| Domain | ID | Name | Use | |
|---|---|---|---|---|
| Enterprise | T1005 | 从本地系统获取数据 |
esentutl can be used to collect data from local file systems.[2] |
|
| Enterprise | T1003 | .003 | 操作系统凭证转储: NTDS |
esentutl can copy |
| Enterprise | T1570 | 横向工具传输 |
esentutl can be used to copy files to/from a remote share.[3] |
|
| Enterprise | T1006 | 直接卷访问 |
esentutl can use the Volume Shadow Copy service to copy locked files such as |
|
| Enterprise | T1105 | 输入工具传输 | ||
| Enterprise | T1564 | .004 | 隐藏伪装: NTFS File Attributes |
esentutl can be used to read and write alternate data streams.[3] |