Execution
T1204 suspicious_lnk: LNK file with suspicious content
T1059.001 url_cmdline: Cmdline of process contains URL
T1059.003 url_cmdline: Cmdline of process contains URL
Persistence
T1197 bitsadmin_download: Downloads a file using bitsadmin and tries to run
Privilege Escalation
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
Defense Evasion
T1197 bitsadmin_download: Downloads a file using bitsadmin and tries to run
T1218.011 lolbin_advpack_launchinfsection: Executes .wsh/.sct script by calling the LaunchINFSection function from advpack.dll
T1562.001 browser_security: Modifies browser security settings
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
Credential Access
T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files
Discovery
T1082 fingerprint_to_file: Collects data about system and user and writes it to a text file
T1012 infostealer_typedurls: Collects information about the URLs typed in the browser
Other
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object
test_check_service: Starts services
yara_rules: Static rules