Adversary Emulation Library
In collaboration with Center Participants, the MITRE Center for Threat-Informed Defense
(Center) maintains a library of adversary emulation
plans to allow organizations to evaluate their defensive capabilities against the
real-world threats they face. Emulation plans are an essential component in testing
current defenses for organizations that are looking to prioritize their defenses around
actual adversary behavior. Focusing our energies on developing a set of common emulation
plans that are available to all means that organizations can use their limited time and
resources to focus on understanding how their defenses actually fare against real-world
threats.
The library contains two types of adversary emulation plans: full emulation and micro
emulation.
Full emulation plans are a comprehensive approach to emulating a specific adversary,
e.g. FIN6, from initial access to exfiltration. These plans emulate a wide
range of ATT&CK tactics & techniques and are designed to emulate a real breach from the
designated adversary.
Micro emulation plans are a focused approach to emulating compound behaviors seen
across multiple adversaries, e.g. webshells.
These plans emulate a small amount of ATT&CK techniques that are typically performed as
part of one adversary action.
Also see our blogs on the Adversary Emulation
Library
and Micro Emulation
Plans.
Available adversary emulation plans are listed below:
| Full Emulation Plans | Intelligence Summary |
|---|
| APT29 | APT29 is thought to be an organized and well-resourced cyber threat actor whose collection objectives appear to align with the interests of the Russian Federation... |
| Blind Eagle | Blind Eagle is a South American threat actor focused on Colombia-based institutions, including entities in the financial, manufacturing, and petroleum sectors. Largely opportunistic in their motives, Blind Eagle leverages commodity RATs modified to fit the environment... |
| Carbanak Group | Carbanak is a threat group who has been found to manipulate financial assets, such as by transferring funds from bank accounts or by taking over ATM infrastructures... |
| FIN6 | FIN6 is thought to be a financially motivated cyber-crime group. The group has aggressively targeted and compromised high-volume POS systems in the hospitality and retail sectors since at least 2015... |
| FIN7 | FIN7 is a financially-motivated threat group that has been associated with malicious operations dating back to late 2015. The group is characterized by their persistent targeting and large-scale theft of payment card data from victim systems... |
| menuPass | menuPass is thought to be threat group motivated by collection objectives, with targeting that is consistent with Chinese strategic objectives... |
| OceanLotus | OceanLotus is a cyber threat actor aligning to the interests of the Vietnamese government. First seen in 2012, OceanLotus targets private corporations in the manufacturing, consumer product, and hospitality sectors as well as foreign governments, political dissidents, and journalists.... |
| OilRig | OilRig is a cyber threat actor with operations aligning to the strategic objectives of the Iranian government. OilRig has been operational since at least 2014 and has a history of widespread impact, with operations directed against financial, government, energy, chemical, telecommunications and other sectors around the globe... |