| 7zip CommandLine To SMB Share Path |
Archive via Utility |
Collection |
Hunting |
| AWS Create Policy Version to allow all resources |
Cloud Accounts |
Defense Evasion |
TTP |
| AWS CreateAccessKey |
Cloud Account |
Persistence |
Hunting |
| AWS CreateLoginProfile |
Cloud Account |
Persistence |
TTP |
| AWS Cross Account Activity From Previously Unseen Account |
None |
None |
Anomaly |
| AWS Detect Users creating keys with encrypt policy without MFA |
Data Encrypted for Impact |
Impact |
TTP |
| AWS Detect Users with KMS keys performing encryption S3 |
Data Encrypted for Impact |
Impact |
Anomaly |
| AWS ECR Container Scanning Findings High |
Malicious Image |
Execution |
TTP |
| AWS ECR Container Scanning Findings Low Informational Unknown |
Malicious Image |
Execution |
Hunting |
| AWS ECR Container Scanning Findings Medium |
Malicious Image |
Execution |
Anomaly |
| AWS ECR Container Upload Outside Business Hours |
Malicious Image |
Execution |
Anomaly |
| AWS ECR Container Upload Unknown User |
Malicious Image |
Execution |
Anomaly |
| AWS Excessive Security Scanning |
Cloud Service Discovery |
Discovery |
TTP |
| AWS IAM AccessDenied Discovery Events |
Cloud Infrastructure Discovery |
Discovery |
Anomaly |
| AWS IAM Assume Role Policy Brute Force |
Cloud Infrastructure Discovery, Brute Force |
Discovery |
TTP |
| AWS IAM Delete Policy |
Account Manipulation |
Persistence |
Hunting |
| AWS IAM Failure Group Deletion |
Account Manipulation |
Persistence |
Anomaly |
| AWS IAM Successful Group Deletion |
Cloud Groups, Account Manipulation |
Discovery |
Hunting |
| AWS Network Access Control List Created with All Open Ports |
Disable or Modify Cloud Firewall |
Defense Evasion |
TTP |
| AWS Network Access Control List Deleted |
Disable or Modify Cloud Firewall |
Defense Evasion |
Anomaly |
| AWS SAML Access by Provider User and Principal |
Valid Accounts |
Defense Evasion |
Anomaly |
| AWS SAML Update identity provider |
Valid Accounts |
Defense Evasion |
TTP |
| AWS SetDefaultPolicyVersion |
Cloud Accounts |
Defense Evasion |
TTP |
| AWS UpdateLoginProfile |
Cloud Account |
Persistence |
TTP |
| Abnormally High Number Of Cloud Infrastructure API Calls |
Cloud Accounts |
Defense Evasion |
Anomaly |
| Abnormally High Number Of Cloud Instances Destroyed |
Cloud Accounts |
Defense Evasion |
Anomaly |
| Abnormally High Number Of Cloud Instances Launched |
Cloud Accounts |
Defense Evasion |
Anomaly |
| Abnormally High Number Of Cloud Security Group API Calls |
Cloud Accounts |
Defense Evasion |
Anomaly |
| Access LSASS Memory for Dump Creation |
LSASS Memory |
Credential Access |
TTP |
| Account Discovery With Net App |
Domain Account |
Discovery |
TTP |
| Add DefaultUser And Password In Registry |
Credentials in Registry |
Credential Access |
Anomaly |
| AdsiSearcher Account Discovery |
Domain Account |
Discovery |
TTP |
| Allow File And Printing Sharing In Firewall |
Disable or Modify Cloud Firewall |
Defense Evasion |
TTP |
| Allow Inbound Traffic By Firewall Rule Registry |
Remote Desktop Protocol |
Lateral Movement |
TTP |
| Allow Inbound Traffic In Firewall Rule |
Remote Desktop Protocol |
Lateral Movement |
TTP |
| Allow Network Discovery In Firewall |
Disable or Modify Cloud Firewall |
Defense Evasion |
TTP |
| Allow Operation with Consent Admin |
Abuse Elevation Control Mechanism |
Privilege Escalation |
TTP |
| Amazon EKS Kubernetes Pod scan detection |
Cloud Service Discovery |
Discovery |
Hunting |
| Amazon EKS Kubernetes cluster scan detection |
Cloud Service Discovery |
Discovery |
Hunting |
| Anomalous usage of 7zip |
Archive via Utility |
Collection |
Anomaly |
| Any Powershell DownloadFile |
PowerShell |
Execution |
TTP |
| Any Powershell DownloadString |
PowerShell |
Execution |
TTP |
| Applying Stolen Credentials via Mimikatz modules |
Process Injection, Exploitation for Privilege Escalation, Valid Accounts, Account Manipulation, Access Token Manipulation, Create or Modify System Process, Boot or Logon Autostart Execution, Abuse Elevation Control Mechanism, Compromise Client Software Binary, Modify Authentication Process, Steal or Forge Kerberos Tickets |
Defense Evasion |
TTP |
| Applying Stolen Credentials via PowerSploit modules |
Process Injection, Exploitation for Privilege Escalation, Valid Accounts, Account Manipulation, Access Token Manipulation, Create or Modify System Process, Boot or Logon Autostart Execution, Abuse Elevation Control Mechanism, Compromise Client Software Binary, Credentials from Password Stores, Steal or Forge Kerberos Tickets |
Defense Evasion |
TTP |
| Assessment of Credential Strength via DSInternals modules |
Valid Accounts, Account Manipulation, Account Discovery, Password Policy Discovery, Unsecured Credentials, Credentials from Password Stores |
Defense Evasion |
TTP |
| Attacker Tools On Endpoint |
Match Legitimate Name or Location, Active Scanning, OS Credential Dumping |
Defense Evasion |
TTP |
| Attempt To Add Certificate To Untrusted Store |
Install Root Certificate |
Defense Evasion |
TTP |
| Attempt To Disable Services |
Service Stop |
Impact |
TTP |
| Attempt To Stop Security Service |
Disable or Modify Tools |
Defense Evasion |
TTP |
| Attempt To delete Services |
Service Stop |
Impact |
TTP |
| Attempted Credential Dump From Registry via Reg exe |
OS Credential Dumping |
Credential Access |
TTP |
| Attempted Credential Dump From Registry via Reg exe |
Security Account Manager |
Credential Access |
TTP |
| Auto Admin Logon Registry Entry |
Credentials in Registry |
Credential Access |
TTP |
| BCDEdit Failure Recovery Modification |
Inhibit System Recovery |
Impact |
TTP |
| BITS Job Persistence |
BITS Jobs |
Defense Evasion |
TTP |
| BITSAdmin Download File |
BITS Jobs, Ingress Tool Transfer |
Defense Evasion |
TTP |
| Batch File Write to System32 |
Malicious File |
Execution |
TTP |
| Bcdedit Command Back To Normal Mode Boot |
Inhibit System Recovery |
Impact |
TTP |
| CHCP Command Execution |
Command and Scripting Interpreter |
Execution |
TTP |
| CMD Echo Pipe - Escalation |
Windows Command Shell, Windows Service |
Execution |
TTP |
| CMLUA Or CMSTPLUA UAC Bypass |
CMSTP |
Defense Evasion |
TTP |
| CertUtil Download With URLCache and Split Arguments |
Ingress Tool Transfer |
Command And Control |
TTP |
| CertUtil Download With VerifyCtl and Split Arguments |
Ingress Tool Transfer |
Command And Control |
TTP |
| CertUtil With Decode Argument |
Deobfuscate/Decode Files or Information |
Defense Evasion |
TTP |
| Certutil exe certificate extraction |
None |
None |
TTP |
| Change To Safe Mode With Network Config |
Inhibit System Recovery |
Impact |
TTP |
| Check Elevated CMD using whoami |
System Owner/User Discovery |
Discovery |
TTP |
| Child Processes of Spoolsv exe |
Exploitation for Privilege Escalation |
Privilege Escalation |
TTP |
| Circle CI Disable Security Job |
Compromise Client Software Binary |
Persistence |
Anomaly |
| Circle CI Disable Security Step |
Compromise Client Software Binary |
Persistence |
Anomaly |
| Clear Unallocated Sector Using Cipher App |
File Deletion |
Defense Evasion |
TTP |
| Clop Common Exec Parameter |
User Execution |
Execution |
TTP |
| Clop Ransomware Known Service Name |
Create or Modify System Process |
Persistence |
TTP |
| Cloud API Calls From Previously Unseen User Roles |
Valid Accounts |
Defense Evasion |
Anomaly |
| Cloud Compute Instance Created By Previously Unseen User |
Cloud Accounts |
Defense Evasion |
Anomaly |
| Cloud Compute Instance Created In Previously Unused Region |
Unused/Unsupported Cloud Regions |
Defense Evasion |
Anomaly |
| Cloud Compute Instance Created With Previously Unseen Image |
None |
None |
Anomaly |
| Cloud Compute Instance Created With Previously Unseen Instance Type |
None |
None |
Anomaly |
| Cloud Instance Modified By Previously Unseen User |
Cloud Accounts |
Defense Evasion |
Anomaly |
| Cloud Provisioning Activity From Previously Unseen City |
Valid Accounts |
Defense Evasion |
Anomaly |
| Cloud Provisioning Activity From Previously Unseen Country |
Valid Accounts |
Defense Evasion |
Anomaly |
| Cloud Provisioning Activity From Previously Unseen IP Address |
Valid Accounts |
Defense Evasion |
Anomaly |
| Cloud Provisioning Activity From Previously Unseen Region |
Valid Accounts |
Defense Evasion |
Anomaly |
| Cmdline Tool Not Executed In CMD Shell |
JavaScript |
Execution |
TTP |
| Cobalt Strike Named Pipes |
Process Injection |
Defense Evasion |
TTP |
| Common Ransomware Extensions |
Data Destruction |
Impact |
Hunting |
| Common Ransomware Notes |
Data Destruction |
Impact |
Hunting |
| Conti Common Exec parameter |
User Execution |
Execution |
TTP |
| Control Loading from World Writable Directory |
Control Panel |
Defense Evasion |
TTP |
| Correlation by Repository and Risk |
Malicious Image |
Execution |
Correlation |
| Correlation by User and Risk |
Malicious Image |
Execution |
Correlation |
| Create Remote Thread In Shell Application |
Process Injection |
Defense Evasion |
TTP |
| Create Remote Thread into LSASS |
LSASS Memory |
Credential Access |
TTP |
| Create Service In Suspicious File Path |
Service Execution |
Execution |
TTP |
| Create local admin accounts using net exe |
Local Account |
Persistence |
TTP |
| Create or delete windows shares using net exe |
Network Share Connection Removal |
Defense Evasion |
TTP |
| Creation of Shadow Copy |
NTDS |
Credential Access |
TTP |
| Creation of Shadow Copy with wmic and powershell |
NTDS |
Credential Access |
TTP |
| Creation of lsass Dump with Taskmgr |
LSASS Memory |
Credential Access |
TTP |
| Credential Dumping via Copy Command from Shadow Copy |
NTDS |
Credential Access |
TTP |
| Credential Dumping via Symlink to Shadow Copy |
NTDS |
Credential Access |
TTP |
| Credential Extraction indicative of FGDump and CacheDump with s option |
OS Credential Dumping |
Credential Access |
TTP |
| Credential Extraction indicative of FGDump and CacheDump with v option |
OS Credential Dumping |
Credential Access |
TTP |
| Credential Extraction indicative of Lazagne command line options |
OS Credential Dumping, Credentials from Password Stores |
Credential Access |
TTP |
| Credential Extraction indicative of use of DSInternals credential conversion modules |
OS Credential Dumping |
Credential Access |
TTP |
| Credential Extraction indicative of use of DSInternals modules |
OS Credential Dumping |
Credential Access |
TTP |
| Credential Extraction indicative of use of Mimikatz modules |
OS Credential Dumping |
Credential Access |
TTP |
| Credential Extraction indicative of use of PowerSploit modules |
OS Credential Dumping |
Credential Access |
TTP |
| Credential Extraction native Microsoft debuggers peek into the kernel |
OS Credential Dumping |
Credential Access |
TTP |
| Credential Extraction native Microsoft debuggers via z command line option |
OS Credential Dumping |
Credential Access |
TTP |
| Credential Extraction via Get-ADDBAccount module present in PowerSploit and DSInternals |
OS Credential Dumping |
Credential Access |
TTP |
| DLLHost with no Command Line Arguments with Network |
Process Injection |
Defense Evasion |
TTP |
| DNS Exfiltration Using Nslookup App |
Exfiltration Over Alternative Protocol |
Exfiltration |
TTP |
| DNS Query Length Outliers - MLTK |
DNS |
Command And Control |
Anomaly |
| DNS Query Length With High Standard Deviation |
Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
Exfiltration |
Anomaly |
| DSQuery Domain Discovery |
Domain Trust Discovery |
Discovery |
TTP |
| Delete A Net User |
Service Stop |
Impact |
Anomaly |
| Delete ShadowCopy With PowerShell |
Inhibit System Recovery |
Impact |
TTP |
| Deleting Of Net Users |
Account Access Removal |
Impact |
TTP |
| Deleting Shadow Copies |
Inhibit System Recovery |
Impact |
TTP |
| Deny Permission using Cacls Utility |
File and Directory Permissions Modification |
Defense Evasion |
TTP |
| Detect ARP Poisoning |
Hardware Additions, Network Denial of Service, ARP Cache Poisoning |
Initial Access |
TTP |
| Detect AWS Console Login by New User |
None |
None |
Hunting |
| Detect AWS Console Login by User from New City |
Unused/Unsupported Cloud Regions |
Defense Evasion |
Hunting |
| Detect AWS Console Login by User from New Country |
Unused/Unsupported Cloud Regions |
Defense Evasion |
Hunting |
| Detect AWS Console Login by User from New Region |
Unused/Unsupported Cloud Regions |
Defense Evasion |
Hunting |
| Detect Activity Related to Pass the Hash Attacks |
Pass the Hash |
Defense Evasion |
TTP |
| Detect AzureHound Command-Line Arguments |
Domain Account, Local Account, Domain Trust Discovery, Domain Groups, Local Groups |
Discovery |
TTP |
| Detect AzureHound File Modifications |
Domain Account, Local Account, Domain Trust Discovery, Domain Groups, Local Groups |
Discovery |
TTP |
| Detect Baron Samedit CVE-2021-3156 |
Exploitation for Privilege Escalation |
Privilege Escalation |
TTP |
| Detect Baron Samedit CVE-2021-3156 Segfault |
Exploitation for Privilege Escalation |
Privilege Escalation |
TTP |
| Detect Baron Samedit CVE-2021-3156 via OSQuery |
Exploitation for Privilege Escalation |
Privilege Escalation |
TTP |
| Detect Computer Changed with Anonymous Account |
Exploitation of Remote Services |
Lateral Movement |
Hunting |
| Detect Copy of ShadowCopy with Script Block Logging |
Security Account Manager |
Credential Access |
TTP |
| Detect Credential Dumping through LSASS access |
LSASS Memory |
Credential Access |
TTP |
| Detect Dump LSASS Memory using comsvcs |
NTDS |
Credential Access |
TTP |
| Detect Empire with PowerShell Script Block Logging |
PowerShell |
Execution |
TTP |
| Detect Excessive Account Lockouts From Endpoint |
Domain Accounts |
Defense Evasion |
Anomaly |
| Detect Excessive User Account Lockouts |
Local Accounts |
Defense Evasion |
Anomaly |
| Detect Exchange Web Shell |
Web Shell |
Persistence |
TTP |
| Detect F5 TMUI RCE CVE-2020-5902 |
Exploit Public-Facing Application |
Initial Access |
TTP |
| Detect GCP Storage access from a new IP |
Data from Cloud Storage Object |
Collection |
Anomaly |
| Detect HTML Help Renamed |
Compiled HTML File |
Defense Evasion |
Hunting |
| Detect HTML Help Spawn Child Process |
Compiled HTML File |
Defense Evasion |
TTP |
| Detect HTML Help URL in Command Line |
Compiled HTML File |
Defense Evasion |
TTP |
| Detect HTML Help Using InfoTech Storage Handlers |
Compiled HTML File |
Defense Evasion |
TTP |
| Detect IPv6 Network Infrastructure Threats |
Hardware Additions, Network Denial of Service, ARP Cache Poisoning |
Initial Access |
TTP |
| Detect Kerberoasting |
Kerberoasting |
Credential Access |
TTP |
| Detect Large Outbound ICMP Packets |
Non-Application Layer Protocol |
Command And Control |
TTP |
| Detect MSHTA Url in Command Line |
Mshta |
Defense Evasion |
TTP |
| Detect Mimikatz Using Loaded Images |
LSASS Memory |
Credential Access |
TTP |
| Detect Mimikatz With PowerShell Script Block Logging |
OS Credential Dumping |
Credential Access |
TTP |
| Detect New Local Admin account |
Local Account |
Persistence |
TTP |
| Detect New Login Attempts to Routers |
None |
None |
TTP |
| Detect New Open GCP Storage Buckets |
Data from Cloud Storage Object |
Collection |
TTP |
| Detect New Open S3 Buckets over AWS CLI |
Data from Cloud Storage Object |
Collection |
TTP |
| Detect New Open S3 buckets |
Data from Cloud Storage Object |
Collection |
TTP |
| Detect Outbound SMB Traffic |
File Transfer Protocols |
Command And Control |
TTP |
| Detect Outlook exe writing a zip file |
Spearphishing Attachment |
Initial Access |
TTP |
| Detect Pass the Hash |
Pass the Hash |
Defense Evasion |
TTP |
| Detect Path Interception By Creation Of program exe |
Path Interception by Unquoted Path |
Persistence |
TTP |
| Detect Port Security Violation |
Hardware Additions, Network Denial of Service, ARP Cache Poisoning |
Initial Access |
TTP |
| Detect Prohibited Applications Spawning cmd exe |
Windows Command Shell |
Execution |
Hunting |
| Detect Prohibited Applications Spawning cmd exe |
Command and Scripting Interpreter |
Execution |
TTP |
| Detect PsExec With accepteula Flag |
SMB/Windows Admin Shares |
Lateral Movement |
TTP |
| Detect RClone Command-Line Usage |
Automated Exfiltration |
Exfiltration |
TTP |
| Detect Rare Executables |
None |
None |
Anomaly |
| Detect Regasm Spawning a Process |
Regsvcs/Regasm |
Defense Evasion |
TTP |
| Detect Regasm with Network Connection |
Regsvcs/Regasm |
Defense Evasion |
TTP |
| Detect Regasm with no Command Line Arguments |
Regsvcs/Regasm |
Defense Evasion |
TTP |
| Detect Regsvcs Spawning a Process |
Regsvcs/Regasm |
Defense Evasion |
TTP |
| Detect Regsvcs with Network Connection |
Regsvcs/Regasm |
Defense Evasion |
TTP |
| Detect Regsvcs with No Command Line Arguments |
Regsvcs/Regasm |
Defense Evasion |
TTP |
| Detect Regsvr32 Application Control Bypass |
Regsvr32 |
Defense Evasion |
TTP |
| Detect Renamed 7-Zip |
Archive via Utility |
Collection |
Hunting |
| Detect Renamed PSExec |
Service Execution |
Execution |
Hunting |
| Detect Renamed RClone |
Automated Exfiltration |
Exfiltration |
Hunting |
| Detect Renamed WinRAR |
Archive via Utility |
Collection |
Hunting |
| Detect Rogue DHCP Server |
Hardware Additions, Network Denial of Service, Man-in-the-Middle |
Initial Access |
TTP |
| Detect Rundll32 Application Control Bypass - advpack |
Rundll32 |
Defense Evasion |
TTP |
| Detect Rundll32 Application Control Bypass - setupapi |
Rundll32 |
Defense Evasion |
TTP |
| Detect Rundll32 Application Control Bypass - syssetup |
Rundll32 |
Defense Evasion |
TTP |
| Detect Rundll32 Inline HTA Execution |
Mshta |
Defense Evasion |
TTP |
| Detect S3 access from a new IP |
Data from Cloud Storage Object |
Collection |
Anomaly |
| Detect SNICat SNI Exfiltration |
Exfiltration Over C2 Channel |
Exfiltration |
TTP |
| Detect SharpHound Command-Line Arguments |
Domain Account, Local Account, Domain Trust Discovery, Domain Groups, Local Groups |
Discovery |
TTP |
| Detect SharpHound File Modifications |
Domain Account, Local Account, Domain Trust Discovery, Domain Groups, Local Groups |
Discovery |
TTP |
| Detect SharpHound Usage |
Domain Account, Local Account, Domain Trust Discovery, Domain Groups, Local Groups |
Discovery |
TTP |
| Detect Software Download To Network Device |
TFTP Boot |
Defense Evasion |
TTP |
| Detect Spike in AWS Security Hub Alerts for EC2 Instance |
None |
None |
Anomaly |
| Detect Spike in AWS Security Hub Alerts for User |
None |
None |
Anomaly |
| Detect Spike in S3 Bucket deletion |
Data from Cloud Storage Object |
Collection |
Anomaly |
| Detect Spike in blocked Outbound Traffic from your AWS |
None |
None |
Anomaly |
| Detect Traffic Mirroring |
Hardware Additions, Network Denial of Service, Traffic Duplication |
Initial Access |
TTP |
| Detect Unauthorized Assets by MAC address |
None |
None |
TTP |
| Detect Use of cmd exe to Launch Script Interpreters |
Windows Command Shell |
Execution |
TTP |
| Detect WMI Event Subscription Persistence |
Windows Management Instrumentation Event Subscription |
Privilege Escalation |
TTP |
| Detect Windows DNS SIGRed via Splunk Stream |
Exploitation for Client Execution |
Execution |
TTP |
| Detect Windows DNS SIGRed via Zeek |
Exploitation for Client Execution |
Execution |
TTP |
| Detect Zerologon via Zeek |
Exploit Public-Facing Application |
Initial Access |
TTP |
| Detect attackers scanning for vulnerable JBoss servers |
System Information Discovery |
Discovery |
TTP |
| Detect hosts connecting to dynamic domain providers |
Drive-by Compromise |
Initial Access |
TTP |
| Detect malicious requests to exploit JBoss servers |
None |
None |
TTP |
| Detect mshta inline hta execution |
Mshta |
Defense Evasion |
TTP |
| Detect mshta renamed |
Mshta |
Defense Evasion |
Hunting |
| Detect processes used for System Network Configuration Discovery |
System Network Configuration Discovery |
Discovery |
TTP |
| Detect shared ec2 snapshot |
Transfer Data to Cloud Account |
Exfiltration |
TTP |
| Detection of tools built by NirSoft |
Software Deployment Tools |
Execution |
TTP |
| Disable AMSI Through Registry |
Disable or Modify Tools |
Defense Evasion |
TTP |
| Disable ETW Through Registry |
Disable or Modify Tools |
Defense Evasion |
TTP |
| Disable Logs Using WevtUtil |
Clear Windows Event Logs |
Defense Evasion |
TTP |
| Disable Net User Account |
Service Stop |
Impact |
TTP |
| Disable Registry Tool |
Disable or Modify Tools |
Defense Evasion |
TTP |
| Disable Show Hidden Files |
Hidden Files and Directories, Disable or Modify Tools |
Defense Evasion |
TTP |
| Disable Windows App Hotkeys |
Disable or Modify Tools |
Defense Evasion |
TTP |
| Disable Windows Behavior Monitoring |
Disable or Modify Tools |
Defense Evasion |
TTP |
| Disable Windows SmartScreen Protection |
Disable or Modify Tools |
Defense Evasion |
TTP |
| Disabling CMD Application |
Disable or Modify Tools |
Defense Evasion |
TTP |
| Disabling ControlPanel |
Disable or Modify Tools |
Defense Evasion |
TTP |
| Disabling Firewall with Netsh |
Disable or Modify Tools |
Defense Evasion |
TTP |
| Disabling FolderOptions Windows Feature |
Disable or Modify Tools |
Defense Evasion |
TTP |
| Disabling Net User Account |
Account Access Removal |
Impact |
TTP |
| Disabling NoRun Windows App |
Disable or Modify Tools |
Defense Evasion |
TTP |
| Disabling Remote User Account Control |
Bypass User Account Control |
Privilege Escalation |
TTP |
| Disabling SystemRestore In Registry |
Disable or Modify Tools |
Defense Evasion |
TTP |
| Disabling Task Manager |
Disable or Modify Tools |
Defense Evasion |
TTP |
| Domain Account Discovery With Net App |
Domain Account |
Discovery |
TTP |
| Domain Account Discovery with Dsquery |
Domain Account |
Discovery |
Hunting |
| Domain Account Discovery with Wmic |
Domain Account |
Discovery |
TTP |
| Domain Controller Discovery with Nltest |
Remote System Discovery |
Discovery |
TTP |
| Domain Controller Discovery with Wmic |
Remote System Discovery |
Discovery |
Hunting |
| Domain Group Discovery With Dsquery |
Domain Groups |
Discovery |
Hunting |
| Domain Group Discovery With Net |
Domain Groups |
Discovery |
Hunting |
| Domain Group Discovery With Wmic |
Domain Groups |
Discovery |
Hunting |
| Domain Group Discovery with Adsisearcher |
Domain Groups |
Discovery |
TTP |
| Download Files Using Telegram |
Ingress Tool Transfer |
Command And Control |
TTP |
| Drop IcedID License dat |
Malicious File |
Execution |
Hunting |
| Dump LSASS via comsvcs DLL |
LSASS Memory |
Credential Access |
TTP |
| Dump LSASS via procdump |
LSASS Memory |
Credential Access |
TTP |
| Elevated Group Discovery With Net |
Domain Groups |
Discovery |
TTP |
| Elevated Group Discovery With Wmic |
Domain Groups |
Discovery |
TTP |
| Elevated Group Discovery with PowerView |
Domain Groups |
Discovery |
Hunting |
| Email Attachments With Lots Of Spaces |
None |
None |
Anomaly |
| Email files written outside of the Outlook directory |
Local Email Collection |
Collection |
TTP |
| Email servers sending high volume traffic to hosts |
Remote Email Collection |
Collection |
Anomaly |
| Enable RDP In Other Port Number |
Remote Services |
Lateral Movement |
TTP |
| Enumerate Users Local Group Using Telegram |
Account Discovery |
Discovery |
TTP |
| Esentutl SAM Copy |
Security Account Manager |
Credential Access |
Hunting |
| Eventvwr UAC Bypass |
Bypass User Account Control |
Privilege Escalation |
TTP |
| Excel Spawning PowerShell |
Security Account Manager |
Credential Access |
TTP |
| Excel Spawning Windows Script Host |
Security Account Manager |
Credential Access |
TTP |
| Excessive Attempt To Disable Services |
Service Stop |
Impact |
Anomaly |
| Excessive DNS Failures |
DNS |
Command And Control |
Anomaly |
| Excessive Service Stop Attempt |
Service Stop |
Impact |
Anomaly |
| Excessive Usage Of Cacls App |
File and Directory Permissions Modification |
Defense Evasion |
Anomaly |
| Excessive Usage Of Net App |
Account Access Removal |
Impact |
Anomaly |
| Excessive Usage Of SC Service Utility |
Service Execution |
Execution |
Anomaly |
| Excessive Usage Of Taskkill |
Disable or Modify Tools |
Defense Evasion |
Anomaly |
| Excessive Usage of NSLOOKUP App |
Exfiltration Over Alternative Protocol |
Exfiltration |
Anomaly |
| Excessive number of distinct processes created in Windows Temp folder |
Command and Scripting Interpreter |
Execution |
Anomaly |
| Excessive number of service control start as disabled |
Disable or Modify Tools |
Defense Evasion |
Anomaly |
| Excessive number of taskhost processes |
System Owner/User Discovery |
Discovery |
Anomaly |
| Exchange PowerShell Abuse via SSRF |
Exploit Public-Facing Application |
Initial Access |
TTP |
| Exchange PowerShell Module Usage |
PowerShell |
Execution |
TTP |
| Executables Or Script Creation In Suspicious Path |
Masquerading |
Defense Evasion |
TTP |
| Execute Javascript With Jscript COM CLSID |
Visual Basic |
Execution |
TTP |
| Execution of File with Multiple Extensions |
Rename System Utilities |
Defense Evasion |
TTP |
| Extraction of Registry Hives |
Security Account Manager |
Credential Access |
TTP |
| File with Samsam Extension |
None |
None |
TTP |
| First Time Seen Child Process of Zoom |
Exploitation for Privilege Escalation |
Privilege Escalation |
Anomaly |
| First Time Seen Running Windows Service |
Service Execution |
Execution |
Anomaly |
| First time seen command line argument |
Command and Scripting Interpreter, Regsvr32, Indirect Command Execution |
Execution |
Anomaly |
| FodHelper UAC Bypass |
Modify Registry, Bypass User Account Control |
Defense Evasion |
TTP |
| Fsutil Zeroing File |
Indicator Removal on Host |
Defense Evasion |
TTP |
| GCP Detect gcploit framework |
Valid Accounts |
Defense Evasion |
TTP |
| GCP Kubernetes cluster pod scan detection |
Cloud Service Discovery |
Discovery |
Hunting |
| GPUpdate with no Command Line Arguments with Network |
Process Injection |
Defense Evasion |
TTP |
| GSuite Email Suspicious Attachment |
Spearphishing Attachment |
Initial Access |
Anomaly |
| Get ADDefaultDomainPasswordPolicy with Powershell |
Password Policy Discovery |
Discovery |
Hunting |
| Get ADDefaultDomainPasswordPolicy with Powershell Script Block |
Password Policy Discovery |
Discovery |
Hunting |
| Get ADUser with PowerShell |
Domain Account |
Discovery |
Hunting |
| Get ADUser with PowerShell Script Block |
Domain Account |
Discovery |
Hunting |
| Get ADUserResultantPasswordPolicy with Powershell |
Password Policy Discovery |
Discovery |
TTP |
| Get ADUserResultantPasswordPolicy with Powershell Script Block |
Password Policy Discovery |
Discovery |
TTP |
| Get DomainPolicy with Powershell |
Password Policy Discovery |
Discovery |
TTP |
| Get DomainPolicy with Powershell Script Block |
Password Policy Discovery |
Discovery |
TTP |
| Get DomainUser with PowerShell |
Domain Account |
Discovery |
TTP |
| Get DomainUser with PowerShell Script Block |
Domain Account |
Discovery |
TTP |
| Get WMIObject Group Discovery |
Local Groups |
Discovery |
Hunting |
| Get WMIObject Group Discovery with Script Block Logging |
Local Groups |
Discovery |
Hunting |
| Get-DomainTrust with PowerShell |
Domain Trust Discovery |
Discovery |
TTP |
| Get-DomainTrust with PowerShell Script Block |
Domain Trust Discovery |
Discovery |
TTP |
| Get-ForestTrust with PowerShell |
Domain Trust Discovery |
Discovery |
TTP |
| Get-ForestTrust with PowerShell Script Block |
Domain Trust Discovery |
Discovery |
TTP |
| GetAdComputer with PowerShell |
Remote System Discovery |
Discovery |
Hunting |
| GetAdComputer with PowerShell Script Block |
Remote System Discovery |
Discovery |
Hunting |
| GetAdGroup with PowerShell |
Domain Groups |
Discovery |
Hunting |
| GetAdGroup with PowerShell Script Block |
Domain Groups |
Discovery |
Hunting |
| GetCurrent User with PowerShell |
System Owner/User Discovery |
Discovery |
Hunting |
| GetCurrent User with PowerShell Script Block |
System Owner/User Discovery |
Discovery |
Hunting |
| GetDomainComputer with PowerShell |
Remote System Discovery |
Discovery |
TTP |
| GetDomainComputer with PowerShell Script Block |
Remote System Discovery |
Discovery |
TTP |
| GetDomainController with PowerShell |
Remote System Discovery |
Discovery |
Hunting |
| GetDomainController with PowerShell Script Block |
Remote System Discovery |
Discovery |
TTP |
| GetDomainGroup with PowerShell |
Domain Groups |
Discovery |
TTP |
| GetDomainGroup with PowerShell Script Block |
Domain Groups |
Discovery |
TTP |
| GetLocalUser with PowerShell |
Local Account |
Discovery |
Hunting |
| GetLocalUser with PowerShell Script Block |
Local Account |
Discovery |
Hunting |
| GetNetTcpconnection with PowerShell |
System Network Connections Discovery |
Discovery |
Hunting |
| GetNetTcpconnection with PowerShell Script Block |
System Network Connections Discovery |
Discovery |
Hunting |
| GetWmiObject DS User with PowerShell |
Domain Account |
Discovery |
TTP |
| GetWmiObject DS User with PowerShell Script Block |
Domain Account |
Discovery |
TTP |
| GetWmiObject Ds Computer with PowerShell |
Remote System Discovery |
Discovery |
TTP |
| GetWmiObject Ds Computer with PowerShell Script Block |
Remote System Discovery |
Discovery |
TTP |
| GetWmiObject Ds Group with PowerShell |
Domain Groups |
Discovery |
TTP |
| GetWmiObject Ds Group with PowerShell Script Block |
Domain Groups |
Discovery |
TTP |
| GetWmiObject User Account with PowerShell |
Local Account |
Discovery |
Hunting |
| GetWmiObject User Account with PowerShell Script Block |
Local Account |
Discovery |
Hunting |
| GitHub Dependabot Alert |
Compromise Software Dependencies and Development Tools |
Initial Access |
Anomaly |
| GitHub Pull Request from Unknown User |
Compromise Software Dependencies and Development Tools |
Initial Access |
Anomaly |
| Github Commit Changes In Master |
Trusted Relationship |
Initial Access |
Anomaly |
| Github Commit In Develop |
Trusted Relationship |
Initial Access |
Anomaly |
| Grant Permission Using Cacls Utility |
File and Directory Permissions Modification |
Defense Evasion |
TTP |
| Gsuite Drive Share In External Email |
Exfiltration to Cloud Storage |
Exfiltration |
Anomaly |
| Gsuite Email Suspicious Subject With Attachment |
Spearphishing Attachment |
Initial Access |
Anomaly |
| Gsuite Email With Known Abuse Web Service Link |
Spearphishing Attachment |
Initial Access |
Anomaly |
| Gsuite Outbound Email With Attachment To External Domain |
Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
Exfiltration |
Anomaly |
| Gsuite Suspicious Shared File Name |
Spearphishing Attachment |
Initial Access |
Anomaly |
| Hide User Account From Sign-In Screen |
Disable or Modify Tools |
Defense Evasion |
TTP |
| Hiding Files And Directories With Attrib exe |
Windows File and Directory Permissions Modification |
Defense Evasion |
TTP |
| High File Deletion Frequency |
Data Destruction |
Impact |
Anomaly |
| High Number of Login Failures from a single source |
Password Guessing |
Credential Access |
Anomaly |
| High Process Termination Frequency |
Data Encrypted for Impact |
Impact |
Anomaly |
| Hosts receiving high volume of network traffic from email server |
Remote Email Collection |
Collection |
Anomaly |
| ICACLS Grant Command |
File and Directory Permissions Modification |
Defense Evasion |
TTP |
| Icacls Deny Command |
File and Directory Permissions Modification |
Defense Evasion |
TTP |
| IcedID Exfiltrated Archived File Creation |
Archive via Utility |
Collection |
Hunting |
| Illegal Access To User Content via PowerSploit modules |
Remote Services, Screen Capture, Audio Capture, Remote Service Session Hijacking |
Lateral Movement |
TTP |
| Illegal Account Creation via PowerSploit modules |
Establish Accounts |
Resource Development |
TTP |
| Illegal Deletion of Logs via Mimikatz modules |
Indicator Removal on Host |
Defense Evasion |
TTP |
| Illegal Enabling or Disabling of Accounts via DSInternals modules |
Valid Accounts, Account Manipulation |
Defense Evasion |
TTP |
| Illegal Management of Active Directory Elements and Policies via DSInternals modules |
Account Manipulation, Rogue Domain Controller, Domain Policy Modification |
Persistence |
TTP |
| Illegal Management of Computers and Active Directory Elements via PowerSploit modules |
Account Manipulation, Rogue Domain Controller, Domain Policy Modification |
Persistence |
TTP |
| Illegal Privilege Elevation and Persistence via PowerSploit modules |
Scheduled Task/Job, Access Token Manipulation, Abuse Elevation Control Mechanism |
Execution |
TTP |
| Illegal Privilege Elevation via Mimikatz modules |
Access Token Manipulation, Abuse Elevation Control Mechanism |
Defense Evasion |
TTP |
| Illegal Service and Process Control via Mimikatz modules |
Process Injection, Native API, System Services |
Defense Evasion |
TTP |
| Illegal Service and Process Control via PowerSploit modules |
Process Injection, Native API, System Services |
Defense Evasion |
TTP |
| Jscript Execution Using Cscript App |
JavaScript |
Execution |
TTP |
| Kerberoasting spn request with RC4 encryption |
Kerberoasting |
Credential Access |
TTP |
| Known Services Killed by Ransomware |
Inhibit System Recovery |
Impact |
TTP |
| Kubernetes AWS detect suspicious kubectl calls |
None |
None |
Hunting |
| Kubernetes Nginx Ingress LFI |
Exploitation for Credential Access |
Credential Access |
TTP |
| Kubernetes Nginx Ingress RFI |
Exploitation for Credential Access |
Credential Access |
TTP |
| Kubernetes Scanner Image Pulling |
Cloud Service Discovery |
Discovery |
TTP |
| Large Volume of DNS ANY Queries |
Reflection Amplification |
Impact |
Anomaly |
| Local Account Discovery With Wmic |
Local Account |
Discovery |
Hunting |
| Local Account Discovery with Net |
Local Account |
Discovery |
Hunting |
| MS Scripting Process Loading Ldap Module |
JavaScript |
Execution |
Anomaly |
| MS Scripting Process Loading WMI Module |
JavaScript |
Execution |
Anomaly |
| MSHTML Module Load in Office Product |
Spearphishing Attachment |
Initial Access |
TTP |
| MacOS - Re-opened Applications |
None |
None |
TTP |
| Mailsniper Invoke functions |
Local Email Collection |
Collection |
TTP |
| Malicious PowerShell Process - Connect To Internet With Hidden Window |
PowerShell |
Execution |
TTP |
| Malicious PowerShell Process - Encoded Command |
Obfuscated Files or Information |
Defense Evasion |
Hunting |
| Malicious PowerShell Process - Execution Policy Bypass |
PowerShell |
Execution |
TTP |
| Malicious PowerShell Process With Obfuscation Techniques |
PowerShell |
Execution |
TTP |
| Malicious Powershell Executed As A Service |
Service Execution |
Execution |
TTP |
| Modification Of Wallpaper |
Defacement |
Impact |
TTP |
| Modify ACL permission To Files Or Folder |
File and Directory Permissions Modification |
Defense Evasion |
TTP |
| Modify ACLs Permission Of Files Or Folders |
File and Directory Permissions Modification |
Defense Evasion |
Anomaly |
| Monitor Email For Brand Abuse |
None |
None |
TTP |
| Monitor Registry Keys for Print Monitors |
Port Monitors |
Persistence |
TTP |
| Monitor Web Traffic For Brand Abuse |
None |
None |
TTP |
| More than usual number of LOLBAS applications in short time period |
Command and Scripting Interpreter, Scheduled Task/Job |
Execution |
Anomaly |
| Mshta spawning Rundll32 OR Regsvr32 Process |
Mshta |
Defense Evasion |
TTP |
| Msmpeng Application DLL Side Loading |
DLL Side-Loading |
Persistence |
TTP |
| Multiple Archive Files Http Post Traffic |
Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
Exfiltration |
TTP |
| Multiple Disabled Users Failing To Authenticate From Host Using Kerberos |
Password Spraying |
Credential Access |
Anomaly |
| Multiple Invalid Users Failing To Authenticate From Host Using Kerberos |
Password Spraying |
Credential Access |
Anomaly |
| Multiple Invalid Users Failing To Authenticate From Host Using NTLM |
Password Spraying |
Credential Access |
Anomaly |
| Multiple Okta Users With Invalid Credentials From The Same IP |
Default Accounts |
Defense Evasion |
TTP |
| Multiple Users Attempting To Authenticate Using Explicit Credentials |
Password Spraying |
Credential Access |
Anomaly |
| Multiple Users Failing To Authenticate From Host Using Kerberos |
Password Spraying |
Credential Access |
Anomaly |
| Multiple Users Failing To Authenticate From Host Using NTLM |
Password Spraying |
Credential Access |
Anomaly |
| Multiple Users Failing To Authenticate From Process |
Password Spraying |
Credential Access |
Anomaly |
| Multiple Users Remotely Failing To Authenticate From Host |
Password Spraying |
Credential Access |
Anomaly |
| NET Profiler UAC bypass |
Bypass User Account Control |
Privilege Escalation |
TTP |
| NLTest Domain Trust Discovery |
Domain Trust Discovery |
Discovery |
TTP |
| Net Localgroup Discovery |
Local Groups |
Discovery |
Hunting |
| Network Connection Discovery With Arp |
System Network Connections Discovery |
Discovery |
Hunting |
| Network Connection Discovery With Net |
System Network Connections Discovery |
Discovery |
Hunting |
| Network Connection Discovery With Netstat |
System Network Connections Discovery |
Discovery |
Hunting |
| New container uploaded to AWS ECR |
Implant Internal Image |
Persistence |
Hunting |
| Nishang PowershellTCPOneLine |
PowerShell |
Execution |
TTP |
| No Windows Updates in a time frame |
None |
None |
Hunting |
| Non Chrome Process Accessing Chrome Default Dir |
Credentials from Web Browsers |
Credential Access |
Anomaly |
| Non Firefox Process Access Firefox Profile Dir |
Credentials from Web Browsers |
Credential Access |
Anomaly |
| Ntdsutil Export NTDS |
NTDS |
Credential Access |
TTP |
| O365 Add App Role Assignment Grant User |
Cloud Account |
Persistence |
TTP |
| O365 Added Service Principal |
Cloud Account |
Persistence |
TTP |
| O365 Bypass MFA via Trusted IP |
Disable or Modify Cloud Firewall |
Defense Evasion |
TTP |
| O365 Disable MFA |
Modify Authentication Process |
Credential Access |
TTP |
| O365 Excessive Authentication Failures Alert |
Brute Force |
Credential Access |
Anomaly |
| O365 Excessive SSO logon errors |
Modify Authentication Process |
Credential Access |
Anomaly |
| O365 New Federated Domain Added |
Cloud Account |
Persistence |
TTP |
| O365 PST export alert |
Email Collection |
Collection |
TTP |
| O365 Suspicious Admin Email Forwarding |
Email Forwarding Rule |
Collection |
Anomaly |
| O365 Suspicious Rights Delegation |
Remote Email Collection |
Collection |
TTP |
| O365 Suspicious User Email Forwarding |
Email Forwarding Rule |
Collection |
Anomaly |
| Office Application Drop Executable |
Spearphishing Attachment |
Initial Access |
TTP |
| Office Application Spawn Regsvr32 process |
Spearphishing Attachment |
Initial Access |
TTP |
| Office Application Spawn rundll32 process |
Spearphishing Attachment |
Initial Access |
TTP |
| Office Document Creating Schedule Task |
Spearphishing Attachment |
Initial Access |
TTP |
| Office Document Executing Macro Code |
Spearphishing Attachment |
Initial Access |
TTP |
| Office Document Spawned Child Process To Download |
Spearphishing Attachment |
Initial Access |
TTP |
| Office Product Spawn CMD Process |
Mshta |
Defense Evasion |
TTP |
| Office Product Spawning BITSAdmin |
Spearphishing Attachment |
Initial Access |
TTP |
| Office Product Spawning CertUtil |
Spearphishing Attachment |
Initial Access |
TTP |
| Office Product Spawning MSHTA |
Spearphishing Attachment |
Initial Access |
TTP |
| Office Product Spawning Rundll32 with no DLL |
Spearphishing Attachment |
Initial Access |
TTP |
| Office Product Spawning Wmic |
Spearphishing Attachment |
Initial Access |
TTP |
| Office Product Writing cab or inf |
Spearphishing Attachment |
Initial Access |
TTP |
| Office Spawning Control |
Spearphishing Attachment |
Initial Access |
TTP |
| Okta Account Lockout Events |
Default Accounts |
Defense Evasion |
Anomaly |
| Okta Failed SSO Attempts |
Default Accounts |
Defense Evasion |
Anomaly |
| Okta User Logins From Multiple Cities |
Default Accounts |
Defense Evasion |
Anomaly |
| Overwriting Accessibility Binaries |
Accessibility Features |
Privilege Escalation |
TTP |
| Password Policy Discovery with Net |
Password Policy Discovery |
Discovery |
Hunting |
| Permission Modification using Takeown App |
File and Directory Permissions Modification |
Defense Evasion |
TTP |
| PetitPotam Network Share Access Request |
Forced Authentication |
Credential Access |
TTP |
| PetitPotam Suspicious Kerberos TGT Request |
OS Credential Dumping |
Credential Access |
TTP |
| Phishing Email Detection by Machine Learning Method - SSA |
Phishing |
Initial Access |
Anomaly |
| Plain HTTP POST Exfiltrated Data |
Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
Exfiltration |
TTP |
| Potential Pass the Token or Hash Observed at the Destination Device |
Pass the Hash |
Defense Evasion |
TTP |
| Potential Pass the Token or Hash Observed by an Event Collecting Device |
Pass the Hash |
Defense Evasion |
TTP |
| PowerShell 4104 Hunting |
PowerShell |
Execution |
Hunting |
| PowerShell Domain Enumeration |
PowerShell |
Execution |
TTP |
| PowerShell Get LocalGroup Discovery |
Local Groups |
Discovery |
Hunting |
| PowerShell Loading DotNET into Memory via System Reflection Assembly |
PowerShell |
Execution |
TTP |
| PowerShell Start-BitsTransfer |
BITS Jobs |
Defense Evasion |
TTP |
| Powershell Creating Thread Mutex |
Indicator Removal from Tools |
Defense Evasion |
TTP |
| Powershell Disable Security Monitoring |
Disable or Modify Tools |
Defense Evasion |
TTP |
| Powershell Enable SMB1Protocol Feature |
Indicator Removal from Tools |
Defense Evasion |
TTP |
| Powershell Execute COM Object |
Component Object Model Hijacking |
Privilege Escalation |
TTP |
| Powershell Fileless Process Injection via GetProcAddress |
Process Injection, PowerShell |
Defense Evasion |
TTP |
| Powershell Fileless Script Contains Base64 Encoded Content |
Obfuscated Files or Information, PowerShell |
Defense Evasion |
TTP |
| Powershell Get LocalGroup Discovery with Script Block Logging |
Local Groups |
Discovery |
Hunting |
| Powershell Processing Stream Of Data |
PowerShell |
Execution |
TTP |
| Powershell Remote Thread To Known Windows Process |
Process Injection |
Defense Evasion |
TTP |
| Powershell Using memory As Backing Store |
Deobfuscate/Decode Files or Information |
Defense Evasion |
TTP |
| Prevent Automatic Repair Mode using Bcdedit |
Inhibit System Recovery |
Impact |
TTP |
| Print Spooler Adding A Printer Driver |
Print Processors |
Persistence |
TTP |
| Print Spooler Failed to Load a Plug-in |
Print Processors |
Persistence |
TTP |
| Probing Access with Stolen Credentials via PowerSploit modules |
Valid Accounts, Account Manipulation |
Defense Evasion |
TTP |
| Process Creating LNK file in Suspicious Location |
Spearphishing Link |
Initial Access |
TTP |
| Process Deleting Its Process File Path |
Indicator Removal on Host |
Defense Evasion |
TTP |
| Process Execution via WMI |
Windows Management Instrumentation |
Execution |
TTP |
| Process Kill Base On File Path |
Disable or Modify Tools |
Defense Evasion |
TTP |
| Processes Tapping Keyboard Events |
None |
None |
TTP |
| Processes launching netsh |
Disable or Modify System Firewall |
Defense Evasion |
TTP |
| Prohibited Network Traffic Allowed |
Exfiltration Over Alternative Protocol |
Exfiltration |
TTP |
| Protocol or Port Mismatch |
Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol |
Exfiltration |
Anomaly |
| Protocols passing authentication in cleartext |
None |
None |
TTP |
| Ransomware Notes bulk creation |
Data Encrypted for Impact |
Impact |
Anomaly |
| Rare Parent-Child Process Relationship |
Exploitation for Client Execution, Command and Scripting Interpreter, Scheduled Task/Job, Software Deployment Tools |
Execution |
Anomaly |
| Recon AVProduct Through Pwh or WMI |
Gather Victim Host Information |
Reconnaissance |
TTP |
| Recon Using WMI Class |
Gather Victim Host Information |
Reconnaissance |
TTP |
| Reconnaissance and Access to Accounts Groups and Policies via PowerSploit modules |
Valid Accounts, Account Discovery, Domain Policy Modification |
Defense Evasion |
TTP |
| Reconnaissance and Access to Accounts and Groups via Mimikatz modules |
Valid Accounts, Account Discovery, Domain Policy Modification |
Defense Evasion |
TTP |
| Reconnaissance and Access to Active Directoty Infrastructure via PowerSploit modules |
Trusted Relationship, Domain Trust Discovery, Gather Victim Network Information, Gather Victim Org Information, Active Scanning |
Initial Access |
TTP |
| Reconnaissance and Access to Computers and Domains via PowerSploit modules |
Gather Victim Host Information, Gather Victim Network Information, Account Discovery |
Reconnaissance |
TTP |
| Reconnaissance and Access to Computers via Mimikatz modules |
Gather Victim Host Information |
Reconnaissance |
TTP |
| Reconnaissance and Access to Operating System Elements via PowerSploit modules |
System Service Discovery, Query Registry, Network Service Scanning, Windows Management Instrumentation, Process Discovery, File and Directory Discovery, Software Discovery, Software |
Discovery |
TTP |
| Reconnaissance and Access to Processes and Services via Mimikatz modules |
System Service Discovery, Network Service Scanning, Process Discovery |
Discovery |
TTP |
| Reconnaissance and Access to Shared Resources via Mimikatz modules |
SMB/Windows Admin Shares, Network Share Discovery, Data from Network Shared Drive |
Lateral Movement |
TTP |
| Reconnaissance and Access to Shared Resources via PowerSploit modules |
SMB/Windows Admin Shares, Network Share Discovery, Data from Network Shared Drive |
Lateral Movement |
TTP |
| Reconnaissance of Access and Persistence Opportunities via PowerSploit modules |
Scheduled Task/Job, Exploitation for Privilege Escalation, Valid Accounts, Create or Modify System Process, Boot or Logon Autostart Execution, Hijack Execution Flow |
Execution |
TTP |
| Reconnaissance of Connectivity via PowerSploit modules |
SMB/Windows Admin Shares, Network Share Discovery, Data from Network Shared Drive |
Lateral Movement |
TTP |
| Reconnaissance of Credential Stores and Services via Mimikatz modules |
Credentials, Domain Properties, Network Trust Dependencies, Exploitation for Privilege Escalation, Valid Accounts, Account Manipulation |
Reconnaissance |
TTP |
| Reconnaissance of Defensive Tools via PowerSploit modules |
Vulnerability Scanning, Software |
Reconnaissance |
TTP |
| Reconnaissance of Privilege Escalation Opportunities via PowerSploit modules |
Exploitation for Privilege Escalation, Valid Accounts, Account Manipulation |
Privilege Escalation |
TTP |
| Reconnaissance of Process or Service Hijacking Opportunities via Mimikatz modules |
Create or Modify System Process, Process Injection, Hijack Execution Flow |
Persistence |
TTP |
| Recursive Delete of Directory In Batch CMD |
File Deletion |
Defense Evasion |
TTP |
| Reg exe Manipulating Windows Services Registry Keys |
Services Registry Permissions Weakness |
Persistence |
TTP |
| Registry Keys Used For Persistence |
Registry Run Keys / Startup Folder |
Persistence |
TTP |
| Registry Keys Used For Privilege Escalation |
Image File Execution Options Injection |
Privilege Escalation |
TTP |
| Registry Keys for Creating SHIM Databases |
Application Shimming |
Privilege Escalation |
TTP |
| Remcos RAT File Creation in Remcos Folder |
Screen Capture |
Collection |
TTP |
| Remote Desktop Network Bruteforce |
Remote Desktop Protocol |
Lateral Movement |
TTP |
| Remote Desktop Network Traffic |
Remote Desktop Protocol |
Lateral Movement |
Anomaly |
| Remote Desktop Process Running On System |
Remote Desktop Protocol |
Lateral Movement |
Hunting |
| Remote Process Instantiation via WMI |
Windows Management Instrumentation |
Execution |
TTP |
| Remote System Discovery with Adsisearcher |
Remote System Discovery |
Discovery |
TTP |
| Remote System Discovery with Dsquery |
Remote System Discovery |
Discovery |
Hunting |
| Remote System Discovery with Net |
Remote System Discovery |
Discovery |
Hunting |
| Remote System Discovery with Wmic |
Remote System Discovery |
Discovery |
TTP |
| Remote WMI Command Attempt |
Windows Management Instrumentation |
Execution |
TTP |
| Resize ShadowStorage volume |
Inhibit System Recovery |
Impact |
TTP |
| Resize Shadowstorage Volume |
Service Stop |
Impact |
TTP |
| Revil Common Exec Parameter |
User Execution |
Execution |
TTP |
| Revil Registry Entry |
Modify Registry |
Defense Evasion |
TTP |
| RunDLL Loading DLL By Ordinal |
Rundll32 |
Defense Evasion |
TTP |
| Rundll32 Control RunDLL Hunt |
Rundll32 |
Defense Evasion |
Hunting |
| Rundll32 Control RunDLL World Writable Directory |
Rundll32 |
Defense Evasion |
TTP |
| Rundll32 Create Remote Thread To A Process |
Process Injection |
Defense Evasion |
TTP |
| Rundll32 CreateRemoteThread In Browser |
Process Injection |
Defense Evasion |
TTP |
| Rundll32 DNSQuery |
Rundll32 |
Defense Evasion |
TTP |
| Rundll32 Process Creating Exe Dll Files |
Rundll32 |
Defense Evasion |
TTP |
| Rundll32 with no Command Line Arguments with Network |
Rundll32 |
Defense Evasion |
TTP |
| Ryuk Test Files Detected |
Data Encrypted for Impact |
Impact |
TTP |
| Ryuk Wake on LAN Command |
Windows Command Shell |
Execution |
TTP |
| SAM Database File Access Attempt |
Security Account Manager |
Credential Access |
Hunting |
| SLUI RunAs Elevated |
Bypass User Account Control |
Privilege Escalation |
TTP |
| SLUI Spawning a Process |
Bypass User Account Control |
Privilege Escalation |
TTP |
| SMB Traffic Spike |
SMB/Windows Admin Shares |
Lateral Movement |
Anomaly |
| SMB Traffic Spike - MLTK |
SMB/Windows Admin Shares |
Lateral Movement |
Anomaly |
| SQL Injection with Long URLs |
Exploit Public-Facing Application |
Initial Access |
TTP |
| Samsam Test File Write |
Data Encrypted for Impact |
Impact |
TTP |
| Sc exe Manipulating Windows Services |
Windows Service |
Persistence |
TTP |
| SchCache Change By App Connect And Create ADSI Object |
Domain Account |
Discovery |
Anomaly |
| Schedule Task with HTTP Command Arguments |
Scheduled Task/Job |
Execution |
TTP |
| Schedule Task with Rundll32 Command Trigger |
Scheduled Task/Job |
Execution |
TTP |
| Scheduled Task Deleted Or Created via CMD |
Scheduled Task |
Execution |
TTP |
| Schtasks Run Task On Demand |
Scheduled Task/Job |
Execution |
TTP |
| Schtasks scheduling job on remote system |
Scheduled Task |
Execution |
TTP |
| Schtasks used for forcing a reboot |
Scheduled Task |
Execution |
TTP |
| Script Execution via WMI |
Windows Management Instrumentation |
Execution |
TTP |
| Sdclt UAC Bypass |
Bypass User Account Control |
Privilege Escalation |
TTP |
| SearchProtocolHost with no Command Line with Network |
Process Injection |
Defense Evasion |
TTP |
| SecretDumps Offline NTDS Dumping Tool |
NTDS |
Credential Access |
TTP |
| Services Escalate Exe |
Abuse Elevation Control Mechanism |
Privilege Escalation |
TTP |
| Set Default PowerShell Execution Policy To Unrestricted or Bypass |
PowerShell |
Execution |
TTP |
| Setting Credentials via DSInternals modules |
Exploitation for Privilege Escalation, Valid Accounts, Account Manipulation |
Privilege Escalation |
TTP |
| Setting Credentials via Mimikatz modules |
Exploitation for Privilege Escalation, Valid Accounts, Account Manipulation |
Privilege Escalation |
TTP |
| Setting Credentials via PowerSploit modules |
Exploitation for Privilege Escalation, Valid Accounts, Account Manipulation |
Privilege Escalation |
TTP |
| Shim Database File Creation |
Application Shimming |
Privilege Escalation |
TTP |
| Shim Database Installation With Suspicious Parameters |
Application Shimming |
Privilege Escalation |
TTP |
| Short Lived Windows Accounts |
Local Account |
Persistence |
TTP |
| SilentCleanup UAC Bypass |
Bypass User Account Control |
Privilege Escalation |
TTP |
| Single Letter Process On Endpoint |
Malicious File |
Execution |
TTP |
| Spike in File Writes |
None |
None |
Anomaly |
| Spoolsv Spawning Rundll32 |
Print Processors |
Persistence |
TTP |
| Spoolsv Suspicious Loaded Modules |
Print Processors |
Persistence |
TTP |
| Spoolsv Suspicious Process Access |
Exploitation for Privilege Escalation |
Privilege Escalation |
TTP |
| Spoolsv Writing a DLL |
Print Processors |
Persistence |
TTP |
| Spoolsv Writing a DLL - Sysmon |
Print Processors |
Persistence |
TTP |
| Sqlite Module In Temp Folder |
Data from Local System |
Collection |
TTP |
| Start Up During Safe Mode Boot |
Registry Run Keys / Startup Folder |
Persistence |
TTP |
| Sunburst Correlation DLL and Network Event |
Exploitation for Client Execution |
Execution |
TTP |
| Supernova Webshell |
Web Shell |
Persistence |
TTP |
| Suspicious Curl Network Connection |
Ingress Tool Transfer |
Command And Control |
TTP |
| Suspicious DLLHost no Command Line Arguments |
Process Injection |
Defense Evasion |
TTP |
| Suspicious Driver Loaded Path |
Windows Service |
Persistence |
TTP |
| Suspicious Email Attachment Extensions |
Spearphishing Attachment |
Initial Access |
Anomaly |
| Suspicious Event Log Service Behavior |
Clear Windows Event Logs |
Defense Evasion |
TTP |
| Suspicious GPUpdate no Command Line Arguments |
Process Injection |
Defense Evasion |
TTP |
| Suspicious IcedID Regsvr32 Cmdline |
Regsvr32 |
Defense Evasion |
TTP |
| Suspicious IcedID Rundll32 Cmdline |
Rundll32 |
Defense Evasion |
TTP |
| Suspicious Image Creation In Appdata Folder |
Screen Capture |
Collection |
TTP |
| Suspicious Java Classes |
None |
None |
Anomaly |
| Suspicious MSBuild Rename |
MSBuild, Rename System Utilities |
Defense Evasion |
TTP |
| Suspicious MSBuild Spawn |
MSBuild |
Defense Evasion |
TTP |
| Suspicious PlistBuddy Usage |
Launch Agent |
Persistence |
TTP |
| Suspicious PlistBuddy Usage via OSquery |
Launch Agent |
Persistence |
TTP |
| Suspicious Process File Path |
Create or Modify System Process |
Persistence |
TTP |
| Suspicious Reg exe Process |
Modify Registry |
Defense Evasion |
TTP |
| Suspicious Regsvr32 Register Suspicious Path |
Regsvr32 |
Defense Evasion |
TTP |
| Suspicious Rundll32 PluginInit |
Rundll32 |
Defense Evasion |
TTP |
| Suspicious Rundll32 Rename |
Rundll32, Rename System Utilities |
Defense Evasion |
Hunting |
| Suspicious Rundll32 StartW |
Rundll32 |
Defense Evasion |
TTP |
| Suspicious Rundll32 dllregisterserver |
Rundll32 |
Defense Evasion |
TTP |
| Suspicious Rundll32 no Command Line Arguments |
Rundll32 |
Defense Evasion |
TTP |
| Suspicious SQLite3 LSQuarantine Behavior |
Data Staged |
Collection |
TTP |
| Suspicious Scheduled Task from Public Directory |
Scheduled Task |
Execution |
Anomaly |
| Suspicious SearchProtocolHost no Command Line Arguments |
Process Injection |
Defense Evasion |
TTP |
| Suspicious WAV file in Appdata Folder |
Screen Capture |
Collection |
TTP |
| Suspicious microsoft workflow compiler rename |
Trusted Developer Utilities Proxy Execution, Rename System Utilities |
Defense Evasion |
Hunting |
| Suspicious microsoft workflow compiler usage |
Trusted Developer Utilities Proxy Execution |
Defense Evasion |
TTP |
| Suspicious msbuild path |
MSBuild, Rename System Utilities |
Defense Evasion |
TTP |
| Suspicious mshta child process |
Mshta |
Defense Evasion |
TTP |
| Suspicious mshta spawn |
Mshta |
Defense Evasion |
TTP |
| Suspicious wevtutil Usage |
Clear Windows Event Logs |
Defense Evasion |
TTP |
| Suspicious writes to windows Recycle Bin |
Masquerading |
Defense Evasion |
TTP |
| System Information Discovery Detection |
System Information Discovery |
Discovery |
TTP |
| System Process Running from Unexpected Location |
Masquerading |
Defense Evasion |
Anomaly |
| System Processes Run From Unexpected Locations |
Rename System Utilities |
Defense Evasion |
TTP |
| System User Discovery With Query |
System Owner/User Discovery |
Discovery |
Hunting |
| System User Discovery With Whoami |
System Owner/User Discovery |
Discovery |
Hunting |
| TOR Traffic |
Web Protocols |
Command And Control |
TTP |
| Trickbot Named Pipe |
Process Injection |
Defense Evasion |
TTP |
| UAC Bypass MMC Load Unsigned Dll |
Bypass User Account Control |
Privilege Escalation |
TTP |
| UAC Bypass With Colorui COM Object |
CMSTP |
Defense Evasion |
TTP |
| USN Journal Deletion |
Indicator Removal on Host |
Defense Evasion |
TTP |
| Unified Messaging Service Spawning a Process |
Exploit Public-Facing Application |
Initial Access |
TTP |
| Uninstall App Using MsiExec |
Msiexec |
Defense Evasion |
TTP |
| Unload Sysmon Filter Driver |
Disable or Modify Tools |
Defense Evasion |
TTP |
| Unloading AMSI via Reflection |
Impair Defenses |
Defense Evasion |
TTP |
| Unusually Long Command Line |
None |
None |
Anomaly |
| Unusually Long Command Line |
None |
None |
Anomaly |
| Unusually Long Command Line - MLTK |
None |
None |
Anomaly |
| Unusually Long Content-Type Length |
None |
None |
Anomaly |
| User Discovery With Env Vars PowerShell |
System Owner/User Discovery |
Discovery |
Hunting |
| User Discovery With Env Vars PowerShell Script Block |
System Owner/User Discovery |
Discovery |
Hunting |
| W3WP Spawning Shell |
Web Shell |
Persistence |
TTP |
| WBAdmin Delete System Backups |
Inhibit System Recovery |
Impact |
TTP |
| WMI Permanent Event Subscription |
Windows Management Instrumentation |
Execution |
TTP |
| WMI Permanent Event Subscription - Sysmon |
Windows Management Instrumentation Event Subscription |
Privilege Escalation |
TTP |
| WMI Recon Running Process Or Services |
Gather Victim Host Information |
Reconnaissance |
TTP |
| WMI Temporary Event Subscription |
Windows Management Instrumentation |
Execution |
TTP |
| WSReset UAC Bypass |
Bypass User Account Control |
Privilege Escalation |
TTP |
| Wbemprox COM Object Execution |
CMSTP |
Defense Evasion |
TTP |
| Web Servers Executing Suspicious Processes |
System Information Discovery |
Discovery |
TTP |
| Wermgr Process Connecting To IP Check Web Services |
IP Addresses |
Reconnaissance |
TTP |
| Wermgr Process Create Executable File |
Obfuscated Files or Information |
Defense Evasion |
TTP |
| Wermgr Process Spawned CMD Or Powershell Process |
Command and Scripting Interpreter |
Execution |
TTP |
| WevtUtil Usage To Clear Logs |
Clear Windows Event Logs |
Defense Evasion |
TTP |
| Wevtutil Usage To Disable Logs |
Clear Windows Event Logs |
Defense Evasion |
TTP |
| WinEvent Scheduled Task Created Within Public Path |
Scheduled Task |
Execution |
TTP |
| WinEvent Scheduled Task Created to Spawn Shell |
Scheduled Task |
Execution |
TTP |
| WinRM Spawning a Process |
Exploit Public-Facing Application |
Initial Access |
TTP |
| Windows AdFind Exe |
Remote System Discovery |
Discovery |
TTP |
| Windows DisableAntiSpyware Registry |
Disable or Modify Tools |
Defense Evasion |
TTP |
| Windows Event Log Cleared |
Clear Windows Event Logs |
Defense Evasion |
TTP |
| Windows Security Account Manager Stopped |
Service Stop |
Impact |
TTP |
| Winword Spawning Cmd |
Spearphishing Attachment |
Initial Access |
TTP |
| Winword Spawning PowerShell |
Spearphishing Attachment |
Initial Access |
TTP |
| Winword Spawning Windows Script Host |
Spearphishing Attachment |
Initial Access |
TTP |
| Wmic Group Discovery |
Local Groups |
Discovery |
Hunting |
| Write Executable in SMB Share |
SMB/Windows Admin Shares |
Lateral Movement |
TTP |
| XMRIG Driver Loaded |
Windows Service |
Persistence |
TTP |
| XSL Script Execution With WMIC |
XSL Script Processing |
Defense Evasion |
TTP |
| aws detect attach to role policy |
Valid Accounts |
Defense Evasion |
Hunting |
| aws detect permanent key creation |
Valid Accounts |
Defense Evasion |
Hunting |
| aws detect role creation |
Valid Accounts |
Defense Evasion |
Hunting |
| aws detect sts assume role abuse |
Valid Accounts |
Defense Evasion |
Hunting |
| aws detect sts get session token abuse |
Use Alternate Authentication Material |
Defense Evasion |
Hunting |