Commit 5: Trim Intel Resources to foundational-only (per-chokepoint judgment)

YAML: Removed variant-specific, single-incident, secondary, and annual
report entries from all 7 chokepoint Intel sections. Migrated variant-
specific sources to SourceURL on variation cards (Commit 3). Added
Tier: primary to entries that lacked the field. No Tier: supporting entries
remain in any chokepoint file.

Entry counts after trim:
  clickfix:             18 → 9
  renamed-rmm:           7 → 4
  edr-bypass:           10 → 4  (Tier field added to all kept entries)
  ransomware-svc:        8 → 3
  browser-credential:    9 → 5  (Tier field added to all kept entries)
  web-shells:           10 → 5  (Tier field added to all kept entries)
  remote-execution:      9 → 7

Layout: Replaced tiered Intel rendering (primary card grid + supporting
collapsible toggle) with a uniform flat link list — title (link) + one
sentence description. Removed intel-card, intel-grid, intel-card-name,
intel-card-desc, intel-linked, intel-link-tag, intel-supporting-toggle CSS.
Removed intel-supporting-toggle JS event handler.

https://claude.ai/code/session_018xsxUHnwvGtKP6J2W69qa5
This commit is contained in:
Claude
2026-03-22 23:50:00 +00:00
parent 3679258a43
commit fb1171be45
8 changed files with 33 additions and 287 deletions
@@ -191,7 +191,7 @@ Intel:
URL: https://attack.mitre.org/software/S0357/
Description: Lists every known threat actor (APT groups, ransomware operators) documented using Impacket; far more useful to a defender than the raw GitHub repo for understanding real-world prevalence
- Name: MITRE ATT&CK — T1021.003 DCOM
Tier: supporting
Tier: primary
URL: https://attack.mitre.org/techniques/T1021/003/
Description: Technique definition for DCOM-based lateral movement; covers dcomexec.py usage and detection guidance
- Name: MITRE ATT&CK — T1569.002 Service Execution
@@ -203,27 +203,19 @@ Intel:
URL: https://www.microsoft.com/en-us/security/blog/2024/09/26/storm-0501-ransomware-attacks-expanding-to-hybrid-cloud-environments/
Description: Documents Storm-0501 using Impacket SecretsDump for lateral movement in hybrid cloud environments; concrete example of Impacket use in a 2024 ransomware campaign
LinkedFrom: ["Impacket"]
- Name: ThreatLocker — Top 10 Post-Exploitation Tools Threat Actors Use
Tier: primary
URL: https://www.threatlocker.com/blog/top-post-exploitation-tools-threat-actors-use
Description: Real-world prevalence data for post-exploitation tooling including Impacket, NetExec, and C2 frameworks observed across actual intrusions
- Name: Impacket GitHub
Tier: supporting
Tier: primary
URL: https://github.com/fortra/impacket
Description: Monitor releases and PRs for new execution modules; source of truth for what capabilities the suite currently covers
- Name: NetExec GitHub
Tier: supporting
Tier: primary
URL: https://github.com/Pennyw0rth/NetExec
Description: Active successor to CrackMapExec; track new protocol support and OPSEC improvements that affect detection
- Name: SOC Investigation — Event ID 5145 Threat Hunting
Tier: supporting
Tier: primary
URL: https://www.socinvestigation.com/threat-hunting-with-eventid-5145-object-access-detailed-file-share/
Description: Detailed guidance on using Event ID 5145 (Detailed File Share) for lateral movement detection; covers IPC$ access correlation
LinkedFrom: ["Remote Execution Primitive"]
- Name: "hunt.io — C2 Infrastructure Tracking"
Tier: supporting
URL: "https://hunt.io"
Description: "Real-time C2 infrastructure map; AttackCapture feed tags Cobalt Strike, Sliver, Havoc, and Metasploit servers by banner and certificate fingerprint."
RelatedChokepoints:
- ransomware-service-manipulation