Execution
T1204 suspicious_lnk: LNK file with suspicious content
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1059.003 suspicious_cmd_process: Cmd.exe without commandline launches a new process
T1059.003 suspicious_cmd: Executes cmd.exe with a suspicious command line
T1059.003 suspicious_cmd_process_2: Cmd.exe performs suspicious activity (stdout)
Persistence
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
Privilege Escalation
T1053.005 persistence_autorun: Makes itself run automatically on Windows startup
T1053.005 creates_tasks: Creates a delayed task using Task Scheduler
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
Defense Evasion
T1027 suspicious_cmd: Executes cmd.exe with a suspicious command line
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
Other
yara_rules: Static rules
unexpected_exception: Unexpected exception
no_graphical_activity: No graphic activity
creates_suspended_process: Creates suspended process
get_policy_info: Retrieves information about a Policy object