Pretnje
3 direktna pogotka-
№ 011
Fileless malware … It hangs its execution on scheduled tasks and the Windows registry — again with no conspicuous file. A restart clears it from memory, but persistence techniques …pretnja · malware
-
№ 022
Kerberoasting Kerberoasting is an attack specific to Windows domain networks and Active Directory (AD). User logins are handled by the Kerberos protocol, which issues tickets …pretnja · identity
-
№ 023
Pass-the-Hash … t it does not keep the password in readable form, Windows remembers its cryptographic fingerprint — the hash. With older Windows authentication (NTLM), the pass …pretnja · identity
Tehnike
5 direktnih pogodaka-
№ 020
Access Token Manipulation Token abuse involves stealing or manipulating authentication tokens, session cookies, or access keys to assume the identity of a legitimate user or service. The attacker can use a token without knowing the password.tehnika · privileges
-
№ 016
DLL Sideloading Exploits the DLL search order in the Windows operating system.tehnika · execution
-
№ 015
Living off the Land … l, certutil, mshta, regsvr32, rundll32, and other Windows tools.tehnika · execution
-
№ 029
Domain Account Discovery Uses LDAP queries, BloodHound, or standard Windows commands.tehnika · discovery
-
№ 043
Log Tampering Targets Windows Event Log, syslog, web server logs, and SIEM sources.tehnika · evasion