Advisor

Execution 17 articles

01
Cloud Function Execution Abuse
Overview Cloud Function Execution Abuse involves adversaries leveraging cloud-based serverless functions to execute malicious code or commands within a target environment. This technique plays a critical role in various stages…
02
Command-Line Interface Execution
Overview Command-Line Interface (CLI) Execution is a technique used by adversaries to run commands or scripts directly on a target system through a command-line environment. It plays a critical role…
03
Container Runtime Execution
Overview Container Runtime Execution refers to the technique where adversaries leverage container runtimes to execute malicious code within containerized environments. This technique plays a critical role in the Execution phase…
04
DLL Execution via Load Order Hijacking
Overview DLL Execution via Load Order Hijacking is a technique where adversaries exploit the order in which Windows operating systems load Dynamic Link Libraries (DLLs) to execute malicious code. This…
05
Dynamic Code Execution in Memory
Overview Dynamic Code Execution in Memory is a technique used by adversaries to run code directly within a system’s memory without writing it to disk. This approach facilitates stealthy execution,…
06
Installer Package Execution
Overview Installer Package Execution is a technique where adversaries leverage legitimate software installation packages to execute malicious code on a target system. This method plays a critical role in multiple…
07
Living-off-the-Land Binary (LOLBins) Execution
Overview Living-off-the-Land Binary (LOLBins) Execution is a technique where adversaries leverage legitimate, pre-installed system binaries and scripts to carry out malicious activities. This approach enables attackers to execute code, escalate…
08
Macro-Based Execution
Overview Macro-Based Execution is a technique where adversaries leverage macros—scripts embedded within documents—to execute malicious code on a target system. Commonly used during the initial access and execution phases, this…
09
MSHTA and HTML Application Execution
Overview MSHTA is a Windows utility that executes HTML Applications (HTA), which are HTML files with embedded scripts capable of running with system-level permissions. Adversaries leverage MSHTA to execute malicious…
10
Office Application Exploitation
Overview Office Application Exploitation involves adversaries leveraging vulnerabilities or features within office productivity software to execute malicious code or gain unauthorized access. This technique is commonly used during various stages…
11
PowerShell-Based Execution
Overview PowerShell-Based Execution is a technique where adversaries leverage the Windows PowerShell scripting environment to execute malicious code or commands. This method plays a critical role in the attack lifecycle…
12
Scheduled Task Execution
Overview Scheduled Task Execution is a technique used by adversaries to run malicious code or commands at predetermined times or intervals. It plays a critical role in maintaining persistence, executing…
13
Scripting Language Abuse
Overview Scripting Language Abuse involves adversaries leveraging legitimate scripting languages to execute malicious actions within a target environment. This technique plays a critical role in multiple stages of the attack…
14
Service-Based Execution
Overview Service-Based Execution is a technique where adversaries leverage operating system services to execute malicious code. This approach allows attackers to run payloads with system or elevated privileges, often blending…
15
Signed Binary Proxy Execution
Overview Signed Binary Proxy Execution is a technique where adversaries leverage digitally signed, trusted binaries to execute malicious code indirectly. This approach allows attackers to bypass security controls by using…
16
User-Initiated Execution
Overview User-Initiated Execution is a technique where adversaries rely on a legitimate user to trigger the execution of malicious code or commands. This approach leverages user actions to bypass automated…
17
Windows Management Instrumentation (WMI) Execution
Overview Windows Management Instrumentation (WMI) Execution is a technique that leverages the WMI infrastructure in Windows operating systems to execute code or commands remotely or locally. It is commonly used…