ENDPOINT & ADVERSARY
Endpoint & Adversary Techniques
Endpoint tradecraft, privilege and persistence techniques, and adversary implementation research.
← All categoriesNOTE
Note
3PROCEDURE
Procedure
5601
Malicious Macro Launches a bat Script Through the Shell Function to Execute Commands
↗02Launching Calculator by Invoking Malicious Macro Code Through Word Template Injection
↗03Creating a Scheduled Task Through Macro Code
↗04Using Bad-PDF to Steal NTLM Hashes from a Windows Host
↗05Exporting Domain Credential Files Through Direct Volume Access with NinjaCopy
↗06Stealing Domain Users' Plaintext Passwords with a Windows Password Filter DLL
↗07Dumping Domain Cached Credentials (mscash) with cachedump
↗08Abusing Security Support Provider (SSP) to Steal Domain Controller User Credentials
↗09Exporting User Credentials from the Proc File System Through MimiPenguin
↗10Obtaining Domain Password Credentials with NtdsAudit
↗11Using C++ to Call ntdll.RtlCompressBuffer to Compress Collected Data
↗12SNMP Service Brute Force and Information Gathering
↗13Testing Target Connectivity with the Test-Connection Function in PowerShell
↗14Collecting Information on windows with powershell and Saving It to the File System as html
↗15Gathering Network Information on windows Systems Through Command Execution
↗16Verifying a User's Working Environment by Counting Files in the Documents Directory
↗17Detecting a Sandbox Environment by Calculating Active Window Titles and Checking a Specific Module
↗18mavinject.exe
↗19Arbitrary Command Execution Using the Mssql sp_procoption Stored Procedure
↗20Injecting Malicious Code into a Legitimate Process Through Process Hollowing and Executing It
↗21Creating a windows Service with powershell
↗22Creating a Scheduled Task with powershell
↗23Achieving Persistence by Adding a Registry Startup Entry with a powershell Script
↗24Maintaining Access by Combining the Windows Screen Saver Feature with MSF
↗25Maintaining Access to a Windows System with a Word WLL Add-In
↗26Maintaining Access by Creating a windows System Service Backdoor with powershell
↗27Maintaining Access by Abusing a systemd Timer to Create a Scheduled Task
↗28Creating a Scheduled Task Through the ITaskService COM Component to Achieve Automatic Startup
↗29Maintaining Access to a Windows System Through DLL Hijacking Combined with MSF
↗30Maintaining Windows Access by Creating a VBS Backdoor with MSF persistence
↗31Setting the Registry Startup Item to calc.exe Through a VBS Script
↗32Maintaining Access by Executing a Backdoor Through Default File Associations
↗33Using the Local APPINFO RPC Service to Bypass Windows UAC and Launch a High-Privilege Application
↗34Bypassing UAC Through Registry Hijacking
↗35Modifying Process Access-Token Privileges with AdjustTokenPrivileges
↗36Disabling UAC by Modifying the Registry
↗37Obtaining a High-Privilege Shell by Hijacking a Binary Used by the 7-Zip Installer
↗38System Privilege Escalation by Obtaining windows Patch Information
↗39Obtaining a Host Shell by Executing a Payload with the Allowlisted Rundll32.exe
↗40Obtaining Shell Access by Executing a Payload with the Allowlisted zipfldr.dll
↗41Abusing MSXSL.EXE to Execute an XSL File for Arbitrary Command Execution
↗42Abusing the WindowsUpdate Program to Execute a Malicious DLL and Obtain Host Access
↗43Abusing the Allowlisted IEexec.exe to Execute a Backdoor and Obtain Host Access
↗44Obtaining Windows System Privileges Through CLR Hijacking Combined with MSF
↗45Side-Loading a Malicious duser.dll Through the Allowlisted rekeywiz.exe to Launch Calculator
↗46Listening on a Specified Port on Windows with PowerShell
↗47Creating a New Directory on a Specified FTP Server Through powershell
↗48Decoding a Server Port from Base64 Multiple Times with PowerShell
↗49Clearing Traces on Windows with a BAT Program
↗50Using powershell to Copy a File to a System Directory and Disguise It as a Normal File
↗51Using mklink to Execute a File's ADS Alternate Data Stream
↗52Stopping the Windows Volume Shadow Copy Service with PowerShell
↗53Setting a File or Directory's Attributes to Hidden with PowerShell
↗54Deleting Disk Volume Shadow Copies Through WMI
↗55Evading Antivirus Detection with ADS Alternate Data Streams
↗56Disabling Office Macro Warnings Through the Registry to Execute Macro Code More Stealthily
↗ANALYSIS