← LibraryTechnique entry
CVE-ETERNALBLUEInitial Access
EternalBlue (MS17-010 / CVE-2017-0144)
SMBv1 pre-auth heap overflow — WannaCry / NotPetya propagation engine; still works on unpatched legacy networks.
§ Where this technique fits
CVE-ETERNALBLUE is catalogued under the Initial Access tactic of the offensive-security kill-chain. It appears in 2 approved dossiers in the registry, typically at step 3.5 on average.
§ Dossiers chaining this technique
- step 2 / 5
EternalBlue (MS17-010) → SMBv1 wormable spread
Unpatched Windows 7 / Server 2008 with SMBv1 enabled — pre-auth kernel RCE. Used by WannaCry / NotPetya in 2017, still found on enclave / industrial networks.
- step 5 / 6
Trusted updater hijack → wormable destructive payload (NotPetya / M.E.Doc)
Compromise a niche third-party vendor (regional tax software, niche industry tooling). Push a malicious update; every customer auto-installs it. Payload spreads via SMB + Mimikatz, wipes drives.
§ What commonly comes next
- 01Command and Scripting Interpreterseen 1×T1059 · Execution
- 02Data Destructionseen 1×T1485 · Impact