Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1087 | .002 | Account Discovery: Domain Account |
POWRUNER may collect user account information by running |
Enterprise | T1071 | .001 | Application Layer Protocol: Web Protocols | |
.004 | Application Layer Protocol: DNS | |||
Enterprise | T1059 | .001 | Command and Scripting Interpreter: PowerShell | |
.003 | Command and Scripting Interpreter: Windows Command Shell | |||
Enterprise | T1132 | .001 | Data Encoding: Standard Encoding | |
Enterprise | T1083 | File and Directory Discovery | ||
Enterprise | T1105 | Ingress Tool Transfer |
POWRUNER can download or upload files from its C2 server.[1] |
|
Enterprise | T1069 | .001 | Permission Groups Discovery: Local Groups |
POWRUNER may collect local group information by running |
.002 | Permission Groups Discovery: Domain Groups |
POWRUNER may collect domain group information by running |
||
Enterprise | T1057 | Process Discovery |
POWRUNER may collect process information by running |
|
Enterprise | T1012 | Query Registry |
POWRUNER may query the Registry by running |
|
Enterprise | T1053 | .005 | Scheduled Task/Job: Scheduled Task |
POWRUNER persists through a scheduled task that executes it every minute.[1] |
Enterprise | T1113 | Screen Capture | ||
Enterprise | T1518 | .001 | Software Discovery: Security Software Discovery |
POWRUNER may collect information on the victim's anti-virus software.[1] |
Enterprise | T1082 | System Information Discovery |
POWRUNER may collect information about the system by running |
|
Enterprise | T1016 | System Network Configuration Discovery |
POWRUNER may collect network configuration data by running |
|
Enterprise | T1049 | System Network Connections Discovery |
POWRUNER may collect active network connections by running |
|
Enterprise | T1033 | System Owner/User Discovery |
POWRUNER may collect information about the currently logged in user by running |
|
Enterprise | T1047 | Windows Management Instrumentation |
POWRUNER may use WMI when collecting information about a victim.[1] |
ID | Name | References |
---|---|---|
G0049 | OilRig |