ATT&CKReferencesGitHub PoshC2

GitHub PoshC2

Nettitude. (2018, July 23). Python Server for PoshC2. Retrieved April 23, 2019.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples31

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
ToolPoshC2

PoshC2 contains an implementation of Mimikatz to gather credentials from memory.

T1007
System Service Discovery
ToolPoshC2

PoshC2 can enumerate service and service permission information.

T1016
System Network Configuration Discovery
ToolPoshC2

PoshC2 can enumerate network adapter information.

T1040
Network Sniffing
ToolPoshC2

PoshC2 contains a module for taking packet captures on compromised hosts.

T1046
Network Service Discovery
ToolPoshC2

PoshC2 can perform port scans from an infected host.

T1047
Windows Management Instrumentation
ToolPoshC2

PoshC2 has a number of modules that use WMI to execute tasks.

T1049
System Network Connections Discovery
ToolPoshC2

PoshC2 contains an implementation of netstat to enumerate TCP and UDP connections.

T1055
Process Injection
ToolPoshC2

PoshC2 contains multiple modules for injecting into processes, such as Invoke-PSInject.

T1056.001
Keylogging
ToolPoshC2

PoshC2 has modules for keystroke logging and capturing credentials from spoofed Outlook authentication messages.

T1068
Exploitation for Privilege Escalation
ToolPoshC2

PoshC2 contains modules for local privilege escalation exploits such as CVE-2016-9192 and CVE-2016-0099.

T1069.001
Local Groups
ToolPoshC2

PoshC2 contains modules, such as Get-LocAdm for enumerating permission groups.

T1071.001
Web Protocols
ToolPoshC2

PoshC2 can use protocols like HTTP/HTTPS for command and control traffic.

T1082
System Information Discovery
ToolPoshC2

PoshC2 contains modules, such as Get-ComputerInfo, for enumerating common system information.

T1083
File and Directory Discovery
ToolPoshC2

PoshC2 can enumerate files on the local file system and includes a module for enumerating recently accessed files.

T1087.001
Local Account
ToolPoshC2

PoshC2 can enumerate local and domain user account information.

T1087.002
Domain Account
ToolPoshC2

PoshC2 can enumerate local and domain user account information.

T1090
Proxy
ToolPoshC2

PoshC2 contains modules that allow for use of proxies in command and control.

T1110
Brute Force
ToolPoshC2

PoshC2 has modules for brute forcing local administrator and AD user accounts.

T1119
Automated Collection
ToolPoshC2

PoshC2 contains a module for recursively parsing through files and directories to gather valid credit card numbers.

T1134
Access Token Manipulation
ToolPoshC2

PoshC2 can use Invoke-TokenManipulation for manipulating tokens.

T1134.002
Create Process with Token
ToolPoshC2

PoshC2 can use Invoke-RunAs to make tokens.

T1201
Password Policy Discovery
ToolPoshC2

PoshC2 can use Get-PassPol to enumerate the domain password policy.

T1210
Exploitation of Remote Services
ToolPoshC2

PoshC2 contains a module for exploiting SMB via EternalBlue.

T1482
Domain Trust Discovery
ToolPoshC2

PoshC2 has modules for enumerating domain trusts.

T1546.003
Windows Management Instrumentation Event Subscription
ToolPoshC2

PoshC2 has the ability to persist on a system using WMI events.

T1548.002
Bypass User Account Control
ToolPoshC2

PoshC2 can utilize multiple methods to bypass UAC.

T1550.002
Pass the Hash
ToolPoshC2

PoshC2 has a number of modules that leverage pass the hash for lateral movement.

T1552.001
Credentials In Files
ToolPoshC2

PoshC2 contains modules for searching for passwords in local and remote files.

T1557.001
Name Resolution Poisoning and SMB Relay
ToolPoshC2

PoshC2 can use Inveigh to conduct name service poisoning for credential theft and associated relay attacks.

T1560.001
Archive via Utility
ToolPoshC2

PoshC2 contains a module for compressing data using ZIP.

T1569.002
Service Execution
ToolPoshC2

PoshC2 contains an implementation of PsExec for remote execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.