ATT&CKReferencesGithub Covenant

Github Covenant

cobbr. (2021, April 21). Covenant. Retrieved September 4, 2024.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples10

TechniqueUsed byProcedure example
T1047
Windows Management Instrumentation
ToolCovenant

Covenant can utilize WMI to install new Grunt listeners through XSL files or command one-liners.

T1059.001
PowerShell
ToolCovenant

Covenant can create PowerShell-based launchers for Grunt installation.

T1059.003
Windows Command Shell
ToolCovenant

Covenant provides access to a Command Shell in Windows environments for follow-on command execution and tasking.

T1071.001
Web Protocols
ToolCovenant

Covenant can establish command and control via HTTP.

T1082
System Information Discovery
ToolCovenant

Covenant implants can gather basic information on infected systems.

T1218.004
InstallUtil
ToolCovenant

Covenant can create launchers via an InstallUtil XML file to install new Grunt listeners.

T1218.005
Mshta
ToolCovenant

Covenant can create HTA files to install Grunt listeners.

T1218.010
Regsvr32
ToolCovenant

Covenant can create SCT files for installation via `Regsvr32` to deploy new Grunt listeners.

T1571
Non-Standard Port
ToolCovenant

Covenant listeners and controllers can be configured to use non-standard ports.

T1573.002
Asymmetric Cryptography
ToolCovenant

Covenant can utilize SSL to encrypt command and control traffic.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.