Domain | ID | Name | Use | |
---|---|---|---|---|
Enterprise | T1071 | .001 | Application Layer Protocol: Web Protocols | |
Enterprise | T1059 | .001 | Command and Scripting Interpreter: PowerShell |
TAMECAT has used PowerShell to download and run additional content.[1] |
.003 | Command and Scripting Interpreter: Windows Command Shell | |||
.005 | Command and Scripting Interpreter: Visual Basic | |||
Enterprise | T1132 | .001 | Data Encoding: Standard Encoding | |
Enterprise | T1573 | .001 | Encrypted Channel: Symmetric Cryptography | |
Enterprise | T1105 | Ingress Tool Transfer |
TAMECAT has used |
|
Enterprise | T1518 | .001 | Software Discovery: Security Software Discovery |
TAMECAT has used Windows Management Instrumentation (WMI) to check for anti-virus products.[1] |
Enterprise | T1047 | Windows Management Instrumentation |
TAMECAT has used Windows Management Instrumentation (WMI) to query anti-virus products.[1] |