{
  "type": "bundle",
  "id": "bundle--d71cc3c4cada3ce2b501a93c3642387e",
  "objects": [
    {
      "type": "identity",
      "spec_version": "2.1",
      "id": "identity--cyberattack-case-library",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Cyberattack Case Library",
      "description": "Primary-source legal and threat intelligence archive.",
      "identity_class": "organization"
    },
    {
      "type": "threat-actor",
      "spec_version": "2.1",
      "id": "threat-actor--7004742d9cb776753eae8c5f0da22c37",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Sandworm Team",
      "description": "Attributed in official legal proceedings. U.S. Department of Justice Indictment (W.D. Pa.) & CISA",
      "aliases": [
        "Telebots",
        "Voodoo Bear",
        "Iron Viking",
        "Unit 74455",
        "BlackEnergy Group"
      ],
      "roles": [
        "adversary"
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "threat-actor",
      "spec_version": "2.1",
      "id": "threat-actor--110afcbc05945293de96edcb865d7812",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "APT28",
      "description": "Attributed in official legal proceedings. U.S. Department of Justice Indictment (D.D.C.)",
      "aliases": [
        "Fancy Bear",
        "Sofacy",
        "Sednit",
        "STRONTIUM",
        "Unit 26165"
      ],
      "roles": [
        "adversary"
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "threat-actor",
      "spec_version": "2.1",
      "id": "threat-actor--fa16c7f27a0ad2973f6b388b85929931",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "APT29",
      "description": "Attributed in official legal proceedings. CISA Advisory AA20-352A & White House Statement",
      "aliases": [
        "Cozy Bear",
        "Nobelium",
        "Midnight Blizzard",
        "The Dukes",
        "SVR"
      ],
      "roles": [
        "adversary"
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "threat-actor",
      "spec_version": "2.1",
      "id": "threat-actor--a7db4a542e2fb8da4aabd54549b1c40b",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "LockBit Ransomware Group",
      "description": "Attributed in official legal proceedings. U.S. Department of Justice (D.N.J.) & NCA Operation Cronos",
      "aliases": [
        "LockBit 2.0",
        "LockBit 3.0",
        "LockBit Black",
        "LockBit Green"
      ],
      "roles": [
        "adversary"
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "threat-actor",
      "spec_version": "2.1",
      "id": "threat-actor--21494b97c13f6998e27a6c63fee69b73",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Volt Typhoon",
      "description": "Attributed in official legal proceedings. CISA, FBI, NSA Joint Cybersecurity Advisory",
      "aliases": [
        "BRONZE SILHOUETTE",
        "Vanguard Panda",
        "Insidious Taurus"
      ],
      "roles": [
        "adversary"
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "threat-actor",
      "spec_version": "2.1",
      "id": "threat-actor--b9f5a81aa5b8ff9e9e57812495b14ac0",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Salt Typhoon",
      "description": "Attributed in official legal proceedings. CISA & FBI Joint Statement on Telecommunications Infiltration",
      "aliases": [
        "GhostEmperor",
        "FamousSparrow"
      ],
      "roles": [
        "adversary"
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "threat-actor",
      "spec_version": "2.1",
      "id": "threat-actor--d77a7efd9d1b6620bce429be0c9e55d3",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Lazarus Group",
      "description": "Attributed in official legal proceedings. U.S. Department of Justice Indictment (C.D. Cal.)",
      "aliases": [
        "HIDDEN COBRA",
        "Guardians of Peace",
        "Zinc",
        "APT38",
        "Labyrinth Chollima"
      ],
      "roles": [
        "adversary"
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "threat-actor",
      "spec_version": "2.1",
      "id": "threat-actor--3e382750eb94f84926325593487a63c5",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Evil Corp",
      "description": "Attributed in official legal proceedings. U.S. Department of Justice (W.D. Pa.) & OFAC Sanctions",
      "aliases": [
        "Indiktor",
        "Dridex Gang"
      ],
      "roles": [
        "adversary"
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "threat-actor",
      "spec_version": "2.1",
      "id": "threat-actor--3ab18ccd7a511ec49ea14c12ad1df7c4",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "FIN7",
      "description": "Attributed in official legal proceedings. U.S. Department of Justice Indictments (W.D. Wash.)",
      "aliases": [
        "Carbanak Group",
        "Navigator Group",
        "ELBRUS"
      ],
      "roles": [
        "adversary"
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "threat-actor",
      "spec_version": "2.1",
      "id": "threat-actor--12ad0d7c4b4158d823c8ac353ff6082f",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "DarkSide",
      "description": "Attributed in official legal proceedings. CISA Advisory AA21-131A & DOJ Forfeiture Actions",
      "aliases": [
        "BlackMatter",
        "ALPHV Affiliate"
      ],
      "roles": [
        "adversary"
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "threat-actor",
      "spec_version": "2.1",
      "id": "threat-actor--f5f04a2e9e4067478fb0d656d3025e03",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "ALPHV / BlackCat",
      "description": "Attributed in official legal proceedings. DOJ Takedown & CISA Joint Advisory AA23-353A",
      "aliases": [
        "BlackCat",
        "Noberus"
      ],
      "roles": [
        "adversary"
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "threat-actor",
      "spec_version": "2.1",
      "id": "threat-actor--7379448e5cd6392d57f0ea2dc74e176b",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Wizard Spider",
      "description": "Attributed in official legal proceedings. U.S. Department of Justice Indictment (N.D. Ohio)",
      "aliases": [
        "Trickbot Group",
        "Conti",
        "UNC1878",
        "Grim Spider"
      ],
      "roles": [
        "adversary"
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "threat-actor",
      "spec_version": "2.1",
      "id": "threat-actor--42b25cc5820ff014887a110c1e042d01",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "CL0P",
      "description": "Attributed in official legal proceedings. CISA Advisory AA23-158A (MOVEit Campaign)",
      "aliases": [
        "TA505",
        "FIN11",
        "Lace Tempest"
      ],
      "roles": [
        "adversary"
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "threat-actor",
      "spec_version": "2.1",
      "id": "threat-actor--64106300a71386945c56658d15b15692",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "REvil / Sodinokibi",
      "description": "Attributed in official legal proceedings. U.S. Department of Justice (N.D. Tex.) & Europol Operation GoldDust",
      "aliases": [
        "Sodinokibi",
        "Gold Southfield"
      ],
      "roles": [
        "adversary"
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "threat-actor",
      "spec_version": "2.1",
      "id": "threat-actor--0215727816d0c0325a1bfe086ea8e0da",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "PLA Unit 61398",
      "description": "Attributed in official legal proceedings. U.S. Department of Justice Indictment (W.D. Pa., May 2014)",
      "aliases": [
        "APT1",
        "Comment Crew",
        "TG-8223"
      ],
      "roles": [
        "adversary"
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "threat-actor",
      "spec_version": "2.1",
      "id": "threat-actor--87c373ada462da37dda9af079f9b28d6",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "IRGC Cyber-Electronic Command",
      "description": "Attributed in official legal proceedings. U.S. Department of Justice (W.D. Pa.) & CISA Advisory AA23-335A",
      "aliases": [
        "CyberAv3ngers",
        "Shahid Shoushtari",
        "Cotton Sandstorm"
      ],
      "roles": [
        "adversary"
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--c9a6265b74aa63a4bda48e70fbe74596",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Spearphishing Attachment",
      "description": "Adversaries send spearphishing emails with malicious attachments to gain initial access to victim systems.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1566.001",
          "url": "https://attack.mitre.org/techniques/T1566/001/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--3e9e9d8cdd63fe50a7c5bc2a97c75244",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Spearphishing Link",
      "description": "Adversaries send spearphishing emails containing malicious hyperlinks to lure users into downloading payloads or entering credentials.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1566.002",
          "url": "https://attack.mitre.org/techniques/T1566/002/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--52b4d166dd13f10c31fa50cae77c0d83",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Exploit Public-Facing Application",
      "description": "Adversaries exploit vulnerabilities in internet-connected software such as web servers or VPN appliances.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1190",
          "url": "https://attack.mitre.org/techniques/T1190/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--873f4825621256e0af7750a1d7d23da1",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Valid Accounts",
      "description": "Adversaries obtain and misuse legitimate credentials of existing user accounts to maintain persistence and bypass controls.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1078",
          "url": "https://attack.mitre.org/techniques/T1078/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--63231ddbcea87f473977a667542d4d04",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "PowerShell",
      "description": "Adversaries abuse the Windows PowerShell command environment to execute commands and download malicious payloads.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1059.001",
          "url": "https://attack.mitre.org/techniques/T1059/001/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--e0a002bd92dee8376dafd4f3545d2bbc",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Windows Command Shell",
      "description": "Adversaries execute commands and batch scripts using the Windows cmd.exe command shell.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1059.003",
          "url": "https://attack.mitre.org/techniques/T1059/003/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--518a2d9df0d2c0be6d1fe4ba527ee3ba",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Remote Desktop Protocol",
      "description": "Adversaries use Remote Desktop Protocol (RDP) connections to log into target systems interactively.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1021.001",
          "url": "https://attack.mitre.org/techniques/T1021/001/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--44a1263b9139b047f0289dbd373a9088",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Data Encrypted for Impact",
      "description": "Adversaries encrypt victim files and databases to disrupt business operations and demand financial extortion.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1486",
          "url": "https://attack.mitre.org/techniques/T1486/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--03288c6f5b9c797eafd2bc3a24e37d60",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Inhibit System Recovery",
      "description": "Adversaries delete volume shadow copies and system restore points to prevent recovery from ransomware.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1490",
          "url": "https://attack.mitre.org/techniques/T1490/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--d387970359a2a24f54d024e29a87ec28",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "OS Credential Dumping",
      "description": "Adversaries dump plaintext passwords and hashes from operating system memory structures such as LSASS.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1003",
          "url": "https://attack.mitre.org/techniques/T1003/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--a184978df9d1587aea33cb163796a15d",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Exfiltration Over C2 Channel",
      "description": "Adversaries transmit stolen data over existing command and control channels back to adversary servers.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1041",
          "url": "https://attack.mitre.org/techniques/T1041/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--f58c38c1ab26ab8630469f714e159d71",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Exfiltration Over Web Service",
      "description": "Adversaries exfiltrate sensitive files to legitimate cloud storage providers like Mega or Google Drive.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1567",
          "url": "https://attack.mitre.org/techniques/T1567/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--d8f146906d0db41f9421c66c951b05c3",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Ingress Tool Transfer",
      "description": "Adversaries transfer tools and post-exploitation binaries from external infrastructure onto compromised hosts.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1105",
          "url": "https://attack.mitre.org/techniques/T1105/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--14a8b5ae92b8ba5aeef611539a2af303",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Indicator Removal",
      "description": "Adversaries delete event logs and temporary files to hinder incident response and forensic attribution.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1070",
          "url": "https://attack.mitre.org/techniques/T1070/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--1b725a7928b9504c29513ac3f7c52e87",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Data Destruction",
      "description": "Adversaries irreversibly overwrite storage media and files to destroy data rather than extort ransoms.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1485",
          "url": "https://attack.mitre.org/techniques/T1485/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--45740b4c4092f3127f7d4d6bd9d773f6",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Disable or Modify Tools",
      "description": "Adversaries disable endpoint security software and antivirus services to prevent detection.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1562.001",
          "url": "https://attack.mitre.org/techniques/T1562/001/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--36d2292a38b40299991cc427446dba21",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Proxy",
      "description": "Adversaries route network communications through intermediate proxy chains or Tor to hide origin IP addresses.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1090",
          "url": "https://attack.mitre.org/techniques/T1090/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--3ce795d8c653df13fbd8a47186a75943",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Scheduled Task",
      "description": "Adversaries abuse task scheduling utilities to execute malicious code at fixed intervals or system startup.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1053.005",
          "url": "https://attack.mitre.org/techniques/T1053/005/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--9e50e1f83f5d1fe4fbab00ab98d9625b",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "System Information Discovery",
      "description": "Adversaries gather details about the operating system and architecture to guide further exploitation.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1082",
          "url": "https://attack.mitre.org/techniques/T1082/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--042f4776884f53480f0fd39ad7a5cd57",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Account Discovery",
      "description": "Adversaries enumerate domain and local user accounts to locate high-privilege targets.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1087",
          "url": "https://attack.mitre.org/techniques/T1087/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--420c7294421350c4efca41daf672aaf8",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "File and Directory Discovery",
      "description": "Adversaries search file systems and shared drives for sensitive files and trade secrets.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1083",
          "url": "https://attack.mitre.org/techniques/T1083/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--ac1acad2f99887b8d124b4f165340535",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Obfuscated Files or Information",
      "description": "Adversaries encrypt or encode payload strings and executable code to conceal malicious contents.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1027",
          "url": "https://attack.mitre.org/techniques/T1027/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--5334690e358f6311b11367ac36045725",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Registry Run Keys / Startup Folder",
      "description": "Adversaries add program references to Windows registry run keys to execute malware on user logon.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1547.001",
          "url": "https://attack.mitre.org/techniques/T1547/001/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--568db322da05b5d89cbfd267d9293d53",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Obtain Tool",
      "description": "Adversaries buy or download third-party commercial tools and exploits for intrusion operations.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1588.002",
          "url": "https://attack.mitre.org/techniques/T1588/002/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--e7ecdd2ff1fc2f635615db2a03253742",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Web Protocols",
      "description": "Adversaries communicate using standard HTTP and HTTPS web protocols to blend with regular traffic.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1071.001",
          "url": "https://attack.mitre.org/techniques/T1071/001/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--dd7549ea41d7acb703592b6b02eac663",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Credentials from Password Stores",
      "description": "Adversaries search local browser credential databases and keyrings for cached web passwords.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1555",
          "url": "https://attack.mitre.org/techniques/T1555/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--5b080f9d50e3bd35ec644b629a46ed09",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Brute Force",
      "description": "Adversaries use automated credential guessing or password spraying against authentication portals.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1110",
          "url": "https://attack.mitre.org/techniques/T1110/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--5b8380ed4b8fd92e1eb8a822d45527e2",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "DLL Side-Loading",
      "description": "Adversaries execute malicious dynamic-link libraries by placing them alongside signed, legitimate executables.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1574.002",
          "url": "https://attack.mitre.org/techniques/T1574/002/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--e5bfa33b4f18d2d536aae74ede396d34",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Process Discovery",
      "description": "Adversaries enumerate running system processes to locate security agents and target software.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1057",
          "url": "https://attack.mitre.org/techniques/T1057/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--1a83ffd1fd98227f561fb3f03db2fd63",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "External Remote Services",
      "description": "Adversaries connect to external-facing VPNs, Citrix gateways, and portals using stolen credentials.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1133",
          "url": "https://attack.mitre.org/techniques/T1133/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--f9c0c76cc8862de0a9083edf0c6ea840",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Service Execution",
      "description": "Adversaries create and run Windows services to execute payloads with system privileges.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1569.002",
          "url": "https://attack.mitre.org/techniques/T1569/002/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--a3cc3351c24df84731a8d2d00c9e9c5a",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Network Service Discovery",
      "description": "Adversaries scan network IP ranges to identify open ports, listening services, and exploitable servers.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1046",
          "url": "https://attack.mitre.org/techniques/T1046/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--c0615fe100c3df4a40269c18ad9713f2",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Lateral Tool Transfer",
      "description": "Adversaries copy binaries, scripts, and utilities from one internal host to another.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1570",
          "url": "https://attack.mitre.org/techniques/T1570/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--9436310b4782145ffc09c6bff4091bd8",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Archive via Utility",
      "description": "Adversaries compress and password-protect stolen files using tools like 7-Zip, WinRAR, or tar.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1560.001",
          "url": "https://attack.mitre.org/techniques/T1560/001/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--9cfdbdacf4fa241327d10e61ef7d61e9",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Local Data Staging",
      "description": "Adversaries stage stolen documents in hidden directories before exfiltrating them.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1074.001",
          "url": "https://attack.mitre.org/techniques/T1074/001/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--d77d945aa3664e9742317aba47e126df",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Compromise Infrastructure",
      "description": "Adversaries hijack third-party domains, servers, and routers to use as attack relay infrastructure.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1584",
          "url": "https://attack.mitre.org/techniques/T1584/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--30f45e1ab9a4ba132c60a27dab923a0f",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Domains",
      "description": "Adversaries register typo-squatted or deceptively named domain names for phishing campaigns.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1583.001",
          "url": "https://attack.mitre.org/techniques/T1583/001/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--afdee52ea22045899a658ec2a47f5cf6",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "SMB / Windows Admin Shares",
      "description": "Adversaries leverage Server Message Block (SMB) and administrative shares (C$, ADMIN$) for lateral spread.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1021.002",
          "url": "https://attack.mitre.org/techniques/T1021/002/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--35c4d3e42e1ec7808d982eaef78eb493",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Kerberoasting",
      "description": "Adversaries request Kerberos service tickets for accounts with Service Principal Names and crack hashes offline.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1558.003",
          "url": "https://attack.mitre.org/techniques/T1558/003/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--35788b4632f9cdd6ff8b0edbab9d85d5",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "System Service Discovery",
      "description": "Adversaries list configured system services to find exploitable software paths and vulnerable configurations.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1007",
          "url": "https://attack.mitre.org/techniques/T1007/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--6b5b16b38de22dd8fb618a889de90c9a",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Process Injection",
      "description": "Adversaries inject malicious code into processes to evade process-based defenses and elevate privileges.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1055",
          "url": "https://attack.mitre.org/techniques/T1055/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--9ab7330e5ab08a44d6e21340734dfb0c",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Process Hollowing",
      "description": "Adversaries hollow out legitimate executables in memory and overwrite them with malicious payloads.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1055.012",
          "url": "https://attack.mitre.org/techniques/T1055/012/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--3c83319d20cd6d0d36f0e707a07b138f",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Masquerading",
      "description": "Adversaries manipulate features of their artifacts to make them appear legitimate or benign.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1036",
          "url": "https://attack.mitre.org/techniques/T1036/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--3c0f01e7f38e82580e943d707c1d5ef2",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Match Legitimate Name or Location",
      "description": "Adversaries match or approximate the name or location of legitimate system files.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1036.005",
          "url": "https://attack.mitre.org/techniques/T1036/005/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--be115381d9c6bad28e26a344e3ba0765",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Data Encoding",
      "description": "Adversaries encode data with standard algorithms to make communications and metadata more difficult to inspect.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1132",
          "url": "https://attack.mitre.org/techniques/T1132/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--7923299800fce72de40fd32686460cce",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Windows Management Instrumentation",
      "description": "Adversaries abuse WMI to execute malicious commands and query administrative system details.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1047",
          "url": "https://attack.mitre.org/techniques/T1047/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--820abb4a0ea7d65adea7d83109abadd9",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Remote System Discovery",
      "description": "Adversaries search for other systems on an internal network to identify lateral movement candidates.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1018",
          "url": "https://attack.mitre.org/techniques/T1018/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--df7fd730e7dd7d6086273d332df645ca",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "System Network Configuration Discovery",
      "description": "Adversaries search for network settings and IP configurations to understand internal network routing.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1016",
          "url": "https://attack.mitre.org/techniques/T1016/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--80564379e819273f41cc17ea54ba795a",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "System Owner/User Discovery",
      "description": "Adversaries identify the primary user or logged-on account on compromised hosts.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1033",
          "url": "https://attack.mitre.org/techniques/T1033/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--0ae6872ddf1504dc2191c18c7f097637",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Modify Registry",
      "description": "Adversaries modify the Windows registry to hide artifacts and disable security controls.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1112",
          "url": "https://attack.mitre.org/techniques/T1112/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--43308f2e7e6dedf65f0ec2e0e845061f",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Windows Service",
      "description": "Adversaries install or configure Windows services to maintain persistence and execute on system reboot.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1543.003",
          "url": "https://attack.mitre.org/techniques/T1543/003/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--01300bd14109fe08ca3c6d5660537789",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Bypass User Account Control",
      "description": "Adversaries bypass Windows UAC mechanisms to elevate process execution rights.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1548.002",
          "url": "https://attack.mitre.org/techniques/T1548/002/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--631959e1893cc76e519e13e91cd1c9f3",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Keylogging",
      "description": "Adversaries record keystrokes to harvest passwords and confidential communications.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1056.001",
          "url": "https://attack.mitre.org/techniques/T1056/001/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--f2887323eaf7021ef4dd42bb3cdddb3e",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Screen Capture",
      "description": "Adversaries take screenshots of victim desktop sessions to collect sensitive information.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1113",
          "url": "https://attack.mitre.org/techniques/T1113/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--9512c28017f8d85a3e1c07e47170316c",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "System Time Discovery",
      "description": "Adversaries check system time and timezone to synchronize distributed intrusion events.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1124",
          "url": "https://attack.mitre.org/techniques/T1124/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--f063b54d741b82a62ff9452480df6981",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Automated Exfiltration",
      "description": "Adversaries use automated scripts to periodically transmit collected data out of the network.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1020",
          "url": "https://attack.mitre.org/techniques/T1020/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--43321b0d8fe459a848f2c58808db05aa",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Steganography",
      "description": "Adversaries hide command payloads or stolen data within image or media files.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1001.002",
          "url": "https://attack.mitre.org/techniques/T1001/002/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--ef534a0a54933bcc64335cbe32413998",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Web Service: Dead Drop Resolver",
      "description": "Adversaries post command and control addresses on external forums or paste sites.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1102",
          "url": "https://attack.mitre.org/techniques/T1102/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--a93ceab79d6768c3ce0df24cfe7550cc",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Non-Standard Port",
      "description": "Adversaries communicate using non-standard ports to bypass simple firewall rules.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1571",
          "url": "https://attack.mitre.org/techniques/T1571/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--39e391bb6b527e0d07956fc21984b44c",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Encrypted Channel",
      "description": "Adversaries encrypt C2 traffic using symmetric or asymmetric encryption to evade inspection.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1573",
          "url": "https://attack.mitre.org/techniques/T1573/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--4912463066e5ddd78c948d75b97d46d5",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "DNS Tunneling",
      "description": "Adversaries encode commands and data within DNS query and response packets.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1071.004",
          "url": "https://attack.mitre.org/techniques/T1071/004/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--2ad9a5c6a6e91c694c0368a6db888a01",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Network Denial of Service",
      "description": "Adversaries flood network connections to exhaust bandwidth and disable internet access.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1498",
          "url": "https://attack.mitre.org/techniques/T1498/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--5adeca706d20818a72307c661fdbe8f7",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Endpoint Denial of Service",
      "description": "Adversaries crash host services or exhaust local CPU and memory resources.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1499",
          "url": "https://attack.mitre.org/techniques/T1499/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--61e3d0963aa8f810726c6726ae37e9ff",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Exploitation for Privilege Escalation",
      "description": "Adversaries exploit software vulnerabilities in operating systems to execute code with elevated system permissions.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1068",
          "url": "https://attack.mitre.org/techniques/T1068/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--bfae3224a069f0c9d3c4cf10f3bf84ac",
      "created": "2026-09-24T00:00:00.000Z",
      "modified": "2026-09-24T00:00:00.000Z",
      "name": "Windows Management Instrumentation Event Subscription",
      "description": "Adversaries create WMI event filters and consumers to trigger persistent payload execution upon system events.",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1546.003",
          "url": "https://attack.mitre.org/techniques/T1546/003/"
        }
      ],
      "created_by_ref": "identity--cyberattack-case-library"
    }
  ]
}