Covenant is a multi-platform command and control framework written in .NET. While designed for penetration testing and security research, the tool has also been used by threat actors such as HAFNIUM during operations. Covenant functions through a central listener managing multiple deployed "Grunts" that communicate back to the controller.
| Technique | Procedure example |
|---|---|
| T1047 Windows Management Instrumentation |
Covenant can utilize WMI to install new Grunt listeners through XSL files or command one-liners. |
| T1059.001 PowerShell |
Covenant can create PowerShell-based launchers for Grunt installation. |
| T1059.003 Windows Command Shell |
Covenant provides access to a Command Shell in Windows environments for follow-on command execution and tasking. |
| T1071.001 Web Protocols |
Covenant can establish command and control via HTTP. |
| T1082 System Information Discovery |
Covenant implants can gather basic information on infected systems. |
| T1218.004 InstallUtil |
Covenant can create launchers via an InstallUtil XML file to install new Grunt listeners. |
| T1218.005 Mshta |
Covenant can create HTA files to install Grunt listeners. |
| T1218.010 Regsvr32 |
Covenant can create SCT files for installation via `Regsvr32` to deploy new Grunt listeners. |
| T1571 Non-Standard Port |
Covenant listeners and controllers can be configured to use non-standard ports. |
| T1573.002 Asymmetric Cryptography |
Covenant can utilize SSL to encrypt command and control traffic. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.