[pwnbase.io V.2.1.0_FUI]
| Tactic | MITRE ID | Technique Description | Defense Focus |
|---|---|---|---|
| [Credential Access] | T1003 | OS Credential Dumping: Used tools like Mimikatz, NTLM relay, and mined credentials from Chrome/Firefox profile folders. | LSASS Protection, Browser Password Policy |
| [Defense Evasion] | T1070.004 | Indicator Removal: Used anti-forensics techniques including deleting log files and custom tools to avoid EDR. | Off-host log collection, EDR Behavioral Monitoring |
| [Initial Access] | T1078 | Valid Accounts: Gained initial entry through compromised contractor accounts accessing Virtual Desktop Infrastructure (VDI). | MFA on VDI, Strong Vendor Credential Management |
| [Command and Control] | T1573.002 | Encrypted Channel: Established C2 primarily with an RDP client running over port 443, routed through the **TOR network**. | TOR Egress Monitoring, C2 Domain Blocking |
[END OF FILE]