 | Abuse of elevation control mechanisms | |
 | Account discovery across environment | |
 | Adversary-in-the-Middle (AiTM) real-time relay | |
 | Anti-VM / sandbox evasion checks | |
 | Application-layer C2 over web protocols | |
 | AutoIt / script interpreter execution | |
 | Automated credential guessing and credential stuffing | |
 | Backdoor compcheckresult.cgi to deploy web shell | |
 | Black Friday-themed e-commerce phishing | |
 | Browser credential extraction | |
 | Browser data and profile discovery | |
 | Browser information discovery | |
 | Brute-force SSH to expand access to IoT and embedded devices | |
 | Bypass of UAC / elevated execution | |
 | C2 communications over web protocols | |
 | Certificate & DNS-based host discovery | |
 | Cloud account access for persistence/exfiltration | |
 | Collection of local files and application data | |
 | Collection of local system and synced files | |
 | Command/scripting interpreters for tooling and automation | |
 | Cookie and session data capture | |
 | Create/modify systemd service for persistence | |
 | Create/modify Windows service for persistence | |
 | Creation of scheduled tasks for persistence | |
 | Credential harvesting and OS credential dumping | |
 | Credentials extraction from registry (saved sessions) | |
 | Credentials in files (VPN and app config extraction) | |
 | Credential stuffing against edge devices | |
 | Data encryption for impact (ransomware) | |
 | Deletion of installers and artifacts (indicator removal) | |
 | Deployment of remote access frameworks (C2) | |
 | DLL side-loading for stealthy execution | |
 | DNS-based signaling and C2 fallback | |
 | Domain account enumeration | |
 | Domain account usage after compromise | |
 | Download and transfer of payload artifacts | |
 | Download final payload (ingress tool transfer) | |
 | Download of second-stage payloads (Ingress Tool Transfer) | |
 | Drive-by compromise via fake installation page | |
 | Dynamic resolution / domain churn for resilience | |
 | Email credential harvesting / mailbox collection | |
 | Email-delivered REvil malware | |
 | Encrypt data for impact with ransomware | |
 | Encrypted channels (asymmetric) for secure comms | |
 | Encrypted/obfuscated JavaScript on phishing page | |
 | Encrypted tasking channel | |
 | Establish application-layer C2 channels | |
 | Evasion via virtualization/sandbox detection and anti-forensics | |
 | Execute commands via web shell / injected scripts | |
 | Execution of JavaScript downloader | |