Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1059 | .003 | Command and Scripting Interpreter: Windows Command Shell |
hcdLoader provides command-line access to the compromised system.[1] |
Enterprise | T1543 | .003 | Create or Modify System Process: Windows Service |
hcdLoader installs itself as a service for persistence.[1][2] |