| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1090 | 代理 | ||
| Enterprise | T1059 | .001 | 命令与脚本解释器: PowerShell | |
| Enterprise | T1113 | 屏幕捕获 | ||
| Enterprise | T1057 | 进程发现 | ||
| Enterprise | T1055 | .001 | 进程注入: Dynamic-link Library Injection |
Socksbot creates a suspended svchost process and injects its DLL into it.[1] |