Technique List

Technique Name Technique ID's Categories Snippet(s) Rules(s) OS Creation Date
PE Injection U1216 E1055.002 Process Manipulating 5 years, 10 months
IAT Hooking U1217 F0015.003 Process Manipulating 5 years, 10 months
Injection using Shims U1218 E1055.m03 Process Manipulating 5 years, 10 months
Extra Window Memory Injection U1219 E1055.011 Process Manipulating 5 years, 10 months
Atom Bombing U1220 Process Manipulating 5 years, 10 months
APC injection U1221 E1055.004 Process Manipulating 5 years, 10 months
Image File Execution Options Injection U1222 Process Manipulating 5 years, 10 months
Thread Execution Hijacking U1223 E1055.003 Process Manipulating 5 years, 10 months
Reflective DLL injection U1224 Process Manipulating 5 years, 10 months
SuspendThread U0101 C0055 Anti-Debugging 5 years, 10 months
Guard Pages U0102 B0006.006 Anti-Debugging 5 years, 10 months
NtSetDebugFilterState U0103 Anti-Debugging 5 years, 10 months
Code Cave U0502 Antivirus/EDR Evasion 5 years, 10 months
Stolen certificate U0503 Antivirus/EDR Evasion 5 years, 10 months
Redirect Antivirus Website U0504 Antivirus/EDR Evasion 5 years, 10 months
Time Bomb U1005 B0007.008 Sandbox Evasion, Others 5 years, 10 months
Shortcut Hiding U0505 Antivirus/EDR Evasion 5 years, 10 months
Geofencing U1006 Others 5 years, 10 months
Custom Encoding U0702 E1027.m03 Data Obfuscation 5 years, 10 months
Cryptography U0703 E1027.m04 Data Obfuscation 5 years, 10 months
ROL U0704 Data Obfuscation 5 years, 10 months
Caesar Cipher U0705 Data Obfuscation 5 years, 10 months
Base64 U0706 E1027.m02 Data Obfuscation 5 years, 10 months
XOR Operation U0701 E1027.m02 Data Obfuscation 5 years, 10 months
FIleless Mechanisms U1205 B0027.001 Process Manipulating 5 years, 10 months
DLL Injection via CreateRemoteThread and LoadLibrary U1226 E1055.001 Process Manipulating 5 years, 10 months
Hook Injection U1227 E1055.m01 Process Manipulating 5 years, 10 months
Entry Point Modification U1228 Process Manipulating 5 years, 10 months
Parent Process Detection U0404 Anti-Monitoring 5 years, 10 months
Process Camouflage, Masquerading U1230 F0005 Process Manipulating 5 years, 10 months

Filter