Detections
- Home
- - Detections
- -DT036
- ID: DT036
- Created: 01st June 2024
- Updated: 17th June 2024
- Platform: Windows
- Contributor: The ITM Team
Windows Jump Lists
Windows Jump Lists are a feature that provides quick access to recently or frequently used files.
Sections
| ID | Name | Description | 
|---|---|---|
| AF015 | File Deletion | A subject deletes a file or files to prevent them from being available for later analysis or to disrupt the availability of a system. This could include log files, files downloaded by the subject, files created by the subject, or system files. | 
| PR003 | Software Installation | A subject may install or attempt to install software that will be used to exfiltrate sensitive data or contravene internal policies. | 
| AF003 | Timestomping | A subject modifies the modified, accessed, created (MAC) file time attributes to hide new files or obscure changes made to existing files to hinder an investigation by removing a file or files from a timeframe scope. 
 nTimestomp is part of the nTimetools repository, and it provides tools for working with timestamps on files on the Windows operating system. This tool allows for a user to provide arguments for each timestamp, as well as the option to set all timestamps to the same value. 
 Linux has the built-in command  
 The argument  | 
| IF005 | Exfiltration via Messaging Applications | A subject uses a messaging application to exfiltrate data through messages or uploaded media. | 
| ME002 | Unrestricted Software Installation | A subject can install software on a device without restriction. | 
| ME003 | Installed Software | A subject can leverage software approved for installation or software that is already installed. | 
| AF016 | Uninstalling Software | The subject uninstalls software, which may also remove relevant artifacts from the system's disk, such as regsitry keys or files necessary for the software to run, preventing them from being used by investigators to track activity. | 
| IF017 | Excessive Personal Use | A subject uses organizational resources, such as internet access, email, or work devices, for personal activities both during and outside work hours, exceeding reasonable personal use. This leads to reduced productivity, increased security risks, and the potential mixing of personal and organizational data, ultimately affecting the organization’s efficiency and overall security. | 
| PR017.001 | Archive via Utility | A subject uses utilities to compress and/or encrypt collected data prior to exfiltration. | 
| PR017.002 | Archive via Library | A subject uses utilities to compress and/or encrypt collected data prior to exfiltration. | 
| PR017.003 | Archive via Compression | A subject uses utilities to compress collected data prior to exfiltration. | 
| PR017.004 | Archive via Encryption | A subject uses utilities to encrypt collected data prior to exfiltration. | 
| IF005.001 | Exfiltration via Installed Messaging Application | A subject exfiltrates information using a messaging application that is already installed on the system. They will access the conversation at a later date to retrieve information on a different system. | 
| PR003.011 | Installing Screen Sharing Software | A subject installs screen sharing software which can be used to capture images or other information from a target system. | 
| PR003.009 | Installing FTP Clients | A subject installs a File Transfer Protocol (FTP) client which can be used to access FTP servers across the a network. | 
| PR003.010 | Installing RDP Clients | A subject installs a Remote Desktop Protocol (RDP) client which can be used to access RDP servers across a network. | 
| PR003.008 | Installing SSH Clients | A subject installs a Secure Shell (SSH) client, which can be used to access SSH servers across a network. | 
| PR003.006 | Installing Note-Taking Applications | A subject installs an unapproved note taking application with the ability to sync notes across the Internet. | 
| PR003.005 | Installing Cloud Storage Applications | A subject can install an unapproved cloud storage application that has the ability to sync files across the Internet. | 
| PR003.003 | Installing Browsers | A subject can install an unapproved browser with features that frustrate or prevent preventions or detections, such as built-in VPN, Tor access, or automatic browser artifact destruction. | 
| PR003.002 | Installing VPN Applications | A subject installs a VPN application that allows them to tunnel their traffic. | 
| PR003.001 | Installing Virtual Machines | A subject installs a hypervisor that allows them to create and access virtual environments on a device. | 
| ME003.011 | Screen Sharing Software | A subject has access to or can install screen sharing software which can be used to capture images or other information from a target system. | 
| IF009.002 | Inappropriate Software | A subject installs software that is not considered appropriate by the organization. | 
| IF009.001 | Unwanted Software | A subject installs software that is not inherently malicious, but is not wanted, commonly known as “greyware” or “potentially unwanted programs”. | 
| IF002.006 | Exfiltration via USB to USB Data Transfer | A USB to USB data transfer cable is a device designed to connect two computers directly together for the purpose of transferring files between them. These cables are equipped with a small electronic circuit to facilitate data transfer without the need for an intermediate storage device. Typically a USB to USB data transfer cable will require specific software to be installed to facilitate the data transfer. In the context of an insider threat, a USB to USB data transfer cable can be a tool for exfiltrating sensitive data from an organization's environment. | 
| IF002.008 | Exfiltration via USB to Mobile Device | The subject uses a USB cable, and any relevant software if required, to transfer files or data from one system to a mobile device. This device is then taken outside of the organization's control, where the subject can later access the contents. | 
| PR006.004 | Security Enumeration via Network Activity | A subject attempts to identify security software by monitoring network traffic. | 
| PR003.012 | Installation of Dark Web-Capable Browsers | The subject installs a browser capable of accessing anonymity networks, such as the Tor Browser (used for  
 Installation of the Tor Browser Bundle typically involves downloading a signed executable or compressed package from  
 In environments with proxy filtering, the subject may attempt to chain Tor through bridge relays or VPNs, obfuscate traffic using SOCKS5 tunneling, or execute from non-standard directories (e.g., cloud-sync folders, external volumes). Some subjects bypass endpoint controls entirely by booting into live-operating systems (e.g., Tails, Whonix) which route all system traffic through Tor by default and leave minimal forensic artifacts on host storage. 
 This installation is rarely accidental and often coincides with other policy evasions or drift indicators. The presence of anonymizing tools—even in dormant form—warrants scrutiny as a preparatory indicator linked to potential data exfiltration, credential harvesting, or external coordination. | 
| PR018.002 | Impairing a Security Agent | A subject abuses their access or conducts unapproved changes to impair the effectiveness of a security agent, such as causing it to crash, killing any associated system processes, installing conflicting software, or preventing connectivity to telemetry domains. |