Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1003.002 Security Account Manager |
POWERTON has the ability to dump password hashes. |
| T1059.001 PowerShell |
POWERTON is written in PowerShell. |
| T1071.001 Web Protocols |
POWERTON has used HTTP/HTTPS for C2 traffic. |
| T1546.003 Windows Management Instrumentation Event Subscription |
POWERTON can use WMI for persistence. |
| T1547.001 Registry Run Keys / Startup Folder |
POWERTON can install a Registry Run key for persistence. |
| T1573.001 Symmetric Cryptography |
POWERTON has used AES for encrypting C2 traffic. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.