Windows LOLBin Binary in Non Standard Path
Masquerading, Rename System Utilities, System Binary Proxy Execution, InstallUtil
Masquerading, Rename System Utilities, System Binary Proxy Execution, InstallUtil
Masquerading, Rename System Utilities
NTDS, OS Credential Dumping
Masquerading
File and Directory Permissions Modification
Account Access Removal
Masquerading, Rename System Utilities, System Binary Proxy Execution, InstallUtil
MSBuild, Trusted Developer Utilities Proxy Execution
Trusted Developer Utilities Proxy Execution, MSBuild
Command and Scripting Interpreter
Mshta, System Binary Proxy Execution
Mshta, System Binary Proxy Execution
Mshta, System Binary Proxy Execution
System Binary Proxy Execution, Mshta
System Binary Proxy Execution
Command and Scripting Interpreter
BITS Jobs, Ingress Tool Transfer
Deobfuscate/Decode Files or Information
Ingress Tool Transfer
Ingress Tool Transfer
BITS Jobs, Ingress Tool Transfer
Dynamic-link Library Injection, System Binary Proxy Execution, Process Injection
BITS Jobs
Automated Exfiltration
Automated Exfiltration
File Deletion, Indicator Removal on Host
Windows File and Directory Permissions Modification, File and Directory Permissions Modification
Indicator Removal on Host
Inhibit System Recovery
Inhibit System Recovery
Domain Accounts
Exfiltration Over Alternative Protocol
Automated Exfiltration
Ingress Tool Transfer
Command and Scripting Interpreter, Indirect Command Execution
Service Stop
Exploitation for Client Execution, Command and Scripting Interpreter, Scheduled Task/Job, Software Deployment Tools
File and Directory Permissions Modification
Service Stop, Valid Accounts
File and Directory Permissions Modification
OS Credential Dumping, Security Account Manager
OS Credential Dumping, Security Account Manager
Service Stop
Service Stop, Create or Modify System Process, Windows Service
Archive via Utility, Archive Collected Data
Data Destruction, File Deletion, Indicator Removal on Host
Indicator Removal on Host, Clear Windows Event Logs
Indicator Removal on Host, Clear Windows Event Logs
Kerberoasting, Steal or Forge Kerberos Tickets
Command and Scripting Interpreter, Scheduled Task/Job