Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks
| Discovery | RMM Tools | Defense Evasion | Credential Theft | OffSec | Networking | LOLBAS | Exfiltration |
|---|---|---|---|---|---|---|---|
|
Advanced IP Scanner
Navicat
PDQ Inventory
RoboCopy
SoftPerfect NetScan
|
AnyDesk
Atera
HCL BigFix
N-Able
PDQ Deploy
ScreenConnect
SimpleHelp
Splashtop
eHorus
|
EDRSandBlast
KillAV
ThrottleStop driver
|
Mimikatz
|
|
Cloudflared
FRP
Ligolo
PuTTY
RevSocks
|
BITSAdmin
Process Explorer
PsExec
|
RClone
|
| Vendor | Product | CVE | Source |
|---|---|---|---|
| SimpleHelp | SimpleHelp RMM | CVE-2024-57727 | arcticwolf.com |
| Initial Access | Execution | Persistence | Privilege Escalation | Stealth | Defense Evasion | Credential Access | Discovery | Lateral Movement | Exfiltration | Command and Control | Impact | Resource Development | Defense Impairment |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Valid Accounts | Windows Management Instrumentation | Modify Registry | Domain or Tenant Policy Modification: Group Policy Modification | Direct Volume Access | Impair Defenses | OS Credential Dumping: LSASS Memory | System Network Configuration Discovery | Remote Services | Exfiltration Over C2 Channel | Application Layer Protocol: Web Protocols | Data Encrypted for Impact | Acquire Infrastructure: Web Services | Modify Registry |
| External Remote Services | Command and Scripting Interpreter | Create Account: Domain Account | Create or Modify System Process: Windows Service | Obfuscated Files or Information | Disable or Modify Tools | OS Credential Dumping: NTDS | Remote System Discovery | Remote Services: Remote Desktop Protocol | Exfiltration Over Alternative Protocol | Proxy: Multi-hop Proxy | Service Stop | Establish Accounts: Social Media Accounts | Subvert Trust Controls: Code Signing |
| Exploit Public-Facing Application | Command and Scripting Interpreter: PowerShell | Server Software Component: Web Shell | Abuse Elevation Control Mechanism: Bypass User Account Control | Obfuscated Files or Information: Software Packing | Safe Mode Boot | Brute Force | System Owner/User Discovery | Software Deployment Tools | Exfiltration Over Web Service | Ingress Tool Transfer | Inhibit System Recovery | Establish Accounts: Email Accounts | Disable or Modify Tools |
| Phishing | Command and Scripting Interpreter: Windows Command Shell | Create or Modify System Process: Windows Service | Obfuscated Files or Information: Command Obfuscation | Steal or Forge Kerberos Tickets | Network Service Discovery | Lateral Tool Transfer | Exfiltration Over Web Service: Exfiltration to Cloud Storage | Remote Access Tools | System Shutdown/Reboot | Obtain Capabilities: Tool | Disable or Modify System Firewall | ||
| Software Deployment Tools | Obfuscated Files or Information: Encrypted/Encoded File | System Network Connections Discovery | Encrypted Channel: Asymmetric Cryptography | Financial Theft | Stage Capabilities: Upload Tool | Prevent Command History Logging | |||||||
| Native API | Indicator Removal | Process Discovery | Acquire Access | ||||||||||
| Inter-Process Communication: Component Object Model | Indicator Removal: Clear Command History | Permission Groups Discovery: Domain Groups | |||||||||||
| System Services: Service Execution | Indicator Removal: File Deletion | System Information Discovery | |||||||||||
| ESXi Administration Command | System Binary Proxy Execution: MMC | File and Directory Discovery | |||||||||||
| Hide Artifacts: Hidden Window | Account Discovery: Local Account | ||||||||||||
| Hide Artifacts: File/Path Exclusions | Network Share Discovery | ||||||||||||
| Software Discovery: Security Software Discovery | |||||||||||||
| Device Driver Discovery |
T1489
T1572