Covenant

S1155

Tool.View on attack.mitre.org

About this tool

Covenant is a multi-platform command and control framework written in .NET. While designed for penetration testing and security research, the tool has also been used by threat actors such as HAFNIUM during operations. Covenant functions through a central listener managing multiple deployed "Grunts" that communicate back to the controller.

Techniques used10

Procedure examples10

TechniqueProcedure example
T1047
Windows Management Instrumentation

Covenant can utilize WMI to install new Grunt listeners through XSL files or command one-liners.

T1059.001
PowerShell

Covenant can create PowerShell-based launchers for Grunt installation.

T1059.003
Windows Command Shell

Covenant provides access to a Command Shell in Windows environments for follow-on command execution and tasking.

T1071.001
Web Protocols

Covenant can establish command and control via HTTP.

T1082
System Information Discovery

Covenant implants can gather basic information on infected systems.

T1218.004
InstallUtil

Covenant can create launchers via an InstallUtil XML file to install new Grunt listeners.

T1218.005
Mshta

Covenant can create HTA files to install Grunt listeners.

T1218.010
Regsvr32

Covenant can create SCT files for installation via `Regsvr32` to deploy new Grunt listeners.

T1571
Non-Standard Port

Covenant listeners and controllers can be configured to use non-standard ports.

T1573.002
Asymmetric Cryptography

Covenant can utilize SSL to encrypt command and control traffic.

Groups that use it1

Campaigns0

None recorded.

References2

  1. Github Covenant Open source
    cobbr. (2021, April 21). Covenant. Retrieved September 4, 2024.
  2. Microsoft HAFNIUM March 2020 Open source
    MSTIC. (2021, March 2). HAFNIUM targeting Exchange Servers with 0-day exploits. Retrieved March 3, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.