/
cyberknowledge
/
attack_chains
Обзор
Документация
Войти
/
cyberknowledge
/
attack_chains
Код
Запросы
0
Задачи
Вики
Пакеты
0
Релизы
0
Аналитика
master
samples/step_sample_100.jsonl
100 строк
49 KB
Codex Agent
Document Postgres+S3 storage model and refresh public dataset stats.
22 июл 2026, 13:25
22 июл 2026, 13:25
b8ae70b
Код
Авторство
О чём код?
{"chain_id": "db0db10144c9564abcf814f3213acc85", "source_id": "malpedia_family_reports", "order": 1, "label": "Technique T1071.001", "narrative": "According to PcRisk, Research shows that the OceanLotus 'backdoor' targets MacOS computers. Cyber criminals behind this backdoor have already used this malware to attack human rights and media organizations, some research institutes, and maritime construction companies.\r\n\r\nThe OceanLotus backdoor is distributed via a fake Adobe Flash Player installer and a malicious Word document (it is likely that threat authors distribute the document via malspam emails).", "mitre_attack": [{"technique_id": "T1071.001"}]} {"chain_id": "db0db10144c9564abcf814f3213acc85", "source_id": "malpedia_family_reports", "order": 2, "label": "Technique T1204.002", "narrative": "According to PcRisk, Research shows that the OceanLotus 'backdoor' targets MacOS computers. Cyber criminals behind this backdoor have already used this malware to attack human rights and media organizations, some research institutes, and maritime construction companies.\r\n\r\nThe OceanLotus backdoor is distributed via a fake Adobe Flash Player installer and a malicious Word document (it is likely that threat authors distribute the document via malspam emails).", "mitre_attack": [{"technique_id": "T1204.002"}]} {"chain_id": "7740592da02b06f2131baa20be3ea72d", "source_id": "awesome_attack_attribution", "order": 1, "label": "Technique T1595", "narrative": "Tools associated with groups (partial)", "mitre_attack": [{"technique_id": "T1595"}]} {"chain_id": "7740592da02b06f2131baa20be3ea72d", "source_id": "awesome_attack_attribution", "order": 2, "label": "Technique T1071", "narrative": "Tools associated with groups (partial)", "mitre_attack": [{"technique_id": "T1071"}]} {"chain_id": "7740592da02b06f2131baa20be3ea72d", "source_id": "awesome_attack_attribution", "order": 3, "label": "Technique T1059", "narrative": "Tools associated with groups (partial)", "mitre_attack": [{"technique_id": "T1059"}]} {"chain_id": "03275c10767648014ce742f211025a70", "source_id": "mthcht_threatintel_reports", "order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network/)\n", "mitre_attack": [{"technique_id": "T1595"}]} {"chain_id": "03275c10767648014ce742f211025a70", "source_id": "mthcht_threatintel_reports", "order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network/)\n", "mitre_attack": [{"technique_id": "T1071"}]} {"chain_id": "03275c10767648014ce742f211025a70", "source_id": "mthcht_threatintel_reports", "order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network/)\n", "mitre_attack": [{"technique_id": "T1059"}]} {"chain_id": "beae9b71b9a1b28b4c9464de28a02d3d", "source_id": "mthcht_threatintel_reports", "order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://bin.re/blog/the-dga-of-ranbyus/)\n", "mitre_attack": [{"technique_id": "T1595"}]} {"chain_id": "beae9b71b9a1b28b4c9464de28a02d3d", "source_id": "mthcht_threatintel_reports", "order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://bin.re/blog/the-dga-of-ranbyus/)\n", "mitre_attack": [{"technique_id": "T1071"}]} {"chain_id": "beae9b71b9a1b28b4c9464de28a02d3d", "source_id": "mthcht_threatintel_reports", "order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://bin.re/blog/the-dga-of-ranbyus/)\n", "mitre_attack": [{"technique_id": "T1059"}]} {"chain_id": "247d8f6abbede11e49a8e8074d1c2e42", "source_id": "mthcht_threatintel_reports", "order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://anchorednarratives.substack.com/p/tracking-strongpity-with-yara)\n", "mitre_attack": [{"technique_id": "T1595"}]} {"chain_id": "247d8f6abbede11e49a8e8074d1c2e42", "source_id": "mthcht_threatintel_reports", "order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://anchorednarratives.substack.com/p/tracking-strongpity-with-yara)\n", "mitre_attack": [{"technique_id": "T1071"}]} {"chain_id": "247d8f6abbede11e49a8e8074d1c2e42", "source_id": "mthcht_threatintel_reports", "order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://anchorednarratives.substack.com/p/tracking-strongpity-with-yara)\n", "mitre_attack": [{"technique_id": "T1059"}]} {"chain_id": "89e1cb63d63c59582dea61942d90fbb7", "source_id": "misp_galaxy_relations", "order": 1, "label": "Technique T1106", "narrative": "T1106 ['attack-Linux:execution', 'attack-macOS:execution', 'attack-Windows:execution'] ['Module: Module Load', 'Process: OS API Execution'] ['Linux', 'macOS', 'Windows'] ['https://attack.mitre.org/techniques/T1106', 'https://developer.apple.com/documentation/coreservices', 'https://developer.apple.com/documentation/foundation', 'https://developer.apple.com/library/archive/documentation/MacOSX/Conc", "mitre_attack": [{"technique_id": "T1106"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/mitre-attack-pattern.json"}]} {"chain_id": "409b5b2ad8d600a750d1ad1e3ea36b7d", "source_id": "huntress_blog", "order": 1, "label": "Using Backup Utilities for Data Exfiltration", "narrative": "“Double extortion” attacks, often perpetrated by ransomware threat actors, include data exfiltration prior to file encryption. Huntress analysts have observed various means of data exfiltration, but recently observed the use of a legitimate backup application seen by others to be associated with a Noberus/ALPHV ransomware affiliate. Learn More", "mitre_attack": [{"technique_id": "T1041"}, {"technique_id": "T1486"}]} {"chain_id": "409b5b2ad8d600a750d1ad1e3ea36b7d", "source_id": "huntress_blog", "order": 2, "label": "Exposing Data Exfil: LOLBins, TTPs, and Binaries…Oh, My!", "narrative": "Threat actors often steal data during the course of their attacks. This is particularly true for ransomware threat actors, who do it before deploying file encryption in order to engage in “double extortion” activities. This activity can be difficult to detect, particularly if it’s not dissimilar to legitimate actions taken by system administrators. Learn More", "mitre_attack": [{"technique_id": "T1041"}, {"technique_id": "T1486"}]} {"chain_id": "409b5b2ad8d600a750d1ad1e3ea36b7d", "source_id": "huntress_blog", "order": 3, "label": "Can’t Touch This: Data Exfiltration via Finger", "narrative": "Threat actors frequently make use of native utilities during incidents. However, this blog post discusses a rarely-observed means of data exfiltration. Learn More", "mitre_attack": [{"technique_id": "T1041"}]} {"chain_id": "409b5b2ad8d600a750d1ad1e3ea36b7d", "source_id": "huntress_blog", "order": 4, "label": "Akira, LimeWire, and the Sour Taste of Data Exfiltration", "narrative": "A recent investigation uncovered an Akira affiliate abusing a website owned by file-sharing app LimeWire for data exfiltration. Here's how the attack unfolded. Learn More", "mitre_attack": [{"technique_id": "T1041"}]} {"chain_id": "1e2d630c01e9e0920d340b01aacd15aa", "source_id": "cisa_aa_catalog", "order": 1, "label": "Reconnaissance", "narrative": "ABB FLXEON Controllers: ABB FLXEON Controllers\nAn update is available that resolves a privately reported vulnerability in the product versions listed as affected in this advisory.\n\nFLXEON devices are not intended to be inter", "mitre_attack": [{"technique_id": "T1592"}]} {"chain_id": "1e2d630c01e9e0920d340b01aacd15aa", "source_id": "cisa_aa_catalog", "order": 2, "label": "Initial Access", "narrative": "ABB FLXEON Controllers: ABB FLXEON Controllers\nAn update is available that resolves a privately reported vulnerability in the product versions listed as affected in this advisory.\n\nFLXEON devices are not intended to be inter", "mitre_attack": [{"technique_id": "T1190"}]} {"chain_id": "1e2d630c01e9e0920d340b01aacd15aa", "source_id": "cisa_aa_catalog", "order": 3, "label": "Execution", "narrative": "ABB FLXEON Controllers: ABB FLXEON Controllers\nAn update is available that resolves a privately reported vulnerability in the product versions listed as affected in this advisory.\n\nFLXEON devices are not intended to be inter", "mitre_attack": [{"technique_id": "T1059"}]} {"chain_id": "1e2d630c01e9e0920d340b01aacd15aa", "source_id": "cisa_aa_catalog", "order": 4, "label": "Persistence", "narrative": "ABB FLXEON Controllers: ABB FLXEON Controllers\nAn update is available that resolves a privately reported vulnerability in the product versions listed as affected in this advisory.\n\nFLXEON devices are not intended to be inter", "mitre_attack": [{"technique_id": "T1078"}]} {"chain_id": "1e2d630c01e9e0920d340b01aacd15aa", "source_id": "cisa_aa_catalog", "order": 5, "label": "Impact", "narrative": "ABB FLXEON Controllers: ABB FLXEON Controllers\nAn update is available that resolves a privately reported vulnerability in the product versions listed as affected in this advisory.\n\nFLXEON devices are not intended to be inter", "mitre_attack": [{"technique_id": "T1486"}]} {"chain_id": "a7252263d6774e5c69b0bc8999ca2699", "source_id": "sigma_attack_stage_tags", "order": 1, "label": "Remote XSL Execution Via Msxsl.EXE", "narrative": "Detects the execution of the \"msxsl\" binary with an \"http\" keyword in the command line. This might indicate a potential remote execution of XSL files.", "mitre_attack": [{"technique_id": "T1220"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_sft_soc_raw_external_sigma\\windows\\process_creation\\proc_creation_win_msxsl_remote_execution.yml"}]} {"chain_id": "8dc39d558f1178c68b228d2360cadae7", "source_id": "awesome_attack_attribution", "order": 1, "label": "Technique T1595", "narrative": "SOC - DCsync explained", "mitre_attack": [{"technique_id": "T1595"}]} {"chain_id": "8dc39d558f1178c68b228d2360cadae7", "source_id": "awesome_attack_attribution", "order": 2, "label": "Technique T1071", "narrative": "SOC - DCsync explained", "mitre_attack": [{"technique_id": "T1071"}]} {"chain_id": "8dc39d558f1178c68b228d2360cadae7", "source_id": "awesome_attack_attribution", "order": 3, "label": "Technique T1059", "narrative": "SOC - DCsync explained", "mitre_attack": [{"technique_id": "T1059"}]} {"chain_id": "3e61d2b5132d24c3458935e5f906e1d6", "source_id": "awesome_attack_attribution", "order": 1, "label": "Technique T1595", "narrative": "Conferences channel - Preludeorg", "mitre_attack": [{"technique_id": "T1595"}]} {"chain_id": "3e61d2b5132d24c3458935e5f906e1d6", "source_id": "awesome_attack_attribution", "order": 2, "label": "Technique T1071", "narrative": "Conferences channel - Preludeorg", "mitre_attack": [{"technique_id": "T1071"}]} {"chain_id": "3e61d2b5132d24c3458935e5f906e1d6", "source_id": "awesome_attack_attribution", "order": 3, "label": "Technique T1059", "narrative": "Conferences channel - Preludeorg", "mitre_attack": [{"technique_id": "T1059"}]} {"chain_id": "79b41cc2def860a7c00cb20f16eaada5", "source_id": "crowdstrike_adversary", "order": 1, "label": "Technique T1005", "narrative": "[Inception](https://attack.mitre.org/groups/G0100) is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.(Citation: Unit 42 Inception November 2018)(Citation: Symantec Inception Framework March 2018)(Citation: Kaspersky Cloud Atlas December 2014)", "mitre_attack": [{"technique_id": "T1005"}]} {"chain_id": "79b41cc2def860a7c00cb20f16eaada5", "source_id": "crowdstrike_adversary", "order": 2, "label": "Technique T1027.013", "narrative": "[Inception](https://attack.mitre.org/groups/G0100) is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.(Citation: Unit 42 Inception November 2018)(Citation: Symantec Inception Framework March 2018)(Citation: Kaspersky Cloud Atlas December 2014)", "mitre_attack": [{"technique_id": "T1027.013"}]} {"chain_id": "79b41cc2def860a7c00cb20f16eaada5", "source_id": "crowdstrike_adversary", "order": 3, "label": "Technique T1057", "narrative": "[Inception](https://attack.mitre.org/groups/G0100) is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.(Citation: Unit 42 Inception November 2018)(Citation: Symantec Inception Framework March 2018)(Citation: Kaspersky Cloud Atlas December 2014)", "mitre_attack": [{"technique_id": "T1057"}]} {"chain_id": "79b41cc2def860a7c00cb20f16eaada5", "source_id": "crowdstrike_adversary", "order": 4, "label": "Technique T1059.001", "narrative": "[Inception](https://attack.mitre.org/groups/G0100) is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.(Citation: Unit 42 Inception November 2018)(Citation: Symantec Inception Framework March 2018)(Citation: Kaspersky Cloud Atlas December 2014)", "mitre_attack": [{"technique_id": "T1059.001"}]} {"chain_id": "79b41cc2def860a7c00cb20f16eaada5", "source_id": "crowdstrike_adversary", "order": 5, "label": "Technique T1059.005", "narrative": "[Inception](https://attack.mitre.org/groups/G0100) is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.(Citation: Unit 42 Inception November 2018)(Citation: Symantec Inception Framework March 2018)(Citation: Kaspersky Cloud Atlas December 2014)", "mitre_attack": [{"technique_id": "T1059.005"}]} {"chain_id": "79b41cc2def860a7c00cb20f16eaada5", "source_id": "crowdstrike_adversary", "order": 6, "label": "Technique T1069.002", "narrative": "[Inception](https://attack.mitre.org/groups/G0100) is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.(Citation: Unit 42 Inception November 2018)(Citation: Symantec Inception Framework March 2018)(Citation: Kaspersky Cloud Atlas December 2014)", "mitre_attack": [{"technique_id": "T1069.002"}]} {"chain_id": "79b41cc2def860a7c00cb20f16eaada5", "source_id": "crowdstrike_adversary", "order": 7, "label": "Technique T1071.001", "narrative": "[Inception](https://attack.mitre.org/groups/G0100) is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.(Citation: Unit 42 Inception November 2018)(Citation: Symantec Inception Framework March 2018)(Citation: Kaspersky Cloud Atlas December 2014)", "mitre_attack": [{"technique_id": "T1071.001"}]} {"chain_id": "79b41cc2def860a7c00cb20f16eaada5", "source_id": "crowdstrike_adversary", "order": 8, "label": "Technique T1082", "narrative": "[Inception](https://attack.mitre.org/groups/G0100) is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.(Citation: Unit 42 Inception November 2018)(Citation: Symantec Inception Framework March 2018)(Citation: Kaspersky Cloud Atlas December 2014)", "mitre_attack": [{"technique_id": "T1082"}]} {"chain_id": "79b41cc2def860a7c00cb20f16eaada5", "source_id": "crowdstrike_adversary", "order": 9, "label": "Technique T1083", "narrative": "[Inception](https://attack.mitre.org/groups/G0100) is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.(Citation: Unit 42 Inception November 2018)(Citation: Symantec Inception Framework March 2018)(Citation: Kaspersky Cloud Atlas December 2014)", "mitre_attack": [{"technique_id": "T1083"}]} {"chain_id": "79b41cc2def860a7c00cb20f16eaada5", "source_id": "crowdstrike_adversary", "order": 10, "label": "Technique T1090.003", "narrative": "[Inception](https://attack.mitre.org/groups/G0100) is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.(Citation: Unit 42 Inception November 2018)(Citation: Symantec Inception Framework March 2018)(Citation: Kaspersky Cloud Atlas December 2014)", "mitre_attack": [{"technique_id": "T1090.003"}]} {"chain_id": "79b41cc2def860a7c00cb20f16eaada5", "source_id": "crowdstrike_adversary", "order": 11, "label": "Technique T1102", "narrative": "[Inception](https://attack.mitre.org/groups/G0100) is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.(Citation: Unit 42 Inception November 2018)(Citation: Symantec Inception Framework March 2018)(Citation: Kaspersky Cloud Atlas December 2014)", "mitre_attack": [{"technique_id": "T1102"}]} {"chain_id": "79b41cc2def860a7c00cb20f16eaada5", "source_id": "crowdstrike_adversary", "order": 12, "label": "Technique T1203", "narrative": "[Inception](https://attack.mitre.org/groups/G0100) is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.(Citation: Unit 42 Inception November 2018)(Citation: Symantec Inception Framework March 2018)(Citation: Kaspersky Cloud Atlas December 2014)", "mitre_attack": [{"technique_id": "T1203"}]} {"chain_id": "79b41cc2def860a7c00cb20f16eaada5", "source_id": "crowdstrike_adversary", "order": 13, "label": "Technique T1204.002", "narrative": "[Inception](https://attack.mitre.org/groups/G0100) is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.(Citation: Unit 42 Inception November 2018)(Citation: Symantec Inception Framework March 2018)(Citation: Kaspersky Cloud Atlas December 2014)", "mitre_attack": [{"technique_id": "T1204.002"}]} {"chain_id": "79b41cc2def860a7c00cb20f16eaada5", "source_id": "crowdstrike_adversary", "order": 14, "label": "Technique T1218.005", "narrative": "[Inception](https://attack.mitre.org/groups/G0100) is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.(Citation: Unit 42 Inception November 2018)(Citation: Symantec Inception Framework March 2018)(Citation: Kaspersky Cloud Atlas December 2014)", "mitre_attack": [{"technique_id": "T1218.005"}]} {"chain_id": "79b41cc2def860a7c00cb20f16eaada5", "source_id": "crowdstrike_adversary", "order": 15, "label": "Technique T1218.010", "narrative": "[Inception](https://attack.mitre.org/groups/G0100) is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.(Citation: Unit 42 Inception November 2018)(Citation: Symantec Inception Framework March 2018)(Citation: Kaspersky Cloud Atlas December 2014)", "mitre_attack": [{"technique_id": "T1218.010"}]} {"chain_id": "79b41cc2def860a7c00cb20f16eaada5", "source_id": "crowdstrike_adversary", "order": 16, "label": "Technique T1221", "narrative": "[Inception](https://attack.mitre.org/groups/G0100) is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.(Citation: Unit 42 Inception November 2018)(Citation: Symantec Inception Framework March 2018)(Citation: Kaspersky Cloud Atlas December 2014)", "mitre_attack": [{"technique_id": "T1221"}]} {"chain_id": "79b41cc2def860a7c00cb20f16eaada5", "source_id": "crowdstrike_adversary", "order": 17, "label": "Technique T1518", "narrative": "[Inception](https://attack.mitre.org/groups/G0100) is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.(Citation: Unit 42 Inception November 2018)(Citation: Symantec Inception Framework March 2018)(Citation: Kaspersky Cloud Atlas December 2014)", "mitre_attack": [{"technique_id": "T1518"}]} {"chain_id": "79b41cc2def860a7c00cb20f16eaada5", "source_id": "crowdstrike_adversary", "order": 18, "label": "Technique T1547.001", "narrative": "[Inception](https://attack.mitre.org/groups/G0100) is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.(Citation: Unit 42 Inception November 2018)(Citation: Symantec Inception Framework March 2018)(Citation: Kaspersky Cloud Atlas December 2014)", "mitre_attack": [{"technique_id": "T1547.001"}]} {"chain_id": "79b41cc2def860a7c00cb20f16eaada5", "source_id": "crowdstrike_adversary", "order": 19, "label": "Technique T1555.003", "narrative": "[Inception](https://attack.mitre.org/groups/G0100) is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.(Citation: Unit 42 Inception November 2018)(Citation: Symantec Inception Framework March 2018)(Citation: Kaspersky Cloud Atlas December 2014)", "mitre_attack": [{"technique_id": "T1555.003"}]} {"chain_id": "79b41cc2def860a7c00cb20f16eaada5", "source_id": "crowdstrike_adversary", "order": 20, "label": "Technique T1566.001", "narrative": "[Inception](https://attack.mitre.org/groups/G0100) is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.(Citation: Unit 42 Inception November 2018)(Citation: Symantec Inception Framework March 2018)(Citation: Kaspersky Cloud Atlas December 2014)", "mitre_attack": [{"technique_id": "T1566.001"}]} {"chain_id": "3faa28b2f1ebdaf9dd8862e1d864e7f9", "source_id": "mitre_car_analytics", "order": 1, "label": "CAR T1546", "narrative": "---\ntitle: Debuggers for Accessibility Applications\nsubmission_date: 2014/11/21\ninformation_domain: Host\nplatforms:\n - Windows\nsubtypes:\n - Process\nanalytic_types:\n - TTP\ncontributors:\n - MITRE\nid: CAR-2014-11-003\ndescription: |\n The Windows Registry location `HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options` allows for parameters to be set for applications durin", "mitre_attack": [{"technique_id": "T1546"}]} {"chain_id": "3faa28b2f1ebdaf9dd8862e1d864e7f9", "source_id": "mitre_car_analytics", "order": 2, "label": "CAR T1546.008", "narrative": "---\ntitle: Debuggers for Accessibility Applications\nsubmission_date: 2014/11/21\ninformation_domain: Host\nplatforms:\n - Windows\nsubtypes:\n - Process\nanalytic_types:\n - TTP\ncontributors:\n - MITRE\nid: CAR-2014-11-003\ndescription: |\n The Windows Registry location `HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options` allows for parameters to be set for applications durin", "mitre_attack": [{"technique_id": "T1546.008"}]} {"chain_id": "a6f41c801a18cd38ada55f47c2321f56", "source_id": "mthcht_threatintel_reports", "order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://attack.mitre.org/groups/G0129)\n", "mitre_attack": [{"technique_id": "T1595"}]} {"chain_id": "a6f41c801a18cd38ada55f47c2321f56", "source_id": "mthcht_threatintel_reports", "order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://attack.mitre.org/groups/G0129)\n", "mitre_attack": [{"technique_id": "T1071"}]} {"chain_id": "a6f41c801a18cd38ada55f47c2321f56", "source_id": "mthcht_threatintel_reports", "order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://attack.mitre.org/groups/G0129)\n", "mitre_attack": [{"technique_id": "T1059"}]} {"chain_id": "6717fd9c86dc35e9d837c7a8134c0aa1", "source_id": "awesome_attack_attribution", "order": 1, "label": "Technique T1595", "narrative": "joesandbox", "mitre_attack": [{"technique_id": "T1595"}]} {"chain_id": "6717fd9c86dc35e9d837c7a8134c0aa1", "source_id": "awesome_attack_attribution", "order": 2, "label": "Technique T1071", "narrative": "joesandbox", "mitre_attack": [{"technique_id": "T1071"}]} {"chain_id": "6717fd9c86dc35e9d837c7a8134c0aa1", "source_id": "awesome_attack_attribution", "order": 3, "label": "Technique T1059", "narrative": "joesandbox", "mitre_attack": [{"technique_id": "T1059"}]} {"chain_id": "2163a861593ad0a6fd0a17c0c9e2d04e", "source_id": "misp_galaxy_relations", "order": 1, "label": "Technique T1584", "narrative": "Florian Roth (Nextron Systems) 2018-01-23 ['Admin activity (especially in /tmp folders)', 'Crazy web applications'] lnx_auditd_susp_exe_folders.yml medium No established category linux ['Internal Research', 'https://github.com/SigmaHQ/sigma/tree/master/rules/linux/auditd/syscall/lnx_auditd_susp_exe_folders.yml'] ['attack.t1587', 'attack.t1584', 'attack.resource-development']", "mitre_attack": [{"technique_id": "T1584"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/sigma-rules.json"}]} {"chain_id": "2163a861593ad0a6fd0a17c0c9e2d04e", "source_id": "misp_galaxy_relations", "order": 2, "label": "Technique T1587", "narrative": "Florian Roth (Nextron Systems) 2018-01-23 ['Admin activity (especially in /tmp folders)', 'Crazy web applications'] lnx_auditd_susp_exe_folders.yml medium No established category linux ['Internal Research', 'https://github.com/SigmaHQ/sigma/tree/master/rules/linux/auditd/syscall/lnx_auditd_susp_exe_folders.yml'] ['attack.t1587', 'attack.t1584', 'attack.resource-development']", "mitre_attack": [{"technique_id": "T1587"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/sigma-rules.json"}]} {"chain_id": "fef74937052f072fd4fca934e6a139e2", "source_id": "sigma_attack_stage_tags", "order": 1, "label": "HackTool - RemoteKrbRelay Execution", "narrative": "Detects the use of RemoteKrbRelay, a Kerberos relaying tool via CommandLine flags and PE metadata.\n", "mitre_attack": [{"technique_id": "T1558.003"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_sft_soc_raw_external_sigma\\windows\\process_creation\\proc_creation_win_hktl_krbrelay_remote.yml"}]} {"chain_id": "9cfdfe66ce1c867d8fc2ecbe62c2aeef", "source_id": "mordor_metadata", "order": 1, "label": "Technique T1059", "narrative": "title: RDP TaskManager LSASS Dump\nid: SDWIN-191027055035\ncontributors:\n- Roberto Rodriguez @Cyb3rWard0g\ncreation_date: 2019/10/27\nmodification_date: 2020/09/21\nplatform:\n- Windows\ntype: atomic\ntags:\n - RDP Interactive\ndescription: This dataset represents adversaries using RDP and task manager interactively and dump the memory space of lsass.\nattack_mappings:\n - technique: T1003\n sub-technique", "mitre_attack": [{"technique_id": "T1059"}], "evidence_refs": [{"project": "threat_logs", "ref": "OTRF/Security-Datasets"}]} {"chain_id": "9cfdfe66ce1c867d8fc2ecbe62c2aeef", "source_id": "mordor_metadata", "order": 2, "label": "Technique T1003", "narrative": "title: RDP TaskManager LSASS Dump\nid: SDWIN-191027055035\ncontributors:\n- Roberto Rodriguez @Cyb3rWard0g\ncreation_date: 2019/10/27\nmodification_date: 2020/09/21\nplatform:\n- Windows\ntype: atomic\ntags:\n - RDP Interactive\ndescription: This dataset represents adversaries using RDP and task manager interactively and dump the memory space of lsass.\nattack_mappings:\n - technique: T1003\n sub-technique", "mitre_attack": [{"technique_id": "T1003"}], "evidence_refs": [{"project": "threat_logs", "ref": "OTRF/Security-Datasets"}]} {"chain_id": "9cfdfe66ce1c867d8fc2ecbe62c2aeef", "source_id": "mordor_metadata", "order": 3, "label": "Technique T1021", "narrative": "title: RDP TaskManager LSASS Dump\nid: SDWIN-191027055035\ncontributors:\n- Roberto Rodriguez @Cyb3rWard0g\ncreation_date: 2019/10/27\nmodification_date: 2020/09/21\nplatform:\n- Windows\ntype: atomic\ntags:\n - RDP Interactive\ndescription: This dataset represents adversaries using RDP and task manager interactively and dump the memory space of lsass.\nattack_mappings:\n - technique: T1003\n sub-technique", "mitre_attack": [{"technique_id": "T1021"}], "evidence_refs": [{"project": "threat_logs", "ref": "OTRF/Security-Datasets"}]} {"chain_id": "cc84d9d75c27d43ba69155aa3313079c", "source_id": "sigma_attack_stage_tags", "order": 1, "label": "User Added To Group With CA Policy Modification Access", "narrative": "Monitor and alert on group membership additions of groups that have CA policy modification access", "mitre_attack": [{"technique_id": "T1548"}, {"technique_id": "T1556"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_sft_soc_raw_external_sigma\\cloud\\azure\\audit_logs\\azure_group_user_addition_ca_modification.yml"}]} {"chain_id": "6e78d4f811b72c4df77d4e5f068cff34", "source_id": "mthcht_threatintel_reports", "order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://community.riskiq.com/article/8830dd9c)\n", "mitre_attack": [{"technique_id": "T1595"}]} {"chain_id": "6e78d4f811b72c4df77d4e5f068cff34", "source_id": "mthcht_threatintel_reports", "order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://community.riskiq.com/article/8830dd9c)\n", "mitre_attack": [{"technique_id": "T1071"}]} {"chain_id": "6e78d4f811b72c4df77d4e5f068cff34", "source_id": "mthcht_threatintel_reports", "order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://community.riskiq.com/article/8830dd9c)\n", "mitre_attack": [{"technique_id": "T1059"}]} {"chain_id": "3e51e476c44d33e5174e21431f66d9b8", "source_id": "aptnotes_stix", "order": 1, "label": "Technique T1566", "narrative": "APT report by AhnLab (2014)", "mitre_attack": [{"technique_id": "T1566"}]} {"chain_id": "3e51e476c44d33e5174e21431f66d9b8", "source_id": "aptnotes_stix", "order": 2, "label": "Technique T1059", "narrative": "APT report by AhnLab (2014)", "mitre_attack": [{"technique_id": "T1059"}]} {"chain_id": "3e51e476c44d33e5174e21431f66d9b8", "source_id": "aptnotes_stix", "order": 3, "label": "Technique T1071", "narrative": "APT report by AhnLab (2014)", "mitre_attack": [{"technique_id": "T1071"}]} {"chain_id": "fa7758f0377456ebfa86046879424414", "source_id": "misp_galaxy_relations", "order": 1, "label": "Technique T1547.001", "narrative": "Florian Roth (Nextron Systems) 2021-03-05 ['Unknown'] registry_set_vbs_payload_stored.yml high registry_set windows ['https://www.microsoft.com/security/blog/2021/03/04/goldmax-goldfinder-sibot-analyzing-nobelium-malware/', 'https://github.com/SigmaHQ/sigma/tree/master/rules/windows/registry/registry_set/registry_set_vbs_payload_stored.yml'] ['attack.privilege-escalation', 'attack.persistence', 'a", "mitre_attack": [{"technique_id": "T1547.001"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/sigma-rules.json"}]} {"chain_id": "543eb7f3e55d27e65b6f999d8a3a7d33", "source_id": "sigma_attack_stage_tags", "order": 1, "label": "OneNote.EXE Execution of Malicious Embedded Scripts", "narrative": "Detects the execution of malicious OneNote documents that contain embedded scripts.\nWhen a user clicks on a OneNote attachment and then on the malicious link inside the \".one\" file, it exports and executes the malicious embedded script from specific directories.\n", "mitre_attack": [{"technique_id": "T1218.001"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_sft_soc_raw_external_sigma\\windows\\process_creation\\proc_creation_win_office_onenote_embedded_script_execution.yml"}]} {"chain_id": "f6b6f115bff8eaf5e9021729fc741458", "source_id": "redstack_vault_chains", "order": 1, "label": "Exploit-Apache-mod_rewrite-Improper-Escaping", "narrative": "Exploit improper output escaping in Apache HTTP Server's mod_rewrite module to map crafted URLs to unintended but permitted filesystem locations, enabling source code disclosure or code execution.", "mitre_attack": []} {"chain_id": "13909eb80176cda9db4fb113eab16fb6", "source_id": "mthcht_threatintel_reports", "order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://community.riskiq.com/article/56d50011)\n", "mitre_attack": [{"technique_id": "T1595"}]} {"chain_id": "13909eb80176cda9db4fb113eab16fb6", "source_id": "mthcht_threatintel_reports", "order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://community.riskiq.com/article/56d50011)\n", "mitre_attack": [{"technique_id": "T1071"}]} {"chain_id": "13909eb80176cda9db4fb113eab16fb6", "source_id": "mthcht_threatintel_reports", "order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://community.riskiq.com/article/56d50011)\n", "mitre_attack": [{"technique_id": "T1059"}]} {"chain_id": "6005d88bb0b2e9e28723e98ee2de884c", "source_id": "misp_galaxy_relations", "order": 1, "label": "Technique T1045", "narrative": "MOB-T1045 ['mitre-mobile-attack:mobile-attack:app-delivery-via-authorized-app-store'] ['Android', 'iOS'] ['https://attack.mitre.org/mobile/index.php/Technique/MOB-T1045', 'https://jon.oberheide.org/files/summercon12-bouncer.pdf']", "mitre_attack": [{"technique_id": "T1045"}], "evidence_refs": [{"project": "github", "ref": "MISP/misp-galaxy/clusters/mitre-mobile-attack-attack-pattern.json"}]} {"chain_id": "506e8377e1398c85224fb44c0546cae8", "source_id": "mitre_attack_stix_campaigns", "order": 1, "label": "Technique T1053.005", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1053.005"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]} {"chain_id": "506e8377e1398c85224fb44c0546cae8", "source_id": "mitre_attack_stix_campaigns", "order": 2, "label": "Technique T1059.001", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1059.001"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]} {"chain_id": "506e8377e1398c85224fb44c0546cae8", "source_id": "mitre_attack_stix_campaigns", "order": 3, "label": "Technique T1059.005", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1059.005"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]} {"chain_id": "506e8377e1398c85224fb44c0546cae8", "source_id": "mitre_attack_stix_campaigns", "order": 4, "label": "Technique T1071.001", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1071.001"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]} {"chain_id": "506e8377e1398c85224fb44c0546cae8", "source_id": "mitre_attack_stix_campaigns", "order": 5, "label": "Technique T1074.001", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1074.001"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]} {"chain_id": "506e8377e1398c85224fb44c0546cae8", "source_id": "mitre_attack_stix_campaigns", "order": 6, "label": "Technique T1082", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1082"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]} {"chain_id": "506e8377e1398c85224fb44c0546cae8", "source_id": "mitre_attack_stix_campaigns", "order": 7, "label": "Technique T1132.001", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1132.001"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]} {"chain_id": "506e8377e1398c85224fb44c0546cae8", "source_id": "mitre_attack_stix_campaigns", "order": 8, "label": "Technique T1140", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1140"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]} {"chain_id": "506e8377e1398c85224fb44c0546cae8", "source_id": "mitre_attack_stix_campaigns", "order": 9, "label": "Technique T1217", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1217"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]} {"chain_id": "506e8377e1398c85224fb44c0546cae8", "source_id": "mitre_attack_stix_campaigns", "order": 10, "label": "Technique T1518", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1518"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]} {"chain_id": "506e8377e1398c85224fb44c0546cae8", "source_id": "mitre_attack_stix_campaigns", "order": 11, "label": "Technique T1555.003", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1555.003"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]} {"chain_id": "506e8377e1398c85224fb44c0546cae8", "source_id": "mitre_attack_stix_campaigns", "order": 12, "label": "Technique T1555.004", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1555.004"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]} {"chain_id": "506e8377e1398c85224fb44c0546cae8", "source_id": "mitre_attack_stix_campaigns", "order": 13, "label": "Technique T1584.004", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1584.004"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]} {"chain_id": "506e8377e1398c85224fb44c0546cae8", "source_id": "mitre_attack_stix_campaigns", "order": 14, "label": "Technique T1587.001", "narrative": "[Juicy Mix](https://attack.mitre.org/campaigns/C0044) was a campaign conducted by [OilRig](https://attack.mitre.org/groups/G0049) throughout 2022 that targeted Israeli organizations with the [Mango](https://attack.mitre.org/software/S1169) backdoor.(Citation: ESET OilRig Campaigns Sep 2023)", "mitre_attack": [{"technique_id": "T1587.001"}], "evidence_refs": [{"project": "lora_soc", "ref": "C:\\Drachukov\\attack_chains\\data\\cache\\lora_soc\\lora_soc_external_raw_mitre_cti\\enterprise-attack.json"}]} {"chain_id": "a13ee6e28ec1643566f9a62f478953b0", "source_id": "mthcht_threatintel_reports", "order": 1, "label": "Technique T1595", "narrative": "[Link to the article](https://raw.githubusercontent.com/sophoslabs/IoCs/master/2404%20impersonation%20campaign.csv)\n", "mitre_attack": [{"technique_id": "T1595"}]} {"chain_id": "a13ee6e28ec1643566f9a62f478953b0", "source_id": "mthcht_threatintel_reports", "order": 2, "label": "Technique T1071", "narrative": "[Link to the article](https://raw.githubusercontent.com/sophoslabs/IoCs/master/2404%20impersonation%20campaign.csv)\n", "mitre_attack": [{"technique_id": "T1071"}]} {"chain_id": "a13ee6e28ec1643566f9a62f478953b0", "source_id": "mthcht_threatintel_reports", "order": 3, "label": "Technique T1059", "narrative": "[Link to the article](https://raw.githubusercontent.com/sophoslabs/IoCs/master/2404%20impersonation%20campaign.csv)\n", "mitre_attack": [{"technique_id": "T1059"}]} {"chain_id": "76415729bb09d91da6b44835348521a2", "source_id": "huntress_blog", "order": 1, "label": "Phase 1: Understanding the event flow", "narrative": "In Part 5A we showed how ADWS hides the attacker’s IP from network sensors and Event 1644—the network sees only an encrypted blob on port 9389, and the LDAP log shows [::1] as the client. Here’s the full event sequence that makes attribution possible anyway. Event 5156 is the missing piece. It comes from the Windows Filtering Platform (WFP) and hits the Security event log every time a network connection is permitted. It’s become one of my favorite events for correlation work because it records the application that owns the connection, not just the port. So instead of seeing generic svchost.exe , you see microsoft.activedirectory.webservices.exe. It’s on by default under the Filtering Platform Connection audit subcategory, so no extra configuration is needed. When a remote host connects to ADWS on port 9389, Event 5156 captures the inbound connection with the real source IP. That happens before ADWS translates the request into an internal LDAP call, which is the step that swaps the real IP for localhost. Figure 1: Event 5156 (Security Log): The Windows Filtering Platform captures the inbound ADWS connection with the real source IP before the request is translated internally. Figure ", "mitre_attack": []} {"chain_id": "76415729bb09d91da6b44835348521a2", "source_id": "huntress_blog", "order": 2, "label": "Phase 2: Port-based correlation", "narrative": "Event 1644 shows the client as [::1]:60983 (localhost with ephemeral port). If we could find an internal Event 5156 showing ADWS connecting to LDAP on that same port, we could chain: External 5156 → Internal 5156 (matching port) → 1644. Running SOAPy from the Linux box (10.1.1.13) and checking the logs: Event 1644: Client: [::1]:60983 User: MARVEL\\loki Filter: ( & (objectClass=user) ... ) Internal 5156 events found: 03:54:46.406 | ::1:61532 03:53:46.393 | ::1:61522 03:52:46.380 | ::1:61514 The ports don’t match. Event 1644 shows port 60983, but the internal 5156 events show 61532, 61522, and so on. Port 60983 is a persistent LDAP connection ADWS established long before the test. The original 5156 for that connection had already rolled out of the Security log. New queries reuse this existing connection — no new 5156 is created for each query. Port-based correlation only works in a SIEM where the original 5156 (when the persistent connection was first established) is still retained. On a live DC query, it may have rolled out.", "mitre_attack": []} {"chain_id": "76415729bb09d91da6b44835348521a2", "source_id": "huntress_blog", "order": 3, "label": "Phase 3: Timestamp-based correlation", "narrative": "Port-based correlation failed, but the events still happen in sequence with predictable timing. Even if the persistent connection’s original 5156 has rolled out of the log, the external 5156 that fired for the current query is still there — timestamped within milliseconds of Event 1644. The hypothesis: correlate by time window. External 5156 → [ADWS processing] → Event 1644 ~60–80ms Same SOAPy attack, checking timestamps: External 5156: Time: 03:53:28.407 Source IP: 10.1.1.13 Dest Port: 9389 Application: microsoft.activedirectory.webservices.exe Event 1644: Time: 03:53:28.469 Client: [::1]:60983 User: MARVEL\\loki Filter: ( & (objectClass=user) (objectCategory=CN=Person,CN=Schema,CN=Configuration,DC=marvel,DC=local) ) Attributes: [all_with_list]nTSecurityDescriptor Controls: SDflags:0x7; Delta: 62ms Repeated testing across three runs: Test Run External 5156 Event 1644 Delta Run 1 03:52:22.256 03:52:22.339 83.2ms Run 2 03:53:28.407 03:53:28.469 61.2ms Run 3 03:55:25.275 03:55:25.341 65.8ms Consistent ~60-80ms window across all three runs. The processing delay between external connection and LDAP query execution is stable enough to correlate events.", "mitre_attack": []} {"chain_id": "76415729bb09d91da6b44835348521a2", "source_id": "huntress_blog", "order": 4, "label": "Phase 4: Building the detection script", "narrative": "With timestamp correlation confirmed as reliable, the next step was building a script that could do this automatically — collecting the relevant events, attempting port-based correlation first, then falling back to the timing window. Running Get-ADWSAttribution.ps1 during active SOAPy enumeration: Figure 4: Get-ADWSAttribution.ps1 correlating Event 5156 → 1644 to attribute LDAP queries back to their source IP, catching MARVEL\\loki mid-BloodHound enumeration. Source IP 10.1.1.13 correctly attributed to all three queries. The real-time monitor mode catches it as it happens: Figure 5: Three events. One attacker. Event 5156 tells you who connected. Event 1138 tells you ADWS proxied it. Event 1644 tells you what they were after. ", "mitre_attack": []}