| Technique | Procedure example |
|---|---|
| T1003.002 Security Account Manager |
Koadic can gather hashed passwords by dumping SAM/SECURITY hive. |
| T1003.003 NTDS |
Koadic can gather hashed passwords by gathering domain controller hashes from NTDS. |
| T1005 Data from Local System |
Koadic can download files off the target system to send back to the server. |
| T1016 System Network Configuration Discovery |
Koadic can retrieve the contents of the IP routing table as well as information about the Windows domain. |
| T1021.001 Remote Desktop Protocol |
Koadic can enable remote desktop on the victim's machine. |
| T1033 System Owner/User Discovery |
Koadic can identify logged in users across the domain and views user sessions. |
| T1046 Network Service Discovery |
Koadic can scan for open TCP ports on the target network. |
| T1047 Windows Management Instrumentation |
Koadic can use WMI to execute commands. |
| T1053.005 Scheduled Task |
Koadic has used scheduled tasks to add persistence. |
| T1055.001 Dynamic-link Library Injection |
Koadic can perform process injection by using a reflective DLL. |
| T1059.001 PowerShell |
Koadic has used PowerShell to establish persistence. |
| T1059.003 Windows Command Shell |
Koadic can open an interactive command-shell to perform command line functions on victim machines. Koadic performs most of its operations using Windows Script Host (Jscript) and to run arbitrary shellcode. |
| T1059.005 Visual Basic |
Koadic performs most of its operations using Windows Script Host (VBScript) and runs arbitrary shellcode . |
| T1071.001 Web Protocols |
Koadic has used HTTP for C2 communications. |
| T1082 System Information Discovery |
Koadic can obtain the OS version and build, computer name, and processor architecture from a compromised host. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.