Home >
Enterprise >
Participants >
ReaQta >
Command and Scripting Interpreter: PowerShell (T1059.001)
|
|
See subtechnique results for:
Carbanak+FIN7 |
||||||
Step | ATT&CK Pattern |
|
||||
2.B.3
|
|
|||||
3.B.3
|
|
|||||
4.B.3
|
|
|||||
6.A.1
|
|
|||||
13.B.3
|
|
|||||
14.A.2
|
|
|||||
14.A.4
|
|
|||||
15.A.4
|
|
|||||
19.B.1
|
|
APT29 |
||||||
Step | ATT&CK Pattern |
|
||||
1.B.2
|
|
|||||
4.A.2
|
|
|||||
9.B.1
|
|
|||||
11.A.12
|
|
|||||
20.A.3
|
|
Procedure
Spawned interactive powershell.exe
Criteria
powershell.exe spawning from cmd.exe
Footnotes
- Though no image was captured, MITRE confirmed that the vendor has the capability to show available telemetry in a separate view.