ATT&CKReferencesLOLBAS Esentutl

LOLBAS Esentutl

LOLBAS. (n.d.). Esentutl.exe. Retrieved September 3, 2019.

Open the source

Techniques1

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples5

TechniqueUsed byProcedure example
T1003.003
NTDS
Toolesentutl

esentutl can copy `ntds.dit` using the Volume Shadow Copy service.

T1006
Direct Volume Access
Toolesentutl

esentutl can use the Volume Shadow Copy service to copy locked files such as `ntds.dit`.

T1105
Ingress Tool Transfer
Toolesentutl

esentutl can be used to copy files from a given URL.

T1564.004
NTFS File Attributes
Toolesentutl

esentutl can be used to read and write alternate data streams.

T1570
Lateral Tool Transfer
Toolesentutl

esentutl can be used to copy files to/from a remote share.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.