1200KM / tool
Donut — Attack Tool
Donut is an open source framework used to generate position-independent shellcode. Donut generated code has been used by multiple threat actors to inject and load malicious payloads into memory.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: Donut
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Documented actor use
Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.
- Indrik Spider · G0119 · Pinned relationship source (relationship--7e2dcce1-8fde-4f88-9e48-13a736c694e3)
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1027.002 · Software Packing · Detection rules & anomalies
- T1027.013 · Encrypted/Encoded File · Detection rules & anomalies
- T1027.015 · Compression · Detection rules & anomalies
- T1055 · Process Injection · Detection rules & anomalies
- T1057 · Process Discovery · Detection rules & anomalies
- T1059 · Command and Scripting Interpreter · Detection rules & anomalies
- T1059.001 · PowerShell · Detection rules & anomalies
- T1059.005 · Visual Basic · Detection rules & anomalies
- T1059.006 · Python · Detection rules & anomalies
- T1059.007 · JavaScript · Detection rules & anomalies
- T1070 · Indicator Removal · Detection rules & anomalies
- T1071.001 · Web Protocols · Detection rules & anomalies
- T1105 · Ingress Tool Transfer · Detection rules & anomalies
- T1106 · Native API · Detection rules & anomalies
- T1620 · Reflective Code Loading · Detection rules & anomalies
- T1685 · Disable or Modify Tools · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Application Log Content · DC0038
- Cloud Service Modification · DC0069
- Command Execution · DC0064
- File Access · DC0055
- File Creation · DC0039
- File Deletion · DC0040
- File Metadata · DC0059
- File Modification · DC0061
- Host Status · DC0018
- Module Load · DC0016
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
- OS API Execution · DC0021
- Process Access · DC0035
- Process Creation · DC0032
- Process Metadata · DC0034
- Process Modification · DC0020
- Process Termination · DC0033
- Scheduled Job Modification · DC0012
- Script Execution · DC0029
- Service Creation · DC0060
- Service Metadata · DC0041
- Service Modification · DC0065
- User Account Authentication · DC0002
- Windows Registry Key Modification · DC0063
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.