{
  "name": "Spetsvuzavtomatika leak — documented capabilities (Enterprise)",
  "versions": {
    "attack": "19",
    "navigator": "5.3.2",
    "layer": "4.5"
  },
  "domain": "enterprise-attack",
  "description": "Techniques described in the leaked Spetsvuzavtomatika project documents, as analysed by DomainTools Investigations (30 Sep 2026) and mapped by FireIntel Threat Research. A map of documented intent, not of observed intrusions. Source post: https://fireintel.net/blog/spetsvuzavtomatika-leak-svr-cyber-development",
  "sorting": 0,
  "hideDisabled": false,
  "techniques": [
    {
      "techniqueID": "T1596.005",
      "color": "#7c86f0",
      "comment": "Felix-23 / HAD: Target records enriched from Shodan and similar scan databases.",
      "enabled": true
    },
    {
      "techniqueID": "T1595.002",
      "color": "#7c86f0",
      "comment": "Felix-23 / HAD: Vulnerability confirmation; scanning through OWASP Nettacker.",
      "enabled": true
    },
    {
      "techniqueID": "T1110",
      "color": "#7c86f0",
      "comment": "Felix-23 / HAD: Credential testing and brute-force attacks against discovered services.",
      "enabled": true
    },
    {
      "techniqueID": "T1190",
      "color": "#7c86f0",
      "comment": "Felix-23 / HAD: Remote-code-execution checks and SQL-injection tests.",
      "enabled": true
    },
    {
      "techniqueID": "T1583.003",
      "color": "#7c86f0",
      "comment": "Felix-23 / HAD: Distributed VPS nodes managed as resources, with tunnelling state and forwarded ports.",
      "enabled": true
    },
    {
      "techniqueID": "T1090.003",
      "color": "#7c86f0",
      "comment": "Felix-23 / HAD: Activity routed through Tor, proxy chains and rotating addresses.",
      "enabled": true
    },
    {
      "techniqueID": "T1498",
      "color": "#7c86f0",
      "comment": "Felix-23 / HAD: DDoS impact measurement; high-volume traffic through BoNeSi.",
      "enabled": true
    },
    {
      "techniqueID": "T1572",
      "color": "#7c86f0",
      "comment": "Putnik: Ethernet bridged over TAP-mode OpenVPN or SoftEther for remote Layer 2 access.",
      "enabled": true
    },
    {
      "techniqueID": "T1557.002",
      "color": "#7c86f0",
      "comment": "Putnik: ARP spoofing scenarios.",
      "enabled": true
    },
    {
      "techniqueID": "T1557.003",
      "color": "#7c86f0",
      "comment": "Putnik: DHCP spoofing scenarios.",
      "enabled": true
    },
    {
      "techniqueID": "T1557.001",
      "color": "#7c86f0",
      "comment": "Putnik: LLMNR, NBT-NS and mDNS poisoning; NTLM capture with Responder.",
      "enabled": true
    },
    {
      "techniqueID": "T1187",
      "color": "#7c86f0",
      "comment": "Putnik: Authentication coercion and printer interception.",
      "enabled": true
    },
    {
      "techniqueID": "T1068",
      "color": "#7c86f0",
      "comment": "Putnik: Zerologon, CVE-2020-1472, against the domain controller.",
      "enabled": true
    },
    {
      "techniqueID": "T1003.003",
      "color": "#7c86f0",
      "comment": "Putnik: NTDS extraction and Kerberos-key recovery.",
      "enabled": true
    },
    {
      "techniqueID": "T1550.002",
      "color": "#7c86f0",
      "comment": "Putnik: Command execution with recovered hashes.",
      "enabled": true
    },
    {
      "techniqueID": "T1136.002",
      "color": "#7c86f0",
      "comment": "Putnik: A domain account created and raised to Domain Admin.",
      "enabled": true
    },
    {
      "techniqueID": "T1102",
      "color": "#7c86f0",
      "comment": "Initiative-24: Implants controlled through trusted public cloud services.",
      "enabled": true
    },
    {
      "techniqueID": "T1567.002",
      "color": "#7c86f0",
      "comment": "Initiative-24: Collected data staged and moved through cloud storage.",
      "enabled": true
    },
    {
      "techniqueID": "T1564",
      "color": "#7c86f0",
      "comment": "Initiative-24: Hidden Exchange folders holding instructions or data out of normal view.",
      "enabled": true
    },
    {
      "techniqueID": "T1583",
      "color": "#7c86f0",
      "comment": "Chain-24: Anonymous purchase of VPS and VDS hosting.",
      "enabled": true
    },
    {
      "techniqueID": "T1585.002",
      "color": "#7c86f0",
      "comment": "Chain-24: Email accounts provisioned through anonymous payment.",
      "enabled": true
    }
  ],
  "gradient": {
    "colors": [
      "#ffffff",
      "#7c86f0"
    ],
    "minValue": 0,
    "maxValue": 1
  },
  "legendItems": [
    {
      "label": "Documented in the leaked project files",
      "color": "#7c86f0"
    }
  ],
  "showTacticRowBackground": false,
  "selectTechniquesAcrossTactics": true,
  "selectSubtechniquesWithParent": false
}