1200KM / simulation
T1106 Native API — Attack Simulation
Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes. These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations.…
Technique description
Adversaries may interact with the native OS application programming interface (API) to execute behaviors. Native APIs provide a controlled means of calling low-level OS services within the kernel, such as those involving hardware/devices, memory, and processes. These native APIs are leveraged by the OS during system boot (when other system components are not yet initialized) as well as carrying out tasks and requests during routine operations.…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- WinPwn - Get SYSTEM shell - Bind System Shell using CreateProcess technique
Procedure 7ec5b74e-8289-4ff2-a162-b6f286a33abd; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Execution through API - CreateProcess
Procedure 99be2089-c52d-4a4a-b5c3-261ee42c8b62; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Run Shellcode via Syscall in Go
Procedure ae56083f-28d0-417d-84da-df4242da1f7c; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- WinPwn - Get SYSTEM shell - Pop System Shell using CreateProcess technique
Procedure ce4e76e6-de70-4392-9efe-b281fc2b4087; elevation not declared required; cleanup not declared. Not executed or individually validated.
- WinPwn - Get SYSTEM shell - Pop System Shell using NamedPipe Impersonation technique
Procedure e1f93a06-1649-4f07-89a8-f57279a7d60e; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Turla · G0010
- Lazarus Group · G0032
- Sandworm Team · G0034
- menuPass · G0045
- Gamaredon Group · G0047
- APT37 · G0067
- Gorgon Group · G0078
- Tropic Trooper · G0081
- APT38 · G0082
- WIRTE · G0090
- Silence · G0091
- TA505 · G0092
- Kimsuky · G0094
- BlackTech · G0098
- Chimera · G0114
- Higaisa · G0126
- Mustang Panda · G0129
- SideCopy · G1008
- ToddyCat · G1022
- Medusa Group · G1051
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.