ATT&CKReferencesDonut Github

Donut Github

TheWover. (2019, May 9). donut. Retrieved March 25, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples16

TechniqueUsed byProcedure example
T1027.002
Software Packing
ToolDonut

Donut can generate packed code modules.

T1027.013
Encrypted/Encoded File
ToolDonut

Donut can generate encrypted, compressed/encoded, or otherwise obfuscated code modules.

T1027.015
Compression
ToolDonut

Donut can generate encrypted, compressed/encoded, or otherwise obfuscated code modules.

T1055
Process Injection
ToolDonut

Donut includes a subproject DonutTest to inject shellcode into a target process.

T1057
Process Discovery
ToolDonut

Donut includes subprojects that enumerate and identify information about Process Injection candidates.

T1059
Command and Scripting Interpreter
ToolDonut

Donut can generate shellcode outputs that execute via Ruby.

T1059.001
PowerShell
ToolDonut

Donut can generate shellcode outputs that execute via PowerShell.

T1059.005
Visual Basic
ToolDonut

Donut can generate shellcode outputs that execute via VBScript.

T1059.006
Python
ToolDonut

Donut can generate shellcode outputs that execute via Python.

T1059.007
JavaScript
ToolDonut

Donut can generate shellcode outputs that execute via JavaScript or JScript.

T1070
Indicator Removal
ToolDonut

Donut can erase file references to payloads in-memory after being reflectively loaded and executed.

T1071.001
Web Protocols
ToolDonut

Donut can use HTTP to download previously staged shellcode payloads.

T1105
Ingress Tool Transfer
ToolDonut

Donut can download and execute previously staged shellcode payloads.

T1106
Native API
ToolDonut

Donut code modules use various API functions to load and inject code.

T1620
Reflective Code Loading
ToolDonut

Donut can generate code modules that enable in-memory execution of VBScript, JScript, EXE, DLL, and dotNET payloads.

T1685
Disable or Modify Tools
ToolDonut

Donut can patch Antimalware Scan Interface (AMSI), Windows Lockdown Policy (WLDP), as well as exit-related Native API functions to avoid process termination.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.