| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1543 | .003 | 创建或修改系统进程: Windows Service |
Briba installs a service pointing to a malicious DLL dropped to disk.[2] |
| Enterprise | T1547 | .001 | 启动或登录自动启动执行: Registry Run Keys / Startup Folder |
Briba creates run key Registry entries pointing to malicious DLLs dropped to disk.[2] |
| Enterprise | T1218 | .011 | 系统二进制代理执行: Rundll32 |
Briba uses rundll32 within Registry Run Keys / Startup Folder entries to execute malicious DLLs.[2] |
| Enterprise | T1105 | 输入工具传输 | ||