PowerSploit is an open source, offensive security framework comprised of PowerShell modules and scripts that perform a wide range of tasks related to penetration testing such as code execution, persistence, bypassing anti-virus, recon, and exfiltration.
| Technique | Procedure example |
|---|---|
| T1003.001 LSASS Memory |
PowerSploit contains a collection of Exfiltration modules that can harvest credentials using Mimikatz. |
| T1005 Data from Local System |
PowerSploit contains a collection of Exfiltration modules that can access data from local files, volumes, and processes. |
| T1012 Query Registry |
PowerSploit contains a collection of Privesc-PowerUp modules that can query Registry keys for potential opportunities. |
| T1027.005 Indicator Removal from Tools |
PowerSploit's |
| T1027.010 Command Obfuscation |
PowerSploit contains a collection of ScriptModification modules that compress and encode scripts and payloads. |
| T1047 Windows Management Instrumentation |
PowerSploit's |
| T1053.005 Scheduled Task |
PowerSploit's |
| T1055.001 Dynamic-link Library Injection |
PowerSploit contains a collection of CodeExecution modules that inject code (DLL, shellcode) into a process. |
| T1056.001 Keylogging |
PowerSploit's |
| T1057 Process Discovery |
PowerSploit's |
| T1059.001 PowerShell |
PowerSploit modules are written in and executed via PowerShell. |
| T1087.001 Local Account |
PowerSploit's |
| T1113 Screen Capture |
PowerSploit's |
| T1123 Audio Capture |
PowerSploit's |
| T1134 Access Token Manipulation |
PowerSploit's |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.