Execution
T1059.001 suspicious_powershell: Creates suspicious powershell process
T1059.001 suspicious_process: Spawns a suspicious process
T1106 susp_callbacks: Suspicious usage of some WinAPI with callbacks
T1059.003 suspicious_batch: Suspicious batch
Privilege Escalation
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
Defense Evasion
T1497.001 antivm_firmware: Attempts to detect VM by firmware
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1027.002 packer_enigma: Enigma protector indicators detected
T1027.004 compiles_code: Compiles C# code
T1497 checks_firmware: Attempts to read firmware information (potentially for evasion)
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
Discovery
T1497.001 antivm_firmware: Attempts to detect VM by firmware
T1518 locates_browser: Attempts to identify where browsers are installed
T1497 checks_firmware: Attempts to read firmware information (potentially for evasion)
T1497.001 antivm_queries_computername: Retrieves the computer name
T1082 checks_firmware: Attempts to read firmware information (potentially for evasion)
Other
creates_exe: Creates executable files in the file system
creates_in_windows: Creates files in the Windows directory
codepage: Checks the system code page
executes_dropped_exe: Executes dropped exe files
checktokenmembership: Checks user token with CheckTokenMembership call