| metadata | {"subdomain":"adversary-emulation","when_to_use":"Pink Sandstorm, Agrius, Agonizing Serpens, AMERICIUM, BlackShadow, DEV-0227, Marshtreader, G1030, Iranian MOIS destructive operations, Apostle wiper, Fantasy wiper, DEADWOOD wiper, MultiLayer wiper, BFG Agonizer, Moneybird ransomware, IPsec Helper backdoor, ASPXSpy web shell, Israel wiper operations, diamond industry targeting, destructive attacks masquerading as ransomware, hack-and-leak operations","tags":"pink-sandstorm, agrius, agonizing-serpens, americium, blackshadow, dev-0227, iran, mois, destructive, wiper, ransomware, nation-state, g1030, adversary-emulation, mitre-attack","mitre_attack":"T1583, T1560.001, T1119, T1110, T1110.003, T1059.001, T1059.003, T1059.005, T1543.003, T1005, T1074.001, T1140, T1685, T1685.005, T1041, T1190, T1570, T1036, T1036.004, T1046, T1003.001, T1003.002, T1021.001, T1018, T1505.003, T1078.002, T1027, T1027.009, T1027.013, T1569.002, T1112, T1497.003, T1070, T1070.004, T1070.006, T1070.009, T1071.001, T1057, T1053.005, T1529, T1485, T1486, T1561.001, T1561.002, T1480, T1490, T1531, T1554, T1565.001, T1083, T1124"} |