1200KM / tool
SILENTTRINITY — Attack Tool
SILENTTRINITY is an open source remote administration and post-exploitation framework primarily written in Python that includes stagers written in Powershell, C, and Boo. SILENTTRINITY was used in a 2019 campaign against Croatian government agencies by unidentified cyber actors.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: SILENTTRINITY
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1003.001 · LSASS Memory · Detection rules & anomalies
- T1007 · System Service Discovery · Detection rules & anomalies
- T1010 · Application Window Discovery · Detection rules & anomalies
- T1012 · Query Registry · Detection rules & anomalies
- T1018 · Remote System Discovery · Detection rules & anomalies
- T1021.003 · Distributed Component Object Model · Detection rules & anomalies
- T1021.006 · Windows Remote Management · Detection rules & anomalies
- T1033 · System Owner/User Discovery · Detection rules & anomalies
- T1041 · Exfiltration Over C2 Channel · Detection rules & anomalies
- T1046 · Network Service Discovery · Detection rules & anomalies
- T1047 · Windows Management Instrumentation · Detection rules & anomalies
- T1055 · Process Injection · Detection rules & anomalies
- T1056.001 · Keylogging · Detection rules & anomalies
- T1056.002 · GUI Input Capture · Detection rules & anomalies
- T1057 · Process Discovery · Detection rules & anomalies
- T1059.001 · PowerShell · Detection rules & anomalies
- T1059.003 · Windows Command Shell · Detection rules & anomalies
- T1059.006 · Python · Detection rules & anomalies
- T1069.001 · Local Groups · Detection rules & anomalies
- T1069.002 · Domain Groups · Detection rules & anomalies
- T1070 · Indicator Removal · Detection rules & anomalies
- T1070.004 · File Deletion · Detection rules & anomalies
- T1082 · System Information Discovery · Detection rules & anomalies
- T1083 · File and Directory Discovery · Detection rules & anomalies
- T1087.002 · Domain Account · Detection rules & anomalies
- T1105 · Ingress Tool Transfer · Detection rules & anomalies
- T1106 · Native API · Detection rules & anomalies
- T1112 · Modify Registry · Detection rules & anomalies
- T1113 · Screen Capture · Detection rules & anomalies
- T1115 · Clipboard Data · Detection rules & anomalies
- T1124 · System Time Discovery · Detection rules & anomalies
- T1134.001 · Token Impersonation/Theft · Detection rules & anomalies
- T1134.003 · Make and Impersonate Token · Detection rules & anomalies
- T1135 · Network Share Discovery · Detection rules & anomalies
- T1518.001 · Security Software Discovery · Detection rules & anomalies
- T1543.003 · Windows Service · Detection rules & anomalies
- T1546.001 · Change Default File Association · Detection rules & anomalies
- T1546.003 · Windows Management Instrumentation Event Subscription · Detection rules & anomalies
- T1546.015 · Component Object Model Hijacking · Detection rules & anomalies
- T1547.001 · Registry Run Keys / Startup Folder · Detection rules & anomalies
- T1548.002 · Bypass User Account Control · Detection rules & anomalies
- T1552.006 · Group Policy Preferences · Detection rules & anomalies
- T1555.003 · Credentials from Web Browsers · Detection rules & anomalies
- T1555.004 · Windows Credential Manager · Detection rules & anomalies
- T1556 · Modify Authentication Process · Detection rules & anomalies
- T1558.003 · Kerberoasting · Detection rules & anomalies
- T1559.001 · Component Object Model · Detection rules & anomalies
- T1564.003 · Hidden Window · Detection rules & anomalies
- T1620 · Reflective Code Loading · Detection rules & anomalies
- T1680 · Local Storage Discovery · Detection rules & anomalies
- T1685 · Disable or Modify Tools · Detection rules & anomalies
- T1689 · Downgrade Attack · Detection rules & anomalies
- T1690 · Prevent Command History Logging · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Active Directory Credential Request · DC0084
- Application Log Content · DC0038
- Cloud Service Modification · DC0069
- Command Execution · DC0064
- Driver Load · DC0079
- File Access · DC0055
- File Creation · DC0039
- File Deletion · DC0040
- File Metadata · DC0059
- File Modification · DC0061
- Firmware Modification · DC0004
- Host Status · DC0018
- Instance Enumeration · DC0075
- Logon Session Creation · DC0067
- Logon Session Metadata · DC0088
- Module Load · DC0016
- Named Pipe Metadata · DC0048
- Network Connection Creation · DC0082
- Network Share Access · DC0102
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
- OS API Execution · DC0021
- Process Access · DC0035
- Process Creation · DC0032
- Process Metadata · DC0034
- Process Modification · DC0020
- Process Termination · DC0033
- Scheduled Job Creation · DC0001
- Scheduled Job Metadata · DC0005
- Scheduled Job Modification · DC0012
- Script Execution · DC0029
- Service Creation · DC0060
- Service Metadata · DC0041
- Service Modification · DC0065
- User Account Authentication · DC0002
- User Account Metadata · DC0013
- User Account Modification · DC0010
- WMI Creation · DC0008
- Windows Registry Key Access · DC0050
- Windows Registry Key Modification · DC0063
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.