| Active Setup Registry Autostart |
Active Setup, Boot or Logon Autostart Execution |
TTP |
| Certutil exe certificate extraction |
|
TTP |
| Change Default File Association |
Change Default File Association, Event Triggered Execution |
TTP |
| Detect Path Interception By Creation Of program exe |
Path Interception by Unquoted Path, Hijack Execution Flow |
TTP |
| ETW Registry Disabled |
Indicator Blocking, Trusted Developer Utilities Proxy Execution, Impair Defenses |
TTP |
| Hiding Files And Directories With Attrib exe |
File and Directory Permissions Modification, Windows File and Directory Permissions Modification |
TTP |
| Illegal Account Creation via PowerSploit modules |
Establish Accounts |
TTP |
| Illegal Enabling or Disabling of Accounts via DSInternals modules |
Valid Accounts, Account Manipulation |
TTP |
| Illegal Management of Active Directory Elements and Policies via DSInternals modules |
Account Manipulation, Rogue Domain Controller, Domain Policy Modification |
TTP |
| Illegal Management of Computers and Active Directory Elements via PowerSploit modules |
Account Manipulation, Rogue Domain Controller, Domain Policy Modification |
TTP |
| Illegal Privilege Elevation and Persistence via PowerSploit modules |
Scheduled Task/Job, Access Token Manipulation, Abuse Elevation Control Mechanism |
TTP |
| Logon Script Event Trigger Execution |
Boot or Logon Initialization Scripts, Logon Script (Windows) |
TTP |
| Monitor Registry Keys for Print Monitors |
Port Monitors, Boot or Logon Autostart Execution |
TTP |
| Print Processor Registry Autostart |
Print Processors, Boot or Logon Autostart Execution |
TTP |
| Reg exe Manipulating Windows Services Registry Keys |
Services Registry Permissions Weakness, Hijack Execution Flow |
TTP |
| Registry Keys Used For Persistence |
Registry Run Keys / Startup Folder, Boot or Logon Autostart Execution |
TTP |
| Registry Keys for Creating SHIM Databases |
Application Shimming, Event Triggered Execution |
TTP |
| Sc exe Manipulating Windows Services |
Windows Service, Create or Modify System Process |
TTP |
| Schedule Task with HTTP Command Arguments |
Scheduled Task/Job |
TTP |
| Schedule Task with Rundll32 Command Trigger |
Scheduled Task/Job |
TTP |
| Schtasks used for forcing a reboot |
Scheduled Task, Scheduled Task/Job |
TTP |
| Screensaver Event Trigger Execution |
Event Triggered Execution, Screensaver |
TTP |
| Setting Credentials via DSInternals modules |
Exploitation for Privilege Escalation, Valid Accounts, Account Manipulation |
TTP |
| Setting Credentials via Mimikatz modules |
Exploitation for Privilege Escalation, Valid Accounts, Account Manipulation |
TTP |
| Setting Credentials via PowerSploit modules |
Exploitation for Privilege Escalation, Valid Accounts, Account Manipulation |
TTP |
| Shim Database File Creation |
Application Shimming, Event Triggered Execution |
TTP |
| Shim Database Installation With Suspicious Parameters |
Application Shimming, Event Triggered Execution |
TTP |
| Suspicious Scheduled Task from Public Directory |
Scheduled Task, Scheduled Task/Job |
Anomaly |
| Time Provider Persistence Registry |
Time Providers, Boot or Logon Autostart Execution |
TTP |
| WinEvent Scheduled Task Created Within Public Path |
Scheduled Task, Scheduled Task/Job |
TTP |
| WinEvent Scheduled Task Created to Spawn Shell |
Scheduled Task, Scheduled Task/Job |
TTP |
| WinEvent Windows Task Scheduler Event Action Started |
Scheduled Task |
Hunting |