PowerShellMafia. (2012, May 26). PowerSploit - A PowerShell Post-Exploitation Framework. Retrieved February 6, 2018.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1003.001 LSASS Memory |
ToolPowerSploit | PowerSploit contains a collection of Exfiltration modules that can harvest credentials using Mimikatz. |
| T1005 Data from Local System |
ToolPowerSploit | PowerSploit contains a collection of Exfiltration modules that can access data from local files, volumes, and processes. |
| T1012 Query Registry |
ToolPowerSploit | PowerSploit contains a collection of Privesc-PowerUp modules that can query Registry keys for potential opportunities. |
| T1027.005 Indicator Removal from Tools |
ToolPowerSploit | PowerSploit's |
| T1027.010 Command Obfuscation |
ToolPowerSploit | PowerSploit contains a collection of ScriptModification modules that compress and encode scripts and payloads. |
| T1047 Windows Management Instrumentation |
ToolPowerSploit | PowerSploit's |
| T1053.005 Scheduled Task |
ToolPowerSploit | PowerSploit's |
| T1055.001 Dynamic-link Library Injection |
ToolPowerSploit | PowerSploit contains a collection of CodeExecution modules that inject code (DLL, shellcode) into a process. |
| T1056.001 Keylogging |
ToolPowerSploit | PowerSploit's |
| T1057 Process Discovery |
ToolPowerSploit | PowerSploit's |
| T1059.001 PowerShell |
ToolPowerSploit | PowerSploit modules are written in and executed via PowerShell. |
| T1087.001 Local Account |
ToolPowerSploit | PowerSploit's |
| T1113 Screen Capture |
ToolPowerSploit | PowerSploit's |
| T1123 Audio Capture |
ToolPowerSploit | PowerSploit's |
| T1134 Access Token Manipulation |
ToolPowerSploit | PowerSploit's |
| T1482 Domain Trust Discovery |
ToolPowerSploit | PowerSploit has modules such as |
| T1543.003 Windows Service |
ToolPowerSploit | PowerSploit contains a collection of Privesc-PowerUp modules that can discover and replace/modify service binaries, paths, and configs. |
| T1547.001 Registry Run Keys / Startup Folder |
ToolPowerSploit | PowerSploit's |
| T1547.005 Security Support Provider |
ToolPowerSploit | PowerSploit's |
| T1552.006 Group Policy Preferences |
ToolPowerSploit | PowerSploit contains a collection of Exfiltration modules that can harvest credentials from Group Policy Preferences. |
| T1555.004 Windows Credential Manager |
ToolPowerSploit | PowerSploit contains a collection of Exfiltration modules that can harvest credentials from Windows vault credential objects. |
| T1574.001 DLL |
ToolPowerSploit | PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit DLL hijacking opportunities in services and processes. |
| T1574.007 Path Interception by PATH Environment Variable |
ToolPowerSploit | PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit path interception opportunities in the PATH environment variable. |
| T1574.008 Path Interception by Search Order Hijacking |
ToolPowerSploit | PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit search order hijacking vulnerabilities. |
| T1574.009 Path Interception by Unquoted Path |
ToolPowerSploit | PowerSploit contains a collection of Privesc-PowerUp modules that can discover and exploit unquoted path vulnerabilities. |
| T1620 Reflective Code Loading |
ToolPowerSploit | PowerSploit reflectively loads a Windows PE file into a process. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.