ATT&CKReferencesGitHub SILENTTRINITY Modules July 2019

GitHub SILENTTRINITY Modules July 2019

Salvati, M. (2019, August 6). SILENTTRINITY Modules. Retrieved March 24, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples47

TechniqueUsed byProcedure example
T1003.001
LSASS Memory
ToolSILENTTRINITY

SILENTTRINITY can create a memory dump of LSASS via the `MiniDumpWriteDump Win32` API call.

T1007
System Service Discovery
ToolSILENTTRINITY

SILENTTRINITY can search for modifiable services that could be used for privilege escalation.

T1010
Application Window Discovery
ToolSILENTTRINITY

SILENTTRINITY can enumerate the active Window during keylogging through execution of `GetActiveWindowTitle`.

T1012
Query Registry
ToolSILENTTRINITY

SILENTTRINITY can use the `GetRegValue` function to check Registry keys within `HKCU\Software\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated` and `HKLM\Software\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated`. It also contains additional modules that can check software AutoRun values and use the Win32 namespace to get values from HKCU, HKLM, HKCR, and HKCC hives.

T1018
Remote System Discovery
ToolSILENTTRINITY

SILENTTRINITY can enumerate and collect the properties of domain computers.

T1021.003
Distributed Component Object Model
ToolSILENTTRINITY

SILENTTRINITY can use `System` namespace methods to execute lateral movement using DCOM.

T1021.006
Windows Remote Management
ToolSILENTTRINITY

SILENTTRINITY tracks `TrustedHosts` and can move laterally to these targets via WinRM.

T1033
System Owner/User Discovery
ToolSILENTTRINITY

SILENTTRINITY can gather a list of logged on users.

T1041
Exfiltration Over C2 Channel
ToolSILENTTRINITY

SILENTTRINITY can transfer files from an infected host to the C2 server.

T1046
Network Service Discovery
ToolSILENTTRINITY

SILENTTRINITY can scan for open ports on a compromised machine.

T1047
Windows Management Instrumentation
ToolSILENTTRINITY

SILENTTRINITY can use WMI for lateral movement.

T1055
Process Injection
ToolSILENTTRINITY

SILENTTRINITY can inject shellcode directly into Excel.exe or a specific process.

T1056.001
Keylogging
ToolSILENTTRINITY

SILENTTRINITY has a keylogging capability.

T1056.002
GUI Input Capture
ToolSILENTTRINITY

SILENTTRINITY's `credphisher.py` module can prompt a current user for their credentials.

T1057
Process Discovery
ToolSILENTTRINITY

SILENTTRINITY can enumerate processes, including properties to determine if they have the Common Language Runtime (CLR) loaded.

T1059.001
PowerShell
ToolSILENTTRINITY

SILENTTRINITY can use PowerShell to execute commands.

T1059.003
Windows Command Shell
ToolSILENTTRINITY

SILENTTRINITY can use `cmd.exe` to enable lateral movement using DCOM.

T1059.006
Python
ToolSILENTTRINITY

SILENTTRINITY is written in Python and can use multiple Python scripts for execution on targeted systems.

T1069.001
Local Groups
ToolSILENTTRINITY

SILENTTRINITY can obtain a list of local groups and members.

T1069.002
Domain Groups
ToolSILENTTRINITY

SILENTTRINITY can use `System.DirectoryServices` namespace to retrieve domain group information.

T1070
Indicator Removal
ToolSILENTTRINITY

SILENTTRINITY can remove artifacts from the compromised host, including created Registry keys.

T1070.004
File Deletion
ToolSILENTTRINITY

SILENTTRINITY can remove files from the compromised host.

T1082
System Information Discovery
ToolSILENTTRINITY

SILENTTRINITY can collect information related to a compromised host, including OS version.

T1083
File and Directory Discovery
ToolSILENTTRINITY

SILENTTRINITY has several modules, such as `ls.py`, `pwd.py`, and `recentFiles.py`, to enumerate directories and files.

T1087.002
Domain Account
ToolSILENTTRINITY

SILENTTRINITY can use `System.Security.AccessControl` namespaces to retrieve domain user information.

T1105
Ingress Tool Transfer
ToolSILENTTRINITY

SILENTTRINITY can load additional files and tools, including Mimikatz.

T1106
Native API
ToolSILENTTRINITY

SILENTTRINITY has the ability to leverage API including `GetProcAddress` and `LoadLibrary`.

T1112
Modify Registry
ToolSILENTTRINITY

SILENTTRINITY can modify registry keys, including to enable or disable Remote Desktop Protocol (RDP).

T1113
Screen Capture
ToolSILENTTRINITY

SILENTTRINITY can take a screenshot of the current desktop.

T1124
System Time Discovery
ToolSILENTTRINITY

SILENTTRINITY can collect start time information from a compromised host.

T1134.001
Token Impersonation/Theft
ToolSILENTTRINITY

SILENTTRINITY can find a process owned by a specific user and impersonate the associated token.

T1135
Network Share Discovery
ToolSILENTTRINITY

SILENTTRINITY can enumerate shares on a compromised host.

T1543.003
Windows Service
ToolSILENTTRINITY

SILENTTRINITY can establish persistence by creating a new service.

T1546.001
Change Default File Association
ToolSILENTTRINITY

SILENTTRINITY can conduct an image hijack of an `.msc` file extension as part of its UAC bypass process.

T1546.003
Windows Management Instrumentation Event Subscription
ToolSILENTTRINITY

SILENTTRINITY can create a WMI Event to execute a payload for persistence.

T1546.015
Component Object Model Hijacking
ToolSILENTTRINITY

SILENTTRINITY can add a CLSID key for payload execution through `Registry.CurrentUser.CreateSubKey("Software\\Classes\\CLSID\\{" + clsid + "}\\InProcServer32")`.

T1547.001
Registry Run Keys / Startup Folder
ToolSILENTTRINITY

SILENTTRINITY can establish a LNK file in the startup folder for persistence.

T1548.002
Bypass User Account Control
ToolSILENTTRINITY

SILENTTRINITY contains a number of modules that can bypass UAC, including through Window's Device Manager, Manage Optional Features, and an image hijack on the `.msc` file extension.

T1552.006
Group Policy Preferences
ToolSILENTTRINITY

SILENTTRINITY has a module that can extract cached GPP passwords.

T1555.003
Credentials from Web Browsers
ToolSILENTTRINITY

SILENTTRINITY can collect clear text web credentials for Internet Explorer/Edge.

T1555.004
Windows Credential Manager
ToolSILENTTRINITY

SILENTTRINITY can gather Windows Vault credentials.

T1556
Modify Authentication Process
ToolSILENTTRINITY

SILENTTRINITY can create a backdoor in KeePass using a malicious config file and in TortoiseSVN using a registry hook.

T1558.003
Kerberoasting
ToolSILENTTRINITY

SILENTTRINITY contains a module to conduct Kerberoasting.

T1564.003
Hidden Window
ToolSILENTTRINITY

SILENTTRINITY has the ability to set its window state to hidden.

T1680
Local Storage Discovery
ToolSILENTTRINITY

SILENTTRINITY can collect information related to a compromised host, including a list of drives.

T1685
Disable or Modify Tools
ToolSILENTTRINITY

SILENTTRINITY's `amsiPatch.py` module can disable Antimalware Scan Interface (AMSI) functions.

T1690
Prevent Command History Logging
ToolSILENTTRINITY

SILENTTRINITY can bypass ScriptBlock logging to execute unmanaged PowerShell code from memory.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.