ParityPT catalog

APT groups and checks

Browse the purple-team packs and ATT&CK-mapped techniques available in assessments. Cards are informational only — sign in to run them.

  • APT29 / Midnight Blizzard: Cozy Bear multi-interpreter + C2 pathAPT chain
    G0016

    Multi-interpreter execution (PowerShell, cmd, VBScript, Python), WMI, persistence, Defender tamper, credential access, and HTTP C2/exfil — technique-similarity pack from public APT29 / Midnight Blizzard ATT&CK reporting (including SolarWinds-era scripting notes).

  • APT28 / Forest Blizzard: Fancy Bear LOLBin + persistenceAPT chain
    G0007

    Scripting and rundll32/cmstp proxy execution with COM/Startup persistence, credential access, and log-clearing — APT28-oriented reporting pack.

  • APT41 / Brass Typhoon: APT41 dual espionage / crimeware pathAPT chain
    G0096

    Ingress and certutil staging, LOLBin execution, service/BITS persistence, privilege escalation, and credential access — APT41-style dual-use tradecraft pack.

  • Lazarus Group: Lazarus implant pathAPT chain
    G0032

    Ingress + HTTP C2, PowerShell execution, UAC bypass, service/IFEO persistence, Defender tamper, and RDP — Lazarus-oriented implant/access chain.

  • FIN7: FIN7 living-off-the-landAPT chain
    G0046

    mshta/regsvr32/cscript/cmstp LOLBin execution, certutil/HTTP C2, and persistence via scheduled tasks and BITS — FIN7-style LOTL pack.

  • Sandworm / Voodoo Bear: Sandworm WMI/opsAPT chain
    G0034

    WMI execution and event persistence, PowerShell, scheduled-task/service persistence, and security-log clear — Sandworm-oriented operations pack.

  • Wizard Spider: Wizard Spider ransomware prepAPT chain
    G0102

    Ingress + HTTP C2/exfil, scripting, defense tamper, credential access (LSASS/SAM), local account creation, and RDP — Wizard Spider / Conti-era affiliate prep pack.

  • Volt Typhoon: Volt Typhoon living-off-the-landAPT chain
    G1017

    Native Windows tooling: discovery, WMI, netsh helper, certutil/DNS/HTTP C2, WinRM, and scheduled tasks — Volt Typhoon-style LOTL / hands-on-keyboard pack.

  • Scattered Spider: Scattered Spider identity + remote accessAPT chain
    G1015

    Discovery, scripting, credential access, local account / RDP / WinRM remote access, and defense tamper — Scattered Spider-oriented identity and hands-on access pack.

  • Turla: Turla stealth persistenceAPT chain
    G0010

    Quiet LOLBin execution, COM/AppInit/netsh persistence, and credential access — Turla-oriented stealthy persistence pack.

  • APT33 / Peach Sandstorm: APT33 / Peach SandstormAPT chain
    G0064

    PowerShell and cscript execution, ingress, scheduled-task/service persistence, and credential access — APT33 / Peach Sandstorm similarity pack.

  • APT34 / OilRig: APT34 / OilRigAPT chain
    G0049

    mshta/PowerShell execution, certutil staging, COM/Startup persistence, and credential access — OilRig-oriented pack.

  • APT35 / Charming Kitten: APT35 / Charming KittenAPT chain
    G0059

    Script-host and PowerShell execution, ingress, Run-key/Startup persistence, and credential access — Charming Kitten similarity pack.

  • APT10 / menuPass: APT10 / menuPassAPT chain
    G0045

    Ingress/certutil/HTTP C2, rundll32/regsvr32 execution, service/schtask persistence, and credential access — menuPass / Stone Panda pack.

  • APT32 / OceanLotus: APT32 / OceanLotusAPT chain
    G0050

    LOLBin-heavy execution (mshta/cmstp/cscript), HTTP C2, COM/AppInit persistence, and defense evasion — OceanLotus similarity pack.

  • APT37 / Reaper: APT37 / ReaperAPT chain
    G0067

    Scripting and document-adjacent LOLBins, ingress/HTTP C2, schtask/runkey persistence, and credential access — APT37 / Reaper similarity pack.

  • APT38: APT38 financial ops prepAPT chain
    G0082

    Ingress/C2, defense tamper, credential access, service persistence, and RDP — APT38 financial-operations prep similarity pack.

  • APT39 / Chafer: APT39 / ChaferAPT chain
    G0087

    PowerShell/cmd/WMI execution, persistence, credential access, and WinRM — APT39 / Chafer similarity pack.

  • APT40 / Leviathan: APT40 / LeviathanAPT chain
    G0065

    Web/LOLBin execution, certutil/ingress/HTTP C2, COM/Startup persistence — APT40 / Leviathan similarity pack.

  • APT31 / Zirconium: APT31 / ZirconiumAPT chain
    G0099

    LOTL discovery, scripting, scheduled tasks, and HTTP C2/exfil — APT31 / Zirconium similarity pack.

  • MuddyWater: MuddyWaterAPT chain
    G0069

    mshta/cscript/PowerShell execution, ingress/HTTP C2, BITS/schtask persistence, and credential access — MuddyWater similarity pack.

  • HAFNIUM: HAFNIUM post-compromiseAPT chain
    G0125

    Post-compromise style: discovery, web/LOLBin execution, credential access, WinRM/RDP — HAFNIUM similarity pack (not a web-shell implant).

  • Dragonfly / Energetic Bear: Dragonfly / Energetic BearAPT chain
    G0035

    WMI/ops, discovery, service/schtask persistence, and LOTL execution — Dragonfly / Energetic Bear Windows-host similarity pack.

  • Mustang Panda: Mustang PandaAPT chain
    G0129

    Document-adjacent LOLBins (mshta/cscript), certutil/HTTP C2 staging, Startup/schtask persistence, and credential access — Mustang Panda pack.

  • Kimsuky: KimsukyAPT chain
    G0094

    PowerShell/script execution, ingress/HTTP C2, Run-key/IFEO persistence, and credential theft — Kimsuky-oriented pack.

  • LockBit-style ops: LockBit-style affiliate prepAPT chain
    G0140

    Fast ingress/HTTP C2, defense kill (Defender/firewall), credential access, account creation, and RDP — LockBit-era affiliate prep similarity pack.

  • APT1 / Comment Crew: APT1 / Comment Crew classicAPT chain
    G0006

    Classic intrusion pattern: ingress/HTTP C2, scripting, service/schtask persistence, credential access, and RDP — APT1-era similarity pack.

  • Gamaredon: GamaredonAPT chain
    G0047

    Aggressive scripting and LOLBins, certutil/HTTP C2 staging, Startup/BITS persistence, and light credential access — Gamaredon similarity pack.

  • T1059.001 Encoded PowerShell Executiontechnique
    T1059.001 — Encoded PowerShell Execution

    Windows: attempt a benign encoded PowerShell payload that only writes a marker file. fail if the payload runs and the marker appears (execution path open). pass if AMSI, ASR, Constrained Language, AppLocker/WDAC, or similar blocks execution. not_applicable on non-Windows.

  • T1218.005 mshta LOLBin Executiontechnique
    T1218.005 — mshta LOLBin Execution

    Windows: attempt to run mshta.exe with a local harmless HTA that only writes a marker. fail if the marker is created. pass if Smart App Control, ASR, AppLocker, or WDAC blocks mshta. not_applicable on non-Windows.

  • T1053.005 Scheduled Task Persistencetechnique
    T1053.005 — Scheduled Task Persistence

    Windows: create a short-lived scheduled task named ParityPT-Purple-*, verify it registered, then delete it. fail if creation succeeded. pass if task creation was denied. Agent cleans up on exit. not_applicable on non-Windows.

  • T1547.001 Registry Run Key Persistencetechnique
    T1547.001 — Registry Run Key Persistence

    Windows: write an HKCU Run value pointing at a benign marker command, verify presence, then remove it. fail if the value persisted after write. pass if write was denied. not_applicable on non-Windows.

  • T1003.001 LSASS Handle Accesstechnique
    T1003.001 — LSASS Handle Access

    Windows: attempt to open a handle to LSASS for read (no dump written to disk). fail if a usable handle was obtained. pass if access is denied (PPL, Credential Guard, ASR, or ACL). not_applicable on non-Windows.

  • T1562.001 Defender Tamper Attempttechnique
    T1562.001 — Defender Tamper Attempt

    Windows: attempt to add a temporary Defender path exclusion or disable realtime protection, then revert any successful change. fail if tamper succeeded before revert. pass if Tamper Protection or ACLs blocked the change. not_applicable on non-Windows.

  • T1105 Ingress Tool Transfertechnique
    T1105 — Ingress Tool Transfer

    Windows: attempt HTTPS download of a known-benign blob from the ParityPT probe endpoint (/api/probe/ingress on PUBLIC_URL / apiBaseUrl), hash it, then delete. fail only if the download succeeded. pass if network filtering, ASR, or policy prevented the download. Local-only copies do not count as success. not_applicable on non-Windows.

  • T1543.003 Service Installationtechnique
    T1543.003 — Service Installation

    Windows: attempt to create a temporary service ParityPTPurple*, verify creation, then delete it. fail if the service was created. pass if creation was denied (non-admin / policy). not_applicable on non-Windows.

  • T1070.001 Security Log Clear Capabilitytechnique
    T1070.001 — Security Log Clear Capability

    Windows: probe whether the current context can clear the Security event log (privilege + access check) without wiping production logs when possible; if a clear is attempted and succeeds, that is fail. pass when clear capability is denied. not_applicable on non-Windows.

  • T1548.002 UAC Bypass Path Probetechnique
    T1548.002 — UAC Bypass Path Probe

    Windows: probe a known fodhelper-style auto-elevate registry path with a non-destructive marker command only, then clean up. fail if the HKCU handler was set (bypass path open) or an elevated marker was written. pass if the registry hijack was denied. not_applicable on non-Windows.

  • T1218.010 regsvr32 Scriptlet Executiontechnique
    T1218.010 — regsvr32 Scriptlet Execution

    Windows: attempt regsvr32 with a local harmless .sct scriptlet that only writes a marker file, then clean up. fail if the marker appears. pass if ASR, AppLocker, WDAC, or Smart App Control blocks regsvr32/scrobj. not_applicable on non-Windows.

  • T1218.011 rundll32 Proxy Executiontechnique
    T1218.011 — rundll32 Proxy Execution

    Windows: attempt rundll32 (shell32 ShellExec_RunDLL) to run a benign cmd that writes a marker, then clean up. fail if the marker is created. pass if WDAC/AppLocker/ASR blocks rundll32 proxy execution. not_applicable on non-Windows.

  • T1547.001 Startup Folder Persistencetechnique
    T1547.001 — Startup Folder Persistence

    Windows: drop a short-lived .cmd into the current user Startup folder that would write a marker on logon, verify the file landed, then delete it (does not wait for logon). fail if the Startup file was written. pass if write was denied. not_applicable on non-Windows.

  • T1047 WMI Process Createtechnique
    T1047 — WMI Process Create

    Windows: attempt Win32_Process.Create via WMI to run a benign cmd that writes a marker, then clean up. fail if the marker appears (WMI execution path open). pass if WMI/DCOM restrictions or AppLocker block creation. not_applicable on non-Windows.

  • T1562.004 Firewall Disable Attempttechnique
    T1562.004 — Firewall Disable Attempt

    Windows: attempt to disable a Windows Firewall profile briefly, verify state change, then re-enable. fail if disable succeeded before revert. pass if policy/Tamper Protection/ACL blocked the change. not_applicable on non-Windows.

  • T1197 BITS Job Persistencetechnique
    T1197 — BITS Job Persistence

    Windows: create a short-lived BITS transfer job with a benign local source/dest, verify it exists, then cancel/remove it. fail if the job was created. pass if BITS job creation was denied. not_applicable on non-Windows.

  • T1546.015 COM Hijack Probetechnique
    T1546.015 — COM Hijack Probe

    Windows: write a temporary HKCU CLSID InprocServer32 hijack pointing at a non-existent benign path, verify the key, then remove it (no COM server is loaded). fail if the hijack key persisted after write. pass if registry write was denied. not_applicable on non-Windows.

  • T1136.001 Local Account Creationtechnique
    T1136.001 — Local Account Creation

    Windows: attempt to create a temporary local user ParityPTPurple*, verify creation, then delete it. fail if the account was created. pass if creation was denied (non-admin / policy). not_applicable on non-Windows.

  • T1021.001 RDP Enable Attempttechnique
    T1021.001 — RDP Enable Attempt

    Windows: attempt to enable Remote Desktop by clearing fDenyTSConnections, verify the value, then restore the prior setting. fail if RDP was successfully enabled before restore. pass if registry/policy blocked the change. not_applicable on non-Windows.

  • T1059.005 cscript / VBScript Executiontechnique
    T1059.005 — cscript / VBScript Execution

    Windows: run cscript.exe against a local harmless .vbs that only writes a marker, then delete artifacts. fail if the marker appears. pass if WDAC/AppLocker/ASR blocks cscript or script host. not_applicable on non-Windows.

  • T1105 certutil Decode / Ingresstechnique
    T1105 — certutil Decode / Ingress

    Windows: attempt certutil -decode on a local benign Base64 blob to write a marker file, then delete artifacts. fail if the marker is created. pass if WDAC/AppLocker/ASR or policy blocks certutil abuse. not_applicable on non-Windows.

  • T1218.003 cmstp INF Executiontechnique
    T1218.003 — cmstp INF Execution

    Windows: attempt cmstp.exe with a local harmless INF that runs a marker-writing command, then clean up. fail if the marker appears. pass if WDAC/AppLocker/ASR blocks cmstp. not_applicable on non-Windows.

  • T1546.003 WMI Event Subscriptiontechnique
    T1546.003 — WMI Event Subscription

    Windows: create a temporary WMI event filter + CommandLineEventConsumer binding, verify creation, then delete all objects (does not wait for trigger). fail if subscription objects were created. pass if creation was denied. not_applicable on non-Windows.

  • T1546.012 IFEO Debugger Persistencetechnique
    T1546.012 — IFEO Debugger Persistence

    Windows: write a temporary HKLM Image File Execution Options Debugger value for a non-existent benign exe name, verify the key, then remove it (target is never launched). fail if the key persisted after write. pass if registry write was denied. not_applicable on non-Windows.

  • T1003.002 SAM Registry Hive Exporttechnique
    T1003.002 — SAM Registry Hive Export

    Windows: attempt reg save HKLM\SAM to a temporary file, verify a hive was written, then delete it (no online credential parsing). fail if the hive export succeeded. pass if privilege/ACL blocked the save. not_applicable on non-Windows.

  • T1021.006 WinRM Enable Attempttechnique
    T1021.006 — WinRM Enable Attempt

    Windows: attempt to set WinRM AllowAutoConfig policy to enabled, verify the change, then restore the prior value. fail if enable succeeded before restore. pass if policy/ACL blocked the change. not_applicable on non-Windows.

  • T1546.007 netsh Helper DLLtechnique
    T1546.007 — netsh Helper DLL

    Windows: attempt netsh add helper with a non-existent benign DLL path, verify registration, then delete the helper (DLL is never loaded). fail if the helper was added. pass if netsh helper modification was denied. not_applicable on non-Windows.

  • T1546.010 AppInit_DLLs Persistencetechnique
    T1546.010 — AppInit_DLLs Persistence

    Windows: attempt to set HKLM AppInit_DLLs / LoadAppInit_DLLs to a benign non-existent path, verify values, then restore priors (DLL is never loaded). fail if values were changed successfully. pass if registry write was denied. not_applicable on non-Windows.

  • T1059.003 Windows Command Shelltechnique
    T1059.003 — Windows Command Shell

    Windows: attempt cmd.exe /c to write a marker file under the agent work directory, then delete it. fail if the marker appears. pass if AppLocker/WDAC/ASR or policy blocked cmd. not_applicable on non-Windows.

  • T1059.006 Pythontechnique
    T1059.006 — Python

    Windows: if python/py is on PATH, attempt a one-liner that writes a marker, then delete it. fail if the marker appears. pass if execution was blocked. not_applicable if Python is not installed or on non-Windows.

  • T1059.007 JavaScript / wscripttechnique
    T1059.007 — JavaScript / wscript

    Windows: attempt wscript.exe to run a tiny local .js that writes a marker, then delete artifacts. fail if the marker appears. pass if WSH/WDAC/ASR blocked wscript. not_applicable on non-Windows.

  • T1127.001 MSBuild Inline Tasktechnique
    T1127.001 — MSBuild Inline Task

    Windows: if MSBuild is present, run an inline WriteLinesToFile task that writes a marker, then delete project/marker. fail if the marker appears. pass if MSBuild was blocked. not_applicable if MSBuild is missing or on non-Windows.

  • T1218.007 msiexec Remote Packagetechnique
    T1218.007 — msiexec Remote Package

    Windows: attempt msiexec silent install against the ParityPT package probe URL (/api/probe/package on PUBLIC_URL / apiBaseUrl), capture whether msiexec launched, then stop/cleanup. fail if msiexec ran the remote package path. pass if msiexec could not start. not_applicable on non-Windows.

  • T1218.004 InstallUtil Probetechnique
    T1218.004 — InstallUtil Probe

    Windows: compile a tiny benign installer assembly (Add-Type) and run InstallUtil so Install() writes a marker, then delete artifacts. fail if the marker appears. pass if compile/InstallUtil was blocked. not_applicable if InstallUtil is missing or on non-Windows.

  • T1037.001 Logon Script Persistencetechnique
    T1037.001 — Logon Script Persistence

    Windows: attempt to set HKCU UserInitMprLogonScript to a benign temp .bat, verify, then revert and delete the bat (logon never runs it). fail if the value was set. pass if registry write was denied. not_applicable on non-Windows.

  • T1547.009 Startup Folder Shortcuttechnique
    T1547.009 — Startup Folder Shortcut

    Windows: attempt to create a Startup-folder .lnk that would launch cmd to write a marker, then delete the shortcut (target never launched). fail if the .lnk was created. pass if Startup write was denied. not_applicable on non-Windows.

  • T1546.008 Sticky Keys IFEO Probetechnique
    T1546.008 — Sticky Keys IFEO Probe

    Windows: attempt to set IFEO Debugger on sethc.exe to cmd.exe, verify, then immediately restore prior state (sethc never launched). fail if the Debugger value was set. pass if IFEO write was denied. not_applicable on non-Windows.

  • T1087.001 Local Account Discoverytechnique
    T1087.001 — Local Account Discovery

    Windows: run net user and grade whether local account listing output was obtained. fail if discovery returned results. pass if the command was blocked or produced no usable output. not_applicable on non-Windows.

  • T1057 Process Discoverytechnique
    T1057 — Process Discovery

    Windows: enumerate processes via Get-Process. fail if a process list was returned. pass if enumeration was blocked. not_applicable on non-Windows.

  • T1082 System Information Discoverytechnique
    T1082 — System Information Discovery

    Windows: collect basic host/OS identity (computer name + OS version string). fail if details were returned. pass if collection was blocked. not_applicable on non-Windows.

  • T1135 Network Share Discoverytechnique
    T1135 — Network Share Discovery

    Windows: run net share and grade whether share listing output was obtained. fail if discovery returned share names. pass if blocked or empty. not_applicable on non-Windows.

  • T1560.001 Archive Staged Datatechnique
    T1560.001 — Archive Staged Data

    Windows: create a zip of tiny benign temp files (Compress-Archive), verify creation, then delete. fail if the archive was created. pass if archiving was blocked. not_applicable on non-Windows.

  • T1071.001 Web Protocol C2 Beacontechnique
    T1071.001 — Web Protocol C2 Beacon

    Windows: attempt a benign HTTP(S) GET to the ParityPT beacon probe (/api/probe/beacon on PUBLIC_URL / apiBaseUrl) with a distinctive ParityPT User-Agent. fail only if a response is received. pass if egress filtering blocked the request. No third-party hosts. not_applicable on non-Windows.

  • T1041 Exfiltration Over C2 Channel (HTTP)technique
    T1041 — Exfiltration Over C2 Channel (HTTP)

    Windows: attempt a benign HTTP(S) POST of a small ASCII blob to the ParityPT exfil probe (/api/probe/exfil on PUBLIC_URL / apiBaseUrl). fail only if the ParityPT server accepts the POST. pass if egress filtering blocked upload. No third-party hosts. not_applicable on non-Windows.

  • T1071.004 DNS Application Layer Probetechnique
    T1071.004 — DNS Application Layer Probe

    Windows: resolve the ParityPT host from apiBaseUrl / PUBLIC_URL (hostname or IP). fail if name resolution completes. pass if DNS resolution is blocked closed. No third-party domains. not_applicable on non-Windows.

  • T1021.002 SMB Admin Share Accesstechnique
    T1021.002 — SMB Admin Share Access

    Windows: attempt to write a marker via \\127.0.0.1\C$\Windows\Temp, then delete it. fail if the admin share write succeeded. pass if admin share access was denied. not_applicable on non-Windows.

  • T1557.001 Name Resolution Poisoning Capturetechnique
    T1557.001 — Name Resolution Poisoning Capture

    Windows: listen for a configurable window (default 30s via check Timeout) on LLMNR/mDNS/NBT-NS, spoof replies to the agent host, and capture NetNTLM hashes over HTTP/SMB if clients authenticate. Does not relay credentials. fail if poisonable queries are observed or hashes are captured. pass if the window is quiet (and ideally LLMNR is disabled). not_applicable on non-Windows.