| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1059 | .001 | Command and Scripting Interpreter: PowerShell | |
| Enterprise | T1057 | Process Discovery | ||
| Enterprise | T1055 | .001 | Process Injection: Dynamic-link Library Injection |
Socksbot creates a suspended svchost process and injects its DLL into it.[1] |
| Enterprise | T1090 | Proxy | ||
| Enterprise | T1113 | Screen Capture | ||