Files
imposterandClaude Opus 4.8 a7451bc79a feat(attack-chains): interactive TTP graph view
D3-based TTP graph (graph/list toggle, actor filtering, zoom/pan) on attack-chain pages, with supporting diagram/flow include updates and chain content.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-11 08:13:49 -06:00

6.4 KiB

layout, title, subtitle, last_updated, permalink, show_ttp_overlap, ttp_data_key, stages, actors, chokepoints
layout title subtitle last_updated permalink show_ttp_overlap ttp_data_key stages actors chokepoints
attack-chain Ransomware Attack Chain The chokepoint sequence every ransomware operator must follow. 2026-04-12 /attack-chains/ransomware/ true ransomware_ttp_overlap
id label detection_status attacker_action systems detection_signals chokepoint_links
initial_access Initial Access detected Phishing / exposed VPN / RMM abuse Endpoint · Email GW · VPN
Browser download of renamed/masqueraded binary (missing or mismatched signature)
RDP/VPN login from new geo-location or ASN
Email attachment execution from user Downloads folder
Legitimate RMM tool (AnyDesk, ConnectWise, TeamViewer) installed outside of IT workflow
label slug
Renamed RMM Tools renamed-rmm-tools
label slug
ClickFix Techniques clickfix-techniques
id label detection_status attacker_action systems detection_signals
credential_access Credential Access detected LSASS dump / credential harvest DC · Endpoint
LSASS process access by non-system process (Sysmon EID 10)
SAM/SECURITY registry hive read outside of system tools
rundll32.exe loading comsvcs.dll with MiniDump export
esentutl.exe copying browser credential databases
id label detection_status attacker_action systems detection_signals chokepoint_links
lateral_movement Lateral Movement exploited PsExec / RDP / WMI Domain · Servers
Network logon Type 3 + service creation across multiple hosts in short window
IPC$ share access followed by ADMIN$ write
Unusual admin account authenticating to 5+ hosts within 30 minutes
PsExec service installation (PSEXESVC) on remote host
label slug
Remote Execution Tools remote-execution-tools
id label detection_status attacker_action systems detection_signals chokepoint_links
defense_evasion Defense Evasion detected Kill AV/EDR · Safe-mode boot · Stop backups All hosts
Multiple security/backup services stopped in rapid succession
EDR kill tool execution (Backstab, PowerTool, GMER, Terminator)
bcdedit.exe with safeboot argument
PowerShell Set-MpPreference DisableRealtimeMonitoring / DisableAntiSpyware
Veeam, VSS, or SQL service termination
label slug
Ransomware Service Manipulation ransomware-service-manipulation
id label mitre_tactic mitre_techniques detection_status attacker_action systems detection_signals
impact Impact TA0040
id name
T1486 Data Encrypted for Impact
id name
T1490 Inhibit System Recovery
id name
T1567.002 Exfiltration to Cloud Storage
exploited Exfil data · VSS delete · File encrypt All file servers · Cloud storage
vssadmin delete shadows / wmic shadowcopy delete / PowerShell Get-WmiObject Win32_Shadowcopy | Remove-WmiObject
Mass file modifications with high-entropy output (bulk file rename)
Ransom note .txt/.html creation across multiple directories
WinSCP / RClone / FileZilla outbound to cloud storage (Mega, attacker infrastructure)
name status initial_access credential_access lateral_movement defense_evasion impact
BlackBasta Inactive QakBot phishing / Teams social engineering / exploit acquisition (zero-days purchased within days of disclosure) Mimikatz LSASS dump + ZeroLogon / NoPac / PrintNightmare CVE exploitation PsExec + Cobalt Strike beacon (custom 'Coba PROXY' C2 infrastructure) Backstab EDR kill + PowerShell Defender disable (DisableAntiSpyware) + bcdedit safeboot vssadmin delete shadows + ChaCha20/RSA-4096 file encrypt (.basta extension)
name status initial_access credential_access lateral_movement defense_evasion impact
LockBit 3.0 Disrupted Stolen RDP creds / exposed RMM / valid accounts LSASS dump + SAM hive export PsExec + Cobalt Strike + GPO mass-deploy Comprehensive service kill list (50+ services) + registry modification WMI shadow copy delete + fastest-in-class encrypt (LockBit 3.0 / Black)
name status initial_access credential_access lateral_movement defense_evasion impact
Akira Active VPN compromise (no MFA) / SonicWall exploitation / Veeam CVE-2024-40711 Mimikatz + LaZagne + esentutl browser credential theft + comsvcs.dll LSASS MiniDump RDP + SSH + AnyDesk / RustDesk / MobaXterm PowerTool + Terminator BYOVD + Zemana AntiMalware driver EDR kill PowerShell WMI shadow delete + Akira / Akira_v2 (Rust) / Megazord encrypt
name status initial_access credential_access lateral_movement defense_evasion impact
Alphv/BlackCat Defunct Stolen creds / Eamfo infostealer (Veeam credential theft) / exposed web services Eamfo Veeam credential theft + LSASS dump PsExec + RDP + WMI Multi-vendor EDR termination + reg.exe registry modification + bcdedit safeboot vssadmin delete shadows + vim-cmd snapshot.removeall (ESXi) + cross-platform Rust encrypt
name status initial_access credential_access lateral_movement defense_evasion impact
Play Active N-day exploits (FortiOS, Exchange ProxyNotShell/OWASSRF) Mimikatz LSASS dump PsExec + WMI + Grixba custom infostealer GMER + IOBit + Process Hacker + PowerTool Custom .NET VSS Copying Tool + PlayCrypt selective file encrypt
initial_access credential_access lateral_movement defense_evasion impact
User executes payload OR exposed service is network-reachable Elevated process reads memory/registry containing credential material Valid admin credentials + network path open (445 / 3389 / 135) SYSTEM-level process with service stop/delete permission File system write access + encryption library loaded

Research Methodology

Source: Kitsune pipeline over ORKL + vendor reports - 260 procedures / 36 reports / 5 actors. Convergent techniques only.

  • [Infostealers]({{ '/attack-chains/infostealers/' | relative_url }}) - Often precedes ransomware via IABs
  • [AiTM / Phishing Kits]({{ '/attack-chains/aitm/' | relative_url }}) - AiTM-compromised accounts sold to ransomware IABs