Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/Software/S0692
MITRE ATT&CK Tool

SILENTTRINITY (S0692)

ShareXLinkedInRedditHN

[SILENTTRINITY](https://attack.mitre.org/software/S0692) is an open source remote administration and post-exploitation framework primarily written in Python that includes stagers written in Powershell, C, and Boo. [SILENTTRINITY](https://attack.mitre.org/software/S0692) was used in a 2019 campaign against Croatian government agencies by unidentified cyber actors.(Citation: GitHub SILENTTRINITY March 2022)(Citation: Security Affairs SILENTTRINITY July 2019)

Platforms: Windows

▪Techniques implemented (53)

T1552.006Group Policy PreferencesT1620Reflective Code LoadingT1069.002Domain GroupsT1105Ingress Tool TransferT1546.001Change Default File AssociationT1115Clipboard DataT1070Indicator RemovalT1003.001LSASS MemoryT1135Network Share DiscoveryT1564.003Hidden WindowT1543.003Windows ServiceT1069.001Local GroupsT1685Disable or Modify ToolsT1113Screen CaptureT1047Windows Management InstrumentationT1055Process InjectionT1112Modify RegistryT1124System Time DiscoveryT1546.003Windows Management Instrumentation Event SubscriptionT1134.001Token Impersonation/TheftT1556Modify Authentication ProcessT1012Query RegistryT1689Downgrade AttackT1087.002Domain AccountT1018Remote System DiscoveryT1690Prevent Command History LoggingT1070.004File DeletionT1134.003Make and Impersonate TokenT1059.006PythonT1046Network Service DiscoveryT1059.001PowerShellT1555.003Credentials from Web BrowsersT1106Native APIT1558.003KerberoastingT1546.015Component Object Model HijackingT1041Exfiltration Over C2 ChannelT1555.004Windows Credential ManagerT1021.003Distributed Component Object ModelT1083File and Directory DiscoveryT1680Local Storage DiscoveryT1548.002Bypass User Account ControlT1559.001Component Object ModelT1059.003Windows Command ShellT1010Application Window DiscoveryT1021.006Windows Remote ManagementT1547.001Registry Run Keys / Startup FolderT1057Process DiscoveryT1056.002GUI Input CaptureT1056.001KeyloggingT1033System Owner/User DiscoveryT1518.001Security Software DiscoveryT1082System Information DiscoveryT1007System Service Discovery
S0692on MITRE ATT&CK →

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.