1. RootkitInstallation: MissingDriverLoad
2. RootkitInstallation: LoadAndCallImage
3. RootkitInstallation: DriverSupersede
4. RootkitInstallation: ChangeDrvPath
5. Invasion: Runner
6. Invasion: RawDisk
7. Invasion: PhysicalMemory
8. Invasion: FileDrop
9. Invasion: DebugControl
10. Injection: SetWinEventHook
11. Injection: SetWindowsHookEx
12. Injection: SetThreadContext
13. Injection: Services
14. Injection: ProcessInject
15. Injection: KnownDlls
16. Injection: DupHandles
17. Injection: CreateRemoteThread
18. Injection: APC dll injection
19. Injection: AdvancedProcessTermination
20. InfoSend: ICMP Test
21. InfoSend: DNS Test
22. Impersonation: OLE automation
23. Impersonation: ExplorerAsParent
24. Impersonation: DDE
25. Impersonation: Coat
26. Impersonation: BITS
27. Hijacking: WinlogonNotify
28. Hijacking: Userinit
29. Hijacking: UIHost
30. Hijacking: SupersedeServiceDll
31. Hijacking: StartupPrograms
32. Hijacking: ChangeDebuggerPath
33. Hijacking: AppinitDlls
34. Hijacking: ActiveDesktop