Skip to main content
Mallory
MalwareRansomwareUsed by 18 actorsExploits 23 CVEs

Metasploit

Metasploit is an open-source exploitation and penetration-testing framework created by HD Moore in 2003 and widely used by both defenders and attackers. The provided content consistently describes it as a dual-use offensive framework rather than a single bespoke malware family, but it is repeatedly observed in real intrusions as an exploitation, payload delivery, command-and-control, persistence, and post-exploitation platform. Associated payloads and components mentioned in the content include Meterpreter, reverse HTTP/reverse HTTPS shells, msfvenom-generated payloads, Windows stagers, and Metasploit modules for public-facing application exploitation.

Across the cited reporting, Metasploit was used or observed in multiple intrusion contexts. In one set of Asia-focused government intrusions involving DLL sideloading, shellcode consistent with a Metasploit or Cobalt Strike reverse HTTP shell connected to 91.245.253[.]52:6060/rKVI. Splunk documented Metasploit exploitation of Atlassian Confluence on Windows via malicious Java plugin execution that typically leads to Meterpreter download and full control of the Confluence server. A DFIR case involving Apache ActiveMQ CVE-2023-46604 described a Metasploit stager downloaded via CertUtil, C2 to 166.62.100[.]52, subsequent LSASS dumping, and later remote service creation to run Metasploit payloads across domain controllers and servers before LockBit deployment. A joint CISA/FBI/CNMF advisory on an aeronautical-sector compromise reported a Metasploit Meterpreter variant named bitmap.exe communicating with 179.60.147[.]4, and also noted Metasploit installed as a Windows service on a domain controller. Breakglass Intelligence reported a Metasploit payload ab.exe (MD5 cafc9d45da602fdf794421fc90375024) communicating with 45.76.180[.]12, with the same server assessed to host a concealed Meterpreter reverse_https listener on port 443 behind Apache.

The content also ties Metasploit to exploitation of known vulnerabilities through public modules, including BlueKeep (CVE-2019-0708), where a public Metasploit exploit raised concern because the flaw was wormable across older Windows systems, and newer modules for vulnerabilities such as Ollama CVE-2024-37032, BeyondTrust CVE-2026-1731, Grandstream GXP1600 CVE-2026-2329, and several CVEs discussed in EPSS/KEV analysis, including Citrix NetScaler and Atlassian Confluence issues. Infection vectors and delivery mechanisms mentioned in the content include exploitation of public-facing applications, phishing documents with macros, malicious Java plugin execution, SSH tunneling to run Metasploit, and staged payload download via LOLBINs such as CertUtil.

Threat actors and malware operations associated with Metasploit in the content include Flax Typhoon, which uses Metasploit alongside China Chopper, Juicy Potato, Mimikatz, and SoftEther VPN in espionage operations against Taiwanese government, education, critical manufacturing, and IT organizations; LockBit 3.0 affiliates, which use Metasploit for reconnaissance, remote access, credential dumping, privilege escalation, and exfiltration; and Sandworm-related victim environments where preexisting Metasploit and other RAT/C2 activity was observed before Sandworm activity. The content also notes broader criminal and intrusion-set use, including macro-laden phishing campaigns, ransomware preparation, and use in simulated attacks.

Capabilities directly supported by the content include exploit delivery, reverse shell and Meterpreter session establishment, command-and-control over HTTP/HTTPS, post-exploitation on Windows, persistence via newly added modules such as Windows Registry Active Setup and WSL startup-folder persistence, evasion via Linux RC4 Packer for ARM64, and credential theft or follow-on tooling integration. The content further notes that Metasploit’s Windows stagers use PEB walking with ROR13 hashing for API resolution.

High-confidence indicators explicitly mentioned in the content include 91.245.253[.]52:6060/rKVI, 166.62.100[.]52, 179.60.147[.]4, 45.76.180[.]12, cdn.kkxx888666[.]com, payload names ab.exe and bitmap.exe, and MD5 cafc9d45da602fdf794421fc90375024 for ab.exe.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

EXPLOITED CVES

Vulnerabilities exploited

23 CVEs Mallory has correlated with this family across public research and vendor advisories. Each row links to the full Mallory page for that vulnerability.

23 CVES
CVE-2025-7775Unauthenticated RCE in Citrix NetScaler ADC and GatewayExploited in the wild

Check Point researchers said the tool is being discussed on underground forums, where hackers are exchanging instructions on how to deploy it against three Citrix NetScaler flaws disclosed last week: CVE-2025-7775, CVE-2025-7776 and CVE-2025-8424. The most critical of these, CVE-2025-7775, allows unauthenticated remote code execution.

via bank info securitybankinfosecurity.com
CVE-2026-20182Authentication Bypass in Cisco Catalyst SD-WAN Controller and Manager

Rapid7 Labs discovered a new authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Controller (formerly known as vSmart), CVE-2026-20182. This new authentication bypass vulnerability affects the “vdaemon” service over DTLS (UDP port 12346)... a remote unauthenticated attacker can leverage CVE-2026-20182 to become an authenticated peer of the target appliance, and perform privileged operations, such as injecting an attacker controlled public key into the vmanage-admin user account’s authorized SSH keys file.

via rapid7 blograpid7.com
CVE-2019-0708BlueKeep

On Friday, that dreaded day arrived when the Metasploit framework—an open source tool used by white hat and black hat hackers alike—released just such an exploit into the wild.

via arstechnicaarstechnica.com
CVE-2026-31431Copy Fail local privilege escalation in Linux kernel algif_aead/AF_ALG

На момент публикации CVE-2026-31431 не зарегистрирован в NVD... Copy Fail - local privilege escalation... Metasploit-модуль опубликован в день раскрытия... PoC для Kubernetes с escape на уровень ноды опубликован на GitHub... CISA добавляет в KEV.

via codebycodeby.net
CVE-2024-27198Authentication Bypass in JetBrains TeamCity On-Premises

This activity can be associated with a malicious plugin installed by metasploit for remote code execution... References ... CVE-2024-27198/modules/exploits/multi/http/jetbrains_teamcity_rce_cve_2024_27198.rb ... critical JetBrains TeamCity on-premises ... CVE-2024-27198 and CVE-2024-27199 JetBrains TeamCity multiple authentication bypass vulnerabilities fixed.

via splunk researchresearch.splunk.com
CVE-2025-15556Notepad++ WinGUp updater download of code without integrity check

The campaign rotated C2 servers across three attack chains to deliver a Metasploit loader, Cobalt Strike Beacon, and a custom backdoor called Chrysalis.

via recorded future blogrecordedfuture.com
CVE-2021-44228Log4Shell

Additional ClamAV signatures include "PUA.Unix.File.Metasploit" entries related to ongoing exploitation campaigns.

via talos intelligence blogblog.talosintelligence.com
CVE-2022-47966Unauthenticated RCE in Zoho ManageEngine SAML SSOExploited in the wild

Analysts confirmed that nation-state advanced persistent threat (APT) actors exploited CVE-2022-47966 to gain unauthorized access to a public-facing application (Zoho ManageEngine ServiceDesk Plus), establish persistence, and move laterally through the network. This vulnerability allows for remote code execution on the ManageEngine application.

via cisa advisoriescisa.gov
CVE-2023-34362SQL Injection in Progress MOVEit Transfer

The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.

via arxivarxiv.org
CVE-2023-22515Broken Access Control in Atlassian Confluence Data Center and Server

The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.

via arxivarxiv.org
CVE-2023-4966CitrixBleed

The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.

via arxivarxiv.org
CVE-2017-0144EternalBlue SMBv1 Remote Code Execution in Microsoft Windows

"The latest Metasploit update, released on February 27, 2026, brings significant firepower... The release introduces seven new modules..."

via cyber security newscybersecuritynews.com
CVE-2023-22518Improper Authorization in Atlassian Confluence Data Center and Server

The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.

via arxivarxiv.org
CVE-2023-7028GitLab password reset account takeover via unverified email address

The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.

via arxivarxiv.org
CVE-2023-42793JetBrains TeamCity Authentication Bypass RCE

The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.

via arxivarxiv.org
CVE-2024-4577PHP-CGI Argument Injection RCE on Windows

The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.

via arxivarxiv.org
CVE-2024-21762Fortinet FortiOS/FortiProxy SSL VPN Out-of-Bounds Write RCE

The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.

via arxivarxiv.org
CVE-2023-3519Unauthenticated RCE in Citrix NetScaler ADC and NetScaler Gateway

The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.

via arxivarxiv.org
CVE-2023-29357Microsoft SharePoint Server JWT Spoofing Privilege Escalation

The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.

via arxivarxiv.org
CVE-2024-4040CrushFTP Server-Side Template Injection RCE

The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.

via arxivarxiv.org
CVE-2023-48788SQL Injection RCE in Fortinet FortiClient EMS

The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.

via arxivarxiv.org
CVE-2023-22527Unauthenticated RCE in Atlassian Confluence Data Center and Server

The content repeatedly references public exploit availability and notes that “A Metasploit module was made available…” for multiple CVEs; it also states EPSS uses “MetaSploit” as a data source and that removal/republishing of a Metasploit module materially changed EPSS scores.

via arxivarxiv.org
CVE-2023-46604Apache ActiveMQ OpenWire Remote Code ExecutionExploited in the wild

A threat actor exploited CVE-2023-46604 on an internet-facing Apache ActiveMQ server... The threat actor was able to perform remote code execution (RCE) by using a Java Spring class and a custom Java Spring bean configuration XML file.

via dfir reportthedfirreport.com
THREAT ACTORS

Groups observed using it

18 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
Cobalt Group

Tools: SpicyOmelette, Cobalt Strike, Meterpreter, Mimikatz, CobtInt, ATMSpitter, Carbanak, Buhtrap, Cyst, Metasploit.

via secureworks threat profilessecureworks.com
Sandworm

Four more victims had ongoing command and control activity using commercial frameworks such as Cobalt Strike, Metasploit and other Remote Access Trojans (RATs).

via nozomi networks blognozominetworks.com
APT28

The phishing emails contained a link to the domain docs.google.com.spreadsheets.d.1ip6eeakdebmwteh36vana4hu-glaeksstsht-boujdk.zhblz[.]com where John Hammond’s reCAPTCHA Phish POC was used to deliver Metasploit payloads with the C2 IP address 203.161.50[.]145

via ctrlaltintel blogctrlaltintel.com
APT29

The phishing emails contained a link to the domain docs.google.com.spreadsheets.d.1ip6eeakdebmwteh36vana4hu-glaeksstsht-boujdk.zhblz[.]com where John Hammond’s reCAPTCHA Phish POC was used to deliver Metasploit payloads with the C2 IP address 203.161.50[.]145

via ctrlaltintel blogctrlaltintel.com
Lotus Blossom

The campaign rotated C2 servers across three attack chains to deliver a Metasploit loader, Cobalt Strike Beacon, and a custom backdoor called Chrysalis.

via recorded future blogrecordedfuture.com
Salt Typhoon

"...we found a running Metasploit with cdn.kkxx888666[.]com as its C&C server."

via eset welivesecurity blogwelivesecurity.com
MuddyWater

The group uses macro-laden phishing documents, publicly available tools such as Metasploit and LaZagne and custom tools including PowerStats and Forelord.

via secureworks threat profilessecureworks.com
UNK_GreenSec

TransferLoader malware, which later launches the Morpheus and Metasploit ransomware strains.

via scworldscworld.com
TA422

...provided a PowerShell command to create an SSH tunnel and run Metasploit.

via hackreadhackread.com
SideWinder

"Another two applications were built from JavaPayload for Metasploit that will load extra code from the remote server configured in the sample."

via trend micro researchtrendmicro.com
FIN6

FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database.

via mitre attackattack.mitre.org
FIN7

"...using various tools, such as Metasploit, Cobalt Strike, Carbanak malware..."

via bleeping computerbleepingcomputer.com
TEMP.Veles

...testing customized versions of multiple open-source frameworks, including Metasploit, Cobalt Strike, PowerSploit...

via web archiveweb.archive.org
Flax Typhoon

The group uses the China Chopper web shell, Metasploit, Juicy Potato privilege escalation tool, Mimikatz, and SoftEther VPN client.

via splunk researchresearch.splunk.com
UNG0002

...post-exploitation tools such as Cobalt Strike and Metasploit...

via cloudatg insightscloudatg.com
ShadowSyndicate

ShadowSyndicate continues to be associated with toolkits including Cobalt Strike, Metasploit, Havoc, Mythic, Sliver, AsyncRAT, MeshAgent, and Brute Ratel.

via the hacker newsthehackernews.com
RomCom

"Observed payloads have included BEACON, METASPLOIT stager, or BUGHATCH."

via mandiant threat intelligencecloud.google.com
Volt Typhoon

...the following tools could be used by an actor to obtain the same information: ... Metasploit

via cisa advisoriescisa.gov
MITRE ATT&CK

Techniques & procedures

27 distinct techniques documented for this family, organized by ATT&CK tactic.

T1588.002ToolEvidence1

The content repeatedly states that threat actors 'obtained,' 'acquired,' or 'used' publicly available, open-source, legitimate, or modified tools such as Mimikatz, Cobalt Strike, PsExec, Empire, Impacket, and many others.

Initial Access

2 techniques
T1078Valid AccountsEvidence3

exploit the box somehow (ssh_login for instance)

T1190Exploit Public-Facing ApplicationEvidence1

a remote unauthenticated attacker can bypass authentication by connecting to the vSmart DTLS port with any self-signed client certificate and claiming to be a vHub (type 2) in the CHALLENGE_ACK message. No valid credentials, no CA-signed certificate, and no knowledge of the SD-WAN deployment are required.

Execution

8 techniques
T1053Scheduled Task/JobEvidence1

Windows operating systems provide a utility (schtasks.exe) which enables system administrators to execute a program or a script at a specific given date and time. This kind of behavior has been heavily abused by threat actors and red teams as a persistence mechanism.

T1053.005Scheduled TaskEvidence1

References https://attack.mitre.org/techniques/T1053/ ... The persistence technique of scheduled tasks can be implemented both manually and automatically.

T1059Command and Scripting InterpreterEvidence7
TacticExecution

For instance, a Metasploit module can force the device to run remote scripts.

T1059.001PowerShellEvidence1
TacticExecution

From the command prompt the “ schtasks ” executable can be used to create a schedule task that will download and execute a PowerShell based payload in every Windows logon as a SYSTEM.

T1059.004Unix ShellEvidence2
TacticExecution

As we can see above, the attacker achieves unauthenticated RCE with root privileges on the device. This is demonstrated by the attacker executing a reverse shell payload and running several arbitrary OS shell commands.

T1203Exploitation for Client ExecutionEvidence7
TacticExecution

According to the report, “This helper function ParseICECandidate contains a stack based buffer overflow.” ... an unauthenticated attacker can trigger a classic stack crash by sending an overly long request.

T1574Hijack Execution FlowEvidence1

This malicious DLL needs to be dropped in one of the folders that windows are loading DLL files. As it can be see below when the service restarted a Meterpreter session opened with SYSTEM privileges through DLL hijacking.

T1574.001DLLEvidence1

If these DLL’s doesn’t exist or are implemented in an insecure way (DLL’s are called without using a fully qualified path) then it is possible to escalate privileges by forcing the application to load and execute a malicious DLL file.

Persistence

6 techniques
T1053Scheduled Task/JobEvidence1

Windows operating systems provide a utility (schtasks.exe) which enables system administrators to execute a program or a script at a specific given date and time. This kind of behavior has been heavily abused by threat actors and red teams as a persistence mechanism.

T1053.005Scheduled TaskEvidence1

References https://attack.mitre.org/techniques/T1053/ ... The persistence technique of scheduled tasks can be implemented both manually and automatically.

T1078Valid AccountsEvidence3

exploit the box somehow (ssh_login for instance)

T1098.004SSH Authorized KeysEvidence1

We identified a particularly impactful post-authentication primitive: persistent SSH key injection via MSG_VMANAGE_TO_PEER (Message type 14).

T1505.003Web ShellEvidence1

use exploit/multi/persistence/obsidian_plugin

T1543.002Systemd ServiceEvidence1

Pulls out systemd from the init persistence module and adds new persistence mixin.

T1053Scheduled Task/JobEvidence1

Windows operating systems provide a utility (schtasks.exe) which enables system administrators to execute a program or a script at a specific given date and time. This kind of behavior has been heavily abused by threat actors and red teams as a persistence mechanism.

T1053.005Scheduled TaskEvidence1

References https://attack.mitre.org/techniques/T1053/ ... The persistence technique of scheduled tasks can be implemented both manually and automatically.

T1068Exploitation for Privilege EscalationEvidence6

Conversation Add Windows Defender BlueHammer LPE exploit ( CVE-2026-33825 )

T1078Valid AccountsEvidence3

exploit the box somehow (ssh_login for instance)

T1098.004SSH Authorized KeysEvidence1

We identified a particularly impactful post-authentication primitive: persistent SSH key injection via MSG_VMANAGE_TO_PEER (Message type 14).

T1543.002Systemd ServiceEvidence1

Pulls out systemd from the init persistence module and adds new persistence mixin.

T1548Abuse Elevation Control MechanismEvidence1

In Windows environments when an application or a service is starting it looks for a number of DLL’s in order to function properly... then it is possible to escalate privileges by forcing the application to load and execute a malicious DLL file.

Stealth

4 techniques
T1027.007Dynamic API ResolutionEvidence1
TacticStealth

Once you have the base address of kernel32.dll, you walk its export table and find WinExec using a ROR13 hash comparison | The challenge on Windows is that you can’t call WinExec directly in position-independent shellcode. You don't know where kernel32.dll is loaded at runtime (ASLR). Instead, you find it dynamically by walking the Process Environment Block | The Windows synthesiser uses a technique called PEB walking with ROR13 hashing — the same approach used by Metasploit’s Windows stagers.

T1078Valid AccountsEvidence3

exploit the box somehow (ssh_login for instance)

T1574Hijack Execution FlowEvidence1

This malicious DLL needs to be dropped in one of the folders that windows are loading DLL files. As it can be see below when the service restarted a Meterpreter session opened with SYSTEM privileges through DLL hijacking.

T1574.001DLLEvidence1

If these DLL’s doesn’t exist or are implemented in an insecure way (DLL’s are called without using a fully qualified path) then it is possible to escalate privileges by forcing the application to load and execute a malicious DLL file.

Credential Access

5 techniques
T1110Brute ForceEvidence1

ssh_login: Convert to run_scanner ... ssh_login: Use SSH mixin ... ssh_login: Add store_ssh_key_loot() ... ssh_login: Support BLANK_PASSWORDS, USER_AS_PASS & ANONYMOUS_LOGIN

T1110.001Password GuessingEvidence1

ssh_login: Support BLANK_PASSWORDS, USER_AS_PASS & ANONYMOUS_LOGIN

T1555Credentials from Password StoresEvidence1

ssh_creds: Add PARSE_KNOWN_HOSTS - report_host() ... ssh_creds: Add CRACK_KNOWN_HOSTS - report_host ... ssh_creds: Add report_note(ssh.privatekey)

T1557Adversary-in-the-MiddleEvidence1

The majority of the applications used Transport Layer Security (TLS). However, none of the apps verified the certificate used by the server, which meant that Man-in-the-Middle attacks were still possible using an intercepting proxy tool.

T1649Steal or Forge Authentication CertificatesEvidence2

ssh_creds: Add ATT&CK ref

Lateral Movement

2 techniques
T1021Remote ServicesEvidence1

GOLD KINGSWOOD is a cybercriminal group that uses tactics more commonly associated with government-sponsored threat actors to infiltrate the internal networks of financial institutions around the globe.

T1210Exploitation of Remote ServicesEvidence1

For instance, a Metasploit module can force the device to run remote scripts. The attacker crafts a special SIP INVITE message stuffed with padding characters.

Collection

2 techniques
T1557Adversary-in-the-MiddleEvidence1

The majority of the applications used Transport Layer Security (TLS). However, none of the apps verified the certificate used by the server, which meant that Man-in-the-Middle attacks were still possible using an intercepting proxy tool.

T1602.001SNMP (MIB Dump)Evidence1

At this point the attacker can begin to execute arbitrary NETCONF commands, for example the following “get-config” command can be run by the attacker in the NETCONF session.

T1071Application Layer ProtocolEvidence2

Add support for HTTP/S PHP and TLV config | Add support for HTTP/S PHP and TLV config ... Fix custom_headers emission, add C2 UUID for placement ... Wire MC2 into PHP payloads ... Wire MC2 into mettle

T1105Ingress Tool TransferEvidence2

This script then executes within the context of the Android application and can potentially instruct the device to download a malicious payload from the attacker’s server, providing access to the user’s phone with the privileges of the application.

INDICATORS OF COMPROMISE

IOCs tracked for this family

10 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.

View more in app
Network
5 tracked

IPs, domains, and DNS infrastructure linked to this family.

Hashes
5 tracked

File hashes (MD5, SHA-1, SHA-256) from samples and reports.

TypeValueLatest sighting
hash.md5●●●●●●●●●●●●View more in app1 year ago
hash.md5●●●●●●●●●●●●View more in app1 year ago
ip.v4●●●●●●●●●●●●View more in app3 years ago
ip.v4●●●●●●●●●●●●View more in app3 years ago
ip.v4●●●●●●●●●●●●View more in app4 years ago
ip.v4●●●●●●●●●●●●View more in app4 years ago
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching10

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution18

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities23

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping27

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.