ATT&CKReferencesGitHub PowerSploit May 2012

GitHub PowerSploit May 2012

PowerShellMafia. (2012, May 26). PowerSploit - A PowerShell Post-Exploitation Framework. Retrieved February 6, 2018.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples26

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
ToolPowerSploit

PowerSploit contains a collection of Exfiltration modules that can harvest credentials using Mimikatz.

T1005
Data from Local System
ToolPowerSploit

PowerSploit contains a collection of Exfiltration modules that can access data from local files, volumes, and processes.

T1012
Query Registry
ToolPowerSploit

PowerSploit contains a collection of Privesc-PowerUp modules that can query Registry keys for potential opportunities.

T1027.005
Indicator Removal from Tools
ToolPowerSploit

PowerSploit's Find-AVSignature AntivirusBypass module can be used to locate single byte anti-virus signatures.

T1027.010
Command Obfuscation
ToolPowerSploit

PowerSploit contains a collection of ScriptModification modules that compress and encode scripts and payloads.

T1047
Windows Management Instrumentation
ToolPowerSploit

PowerSploit's Invoke-WmiCommand CodeExecution module uses WMI to execute and retrieve the output from a PowerShell payload.

T1053.005
Scheduled Task
ToolPowerSploit

PowerSploit's New-UserPersistenceOption Persistence argument can be used to establish via a Scheduled Task/Job.

T1055.001
Dynamic-link Library Injection
ToolPowerSploit

PowerSploit contains a collection of CodeExecution modules that inject code (DLL, shellcode) into a process.

T1056.001
Keylogging
ToolPowerSploit

PowerSploit's Get-Keystrokes Exfiltration module can log keystrokes.

T1057
Process Discovery
ToolPowerSploit

PowerSploit's Get-ProcessTokenPrivilege Privesc-PowerUp module can enumerate privileges for a given process.

T1059.001
PowerShell
ToolPowerSploit

PowerSploit modules are written in and executed via PowerShell.

T1087.001
Local Account
ToolPowerSploit

PowerSploit's Get-ProcessTokenGroup Privesc-PowerUp module can enumerate all SIDs associated with its current token.

T1113
Screen Capture
ToolPowerSploit

PowerSploit's Get-TimedScreenshot Exfiltration module can take screenshots at regular intervals.

T1123
Audio Capture
ToolPowerSploit

PowerSploit's Get-MicrophoneAudio Exfiltration module can record system microphone audio.

T1134
Access Token Manipulation
ToolPowerSploit

PowerSploit's Invoke-TokenManipulation Exfiltration module can be used to manipulate tokens.

T1482
Domain Trust Discovery
ToolPowerSploit

PowerSploit has modules such as Get-NetDomainTrust and Get-NetForestTrust to enumerate domain and forest trusts.

T1543.003
Windows Service
ToolPowerSploit

PowerSploit contains a collection of Privesc-PowerUp modules that can discover and replace/modify service binaries, paths, and configs.

T1547.001
Registry Run Keys / Startup Folder
ToolPowerSploit

PowerSploit's New-UserPersistenceOption Persistence argument can be used to establish via the HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run Registry key.

T1547.005
Security Support Provider
ToolPowerSploit

PowerSploit's Install-SSP Persistence module can be used to establish by installing a SSP DLL.

T1552.006
Group Policy Preferences
ToolPowerSploit

PowerSploit contains a collection of Exfiltration modules that can harvest credentials from Group Policy Preferences.

T1555.004
Windows Credential Manager
ToolPowerSploit

PowerSploit contains a collection of Exfiltration modules that can harvest credentials from Windows vault credential objects.

T1574.001
DLL
ToolPowerSploit

PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit DLL hijacking opportunities in services and processes.

T1574.007
Path Interception by PATH Environment Variable
ToolPowerSploit

PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit path interception opportunities in the PATH environment variable.

T1574.008
Path Interception by Search Order Hijacking
ToolPowerSploit

PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit search order hijacking vulnerabilities.

T1574.009
Path Interception by Unquoted Path
ToolPowerSploit

PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit unquoted path vulnerabilities.

T1620
Reflective Code Loading
ToolPowerSploit

PowerSploit reflectively loads a Windows PE file into a process.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.