TheWover. (2019, May 9). donut. Retrieved March 25, 2022.
Not cited by any technique.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1027.002 Software Packing |
ToolDonut | Donut can generate packed code modules. |
| T1027.013 Encrypted/Encoded File |
ToolDonut | Donut can generate encrypted, compressed/encoded, or otherwise obfuscated code modules. |
| T1027.015 Compression |
ToolDonut | Donut can generate encrypted, compressed/encoded, or otherwise obfuscated code modules. |
| T1055 Process Injection |
ToolDonut | Donut includes a subproject |
| T1057 Process Discovery |
ToolDonut | Donut includes subprojects that enumerate and identify information about Process Injection candidates. |
| T1059 Command and Scripting Interpreter |
ToolDonut | Donut can generate shellcode outputs that execute via Ruby. |
| T1059.001 PowerShell |
ToolDonut | Donut can generate shellcode outputs that execute via PowerShell. |
| T1059.005 Visual Basic |
ToolDonut | Donut can generate shellcode outputs that execute via VBScript. |
| T1059.006 Python |
ToolDonut | Donut can generate shellcode outputs that execute via Python. |
| T1059.007 JavaScript |
ToolDonut | Donut can generate shellcode outputs that execute via JavaScript or JScript. |
| T1070 Indicator Removal |
ToolDonut | Donut can erase file references to payloads in-memory after being reflectively loaded and executed. |
| T1071.001 Web Protocols |
ToolDonut | Donut can use HTTP to download previously staged shellcode payloads. |
| T1105 Ingress Tool Transfer |
ToolDonut | Donut can download and execute previously staged shellcode payloads. |
| T1106 Native API |
ToolDonut | Donut code modules use various API functions to load and inject code. |
| T1620 Reflective Code Loading |
ToolDonut | Donut can generate code modules that enable in-memory execution of VBScript, JScript, EXE, DLL, and dotNET payloads. |
| T1685 Disable or Modify Tools |
ToolDonut | Donut can patch Antimalware Scan Interface (AMSI), Windows Lockdown Policy (WLDP), as well as exit-related Native API functions to avoid process termination. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.