Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business
Discovery | RMM Tools | Defense Evasion | Credential Theft | OffSec | Networking | LOLBAS | Exfiltration |
---|---|---|---|---|---|---|---|
Advanced IP Scanner
Navicat
PDQ Inventory
RoboCopy
SoftPerfect NetScan
|
AnyDesk
Atera
eHorus
HCL BigFix
N-Able
PDQ Deploy
ScreenConnect
SimpleHelp
Splashtop
|
EDRSandBlast
KillAV
ThrottleStop driver
|
Mimikatz
|
|
Cloudflared
FRP
Ligolo
PuTTY
RevSocks
|
BITSAdmin
Process Explorer
PsExec
|
RClone
|
Vendor | Product | CVE | Source |
---|---|---|---|
SimpleHelp | SimpleHelp RMM | CVE-2024-57727 | arcticwolf.com |
Initial Access | Execution | Defense Evasion | Credential Access | Discovery | Lateral Movement | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|
Valid Accounts | Command and Scripting Interpreter | Impair Defenses | Brute Force | File and Directory Discovery | Remote Services | Ingress Tool Transfer | Exfiltration Over C2 Channel | Inhibit System Recovery |
Phishing | Windows Management Instrumentation | Disable or Modify Tools | Network Share Discovery | Exfiltration Over Web Service | Service Stop | |||
External Remote Services | Safe Mode Boot | Exfiltration Over Alternative Protocol | Data Encrypted for Impact |
No negotiation chats available.