| Technique | Procedure example |
|---|---|
| T1027.002 Software Packing |
Donut can generate packed code modules. |
| T1027.013 Encrypted/Encoded File |
Donut can generate encrypted, compressed/encoded, or otherwise obfuscated code modules. |
| T1027.015 Compression |
Donut can generate encrypted, compressed/encoded, or otherwise obfuscated code modules. |
| T1055 Process Injection |
Donut includes a subproject |
| T1057 Process Discovery |
Donut includes subprojects that enumerate and identify information about Process Injection candidates. |
| T1059 Command and Scripting Interpreter |
Donut can generate shellcode outputs that execute via Ruby. |
| T1059.001 PowerShell |
Donut can generate shellcode outputs that execute via PowerShell. |
| T1059.005 Visual Basic |
Donut can generate shellcode outputs that execute via VBScript. |
| T1059.006 Python |
Donut can generate shellcode outputs that execute via Python. |
| T1059.007 JavaScript |
Donut can generate shellcode outputs that execute via JavaScript or JScript. |
| T1070 Indicator Removal |
Donut can erase file references to payloads in-memory after being reflectively loaded and executed. |
| T1071.001 Web Protocols |
Donut can use HTTP to download previously staged shellcode payloads. |
| T1105 Ingress Tool Transfer |
Donut can download and execute previously staged shellcode payloads. |
| T1106 Native API |
Donut code modules use various API functions to load and inject code. |
| T1620 Reflective Code Loading |
Donut can generate code modules that enable in-memory execution of VBScript, JScript, EXE, DLL, and dotNET payloads. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.