1200KM / tool
PowerSploit — Attack Tool
PowerSploit is an open source, offensive security framework comprised of PowerShell modules and scripts that perform a wide range of tasks related to penetration testing such as code execution, persistence, bypassing anti-virus, recon, and exfiltration.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: PowerSploit
Existing author guides
No reviewed association in this snapshot.
Primary documentation
Connected ecosystem references
Linked tags
Documented actor use
Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.
- Patchwork · G0040 · Pinned relationship source (relationship--f07267d5-f532-4a52-abd6-20d5f94a2bf8)
- menuPass · G0045 · Pinned relationship source (relationship--80d72d09-c1a4-4735-b85a-28bfc19ef8b9)
- FIN7 · G0046 · Pinned relationship source (relationship--6afed42c-6a42-402a-8964-7fcde5435336)
- APT33 · G0064 · Pinned relationship source (relationship--148d82d9-c55b-4ce4-adb2-79387dab01ab)
- Leviathan · G0065 · Pinned relationship source (relationship--962f1bc9-89f8-4fbe-b981-b63cce196cbf)
- MuddyWater · G0069 · Pinned relationship source (relationship--649748ff-e2d0-4369-8f5d-3c8b5b5010ed)
- TA505 · G0092 · Pinned relationship source (relationship--e3c860e4-c981-4a9a-8a8e-8ba0207f834b)
- APT41 · G0096 · Pinned relationship source (relationship--48c34dc3-0c3f-426d-b99a-b72e595da287)
- Earth Lusca · G1006 · Pinned relationship source (relationship--427f7417-6d8a-4b0b-8bcf-a6acdd28586e)
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1003.001 · LSASS Memory · Detection rules & anomalies
- T1005 · Data from Local System · Detection rules & anomalies
- T1012 · Query Registry · Detection rules & anomalies
- T1027.005 · Indicator Removal from Tools · Detection rules & anomalies
- T1027.010 · Command Obfuscation · Detection rules & anomalies
- T1047 · Windows Management Instrumentation · Detection rules & anomalies
- T1053.005 · Scheduled Task · Detection rules & anomalies
- T1055.001 · Dynamic-link Library Injection · Detection rules & anomalies
- T1056.001 · Keylogging · Detection rules & anomalies
- T1057 · Process Discovery · Detection rules & anomalies
- T1059.001 · PowerShell · Detection rules & anomalies
- T1087.001 · Local Account · Detection rules & anomalies
- T1113 · Screen Capture · Detection rules & anomalies
- T1123 · Audio Capture · Detection rules & anomalies
- T1134 · Access Token Manipulation · Detection rules & anomalies
- T1482 · Domain Trust Discovery · Detection rules & anomalies
- T1543.003 · Windows Service · Detection rules & anomalies
- T1547.001 · Registry Run Keys / Startup Folder · Detection rules & anomalies
- T1547.005 · Security Support Provider · Detection rules & anomalies
- T1552.002 · Credentials in Registry · Detection rules & anomalies
- T1552.006 · Group Policy Preferences · Detection rules & anomalies
- T1555.004 · Windows Credential Manager · Detection rules & anomalies
- T1558.003 · Kerberoasting · Detection rules & anomalies
- T1574.001 · DLL · Detection rules & anomalies
- T1574.007 · Path Interception by PATH Environment Variable · Detection rules & anomalies
- T1574.008 · Path Interception by Search Order Hijacking · Detection rules & anomalies
- T1574.009 · Path Interception by Unquoted Path · Detection rules & anomalies
- T1620 · Reflective Code Loading · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Active Directory Credential Request · DC0084
- Active Directory Object Access · DC0071
- Active Directory Object Modification · DC0066
- Application Log Content · DC0038
- Command Execution · DC0064
- Driver Load · DC0079
- File Access · DC0055
- File Creation · DC0039
- File Metadata · DC0059
- File Modification · DC0061
- Firmware Modification · DC0004
- Logon Session Creation · DC0067
- Logon Session Metadata · DC0088
- Module Load · DC0016
- Named Pipe Metadata · DC0048
- Network Connection Creation · DC0082
- Network Share Access · DC0102
- Network Traffic Content · DC0085
- OS API Execution · DC0021
- Process Access · DC0035
- Process Creation · DC0032
- Process Metadata · DC0034
- Process Modification · DC0020
- Scheduled Job Creation · DC0001
- Scheduled Job Modification · DC0012
- Script Execution · DC0029
- Service Creation · DC0060
- User Account Metadata · DC0013
- WMI Creation · DC0008
- Windows Registry Key Access · DC0050
- Windows Registry Key Modification · DC0063
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.