Updates for ATT&CK v17

This commit is contained in:
Wietze 2025-04-26 20:23:10 +01:00
parent 7dbdad68e9
commit e15a9c3e27
No known key found for this signature in database
GPG Key ID: E17630129FF993CF
3 changed files with 3 additions and 3 deletions

View File

@ -9,7 +9,7 @@ Commands:
Usecase: Reverse PowerShell session over MS provided infrastructure. Usecase: Reverse PowerShell session over MS provided infrastructure.
Category: Execute Category: Execute
Privileges: User Privileges: User
MitreID: T1219 MitreID: T1219.001
OperatingSystem: Windows 10, Windows 11 OperatingSystem: Windows 10, Windows 11
Full_Path: Full_Path:
- Path: 'C:\Users\<username>\AppData\Local\Programs\Microsoft VS Code\Code.exe' - Path: 'C:\Users\<username>\AppData\Local\Programs\Microsoft VS Code\Code.exe'

View File

@ -9,7 +9,7 @@ Commands:
Usecase: Use binary to bypass Application whitelisting Usecase: Use binary to bypass Application whitelisting
Category: AWL Bypass Category: AWL Bypass
Privileges: User Privileges: User
MitreID: T1127 MitreID: T1127.002
OperatingSystem: Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11 OperatingSystem: Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
Tags: Tags:
- Execute: ClickOnce - Execute: ClickOnce

View File

@ -9,7 +9,7 @@ Commands:
Usecase: Use binary to bypass Application whitelisting Usecase: Use binary to bypass Application whitelisting
Category: AWL Bypass Category: AWL Bypass
Privileges: User Privileges: User
MitreID: T1127 MitreID: T1127.002
OperatingSystem: Windows Vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11 OperatingSystem: Windows Vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
Tags: Tags:
- Execute: ClickOnce - Execute: ClickOnce