BH12108 | Accesses the httpd.conf file. | |
BH12115 | Accesses the operating system's file system table. | |
BH12122 | Accesses the wp-config.php file. | |
BH12153 | Changes file ownership. | |
BH12160 | Changes security permissions of a file or a directory using WMI. | |
BH12161 | Changes security permissions of a file using WMI. | |
BH12174 | Checks file permissions. | |
BH12178 | Accesses the Openbox environment configuration file. | |
BH12194 | Contains references to UNIX/Linux login log files. | |
BH12196 | Copies files to Windows system directories. | |
BH12206 | Creates a virtual file system. | |
BH12217 | Creates new files, folders or registry keys. | |
BH12221 | Deletes a file or a directory using WMI. | |
BH12222 | Deletes a file using WMI. | |
BH12223 | Deletes a file/directory. | |
BH12232 | Deletes an object identifier (OID). | |
BH12237 | Deletes files in Windows system directories. | |
BH12239 | Deletes files in common user, data, or temporary directories. | |
BH12357 | Formats a disk. | |
BH12369 | Imports form fields from file. | |
BH12370 | Imports icon data from another file. | |
BH12374 | Imports security settings from an embedded file. | |
BH12375 | Imports values from .PSD1 file. | |
BH12377 | Imports watermark from file. | |
BH12378 | Includes a file with the compiled script. | |
BH12379 | Includes and installs a file with the compiled script. | |
BH12387 | Installs packages via apt. | |
BH12388 | Installs packages via dpkg. | |
BH12389 | Installs packages via pip. | |
BH12390 | Installs packages via yum. | |
BH12420 | Modifies an object identifier (OID). | |
BH12422 | Modifies file/directory attributes. | |
BH12423 | Modifies file/directory ownership. | |
BH12427 | Modifies the timestamp of a file. | |
BH12449 | Might tamper with volume shadow copies. | |
BH12454 | Mounts a volume inside a backup so that the files on the volume can be browsed. | |
BH12455 | Mounts ISO or VHD disk images. | |
BH12456 | Mounts WIM or VHD disk image files. | |
BH12490 | Removes shadow copies using WMI. | |
BH12498 | Replaces locked operating system files. | |
BH12562 | Sets the 'system file' attribute to files/directories. | |
BH12591 | Tampers with access control lists (DACLs) on files or directories. | |
BH12599 | Tampers with Authenticode signatures. | |
BH12613 | Tampers with command line execution history. | |
BH12624 | Tampers with discretionary access control lists (DACL) on specified files. | |
BH12625 | Tampers with disk quotas on NTFS volumes. | |
BH12666 | Tampers with iSCSI storage. | |
BH12700 | Tampers with NTFS volume behavior. | |
BH12701 | Tampers with object identifiers (OIDs). | |
BH12736 | Tampers with storage tiers. | |
BH12763 | Tampers with volume labels of a disk. | |
BH12765 | Tampers with WIM or VHD disk image files. | |
BH12768 | Tampers with Windows Catalog files. | |
BH12820 | Writes to files in Windows system directories. | |
BH12852 | Erases backup catalog stored on the local computer. | |
BH12853 | Erases system state backups. | |
BH12854 | Erases Volume Shadow copies. | |
BH12855 | Copies the permission bits of a file. | |
BH12856 | Copies the permission bits, last access time, last modification time, and flags of a file. | |
BH12860 | Accesses a shell configuration file. | |
BH12861 | Accesses an Xorg configuration file. | |
BH12862 | Accesses an SSH configuration file. | |
BH12863 | Accesses the Openbox autostart configuration file. | |
BH12864 | Accesses the Fluxbox configuration directory. | |
BH12865 | Accesses the .gnupg/gpg-agent.conf file. | |
BH12866 | Accesses the Herbsluftwm configuration directory. | |
BH12867 | Accesses the Xfce4 configuration directory. | |
BH12868 | Accesses a block device pseudo-file. | |
BH12869 | Accesses data from the proc filesystem. | |
BH12870 | Installs packages via pacman. | |
BH12871 | Installs packages via emerge. | |
BH12880 | Accesses a systemd service file. | |
BH12881 | Accesses the /efi partition. | |
BH12882 | Accesses the /boot directory. | |
BH12884 | Accesses a systemd timer file. | |
BH12885 | Unmounts a filesystem. | |
BH12887 | Accesses the /etc/polkit-1/rules.d directory. | |
BH12902 | Accesses a PAM configuration file. | |
BH12904 | Accesses an external mountpoint. | |
BH12926 | Accesses the /etc/ssl directory. | |
BH12927 | Accesses the Cinnamon configuration directory. | |
BH12928 | Mounts a filesystem. | |
BH12940 | Accesses a systemd socket file. | |
BH12941 | Accesses a systemd device file. | |
BH12942 | Accesses a systemd mount file. | |
BH12943 | Accesses a systemd target file. | |
BH12944 | Accesses a systemd path file. | |
BH12950 | Accesses the /proc/sys directory. | |
BH12961 | Access the /etc/security directory. | |
BH12965 | Copies files/folders between a Docker container and the local filesystem. | |
BH12979 | Accesses the /etc/dbus-1 directory. | |
BH12980 | Accesses the /etc/grub.d directory. | |
BH12981 | Accesses the /etc/firewalld directory. | |
BH12982 | Accesses the /etc/modprobe.d directory. | |
BH12983 | Accesses the /etc/modules-load.d directory | |
BH12984 | Accesses the /etc/resolv.conf file. | |
BH12985 | Accesses the /etc/named.conf file. | |
BH12986 | Accesses the /etc/ld.so.conf file. | |
BH12987 | Accesses the /etc/ld.so.conf.d directory. | |
BH12988 | Accesses the /etc/nftables.conf file. | |
BH12989 | Accesses the /etc/pacman.conf file. | |
BH12990 | Accesses the /etc/mkinitcpio.conf file. | |
BH12991 | Accesses the /etc/apt directory. | |
BH12992 | Accesses the /etc/sudoers file. | |
BH12993 | Accesses the /etc/sudoers.d directory. | |
BH12994 | Accesses the /etc/sudo.conf file. | |
BH12995 | Accesses the /etc/doas.conf file. | |
BH12996 | Accesses the /etc/default directory. | |
BH12997 | Accesses the /dev/random pseudo-file. | |
BH12998 | Accesses the /dev/urandom pseudo-file. | |
BH12999 | Accesses the /dev/zero pseudo-file. | |
BH13000 | Accesses the /dev/null pseudo-file. | |
BH13001 | Accesses the /proc/net directory. | |
BH13002 | Accesses the /proc/self directory. | |
BH13003 | Accesses the /etc/audit directory. | |
BH13004 | Accesses the /run/systemd directory. | |
BH13005 | Accesses the Wayland weston.ini file. | |
BH13006 | Accesses the systemd-boot loader.conf file. | |
BH13009 | Truncates a file. | |
BH13019 | Installs a Ruby gem package. | |
BH13020 | Installs a NodeJS package via npm. | |
BH13021 | Installs a NodeJS package via yarn. | |
BH13022 | Accesses the /etc/conf.d directory. | |
BH13023 | Adds an OpenRC service. | |
BH13024 | Deletes an OpenRC service. | |
BH13029 | Accesses the OpenRC service directory. | |
BH13030 | Accesses the /var/service directory. | |
BH13041 | Accesses an OpenLDAP server configuration. | |
BH13042 | Accesses an OpenLDAP client configuration. | |
BH13043 | Accesses the /etc/krb5.conf file. | |
BH13050 | Accesses the /sys/firmware directory. | |
BH13051 | Accesses the Kafka server configuration. | |
BH13053 | Accesses the /etc/supervisor/conf.d directory. | |
BH13054 | Accesses the /etc/supervisor/supervisord.conf file. | |
BH13055 | Accesses the /etc/skel directory. | |
BH13056 | Accesses the /etc/incron.d directory. | |
BH13057 | Accesses the /etc/incron.conf file. | |
BH13058 | Accesses a .git directory. | |
BH13059 | Accesses a .svn directory. | |
BH13066 | Accesses the /etc/environment.d directory. | |
BH13067 | Accesses /etc/exports. | |
BH13068 | Accesses the /etc/lxc/default.conf file. | |
BH13069 | Accesses the /etc/lxc/lxc-usernet file. | |
BH13119 | Accesses OfflineIMAP configuration file. | |
BH13120 | Accesses the KDE daemon configuration file. | |
BH13121 | Accesses the KDE desktop session configuration file. | |
BH13123 | Accesses the i3wm configuration. | |
BH13124 | Accesses the Sway configuration. | |
BH13125 | Accesses the bspwm configuration. | |
BH13128 | Deletes a file/directory using reflection. | |
BH13129 | Modifies file/directory permissions using reflection. | |
BH13149 | Modifies file/directory attributes using reflection. | |
BH13150 | Changes file ownership using reflection. | |
BH13151 | Changes group ownership of a file or directory using reflection. | |
BH13153 | Sets the 'system file' attribute to files/directories using reflection. | |
BH13173 | Creates a virtual sysfs attribute file for a device. | |
BH13174 | Removes a virtual sysfs attribute file from a device. | |
BH13179 | Creates a virtual sysfs attribute file for a device driver. | |
BH13180 | Removes a virtual sysfs attribute file from a device driver. | |
BH13194 | Modifies a shell configuration file. | |
BH13219 | Uses Linux kernel APIs for access to the virtual filesystem. | |
BH13220 | Uses Linux kernel APIs for access to the debugfs filesystem. | |
BH13221 | Uses Linux kernel APIs for access to the sysfs filesystem. | |
BH13222 | Uses Linux kernel APIs for access to the procfs filesystem. | |
BH13247 | Serializes data into the standard URL-encoded notation. | |
BH13248 | Serializes data into the JSON format. | |
BH13292 | Serializes data into the XML format. | |
BH15146 | Encrypts a file. | |
BH15148 | Encrypts files using cipher tool. | |
BH15151 | Encrypts or encodes data in memory using the Windows Cryptography API. | |
BH15152 | Encrypts or encodes files and other data using the Windows Cryptography API. | |
BH15187 | Encodes data using the Base32 algorithm. | |
BH15189 | Encodes data using the Base16 algorithm. | |
BH15190 | Decodes data using the Base16 algorithm. | |
BH15191 | Encodes data using the Ascii85 algorithm. | |
BH15192 | Decodes data using the Ascii85 algorithm. | |
BH15193 | Encodes data using the Base85 algorithm. | |
BH15194 | Decodes data using the Base85 algorithm. | |
BH15199 | Encodes data using the BinHex4 algorithm. | |
BH15200 | Decodes data using the BinHex4 algorithm. | |
BH15210 | Decrypts encrypted data with openssl. | |
BH15211 | Encrypts data with openssl. | |
BH15212 | Encrypts data with gpg. | |
BH15213 | Decrypts data with gpg. | |
BH15214 | Decompresses a Zip archive. | |
BH15215 | Decompresses a Rar archive. | |
BH15216 | Decompresses a Tar archive. | |
BH15229 | Encodes data using the Base64 algorithm using reflection. | |
BH15230 | Decodes data using the Base64 algorithm using reflection. | |
BH15231 | Creates/Opens a Zip archive for writing. | |
BH15232 | Adds files to a Zip archive. | |
BH15233 | Writes compressed data to a Zip archive. | |
BH15237 | Calculates the MD5 hash of data. | |
BH15238 | Calculates the SHA-1 hash of data. | |
BH15239 | Calculates the SHA-256 hash of data. | |
BH15240 | Calculates the MD4 hash of data. | |
BH15241 | Calculates the RIPEMD160 hash of data. | |
BH15242 | Calculates the SHA-224 hash of data. | |
BH15243 | Calculates the SHA-3 hash of data. | |
BH15244 | Calculates the SHA-384 hash of data. | |
BH15245 | Calculates the SHA-512 hash of data. | |
BH15246 | Calculates the SM3 hash of data. | |
BH15247 | Calculates the BLAKE-2 hash of data. | |
BH15248 | Calculates the SHAKE-128 hash of data. | |
BH15249 | Calculates the SHAKE-256 hash of data. | |
BH15250 | Calculates the WHIRLPOOL hash of data. | |
BH15287 | Calculates the MD5 hash of data and encodes it using the Base64 algorithm. | |
BH15288 | Calculates the RIPEMD160 hash of data and encodes it using the Base64 algorithm. | |
BH15289 | Calculates the SHA-1 hash of data and encodes it using the Base64 algorithm. | |
BH15290 | Calculates the SHA-256 hash of data and encodes it using the Base64 algorithm. | |
BH15291 | Calculates the SHA-384 hash of data and encodes it using the Base64 algorithm. | |
BH15292 | Calculates the SHA-512 hash of data and encodes it using the Base64 algorithm. | |
BH15293 | Encodes data using the Bubble Babble algorithm. | |
BH15298 | Calculates a cryptographic hash of data and encodes it using the Base64 algorithm. | |
BH15299 | Creates a cryptographic hash of file contents. | |
BH15301 | Calculates the SHA-512/224 hash of data. | |
BH15302 | Calculates the SHA-512/256 hash of data. | |
BH15313 | Encodes data using the ASN.1 DER encoding. | |
BH15314 | Decodes data using the ASN.1 DER encoding. | |
BH15315 | Encodes data using the PEM encoding. | |
BH15316 | Decodes data using the PEM encoding. | |
BH17101 | Accesses /etc/environment file. | |
BH17102 | Accesses /etc/group file. | |
BH17103 | Accesses /etc/gshadow file. | |
BH17104 | Accesses /etc/init.d directory. | |
BH17105 | Accesses /etc/login.defs file. | |
BH17106 | Accesses /etc/network/interfaces file. | |
BH17107 | Accesses /etc/networks file. | |
BH17108 | Accesses /etc/pam.d/chpasswd file. | |
BH17109 | Accesses /etc/passwd file. | |
BH17110 | Accesses /etc/rc.d directory. | |
BH17112 | Accesses /etc/shells file. | |
BH17113 | Accesses /etc/subgid file. | |
BH17114 | Accesses /etc/subuid file. | |
BH17115 | Accesses /etc/usertty file. | |
BH17116 | Accesses rc.local file. | |
BH17146 | Modifies Bitcoin wallet files. | |
BH17147 | Accesses Bitcoin wallet files. | |
BH17237 | Writes data to AIM user account settings. | |
BH17238 | Writes data to Chrome certificate databases. | |
BH17239 | Writes data to Chrome cookie databases. | |
BH17240 | Writes data to Chrome navigation history databases. | |
BH17241 | Writes data to Chrome session databases. | |
BH17242 | Writes data to Chrome stored credentials databases. | |
BH17243 | Writes data to Chromium certificate databases. | |
BH17244 | Writes data to Chromium cookie databases. | |
BH17245 | Writes data to Chromium navigation history databases. | |
BH17246 | Writes data to Chromium preferences databases. | |
BH17247 | Writes data to Chromium session databases. | |
BH17248 | Writes data to Chromium stored credentials databases. | |
BH17249 | Writes data to Firefox add-on databases. | |
BH17250 | Writes data to Firefox anti-phishing databases. | |
BH17251 | Writes data to Firefox certificate databases. | |
BH17252 | Writes data to Firefox cookie databases. | |
BH17253 | Writes data to Firefox MIME plugin/configuration databases. | |
BH17254 | Writes data to Firefox navigation history databases. | |
BH17255 | Writes data to Firefox preferences databases. | |
BH17256 | Writes data to Firefox saved form data databases. | |
BH17257 | Writes data to Firefox security module database. | |
BH17258 | Writes data to Firefox session databases. | |
BH17259 | Writes data to Firefox stored credentials databases. | |
BH17260 | Writes data to iChat user account settings. | |
BH17261 | Writes data to Internet Explorer cookie databases. | |
BH17262 | Writes data to Internet Explorer navigation history databases. | |
BH17263 | Writes data to Internet Explorer preferences databases. | |
BH17264 | Writes data to Netscape add-on databases. | |
BH17265 | Writes data to Netscape certificate databases. | |
BH17266 | Writes data to Netscape contact/address book. | |
BH17267 | Writes data to Netscape cookie databases. | |
BH17268 | Writes data to Netscape integrated instant messaging databases. | |
BH17269 | Writes data to Netscape mailbox files. | |
BH17270 | Writes data to Netscape MIME plugin/configuration databases. | |
BH17271 | Writes data to Netscape navigation history databases. | |
BH17272 | Writes data to Netscape preferences databases. | |
BH17273 | Writes data to Netscape saved form data databases. | |
BH17274 | Writes data to Netscape security module database. | |
BH17275 | Writes data to Netscape stored credentials databases. | |
BH17276 | Writes data to Opera cookie databases. | |
BH17277 | Writes data to Opera navigation history databases. | |
BH17278 | Writes data to Opera preferences databases. | |
BH17279 | Writes data to Opera stored credentials databases. | |
BH17280 | Writes data to Outlook email/contact backups. | |
BH17281 | Writes data to Outlook mailbox files. | |
BH17282 | Writes data to Outlook offline/cached items. | |
BH17283 | Writes data to Pidgin stored credentials. | |
BH17284 | Writes data to Safari cookie databases. | |
BH17285 | Writes data to Safari navigation history databases. | |
BH17286 | Writes data to Safari session databases. | |
BH17287 | Writes data to Skype chat history database. | |
BH17288 | Writes data to Skype stored credentials. | |
BH17289 | Writes data to Thunderbird certificate database. | |
BH17290 | Writes data to Thunderbird cookie files. | |
BH17291 | Writes data to Thunderbird download history database. | |
BH17292 | Writes data to Thunderbird extension database. | |
BH17293 | Writes data to Thunderbird mailbox files. | |
BH17294 | Writes data to Thunderbird stored credentials. | |
BH17295 | Writes data to Windows Mail stored credentials. | |
BH17296 | Modifies log files. | |
BH17297 | Modifies SSH key files. | |
BH17298 | Modifies user login log files. | |
BH17307 | Accesses user login log files. | |
BH17362 | Writes data to the Chrome local state file which contains the encryption key for local databases. | |
BH17364 | Writes data to the Chromium local state file which contains the encryption key for local databases. | |
BH17366 | Writes data to the Opera local state file which contains the encryption key for local databases. | |
BH17368 | Writes data to the Vivaldi browser's local state file which contains the encryption key for local databases. | |
BH17370 | Writes data to the Yandex browser's local state file which contains the encryption key for local databases. | |
BH17373 | Writes data to Vivaldi browser's stored credentials databases. | |
BH17376 | Writes data to Yandex browser's stored credentials databases. | |
BH17379 | Writes data to the Firefox profiles.ini file which contains information about profiles and the path to the directory with local databases. | |
BH17381 | Writes data to the Microsoft Edge local state file which contains the encryption key for local databases. | |
BH17383 | Writes data to Microsoft Edge stored credentials databases. | |
BH17386 | Writes data to Safari stored credentials databases. | |
BH17388 | Writes data to the SeaMonkey browser's profiles.ini file which contains information about profiles and the path to the directory with local databases. | |
BH17390 | Writes data to SeaMonkey browser's stored credentials databases. | |
BH17393 | Writes data to the Waterfox browser's profiles.ini file which contains information about profiles and the path to the directory with local databases. | |
BH17395 | Writes data to Waterfox browser's stored credentials databases. | |
BH17398 | Writes data to the Brave browser's local state file which contains the encryption key for local databases. | |
BH17400 | Writes data to Brave browser's stored credentials databases. | |
BH17405 | Writes data to files containing encrypted Windows Data Protection API master keys. | |
BH17407 | Writes data to files containing encrypted credentials from the Windows Credential Manager. | |
BH17415 | Writes data to files containing SSL certificates installed on the system. | |
BH17428 | Writes data to Eudora stored credentials. | |
BH17430 | Writes data to GroupMail stored credentials. | |
BH18244 | Accesses the /etc/selinux/config file. | |
BH18246 | Accesses the /etc/apparmor directory. | |
BH19148 | Enumerates default folder locations. | |
BH19173 | Enumerates file systems. | |
BH19182 | Enumerates index path. | |
BH19357 | Gets information about .pfx certificate files on the computer. | |
BH19360 | Gets information about document file. | |
BH19362 | Gets information about the Authenticode signature for a file. | |
BH19366 | Gets information about volumes that BitLocker can protect. | |
BH19473 | Accesses the /etc/lsb-release file. | |
BH19474 | Accesses the /proc/cpuinfo pseudo-file. | |
BH19475 | Accesses the /proc/kmsg pseudo-file. | |
BH20178 | Uses PowerSploit/Empire command to convert objects into a series of comma-separated (CSV) strings and save the strings in a CSV file. | |
BH20179 | Uses PowerSploit/Empire command to copy a file from an NTFS partitioned volume by reading the raw volume and parsing the NTFS structures. | |
BH20183 | Uses PowerSploit/Empire command to create a new volume shadow copy. | |
BH20189 | Uses PowerSploit/Empire command to encrypt text file or script. | |
BH20242 | Uses PowerSploit/Empire command to mount a volume shadow copy. | |
BH20246 | Uses PowerSploit/Empire command to patch in the specified command to a pre-compiled C# service executable and write the binary out. | |
BH20254 | Uses PowerSploit/Empire command to remove a volume shadow copy. | |
BH20259 | Uses PowerSploit/Empire command to restore a service binary backed up by Install-ServiceBinary. | |
BH20311 | Uses PowerSploit/Empire command to set the binary path for a service to a specified value. | |