SILENTTRINITY is an open source remote administration and post-exploitation framework primarily written in Python that includes stagers written in Powershell, C, and Boo. SILENTTRINITY was used in a 2019 campaign against Croatian government agencies by unidentified cyber actors.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
SILENTTRINITY can create a memory dump of LSASS via the `MiniDumpWriteDump Win32` API call. |
| T1007 System Service Discovery |
SILENTTRINITY can search for modifiable services that could be used for privilege escalation. |
| T1010 Application Window Discovery |
SILENTTRINITY can enumerate the active Window during keylogging through execution of `GetActiveWindowTitle`. |
| T1012 Query Registry |
SILENTTRINITY can use the `GetRegValue` function to check Registry keys within `HKCU\Software\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated` and `HKLM\Software\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated`. It also contains additional modules that can check software AutoRun values and use the Win32 namespace to get values from HKCU, HKLM, HKCR, and HKCC hives. |
| T1018 Remote System Discovery |
SILENTTRINITY can enumerate and collect the properties of domain computers. |
| T1021.003 Distributed Component Object Model |
SILENTTRINITY can use `System` namespace methods to execute lateral movement using DCOM. |
| T1021.006 Windows Remote Management |
SILENTTRINITY tracks `TrustedHosts` and can move laterally to these targets via WinRM. |
| T1033 System Owner/User Discovery |
SILENTTRINITY can gather a list of logged on users. |
| T1041 Exfiltration Over C2 Channel |
SILENTTRINITY can transfer files from an infected host to the C2 server. |
| T1046 Network Service Discovery |
SILENTTRINITY can scan for open ports on a compromised machine. |
| T1047 Windows Management Instrumentation |
SILENTTRINITY can use WMI for lateral movement. |
| T1055 Process Injection |
SILENTTRINITY can inject shellcode directly into Excel.exe or a specific process. |
| T1056.001 Keylogging |
SILENTTRINITY has a keylogging capability. |
| T1056.002 GUI Input Capture |
SILENTTRINITY's `credphisher.py` module can prompt a current user for their credentials. |
| T1057 Process Discovery |
SILENTTRINITY can enumerate processes, including properties to determine if they have the Common Language Runtime (CLR) loaded. |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.