More changes (mainly changing some T1218 instances to T1202)

This commit is contained in:
Wietze
2021-11-05 20:17:04 +00:00
parent 2577066af9
commit bc51cb4e03
10 changed files with 19 additions and 19 deletions

View File

@@ -9,14 +9,14 @@ Commands:
Usecase: Performs execution of specified file with explorer parent process breaking the process tree, can be used for defense evasion.
Category: Execute
Privileges: User
MitreID: T1218
MitreID: T1202
OperatingSystem: Windows XP, Windows 7, Windows 8, Windows 8.1, Windows 10
- Command: explorer.exe C:\Windows\System32\notepad.exe
Description: Execute calc.exe with the parent process spawning from a new instance of explorer.exe
Usecase: Performs execution of specified file with explorer parent process breaking the process tree, can be used for defense evasion.
Category: Execute
Privileges: User
MitreID: T1218
MitreID: T1202
OperatingSystem: Windows 10 (Tested)
Full_Path:
- Path: C:\Windows\explorer.exe