ATT&CKSoftwarePowerSploit

PowerSploit

S0194

Tool.View on attack.mitre.org

About this tool

PowerSploit is an open source, offensive security framework comprised of PowerShell modules and scripts that perform a wide range of tasks related to penetration testing such as code execution, persistence, bypassing anti-virus, recon, and exfiltration.

Techniques used28

Procedure examples28

TechniqueProcedure example
T1003.001
LSASS Memory

PowerSploit contains a collection of Exfiltration modules that can harvest credentials using Mimikatz.

T1005
Data from Local System

PowerSploit contains a collection of Exfiltration modules that can access data from local files, volumes, and processes.

T1012
Query Registry

PowerSploit contains a collection of Privesc-PowerUp modules that can query Registry keys for potential opportunities.

T1027.005
Indicator Removal from Tools

PowerSploit's Find-AVSignature AntivirusBypass module can be used to locate single byte anti-virus signatures.

T1027.010
Command Obfuscation

PowerSploit contains a collection of ScriptModification modules that compress and encode scripts and payloads.

T1047
Windows Management Instrumentation

PowerSploit's Invoke-WmiCommand CodeExecution module uses WMI to execute and retrieve the output from a PowerShell payload.

T1053.005
Scheduled Task

PowerSploit's New-UserPersistenceOption Persistence argument can be used to establish via a Scheduled Task/Job.

T1055.001
Dynamic-link Library Injection

PowerSploit contains a collection of CodeExecution modules that inject code (DLL, shellcode) into a process.

T1056.001
Keylogging

PowerSploit's Get-Keystrokes Exfiltration module can log keystrokes.

T1057
Process Discovery

PowerSploit's Get-ProcessTokenPrivilege Privesc-PowerUp module can enumerate privileges for a given process.

T1059.001
PowerShell

PowerSploit modules are written in and executed via PowerShell.

T1087.001
Local Account

PowerSploit's Get-ProcessTokenGroup Privesc-PowerUp module can enumerate all SIDs associated with its current token.

T1113
Screen Capture

PowerSploit's Get-TimedScreenshot Exfiltration module can take screenshots at regular intervals.

T1123
Audio Capture

PowerSploit's Get-MicrophoneAudio Exfiltration module can record system microphone audio.

T1134
Access Token Manipulation

PowerSploit's Invoke-TokenManipulation Exfiltration module can be used to manipulate tokens.

View all 28 procedure examples

Groups that use it9

Campaigns2

References3

  1. GitHub PowerSploit May 2012 Open source
    PowerShellMafia. (2012, May 26). PowerSploit - A PowerShell Post-Exploitation Framework. Retrieved February 6, 2018.
  2. PowerShellMagazine PowerSploit July 2014 Open source
    Graeber, M. (2014, July 8). PowerSploit. Retrieved February 6, 2018.
  3. PowerSploit Documentation Open source
    PowerSploit. (n.d.). PowerSploit. Retrieved February 6, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.