
Technique List
Technique Name | Technique ID's | Categories | Has Snippet(s) | Has Rules(s) | Creation Date |
---|---|---|---|---|---|
SMB / Named Pipes | U9011 | Network Evasion | 3 months, 1 week | ||
Right-to-Left Override (RLO) Extension Spoofing | U1010 | Others | 4 months | ||
DLL Unhooking | U0522 | Antivirus/EDR Evasion | 5 months | ||
Shikata Ga Nai (SGN) | U0708 | Data Obfuscation | 5 months | ||
C2 via FTP(S) | U0910 | Network Evasion | 5 months, 3 weeks | ||
Evasion using direct Syscalls | U0521 | Antivirus/EDR Evasion | 6 months, 2 weeks | ||
Hell's Gate | U0520 | Antivirus/EDR Evasion | 8 months | ||
XSL Script Processing | T1220 | Defense Evasion [Mitre] | 8 months, 2 weeks | ||
Virtualization/Sandbox Evasion: Time Based Evasion | T1497.003 | Defense Evasion [Mitre] | 8 months, 2 weeks | ||
Virtualization/Sandbox Evasion: User Activity Based Checks | T1497.002 | Defense Evasion [Mitre] | 8 months, 2 weeks | ||
Virtualization/Sandbox Evasion: System Checks | T1497.001 | Defense Evasion [Mitre] | 8 months, 2 weeks | ||
Valid Accounts: Local Accounts | T1078.003 | Defense Evasion [Mitre] | 8 months, 2 weeks | ||
Valid Accounts: Domain Accounts | T1078.002 | Defense Evasion [Mitre] | 8 months, 2 weeks | ||
Valid Accounts: Default Accounts | T1078.001 | Defense Evasion [Mitre] | 8 months, 2 weeks | ||
ScrubCrypt | U1430 | Packers | 8 months, 2 weeks | ||
Constant Blinding | U0707 | Data Obfuscation | 8 months, 2 weeks | ||
Unloading Module with FreeLibrary | U0519 | Antivirus/EDR Evasion | 8 months, 2 weeks | ||
AddVectoredExceptionHandler | U0125 | Anti-Debugging | 8 months, 4 weeks | ||
Call to Interrupt Procedure | U0124 | Anti-Debugging | 8 months, 4 weeks | ||
Use Alternate Authentication Material: Pass the Ticket | T1550.003 | Defense Evasion [Mitre] | 9 months | ||
Use Alternate Authentication Material: Pass the Hash | T1550.002 | Defense Evasion [Mitre] | 9 months | ||
Trusted Developer Utilities Proxy Execution: MSBuild | T1127.001 | Defense Evasion [Mitre] | 9 months | ||
Traffic Signaling: Socket Filters | T1205.002 | Defense Evasion [Mitre] | 9 months | ||
Traffic Signaling: Port Knocking | T1205.001 | Defense Evasion [Mitre] | 9 months | ||
Template Injection | T1221 | Defense Evasion [Mitre] | 9 months | ||
System Script Proxy Execution: PubPrn | T1216.001 | Defense Evasion [Mitre] | 9 months | ||
System Binary Proxy Execution: MMC | T1218.014 | Defense Evasion [Mitre] | 9 months | ||
System Binary Proxy Execution: Mavinject | T1218.013 | Defense Evasion [Mitre] | 9 months | ||
System Binary Proxy Execution: Verclsid | T1218.012 | Defense Evasion [Mitre] | 9 months | ||
System Binary Proxy Execution: Rundll32 | T1218.011 | Defense Evasion [Mitre] | 9 months |