Version: 1.70032

Released Date: Feb 08, 2024 14:26

Modified (28)

Version
Name

Total: 28

Name
ATT&CK Tactics & Techniques
Status
Update
ATT&CK Version
Check Python
Mod
Check to see what version of python is installed.
V10
Check Security Services
Mod
This ability checks for security services.
V10
Clear Logs
Mod
This ability clears Sysmon logs.
V10
CMSTP Executing UAC Bypass
Mod
CMSTP Executing UAC Bypass.
V10
Compiled HTML Help Local Payload
Mod
This ability uses hh.exe to execute a local compiled HTML Help payload.
V10
Compress Staged Directory
Mod
Compress a directory on the file system.
V10
Create Staging Directory
Mod
This ability creates a directory for exfil staging.
V10
Discover PowerShell Version
Mod
This ability discover the PowerShell version.
V10
Emulate Administrator Tasks
Mod
This ability emulates administrator tasks on a system in a separate process.
V10
Exfiltrate Data Via HTTPS
Mod
This ability creates a test file on the target machine and uploads it to file share website.
V10
Find AV Signature
Mod
This ability uses PowerSploits Find-AVSignature AntivirusBypass module to locate single byte anti-virus signatures.
V10
Find Files
Mod
This ability locates files deemed sensitive.
V10
Find Nonstandard Shares
Mod
This ability finds non-standard shares on the target machine in the domain.
V10
Get GPP Password
Mod
This ability finds the encrypted cpassword value within Group Policy Preference files on the Domain Controller.
V10
Hook PowerShell TLS Encrypt/Decrypt Messages
Mod
Hooks functions in PowerShell to read TLS Communications..
V10
Install PowerShell Core 6
Mod
Download, install and start new process under PowerShell Core 6.
V10
Invoke-MemeKatz
Mod
This ability downloads random meme and sets as desktop background.
V10
MSBuild Bypass Using Inline Tasks (C#)
Mod
Executes the code in a project file using msbuild.exe.
V10
MSBuild Bypass Using Inline Tasks (VB)
Mod
Executes the code in a project file using msbuild.exe.
V10
PowerShell Information Gathering
Mod
This ability collects information by PowerShell.
V10
PowerShell Process Enumeration
Mod
This ability captures running processes via PowerShell.
V10
Regsvr32 Local COM Scriptlet Execution
Mod
Regsvr32 Local COM Scriptlet Execution.
V10
Rundll32 syssetup.dll Execution
Mod
Test execution of a command using rundll32.exe with syssetup.dll.
V10
Screen Capture
Mod
Capture the contents of the screen.
V10
Stop PowerShell Processes
Mod
This ability stops all PowerShell processes.
V10
SysInternals PSTool Process Discovery
Mod
Process discovery via SysInternals pstool.
V10
View Admin Shares
Mod
Network share discovery.
V10