Execution
T1047 has_wmi: Executes one or several WMI requests
Persistence
T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key
T1574 dropper_dll: Creates DLL, which is then loaded into the process
Privilege Escalation
T1574.011 persistence_services: Modifies Services registry key
T1543.003 persistence_services: Modifies Services registry key
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
Defense Evasion
T1562.001 disables_security: Disables Windows Security options
T1562.001 stops_security_center: Stops Security Center
T1562.001 disables_windowsupdate: Disables Windows Auto Updates
T1574.011 persistence_services: Modifies Services registry key
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1574 dropper_dll: Creates DLL, which is then loaded into the process
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1027.002 nsis_archive: One of the packages is NSIS archive
T1070 stealth_window: A process created a hidden window
Credential Access
T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files
Discovery
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1518 locates_browser: Attempts to identify where browsers are installed
Impact
T1490 vssadmin_delete_shadows: Attempt to delete volume shadow copies
T1489 stops_service: Stops Windows services
T1489 stops_security_center: Stops Security Center
T1490 wbadmin_delete_backup: Removes system backup copies using wbadmin utility
T1489 net_stop: Stops services through the use of net stop
Other
ransomware_shadowcopy: Removes volume shadow copies
ransomware_bcdedit: Runs bcdedit commands specific to ransomware
require_administrator: Requests administrator privileges
creates_exe: Creates executable files in the file system
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
checktokenmembership: Checks user token with CheckTokenMembership call
pe_overlay: PE file contains overlay
executes_dropped_exe: Executes dropped exe files
yara_rules: Static rules