Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1059 | .001 | Command and Scripting Interpreter: PowerShell | |
Enterprise | T1057 | Process Discovery | ||
Enterprise | T1055 | .001 | Process Injection: Dynamic-link Library Injection |
Socksbot creates a suspended svchost process and injects its DLL into it.[1] |
Enterprise | T1090 | Proxy | ||
Enterprise | T1113 | Screen Capture |