ParityPT catalog
APT groups, ransomware exercise, and checks
Browse purple teaming packs, the Ransomware Simulator stages, and ATT&CK-mapped techniques. Run a pack as published, or assemble a Custom Attack Chain and Build Your Own Narrative — phishing → purple teaming → ransomware. For standalone exercises see Phishing and Ransomware. Cards here are informational — sign in to run them.
Build Your Own Narrative
These APT groups and checks are building blocks. Customize the chain, then chain scenarios for a full attack path. Details on the narrative page.
Ransomware Simulator
Dedicated Impact exercise (T1486 / T1490). Reversible mode uses Temp sandbox canaries; Aggressive lab encrypts an approved path allowlist after dual acknowledgment. Score encrypt, note, VSS inhibit, and backup wipe — then optional Blow up or Recover. Pass = defenses blocked that stage.
- T1486 Ransomware Canary EncryptexerciseT1486 — Ransomware Canary Encrypt
In the ransomware simulator, the agent encrypts designated canary files—reversibly in standard mode, or broadly under approved lab paths in aggressive mode—mimicking mass file impact. Successful encryption shows endpoint and application controls did not stop a encryptor-style process from modifying user data. When encryption is blocked, controlled folder access, EDR, or ACLs intercepted the activity before meaningful damage.
- T1490 Ransomware Note DropexerciseT1490 — Ransomware Note Drop
The simulator drops a marked ransom note file (README_PARITY_RANSOM.txt) in sandbox or lab directories, reproducing the psychological and forensic signature of real ransomware campaigns. A written note means nothing prevented file creation in those locations— the same gap real operators exploit for visibility and pressure. Blocked writes indicate filesystem or anti-ransomware controls are engaging on note-drop behavior.
- T1490 Volume Shadow Copy InhibitexerciseT1490 — Volume Shadow Copy Inhibit
This graded probe creates a single volume shadow copy via WMI/CIM (with legacy tooling fallback) and then deletes only that shadow—simulating the inhibit-recovery step many ransomware families perform before encryption. Completing create-and-delete shows a standard user context can manipulate VSS, which precedes full shadow wipe in real incidents. Denied or elevated-only operations indicate backup-recovery points are better protected.
- T1490 Volume Shadow Copy Blow UpexerciseT1490 — Volume Shadow Copy Blow Up
In aggressive, acknowledged lab mode, the agent deletes all volume shadow copies on the system volume—mirroring the irreversible recovery destruction phase of ransomware. A drop in shadow count confirms an unprivileged or low-privileged process could wipe local restore points before encryption. When deletion is blocked or the inventory was already empty without a successful wipe, recovery snapshots are harder for an attacker to erase locally.
- T1490 Backup Canary WipeexerciseT1490 — Backup Canary Wipe
The agent stages fake backup files and deletes them—and in aggressive mode may target existing backup-like files under approved lab roots—simulating attackers who destroy local and pseudo-backup copies before encryption. Successful deletion means workstation principals can remove files that resemble backup stores, a pattern seen before full ransomware impact. Blocked deletes suggest backup paths or repositories are isolated from casual user delete rights.
- Ransomware Simulator RecoverexerciseRansomware Simulator Recover
Recover is the post-exercise cleanup action: it decrypts.paritylocked canaries using the assessment recovery key and removes simulator ransom notes from sandbox and lab paths. Successful recovery restores exercise files to their pre-impact state so aggressive labs do not leave operational debris. It does not rebuild volume shadow copies deleted by the blow-up stage—those require your normal backup restore process.
APT groups
Technique-similarity packs drawn from public ATT&CK reporting — not full adversary emulation. Stages map to the same checks you run in a scenario.
- APT29 / Midnight Blizzard: Cozy Bear multi-interpreter + C2 pathAPT chainG0016
Walks through multi-interpreter execution, WMI, persistence, Defender tamper, host and AD credential abuse (delegation, AdminSDHolder, DCSync rights, trusts), lateral movement, and HTTP C2/exfil. Run it to validate detections against a long-form espionage chain that blends scripting tradecraft with domain privilege escalation.
- APT28 / Forest Blizzard: Fancy Bear LOLBin + persistenceAPT chainG0007
Covers LOLBin and scripting execution, COM/Startup persistence, AD GPO/SYSVOL and delegation exposure, credential theft, and security log clearing. Use it to test whether your stack catches APT28-style foothold and cleanup behavior before attackers pivot deeper in the domain.
- APT41 / Brass Typhoon: APT41 dual espionage / crimeware pathAPT chainG0096
Stages ingress and certutil download, LOLBin execution, UAC bypass, service and BITS persistence, AD trust discovery, spooler coercion, credential access, and HTTP exfil. Teams run this to stress tradecraft that blends espionage and crimeware techniques on a single host path.
- Lazarus Group: Lazarus implant pathAPT chainG0032
Walks through ingress, HTTP C2, PowerShell execution, UAC bypass, service and IFEO persistence, Defender tamper, RDP enablement, and exfil. Validates whether you can detect and block an implant-style access chain after initial compromise.
- FIN7: FIN7 living-off-the-landAPT chainG0046
Tests mshta, regsvr32, cscript, and cmstp execution alongside certutil/HTTP C2, AS-REP roasting, GPO/SYSVOL exposure, and scheduled-task/BITS persistence. Ideal for assessing living-off-the-land detections against payment-sector tradecraft that avoids custom malware.
- Sandworm / Voodoo Bear: Sandworm WMI/opsAPT chainG0034
Focuses on WMI execution and event subscription persistence, PowerShell, scheduled-task and service persistence, and security log clearing. Run it to verify operational detections for WMI-heavy intrusion and anti-forensics on Windows hosts.
- Wizard Spider: Wizard Spider ransomware prepAPT chainG0102
Simulates affiliate prep: ingress and HTTP C2, defense tamper, host and AD credential abuse (Kerberoast, AS-REP, password policy), privileged group recon, GPO/SYSVOL exposure, lateral movement surfaces, staging, and ransomware impact canaries. Exercises the full pre-encryption path affiliates use before deploying ransomware.
- Volt Typhoon: Volt Typhoon living-off-the-landAPT chainG1017
Uses native Windows tooling for host and AD discovery, WMI and script execution, certutil/DNS/HTTP C2, netsh helper and scheduled-task persistence, WinRM lateral movement, and log clearing. Validates detection of quiet, hands-on-keyboard activity that avoids third-party malware.
- Scattered Spider: Scattered Spider identity + remote accessAPT chainG1015
Targets identity abuse: host and AD discovery, scripting, AS-REP/Kerberoast and password-policy probes, local account creation, RDP and WinRM enablement, and defense tamper. Run this to test controls against groups that prioritize credential theft and interactive remote access over malware deployment.
- Turla: Turla stealth persistenceAPT chainG0010
Exercises quiet LOLBin execution, COM/AppInit/netsh persistence, LSASS credential access, and security log clearing. Use it to evaluate stealthy long-dwell persistence detections aligned with a low-noise host footprint.
- APT33 / Peach Sandstorm: APT33 / Peach SandstormAPT chainG0064
Covers PowerShell and cscript execution, ingress and HTTP C2, scheduled-task and service persistence, credential access, Defender tamper, and exfil. Validates end-to-end detections for a compact initial access and staging chain.
- APT34 / OilRig: APT34 / OilRigAPT chainG0049
Tests mshta and PowerShell execution, certutil staging, COM/Startup persistence, and LSASS/SAM credential access. Run it to assess document-adjacent execution and quiet persistence on compromised workstations.
- APT35 / Charming Kitten: APT35 / Charming KittenAPT chainG0059
Exercises script-host and PowerShell execution, ingress and HTTP C2, Run-key/Startup persistence, credential theft, and HTTP exfil. Useful for testing phishing-driven footholds that establish persistence quickly on a single endpoint.
- APT10 / menuPass: APT10 / menuPassAPT chainG0045
Stages ingress, certutil, and HTTP C2, rundll32/regsvr32 execution, service and scheduled-task persistence, credential access, WinRM lateral movement, and exfil. Validates detections against long-haul espionage tradecraft on Windows infrastructure.
- APT32 / OceanLotus: APT32 / OceanLotusAPT chainG0050
LOLBin-heavy execution via mshta, cmstp, and cscript, plus HTTP C2, COM/AppInit persistence, Defender tamper, log clearing, and exfil. Run this to test tradecraft that favors dual-use binaries and layered defense evasion.
- APT37 / Reaper: APT37 / ReaperAPT chainG0067
Covers scripting and document-adjacent LOLBins, ingress and HTTP C2, scheduled-task/Run-key persistence, credential access, and exfil. Exercises a typical initial compromise through credential theft on a single endpoint path.
- APT38: APT38 financial ops prepAPT chainG0082
Tests ingress and HTTP C2, defense tamper (Defender, firewall, log clearing), credential access, service persistence, RDP enablement, and exfil. Use it to validate controls ahead of financial-sector intrusions that prioritize quiet lateral movement and defense disablement.
- APT39 / Chafer: APT39 / ChaferAPT chainG0087
Exercises PowerShell, cmd, and WMI execution, multi-vector persistence, credential access, WinRM enablement, and HTTP/DNS C2. Run this to assess tradecraft focused on surveillance and remote administration paths.
- APT40 / Leviathan: APT40 / LeviathanAPT chainG0065
Covers web and LOLBin execution, certutil/ingress/HTTP C2, COM/Startup persistence, credential access, and exfil. Validates staging and persistence detections on research and maritime-sector targets.
- APT31 / Zirconium: APT31 / ZirconiumAPT chainG0099
Focuses on host discovery, scripting, scheduled-task persistence, HTTP/DNS C2, and archived HTTP exfil. Run it to test long-campaign tradecraft that emphasizes reconnaissance and staged data collection before exfiltration.
- MuddyWater: MuddyWaterAPT chainG0069
Tests mshta, cscript, and PowerShell execution, ingress and HTTP C2, BITS and scheduled-task persistence, credential access, and exfil. Exercises intrusion patterns that blend script droppers with resilient persistence.
- HAFNIUM: HAFNIUM post-compromiseAPT chainG0125
Post-compromise style: host discovery, web and script execution, credential access, WinRM/RDP lateral movement, and HTTP C2. Run this to validate on-prem detections after server initial access—not a web-shell implant test.
- Dragonfly / Energetic Bear: Dragonfly / Energetic BearAPT chainG0035
Combines WMI and LOTL execution, host discovery, service and scheduled-task persistence, HTTP/DNS C2, and credential access. Tests ICS-adjacent tradecraft on Windows hosts without requiring OT-specific tooling.
- Mustang Panda: Mustang PandaAPT chainG0129
Uses document-adjacent LOLBins, certutil and HTTP C2 staging, Startup and scheduled-task persistence, and credential access. Validates detections against campaigns that favor phishing lures and native staging tools.
- Kimsuky: KimsukyAPT chainG0094
Covers PowerShell and script execution, ingress and HTTP C2, Run-key/IFEO persistence, LSASS/SAM credential theft, and exfil. Run this to assess espionage footholds on researcher and policy targets.
- LockBit-style ops: LockBit-style affiliate prepAPT chainG0140
Fast ingress and HTTP C2, defense disablement (Defender, firewall, log clearing), host and AD credential abuse, privileged group recon, spooler coercion, account creation, RDP, staging, and ransomware impact canaries. Exercises the compressed affiliate playbook used before LockBit-style encryption deployments.
- APT1 / Comment Crew: APT1 / Comment Crew classicAPT chainG0006
Classic intrusion pattern: ingress and HTTP C2, scripting, service/scheduled-task/Run-key persistence, credential access, and RDP. Use it as a baseline long-dwell espionage chain to benchmark foundational detections.
- Gamaredon: GamaredonAPT chainG0047
Aggressive scripting and LOLBins, certutil and HTTP C2 staging, Startup and BITS persistence, credential access, and exfil. Run this to test high-volume, noisy tradecraft typical of sustained targeting campaigns.
- FIN6: FIN6 AD identity abuseAPT chainG0037
AD-focused identity abuse: privileged group recon, AS-REP/Kerberoast, password-policy probes, AdminSDHolder discovery, GPO/SYSVOL exposure, and light host credential access. Validates identity-layer controls against payment-sector abuse without full ransomware impact.
- Black Basta: Black Basta coerce + relay surfaceAPT chainG1040
Tests name-poison capture, LDAP signing posture, spooler/RPC coercion, Kerberoast/AS-REP, defense tamper, staging, and ransomware impact canaries. Run this to validate coerce/relay and AD credential surfaces that affiliates exploit before encryption.
- APT29 / Midnight Blizzard: Midnight Blizzard domain dominanceAPT chainG0016
AD-heavy follow-on: trust and privileged-group discovery, Kerberos delegation, AdminSDHolder, DCSync rights, ADCS abuse, shadow credentials, SID history, GPO/SYSVOL collection, and exfil. Exercises domain dominance paths beyond initial host compromise—run after foothold validation to test tier-zero controls.
Checks
Authorized Windows purple teaming probes named with MITRE ATT&CK technique IDs. Pass means defenses blocked the path; fail means the technique succeeded in the lab. Ransomware Simulator stages are listed above.
- T1059.001 Encoded PowerShell ExecutiontechniqueT1059.001 — Encoded PowerShell Execution
This exercise launches PowerShell using a Base64-encoded command line, a common way attackers hide malicious scripts from casual inspection. When controls block the technique, encoded execution or outbound staging is stopped before it completes. When it succeeds, obfuscated PowerShell ran—indicating a meaningful detection and prevention gap.
- T1218.005 mshta LOLBin ExecutiontechniqueT1218.005 — mshta LOLBin Execution
This exercise runs mshta.exe, a signed Windows binary often abused to execute HTML Application scripts without dropping a traditional executable. Blocking means application control, ASR, or network policy prevented mshta from completing its action or reaching outbound endpoints. Success means mshta executed the staged content—behavior consistent with living-off-the-land intrusion tradecraft.
- T1053.005 Scheduled Task PersistencetechniqueT1053.005 — Scheduled Task Persistence
This exercise registers a short-lived scheduled task, mimicking a common persistence method that survives reboots and runs under a trusted scheduler context. The probe verifies the task was registered, then removes it so no lasting change remains. When creation is denied, privilege boundaries or policy prevented an unprivileged actor from establishing scheduled persistence. When creation succeeds, an attacker at the same privilege level could register tasks—a control gap worth addressing before real malware does the same.
- T1547.001 Registry Run Key PersistencetechniqueT1547.001 — Registry Run Key Persistence
This exercise writes a benign value to a Run or RunOnce registry key, simulating autorun persistence that executes at user logon. The probe confirms the value landed, then deletes it. Denied writes indicate registry protections or EDR persistence controls are effective for the tested identity. A successful write means the account could establish autorun persistence—a finding that should trigger hardening of registry monitoring and admin rights.
- T1003.001 LSASS Credential DumptechniqueT1003.001 — LSASS Credential Dump
This exercise attempts to open a handle to the LSASS process—the memory space where Windows stores interactive credentials. The probe requests limited query access by default and can escalate to VM_READ access masks that credential-theft tooling typically needs, still without writing a memory dump. The goal is to see whether credential-theft protections detect or block access to LSASS. When blocked, PPL, Credential Guard, ASR, or EDR credential-access rules prevented the handle from opening. When the handle opens, an actor at the tested privilege level can touch LSASS, which is a strong precursor to credential theft and lateral movement.
- T1562.001 Defender Tamper AttempttechniqueT1562.001 — Defender Tamper Attempt
This exercise attempts a controlled change to Windows Defender—such as adding a temporary exclusion or disabling real-time protection—then reverts any change that went through. The intent is to test whether tamper protection and administrative controls prevent endpoint defenses from being weakened on the host. When blocked, Defender settings remained intact under policy or tamper protection. When tampering succeeds, even briefly, an attacker could blind or bypass local AV before the revert—an exposure that demands immediate policy review.
- T1105 Ingress Tool TransfertechniqueT1105 — Ingress Tool Transfer
This exercise downloads a known-benign file from the assessment platform over HTTPS, simulating ingress tool transfer—the stage where attackers pull second-stage payloads onto a compromised host. The probe hashes the file, confirms it arrived, then deletes it. When network filtering, ASR, or proxy policy blocks the download, ingress is constrained. When the download completes, outbound HTTPS retrieval of arbitrary content succeeded—a common initial step in ransomware and post-exploitation workflows.
- T1543.003 Service InstallationtechniqueT1543.003 — Service Installation
This exercise attempts to register a temporary Windows service, a persistence and privilege technique that runs code under the Service Control Manager with SYSTEM context when configured that way. The probe verifies registration, then deletes the service. Denied creation indicates the tested account lacks rights or policy blocks new service installation. Successful creation means an actor at that privilege level can install services—a high-impact persistence vector on servers and workstations alike.
- T1070.001 Security Log Clear CapabilitytechniqueT1070.001 — Security Log Clear Capability
This exercise checks whether the running token holds or can enable SeSecurityPrivilege—the right required to clear the Windows Security event log—without actually wiping the log. It is a dry capability probe aligned to the privilege level of the account under test. When the privilege is absent or cannot be enabled, the account cannot erase Security log evidence locally—a positive control outcome. When the capability is present, a compromised admin could destroy audit trails on the endpoint, which makes centralized log forwarding essential.
- T1548.002 UAC Bypass Path ProbetechniqueT1548.002 — UAC Bypass Path Probe
This exercise tests a fodhelper-style User Account Control bypass: a temporary registry handler redirects an auto-elevating Windows binary to run a payload command without a consent prompt. The probe cleans up registry changes and stray processes immediately afterward. When the hijack write is denied, UAC bypass paths are constrained for the tested user. When the handler is set or an elevated payload is written, silent elevation without prompt succeeded—meaning standard users may reach admin context through a known bypass.
- T1218.010 regsvr32 Scriptlet ExecutiontechniqueT1218.010 — regsvr32 Scriptlet Execution
This exercise invokes regsvr32 with a scriptlet, abusing a trusted signed binary to run script code—technique often called Squiblydoo. Blocking by ASR, AppLocker, or network policy stops regsvr32 from completing the scriptlet or reaching outbound endpoints. Success means regsvr32 executed attacker-controlled script content—behavior aligned with Squiblydoo-style intrusion tradecraft.
- T1218.011 rundll32 Proxy ExecutiontechniqueT1218.011 — rundll32 Proxy Execution
This exercise launches rundll32.exe to invoke a DLL export or proxy execution path, a classic LOLBin pattern used to run code without spawning a obvious malicious executable. When WDAC, AppLocker, or ASR blocks rundll32 or outbound staging, the proxy chain stops early. Success indicates rundll32 completed the proxy execution—behavior seen in commodity loaders and hands-on-keyboard activity.
- T1547.001 Startup Folder PersistencetechniqueT1547.001 — Startup Folder Persistence
This exercise drops a short-lived script into the current user's Startup folder, simulating logon persistence that executes without touching the registry. The probe confirms the file landed, then removes it without waiting for a reboot. Denied writes show folder protections or EDR persistence controls are working for the tested identity. A successful write means the account can plant logon persistence—a finding that should drive monitoring of Startup folder changes across the fleet.
- T1047 WMI Process CreatetechniqueT1047 — WMI Process Create
This exercise creates a process through WMI's Win32_Process.Create method, a technique attackers use for stealthy execution and lateral movement because it often appears as WmiPrvSE spawning children. When WMI permissions, AppLocker, or egress controls block creation or staging, the chain fails. Success means WMI launched the intended process—indicating WMI is a viable execution path for the tested account.
- T1562.004 Firewall Disable AttempttechniqueT1562.004 — Firewall Disable Attempt
This exercise briefly attempts to disable a Windows Firewall profile, simulating defense evasion where attackers open the host to inbound connections or reduce outbound inspection visibility. The probe verifies the state change, then restores the prior configuration. When policy or tamper controls block the change, the firewall profile remained enabled—a desired outcome. When disable succeeds, even momentarily, local firewall protections can be weakened on demand, which often precedes lateral movement or C2 establishment.
- T1197 BITS Job PersistencetechniqueT1197 — BITS Job Persistence
This exercise creates a short-lived Background Intelligent Transfer Service job, a technique abusers leverage for quiet downloads and persistence because BITS runs with service privileges and can resume transfers. The probe confirms the job registered, then cancels and removes it. Denied job creation indicates BITS abuse is constrained for the tested account. Successful creation means an actor can register BITS jobs—a tradecraft vector for stealthy ingress and scheduled retrieval.
- T1546.015 COM Hijack ProbetechniqueT1546.015 — COM Hijack Probe
This exercise writes a temporary COM hijack under the current user's Classes hive, redirecting a CLSID to a benign path—simulating persistence and elevation tricks that load attacker code when a legitimate COM object is instantiated. The probe verifies the key, then removes it without loading a malicious server. Denied registry writes indicate COM hijack persistence is blocked for the tested user. Successful writes mean HKCU COM overrides can be established—a common persistence method that evades naive HKLM-only monitoring.
- T1136.001 Local Account CreationtechniqueT1136.001 — Local Account Creation
This exercise attempts to create a temporary local user account, mimicking post-exploitation steps where attackers establish backup access independent of domain credentials. The probe verifies the account exists, then deletes it. Denied creation shows the tested identity cannot add local users—a sound least-privilege outcome. Successful creation means a local backdoor account could be added at the same privilege level, which is especially concerning on servers and shared workstations.
- T1021.001 RDP Enable AttempttechniqueT1021.001 — RDP Enable Attempt
This exercise attempts to enable Remote Desktop by changing the fDenyTSConnections setting, simulating how attackers open graphical remote access for persistence and interactive control. The probe verifies the change, then restores the prior value. When registry or policy blocks the change, RDP remains disabled as intended. When enable succeeds, even briefly, the host accepted a configuration that allows remote desktop sessions—a common step before hands-on-keyboard activity over port 3389.
- T1059.005 cscript / VBScript ExecutiontechniqueT1059.005 — cscript / VBScript Execution
This exercise runs a VBScript through cscript.exe, validating that Windows Script Host remains a viable execution path on the endpoint. When WDAC, AppLocker, or ASR blocks cscript or outbound staging, script-host abuse is constrained. Success means cscript executed the staged script—behavior aligned with phishing droppers and legacy malware chains.
- T1105 certutil Decode / IngresstechniqueT1105 — certutil Decode / Ingress
This exercise uses certutil.exe to decode a local Base64 blob or download staged content—abusing a signed utility commonly seen in fileless download cradles. Blocking by application control or egress policy stops certutil from decoding or reaching remote endpoints. Success means certutil completed the decode or download chain, indicating this LOLBin remains available for staging malware without traditional download tools.
- T1218.003 cmstp INF ExecutiontechniqueT1218.003 — cmstp INF Execution
This exercise runs cmstp.exe against a benign INF file, simulating a Connection Manager Profile Installer abuse path that can execute commands and, in some configurations, interact with UAC elevation behavior. When WDAC, AppLocker, or ASR blocks cmstp or network staging, the LOLBin chain stops. Success means cmstp processed the INF—a known bypass and execution vector in red-team and real-world intrusions.
- T1546.003 WMI Event SubscriptiontechniqueT1546.003 — WMI Event Subscription
This exercise creates a temporary WMI event subscription—filter, consumer, and binding—mimicking fileless persistence that fires when a defined condition occurs, often without dropping traditional malware on disk. The probe verifies the subscription objects exist, then deletes them without waiting for a trigger. Denied creation indicates WMI persistence is blocked for the tested identity. Successful creation means permanent-style WMI subscriptions can be registered—a stealthy persistence channel that survives reboots when left in place.
- T1546.012 IFEO Debugger PersistencetechniqueT1546.012 — IFEO Debugger Persistence
This exercise writes a temporary Image File Execution Options Debugger value for a benign executable name, simulating persistence that hijacks process launch so a debugger command runs whenever the target image starts. The probe verifies the registry value, then removes it without launching the target. Denied writes indicate IFEO modifications are blocked for the tested privilege level. Successful writes mean an actor can set IFEO debugger keys—a technique used for persistence, accessibility abuse, and silent process redirection.
- T1003.002 SAM Registry Hive DumptechniqueT1003.002 — SAM Registry Hive Dump
This exercise attempts to export the SAM and SYSTEM registry hives with reg save, the same offline path attackers use to recover local password hashes. Success indicates an elevated session can pull credential material without touching LSASS directly. Temporary hive files are deleted immediately after the attempt.
- T1021.006 WinRM Enable AttempttechniqueT1021.006 — WinRM Enable Attempt
The agent tries to turn on WinRM auto-configuration, which opens a remote PowerShell and management channel on the host. Attackers often enable WinRM after gaining admin rights to move laterally without RDP. The prior WinRM policy is restored when the check finishes.
- T1546.007 netsh Helper DLLtechniqueT1546.007 — netsh Helper DLL
This probe registers a benign DLL as a netsh helper, a persistence technique that loads attacker code whenever netsh runs. Helpers survive reboots and blend into legitimate network administration tooling. The registration is removed before the agent exits; no DLL is actually loaded.
- T1546.010 AppInit_DLLs PersistencetechniqueT1546.010 — AppInit_DLLs Persistence
The check attempts to set AppInit_DLLs and LoadAppInit_DLLs so a DLL would load into every GUI process that links user32. This is a classic persistence path on older Windows builds, though Secure Boot and modern defaults often block it. Registry values are reverted immediately; no DLL is loaded.
- T1059.003 Windows Command ShelltechniqueT1059.003 — Windows Command Shell
This simulation runs cmd.exe with a benign command chain—the same entry point used in living-off-the-land attacks, phishing follow-on, and staged downloaders. Defenses should catch cmd spawning from unusual parents or writing to Temp.
- T1059.006 PythontechniqueT1059.006 — Python
The agent runs a real python or py interpreter on PATH to execute a short script—Microsoft Store execution aliases are ignored. Python is increasingly used as a cross-platform implant and staging runtime on Windows endpoints.
- T1059.007 JavaScript / wscripttechniqueT1059.007 — JavaScript / wscript
This exercise launches wscript.exe against a local JScript file, the same script-host path seen in macro droppers and fileless staging chains. JScript can invoke WScript.Shell, write files, and spawn PowerShell without a compiled binary.
- T1127.001 MSBuild Inline TasktechniqueT1127.001 — MSBuild Inline Task
The agent invokes MSBuild against a project containing inline task code—a trusted signed binary that compiles and executes arbitrary.NET without dropping a separate executable. Attackers abuse MSBuild on workstations to bypass application whitelisting.
- T1218.007 msiexec Remote PackagetechniqueT1218.007 — msiexec Remote Package
This probe runs msiexec against a remote package URL on the ParityPT assessment host, simulating silent install from the network—a common LOLBin for pulling payloads without a browser download. Success means msiexec could reach out and attempt the install path. No third-party hosts are contacted.
- T1218.004 InstallUtil ProbetechniqueT1218.004 — InstallUtil Probe
The check compiles and runs a benign.NET installer through InstallUtil.exe, which loads and executes an assembly's uninstall method—another signed Microsoft binary abused for code execution. Attackers pair this with inline compilation to avoid dropping obvious executables.
- T1037.001 Logon Script PersistencetechniqueT1037.001 — Logon Script Persistence
The agent sets the UserInitMprLogonScript registry value to point at a benign batch file, establishing logon-script persistence that runs on every user sign-in. This UserInitMprLogonScript path is less monitored than Run keys but equally durable. The value is reverted and the batch file deleted; logon is not waited for.
- T1547.009 Startup Folder ShortcuttechniqueT1547.009 — Startup Folder Shortcut
This exercise drops a.lnk shortcut in the user's Startup folder targeting cmd to write a payload—a persistence method that survives reboots and avoids direct registry edits. Startup shortcuts are easy to miss in autoruns reviews because they look like user preferences. The shortcut is deleted immediately; the target is never launched.
- T1546.008 Sticky Keys IFEO ProbetechniqueT1546.008 — Sticky Keys IFEO Probe
The check sets an Image File Execution Options Debugger on sethc.exe (Sticky Keys) to cmd.exe—the accessibility backdoor used when attackers have console or RDP access and want a SYSTEM shell at the login screen. IFEO debugger hijacks on accessibility binaries are a well-known privilege-escalation path. The Debugger value is restored immediately; sethc is never launched.
- T1087.001 Local Account DiscoverytechniqueT1087.001 — Local Account Discovery
The agent runs net user to list local accounts on the host, a standard reconnaissance step after initial access. Account names reveal service accounts, shared workstations, and naming conventions useful for password spraying or targeted attacks. Empty output is treated as inconclusive rather than a clean result.
- T1057 Process DiscoverytechniqueT1057 — Process Discovery
This probe enumerates running processes via tasklist or Get-Process to map security tools, VPN clients, and high-value applications on the endpoint. Process lists help attackers choose evasion techniques and timing for credential access. Empty output is inconclusive.
- T1082 System Information DiscoverytechniqueT1082 — System Information Discovery
The agent collects basic host identity—computer name and OS version—information attackers use to tailor payloads and identify domain membership. This is often among the first commands in an intrusion after foothold. Empty output is inconclusive.
- T1135 Network Share DiscoverytechniqueT1135 — Network Share Discovery
The check runs net share to list shares exposed on the local machine, revealing file servers, hidden admin shares, and misconfigured permissions. Share enumeration frequently precedes lateral movement over SMB or admin-share abuse. Empty output is inconclusive.
- T1560.001 Archive Staged DatatechniqueT1560.001 — Archive Staged Data
The agent creates a zip archive of small benign temp files using Compress-Archive, simulating the staging step before data exfiltration. Attackers compress collections to reduce transfer size and evade simple DLP on individual files. The archive is deleted after verification.
- T1071.001 Web Protocol C2 BeacontechniqueT1071.001 — Web Protocol C2 Beacon
This exercise sends a benign HTTPS GET to the ParityPT beacon endpoint with a distinctive assessment User-Agent, simulating periodic command-and-control check-ins over web protocols. Outbound HTTPS is the most common C2 channel because it blends with normal traffic. Only the configured ParityPT host is contacted.
- T1041 Exfiltration Over C2 Channel (HTTP)techniqueT1041 — Exfiltration Over C2 Channel (HTTP)
The agent attempts an HTTPS POST of a small benign blob to the ParityPT exfil probe, representing data theft over the same channel as C2. Successful upload means outbound POST bodies are not inspected or blocked at the perimeter. Only the ParityPT assessment host receives the POST.
- T1071.004 DNS Application Layer ProbetechniqueT1071.004 — DNS Application Layer Probe
This probe resolves the ParityPT assessment hostname through the endpoint's configured DNS resolver, testing whether DNS is available as a command or exfiltration channel. DNS tunneling and lookup-based C2 often bypass web proxies entirely. Only the ParityPT host name is queried.
- T1021.002 SMB Admin Share AccesstechniqueT1021.002 — SMB Admin Share Access
The agent attempts to write a short-lived payload through the local C$ administrative share at 127.0.0.1, the same SMB path used for lateral movement and remote file placement. Admin share write access from a standard user context indicates dangerous local privilege or misconfiguration. The payload is deleted after the attempt.
- T1557.001 Name Resolution Poisoning CapturetechniqueT1557.001 — Name Resolution Poisoning Capture
For a short listen window the agent watches LLMNR, mDNS, and NBT-NS, responds to poisonable name lookups, and captures NetNTLM hashes offered over HTTP and SMB—without relaying credentials. This mirrors responder-style attacks on flat networks where multicast name resolution is still enabled. Domain controllers are skipped; LanmanServer is paused briefly and restored.
- T1518.001 Security Software DiscoverytechniqueT1518.001 — Security Software Discovery
This check simulates early-stage reconnaissance to identify installed antivirus, EDR, and other security products on the endpoint. When enumeration succeeds, an attacker learns which defenses are present and can tailor evasion or tampering accordingly. Detection or blocking here indicates your controls are surfacing security-software discovery before follow-on disablement attempts.
- T1518 Software DiscoverytechniqueT1518 — Software Discovery
This check samples installed application names from Windows Uninstall registry keys, a common post-compromise inventory technique. Successful enumeration gives an attacker a map of exploitable software, VPN clients, and admin utilities on the host. Blocking or alerting on bulk registry reads limits targeted exploitation of known vulnerable applications.
- T1016 System Network Configuration DiscoverytechniqueT1016 — System Network Configuration Discovery
This check collects local IP addresses, DNS settings, and adapter details—the network mapping attackers perform after gaining a foothold. When it succeeds, the adversary gains context on routing, segmentation, and reachable subnets for lateral movement. Denial or detection shows visibility into host-level network reconnaissance in the attack chain.
- T1049 System Network Connections DiscoverytechniqueT1049 — System Network Connections Discovery
This check lists established TCP connections to reveal live communication partners, admin sessions, and potential command-and-control endpoints. Success exposes relationships an attacker can exploit for pivoting or blending with legitimate traffic. Monitoring netstat-style enumeration from non-admin tooling catches this mid-campaign reconnaissance.
- T1018 Remote System DiscoverytechniqueT1018 — Remote System Discovery
This check discovers nearby systems through ARP cache, neighbor tables, and NetBIOS-style host queries without performing a port scan. Successful discovery expands the attacker's target list within the broadcast domain. Segmentation and detection of neighbor or net view enumeration reduce options for lateral movement.
- T1083 File and Directory DiscoverytechniqueT1083 — File and Directory Discovery
This check performs shallow directory listing of high-value paths such as user Desktop, Documents, and ProgramData. Success indicates an attacker can map where sensitive files may reside before collection or staging. Alerting on scripted directory enumeration from unusual parents helps catch pre-exfiltration activity early.
- T1012 Query RegistrytechniqueT1012 — Query Registry
This check reads common registry keys used for persistence scouting, software inventory, and environment mapping. When queries succeed, an attacker learns autorun locations, installed products, and system configuration details. Registry telemetry and appropriate ACLs limit passive environment reconnaissance on workstations.
- T1069.001 Local GroupstechniqueT1069.001 — Local Groups
This check enumerates local security groups and administrator membership on the workstation. Success reveals who holds elevated local access—a common precursor to privilege escalation or targeted credential theft. Monitoring local group queries from non-IT processes surfaces this reconnaissance before abuse occurs.
- T1007 System Service DiscoverytechniqueT1007 — System Service Discovery
This check samples installed and running Windows services to identify security tools, management agents, and potential persistence targets. Successful enumeration helps an attacker plan service abuse, evasion, or binary-path manipulation. Correlating service discovery with subsequent service creation strengthens end-to-end detection.
- T1033 System Owner/User DiscoverytechniqueT1033 — System Owner/User Discovery
This check collects the current logged-on user and active session details through standard identity commands. Success confirms which account context the attacker occupies and whether privileged sessions are active on the host. Baseline and alert on bursts of identity discovery from implants or Office macro child processes.
- T1120 Peripheral Device DiscoverytechniqueT1120 — Peripheral Device Discovery
This check enumerates connected PnP and USB-style devices to assess removable media and hardware attack surfaces. Success may indicate preparation for data theft via external drives or evaluation of device-control policies. PnP enumeration from unexpected processes warrants investigation, especially before large file transfers.
- T1555.004 Windows Credential ManagertechniqueT1555.004 — Windows Credential Manager
This check attempts to read secrets stored in Windows Credential Manager, including saved passwords and network credentials. Success means locally stored credentials can be harvested for lateral movement, VPN access, or cloud sign-in. Recovered material is sealed for assessment review rather than left in finding text.
- T1555.003 Credentials from Web BrowserstechniqueT1555.003 — Credentials from Web Browsers
This check accesses Chromium-based browser password stores, decrypts saved login credentials, and records recovered secrets for assessment review. Success demonstrates that browser-stored passwords are extractable on the endpoint—a common post-phishing objective. Empty or inaccessible vaults are treated as out of scope rather than a control success.
- T1003.005 Cached Domain CredentialstechniqueT1003.005 — Cached Domain Credentials
This check assesses MITRE ATT&CK T1003.005 on domain-joined hosts by exporting the SECURITY and SYSTEM registry hives (the path used to recover cached domain logon hashes offline). Workgroup / non-domain hosts are N/A — they do not store domain MSCache/DCC2 material. Hive files are removed after the probe.
- T1115 Clipboard DatatechniqueT1115 — Clipboard Data
This check reads the current clipboard contents, which often contain passwords, tokens, or sensitive text copied by users. Success shows clipboard data is accessible to code running in the user session without additional privileges. Collected text is sealed for assessment review and is not written to disk on the host.
- T1114 Email CollectiontechniqueT1114 — Email Collection
This check locates Outlook OST and PST data files under the user profile without reading mailbox content. Success confirms mail archives are present and reachable—a staging step before full email theft or search. Monitoring non-Outlook processes touching mail data paths helps detect escalation from discovery to collection.
- T1053.005 Remote Scheduled Task ProbetechniqueT1053.005 — Remote Scheduled Task Probe
This check creates and runs a short-lived scheduled task using remote task scheduler syntax against localhost, mimicking lateral execution via schtasks. Success means remote-style task operations are permitted—a technique commonly used to run code on other hosts without interactive logon. The task is deleted after execution and is not left as persistence.
- T1021.006 WinRM Invoke ProbetechniqueT1021.006 — WinRM Invoke Probe
This check attempts to execute a command on localhost through WinRM remote invocation, simulating PowerShell remoting lateral movement. Success indicates WinRM-based remote execution is available from the current security context. This exercise uses invocation only and does not enable or reconfigure the WinRM service.
- T1021.003 DCOM / WMI Lateral ProbetechniqueT1021.003 — DCOM / WMI Lateral Probe
This check attempts remote process creation against localhost via WMI and DCOM, a classic lateral execution path used to run commands without an interactive logon. Success shows WMI remote execution is permitted from the current context. Any spawned marker process is short-lived and no persistent services or tasks are left behind.
- T1134 Access Token Privilege EnumerationtechniqueT1134 — Access Token Privilege Enumeration
This check lists privileges held by the current process token, such as SeDebugPrivilege or SeImpersonatePrivilege. Success reveals which escalation paths may be available without yet attempting token theft or impersonation. This is reconnaissance only—the assessment does not duplicate, steal, or adjust tokens.
- T1558.003 Kerberoasting ProbetechniqueT1558.003 — Kerberoasting Probe
This check searches Active Directory for user accounts with service principal names and requests Kerberos service tickets suitable for offline password cracking. Success means roastable service accounts exist and ticket material was captured—a direct path toward domain credential compromise. Recovered hashes are sealed for assessment review in standard cracking formats.
- T1558.004 AS-REP Roasting ProbetechniqueT1558.004 — AS-REP Roasting Probe
This check identifies domain accounts exempt from Kerberos pre-authentication and requests AS-REP hashes for offline cracking. Success indicates misconfigured accounts that allow authentication material to be harvested without knowing the current password. When no such accounts exist or LDAP access is denied, the exposure is reduced.
- T1558.001 Kerberos Delegation ExposuretechniqueT1558.001 — Kerberos Delegation Exposure
This check enumerates Kerberos delegation configurations including unconstrained, constrained, and resource-based constrained delegation across Active Directory objects. Success exposes delegation relationships adversaries abuse for impersonation and privilege escalation, especially toward tier-zero assets. Readable delegation metadata helps attackers prioritize high-impact targets before ticket abuse.
- T1069.002 Privileged Domain Group DiscoverytechniqueT1069.002 — Privileged Domain Group Discovery
This check queries Active Directory for high-value groups such as Domain Admins and reads membership where the bind identity is permitted. Success means privileged accounts can be mapped—a BloodHound-style reconnaissance step before targeted compromise. Broad read access to tier-zero membership significantly shortens an attacker's path to domain dominance.
- T1482 Domain Trust DiscoverytechniqueT1482 — Domain Trust Discovery
This exercise maps domain and forest trust relationships from Active Directory—direction, type, and partner domains—much like an attacker would during cross-domain reconnaissance. When the agent can read trustedDomain objects, your AD is exposing trust topology to any authenticated (or weakly authenticated) caller who knows where to look. A blocked or empty result means LDAP access controls or monitoring are limiting how much of that attack surface is visible from a standard endpoint.
- T1552.006 GPO / SYSVOL Exposure ProbetechniqueT1552.006 — GPO / SYSVOL Exposure Probe
The agent enumerates Group Policy objects over LDAP and walks SYSVOL for legacy Group Policy Preferences files that may still contain encrypted cpassword values. Readable GPO metadata or recoverable cpassword artifacts give an intruder a direct path to local and domain credentials without touching a DC interactively. When enumeration or file reads are denied, GPO and SYSVOL exposure is better contained.
- T1557 LDAP Signing Posture ProbetechniqueT1557 — LDAP Signing Posture Probe
After a normal authenticated bind, the agent tests whether the domain controller still accepts unsigned LDAP connections. DCs that permit unsigned binds are vulnerable to relay and man-in-the-middle attacks that piggyback on NTLM or other cleartext-adjacent authentication paths. When unsigned binds are rejected, a key prerequisite for LDAP relay has been removed.
- T1222.001 AdminSDHolder ACL / adminCount DiscoverytechniqueT1222.001 — AdminSDHolder ACL / adminCount Discovery
This check surfaces accounts marked with adminCount and inspects AdminSDHolder-related ACL exposure—protected principals that should inherit tier-zero security descriptors. Broad visibility into adminCount users or unexpected write access to AdminSDHolder creates paths toward persistent privilege escalation. Tighter LDAP controls and clean adminCount hygiene reduce how much of that surface an attacker can map.
- T1003.006 DCSync Rights DiscoverytechniqueT1003.006 — DCSync Rights Discovery
The agent reads the domain naming context DACL and identifies principals other than domain controllers and baseline admin groups that hold replication-style rights—without performing an actual DCSync. Unexpected trustees with Get-Changes–class permissions can extract password hashes and Kerberos keys from AD offline. When only expected infrastructure accounts hold those rights, the DCSync abuse path is narrower.
- T1187 Spooler / RPC Coerce SurfacetechniqueT1187 — Spooler / RPC Coerce Surface
From a workstation context, the agent checks whether SMB (445) and RPC (135) on the configured domain controller are reachable— the network preconditions for Print Spooler coercion attacks such as PetitPotam. Open paths from standard hosts to DC RPC/SMB increase the chance an attacker can force authentication or relay NTLM to the DC. Filtered or closed ports break that coerce-and-relay chain before payload delivery.
- T1201 Domain Password Policy / Weak Account HygienetechniqueT1201 — Domain Password Policy / Weak Account Hygiene
The agent pulls domain password policy, fine-grained password policies, and flags accounts with password-not-required or never-expire settings. Weak minimum length, disabled lockout, or broad exceptions for service accounts make credential guessing and long-lived compromise easier. Strong baseline policy with few exceptions signals better account hygiene.
- T1649 ADCS Certificate Template AbusetechniqueT1649 — ADCS Certificate Template Abuse
This exercise enumerates certificate templates and PKI ACLs for known AD CS misconfigurations (ESC1–ESC15 class issues), probes HTTP enrollment surfaces, and may attempt enrollment and certificate-based logon to prove impact. Vulnerable templates or reachable HTTP enrollment let an attacker mint certificates that impersonate users or elevate to domain admin. Hardened templates, restricted ACLs, and disabled anonymous HTTP enrollment close the most common AD CS escalation routes.
- T1556.006 Shadow Credentials (KeyCredentialLink)techniqueT1556.006 — Shadow Credentials (KeyCredentialLink)
The agent searches for msDS-KeyCredentialLink values on user and computer objects—attributes used by shadow credentials attacks to register alternate keys for Kerberos PKINIT logon. Populated KeyCredentialLink entries on privileged or high-value accounts indicate either active abuse or dangerous write access waiting to be exploited. Clearing unexpected links and restricting who can write the attribute reduces shadow credential risk.
- T1134.005 SID History Injection DiscoverytechniqueT1134.005 — SID History Injection Discovery
This check enumerates sIDHistory on directory accounts and highlights history SIDs that map to privileged RIDs— a technique used to inherit domain admin rights after migrations or trust abuse. Readable sIDHistory with elevated historical SIDs is a direct indicator of privilege injection risk. Clean post-migration hygiene and SID filtering on trusts limit this persistence path.
- T1087.002 Pre-Windows 2000 Compatible AccesstechniqueT1087.002 — Pre-Windows 2000 Compatible Access
The agent verifies whether Everyone or Anonymous Logon is a member of Pre-Windows 2000 Compatible Access—a legacy group that can enable unauthenticated or low-privilege enumeration of SAM-related information. Membership of these broad principals lowers the bar for anonymous reconnaissance against the domain. Removing them restores a baseline that expects authenticated access for sensitive directory queries.
- T1552.001 Credentials in AD DescriptionstechniqueT1552.001 — Credentials in AD Descriptions
User and computer description fields are scanned for keywords and patterns that suggest embedded passwords or secrets. Helpdesk notes and ad hoc documentation in AD attributes are a common source of credential leaks that bypass vault controls entirely. Empty or sanitized descriptions mean one less opportunistic credential harvest for an intruder with LDAP read access.
- T1484.002 Foreign Principals in Privileged GroupstechniqueT1484.002 — Foreign Principals in Privileged Groups
The agent looks for ForeignSecurityPrincipals nested inside privileged groups such as Domain Admins— a sign that trust relationships or cross-domain group membership may grant unexpected elevation. Foreign principals in tier-zero groups expand your blast radius to partner domains and complicate incident scoping. Removing stray FSP members and reviewing trusts keeps privileged group membership within expected boundaries.
- T1136.002 Machine Account QuotatechniqueT1136.002 — Machine Account Quota
This exercise reads ms-DS-MachineAccountQuota on the domain, which controls how many computer accounts a standard user can create without admin help. A quota above zero lets attackers stage rogue machine accounts for Kerberos relay, RBCD, and other AD attacks from a compromised standard user session. Setting quota to zero and requiring privileged joins closes that pre-admission path.
- T1484.001 Exchange PrivExchange PathtechniqueT1484.001 — Exchange PrivExchange Path
The agent searches for the Exchange Windows Permissions group, which historically granted WriteDacl over the domain object and enabled PrivExchange-class escalation to domain admin. Presence of this group on a domain that still runs or once ran Exchange signals a well-known ACL abuse path that attackers actively target. Absence or proper hardening of Exchange role groups removes that specific escalation lane.
- T1557.001 SMB Null Session / Relay SurfacetechniqueT1557.001 — SMB Null Session / Relay Surface
Toward the configured domain controller, the agent attempts SMB null-session access and anonymous share enumeration—the classic setup for NTLM relay when combined with name-resolution poisoning. Successful null sessions or anonymous net view from a standard host mean an attacker could relay captured hashes or map shares without valid credentials. Required signing and disabled anonymous access break that relay surface.
- T1558.003 RC4 / Legacy Kerberos EncryptiontechniqueT1558.003 — RC4 / Legacy Kerberos Encryption
The agent identifies service accounts with SPNs that still permit RC4 or legacy DES Kerberos encryption types. RC4-capable SPN accounts remain Kerberoast targets because offline cracking of ticket material is far more practical than against AES-only accounts. Migrating service accounts to AES-only encryption and rotating keys after the change shrinks the offline attack window.