1200KM / tool
Pupy — Attack Tool
Pupy is an open source, cross-platform (Windows, Linux, OSX, Android) remote administration and post-exploitation tool. It is written in Python and can be generated as a payload in several different ways (Windows exe, Python file, PowerShell oneliner/file, Linux elf, APK, Rubber Ducky, etc.). Pupy is publicly available on GitHub.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: Pupy
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Documented actor use
Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.
- Magic Hound · G0059 · Pinned relationship source (relationship--cde73e1c-da81-4673-a161-49693b45cd48)
- APT33 · G0064 · Pinned relationship source (relationship--d2c3b075-5299-42e5-95de-8248dc0da551)
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1003.001 · LSASS Memory · Detection rules & anomalies
- T1003.004 · LSA Secrets · Detection rules & anomalies
- T1003.005 · Cached Domain Credentials · Detection rules & anomalies
- T1016 · System Network Configuration Discovery · Detection rules & anomalies
- T1021.001 · Remote Desktop Protocol · Detection rules & anomalies
- T1033 · System Owner/User Discovery · Detection rules & anomalies
- T1041 · Exfiltration Over C2 Channel · Detection rules & anomalies
- T1046 · Network Service Discovery · Detection rules & anomalies
- T1049 · System Network Connections Discovery · Detection rules & anomalies
- T1055.001 · Dynamic-link Library Injection · Detection rules & anomalies
- T1056.001 · Keylogging · Detection rules & anomalies
- T1057 · Process Discovery · Detection rules & anomalies
- T1059.001 · PowerShell · Detection rules & anomalies
- T1059.006 · Python · Detection rules & anomalies
- T1071.001 · Web Protocols · Detection rules & anomalies
- T1082 · System Information Discovery · Detection rules & anomalies
- T1083 · File and Directory Discovery · Detection rules & anomalies
- T1087.001 · Local Account · Detection rules & anomalies
- T1105 · Ingress Tool Transfer · Detection rules & anomalies
- T1113 · Screen Capture · Detection rules & anomalies
- T1114.001 · Local Email Collection · Detection rules & anomalies
- T1123 · Audio Capture · Detection rules & anomalies
- T1125 · Video Capture · Detection rules & anomalies
- T1134.001 · Token Impersonation/Theft · Detection rules & anomalies
- T1135 · Network Share Discovery · Detection rules & anomalies
- T1136.001 · Local Account · Detection rules & anomalies
- T1136.002 · Domain Account · Detection rules & anomalies
- T1497.001 · System Checks · Detection rules & anomalies
- T1543.002 · Systemd Service · Detection rules & anomalies
- T1547.001 · Registry Run Keys / Startup Folder · Detection rules & anomalies
- T1547.013 · XDG Autostart Entries · Detection rules & anomalies
- T1548.002 · Bypass User Account Control · Detection rules & anomalies
- T1550.003 · Pass the Ticket · Detection rules & anomalies
- T1552.001 · Credentials In Files · Detection rules & anomalies
- T1555 · Credentials from Password Stores · Detection rules & anomalies
- T1555.003 · Credentials from Web Browsers · Detection rules & anomalies
- T1557.001 · Name Resolution Poisoning and SMB Relay · Detection rules & anomalies
- T1560.001 · Archive via Utility · Detection rules & anomalies
- T1569.002 · Service Execution · Detection rules & anomalies
- T1573.002 · Asymmetric Cryptography · Detection rules & anomalies
- T1685.005 · Clear Windows Event Logs · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Active Directory Credential Request · DC0084
- Application Log Content · DC0038
- Cloud Service Enumeration · DC0083
- Command Execution · DC0064
- File Access · DC0055
- File Creation · DC0039
- File Deletion · DC0040
- File Metadata · DC0059
- File Modification · DC0061
- Firmware Modification · DC0004
- Instance Enumeration · DC0075
- Logon Session Creation · DC0067
- Logon Session Metadata · DC0088
- Module Load · DC0016
- Named Pipe Metadata · DC0048
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
- OS API Execution · DC0021
- Process Access · DC0035
- Process Creation · DC0032
- Process Metadata · DC0034
- Script Execution · DC0029
- Service Creation · DC0060
- User Account Authentication · DC0002
- User Account Creation · DC0014
- User Account Metadata · DC0013
- Windows Registry Key Modification · DC0063
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.