TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

Black Hills InfoSec

Click to Enable Content

BHIS · 2016-04-01 · Read original ↗

ATT&CK techniques detected

3 predictions
T1041Exfiltration Over C2 Channel
80%
"click to enable content click to enable content advisory : the techniques and tools referenced within this blog post may be outdated and do not apply to current situations. however, there is still potential for this blog entry to be used as an opportunity to learn and to possibly…"
T1204User Execution
50%
"automatically when the file is opened but powerpoint does not. i have heard and read about hacks to accomplish the same in powerpoint but, in this case, we will simply use custom actions in the presentation to trigger execution of the code when the user clicks inside the slidesho…"
T1204.002Malicious File
39%
"automatically when the file is opened but powerpoint does not. i have heard and read about hacks to accomplish the same in powerpoint but, in this case, we will simply use custom actions in the presentation to trigger execution of the code when the user clicks inside the slidesho…"

Summary

Sally Vandeven // Evading anti-virus scanners has become a bit of a sport around BHIS.  When we do C2 testing for our customers we start with a host on the […]

The post Click to Enable Content appeared first on Black Hills Information Security, Inc..