ParityPT catalog

APT groups, ransomware exercise, and checks

Browse purple teaming packs, the Ransomware Simulator stages, and ATT&CK-mapped techniques. Run a pack as published, or assemble a Custom Attack Chain and Build Your Own Narrative — phishing → purple teaming → ransomware. For standalone exercises see Phishing and Ransomware. Cards here are informational — sign in to run them.

  • T1486 Ransomware Canary Encryptexercise
    T1486 — Ransomware Canary Encrypt

    In the ransomware simulator, the agent encrypts designated canary files—reversibly in standard mode, or broadly under approved lab paths in aggressive mode—mimicking mass file impact. Successful encryption shows endpoint and application controls did not stop a encryptor-style process from modifying user data. When encryption is blocked, controlled folder access, EDR, or ACLs intercepted the activity before meaningful damage.

  • T1490 Ransomware Note Dropexercise
    T1490 — Ransomware Note Drop

    The simulator drops a marked ransom note file (README_PARITY_RANSOM.txt) in sandbox or lab directories, reproducing the psychological and forensic signature of real ransomware campaigns. A written note means nothing prevented file creation in those locations— the same gap real operators exploit for visibility and pressure. Blocked writes indicate filesystem or anti-ransomware controls are engaging on note-drop behavior.

  • T1490 Volume Shadow Copy Inhibitexercise
    T1490 — Volume Shadow Copy Inhibit

    This graded probe creates a single volume shadow copy via WMI/CIM (with legacy tooling fallback) and then deletes only that shadow—simulating the inhibit-recovery step many ransomware families perform before encryption. Completing create-and-delete shows a standard user context can manipulate VSS, which precedes full shadow wipe in real incidents. Denied or elevated-only operations indicate backup-recovery points are better protected.

  • T1490 Volume Shadow Copy Blow Upexercise
    T1490 — Volume Shadow Copy Blow Up

    In aggressive, acknowledged lab mode, the agent deletes all volume shadow copies on the system volume—mirroring the irreversible recovery destruction phase of ransomware. A drop in shadow count confirms an unprivileged or low-privileged process could wipe local restore points before encryption. When deletion is blocked or the inventory was already empty without a successful wipe, recovery snapshots are harder for an attacker to erase locally.

  • T1490 Backup Canary Wipeexercise
    T1490 — Backup Canary Wipe

    The agent stages fake backup files and deletes them—and in aggressive mode may target existing backup-like files under approved lab roots—simulating attackers who destroy local and pseudo-backup copies before encryption. Successful deletion means workstation principals can remove files that resemble backup stores, a pattern seen before full ransomware impact. Blocked deletes suggest backup paths or repositories are isolated from casual user delete rights.

  • Ransomware Simulator Recoverexercise
    Ransomware Simulator Recover

    Recover is the post-exercise cleanup action: it decrypts.paritylocked canaries using the assessment recovery key and removes simulator ransom notes from sandbox and lab paths. Successful recovery restores exercise files to their pre-impact state so aggressive labs do not leave operational debris. It does not rebuild volume shadow copies deleted by the blow-up stage—those require your normal backup restore process.

  • APT29 / Midnight Blizzard: Cozy Bear multi-interpreter + C2 pathAPT chain
    G0016

    Walks through multi-interpreter execution, WMI, persistence, Defender tamper, host and AD credential abuse (delegation, AdminSDHolder, DCSync rights, trusts), lateral movement, and HTTP C2/exfil. Run it to validate detections against a long-form espionage chain that blends scripting tradecraft with domain privilege escalation.

  • APT28 / Forest Blizzard: Fancy Bear LOLBin + persistenceAPT chain
    G0007

    Covers LOLBin and scripting execution, COM/Startup persistence, AD GPO/SYSVOL and delegation exposure, credential theft, and security log clearing. Use it to test whether your stack catches APT28-style foothold and cleanup behavior before attackers pivot deeper in the domain.

  • APT41 / Brass Typhoon: APT41 dual espionage / crimeware pathAPT chain
    G0096

    Stages ingress and certutil download, LOLBin execution, UAC bypass, service and BITS persistence, AD trust discovery, spooler coercion, credential access, and HTTP exfil. Teams run this to stress tradecraft that blends espionage and crimeware techniques on a single host path.

  • Lazarus Group: Lazarus implant pathAPT chain
    G0032

    Walks through ingress, HTTP C2, PowerShell execution, UAC bypass, service and IFEO persistence, Defender tamper, RDP enablement, and exfil. Validates whether you can detect and block an implant-style access chain after initial compromise.

  • FIN7: FIN7 living-off-the-landAPT chain
    G0046

    Tests mshta, regsvr32, cscript, and cmstp execution alongside certutil/HTTP C2, AS-REP roasting, GPO/SYSVOL exposure, and scheduled-task/BITS persistence. Ideal for assessing living-off-the-land detections against payment-sector tradecraft that avoids custom malware.

  • Sandworm / Voodoo Bear: Sandworm WMI/opsAPT chain
    G0034

    Focuses on WMI execution and event subscription persistence, PowerShell, scheduled-task and service persistence, and security log clearing. Run it to verify operational detections for WMI-heavy intrusion and anti-forensics on Windows hosts.

  • Wizard Spider: Wizard Spider ransomware prepAPT chain
    G0102

    Simulates affiliate prep: ingress and HTTP C2, defense tamper, host and AD credential abuse (Kerberoast, AS-REP, password policy), privileged group recon, GPO/SYSVOL exposure, lateral movement surfaces, staging, and ransomware impact canaries. Exercises the full pre-encryption path affiliates use before deploying ransomware.

  • Volt Typhoon: Volt Typhoon living-off-the-landAPT chain
    G1017

    Uses native Windows tooling for host and AD discovery, WMI and script execution, certutil/DNS/HTTP C2, netsh helper and scheduled-task persistence, WinRM lateral movement, and log clearing. Validates detection of quiet, hands-on-keyboard activity that avoids third-party malware.

  • Scattered Spider: Scattered Spider identity + remote accessAPT chain
    G1015

    Targets identity abuse: host and AD discovery, scripting, AS-REP/Kerberoast and password-policy probes, local account creation, RDP and WinRM enablement, and defense tamper. Run this to test controls against groups that prioritize credential theft and interactive remote access over malware deployment.

  • Turla: Turla stealth persistenceAPT chain
    G0010

    Exercises quiet LOLBin execution, COM/AppInit/netsh persistence, LSASS credential access, and security log clearing. Use it to evaluate stealthy long-dwell persistence detections aligned with a low-noise host footprint.

  • APT33 / Peach Sandstorm: APT33 / Peach SandstormAPT chain
    G0064

    Covers PowerShell and cscript execution, ingress and HTTP C2, scheduled-task and service persistence, credential access, Defender tamper, and exfil. Validates end-to-end detections for a compact initial access and staging chain.

  • APT34 / OilRig: APT34 / OilRigAPT chain
    G0049

    Tests mshta and PowerShell execution, certutil staging, COM/Startup persistence, and LSASS/SAM credential access. Run it to assess document-adjacent execution and quiet persistence on compromised workstations.

  • APT35 / Charming Kitten: APT35 / Charming KittenAPT chain
    G0059

    Exercises script-host and PowerShell execution, ingress and HTTP C2, Run-key/Startup persistence, credential theft, and HTTP exfil. Useful for testing phishing-driven footholds that establish persistence quickly on a single endpoint.

  • APT10 / menuPass: APT10 / menuPassAPT chain
    G0045

    Stages ingress, certutil, and HTTP C2, rundll32/regsvr32 execution, service and scheduled-task persistence, credential access, WinRM lateral movement, and exfil. Validates detections against long-haul espionage tradecraft on Windows infrastructure.

  • APT32 / OceanLotus: APT32 / OceanLotusAPT chain
    G0050

    LOLBin-heavy execution via mshta, cmstp, and cscript, plus HTTP C2, COM/AppInit persistence, Defender tamper, log clearing, and exfil. Run this to test tradecraft that favors dual-use binaries and layered defense evasion.

  • APT37 / Reaper: APT37 / ReaperAPT chain
    G0067

    Covers scripting and document-adjacent LOLBins, ingress and HTTP C2, scheduled-task/Run-key persistence, credential access, and exfil. Exercises a typical initial compromise through credential theft on a single endpoint path.

  • APT38: APT38 financial ops prepAPT chain
    G0082

    Tests ingress and HTTP C2, defense tamper (Defender, firewall, log clearing), credential access, service persistence, RDP enablement, and exfil. Use it to validate controls ahead of financial-sector intrusions that prioritize quiet lateral movement and defense disablement.

  • APT39 / Chafer: APT39 / ChaferAPT chain
    G0087

    Exercises PowerShell, cmd, and WMI execution, multi-vector persistence, credential access, WinRM enablement, and HTTP/DNS C2. Run this to assess tradecraft focused on surveillance and remote administration paths.

  • APT40 / Leviathan: APT40 / LeviathanAPT chain
    G0065

    Covers web and LOLBin execution, certutil/ingress/HTTP C2, COM/Startup persistence, credential access, and exfil. Validates staging and persistence detections on research and maritime-sector targets.

  • APT31 / Zirconium: APT31 / ZirconiumAPT chain
    G0099

    Focuses on host discovery, scripting, scheduled-task persistence, HTTP/DNS C2, and archived HTTP exfil. Run it to test long-campaign tradecraft that emphasizes reconnaissance and staged data collection before exfiltration.

  • MuddyWater: MuddyWaterAPT chain
    G0069

    Tests mshta, cscript, and PowerShell execution, ingress and HTTP C2, BITS and scheduled-task persistence, credential access, and exfil. Exercises intrusion patterns that blend script droppers with resilient persistence.

  • HAFNIUM: HAFNIUM post-compromiseAPT chain
    G0125

    Post-compromise style: host discovery, web and script execution, credential access, WinRM/RDP lateral movement, and HTTP C2. Run this to validate on-prem detections after server initial access—not a web-shell implant test.

  • Dragonfly / Energetic Bear: Dragonfly / Energetic BearAPT chain
    G0035

    Combines WMI and LOTL execution, host discovery, service and scheduled-task persistence, HTTP/DNS C2, and credential access. Tests ICS-adjacent tradecraft on Windows hosts without requiring OT-specific tooling.

  • Mustang Panda: Mustang PandaAPT chain
    G0129

    Uses document-adjacent LOLBins, certutil and HTTP C2 staging, Startup and scheduled-task persistence, and credential access. Validates detections against campaigns that favor phishing lures and native staging tools.

  • Kimsuky: KimsukyAPT chain
    G0094

    Covers PowerShell and script execution, ingress and HTTP C2, Run-key/IFEO persistence, LSASS/SAM credential theft, and exfil. Run this to assess espionage footholds on researcher and policy targets.

  • LockBit-style ops: LockBit-style affiliate prepAPT chain
    G0140

    Fast ingress and HTTP C2, defense disablement (Defender, firewall, log clearing), host and AD credential abuse, privileged group recon, spooler coercion, account creation, RDP, staging, and ransomware impact canaries. Exercises the compressed affiliate playbook used before LockBit-style encryption deployments.

  • APT1 / Comment Crew: APT1 / Comment Crew classicAPT chain
    G0006

    Classic intrusion pattern: ingress and HTTP C2, scripting, service/scheduled-task/Run-key persistence, credential access, and RDP. Use it as a baseline long-dwell espionage chain to benchmark foundational detections.

  • Gamaredon: GamaredonAPT chain
    G0047

    Aggressive scripting and LOLBins, certutil and HTTP C2 staging, Startup and BITS persistence, credential access, and exfil. Run this to test high-volume, noisy tradecraft typical of sustained targeting campaigns.

  • FIN6: FIN6 AD identity abuseAPT chain
    G0037

    AD-focused identity abuse: privileged group recon, AS-REP/Kerberoast, password-policy probes, AdminSDHolder discovery, GPO/SYSVOL exposure, and light host credential access. Validates identity-layer controls against payment-sector abuse without full ransomware impact.

  • Black Basta: Black Basta coerce + relay surfaceAPT chain
    G1040

    Tests name-poison capture, LDAP signing posture, spooler/RPC coercion, Kerberoast/AS-REP, defense tamper, staging, and ransomware impact canaries. Run this to validate coerce/relay and AD credential surfaces that affiliates exploit before encryption.

  • APT29 / Midnight Blizzard: Midnight Blizzard domain dominanceAPT chain
    G0016

    AD-heavy follow-on: trust and privileged-group discovery, Kerberos delegation, AdminSDHolder, DCSync rights, ADCS abuse, shadow credentials, SID history, GPO/SYSVOL collection, and exfil. Exercises domain dominance paths beyond initial host compromise—run after foothold validation to test tier-zero controls.

  • T1059.001 Encoded PowerShell Executiontechnique
    T1059.001 — Encoded PowerShell Execution

    This exercise launches PowerShell using a Base64-encoded command line, a common way attackers hide malicious scripts from casual inspection. When controls block the technique, encoded execution or outbound staging is stopped before it completes. When it succeeds, obfuscated PowerShell ran—indicating a meaningful detection and prevention gap.

  • T1218.005 mshta LOLBin Executiontechnique
    T1218.005 — mshta LOLBin Execution

    This exercise runs mshta.exe, a signed Windows binary often abused to execute HTML Application scripts without dropping a traditional executable. Blocking means application control, ASR, or network policy prevented mshta from completing its action or reaching outbound endpoints. Success means mshta executed the staged content—behavior consistent with living-off-the-land intrusion tradecraft.

  • T1053.005 Scheduled Task Persistencetechnique
    T1053.005 — Scheduled Task Persistence

    This exercise registers a short-lived scheduled task, mimicking a common persistence method that survives reboots and runs under a trusted scheduler context. The probe verifies the task was registered, then removes it so no lasting change remains. When creation is denied, privilege boundaries or policy prevented an unprivileged actor from establishing scheduled persistence. When creation succeeds, an attacker at the same privilege level could register tasks—a control gap worth addressing before real malware does the same.

  • T1547.001 Registry Run Key Persistencetechnique
    T1547.001 — Registry Run Key Persistence

    This exercise writes a benign value to a Run or RunOnce registry key, simulating autorun persistence that executes at user logon. The probe confirms the value landed, then deletes it. Denied writes indicate registry protections or EDR persistence controls are effective for the tested identity. A successful write means the account could establish autorun persistence—a finding that should trigger hardening of registry monitoring and admin rights.

  • T1003.001 LSASS Credential Dumptechnique
    T1003.001 — LSASS Credential Dump

    This exercise attempts to open a handle to the LSASS process—the memory space where Windows stores interactive credentials. The probe requests limited query access by default and can escalate to VM_READ access masks that credential-theft tooling typically needs, still without writing a memory dump. The goal is to see whether credential-theft protections detect or block access to LSASS. When blocked, PPL, Credential Guard, ASR, or EDR credential-access rules prevented the handle from opening. When the handle opens, an actor at the tested privilege level can touch LSASS, which is a strong precursor to credential theft and lateral movement.

  • T1562.001 Defender Tamper Attempttechnique
    T1562.001 — Defender Tamper Attempt

    This exercise attempts a controlled change to Windows Defender—such as adding a temporary exclusion or disabling real-time protection—then reverts any change that went through. The intent is to test whether tamper protection and administrative controls prevent endpoint defenses from being weakened on the host. When blocked, Defender settings remained intact under policy or tamper protection. When tampering succeeds, even briefly, an attacker could blind or bypass local AV before the revert—an exposure that demands immediate policy review.

  • T1105 Ingress Tool Transfertechnique
    T1105 — Ingress Tool Transfer

    This exercise downloads a known-benign file from the assessment platform over HTTPS, simulating ingress tool transfer—the stage where attackers pull second-stage payloads onto a compromised host. The probe hashes the file, confirms it arrived, then deletes it. When network filtering, ASR, or proxy policy blocks the download, ingress is constrained. When the download completes, outbound HTTPS retrieval of arbitrary content succeeded—a common initial step in ransomware and post-exploitation workflows.

  • T1543.003 Service Installationtechnique
    T1543.003 — Service Installation

    This exercise attempts to register a temporary Windows service, a persistence and privilege technique that runs code under the Service Control Manager with SYSTEM context when configured that way. The probe verifies registration, then deletes the service. Denied creation indicates the tested account lacks rights or policy blocks new service installation. Successful creation means an actor at that privilege level can install services—a high-impact persistence vector on servers and workstations alike.

  • T1070.001 Security Log Clear Capabilitytechnique
    T1070.001 — Security Log Clear Capability

    This exercise checks whether the running token holds or can enable SeSecurityPrivilege—the right required to clear the Windows Security event log—without actually wiping the log. It is a dry capability probe aligned to the privilege level of the account under test. When the privilege is absent or cannot be enabled, the account cannot erase Security log evidence locally—a positive control outcome. When the capability is present, a compromised admin could destroy audit trails on the endpoint, which makes centralized log forwarding essential.

  • T1548.002 UAC Bypass Path Probetechnique
    T1548.002 — UAC Bypass Path Probe

    This exercise tests a fodhelper-style User Account Control bypass: a temporary registry handler redirects an auto-elevating Windows binary to run a payload command without a consent prompt. The probe cleans up registry changes and stray processes immediately afterward. When the hijack write is denied, UAC bypass paths are constrained for the tested user. When the handler is set or an elevated payload is written, silent elevation without prompt succeeded—meaning standard users may reach admin context through a known bypass.

  • T1218.010 regsvr32 Scriptlet Executiontechnique
    T1218.010 — regsvr32 Scriptlet Execution

    This exercise invokes regsvr32 with a scriptlet, abusing a trusted signed binary to run script code—technique often called Squiblydoo. Blocking by ASR, AppLocker, or network policy stops regsvr32 from completing the scriptlet or reaching outbound endpoints. Success means regsvr32 executed attacker-controlled script content—behavior aligned with Squiblydoo-style intrusion tradecraft.

  • T1218.011 rundll32 Proxy Executiontechnique
    T1218.011 — rundll32 Proxy Execution

    This exercise launches rundll32.exe to invoke a DLL export or proxy execution path, a classic LOLBin pattern used to run code without spawning a obvious malicious executable. When WDAC, AppLocker, or ASR blocks rundll32 or outbound staging, the proxy chain stops early. Success indicates rundll32 completed the proxy execution—behavior seen in commodity loaders and hands-on-keyboard activity.

  • T1547.001 Startup Folder Persistencetechnique
    T1547.001 — Startup Folder Persistence

    This exercise drops a short-lived script into the current user's Startup folder, simulating logon persistence that executes without touching the registry. The probe confirms the file landed, then removes it without waiting for a reboot. Denied writes show folder protections or EDR persistence controls are working for the tested identity. A successful write means the account can plant logon persistence—a finding that should drive monitoring of Startup folder changes across the fleet.

  • T1047 WMI Process Createtechnique
    T1047 — WMI Process Create

    This exercise creates a process through WMI's Win32_Process.Create method, a technique attackers use for stealthy execution and lateral movement because it often appears as WmiPrvSE spawning children. When WMI permissions, AppLocker, or egress controls block creation or staging, the chain fails. Success means WMI launched the intended process—indicating WMI is a viable execution path for the tested account.

  • T1562.004 Firewall Disable Attempttechnique
    T1562.004 — Firewall Disable Attempt

    This exercise briefly attempts to disable a Windows Firewall profile, simulating defense evasion where attackers open the host to inbound connections or reduce outbound inspection visibility. The probe verifies the state change, then restores the prior configuration. When policy or tamper controls block the change, the firewall profile remained enabled—a desired outcome. When disable succeeds, even momentarily, local firewall protections can be weakened on demand, which often precedes lateral movement or C2 establishment.

  • T1197 BITS Job Persistencetechnique
    T1197 — BITS Job Persistence

    This exercise creates a short-lived Background Intelligent Transfer Service job, a technique abusers leverage for quiet downloads and persistence because BITS runs with service privileges and can resume transfers. The probe confirms the job registered, then cancels and removes it. Denied job creation indicates BITS abuse is constrained for the tested account. Successful creation means an actor can register BITS jobs—a tradecraft vector for stealthy ingress and scheduled retrieval.

  • T1546.015 COM Hijack Probetechnique
    T1546.015 — COM Hijack Probe

    This exercise writes a temporary COM hijack under the current user's Classes hive, redirecting a CLSID to a benign path—simulating persistence and elevation tricks that load attacker code when a legitimate COM object is instantiated. The probe verifies the key, then removes it without loading a malicious server. Denied registry writes indicate COM hijack persistence is blocked for the tested user. Successful writes mean HKCU COM overrides can be established—a common persistence method that evades naive HKLM-only monitoring.

  • T1136.001 Local Account Creationtechnique
    T1136.001 — Local Account Creation

    This exercise attempts to create a temporary local user account, mimicking post-exploitation steps where attackers establish backup access independent of domain credentials. The probe verifies the account exists, then deletes it. Denied creation shows the tested identity cannot add local users—a sound least-privilege outcome. Successful creation means a local backdoor account could be added at the same privilege level, which is especially concerning on servers and shared workstations.

  • T1021.001 RDP Enable Attempttechnique
    T1021.001 — RDP Enable Attempt

    This exercise attempts to enable Remote Desktop by changing the fDenyTSConnections setting, simulating how attackers open graphical remote access for persistence and interactive control. The probe verifies the change, then restores the prior value. When registry or policy blocks the change, RDP remains disabled as intended. When enable succeeds, even briefly, the host accepted a configuration that allows remote desktop sessions—a common step before hands-on-keyboard activity over port 3389.

  • T1059.005 cscript / VBScript Executiontechnique
    T1059.005 — cscript / VBScript Execution

    This exercise runs a VBScript through cscript.exe, validating that Windows Script Host remains a viable execution path on the endpoint. When WDAC, AppLocker, or ASR blocks cscript or outbound staging, script-host abuse is constrained. Success means cscript executed the staged script—behavior aligned with phishing droppers and legacy malware chains.

  • T1105 certutil Decode / Ingresstechnique
    T1105 — certutil Decode / Ingress

    This exercise uses certutil.exe to decode a local Base64 blob or download staged content—abusing a signed utility commonly seen in fileless download cradles. Blocking by application control or egress policy stops certutil from decoding or reaching remote endpoints. Success means certutil completed the decode or download chain, indicating this LOLBin remains available for staging malware without traditional download tools.

  • T1218.003 cmstp INF Executiontechnique
    T1218.003 — cmstp INF Execution

    This exercise runs cmstp.exe against a benign INF file, simulating a Connection Manager Profile Installer abuse path that can execute commands and, in some configurations, interact with UAC elevation behavior. When WDAC, AppLocker, or ASR blocks cmstp or network staging, the LOLBin chain stops. Success means cmstp processed the INF—a known bypass and execution vector in red-team and real-world intrusions.

  • T1546.003 WMI Event Subscriptiontechnique
    T1546.003 — WMI Event Subscription

    This exercise creates a temporary WMI event subscription—filter, consumer, and binding—mimicking fileless persistence that fires when a defined condition occurs, often without dropping traditional malware on disk. The probe verifies the subscription objects exist, then deletes them without waiting for a trigger. Denied creation indicates WMI persistence is blocked for the tested identity. Successful creation means permanent-style WMI subscriptions can be registered—a stealthy persistence channel that survives reboots when left in place.

  • T1546.012 IFEO Debugger Persistencetechnique
    T1546.012 — IFEO Debugger Persistence

    This exercise writes a temporary Image File Execution Options Debugger value for a benign executable name, simulating persistence that hijacks process launch so a debugger command runs whenever the target image starts. The probe verifies the registry value, then removes it without launching the target. Denied writes indicate IFEO modifications are blocked for the tested privilege level. Successful writes mean an actor can set IFEO debugger keys—a technique used for persistence, accessibility abuse, and silent process redirection.

  • T1003.002 SAM Registry Hive Dumptechnique
    T1003.002 — SAM Registry Hive Dump

    This exercise attempts to export the SAM and SYSTEM registry hives with reg save, the same offline path attackers use to recover local password hashes. Success indicates an elevated session can pull credential material without touching LSASS directly. Temporary hive files are deleted immediately after the attempt.

  • T1021.006 WinRM Enable Attempttechnique
    T1021.006 — WinRM Enable Attempt

    The agent tries to turn on WinRM auto-configuration, which opens a remote PowerShell and management channel on the host. Attackers often enable WinRM after gaining admin rights to move laterally without RDP. The prior WinRM policy is restored when the check finishes.

  • T1546.007 netsh Helper DLLtechnique
    T1546.007 — netsh Helper DLL

    This probe registers a benign DLL as a netsh helper, a persistence technique that loads attacker code whenever netsh runs. Helpers survive reboots and blend into legitimate network administration tooling. The registration is removed before the agent exits; no DLL is actually loaded.

  • T1546.010 AppInit_DLLs Persistencetechnique
    T1546.010 — AppInit_DLLs Persistence

    The check attempts to set AppInit_DLLs and LoadAppInit_DLLs so a DLL would load into every GUI process that links user32. This is a classic persistence path on older Windows builds, though Secure Boot and modern defaults often block it. Registry values are reverted immediately; no DLL is loaded.

  • T1059.003 Windows Command Shelltechnique
    T1059.003 — Windows Command Shell

    This simulation runs cmd.exe with a benign command chain—the same entry point used in living-off-the-land attacks, phishing follow-on, and staged downloaders. Defenses should catch cmd spawning from unusual parents or writing to Temp.

  • T1059.006 Pythontechnique
    T1059.006 — Python

    The agent runs a real python or py interpreter on PATH to execute a short script—Microsoft Store execution aliases are ignored. Python is increasingly used as a cross-platform implant and staging runtime on Windows endpoints.

  • T1059.007 JavaScript / wscripttechnique
    T1059.007 — JavaScript / wscript

    This exercise launches wscript.exe against a local JScript file, the same script-host path seen in macro droppers and fileless staging chains. JScript can invoke WScript.Shell, write files, and spawn PowerShell without a compiled binary.

  • T1127.001 MSBuild Inline Tasktechnique
    T1127.001 — MSBuild Inline Task

    The agent invokes MSBuild against a project containing inline task code—a trusted signed binary that compiles and executes arbitrary.NET without dropping a separate executable. Attackers abuse MSBuild on workstations to bypass application whitelisting.

  • T1218.007 msiexec Remote Packagetechnique
    T1218.007 — msiexec Remote Package

    This probe runs msiexec against a remote package URL on the ParityPT assessment host, simulating silent install from the network—a common LOLBin for pulling payloads without a browser download. Success means msiexec could reach out and attempt the install path. No third-party hosts are contacted.

  • T1218.004 InstallUtil Probetechnique
    T1218.004 — InstallUtil Probe

    The check compiles and runs a benign.NET installer through InstallUtil.exe, which loads and executes an assembly's uninstall method—another signed Microsoft binary abused for code execution. Attackers pair this with inline compilation to avoid dropping obvious executables.

  • T1037.001 Logon Script Persistencetechnique
    T1037.001 — Logon Script Persistence

    The agent sets the UserInitMprLogonScript registry value to point at a benign batch file, establishing logon-script persistence that runs on every user sign-in. This UserInitMprLogonScript path is less monitored than Run keys but equally durable. The value is reverted and the batch file deleted; logon is not waited for.

  • T1547.009 Startup Folder Shortcuttechnique
    T1547.009 — Startup Folder Shortcut

    This exercise drops a.lnk shortcut in the user's Startup folder targeting cmd to write a payload—a persistence method that survives reboots and avoids direct registry edits. Startup shortcuts are easy to miss in autoruns reviews because they look like user preferences. The shortcut is deleted immediately; the target is never launched.

  • T1546.008 Sticky Keys IFEO Probetechnique
    T1546.008 — Sticky Keys IFEO Probe

    The check sets an Image File Execution Options Debugger on sethc.exe (Sticky Keys) to cmd.exe—the accessibility backdoor used when attackers have console or RDP access and want a SYSTEM shell at the login screen. IFEO debugger hijacks on accessibility binaries are a well-known privilege-escalation path. The Debugger value is restored immediately; sethc is never launched.

  • T1087.001 Local Account Discoverytechnique
    T1087.001 — Local Account Discovery

    The agent runs net user to list local accounts on the host, a standard reconnaissance step after initial access. Account names reveal service accounts, shared workstations, and naming conventions useful for password spraying or targeted attacks. Empty output is treated as inconclusive rather than a clean result.

  • T1057 Process Discoverytechnique
    T1057 — Process Discovery

    This probe enumerates running processes via tasklist or Get-Process to map security tools, VPN clients, and high-value applications on the endpoint. Process lists help attackers choose evasion techniques and timing for credential access. Empty output is inconclusive.

  • T1082 System Information Discoverytechnique
    T1082 — System Information Discovery

    The agent collects basic host identity—computer name and OS version—information attackers use to tailor payloads and identify domain membership. This is often among the first commands in an intrusion after foothold. Empty output is inconclusive.

  • T1135 Network Share Discoverytechnique
    T1135 — Network Share Discovery

    The check runs net share to list shares exposed on the local machine, revealing file servers, hidden admin shares, and misconfigured permissions. Share enumeration frequently precedes lateral movement over SMB or admin-share abuse. Empty output is inconclusive.

  • T1560.001 Archive Staged Datatechnique
    T1560.001 — Archive Staged Data

    The agent creates a zip archive of small benign temp files using Compress-Archive, simulating the staging step before data exfiltration. Attackers compress collections to reduce transfer size and evade simple DLP on individual files. The archive is deleted after verification.

  • T1071.001 Web Protocol C2 Beacontechnique
    T1071.001 — Web Protocol C2 Beacon

    This exercise sends a benign HTTPS GET to the ParityPT beacon endpoint with a distinctive assessment User-Agent, simulating periodic command-and-control check-ins over web protocols. Outbound HTTPS is the most common C2 channel because it blends with normal traffic. Only the configured ParityPT host is contacted.

  • T1041 Exfiltration Over C2 Channel (HTTP)technique
    T1041 — Exfiltration Over C2 Channel (HTTP)

    The agent attempts an HTTPS POST of a small benign blob to the ParityPT exfil probe, representing data theft over the same channel as C2. Successful upload means outbound POST bodies are not inspected or blocked at the perimeter. Only the ParityPT assessment host receives the POST.

  • T1071.004 DNS Application Layer Probetechnique
    T1071.004 — DNS Application Layer Probe

    This probe resolves the ParityPT assessment hostname through the endpoint's configured DNS resolver, testing whether DNS is available as a command or exfiltration channel. DNS tunneling and lookup-based C2 often bypass web proxies entirely. Only the ParityPT host name is queried.

  • T1021.002 SMB Admin Share Accesstechnique
    T1021.002 — SMB Admin Share Access

    The agent attempts to write a short-lived payload through the local C$ administrative share at 127.0.0.1, the same SMB path used for lateral movement and remote file placement. Admin share write access from a standard user context indicates dangerous local privilege or misconfiguration. The payload is deleted after the attempt.

  • T1557.001 Name Resolution Poisoning Capturetechnique
    T1557.001 — Name Resolution Poisoning Capture

    For a short listen window the agent watches LLMNR, mDNS, and NBT-NS, responds to poisonable name lookups, and captures NetNTLM hashes offered over HTTP and SMB—without relaying credentials. This mirrors responder-style attacks on flat networks where multicast name resolution is still enabled. Domain controllers are skipped; LanmanServer is paused briefly and restored.

  • T1518.001 Security Software Discoverytechnique
    T1518.001 — Security Software Discovery

    This check simulates early-stage reconnaissance to identify installed antivirus, EDR, and other security products on the endpoint. When enumeration succeeds, an attacker learns which defenses are present and can tailor evasion or tampering accordingly. Detection or blocking here indicates your controls are surfacing security-software discovery before follow-on disablement attempts.

  • T1518 Software Discoverytechnique
    T1518 — Software Discovery

    This check samples installed application names from Windows Uninstall registry keys, a common post-compromise inventory technique. Successful enumeration gives an attacker a map of exploitable software, VPN clients, and admin utilities on the host. Blocking or alerting on bulk registry reads limits targeted exploitation of known vulnerable applications.

  • T1016 System Network Configuration Discoverytechnique
    T1016 — System Network Configuration Discovery

    This check collects local IP addresses, DNS settings, and adapter details—the network mapping attackers perform after gaining a foothold. When it succeeds, the adversary gains context on routing, segmentation, and reachable subnets for lateral movement. Denial or detection shows visibility into host-level network reconnaissance in the attack chain.

  • T1049 System Network Connections Discoverytechnique
    T1049 — System Network Connections Discovery

    This check lists established TCP connections to reveal live communication partners, admin sessions, and potential command-and-control endpoints. Success exposes relationships an attacker can exploit for pivoting or blending with legitimate traffic. Monitoring netstat-style enumeration from non-admin tooling catches this mid-campaign reconnaissance.

  • T1018 Remote System Discoverytechnique
    T1018 — Remote System Discovery

    This check discovers nearby systems through ARP cache, neighbor tables, and NetBIOS-style host queries without performing a port scan. Successful discovery expands the attacker's target list within the broadcast domain. Segmentation and detection of neighbor or net view enumeration reduce options for lateral movement.

  • T1083 File and Directory Discoverytechnique
    T1083 — File and Directory Discovery

    This check performs shallow directory listing of high-value paths such as user Desktop, Documents, and ProgramData. Success indicates an attacker can map where sensitive files may reside before collection or staging. Alerting on scripted directory enumeration from unusual parents helps catch pre-exfiltration activity early.

  • T1012 Query Registrytechnique
    T1012 — Query Registry

    This check reads common registry keys used for persistence scouting, software inventory, and environment mapping. When queries succeed, an attacker learns autorun locations, installed products, and system configuration details. Registry telemetry and appropriate ACLs limit passive environment reconnaissance on workstations.

  • T1069.001 Local Groupstechnique
    T1069.001 — Local Groups

    This check enumerates local security groups and administrator membership on the workstation. Success reveals who holds elevated local access—a common precursor to privilege escalation or targeted credential theft. Monitoring local group queries from non-IT processes surfaces this reconnaissance before abuse occurs.

  • T1007 System Service Discoverytechnique
    T1007 — System Service Discovery

    This check samples installed and running Windows services to identify security tools, management agents, and potential persistence targets. Successful enumeration helps an attacker plan service abuse, evasion, or binary-path manipulation. Correlating service discovery with subsequent service creation strengthens end-to-end detection.

  • T1033 System Owner/User Discoverytechnique
    T1033 — System Owner/User Discovery

    This check collects the current logged-on user and active session details through standard identity commands. Success confirms which account context the attacker occupies and whether privileged sessions are active on the host. Baseline and alert on bursts of identity discovery from implants or Office macro child processes.

  • T1120 Peripheral Device Discoverytechnique
    T1120 — Peripheral Device Discovery

    This check enumerates connected PnP and USB-style devices to assess removable media and hardware attack surfaces. Success may indicate preparation for data theft via external drives or evaluation of device-control policies. PnP enumeration from unexpected processes warrants investigation, especially before large file transfers.

  • T1555.004 Windows Credential Managertechnique
    T1555.004 — Windows Credential Manager

    This check attempts to read secrets stored in Windows Credential Manager, including saved passwords and network credentials. Success means locally stored credentials can be harvested for lateral movement, VPN access, or cloud sign-in. Recovered material is sealed for assessment review rather than left in finding text.

  • T1555.003 Credentials from Web Browserstechnique
    T1555.003 — Credentials from Web Browsers

    This check accesses Chromium-based browser password stores, decrypts saved login credentials, and records recovered secrets for assessment review. Success demonstrates that browser-stored passwords are extractable on the endpoint—a common post-phishing objective. Empty or inaccessible vaults are treated as out of scope rather than a control success.

  • T1003.005 Cached Domain Credentialstechnique
    T1003.005 — Cached Domain Credentials

    This check assesses MITRE ATT&CK T1003.005 on domain-joined hosts by exporting the SECURITY and SYSTEM registry hives (the path used to recover cached domain logon hashes offline). Workgroup / non-domain hosts are N/A — they do not store domain MSCache/DCC2 material. Hive files are removed after the probe.

  • T1115 Clipboard Datatechnique
    T1115 — Clipboard Data

    This check reads the current clipboard contents, which often contain passwords, tokens, or sensitive text copied by users. Success shows clipboard data is accessible to code running in the user session without additional privileges. Collected text is sealed for assessment review and is not written to disk on the host.

  • T1114 Email Collectiontechnique
    T1114 — Email Collection

    This check locates Outlook OST and PST data files under the user profile without reading mailbox content. Success confirms mail archives are present and reachable—a staging step before full email theft or search. Monitoring non-Outlook processes touching mail data paths helps detect escalation from discovery to collection.

  • T1053.005 Remote Scheduled Task Probetechnique
    T1053.005 — Remote Scheduled Task Probe

    This check creates and runs a short-lived scheduled task using remote task scheduler syntax against localhost, mimicking lateral execution via schtasks. Success means remote-style task operations are permitted—a technique commonly used to run code on other hosts without interactive logon. The task is deleted after execution and is not left as persistence.

  • T1021.006 WinRM Invoke Probetechnique
    T1021.006 — WinRM Invoke Probe

    This check attempts to execute a command on localhost through WinRM remote invocation, simulating PowerShell remoting lateral movement. Success indicates WinRM-based remote execution is available from the current security context. This exercise uses invocation only and does not enable or reconfigure the WinRM service.

  • T1021.003 DCOM / WMI Lateral Probetechnique
    T1021.003 — DCOM / WMI Lateral Probe

    This check attempts remote process creation against localhost via WMI and DCOM, a classic lateral execution path used to run commands without an interactive logon. Success shows WMI remote execution is permitted from the current context. Any spawned marker process is short-lived and no persistent services or tasks are left behind.

  • T1134 Access Token Privilege Enumerationtechnique
    T1134 — Access Token Privilege Enumeration

    This check lists privileges held by the current process token, such as SeDebugPrivilege or SeImpersonatePrivilege. Success reveals which escalation paths may be available without yet attempting token theft or impersonation. This is reconnaissance only—the assessment does not duplicate, steal, or adjust tokens.

  • T1558.003 Kerberoasting Probetechnique
    T1558.003 — Kerberoasting Probe

    This check searches Active Directory for user accounts with service principal names and requests Kerberos service tickets suitable for offline password cracking. Success means roastable service accounts exist and ticket material was captured—a direct path toward domain credential compromise. Recovered hashes are sealed for assessment review in standard cracking formats.

  • T1558.004 AS-REP Roasting Probetechnique
    T1558.004 — AS-REP Roasting Probe

    This check identifies domain accounts exempt from Kerberos pre-authentication and requests AS-REP hashes for offline cracking. Success indicates misconfigured accounts that allow authentication material to be harvested without knowing the current password. When no such accounts exist or LDAP access is denied, the exposure is reduced.

  • T1558.001 Kerberos Delegation Exposuretechnique
    T1558.001 — Kerberos Delegation Exposure

    This check enumerates Kerberos delegation configurations including unconstrained, constrained, and resource-based constrained delegation across Active Directory objects. Success exposes delegation relationships adversaries abuse for impersonation and privilege escalation, especially toward tier-zero assets. Readable delegation metadata helps attackers prioritize high-impact targets before ticket abuse.

  • T1069.002 Privileged Domain Group Discoverytechnique
    T1069.002 — Privileged Domain Group Discovery

    This check queries Active Directory for high-value groups such as Domain Admins and reads membership where the bind identity is permitted. Success means privileged accounts can be mapped—a BloodHound-style reconnaissance step before targeted compromise. Broad read access to tier-zero membership significantly shortens an attacker's path to domain dominance.

  • T1482 Domain Trust Discoverytechnique
    T1482 — Domain Trust Discovery

    This exercise maps domain and forest trust relationships from Active Directory—direction, type, and partner domains—much like an attacker would during cross-domain reconnaissance. When the agent can read trustedDomain objects, your AD is exposing trust topology to any authenticated (or weakly authenticated) caller who knows where to look. A blocked or empty result means LDAP access controls or monitoring are limiting how much of that attack surface is visible from a standard endpoint.

  • T1552.006 GPO / SYSVOL Exposure Probetechnique
    T1552.006 — GPO / SYSVOL Exposure Probe

    The agent enumerates Group Policy objects over LDAP and walks SYSVOL for legacy Group Policy Preferences files that may still contain encrypted cpassword values. Readable GPO metadata or recoverable cpassword artifacts give an intruder a direct path to local and domain credentials without touching a DC interactively. When enumeration or file reads are denied, GPO and SYSVOL exposure is better contained.

  • T1557 LDAP Signing Posture Probetechnique
    T1557 — LDAP Signing Posture Probe

    After a normal authenticated bind, the agent tests whether the domain controller still accepts unsigned LDAP connections. DCs that permit unsigned binds are vulnerable to relay and man-in-the-middle attacks that piggyback on NTLM or other cleartext-adjacent authentication paths. When unsigned binds are rejected, a key prerequisite for LDAP relay has been removed.

  • T1222.001 AdminSDHolder ACL / adminCount Discoverytechnique
    T1222.001 — AdminSDHolder ACL / adminCount Discovery

    This check surfaces accounts marked with adminCount and inspects AdminSDHolder-related ACL exposure—protected principals that should inherit tier-zero security descriptors. Broad visibility into adminCount users or unexpected write access to AdminSDHolder creates paths toward persistent privilege escalation. Tighter LDAP controls and clean adminCount hygiene reduce how much of that surface an attacker can map.

  • T1003.006 DCSync Rights Discoverytechnique
    T1003.006 — DCSync Rights Discovery

    The agent reads the domain naming context DACL and identifies principals other than domain controllers and baseline admin groups that hold replication-style rights—without performing an actual DCSync. Unexpected trustees with Get-Changes–class permissions can extract password hashes and Kerberos keys from AD offline. When only expected infrastructure accounts hold those rights, the DCSync abuse path is narrower.

  • T1187 Spooler / RPC Coerce Surfacetechnique
    T1187 — Spooler / RPC Coerce Surface

    From a workstation context, the agent checks whether SMB (445) and RPC (135) on the configured domain controller are reachable— the network preconditions for Print Spooler coercion attacks such as PetitPotam. Open paths from standard hosts to DC RPC/SMB increase the chance an attacker can force authentication or relay NTLM to the DC. Filtered or closed ports break that coerce-and-relay chain before payload delivery.

  • T1201 Domain Password Policy / Weak Account Hygienetechnique
    T1201 — Domain Password Policy / Weak Account Hygiene

    The agent pulls domain password policy, fine-grained password policies, and flags accounts with password-not-required or never-expire settings. Weak minimum length, disabled lockout, or broad exceptions for service accounts make credential guessing and long-lived compromise easier. Strong baseline policy with few exceptions signals better account hygiene.

  • T1649 ADCS Certificate Template Abusetechnique
    T1649 — ADCS Certificate Template Abuse

    This exercise enumerates certificate templates and PKI ACLs for known AD CS misconfigurations (ESC1–ESC15 class issues), probes HTTP enrollment surfaces, and may attempt enrollment and certificate-based logon to prove impact. Vulnerable templates or reachable HTTP enrollment let an attacker mint certificates that impersonate users or elevate to domain admin. Hardened templates, restricted ACLs, and disabled anonymous HTTP enrollment close the most common AD CS escalation routes.

  • T1556.006 Shadow Credentials (KeyCredentialLink)technique
    T1556.006 — Shadow Credentials (KeyCredentialLink)

    The agent searches for msDS-KeyCredentialLink values on user and computer objects—attributes used by shadow credentials attacks to register alternate keys for Kerberos PKINIT logon. Populated KeyCredentialLink entries on privileged or high-value accounts indicate either active abuse or dangerous write access waiting to be exploited. Clearing unexpected links and restricting who can write the attribute reduces shadow credential risk.

  • T1134.005 SID History Injection Discoverytechnique
    T1134.005 — SID History Injection Discovery

    This check enumerates sIDHistory on directory accounts and highlights history SIDs that map to privileged RIDs— a technique used to inherit domain admin rights after migrations or trust abuse. Readable sIDHistory with elevated historical SIDs is a direct indicator of privilege injection risk. Clean post-migration hygiene and SID filtering on trusts limit this persistence path.

  • T1087.002 Pre-Windows 2000 Compatible Accesstechnique
    T1087.002 — Pre-Windows 2000 Compatible Access

    The agent verifies whether Everyone or Anonymous Logon is a member of Pre-Windows 2000 Compatible Access—a legacy group that can enable unauthenticated or low-privilege enumeration of SAM-related information. Membership of these broad principals lowers the bar for anonymous reconnaissance against the domain. Removing them restores a baseline that expects authenticated access for sensitive directory queries.

  • T1552.001 Credentials in AD Descriptionstechnique
    T1552.001 — Credentials in AD Descriptions

    User and computer description fields are scanned for keywords and patterns that suggest embedded passwords or secrets. Helpdesk notes and ad hoc documentation in AD attributes are a common source of credential leaks that bypass vault controls entirely. Empty or sanitized descriptions mean one less opportunistic credential harvest for an intruder with LDAP read access.

  • T1484.002 Foreign Principals in Privileged Groupstechnique
    T1484.002 — Foreign Principals in Privileged Groups

    The agent looks for ForeignSecurityPrincipals nested inside privileged groups such as Domain Admins— a sign that trust relationships or cross-domain group membership may grant unexpected elevation. Foreign principals in tier-zero groups expand your blast radius to partner domains and complicate incident scoping. Removing stray FSP members and reviewing trusts keeps privileged group membership within expected boundaries.

  • T1136.002 Machine Account Quotatechnique
    T1136.002 — Machine Account Quota

    This exercise reads ms-DS-MachineAccountQuota on the domain, which controls how many computer accounts a standard user can create without admin help. A quota above zero lets attackers stage rogue machine accounts for Kerberos relay, RBCD, and other AD attacks from a compromised standard user session. Setting quota to zero and requiring privileged joins closes that pre-admission path.

  • T1484.001 Exchange PrivExchange Pathtechnique
    T1484.001 — Exchange PrivExchange Path

    The agent searches for the Exchange Windows Permissions group, which historically granted WriteDacl over the domain object and enabled PrivExchange-class escalation to domain admin. Presence of this group on a domain that still runs or once ran Exchange signals a well-known ACL abuse path that attackers actively target. Absence or proper hardening of Exchange role groups removes that specific escalation lane.

  • T1557.001 SMB Null Session / Relay Surfacetechnique
    T1557.001 — SMB Null Session / Relay Surface

    Toward the configured domain controller, the agent attempts SMB null-session access and anonymous share enumeration—the classic setup for NTLM relay when combined with name-resolution poisoning. Successful null sessions or anonymous net view from a standard host mean an attacker could relay captured hashes or map shares without valid credentials. Required signing and disabled anonymous access break that relay surface.

  • T1558.003 RC4 / Legacy Kerberos Encryptiontechnique
    T1558.003 — RC4 / Legacy Kerberos Encryption

    The agent identifies service accounts with SPNs that still permit RC4 or legacy DES Kerberos encryption types. RC4-capable SPN accounts remain Kerberoast targets because offline cracking of ticket material is far more practical than against AES-only accounts. Migrating service accounts to AES-only encryption and rotating keys after the change shrinks the offline attack window.