Odbcconf realign to T1218.008, hh.exe to T1218.001

This commit is contained in:
Wietze 2021-11-16 14:08:04 +00:00
parent 23dd0236ae
commit f7b30775a4
No known key found for this signature in database
GPG Key ID: E17630129FF993CF
2 changed files with 3 additions and 3 deletions

View File

@ -16,7 +16,7 @@ Commands:
Usecase: Execute process with HH.exe
Category: Execute
Privileges: User
MitreID: T1202
MitreID: T1218.001
OperatingSystem: Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10
Full_Path:
- Path: C:\Windows\System32\hh.exe

View File

@ -9,14 +9,14 @@ Commands:
Usecase: Execute dll file using technique that can evade defensive counter measures
Category: Execute
Privileges: User
MitreID: T1218
MitreID: T1218.008
OperatingSystem: Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10
- Command: odbcconf /a {REGSVR c:\test\test.dll}
Description: Execute DllREgisterServer from DLL specified.
Usecase: Execute dll file using technique that can evade defensive counter measures
Category: Execute
Privileges: User
MitreID: T1218
MitreID: T1218.008
OperatingSystem: Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10
Full_Path:
- Path: C:\Windows\System32\odbcconf.exe