| APT29 (Cozy Bear / Midnight Blizzard) | emulation/apt29/SKILL.md | tier-3 | Cloud-identity espionage, OAuth abuse, supply chain | recon, cloud, web (oauth/saml), post-exploit |
| Sandworm (APT44 / Seashell Blizzard) | emulation/sandworm/SKILL.md | tier-3 | ICS/OT disruption, destructive ops, LOTL | recon, exploit/cve, ics-ot, post-exploit |
| Scattered Spider (UNC3944 / Octo Tempest) | emulation/scattered-spider/SKILL.md | tier-2 | Help-desk social engineering → cloud/SaaS → ransomware | phish, cloud, ad, post-exploit |
| Volt Typhoon (Vanguard Panda) | emulation/volt-typhoon/SKILL.md | tier-3 | Edge-device access, LOTL, long-dwell pre-positioning | recon, exploit/cve, ad, post-exploit |
| Lazarus (Hidden Cobra) | emulation/lazarus/SKILL.md | tier-3 | Financial/crypto/DeFi theft, supply-chain, social | osint, phish, contracts, web, post-exploit |
| FIN7 (Carbon Spider / Sangria Tempest) | emulation/fin7/SKILL.md | tier-2 | Spearphishing → big-game-hunting ransomware | phish, ad, post-exploit, exploit |
| LockBit / RaaS affiliate | emulation/lockbit/SKILL.md | tier-2 | Generic ransomware affiliate kill chain | recon, exploit/cve, ad, post-exploit |