-
Notifications
You must be signed in to change notification settings - Fork 326
UNC2452 Coverage
Ivan Kirillov edited this page May 3, 2021
·
1 revision
Based on this ATT&CK Navigator layer.
- CAR-2014-11-004 : Remote PowerShell Sessions
- CAR-2014-04-003 : Powershell Execution
- CAR-2014-04-003 : Powershell Execution
- CAR-2013-04-002 : Quick execution of a series of suspicious commands
- CAR-2016-03-001 : Host Discovery Commands
- CAR-2020-11-006 : Local Permission Group Discovery
- CAR-2013-04-002 : Quick execution of a series of suspicious commands
- CAR-2016-03-001 : Host Discovery Commands
- CAR-2015-04-002 : Remotely Scheduled Tasks via Schtasks
- CAR-2013-04-002 : Quick execution of a series of suspicious commands
- CAR-2020-09-001 : Scheduled Task - FileAccess
- CAR-2013-01-002 : Autorun Differences
- CAR-2013-08-001 : Execution with schtasks
- CAR-2014-02-001 : Service Binary Modifications
- CAR-2013-04-002 : Quick execution of a series of suspicious commands
- CAR-2013-09-005 : Service Outlier Executables
- CAR-2013-01-002 : Autorun Differences
- CAR-2014-05-002 : Services launching Cmd
- CAR-2014-03-005 : Remotely Launched Executables via Services
- CAR-2013-04-002 : Quick execution of a series of suspicious commands
- CAR-2016-04-003 : User Activity from Stopping Windows Defensive Services
- CAR-2013-04-002 : Quick execution of a series of suspicious commands
- CAR-2014-11-005 : Remote Registry
- CAR-2013-01-002 : Autorun Differences
- CAR-2020-05-003 : Rare LolBAS Command Lines
- CAR-2013-03-001 : Reg.exe called from Command Shell
- CAR-2013-04-002 : Quick execution of a series of suspicious commands
- CAR-2020-05-003 : Rare LolBAS Command Lines
- CAR-2013-03-001 : Reg.exe called from Command Shell
- CAR-2013-04-002 : Quick execution of a series of suspicious commands
- CAR-2016-03-001 : Host Discovery Commands
- CAR-2013-04-002 : Quick execution of a series of suspicious commands
- CAR-2016-03-001 : Host Discovery Commands
- CAR-2013-04-002 : Quick execution of a series of suspicious commands
- CAR-2016-03-001 : Host Discovery Commands