byt3bl33d3r. (n.d.). SILENTTRINITY. Retrieved September 12, 2024.
Not cited by any technique.
None recorded.
None recorded.
None recorded.
| Technique | Used by | Procedure example |
|---|---|---|
| T1115 Clipboard Data |
ToolSILENTTRINITY | SILENTTRINITY can monitor Clipboard text and can use `System.Windows.Forms.Clipboard.GetText()` to collect data from the clipboard. |
| T1134.003 Make and Impersonate Token |
ToolSILENTTRINITY | SILENTTRINITY can make tokens from known credentials. |
| T1559.001 Component Object Model |
ToolSILENTTRINITY | SILENTTRINITY can insert malicious shellcode into Excel.exe using a `Microsoft.Office.Interop` object. |
| T1620 Reflective Code Loading |
ToolSILENTTRINITY | SILENTTRINITY can run a .NET executable within the memory of a sacrificial process by loading the CLR. |
| T1689 Downgrade Attack |
ToolSILENTTRINITY | SILENTTRINITY can downgrade NTLM to capture NTLM hashes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.