Skip to content

UNC2452 Coverage

Ivan Kirillov edited this page May 3, 2021 · 1 revision

Based on this ATT&CK Navigator layer.

T1560.001 : Archive via Utility

T1059.001 : PowerShell

T1059.003 : Windows Command Shell

T1105 : Ingress Tool Transfer

T1036 : Masquerading

T1036.005 : Match Legitimate Name or Location

T1069.002 : Domain Groups

T1057 : Process Discovery

T1053.005 : Scheduled Task

T1218.011 : Rundll32

T1059 : Command and Scripting Interpreter

T1546.003 : Windows Management Instrumentation Event Subscription

T1098 : Account Manipulation

T1543.003 : Windows Service

T1562.001 : Disable or Modify Tools

T1112 : Modify Registry

T1012 : Query Registry

T1518.001 : Security Software Discovery

T1082 : System Information Discovery

T1016 : System Network Configuration Discovery

T1033 : System Owner/User Discovery

T1007 : System Service Discovery

T1047 : Windows Management Instrumentation