Classe: HackTool
Les programmes HackTool sont utilisés pour créer de nouveaux utilisateurs dans la liste des visiteurs système autorisés et pour supprimer des informations des journaux système afin de masquer la présence de l'utilisateur malveillant sur le système. Ces programmes sont également utilisés pour analyser et collecter des paquets réseau pour effectuer des actions malveillantes spécifiques. Les utilisateurs malveillants utilisent des programmes HackTool lors de la configuration d'attaques sur des ordinateurs locaux ou distants.Plus d'informations
Plateforme: Win64
Win64 est une plate-forme sur les systèmes d'exploitation Windows pour l'exécution d'applications 32/64 bits. Les programmes Win64 ne peuvent pas être lancés sur des versions 32 bits de Windows.Famille: HackTool.Win64.AmsiETWPatch
No family descriptionExamples
F477C873ABE1E0D703E25CE1D0DFC584Tactics and Techniques: Mitre*
TA0005
Defense Evasion
The adversary is trying to avoid being detected. Defense Evasion consists of techniques that adversaries use to avoid detection throughout their compromise. Techniques used for defense evasion include uninstalling/disabling security software or obfuscating/encrypting data and scripts. Adversaries also leverage and abuse trusted processes to hide and masquerade their malware. Other tactics' techniques are cross-listed here when those techniques include the added benefit of subverting defenses.
T1564.001
Hidden Files and Directories
Adversaries may set files and directories to be hidden to evade detection mechanisms. To prevent normal users from accidentally changing special files on a system, most operating systems have the concept of a ‘hidden’ file. These files don’t show up when a user browses the file system with a GUI or when using normal commands on the command line. Users must explicitly ask to show the hidden files either via a series of Graphical User Interface (GUI) prompts or with command line switches (
dir /a for Windows and ls –a for Linux and macOS). TA0011
Command and Control
The adversary is trying to communicate with compromised systems to control them. Command and Control consists of techniques that adversaries may use to communicate with systems under their control within a victim network. Adversaries commonly attempt to mimic normal, expected traffic to avoid detection. There are many ways an adversary can establish command and control with various levels of stealth depending on the victim's network structure and defenses.
T1071.001
Web Protocols
Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server.
* © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.