Skip to content

Techniques overview

A runtime is a list of technique steps applied in order. Techniques are split into three categories (TechniqueDef.category):

  • Preparation — modifies the current process state (e.g. patches AMSI) but never runs a payload.
  • Execution — runs a decrypted payload; only these take params.payload.
  • Control — orchestrates the chain (living_off_the_land, sleep).

A step only continues if the loader gets control back, so a terminal step (reflective_loading of a PE executable, dotnet_hosting) must be the last one; src/plan/validate.rs enforces it. Everything else chains.

Every technique fragment calls the stub’s nt_* helpers (src/engine/syscalls.rs: nt_alloc_vm, nt_write_vm, nt_read_vm, nt_protect_vm, nt_create_thread_ex, nt_wait_for_single_object, nt_get_context_thread, …) and never the Win32 APIs directly. See Syscall layer.

The registry (src/techniques/mod.rs) is metadata-only; inspect it with picaro techniques list, picaro techniques show <name> (a styled page that pages long documents full-screen; --raw prints the Markdown verbatim) and picaro techniques validate. Adding one: Adding a technique.

TechniqueCategoryATT&CKStabilitySummary
patch_amsipreparationT1562.001stablePatches AmsiScanBuffer in the current process so it always returns clean, disabling AMSI for in-process callers.
patch_etwpreparationT1562.006stableOverwrites the ETW event-writing exports in the current process so it emits no ETW events.
anti_debugpreparationT1622stableChecks the current process for signs of a debugger and, by default, aborts so the payload never runs.
sleep_obfuscationpreparationT1027experimentalEncrypts the executable image region for the duration of a sleep (ekko variant), so a memory scanner sees RC4 ciphertext.
bouncerpreparationT1497.001, T1614.001stableGates the payload on declared host checks (hostname, locale, uptime, RAM, VM/sandbox) and aborts the pipeline when they fail.
unhook_ntdllpreparationT1562.001stableRestores the loaded ntdll.dll’s code section from a clean on-disk copy (base fixups applied on x86), removing userland hooks.
guardrailpreparationT1480stableAborts the chain after a deadline or a run-count, so the payload does not run out of scope.
process_hollowingexecutionT1055.012experimentalRuns the payload inside a suspended, legitimate process (svchost.exe by default).
process_ghostingexecutionT1055.012experimentalMaps a full PE image from a delete-on-close file, so the payload runs with no backing file on disk.
reflective_loadingexecutionT1620experimentalMaps the payload into the current process (manual mapping), resolves imports and relocations, and runs its entry point.
dotnet_hostingexecutionT1620experimentalHosts the CLR in the stub and runs a managed (format: dotnet) assembly from memory.
execution_callbacksexecutionT1106, T1620stableRuns the payload as the callback of a legitimate Windows enumeration API (CertEnumSystemStoreLocation) in the current process, from no dedicated thread.
module_stompingexecutionT1055stableOverwrites a legitimate signed DLL’s code section with the payload and runs it from there.
dll_hollowingexecutionT1574.002experimentalLoads a signed DLL, hollows its code section with the payload and runs it from there, restoring the original bytes so the module keeps proxying its exports.
fibersexecutionT1055stableRuns the payload on a fiber of the loader’s own thread; control returns to the loader when it does.
early_birdexecutionT1055.004experimentalCreates the target suspended, writes the payload and queues an APC before the target’s loader runs, so the payload executes first.
pe_injectionexecutionT1055.002experimentalMaps a full PE image into a freshly created suspended process and starts it at its entry point, without unmapping the target’s own image. TLS is provisioned and the payload’s DLL_PROCESS_ATTACH callbacks run before the entry thread (runtime verification pending).
thread_hijackingexecutionT1055.003experimentalSuspends a thread that already exists in a running process, points its instruction pointer at the payload and resumes it — no thread is ever created.
living_off_the_landcontrolT1218, T1105stableLaunches a signed Microsoft binary (or any command) as a chain step, resolving a bare name against System32 and quoting its arguments.
sleepcontrolT1497stableWaits a number of milliseconds between two steps of a runtime chain.
network_stagercontrolT1105, T1071experimentalFetches a payload over the network at run time (http/https/ftp via certutil, scp) and hands it to the next Execution step, optionally decrypting it first.
self_deletionpreparationT1070.004stableRenames the running image into an alternate data stream of its own path (default) or deletes it after exit, so the loader’s bytes leave the file the path names.
timestompingpreparationT1070.006stableCopies a reference file’s creation/access/write times onto the artifact, so it looks like it has been on disk longer.
stack_spoofingpreparationT1036stableFabricates the top of the stack for every syscall, so a stack walk during the call sees ntdll code addresses instead of the loader.
ppid_spoofingcontrolT1134.004stableLaunches a process whose recorded parent is a different, legitimate process.