Professional Documents
Culture Documents
Commands
1 C:\Windows\system32\cmd.exe /C net time
T1016.001
System Network Configuration Discovery:
Internet Connection Discovery
T1018
Remote System Discovery
T1018
Remote System Discovery
T1069.002
Permission Groups Discovery: Domain
Groups
T1087.002
Account Discovery: Domain Account
T1018
Remote System Discovery
T1016.001
System Network Configuration Discovery:
Internet Connection Discovery
T1018
Remote System Discovery
T1069.002
Permission Groups Discovery: Domain
Groups
T1087.002
Account Discovery: Domain Account
Sr. no. Commands
T1078.003
Valid Accounts: Local
Accounts
T1136.001
Create Account: Local
Account
T1098 - Account
Manipulation and
T1078.003 - Valid
Accounts: Local
Accounts
T1078.003 - Valid
Accounts: Local
Accounts T1136.001-
Create Account: Local
Account
T1078.003 - Valid
Accounts: Local
Accounts T1136.001-
Create Account: Local
Account
T1098 - Account
Manipulation and
T1078.003 - Valid
Accounts: Local
Accounts
T1547.001-Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder and T1112 - Modify Registry
?dv=win_exe'; $Destination='C:\Pr Yara gave a score of 9
Binary didn't run
Binary didn't run
Binary didn't run
Binary didn't run
T1047
Windows
Management
Instrumentation Prodump has been taggetd by yara with 9 score, Prodump rule has been created
Sr. no. Commands Detection
T1562.001
Impair Defenses: Disable or
Modify Tools
Q0025
rem reg add "HKLM\System\CurrentControlSet\Services\ Disable or Stop Services, or
4 SecurityHealthService" /v "Start" /t REG_DWORD /d "4" /f Terminate Processes
5 rem 1 - Disable Real-time protection
reg delete "HKLM\Software\Policies\Microsoft\Windows T1070
6 Defender" /f Indicator Removal on Host
T1562.001
reg add "HKLM\Software\Policies\Microsoft\Windows Defender" /v Impair Defenses: Disable or
7 "DisableAntiSpyware" /t REG_DWORD /d "1" /f Modify Tools
T1562.001
reg add "HKLM\Software\Policies\Microsoft\Windows Defender" /v Impair Defenses: Disable or
8 "DisableAntiVirus" /t REG_DWORD /d "1" /f Modify Tools
Added a rule
Added a rule
Added a rule
Added a rule
Added a rule
Added a rule
Added a rule
Added a rule
Added a rule
Added a rule
Added a rule
Added a rule