Scenario 01 · Espionage · APT29 / Cozy Bear
We took APT29's own tradecraft — credential theft, Windows Defender tampering and a broad discovery sweep — and ran a non-destructive subset of it by hand on a Windows victim. THRONE caught all fourteen detections end to end, ONYX triaged them into three incidents, and every incident rebuilt itself as a process tree from Sysmon's own process GUIDs.
APT29 — also known as Cozy Bear, attributed to Russia's SVR and catalogued by MITRE ATT&CK as G0016 — is the espionage benchmark: patient, quiet and almost entirely dependent on tooling that already ships with Windows. We reproduced a recognisable slice of its kill chain by hand on one victim and measured, to the alert, what THRONE made of it.
The batch covered the moves that define a Cozy Bear intrusion: dumping the SAM and SYSTEM registry hives for offline
credential cracking, disabling and carving exclusions into Windows Defender, and a broad reconnaissance sweep across the
host, its accounts and the surrounding domain. Every single action used a legitimate, Microsoft-signed binary —
reg.exe, wmic.exe, powershell.exe, net.exe, nltest.exe,
rundll32.exe, systeminfo.exe. No malware was dropped and no exploit was fired; there was nothing
for a signature-based antivirus to match on.
That is the whole point of this adversary, and the whole point of the test. Within seconds of each command, THRONE's Sigma sweep raised all fourteen detections, ONYX — THRONE's AI SOC analyst — clustered them by process lineage into three investigable incidents (INC-55827, INC-55830 and INC-55831), and each incident was reconstructed as a parent-to-child process tree straight from Sysmon's own event GUIDs. An analyst opened three incidents, not fourteen disconnected alerts.
APT29 is widely attributed to the SVR, Russia's foreign-intelligence service. It is an espionage actor, not a smash-and-grab crew: its mission is quiet, long-term access to the communications of governments, diplomats, think tanks and the technology supply chain that serves them.
Cozy Bear · The Dukes · Midnight Blizzard · Nobelium · UNC2452 · Dark Halo · YTTRIUM · Cloaked Ursa · StellarParticle. MITRE ATT&CK group ID G0016.
The group's reputation rests on a string of campaigns that between them defined the modern espionage threat model:
| Period | Campaign | What it was |
|---|---|---|
| 2014–16 | The Dukes / CozyDuke | A long-running modular toolset (MiniDuke, SeaDuke, CozyCar, HammerDuke) run against governments, NATO members and policy institutes. |
| 2016 | DNC intrusion | Compromise of the US Democratic National Committee network, present alongside APT28 / Fancy Bear. |
| 2020 | WellMess / WellMail | Targeting of COVID-19 vaccine research in the UK, US and Canada, called out in a joint NCSC / CISA / NSA advisory. |
| 2020 | SolarWinds (SUNBURST) | A supply-chain compromise of SolarWinds Orion that reached roughly 18,000 organisations, with hands-on-keyboard follow-up into select US federal agencies and security firms. |
| 2024 | Midnight Blizzard | Breach of Microsoft corporate email via password-spray against a legacy test tenant, then OAuth-application abuse; a related intrusion was reported by HPE. |
Across those operations a consistent style emerges, and it is exactly what makes APT29 hard to catch. It lives off the
land: wherever possible it uses the target's own administrative tooling — PowerShell, WMI, reg.exe,
net.exe — rather than dropping custom malware. It abuses legitimate credentials and tokens instead of
firing exploits, and has repeatedly pivoted into cloud and identity infrastructure (Microsoft 365, OAuth
applications, and AD FS backdoors such as FoggyWeb and MagicWeb). In the Duke era it hid its command-and-control inside
ordinary cloud services — Dropbox, OneDrive, Google Drive, Trello, even social-media accounts — so the traffic looked
routine. And it is patient and tidy: low-and-slow operations, careful operational security, and deliberate cleanup
to frustrate forensics.
The techniques we ran below are not a guess at that style. APT29 was the actor emulated in MITRE's 2019–2020 ATT&CK Evaluations, and the public APT29 emulation plan that came out of that work — credential-hive theft, Defender tampering, WMI and PowerShell execution, broad discovery — is the direct lineage of the command batch in this report.
No C2, no implant, no automation, no theatre. We executed APT29 techniques directly on the target as a non-destructive command batch and watched what THRONE made of them. The honest framing matters: this is a controlled technique test, not a live operation.
Every technique ran on a single Windows victim, WIN-J50RP1JBGD4 (204.168.192.149 · internal 10.0.0.5), as a curated, non-destructive subset of the APT29 kill chain — the recognisable Cozy Bear moves, minus anything that would damage the box or exfiltrate real data. The host runs Microsoft Sysmon and streams its telemetry to the THRONE cloud tenant. Everything shown is the real lab: hostnames, IP addresses, alert IDs and incident IDs are reproduced exactly as captured, nothing redacted.
This is not a Caldera operation. The autonomous, fact-chained APT29 run — where a real command-and-control server drives the adversary itself — is a separate report. Here the sequence was ours, by hand; only the detections were THRONE's.
The path from a keystroke on the box to a scored, reconstructed incident is fully automatic and completes in seconds. No step below is operated by a human:
Sysmon records each action as a structured event — process creation with the full command line, registry save/export,
image loads — and the host ships it as tenant-tagged syslog so THRONE attributes it to the right customer. The ingest
endpoint on port :1514 hands events to Kafka; the ch_pump consumer parses and
normalises them into ClickHouse. From there THRONE's detection pass runs two engines side by side: a Sigma
sweep of 3,148 rules mapped to 389 ATT&CK techniques, matching on command-line and event fields, and a behavioral
engine that scores sequences rather than single lines. Matches become alerts; ONYX triages and clusters them into
incidents; and the causality tree is rebuilt from the parent/child process GUIDs Sysmon stamps on every event.
The subset we ran on WIN-J50RP1JBGD4, grouped by ATT&CK tactic. Each technique threw Windows telemetry that THRONE matched against its Sigma detections — and every one was caught. Below the map: what each move does, and why an espionage actor like Cozy Bear reaches for it.
Cozy Bear rarely needs a new executable; it runs code through interpreters that are already present and already trusted.
Here powershell.exe was spawned non-interactively — the hallmark of a script running on an adversary's
behalf rather than an administrator typing at a console — and wmic.exe was used to create a process via
process call create. WMI is a favourite because the same call can execute locally or against a remote
host, giving one command both an execution and a lateral-movement role, and because it leaves a far less obvious trace
than a dropped binary. Mapped to T1059.001 and T1047.
The crown jewel of the batch. reg.exe save was pointed at HKLM\SAM and HKLM\SYSTEM —
the registry hives that hold local password hashes and the boot key needed to decrypt them. Copying the hives to disk lets
an attacker crack or pass the hashes offline, on their own hardware, without ever touching lsass.exe and
tripping the EDR hooks that watch it. Because reg.exe is a signed Microsoft binary performing a legitimate
operation, the only thing that separates attack from administration is what it is saving — which is exactly what
THRONE keys on. Mapped to T1003.002.
Before the noisier work, the intrusion tried to blind the endpoint. PowerShell's Set-MpPreference was used to
disable Defender's real-time monitoring, and Add-MpPreference -ExclusionPath to carve out a folder where later
tooling could run unscanned. Disabling and then excluding is a deliberate two-step: even if monitoring is switched
back on, the exclusion remains a safe harbour. Alongside it, rundll32.exe was used for proxy execution —
running code by way of a trusted system binary so it inherits that binary's reputation. Mapped to
T1562.001 (three separate rules) and T1218.011.
The largest phase, and the most human. Having landed, an operator wants to know where they are before deciding what to do
next, so a burst of read-only commands maps the ground: systeminfo for OS and patch level
(T1082); net user and net localgroup for local accounts
(T1087.001); net group for domain groups (T1069);
nltest /dclist: and /domain_trusts to find domain controllers and trust relationships
(T1018); wmic against the SecurityCenter2 namespace to enumerate installed
antivirus (T1518.001); and reg query to read configuration and service keys
(T1012). Each command is something a busy administrator might run — the tell is that they run
together, in seconds, from one parent process.
Finally, an automated-collection step (T1119): scripted enumeration that, in a live operation, would stage files of interest for exfiltration. In the lab it touched nothing sensitive, but it completes the espionage shape — get in quietly, see everything, take what matters.
Within seconds of each technique running, Sigma fired and ONYX — THRONE's AI SOC analyst — triaged the alerts into incidents. The full set of detections from this one batch, all on WIN-J50RP1JBGD4:
| Alert | Detection | Sev | ATT&CK |
|---|---|---|---|
| ALR-175421 | Dumping of Sensitive Hives Via Reg.EXE | HIGH | T1003.002 |
| ALR-175414 | Suspicious Process Created Via Wmic.EXE | HIGH | T1047 |
| ALR-175411 | Tamper Windows Defender – PSClassic | HIGH | T1562.001 |
| ALR-175406 | Disable Windows Defender AV Monitoring | HIGH | T1562.001 |
| ALR-175422 | Automated Collection Command Prompt | MED | T1119 |
| ALR-175420 | Group & Account Reconnaissance Via Net.EXE | MED | T1069 |
| ALR-175419 | Potential Recon Activity Via Nltest.EXE | MED | T1018 |
| ALR-175418 | Potentially Suspicious Rundll32 Activity | MED | T1218.011 |
| ALR-175415 | Product Reconnaissance Via Wmic.EXE | MED | T1518.001 |
| ALR-175413 | Config & Service Recon Via Reg.EXE | MED | T1012 |
| ALR-175412 | Windows Defender Exclusions Added | MED | T1562.001 |
| ALR-175417 | Local Accounts Discovery | LOW | T1087.001 |
| ALR-175416 | Suspicious Execution of Systeminfo | LOW | T1082 |
| ALR-175410 | Non-Interactive PowerShell Spawned | LOW | T1059.001 |
Four HIGH-severity alerts anchor the wave — the SAM/SYSTEM hive dump reaching for stored credentials, a WMIC-spawned process, and two separate Windows Defender tamper detections — while the discovery and collection tradecraft fills in the rest of the Cozy Bear shape. The detections that matter most, in detail:
The Sigma rule Dumping of Sensitive Hives Via Reg.EXE fires on a process-creation event where the image is
reg.exe, the command line contains save or export, and the target references
hklm\sam, hklm\system or hklm\security. That combination has essentially no
legitimate use on a workstation, so it maps cleanly to T1003.002 (OS Credential Dumping: Security
Account Manager) and ONYX scored it HIGH — the single most serious action in the batch,
because the hive copies enable offline hash cracking with no further noise on the box.
Two rules fire on the tampering itself: Tamper Windows Defender – PSClassic watches PowerShell for
Set-MpPreference calls that disable real-time or IOAV protection, and Disable Windows Defender AV
Monitoring catches the same intent across command-line and policy changes; a third, Windows Defender Exclusions
Added (ALR-175412), flags Add-MpPreference -ExclusionPath. All three map to
T1562.001 (Impair Defenses: Disable or Modify Tools). ONYX grouped them, together with the
rundll32 proxy execution, into INC-55831 — an endpoint actively being blinded, which is
why two of the three land HIGH.
Suspicious Process Created Via Wmic.EXE keys on wmic.exe invoking process call create —
the WMI path to spawning a new process, locally or on a remote host. Because the same command is a lateral-movement
primitive, it maps to T1047 and is scored HIGH even on a single box:
the technique's blast radius, not the current blast, is what sets the severity.
Potential Recon Activity Via Nltest.EXE matches nltest with arguments such as /dclist: or
/domain_trusts — the commands used to enumerate domain controllers and trust relationships. It maps to
T1018 (Remote System Discovery) and sits MED on its own, but it
appears in the lineage of both discovery incidents (INC-55830 and INC-55827),
where its value is corroboration: domain recon from the same parent that is reading accounts and configuration is no longer
routine.
Potentially Suspicious Rundll32 Activity flags rundll32.exe used to proxy execution through a trusted
binary — a classic way to run code that inherits a signed process's reputation. It maps to T1218.011
(System Binary Proxy Execution: Rundll32), and ONYX placed it inside the defense-evasion incident
INC-55831, where it reads as part of the same effort to move quietly past the endpoint's controls.
THRONE reconstructs each incident's causality from Sysmon's process GUIDs — parent to child, start to end — and renders it live on a 2D canvas. No log-grepping; the analyst sees the whole lineage. Captured directly from the Incidents tab.
Every Sysmon event carries two identifiers that make this possible: a ProcessGuid for the process that raised
it and a ParentProcessGuid for the process that spawned it. THRONE stitches those GUIDs into a directed graph,
so a tree is not a guess reassembled after the fact from timestamps — it is the literal parent/child chain the box reported,
drawn exactly as it happened.
whoami, WMIC,
nltest, netstat, net/net1, reg and
systeminfo (T1012, T1033, T1016,
T1082, T1087.001) — 5 linked alerts in one investigable incident.
rundll32 proxy execution (T1218.011).
net, nltest and
whoami, confirming the endpoint ships directly to THRONE with correct tenant attribution.APT29 is the espionage baseline — credential theft + defense evasion + broad discovery, all detected, with the full lineage reconstructed from Sysmon process GUIDs. Nothing was inferred after the fact; each tree is the real parent/child chain as the box reported it.
Nothing in this batch was malware. Every line was a signed Windows binary doing something a system administrator might plausibly do. That is precisely what makes APT29 difficult — and precisely where signature-based defenses go blind.
A traditional antivirus has nothing to match: no malicious file, no known-bad hash, no exploit. reg.exe,
net.exe, systeminfo and powershell.exe are all legitimate, and each individual
command is benign in isolation — administrators dump no hives, but they do run net user and
systeminfo every day. The malicious signal does not live in any single event. It lives in the sequence and
the lineage: one parent process spawning a credential-hive dump, a Defender disable and a domain-wide discovery sweep
within the same few seconds.
That is why reconstructing causality is not a cosmetic feature. A flat list of fourteen alerts invites an analyst to close them one at a time as low-value “admin activity”. Three process trees tell a story no single row can: these commands share a root, and that root is behaving like an intruder. Add the group's real-world habits — patient low-and-slow operations, abuse of legitimate credentials and cloud identity rather than exploits, and deliberate cleanup afterwards — and the lesson is that detecting Cozy Bear is a problem of correlation and behaviour, not of signatures.
Concrete, vendor-neutral steps that would surface this exact batch on any estate.
Deploy Sysmon (or an EDR) with a tuned config that records process creation with the full command line, registry
save/export, and image loads — and turn on PowerShell script-block logging. Without command-line capture, every detection in
this report is invisible: the difference between reg save HKLM\SAM and a harmless reg query lives
entirely in the arguments.
Alert on any process copying or exporting HKLM\SAM, HKLM\SYSTEM or HKLM\SECURITY,
and on access to ntds.dit via vssadmin, esentutl or shadow copies. There is no
legitimate reason for a workstation to do this; score it high regardless of which account or tool performed it.
An adversary disabling real-time monitoring (Set-MpPreference) or adding exclusions
(Add-MpPreference -ExclusionPath) is a pre-attack tell, not a configuration note. Watch the policy registry
keys as well — turning the control off and carving an exclusion are the two halves of the same move.
A single net, nltest or whoami is noise. The same parent spawning all of them — plus
systeminfo and a reg query — within seconds is the reconnaissance signature. Group alerts by
process ancestry before deciding severity, which is exactly what let THRONE collapse fourteen alerts into three incidents an
analyst can actually work.