Attack, investigate, detect, and mitigate, MITRE ATT&CK mapped
Execute and detect obfuscated PowerShell commands used for initial compromise.
Establish and detect persistence through scheduled tasks on Windows systems.
Move laterally using administrative shares and detect the network-level artifacts.
Craft and detect targeted phishing attacks using malicious Office document macros.
Dump credentials from LSASS process memory using multiple techniques and detect the access patterns.
Inject malicious code into legitimate processes using thread hijacking techniques and detect cross-process manipulation.
Simulate a ransomware attack chain including shadow copy deletion, recovery disabling, and mass file encryption.
Establish and detect command-and-control communication using HTTPS beaconing with encoded payloads.
Bypass User Account Control using legitimate Windows auto-elevate mechanisms to gain elevated privileges without triggering a UAC prompt.
Enumerate Active Directory domain accounts using built-in tools and offensive frameworks, and detect the reconnaissance activity.
Clear Windows event logs to cover tracks and detect the anti-forensics activity through log gap analysis and audit events.
Add unauthorized credentials to Azure AD application registrations and service principals to establish persistent cloud access.