SCYTHE
Setup Campaign
Community Threats (Third Party Adversary Emulation Plans)

Deploy Payload
User Execution: Malicious File (T1204.002):
Signed Binary Proxy Execution: Rundll32 (T1218.011):
Command and Scripting Interpreter: PowerShell (T1059.001)
Emulate TTPs
Load Python Runtime
Download files
Privilege Escalation (TA0004)
UAC (T1088)
Credential Access (TA0006)
Credential Dumping (T1003)
Persistence (TA0003)
New Service (T1050)
Scheduled Task (T1168)
Clean up
Persistence:
Kill agent:
Last updated