| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1543 | .003 | 创建或修改系统进程: Windows Service |
hcdLoader installs itself as a service for persistence.[1][2] |
| Enterprise | T1059 | .003 | 命令与脚本解释器: Windows Command Shell |
hcdLoader provides command-line access to the compromised system.[1] |