ParityPT catalog
APT groups and checks
Browse the purple-team packs and ATT&CK-mapped techniques available in assessments. Cards are informational only — sign in to run them.
APT groups
Technique-similarity packs drawn from public ATT&CK reporting — not full adversary emulation. Stages map to the same checks you run in an assessment.
- APT29 / Midnight Blizzard: Cozy Bear multi-interpreter + C2 pathAPT chainG0016
Multi-interpreter execution (PowerShell, cmd, VBScript, Python), WMI, persistence, Defender tamper, credential access, and HTTP C2/exfil — technique-similarity pack from public APT29 / Midnight Blizzard ATT&CK reporting (including SolarWinds-era scripting notes).
- APT28 / Forest Blizzard: Fancy Bear LOLBin + persistenceAPT chainG0007
Scripting and rundll32/cmstp proxy execution with COM/Startup persistence, credential access, and log-clearing — APT28-oriented reporting pack.
- APT41 / Brass Typhoon: APT41 dual espionage / crimeware pathAPT chainG0096
Ingress and certutil staging, LOLBin execution, service/BITS persistence, privilege escalation, and credential access — APT41-style dual-use tradecraft pack.
- Lazarus Group: Lazarus implant pathAPT chainG0032
Ingress + HTTP C2, PowerShell execution, UAC bypass, service/IFEO persistence, Defender tamper, and RDP — Lazarus-oriented implant/access chain.
- FIN7: FIN7 living-off-the-landAPT chainG0046
mshta/regsvr32/cscript/cmstp LOLBin execution, certutil/HTTP C2, and persistence via scheduled tasks and BITS — FIN7-style LOTL pack.
- Sandworm / Voodoo Bear: Sandworm WMI/opsAPT chainG0034
WMI execution and event persistence, PowerShell, scheduled-task/service persistence, and security-log clear — Sandworm-oriented operations pack.
- Wizard Spider: Wizard Spider ransomware prepAPT chainG0102
Ingress + HTTP C2/exfil, scripting, defense tamper, credential access (LSASS/SAM), local account creation, and RDP — Wizard Spider / Conti-era affiliate prep pack.
- Volt Typhoon: Volt Typhoon living-off-the-landAPT chainG1017
Native Windows tooling: discovery, WMI, netsh helper, certutil/DNS/HTTP C2, WinRM, and scheduled tasks — Volt Typhoon-style LOTL / hands-on-keyboard pack.
- Scattered Spider: Scattered Spider identity + remote accessAPT chainG1015
Discovery, scripting, credential access, local account / RDP / WinRM remote access, and defense tamper — Scattered Spider-oriented identity and hands-on access pack.
- Turla: Turla stealth persistenceAPT chainG0010
Quiet LOLBin execution, COM/AppInit/netsh persistence, and credential access — Turla-oriented stealthy persistence pack.
- APT33 / Peach Sandstorm: APT33 / Peach SandstormAPT chainG0064
PowerShell and cscript execution, ingress, scheduled-task/service persistence, and credential access — APT33 / Peach Sandstorm similarity pack.
- APT34 / OilRig: APT34 / OilRigAPT chainG0049
mshta/PowerShell execution, certutil staging, COM/Startup persistence, and credential access — OilRig-oriented pack.
- APT35 / Charming Kitten: APT35 / Charming KittenAPT chainG0059
Script-host and PowerShell execution, ingress, Run-key/Startup persistence, and credential access — Charming Kitten similarity pack.
- APT10 / menuPass: APT10 / menuPassAPT chainG0045
Ingress/certutil/HTTP C2, rundll32/regsvr32 execution, service/schtask persistence, and credential access — menuPass / Stone Panda pack.
- APT32 / OceanLotus: APT32 / OceanLotusAPT chainG0050
LOLBin-heavy execution (mshta/cmstp/cscript), HTTP C2, COM/AppInit persistence, and defense evasion — OceanLotus similarity pack.
- APT37 / Reaper: APT37 / ReaperAPT chainG0067
Scripting and document-adjacent LOLBins, ingress/HTTP C2, schtask/runkey persistence, and credential access — APT37 / Reaper similarity pack.
- APT38: APT38 financial ops prepAPT chainG0082
Ingress/C2, defense tamper, credential access, service persistence, and RDP — APT38 financial-operations prep similarity pack.
- APT39 / Chafer: APT39 / ChaferAPT chainG0087
PowerShell/cmd/WMI execution, persistence, credential access, and WinRM — APT39 / Chafer similarity pack.
- APT40 / Leviathan: APT40 / LeviathanAPT chainG0065
Web/LOLBin execution, certutil/ingress/HTTP C2, COM/Startup persistence — APT40 / Leviathan similarity pack.
- APT31 / Zirconium: APT31 / ZirconiumAPT chainG0099
LOTL discovery, scripting, scheduled tasks, and HTTP C2/exfil — APT31 / Zirconium similarity pack.
- MuddyWater: MuddyWaterAPT chainG0069
mshta/cscript/PowerShell execution, ingress/HTTP C2, BITS/schtask persistence, and credential access — MuddyWater similarity pack.
- HAFNIUM: HAFNIUM post-compromiseAPT chainG0125
Post-compromise style: discovery, web/LOLBin execution, credential access, WinRM/RDP — HAFNIUM similarity pack (not a web-shell implant).
- Dragonfly / Energetic Bear: Dragonfly / Energetic BearAPT chainG0035
WMI/ops, discovery, service/schtask persistence, and LOTL execution — Dragonfly / Energetic Bear Windows-host similarity pack.
- Mustang Panda: Mustang PandaAPT chainG0129
Document-adjacent LOLBins (mshta/cscript), certutil/HTTP C2 staging, Startup/schtask persistence, and credential access — Mustang Panda pack.
- Kimsuky: KimsukyAPT chainG0094
PowerShell/script execution, ingress/HTTP C2, Run-key/IFEO persistence, and credential theft — Kimsuky-oriented pack.
- LockBit-style ops: LockBit-style affiliate prepAPT chainG0140
Fast ingress/HTTP C2, defense kill (Defender/firewall), credential access, account creation, and RDP — LockBit-era affiliate prep similarity pack.
- APT1 / Comment Crew: APT1 / Comment Crew classicAPT chainG0006
Classic intrusion pattern: ingress/HTTP C2, scripting, service/schtask persistence, credential access, and RDP — APT1-era similarity pack.
- Gamaredon: GamaredonAPT chainG0047
Aggressive scripting and LOLBins, certutil/HTTP C2 staging, Startup/BITS persistence, and light credential access — Gamaredon similarity pack.
Checks
Authorized Windows purple-team probes named with MITRE ATT&CK technique IDs. Pass means defenses blocked the path; fail means the technique succeeded in the lab.
- T1059.001 Encoded PowerShell ExecutiontechniqueT1059.001 — Encoded PowerShell Execution
Windows: attempt a benign encoded PowerShell payload that only writes a marker file. fail if the payload runs and the marker appears (execution path open). pass if AMSI, ASR, Constrained Language, AppLocker/WDAC, or similar blocks execution. not_applicable on non-Windows.
- T1218.005 mshta LOLBin ExecutiontechniqueT1218.005 — mshta LOLBin Execution
Windows: attempt to run mshta.exe with a local harmless HTA that only writes a marker. fail if the marker is created. pass if Smart App Control, ASR, AppLocker, or WDAC blocks mshta. not_applicable on non-Windows.
- T1053.005 Scheduled Task PersistencetechniqueT1053.005 — Scheduled Task Persistence
Windows: create a short-lived scheduled task named ParityPT-Purple-*, verify it registered, then delete it. fail if creation succeeded. pass if task creation was denied. Agent cleans up on exit. not_applicable on non-Windows.
- T1547.001 Registry Run Key PersistencetechniqueT1547.001 — Registry Run Key Persistence
Windows: write an HKCU Run value pointing at a benign marker command, verify presence, then remove it. fail if the value persisted after write. pass if write was denied. not_applicable on non-Windows.
- T1003.001 LSASS Handle AccesstechniqueT1003.001 — LSASS Handle Access
Windows: attempt to open a handle to LSASS for read (no dump written to disk). fail if a usable handle was obtained. pass if access is denied (PPL, Credential Guard, ASR, or ACL). not_applicable on non-Windows.
- T1562.001 Defender Tamper AttempttechniqueT1562.001 — Defender Tamper Attempt
Windows: attempt to add a temporary Defender path exclusion or disable realtime protection, then revert any successful change. fail if tamper succeeded before revert. pass if Tamper Protection or ACLs blocked the change. not_applicable on non-Windows.
- T1105 Ingress Tool TransfertechniqueT1105 — Ingress Tool Transfer
Windows: attempt HTTPS download of a known-benign blob from the ParityPT probe endpoint (/api/probe/ingress on PUBLIC_URL / apiBaseUrl), hash it, then delete. fail only if the download succeeded. pass if network filtering, ASR, or policy prevented the download. Local-only copies do not count as success. not_applicable on non-Windows.
- T1543.003 Service InstallationtechniqueT1543.003 — Service Installation
Windows: attempt to create a temporary service ParityPTPurple*, verify creation, then delete it. fail if the service was created. pass if creation was denied (non-admin / policy). not_applicable on non-Windows.
- T1070.001 Security Log Clear CapabilitytechniqueT1070.001 — Security Log Clear Capability
Windows: probe whether the current context can clear the Security event log (privilege + access check) without wiping production logs when possible; if a clear is attempted and succeeds, that is fail. pass when clear capability is denied. not_applicable on non-Windows.
- T1548.002 UAC Bypass Path ProbetechniqueT1548.002 — UAC Bypass Path Probe
Windows: probe a known fodhelper-style auto-elevate registry path with a non-destructive marker command only, then clean up. fail if the HKCU handler was set (bypass path open) or an elevated marker was written. pass if the registry hijack was denied. not_applicable on non-Windows.
- T1218.010 regsvr32 Scriptlet ExecutiontechniqueT1218.010 — regsvr32 Scriptlet Execution
Windows: attempt regsvr32 with a local harmless .sct scriptlet that only writes a marker file, then clean up. fail if the marker appears. pass if ASR, AppLocker, WDAC, or Smart App Control blocks regsvr32/scrobj. not_applicable on non-Windows.
- T1218.011 rundll32 Proxy ExecutiontechniqueT1218.011 — rundll32 Proxy Execution
Windows: attempt rundll32 (shell32 ShellExec_RunDLL) to run a benign cmd that writes a marker, then clean up. fail if the marker is created. pass if WDAC/AppLocker/ASR blocks rundll32 proxy execution. not_applicable on non-Windows.
- T1547.001 Startup Folder PersistencetechniqueT1547.001 — Startup Folder Persistence
Windows: drop a short-lived .cmd into the current user Startup folder that would write a marker on logon, verify the file landed, then delete it (does not wait for logon). fail if the Startup file was written. pass if write was denied. not_applicable on non-Windows.
- T1047 WMI Process CreatetechniqueT1047 — WMI Process Create
Windows: attempt Win32_Process.Create via WMI to run a benign cmd that writes a marker, then clean up. fail if the marker appears (WMI execution path open). pass if WMI/DCOM restrictions or AppLocker block creation. not_applicable on non-Windows.
- T1562.004 Firewall Disable AttempttechniqueT1562.004 — Firewall Disable Attempt
Windows: attempt to disable a Windows Firewall profile briefly, verify state change, then re-enable. fail if disable succeeded before revert. pass if policy/Tamper Protection/ACL blocked the change. not_applicable on non-Windows.
- T1197 BITS Job PersistencetechniqueT1197 — BITS Job Persistence
Windows: create a short-lived BITS transfer job with a benign local source/dest, verify it exists, then cancel/remove it. fail if the job was created. pass if BITS job creation was denied. not_applicable on non-Windows.
- T1546.015 COM Hijack ProbetechniqueT1546.015 — COM Hijack Probe
Windows: write a temporary HKCU CLSID InprocServer32 hijack pointing at a non-existent benign path, verify the key, then remove it (no COM server is loaded). fail if the hijack key persisted after write. pass if registry write was denied. not_applicable on non-Windows.
- T1136.001 Local Account CreationtechniqueT1136.001 — Local Account Creation
Windows: attempt to create a temporary local user ParityPTPurple*, verify creation, then delete it. fail if the account was created. pass if creation was denied (non-admin / policy). not_applicable on non-Windows.
- T1021.001 RDP Enable AttempttechniqueT1021.001 — RDP Enable Attempt
Windows: attempt to enable Remote Desktop by clearing fDenyTSConnections, verify the value, then restore the prior setting. fail if RDP was successfully enabled before restore. pass if registry/policy blocked the change. not_applicable on non-Windows.
- T1059.005 cscript / VBScript ExecutiontechniqueT1059.005 — cscript / VBScript Execution
Windows: run cscript.exe against a local harmless .vbs that only writes a marker, then delete artifacts. fail if the marker appears. pass if WDAC/AppLocker/ASR blocks cscript or script host. not_applicable on non-Windows.
- T1105 certutil Decode / IngresstechniqueT1105 — certutil Decode / Ingress
Windows: attempt certutil -decode on a local benign Base64 blob to write a marker file, then delete artifacts. fail if the marker is created. pass if WDAC/AppLocker/ASR or policy blocks certutil abuse. not_applicable on non-Windows.
- T1218.003 cmstp INF ExecutiontechniqueT1218.003 — cmstp INF Execution
Windows: attempt cmstp.exe with a local harmless INF that runs a marker-writing command, then clean up. fail if the marker appears. pass if WDAC/AppLocker/ASR blocks cmstp. not_applicable on non-Windows.
- T1546.003 WMI Event SubscriptiontechniqueT1546.003 — WMI Event Subscription
Windows: create a temporary WMI event filter + CommandLineEventConsumer binding, verify creation, then delete all objects (does not wait for trigger). fail if subscription objects were created. pass if creation was denied. not_applicable on non-Windows.
- T1546.012 IFEO Debugger PersistencetechniqueT1546.012 — IFEO Debugger Persistence
Windows: write a temporary HKLM Image File Execution Options Debugger value for a non-existent benign exe name, verify the key, then remove it (target is never launched). fail if the key persisted after write. pass if registry write was denied. not_applicable on non-Windows.
- T1003.002 SAM Registry Hive ExporttechniqueT1003.002 — SAM Registry Hive Export
Windows: attempt reg save HKLM\SAM to a temporary file, verify a hive was written, then delete it (no online credential parsing). fail if the hive export succeeded. pass if privilege/ACL blocked the save. not_applicable on non-Windows.
- T1021.006 WinRM Enable AttempttechniqueT1021.006 — WinRM Enable Attempt
Windows: attempt to set WinRM AllowAutoConfig policy to enabled, verify the change, then restore the prior value. fail if enable succeeded before restore. pass if policy/ACL blocked the change. not_applicable on non-Windows.
- T1546.007 netsh Helper DLLtechniqueT1546.007 — netsh Helper DLL
Windows: attempt netsh add helper with a non-existent benign DLL path, verify registration, then delete the helper (DLL is never loaded). fail if the helper was added. pass if netsh helper modification was denied. not_applicable on non-Windows.
- T1546.010 AppInit_DLLs PersistencetechniqueT1546.010 — AppInit_DLLs Persistence
Windows: attempt to set HKLM AppInit_DLLs / LoadAppInit_DLLs to a benign non-existent path, verify values, then restore priors (DLL is never loaded). fail if values were changed successfully. pass if registry write was denied. not_applicable on non-Windows.
- T1059.003 Windows Command ShelltechniqueT1059.003 — Windows Command Shell
Windows: attempt cmd.exe /c to write a marker file under the agent work directory, then delete it. fail if the marker appears. pass if AppLocker/WDAC/ASR or policy blocked cmd. not_applicable on non-Windows.
- T1059.006 PythontechniqueT1059.006 — Python
Windows: if python/py is on PATH, attempt a one-liner that writes a marker, then delete it. fail if the marker appears. pass if execution was blocked. not_applicable if Python is not installed or on non-Windows.
- T1059.007 JavaScript / wscripttechniqueT1059.007 — JavaScript / wscript
Windows: attempt wscript.exe to run a tiny local .js that writes a marker, then delete artifacts. fail if the marker appears. pass if WSH/WDAC/ASR blocked wscript. not_applicable on non-Windows.
- T1127.001 MSBuild Inline TasktechniqueT1127.001 — MSBuild Inline Task
Windows: if MSBuild is present, run an inline WriteLinesToFile task that writes a marker, then delete project/marker. fail if the marker appears. pass if MSBuild was blocked. not_applicable if MSBuild is missing or on non-Windows.
- T1218.007 msiexec Remote PackagetechniqueT1218.007 — msiexec Remote Package
Windows: attempt msiexec silent install against the ParityPT package probe URL (/api/probe/package on PUBLIC_URL / apiBaseUrl), capture whether msiexec launched, then stop/cleanup. fail if msiexec ran the remote package path. pass if msiexec could not start. not_applicable on non-Windows.
- T1218.004 InstallUtil ProbetechniqueT1218.004 — InstallUtil Probe
Windows: compile a tiny benign installer assembly (Add-Type) and run InstallUtil so Install() writes a marker, then delete artifacts. fail if the marker appears. pass if compile/InstallUtil was blocked. not_applicable if InstallUtil is missing or on non-Windows.
- T1037.001 Logon Script PersistencetechniqueT1037.001 — Logon Script Persistence
Windows: attempt to set HKCU UserInitMprLogonScript to a benign temp .bat, verify, then revert and delete the bat (logon never runs it). fail if the value was set. pass if registry write was denied. not_applicable on non-Windows.
- T1547.009 Startup Folder ShortcuttechniqueT1547.009 — Startup Folder Shortcut
Windows: attempt to create a Startup-folder .lnk that would launch cmd to write a marker, then delete the shortcut (target never launched). fail if the .lnk was created. pass if Startup write was denied. not_applicable on non-Windows.
- T1546.008 Sticky Keys IFEO ProbetechniqueT1546.008 — Sticky Keys IFEO Probe
Windows: attempt to set IFEO Debugger on sethc.exe to cmd.exe, verify, then immediately restore prior state (sethc never launched). fail if the Debugger value was set. pass if IFEO write was denied. not_applicable on non-Windows.
- T1087.001 Local Account DiscoverytechniqueT1087.001 — Local Account Discovery
Windows: run net user and grade whether local account listing output was obtained. fail if discovery returned results. pass if the command was blocked or produced no usable output. not_applicable on non-Windows.
- T1057 Process DiscoverytechniqueT1057 — Process Discovery
Windows: enumerate processes via Get-Process. fail if a process list was returned. pass if enumeration was blocked. not_applicable on non-Windows.
- T1082 System Information DiscoverytechniqueT1082 — System Information Discovery
Windows: collect basic host/OS identity (computer name + OS version string). fail if details were returned. pass if collection was blocked. not_applicable on non-Windows.
- T1135 Network Share DiscoverytechniqueT1135 — Network Share Discovery
Windows: run net share and grade whether share listing output was obtained. fail if discovery returned share names. pass if blocked or empty. not_applicable on non-Windows.
- T1560.001 Archive Staged DatatechniqueT1560.001 — Archive Staged Data
Windows: create a zip of tiny benign temp files (Compress-Archive), verify creation, then delete. fail if the archive was created. pass if archiving was blocked. not_applicable on non-Windows.
- T1071.001 Web Protocol C2 BeacontechniqueT1071.001 — Web Protocol C2 Beacon
Windows: attempt a benign HTTP(S) GET to the ParityPT beacon probe (/api/probe/beacon on PUBLIC_URL / apiBaseUrl) with a distinctive ParityPT User-Agent. fail only if a response is received. pass if egress filtering blocked the request. No third-party hosts. not_applicable on non-Windows.
- T1041 Exfiltration Over C2 Channel (HTTP)techniqueT1041 — Exfiltration Over C2 Channel (HTTP)
Windows: attempt a benign HTTP(S) POST of a small ASCII blob to the ParityPT exfil probe (/api/probe/exfil on PUBLIC_URL / apiBaseUrl). fail only if the ParityPT server accepts the POST. pass if egress filtering blocked upload. No third-party hosts. not_applicable on non-Windows.
- T1071.004 DNS Application Layer ProbetechniqueT1071.004 — DNS Application Layer Probe
Windows: resolve the ParityPT host from apiBaseUrl / PUBLIC_URL (hostname or IP). fail if name resolution completes. pass if DNS resolution is blocked closed. No third-party domains. not_applicable on non-Windows.
- T1021.002 SMB Admin Share AccesstechniqueT1021.002 — SMB Admin Share Access
Windows: attempt to write a marker via \\127.0.0.1\C$\Windows\Temp, then delete it. fail if the admin share write succeeded. pass if admin share access was denied. not_applicable on non-Windows.
- T1557.001 Name Resolution Poisoning CapturetechniqueT1557.001 — Name Resolution Poisoning Capture
Windows: listen for a configurable window (default 30s via check Timeout) on LLMNR/mDNS/NBT-NS, spoof replies to the agent host, and capture NetNTLM hashes over HTTP/SMB if clients authenticate. Does not relay credentials. fail if poisonable queries are observed or hashes are captured. pass if the window is quiet (and ideally LLMNR is disabled). not_applicable on non-Windows.