Scattered Spider — UNC3944 / Octo Tempest

Financially-motivated intrusion set that weaponizes the help desk. Initial access comes from vishing, SIM-swaps, MFA push-bombing and AiTM phishing rather than malware — so the highest-value hunt angles are identity abuse, legitimate remote-access tooling, and BYOVD EDR tampering, not signatures. Culminates in cloud/SaaS data theft and DragonForce ransomware (frequently ESXi-targeting).
Actor
Scattered Spider
MITRE Group
G1015
Aliases
UNC3944 · Octo Tempest · 0ktapus · Muddled Libra · LUCR-3
Type
eCrime · Identity / Extortion
Severity
High
Primary Surface
Identity / SSO / Cloud
Author
HuntPack
Confidence
High (multi-source)
01

Executive Summary

Scattered Spider is a native-English-speaking, financially-motivated collective (overlapping with the broader "Com" ecosystem) that specializes in social-engineering the human perimeter. The signature play: call the IT help desk impersonating an employee (or, per the July 2025 FBI/CISA update, impersonate an employee to a third-party/outsourced IT provider), talk an agent into resetting a password and/or MFA, enroll an attacker-controlled authenticator, and log in as a legitimate user. From there they move fast — hours, not weeks — into SSO, VDI, cloud, and SaaS.

Because initial access rarely involves a dropped binary, endpoint AV signatures miss the front of the kill chain. The defensible signal is behavioral: abuse of legitimate remote-access tools (AnyDesk, TeamViewer, Splashtop, ScreenConnect, Tailscale, Ngrok, Teleport), LSASS credential theft with Sysinternals/Mimikatz, AD reconnaissance (ADExplorer, SharpHound), identity-provider anomalies (MFA resets, new device enrollment, added federated IdPs, backdoor IAM users), and — late in the chain — BYOVD EDR-killers (STONESTOP/POORTRY) and shadow-copy destruction preceding DragonForce ransomware and ESXi encryption.

Defender priority: Instrument the identity plane first. Alert on help-desk-driven MFA/credential resets and new authenticator enrollment, then chain endpoint hunts (RMM tooling → credential access → BYOVD → shadow-copy deletion) to catch the hands-on-keyboard phase before extortion. Treat any first-time appearance of a remote-access tool on a server or admin workstation as hunt-worthy.

02

Source Review & Web Hunter Notes

TierSourceKey FindingCarry Fwd
1CISA/FBI AA23-320A (updated 2025-07-29)Vishing help-desk impersonation, SIM-swap, push-bombing; now impersonating employees to third-party IT; Snowflake/Teams/Slack/Exchange targeting; DragonForce + ESXi encryptionyes
1MITRE ATT&CK G1015Canonical technique set across all 14 tactics; alias consolidationyes
2CrowdStrike Services blogEscalation across industries; help-desk vishing in nearly all 2025 incidents targeting Entra ID / SSO / VDIyes
2Permiso — LUCR-3 "SaaS-y in the Cloud"Backdoor IAM user creation (CreateUser/CreateAccessKey), added federated IdP + auto account-linking to SSO tenantsyes
2Trellix / Rapid7 modus-operandiSTONESTOP + POORTRY BYOVD EDR-killer; LSASS dumping via ProcDump/Mimikatz; ADExplorer reconyes
2Darktrace / ReliaQuest / ObsidianNgrok/Teleport anomalous C2; AiTM token theft; IR-channel eavesdropping on Teams/Slackpartial
3BleepingComputer / Cyber Dive (news)2025 sector rotation: UK retail → insurance → aviation/transportpartial

Decisions

DecisionRationalePack Change
Purple / identity themePrimary attack surface is identity & SSO, not endpoint malwareTheme + section ordering leads with identity
Cloud/IdP steps go to Native Audit Hunts (§7)Front of kill chain lives in Okta/Entra/CloudTrail logs, not endpoint EDR§7 expanded; CQL variants flagged "requires log ingestion"
No campaign-specific hashes hard-codedScattered Spider infra is highly perishable; tool binaries are legitimate/renamedIOCs are pattern- & behavior-based; validate against current advisory
03

Hunt Brief & Attack Chain

Working hypothesis: If Scattered Spider is operating in the environment, we will observe a help-desk-driven identity reset closely followed by (a) a legitimate remote-access tool appearing for the first time on an admin/server host, (b) LSASS/AD credential access, and (c) — before impact — BYOVD driver loads and shadow-copy deletion. Detecting any two of these in temporal proximity is high-confidence for an active intrusion.

Attack chain

#StepTelemetryHunt Angle
1Recon / resource dev — register victim-sso.com/-okta/-helpdesk lures; SIM-swap prepDNS, proxy, external TINewly-registered lookalike domains; smishing lures
2Initial access — vishing help desk → password/MFA reset; push-bombing; AiTM phishIdP audit (Okta/Entra), help-desk ticketingMFA reset + new device enroll from anomalous geo
3Persistence — enroll attacker MFA; add federated IdP; backdoor IAM user; inbox rulesEntra/Okta admin logs, CloudTrail, O365 auditNew IdP/domain federation; CreateUser/CreateAccessKey; New-InboxRule forward/delete
4Defense evasion — install legit RMM; BYOVD (STONESTOP/POORTRY) to kill EDR; LOTLProcessRollup2, driver load, service stopFirst-seen RMM on server; vulnerable-driver write + EDR service tamper
5Credential access — LSASS dump (ProcDump/comsvcs/Mimikatz); ADExplorer; DCSyncProcessRollup2, cross-proc accessLSASS minidump; AD replication from non-DC
6Discovery / lateral — cloud & AD enum; RDP/PsExec; Teleport/SSM pivotProcessRollup2, network, IdPSharpHound; burst RDP from new host; Teleport sessions
7Collection / exfil — SharePoint/Snowflake/cloud storage theft; IR-channel eavesdroppingCloud data-access logs, networkBulk download; anomalous Snowflake queries; joining IR calls
8Impact — shadow-copy delete → DragonForce ransomware; ESXi encryptionProcessRollup2, ESXi shell logsvssadmin/wbadmin delete; esxcli vm kill; mass file rename

Hypotheses (fidelity-ordered)

IDHypothesisMITREConf
H1Unauthorized remote-access tool executed/installed on server or admin hostT1219High
H2Reverse-tunnel / relay tooling (Ngrok, Teleport, Tailscale) used for covert C2T1572, T1090High
H3BYOVD vulnerable-driver write + EDR/AV service tamper (STONESTOP/POORTRY)T1562.001, T1068High
H4LSASS credential dumping via comsvcs/ProcDump/MimikatzT1003.001High
H5AD reconnaissance utilities (ADExplorer, SharpHound) executedT1087, T1069Med
H6Shadow-copy / backup destruction preceding encryptionT1490High
H7MFA push-bombing burst (rapid repeated auth attempts on one account)T1621Med
H8Identity persistence — new IdP federation, backdoor IAM user, mailbox forwarding ruleT1136, T1484.002, T1114.003Med
04

Consolidated IOC Table

Scattered Spider infrastructure and file hashes are highly perishable and the tooling is largely legitimate software. Prefer the behavioral IOCs below; validate any atomic indicator against the current CISA AA23-320A appendix before deploying as a block.

TypeValueConfActionContext
Domain pattern*-sso.com, *-okta.com, *-helpdesk.com, *-vpn.com, *-servicedesk.commediumhuntLookalike SSO/help-desk phishing lures (org-name prefixed)
Toolanydesk.exe, teamviewer.exe, screenconnect, splashtop, tailscalemediumhuntLegitimate RMM abused for persistence/C2; alert on first-seen
Toolngrok.exe, tsh.exe (Teleport), teleporthighhuntReverse tunnel / relay; rarely legitimate on servers
Toolprocdump, mimikatz, ADExplorer, SharpHoundhighhuntCredential access & AD recon
MalwareSTONESTOP (loader) + POORTRY (signed malicious driver)highhuntBYOVD EDR-killer toolkit; hunt on anomalous driver loads
Network*.ngrok.io, *.ngrok-free.app, *.teleport.shmediumhuntTunnel egress endpoints
BehaviorHelp-desk MFA reset + new authenticator enrollment < 1h aparthighdetectSignature initial-access pattern (IdP logs)
BehaviorNew federated IdP / domain added to SSO tenanthighdetectLUCR-3 cloud persistence
RansomwareDragonForce payload; ESXi mass-encryptionhighdetectTerminal impact stage
05

Affected Surface & Telemetry Matrix

SurfaceRequired TelemetryPriorityGap Risk
Identity provider (Okta / Entra ID)Admin & auth audit logs (MFA reset, device enroll, federation)CriticalHigh — needs IdP log ingestion into Falcon/NG-SIEM
Windows endpoints / serversProcessRollup2, driver load, service state, cross-process accessCriticalLow — native Falcon sensor
Domain controllersAD replication, account/group changes, Identity Protection eventsHighMedium — requires Falcon Identity Protection
Cloud IAM (AWS / Azure)CloudTrail, Azure activity/sign-in logsHighHigh — needs cloud log connector
M365 / Exchange OnlineUnified audit log (inbox rules, mailbox access)HighMedium — needs O365 connector
VMware ESXiESXi shell / vpxa logs, hostdHighHigh — ESXi hosts rarely carry EDR
SaaS data stores (Snowflake, SharePoint)Query & download audit logsMediumHigh — SaaS-specific logging
06

ATT&CK Mapping

TacticTechniqueObserved BehaviorQuery / Control
Resource DevT1583.001 DomainsRegister lookalike SSO/help-desk domains§7 native / TI
Initial AccessT1566 Phishing · T1660 (smishing)AiTM phish, smishing lures§7 IdP
Initial AccessT1078 Valid AccountsVishing help desk → valid creds§7 IdP / Q8
Credential AccessT1621 MFA Request GenerationPush-bombing / MFA fatigueQ8, §7
Credential AccessT1003.001 LSASS MemoryProcDump/comsvcs/Mimikatz dumpQ4
PersistenceT1136 Create Account · T1556.007Backdoor IAM user; MFA re-enroll§7 cloud
PersistenceT1484.002 Domain Trust ModificationAdd federated IdP to SSO tenant§7 cloud
PersistenceT1114.003 Email Forwarding RuleMalicious inbox rules§7 O365
Defense EvasionT1562.001 Disable/Modify ToolsBYOVD EDR-killer; stop AV servicesQ3, Q7
Privilege EscalationT1068 Exploit for Priv-EscVulnerable signed driver → SYSTEMQ3
Command & ControlT1219 Remote Access SoftwareAnyDesk/TeamViewer/Splashtop/ScreenConnectQ1
Command & ControlT1572 Protocol Tunneling · T1090Ngrok / Teleport / Tailscale tunnelsQ2
DiscoveryT1087 Account · T1069 GroupsADExplorer / SharpHound reconQ5
ImpactT1490 Inhibit System Recoveryvssadmin/wbadmin shadow-copy deleteQ6
ImpactT1486 Data Encrypted for ImpactDragonForce ransomware; ESXi encryptQ6 / §7
07

Native Audit-Log Hunts (non-CQL)

The front of Scattered Spider's kill chain lives in identity and cloud audit logs. Run these in the source platform (or in Falcon NG-SIEM if the connector is ingesting them). They are the highest-value detections in this pack.

HuntSourceLogicResponse
Help-desk MFA reset + re-enrollOkta / Entra ID auditMFA factor reset event followed by new factor/device enrollment for same user within <1h, esp. from new IP/geoFreeze account; verify with user out-of-band
New device / authenticator enrollmentEntra ID sign-in + auditNew authenticator registered from device/geo never seen for that userChallenge; revoke sessions
Federated IdP / domain addedEntra ID / Okta adminSet-DomainAuthentication / new federation trust or added external IdP with auto account-linkingTreat as critical; validate change ticket
Backdoor IAM userAWS CloudTrailCreateUser + CreateAccessKey / CreateLoginProfile by a recently-compromised principal; names mimic real usersDisable keys; review IAM policy attach
Malicious inbox ruleM365 Unified AuditNew-InboxRule/Set-InboxRule with ForwardTo/RedirectTo/DeleteMessage to external addressRemove rule; inspect mailbox access
Impossible travel to SSO/VDIEntra ID / VPN / VDISuccessful auth from geographically impossible locations within short windowRevoke tokens; force re-auth
Anomalous Snowflake accessSnowflake query logBulk export / unusual query volume from new client IP or appSuspend session; review data scope
IR-channel eavesdroppingTeams / Slack auditCompromised account joins IR/security channels or bridges; searches for "incident", "breach"Move IR comms off-band; rotate
08

CrowdStrike LogScale CQL Hunt Queries

Pick your tenant's cloud first — every "Open in Falcon" button below uses this selection.
Q1 · Remote-access tool execution (RMM abuse)
CONF HIGHFP MEDCOST LOW

Looks for: execution of legitimate remote-access / RMM tools Scattered Spider favors. Accomplishes: surfaces first-seen RMM on servers and admin hosts, the group's persistence & hands-on-keyboard channel.

Common FP: sanctioned IT support tools. Tune by baselining approved RMM per host role and excluding your standard support product / install paths.
// HUNT: Remote-access / RMM tool execution
// MITRE: T1219
// CONF: high   FP: medium   COST: low
// REQUIRES: ProcessRollup2 process telemetry
// FALSE POSITIVES: sanctioned IT remote-support tooling
// TUNING: exclude approved product + install path; scope to server/admin OUs
#event_simpleName=ProcessRollup2
| ImageFileName=/\\(anydesk|teamviewer|screenconnect|connectwisecontrol|splashtop|tailscale|atera|syncro|pulseway|logmein|gotoassist|remoteutilities|rustdesk)\w*\.exe$/i
| groupBy([ComputerName, UserName, ImageFileName], function=([count(as=execs), min(@timestamp, as=firstSeen), max(@timestamp, as=lastSeen)]))
| sort(firstSeen, order=desc, limit=200)
Q2 · Reverse-tunnel / relay tooling (Ngrok, Teleport, Tailscale)
CONF HIGHFP LOWCOST LOW

Looks for: tunnel / relay binaries and command lines used for covert C2 egress. Accomplishes: catches Ngrok/Teleport/Tailscale channels that bypass proxy egress controls.

// HUNT: Reverse-tunnel / relay tooling for C2
// MITRE: T1572, T1090
// CONF: high   FP: low   COST: low
// REQUIRES: ProcessRollup2 with CommandLine
// FALSE POSITIVES: rare sanctioned use of Tailscale/Teleport in devops
// TUNING: exclude approved devops hosts running Tailscale/Teleport agents
#event_simpleName=ProcessRollup2
| ImageFileName=/\\(ngrok|tsh|teleport|cloudflared|frpc|gost)\.exe$/i
   or CommandLine=/(ngrok\s+(tcp|http|start)|tunnel|--authtoken|teleport\s+login|tsh\s+(login|ssh))/i
| table([@timestamp, ComputerName, UserName, ImageFileName, CommandLine, ParentBaseFileName], limit=200)
Q3 · BYOVD vulnerable-driver write (STONESTOP/POORTRY class)
CONF HIGHFP LOWCOST MED

Looks for: a driver (.sys) written to disk outside normal driver stores, the precursor to loading a malicious/vulnerable signed driver to kill EDR. Accomplishes: detects the BYOVD setup step before EDR is blinded.

Common FP: legitimate software/driver installers write to System32\drivers. Tune by excluding trusted installer parents and signed vendor update processes.
// HUNT: BYOVD - driver written outside standard driver store
// MITRE: T1562.001, T1068
// CONF: high   FP: low   COST: medium
// REQUIRES: NewExecutableWritten / PeFileWritten with TargetFileName
// FALSE POSITIVES: legit driver installers into System32\drivers
// TUNING: exclude trusted installer parents (msiexec, vendor updaters), signed paths
#event_simpleName=/NewExecutableWritten|PeFileWritten/
| TargetFileName=/\.sys$/i
| TargetFileName!=/\\(System32|SysWOW64)\\DriverStore\\/i
| TargetFileName=/\\(Users|Temp|ProgramData|Windows\\Temp|PerfLogs)\\/i
| groupBy([ComputerName, UserName, TargetFileName, ParentBaseFileName], function=count(as=writes))
| sort(writes, order=desc, limit=200)
Q4 · LSASS credential dumping (comsvcs / ProcDump / MiniDump)
CONF HIGHFP LOWCOST LOW

Looks for: command lines that dump LSASS memory — comsvcs.dll MiniDump, ProcDump against lsass, or rundll32 minidump patterns. Accomplishes: catches the group's primary on-host credential-theft step.

// HUNT: LSASS memory dump via comsvcs/ProcDump/MiniDump
// MITRE: T1003.001
// CONF: high   FP: low   COST: low
// REQUIRES: ProcessRollup2 with CommandLine
// FALSE POSITIVES: rare admin/DFIR memory captures
// TUNING: exclude sanctioned DFIR collection hosts/accounts
#event_simpleName=ProcessRollup2
| (CommandLine=/comsvcs\.dll.{0,40}(MiniDump|#\+?24)/i
   or CommandLine=/(procdump(64)?\.exe).{0,60}(-ma|-mm).{0,20}lsass/i
   or CommandLine=/rundll32.{0,60}MiniDump/i
   or CommandLine=/lsass\.dmp/i)
| table([@timestamp, ComputerName, UserName, ImageFileName, CommandLine, ParentBaseFileName], limit=200)
Q5 · AD reconnaissance (ADExplorer / SharpHound / BloodHound)
CONF HIGHFP MEDCOST LOW

Looks for: AD enumeration tooling execution or its command-line collection flags. Accomplishes: flags the discovery phase that precedes lateral movement and privilege targeting.

Common FP: ADExplorer is a Sysinternals admin tool. Tune by excluding known AD-admin accounts / jump hosts and alerting only on non-admin or server-side execution.
// HUNT: AD recon utilities
// MITRE: T1087, T1069, T1482
// CONF: high   FP: medium   COST: low
// REQUIRES: ProcessRollup2 with CommandLine
// FALSE POSITIVES: legitimate AD admin use of ADExplorer
// TUNING: exclude AD-admin accounts and sanctioned admin jump hosts
#event_simpleName=ProcessRollup2
| ImageFileName=/\\(ADExplorer(64)?|SharpHound|BloodHound|AzureHound)\.exe$/i
   or CommandLine=/(-CollectionMethod\s+(All|DCOnly|Session)|Invoke-BloodHound|SharpHound)/i
| groupBy([ComputerName, UserName, ImageFileName], function=([count(as=execs), collect(CommandLine, limit=3)]))
| sort(execs, order=desc, limit=200)
Q6 · Shadow-copy & backup destruction (ransomware prep)
CONF HIGHFP LOWCOST LOW

Looks for: deletion of Volume Shadow Copies / backup catalogs and recovery disablement — the immediate precursor to DragonForce encryption. Accomplishes: last-chance detection before impact.

// HUNT: Inhibit system recovery (shadow copy / backup delete)
// MITRE: T1490
// CONF: high   FP: low   COST: low
// REQUIRES: ProcessRollup2 with CommandLine
// FALSE POSITIVES: rare legitimate backup maintenance scripts
// TUNING: exclude approved backup-admin service accounts
#event_simpleName=ProcessRollup2
| (CommandLine=/vssadmin(\.exe)?\s+delete\s+shadows/i
   or CommandLine=/wmic\s+shadowcopy\s+delete/i
   or CommandLine=/wbadmin\s+delete\s+(catalog|systemstatebackup)/i
   or CommandLine=/bcdedit.{0,40}(recoveryenabled\s+no|bootstatuspolicy\s+ignoreallfailures)/i)
| table([@timestamp, ComputerName, UserName, ImageFileName, CommandLine, ParentBaseFileName], limit=200)
Q7 · Security-service tamper (stop / disable EDR & AV)
CONF MEDFP MEDCOST LOW

Looks for: command-line attempts to stop, delete, or disable security services via sc, net stop, taskkill, or PowerShell. Accomplishes: catches userland defense-evasion that accompanies or substitutes for BYOVD.

Common FP: legitimate patching / agent upgrades restart security services. Tune by excluding your EDR's own updater and change-window maintenance accounts.
// HUNT: Stop/disable EDR-AV services
// MITRE: T1562.001
// CONF: medium   FP: medium   COST: low
// REQUIRES: ProcessRollup2 with CommandLine
// FALSE POSITIVES: agent upgrades / patch windows restarting services
// TUNING: exclude EDR updater process + scheduled maintenance accounts
#event_simpleName=ProcessRollup2
| CommandLine=/(sc(\.exe)?\s+(stop|delete|config).{0,40}(sense|csagent|windefend|mssense|sophos|sentinel|carbonblack|cylance)|net\s+stop\s+.{0,30}(defender|falcon|sophos|sentinel)|taskkill.{0,30}(MsMpEng|CSFalcon|Sense)|Set-MpPreference\s+-DisableRealtimeMonitoring\s+\$true)/i
| table([@timestamp, ComputerName, UserName, ImageFileName, CommandLine, ParentBaseFileName], limit=200)
Q8 · MFA push-bombing burst (rapid repeated auth)
CONF MEDFP MEDCOST MED

Looks for: a burst of failed logons against a single account in a short window (MFA fatigue / push-bombing). Accomplishes: flags the initial-access attempt on endpoints reporting logon telemetry.

Common FP: users with expired cached creds after password change. Tune the threshold to your environment and correlate with a subsequent success. Best run against ingested IdP logs (see §7).
// HUNT: MFA push-bombing / repeated failed auth burst
// MITRE: T1621, T1110
// CONF: medium   FP: medium   COST: medium
// REQUIRES: UserLogonFailed2 (endpoint) or ingested IdP auth logs
// FALSE POSITIVES: stale cached creds after password reset
// TUNING: raise fail threshold; correlate with subsequent UserLogon success
#event_simpleName=UserLogonFailed2
| bucket(span=10m, field=@timestamp)
| groupBy([UserName, _bucket], function=count(as=fails))
| fails >= 10
| sort(fails, order=desc, limit=200)
Q9 · Process-to-tunnel network correlation (RMM/tunnel egress)
CONF MEDFP MEDCOST MED

Looks for: outbound connections resolving to tunnel/RMM egress domains. Accomplishes: corroborates Q1/Q2 process hits with network egress to known relay infrastructure.

Common FP: developers/devops legitimately using ngrok/cloudflared. Tune by scoping out sanctioned dev hosts and correlating with the process hits from Q1/Q2.
// HUNT: DNS to tunnel/RMM relay infrastructure
// MITRE: T1572, T1219
// CONF: medium   FP: medium   COST: medium
// REQUIRES: DnsRequest telemetry
// FALSE POSITIVES: sanctioned dev use of tunnel services
// TUNING: exclude approved dev/devops hosts; correlate with Q1/Q2
#event_simpleName=DnsRequest
| DomainName=/(ngrok\.(io|com)|ngrok-free\.app|teleport\.sh|trycloudflare\.com|tailscale\.com|\.ts\.net)$/i
| groupBy([ComputerName, DomainName], function=([count(as=lookups), collect(ContextBaseFileName, limit=3)]))
| sort(lookups, order=desc, limit=200)
09

CrowdStrike Custom IOA Recommendations

Queries Q3, Q4, and Q6 are strong promotion candidates for Custom IOAs (low FP, high confidence, terminal-stage). Q1/Q2 are best kept as scheduled hunts until baselined.

IOA NameField PatternsExpected Benign ExclusionsDeployment Path
SS — LSASS MiniDumpProcess create; CmdLine matches comsvcs.dll MiniDump / procdump … lsassSanctioned DFIR collection hostsEndpoint Security → Custom IOA → Process Creation, action Detect/Block
SS — BYOVD driver dropFile write of .sys to Temp/ProgramData/Users by non-installer parentVendor updaters (msiexec, signed installers)Custom IOA → File Creation, action Detect
SS — Shadow-copy deleteProcess create; CmdLine vssadmin delete shadows / wbadmin delete catalogApproved backup-admin service accountsCustom IOA → Process Creation, action Block
SS — Tunnel binaryProcess create; image ngrok/tsh/cloudflared on server OUSanctioned devops hostsCustom IOA → Process Creation, action Detect
⚠ Validate field names and IOA rule-group scoping in your tenant. Test each IOA in "Monitor" mode against a benign baseline before switching to Detect/Block.
10

Machine-Readable IOC Appendix

{
  "actor": "Scattered Spider",
  "aliases": ["UNC3944", "Octo Tempest", "0ktapus", "Muddled Libra", "LUCR-3", "Scatter Swine", "Storm-0875"],
  "mitre_group": "G1015",
  "generated": "2026-07-01",
  "confidence_note": "Infrastructure and hashes are highly perishable; prefer behavioral IOCs. Validate atomics against current CISA AA23-320A appendix.",
  "indicators": [
    { "type": "domain_pattern", "value": "*-sso.com | *-okta.com | *-helpdesk.com | *-vpn.com | *-servicedesk.com", "confidence": "medium", "action": "hunt", "source": "CISA AA23-320A", "expiry": "2026-10-01" },
    { "type": "tool", "value": "anydesk.exe, teamviewer.exe, screenconnect, splashtop, tailscale, rustdesk", "confidence": "medium", "action": "hunt", "source": "Trellix/Rapid7", "expiry": "2026-10-01" },
    { "type": "tool", "value": "ngrok.exe, tsh.exe, teleport, cloudflared", "confidence": "high", "action": "hunt", "source": "Darktrace/ReliaQuest", "expiry": "2026-10-01" },
    { "type": "tool", "value": "procdump, mimikatz, ADExplorer, SharpHound", "confidence": "high", "action": "hunt", "source": "Trellix", "expiry": "2026-10-01" },
    { "type": "malware", "value": "STONESTOP (loader) + POORTRY (signed driver) BYOVD toolkit", "confidence": "high", "action": "hunt", "source": "Trellix/industry", "expiry": "2026-10-01" },
    { "type": "network", "value": "*.ngrok.io, *.ngrok-free.app, *.teleport.sh, *.ts.net, *.trycloudflare.com", "confidence": "medium", "action": "hunt", "source": "web-hunter", "expiry": "2026-08-01" },
    { "type": "behavior", "value": "help-desk MFA reset + new authenticator enrollment <1h", "confidence": "high", "action": "detect", "source": "CrowdStrike/CISA", "expiry": "2027-01-01" },
    { "type": "behavior", "value": "new federated IdP/domain added to SSO tenant; auto account-linking", "confidence": "high", "action": "detect", "source": "Permiso LUCR-3", "expiry": "2027-01-01" },
    { "type": "behavior", "value": "AWS CloudTrail CreateUser + CreateAccessKey by compromised principal", "confidence": "high", "action": "detect", "source": "Permiso LUCR-3", "expiry": "2027-01-01" },
    { "type": "behavior", "value": "New-InboxRule with ForwardTo/RedirectTo/DeleteMessage to external", "confidence": "medium", "action": "detect", "source": "Microsoft/Red Canary", "expiry": "2027-01-01" },
    { "type": "ransomware", "value": "DragonForce payload; ESXi mass encryption", "confidence": "high", "action": "detect", "source": "CISA AA23-320A", "expiry": "2027-01-01" }
  ]
}
11

Detection Validation Gates

GateRequirementEvidence
1 · Telemetry readyProcessRollup2 + DnsRequest flowing; IdP/cloud connectors ingesting for §7 huntsConfirm event counts > 0 over 24h per source
2 · Benign baselineQ1/Q5/Q7/Q8/Q9 run in monitor mode; approved RMM & admin tools cataloguedFP list built; exclusions applied
3 · Positive testsAtomic Red Team / lab exec of RMM, comsvcs MiniDump, vssadmin delete, ngrok tunnelEach query fires on the corresponding test
4 · PromotionQ3/Q4/Q6 promoted to Custom IOA after clean baseline; §7 identity hunts wired to alertsIOA in Detect/Block; alert routing verified
12

Hardening — Tiered

Immediate (this week)
  • Help-desk identity-verification protocol (M1017, CISA): require multi-factor, out-of-band caller verification (manager callback, video, or in-person) before any password or MFA reset. This is the single highest-leverage control against Scattered Spider.
  • Restrict/monitor remote-access tooling (M1042): application-control or block unsanctioned RMM (AnyDesk, ScreenConnect, Splashtop, TeamViewer, RustDesk); alert on any first-seen on servers (feeds Q1).
  • Enable BYOVD protection (M1038): turn on Microsoft vulnerable-driver blocklist (HVCI / Sdb blocklist) and EDR tamper protection; deny unsigned/known-vulnerable drivers.
  • Number-matching / phishing-resistant MFA (M1032): disable simple push-approval; enforce number matching to defeat push-bombing.
Near term (1–4 weeks)
  • Phishing-resistant MFA (FIDO2/WebAuthn) (M1032) for admins, IT/help-desk, and remote access — removes push-bombing and AiTM entirely for those accounts.
  • Lock down SSO federation changes (M1018): restrict who can add federated IdPs / modify domain authentication; alert on every change (feeds §7).
  • Credential Guard + LSASS PPL (M1043/M1040): enable LSA protection and Credential Guard to blunt LSASS dumping (feeds Q4).
  • Tiered admin + PIM/JIT (M1026): remove standing privilege; just-in-time elevation with approval for cloud & AD admin roles.
Strategic (1–3 months)
  • Conditional Access hardening (M1036): device-compliance + managed-network requirements for VDI/SSO; block legacy auth; session controls on high-value SaaS.
  • SIM-swap resilience: eliminate SMS/voice MFA org-wide; coordinate with carriers on port-freeze for executive/admin lines.
  • Immutable/off-domain backups + ESXi hardening (M1053): air-gapped/immutable backups; lockdown mode, MFA, and restricted SSH on ESXi to counter the ransomware end-state.
  • Ingest identity & cloud logs into NG-SIEM: wire Okta/Entra/CloudTrail/O365 so §7 hunts run continuously as detections, not manual reviews.
⚠ M-number mappings are MITRE mitigation identifiers (the "why"); pair each with your platform's benchmark (CIS / MS Security Baseline / vendor guide) for the exact "what/where" before deployment.
13

Deployable Playbooks

Playbook A — Enforce number-matching & phishing-resistant MFA (Entra ID)

1. Entra admin center > Protection > Authentication methods.
2. Enable "Microsoft Authenticator" > configure:
     - Require number matching for push notifications = Enabled (All users)
     - Show application name / geo in push = Enabled
3. Enable FIDO2 security key method; scope to Admins + IT/Helpdesk + Remote-access groups.
4. Conditional Access > New policy:
     - Users: Directory roles = all privileged roles + Helpdesk group
     - Grant: Require authentication strength = "Phishing-resistant MFA"
5. Report-only > validate > enable. Disable SMS/voice as an approved method.

Playbook B — Block vulnerable drivers (BYOVD) — HVCI + blocklist

# Enable Microsoft vulnerable-driver blocklist (Windows built-in)
reg add "HKLM\SYSTEM\CurrentControlSet\Control\CI\Config" /v VulnerableDriverBlocklistEnable /t REG_DWORD /d 1 /f

# Enable Memory Integrity (HVCI)
# HVCI needs VBS enabled as well -- the scenario key alone is inert and the
# control silently never activates. All three values are required.
reg add "HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard" /v EnableVirtualizationBasedSecurity /t REG_DWORD /d 1 /f
reg add "HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard" /v RequirePlatformSecurityFeatures /t REG_DWORD /d 1 /f
reg add "HKLM\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity" /v Enabled /t REG_DWORD /d 1 /f
# Prereqs: UEFI + Secure Boot + virtualization extensions. Reboot required.
# PILOT FIRST -- incompatible legacy drivers can block boot under HVCI.
# Verify AFTER reboot (SecurityServicesRunning must contain 2):
#   (Get-CimInstance Win32_DeviceGuard -Namespace root\Microsoft\Windows\DeviceGuard).SecurityServicesRunning
# Rollback: set both DeviceGuard values and the scenario Enabled back to 0, then reboot.
#   If the host will not boot, revert from Safe Mode or WinRE.

# Verify (reboot required)
Get-CimInstance -ClassName Win32_DeviceGuard -Namespace root\Microsoft\Windows\DeviceGuard |
  Select-Object -ExpandProperty SecurityServicesRunning
# 2 in the list = HVCI running. Confirm EDR "Tamper Protection" is ON in your console.

Playbook C — Enable LSA Protection (PPL) + Credential Guard

# LSASS as Protected Process Light
reg add "HKLM\SYSTEM\CurrentControlSet\Control\Lsa" /v RunAsPPL /t REG_DWORD /d 1 /f

# Credential Guard via Device Guard (also needs HVCI above)
reg add "HKLM\SYSTEM\CurrentControlSet\Control\LSA" /v LsaCfgFlags /t REG_DWORD /d 1 /f

# Verify after reboot
Get-CimInstance -ClassName Win32_DeviceGuard -Namespace root\Microsoft\Windows\DeviceGuard |
  Select-Object SecurityServicesConfigured, SecurityServicesRunning
# Test that comsvcs MiniDump against lsass now fails (should be blocked / access denied).

Playbook D — CQL spot-check after hardening

// Confirm no successful LSASS dump activity post-PPL rollout
#event_simpleName=ProcessRollup2
| CommandLine=/comsvcs\.dll.{0,40}MiniDump|procdump.{0,60}lsass/i
| table([@timestamp, ComputerName, UserName, CommandLine])
// Expect: zero hits, or only sanctioned DFIR hosts.
14

Containment Runbook

Phase 1 — Isolate
  • Network-contain affected hosts via Falcon; do not tip off the actor on monitored channels — assume they are watching Teams/Slack/Exchange and IR calls. Move IR comms out-of-band immediately.
  • Suspend the compromised identities; revoke all active sessions/refresh tokens (Entra "Revoke sessions", Okta clear sessions).
  • Freeze help-desk password/MFA resets org-wide pending identity re-verification.
Phase 2 — Eradicate
  • Remove attacker MFA enrollments; delete rogue federated IdPs/domains and backdoor IAM users; rotate the keys they created.
  • Remove malicious inbox/forwarding rules; hunt for additional persistence (RMM installs, scheduled tasks, new local admins).
  • Rotate credentials broadly — privileged accounts, service accounts, and any secrets exposed via LSASS/AD dumps; force password reset with re-verification.
  • Uninstall unsanctioned RMM; remove BYOVD drivers; confirm EDR tamper protection restored on all hosts.
Phase 3 — Recover
  • Restore from immutable/off-domain backups only after eradication is confirmed; validate ESXi integrity before repowering VMs.
  • Re-enable services under monitoring; keep §7 identity hunts and Q1–Q9 in heightened alerting for 30+ days.
  • Post-incident: enforce phishing-resistant MFA, harden help-desk verification, and brief execs on SIM-swap risk.
15

Detection Coverage Map

BehaviorPrimary DetectionFallbackKnown Gap
Help-desk vishing → MFA reset§7 IdP audit huntHelp-desk ticket review⚠ No endpoint signal; needs IdP log ingestion
Push-bombingQ8 / §7Entra risky sign-inEndpoint Q8 weaker than IdP-native
RMM abuseQ1Q9 networkFP tuning required per environment
Tunnel C2Q2 + Q9Proxy logsEncrypted/sanctioned dev use
BYOVD EDR-killQ3EDR tamper alertPost-kill telemetry may be lost
LSASS dumpQ4Q7 service tamperNon-cmdline dump variants
AD reconQ5Identity ProtectionLDAP-only recon w/o tooling
Cloud/IdP persistence§7 CloudTrail/Entra⚠ Requires cloud connectors
Inbox-rule persistence§7 O365 audit⚠ Requires O365 connector
Shadow-copy delete / ransomwareQ6RansomwareOpenFileESXi encryption not on EDR
ESXi encryption§7 ESXi logsBackup alerts⚠ ESXi rarely carries a sensor
16

Hunt Summary Ticket

TITLE:       Threat Hunt — Scattered Spider (UNC3944 / Octo Tempest)
SCOPE:       Identity plane (Okta/Entra), Windows endpoints & servers, cloud IAM, M365, ESXi
HYPOTHESIS:  A help-desk-driven identity reset is followed by RMM tooling, credential
             access, and pre-encryption behaviors indicating an active intrusion.
QUERIES RUN: Q1 RMM exec · Q2 tunnels · Q3 BYOVD · Q4 LSASS · Q5 AD recon ·
             Q6 shadow-copy delete · Q7 service tamper · Q8 push-bombing · Q9 tunnel DNS
             + §7 native identity/cloud audit hunts
DATA:        ProcessRollup2, NewExecutableWritten/PeFileWritten, DnsRequest,
             UserLogonFailed2; (IdP/CloudTrail/O365 if ingested)
FINDINGS:    <populate>
GAPS:        IdP/cloud/O365/ESXi log ingestion; per-env RMM baseline
ACTIONS:     Promote Q3/Q4/Q6 to Custom IOA; enforce number-matching MFA;
             harden help-desk verification; enable HVCI + LSA PPL
OWNER:       HuntPack
STATUS:      Draft v0.1 · 2026-07-01
17

Changelog

VersionDateChange Summary
v0.12026-07-01Initial draft — 9 CQL hunts, 8 native identity/cloud audit hunts, IOA recs, tiered hardening, playbooks, containment runbook. Generated via HuntPack v2 pipeline.
18

References

TierSourceUsed ForAccess Date
1CISA/FBI AA23-320A — Scattered SpiderCore TTPs, IOCs, mitigations2026-07-01
1FBI/CISA advisory PDF (2025-07-29 update)Third-party IT targeting, DragonForce/ESXi2026-07-01
1MITRE ATT&CK — G1015Technique mapping, aliases2026-07-01
2CrowdStrike Services — escalating attacksHelp-desk vishing, SSO/VDI targeting2026-07-01
2Permiso — LUCR-3 SaaS/CloudBackdoor IAM, IdP federation persistence2026-07-01
2Trellix — Modus OperandiSTONESTOP/POORTRY, LSASS, ADExplorer2026-07-01
2Rapid7 — Insights & RecommendationsTooling, BYOVD, recommendations2026-07-01
3BleepingComputer — aviation shift2025 sector rotation context2026-07-01

Automated pack — treat queries as starting points. Validate field names and tune FP exclusions in your own tenant before relying on any detection. Atomic IOCs (domains/hashes) for this actor are perishable; re-check the current CISA AA23-320A appendix.