| Brute Force Attack | file-delete ↳ dell-file-operations-2
file-read ↳ dell-file-operations-1 ↳ dell-file-operations-4
file-write ↳ dell-file-operations-3 ↳ json-dell-file-operations
remote-access ↳ dell-file-remote-access
| T1078 - Valid Accounts
| |
| Compromised Credentials | file-delete ↳ dell-file-operations-2
file-read ↳ dell-file-operations-1 ↳ dell-file-operations-4
file-write ↳ dell-file-operations-3 ↳ json-dell-file-operations
remote-access ↳ dell-file-remote-access
| T1003.003 - T1003.003 T1021 - Remote Services T1078 - Valid Accounts T1083 - File and Directory Discovery
| |
| Data Access | file-delete ↳ dell-file-operations-2
file-read ↳ dell-file-operations-1 ↳ dell-file-operations-4
file-write ↳ dell-file-operations-3 ↳ json-dell-file-operations
remote-access ↳ dell-file-remote-access
| T1083 - File and Directory Discovery
| |
| Data Exfiltration | file-delete ↳ dell-file-operations-2
file-read ↳ dell-file-operations-1 ↳ dell-file-operations-4
file-write ↳ dell-file-operations-3 ↳ json-dell-file-operations
remote-access ↳ dell-file-remote-access
| T1204 - User Execution
| |
| Lateral Movement | file-delete ↳ dell-file-operations-2
file-read ↳ dell-file-operations-1 ↳ dell-file-operations-4
file-write ↳ dell-file-operations-3 ↳ json-dell-file-operations
remote-access ↳ dell-file-remote-access
| T1018 - Remote System Discovery T1021 - Remote Services T1078 - Valid Accounts T1550 - Use Alternate Authentication Material T1550.002 - Use Alternate Authentication Material: Pass the Hash T1558.003 - Steal or Forge Kerberos Tickets: Kerberoasting
| |
| Malware | file-delete ↳ dell-file-operations-2
file-read ↳ dell-file-operations-1 ↳ dell-file-operations-4
file-write ↳ dell-file-operations-3 ↳ json-dell-file-operations
remote-access ↳ dell-file-remote-access
| T1003.002 - T1003.002 T1027 - Obfuscated Files or Information T1085 - Signed Binary Proxy Execution: Rundll32 T1204 - User Execution
| |
| Privilege Abuse | file-delete ↳ dell-file-operations-2
file-read ↳ dell-file-operations-1 ↳ dell-file-operations-4
file-write ↳ dell-file-operations-3 ↳ json-dell-file-operations
remote-access ↳ dell-file-remote-access
| T1021 - Remote Services T1078 - Valid Accounts
| |
| Privilege Escalation | file-delete ↳ dell-file-operations-2
file-read ↳ dell-file-operations-1 ↳ dell-file-operations-4
file-write ↳ dell-file-operations-3 ↳ json-dell-file-operations
remote-access ↳ dell-file-remote-access
| T1078 - Valid Accounts
| |
| Privileged Activity | file-delete ↳ dell-file-operations-2
file-read ↳ dell-file-operations-1 ↳ dell-file-operations-4
file-write ↳ dell-file-operations-3 ↳ json-dell-file-operations
remote-access ↳ dell-file-remote-access
| T1021 - Remote Services T1068 - Exploitation for Privilege Escalation T1078 - Valid Accounts
| |