AWS ECR Container Upload Outside Business Hours
Malicious Image, User Execution
Malicious Image, User Execution
Malicious Image, User Execution
Malicious Image, User Execution
Malicious Image, User Execution
Malicious Image, User Execution
Malicious Image, User Execution
Malicious Image, User Execution
Malicious Image, User Execution
Command and Scripting Interpreter
Command and Scripting Interpreter
Malicious Image, User Execution
Malicious Image, User Execution
Shared Modules
Exploit Public-Facing Application, Ingress Tool Transfer, Command and Scripting Interpreter
Command and Scripting Interpreter, Windows Command Shell, Windows Service, Create or Modify System Process
Command and Scripting Interpreter, Windows Command Shell, Windows Service, Create or Modify System Process
Command and Scripting Interpreter, PowerShell
Command and Scripting Interpreter, PowerShell
Command and Scripting Interpreter, PowerShell
Command and Scripting Interpreter, PowerShell
Steal or Forge Authentication Certificates, Command and Scripting Interpreter, PowerShell
Steal or Forge Authentication Certificates, Command and Scripting Interpreter, PowerShell
PowerShell, Command and Scripting Interpreter
PowerShell, Command and Scripting Interpreter
File and Directory Permissions Modification, System Network Connections Discovery, System Owner/User Discovery, System Shutdown/Reboot, System Network Config...
Command and Scripting Interpreter, PowerShell
Command and Scripting Interpreter, PowerShell
Scheduled Task, Command and Scripting Interpreter
Scheduled Task, Command and Scripting Interpreter
Malicious File, Masquerade File Type
Remote Services, SMB/Windows Admin Shares, Distributed Component Object Model, Windows Management Instrumentation, Windows Service
Remote Services, SMB/Windows Admin Shares, Distributed Component Object Model, Windows Management Instrumentation, Windows Service
Account Discovery, Domain Account, User Execution, Malicious File
Account Discovery, Domain Account, User Execution, Malicious File
Remote Services, SMB/Windows Admin Shares, Distributed Component Object Model, Windows Management Instrumentation, Windows Service
PowerShell, Ingress Tool Transfer
Windows Management Instrumentation
PowerShell, Ingress Tool Transfer, Fileless Storage
Scheduled Task, PowerShell, Command and Scripting Interpreter
Scheduled Task, PowerShell, Command and Scripting Interpreter
Scheduled Task, PowerShell, Command and Scripting Interpreter
Command and Scripting Interpreter, Exploit Public-Facing Application, External Remote Services
Kernel Modules and Extensions, Service Execution
PowerShell, Command and Scripting Interpreter
PowerShell, Command and Scripting Interpreter
Unix Shell, Command and Scripting Interpreter
Unix Shell, Command and Scripting Interpreter
Command and Scripting Interpreter, PowerShell
Command and Scripting Interpreter, PowerShell
Command and Scripting Interpreter, PowerShell
Command and Scripting Interpreter, PowerShell
Remote Services, Distributed Component Object Model, Windows Remote Management, Windows Management Instrumentation, Scheduled Task, Windows Service, PowerShe...
Remote Services, Distributed Component Object Model, Windows Remote Management, Windows Management Instrumentation, Scheduled Task, Windows Service, PowerShe...
Remote Services, Distributed Component Object Model, Windows Remote Management, Windows Management Instrumentation, Scheduled Task, Windows Service, PowerShe...
PowerShell, Command and Scripting Interpreter
PowerShell, Command and Scripting Interpreter
Command and Scripting Interpreter, PowerShell
Command and Scripting Interpreter, PowerShell
Command and Scripting Interpreter, PowerShell
Command and Scripting Interpreter, PowerShell
Scheduled Task/Job
Command and Scripting Interpreter, Process Injection, PowerShell
Command and Scripting Interpreter, Process Injection, PowerShell
Impair Defenses, PowerShell, Command and Scripting Interpreter
Impair Defenses, PowerShell, Command and Scripting Interpreter
Component Object Model Hijacking, Event Triggered Execution, PowerShell
Cron, Scheduled Task/Job
Cron, Scheduled Task/Job
Visual Basic, Command and Scripting Interpreter
Visual Basic, Command and Scripting Interpreter
Visual Basic, Command and Scripting Interpreter
Visual Basic, Command and Scripting Interpreter
Command and Scripting Interpreter, PowerShell, Ingress Tool Transfer
Command and Scripting Interpreter, PowerShell, Ingress Tool Transfer
Command and Scripting Interpreter, PowerShell
Command and Scripting Interpreter, PowerShell
Scheduled Task/Job
Systemd Timers, Scheduled Task/Job
Systemd Timers, Scheduled Task/Job
Gather Victim Host Information, PowerShell
User Execution, Malicious File
User Execution, Malicious File
Scheduled Task, Scheduled Task/Job
Scheduled Task, Scheduled Task/Job
Scheduled Task
Command and Scripting Interpreter, Obfuscated Files or Information, PowerShell
Command and Scripting Interpreter, Obfuscated Files or Information, PowerShell
Command and Scripting Interpreter, PowerShell
Command and Scripting Interpreter, PowerShell
Scheduled Task, Scheduled Task/Job
Scheduled Task, Scheduled Task/Job
Account Discovery, Local Account, PowerShell
Scheduled Task, Scheduled Task/Job
Scheduled Task, Scheduled Task/Job
Windows Command Shell, Command and Scripting Interpreter
Windows Command Shell, Command and Scripting Interpreter
Scheduled Task/Job
Command and Scripting Interpreter, PowerShell, Ingress Tool Transfer
Command and Scripting Interpreter, PowerShell, Ingress Tool Transfer
Scheduled Task, Scheduled Task/Job
Scheduled Task, Scheduled Task/Job
PowerShell, Command and Scripting Interpreter
PowerShell, Command and Scripting Interpreter
Scheduled Task
PowerShell
Windows Management Instrumentation
PowerShell, Command and Scripting Interpreter
PowerShell, Command and Scripting Interpreter
Windows Management Instrumentation
User Execution
System Services, Service Execution
System Services, Service Execution
PowerShell, Command and Scripting Interpreter
PowerShell, Command and Scripting Interpreter
Scheduled Task/Job, Scheduled Task
Scheduled Task/Job, Scheduled Task
Command and Scripting Interpreter
Malicious File, User Execution
Malicious File, User Execution
Windows Management Instrumentation
Command and Scripting Interpreter, PowerShell
Command and Scripting Interpreter, PowerShell
Command and Scripting Interpreter
Windows Management Instrumentation
System Services, Service Execution
System Services, Service Execution
Command and Scripting Interpreter, JavaScript
Command and Scripting Interpreter, JavaScript
Windows Management Instrumentation
Command and Scripting Interpreter, PowerShell
Command and Scripting Interpreter, PowerShell
Component Object Model Hijacking, Command and Scripting Interpreter, PowerShell
Component Object Model Hijacking, Command and Scripting Interpreter, PowerShell
Spearphishing Attachment, Phishing, Malicious Link, User Execution
Spearphishing Attachment, Phishing, Malicious Link, User Execution
Command and Scripting Interpreter
Ingress Tool Transfer, Exploit Public-Facing Application, Command and Scripting Interpreter, External Remote Services
Ingress Tool Transfer, Exploit Public-Facing Application, Command and Scripting Interpreter, External Remote Services
Windows Command Shell, Command and Scripting Interpreter
Windows Command Shell, Command and Scripting Interpreter
Obfuscated Files or Information, Unix Shell
PowerShell, Command and Scripting Interpreter, Disable or Modify Tools, Impair Defenses
PowerShell, Command and Scripting Interpreter, Disable or Modify Tools, Impair Defenses
Command and Scripting Interpreter
Command and Scripting Interpreter
Command and Scripting Interpreter
Command and Scripting Interpreter
Command and Scripting Interpreter
At, Scheduled Task/Job
At, Scheduled Task/Job
At, Scheduled Task/Job
At, Scheduled Task/Job
Command and Scripting Interpreter
Scheduled Task, Scheduled Task/Job
Scheduled Task, Scheduled Task/Job
Obfuscated Files or Information, Indicator Removal from Tools, PowerShell
Scheduled Task, Impair Defenses
System Services, Service Execution
System Services, Service Execution
Account Discovery, Local Account, PowerShell
Unix Shell, Command and Scripting Interpreter
Unix Shell, Command and Scripting Interpreter
Command and Scripting Interpreter
Command and Scripting Interpreter
OS Credential Dumping, PowerShell
Domain Trust Discovery, PowerShell
User Execution
Windows Management Instrumentation
Scheduled Task, Scheduled Task/Job
Scheduled Task, Scheduled Task/Job
Windows Command Shell
Systemd Timers, Scheduled Task/Job
Systemd Timers, Scheduled Task/Job
Systemd Timers, Scheduled Task/Job
Systemd Timers, Scheduled Task/Job
Cron, Scheduled Task/Job
Cron, Scheduled Task/Job
Cron, Scheduled Task/Job
Cron, Scheduled Task/Job
Cron, Scheduled Task/Job
Cron, Scheduled Task/Job
Cron, Scheduled Task/Job
Cron, Scheduled Task/Job
Cron, Scheduled Task/Job
Cron, Scheduled Task/Job
Exploit Public-Facing Application, Command and Scripting Interpreter
Unix Shell
Scheduled Task
Scheduled Task/Job, Scheduled Task
Scheduled Task/Job, Scheduled Task
Windows Management Instrumentation
Scheduled Task/Job, Scheduled Task
Scheduled Task/Job, Scheduled Task
Windows Management Instrumentation
Windows Management Instrumentation
Scheduled Task/Job, Scheduled Task
Scheduled Task/Job, Scheduled Task
Scheduled Task/Job, At
Scheduled Task/Job, At
Command and Scripting Interpreter, Component Object Model
Command and Scripting Interpreter, Component Object Model
Visual Basic, Command and Scripting Interpreter
Visual Basic, Command and Scripting Interpreter
Command and Scripting Interpreter, JavaScript
Command and Scripting Interpreter, JavaScript
Command and Scripting Interpreter, JavaScript
Command and Scripting Interpreter, JavaScript
Command and Scripting Interpreter, JavaScript
Command and Scripting Interpreter, JavaScript
Malicious Image, User Execution
Malicious Image, User Execution
Malicious Image, User Execution
Malicious Image, User Execution
Malicious Image, User Execution
Malicious Image, User Execution
User Execution, Malicious File
User Execution, Malicious File
Command and Scripting Interpreter
System Services, Service Execution
System Services, Service Execution
Command and Scripting Interpreter, Visual Basic
Command and Scripting Interpreter, Visual Basic
Command and Scripting Interpreter
User Execution
User Execution
Command and Scripting Interpreter
Scheduled Task/Job
System Services, Service Execution
System Services, Service Execution
Command and Scripting Interpreter, PowerShell
Command and Scripting Interpreter, PowerShell
Scheduled Task, Scheduled Task/Job
Scheduled Task, Scheduled Task/Job
Command and Scripting Interpreter, Windows Command Shell
Command and Scripting Interpreter, Windows Command Shell
PowerShell
Exploitation for Client Execution
User Execution, Malicious File
User Execution, Malicious File
Scheduled Task, Scheduled Task/Job
Scheduled Task, Scheduled Task/Job
Command and Scripting Interpreter, Windows Command Shell
Command and Scripting Interpreter, Windows Command Shell
Windows Command Shell
Exploitation for Client Execution
Exploitation for Client Execution
Malicious File
Command and Scripting Interpreter, Windows Command Shell
Command and Scripting Interpreter, Windows Command Shell
PowerShell, Windows Command Shell
PowerShell, Windows Command Shell
Command and Scripting Interpreter, PowerShell
Command and Scripting Interpreter, PowerShell
System Services, Service Execution
System Services, Service Execution
Software Deployment Tools
Scheduled Task
Windows Management Instrumentation
Windows Management Instrumentation
Windows Management Instrumentation
Windows Management Instrumentation