Persistence T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
Privilege Escalation T1547.001 persistence_autorun: Makes itself run automatically on Windows startup
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
Defense Evasion T1564.001 stealth_file: Creates hidden or system files
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
Other networkdyndns_checkip: Connects to a Dynamic DNS domain
creates_in_programdata: Creates files in the ProgramData directory
suricata_alert: Malicious traffic detected