006 - TA0009 | N/A | GoGoogle | Credential Access | https://www.nirsoft.net/utils/bullets_password_view.html | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 46955 |
| 199 | *HackTool:Win32/Passview!MSR* | .{0,1000}HackTool\:Win32\/Passview!MSR.{0,1000} | signature_keyword | VNCPassView | recover the passwords stored by the VNC tool | T1003 - T1555 - T1081 | TA0006 - TA0007 | N/A | GoGoogle - 8BASE | Credential Access | https://www.nirsoft.net/utils/vnc_password.html | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 46956 |
| 200 | *HackTool:Win32/Passview!MTB* | .{0,1000}HackTool\:Win32\/Passview!MTB.{0,1000} | signature_keyword | MailPassView | Mail PassView is a small password-recovery tool that reveals the passwords and other account details for multiple email clients | T1003 - T1081 - T1110 | TA0006 - TA0009 | N/A | BlackSuit - Royal - GoGoogle - Kimsuky - Evilnum - XDSpy | Credential Access | https://www.nirsoft.net/utils/mailpv.html | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 46957 |
| 201 | *HackTool:Win32/PWDump* | .{0,1000}HackTool\:Win32\/PWDump.{0,1000} | signature_keyword | PwDump7 | pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format. | T1003.001 - T1555.003 - T1077 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://www.openwall.com/passwords/windows-pwdump | 1 | 0 | #Avsignature | N/A | 10 | 8 | N/A | N/A | N/A | N/A | 46960 |
| 202 | *HackTool:Win32/RouterScan* | .{0,1000}HackTool\:Win32\/RouterScan.{0,1000} | signature_keyword | RouterScan | a penetration testing tool to maliciously scan for and brute force routers - cameras and network-attached storage devices with web interfaces | T1110 | TA0006 - TA0007 | RouterScan | Conti | Credential Access | https://github.com/mustafashykh/router-scan | 1 | 0 | #Avsignature | N/A | 8 | 1 | 83 | 44 | 2019-02-24T14:31:16Z | 2019-02-24T07:52:22Z | 46961 |
| 203 | *HackTool:Win32/SmbAgent* | .{0,1000}HackTool\:Win32\/SmbAgent.{0,1000} | signature_keyword | pingcastle | active directory weakness scan Vulnerability scanner | T1016 - T1069.002 - T1087.002 - T1485 | TA0007 - TA0008 | N/A | MAZE - BianLian - Scattered Spider* - DragonForce | Vulnerability Scanner | https://github.com/netwrix/pingcastle | 1 | 0 | #Avsignature | N/A | 10 | 10 | 2486 | 303 | 2025-02-28T10:16:24Z | 2018-08-31T17:42:48Z | 46962 |
| 204 | *HackTool:Win64* | .{0,1000}HackTool\:Win64.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 46963 |
| 205 | *HackTool:Win64* | .{0,1000}HackTool\:Win64.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 46964 |
| 206 | *HackTool:Win64/CobaltStrike* | .{0,1000}HackTool\:Win64\/CobaltStrike.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 46965 |
| 207 | *HackTool:Win64/FakeRclone* | .{0,1000}HackTool\:Win64\/FakeRclone.{0,1000} | signature_keyword | rclone | Rclone is a command line program for syncing files with cloud storage services - abused by a lot of ransomware groups | T1567.002 - T1560.001 - T1030 - T1048.002 - T1048.003 - T1567.002 - T1083 | TA0010 | N/A | Dispossessor - BlackSuit - Royal - Black Basta - Akira - Karakurt - AvosLocker - LockBit - BianLian - Hive - Daixin - Conti - Dagon Locker - Trigona - Quantum - Revil - 8BASE - INC Ransom - Cactus - EvilCorp* - Scattered Spider* - FiveHands - Cinnamon Tempest - EMBER BEA - Gamaredon | Data Exfiltration | https://github.com/rclone/rclone | 1 | 0 | #Avsignature | N/A | 8 | 10 | 49963 | 4453 | 2025-04-22T16:26:31Z | 2014-03-16T16:19:57Z | 46966 |
| 208 | *HackTool:Win64/JuicyPotato* | .{0,1000}HackTool\:Win64\/JuicyPotato.{0,1000} | signature_keyword | Bat-Potato | Automating Juicy Potato Local Privilege Escalation CMD exploit for penetration testers | T1055.012 - T1068 - T1548.002 - T1505.003 | TA0004 - TA0003 - TA0005 | N/A | N/A | Privilege Escalation | https://github.com/0x4xel/Bat-Potato | 1 | 0 | #Avsignature | N/A | 10 | 1 | 42 | 11 | 2022-12-13T20:19:51Z | 2022-12-12T20:50:22Z | 46967 |
| 209 | *HEUR:Exploit.MSIL.CVE-2022-22718.gen* | .{0,1000}HEUR\:Exploit\.MSIL\.CVE\-2022\-22718\.gen.{0,1000} | signature_keyword | SpoolFool | Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE) | T1068 - T1055 - T1059.003 | TA0004 - TA0005 - TA0003 | Dispossessor | Privilege Escalation | https://github.com/ly4k/SpoolFool | 1 | 0 | #Avsignature | N/A | 9 | 8 | 788 | 160 | 2022-02-09T16:54:09Z | 2022-02-08T17:25:44Z | 47135 | |
| 210 | *HEUR:HackTool.MSIL.SharpDump.gen* | .{0,1000}HEUR\:HackTool\.MSIL\.SharpDump\.gen.{0,1000} | signature_keyword | SharpDump | SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality. | T1003 - T1055 - T1070 | TA0006 - TA0005 - TA0008 | N/A | Avaddon | Credential Access | https://github.com/GhostPack/SharpDump | 1 | 0 | #Avsignature | N/A | 10 | 7 | 664 | 130 | 2019-02-07T02:52:20Z | 2018-07-24T17:42:19Z | 47136 |
| 211 | *HEUR:HackTool.Python.Impacket.gen* | .{0,1000}HEUR\:HackTool\.Python\.Impacket\.gen.{0,1000} | signature_keyword | susinternals | python implementation of PSExec native service implementation | T1569.002 - T1021.002 - T1035 | TA0002 - TA0004 - TA0008 - TA0003 | N/A | N/A | Lateral Movement | https://github.com/sensepost/susinternals | 1 | 0 | #Avsignature | N/A | 7 | 2 | 194 | 18 | 2025-02-11T09:34:50Z | 2025-02-10T07:40:36Z | 47137 |
| 212 | *HEUR:Trojan.Linux.Vilers.a* | .{0,1000}HEUR\:Trojan\.Linux\.Vilers\.a.{0,1000} | signature_keyword | sliver | Sliver is an open source cross-platform adversary emulation/red team framework | T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012 | TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043 | N/A | AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta | C2 | https://github.com/gsmith257-cyber/better-sliver | 1 | 0 | #Avsignature | N/A | 10 | 10 | 98 | 10 | 2024-07-22T12:32:16Z | 2023-12-12T02:04:36Z | 47138 |
| 213 | *HEUR:Trojan.Script.XZ* | .{0,1000}HEUR\:Trojan\.Script\.XZ.{0,1000} | signature_keyword | xz | backdoor in upstream xz/liblzma leading to ssh server compromise | T1174 - T1056 - T1210 - T1550 - T1036 - T1077 | TA0005 - TA0006 - TA0003 - TA0008 - TA0009 - TA0011 | N/A | N/A | Malware | https://securelist.com/xz-backdoor-story-part-1/112354/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47139 |
| 214 | *HEUR:Trojan-PSW.Win64.Mimilove* | .{0,1000}HEUR\:Trojan\-PSW\.Win64\.Mimilove.{0,1000} | signature_keyword | mimikatz | Mimikatz AV signatures | T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003 | TA0004 - TA0006 - TA0003 - TA0008 - TA0009 | N/A | Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx | Exploitation tool | https://github.com/gentilkiwi/mimikatz | 1 | 0 | #Avsignature | N/A | 10 | 10 | 20094 | 3854 | 2024-07-05T17:42:58Z | 2014-04-06T18:30:02Z | 47140 |
| 215 | *HEUR:Trojan-PSW.Win64.NTLM.gen* | .{0,1000}HEUR\:Trojan\-PSW\.Win64\.NTLM\.gen.{0,1000} | signature_keyword | NtlmThief | Extracting NetNTLM without touching lsass.exe | T1558.003 - T1003.001 | TA0006 | N/A | N/A | Credential Access | https://github.com/MzHmO/NtlmThief | 1 | 0 | #Avsignature | N/A | 10 | 3 | 235 | 33 | 2023-11-27T14:50:10Z | 2023-11-26T08:14:50Z | 47141 |
| 216 | *hiddentear/msil* | .{0,1000}hiddentear\/msil.{0,1000} | signature_keyword | hidden-tear | open source ransomware - many variant in the wild | T1486 - T1059 - T1485 - T1489 - T1070 - T1488 | TA0005 - TA0009 - TA0040 - TA0042 | N/A | N/A | Ransomware | https://github.com/goliate/hidden-tear | 1 | 0 | N/A | N/A | 10 | 8 | 765 | 394 | 2020-07-08T22:34:01Z | 2015-08-19T09:06:51Z | 47163 |
| 217 | *HKTL* | .{0,1000}HKTL.{0,1000} | signature_keyword | Antivirus Signature | Antivirus signature_keyword for hacktool | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | #Avsignature | hacktool signatures | 10 | 10 | N/A | N/A | N/A | N/A | 47238 |
| 218 | *HKTL_HTRAN* | .{0,1000}HKTL_HTRAN.{0,1000} | signature_keyword | htran | proxies connections through intermediate hops and aids users in disguising their true geographical location. It can be used by adversaries to hide their location when interacting with the victim networks | T1055 - T1090 - T1014 | TA0003 - TA0005 - TA0011 | N/A | GALLIUM - APT10 - APT12 - Deep Panda - MenuPass | C2 | https://github.com/HiwinCN/Htran | 1 | 0 | #Avsignature | N/A | 9 | 10 | 256 | 88 | 2021-04-25T09:57:46Z | 2015-12-03T04:54:53Z | 47239 |
| 219 | *HKTL_MIMIKATZ* | .{0,1000}HKTL_MIMIKATZ.{0,1000} | signature_keyword | mimikatz | Mimikatz AV signatures | T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003 | TA0004 - TA0006 - TA0003 - TA0008 - TA0009 | N/A | Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx | Exploitation tool | https://github.com/gentilkiwi/mimikatz | 1 | 0 | #Avsignature | N/A | 10 | 10 | 20094 | 3854 | 2024-07-05T17:42:58Z | 2014-04-06T18:30:02Z | 47240 |
| 220 | *HKTL_NETCAT* | .{0,1000}HKTL_NETCAT.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 47241 |
| 221 | *HKTL_PTHTOOLKIT* | .{0,1000}HKTL_PTHTOOLKIT.{0,1000} | signature_keyword | lslsass | dump active logon session password hashes from the lsass process (old tool for vista and older) | T1003.001 | TA0006 | N/A | APT1 | Credential Access | https://www.virustotal.com/gui/file/b24ab1f8cb68547932dd8a5c81e9b2133763a7ddf48aa431456530c1340b939e/details | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47242 |
| 222 | *HKTL_PWDUMP.* | .{0,1000}HKTL_PWDUMP\..{0,1000} | signature_keyword | PWDumpX | PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems. | T1003.001 - T1555.003 - T1077 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://packetstormsecurity.com/files/download/52580/PWDumpX.zip | 1 | 0 | #Avsignature | N/A | 10 | 8 | N/A | N/A | N/A | N/A | 47243 |
| 223 | *HTool/WCE* | .{0,1000}HTool\/WCE.{0,1000} | signature_keyword | Antivirus Signature | Generic hacktool Engine signature | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 1 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 47318 |
| 224 | *HTool-EmpireAgent* | .{0,1000}HTool\-EmpireAgent.{0,1000} | signature_keyword | LAPSToolkit | Functions written in PowerShell that leverage PowerView to audit and attack Active Directory environments that have deployed Microsofts Local Administrator Password Solution (LAPS). It includes finding groups specifically delegated by sysadmins. finding users with All Extended Rights that can view passwords. and viewing all computers with LAPS enabled | T1087.001 - T1069 - T1069.003 - T1069.007 - T1069.002 - T1069.001 | TA0007 - TA0008 - TA0009 | N/A | Scattered Spider* | Discovery | https://github.com/leoloobeek/LAPSToolkit | 1 | 0 | #Avsignature | N/A | 10 | 9 | 859 | 119 | 2018-01-31T14:45:35Z | 2016-04-27T00:06:20Z | 47319 |
| 225 | *HTool-EmpireAgent* | .{0,1000}HTool\-EmpireAgent.{0,1000} | signature_keyword | powerview | PowerView is a PowerShell tool to gain network situational awareness on Windows domains | T1046 - T1087.001 - T1016 | TA0007 - TA0008 - TA0009 | N/A | Dispossessor - MAZE - Conti - XingLocker - Rhysida - BlackByte - Black Basta - MUSTANG PANDA | Discovery | https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1 | 1 | 0 | #Avsignature | N/A | 10 | 10 | 12274 | 4660 | 2020-08-17T23:19:49Z | 2012-05-26T16:08:48Z | 47320 |
| 226 | *HTool-GhostPack* | .{0,1000}HTool\-GhostPack.{0,1000} | signature_keyword | SharpDump | SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality. | T1003 - T1055 - T1070 | TA0006 - TA0005 - TA0008 | N/A | Avaddon | Credential Access | https://github.com/GhostPack/SharpDump | 1 | 0 | #Avsignature | N/A | 10 | 7 | 664 | 130 | 2019-02-07T02:52:20Z | 2018-07-24T17:42:19Z | 47321 |
| 227 | *HTool-GSECDump* | .{0,1000}HTool\-GSECDump.{0,1000} | signature_keyword | gsecdump | credential dumper used to obtain password hashes and LSA secrets from Windows operating systems | T1003.001 - T1003.002 - T1555.003 - T1555.001 | TA0006 - TA0008 | N/A | APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick | Credential Access | https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47322 |
| 228 | *HTool-Lazagne* | .{0,1000}HTool\-Lazagne.{0,1000} | signature_keyword | LaZagne | The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software. | T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001 | TA0006 - TA0009 | N/A | Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT | Credential Access | https://github.com/AlessandroZ/LaZagne | 1 | 1 | #Avsignature | N/A | 10 | 10 | 9941 | 2062 | 2025-04-10T14:24:35Z | 2015-02-16T14:10:02Z | 47323 |
| 229 | *HTool-PassView* | .{0,1000}HTool\-PassView.{0,1000} | signature_keyword | bulletpassview | BulletsPassView is a password recovery tool that reveals the passwords stored behind the bullets in the standard password text-box of Windows operating system and Internet Explorer Web browser. After revealing the passwords. you can easily copy them to the clipboard or save them into text/html/csv/xml file. | T1040 - T1003 - T1078 - T1518 - T1555 | TA0006 - TA0009 | N/A | GoGoogle | Credential Access | https://www.nirsoft.net/utils/bullets_password_view.html | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 47324 |
| 230 | *HTool-Portscan.gen* | .{0,1000}HTool\-Portscan\.gen.{0,1000} | signature_keyword | advanced port scanner | port scanner tool abused by ransomware actors | T1135 - T1021 - T1016 - T1046 | TA0007 - TA0043 | N/A | Dispossessor - LockBit - BianLian - PYSA - Trigona - EvilCorp* - Fog - Scattered Spider* - INDRIK SPIDER - Medusa Locker | Discovery | https://www.advanced-port-scanner.com/ | 1 | 0 | #Avsignature | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 47325 |
| 231 | *HTool-SessionGopher* | .{0,1000}HTool\-SessionGopher.{0,1000} | signature_keyword | SessionGopher | uses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally. | T1047 - T1003.008 - T1552.004 - T1555.003 | TA0006 | N/A | PYSA - DarkSide - Sphinx | Credential Access | https://github.com/Arvanaghi/SessionGopher | 1 | 0 | #Avsignature | N/A | 10 | 10 | 1255 | 173 | 2022-11-22T21:33:23Z | 2017-03-08T02:49:32Z | 47326 |
| 232 | *impacket* | .{0,1000}impacket.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Lateral Movement | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 48252 |
| 233 | *Linux.Backdoor* | .{0,1000}Linux\.Backdoor.{0,1000} | signature_keyword | Antivirus Signature | AV signature of noodlerat malware | T1059.004 - T1078 - T1105 - T1100 - T1547.006 | TA0003 - TA0005 - TA0010 - TA0011 | N/A | N/A | Malware | N/A | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 51056 |
| 234 | *Linux.Cloudsnooper* | .{0,1000}Linux\.Cloudsnooper.{0,1000} | signature_keyword | NoodleRAT | AV signature of noodlerat malware | T1059.004 - T1078 - T1105 - T1100 - T1547.006 | TA0003 - TA0005 - TA0010 - TA0011 | N/A | N/A | Malware | https://www.trendmicro.com/en_us/research/24/f/noodle-rat-reviewing-the-new-backdoor-used-by-chinese-speaking-g.html | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 51057 |
| 235 | *Linux.Hacktool.Earthworm* | .{0,1000}Linux\.Hacktool\.Earthworm.{0,1000} | signature_keyword | EarthWorm | SOCKS v5 proxy service used for data forwarding in complex network environments | T1090.002 - T1573.001 - T1095 | TA0010 - TA0008 - TA0011 | N/A | APT27 - APT15 - Calypso - Earth Lusca - Worok | C2 | https://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a4 | 1 | 0 | #Avsignature | N/A | 10 | 10 | 156 | 177 | 2021-01-26T23:16:49Z | 2019-01-03T05:01:20Z | 51058 |
| 236 | *Linux.NOODLERAT* | .{0,1000}Linux\.NOODLERAT.{0,1000} | signature_keyword | NoodleRAT | AV signature of noodlerat malware | T1059.004 - T1078 - T1105 - T1100 - T1547.006 | TA0003 - TA0005 - TA0010 - TA0011 | N/A | N/A | Malware | https://www.trendmicro.com/en_us/research/24/f/noodle-rat-reviewing-the-new-backdoor-used-by-chinese-speaking-g.html | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 51059 |
| 237 | *Linux/CoinMiner* | .{0,1000}Linux\/CoinMiner.{0,1000} | signature_keyword | cryptomining | A Linux Cyptomining malware | T1496 | TA0009 | N/A | N/A | Cryptomining | https://github.com/tarcisio-marinho/cryptomining | 1 | 0 | #Avsignature | 7 | 1 | 36 | 15 | 2023-05-05T02:42:59Z | 2018-04-07T03:59:52Z | 51060 | |
| 238 | *Linux/CoinMiner.NM* | .{0,1000}Linux\/CoinMiner\.NM.{0,1000} | signature_keyword | cryptomining | A Linux Cyptomining malware | T1496 | TA0009 | N/A | N/A | Cryptomining | https://github.com/tarcisio-marinho/cryptomining | 1 | 0 | #Avsignature | 7 | 1 | 36 | 15 | 2023-05-05T02:42:59Z | 2018-04-07T03:59:52Z | 51061 | |
| 239 | *LINUX/CoinMiner.wgudk* | .{0,1000}LINUX\/CoinMiner\.wgudk.{0,1000} | signature_keyword | cryptomining | A Linux Cyptomining malware | T1496 | TA0009 | N/A | N/A | Cryptomining | https://github.com/tarcisio-marinho/cryptomining | 1 | 0 | #Avsignature | 7 | 1 | 36 | 15 | 2023-05-05T02:42:59Z | 2018-04-07T03:59:52Z | 51062 | |
| 240 | *Linux/Filecoder.GonnaCry* | .{0,1000}Linux\/Filecoder\.GonnaCry.{0,1000} | signature_keyword | GonnaCry | a linux ransomware | T1486 - T1059 - T1020 - T1083 - T1070 | TA0040 - TA0005 - TA0009 - TA0010 | N/A | N/A | Ransomware | https://github.com/tarcisio-marinho/GonnaCry | 1 | 0 | #linux #Avsignature | N/A | 10 | 8 | 717 | 402 | 2025-01-24T13:39:57Z | 2017-05-12T23:46:28Z | 51063 |
| 241 | *Linux/SSHDoor* | .{0,1000}Linux\/SSHDoor.{0,1000} | signature_keyword | sshdoor | Openssh backdoor | T1059.003 - T1105 - T1071.001 | TA0011 - TA0003 | N/A | FANCY BEAR | Persistence | https://web-assets.esetstatic.com/wls/2018/12/ESET-The_Dark_Side_of_the_ForSSHe.pdf | 1 | 0 | #Avsignature | N/A | 10 | 9 | N/A | N/A | N/A | N/A | 51064 |
| 242 | *Lsass-Mdump* | .{0,1000}Lsass\-Mdump.{0,1000} | signature_keyword | Antivirus Signature | Dump LSASS memory through a process snapshot (-r) avoiding interacting with it directly | T1110 | TA0006 | N/A | N/A | Credential Access | lsass dump malware signature | 1 | 1 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 51432 |
| 243 | *Malware.Htool* | .{0,1000}Malware\.HTool.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | #Avsignature | hacktool signatures | 10 | 10 | N/A | N/A | N/A | N/A | 51620 |
| 244 | *MEM:Trojan.Linux.XZ* | .{0,1000}MEM\:Trojan\.Linux\.XZ.{0,1000} | signature_keyword | xz | backdoor in upstream xz/liblzma leading to ssh server compromise | T1174 - T1056 - T1210 - T1550 - T1036 - T1077 | TA0005 - TA0006 - TA0003 - TA0008 - TA0009 - TA0011 | N/A | N/A | Malware | https://securelist.com/xz-backdoor-story-part-1/112354/ | 1 | 0 | #linux | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 51750 |
| 245 | *Mimikatz.Spyware.Stealer.DDS* | .{0,1000}Mimikatz\.Spyware\.Stealer\.DDS.{0,1000} | signature_keyword | mimikatz | Mimikatz AV signatures | T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003 | TA0004 - TA0006 - TA0003 - TA0008 - TA0009 | N/A | Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx | Exploitation tool | https://github.com/gentilkiwi/mimikatz | 1 | 0 | #Avsignature | N/A | 10 | 10 | 20094 | 3854 | 2024-07-05T17:42:58Z | 2014-04-06T18:30:02Z | 52029 |
| 246 | *MSFPsExeCommand* | .{0,1000}MSFPsExeCommand.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Lateral Movement | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 52374 |
| 247 | *MSIL.ClipBanker* | .{0,1000}MSIL\.ClipBanker.{0,1000} | signature_keyword | SharpClipboard | monitor the content of the clipboard continuously | T1115 | TA0006 - TA0009 | N/A | N/A | Credential Access | http://github.com/slyd0g/SharpClipboard | 1 | 0 | #Avsignature | N/A | 8 | 1 | N/A | N/A | N/A | N/A | 52462 |
| 248 | *MSIL/ClipBanker* | .{0,1000}MSIL\/ClipBanker.{0,1000} | signature_keyword | SharpClipboard | monitor the content of the clipboard continuously | T1115 | TA0006 - TA0009 | N/A | N/A | Credential Access | http://github.com/slyd0g/SharpClipboard | 1 | 0 | #Avsignature | N/A | 8 | 1 | N/A | N/A | N/A | N/A | 52463 |
| 249 | *MSIL/CVE_2022_22718.A!exploit* | .{0,1000}MSIL\/CVE_2022_22718\.A!exploit.{0,1000} | signature_keyword | SpoolFool | Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE) | T1068 - T1055 - T1059.003 | TA0004 - TA0005 - TA0003 | Dispossessor | Privilege Escalation | https://github.com/ly4k/SpoolFool | 1 | 0 | #Avsignature | N/A | 9 | 8 | 788 | 160 | 2022-02-09T16:54:09Z | 2022-02-08T17:25:44Z | 52464 | |
| 250 | *MSIL/Exploit.CVE-2022-22718.A* | .{0,1000}MSIL\/Exploit\.CVE\-2022\-22718\.A.{0,1000} | signature_keyword | SpoolFool | Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE) | T1068 - T1055 - T1059.003 | TA0004 - TA0005 - TA0003 | Dispossessor | Privilege Escalation | https://github.com/ly4k/SpoolFool | 1 | 0 | #Avsignature | N/A | 9 | 8 | 788 | 160 | 2022-02-09T16:54:09Z | 2022-02-08T17:25:44Z | 52465 | |
| 251 | *MSIL/Hiddentear* | .{0,1000}MSIL\/Hiddentear.{0,1000} | signature_keyword | hidden-tear | open source ransomware - many variant in the wild | T1486 - T1059 - T1485 - T1489 - T1070 - T1488 | TA0005 - TA0009 - TA0040 - TA0042 | N/A | N/A | Ransomware | https://github.com/goliate/hidden-tear | 1 | 0 | N/A | N/A | 10 | 8 | 765 | 394 | 2020-07-08T22:34:01Z | 2015-08-19T09:06:51Z | 52466 |
| 252 | *MSIL/Riskware.Snaffler* | .{0,1000}MSIL\/Riskware\.Snaffler.{0,1000} | signature_keyword | Group3r | Find vulnerabilities in AD Group Policy | T1484.002 - T1069.002 - T1087.002 | TA0007 - TA0040 | N/A | KNOTWEED | Discovery | https://github.com/Group3r/Group3r | 1 | 0 | #Avsignature | AD Enumeration | 7 | 8 | 781 | 68 | 2025-04-08T05:03:34Z | 2021-07-05T05:05:42Z | 52469 |
| 253 | *Multi.Trojan.Sliver* | .{0,1000}Multi\.Trojan\.Sliver.{0,1000} | signature_keyword | sliver | Sliver is an open source cross-platform adversary emulation/red team framework | T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012 | TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043 | N/A | AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta | C2 | https://github.com/gsmith257-cyber/better-sliver | 1 | 0 | #Avsignature | N/A | 10 | 10 | 98 | 10 | 2024-07-22T12:32:16Z | 2023-12-12T02:04:36Z | 52509 |
| 254 | *NirPassView (PUA)* | .{0,1000}NirPassView\s\(PUA\).{0,1000} | signature_keyword | bulletpassview | BulletsPassView is a password recovery tool that reveals the passwords stored behind the bullets in the standard password text-box of Windows operating system and Internet Explorer Web browser. After revealing the passwords. you can easily copy them to the clipboard or save them into text/html/csv/xml file. | T1040 - T1003 - T1078 - T1518 - T1555 | TA0006 - TA0009 | N/A | GoGoogle | Credential Access | https://www.nirsoft.net/utils/bullets_password_view.html | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 53434 |
| 255 | *Nirsoft PasswordFox (PUA)* | .{0,1000}Nirsoft\sPasswordFox\s\(PUA\).{0,1000} | signature_keyword | passwordfox | recovery tool that allows you to view the user names and passwords stored by Mozilla Firefox | T1555.003 - T1003 - T1083 | TA0006 | N/A | LockBit - GoGoogle - 8BASE - XDSpy | Credential Access | https://www.nirsoft.net/utils/passwordfox.html | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 53435 |
| 256 | *PowerShell/HackTool* | .{0,1000}PowerShell\/HackTool.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 55244 |
| 257 | *PowerShell/HackTool.SessionGopher* | .{0,1000}PowerShell\/HackTool\.SessionGopher.{0,1000} | signature_keyword | SessionGopher | uses WMI to extract saved session information for remote access tools such as WinSCP - PuTTY - SuperPuTTY - FileZilla and Microsoft Remote Desktop. It can be run remotely or locally. | T1047 - T1003.008 - T1552.004 - T1555.003 | TA0006 | N/A | PYSA - DarkSide - Sphinx | Credential Access | https://github.com/Arvanaghi/SessionGopher | 1 | 0 | #Avsignature | N/A | 10 | 10 | 1255 | 173 | 2022-11-22T21:33:23Z | 2017-03-08T02:49:32Z | 55245 |
| 258 | *PowerShell/ReverseShell.DR* | .{0,1000}PowerShell\/ReverseShell\.DR.{0,1000} | signature_keyword | powercat | Netcat - The powershell version | T1571 - T1048.003 - T1095 | TA0042 - TA0011 | N/A | N/A | C2 | https://github.com/besimorhino/powercat | 1 | 0 | #Avsignature | N/A | 10 | 10 | 2229 | 482 | 2024-03-05T18:05:07Z | 2014-08-21T14:38:46Z | 55246 |
| 259 | *PowerShell/Turla.T* | .{0,1000}PowerShell\/Turla\.T.{0,1000} | signature_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 55247 | |
| 260 | *PShlSpy* | .{0,1000}PShlSpy.{0,1000} | signature_keyword | Antivirus Signature | highly revelant Antivirus signature. phishing tools | N/A | N/A | N/A | N/A | Phishing | N/A | 1 | 1 | N/A | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 55703 |
| 261 | *PSWtool* | .{0,1000}PSWtool.{0,1000} | signature_keyword | Antivirus Signature | highly revelant Antivirus signature. Programs classified as PSWTool can be used to view or restore forgotten often hidden passwords. They can also be used with malicious intent. even though the programs themselves have no malicious payload. | N/A | N/A | N/A | N/A | Credential Access | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 55739 |
| 262 | *PSWTool.PasswordFox.* | .{0,1000}PSWTool\.PasswordFox\..{0,1000} | signature_keyword | passwordfox | recovery tool that allows you to view the user names and passwords stored by Mozilla Firefox | T1555.003 - T1003 - T1083 | TA0006 | N/A | LockBit - GoGoogle - 8BASE - XDSpy | Credential Access | https://www.nirsoft.net/utils/passwordfox.html | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 55740 |
| 263 | *PSWTool.Win32.PassView* | .{0,1000}PSWTool\.Win32\.PassView.{0,1000} | signature_keyword | webBrowserPassView | WebBrowserPassView is a password recovery tool that reveals the passwords stored by the following Web browsers: Internet Explorer (Version 4.0 - 11.0). Mozilla Firefox (All Versions). Google Chrome. Safari. and Opera. This tool can be used to recover your lost/forgotten password of any Website. including popular Web sites. like Facebook. Yahoo. Google. and GMail. as long as the password is stored by your Web Browser. | T1003 - T1555 - T1503 | TA0006 - TA0007 - TA0009 | N/A | Phobos - GoGoogle - 8BASE - Kimsuky - Dispossessor - Loki | Credential Access | https://www.nirsoft.net/utils/web_browser_password.html | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 55741 |
| 264 | *PSWTool.Win32.PWDump* | .{0,1000}PSWTool\.Win32\.PWDump.{0,1000} | signature_keyword | PWDumpX | PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems. | T1003.001 - T1555.003 - T1077 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://packetstormsecurity.com/files/download/52580/PWDumpX.zip | 1 | 0 | #Avsignature | N/A | 10 | 8 | N/A | N/A | N/A | N/A | 55742 |
| 265 | *PSWTool.Win64.FirePass.* | .{0,1000}PSWTool\.Win64\.FirePass\..{0,1000} | signature_keyword | passwordfox | recovery tool that allows you to view the user names and passwords stored by Mozilla Firefox | T1555.003 - T1003 - T1083 | TA0006 | N/A | LockBit - GoGoogle - 8BASE - XDSpy | Credential Access | https://www.nirsoft.net/utils/passwordfox.html | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 55743 |
| 266 | *PSWTool.Win64.Gsecdmp* | .{0,1000}PSWTool\.Win64\.Gsecdmp.{0,1000} | signature_keyword | gsecdump | credential dumper used to obtain password hashes and LSA secrets from Windows operating systems | T1003.001 - T1003.002 - T1555.003 - T1555.001 | TA0006 - TA0008 | N/A | APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick | Credential Access | https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 55744 |
| 267 | *PUA.Win32.DefenderControl* | .{0,1000}PUA\.Win32\.DefenderControl.{0,1000} | signature_keyword | defender-control | disable windows defender permanently | T1562.001 - T1562.004 - T1089 | TA0005 - TA0002 | N/A | LockBit | Defense Evasion | https://www.sordum.org/9480/defender-control-v2-1/ | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 55786 |
| 268 | *PUA.Win64.PCHunter.YACIU* | .{0,1000}PUA\.Win64\.PCHunter\.YACIU.{0,1000} | signature_keyword | PCHunter | PCHunter is a toolkit offering deep access to kernel setting - processes - network and startup configurations. It is designed to detect and remove malware - including rootkits but is also abused by attackers to disable antivirus | T1562 - T1055 - T1070 | TA0005 - TA0004 | N/A | LockBit - Conti - 8BASE - TargetCompany - Hive - Qilin | Defense Evasion | https://www.majorgeeks.com/files/details/pc_hunter.html | 1 | 0 | #Avsignature | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 55788 |
| 269 | *PUA.Win64.Rentdrv.* | .{0,1000}PUA\.Win64\.Rentdrv\..{0,1000} | signature_keyword | BadRentdrv2 | A vulnerable driver (BYOVD) capable of terminating several EDRs and antivirus software | T1562 - T1068 - T1210 - T1489 - T1496 | TA0005 - TA0004 - TA0040 | N/A | Agrius | Defense Evasion | https://github.com/keowu/BadRentdrv2 | 1 | 0 | #Avsignature | N/A | 10 | 1 | 95 | 20 | 2024-12-26T13:43:18Z | 2023-10-01T18:24:38Z | 55789 |
| 270 | *PUA:Win32/AmmyyAdmin* | .{0,1000}PUA\:Win32\/AmmyyAdmin.{0,1000} | signature_keyword | Ammyy Admin | Ammyy Admin is a remote desktop software application abudsed by attackers | T1021 - T1219 - T1563 - T1608 | TA0002 - TA0008 - TA0011 - TA0040 | N/A | Anunak | RMM | https://www.ammyy.com | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 55790 |
| 271 | *PUA:Win32/AmmyyAdmin* | .{0,1000}PUA\:Win32\/AmmyyAdmin.{0,1000} | signature_keyword | Ammyy Admin | Antiviurs signature_keyword | T1021 - T1219 - T1563 - T1608 | TA0002 - TA0008 - TA0011 - TA0040 | N/A | Anunak | RMM | N/A | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 55791 |
| 272 | *PUA:Win32/PassShow* | .{0,1000}PUA\:Win32\/PassShow.{0,1000} | signature_keyword | SniffPass | password monitoring software that listens to your network - capture the passwords that pass through your network adapter and display them on the screen instantly | T1040 - T1071 - T1041 | TA0006 - TA0007 - TA0009 | N/A | GoGoogle - Kimsuky | Credential Access | https://www.nirsoft.net/utils/password_sniffer.html | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 55793 |
| 273 | *PUA:Win32/PassShow* | .{0,1000}PUA\:Win32\/PassShow.{0,1000} | signature_keyword | webBrowserPassView | WebBrowserPassView is a password recovery tool that reveals the passwords stored by the following Web browsers: Internet Explorer (Version 4.0 - 11.0). Mozilla Firefox (All Versions). Google Chrome. Safari. and Opera. This tool can be used to recover your lost/forgotten password of any Website. including popular Web sites. like Facebook. Yahoo. Google. and GMail. as long as the password is stored by your Web Browser. | T1003 - T1555 - T1503 | TA0006 - TA0007 - TA0009 | N/A | Phobos - GoGoogle - 8BASE - Kimsuky - Dispossessor - Loki | Credential Access | https://www.nirsoft.net/utils/web_browser_password.html | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 55794 |
| 274 | *PWCrack-PWDump* | .{0,1000}PWCrack\-PWDump.{0,1000} | signature_keyword | PWDumpX | PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems. | T1003.001 - T1555.003 - T1077 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://packetstormsecurity.com/files/download/52580/PWDumpX.zip | 1 | 0 | #Avsignature | N/A | 10 | 8 | N/A | N/A | N/A | N/A | 55851 |
| 275 | *PWCrack-Pwdump.* | .{0,1000}PWCrack\-Pwdump\..{0,1000} | signature_keyword | PwDump7 | pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format. | T1003.001 - T1555.003 - T1077 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://www.openwall.com/passwords/windows-pwdump | 1 | 0 | #Avsignature | N/A | 10 | 8 | N/A | N/A | N/A | N/A | 55852 |
| 276 | *PWDump * | .{0,1000}PWDump\s.{0,1000} | signature_keyword | Antivirus Signature | Antivirus signature - a tool used within a command-line interface on 64bit Windows computers to extract the NTLM (LanMan) hashes from LSASS.exe in memory. This tool may be used in conjunction with malware or other penetration testing tools to obtain credentials for use in Windows authentication systems | N/A | N/A | N/A | N/A | Credential Access | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 55864 |
| 277 | *PWDump7 Raw Password Extractor (PUA)* | .{0,1000}PWDump7\sRaw\sPassword\sExtractor\s\(PUA\).{0,1000} | signature_keyword | PwDump7 | pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format. | T1003.001 - T1555.003 - T1077 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://www.openwall.com/passwords/windows-pwdump | 1 | 0 | #Avsignature | N/A | 10 | 8 | N/A | N/A | N/A | N/A | 55873 |
| 278 | *PWDumpX (PUA)* | .{0,1000}PWDumpX\s\(PUA\).{0,1000} | signature_keyword | PWDumpX | PWDumpX tool allows a user with administrative privileges to retrieve the encrypted password hashes and LSA secrets from a Windows system. This tool can be used on the local system or on one or more remote systems. | T1003.001 - T1555.003 - T1077 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://packetstormsecurity.com/files/download/52580/PWDumpX.zip | 1 | 0 | #Avsignature | N/A | 10 | 8 | N/A | N/A | N/A | N/A | 55878 |
| 279 | *PWS:Win32/Mpass* | .{0,1000}PWS\:Win32\/Mpass.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 55915 |
| 280 | *Python.Stealer* | .{0,1000}Python\.Stealer.{0,1000} | signature_keyword | cstealer | NiceRAT stealer - clone of cstealer | T1056.001 - T1560.001 - T1564.004 - T1113 - T1003 - T1036 - T1555.003 - T1555.001 - T1213.002 - T1027.002 | TA0006 - TA0009 - TA0010 | N/A | N/A | Credential Access | https://github.com/0x00G/NiceRAT | 1 | 0 | N/A | N/A | 10 | 2 | 118 | 86 | 2024-10-20T18:38:53Z | 2022-11-20T19:11:00Z | 56096 |
| 281 | *Ransom.Win32.* | .{0,1000}Ransom\.Win32\..{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword for ransomware | T1486 - T1489 - T1490 - T1485 - T1487 - T1491 - T1492 - T1488 - T1493 - T1497 | TA0007 - TA0003 - TA0002 - TA0004 - TA0006 - TA0010 | N/A | N/A | Ransomware | https://www.trendmicro.com/content/dam/trendmicro/global/en/research/23/e/blackcat-ransomware-deploys-new-signed-kernel-driver/indicators-blackcat-ransomware-deploys-new-signed-kernel-driver.txt | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 56243 |
| 282 | *Ransom:Linux/BlackBasta* | .{0,1000}Ransom\:Linux\/BlackBasta.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 56244 |
| 283 | *Ransom:MSIL/Jasmin.* | .{0,1000}Ransom\:MSIL\/Jasmin\..{0,1000} | signature_keyword | Jasmin-Ransomware | Jasmin Ransomware is an advanced red team tool (WannaCry Clone) used for simulating real ransomware attacks | T1486 | TA0040 - TA0002 - TA0010 | N/A | N/A | Ransomware | https://github.com/codesiddhant/Jasmin-Ransomware | 1 | 0 | #Avsignature | defender signature | 10 | 3 | 252 | 80 | 2021-03-01T14:51:06Z | 2021-02-27T07:09:08Z | 56245 |
| 284 | *Ransom:Win32* | .{0,1000}Ransom\:Win32.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | ransom signatures | 10 | 10 | N/A | N/A | N/A | N/A | 56246 |
| 285 | *Ransom:Win32* | .{0,1000}Ransom\:Win32.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 56247 |
| 286 | *Ransom:Win32/BlackBasta* | .{0,1000}Ransom\:Win32\/BlackBasta.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 56248 |
| 287 | *Ransom:Win32/Dedsec* | .{0,1000}Ransom\:Win32\/Dedsec.{0,1000} | signature_keyword | DEDSEC-RANSOMWARE | dedsec ransomware | T1486 - T1489 - T1490 - T1495 - T1488 - T1482 | TA0040 - TA0043 - TA0042 - TA0009 - TA0010 | N/A | N/A | Ransomware | https://github.com/xelroth/DEDSEC-RANSOMWARE | 1 | 0 | N/A | N/A | 10 | 1 | 7 | 1 | 2024-05-17T11:12:23Z | 2024-05-17T10:34:03Z | 56249 |
| 288 | *Ransom:Win32/Sodinokibi* | .{0,1000}Ransom\:Win32\/Sodinokibi.{0,1000} | signature_keyword | Lime-Crypter | An obfuscation tool for .Net + Native files | T1027 - T1045 | TA0005 | N/A | N/A | Defense Evasion | https://github.com/NYAN-x-CAT/Lime-Crypter | 1 | 0 | N/A | N/A | 9 | 6 | 515 | 199 | 2024-04-22T21:31:18Z | 2018-07-14T13:44:58Z | 56250 |
| 289 | *Ransom:Win64* | .{0,1000}Ransom\:Win64.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 56252 |
| 290 | *Ransom:Win64/PrinceRansom.YAA!MTB* | .{0,1000}Ransom\:Win64\/PrinceRansom\.YAA!MTB.{0,1000} | signature_keyword | Prince-Ransomware | Go ransomware utilising ChaCha20 and ECIES encryption. | T1486 - T1489 - T1027 | TA0040 - TA0009 | N/A | N/A | Ransomware | https://github.com/SecDbg/Prince-Ransomware | 1 | 0 | #Avsignature | N/A | 10 | N/A | 56253 | ||||
| 291 | *Ransom_Petya* | .{0,1000}Ransom_Petya.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Ransomware | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 56254 |
| 292 | *Ransom_WCRY* | .{0,1000}Ransom_WCRY.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Ransomware | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 56255 |
| 293 | *REG/KillAV.A* | .{0,1000}REG\/KillAV\.A.{0,1000} | signature_keyword | windows-defender-remover | hacktool used to remove Windows Defender | T1089 - T1562.001 - T1562.004 | TA0005 - TA0040 | N/A | Black Basta | Defense Evasion | https://github.com/ionuttbara/windows-defender-remover | 1 | 0 | #Avsignature | N/A | 10 | 10 | 5266 | 354 | 2025-02-13T20:21:07Z | 2021-08-13T20:44:46Z | 56884 |
| 294 | *RemAdm* | .{0,1000}RemAdm.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword for remote administration tools | T1021 - T1027 - T1046 - T1057 - T1068 - T1072 - T1078 - T1135 - T1485 - T1489 - T1497 - T1547 | TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0011 | N/A | N/A | C2 | N/A | 1 | 0 | #Avsignature | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 56940 |
| 295 | *RemoteAccess:MSIL/AsyncRAT* | .{0,1000}RemoteAccess\:MSIL\/AsyncRAT.{0,1000} | signature_keyword | AsyncRAT-C-Sharp | Open-Source Remote Administration Tool For Windows C# (RAT) | T1021.002 - T1056.001 - T1113 - T1133 - T1041 - T1555 - T1129 - T1564.001 | TA0001 - TA0002 - TA0003 - TA0005 - TA0006 - TA0009 | N/A | TA2541 - APT-C-36 - Earth Berberoka - Operation Comando - TA558 | C2 | https://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp | 1 | 0 | N/A | N/A | 10 | 10 | 2484 | 754 | 2023-10-16T21:41:12Z | 2019-01-19T04:02:26Z | 57002 |
| 296 | *RemoteAccess:Win32/AmmyAdmin* | .{0,1000}RemoteAccess\:Win32\/AmmyAdmin.{0,1000} | signature_keyword | Ammyy Admin | Antiviurs signature_keyword | T1021 - T1219 - T1563 - T1608 | TA0002 - TA0008 - TA0011 - TA0040 | N/A | Anunak | RMM | https://www.ammyy.com | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 57003 |
| 297 | *RemoteAccess:Win32/AnyplaceControl* | .{0,1000}RemoteAccess\:Win32\/AnyplaceControl.{0,1000} | signature_keyword | AnyplaceControl | access your unattended PC from anywhere | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | www.anyplace-control[.]com | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 57004 |
| 298 | *RemoteAccess:Win32/DameWareMiniRemoteControl.B* | .{0,1000}RemoteAccess\:Win32\/DameWareMiniRemoteControl\.B.{0,1000} | signature_keyword | Dameware | Solarwind Dameware Mini Remote Control tool | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.solarwinds.com/dameware-mini-remote-control | 1 | 0 | N/A | Dameware Mini Remote Control | 10 | 10 | N/A | N/A | N/A | N/A | 57005 |
| 299 | *RemoteAccess:Win32/RealVNC* | .{0,1000}RemoteAccess\:Win32\/RealVNC.{0,1000} | signature_keyword | vncviewer | VNCViewer is an RMM tool that has been exploited by attackers to gain unauthorized remote access | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | N/A | RMM | N/A | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 57006 |
| 300 | *RemoteAccess:Win32/TightVNC* | .{0,1000}RemoteAccess\:Win32\/TightVNC.{0,1000} | signature_keyword | tightvnc | TightVNC is a free and Open Source remote desktop software that lets you access and control a computer over the network - often abused by attackers | T1021 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | Scattered Spider* | RMM | https://www.tightvnc.com | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 57007 |
| 301 | *RemoteAccess:Win32/UltraVNC* | .{0,1000}RemoteAccess\:Win32\/UltraVNC.{0,1000} | signature_keyword | UltraVNC | UltraVNC remote access software usage | T1021.001 - T1219 - T1076 - T1563.002 | TA0008 - TA0009 - TA0010 - TA0011 | N/A | Dispossessor - Gamaredon Group - APT39 | RMM | https://uvnc.com/downloads/ultravnc.html | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 57008 |
| 302 | *RemoteAdmin.RemoteUtilities* | .{0,1000}RemoteAdmin\.RemoteUtilities.{0,1000} | signature_keyword | RemoteUtilities | RemoteUtilities Remote Access softwares | T1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | RagnarLocker - MuddyWater - UAC-0050 | RMM | https://www.remoteutilities.com/ | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 57009 |
| 303 | *RiskWare.AdFind* | .{0,1000}RiskWare\.AdFind.{0,1000} | signature_keyword | adfind | adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers are abusing it to gather valuable information about the network environment | T1087 - T1016 - T1482 | TA0007 - TA0008 - TA0043 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 57323 |
| 304 | *RiskWare.DefenderControl* | .{0,1000}RiskWare\.DefenderControl.{0,1000} | signature_keyword | defender-control | disable windows defender permanently | T1562.001 - T1562.004 - T1089 | TA0005 - TA0002 | N/A | LockBit | Defense Evasion | https://www.sordum.org/9480/defender-control-v2-1/ | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 57324 |
| 305 | *Riskware.Hakc2* | .{0,1000}Riskware\.Hakc2.{0,1000} | signature_keyword | hak5 cloudc2 | Cloud C2 makes it easy for pentesters and security teams to deploy and manage Hak5 gear from the cloud | T1021 - T1102 - T1213 | TA0002 - TA0003 - TA0006 - TA0010 - TA0011 | N/A | N/A | C2 | https://shop.hak5.org/products/c2? | 1 | 0 | #Avsignature | N/A | 10 | 9 | N/A | N/A | N/A | N/A | 57325 |
| 306 | *RiskWare.PcHunter* | .{0,1000}RiskWare\.PcHunter.{0,1000} | signature_keyword | PCHunter | PCHunter is a toolkit offering deep access to kernel setting - processes - network and startup configurations. It is designed to detect and remove malware - including rootkits but is also abused by attackers to disable antivirus | T1562 - T1055 - T1070 | TA0005 - TA0004 | N/A | LockBit - Conti - 8BASE - TargetCompany - Hive - Qilin | Defense Evasion | https://www.majorgeeks.com/files/details/pc_hunter.html | 1 | 0 | #Avsignature | N/A | 8 | 10 | N/A | N/A | N/A | N/A | 57326 |
| 307 | *Riskware/AdFind* | .{0,1000}Riskware\/AdFind.{0,1000} | signature_keyword | adfind | adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers are abusing it to gather valuable information about the network environment | T1087 - T1016 - T1482 | TA0007 - TA0008 - TA0043 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 57327 |
| 308 | *Riskware/Hakc2* | .{0,1000}Riskware\/Hakc2.{0,1000} | signature_keyword | hak5 cloudc2 | Cloud C2 makes it easy for pentesters and security teams to deploy and manage Hak5 gear from the cloud | T1021 - T1102 - T1213 | TA0002 - TA0003 - TA0006 - TA0010 - TA0011 | N/A | N/A | C2 | https://shop.hak5.org/products/c2? | 1 | 0 | #Avsignature | N/A | 10 | 9 | N/A | N/A | N/A | N/A | 57328 |
| 309 | *Riskware/Htran* | .{0,1000}Riskware\/Htran.{0,1000} | signature_keyword | htran | proxies connections through intermediate hops and aids users in disguising their true geographical location. It can be used by adversaries to hide their location when interacting with the victim networks | T1055 - T1090 - T1014 | TA0003 - TA0005 - TA0011 | N/A | GALLIUM - APT10 - APT12 - Deep Panda - MenuPass | C2 | https://github.com/HiwinCN/Htran | 1 | 0 | #Avsignature | N/A | 9 | 10 | 256 | 88 | 2021-04-25T09:57:46Z | 2015-12-03T04:54:53Z | 57329 |
| 310 | *Riskware/WebBrowserPassView* | .{0,1000}Riskware\/WebBrowserPassView.{0,1000} | signature_keyword | webBrowserPassView | WebBrowserPassView is a password recovery tool that reveals the passwords stored by the following Web browsers: Internet Explorer (Version 4.0 - 11.0). Mozilla Firefox (All Versions). Google Chrome. Safari. and Opera. This tool can be used to recover your lost/forgotten password of any Website. including popular Web sites. like Facebook. Yahoo. Google. and GMail. as long as the password is stored by your Web Browser. | T1003 - T1555 - T1503 | TA0006 - TA0007 - TA0009 | N/A | Phobos - GoGoogle - 8BASE - Kimsuky - Dispossessor - Loki | Credential Access | https://www.nirsoft.net/utils/web_browser_password.html | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 57330 |
| 311 | *Rootkit.Win64.* | .{0,1000}Rootkit\.Win64\..{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword for ransomware | T1486 - T1489 - T1490 - T1485 - T1487 - T1491 - T1492 - T1488 - T1493 - T1497 | TA0007 - TA0003 - TA0002 - TA0004 - TA0006 - TA0010 | N/A | N/A | Ransomware | https://www.trendmicro.com/content/dam/trendmicro/global/en/research/23/e/blackcat-ransomware-deploys-new-signed-kernel-driver/indicators-blackcat-ransomware-deploys-new-signed-kernel-driver.txt | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 57464 |
| 312 | *SPR/Ammyy.R* | .{0,1000}SPR\/Ammyy\.R.{0,1000} | signature_keyword | Ammyy Admin | Antiviurs signature_keyword | T1021 - T1219 - T1563 - T1608 | TA0002 - TA0008 - TA0011 - TA0040 | N/A | Anunak | RMM | https://www.ammyy.com | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 60013 |
| 313 | *SupportScam:Win32* | .{0,1000}SupportScam\:Win32.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 60665 |
| 314 | *Tojan:Win32/Goodkit* | .{0,1000}Tojan\:Win32\/Goodkit.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 61390 |
| 315 | *Tool.Linux.EarthWorm* | .{0,1000}Tool\.Linux\.EarthWorm.{0,1000} | signature_keyword | EarthWorm | SOCKS v5 proxy service used for data forwarding in complex network environments | T1090.002 - T1573.001 - T1095 | TA0010 - TA0008 - TA0011 | N/A | APT27 - APT15 - Calypso - Earth Lusca - Worok | C2 | https://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a4 | 1 | 0 | #Avsignature | N/A | 10 | 10 | 156 | 177 | 2021-01-26T23:16:49Z | 2019-01-03T05:01:20Z | 61462 |
| 316 | *Tool.SharpSharesNET* | .{0,1000}Tool\.SharpSharesNET.{0,1000} | signature_keyword | SharpShares | Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain | T1046 - T1135 | TA0007 - TA0001 | N/A | Black Basta - BlackSuit - Royal - BianLian - Fog | Discovery | https://github.com/mitchmoser/SharpShares | 1 | 0 | #Avsignature | N/A | 10 | 4 | 351 | 49 | 2021-09-21T08:14:27Z | 2020-09-25T22:35:57Z | 61463 |
| 317 | *Troj/Carbanak-* | .{0,1000}Troj\/Carbanak\-.{0,1000} | signature_keyword | Carbanak | remote backdoor used by a group of the same name (Carbanak). It is intended for espionage - data exfiltration and providing remote access to infected machines | T1021.002 - T1071.001 - T1105 - T1059 - T1003 - T1078 - T1041 | TA0006 - TA0008 - TA0010 - TA0011 | Carbanak | FIN7 - Carbanak | Malware | https://github.com/0x25bit/Updated-Carbanak-Source-with-Plugins | 1 | 0 | #Avsignature | N/A | 10 | 4 | 396 | 223 | 2019-05-01T23:31:35Z | 2019-04-22T21:01:08Z | 61571 |
| 318 | *TROJ_ZIPBOMB.* | .{0,1000}TROJ_ZIPBOMB\..{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 61572 |
| 319 | *Trojan.AddUser* | .{0,1000}Trojan\.AddUser.{0,1000} | signature_keyword | SpoolFool | Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE) | T1068 - T1055 - T1059.003 | TA0004 - TA0005 - TA0003 | Dispossessor | Privilege Escalation | https://github.com/ly4k/SpoolFool | 1 | 0 | #Avsignature | N/A | 9 | 8 | 788 | 160 | 2022-02-09T16:54:09Z | 2022-02-08T17:25:44Z | 61573 | |
| 320 | *Trojan.Carberp.B!g1* | .{0,1000}Trojan\.Carberp\.B!g1.{0,1000} | signature_keyword | Carbanak | remote backdoor used by a group of the same name (Carbanak). It is intended for espionage - data exfiltration and providing remote access to infected machines | T1021.002 - T1071.001 - T1105 - T1059 - T1003 - T1078 - T1041 | TA0006 - TA0008 - TA0010 - TA0011 | Carbanak | FIN7 - Carbanak | Malware | https://github.com/0x25bit/Updated-Carbanak-Source-with-Plugins | 1 | 0 | #Avsignature | N/A | 10 | 4 | 396 | 223 | 2019-05-01T23:31:35Z | 2019-04-22T21:01:08Z | 61574 |
| 321 | *Trojan.HackTool.PowerSploit* | .{0,1000}Trojan\.HackTool\.PowerSploit.{0,1000} | signature_keyword | powerview | PowerView is a PowerShell tool to gain network situational awareness on Windows domains | T1046 - T1087.001 - T1016 | TA0007 - TA0008 - TA0009 | N/A | Dispossessor - MAZE - Conti - XingLocker - Rhysida - BlackByte - Black Basta - MUSTANG PANDA | Discovery | https://github.com/PowerShellMafia/PowerSploit/blob/master/Recon/PowerView.ps1 | 1 | 0 | #Avsignature | N/A | 10 | 10 | 12274 | 4660 | 2020-08-17T23:19:49Z | 2012-05-26T16:08:48Z | 61575 |
| 322 | *Trojan.HTool* | .{0,1000}Trojan\.HTool.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | #Avsignature | hacktool signatures | 10 | 10 | N/A | N/A | N/A | N/A | 61576 |
| 323 | *Trojan.Keylogger.Win32* | .{0,1000}Trojan\.Keylogger\.Win32.{0,1000} | signature_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 61577 | |
| 324 | *Trojan.KillAV* | .{0,1000}Trojan\.KillAV.{0,1000} | signature_keyword | Krueger | remotely killing EDR with WDAC | T1562.001 - T1562.004 - T1218.011 - T1548.002 - T1027 | TA0005 - TA0040 | N/A | N/A | Defense Evasion | https://github.com/logangoins/Krueger | 1 | 0 | #Avsignature | N/A | 9 | 4 | 353 | 42 | 2025-01-06T06:57:14Z | 2024-11-15T20:11:01Z | 61578 |
| 325 | *Trojan.Lazagne* | .{0,1000}Trojan\.Lazagne.{0,1000} | signature_keyword | LaZagne | The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software. | T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001 | TA0006 - TA0009 | N/A | Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT | Credential Access | https://github.com/AlessandroZ/LaZagne | 1 | 1 | #Avsignature | N/A | 10 | 10 | 9941 | 2062 | 2025-04-10T14:24:35Z | 2015-02-16T14:10:02Z | 61579 |
| 326 | *Trojan.Linux* | .{0,1000}Trojan\.Linux.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | #Avsignature | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 61580 |
| 327 | *Trojan.Linux.SSHDoor* | .{0,1000}Trojan\.Linux\.SSHDoor.{0,1000} | signature_keyword | sshdoor | Openssh backdoor | T1059.003 - T1105 - T1071.001 | TA0011 - TA0003 | N/A | FANCY BEAR | Persistence | https://web-assets.esetstatic.com/wls/2018/12/ESET-The_Dark_Side_of_the_ForSSHe.pdf | 1 | 0 | #Avsignature | N/A | 10 | 9 | N/A | N/A | N/A | N/A | 61581 |
| 328 | *Trojan.Meterpreter* | .{0,1000}Trojan\.Meterpreter.{0,1000} | signature_keyword | EternalBlack | EternalRomance exploit implemented by Playbit EternalBlack often used by ransomware group like Dispossessor | T1210 - T1489 - T1105 - T1486 | TA0001 - TA0002 - TA0009 - TA0040 | EternalBlack | Dispossessor | Exploitation tool | https://research.checkpoint.com/2020/graphology-of-an-exploit-playbit/ | 1 | 0 | #Avsignature | CVE-2020-0796 | 10 | 10 | N/A | N/A | N/A | N/A | 61582 |
| 329 | *Trojan.PWS.Stealer.* | .{0,1000}Trojan\.PWS\.Stealer\..{0,1000} | signature_keyword | Blank-Grabber | Stealer with multiple functions | T1003 - T1056 | TA0006 - TA0009 | N/A | N/A | Credential Access | https://github.com/Blank-c/Blank-Grabber | 1 | 0 | N/A | N/A | 10 | 9 | 831 | 220 | 2023-08-06T06:26:16Z | 2022-01-26T12:04:56Z | 61583 |
| 330 | *Trojan.RemoteUtilitiesRAT* | .{0,1000}Trojan\.RemoteUtilitiesRAT.{0,1000} | signature_keyword | RemoteUtilities | RemoteUtilities Remote Access softwares | T1021 - T1083 - T1113 - T1218.007 - T1105 - T1071 - T1090 | TA0003 - TA0008 - TA0011 | N/A | RagnarLocker - MuddyWater - UAC-0050 | RMM | https://www.remoteutilities.com/ | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 61584 |
| 331 | *Trojan.Shell.XZ* | .{0,1000}Trojan\.Shell\.XZ.{0,1000} | signature_keyword | xz | backdoor in upstream xz/liblzma leading to ssh server compromise | T1174 - T1056 - T1210 - T1550 - T1036 - T1077 | TA0005 - TA0006 - TA0003 - TA0008 - TA0009 - TA0011 | N/A | N/A | Malware | https://securelist.com/xz-backdoor-story-part-1/112354/ | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 61586 |
| 332 | *Trojan.Win32.*.* | .{0,1000}Trojan\.Win32\..{0,1000}\..{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 61587 |
| 333 | *Trojan.Win32.KILLAV.WLEAZ* | .{0,1000}Trojan\.Win32\.KILLAV\.WLEAZ.{0,1000} | signature_keyword | Burntcigar KillAV | Scans for process names linked to known antivirus or EDR products - then adds their process IDs to a stack for later termination - often used by attackers | T1089 - T1489 - T1562 | TA0005 | KillAV | Cuba | Malware | https://www.virustotal.com/gui/file/aeb044d310801d546d10b247164c78afde638a90b6ef2f04e1f40170e54dec03?nocache=1 | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 61588 |
| 334 | *Trojan.Win64* | .{0,1000}Trojan\.Win64.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 61589 |
| 335 | *Trojan.WinGo* | .{0,1000}Trojan\.WinGo.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 61590 |
| 336 | *Trojan/Win.Mimikatz* | .{0,1000}Trojan\/Win\.Mimikatz.{0,1000} | signature_keyword | mimikatz | Mimikatz AV signatures | T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003 | TA0004 - TA0006 - TA0003 - TA0008 - TA0009 | N/A | Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx | Exploitation tool | https://github.com/gentilkiwi/mimikatz | 1 | 0 | #Avsignature | N/A | 10 | 10 | 20094 | 3854 | 2024-07-05T17:42:58Z | 2014-04-06T18:30:02Z | 61591 |
| 337 | *Trojan/Win32* | .{0,1000}Trojan\/Win32.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 61592 |
| 338 | *Trojan/Win32.Hakc2* | .{0,1000}Trojan\/Win32\.Hakc2.{0,1000} | signature_keyword | hak5 cloudc2 | Cloud C2 makes it easy for pentesters and security teams to deploy and manage Hak5 gear from the cloud | T1021 - T1102 - T1213 | TA0002 - TA0003 - TA0006 - TA0010 - TA0011 | N/A | N/A | C2 | https://shop.hak5.org/products/c2? | 1 | 0 | #Avsignature | N/A | 10 | 9 | N/A | N/A | N/A | N/A | 61593 |
| 339 | *Trojan/Win64* | .{0,1000}Trojan\/Win64.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 61594 |
| 340 | *Trojan:MacOS* | .{0,1000}Trojan\:MacOS.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 61595 |
| 341 | *Trojan:MSIL/Dothetuk.* | .{0,1000}Trojan\:MSIL\/Dothetuk\..{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword for xeno rat client.exe | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 61596 |
| 342 | *Trojan:MSIL/GodPotato* | .{0,1000}Trojan\:MSIL\/GodPotato.{0,1000} | signature_keyword | DeadPotato | DeadPotato is a windows privilege escalation utility from the Potato family of exploits leveraging the SeImpersonate right to obtain SYSTEM privileges | T1134.001 - T1068 - T1055 - T1546.015 | TA0004 - TA0006 - TA0011 | N/A | N/A | Privilege Escalation | https://github.com/lypd0/DeadPotato | 1 | 1 | N/A | N/A | 10 | 4 | 382 | 45 | 2024-08-17T06:08:29Z | 2024-07-31T01:08:30Z | 61597 |
| 343 | *Trojan:PowerShell* | .{0,1000}Trojan\:PowerShell.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | trojan powershell signatures | 10 | 10 | N/A | N/A | N/A | N/A | 61598 |
| 344 | *Trojan:PowerShell/BatLoader* | .{0,1000}Trojan\:PowerShell\/BatLoader.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 61599 |
| 345 | *Trojan:PowerShell/ReverseShell.* | .{0,1000}Trojan\:PowerShell\/ReverseShell\..{0,1000} | signature_keyword | reverse-shell-generator | Reverse Shell Generator | T1105 - T1071.004 - T1016 - T1090 - T1029 - T1041 | TA0011 - TA0010- TA0002 | N/A | N/A | C2 | https://github.com/0dayCTF/reverse-shell-generator | 1 | 1 | N/A | N/A | 10 | 10 | 3312 | 702 | 2024-10-31T22:38:04Z | 2021-02-27T00:53:13Z | 61600 |
| 346 | *Trojan:Python/BatLoader* | .{0,1000}Trojan\:Python\/BatLoader.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 61601 |
| 347 | *Trojan:Win32* | .{0,1000}Trojan\:Win32.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 61602 |
| 348 | *Trojan:Win32/Batloader* | .{0,1000}Trojan\:Win32\/Batloader.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 61603 |
| 349 | *Trojan:Win32/Casdet!rfn* | .{0,1000}Trojan\:Win32\/Casdet!rfn.{0,1000} | signature_keyword | Venom | Venom - A Multi-hop Proxy for Penetration Testers | T1090 | TA0005 - TA0011 | N/A | N/A | Defense Evasion | https://github.com/Dliv3/Venom | 1 | 0 | #Avsignature | N/A | 10 | 10 | 2070 | 357 | 2022-05-11T03:13:20Z | 2019-01-13T07:35:29Z | 61604 |
| 350 | *Trojan:Win32/Ceevee* | .{0,1000}Trojan\:Win32\/Ceevee.{0,1000} | signature_keyword | Invoke-TheHash | Invoke-TheHash contains PowerShell functions for performing pass the hash WMI and SMB tasks. WMI and SMB connections are accessed through the .NET TCPClient. Authentication is performed by passing an NTLM hash into the NTLMv2 authentication protocol. Local administrator privilege is not required client-side. -signature observed with Invoke-SMBExec.ps1 | T1028 - T1047 - T1075 - T1078 | TA0003 - TA0004 - TA0006 | N/A | FoxKitten | Lateral Movement | https://github.com/Kevin-Robertson/Invoke-TheHash | 1 | 0 | N/A | N/A | 10 | 10 | 1569 | 308 | 2018-12-09T15:38:36Z | 2017-01-03T01:05:39Z | 61605 |
| 351 | *Trojan:Win32/Eqtonex!rfn* | .{0,1000}Trojan\:Win32\/Eqtonex!rfn.{0,1000} | signature_keyword | Smbtouch-Scanner | Smbtouch detect whether the target is vulnerable of one of these vulnerabilities: ETERNALBLUE - ETERNALCHAMPION - ETERNALROMANCE - ETERNALSYNERGY | T1210 - T1046 - T1133 | TA0007 - TA0043 - TA0008 | N/A | APT15 - Turla | Lateral Movement | https://github.com/3gstudent/Smbtouch-Scanner | 1 | 0 | #Avsignature | N/A | 10 | 2 | 140 | 66 | 2021-04-17T01:42:06Z | 2017-04-21T01:38:55Z | 61606 |
| 352 | *Trojan:Win32/EugenLoader* | .{0,1000}Trojan\:Win32\/EugenLoader.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 61607 |
| 353 | *Trojan:Win32/GhostSocks* | .{0,1000}Trojan\:Win32\/GhostSocks.{0,1000} | signature_keyword | ghostsocks | SOCKS5 proxy based on lightsocks | T1090.002 - T1090 | TA0005 - TA0008 | Lumma Stealer | N/A | Defense Evasion | https://github.com/LemonSaaS/ghostsocks | 1 | 0 | #Avsignature | N/A | 7 | 1 | 2 | 1 | 2017-11-14T16:56:05Z | 2017-11-13T03:38:57Z | 61608 |
| 354 | *Trojan:Win32/Gozi* | .{0,1000}Trojan\:Win32\/Gozi.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 61609 |
| 355 | *Trojan:Win32/IceId* | .{0,1000}Trojan\:Win32\/IceId.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 61610 |
| 356 | *Trojan:Win32/KillAV.SA* | .{0,1000}Trojan\:Win32\/KillAV\.SA.{0,1000} | signature_keyword | Burntcigar KillAV | Scans for process names linked to known antivirus or EDR products - then adds their process IDs to a stack for later termination - often used by attackers | T1089 - T1489 - T1562 | TA0005 | KillAV | Cuba | Malware | https://www.virustotal.com/gui/file/aeb044d310801d546d10b247164c78afde638a90b6ef2f04e1f40170e54dec03?nocache=1 | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 61611 |
| 357 | *Trojan:Win32/Malagent!MSR* | .{0,1000}Trojan\:Win32\/Malagent!MSR.{0,1000} | signature_keyword | PipeViewer | A tool that shows detailed information about named pipes in Windows | T1022.002 - T1056.002 | TA0005 - TA0009 | N/A | N/A | discovery | https://github.com/cyberark/PipeViewer | 1 | 0 | N/A | N/A | 5 | 7 | 620 | 55 | 2024-11-15T09:55:35Z | 2022-12-22T12:35:34Z | 61612 |
| 358 | *Trojan:Win32/RemoteSysDisc.E!adfind* | .{0,1000}Trojan\:Win32\/RemoteSysDisc\.E!adfind.{0,1000} | signature_keyword | adfind | adfind is a command-line tool often used by administrators for Active Directory queries. However. attackers are abusing it to gather valuable information about the network environment | T1087 - T1016 - T1482 | TA0007 - TA0008 - TA0043 | N/A | APT29 - Akira - Black Basta - BlackSuit - Conti - COZY BEAR - Dagon Locker - Diavol - FIN6 - FIN7 - INC Ransom - LockBit - MAZE - MUSTANG PANDA - NetWalker - Nokoyawa - PLAY - Quantum - REvil - Royal - Ryuk - TA505 - TRAVELING SPIDER - Unit 29155 - WIZARD SPIDER - Wizard Spider - XingLocker - menuPass - Dispossessor | Discovery | https://www.virustotal.com/gui/file/484dd00e85c033fbfd506b956ac0acd29b30f239755ed753a2788a842425b384/behavior | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 61613 |
| 359 | *Trojan:Win32/Rozena.HNB!MTB* | .{0,1000}Trojan\:Win32\/Rozena\.HNB!MTB.{0,1000} | signature_keyword | BlockEtw | .Net Assembly to block ETW telemetry in current process | T1055.001 - T1562.001 | TA0005 | N/A | N/A | Defense Evasion | https://github.com/Soledge/BlockEtw | 1 | 0 | #Avsignature | N/A | 10 | 1 | 78 | 19 | 2020-05-14T19:24:49Z | 2020-05-14T02:40:50Z | 61614 |
| 360 | *Trojan:Win32/Sabsik.TE.B!ml* | .{0,1000}Trojan\:Win32\/Sabsik\.TE\.B!ml.{0,1000} | signature_keyword | sharphound | C# Data Collector for BloodHound | T1087.001 - T1087.002 - T1482 - T1016 - T1018 - T1046 | TA0007 - TA0043 - TA0005 - TA0042 | Dispossessor - Trickbot - Dridex - Locky - Uyghur - BlackCat - ALPHV - Defray777 - RansomExx | APT20 - TA505 - APT29 - GOLD DUPONT - Scattered Spider - UNC3944 - TA2101 - Wizard Spider - Grim Spider - Lunar Spider - Dispossessor | Discovery | https://github.com/BloodHoundAD/SharpHound | 1 | 0 | #Avsignature | N/A | N/A | 10 | 904 | 195 | 2025-04-18T20:45:04Z | 2021-07-12T17:07:04Z | 61615 |
| 361 | *Trojan:Win32/Smokeloader* | .{0,1000}Trojan\:Win32\/Smokeloader.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 61616 |
| 362 | *Trojan:Win32/Trickbot* | .{0,1000}Trojan\:Win32\/Trickbot.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 61617 |
| 363 | *Trojan:Win32/TrickbotCrypt* | .{0,1000}Trojan\:Win32\/TrickbotCrypt.{0,1000} | signature_keyword | merlin | Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT) | T1219 - T1105 - T1071 - T1090 - T1055 - T1047 | TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011 | N/A | N/A | C2 | https://github.com/Ne0nd0g/merlin | 1 | 0 | N/A | N/A | 10 | 10 | 5221 | 826 | 2025-04-17T15:08:42Z | 2017-01-06T11:18:20Z | 61618 |
| 364 | *Trojan:Win64* | .{0,1000}Trojan\:Win64.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 61620 |
| 365 | *Trojan:Win64/CobaltStrike* | .{0,1000}Trojan\:Win64\/CobaltStrike.{0,1000} | signature_keyword | S-inject | Windows injection of x86/x64 DLL and Shellcode | T1055 - T1027 | TA0002 - TA0005 - TA0003 | N/A | N/A | Defense Evasion | https://github.com/Joe1sn/S-inject | 1 | 0 | N/A | N/A | 10 | 4 | 313 | 45 | 2025-04-06T08:06:39Z | 2024-02-05T04:39:10Z | 61621 |
| 366 | *Trojan:Win64/CryptInject.XY!MTB* | .{0,1000}Trojan\:Win64\/CryptInject\.XY!MTB.{0,1000} | signature_keyword | POC | CVE-2024-6768: Improper validation of specified quantity in input produces an unrecoverable state in CLFS.sys causing a BSoD | T1499 - T1485 | TA0043 - TA0042 - TA0005 | N/A | N/A | Impact | https://github.com/fortra/CVE-2024-6768 | 1 | 0 | #Avsignature | N/A | 10 | 1 | 16 | 4 | 2024-08-12T20:48:52Z | 2024-07-18T07:52:46Z | 61622 |
| 367 | *Trojan:Win64/IcedID* | .{0,1000}Trojan\:Win64\/IcedID.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 61623 |
| 368 | *Trojan:Win64/IceId* | .{0,1000}Trojan\:Win64\/IceId.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 61624 |
| 369 | *Trojan:Win64/Lumma* | .{0,1000}Trojan\:Win64\/Lumma.{0,1000} | signature_keyword | Lumma Stealer | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 61625 |
| 370 | *Trojan:Win64/Meterpreter* | .{0,1000}Trojan\:Win64\/Meterpreter.{0,1000} | signature_keyword | EternalBlack | EternalRomance exploit implemented by Playbit EternalBlack often used by ransomware group like Dispossessor | T1210 - T1489 - T1105 - T1486 | TA0001 - TA0002 - TA0009 - TA0040 | EternalBlack | Dispossessor | Exploitation tool | https://research.checkpoint.com/2020/graphology-of-an-exploit-playbit/ | 1 | 0 | #Avsignature | CVE-2020-0796 | 10 | 10 | N/A | N/A | N/A | N/A | 61626 |
| 371 | *Trojan:Win64/r77RootKit* | .{0,1000}Trojan\:Win64\/r77RootKit.{0,1000} | signature_keyword | r77-rootkit | Fileless ring 3 rootkit with installer and persistence that hides processes, files, network connections | T1014 - T1055 - T1055.013 - T1060 - T1106 - T1070.009 | TA0005 - TA0003 | N/A | N/A | Persistence | https://github.com/bytecode77/r77-rootkit | 1 | 0 | N/A | N/A | 10 | 10 | 1884 | 425 | 2025-03-25T17:59:20Z | 2017-12-17T13:04:14Z | 61627 |
| 372 | *TrojanDownloader:Java/GodzillaWebShell* | .{0,1000}TrojanDownloader\:Java\/GodzillaWebShell.{0,1000} | signature_keyword | Godzilla | Webshell Manager Tool that provide request proxy, server info, RCE shell, terminal execution, memory shell, port forwarding, and MSF bind/reverse shell capabilities. | T1100 - T1018 - T1059 - T1090 - T1021 - T1205 - T1105 - T1568 | TA0001 - TA0002 - TA0003 - TA0011 | N/A | N/A | C2 | https://github.com/BeichenDream/Godzilla | 1 | 0 | N/A | N/A | 10 | 10 | 4096 | 551 | 2024-07-17T07:56:35Z | 2020-08-17T17:27:56Z | 61628 |
| 373 | *TrojanDownloader:Java/GodzillaWebShell.C* | .{0,1000}TrojanDownloader\:Java\/GodzillaWebShell\.C.{0,1000} | signature_keyword | Godzilla | Webshell Manager Tool that provide request proxy, server info, RCE shell, terminal execution, memory shell, port forwarding, and MSF bind/reverse shell capabilities. | T1100 - T1018 - T1059 - T1090 - T1021 - T1205 - T1105 - T1568 | TA0001 - TA0002 - TA0003 - TA0011 | N/A | N/A | C2 | https://github.com/BeichenDream/Godzilla | 1 | 0 | N/A | N/A | 10 | 10 | 4096 | 551 | 2024-07-17T07:56:35Z | 2020-08-17T17:27:56Z | 61629 |
| 374 | *TrojanDownloader:PowerShell/EugenLoader* | .{0,1000}TrojanDownloader\:PowerShell\/EugenLoader.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 61630 |
| 375 | *TrojanDownloader:PowerShell/Malgent* | .{0,1000}TrojanDownloader\:PowerShell\/Malgent.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 61631 |
| 376 | *TrojanDropper:PowerShell/* | .{0,1000}TrojanDropper\:PowerShell\/.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 61632 |
| 377 | *TrojanDropper:Win32* | .{0,1000}TrojanDropper\:Win32.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 61633 |
| 378 | *Trojan-PSW.Win64.Mimilove* | .{0,1000}Trojan\-PSW\.Win64\.Mimilove.{0,1000} | signature_keyword | mimikatz | Mimikatz AV signatures | T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003 | TA0004 - TA0006 - TA0003 - TA0008 - TA0009 | N/A | Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx | Exploitation tool | https://github.com/gentilkiwi/mimikatz | 1 | 0 | #Avsignature | N/A | 10 | 10 | 20094 | 3854 | 2024-07-05T17:42:58Z | 2014-04-06T18:30:02Z | 61634 |
| 379 | *TrojanSpy.Win64* | .{0,1000}TrojanSpy\.Win64.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 61635 |
| 380 | *TrojanSpy:MSIL/JSSLoader* | .{0,1000}TrojanSpy\:MSIL\/JSSLoader.{0,1000} | signature_keyword | Antivirus Signature | antivirus signatures | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 61636 |
| 381 | *TrojanSpy:MSIL/JSSLoader* | .{0,1000}TrojanSpy\:MSIL\/JSSLoader.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 61637 |
| 382 | *TrojanSpy:Win32/Tinukebot* | .{0,1000}TrojanSpy\:Win32\/Tinukebot.{0,1000} | signature_keyword | HVNC | Standalone HVNC Client & Server Coded in C++ (Modified Tinynuke) | T1021.005 - T1071 - T1563.002 - T1219 | TA0001 - TA0002 - TA0008 | N/A | N/A | RMM | https://github.com/Meltedd/HVNC | 1 | 0 | N/A | antivirus signature | 10 | 5 | 445 | 133 | 2025-03-27T21:20:10Z | 2021-09-03T17:34:44Z | 61638 |
| 383 | *Unix.Malware.Sliver-* | .{0,1000}Unix\.Malware\.Sliver\-.{0,1000} | signature_keyword | sliver | Sliver is an open source cross-platform adversary emulation/red team framework | T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012 | TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043 | N/A | AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta | C2 | https://github.com/gsmith257-cyber/better-sliver | 1 | 0 | #Avsignature | N/A | 10 | 10 | 98 | 10 | 2024-07-22T12:32:16Z | 2023-12-12T02:04:36Z | 61876 |
| 384 | *VBS.Revbshell* | .{0,1000}VBS\.Revbshell.{0,1000} | signature_keyword | revbshell | ReVBShell - Reverse VBS Shell | T1059.005 - T1573.001 - T1105 | TA0011 - TA0010 | N/A | N/A | C2 | https://github.com/bitsadmin/revbshell | 1 | 0 | #Avsignature | N/A | 10 | 10 | 81 | 27 | 2019-10-08T12:00:05Z | 2017-02-19T18:58:52Z | 62142 |
| 385 | *VirTool*RemoteExec* | .{0,1000}VirTool.{0,1000}RemoteExec.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Lateral Movement | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 62202 |
| 386 | *VirTool:Linux/Sliver* | .{0,1000}VirTool\:Linux\/Sliver.{0,1000} | signature_keyword | sliver | Sliver is an open source cross-platform adversary emulation/red team framework | T1105 - T1071.004 - T1021 - T1573.001 - T1132 - T1095 - T1041 - T1074.002 - T1568.002 - T1204 - T1055.012 | TA0001 - TA0002 - TA0003 - TA0004 - TA0005 - TA0006 - TA0007 - TA0008 - TA0009 - TA0010 - TA0011 - TA0040 - TA0042 - TA0043 | N/A | AvosLocker - APT29 - Cinnamon Tempest - GOLD CABIN - COZY BEAR - Black Basta | C2 | https://github.com/gsmith257-cyber/better-sliver | 1 | 0 | #Avsignature | N/A | 10 | 10 | 98 | 10 | 2024-07-22T12:32:16Z | 2023-12-12T02:04:36Z | 62203 |
| 387 | *VirTool:MSIL* | .{0,1000}VirTool\:MSIL.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 62204 |
| 388 | *VirTool:MSIL/Aikaantivm.GG!MTB* | .{0,1000}VirTool\:MSIL\/Aikaantivm\.GG!MTB.{0,1000} | signature_keyword | PEASS | PEASS - Privilege Escalation Awesome Scripts SUITE | T1068 - T1055 - T1053 - T1059 - T1134 - T1216 - T1003 - T1187 - T1548.001 - T1548.002 | TA0002 - TA0004 - TA0006 - TA0008 - TA0007 - TA0005 | N/A | Scattered Spider* - PLAY - EMBER BEAR - COZY BEAR - Dispossessor | Privilege Escalation | https://github.com/carlospolop/PEASS-ng | 1 | 0 | N/A | N/A | N/A | 10 | 17347 | 3209 | 2025-04-01T04:29:00Z | 2019-01-13T19:58:24Z | 62205 |
| 389 | *VirTool:MSIL/DarkStealer.A!MTB* | .{0,1000}VirTool\:MSIL\/DarkStealer\.A!MTB.{0,1000} | signature_keyword | Godzilla | Webshell Manager Tool that provide request proxy, server info, RCE shell, terminal execution, memory shell, port forwarding, and MSF bind/reverse shell capabilities. | T1100 - T1018 - T1059 - T1090 - T1021 - T1205 - T1105 - T1568 | TA0001 - TA0002 - TA0003 - TA0011 | N/A | N/A | C2 | https://github.com/BeichenDream/Godzilla | 1 | 0 | N/A | N/A | 10 | 10 | 4096 | 551 | 2024-07-17T07:56:35Z | 2020-08-17T17:27:56Z | 62206 |
| 390 | *VirTool:MSIL/Kanuko.A!MTB* | .{0,1000}VirTool\:MSIL\/Kanuko\.A!MTB.{0,1000} | signature_keyword | SharpEDRChecker | Checks for the presence of known defensive products such as AV/EDR and logging tools | T1083 - T1518.001 - T1063 | TA0007 - TA0005 | N/A | N/A | Discovery | https://github.com/PwnDexter/SharpEDRChecker | 1 | 0 | N/A | N/A | 8 | 8 | 706 | 98 | 2023-10-09T11:17:49Z | 2020-06-16T10:25:00Z | 62207 |
| 391 | *VirTool:MSIL/Sabakz.A!MTB* | .{0,1000}VirTool\:MSIL\/Sabakz\.A!MTB.{0,1000} | signature_keyword | Sandman | Sandman is a NTP based backdoor for red team engagements in hardened networks. | T1105 - T1027 - T1071.001 | TA0011 - TA0005 | N/A | N/A | Persistence | https://github.com/Idov31/Sandman | 1 | 0 | #Avsignature | N/A | 10 | 8 | 785 | 108 | 2024-03-31T17:40:15Z | 2022-08-21T11:04:45Z | 62208 |
| 392 | *VirTool:MSIL/Spfolz.A!MTB | .{0,1000}VirTool\:MSIL\/Spfolz\.A!MTB | signature_keyword | SpoolFool | Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE) | T1068 - T1055 - T1059.003 | TA0004 - TA0005 - TA0003 | Dispossessor | Privilege Escalation | https://github.com/ly4k/SpoolFool | 1 | 0 | #Avsignature | N/A | 9 | 8 | 788 | 160 | 2022-02-09T16:54:09Z | 2022-02-08T17:25:44Z | 62209 | |
| 393 | *VirTool:PowerShell/Dipadz.* | .{0,1000}VirTool\:PowerShell\/Dipadz\..{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 62210 |
| 394 | *VirTool:PowerShell/Dipadz.A!MTB* | .{0,1000}VirTool\:PowerShell\/Dipadz\.A!MTB.{0,1000} | signature_keyword | Amnesiac | Amnesiac is a post-exploitation framework entirely written in PowerShell and designed to assist with Lateral Movement within Active Directory environments - signatureobserved for dpapi.ps1and HiveDump.ps1 | T1021.002 - T1550.002 | TA0008 | N/A | Black Basta | Framework | https://github.com/Leo4j/Amnesiac | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 63 | 2025-03-18T09:32:04Z | 2023-10-31T15:06:25Z | 62211 |
| 395 | *VirTool:Python/RemoteSvcExecute.A* | .{0,1000}VirTool\:Python\/RemoteSvcExecute\.A.{0,1000} | signature_keyword | susinternals | python implementation of PSExec native service implementation | T1569.002 - T1021.002 - T1035 | TA0002 - TA0004 - TA0008 - TA0003 | N/A | N/A | Lateral Movement | https://github.com/sensepost/susinternals | 1 | 0 | #Avsignature | N/A | 7 | 2 | 194 | 18 | 2025-02-11T09:34:50Z | 2025-02-10T07:40:36Z | 62213 |
| 396 | *VirTool:Python/Wraitratz.A* | .{0,1000}VirTool\:Python\/Wraitratz\.A.{0,1000} | signature_keyword | wraith | A free and open-source, modular Remote Administration Tool (RAT) / Payload Dropper written in Go(lang) with a flexible command and control (C2) system. | T1059 - T1204 - T1105 - T1136 - T1021 | TA0002 - TA0003 - TA0011 | N/A | N/A | C2 | https://github.com/wraith-labs/wraith | 1 | 1 | N/A | N/A | 10 | 10 | 223 | 49 | 2023-12-03T22:16:27Z | 2020-01-23T17:09:23Z | 62214 |
| 397 | *VirTool:Win32* | .{0,1000}VirTool\:Win32.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 62215 |
| 398 | *VirTool:Win32/RemoteExec* | .{0,1000}VirTool\:Win32\/RemoteExec.{0,1000} | signature_keyword | psexec | PsExec is a legitimate Microsoft tool for remote administration. However. attackers can misuse it to execute malicious commands or software on other network machines. install persistent threats. and evade some security systems. | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Lateral Movement | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | #Avsignature | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 62216 |
| 399 | *VirTool:Win32/RemoteExec* | .{0,1000}VirTool\:Win32\/RemoteExec.{0,1000} | signature_keyword | Antivirus Signature | AV signature often associated with C2 communications (cobaltstrike for example) | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 62217 |
| 400 | *VirTool:Win64/Backstab* | .{0,1000}VirTool\:Win64\/Backstab.{0,1000} | signature_keyword | Backstab | A tool to kill antimalware protected processes | T1562.001 - T1569 - T1059 | TA0005 - TA0040 - TA0002 | N/A | Black Basta - LockBit | Defense Evasion | https://github.com/Yaxser/Backstab | 1 | 0 | #Avsignature | N/A | 10 | 10 | 1435 | 244 | 2021-06-19T20:01:52Z | 2021-06-15T16:02:11Z | 62218 |
| 401 | *VirTool:Win64/RemoteExec* | .{0,1000}VirTool\:Win64\/RemoteExec.{0,1000} | signature_keyword | psexec | PsExec is a legitimate Microsoft tool for remote administration. However. attackers can misuse it to execute malicious commands or software on other network machines. install persistent threats. and evade some security systems. | T1136.002 - T1543.003 - T1570 - T1021.002 - T1569.002 | TA0002 - TA0004 - TA0008 - TA0011 | N/A | Turla - Chimera - APT1 - Thrip - Moses Staff - BlackTech - Cleaver - DarkVishnya - Sandworm Team - HAFNIUM - Akira - APT39 - FIN5 - FIN6 - Indrik Spider - TEMP.Veles - Kimsuky - GALLIUM - APT29 - Carbanak - Leafminer - FIN8 - Fox Kitten - Dragonfly - Magic Hound - OilRig - Cobalt Group - Naikon - Threat Group-1314 - menuPass - Wizard Spider - ALLANITE - APT20 - APT27 - Antlion - BOSS SPIDER - Common Raven - ENERGETIC BEAR - FIN7 - GOBLIN PANDA - PowerPool - INDRIK SPIDER - WIZARD SPIDER - TINY SPIDER - TA2101 - TRAVELING SPIDER - Common Raven - Antlion - Scattered Spider - COZY BEAR - EMBER BEAR - BERSERK BEAR - Gamaredon - Dispossessor | Lateral Movement | https://learn.microsoft.com/fr-fr/sysinternals/downloads/psexec | 1 | 0 | #Avsignature | greyware tool - risks of False positive ! | 10 | 10 | N/A | N/A | N/A | N/A | 62219 |
| 402 | *VNCPassView.exe* | .{0,1000}VNCPassView\.exe.{0,1000} | signature_keyword | VNCPassView | recover the passwords stored by the VNC tool | T1003 - T1555 - T1081 | TA0006 - TA0007 | N/A | GoGoogle - 8BASE | Credential Access | https://www.nirsoft.net/utils/vnc_password.html | 1 | 1 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 62251 |
| 403 | *W32/CubaHR_KillAV* | .{0,1000}W32\/CubaHR_KillAV.{0,1000} | signature_keyword | Burntcigar KillAV | Scans for process names linked to known antivirus or EDR products - then adds their process IDs to a stack for later termination - often used by attackers | T1089 - T1489 - T1562 | TA0005 | KillAV | Cuba | Malware | https://www.virustotal.com/gui/file/aeb044d310801d546d10b247164c78afde638a90b6ef2f04e1f40170e54dec03?nocache=1 | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 62332 |
| 404 | *W32/EarthWorm* | .{0,1000}W32\/EarthWorm.{0,1000} | signature_keyword | Termite | Termite rootit abused by threat actors | T1014 - T1069 - T1055 | TA0005 - TA0003 - TA0004 | Operation TunnelSnake | Whitefly | Persistence | https://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a4 | 1 | 0 | #Avsignature | N/A | 10 | 10 | 156 | 177 | 2021-01-26T23:16:49Z | 2019-01-03T05:01:20Z | 62333 |
| 405 | *W32/KeyLogger.PMU!tr.spy* | .{0,1000}W32\/KeyLogger\.PMU!tr\.spy.{0,1000} | signature_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 62334 | |
| 406 | *W64/Merlin.T!tr* | .{0,1000}W64\/Merlin\.T!tr.{0,1000} | signature_keyword | merlin-agent | Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT) | T1219 - T1105 - T1071 - T1090 - T1055 - T1047 | TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011 | N/A | N/A | C2 | https://github.com/Ne0nd0g/merlin-agent | 1 | 0 | N/A | N/A | 10 | 10 | 193 | 62 | 2025-04-16T14:12:16Z | 2020-07-17T20:47:56Z | 62340 |
| 407 | *Win.Exploit.Exploitx-9942911-0* | .{0,1000}Win\.Exploit\.Exploitx\-9942911\-0.{0,1000} | signature_keyword | SpoolFool | Exploit for CVE-2022-21999 - Windows Print Spooler Elevation of Privilege Vulnerability (LPE) | T1068 - T1055 - T1059.003 | TA0004 - TA0005 - TA0003 | Dispossessor | Privilege Escalation | https://github.com/ly4k/SpoolFool | 1 | 0 | #Avsignature | N/A | 9 | 8 | 788 | 160 | 2022-02-09T16:54:09Z | 2022-02-08T17:25:44Z | 62610 | |
| 408 | *Win.NOODLERAT* | .{0,1000}Win\.NOODLERAT.{0,1000} | signature_keyword | NoodleRAT | AV signature of noodlerat malware | T1059.004 - T1078 - T1105 - T1100 - T1547.006 | TA0003 - TA0005 - TA0010 - TA0011 | N/A | N/A | Malware | https://www.trendmicro.com/en_us/research/24/f/noodle-rat-reviewing-the-new-backdoor-used-by-chinese-speaking-g.html | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 62611 |
| 409 | *Win.Packed.Immirat-* | .{0,1000}Win\.Packed\.Immirat\-.{0,1000} | signature_keyword | Imminent-Monitor | used for malicious activities such as keylogging - screen capture and remote control of infected systems. | T1012 - T1059 - T1105 - T1071 - T1124 - T1041 | TA0005 - TA0003 - TA0011 - TA0009 | Imminent RAT | PROMETHIUM | Malware | https://github.com/Indestructible7/Imminent-Monitor-v3.9 | 1 | 0 | #Avsignature | N/A | 8 | 1 | 4 | 2 | 2022-11-04T18:48:14Z | 2022-11-04T18:15:20Z | 62612 |
| 410 | *Win.Packed.Seatbelt-* | .{0,1000}Win\.Packed\.Seatbelt\-.{0,1000} | signature_keyword | seatbelt | Seatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many others | T1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518 | TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011 | N/A | Dispossessor | Persistence | https://github.com/GhostPack/Seatbelt | 1 | 0 | #Avsignature | N/A | 10 | 10 | 4047 | 722 | 2025-01-10T20:12:49Z | 2018-07-24T17:38:51Z | 62613 |
| 411 | *Win.Tool.Disabledefender* | .{0,1000}Win\.Tool\.Disabledefender.{0,1000} | signature_keyword | defender-control | disable windows defender permanently | T1562.001 - T1562.004 - T1089 | TA0005 - TA0002 | N/A | LockBit | Defense Evasion | https://www.sordum.org/9480/defender-control-v2-1/ | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 62615 |
| 412 | *Win.Tool.Earthworm-* | .{0,1000}Win\.Tool\.Earthworm\-.{0,1000} | signature_keyword | EarthWorm | SOCKS v5 proxy service used for data forwarding in complex network environments | T1090.002 - T1573.001 - T1095 | TA0010 - TA0008 - TA0011 | N/A | APT27 - APT15 - Calypso - Earth Lusca - Worok | C2 | https://github.com/rootkiter/Binary-files/tree/212c43b40e2e4c2e2703400caaa732557b6080a4 | 1 | 0 | #Avsignature | N/A | 10 | 10 | 156 | 177 | 2021-01-26T23:16:49Z | 2019-01-03T05:01:20Z | 62616 |
| 413 | *Win.Tool.Sharpdump* | .{0,1000}Win\.Tool\.Sharpdump.{0,1000} | signature_keyword | SharpDump | SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality. | T1003 - T1055 - T1070 | TA0006 - TA0005 - TA0008 | N/A | Avaddon | Credential Access | https://github.com/GhostPack/SharpDump | 1 | 0 | #Avsignature | N/A | 10 | 7 | 664 | 130 | 2019-02-07T02:52:20Z | 2018-07-24T17:42:19Z | 62617 |
| 414 | *Win.Trojan.Powercat-* | .{0,1000}Win\.Trojan\.Powercat\-.{0,1000} | signature_keyword | powercat | Netcat - The powershell version | T1571 - T1048.003 - T1095 | TA0042 - TA0011 | N/A | N/A | C2 | https://github.com/besimorhino/powercat | 1 | 0 | #Avsignature | N/A | 10 | 10 | 2229 | 482 | 2024-03-05T18:05:07Z | 2014-08-21T14:38:46Z | 62618 |
| 415 | *Win32.LaZagne* | .{0,1000}Win32\.LaZagne.{0,1000} | signature_keyword | LaZagne | The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software. | T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001 | TA0006 - TA0009 | N/A | Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT | Credential Access | https://github.com/AlessandroZ/LaZagne | 1 | 1 | #Avsignature | N/A | 10 | 10 | 9941 | 2062 | 2025-04-10T14:24:35Z | 2015-02-16T14:10:02Z | 62626 |
| 416 | *Win32.Mimikatz* | .{0,1000}Win32\.Mimikatz.{0,1000} | signature_keyword | mimikatz | Mimikatz AV signatures | T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003 | TA0004 - TA0006 - TA0003 - TA0008 - TA0009 | N/A | Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx | Exploitation tool | https://github.com/gentilkiwi/mimikatz | 1 | 0 | #Avsignature | N/A | 10 | 10 | 20094 | 3854 | 2024-07-05T17:42:58Z | 2014-04-06T18:30:02Z | 62627 |
| 417 | *Win32.PUA.AmmyyAdmin* | .{0,1000}Win32\.PUA\.AmmyyAdmin.{0,1000} | signature_keyword | Ammyy Admin | Antiviurs signature_keyword | T1021 - T1219 - T1563 - T1608 | TA0002 - TA0008 - TA0011 - TA0040 | N/A | Anunak | RMM | N/A | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 62629 |
| 418 | *Win32.Trojan* | .{0,1000}Win32\.Trojan.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 62630 |
| 419 | *Win32/DefenderRmv* | .{0,1000}Win32\/DefenderRmv.{0,1000} | signature_keyword | windows-defender-remover | hacktool used to remove Windows Defender | T1089 - T1562.001 - T1562.004 | TA0005 - TA0040 | N/A | Black Basta | Defense Evasion | https://github.com/ionuttbara/windows-defender-remover | 1 | 0 | #Avsignature | N/A | 10 | 10 | 5266 | 354 | 2025-02-13T20:21:07Z | 2021-08-13T20:44:46Z | 62631 |
| 420 | *Win32/Goodkit* | .{0,1000}Win32\/Goodkit.{0,1000} | signature_keyword | Antivirus Signature | antivirus signatures | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 62633 |
| 421 | *Win32/HackTool.Hucline.F* | .{0,1000}Win32\/HackTool\.Hucline\.F.{0,1000} | signature_keyword | htran | proxies connections through intermediate hops and aids users in disguising their true geographical location. It can be used by adversaries to hide their location when interacting with the victim networks | T1055 - T1090 - T1014 | TA0003 - TA0005 - TA0011 | N/A | GALLIUM - APT10 - APT12 - Deep Panda - MenuPass | C2 | https://github.com/HiwinCN/Htran | 1 | 0 | #Avsignature | N/A | 9 | 10 | 256 | 88 | 2021-04-25T09:57:46Z | 2015-12-03T04:54:53Z | 62634 |
| 422 | *Win32/IceId* | .{0,1000}Win32\/IceId.{0,1000} | signature_keyword | Antivirus Signature | antivirus signatures | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 62635 |
| 423 | *Win32/KidLogger* | .{0,1000}Win32\/KidLogger.{0,1000} | signature_keyword | kiglogger | malware parental control software - keylogger | T1056.001 - T1113 - T1056.004 | TA0006 - TA0009 | N/A | N/A | Collection | https://kidlogger.net/download.html | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 62636 |
| 424 | *Win32/Kportscan* | .{0,1000}Win32\/Kportscan.{0,1000} | signature_keyword | KPortScan | port scanner used by attackers | T1046 - T1595 | TA0043 - TA0001 | N/A | Dispossessor | Reconnaissance | https://github.com/stardust50578/rdp_brute | 1 | 0 | N/A | N/A | 8 | 1 | 2 | 6 | 2019-05-19T14:25:06Z | 2019-05-19T14:29:49Z | 62637 |
| 425 | *Win32/Mikatz* | .{0,1000}Win32\/Mikatz.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | mimikatz signatures | 10 | 10 | N/A | N/A | N/A | N/A | 62638 |
| 426 | *Win32/PSWTool.Gsecdump* | .{0,1000}Win32\/PSWTool\.Gsecdump.{0,1000} | signature_keyword | gsecdump | credential dumper used to obtain password hashes and LSA secrets from Windows operating systems | T1003.001 - T1003.002 - T1555.003 - T1555.001 | TA0006 - TA0008 | N/A | APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick | Credential Access | https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 62639 |
| 427 | *Win32/PWDump* | .{0,1000}Win32\/PWDump.{0,1000} | signature_keyword | PwDump7 | pwdump7 works with its own filesytem driver (from rkdetector.com technology) so users with administrative privileges are able to dump directly from disk both SYSTEM and SAM registry hives. Once dumped - the SYSKEY key will be retrieved from the SYSTEM hive and then used to decrypt both LanMan and NTLM hashes and dump them in pwdump like format. | T1003.001 - T1555.003 - T1077 | TA0006 - TA0008 | N/A | N/A | Credential Access | https://www.openwall.com/passwords/windows-pwdump | 1 | 0 | #Avsignature | N/A | 10 | 8 | N/A | N/A | N/A | N/A | 62640 |
| 428 | *Win32/Riskware.Mimikatz* | .{0,1000}Win32\/Riskware\.Mimikatz.{0,1000} | signature_keyword | mimikatz | mimikatz strings | T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003 | TA0004 - TA0006 - TA0003 - TA0008 - TA0009 | N/A | Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx | Credential Access | https://github.com/gentilkiwi/mimikatz | 1 | 0 | #Avsignature | N/A | 10 | 10 | 20094 | 3854 | 2024-07-05T17:42:58Z | 2014-04-06T18:30:02Z | 62641 |
| 429 | *Win32/Spy.KeyLogger.PMU* | .{0,1000}Win32\/Spy\.KeyLogger\.PMU.{0,1000} | signature_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 62642 | |
| 430 | *Win32/Trickbot* | .{0,1000}Win32\/Trickbot.{0,1000} | signature_keyword | Antivirus Signature | antivirus signatures | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 62643 |
| 431 | *Win32/Turla.BZ* | .{0,1000}Win32\/Turla\.BZ.{0,1000} | signature_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 62644 | |
| 432 | *Win32/UACBypass* | .{0,1000}Win32\/UACBypass.{0,1000} | signature_keyword | Antivirus Signature | windows defender antivirus signature for UAC bypass | N/A | N/A | N/A | N/A | Defense Evasion | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 62645 |
| 433 | *Win32:Gsecdump* | .{0,1000}Win32\:Gsecdump.{0,1000} | signature_keyword | gsecdump | credential dumper used to obtain password hashes and LSA secrets from Windows operating systems | T1003.001 - T1003.002 - T1555.003 - T1555.001 | TA0006 - TA0008 | N/A | APT1 - PittyTiger - Tonto Team - BRONZE BUTLER - Threat Group-3390 - APT22 - APT24 - APT27 - Night Dragon - Tick | Credential Access | https://web.archive.org/web/20150606043951if_/http://www.truesec.se/Upload/Sakerhet/Tools/gsecdump-v2b5.exe | 1 | 0 | #Avsignature | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 62647 |
| 434 | *Win32:Trojan* | .{0,1000}Win32\:Trojan.{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | N/A | N/A | N/A | N/A | N/A | N/A | 62649 |
| 435 | *Win64.Lazagne* | .{0,1000}Win64\.Lazagne.{0,1000} | signature_keyword | LaZagne | The LaZagne project is an open source application used to retrieve lots of passwords stored on a local computer. Each software stores its passwords using different techniques (plaintext APIs custom algorithms databases etc.). This tool has been developed for the purpose of finding these passwords for the most commonly-used software. | T1555 - T1555.001 - T1555.003 - T1555.004 - T1003.001 - T1003.004 - T1003.005 - T1003.007 - T1003.008 - T1552.001 | TA0006 - TA0009 | N/A | Akira - AvosLocker - LockBit - GoGoogle - 8BASE - RansomEXX - Leafminer - Wizard Spider - APT3 - Scattered Spider - OilRig - MuddyWater - Inception - APT33 - TeamTNT - Tonto Team - Evilnum - CHRYSENE - GOLD DUPONT | Credential Access | https://github.com/AlessandroZ/LaZagne | 1 | 1 | #Avsignature | N/A | 10 | 10 | 9941 | 2062 | 2025-04-10T14:24:35Z | 2015-02-16T14:10:02Z | 62656 |
| 436 | *Win64.Mimikatz* | .{0,1000}Win64\.Mimikatz.{0,1000} | signature_keyword | mimikatz | Mimikatz AV signatures | T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003 | TA0004 - TA0006 - TA0003 - TA0008 - TA0009 | N/A | Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx | Exploitation tool | https://github.com/gentilkiwi/mimikatz | 1 | 0 | #Avsignature | N/A | 10 | 10 | 20094 | 3854 | 2024-07-05T17:42:58Z | 2014-04-06T18:30:02Z | 62657 |
| 437 | *Win64.ShadowDumper* | .{0,1000}Win64\.ShadowDumper.{0,1000} | signature_keyword | ShadowDumper | dump LSASS memory | T1003.001 - T1055 | TA0006 | N/A | N/A | Credential Access | https://github.com/Offensive-Panda/ShadowDumper | 1 | 0 | #Avsignature | N/A | 10 | 6 | 521 | 83 | 2025-04-05T08:32:28Z | 2024-11-10T15:26:28Z | 62658 |
| 438 | *Win64/IceId* | .{0,1000}Win64\/IceId.{0,1000} | signature_keyword | Antivirus Signature | antivirus signatures | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 62659 |
| 439 | *Win64/Mikatz* | .{0,1000}Win64\/Mikatz.{0,1000} | signature_keyword | Antivirus Signature | AV signature for exploitation tools | N/A | N/A | N/A | N/A | Exploitation tool | N/A | 1 | 0 | N/A | mimikatz signatures | 10 | 10 | N/A | N/A | N/A | N/A | 62660 |
| 440 | *Win64/MozillaCookiesView* | .{0,1000}Win64\/MozillaCookiesView.{0,1000} | signature_keyword | MozillaCookiesView | nirsoft utility that displays the details of all cookies stored inside the cookies file (cookies.txt or cookies.sqlite) - abused by threat actors | T1070 - T1552.001 - T1125 - T1005 | TA0009 - TA0005 | N/A | MuddyWater | Credential Access | https://www.nirsoft.net/utils/mzcv.html | 1 | 0 | #Avsignature | N/A | 7 | 10 | N/A | N/A | N/A | N/A | 62661 |
| 441 | *Win64/Outflank* | .{0,1000}Win64\/Outflank.{0,1000} | signature_keyword | Dumpert | Dumpert. an LSASS memory dumper using direct system calls and API unhooking Recent malware research shows that there is an increase in malware that is using direct system calls to evade user-mode API hooks used by security products. This tool demonstrates the use of direct System Calls and API unhooking and combine these techniques in a proof of concept code which can be used to create a LSASS memory dump using Cobalt Strike. while not touching disk and evading AV/EDR monitored user-mode API calls. | T1055.011 - T1003 - T1562.001 - T1027 | TA0005 - TA0006 | N/A | Dispossessor | Credential Access | https://github.com/outflanknl/Dumpert | 1 | 0 | #Avsignature | N/A | 10 | 10 | 1523 | 246 | 2021-01-05T08:58:26Z | 2019-06-17T18:22:01Z | 62662 |
| 442 | *Win64/PrintNightmare* | .{0,1000}Win64\/PrintNightmare.{0,1000} | signature_keyword | PrintNightmare | PrintNightmare exploitation AV signature | T1210 - T1059.001 - T1548.002 | TA0001 - TA0002 - TA0004 | N/A | Dispossessor | Privilege Escalation | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 62663 |
| 443 | *Win64/RentDrv.A Potentially Unsafe* | .{0,1000}Win64\/RentDrv\.A\sPotentially\sUnsafe.{0,1000} | signature_keyword | BadRentdrv2 | A vulnerable driver (BYOVD) capable of terminating several EDRs and antivirus software | T1562 - T1068 - T1210 - T1489 - T1496 | TA0005 - TA0004 - TA0040 | N/A | Agrius | Defense Evasion | https://github.com/keowu/BadRentdrv2 | 1 | 0 | #Avsignature | N/A | 10 | 1 | 95 | 20 | 2024-12-26T13:43:18Z | 2023-10-01T18:24:38Z | 62664 |
| 444 | *Win64/Riskware Mimikatz* | .{0,1000}Win64\/Riskware\sMimikatz.{0,1000} | signature_keyword | mimikatz | mimikatz strings | T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003 | TA0004 - TA0006 - TA0003 - TA0008 - TA0009 | N/A | Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx | Credential Access | https://github.com/gentilkiwi/mimikatz | 1 | 0 | #Avsignature | N/A | 10 | 10 | 20094 | 3854 | 2024-07-05T17:42:58Z | 2014-04-06T18:30:02Z | 62665 |
| 445 | *Win64/Riskware.Mimikatz* | .{0,1000}Win64\/Riskware\.Mimikatz.{0,1000} | signature_keyword | mimikatz | mimikatz strings | T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003 | TA0004 - TA0006 - TA0003 - TA0008 - TA0009 | N/A | Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx | Credential Access | https://github.com/gentilkiwi/mimikatz | 1 | 0 | #Avsignature | N/A | 10 | 10 | 20094 | 3854 | 2024-07-05T17:42:58Z | 2014-04-06T18:30:02Z | 62666 |
| 446 | *Win64/Riskware.Mimikatz* | .{0,1000}Win64\/Riskware\.Mimikatz.{0,1000} | signature_keyword | mimikatz | Mimikatz AV signatures | T1134.005 - T1098 - T1547.005 - T1555 - T1555.003 - T1555.004 - T1003.001 - T1003.002 - T1003.004 - T1003.006 - T1207 - T1649 - T1558.001 - T1558.002 - T1552.004 - T1550.002 - T1550.003 | TA0004 - TA0006 - TA0003 - TA0008 - TA0009 | N/A | Black Basta - APT1 - APT24 - APT28 - APT29 - APT32 - APT33 - APT38 - APT39 - APT41 - APT5 - Akira - Avivore - BERSERK BEAR - BOSS SPIDER - BRONZE BUTLER - BackdoorDiplomacy - Blue Mockingbird - CHRYSENE - COZY BEAR - Carbanak - Chamelgang - Chimera - Cleaver - Cobalt Group - DarkHydrus - Dragonfly - Earth Lusca - FANCY BEAR - FIN13 - FIN6 - FIN7 - GALLIUM - Gamaredon - HEXANE - Indrik Spider - Ke3chang - Kimsuky - LAPSUS$ - Leafminer - Magic Hound - MuddyWater - OilRig - PittyTiger - Sandworm Team - Scattered Spider - TA505 - TEMP.Veles - Threat Group-3390 - Thrip - Tonto Team - Turla - Unit 29155 - Volt Typhoon - Whitefly - Wizard Spider - menuPass - Dispossessor - DragonForce - Sphinx | Exploitation tool | https://github.com/gentilkiwi/mimikatz | 1 | 0 | #Avsignature | N/A | 10 | 10 | 20094 | 3854 | 2024-07-05T17:42:58Z | 2014-04-06T18:30:02Z | 62667 |
| 447 | *Win64/Turla.BQ* | .{0,1000}Win64\/Turla\.BQ.{0,1000} | signature_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 62668 | |
| 448 | *Win64/Turla.BR* | .{0,1000}Win64\/Turla\.BR.{0,1000} | signature_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 62669 | |
| 449 | *Win64/Turla.BS* | .{0,1000}Win64\/Turla\.BS.{0,1000} | signature_keyword | Powershell-Scripts-for-Hackers-and-Pentesters | T1059.001 - T1119 - T1027 - T1016 - T1056.001 | TA0002 - TA0009 - TA0005 - TA0007 - TA0010 | N/A | N/A | Collection | https://github.com/Whitecat18/Powershell-Scripts-for-Hackers-and-Pentesters | 1 | 0 | N/A | N/A | 10 | 5 | 415 | 49 | 2025-02-23T09:05:44Z | 2023-02-27T14:27:32Z | 62670 | |
| 450 | *Win64:MerlinAgent* | .{0,1000}Win64\:MerlinAgent.{0,1000} | signature_keyword | merlin-agent | Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT) | T1219 - T1105 - T1071 - T1090 - T1055 - T1047 | TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011 | N/A | N/A | C2 | https://github.com/Ne0nd0g/merlin-agent | 1 | 0 | N/A | N/A | 10 | 10 | 193 | 62 | 2025-04-16T14:12:16Z | 2020-07-17T20:47:56Z | 62671 |
| 451 | *Win64:MerlinAgent* | .{0,1000}Win64\:MerlinAgent.{0,1000} | signature_keyword | merlin-agent-dll | Merlin is a post-exploit Command & Control (C2) tool also known as a Remote Access Tool (RAT) | T1219 - T1105 - T1071 - T1090 - T1055 - T1047 | TA0005 - TA0002 - TA0003 - TA0006 - TA0010 - TA0011 | N/A | N/A | C2 | https://github.com/Ne0nd0g/merlin-agent-dll | 1 | 0 | N/A | N/A | 10 | 10 | 51 | 15 | 2025-04-17T14:01:36Z | 2021-04-17T16:58:24Z | 62672 |
| 452 | *Windows.Hacktool.* | .{0,1000}Windows\.Hacktool\..{0,1000} | signature_keyword | Antivirus Signature | Antiviurs signature_keyword | N/A | N/A | N/A | N/A | Malware | N/A | 1 | 0 | N/A | N/A | 10 | 10 | N/A | N/A | N/A | N/A | 62713 |
| 453 | *Windows.Hacktool.Seatbelt* | .{0,1000}Windows\.Hacktool\.Seatbelt.{0,1000} | signature_keyword | seatbelt | Seatbelt is a comprehensive security scanning tool that can be used to perform a variety of checks. including but not limited to. user privileges. logged in users. network information. system information. and many others | T1012 - T1016 - T1033 - T1046 - T1049 - T1057 - T1069 - T1082 - T1083 - T1098 - T1105 - T1113 - T1135 - T1201 - T1518 | TA0001 - TA0002 - TA0003 - TA0004 - TA0007 - TA0011 | N/A | Dispossessor | Persistence | https://github.com/GhostPack/Seatbelt | 1 | 0 | #Avsignature | N/A | 10 | 10 | 4047 | 722 | 2025-01-10T20:12:49Z | 2018-07-24T17:38:51Z | 62714 |
| 454 | *Windows.Hacktool.SharpDump* | .{0,1000}Windows\.Hacktool\.SharpDump.{0,1000} | signature_keyword | SharpDump | SharpDump is a C# port of PowerSploit's Out-Minidump.ps1 functionality. | T1003 - T1055 - T1070 | TA0006 - TA0005 - TA0008 | N/A | Avaddon | Credential Access | https://github.com/GhostPack/SharpDump | 1 | 0 | #Avsignature | N/A | 10 | 7 | 664 | 130 | 2019-02-07T02:52:20Z | 2018-07-24T17:42:19Z | 62715 |
| 455 | *Windows.Hacktool.SharpShares* | .{0,1000}Windows\.Hacktool\.SharpShares.{0,1000} | signature_keyword | SharpShares | Multithreaded C# .NET Assembly to enumerate accessible network shares in a domain | T1046 - T1135 | TA0007 - TA0001 | N/A | Black Basta - BlackSuit - Royal - BianLian - Fog | Discovery | https://github.com/mitchmoser/SharpShares | 1 | 0 | #Avsignature | N/A | 10 | 4 | 351 | 49 | 2021-09-21T08:14:27Z | 2020-09-25T22:35:57Z | 62716 |
| 456 | *hacktool.remoteexec/remcom* | .{0,1000}hacktool\.remoteexec\/remcom.{0,1000} | signature_keyword | RemCom | Remote Command Executor: A OSS replacement for PsExec and RunAs | T1077 - T1059 - T1021 - T1569.002 | TA0002 - TA0005 - TA0008 | N/A | APT33 - TA558 - The Gorgon Group - Common Raven - APT-C-36 - Operation Comando | Lateral Movement | https://github.com/kavika13/RemCom | 1 | 0 | N/A | N/A | 10 | 4 | 346 | 100 | 2017-10-30T04:48:38Z | 2011-11-09T11:00:09Z | 63722 |