SILENTTRINITY can create a memory dump of LSASS via the MiniDumpWriteDump Win32 API call.3
tool
SILENTTRINITY S0692
- Type
- tool
- Platform
- Windows
- Created
- 23 March 2022
- Last modified
- 30 April 2025
SILENTTRINITY is an open source remote administration and post-exploitation framework primarily written in Python that includes stagers written in Powershell, C, and Boo. SILENTTRINITY was used in a 2019 campaign against Croatian government agencies by unidentified cyber actors.[1][2]
Enterprise ATT&CK only. Any Mobile or ICS rows on the same ATT&CK page are not carried.
MITRE reference S0692
SILENTTRINITY can search for modifiable services that could be used for privilege escalation.4
SILENTTRINITY can enumerate the active Window during keylogging through execution of GetActiveWindowTitle.5
SILENTTRINITY can use the GetRegValue function to check Registry keys within HKCU\Software\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated and HKLM\Software\Policies\Microsoft\Windows\Installer\AlwaysInstallElevated. It also contains additional modules that can check software AutoRun values and use the Win32 namespace to get values from HKCU, HKLM, HKCR, and HKCC hives.6
SILENTTRINITY can enumerate and collect the properties of domain computers.7
SILENTTRINITY can use System namespace methods to execute lateral movement using DCOM.8
Standing S0692
Reach is how much of ATT&CK this tool touches. Coverage is how well defended each thing it does is, as a median per technique rather than a total — a total would just restate the reach. Each figure is ranked against all 825 ATT&CK software entries only where that population actually spreads. Where most of the population shares one value, a percentile would rank the tie instead of the entity, so the raw value is shown and no rank is claimed.
Reach
99th percentile · 99% of 825 ATT&CK software entries have this many Enterprise techniques or fewer.
98th percentile · 98% of 825 ATT&CK software entries have this many tactics spanned or fewer.
61% of the population shares a single value across only 22 distinct values, so a percentile here would rank the tie, not the entity.
85% of the population shares a single value across only 8 distinct values, so a percentile here would rank the tie, not the entity.
Coverage
38th percentile · 62% of 825 ATT&CK software entries have more detection rules per technique.
Detection coverage S0692
1870 distinct rules cover the 53 techniques recorded for this tool. The 2119 technique-to-rule mappings resolve to 1870 distinct rules, because one rule can cover several techniques. 1225 Sigma · 645 Splunk.
Loading detections...
| Select | Title | Description | Category | Status | Event | Product | MITRE ATT&CK | CVEs | Severity | Author | Created | Updated | ID | Refs |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
© 2026 The MITRE Corporation. ATT&CK® and D3FEND™ data reproduced with permission. SigmaHQ detection rules licensed under DRL 1.1. attack.mitre.org · d3fend.mitre.org · CAR analytics licensed under Apache 2.0 · car.mitre.org