Trusted Design

RSA IR: An APT Case Study

概要

This case study contains information from an engagement that the RSA Incident Response (IR) team worked during the September to October 2013 timeframe. It highlights the analysis flow using two of our flagship products, Security Analytics (SA) and the Enterprise Compromise Assessment Tool (ECAT), for an Advance Persistent Threat (APT) intrusion investigation. These key technologies allow RSA analysts to process massive datasets and find forensically interesting artifacts in near real-time and more quickly than using standard incident response processes.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Sandworm Team

Score: 6.96
Matched TTPs:
  • T1132.001 - Standard Encoding
  • T1070.004 - File Deletion
  • T1584.004 - Server
MITREへのリンク →

Patchwork

Score: 4.13
Matched TTPs:
  • T1132.001 - Standard Encoding
  • T1070.004 - File Deletion
MITREへのリンク →

APT42

Score: 6.37
Matched TTPs:
  • T1132.001 - Standard Encoding
  • T1070 - Indicator Removal
MITREへのリンク →

BRONZE BUTLER

Score: 10.56
Matched TTPs:
  • T1132.001 - Standard Encoding
  • T1550.003 - Pass the Ticket
  • T1070.004 - File Deletion
  • T1124 - System Time Discovery
MITREへのリンク →

Lazarus Group

Score: 19.45
Matched TTPs:
  • T1132.001 - Standard Encoding
  • T1070 - Indicator Removal
  • T1583.006 - Web Services
  • T1057 - Process Discovery
  • T1070.004 - File Deletion
  • T1584.004 - Server
  • T1124 - System Time Discovery
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Tropic Trooper

Score: 5.64
Matched TTPs:
  • T1132.001 - Standard Encoding
  • T1057 - Process Discovery
  • T1070.004 - File Deletion
MITREへのリンク →

MuddyWater

Score: 6.28
Matched TTPs:
  • T1132.001 - Standard Encoding
  • T1583.006 - Web Services
  • T1057 - Process Discovery
MITREへのリンク →

APT33

Score: 5.49
Matched TTPs:
  • T1132.001 - Standard Encoding
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

HAFNIUM

Score: 6.28
Matched TTPs:
  • T1132.001 - Standard Encoding
  • T1583.006 - Web Services
  • T1057 - Process Discovery
MITREへのリンク →

Medusa Group

Score: 9.04
Matched TTPs:
  • T1608.002 - Upload Tool
  • T1583.006 - Web Services
  • T1057 - Process Discovery
  • T1070.004 - File Deletion
MITREへのリンク →

Threat Group-3390

Score: 5.51
Matched TTPs:
  • T1608.002 - Upload Tool
  • T1070.004 - File Deletion
MITREへのリンク →

UNC3886

Score: 9.62
Matched TTPs:
  • T1681 - Search Threat Vendor Data
  • T1057 - Process Discovery
  • T1070.004 - File Deletion
  • T1124 - System Time Discovery
MITREへのリンク →

Contagious Interview

Score: 14.12
Matched TTPs:
  • T1681 - Search Threat Vendor Data
  • T1497 - Virtualization/Sandbox Evasion
  • T1583.006 - Web Services
  • T1070.004 - File Deletion
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Mustang Panda

Score: 15.82
Matched TTPs:
  • T1070 - Indicator Removal
  • T1583.006 - Web Services
  • T1057 - Process Discovery
  • T1678 - Delay Execution
  • T1070.004 - File Deletion
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

APT5

Score: 6.52
Matched TTPs:
  • T1070 - Indicator Removal
  • T1057 - Process Discovery
  • T1070.004 - File Deletion
MITREへのリンク →

APT29

Score: 7.24
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1583.006 - Web Services
  • T1070.004 - File Deletion
MITREへのリンク →

APT32

Score: 9.98
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1583.006 - Web Services
  • T1070.004 - File Deletion
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Saint Bear

Score: 5.86
Matched TTPs:
  • T1497 - Virtualization/Sandbox Evasion
  • T1583.006 - Web Services
MITREへのリンク →

Darkhotel

Score: 7.95
Matched TTPs:
  • T1497 - Virtualization/Sandbox Evasion
  • T1057 - Process Discovery
  • T1124 - System Time Discovery
MITREへのリンク →

Earth Lusca

Score: 6.36
Matched TTPs:
  • T1583.006 - Web Services
  • T1057 - Process Discovery
  • T1584.004 - Server
MITREへのリンク →

Turla

Score: 8.96
Matched TTPs:
  • T1583.006 - Web Services
  • T1057 - Process Discovery
  • T1584.004 - Server
  • T1124 - System Time Discovery
MITREへのリンク →

ZIRCONIUM

Score: 4.60
Matched TTPs:
  • T1583.006 - Web Services
  • T1124 - System Time Discovery
MITREへのリンク →

APT28

Score: 9.04
Matched TTPs:
  • T1583.006 - Web Services
  • T1057 - Process Discovery
  • T1070.004 - File Deletion
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

FIN7

Score: 6.12
Matched TTPs:
  • T1583.006 - Web Services
  • T1057 - Process Discovery
  • T1124 - System Time Discovery
MITREへのリンク →

Gamaredon Group

Score: 9.45
Matched TTPs:
  • T1583.006 - Web Services
  • T1057 - Process Discovery
  • T1001 - Data Obfuscation
  • T1070.004 - File Deletion
MITREへのリンク →

Kimsuky

Score: 4.91
Matched TTPs:
  • T1583.006 - Web Services
  • T1057 - Process Discovery
  • T1070.004 - File Deletion
MITREへのリンク →

Magic Hound

Score: 4.91
Matched TTPs:
  • T1583.006 - Web Services
  • T1057 - Process Discovery
  • T1070.004 - File Deletion
MITREへのリンク →

Volt Typhoon

Score: 12.46
Matched TTPs:
  • T1057 - Process Discovery
  • T1070.004 - File Deletion
  • T1584.004 - Server
  • T1596.005 - Scan Databases
  • T1124 - System Time Discovery
MITREへのリンク →

Sidewinder

Score: 4.11
Matched TTPs:
  • T1057 - Process Discovery
  • T1124 - System Time Discovery
MITREへのリンク →

Chimera

Score: 5.49
Matched TTPs:
  • T1057 - Process Discovery
  • T1070.004 - File Deletion
  • T1124 - System Time Discovery
MITREへのリンク →

Higaisa

Score: 4.11
Matched TTPs:
  • T1057 - Process Discovery
  • T1124 - System Time Discovery
MITREへのリンク →

OilRig

Score: 5.64
Matched TTPs:
  • T1057 - Process Discovery
  • T1070.004 - File Deletion
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

FIN6

Score: 4.13
Matched TTPs:
  • T1070.004 - File Deletion
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

APT41

Score: 5.51
Matched TTPs:
  • T1070.004 - File Deletion
  • T1596.005 - Scan Databases
MITREへのリンク →

Wizard Spider

Score: 4.13
Matched TTPs:
  • T1070.004 - File Deletion
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Dragonfly

Score: 4.21
Matched TTPs:
  • T1070.004 - File Deletion
  • T1584.004 - Server
MITREへのリンク →

FIN8

Score: 4.13
Matched TTPs:
  • T1070.004 - File Deletion
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

The White Company

Score: 3.97
Matched TTPs:
  • T1070.004 - File Deletion
  • T1124 - System Time Discovery
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Velvet Ant

Score: 4.13
Matched TTPs:
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

Blue Mockingbird

Score: 4.54
Matched TTPs:
  • T1574.012 - COR_PROFILER
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Lazarus Group

Score: 0.80
Matched TTPs:
  • T1583.006 - Web Services
  • T1070.004 - File Deletion
  • T1057 - Process Discovery
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1584.004 - Server
  • T1124 - System Time Discovery
  • T1070 - Indicator Removal
  • T1132.001 - Standard Encoding
MITREへのリンク →

Mustang Panda

Score: 0.68
Matched TTPs:
  • T1583.006 - Web Services
  • T1070.004 - File Deletion
  • T1678 - Delay Execution
  • T1057 - Process Discovery
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
  • T1070 - Indicator Removal
MITREへのリンク →

Contagious Interview

Score: 0.59
Matched TTPs:
  • T1681 - Search Threat Vendor Data
  • T1583.006 - Web Services
  • T1070.004 - File Deletion
  • T1497 - Virtualization/Sandbox Evasion
  • T1048.003 - Exfiltration Over Unencrypted Non-C2 Protocol
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る