MITRE

Red Teamers

T1566

User Training

Application Log,File,Nework Traffic

Axiom,Gold SOUTHFIELD

Group72

Hikit

Hikit is malware that has been used by Axiom for late-stage persistence and exfiltration after the initial compromise.

Winnti Group

15

Splunk search

Persistence

BZAR

Masquerading

Unit Tests

Persona Creation

Persona Profile Worksheet

Lures

A risk assessment that models organizational strengths and weaknesses

Data Obfuscation

Outbound Internet Network Traffic

C2 Setup

sethc.exe

Pupy,Metasploit Framework

PoshC2

P.A.S.,S0598

APT33

Cloud Accounts

Ruler

Abnormal or malicious behavior

Azure AD, Google Workspace, IaaS, Office 365, SaaS