Adversary intelligence · From the lab
We drive real adversary playbooks — nation-state espionage, ransomware, e-crime — at THRONE and publish exactly what it caught. Real incidents, real process trees, nothing staged. This is the work behind a more capable SOC.
We handed the wheel to a real Caldera C2 and let it fight: an autonomous, fact-chained APT29 operation. THRONE caught the whole kill chain in real time — credential theft, discovery, defense evasion — ONYX auto-triaged it, and every incident rebuilt as a process tree. Full technical detail, real IPs and incident IDs, HD evidence.
Read the operation reportCozy Bear · Russia
Nation-state espionage: credential dumping, WMI execution, Defender tampering, recon — all detected.
TrickBot → Ryuk/Conti
Ransomware chain. THRONE caught shadow-copy deletion and service kills before encryption.
Financially motivated
LOLBins and in-memory LSASS theft via comsvcs — living-off-the-land, flagged.
APT10 · China
Backdoor accounts, service installation, certutil decoding — persistence and credential access.
APT34 · Iran
Credential-manager harvesting via vaultcmd, domain enumeration, DNS-beacon tradecraft.
GRU · Russia
Host-firewall disabling, share enumeration, service-based execution — defense impairment.