Skip to main content

Search

IDDescriptionSignificance / Prevalence
BH12103Accesses audit policy information.
BH12105Accesses DNS configuration.
BH12110Accesses list of all installed applications.
BH12175Checks if the current user has full administrator privileges.
BH12176Checks if user has opted in for data collection as part of Customer Experience Improvement Program.
BH12177Checks login names and enumerates number of logged on users.
BH12179Checks user account information.
BH12180Accesses a common web root directory
BH12401Lists configuration files.
BH12402Lists devices available to the system that can be managed by the MSDSM for MPIO.
BH12403Lists hardware IDs in the MSDSM supported hardware list.
BH12404Lists information about network adapters.
BH12472Reads process information.
BH12530Returns a list of available shared secret templates.
BH12531Returns a list of package providers that are connected to Package Management.
BH12536Returns information about PnP devices.
BH12537Returns the configuration for the App-V client.
BH12553Scans for drivers on the system.
BH12694Tampers with network share configuration.
BH12695Tampers with network shares or mounted drives.
BH12705Tampers with Plug and Play (PnP) devices.
BH12729Tampers with start menu.
BH12750Tampers with the program that is hosting Windows PowerShell.
BH12757Tampers with user identity information.
BH12783Tampers with Windows Services.
BH12858Queries the value of an environment variable.
BH12917Gets a gsettings value.
BH12925Accesses the kernel parameters.
BH12967Inspects changes made on a Docker container.
BH13036Accesses a user sv service directory.
BH13046Lists the cached Kerberos tickets.
BH13048Lists all Firejail sandboxes.
BH13223Reads data from the Name Service Switch (NSS) configuration file.
BH13225Reads data from an SSH configuration file.
BH13233Accesses the system's ARP table.
BH13234Reads data from the /etc/host.conf file, which contains configuration information specific to the resolver library.
BH13236Reads data from the hosts file.
BH13237Reads data from the /etc/config/hosts file.
BH13239Reads data from the /etc/config/resolv.conf file.
BH13270Queries the login name of the user.
BH13271Queries the current working directory.
BH13273Executes a WMI (Windows Management Instrumentation) query.
BH13282Queries information about a display monitor.
BH13284Queries the supplemental group IDs of a process.
BH16133Connects to a repository of user information, including public key certificates.
BH16162Checks connections information.
BH18245Queries SELinux policies.
BH19107Enumerates all active NAT sessions.
BH19109Enumerates all devices with synced browsing sessions.
BH19111Enumerates applied updates on local or remote computer.
BH19112Enumerates applied updates using WMI.
BH19115Enumerates available network shares.
BH19116Enumerates available plug-ins.
BH19117Enumerates available Remote Desktop Session Host servers within a domain.
BH19119Enumerates backup storage locations specified as part of a backup policy.
BH19120Enumerates backups for a server from a specified location.
BH19121Enumerates BIOS information using WMI.
BH19122Enumerates boot configuration using WMI.
BH19125Enumerates CA (Customer Address) routes.
BH19128Enumerates capabilities of a specific user on a constrained session configuration.
BH19129Enumerates CD-ROM information using WMI.
BH19130Enumerates certificates associated with RDS roles.
BH19132Enumerates certificates registered in Active Directory Domain Services.
BH19133Enumerates certificates.
BH19136Enumerates connected disk drives.
BH19138Enumerates control panel items.
BH19139Enumerates CPU information of the system.
BH19140Enumerates CPU information using WMI.
BH19143Enumerates current password and logon restrictions.
BH19144Enumerates current platform information.
BH19145Enumerates currently available disk drives.
BH19150Enumerates desktop monitors using WMI.
BH19151Enumerates detailed properties for a PnP device.
BH19152Enumerates device memory addresses using WMI.
BH19156Enumerates disk partitions using WMI.
BH19157Enumerates DNS server IP addresses from the TCP/IP properties on an interface.
BH19158Enumerates downloads.
BH19159Enumerates drives and network shares.
BH19162Enumerates environment variables.
BH19163Enumerates ETW (Event Tracing for Windows) sessions on the system.
BH19164Enumerates event log settings using WMI.
BH19167Enumerates events and event properties from one or more event logs.
BH19168Enumerates events from event logs using WMI.
BH19170Enumerates execution policies for the current session.
BH19171Enumerates existing AutoLogger session configurations.
BH19174Enumerates files and directories using WMI.
BH19175Enumerates files in a given directory.
BH19176Enumerates files that belong to a specified user.
BH19177Enumerates files using WMI.
BH19179Enumerates groups in a repository of user information.
BH19180Enumerates hardware information (printers).
BH19181Enumerates IDs that identify a Windows installation.
BH19184Enumerates information for local Remote Desktop Session Host sessions.
BH19185Enumerates installed applications using WMI.
BH19186Enumerates installed device drivers.
BH19187Enumerates installed devices.
BH19188Enumerates installed ODBC drivers.
BH19189Enumerates installed Windows Store apps.
BH19193Enumerates kernel modules.
BH19194Enumerates key certificates in the Key Protection Service.
BH19196Enumerates links (such as Excel or DDE/OLE links) in a workbook.
BH19197Enumerates local security groups.
BH19198Enumerates local user accounts.
BH19199Enumerates logical disk drives using WMI.
BH19200Enumerates logon sessions using WMI.
BH19203Enumerates members from a local group.
BH19204Enumerates memory chip information using WMI.
BH19206Enumerates motherboard information using WMI.
BH19209Enumerates names of open workbooks.
BH19210Enumerates NAT objects.
BH19219Enumerates network share/resource information.
BH19220Enumerates network shares or mounted drives.
BH19221Enumerates network shares.
BH19223Enumerates ODBC DSNs.
BH19226Enumerates operating system information using WMI.
BH19227Enumerates operating system recovery settings using WMI.
BH19229Enumerates or sets printer name.
BH19231Enumerates package sources that are registered for a package provider.
BH19234Enumerates physical connection ports using WMI.
BH19235Enumerates physical disk drives using WMI.
BH19236Enumerates physical network routes for a virtualized network.
BH19237Enumerates plugins.
BH19238Enumerates policy entries for virtual machines in a virtual network.
BH19239Enumerates PowerShell sessions on local and remote computers.
BH19240Enumerates printer jobs using WMI.
BH19241Enumerates printer names using WMI.
BH19242Enumerates printer settings using WMI.
BH19244Enumerates processes using WMI.
BH19246Enumerates Provider Addresses.
BH19250Enumerates replication groups.
BH19251Enumerates replication network constraints for Storage Replica partnerships.
BH19252Enumerates replication partnerships.
BH19253Enumerates restore points on the local computer.
BH19254Enumerates Resultant Set of Policy (RSoP) information for a remote user and computer.
BH19256Enumerates rules in a Code Integrity policy.
BH19258Enumerates running processes.
BH19259Enumerates running threads within one or more processes.
BH19260Enumerates scheduled jobs on the local computer.
BH19264Enumerates server features on a managed node.
BH19265Enumerates service account credentials for an Active Directory Rights Management Services (AD RMS) cluster.
BH19266Enumerates services on the computer.
BH19267Enumerates services using WMI.
BH19268Enumerates sessions on a Remote Desktop Session Host server.
BH19269Enumerates sessions on the local Remote Desktop Session Host server.
BH19275Enumerates settings of the server service.
BH19276Enumerates shadow copy settings using WMI.
BH19277Enumerates shared resources using WMI.
BH19280Enumerates sound device information using WMI.
BH19281Enumerates startup programs using WMI.
BH19282Enumerates static mappings configured on NAT instances.
BH19283Enumerates static mappings on Windows Container networking adapters.
BH19285Enumerates supported media formats.
BH19286Enumerates system account information using WMI.
BH19287Enumerates system domain information using WMI.
BH19288Enumerates system drivers using WMI.
BH19289Enumerates system drivers.
BH19290Enumerates system environment variables using WMI.
BH19291Enumerates system firmware environment variables and information.
BH19292Enumerates system firmware tables.
BH19293Enumerates system information from SMBIOS using WMI.
BH19294Enumerates system information using WMI.
BH19295Enumerates system information.
BH19296Enumerates system services load order using WMI.
BH19299Enumerates the addresses associated with the adapters on the local computer.
BH19300Enumerates the credentials from the user's credential set.
BH19301Enumerates the information of a mapped drive.
BH19302Enumerates the key packs installed on a Remote Desktop license server.
BH19303Enumerates the licenses installed on a Remote Desktop license server.
BH19304Enumerates the names of open Excel windows.
BH19306Enumerates the WHEA memory policies for a computer.
BH19307Enumerates trusted execution enclave information.
BH19308Enumerates UEFI variable values related to Secure Boot.
BH19310Enumerates USB printer info.
BH19316Enumerates user accounts using WMI.
BH19317Enumerates user accounts.
BH19318Enumerates user desktop information using WMI.
BH19319Enumerates user groups using WMI.
BH19320Enumerates user groups.
BH19321Enumerates user information (current language).
BH19322Enumerates user information (login name).
BH19323Enumerates user information (monitors).
BH19324Enumerates user information (platform).
BH19325Enumerates user information (plugins).
BH19326Enumerates user information (printer color spaces).
BH19327Enumerates user information (user profile path).
BH19328Enumerates user information (viewer info).
BH19329Enumerates user information using 'finger' command.
BH19331Enumerates users in a repository of user information.
BH19333Enumerates video capture device driver information.
BH19334Enumerates virtual network routes.
BH19335Enumerates Windows Container networking adapters.
BH19337Enumerates WMI aliases.
BH19338Enumerates WMI service settings.
BH19339Enumerates workstation information.
BH19340Gets a list of publishable applications from a collection.
BH19346Gets an NFS mapped identity.
BH19350Gets clustered scheduled tasks for a failover cluster.
BH19358Gets information about a node object or the NLB cluster object that is queried by the caller.
BH19359Gets information about a remote hardware device.
BH19361Gets information about products registered with User Access Logging (UAL).
BH19364Gets information about the Network Load Balancing (NLB) driver on the local machine.
BH19365Gets information about the NLB cluster object that is queried by the caller.
BH19373Gets per-host global information for a Network Virtualization module.
BH19378Gets security access between failover clusters.
BH19379Gets security delegation on a Storage Replica server.
BH19384Gets the basic inventory information of a server.
BH19386Enumerates printer settings.
BH19388Gets the Credential Security Support Provider-related configuration for the client.
BH19390Gets the dedicated IP address that is queried by the caller.
BH19403Gets the name of the failover cluster of which a server is a member.
BH19409Gets the publisher GUID and the policy version of the Secure Boot configuration policy.
BH19413Gets the startup status for User Access Logging (UAL).
BH19419Gets the VFP/VSwitch port ID.
BH19424Gets User Access Logging (UAL) information about virtual machines.
BH19428Retrieves a list of root key values stored by the Microsoft Group KdsSvc.
BH19431Retrieves and displays the list of BPA models installed on the system.
BH19432Retrieves and displays the results of the most recent Best Practices Analyzer (BPA) scan for a specific model.
BH19435Retrieves global settings for all NAT instances on a computer.
BH19438Retrieves information about the SMB clients connected to the SMB witness servers in a cluster.
BH19439Retrieves network Quality of Service (QoS) policies.
BH19442Retrieves printer properties for the specified printer.
BH19443Retrieves process information.
BH19446Retrieves the contents of the DNS client cache.
BH19449Retrieves the list of entry points that have been configured for DirectAccess.
BH19450Enumerates printer drivers installed on the specified computer.
BH19451Retrieves the local computer name.
BH19452Retrieves the name of the user associated with the process.
BH19457Enumerates files through FTP.
BH19458Enumerates CRLs.
BH19465Enumerates connected USB devices.
BH19466Enumerates block devices.
BH19467Enumerates PCI devices.
BH19469Lists registered sd-bus services.
BH19470Gets the status of an sd-bus service.
BH19471Queries the system and user paths.
BH19472Gets the list of network namespaces.
BH19476Queries the computer's network name.
BH19477Gets the network route list.
BH19478Lists all OpenRC services.
BH19479Gets the status of all OpenRC services.
BH19480Gets the status of an OpenRC service.
BH19481Resolves an OpenRC service.
BH19482Looks up user's information.
BH19483Searches for a stored password.
BH19484Lists systemd units loaded into memory.
BH19485Lists systemd sockets loaded into memory.
BH19486Lists systemd timers loaded into memory.
BH19487Examines file capabilities.
BH19488Accesses an auditctl log file.
BH19489Searches for setuid/setgid binaries.
BH19490Queries information about a Linux Container.
BH19491Queries Linux Container system information.
BH19492Lists the Linux Containers existing on the system.
BH19493Shows LXD instance or server information.
BH19494Lists LXD instances.
BH19495Gets detailed wireless information from a wireless interface.
BH19496Lists all imported OpenPGP keys.
BH19497Lists all secret OpenPGP keys.
BH19498Enumerates files in a given directory using reflection.
BH19499Enumerates environment variables using reflection.
BH19500Retrieves process information using reflection.
BH19502Queries the computer's network name and IP address using reflection.
BH19503Enumerates the computer's network interfaces.
BH19504Enumerates the computer's network interfaces using reflection.
BH19505Enumerates physical memory information.
BH19506Enumerates current user's home directory.
BH19507Enumerates the operating system platform.
BH19508Enumerates operating system version.
BH19510Enumerates user information.
BH19511Enumerates tracked git repositories.
BH19512Enumerates tracked git repository URLs.
BH19513Enumerates git repository branches.
BH19518Enumerates the computer's IPv6 interfaces.
BH19521Queries the effective group ID of a process.
BH19522Queries the effective user ID of a process.
BH19523Queries the real group ID of a process.
BH19524Queries the real user ID of a process.
BH19525Queries the real, effective and saved user IDs of a process.
BH19526Queries the real, effective and saved group IDs of a process.
BH19527Enumerates active network connections.
BH19528Enumerates users that are connected on the system.
BH19529Retrieves a list of printers installed on a computer.
BH19530Enumerates print jobs for the specified printer.
BH19531Enumerates printer ports available on the specified computer.
BH19532Queries the ID of a group by its name.
BH19533Queries the ID of a user by its name.
BH19535Enumerates the installed system languages.
BH19537Enumerates environment variables related to Amazon Web Services (AWS).
BH19538Enumerates an environment variable that holds an Amazon Web Services (AWS) access key.
BH19539Enumerates an environment variable that holds an Amazon Web Services (AWS) configuration location.
BH19540Enumerates an environment variable that holds an Amazon Web Services (AWS) secret access key.
BH19541Enumerates an environment variable that holds an Amazon Web Services (AWS) session token.
BH19542Enumerates an environment variable that holds an Amazon Web Services (AWS) access key location.
BH19543Enumerates an environment variable that holds an Amazon Web Services (AWS) web identity token location.
BH20185Uses PowerSploit/Empire command to determine what users or groups are in the specified local group for the machine through Group Policy Object correlation.
BH20190Uses PowerSploit/Empire command to enumerate account logon events and logon with explicit credential events from the specified host.
BH20191Uses PowerSploit/Empire command to enumerate all loaded security support provider packages.
BH20193Uses PowerSploit/Empire command to enumerate all users.
BH20194Uses PowerSploit/Empire command to enumerate groups with users outside of the group's domain and return each foreign member.
BH20195Uses PowerSploit/Empire command to enumerate members of a specific local group on the local or a remote machine.
BH20197Uses PowerSploit/Empire command to enumerate the ACL for a given file path.
BH20198Uses PowerSploit/Empire command to enumerate the Active Directory DNS records for a given zone.
BH20199Uses PowerSploit/Empire command to enumerate the Active Directory DNS zones for a given domain.
BH20200Uses PowerSploit/Empire command to enumerate the local groups on the local or a remote machine.
BH20201Uses PowerSploit/Empire command to enumerate the machines where a specific domain user or group is a member of a specific local group, all through Group Policy Object correlation.
BH20202Uses PowerSploit/Empire command to enumerate the members of specified local group for all the targeted machines on the domain.
BH20203Uses PowerSploit/Empire command to enumerate the proxy server and WPAD specification for the current user on the local or a remote machine.
BH20204Uses PowerSploit/Empire command to enumerate trusted documents and trusted locations for Microsoft Office.
BH20205Uses PowerSploit/Empire command to enumerate users in a specified domain group.
BH20206Uses PowerSploit/Empire command to enumerate users who are in groups outside of the user's domain.
BH20207Uses PowerSploit/Empire command to enumerate users who are in groups outside of their principal domain.
BH20209Uses PowerSploit/Empire command to execute all functions that check for various Windows privilege escalation opportunities.
BH20221Uses PowerSploit/Empire command to find all directories in the system %PATH% that are modifiable by the current user.
BH20222Uses PowerSploit/Empire command to find all DLL hijack locations for currently running processes.
BH20223Uses PowerSploit/Empire command to find domain machines where specific users are logged into.
BH20226Uses PowerSploit/Empire command to find object ACLs in the current or specified domain.
BH20227Uses PowerSploit/Empire command to find user/group/computer objects in Active Directory that have 'outlier' properties set.
BH20230Uses PowerSploit/Empire command to hunt for processes with a specific name or owned by a specific user on domain machines.
BH20234Uses PowerSploit/Empire command to list the device paths of all local volume shadow copies.
BH20244Uses PowerSploit/Empire command to parse a passed string containing multiple possible file/folder paths and return the file paths where the current user has modification rights.
BH20266Uses PowerSploit/Empire command to return a list of all fault-tolerant distributed file systems for the current or specified domain.
BH20268Uses PowerSploit/Empire command to return a list of servers likely functioning as file servers.
BH20269Uses PowerSploit/Empire command to return a System.DirectoryServices.ActiveDirectory.Forest object for the current forest or the forest specified with -Forest X.
BH20270Uses PowerSploit/Empire command to return all computers or specific computer objects in Active Directory.
BH20271Uses PowerSploit/Empire command to return all domains for the current (or specified) forest.
BH20272Uses PowerSploit/Empire command to return all forest trusts for the current or a specified forest.
BH20273Uses PowerSploit/Empire command to return all global catalogs for the current (or specified) forest.
BH20274Uses PowerSploit/Empire command to return all Group Policy Objects (GPOs) in a domain that modify local group memberships through 'Restricted Groups' or Group Policy preferences.
BH20275Uses PowerSploit/Empire command to return all Group Policy Objects (GPOs) or specific GPO objects in Active Directory.
BH20276Uses PowerSploit/Empire command to return all groups or specific group objects in Active Directory.
BH20277Uses PowerSploit/Empire command to return all or specified domain objects in Active Directory.
BH20279Uses PowerSploit/Empire command to return all security groups in the current (or target) domain that have a manager set.
BH20280Uses PowerSploit/Empire command to return all SIDs that the current token context is a part of.
BH20281Uses PowerSploit/Empire command to return all trusts for the current user's domain.
BH20282Uses PowerSploit/Empire command to return all users or specific user objects in Active Directory.
BH20283Uses PowerSploit/Empire command to return detailed information about a specified service by querying the WMI.
BH20286Uses PowerSploit/Empire command to return remote desktop/session information for the local or a remote machine.
BH20287Uses PowerSploit/Empire command to return session information for the local or a remote machine.
BH20289Uses PowerSploit/Empire command to return the AD site where the local or a remote machine resides.
BH20290Uses PowerSploit/Empire command to return the default domain policy or the domain controller policy for a specified domain or domain controller.
BH20291Uses PowerSploit/Empire command to return the domain controllers for the current (or specified) domain.
BH20292Uses PowerSploit/Empire command to return the domain object for the current (or specified) domain.
BH20294Uses PowerSploit/Empire command to return the last user who logged onto the local or a remote machine.
BH20295Uses PowerSploit/Empire command to return the members of a specific domain group.
BH20296Uses PowerSploit/Empire command to return the name and binary path for services with unquoted paths that also have a space in the name.
BH20297Uses PowerSploit/Empire command to return the SID for the current domain or the specified domain.
BH20298Uses PowerSploit/Empire command to return users logged on the local or a remote machine.
BH20300Uses PowerSploit/Empire command to returns open shares on the local or a remote machine.
BH20304Uses PowerSploit/Empire command to search for all organization units (OUs) or specific OU objects in Active Directory.
BH20305Uses PowerSploit/Empire command to search for all sites or specific site objects in Active Directory.
BH20306Uses PowerSploit/Empire command to search for all subnets or specific subnets objects in Active Directory.
BH20307Uses PowerSploit/Empire command to search for computer shares on the domain.
BH20308Uses PowerSploit/Empire command to search for files matching specific criteria on readable shares in the domain.
BH20309Uses PowerSploit/Empire command to search for files on the given path that match a series of specified criteria.