Akira - G1024 (46bb06cb-f2d9-4b37-8c92-a27e224ad90d) |
Intrusion Set |
Mimikatz - S0002 (afc079f3-c0ea-4096-b75d-3f05338b7f60) |
mitre-tool |
1 |
Akira - G1024 (46bb06cb-f2d9-4b37-8c92-a27e224ad90d) |
Intrusion Set |
Valid Accounts - T1078 (b17a1a56-e99c-403c-8948-561df0cffe81) |
Attack Pattern |
1 |
Akira - G1024 (46bb06cb-f2d9-4b37-8c92-a27e224ad90d) |
Intrusion Set |
Akira - S1129 (6f6b2353-4b39-40ce-9d6d-d00b7a61e656) |
Malware |
1 |
Akira - G1024 (46bb06cb-f2d9-4b37-8c92-a27e224ad90d) |
Intrusion Set |
Account Access Removal - T1531 (b24e2a20-3b3d-4bf0-823b-1ed765398fb0) |
Attack Pattern |
1 |
Akira - G1024 (46bb06cb-f2d9-4b37-8c92-a27e224ad90d) |
Intrusion Set |
Exfiltration to Cloud Storage - T1567.002 (bf1b6176-597c-4600-bfcd-ac989670f96b) |
Attack Pattern |
1 |
Akira - G1024 (46bb06cb-f2d9-4b37-8c92-a27e224ad90d) |
Intrusion Set |
LaZagne - S0349 (b76b2d94-60e4-4107-a903-4a3a7622fb3b) |
mitre-tool |
1 |
Akira - G1024 (46bb06cb-f2d9-4b37-8c92-a27e224ad90d) |
Intrusion Set |
Archive via Utility - T1560.001 (00f90846-cbd1-4fc5-9233-df5c2bf2a662) |
Attack Pattern |
1 |
Akira - G1024 (46bb06cb-f2d9-4b37-8c92-a27e224ad90d) |
Intrusion Set |
Domain Trust Discovery - T1482 (767dbf9e-df3f-45cb-8998-4903ab5f80c0) |
Attack Pattern |
1 |
Akira - G1024 (46bb06cb-f2d9-4b37-8c92-a27e224ad90d) |
Intrusion Set |
Financial Theft - T1657 (851e071f-208d-4c79-adc6-5974c85c78f3) |
Attack Pattern |
1 |
Akira - G1024 (46bb06cb-f2d9-4b37-8c92-a27e224ad90d) |
Intrusion Set |
Sharepoint - T1213.002 (0c4b4fda-9062-47da-98b9-ceae2dcf052a) |
Attack Pattern |
1 |
Akira - G1024 (46bb06cb-f2d9-4b37-8c92-a27e224ad90d) |
Intrusion Set |
Remote Access Software - T1219 (4061e78c-1284-44b4-9116-73e4ac3912f7) |
Attack Pattern |
1 |
Akira - G1024 (46bb06cb-f2d9-4b37-8c92-a27e224ad90d) |
Intrusion Set |
AdFind - S0552 (f59508a6-3615-47c3-b493-6676e1a39a87) |
mitre-tool |
1 |
External Remote Services - T1133 (10d51417-ee35-4589-b1ff-b6df1c334e8d) |
Attack Pattern |
Akira - G1024 (46bb06cb-f2d9-4b37-8c92-a27e224ad90d) |
Intrusion Set |
1 |
Akira - G1024 (46bb06cb-f2d9-4b37-8c92-a27e224ad90d) |
Intrusion Set |
PsExec - S0029 (ff6caf67-ea1f-4895-b80e-4bb0fc31c6db) |
mitre-tool |
1 |
Akira - G1024 (46bb06cb-f2d9-4b37-8c92-a27e224ad90d) |
Intrusion Set |
Data Encrypted for Impact - T1486 (b80d107d-fa0d-4b60-9684-b0433e8bdba0) |
Attack Pattern |
1 |
Akira - G1024 (46bb06cb-f2d9-4b37-8c92-a27e224ad90d) |
Intrusion Set |
Remote System Discovery - T1018 (e358d692-23c0-4a31-9eb6-ecc13a8d7735) |
Attack Pattern |
1 |
Akira - G1024 (46bb06cb-f2d9-4b37-8c92-a27e224ad90d) |
Intrusion Set |
Rclone - S1040 (59096109-a1dd-463b-87e7-a8d110fe3a79) |
mitre-tool |
1 |
Mimikatz - S0002 (afc079f3-c0ea-4096-b75d-3f05338b7f60) |
mitre-tool |
Steal or Forge Authentication Certificates - T1649 (7de1f7ac-5d0c-4c9c-8873-627202205331) |
Attack Pattern |
2 |
Mimikatz - S0002 (afc079f3-c0ea-4096-b75d-3f05338b7f60) |
mitre-tool |
SID-History Injection - T1134.005 (b7dc639b-24cd-482d-a7f1-8897eda21023) |
Attack Pattern |
2 |
Mimikatz - S0002 (afc079f3-c0ea-4096-b75d-3f05338b7f60) |
mitre-tool |
Credentials from Password Stores - T1555 (3fc9b85a-2862-4363-a64d-d692e3ffbee0) |
Attack Pattern |
2 |
Credentials from Web Browsers - T1555.003 (58a3e6aa-4453-4cc8-a51f-4befe80b31a8) |
Attack Pattern |
Mimikatz - S0002 (afc079f3-c0ea-4096-b75d-3f05338b7f60) |
mitre-tool |
2 |
Account Manipulation - T1098 (a10641f4-87b4-45a3-a906-92a149cb2c27) |
Attack Pattern |
Mimikatz - S0002 (afc079f3-c0ea-4096-b75d-3f05338b7f60) |
mitre-tool |
2 |
Mimikatz - S0002 (afc079f3-c0ea-4096-b75d-3f05338b7f60) |
mitre-tool |
Windows Credential Manager - T1555.004 (d336b553-5da9-46ca-98a8-0b23f49fb447) |
Attack Pattern |
2 |
LSASS Memory - T1003.001 (65f2d882-3f41-4d48-8a06-29af77ec9f90) |
Attack Pattern |
Mimikatz - S0002 (afc079f3-c0ea-4096-b75d-3f05338b7f60) |
mitre-tool |
2 |
Silver Ticket - T1558.002 (d273434a-448e-4598-8e14-607f4a0d5e27) |
Attack Pattern |
Mimikatz - S0002 (afc079f3-c0ea-4096-b75d-3f05338b7f60) |
mitre-tool |
2 |
Mimikatz - S0002 (afc079f3-c0ea-4096-b75d-3f05338b7f60) |
mitre-tool |
Security Account Manager - T1003.002 (1644e709-12d2-41e5-a60f-3470991f5011) |
Attack Pattern |
2 |
Mimikatz - S0002 (afc079f3-c0ea-4096-b75d-3f05338b7f60) |
mitre-tool |
Private Keys - T1552.004 (60b508a1-6a5e-46b1-821a-9f7b78752abf) |
Attack Pattern |
2 |
Mimikatz - S0002 (afc079f3-c0ea-4096-b75d-3f05338b7f60) |
mitre-tool |
Security Support Provider - T1547.005 (5095a853-299c-4876-abd7-ac0050fb5462) |
Attack Pattern |
2 |
Mimikatz - S0002 (afc079f3-c0ea-4096-b75d-3f05338b7f60) |
mitre-tool |
Pass the Ticket - T1550.003 (7b211ac6-c815-4189-93a9-ab415deca926) |
Attack Pattern |
2 |
Mimikatz - S0002 (afc079f3-c0ea-4096-b75d-3f05338b7f60) |
mitre-tool |
DCSync - T1003.006 (f303a39a-6255-4b89-aecc-18c4d8ca7163) |
Attack Pattern |
2 |
Mimikatz - S0002 (afc079f3-c0ea-4096-b75d-3f05338b7f60) |
mitre-tool |
Rogue Domain Controller - T1207 (564998d8-ab3e-4123-93fb-eccaa6b9714a) |
Attack Pattern |
2 |
Mimikatz - S0002 (afc079f3-c0ea-4096-b75d-3f05338b7f60) |
mitre-tool |
LSA Secrets - T1003.004 (1ecfdab8-7d59-4c98-95d4-dc41970f57fc) |
Attack Pattern |
2 |
Mimikatz - S0002 (afc079f3-c0ea-4096-b75d-3f05338b7f60) |
mitre-tool |
Pass the Hash - T1550.002 (e624264c-033a-424d-9fd7-fc9c3bbdb03e) |
Attack Pattern |
2 |
Mimikatz - S0002 (afc079f3-c0ea-4096-b75d-3f05338b7f60) |
mitre-tool |
Mimikatz (7f3a035d-d83a-45b8-8111-412aa8ade802) |
Tool |
2 |
Mimikatz - S0002 (afc079f3-c0ea-4096-b75d-3f05338b7f60) |
mitre-tool |
Golden Ticket - T1558.001 (768dce68-8d0d-477a-b01d-0eea98b963a1) |
Attack Pattern |
2 |
System Information Discovery - T1082 (354a7f88-63fb-41b5-a801-ce3b377b36f1) |
Attack Pattern |
Akira - S1129 (6f6b2353-4b39-40ce-9d6d-d00b7a61e656) |
Malware |
2 |
Akira - S1129 (6f6b2353-4b39-40ce-9d6d-d00b7a61e656) |
Malware |
Network Share Discovery - T1135 (3489cfc5-640f-4bb3-a103-9137b97de79f) |
Attack Pattern |
2 |
Akira - S1129 (6f6b2353-4b39-40ce-9d6d-d00b7a61e656) |
Malware |
Inhibit System Recovery - T1490 (f5d8eed6-48a9-4cdf-a3d7-d1ffa99c3d2a) |
Attack Pattern |
2 |
PowerShell - T1059.001 (970a3432-3237-47ad-bcca-7d8cbb217736) |
Attack Pattern |
Akira - S1129 (6f6b2353-4b39-40ce-9d6d-d00b7a61e656) |
Malware |
2 |
Akira - S1129 (6f6b2353-4b39-40ce-9d6d-d00b7a61e656) |
Malware |
File and Directory Discovery - T1083 (7bc57495-ea59-4380-be31-a64af124ef18) |
Attack Pattern |
2 |
Native API - T1106 (391d824f-0ef1-47a0-b0ee-c59a75e27670) |
Attack Pattern |
Akira - S1129 (6f6b2353-4b39-40ce-9d6d-d00b7a61e656) |
Malware |
2 |
Process Discovery - T1057 (8f4a33ec-8b1f-4b80-a2f6-642b2e479580) |
Attack Pattern |
Akira - S1129 (6f6b2353-4b39-40ce-9d6d-d00b7a61e656) |
Malware |
2 |
Akira - S1129 (6f6b2353-4b39-40ce-9d6d-d00b7a61e656) |
Malware |
Data Encrypted for Impact - T1486 (b80d107d-fa0d-4b60-9684-b0433e8bdba0) |
Attack Pattern |
2 |
Akira - S1129 (6f6b2353-4b39-40ce-9d6d-d00b7a61e656) |
Malware |
Windows Command Shell - T1059.003 (d1fcf083-a721-4223-aedf-bf8960798d62) |
Attack Pattern |
2 |
Akira - S1129 (6f6b2353-4b39-40ce-9d6d-d00b7a61e656) |
Malware |
Windows Management Instrumentation - T1047 (01a5a209-b94c-450b-b7f9-946497d91055) |
Attack Pattern |
2 |
Exfiltration Over Web Service - T1567 (40597f16-0963-4249-bf4c-ac93b7fb9807) |
Attack Pattern |
Exfiltration to Cloud Storage - T1567.002 (bf1b6176-597c-4600-bfcd-ac989670f96b) |
Attack Pattern |
2 |
LaZagne - S0349 (b76b2d94-60e4-4107-a903-4a3a7622fb3b) |
mitre-tool |
/etc/passwd and /etc/shadow - T1003.008 (d0b4fcdb-d67d-4ed2-99ce-788b12f8c0f4) |
Attack Pattern |
2 |
LaZagne - S0349 (b76b2d94-60e4-4107-a903-4a3a7622fb3b) |
mitre-tool |
Credentials from Password Stores - T1555 (3fc9b85a-2862-4363-a64d-d692e3ffbee0) |
Attack Pattern |
2 |
Credentials from Web Browsers - T1555.003 (58a3e6aa-4453-4cc8-a51f-4befe80b31a8) |
Attack Pattern |
LaZagne - S0349 (b76b2d94-60e4-4107-a903-4a3a7622fb3b) |
mitre-tool |
2 |
Cached Domain Credentials - T1003.005 (6add2ab5-2711-4e9d-87c8-7a0be8531530) |
Attack Pattern |
LaZagne - S0349 (b76b2d94-60e4-4107-a903-4a3a7622fb3b) |
mitre-tool |
2 |
LaZagne - S0349 (b76b2d94-60e4-4107-a903-4a3a7622fb3b) |
mitre-tool |
Windows Credential Manager - T1555.004 (d336b553-5da9-46ca-98a8-0b23f49fb447) |
Attack Pattern |
2 |
LSASS Memory - T1003.001 (65f2d882-3f41-4d48-8a06-29af77ec9f90) |
Attack Pattern |
LaZagne - S0349 (b76b2d94-60e4-4107-a903-4a3a7622fb3b) |
mitre-tool |
2 |
Keychain - T1555.001 (1eaebf46-e361-4437-bc23-d5d65a3b92e3) |
Attack Pattern |
LaZagne - S0349 (b76b2d94-60e4-4107-a903-4a3a7622fb3b) |
mitre-tool |
2 |
LaZagne - S0349 (b76b2d94-60e4-4107-a903-4a3a7622fb3b) |
mitre-tool |
LSA Secrets - T1003.004 (1ecfdab8-7d59-4c98-95d4-dc41970f57fc) |
Attack Pattern |
2 |
LaZagne - S0349 (b76b2d94-60e4-4107-a903-4a3a7622fb3b) |
mitre-tool |
Credentials In Files - T1552.001 (837f9164-50af-4ac0-8219-379d8a74cefc) |
Attack Pattern |
2 |
LaZagne - S0349 (b76b2d94-60e4-4107-a903-4a3a7622fb3b) |
mitre-tool |
Proc Filesystem - T1003.007 (3120b9fa-23b8-4500-ae73-09494f607b7d) |
Attack Pattern |
2 |
Archive Collected Data - T1560 (53ac20cd-aca3-406e-9aa0-9fc7fdc60a5a) |
Attack Pattern |
Archive via Utility - T1560.001 (00f90846-cbd1-4fc5-9233-df5c2bf2a662) |
Attack Pattern |
2 |
Data from Information Repositories - T1213 (d28ef391-8ed4-45dc-bc4a-2f43abf54416) |
Attack Pattern |
Sharepoint - T1213.002 (0c4b4fda-9062-47da-98b9-ceae2dcf052a) |
Attack Pattern |
2 |
System Network Configuration Discovery - T1016 (707399d6-ab3e-4963-9315-d9d3818cd6a0) |
Attack Pattern |
AdFind - S0552 (f59508a6-3615-47c3-b493-6676e1a39a87) |
mitre-tool |
2 |
Domain Groups - T1069.002 (2aed01ad-3df3-4410-a8cb-11ea4ded587c) |
Attack Pattern |
AdFind - S0552 (f59508a6-3615-47c3-b493-6676e1a39a87) |
mitre-tool |
2 |
Domain Trust Discovery - T1482 (767dbf9e-df3f-45cb-8998-4903ab5f80c0) |
Attack Pattern |
AdFind - S0552 (f59508a6-3615-47c3-b493-6676e1a39a87) |
mitre-tool |
2 |
Domain Account - T1087.002 (21875073-b0ee-49e3-9077-1e2a885359af) |
Attack Pattern |
AdFind - S0552 (f59508a6-3615-47c3-b493-6676e1a39a87) |
mitre-tool |
2 |
AdFind - S0552 (f59508a6-3615-47c3-b493-6676e1a39a87) |
mitre-tool |
Remote System Discovery - T1018 (e358d692-23c0-4a31-9eb6-ecc13a8d7735) |
Attack Pattern |
2 |
Windows Service - T1543.003 (2959d63f-73fd-46a1-abd2-109d7dcede32) |
Attack Pattern |
PsExec - S0029 (ff6caf67-ea1f-4895-b80e-4bb0fc31c6db) |
mitre-tool |
2 |
SMB/Windows Admin Shares - T1021.002 (4f9ca633-15c5-463c-9724-bdcd54fde541) |
Attack Pattern |
PsExec - S0029 (ff6caf67-ea1f-4895-b80e-4bb0fc31c6db) |
mitre-tool |
2 |
PsExec - S0029 (ff6caf67-ea1f-4895-b80e-4bb0fc31c6db) |
mitre-tool |
Domain Account - T1136.002 (7610cada-1499-41a4-b3dd-46467b68d177) |
Attack Pattern |
2 |
Lateral Tool Transfer - T1570 (bf90d72c-c00b-45e3-b3aa-68560560d4c5) |
Attack Pattern |
PsExec - S0029 (ff6caf67-ea1f-4895-b80e-4bb0fc31c6db) |
mitre-tool |
2 |
PsExec - S0029 (ff6caf67-ea1f-4895-b80e-4bb0fc31c6db) |
mitre-tool |
PsExec (6dd05630-9bd8-11e8-a8b9-47ce338a4367) |
Tool |
2 |
PsExec - S0029 (ff6caf67-ea1f-4895-b80e-4bb0fc31c6db) |
mitre-tool |
Service Execution - T1569.002 (f1951e8a-500e-4a26-8803-76d95c4554b4) |
Attack Pattern |
2 |
Archive via Utility - T1560.001 (00f90846-cbd1-4fc5-9233-df5c2bf2a662) |
Attack Pattern |
Rclone - S1040 (59096109-a1dd-463b-87e7-a8d110fe3a79) |
mitre-tool |
2 |
File and Directory Discovery - T1083 (7bc57495-ea59-4380-be31-a64af124ef18) |
Attack Pattern |
Rclone - S1040 (59096109-a1dd-463b-87e7-a8d110fe3a79) |
mitre-tool |
2 |
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol - T1048.002 (8e350c1d-ac79-4b5c-bd4e-7476d7e84ec5) |
Attack Pattern |
Rclone - S1040 (59096109-a1dd-463b-87e7-a8d110fe3a79) |
mitre-tool |
2 |
Exfiltration Over Unencrypted Non-C2 Protocol - T1048.003 (fb8d023d-45be-47e9-bc51-f56bcae6435b) |
Attack Pattern |
Rclone - S1040 (59096109-a1dd-463b-87e7-a8d110fe3a79) |
mitre-tool |
2 |
Data Transfer Size Limits - T1030 (c3888c54-775d-4b2f-b759-75a2ececcbfd) |
Attack Pattern |
Rclone - S1040 (59096109-a1dd-463b-87e7-a8d110fe3a79) |
mitre-tool |
2 |
Exfiltration to Cloud Storage - T1567.002 (bf1b6176-597c-4600-bfcd-ac989670f96b) |
Attack Pattern |
Rclone - S1040 (59096109-a1dd-463b-87e7-a8d110fe3a79) |
mitre-tool |
2 |
SID-History Injection - T1134.005 (b7dc639b-24cd-482d-a7f1-8897eda21023) |
Attack Pattern |
Access Token Manipulation - T1134 (dcaa092b-7de9-4a21-977f-7fcb77e89c48) |
Attack Pattern |
3 |
Credentials from Web Browsers - T1555.003 (58a3e6aa-4453-4cc8-a51f-4befe80b31a8) |
Attack Pattern |
Credentials from Password Stores - T1555 (3fc9b85a-2862-4363-a64d-d692e3ffbee0) |
Attack Pattern |
3 |
Windows Credential Manager - T1555.004 (d336b553-5da9-46ca-98a8-0b23f49fb447) |
Attack Pattern |
Credentials from Password Stores - T1555 (3fc9b85a-2862-4363-a64d-d692e3ffbee0) |
Attack Pattern |
3 |
LSASS Memory - T1003.001 (65f2d882-3f41-4d48-8a06-29af77ec9f90) |
Attack Pattern |
OS Credential Dumping - T1003 (0a3ead4e-6d47-4ccb-854c-a6a4f9d96b22) |
Attack Pattern |
3 |
Silver Ticket - T1558.002 (d273434a-448e-4598-8e14-607f4a0d5e27) |
Attack Pattern |
Steal or Forge Kerberos Tickets - T1558 (3fc01293-ef5e-41c6-86ce-61f10706b64a) |
Attack Pattern |
3 |
Security Account Manager - T1003.002 (1644e709-12d2-41e5-a60f-3470991f5011) |
Attack Pattern |
OS Credential Dumping - T1003 (0a3ead4e-6d47-4ccb-854c-a6a4f9d96b22) |
Attack Pattern |
3 |
Unsecured Credentials - T1552 (435dfb86-2697-4867-85b5-2fef496c0517) |
Attack Pattern |
Private Keys - T1552.004 (60b508a1-6a5e-46b1-821a-9f7b78752abf) |
Attack Pattern |
3 |
Security Support Provider - T1547.005 (5095a853-299c-4876-abd7-ac0050fb5462) |
Attack Pattern |
Boot or Logon Autostart Execution - T1547 (1ecb2399-e8ba-4f6b-8ba7-5c27d49405cf) |
Attack Pattern |
3 |
Use Alternate Authentication Material - T1550 (51a14c76-dd3b-440b-9c20-2bf91d25a814) |
Attack Pattern |
Pass the Ticket - T1550.003 (7b211ac6-c815-4189-93a9-ab415deca926) |
Attack Pattern |
3 |
DCSync - T1003.006 (f303a39a-6255-4b89-aecc-18c4d8ca7163) |
Attack Pattern |
OS Credential Dumping - T1003 (0a3ead4e-6d47-4ccb-854c-a6a4f9d96b22) |
Attack Pattern |
3 |
LSA Secrets - T1003.004 (1ecfdab8-7d59-4c98-95d4-dc41970f57fc) |
Attack Pattern |
OS Credential Dumping - T1003 (0a3ead4e-6d47-4ccb-854c-a6a4f9d96b22) |
Attack Pattern |
3 |
Use Alternate Authentication Material - T1550 (51a14c76-dd3b-440b-9c20-2bf91d25a814) |
Attack Pattern |
Pass the Hash - T1550.002 (e624264c-033a-424d-9fd7-fc9c3bbdb03e) |
Attack Pattern |
3 |
MimiKatz (588fb91d-59c6-4667-b299-94676d48b17b) |
Malpedia |
Mimikatz (7f3a035d-d83a-45b8-8111-412aa8ade802) |
Tool |
3 |
Steal or Forge Kerberos Tickets - T1558 (3fc01293-ef5e-41c6-86ce-61f10706b64a) |
Attack Pattern |
Golden Ticket - T1558.001 (768dce68-8d0d-477a-b01d-0eea98b963a1) |
Attack Pattern |
3 |
PowerShell - T1059.001 (970a3432-3237-47ad-bcca-7d8cbb217736) |
Attack Pattern |
Command and Scripting Interpreter - T1059 (7385dfaf-6886-4229-9ecd-6fd678040830) |
Attack Pattern |
3 |
Windows Command Shell - T1059.003 (d1fcf083-a721-4223-aedf-bf8960798d62) |
Attack Pattern |
Command and Scripting Interpreter - T1059 (7385dfaf-6886-4229-9ecd-6fd678040830) |
Attack Pattern |
3 |
/etc/passwd and /etc/shadow - T1003.008 (d0b4fcdb-d67d-4ed2-99ce-788b12f8c0f4) |
Attack Pattern |
OS Credential Dumping - T1003 (0a3ead4e-6d47-4ccb-854c-a6a4f9d96b22) |
Attack Pattern |
3 |
Cached Domain Credentials - T1003.005 (6add2ab5-2711-4e9d-87c8-7a0be8531530) |
Attack Pattern |
OS Credential Dumping - T1003 (0a3ead4e-6d47-4ccb-854c-a6a4f9d96b22) |
Attack Pattern |
3 |
Keychain - T1555.001 (1eaebf46-e361-4437-bc23-d5d65a3b92e3) |
Attack Pattern |
Credentials from Password Stores - T1555 (3fc9b85a-2862-4363-a64d-d692e3ffbee0) |
Attack Pattern |
3 |
Unsecured Credentials - T1552 (435dfb86-2697-4867-85b5-2fef496c0517) |
Attack Pattern |
Credentials In Files - T1552.001 (837f9164-50af-4ac0-8219-379d8a74cefc) |
Attack Pattern |
3 |
OS Credential Dumping - T1003 (0a3ead4e-6d47-4ccb-854c-a6a4f9d96b22) |
Attack Pattern |
Proc Filesystem - T1003.007 (3120b9fa-23b8-4500-ae73-09494f607b7d) |
Attack Pattern |
3 |
Domain Groups - T1069.002 (2aed01ad-3df3-4410-a8cb-11ea4ded587c) |
Attack Pattern |
Permission Groups Discovery - T1069 (15dbf668-795c-41e6-8219-f0447c0e64ce) |
Attack Pattern |
3 |
Domain Account - T1087.002 (21875073-b0ee-49e3-9077-1e2a885359af) |
Attack Pattern |
Account Discovery - T1087 (72b74d71-8169-42aa-92e0-e7b04b9f5a08) |
Attack Pattern |
3 |
Windows Service - T1543.003 (2959d63f-73fd-46a1-abd2-109d7dcede32) |
Attack Pattern |
Create or Modify System Process - T1543 (106c0cf6-bf73-4601-9aa8-0945c2715ec5) |
Attack Pattern |
3 |
SMB/Windows Admin Shares - T1021.002 (4f9ca633-15c5-463c-9724-bdcd54fde541) |
Attack Pattern |
Remote Services - T1021 (54a649ff-439a-41a4-9856-8d144a2551ba) |
Attack Pattern |
3 |
Domain Account - T1136.002 (7610cada-1499-41a4-b3dd-46467b68d177) |
Attack Pattern |
Create Account - T1136 (e01be9c5-e763-4caf-aeb7-000b416aef67) |
Attack Pattern |
3 |
System Services - T1569 (d157f9d2-d09a-4efa-bb2a-64963f94e253) |
Attack Pattern |
Service Execution - T1569.002 (f1951e8a-500e-4a26-8803-76d95c4554b4) |
Attack Pattern |
3 |
Exfiltration Over Alternative Protocol - T1048 (a19e86f8-1c0a-4fea-8407-23b73d615776) |
Attack Pattern |
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol - T1048.002 (8e350c1d-ac79-4b5c-bd4e-7476d7e84ec5) |
Attack Pattern |
3 |
Exfiltration Over Alternative Protocol - T1048 (a19e86f8-1c0a-4fea-8407-23b73d615776) |
Attack Pattern |
Exfiltration Over Unencrypted Non-C2 Protocol - T1048.003 (fb8d023d-45be-47e9-bc51-f56bcae6435b) |
Attack Pattern |
3 |