[pwnbase.io V.2.1.0_FUI]
| Tactic | MITRE ID | Technique Description | Defense Focus |
|---|---|---|---|
| [Defense Evasion] | T1036.005 | Masquerading: Primarily uses "Living Off the Land" (LotL) techniques with native OS tools (net.exe, wmic.exe) to avoid detection. | PowerShell/CMD Logging, Whitelist monitoring on native tools |
| [Command and Control] | T1071.004 | C2 over HTTP/S: Uses small, fragmented, and non-repeating data packets disguised as legitimate HTTPS traffic to communicate C2. | Deep Packet Inspection (DPI) and Behavioral Network Analysis |
| [Persistence] | T1543.003 | Service Creation: Creates custom system services (e.g., cmd.exe running as a service) to maintain long-term access. | Service Creation Monitoring, Baseline Service Analysis |
[END OF FILE]