fin
Financial services
FIN
Payment fraud, wire manipulation and ransomware against trading and core banking, plus state-sponsored theft.
1
hc
Healthcare
HC
Ransomware with direct patient-care impact, clinical device exposure and large-scale PHI theft.
2
tech
Technology / SaaS
SAAS
Supply-chain and tenant compromise, source-code theft and abuse of your platform to reach your customers.
3
energy
Energy and utilities
UTIL
State-sponsored pre-positioning in operational networks, destructive attacks on grid infrastructure and ransomware on the IT side of the business.
4
gov
Government and public sector
GOV
Sustained state-sponsored espionage against policy, defence and citizen-service systems, alongside destructive and hacktivist-fronted operations.
5
mfg
Manufacturing and industrial
MFG
Ransomware that stops production lines, intellectual property theft from design and process data, and extortion aimed at supply-chain leverage.
6
retail
Retail and hospitality
RTL
Payment card theft at scale, identity-led intrusions into loyalty and customer systems, and extortion timed against peak trading.
7
telco
Telecommunications
TEL
State-sponsored compromise of network infrastructure for interception, long-dwell espionage against subscriber data, and identity-led attacks on support workflows.
8
FIN7
fin-actor-fin7
1
GOLD NIAGARA, ITG14, Carbon Spider, ELBRUS, Sangria Tempest
Criminal
G0046
Financially motivated since 2013 across financial services, retail and hospitality; moved into big-game ransomware and its own service brand from 2020.
Money, by whichever route the estate offers
Convincing phone and email pretexts aimed at named staff by role, at times supported by mailed hardware or fake vendor personas.
Custom backdoors and scripting, credential dumping from memory, then interactive movement into card, treasury and payment systems.
Card and payment data theft, and since 2020 ransomware when the data route is closed off.
MITRE records a portion of FIN7 operating from a front company and a shift to big game hunting from 2020. In financial services it works through the people who move money, so the accounts it takes over already carry the authority it needs. The detection value sits at the identity and endpoint layer, not the perimeter.
Wizard Spider
hc-actor-wizard-spider
1
UNC1878, TEMP.MixMaster, Grim Spider, GOLD BLACKBURN
Criminal
G0102
Russia-based group behind TrickBot, Ryuk and Conti, which ran large-scale ransomware operations against hospitals and healthcare providers.
Ransom at the point of maximum operational pressure
Phishing delivering a loader, or access purchased from a broker already inside the estate.
Rapid escalation to domain admin, endpoint tooling disabled, backups located and destroyed.
Domain-wide encryption of clinical and back-office infrastructure.
MITRE records this group's ransomware campaigns against hospitals and healthcare providers specifically. The sequence is fast and consistent, which is an advantage: detections on tool tampering and backup destruction cover the whole operation rather than one variant.
APT29
tech-actor-apt29
1
Midnight Blizzard, Cozy Bear, The Dukes, NOBELIUM, UNC2452
State
G0016
Russian SVR-attributed group; the US and UK governments attributed the SolarWinds Compromise to the SVR, with industry reporting using NOBELIUM and UNC2452 for the same activity.
Persistent access to customer and government data
Password spraying and consent phishing against tenants, and access inherited through a compromised supplier or build system.
Adds credentials to service principals and OAuth applications, then disables or evades audit logging.
Mailbox and document collection held quietly for months or years, including at selected downstream customers.
For a technology company this actor is not after you, it is after who you serve, and MITRE's SolarWinds attribution is the reference case for reaching them through your release path. The techniques leave almost no endpoint evidence, so the detection surface is the cloud control plane and application-registration audit.
Sandworm Team
energy-actor-sandworm-team
1
APT44, Seashell Blizzard, Voodoo Bear, ELECTRUM
State
G0034
Russian GRU Unit 74455. Destructive operations against electrical companies and government organisations, and the NotPetya wiper.
Disruption of physical service delivery
Spearphishing and exploitation of internet-facing infrastructure, and in past operations a trusted software update channel.
Long residence on the IT side, learning the route into operational networks and the engineering workstations that reach them.
Destructive action against control systems and wipers on the IT estate, timed for maximum disruption.
MITRE attributes the 2015 and 2016 attacks on Ukrainian electrical companies and the NotPetya campaign to this group. It is the reason IT-to-OT crossing points and engineering workstations are detection surfaces for a utility rather than an architecture diagram.
APT29
gov-actor-apt29
1
Midnight Blizzard, Cozy Bear, The Dukes, NOBELIUM
State
G0016
Russian SVR. Long-running espionage against government networks in Europe and NATO member countries, research institutes and think tanks.
Durable, quiet access to policy material
Password spraying, consent phishing and access inherited through compromised suppliers.
Adds credentials to service principals and OAuth applications, then disables or evades audit logging.
Mailbox and document collection sustained over months or years.
MITRE records the SolarWinds Compromise attribution to the SVR. For a government body the distinguishing feature is patience: there is no impact event to alert on, so detection depends on cloud control-plane and application audit data retained long enough to be worth querying.
BlackByte
mfg-actor-blackbyte
1
Hecamede
Criminal
G1043
Ransomware operator active since 2021, notable for operations against critical infrastructure entities across North America.
Ransom, priced against downtime
Exploitation of exposed services and use of valid credentials against remote access.
Vulnerable-driver abuse to disable endpoint tooling, then movement to file and virtualisation infrastructure.
Encryption, with successive ransomware versions closing the decryption routes defenders found.
MITRE records that early BlackByte used a common encryption key that allowed a universal decryptor, and that later versions do not. A manufacturer cannot assume recovery will be possible, which moves the whole case for detection earlier in the intrusion.
FIN6
retail-actor-fin6
1
Skeleton Spider, Magecart Group 6, ITG08
Criminal
G0037
Cyber crime group that has stolen payment card data and sold it on underground marketplaces, aggressively targeting point-of-sale systems.
Payment card data, sold on
Social engineering against staff and use of valid credentials into corporate networks.
Escalation toward the cardholder data environment, then onto point-of-sale infrastructure.
Card data scraped from memory and sold, and in later activity ransomware.
MITRE describes this group as aggressively targeting and compromising point-of-sale systems in the hospitality and retail sectors. POS telemetry is therefore a primary detection source in this vertical and is routinely absent from the SIEM in every other one.
Salt Typhoon
telco-actor-salt-typhoon
1
-
State
G1045
PRC state-backed actor responsible for numerous compromises of network infrastructure at major US telecommunications and internet service providers.
Interception at the infrastructure layer
Compromise of network infrastructure rather than of endpoints or user accounts.
Positions inside routing and management infrastructure, where conventional endpoint tooling does not reach.
Access to communications and subscriber data at the provider level.
MITRE records this actor as responsible for numerous compromises of network infrastructure at major US telecommunications and ISP providers. Routers and switches are the target, and their logs are the detection surface, which is a different data pipeline from the one most SOCs have built.
Carbanak
fin-actor-carbanak
2
Anunak
Criminal
G0008
Cybercriminal group that has used Carbanak malware against financial institutions since at least 2013.
Direct theft from the bank, not its customers
Spearphishing against bank staff with weaponised documents.
Months of observation inside the bank, learning payment, card processing and ATM workflows before acting.
Fraudulent transfers, ATM dispensing and card processing manipulation.
MITRE notes Carbanak may be linked to groups tracked separately as Cobalt Group and FIN7, all of which have used the same malware. The distinguishing behaviour is patience: the intrusion is long enough to detect, and the detectable stage is ordinary credential and remote-session activity rather than the fraud itself.
INC Ransom
hc-actor-inc-ransom
2
GOLD IONIC
Criminal
G1032
Ransomware and data extortion group active since 2023, targeting the industrial, healthcare and education sectors in the US and Europe.
Extortion of organisations that cannot absorb downtime
Valid credentials and exploitation of exposed services on estates with long maintenance windows.
Living-off-the-land movement, with data staged before any encryption.
Theft and publication of patient and staff records, with encryption as a second lever.
MITRE lists healthcare among this group's most common targets. Exposure tracks patch latency rather than size, so the detection question is edge-appliance inventory and coverage: the appliances nobody owns are the ones used, and they usually send no telemetry.
Scattered Spider
tech-actor-scattered-spider
2
Roasted 0ktapus, Octo Tempest, Storm-0875, UNC3944
Criminal
G1015
English-speaking group that initially targeted CRM providers, business process outsourcing firms, and telecommunications and technology companies.
Money via identity, at whichever tenant is reachable
Impersonation of IT and help-desk staff to bypass multi-factor authentication.
Administrator access in Okta, AWS and Office 365, then pivots wherever trust relationships allow.
Data theft, extortion, and downstream access to your customers.
MITRE records this group obtaining administrator access in hybrid cloud and identity environments through help-desk impersonation. If you operate an identity, CRM or support platform, your own workflows are the attack path and your customers are the target, which puts support-side telemetry in the SOC rather than in a ticketing report.
Dragonfly
energy-actor-dragonfly
2
Energetic Bear, Berserk Bear, IRON LIBERTY, DYMALLOY
State
G0035
Russian FSB Center 16. Espionage against ICS-related companies and critical infrastructure via supply chain, spearphishing and drive-by compromise.
Access held in reserve, not used immediately
Supply-chain compromise of vendor software and websites, spearphishing, and watering holes aimed at engineering staff.
Credential harvesting and quiet enumeration of control-system documentation and remote access paths.
Persistent access to ICS-adjacent networks with no destructive step. The access is the objective.
This actor collects the information needed to act later: network diagrams, HMI screenshots, vendor remote access. There is no impact event to alert on, so detection depends on credential use and file access telemetry that most utilities keep only on the IT side.
APT28
gov-actor-apt28
2
Fancy Bear, Forest Blizzard, Sofacy, STRONTIUM
State
G0007
Russian GRU Unit 26165, active since at least 2004, with operations against political and international organisations.
Intelligence, and interference in political process
Credential phishing against official and personal accounts, and exploitation of internet-facing services.
Custom implants alongside living-off-the-land tooling, with close-access operations where remote access fails.
Collection of mail, documents and credentials, sometimes published.
MITRE records US indictments of five GRU officers for operations against anti-doping bodies, a nuclear facility and the OPCW. The targeting extends to staff personal accounts and to the devices they bring to work, which is a monitoring scope question a government body has to answer explicitly.
Play
mfg-actor-play
2
Playcrypt operators
Criminal
G1040
Ransomware group active since 2022 against business, government, critical infrastructure, healthcare and media in North America, South America and Europe.
Double extortion: data first, encryption second
Valid accounts and exploitation of internet-facing services.
Living-off-the-land tooling and credential access, staging data before any encryption.
Exfiltration followed by encryption, operated as a closed group rather than an affiliate model.
MITRE assesses this as a closed group, which means the tradecraft is consistent rather than varying by affiliate. That consistency is an advantage: detections written for its staging behaviour hold, instead of decaying as affiliates rotate.
FIN7
retail-actor-fin7
2
Carbon Spider, Sangria Tempest, ELBRUS
Criminal
G0046
Financially motivated group that has targeted retail, restaurant and hospitality organisations, historically via point-of-sale malware.
Card data, and since 2020 ransom
Convincing pretexts aimed at named staff by role, at times supported by mailed hardware.
Custom backdoors and scripting, credential dumping, then movement into payment infrastructure.
Card data theft, and since 2020 big-game ransomware under its own service brand.
MITRE notes a portion of FIN7 operated from a front company and often used point-of-sale malware. The group's shift to ransomware means a retailer now faces both outcomes from the same initial access, and the detections that catch the early stages serve both.
GALLIUM
telco-actor-gallium
2
Granite Typhoon
State
G0093
Chinese state-sponsored group known for Operation Soft Cell, a long-term campaign against telecommunications providers.
Subscriber records and call detail data
Exploitation of unpatched internet-facing services, particularly web application servers.
Web shells and credential harvesting, then patient movement toward subscriber data stores.
Bulk theft of call records and subscriber information over extended periods.
Operation Soft Cell is the reference case for long-dwell telecommunications intrusion. Web shells on application servers are where it starts, and web application logs with a long lookback are where it is found, often years after the fact.
Cobalt Group
fin-actor-cobalt-group
3
GOLD KINGSWOOD, Cobalt Gang, Cobalt Spider
Criminal
G0080
Financially motivated group targeting financial institutions since 2016 through ATM systems, card processing, payment systems and SWIFT.
Money via the payment rails themselves
Spearphishing against bank employees, and access gained through other organisations already compromised.
Commodity and custom tooling toward card processing, ATM and SWIFT infrastructure.
Theft through ATM dispensing and payment system manipulation.
MITRE records this group compromising organisations in order to use that access against additional victims. For a bank that means partner and correspondent connections are an entry route, and the authentication records covering them belong in monitoring rather than in a vendor file.
Akira
hc-actor-akira
3
GOLD SAHARA, PUNK SPIDER, Howling Scorpius
Criminal
G1024
Ransomware deployment entity active since 2023 using compromised credentials against single-factor VPNs, with variants targeting Windows and VMware ESXi.
Double extortion against virtualised estates
Compromised credentials against single-factor external access, particularly VPNs.
Publicly available tools for lateral movement rather than custom implants.
Data exfiltrated before encryption, with threats to publish if the ransom is refused.
MITRE records variants capable of targeting VMware ESXi hypervisors. In a hospital that means the virtualisation layer under EHR and imaging is a direct target, and hypervisor logs are a detection source rather than an infrastructure concern.
LAPSUS$
tech-actor-lapsuss
3
DEV-0537, Strawberry Tempest
Extortion
G1004
Group specialising in large-scale social engineering and extortion, including destructive attacks without the use of ransomware.
Notoriety, then extortion
Insider recruitment, purchased credentials, and MFA prompt bombing against engineers.
Hunts secrets in repositories, wikis and CI variables to reach production directly.
Source code and internal tooling theft, published for leverage.
MITRE describes destructive attacks without ransomware, which removes the encryption event most response plans are built around. The route runs through your engineers and your own secrets hygiene, so repository audit, secret-scanning findings and token inventory are the telemetry that matters and are rarely wired into the SOC.
ALLANITE
energy-actor-allanite
3
Palmetto Fusion
State
G1000
Suspected Russian group targeting electric utilities in the US and UK; maintains ICS presence for understanding and persistence.
Understanding of the process, and persistence
Phishing and watering-hole compromise of utility staff and their suppliers.
Harvests credentials and collects operational information, without demonstrating disruptive capability.
A maintained presence in ICS environments rather than an attack.
MITRE notes this group's technical capability has not shown disruptive or destructive ability, which is exactly what makes it hard to justify detection spend. It is only visible in authentication and remote-access telemetry from the operational side.
Gamaredon Group
gov-actor-gamaredon-group
3
Armageddon, Shuckworm, Primitive Bear, Aqua Blizzard
State
G0047
Russian FSB Center 18, targeting Ukrainian military, law enforcement, judiciary and NGO organisations since 2013.
Volume collection from government bodies
High-volume spearphishing with document lures aimed at government staff.
Script-based tooling and removable-media propagation rather than sophisticated implants.
Continuous document and credential collection across many bodies at once.
This actor trades sophistication for volume, and it works because government estates are large, federated and unevenly instrumented. The detection targets are ordinary script execution and removable media, both of which are cheap to collect and frequently not collected.
Cinnamon Tempest
mfg-actor-cinnamon-tempest
3
BRONZE STARLIGHT, Emperor Dragonfly, DEV-0401
State + criminal
G1021
China-based group deploying short-lived ransomware strains built on leaked Babuk source, possibly as cover for intellectual property theft.
Possibly intellectual property, behind a ransomware front
Exploitation of internet-facing applications, operating all stages itself rather than buying access.
Hands-on movement toward design, process and engineering data.
Ransomware deployment using a variant that is then retired.
MITRE notes the short lifespan of each ransomware variant, the victimology and the use of government-linked malware, and assesses the motivation may be intellectual property theft rather than financial gain. For a manufacturer that changes the response: treat it as a design-data breach, not an outage.
FIN8
retail-actor-fin8
3
Syssphinx
Criminal
G0061
Financially motivated group targeting hospitality, retail and entertainment, which moved from point-of-sale devices to ransomware in 2021.
Whichever pays more: cards, then ransom
Spearphishing and social engineering against operational staff.
Limited, deliberate movement toward payment systems using tooling built for the purpose.
Card theft, or ransomware deployment depending on the environment.
MITRE records the 2021 switch from point-of-sale targeting to distributing ransomware variants. Retail security programmes built entirely around cardholder data scope will not see the second outcome, because it lands outside the audited boundary.
APT5
telco-actor-apt5
3
Keyhole Panda, Mulberry Typhoon, UNC2630
State
G1023
China-based espionage actor active since 2007 with significant interest in compromising networking devices and their underlying software.
Persistent access through the network layer
Zero-day exploitation of networking devices and VPN appliances.
Implants in device firmware and software that survive reboots and updates.
Durable access to traffic and to the networks the devices serve.
MITRE notes advanced tradecraft and significant interest in networking devices, including zero-day use. Appliances that cannot run an agent still produce configuration and authentication logs, and collecting those is the only available detection route.
APT38
fin-actor-apt38
4
NICKEL GLADSTONE, BeagleBoyz, Bluenoroff, Stardust Chollima, Sapphire Sleet
State
G0082
North Korean state-sponsored group specialising in financial operations, attributed to the Reconnaissance General Bureau.
Revenue for the DPRK state
Extended reconnaissance, then targeted intrusion into banks, ATM networks and cryptocurrency exchanges.
Long quiet residence, learning the payment workflow and reconciliation controls before touching anything.
Fraudulent transfers through payment rails, with some operations ending destructively.
MITRE records targeting of banks, casinos, cryptocurrency exchanges, SWIFT endpoints and ATMs in at least 38 countries, including the 2016 Bank of Bangladesh heist. This is the actor that attacks the integrity of your records rather than their confidentiality, which makes core banking and database audit trails a detection surface rather than a compliance artefact.
Orangeworm
hc-actor-orangeworm
4
-
Criminal
G0071
Group targeting healthcare organisations in the US, Europe and Asia since 2015, likely for corporate espionage.
Information about healthcare operations and technology
Access to healthcare provider networks and their technology suppliers.
Aggressive internal copying of its implant across the network, including onto imaging and clinical systems.
Long-running collection with no destructive or extortion step.
MITRE notes that reverse engineering of the group's Kwampirs implant shows significant overlap with Shamoon, a wiper. The collection behaviour is noisy on the network and quiet everywhere else, which makes internal traffic between clinical systems the place it appears.
APT41
tech-actor-apt41
4
Wicked Panda, Brass Typhoon, BARIUM
State + criminal
G0096
Chinese state-sponsored group that overlaps at least partially with reporting on BARIUM and Winnti Group, known for a wide range of malware and tooling.
Espionage using your product as the delivery vehicle
Exploitation of internet-facing services and phishing aimed at developers.
Works toward build and distribution infrastructure, using signed tooling to stay unremarkable.
Implants in software that customers install and trust.
MITRE notes the group's use of a wide range of malware and tools to complete mission objectives, including against the technology sector. Supply-chain compromise turns your release process into the adversary's distribution network, and build logs and repository audit are the only place it is visible.
HEXANE
energy-actor-hexane
4
Lyceum, Siamesekitten, Spirlin
State
G1001
Espionage against oil and gas, telecommunications and aviation in the Middle East and Africa.
Long-term access to energy operators
Password spraying and credential stuffing against exposed services, plus targeted social engineering.
DNS-based tunnelling and script-based tooling, blending into normal administrative activity.
Sustained collection from oil, gas and telecommunications operators.
MITRE tracks this group separately from APT33 and OilRig despite similar tradecraft, on the basis of different victims and tools. For an energy operator the practical consequence is DNS: outbound resolver telemetry is the source where this actor is visible and the one most often not collected.
Mustang Panda
gov-actor-mustang-panda
4
TWILL TYPHOON, RedDelta, BRONZE PRESIDENT
State
G0129
China-based espionage against government, diplomatic and non-governmental organisations across the US, Europe and Asia.
Diplomatic and policy intelligence
Tailored phishing lures and decoy documents matched to the recipient's policy area.
DLL side-loading through signed legitimate binaries, then quiet persistence.
Long-running collection from ministries, missions and think tanks.
MITRE notes tailored lures and decoy documents as the group's signature. Because delivery is targeted rather than broad, volume-based email detection misses it, and the reliable signal is side-loading behaviour in process telemetry.
Chimera
mfg-actor-chimera
4
-
State
G0114
Suspected China-based group active since 2018 targeting the semiconductor industry in Taiwan and airline industry data.
Semiconductor and process intellectual property
Credential stuffing and valid accounts against exposed services.
Extended quiet residence using legitimate administrative tooling.
Theft of semiconductor design and process data over long periods.
This is the case where the loss has no operational symptom at all. Detection depends on file access audit and authentication telemetry retained long enough to reconstruct months of activity, which is a retention decision made before the intrusion, not during it.
Scattered Spider
retail-actor-scattered-spider
4
Octo Tempest, Roasted 0ktapus, UNC3944
Criminal
G1015
English-speaking group that expanded into retail and hospitality in 2023, using help-desk impersonation and MFA bypass.
Fast monetisation through identity
Impersonation of IT and help-desk staff by phone to bypass multi-factor authentication.
Administrator access in identity and cloud platforms, using the tooling already in place.
Data theft, extortion, and ransomware for financial gain.
MITRE records the 2023 expansion into gaming, hospitality and retail, and the move into hybrid cloud and identity environments. Retail's seasonal and franchise staffing makes help-desk verification hard, which is precisely the condition this group is built for.
Sea Turtle
telco-actor-sea-turtle
4
Marbled Dust, Teal Kurma, SILICON
State
G1041
Türkiye-linked actor performing DNS-based intrusions, compromising DNS providers to hijack resolution for downstream victims.
Credentials, via control of name resolution
Compromise of registrars and DNS providers rather than of the eventual victim.
Hijacks DNS resolution to redirect victims to spoofed login portals.
Credential collection at scale from organisations that were never touched directly.
MITRE describes this actor targeting registrars managing country-code top-level domains and hijacking DNS resolution to spoof login portals. A telecommunications provider is both a target and a delivery mechanism here, which puts DNS infrastructure change records inside the monitoring scope.
Scattered Spider
fin-actor-scattered-spider
5
Roasted 0ktapus, Octo Tempest, Storm-0875, UNC3944
Criminal
G1015
English-speaking group relying heavily on social engineering and help-desk impersonation, which expanded into financial services in 2023.
Fast monetisation through identity
Impersonation of IT and help-desk staff by phone to bypass multi-factor authentication. No malware required.
Enrols its own authenticator, reads internal documentation, and uses the cloud and SaaS admin tooling already in place.
Rapid data theft, extortion, and ransomware for financial gain.
MITRE records the group adapting its tooling to evade endpoint detection and expanding into hybrid cloud and identity environments. Nothing malicious executes, so the whole intrusion lives in identity provider, ITSM and SaaS audit logs, which are often not collected or not correlated.
Deep Panda
hc-actor-deep-panda
5
Shell Crew, Black Vine, WebMasters, KungFu Kittens
State
G0009
Suspected Chinese group known for targeting several industries; the intrusion into the healthcare company Anthem has been attributed to it.
Bulk personal and health records for intelligence use
Web application exploitation and credential theft against internet-facing systems.
Long quiet residence using legitimate administrative tooling and stolen credentials.
Theft of large volumes of member and patient records.
MITRE attributes the Anthem intrusion to this group. Records taken for intelligence purposes never appear on a leak site, so there is no external signal at all: the theft is visible only in database and file access telemetry retained long enough to reconstruct it.
menuPass
tech-actor-menupass
5
APT10, Stone Panda, Cicada, Red Apollo, BRONZE RIVERSIDE
State
G0045
Chinese MSS-linked group active since 2006, known to have targeted managed IT service providers in 2016 and 2017.
Many customers through one provider
Phishing and exploitation against the service provider rather than its customers.
Uses the provider's own management connections into customer environments as an authorised operator would.
Collection across many customer estates from a single position.
MITRE records the targeting of managed IT service providers specifically. If you hold management access into customer environments, that access is the asset, and the detection question is whether anyone reviews how your own support connections are used.
CyberAv3ngers
energy-actor-cyberav3ngers
5
Soldiers of Soloman
State
G1027
IRGC-affiliated group that targeted Unitronics programmable logic controllers globally, defacing device interfaces.
Visible, symbolic disruption
Directly against internet-exposed PLCs and HMIs, often still on default credentials.
No lateral movement needed. The exposed device is the target.
Defacement of the device interface and loss of local control.
MITRE records this group's 2023 global targeting of Unitronics PLCs, found in water and wastewater, energy, food and beverage and healthcare. The exposure is an asset-inventory problem before it is a detection problem: the devices involved are usually not in anyone's monitoring scope.
Ke3chang
gov-actor-ke3chang
5
APT15, Nylon Typhoon, Vixen Panda, NICKEL
State
G0004
China-attributed group targeting oil, government, diplomatic, military and NGO organisations since at least 2010.
Access to diplomatic and military correspondence
Spearphishing and exploitation of externally facing services.
Credential dumping and domain reconnaissance, with backdoors left on infrequently rebuilt hosts.
Sustained access to diplomatic and government networks across several continents.
Fifteen years of continuous operation against government targets means this actor is best understood as a permanent condition rather than an incident. Persistence on long-lived servers is where it is found, which makes host inventory and process telemetry on those servers the priority.
APT41
mfg-actor-apt41
5
Wicked Panda, Brass Typhoon, BARIUM
State + criminal
G0096
Chinese state-sponsored espionage group that also conducts financially motivated operations across manufacturing-adjacent sectors.
Espionage, with opportunistic monetisation
Exploitation of internet-facing applications and phishing against technical staff.
Signed tooling and supply-chain positioning, with beaconing that resembles normal traffic.
Theft of design and operational data, sometimes alongside criminal activity in the same intrusion.
MITRE records targeting across fourteen countries and a wide range of industries. For a manufacturer with a software or firmware product, the supply-chain dimension matters most: build and distribution infrastructure is in scope even when it sits outside the security team's remit.
ShinyHunters
retail-actor-shinyhunters
5
UNC6240, Bling Libra
Criminal
G1057
Criminal collective active since 2019 gathering credentials and personally identifiable information for resale or extortion.
Customer data, resold or used for extortion
Legitimate credentials obtained from leaks, phishing and third-party exposure.
Straight to customer data stores and SaaS platforms, without endpoint activity.
Bulk PII theft, resale, and extortion of the victim.
MITRE associates this collective with the broader community that also includes Scattered Spider and LAPSUS$, with joint operations reported under combined names. For a retailer the practical point is that loyalty and customer databases are the target, and their access logs are the only place the theft appears.
Leviathan
telco-actor-leviathan
5
APT40, Kryptonite Panda, Gingham Typhoon
State
G0065
Chinese MSS-attributed group active since 2009 across telecommunications-adjacent sectors including transportation and maritime.
Broad sectoral intelligence collection
Rapid exploitation of newly disclosed vulnerabilities in internet-facing systems.
Web shells and credential access, then lateral movement into data of interest.
Collection across the sectors it targets, sustained over years.
The distinguishing behaviour is speed against new disclosures. For a provider with a large internet-facing estate, the detection question is whether exploitation attempts against newly disclosed vulnerabilities are visible within days, not whether patching is complete.
Indrik Spider
fin-actor-indrik-spider
6
Evil Corp, Manatee Tempest, DEV-0243, UNC2165
Criminal
G0119
Russia-based group that began with the Dridex banking trojan and moved into ransomware operations from 2017.
Large ransom payments
Compromised legitimate websites and fake update prompts delivering a loader, often supplied by a partner broker.
Banking-trojan lineage tooling, credential theft and escalation to domain admin.
Targeted ransomware, with the toolset diversified after sanctions and indictment in 2019.
MITRE notes the group changed tactics and diversified its toolset following US sanctions. Those sanctions make paying a legal problem as well as a commercial one, so early endpoint detection is the only workable answer rather than one option among several.
APT41
hc-actor-apt41
6
Wicked Panda, Brass Typhoon, BARIUM
State + criminal
G0096
Chinese state-sponsored espionage group that also conducts financially motivated operations, with healthcare among its listed targets.
Research and clinical intellectual property, plus opportunistic profit
Web application exploitation and phishing aimed at research and clinical environments.
Long quiet residence using signed tooling and beaconing that resembles normal cloud traffic.
Theft of trial, genomic and device research data, sometimes alongside criminal monetisation in the same intrusion.
MITRE lists healthcare first among the industries this group targets, across fourteen countries. Where an organisation does research the threat is espionage rather than extortion, and detecting it depends on proxy, DNS, repository and file access data retained for months rather than days.
HAFNIUM
tech-actor-hafnium
6
Silk Typhoon, Operation Exchange Marauder
State
G0125
China-based group that targets remote management tools and cloud software for initial access and operationalises exploits for edge-device vulnerabilities quickly.
Rapid, broad access through the software others run
Exploitation of remote management tools and cloud software, often within days of a disclosure.
Web shells on exposed servers, then credential access and collection.
Access across many organisations at once, chosen afterwards.
MITRE notes an ability to quickly operationalise exploits for identified vulnerabilities in edge devices. For a technology company that cuts both ways: your own edge is exposed, and if you build remote management or cloud software, it is the vehicle.
APT33
energy-actor-apt33
6
Elfin, HOLMIUM, Peach Sandstorm
State
G0064
Suspected Iranian group with particular interest in the aviation and energy sectors across the US, Saudi Arabia and South Korea.
Espionage, with destructive capability held in reserve
Spearphishing with job-themed lures and password spraying against exposed authentication.
Commodity and custom backdoors, credential harvesting, persistence on long-lived hosts.
Collection, with links in public reporting to wiper tooling.
Energy sits alongside aviation as this group's stated interest. The techniques are ordinary — spraying, phishing, backdoors — which means the detection work is ordinary too, and the sector's gap is usually coverage of the corporate estate rather than exotic tradecraft.
MuddyWater
gov-actor-muddywater
6
Mango Sandstorm, Seedworm, Static Kitten, MERCURY
State
G0069
Subordinate element of Iran's Ministry of Intelligence and Security, targeting government, telecommunications, defence and energy organisations.
Regional intelligence collection
Phishing with document lures, and exploitation of exposed remote services.
Legitimate remote management tooling in place of custom implants, plus script-based execution.
Collection across government and adjacent sectors, sustained through reused infrastructure.
MITRE notes this group's reuse of domains and, more recently, commercial satellite internet for command and control. Both point the same way for a government SOC: outbound connection telemetry with a long lookback is worth more here than another endpoint rule.
LAPSUS$
mfg-actor-lapsuss
6
DEV-0537, Strawberry Tempest
Extortion
G1004
Social engineering and extortion group that has targeted manufacturing among other sectors, including destructive attacks without ransomware.
Notoriety, then extortion
Insider recruitment, purchased credentials and MFA prompt bombing.
Hunts internal documentation and secrets to reach source and production systems directly.
Theft and publication, occasionally destruction, without an encryption stage.
MITRE lists manufacturing explicitly among this group's targets and notes destructive attacks without the use of ransomware. The entry route runs through people and documentation rather than malware, so identity and collaboration-platform telemetry carry the detection.
Medusa Group
retail-actor-medusa-group
6
Spearwing
Criminal
G1051
Ransomware-as-a-service operation using living-off-the-land techniques and common remote management software, opportunistic across sectors.
Double extortion, opportunistically
Known vulnerabilities, phishing, and access purchased from initial access brokers.
Publicly available tools and common remote management software rather than custom malware.
Exfiltration before encryption, with publication threatened if the ransom is refused.
MITRE describes the group as opportunistic and sector-agnostic, which means exposure is a function of patch latency and broker activity rather than of being a retailer. The reliance on common remote management software makes an inventory of sanctioned tooling a detection prerequisite.
LAPSUS$
telco-actor-lapsuss
6
DEV-0537, Strawberry Tempest
Extortion
G1004
Social engineering and extortion group that has targeted the telecommunications sector, including through support and identity workflows.
Notoriety, then extortion
SIM swaps, insider recruitment and MFA prompt bombing against staff.
Uses support and provisioning tooling as a legitimate operator would.
Data theft and publication, with downstream effect on subscribers.
MITRE lists telecommunications explicitly among this group's targets. Subscriber provisioning and SIM management tooling is the attack surface, and its audit trail is usually held by an operations team rather than routed into security monitoring.
Spearphishing attachment
fin-t1566-001
1
T1566.001
Initial access
FIN7, Carbanak, Cobalt Group, Indrik Spider
Email gateway, EDR process telemetry
Weaponised documents delivered to finance and treasury staff by name.
4
Detect weaponised attachments reaching finance and treasury staff
Still the most common first move against this industry, and the cheapest place to break the chain before execution.
Spearphishing attachment
hc-t1566-001
1
T1566.001
Initial access
Wizard Spider, APT41, Deep Panda
Email gateway, EDR process telemetry
Invoice and referral lures against clinical and back-office staff.
Password spraying
tech-t1110-003
1
T1110.003
Credential access
APT29, HAFNIUM
Identity provider logs
Low-and-slow authentication attempts against tenants without lockout.
Spearphishing attachment
energy-t1566-001
1
T1566.001
Initial access
Dragonfly, APT33, Sandworm Team, ALLANITE
Email gateway, EDR process telemetry
Engineering-themed lures aimed at staff with operational network access.
Spearphishing attachment
gov-t1566-001
1
T1566.001
Initial access
Gamaredon Group, Mustang Panda, Ke3chang, MuddyWater
Email gateway, EDR process telemetry
Policy-themed decoy documents matched to the recipient's brief.
Exploit public-facing application
mfg-t1190
1
T1190
Initial access
Cinnamon Tempest, Play, BlackByte, APT41
WAF / edge logs, Web application logs
Internet-facing applications exploited without any user involvement.
5
Detect exploitation of internet-facing applications
Play, BlackByte and Cinnamon Tempest all enter this way, with no user involvement to catch upstream.
Voice phishing
retail-t1566-004
1
T1566.004
Initial access
Scattered Spider, FIN7, FIN8
Identity provider logs, ITSM records
Help-desk impersonation to reset credentials and bypass MFA.
1
Detect help-desk resets and MFA enrolments outside the verified path
Scattered Spider's entire intrusion runs through this one step, and seasonal and franchise staffing makes verification hard.
Exploit public-facing application
telco-t1190
1
T1190
Initial access
GALLIUM, Leviathan, APT5
WAF / edge logs, Web application logs
Rapid exploitation of newly disclosed flaws in internet-facing systems.
5
Detect exploitation attempts against newly disclosed vulnerabilities
Leviathan moves within days of disclosure, faster than most patch cycles for a large internet-facing estate.
Voice phishing
fin-t1566-004
2
T1566.004
Initial access
FIN7, Scattered Spider
Identity provider logs, ITSM records
Callback to the service desk to reset credentials or enrol a new MFA device.
Exploit public-facing application
hc-t1190
2
T1190
Initial access
INC Ransom, Deep Panda, APT41
WAF / edge logs, Web application logs
Unpatched VPN and portal appliances on constrained maintenance windows.
Voice phishing
tech-t1566-004
2
T1566.004
Initial access
Scattered Spider, LAPSUS$
Identity provider logs, ITSM records
Service-desk manipulation to reset MFA for engineering accounts.
Supply chain compromise
energy-t1195-002
2
T1195.002
Initial access
Dragonfly, Sandworm Team
EDR process telemetry, CI/CD build logs
Vendor software and update channels used to reach ICS-adjacent networks.
1
Detect unexpected change arriving through vendor software and update channels
Dragonfly and Sandworm Team have both reached this sector through a trusted supplier rather than the front door. Nothing else in the estate carries the same implied trust.
Password spraying
gov-t1110-003
2
T1110.003
Credential access
APT29, APT28
Identity provider logs
Tenant-wide attempts against accounts without phishing-resistant factors.
Valid accounts
mfg-t1078
2
T1078
Initial access
Play, BlackByte, Chimera
Identity provider logs, VPN logs
Credential stuffing and purchased access against remote entry points.
4
Detect valid accounts used against remote entry points
Credential stuffing and broker-supplied access are the dominant entry route into plants with large vendor populations.
Valid accounts
retail-t1078
2
T1078
Initial access
ShinyHunters, Medusa Group, FIN6
Identity provider logs, SaaS audit logs
Leaked and purchased credentials used against customer-facing platforms.
Web shell
telco-t1505-003
2
T1505.003
Persistence
GALLIUM, Leviathan
Web application logs, File access audit
Shells left on application servers and rediscovered years later.
2
Detect web shells on internet-facing application servers
GALLIUM's Soft Cell intrusions started here and persisted for years. Web application logs are what find them.
Exploit public-facing application
fin-t1190
3
T1190
Initial access
APT38, Cobalt Group
WAF / edge logs, Web application logs
Exposed transfer, reporting and remote access systems exploited directly.
Valid accounts
hc-t1078
3
T1078
Initial access
Akira, INC Ransom, Wizard Spider
Identity provider logs, VPN logs
Compromised credentials against single-factor external access.
3
Detect valid-account abuse against remote access
Purchased and phished credentials are the dominant entry route into provider networks with large outsourced IT estates.
Supply chain compromise
tech-t1195-002
3
T1195.002
Initial access
APT29, APT41
CI/CD build logs, Code repository audit
Malicious code inserted into build output that customers then trust.
3
Detect unexpected change in build and distribution pipelines
A compromised build ships your compromise to every customer. Nothing else in this list has the same blast radius.
Exploit public-facing application
energy-t1190
3
T1190
Initial access
CyberAv3ngers, HEXANE, Sandworm Team
WAF / edge logs, Web application logs
Internet-exposed HMIs, PLCs and remote access portals.
2
Detect exploitation attempts against internet-exposed control interfaces
CyberAv3ngers attacked exposed PLCs directly. The detection is only as good as the asset inventory behind it, which is the real work.
Spearphishing link
gov-t1566-002
3
T1566.002
Initial access
APT28, APT29
Email gateway, Proxy / web logs
Credential-harvesting pages aimed at official and personal accounts.
Voice phishing
mfg-t1566-004
3
T1566.004
Initial access
LAPSUS$
Identity provider logs, ITSM records
Service-desk manipulation and MFA prompt bombing against staff.
Exploit public-facing application
retail-t1190
3
T1190
Initial access
Medusa Group
WAF / edge logs, Web application logs
Known vulnerabilities in e-commerce and booking applications.
External remote services
telco-t1133
3
T1133
Initial access
APT5, Salt Typhoon
VPN logs, Network device logs
VPN and management appliances reached directly from the internet.
PowerShell
fin-t1059-001
4
T1059.001
Execution
FIN7, Carbanak, Indrik Spider, Scattered Spider
EDR process telemetry, Windows security events
Encoded loaders and in-memory tooling launched from user context.
PowerShell
hc-t1059-001
4
T1059.001
Execution
Wizard Spider, INC Ransom, Akira
EDR process telemetry, Windows security events
Loader and reconnaissance scripting inside the clinical network.
Exploit public-facing application
tech-t1190
4
T1190
Initial access
HAFNIUM, APT41, menuPass
WAF / edge logs, Web application logs
Edge devices and cloud software exploited within days of disclosure.
Password spraying
energy-t1110-003
4
T1110.003
Credential access
HEXANE, APT33
Identity provider logs, VPN logs
Low-and-slow attempts against remote access without lockout policy.
PowerShell
gov-t1059-001
4
T1059.001
Execution
Gamaredon Group, MuddyWater, Mustang Panda
EDR process telemetry, Windows security events
Script-based staging in place of compiled implants.
PowerShell
mfg-t1059-001
4
T1059.001
Execution
Play, BlackByte, Cinnamon Tempest
EDR process telemetry, Windows security events
Living-off-the-land execution on production-adjacent servers.
Spearphishing attachment
retail-t1566-001
4
T1566.001
Initial access
FIN7, FIN8
Email gateway, EDR process telemetry
Lures aimed at store operations and finance staff by role.
System firmware implant
telco-t1542-001
4
T1542.001
Persistence
APT5, Salt Typhoon
Network device logs
Device-level implants that survive reboot and routine updates.
1
Detect firmware and configuration change on network devices
Salt Typhoon and APT5 operate at a layer no endpoint agent reaches. Device configuration change is the available signal.
Malicious file execution
fin-t1204-002
5
T1204.002
Execution
Carbanak, Cobalt Group
EDR process telemetry, Email gateway
User-opened payloads leading to a second-stage implant.
Scheduled task
hc-t1053-005
5
T1053.005
Persistence
Wizard Spider, Orangeworm
Windows security events
Persistence on hosts that are rarely rebuilt.
Web shell
tech-t1505-003
5
T1505.003
Persistence
HAFNIUM, APT41
Web application logs, File access audit
Shells left on exposed servers as a durable foothold.
PowerShell
energy-t1059-001
5
T1059.001
Execution
Sandworm Team, APT33, HEXANE
EDR process telemetry, Windows security events
Script-based tooling on corporate hosts that reach the operational side.
DLL side-loading
gov-t1574-002
5
T1574.002
Defense evasion
Mustang Panda, Ke3chang
EDR process telemetry
Malicious libraries loaded by signed, legitimate binaries.
3
Detect libraries side-loaded by signed, legitimate binaries
Mustang Panda's delivery is targeted rather than broad, so email volume detection misses it. The load behaviour does not.
LSASS memory dump
mfg-t1003-001
5
T1003.001
Credential access
BlackByte, Play, Chimera
EDR process telemetry
Domain admin harvesting in networks shared between office and plant.
MFA request generation
retail-t1621
5
T1621
Credential access
Scattered Spider
Identity provider logs
Repeated push prompts to seasonal and franchise staff.
Modify authentication process
telco-t1556
5
T1556
Credential access
Sea Turtle, Salt Typhoon
Network device logs, Identity provider logs
Authentication paths altered on infrastructure the victim does not control.
Scheduled task
fin-t1053-005
6
T1053.005
Persistence
FIN7, Indrik Spider, Carbanak
Windows security events, EDR process telemetry
Task creation for implant restart, named to mimic vendor software.
LSASS memory dump
hc-t1003-001
6
T1003.001
Credential access
Wizard Spider, Deep Panda, Akira
EDR process telemetry
Domain admin harvesting in flat clinical networks.
4
Detect credential dumping from memory
Flat clinical networks turn one harvested domain admin into estate-wide access; this is where the intrusion becomes unrecoverable.
Unix shell
tech-t1059-004
6
T1059.004
Execution
APT41, menuPass
Linux audit / EDR, Container runtime logs
Post-access execution on build and production Linux hosts.
Valid accounts
energy-t1078
6
T1078
Persistence
Dragonfly, ALLANITE, APT33
Identity provider logs, VPN logs
Harvested engineering and vendor credentials reused over long periods.
3
Detect engineering and vendor credentials used outside their normal pattern
Dragonfly and ALLANITE hold access rather than use it, so there is no impact event to alert on. Authentication anomaly is the whole signal.
Additional cloud credentials
gov-t1098-001
6
T1098.001
Persistence
APT29
Cloud control plane, Identity provider logs
Secrets added to service principals and OAuth applications for durable access.
1
Detect new credentials added to service principals and OAuth applications
APT29's persistence survives password resets and offboarding, and is routinely found months late. It is a low-volume event in the control plane.
Credentials in files
mfg-t1552-001
6
T1552.001
Credential access
LAPSUS$, APT41
File access audit, Code repository audit
Secrets found in engineering shares, wikis and repositories.
PowerShell
retail-t1059-001
6
T1059.001
Execution
FIN7, FIN8, Medusa Group
EDR process telemetry, Windows security events
In-memory tooling launched from user context in store and head-office estates.
Compromise DNS infrastructure
telco-t1584-002
6
T1584.002
Initial access
Sea Turtle
DNS resolver logs, Network device logs
Registrar and DNS provider compromise to redirect resolution.
4
Detect unauthorised change to DNS records and registrar configuration
Sea Turtle compromises resolution rather than the victim. Change records on DNS infrastructure are the detection.
Account manipulation
fin-t1098
7
T1098
Persistence
Scattered Spider, APT38
Identity provider logs
Attacker-controlled authenticator or credential added to a valid account.
1
Detect an authenticator or credential being added on an account the attacker now controls
The pivot point of every help-desk intrusion in this set. It is a single, low-volume identity event, and catching it costs the adversary the entire access path.
SMB admin shares
hc-t1021-002
7
T1021.002
Lateral movement
Orangeworm, Wizard Spider
Windows security events, Network flow
Implant copied aggressively across clinical and imaging systems.
Additional cloud credentials
tech-t1098-001
7
T1098.001
Persistence
APT29
Cloud control plane, Identity provider logs
New secrets or certificates added to service principals and OAuth apps.
2
Detect new credentials added to service principals and OAuth apps
The persistence step that survives password resets and offboarding, and the one most often discovered months late.
LSASS memory dump
energy-t1003-001
7
T1003.001
Credential access
Sandworm Team, Dragonfly
EDR process telemetry
Credential harvesting on the IT estate ahead of crossing into OT.
Replication through removable media
gov-t1091
7
T1091
Lateral movement
Gamaredon Group
Removable media events, EDR process telemetry
Propagation across air-gapped and loosely connected government estates.
5
Detect propagation through removable media
Gamaredon uses it because federated government estates still allow it. The telemetry is inexpensive and almost never collected.
Disable security tools
mfg-t1562-001
7
T1562.001
Defense evasion
BlackByte, Play, Cinnamon Tempest
EDR process telemetry, Windows security events
Vulnerable-driver abuse to remove endpoint tooling before encryption.
1
Detect endpoint tooling being disabled or driver-based kill activity
Shared by every ransomware operator in this set and immediately precedes encryption of the systems production depends on.
LSASS memory dump
retail-t1003-001
7
T1003.001
Credential access
FIN6, FIN7, FIN8
EDR process telemetry
Credential harvesting on the route to the cardholder data environment.
Valid accounts
telco-t1078
7
T1078
Persistence
GALLIUM, Salt Typhoon, LAPSUS$
Identity provider logs, Network device logs
Administrative credentials reused across network management estates.
MFA request generation
fin-t1621
8
T1621
Credential access
Scattered Spider
Identity provider logs
Repeated push prompts until the user approves one.
Disable security tools
hc-t1562-001
8
T1562.001
Defense evasion
Wizard Spider, Akira, INC Ransom
EDR process telemetry, Windows security events
Endpoint tooling removed on servers hosting EHR and imaging workloads.
1
Detect EDR being disabled on clinical and EHR servers
Shared by every ransomware operator in scope, and the immediate precursor to encryption of systems that patient care depends on.
Application access token
tech-t1550-001
8
T1550.001
Credential access
APT29, Scattered Spider
Cloud control plane, SaaS audit logs
Stolen tokens replayed against APIs without triggering MFA.
1
Detect forged or stolen tokens used against tenant APIs
The defining technique of state-sponsored SaaS intrusion. It leaves no authentication event to alert on, only API-side evidence.
Disable security tools
energy-t1562-001
8
T1562.001
Defense evasion
Sandworm Team
EDR process telemetry, Windows security events
Endpoint tooling removed before destructive action.
LSASS memory dump
gov-t1003-001
8
T1003.001
Credential access
Ke3chang, APT28
EDR process telemetry
Domain credential harvesting on long-lived servers.
File deletion
mfg-t1070-004
8
T1070.004
Defense evasion
Play, Cinnamon Tempest
EDR process telemetry, File access audit
Tool and log cleanup to slow the investigation.
Data from local system
retail-t1005
8
T1005
Collection
FIN6, FIN8, FIN7
Point-of-sale logs, EDR process telemetry
Card data scraped from point-of-sale process memory.
2
Detect card data being read from point-of-sale process memory
FIN6, FIN7 and FIN8 all converge here. It is the technique the whole cardholder environment exists to prevent.
LSASS memory dump
telco-t1003-001
8
T1003.001
Credential access
GALLIUM, Leviathan
EDR process telemetry
Credential harvesting on jump hosts serving the network estate.
LSASS memory dump
fin-t1003-001
9
T1003.001
Credential access
FIN7, Indrik Spider, APT38, Carbanak
EDR process telemetry, Windows security events
Credential material harvested for movement into payment systems.
File deletion
hc-t1070-004
9
T1070.004
Defense evasion
INC Ransom, APT41
EDR process telemetry, File access audit
Tooling and log cleanup before and after encryption.
Credentials in files
tech-t1552-001
9
T1552.001
Credential access
LAPSUS$, Scattered Spider, APT41
Code repository audit, File access audit
Secrets in repositories, CI variables and internal wikis.
4
Detect secrets being pulled from repositories and CI variables
One leaked secret converts a low-privilege foothold into production access, and this is the first thing every actor here looks for.
Remote system discovery
energy-t1018
9
T1018
Discovery
Dragonfly, ALLANITE, Sandworm Team
Windows security events, OT / ICS network logs
Mapping of engineering workstations, historians and jump hosts.
Disable cloud logs
gov-t1562-008
9
T1562.008
Defense evasion
APT29
Cloud control plane
Audit destinations disabled or redirected to blind the investigation.
2
Detect audit logging being disabled or redirected
It is both an attack step and the loss of your ability to see the rest of the intrusion, which makes it the highest-value single detection here.
Remote system discovery
mfg-t1018
9
T1018
Discovery
BlackByte, Play, Chimera
Windows security events, Network flow
Enumeration of plant systems, historians and virtualisation hosts.
Data from information repositories
retail-t1213
9
T1213
Collection
ShinyHunters, Scattered Spider
SaaS audit logs, File access audit
Bulk export from loyalty, CRM and customer data platforms.
3
Detect bulk export from loyalty and customer data platforms
ShinyHunters never touches an endpoint. The platform's own access log is the only evidence the theft produces.
Disable security tools
telco-t1562-001
9
T1562.001
Defense evasion
Salt Typhoon, LAPSUS$
EDR process telemetry, Network device logs
Logging and monitoring turned off on the devices that matter most.
Credentials in files
fin-t1552-001
10
T1552.001
Credential access
Scattered Spider, Cobalt Group
File access audit, SaaS audit logs
Secrets pulled from shares, wikis and repositories.
Remote system discovery
hc-t1018
10
T1018
Discovery
Wizard Spider, Akira, Orangeworm
Windows security events, Network flow
Enumeration of clinical systems and connected medical devices.
MFA request generation
tech-t1621
10
T1621
Credential access
LAPSUS$, Scattered Spider
Identity provider logs
Push bombing engineers with production access.
Data from information repositories
energy-t1213
10
T1213
Collection
Dragonfly, ALLANITE
File access audit, SaaS audit logs
Network diagrams, HMI screenshots and vendor remote-access documentation.
Domain account discovery
gov-t1087-002
10
T1087.002
Discovery
Ke3chang, APT28, Gamaredon Group
Windows security events, Identity provider logs
Enumeration of directory accounts and privileged groups.
Data from information repositories
mfg-t1213
10
T1213
Collection
Chimera, APT41, Cinnamon Tempest
File access audit, SaaS audit logs
Design, process and quality data collected from engineering stores.
3
Detect bulk collection from engineering and design repositories
Chimera and Cinnamon Tempest take design and process data with no operational symptom. This is the only place the loss is visible.
Disable security tools
retail-t1562-001
10
T1562.001
Defense evasion
Scattered Spider, Medusa Group, FIN8
EDR process telemetry, Windows security events
Endpoint tooling removed ahead of extortion or encryption.
4
Detect endpoint tooling being disabled
The shared precursor to both extortion and encryption across the criminal groups in this set.
Remote system discovery
telco-t1018
10
T1018
Discovery
GALLIUM, Leviathan, APT5
Network flow, Network device logs
Mapping of routing, management and subscriber infrastructure.
Disable security tools
fin-t1562-001
11
T1562.001
Defense evasion
FIN7, Indrik Spider, Scattered Spider, APT38
EDR process telemetry, Windows security events
Endpoint tooling tampered with or removed ahead of the objective.
2
Detect security tooling being tampered with or removed
Every ransomware operator here does it, and it happens minutes before encryption. A detection on it is the last reliable window to intervene.
Remote desktop protocol
hc-t1021-001
11
T1021.001
Lateral movement
Akira, Wizard Spider, INC Ransom
Windows security events, Network flow
Vendor-style remote sessions blend into legitimate support traffic.
Disable cloud logs
tech-t1562-008
11
T1562.008
Defense evasion
APT29
Cloud control plane
Audit trails and log destinations disabled to blind response.
5
Detect cloud audit logging being disabled or redirected
It is both an attack step and the loss of your ability to see the rest of the intrusion.
Remote desktop protocol
energy-t1021-001
11
T1021.001
Lateral movement
Sandworm Team, Dragonfly
Windows security events, OT / ICS network logs
Movement through jump hosts into engineering segments.
5
Detect remote sessions crossing from corporate into engineering segments
Every actor here that reaches operational systems does so through a jump host. That crossing is a small, countable set of events.
Remote email collection
gov-t1114-002
11
T1114.002
Collection
APT29, APT28
SaaS audit logs, Email gateway
Mailbox access via delegated permissions rather than user sign-in.
4
Detect mailbox access through delegated permissions rather than sign-in
Both Russian groups in this set collect mail without a user authentication event to alert on.
Remote desktop protocol
mfg-t1021-001
11
T1021.001
Lateral movement
Play, BlackByte
Windows security events, Network flow
Interactive movement using harvested credentials.
Remote access software
retail-t1219
11
T1219
Command and control
Medusa Group, Scattered Spider
EDR process telemetry, DNS resolver logs
Common remote management software used as a quiet channel.
Data from information repositories
telco-t1213
11
T1213
Collection
GALLIUM, Salt Typhoon
File access audit, SaaS audit logs
Bulk collection of call detail and subscriber records.
Signed binary proxy execution
fin-t1218
12
T1218
Defense evasion
FIN7, Carbanak
EDR process telemetry
Trusted Windows binaries used to run attacker code.
Remote access software
hc-t1219
12
T1219
Command and control
INC Ransom, Akira
EDR process telemetry, DNS resolver logs
Remote management tooling matching what biomedical vendors already use.
Trusted relationship
tech-t1199
12
T1199
Initial access
menuPass, APT29
Identity provider logs, Cloud control plane
Provider management connections used to reach customer environments.
DNS command and control
energy-t1071-004
12
T1071.004
Command and control
HEXANE, APT33
DNS resolver logs, Network flow
Tunnelled command traffic where outbound HTTP is restricted.
4
Detect DNS used as a command channel
HEXANE tunnels over DNS where outbound HTTP is filtered. Resolver telemetry is cheap to collect and is the one place this appears.
Data from information repositories
gov-t1213
12
T1213
Collection
Mustang Panda, Ke3chang, MuddyWater
File access audit, SaaS audit logs
Bulk document collection from shared drives and collaboration platforms.
Web protocol C2
mfg-t1071-001
12
T1071.001
Command and control
APT41, Chimera, Cinnamon Tempest
Proxy / web logs, DNS resolver logs
Beaconing that resembles ordinary vendor and update traffic.
Remote desktop protocol
retail-t1021-001
12
T1021.001
Lateral movement
FIN6, FIN7, Medusa Group
Windows security events, Network flow
Movement between head office, distribution and store networks.
Remote desktop protocol
telco-t1021-001
12
T1021.001
Lateral movement
GALLIUM, Leviathan
Windows security events, Network flow
Movement through management networks using harvested credentials.
Cloud account discovery
fin-t1087-004
13
T1087.004
Discovery
Scattered Spider
Cloud control plane, Identity provider logs
Enumeration of roles and privileged identities after first access.
Web protocol C2
hc-t1071-001
13
T1071.001
Command and control
APT41, Deep Panda, Wizard Spider
Proxy / web logs, DNS resolver logs
Beaconing from segments with limited egress inspection.
Cloud service discovery
tech-t1526
13
T1526
Discovery
APT29, Scattered Spider
Cloud control plane, SaaS audit logs
Mapping tenants, apps and privileged roles after first access.
Web protocol C2
energy-t1071-001
13
T1071.001
Command and control
Dragonfly, Sandworm Team, APT33
Proxy / web logs, DNS resolver logs
Beaconing from corporate hosts with operational network reach.
Remote access software
gov-t1219
13
T1219
Command and control
MuddyWater
EDR process telemetry, DNS resolver logs
Commercial remote management tooling used in place of custom implants.
Exfiltration to cloud storage
mfg-t1567-002
13
T1567.002
Exfiltration
Play, LAPSUS$, Chimera
Proxy / web logs, DLP / CASB
Design data and documents staged and uploaded ahead of extortion.
Web protocol C2
retail-t1071-001
13
T1071.001
Command and control
FIN7, FIN6, Medusa Group
Proxy / web logs, DNS resolver logs
Beaconing from store estates with limited egress inspection.
Web protocol C2
telco-t1071-001
13
T1071.001
Command and control
Leviathan, GALLIUM, APT5
Proxy / web logs, DNS resolver logs
Beaconing shaped to resemble normal provider traffic.
Remote system discovery
fin-t1018
14
T1018
Discovery
FIN7, Indrik Spider, Carbanak, Cobalt Group
Windows security events, Network flow
Mapping of domain hosts and payment infrastructure.
Data from information repositories
hc-t1213
14
T1213
Collection
Deep Panda, APT41, Orangeworm
File access audit, SaaS audit logs
Bulk collection of member, patient and research records.
Code repository collection
tech-t1213-003
14
T1213.003
Collection
LAPSUS$, APT41
Code repository audit
Bulk clone of private source and internal tooling.
Data destruction
energy-t1485
14
T1485
Impact
Sandworm Team
EDR process telemetry, Backup / storage logs
Wiper activity across the IT estate to prolong the outage.
Web protocol C2
gov-t1071-001
14
T1071.001
Command and control
APT29, MuddyWater, Mustang Panda
Proxy / web logs, DNS resolver logs
Beaconing over reused infrastructure and, more recently, satellite links.
Data encrypted for impact
mfg-t1486
14
T1486
Impact
BlackByte, Play, Cinnamon Tempest
EDR process telemetry, Backup / storage logs
Encryption of file services and virtualisation that plants depend on.
Exfiltration to cloud storage
retail-t1567-002
14
T1567.002
Exfiltration
ShinyHunters, Scattered Spider, Medusa Group
Proxy / web logs, DLP / CASB
Customer and card records uploaded before any ransom demand.
5
Detect bulk upload of customer and card records
The point at which a quiet intrusion becomes a notifiable breach, and the last place to intervene before it does.
Exfiltration to cloud storage
telco-t1567-002
14
T1567.002
Exfiltration
LAPSUS$, GALLIUM
Proxy / web logs, DLP / CASB
Subscriber and internal data pushed out ahead of publication.
Remote desktop protocol
fin-t1021-001
15
T1021.001
Lateral movement
FIN7, Indrik Spider, Carbanak, Cobalt Group
Windows security events, Network flow
Interactive movement using harvested credentials.
Exfiltration to cloud storage
hc-t1567-002
15
T1567.002
Exfiltration
INC Ransom, Akira, APT41
Proxy / web logs, DLP / CASB
Patient data staged and uploaded before extortion.
5
Detect bulk PHI staging and upload
Data theft precedes the ransom note and drives the regulatory consequence, which is often larger than the outage.
Remote email collection
tech-t1114-002
15
T1114.002
Collection
APT29, HAFNIUM, menuPass
SaaS audit logs, Email gateway
Mailbox access via delegated permissions rather than user sign-in.
Transmitted data manipulation
energy-t1565-002
15
T1565.002
Impact
Sandworm Team, CyberAv3ngers
OT / ICS network logs, Network device logs
Interference with control traffic and device interfaces.
Exfiltration to cloud storage
gov-t1567-002
15
T1567.002
Exfiltration
APT28, Gamaredon Group
Proxy / web logs, DLP / CASB
Document archives pushed to consumer storage services.
Inhibit system recovery
mfg-t1490
15
T1490
Impact
BlackByte, Play
Windows security events, Backup / storage logs
Shadow copies and backup jobs destroyed before encryption starts.
2
Detect backup and shadow copy destruction
BlackByte's later versions removed the universal decryptor route, so recovery depends entirely on backups surviving.
Data encrypted for impact
retail-t1486
15
T1486
Impact
Medusa Group, FIN8, Scattered Spider
EDR process telemetry, Backup / storage logs
Encryption timed against peak trading periods.
Network sniffing
telco-t1040
15
T1040
Collection
Salt Typhoon, APT5
Network device logs, Network flow
Interception at the infrastructure layer rather than at the endpoint.
3
Detect interception and monitoring configuration on infrastructure
Interception is the objective for the state actors in this set, and it leaves evidence only on the devices themselves.
Application access token
fin-t1550-001
16
T1550.001
Lateral movement
Scattered Spider
Cloud control plane, SaaS audit logs
Stolen tokens replayed against SaaS and cloud APIs, bypassing MFA.
3
Detect stolen tokens being replayed against cloud and SaaS APIs
Token replay bypasses MFA entirely, so identity controls do not see it. Only the API-side audit trail does.
Data encrypted for impact
hc-t1486
16
T1486
Impact
Akira, Wizard Spider, INC Ransom
EDR process telemetry, Backup / storage logs
Encryption of file, virtualisation and hypervisor infrastructure.
2
Detect encryption behaviour on file and virtual infrastructure
Impact detection is not a substitute for earlier coverage, but in this sector minutes of encryption time translate directly into diverted patients.
Web protocol C2
tech-t1071-001
16
T1071.001
Command and control
APT29, APT41, menuPass
Proxy / web logs, DNS resolver logs
Beaconing that mimics normal SaaS and update traffic.
Remote access software
fin-t1219
17
T1219
Command and control
FIN7, Scattered Spider, Carbanak
EDR process telemetry, DNS resolver logs
Legitimate remote management tools installed as a quiet channel.
Inhibit system recovery
hc-t1490
17
T1490
Impact
Wizard Spider, Akira
Windows security events, Backup / storage logs
Shadow copies and backup jobs destroyed first.
Exfiltration to cloud storage
tech-t1567-002
17
T1567.002
Exfiltration
LAPSUS$, APT41, Scattered Spider
Proxy / web logs, DLP / CASB
Source and customer data pushed to attacker-controlled storage.
Web protocol C2
fin-t1071-001
18
T1071.001
Command and control
APT38, Indrik Spider, Carbanak, Cobalt Group
Proxy / web logs, DNS resolver logs
HTTPS beaconing to attacker infrastructure.
Data destruction
tech-t1485
18
T1485
Impact
LAPSUS$, Scattered Spider
Cloud control plane, Backup / storage logs
Infrastructure and tenant deletion used as leverage.
Exfiltration to cloud storage
fin-t1567-002
19
T1567.002
Exfiltration
Scattered Spider, FIN7
Proxy / web logs, DLP / CASB
Bulk upload of stolen records to consumer storage services.
5
Detect bulk upload of records to consumer cloud storage
Extortion depends on the data leaving. This is the point where a quiet intrusion becomes a reportable breach.
Data encrypted for impact
fin-t1486
20
T1486
Impact
Indrik Spider, FIN7, Scattered Spider
EDR process telemetry, Backup / storage logs
Encryption of file services and virtual infrastructure.
Stored data manipulation
fin-t1565-001
21
T1565.001
Impact
APT38, Carbanak, Cobalt Group
Core banking logs, Database audit
Transaction and card processing records altered to enable or hide fraud.
Help-desk reset followed by a new device and network
fin-hunt-01
1
HUNT-01
Weekly
90 days
T1098
An identity was reset or re-enrolled through the service desk, and the account then authenticated from a device and network it has never used.
Join identity provider enrolment and reset events to ITSM tickets, then to the first authentication after each reset. Flag resets with no matching ticket, and resets where the first subsequent login carries a new device ID and a new ASN inside an hour.
A reset with no ticket, or a reset whose next login comes from unfamiliar infrastructure. Both warrant a call to the named user, not an email.
Identity provider logs, ITSM records
Backup and shadow copy operations outside the maintenance window
hc-hunt-01
1
HUNT-01
Weekly
90 days
T1490
Recovery capability is being removed ahead of encryption, disguised as routine maintenance.
Correlate volume shadow copy deletion, backup job modification and backup agent stops with the approved maintenance calendar. Anything outside the window, or executed by an account that is not the backup service, is in scope.
Deletion or disablement performed interactively, or by an admin account with no backup responsibility.
Windows security events, Backup / storage logs
New credentials on service principals and OAuth apps
tech-hunt-01
1
HUNT-01
Weekly
12 months
T1098.001
A secret or certificate has been added to a privileged application registration without a corresponding change record.
Enumerate every credential-add event on service principals and app registrations, join to change tickets and to the identity that performed it, and review anything performed by a human account against an app it does not own.
A credential added outside change control, or added to an app with mail or directory-wide permissions.
Cloud control plane, Identity provider logs, ITSM records
Corporate host that reached an engineering segment
energy-hunt-01
1
HUNT-01
Weekly
90 days
T1021.001
A host on the corporate network established a session into an engineering or historian segment that its role does not require.
Take every flow and logon crossing the IT-to-OT boundary, join to the source host's owner and role, and subtract the sanctioned jump paths. Group by source host and count distinct destinations.
Any crossing from a host that is not a designated jump host, and any jump host reaching a destination it has not reached before.
OT / ICS network logs, Windows security events, Network flow
Credential added to an application nobody owns
gov-hunt-01
1
HUNT-01
Monthly
365 days
T1098.001
A secret or certificate was added to a service principal or OAuth application, and no team claims the application.
List every credential-add event in the control plane, join to the application's registered owner and to change records. Rank by the privilege the application holds rather than by recency.
A credential on a privileged application with no owner or no change record. APT29's persistence is typically found this way, long after the fact.
Cloud control plane, Identity provider logs
Driver loaded that no platform team deployed
mfg-hunt-01
1
HUNT-01
Fortnightly
90 days
T1562.001
A kernel driver was loaded on a production-adjacent server that does not appear in any build image or deployment record.
Inventory driver loads by signer and hash, subtract the platform baseline, and rank by how few hosts have seen each one. Check the remainder against the vulnerable-driver list.
A rarely seen signed driver on a file or virtualisation server. BlackByte and its peers use exactly this to remove endpoint tooling.
EDR process telemetry, Windows security events
Credential reset with no verified caller
retail-hunt-01
1
HUNT-01
Weekly
90 days
T1566.004
A credential or MFA factor was reset through the service desk without the callback verification the process requires.
Join identity reset and enrolment events to ITSM tickets and to the callback record. Flag resets with no ticket, and tickets with no recorded verification step.
A reset with no verification record, especially on a store or franchise account. This is Scattered Spider's entire entry route.
Identity provider logs, ITSM records
Network device configuration changed outside a window
telco-hunt-01
1
HUNT-01
Weekly
180 days
T1542.001
A router, switch or management appliance had its configuration or firmware changed with no change record behind it.
Diff device configuration snapshots on a fixed schedule, join each difference to the change calendar, and rank the unexplained by the device's position in the topology.
Any unexplained difference on a device carrying subscriber or management traffic. Salt Typhoon and APT5 operate here and nowhere an agent can see.
Network device logs, ITSM records
Remote management tooling with no change record
fin-hunt-02
2
HUNT-02
Fortnightly
60 days
T1219
An RMM binary is running somewhere in the estate that no team owns and no change record explains.
Inventory every remote access executable seen in process telemetry, group by publisher and host, and subtract the tools sanctioned in the CMDB. Pay particular attention to first-seen installs on servers and on finance endpoints.
Any sanctioned-looking RMM tool present on a host outside its normal population, or a tool whose install has no corresponding ticket.
EDR process telemetry, ITSM records
Vendor-style remote sessions into clinical segments
hc-hunt-02
2
HUNT-02
Fortnightly
90 days
T1021.001
Interactive sessions into clinical and biomedical segments are being attributed to vendor support that did not happen.
List every RDP and remote session into clinical VLANs, join to vendor support tickets and to the source ASN, and separate sessions that originate outside the vendor's known ranges.
A support-shaped session with no ticket, or one arriving from consumer or hosting infrastructure.
Windows security events, Network flow, ITSM records
Token use that no authentication explains
tech-hunt-02
2
HUNT-02
Fortnightly
90 days
T1550.001
API activity is occurring under an identity with no matching interactive authentication, indicating a replayed or forged token.
Reconcile API and SaaS audit activity per principal against authentication events in the same window. Focus on principals whose API calls originate from ASNs and user agents absent from their login history.
Sustained API activity with no corresponding sign-in, or activity from infrastructure the identity has never authenticated from.
Cloud control plane, SaaS audit logs, Identity provider logs
Vendor credential used outside its maintenance window
energy-hunt-02
2
HUNT-02
Fortnightly
180 days
T1078
A vendor or engineering account authenticated at a time and from a location that no maintenance record explains.
Join remote access authentications for third-party accounts to the change calendar. Flag sessions with no window, and sessions whose source ASN or country has not been seen for that account before.
A vendor session with no change record. Dragonfly and ALLANITE hold this kind of access for long periods without using it visibly.
VPN logs, Identity provider logs, ITSM records
Mail read without a matching sign-in
gov-hunt-02
2
HUNT-02
Monthly
180 days
T1114.002
A mailbox was accessed through delegated or application permissions, with no corresponding user authentication.
Join mailbox access events to authentication events by principal and time. Isolate access that carries an application identity, then check whether the grant was ever reviewed.
Application-identity mail access on accounts holding policy or negotiation material. Both Russian groups in scope collect this way.
SaaS audit logs, Identity provider logs
Backup job or shadow copy removed outside a change
mfg-hunt-02
2
HUNT-02
Weekly
90 days
T1490
Backup jobs, retention policies or shadow copies were deleted without a change record.
Join backup platform and volume shadow events to change records by time and asset. Flag deletions with no change, and any deletion followed within a day by unusual file write volume.
A deletion with no change record. With no universal decryptor available for current ransomware, this is the event that decides whether recovery is possible.
Backup / storage logs, Windows security events
Process reading point-of-sale memory
retail-hunt-02
2
HUNT-02
Weekly
60 days
T1005
A process that is not part of the payment application read memory belonging to the point-of-sale process.
Take process access telemetry on POS hosts, filter to handles opened against the payment application, and subtract the signed maintenance and monitoring tooling.
Any unsigned or newly seen process touching payment memory. FIN6, FIN7 and FIN8 all converge on this behaviour.
Point-of-sale logs, EDR process telemetry
Web shell on an application server
telco-hunt-02
2
HUNT-02
Fortnightly
365 days
T1505.003
A script file capable of executing commands was written into a web-accessible directory and has been served since.
Correlate file creation in web roots with subsequent requests to the same path. Rank by low request volume from few sources, which is what a shell looks like next to an application.
A rarely requested script serving a small set of clients. GALLIUM's Soft Cell intrusions persisted for years exactly like this.
Web application logs, File access audit
Periodic outbound sessions from payment infrastructure
fin-hunt-03
3
HUNT-03
Monthly
6 months
T1071.001
A host in the payment or treasury segment is beaconing on a fixed interval to infrastructure that carries no business relationship.
Aggregate egress from the segment by destination and compute interval regularity and byte-size variance per destination. Rank by low jitter and small, consistent payloads, then remove known update and telemetry endpoints.
A destination with machine-like periodicity and consistent request sizes, especially over a CDN or a domain registered in the last 90 days.
Network flow, Proxy / web logs, DNS resolver logs
PHI staging before egress
hc-hunt-03
3
HUNT-03
Monthly
6 months
T1567.002
Records are being copied into a staging location and compressed before an upload that has not happened yet.
Look for archive creation on servers that do not normally create archives, sized above a threshold, then check whether the same host has recent egress to file-sharing services or unusual destinations.
Large archives appearing on an EHR-adjacent server, particularly outside business hours.
EDR process telemetry, File access audit, Proxy / web logs
Build pipeline steps that changed without a review
tech-hunt-03
3
HUNT-03
Weekly
12 months
T1195.002
A build definition, runner image or dependency source was modified outside the normal review path.
Diff pipeline definitions and runner images over time, join every change to its pull request and approver, and single out changes merged by their own author or applied directly to the build host.
A pipeline change with no reviewer, a new external dependency source, or a runner that pulled an image nobody published.
CI/CD build logs, Code repository audit
Resolver traffic shaped like a tunnel
energy-hunt-03
3
HUNT-03
Monthly
90 days
T1071.004
Command traffic is leaving over DNS from a segment where outbound web access is restricted.
Aggregate resolver logs by client and second-level domain, and rank by query volume, distinct subdomain count and average label length. Exclude known security and CDN vendors explicitly rather than by pattern.
High distinct-subdomain counts from a small number of hosts. This is how HEXANE operates where HTTP egress is closed.
DNS resolver logs, Network flow
Signed binary loading a library from the wrong place
gov-hunt-03
3
HUNT-03
Fortnightly
90 days
T1574.002
A legitimate signed executable loaded a library from a user-writable directory rather than from its install path.
Take module-load telemetry for commonly abused signed binaries, group by the directory the library came from, and subtract the vendor install paths.
Any load from a profile, temp or shared directory. This is Mustang Panda's delivery mechanism and it does not depend on the lure working twice.
EDR process telemetry, File access audit
Design data read at volume by an unrelated account
mfg-hunt-03
3
HUNT-03
Quarterly
180 days
T1213
Product design, process or quality data was read in bulk by an account with no involvement in those projects.
Rank engineering repository and file-share access by document count per account per week, then subtract the project teams. Give particular attention to service and integration accounts.
A service account or an unrelated user reading broadly across design stores. Chimera-style intrusions produce no other symptom at all.
File access audit, SaaS audit logs
Bulk customer export with no campaign behind it
retail-hunt-03
3
HUNT-03
Fortnightly
180 days
T1213
Loyalty or CRM records were exported at volume by an account with no marketing or support reason to do so.
Rank platform export and report-generation events by record count per account, then join to the campaign and support ticket records that would normally explain them.
A large export with nothing behind it. ShinyHunters-style theft leaves no other trace, because nothing runs on an endpoint.
SaaS audit logs, DLP / CASB
Resolution changed for a domain you own
telco-hunt-03
3
HUNT-03
Monthly
365 days
T1584.002
A DNS record or registrar setting for a domain the organisation owns was changed without an internal request.
Poll authoritative records and registrar configuration on a schedule, diff against the last known state, and join each change to the internal request that should explain it.
Any nameserver or record change with no request behind it. Sea Turtle compromises the provider rather than the victim, so this is the only place it shows.
DNS resolver logs, Network device logs
Service accounts reading document stores at human scale
fin-hunt-04
4
HUNT-04
Monthly
6 months
T1552.001
A service or shared account is enumerating file shares and document stores in a pattern that looks like a person searching for secrets.
Baseline read volume and directory breadth per service account, then look for accounts whose access has widened beyond its normal paths, particularly against folders whose names suggest credentials, keys or payment files.
A non-interactive account touching many directories it has never touched, or reading credential-shaped filenames.
File access audit, SaaS audit logs
Medical devices talking to the internet
hc-hunt-04
4
HUNT-04
Monthly
6 months
T1071.001
A connected clinical device has an egress path it should not have, either through misconfiguration or because it is compromised.
Group flow records by device inventory class, then list every external destination reached by each class. Devices in the same class should look alike; the exceptions are the hunt.
A device reaching destinations its class does not, or resolving domains outside the vendor's update infrastructure.
Network flow, DNS resolver logs
Repository access at clone scale
tech-hunt-04
4
HUNT-04
Monthly
6 months
T1213.003
An account is cloning private repositories far beyond the set its role requires.
Baseline repository breadth per user and per token, then look for accounts and personal access tokens whose clone footprint expanded sharply, especially tokens with no expiry.
A sudden widening of repository access, or a long-lived token cloning repositories its owner has never contributed to.
Code repository audit, Identity provider logs
Operational documentation accessed in bulk
energy-hunt-04
4
HUNT-04
Quarterly
180 days
T1213
Network diagrams, HMI screenshots and vendor remote-access documentation were collected by an account with no project reason to read them.
Rank file and collaboration access by volume against the engineering document stores, then subtract accounts on the projects those documents belong to.
Broad reads across many documents by one account in a short period. This is the collection stage of the espionage actors here, and the only stage that produces evidence.
File access audit, SaaS audit logs
Removable media moving executables between segments
gov-hunt-04
4
HUNT-04
Quarterly
180 days
T1091
An executable written to removable media on one host appeared on a host in a different segment shortly afterwards.
Correlate removable-media write events with first-seen file hashes across the estate, filtered to executables and scripts, within a seven-day window.
The same new hash appearing across segment boundaries with no distribution mechanism behind it. Gamaredon relies on this working.
Removable media events, EDR process telemetry
Remote entry with credentials that have never been used that way
mfg-hunt-04
4
HUNT-04
Fortnightly
90 days
T1078
An account authenticated to remote access from infrastructure it has never used, and then reached systems outside its normal set.
Baseline each remote-access account by source ASN, device and destination set over six months, then surface first-time combinations and rank by the privilege of the destinations reached.
A first-time source paired with a first-time destination. This is the broker-supplied access route that Play and BlackByte both rely on.
VPN logs, Identity provider logs, Windows security events
Remote management tooling in the store estate
retail-hunt-04
4
HUNT-04
Monthly
90 days
T1219
A remote management tool is running on store or distribution hosts that no operations team deployed.
Inventory remote access executables across store estates by publisher and first-seen date, and subtract the sanctioned list. Rank by how recently each appeared.
A sanctioned-looking tool on hosts that no support contract covers. Medusa Group relies on common remote management software rather than custom malware.
EDR process telemetry, Proxy / web logs
Subscriber records read at volume
telco-hunt-04
4
HUNT-04
Quarterly
180 days
T1213
Call detail or subscriber records were queried at a volume no business process requires.
Rank subscriber platform queries by record count per account per day, then subtract billing, support and regulatory reporting workloads by their known schedules.
Sustained high-volume reads outside the reporting schedule. This is the objective for GALLIUM and Salt Typhoon, and the only stage with an audit trail.
File access audit, SaaS audit logs
Phishing-resistant MFA for privileged, treasury and finance roles
fin-prev-01
1
PREV-01
M1032
Multi-factor authentication
T1621, T1098, T1566.004
Move those roles to FIDO2 or platform passkeys and remove push and one-time codes as a fallback for them. The fallback path is what gets attacked, not the primary method.
Push fatigue stops being a detectable event because the prompt no longer exists. Alternate-authenticator enrolment stays a detection, narrowed to the enrolment path itself.
Push-approval detections go quiet for the migrated groups while enrolment volume stays flat. If they keep firing, the fallback was never actually removed.
Identity engineering
One quarter
Removes two techniques
Green
Phishing-resistant MFA on all remote access, including vendors
hc-prev-01
1
PREV-01
M1032
Multi-factor authentication
T1078, T1621
Put VPN, VDI and remote clinical access behind FIDO2 or certificate-bound authentication, including the outsourced IT and biomedical vendor accounts that usually sit outside the rollout.
Valid-account abuse against remote access moves from the dominant entry route to an exception.
New-device and new-ASN login detections stop being the first signal of an intrusion for these accounts.
Identity and vendor management
Two quarters
Removes the entry route
Green
Hardware-bound authentication for anything that reaches production
tech-prev-01
1
PREV-01
M1032
Multi-factor authentication
T1110.003, T1621, T1566.004
Require hardware-bound keys for engineering and production access, remove one-time code and push fallbacks for those groups, and apply lockout policy at the tenant edge.
Password spraying and push bombing come off the detection list for these identities.
Spray detections still fire at the tenant edge but no longer correlate with a successful sign-in.
Identity engineering
One quarter
Removes two techniques
Green
A single audited crossing point between corporate and operational networks
energy-prev-01
1
PREV-01
M1030
Network segmentation
T1021.001, T1018, T1565.002
Collapse every path between IT and OT down to one brokered jump path with its own credentials, and deny the rest at the network rather than by policy.
Boundary-crossing detection narrows from every possible path to one, which makes the remaining detection trustworthy instead of aspirational.
HUNT-01 returns only sessions through the broker. Anything else means a path was missed, which is itself the finding.
Network engineering and OT
Two to four quarters
Removes the path
Green
Phishing-resistant authentication across the whole estate, not just for administrators
gov-prev-01
1
PREV-01
M1032
Multi-factor authentication
T1110.003, T1566.002
Move all staff to FIDO2 or certificate-bound authentication, remove one-time codes as a fallback, and extend the requirement to contractors and seconded staff.
Password spraying and credential-harvesting pages stop producing usable access, which removes the two highest-volume entry techniques here.
Spray and phishing detections keep firing at the edge but stop correlating with a successful sign-in.
Identity engineering
Two to three quarters
Removes two techniques
Green
Vulnerable-driver blocking and tamper protection on production-adjacent servers
mfg-prev-01
1
PREV-01
M1040
Behaviour prevention on endpoint
T1562.001, T1486
Block the vulnerable-driver list at the kernel, enable tamper protection with a separate uninstall credential, and move file and virtualisation servers out of audit mode into blocking mode.
Attempted tampering becomes a prevented event with a name, rather than a race against encryption that response has to win.
HUNT-01 converts from tooling removed to removal blocked. The count can rise; the severity falls.
Endpoint engineering
Two quarters
Removes the window
Green
Callback verification on every credential and MFA reset, including franchises
retail-prev-01
1
PREV-01
M1018
User account management
T1566.004, T1621
Require an out-of-band callback to a number held in the HR or franchise record before any reset or enrolment, and make the ticket the only path that can perform one.
The reset becomes an authorised, ticketed event, so the hunt narrows from every reset to resets with no matching verification.
HUNT-01 returns fewer candidates each month, and the remainder are process failures rather than intrusions.
Service desk and IAM
One to two quarters
Narrows the hunt
Yellow
Management plane separated from the production network
telco-prev-01
1
PREV-01
M1043
Credential access protection
T1078, T1556, T1562.001
Put device management on an out-of-band network reachable only through a brokered jump path with its own hardware-bound credentials, and remove device administration rights from general IT accounts.
Administrative access to infrastructure becomes a small, countable set of sessions rather than an estate-wide possibility.
Device authentication logs show sessions only from the broker. Anything else means a path was missed.
Network engineering
Three to four quarters
Removes the path
Green
Callback verification on every credential and MFA reset
fin-prev-02
2
PREV-02
M1018
User account management
T1566.004, T1098
Require an out-of-band callback to a number held in the HR record before the service desk resets a credential or enrols a device, and make the ticket the only path that can perform the reset.
The reset becomes an authorised, ticketed event, so the hunt narrows from every reset to resets with no matching ticket.
HUNT-01 returns fewer candidates each month, and the ones it returns are process failures rather than intrusions.
Service desk and IAM
One quarter
Narrows the hunt
Yellow
Segment clinical and biomedical devices from general IT
hc-prev-02
2
PREV-02
M1030
Network segmentation
T1018, T1021.001, T1071.001
Put connected devices behind a default-deny egress policy with vendor update destinations allowlisted per device class, and stop general IT subnets reaching device management interfaces.
Device egress hunting narrows to policy exceptions, and movement into clinical VLANs needs a route that no longer exists.
HUNT-04 stops returning devices with novel destinations, because the policy denies them before a flow record exists.
Network engineering and biomed
Two to four quarters
Removes the path
Green
Short-lived credentials in place of long-lived tokens and app secrets
tech-prev-02
2
PREV-02
M1026
Privileged account management
T1550.001, T1098.001, T1552.001
Replace personal access tokens and app secrets with workload identity federation and expiring credentials, forbid non-expiring tokens by policy, and require change control for any credential added to a privileged app registration.
Credential-add hunting narrows from every app registration to the shrinking set that still holds a static secret.
HUNT-01 candidate volume falls as the static-secret population shrinks, and stale-token findings stop recurring.
Platform and IAM
Two to three quarters
Reduces to a residual set
Yellow
Nothing operational answers the internet
energy-prev-02
2
PREV-02
M1035
Limit access to resource over network
T1190
Inventory every control interface with a public address, remove the exposure, and put the remainder behind a brokered path with authentication that the device itself does not provide.
Exploitation of exposed control interfaces stops being a detection target because the interface no longer exists on the internet.
External scanning returns no control interfaces. CyberAv3ngers found its victims by scanning, so this is measured the same way.
Asset owners and network engineering
One to two quarters
Removes the technique
Green
Owned, reviewed and expiring application credentials
gov-prev-02
2
PREV-02
M1018
User account management
T1098.001
Require a named owner and an expiry on every application credential, block non-expiring secrets by policy, and review privileged application grants on a fixed schedule.
Credential-add hunting narrows from every application to the shrinking set that still holds a static secret.
HUNT-01 returns fewer unowned applications each quarter, and the ones it returns have a team to send them to.
Cloud platform and IAM
Two to three quarters
Reduces to a residual set
Yellow
Immutable backups with credentials that do not exist in production
mfg-prev-02
2
PREV-02
M1053
Data backup
T1490, T1486
Hold backup copies in immutable storage reachable only with credentials held outside the production domain, and test restore of production-critical systems on a fixed schedule.
Recovery inhibition remains a detection but stops being the difference between an incident and a stopped line.
Restore tests pass inside the recovery objective, and backup deletion alerts no longer need an emergency path.
Infrastructure and resilience
Two quarters
Removes the leverage
Green
Point-of-sale estates isolated from corporate and store back-office networks
retail-prev-02
2
PREV-02
M1030
Network segmentation
T1005, T1021.001
Put payment infrastructure on its own segment with default-deny access from corporate and store networks, and allow only the payment processor destinations it actually needs.
Card data theft requires a route that no longer exists, and lateral-movement hunting narrows to the brokered path.
HUNT-02 finds no unsigned processes reaching payment memory, because nothing unmanaged can reach the host at all.
Network engineering and payments
Two to three quarters
Removes the path
Green
Firmware integrity verification on network devices
telco-prev-02
2
PREV-02
M1051
Update software
T1542.001, T1133
Enable secure boot and firmware integrity verification where the platform supports it, and where it does not, take periodic configuration and image hashes to a store the device cannot write to.
Firmware implants become detectable by comparison rather than by inference, which is the difference between finding them and not.
HUNT-01 has a trusted baseline to diff against, so unexplained differences are findings rather than uncertainty.
Network engineering
Two to four quarters
Makes it visible
Yellow
Tamper protection and vulnerable-driver blocking on servers
fin-prev-03
3
PREV-03
M1040
Behaviour prevention on endpoint
T1562.001, T1218, T1486
Turn on tamper protection with a separate uninstall credential, block the vulnerable-driver list at the kernel, and move file and virtual infrastructure servers from audit mode into blocking mode.
Attempted tampering becomes a prevented event with a name, instead of a race against encryption that response has to win.
Tamper detections convert from tool removed to removal blocked. The count can go up; the severity comes down.
Endpoint engineering
Two quarters
Removes the window
Green
Immutable, isolated backups with tested clinical restore
hc-prev-03
3
PREV-03
M1053
Data backup
T1490, T1486
Hold backup copies in immutable storage with credentials that do not exist in the production domain, and test restore of EHR-adjacent systems on a fixed schedule against the clinical recovery objective.
Recovery inhibition stays a detection, but it stops being the difference between an outage and diverted patients.
Restore tests pass inside the recovery objective, and backup-deletion alerts no longer need an emergency response path.
Infrastructure and resilience
Two quarters
Removes the leverage
Green
Signed, provenanced builds with two-person review on pipeline changes
tech-prev-03
3
PREV-03
M1045
Code signing
T1195.002
Require signed artefacts with build provenance, run builds on ephemeral runners from a published image, and require a second reviewer for any change to a pipeline definition or dependency source.
Pipeline changes with no reviewer cease to exist as a category, so the hunt reduces to verifying provenance.
Every artefact in the release path carries provenance that can be verified without asking the build team.
Build platform
Two quarters
Removes the largest blast radius
Green
Phishing-resistant authentication for engineering and vendor remote access
energy-prev-03
3
PREV-03
M1032
Multi-factor authentication
T1078, T1110.003
Move engineering and third-party remote access to hardware-bound or certificate-based authentication, and remove password-only fallbacks for those accounts.
Password spraying against remote access comes off the list, and valid-account abuse narrows to credential theft from a managed device.
Spray attempts continue at the edge but stop correlating with successful sessions.
Identity engineering and vendor management
Two quarters
Removes one technique
Green
Audit destinations outside the reach of the accounts being audited
gov-prev-03
3
PREV-03
M1029
Remote data storage
T1562.008
Hold audit logs in a separate account with its own trust path, make the destination immutable for the retention period, and remove log-configuration rights from operational roles.
Disabling audit logging requires crossing an account boundary, which is itself a low-volume and high-signal detection.
Gaps in the log pipeline become explainable by a change record rather than by an investigation.
Security engineering
One to two quarters
Raises the cost
Green
Phishing-resistant authentication on every remote entry point, including vendors
mfg-prev-03
3
PREV-03
M1032
Multi-factor authentication
T1078, T1566.004
Put VPN, vendor access and plant remote support behind hardware-bound authentication, and require callback verification to an HR-held number before any credential reset.
Valid-account abuse narrows to theft from a managed device, and service-desk resets become authorised, ticketed events.
HUNT-04 returns process failures rather than intrusions, and its volume falls quarter on quarter.
Identity engineering and service desk
Two quarters
Removes the entry route
Green
Phishing-resistant authentication for administrators of customer platforms
retail-prev-03
3
PREV-03
M1032
Multi-factor authentication
T1078, T1621
Require hardware-bound authentication for anyone who can export from loyalty, CRM or e-commerce platforms, and remove push and one-time code fallbacks for those roles.
Push fatigue stops being a detectable event for these roles because the prompt no longer exists, and credential reuse stops producing access.
Push-approval detections go quiet for the migrated roles while enrolment volume stays flat.
Identity engineering
One to two quarters
Removes two techniques
Green
No writable web roots on internet-facing application servers
telco-prev-03
3
PREV-03
M1038
Execution prevention
T1505.003, T1190
Deploy application content read-only from the build pipeline, deny write access to web-served directories at runtime, and stage uploads outside the served path.
Web shells cannot be written where they can be served, which removes the persistence technique rather than detecting it.
HUNT-02 finds nothing, and the absence is meaningful because writes are refused rather than merely unobserved.
Application platform
Two quarters
Removes the technique
Green
Bind sessions to managed devices so a stolen token is useless
fin-prev-04
4
PREV-04
M1054
Software configuration
T1550.001, T1087.004
Require token binding or continuous access evaluation for cloud and SaaS APIs, and refuse tokens presented from unmanaged devices or from a new network location mid-session.
Token replay drops from a primary detection target to a residual case covered by API-side audit.
HUNT-02 finds API activity with no matching sign-in only for service principals, not for human accounts.
Cloud platform
Two quarters
Reduces to a residual case
Yellow
Compensating controls on edge appliances that cannot be patched in time
hc-prev-04
4
PREV-04
M1051
Update software
T1190
Where a maintenance window cannot be brought forward, put the appliance behind a filtering proxy or virtual patch and restrict its management interface to a jump path.
Exploitation attempts are absorbed at the edge instead of arriving as a detection with minutes of response time.
Edge logs show blocked exploitation attempts against appliances that previously had nothing between disclosure and patch.
Infrastructure and security engineering
Ongoing
Reduces the exposure window
Yellow
Secret scanning with push protection across every repository
tech-prev-04
4
PREV-04
M1054
Software configuration
T1552.001, T1213.003
Enable push protection organisation-wide rather than per repository, block merges on a detected secret, and rotate automatically on detection instead of filing a ticket.
Credentials in files stops being a detection target for the repository path and stays one for file shares and wikis.
Repository secret findings trend to zero while file-share findings do not, which tells you where to work next.
Developer experience
One quarter
Removes one path
Yellow
Default-deny egress from operational segments
energy-prev-04
4
PREV-04
M1037
Filter network traffic
T1071.004, T1071.001
Deny outbound traffic from operational and historian segments by default, allowlist the vendor destinations those systems genuinely need, and force DNS through an inspected resolver.
Tunnelled command traffic has nowhere to go, so DNS hunting reduces to verifying the allowlist rather than searching the open internet.
HUNT-03 stops finding novel domains from operational hosts, because the policy refuses them before a query is logged.
Network engineering
Two quarters
Narrows the surface
Yellow
Removable media disabled by default across the estate
gov-prev-04
4
PREV-04
M1042
Disable or remove feature or program
T1091
Block execution from removable media by default and grant exceptions per device with an expiry, rather than per user or per site.
Propagation through removable media stops being a technique the estate can carry, and the hunt reduces to reviewing the exception list.
HUNT-04 returns nothing outside the exception list, which is a short and auditable set.
Endpoint engineering
Two quarters
Removes the technique
Green
Design and process data readable only by the projects that need it
mfg-prev-04
4
PREV-04
M1022
Restrict file and directory permissions
T1213
Move engineering stores from broad group access to per-project entitlement with quarterly review, and remove standing access for service and integration accounts.
Bulk-collection hunting narrows from the whole repository to a small entitled population, which makes the hunt finishable.
HUNT-03 has a shorter candidate list each quarter as standing access is withdrawn.
Engineering and IAM
Three to four quarters
Narrows the surface
Yellow
Export limits and approval on customer data platforms
retail-prev-04
4
PREV-04
M1057
Data loss prevention
T1213, T1567.002
Cap bulk export size by role, require approval above the cap, and block consumer file storage destinations from the networks those platforms are administered from.
Bulk export becomes an approved event, so the hunt reduces to exports without approval rather than every export.
HUNT-03 has an approval record to join against, which turns an open-ended search into a reconciliation.
Data protection and platform owners
Two quarters
Narrows the surface
Yellow
Registrar and DNS changes behind multi-party approval
telco-prev-04
4
PREV-04
M1018
User account management
T1584.002, T1556
Enable registrar lock, require two-party approval for nameserver and record changes, and hold registrar credentials separately from the general identity estate.
Resolution hijack requires defeating an approval process rather than a single credential, and the hunt narrows to approved changes.
HUNT-03 reconciles every change against an approval record instead of searching for the unexplained.
Domain and platform owners
One quarter
Raises the cost
Green
Egress allowlist for consumer file storage
fin-prev-05
5
PREV-05
M1057
Data loss prevention
T1567.002, T1552.001
Block consumer cloud storage and file-sharing destinations by default from server segments and finance endpoints, and route named business services through a sanctioned, logged path.
Bulk-upload detection stays, but the volume it has to reason about falls to a short list of sanctioned services.
Exfiltration detections fire against an allowlist rather than the open internet, which is what makes them workable at all.
Network and data protection
One quarter
Narrows the surface
Yellow
Blocking-mode endpoint policy on EHR and imaging servers
hc-prev-05
5
PREV-05
M1040
Behaviour prevention on endpoint
T1562.001, T1059.001, T1486
Take the servers patient care depends on out of audit mode, enable tamper protection with a separate uninstall credential, and constrain script interpreters to signed content.
Encryption behaviour is blocked rather than alerted on, and tool tampering becomes a prevented event.
Impact-stage detections stop being the first place an intrusion is visible on these servers.
Endpoint engineering
Two quarters
Removes the window
Green
Take logging configuration out of the operator role
tech-prev-05
5
PREV-05
M1018
User account management
T1562.008
Remove log-configuration permissions from day-to-day operator roles, hold audit destinations in a separate account with its own trust path, and make the destination immutable for the retention period.
Disabling audit logging now requires crossing an account boundary, which is itself a low-volume, high-signal detection.
Gaps in the log pipeline become explainable by a change record rather than by an investigation.
Cloud platform and security engineering
One quarter
Raises the cost
Yellow
Verified provenance on vendor software and firmware updates
energy-prev-05
5
PREV-05
M1051
Update software
T1195.002
Require signed packages with verifiable provenance for control-system software and firmware, and stage updates in a test environment before they reach production devices.
Supply-chain compromise stops being an unbounded trust assumption and becomes a verification step with an owner.
Every update applied to an operational device has a provenance record that can be checked without contacting the vendor.
Engineering and procurement
Ongoing
Raises the cost
Yellow
Application control on the binaries that side-loading depends on
gov-prev-05
5
PREV-05
M1038
Execution prevention
T1574.002
Enforce library loading from install paths only for the signed binaries commonly abused for side-loading, and deny execution from user-writable directories.
Side-loading becomes a prevented event rather than a behaviour to hunt, and delivery has to find another route.
HUNT-03 converts from finding loads to finding blocked loads, which is a different and much shorter queue.
Endpoint engineering
Two to three quarters
Removes the path
Yellow
A committed patch window for internet-facing systems, with virtual patching where there is none
mfg-prev-05
5
PREV-05
M1051
Update software
T1190
Set a maximum exposure period for internet-facing applications, and where a window cannot be met, place the system behind a filtering proxy or virtual patch until it can.
Exploitation attempts are absorbed at the edge instead of arriving as a detection with minutes of response time.
Edge logs show blocked exploitation attempts against systems that previously had nothing between disclosure and patch.
Infrastructure and security engineering
Ongoing
Reduces the exposure window
Yellow
Blocking-mode endpoint policy across store and distribution estates
retail-prev-05
5
PREV-05
M1040
Behaviour prevention on endpoint
T1562.001, T1486, T1219
Take store and distribution hosts out of audit mode, enable tamper protection with a separate uninstall credential, and allowlist the remote management tools operations actually uses.
Tampering and unsanctioned remote tooling become prevented events, and the RMM inventory hunt reduces to exceptions.
HUNT-04 finds only allowlisted tooling. Anything else is blocked at install rather than found later.
Endpoint engineering and store IT
Two to three quarters
Removes the window
Green
Subscriber data queries scoped and rate-limited by role
telco-prev-05
5
PREV-05
M1022
Restrict file and directory permissions
T1213, T1040
Replace broad query access to subscriber and call detail stores with per-role scoping and rate limits, and route reporting workloads through scheduled jobs rather than interactive queries.
Bulk collection stops being available interactively, so the hunt reduces to comparing scheduled jobs against their expected volume.
HUNT-04 has a schedule to reconcile against, and interactive high-volume reads no longer succeed.
Data platform and IAM
Three quarters
Narrows the surface
Yellow



