BISCUIT

BISCUITBISCUIT

Description

BISCUIT provides attackers with full access to an infected host. BISCUIT capabilities include launching an interactive command shell, enumerating servers on a Windows network, enumerating and manipulating process, and transferring files. BISCUIT communicates using a custom protocol, which is then encrypted using SSL. Once installed BISCUIT will attempt to beacon to its command/control servers approximately every 10 or 30 minutes. It will beacon its primary server first, followed by a secondary server. All communication is encrypted with SSL (OpenSSL 0.9.8i).

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

Software
BISKVIT
Software
CHOPSTICK
Software
Bisonal
Software
BANGAT
Software
SWORD
Software
COOKIEBAG
Sourced from MITRE ATT&CK Enterprise . Curated by Adam Lundqvist, SQUR.