1200KM / tool
Koadic — Attack Tool
Koadic is a Windows post-exploitation framework and penetration testing tool that is publicly available on GitHub. Koadic has several options for staging payloads and creating implants, and performs most of its operations using Windows Script Host.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: Koadic
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Documented actor use
Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.
- APT28 · G0007 · Pinned relationship source (relationship--7a3963b8-3ffd-41a9-bd03-57cba4f03882)
- MuddyWater · G0069 · Pinned relationship source (relationship--fd119308-f4b9-4d06-adf2-08a76baee7d9)
- Sidewinder · G0121 · Pinned relationship source (relationship--eab4c1aa-d84d-4111-ab87-710345bdd31d)
- LazyScripter · G0140 · Pinned relationship source (relationship--c7972596-a87d-48fd-bd6f-f140e16f99a6)
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1003.002 · Security Account Manager · Detection rules & anomalies
- T1003.003 · NTDS · Detection rules & anomalies
- T1005 · Data from Local System · Detection rules & anomalies
- T1016 · System Network Configuration Discovery · Detection rules & anomalies
- T1021.001 · Remote Desktop Protocol · Detection rules & anomalies
- T1033 · System Owner/User Discovery · Detection rules & anomalies
- T1046 · Network Service Discovery · Detection rules & anomalies
- T1047 · Windows Management Instrumentation · Detection rules & anomalies
- T1053.005 · Scheduled Task · Detection rules & anomalies
- T1055.001 · Dynamic-link Library Injection · Detection rules & anomalies
- T1059.001 · PowerShell · Detection rules & anomalies
- T1059.003 · Windows Command Shell · Detection rules & anomalies
- T1059.005 · Visual Basic · Detection rules & anomalies
- T1071.001 · Web Protocols · Detection rules & anomalies
- T1082 · System Information Discovery · Detection rules & anomalies
- T1083 · File and Directory Discovery · Detection rules & anomalies
- T1105 · Ingress Tool Transfer · Detection rules & anomalies
- T1115 · Clipboard Data · Detection rules & anomalies
- T1135 · Network Share Discovery · Detection rules & anomalies
- T1218.005 · Mshta · Detection rules & anomalies
- T1218.010 · Regsvr32 · Detection rules & anomalies
- T1218.011 · Rundll32 · Detection rules & anomalies
- T1547.001 · Registry Run Keys / Startup Folder · Detection rules & anomalies
- T1548.002 · Bypass User Account Control · Detection rules & anomalies
- T1564.003 · Hidden Window · Detection rules & anomalies
- T1569.002 · Service Execution · Detection rules & anomalies
- T1573.002 · Asymmetric Cryptography · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Application Log Content · DC0038
- Command Execution · DC0064
- File Access · DC0055
- File Creation · DC0039
- File Modification · DC0061
- Instance Enumeration · DC0075
- Logon Session Creation · DC0067
- Logon Session Metadata · DC0088
- Module Load · DC0016
- Named Pipe Metadata · DC0048
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
- OS API Execution · DC0021
- Process Access · DC0035
- Process Creation · DC0032
- Process Metadata · DC0034
- Scheduled Job Creation · DC0001
- Scheduled Job Modification · DC0012
- Script Execution · DC0029
- Service Creation · DC0060
- Volume Creation · DC0097
- WMI Creation · DC0008
- Windows Registry Key Modification · DC0063
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.