Privilege Escalation
T1134 opens_process_token: Opens the access token associated with a process
Defense Evasion
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
T1134 opens_process_token: Opens the access token associated with a process
Discovery
T1497 evasion_diskenum: Sandbox evasion using enumeration of partitions
Collection
T1074.001 access_recyclebin: Manipulation with recyclebin detected
Impact
T1486 modifies_files2: Cryptolocker indicators detected (500 or more files are modified)
T1486 modifies_files: Cryptolocker indicators detected (renamed 500 or more files)
T1490 disables_system_restore: Disables System Restore
T1486 ransomware_extensions: Ransomware(s) Lockbit indicators detected (specific extension is added to files)
T1490 vssadmin_delete_shadows: Attempt to delete volume shadow copies
Other
lockbit: Detected ransomware Lockbit
ransomware_shadowcopy: Removes volume shadow copies
creates_suspended_process: Creates suspended process
test_check_service: Starts services
writes_data: Writes big amount of data to disk