{
  "name": "Volt Typhoon Critical Infrastructure Pre-Positioning - ATT&CK Navigator Layer",
  "versions": {
    "attack": "15",
    "navigator": "4.5",
    "layer": "4.5"
  },
  "domain": "enterprise-attack",
  "description": "MITRE ATT&CK technique mappings with verified legal evidence for case volt-typhoon-critical-infrastructure.",
  "filters": {
    "platforms": [
      "Windows",
      "Linux",
      "macOS",
      "Network",
      "PRE"
    ]
  },
  "sorting": 0,
  "layout": {
    "layout": "side",
    "aggregateFunction": "average",
    "showID": true,
    "showName": true,
    "showAggregateScores": false,
    "countUnscored": false
  },
  "hideDisabled": false,
  "techniques": [
    {
      "techniqueID": "T1078",
      "score": 1,
      "color": "#f59e0b",
      "comment": "Volt Typhoon actors exclusively use legitimate credentials and built-in system administration tools (living off the land) to evade security detections.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "CISA Advisory AA24-038A \u00b6 3"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1190",
      "score": 1,
      "color": "#f59e0b",
      "comment": "Initial access was achieved by exploiting zero-day vulnerabilities in edge network routers and VPN firewalls including Fortinet and Ivanti appliances.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "CISA Advisory AA24-038A \u00b6 12"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1584",
      "score": 1,
      "color": "#f59e0b",
      "comment": "Adversaries routed traffic through the KV-botnet of infected small office and home office (SOHO) Cisco and Netgear routers across the United States.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "DOJ Press Release 24-118"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1059.003",
      "score": 1,
      "color": "#f59e0b",
      "comment": "Adversaries executed native cmd.exe utilities including ping, tracert, and netsh to explore domain topology without deploying custom malware.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "Advisory Technical Appendix"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1016",
      "score": 1,
      "color": "#f59e0b",
      "comment": "Volt Typhoon operators ran 'ipconfig /all' and 'netsh interface portproxy show all' to document network interface routing.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "CISA Advisory AA24-038A \u00b6 18"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1018",
      "score": 1,
      "color": "#f59e0b",
      "comment": "Adversaries executed ping sweeps and 'net group \"Domain Computers\" /domain' to identify neighboring workstation hostnames.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "CISA Advisory AA24-038A \u00b6 22"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1033",
      "score": 1,
      "color": "#f59e0b",
      "comment": "The threat group ran 'whoami' and 'net user' commands immediately upon authenticating to establish active privilege scope.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "CISA Technical Appendix"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1057",
      "score": 1,
      "color": "#f59e0b",
      "comment": "Volt Typhoon executed 'tasklist /v' to discover running security monitoring agents and backup daemons on critical servers.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "CISA Advisory AA24-038A \u00b6 19"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    },
    {
      "techniqueID": "T1570",
      "score": 1,
      "color": "#f59e0b",
      "comment": "Adversaries copied living-off-the-land scripts across internal shares using administrative SMB channels.",
      "enabled": true,
      "metadata": [
        {
          "name": "locator",
          "value": "CISA Advisory AA24-038A \u00b6 25"
        },
        {
          "name": "status",
          "value": "reviewed"
        }
      ]
    }
  ],
  "gradient": {
    "colors": [
      "#0e1420",
      "#f59e0b"
    ],
    "minValue": 0,
    "maxValue": 1
  },
  "legendItems": [
    {
      "label": "Mapped in primary evidence",
      "color": "#f59e0b"
    }
  ],
  "metadata": [
    {
      "name": "case_slug",
      "value": "volt-typhoon-critical-infrastructure"
    },
    {
      "name": "case_title",
      "value": "Volt Typhoon Critical Infrastructure Pre-Positioning"
    }
  ]
}