Malware.View on attack.mitre.org
| Technique | Procedure example |
|---|---|
| T1018 Remote System Discovery |
SHOTPUT has a command to list all servers in the domain, as well as one to locate domain controllers on a domain. |
| T1027 Obfuscated Files or Information |
SHOTPUT is obscured using XOR encoding and appended to a valid GIF file. |
| T1049 System Network Connections Discovery |
|
| T1057 Process Discovery |
SHOTPUT has a command to obtain a process listing. |
| T1083 File and Directory Discovery |
SHOTPUT has a command to obtain a directory listing. |
| T1087.001 Local Account |
SHOTPUT has a command to retrieve information about connected users. |
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.