| BH12097 | Reads from or writes to a pipe. | |
| BH12098 | Reads from a pipe. | |
| BH12108 | Accesses the httpd.conf file. | |
| BH12115 | Accesses the operating system's file system table. | |
| BH12122 | Accesses the wp-config.php file. | |
| BH12153 | Changes file ownership. | |
| BH12160 | Changes security permissions of a file or a directory using WMI. | |
| BH12161 | Changes security permissions of a file using WMI. | |
| BH12174 | Checks file permissions. | |
| BH12178 | Accesses the Openbox environment configuration file. | |
| BH12194 | Contains references to UNIX/Linux login log files. | |
| BH12196 | Copies files to Windows system directories. | |
| BH12206 | Creates a virtual file system. | |
| BH12217 | Creates new files, folders or registry keys. | |
| BH12221 | Deletes a file or a directory using WMI. | |
| BH12222 | Deletes a file using WMI. | |
| BH12223 | Deletes a file/directory. | |
| BH12232 | Deletes an object identifier (OID). | |
| BH12237 | Deletes files in Windows system directories. | |
| BH12239 | Deletes files in common user, data, or temporary directories. | |
| BH12357 | Formats a disk. | |
| BH12369 | Imports form fields from file. | |
| BH12370 | Imports icon data from another file. | |
| BH12374 | Imports security settings from an embedded file. | |
| BH12375 | Imports values from .PSD1 file. | |
| BH12377 | Imports watermark from file. | |
| BH12378 | Includes a file with the compiled script. | |
| BH12379 | Includes and installs a file with the compiled script. | |
| BH12387 | Installs packages via apt. | |
| BH12388 | Installs packages via dpkg. | |
| BH12389 | Installs packages via pip. | |
| BH12390 | Installs packages via yum. | |
| BH12420 | Modifies an object identifier (OID). | |
| BH12422 | Modifies file/directory attributes. | |
| BH12423 | Modifies file/directory ownership. | |
| BH12427 | Modifies the timestamp of a file. | |
| BH12449 | Might tamper with volume shadow copies. | |
| BH12454 | Mounts a volume inside a backup so that the files on the volume can be browsed. | |
| BH12455 | Mounts ISO or VHD disk images. | |
| BH12456 | Mounts WIM or VHD disk image files. | |
| BH12490 | Removes shadow copies using WMI. | |
| BH12498 | Replaces locked operating system files. | |
| BH12562 | Sets the 'system file' attribute to files/directories. | |
| BH12591 | Tampers with access control lists (DACLs) on files or directories. | |
| BH12599 | Tampers with Authenticode signatures. | |
| BH12613 | Tampers with command line execution history. | |
| BH12624 | Tampers with discretionary access control lists (DACL) on specified files. | |
| BH12625 | Tampers with disk quotas on NTFS volumes. | |
| BH12666 | Tampers with iSCSI storage. | |
| BH12700 | Tampers with NTFS volume behavior. | |
| BH12701 | Tampers with object identifiers (OIDs). | |
| BH12736 | Tampers with storage tiers. | |
| BH12763 | Tampers with volume labels of a disk. | |
| BH12765 | Tampers with WIM or VHD disk image files. | |
| BH12768 | Tampers with Windows Catalog files. | |
| BH12820 | Writes to files in Windows system directories. | |
| BH12852 | Erases backup catalog stored on the local computer. | |
| BH12853 | Erases system state backups. | |
| BH12854 | Erases Volume Shadow copies. | |
| BH12855 | Copies the permission bits of a file. | |
| BH12856 | Copies the permission bits, last access time, last modification time, and flags of a file. | |
| BH12860 | Accesses a shell configuration file. | |
| BH12861 | Accesses an Xorg configuration file. | |
| BH12862 | Accesses an SSH configuration file. | |
| BH12863 | Accesses the Openbox autostart configuration file. | |
| BH12864 | Accesses the Fluxbox configuration directory. | |
| BH12865 | Accesses the .gnupg/gpg-agent.conf file. | |
| BH12866 | Accesses the Herbsluftwm configuration directory. | |
| BH12867 | Accesses the Xfce4 configuration directory. | |
| BH12868 | Accesses a block device pseudo-file. | |
| BH12869 | Accesses data from the proc filesystem. | |
| BH12870 | Installs packages via pacman. | |
| BH12871 | Installs packages via emerge. | |
| BH12880 | Accesses a systemd service file. | |
| BH12881 | Accesses the /efi partition. | |
| BH12882 | Accesses the /boot directory. | |
| BH12884 | Accesses a systemd timer file. | |
| BH12885 | Unmounts a filesystem. | |
| BH12887 | Accesses the /etc/polkit-1/rules.d directory. | |
| BH12902 | Accesses a PAM configuration file. | |
| BH12904 | Accesses an external mountpoint. | |
| BH12926 | Accesses the /etc/ssl directory. | |
| BH12927 | Accesses the Cinnamon configuration directory. | |
| BH12928 | Mounts a filesystem. | |
| BH12940 | Accesses a systemd socket file. | |
| BH12941 | Accesses a systemd device file. | |
| BH12942 | Accesses a systemd mount file. | |
| BH12943 | Accesses a systemd target file. | |
| BH12944 | Accesses a systemd path file. | |
| BH12950 | Accesses the /proc/sys directory. | |
| BH12961 | Access the /etc/security directory. | |
| BH12965 | Copies files/folders between a Docker container and the local filesystem. | |
| BH12979 | Accesses the /etc/dbus-1 directory. | |
| BH12980 | Accesses the /etc/grub.d directory. | |
| BH12981 | Accesses the /etc/firewalld directory. | |
| BH12982 | Accesses the /etc/modprobe.d directory. | |
| BH12983 | Accesses the /etc/modules-load.d directory. | |
| BH12984 | Accesses the /etc/resolv.conf file. | |
| BH12985 | Accesses the /etc/named.conf file. | |
| BH12986 | Accesses the /etc/ld.so.conf file. | |
| BH12987 | Accesses the /etc/ld.so.conf.d directory. | |
| BH12988 | Accesses the /etc/nftables.conf file. | |
| BH12989 | Accesses the /etc/pacman.conf file. | |
| BH12990 | Accesses the /etc/mkinitcpio.conf file. | |
| BH12991 | Accesses the /etc/apt directory. | |
| BH12992 | Accesses the /etc/sudoers file. | |
| BH12993 | Accesses the /etc/sudoers.d directory. | |
| BH12994 | Accesses the /etc/sudo.conf file. | |
| BH12995 | Accesses the /etc/doas.conf file. | |
| BH12996 | Accesses the /etc/default directory. | |
| BH12997 | Accesses the /dev/random pseudo-file. | |
| BH12998 | Accesses the /dev/urandom pseudo-file. | |
| BH12999 | Accesses the /dev/zero pseudo-file. | |
| BH13000 | Accesses the /dev/null pseudo-file. | |
| BH13001 | Accesses the /proc/net directory. | |
| BH13002 | Accesses the /proc/self directory. | |
| BH13003 | Accesses the /etc/audit directory. | |
| BH13004 | Accesses the /run/systemd directory. | |
| BH13005 | Accesses the Wayland weston.ini file. | |
| BH13006 | Accesses the systemd-boot loader.conf file. | |
| BH13009 | Truncates a file. | |
| BH13019 | Installs a Ruby gem package. | |
| BH13020 | Installs a NodeJS package via npm. | |
| BH13021 | Installs a NodeJS package via yarn. | |
| BH13022 | Accesses the /etc/conf.d directory. | |
| BH13023 | Adds an OpenRC service. | |
| BH13024 | Deletes an OpenRC service. | |
| BH13029 | Accesses the OpenRC service directory. | |
| BH13030 | Accesses the /var/service directory. | |
| BH13041 | Accesses an OpenLDAP server configuration. | |
| BH13042 | Accesses an OpenLDAP client configuration. | |
| BH13043 | Accesses the /etc/krb5.conf file. | |
| BH13050 | Accesses the /sys/firmware directory. | |
| BH13051 | Accesses the Kafka server configuration. | |
| BH13053 | Accesses the /etc/supervisor/conf.d directory. | |
| BH13054 | Accesses the /etc/supervisor/supervisord.conf file. | |
| BH13055 | Accesses the /etc/skel directory. | |
| BH13056 | Accesses the /etc/incron.d directory. | |
| BH13057 | Accesses the /etc/incron.conf file. | |
| BH13058 | Accesses a .git directory. | |
| BH13059 | Accesses a .svn directory. | |
| BH13066 | Accesses the /etc/environment.d directory. | |
| BH13067 | Accesses /etc/exports. | |
| BH13068 | Accesses the /etc/lxc/default.conf file. | |
| BH13069 | Accesses the /etc/lxc/lxc-usernet file. | |
| BH13119 | Accesses OfflineIMAP configuration file. | |
| BH13120 | Accesses the KDE daemon configuration file. | |
| BH13121 | Accesses the KDE desktop session configuration file. | |
| BH13123 | Accesses the i3wm configuration. | |
| BH13124 | Accesses the Sway configuration. | |
| BH13125 | Accesses the bspwm configuration. | |
| BH13128 | Deletes a file/directory using reflection. | |
| BH13129 | Modifies file/directory permissions using reflection. | |
| BH13149 | Modifies file/directory attributes using reflection. | |
| BH13150 | Changes file ownership using reflection. | |
| BH13151 | Changes group ownership of a file or directory using reflection. | |
| BH13153 | Sets the 'system file' attribute to files/directories using reflection. | |
| BH13173 | Creates a virtual sysfs attribute file for a device. | |
| BH13174 | Removes a virtual sysfs attribute file from a device. | |
| BH13179 | Creates a virtual sysfs attribute file for a device driver. | |
| BH13180 | Removes a virtual sysfs attribute file from a device driver. | |
| BH13194 | Modifies a shell configuration file. | |
| BH13219 | Uses Linux kernel APIs for access to the virtual filesystem. | |
| BH13220 | Uses Linux kernel APIs for access to the debugfs filesystem. | |
| BH13221 | Uses Linux kernel APIs for access to the sysfs filesystem. | |
| BH13222 | Uses Linux kernel APIs for access to the procfs filesystem. | |
| BH13247 | Serializes data into the standard URL-encoded notation. | |
| BH13248 | Serializes data into the JSON format. | |
| BH13292 | Serializes data into the XML format. | |
| BH13312 | Uses methods for manipulating other Pickle files in Pickle-serialized data. | |
| BH13313 | Deletes temporary files. | |
| BH13327 | Creates/Opens a file. | |
| BH13328 | Reads from files. | |
| BH13329 | Writes to files. | |
| BH13335 | Creates/opens files in Windows system directories. | |
| BH13336 | Reads from files in Windows system directories. | |
| BH13337 | Creates/opens files in common user, data or temporary directories. | |
| BH13338 | Reads from files in common user, data, or temporary directories. | |
| BH13339 | Writes to files in common user, data, or temporary directories. | |
| BH13352 | Creates a directory. | |
| BH13353 | Removes a directory. | |
| BH13354 | Writes data to Outlook contact/address book. | |
| BH13369 | Creates symbolic\hard links to files or directories. | |
| BH13370 | Mounts filesystems or other media. | |
| BH13371 | Unmounts filesystems or other media. | |
| BH13372 | Lists directory contents. | |
| BH13373 | Accesses command line execution history. | |
| BH13379 | Renames files. | |
| BH13382 | Empties the Recycle Bin. | |
| BH13385 | Copies, moves, renames, or deletes a file system object. | |
| BH13389 | Creates temporary files. | |
| BH13391 | Copies a file. | |
| BH13392 | Copies files to common user, data, or temporary directories. | |
| BH13401 | Opens a file for reading or writing. | |
| BH13405 | Sets or updates the file pointer position within an open file. | |
| BH13407 | Flushes the file's buffer to disk. | |
| BH13410 | Queries the size of a file. | |
| BH13416 | Queries file attributes. | |
| BH13423 | Changes the current directory. | |
| BH13425 | Queries the timestamp of a file/directory. | |
| BH13426 | Queries version information of a file. | |
| BH13433 | Checks if a file or a directory exists. | |
| BH13434 | Closes a previously open file. | |
| BH13441 | Queries the file type of a file. | |
| BH13442 | Changes the size of a file. | |
| BH13444 | Queries file information. | |
| BH13445 | Changes file information. | |
| BH13453 | Reads a value from a standard format .ini file. | |
| BH13454 | Writes a value to a standard format .ini file. | |
| BH13465 | Changes the current working directory. | |
| BH13466 | Opens a file. | |
| BH13467 | Queries the text encoding used in a file. | |
| BH13468 | Moves a file. | |
| BH13481 | Copies a file/directory. | |
| BH13497 | Creates a symbolic link to a file or directory. | |
| BH13521 | Imports the java.nio.file.Files class, which contains methods for file manipulation. | |
| BH13538 | Exports data to file. | |
| BH13546 | Might cache requests. | |
| BH13555 | Might store data using IndexedDB. | |
| BH13578 | Uses json-related functions. | |
| BH13581 | Renames a file or directory. | |
| BH13800 | Accesses a previously opened file in VS Code. | |
| BH13801 | Saves a file. | |
| BH13820 | Accesses the file system. | |
| BH13826 | Makes changes to files in the workspace. | |
| BH13828 | Accesses the VS Code extension secrets storage. | |
| BH13854 | Copies files during installation or upon launch. | |
| BH13855 | Renames files during installation or upon launch. | |
| BH13856 | Deletes files during installation or upon launch. | |
| BH13857 | Creates shortcuts during installation or upon launch. | |
| BH13858 | Modifies configuration files during installation or upon launch. | |
| BH13859 | Installs packages via Windows Installer. | |
| BH13913 | Monitors a file/directory for changes. | |
| BH13914 | Monitors a file for changes. | |
| BH13950 | Imports the java.io.File class, which contains methods for file manipulation. | |
| BH13951 | Imports the java.io.FileInputStream class, which contains methods for reading from files. | |
| BH13952 | Imports the java.io.FileReader class, which contains methods for reading from files. | |
| BH13953 | Imports the java.io.FileOutputStream class, which contains methods for writing to files. | |
| BH13954 | Imports the java.io.FileWriter class, which contains methods for writing to files. | |
| BH13960 | Imports the java.nio.channels.FileChannel class, which contains methods for reading and writing to files. | |
| BH13965 | Loads a property list into a java.util.Properties object. | |
| BH13966 | Saves a property list represented by a java.util.Properties object. | |
| BH13967 | Opens a Zip archive for reading. | |
| BH13979 | Imports the java.util.jar.JarEntry class, which is used to represent a JAR archive entry. | |
| BH13980 | Imports the java.util.jar.JarFile class, which is used to read the contents of a JAR archive. | |
| BH13983 | Imports the java.util.jar.Manifest class, which is used to parse a manifest file of a JAR archive. | |
| BH13989 | Imports the java.io.RandomAccessFile class, which contains methods for reading and writing to a random access file. | |
| BH15146 | Encrypts a file. | |
| BH15148 | Encrypts files using cipher tool. | |
| BH15151 | Encrypts or encodes data in memory using the Windows Cryptography API. | |
| BH15152 | Encrypts or encodes files and other data using the Windows Cryptography API. | |
| BH15187 | Encodes data using the Base32 algorithm. | |
| BH15189 | Encodes data using the Base16 algorithm. | |
| BH15190 | Decodes data using the Base16 algorithm. | |
| BH15191 | Encodes data using the Ascii85 algorithm. | |
| BH15192 | Decodes data using the Ascii85 algorithm. | |
| BH15193 | Encodes data using the Base85 algorithm. | |
| BH15194 | Decodes data using the Base85 algorithm. | |
| BH15199 | Encodes data using the BinHex4 algorithm. | |
| BH15200 | Decodes data using the BinHex4 algorithm. | |
| BH15210 | Decrypts encrypted data with openssl. | |
| BH15211 | Encrypts data with openssl. | |
| BH15212 | Encrypts data with gpg. | |
| BH15213 | Decrypts data with gpg. | |
| BH15214 | Decompresses a Zip archive. | |
| BH15215 | Decompresses a Rar archive. | |
| BH15216 | Decompresses a Tar archive. | |
| BH15229 | Encodes data using the Base64 algorithm using reflection. | |
| BH15230 | Decodes data using the Base64 algorithm using reflection. | |
| BH15231 | Creates/Opens a Zip archive for writing. | |
| BH15232 | Adds files to a Zip archive. | |
| BH15233 | Writes compressed data to a Zip archive. | |
| BH15237 | Calculates the MD5 hash of data. | |
| BH15238 | Calculates the SHA-1 hash of data. | |
| BH15239 | Calculates the SHA-256 hash of data. | |
| BH15240 | Calculates the MD4 hash of data. | |
| BH15241 | Calculates the RIPEMD160 hash of data. | |
| BH15242 | Calculates the SHA-224 hash of data. | |
| BH15243 | Calculates the SHA-3 hash of data. | |
| BH15244 | Calculates the SHA-384 hash of data. | |
| BH15245 | Calculates the SHA-512 hash of data. | |
| BH15246 | Calculates the SM3 hash of data. | |
| BH15247 | Calculates the BLAKE-2 hash of data. | |
| BH15248 | Calculates the SHAKE-128 hash of data. | |
| BH15249 | Calculates the SHAKE-256 hash of data. | |
| BH15250 | Calculates the WHIRLPOOL hash of data. | |
| BH15287 | Calculates the MD5 hash of data and encodes it using the Base64 algorithm. | |
| BH15288 | Calculates the RIPEMD160 hash of data and encodes it using the Base64 algorithm. | |
| BH15289 | Calculates the SHA-1 hash of data and encodes it using the Base64 algorithm. | |
| BH15290 | Calculates the SHA-256 hash of data and encodes it using the Base64 algorithm. | |
| BH15291 | Calculates the SHA-384 hash of data and encodes it using the Base64 algorithm. | |
| BH15292 | Calculates the SHA-512 hash of data and encodes it using the Base64 algorithm. | |
| BH15293 | Encodes data using the Bubble Babble algorithm. | |
| BH15298 | Calculates a cryptographic hash of data and encodes it using the Base64 algorithm. | |
| BH15299 | Creates a cryptographic hash of file contents. | |
| BH15301 | Calculates the SHA-512/224 hash of data. | |
| BH15302 | Calculates the SHA-512/256 hash of data. | |
| BH15313 | Encodes data using the ASN.1 DER encoding. | |
| BH15314 | Decodes data using the ASN.1 DER encoding. | |
| BH15315 | Encodes data using the PEM encoding. | |
| BH15316 | Decodes data using the PEM encoding. | |
| BH15326 | The file is encrypted or contains an encrypted file. | |
| BH16355 | Might use Web Storage API. | |
| BH17101 | Accesses /etc/environment file. | |
| BH17102 | Accesses /etc/group file. | |
| BH17103 | Accesses /etc/gshadow file. | |
| BH17104 | Accesses /etc/init.d directory. | |
| BH17105 | Accesses /etc/login.defs file. | |
| BH17106 | Accesses /etc/network/interfaces file. | |
| BH17107 | Accesses /etc/networks file. | |
| BH17108 | Accesses /etc/pam.d/chpasswd file. | |
| BH17109 | Accesses /etc/passwd file. | |
| BH17110 | Accesses /etc/rc.d directory. | |
| BH17112 | Accesses /etc/shells file. | |
| BH17113 | Accesses /etc/subgid file. | |
| BH17114 | Accesses /etc/subuid file. | |
| BH17115 | Accesses /etc/usertty file. | |
| BH17116 | Accesses rc.local file. | |
| BH17146 | Modifies Bitcoin wallet files. | |
| BH17147 | Accesses Bitcoin wallet files. | |
| BH17237 | Writes data to AIM user account settings. | |
| BH17238 | Writes data to Chrome certificate databases. | |
| BH17239 | Writes data to Chrome cookie databases. | |
| BH17240 | Writes data to Chrome navigation history databases. | |
| BH17241 | Writes data to Chrome session databases. | |
| BH17242 | Writes data to Chrome stored credentials databases. | |
| BH17243 | Writes data to Chromium certificate databases. | |
| BH17244 | Writes data to Chromium cookie databases. | |
| BH17245 | Writes data to Chromium navigation history databases. | |
| BH17246 | Writes data to Chromium preferences databases. | |
| BH17247 | Writes data to Chromium session databases. | |
| BH17248 | Writes data to Chromium stored credentials databases. | |
| BH17249 | Writes data to Firefox add-on databases. | |
| BH17250 | Writes data to Firefox anti-phishing databases. | |
| BH17251 | Writes data to Firefox certificate databases. | |
| BH17252 | Writes data to Firefox cookie databases. | |
| BH17253 | Writes data to Firefox MIME plugin/configuration databases. | |
| BH17254 | Writes data to Firefox navigation history databases. | |
| BH17255 | Writes data to Firefox preferences databases. | |
| BH17256 | Writes data to Firefox saved form data databases. | |
| BH17257 | Writes data to Firefox security module database. | |
| BH17258 | Writes data to Firefox session databases. | |
| BH17259 | Writes data to Firefox stored credentials databases. | |
| BH17260 | Writes data to iChat user account settings. | |
| BH17261 | Writes data to Internet Explorer cookie databases. | |
| BH17262 | Writes data to Internet Explorer navigation history databases. | |
| BH17263 | Writes data to Internet Explorer preferences databases. | |
| BH17264 | Writes data to Netscape add-on databases. | |
| BH17265 | Writes data to Netscape certificate databases. | |
| BH17266 | Writes data to Netscape contact/address book. | |
| BH17267 | Writes data to Netscape cookie databases. | |
| BH17268 | Writes data to Netscape integrated instant messaging databases. | |
| BH17269 | Writes data to Netscape mailbox files. | |
| BH17270 | Writes data to Netscape MIME plugin/configuration databases. | |
| BH17271 | Writes data to Netscape navigation history databases. | |
| BH17272 | Writes data to Netscape preferences databases. | |
| BH17273 | Writes data to Netscape saved form data databases. | |
| BH17274 | Writes data to Netscape security module database. | |
| BH17275 | Writes data to Netscape stored credentials databases. | |
| BH17276 | Writes data to Opera cookie databases. | |
| BH17277 | Writes data to Opera navigation history databases. | |
| BH17278 | Writes data to Opera preferences databases. | |
| BH17279 | Writes data to Opera stored credentials databases. | |
| BH17280 | Writes data to Outlook email/contact backups. | |
| BH17281 | Writes data to Outlook mailbox files. | |
| BH17282 | Writes data to Outlook offline/cached items. | |
| BH17283 | Writes data to Pidgin stored credentials. | |
| BH17284 | Writes data to Safari cookie databases. | |
| BH17285 | Writes data to Safari navigation history databases. | |
| BH17286 | Writes data to Safari session databases. | |
| BH17287 | Writes data to Skype chat history database. | |
| BH17288 | Writes data to Skype stored credentials. | |
| BH17289 | Writes data to Thunderbird certificate database. | |
| BH17290 | Writes data to Thunderbird cookie files. | |
| BH17291 | Writes data to Thunderbird download history database. | |
| BH17292 | Writes data to Thunderbird extension database. | |
| BH17293 | Writes data to Thunderbird mailbox files. | |
| BH17294 | Writes data to Thunderbird stored credentials. | |
| BH17295 | Writes data to Windows Mail stored credentials. | |
| BH17296 | Modifies log files. | |
| BH17297 | Modifies SSH key files. | |
| BH17298 | Modifies user login log files. | |
| BH17307 | Accesses user login log files. | |
| BH17362 | Writes data to the Chrome local state file which contains the encryption key for local databases. | |
| BH17364 | Writes data to the Chromium local state file which contains the encryption key for local databases. | |
| BH17366 | Writes data to the Opera local state file which contains the encryption key for local databases. | |
| BH17368 | Writes data to the Vivaldi browser's local state file which contains the encryption key for local databases. | |
| BH17370 | Writes data to the Yandex browser's local state file which contains the encryption key for local databases. | |
| BH17373 | Writes data to Vivaldi browser's stored credentials databases. | |
| BH17376 | Writes data to Yandex browser's stored credentials databases. | |
| BH17379 | Writes data to the Firefox profiles.ini file which contains information about profiles and the path to the directory with local databases. | |
| BH17381 | Writes data to the Microsoft Edge local state file which contains the encryption key for local databases. | |
| BH17383 | Writes data to Microsoft Edge stored credentials databases. | |
| BH17386 | Writes data to Safari stored credentials databases. | |
| BH17388 | Writes data to the SeaMonkey browser's profiles.ini file which contains information about profiles and the path to the directory with local databases. | |
| BH17390 | Writes data to SeaMonkey browser's stored credentials databases. | |
| BH17393 | Writes data to the Waterfox browser's profiles.ini file which contains information about profiles and the path to the directory with local databases. | |
| BH17395 | Writes data to Waterfox browser's stored credentials databases. | |
| BH17398 | Writes data to the Brave browser's local state file which contains the encryption key for local databases. | |
| BH17400 | Writes data to Brave browser's stored credentials databases. | |
| BH17405 | Writes data to files containing encrypted Windows Data Protection API master keys. | |
| BH17407 | Writes data to files containing encrypted credentials from the Windows Credential Manager. | |
| BH17415 | Writes data to files containing SSL certificates installed on the system. | |
| BH17428 | Writes data to Eudora stored credentials. | |
| BH17430 | Writes data to GroupMail stored credentials. | |
| BH17437 | Accesses system logs. | |
| BH17445 | Contains references to LevelDB storage paths, commonly used by Chromium-based web browsers and Electron applications. | |
| BH18244 | Accesses the /etc/selinux/config file. | |
| BH18246 | Accesses the /etc/apparmor directory. | |
| BH19148 | Enumerates default folder locations. | |
| BH19173 | Enumerates file systems. | |
| BH19182 | Enumerates index path. | |
| BH19357 | Gets information about .pfx certificate files on the computer. | |
| BH19360 | Gets information about document file. | |
| BH19362 | Gets information about the Authenticode signature for a file. | |
| BH19366 | Gets information about volumes that BitLocker can protect. | |
| BH19473 | Accesses the /etc/lsb-release file. | |
| BH19474 | Accesses the /proc/cpuinfo pseudo-file. | |
| BH19475 | Accesses the /proc/kmsg pseudo-file. | |
| BH19567 | Might enumerate available storage. | |
| BH20178 | Uses PowerSploit/Empire command to convert objects into a series of comma-separated (CSV) strings and save the strings in a CSV file. | |
| BH20179 | Uses PowerSploit/Empire command to copy a file from an NTFS partitioned volume by reading the raw volume and parsing the NTFS structures. | |
| BH20183 | Uses PowerSploit/Empire command to create a new volume shadow copy. | |
| BH20189 | Uses PowerSploit/Empire command to encrypt text file or script. | |
| BH20242 | Uses PowerSploit/Empire command to mount a volume shadow copy. | |
| BH20246 | Uses PowerSploit/Empire command to patch in the specified command to a pre-compiled C# service executable and write the binary out. | |
| BH20254 | Uses PowerSploit/Empire command to remove a volume shadow copy. | |
| BH20259 | Uses PowerSploit/Empire command to restore a service binary backed up by Install-ServiceBinary. | |
| BH20311 | Uses PowerSploit/Empire command to set the binary path for a service to a specified value. | |