MONASWIKI

Tradecraft

15 techniques · 10 payloads · 4 playbooks

Detection
T1190FACT

Exploit Public-Facing Application

Initial Access
FACT
WindowsLinuxmacOS
Web AppAPI+1
T1055WORKING

Process Injection

Defense Evasion
WORKING
WindowsLinux
Active DirectoryNetwork
T1078FACT

Valid Accounts

Defense Evasion
FACT
WindowsLinuxmacOSSaaSCloud
Active DirectoryCloud+1
T1110.002FACT

Password Cracking

Credential Access
FACT
WindowsLinux
Active DirectoryWeb App
T1021.002WORKING

SMB/Windows Admin Shares

Lateral Movement
WORKING
Windows
Active DirectoryNetwork
T1059.001FACT

PowerShell

Execution
FACT
Windows
Active DirectoryNetwork
T1082FACT

System Information Discovery

Discovery
FACT
WindowsLinuxmacOSCloud
Active DirectoryNetwork+1
T1136CANDIDATE

Create Account

Persistence
CANDIDATE
WindowsLinuxmacOSCloudSaaS
Active DirectoryCloud
T1558.003FACT

Kerberoasting

Credential Access
FACT
Windows
Active Directory
T1552.001FACT

Credentials In Files

Credential Access
FACT
WindowsLinuxmacOSCloud
Web AppAPI+1
T1566.001CANDIDATE

Spearphishing Attachment

Initial Access
CANDIDATE
WindowsmacOSLinux
Web AppActive Directory
T1098WORKING

Account Manipulation

Persistence
WORKING
WindowsLinuxmacOSCloudSaaS
CloudActive Directory
T1537CANDIDATE

Transfer Data to Cloud Account

Exfiltration
CANDIDATE
Cloud
Cloud
T1210WORKING

Exploitation of Remote Services

Lateral Movement
WORKING
WindowsLinux
Web AppNetwork+1
T1087.002FACT

Domain Account Discovery

Discovery
FACT
Windows
Active Directory