Home >
Enterprise >
Participants >
Secureworks >
Native API (T1106)
|
|
See technique results for:
APT29 |
||||||
Step | ATT&CK Pattern |
|
||||
4.C.10
|
Tactic Execution (TA0002) |
|
||||
4.C.12
|
Tactic Execution (TA0002) |
|
||||
10.B.2
|
Tactic Execution (TA0002) |
|
||||
16.B.2
|
Tactic Execution (TA0002) |
|
Procedure
Executed PowerShell payload via the CreateProcessWithToken API
Criteria
hostui.exe executing the CreateProcessWithToken API