1200KM / tool
Covenant — Attack Tool
Covenant is a multi-platform command and control framework written in .NET. While designed for penetration testing and security research, the tool has also been used by threat actors such as HAFNIUM during operations. Covenant functions through a central listener managing multiple deployed "Grunts" that communicate back to the controller.
Tool identity and evidence
Included because the active pinned ATT&CK object has type tool. This is an upstream classification, not an assurance of benignness or a recommendation to run it.
Aliases: Covenant
Existing author guides
No reviewed association in this snapshot.
Primary documentation
No reviewed association in this snapshot.
Connected ecosystem references
Linked tags
Documented actor use
Explicit actor-to-software uses relationships in the pinned ATT&CK source. These links are historical behavior context, not attribution of current events.
- HAFNIUM · G0125 · Pinned relationship source (relationship--6f917518-2f54-479e-a008-cbf6bd6037c0)
Technique-specific simulations and detections
Detection links describe the associated behavior, not independently verified tool-specific signatures.
- T1047 · Windows Management Instrumentation · Detection rules & anomalies
- T1059.001 · PowerShell · Detection rules & anomalies
- T1059.003 · Windows Command Shell · Detection rules & anomalies
- T1071.001 · Web Protocols · Detection rules & anomalies
- T1082 · System Information Discovery · Detection rules & anomalies
- T1218.004 · InstallUtil · Detection rules & anomalies
- T1218.005 · Mshta · Detection rules & anomalies
- T1218.010 · Regsvr32 · Detection rules & anomalies
- T1571 · Non-Standard Port · Detection rules & anomalies
- T1573.002 · Asymmetric Cryptography · Detection rules & anomalies
Telemetry context
Derived from the explicitly linked TTPs; not proof of sensor coverage for this tool.
- Application Log Content · DC0038
- Command Execution · DC0064
- File Creation · DC0039
- Instance Enumeration · DC0075
- Module Load · DC0016
- Network Connection Creation · DC0082
- Network Traffic Content · DC0085
- Network Traffic Flow · DC0078
- Process Creation · DC0032
- Process Metadata · DC0034
- Script Execution · DC0029
- WMI Creation · DC0008
- Windows Registry Key Modification · DC0063
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.