SOCFRAME / THRONE Journal
All reports

Scenario 01 · Espionage · APT29 / Cozy Bear

Cozy Bear ran its playbook.
We saw every move.

We took APT29's own tradecraft — credential theft, Windows Defender tampering and a broad discovery sweep — and ran a non-destructive subset of it by hand on a Windows victim. THRONE caught all fourteen detections end to end, ONYX triaged them into three incidents, and every incident rebuilt itself as a process tree from Sysmon's own process GUIDs.

Adversary
APT29 · Cozy Bear
Attribution
Russia · SVR (G0016)
Method
Direct execution
Result
Detected end to end
Executive summary

Fourteen signed Windows binaries. Nowhere to hide.

APT29 — also known as Cozy Bear, attributed to Russia's SVR and catalogued by MITRE ATT&CK as G0016 — is the espionage benchmark: patient, quiet and almost entirely dependent on tooling that already ships with Windows. We reproduced a recognisable slice of its kill chain by hand on one victim and measured, to the alert, what THRONE made of it.

14
Detections fired
4
High severity
3
Incidents rebuilt
3,148
Sigma rules in sweep

The batch covered the moves that define a Cozy Bear intrusion: dumping the SAM and SYSTEM registry hives for offline credential cracking, disabling and carving exclusions into Windows Defender, and a broad reconnaissance sweep across the host, its accounts and the surrounding domain. Every single action used a legitimate, Microsoft-signed binary — reg.exe, wmic.exe, powershell.exe, net.exe, nltest.exe, rundll32.exe, systeminfo.exe. No malware was dropped and no exploit was fired; there was nothing for a signature-based antivirus to match on.

That is the whole point of this adversary, and the whole point of the test. Within seconds of each command, THRONE's Sigma sweep raised all fourteen detections, ONYX — THRONE's AI SOC analyst — clustered them by process lineage into three investigable incidents (INC-55827, INC-55830 and INC-55831), and each incident was reconstructed as a parent-to-child process tree straight from Sysmon's own event GUIDs. An analyst opened three incidents, not fourteen disconnected alerts.

The adversary

Who is APT29 / Cozy Bear?

APT29 is widely attributed to the SVR, Russia's foreign-intelligence service. It is an espionage actor, not a smash-and-grab crew: its mission is quiet, long-term access to the communications of governments, diplomats, think tanks and the technology supply chain that serves them.

Also tracked as

Cozy Bear · The Dukes · Midnight Blizzard · Nobelium · UNC2452 · Dark Halo · YTTRIUM · Cloaked Ursa · StellarParticle. MITRE ATT&CK group ID G0016.

The group's reputation rests on a string of campaigns that between them defined the modern espionage threat model:

PeriodCampaignWhat it was
2014–16The Dukes / CozyDukeA long-running modular toolset (MiniDuke, SeaDuke, CozyCar, HammerDuke) run against governments, NATO members and policy institutes.
2016DNC intrusionCompromise of the US Democratic National Committee network, present alongside APT28 / Fancy Bear.
2020WellMess / WellMailTargeting of COVID-19 vaccine research in the UK, US and Canada, called out in a joint NCSC / CISA / NSA advisory.
2020SolarWinds (SUNBURST)A supply-chain compromise of SolarWinds Orion that reached roughly 18,000 organisations, with hands-on-keyboard follow-up into select US federal agencies and security firms.
2024Midnight BlizzardBreach of Microsoft corporate email via password-spray against a legacy test tenant, then OAuth-application abuse; a related intrusion was reported by HPE.

Signature tradecraft

Across those operations a consistent style emerges, and it is exactly what makes APT29 hard to catch. It lives off the land: wherever possible it uses the target's own administrative tooling — PowerShell, WMI, reg.exe, net.exe — rather than dropping custom malware. It abuses legitimate credentials and tokens instead of firing exploits, and has repeatedly pivoted into cloud and identity infrastructure (Microsoft 365, OAuth applications, and AD FS backdoors such as FoggyWeb and MagicWeb). In the Duke era it hid its command-and-control inside ordinary cloud services — Dropbox, OneDrive, Google Drive, Trello, even social-media accounts — so the traffic looked routine. And it is patient and tidy: low-and-slow operations, careful operational security, and deliberate cleanup to frustrate forensics.

The techniques we ran below are not a guess at that style. APT29 was the actor emulated in MITRE's 2019–2020 ATT&CK Evaluations, and the public APT29 emulation plan that came out of that work — credential-hive theft, Defender tampering, WMI and PowerShell execution, broad discovery — is the direct lineage of the command batch in this report.

Setup & methodology

A hand-run subset — honestly

No C2, no implant, no automation, no theatre. We executed APT29 techniques directly on the target as a non-destructive command batch and watched what THRONE made of them. The honest framing matters: this is a controlled technique test, not a live operation.

Every technique ran on a single Windows victim, WIN-J50RP1JBGD4 (204.168.192.149 · internal 10.0.0.5), as a curated, non-destructive subset of the APT29 kill chain — the recognisable Cozy Bear moves, minus anything that would damage the box or exfiltrate real data. The host runs Microsoft Sysmon and streams its telemetry to the THRONE cloud tenant. Everything shown is the real lab: hostnames, IP addresses, alert IDs and incident IDs are reproduced exactly as captured, nothing redacted.

This is not a Caldera operation. The autonomous, fact-chained APT29 run — where a real command-and-control server drives the adversary itself — is a separate report. Here the sequence was ours, by hand; only the detections were THRONE's.

The pipeline, command to incident

The path from a keystroke on the box to a scored, reconstructed incident is fully automatic and completes in seconds. No step below is operated by a human:

Technique run on WIN-J50RP1JBGD4 → Sysmon event (process, registry, image-load)
→ tenant-tagged syslog → THRONE ingest :1514 → Kafka → ch_pump parse → ClickHouse
→ Sigma sweep (3,148 rules / 389 ATT&CK techniques) + behavioral engine → ONYX auto-triage → incident
→ causality tree (parent/child process GUIDs)

Sysmon records each action as a structured event — process creation with the full command line, registry save/export, image loads — and the host ships it as tenant-tagged syslog so THRONE attributes it to the right customer. The ingest endpoint on port :1514 hands events to Kafka; the ch_pump consumer parses and normalises them into ClickHouse. From there THRONE's detection pass runs two engines side by side: a Sigma sweep of 3,148 rules mapped to 389 ATT&CK techniques, matching on command-line and event fields, and a behavioral engine that scores sequences rather than single lines. Matches become alerts; ONYX triages and clusters them into incidents; and the causality tree is rebuilt from the parent/child process GUIDs Sysmon stamps on every event.

The kill chain it ran

The kill chain, phase by phase

The subset we ran on WIN-J50RP1JBGD4, grouped by ATT&CK tactic. Each technique threw Windows telemetry that THRONE matched against its Sigma detections — and every one was caught. Below the map: what each move does, and why an espionage actor like Cozy Bear reaches for it.

Detected
ExecutionNon-interactive PowerShell · T1059.001
Detected
ExecutionWMI · wmic · T1047
Detected
Credential accessreg SAM/SYSTEM hive · T1003.002
Detected
Defense evasionDefender tamper/disable · T1562.001
Detected
Defense evasionrundll32 proxy · T1218.011
Detected
Discoverynet · nltest · T1069 / T1018
Detected
Discoverywmic · systeminfo · T1518.001 / T1082
Detected
Discoverylocal accounts · reg · T1087.001 / T1012
Detected
CollectionAutomated collection · T1119

Execution — T1059.001, T1047

Cozy Bear rarely needs a new executable; it runs code through interpreters that are already present and already trusted. Here powershell.exe was spawned non-interactively — the hallmark of a script running on an adversary's behalf rather than an administrator typing at a console — and wmic.exe was used to create a process via process call create. WMI is a favourite because the same call can execute locally or against a remote host, giving one command both an execution and a lateral-movement role, and because it leaves a far less obvious trace than a dropped binary. Mapped to T1059.001 and T1047.

Credential access — T1003.002

The crown jewel of the batch. reg.exe save was pointed at HKLM\SAM and HKLM\SYSTEM — the registry hives that hold local password hashes and the boot key needed to decrypt them. Copying the hives to disk lets an attacker crack or pass the hashes offline, on their own hardware, without ever touching lsass.exe and tripping the EDR hooks that watch it. Because reg.exe is a signed Microsoft binary performing a legitimate operation, the only thing that separates attack from administration is what it is saving — which is exactly what THRONE keys on. Mapped to T1003.002.

Defense evasion — T1562.001, T1218.011

Before the noisier work, the intrusion tried to blind the endpoint. PowerShell's Set-MpPreference was used to disable Defender's real-time monitoring, and Add-MpPreference -ExclusionPath to carve out a folder where later tooling could run unscanned. Disabling and then excluding is a deliberate two-step: even if monitoring is switched back on, the exclusion remains a safe harbour. Alongside it, rundll32.exe was used for proxy execution — running code by way of a trusted system binary so it inherits that binary's reputation. Mapped to T1562.001 (three separate rules) and T1218.011.

Discovery — T1082, T1087.001, T1069, T1018, T1518.001, T1012

The largest phase, and the most human. Having landed, an operator wants to know where they are before deciding what to do next, so a burst of read-only commands maps the ground: systeminfo for OS and patch level (T1082); net user and net localgroup for local accounts (T1087.001); net group for domain groups (T1069); nltest /dclist: and /domain_trusts to find domain controllers and trust relationships (T1018); wmic against the SecurityCenter2 namespace to enumerate installed antivirus (T1518.001); and reg query to read configuration and service keys (T1012). Each command is something a busy administrator might run — the tell is that they run together, in seconds, from one parent process.

Collection — T1119

Finally, an automated-collection step (T1119): scripted enumeration that, in a live operation, would stage files of interest for exfiltration. In the lab it touched nothing sensitive, but it completes the espionage shape — get in quietly, see everything, take what matters.

The detections

What THRONE caught — fourteen, end to end

Within seconds of each technique running, Sigma fired and ONYX — THRONE's AI SOC analyst — triaged the alerts into incidents. The full set of detections from this one batch, all on WIN-J50RP1JBGD4:

AlertDetectionSevATT&CK
ALR-175421Dumping of Sensitive Hives Via Reg.EXEHIGHT1003.002
ALR-175414Suspicious Process Created Via Wmic.EXEHIGHT1047
ALR-175411Tamper Windows Defender – PSClassicHIGHT1562.001
ALR-175406Disable Windows Defender AV MonitoringHIGHT1562.001
ALR-175422Automated Collection Command PromptMEDT1119
ALR-175420Group & Account Reconnaissance Via Net.EXEMEDT1069
ALR-175419Potential Recon Activity Via Nltest.EXEMEDT1018
ALR-175418Potentially Suspicious Rundll32 ActivityMEDT1218.011
ALR-175415Product Reconnaissance Via Wmic.EXEMEDT1518.001
ALR-175413Config & Service Recon Via Reg.EXEMEDT1012
ALR-175412Windows Defender Exclusions AddedMEDT1562.001
ALR-175417Local Accounts DiscoveryLOWT1087.001
ALR-175416Suspicious Execution of SysteminfoLOWT1082
ALR-175410Non-Interactive PowerShell SpawnedLOWT1059.001

Four HIGH-severity alerts anchor the wave — the SAM/SYSTEM hive dump reaching for stored credentials, a WMIC-spawned process, and two separate Windows Defender tamper detections — while the discovery and collection tradecraft fills in the rest of the Cozy Bear shape. The detections that matter most, in detail:

ALR-175421 — SAM/SYSTEM hive dump (T1003.002)

The Sigma rule Dumping of Sensitive Hives Via Reg.EXE fires on a process-creation event where the image is reg.exe, the command line contains save or export, and the target references hklm\sam, hklm\system or hklm\security. That combination has essentially no legitimate use on a workstation, so it maps cleanly to T1003.002 (OS Credential Dumping: Security Account Manager) and ONYX scored it HIGH — the single most serious action in the batch, because the hive copies enable offline hash cracking with no further noise on the box.

ALR-175411 & ALR-175406 — Windows Defender tampering (T1562.001)

Two rules fire on the tampering itself: Tamper Windows Defender – PSClassic watches PowerShell for Set-MpPreference calls that disable real-time or IOAV protection, and Disable Windows Defender AV Monitoring catches the same intent across command-line and policy changes; a third, Windows Defender Exclusions Added (ALR-175412), flags Add-MpPreference -ExclusionPath. All three map to T1562.001 (Impair Defenses: Disable or Modify Tools). ONYX grouped them, together with the rundll32 proxy execution, into INC-55831 — an endpoint actively being blinded, which is why two of the three land HIGH.

ALR-175414 — WMIC process creation (T1047)

Suspicious Process Created Via Wmic.EXE keys on wmic.exe invoking process call create — the WMI path to spawning a new process, locally or on a remote host. Because the same command is a lateral-movement primitive, it maps to T1047 and is scored HIGH even on a single box: the technique's blast radius, not the current blast, is what sets the severity.

ALR-175419 — Nltest domain recon (T1018)

Potential Recon Activity Via Nltest.EXE matches nltest with arguments such as /dclist: or /domain_trusts — the commands used to enumerate domain controllers and trust relationships. It maps to T1018 (Remote System Discovery) and sits MED on its own, but it appears in the lineage of both discovery incidents (INC-55830 and INC-55827), where its value is corroboration: domain recon from the same parent that is reading accounts and configuration is no longer routine.

ALR-175418 — Rundll32 proxy execution (T1218.011)

Potentially Suspicious Rundll32 Activity flags rundll32.exe used to proxy execution through a trusted binary — a classic way to run code that inherits a signed process's reputation. It maps to T1218.011 (System Binary Proxy Execution: Rundll32), and ONYX placed it inside the defense-evasion incident INC-55831, where it reads as part of the same effort to move quietly past the endpoint's controls.

The evidence

Every incident, rebuilt as a process tree

THRONE reconstructs each incident's causality from Sysmon's process GUIDs — parent to child, start to end — and renders it live on a 2D canvas. No log-grepping; the analyst sees the whole lineage. Captured directly from the Incidents tab.

Every Sysmon event carries two identifiers that make this possible: a ProcessGuid for the process that raised it and a ParentProcessGuid for the process that spawned it. THRONE stitches those GUIDs into a directed graph, so a tree is not a guess reassembled after the fact from timestamps — it is the literal parent/child chain the box reported, drawn exactly as it happened.

THRONE causality graph for INC-55830 showing a 26-node process tree of whoami, WMIC, nltest, netstat, net, net1, reg and systeminfo
INC-55830 — Discovery. A 26-node process tree linking whoami, WMIC, nltest, netstat, net/net1, reg and systeminfo (T1012, T1033, T1016, T1082, T1087.001) — 5 linked alerts in one investigable incident.
THRONE causality graph for INC-55831 showing Windows Defender tampering and rundll32 proxy execution
INC-55831 — Defense Evasion (T1562.001). THRONE caught the intrusion trying to blind the endpoint: “Tamper Windows Defender” (HIGH) and “Defender Exclusions Added”, plus suspicious rundll32 proxy execution (T1218.011).
THRONE causality graph for INC-55827 showing a 13-node tree of net, nltest and whoami
INC-55827 — direct-ship proof. A 13-node tree of net, nltest and whoami, confirming the endpoint ships directly to THRONE with correct tenant attribution.

The espionage baseline

APT29 is the espionage baseline — credential theft + defense evasion + broad discovery, all detected, with the full lineage reconstructed from Sysmon process GUIDs. Nothing was inferred after the fact; each tree is the real parent/child chain as the box reported it.

Why it matters

What makes this adversary hard

Nothing in this batch was malware. Every line was a signed Windows binary doing something a system administrator might plausibly do. That is precisely what makes APT29 difficult — and precisely where signature-based defenses go blind.

A traditional antivirus has nothing to match: no malicious file, no known-bad hash, no exploit. reg.exe, net.exe, systeminfo and powershell.exe are all legitimate, and each individual command is benign in isolation — administrators dump no hives, but they do run net user and systeminfo every day. The malicious signal does not live in any single event. It lives in the sequence and the lineage: one parent process spawning a credential-hive dump, a Defender disable and a domain-wide discovery sweep within the same few seconds.

That is why reconstructing causality is not a cosmetic feature. A flat list of fourteen alerts invites an analyst to close them one at a time as low-value “admin activity”. Three process trees tell a story no single row can: these commands share a root, and that root is behaving like an intruder. Add the group's real-world habits — patient low-and-slow operations, abuse of legitimate credentials and cloud identity rather than exploits, and deliberate cleanup afterwards — and the lesson is that detecting Cozy Bear is a problem of correlation and behaviour, not of signatures.

Defensive takeaways

Four things to take away

Concrete, vendor-neutral steps that would surface this exact batch on any estate.

1. Capture command lines, or you see none of this

Deploy Sysmon (or an EDR) with a tuned config that records process creation with the full command line, registry save/export, and image loads — and turn on PowerShell script-block logging. Without command-line capture, every detection in this report is invisible: the difference between reg save HKLM\SAM and a harmless reg query lives entirely in the arguments.

2. Treat sensitive-hive access as critical, always

Alert on any process copying or exporting HKLM\SAM, HKLM\SYSTEM or HKLM\SECURITY, and on access to ntds.dit via vssadmin, esentutl or shadow copies. There is no legitimate reason for a workstation to do this; score it high regardless of which account or tool performed it.

3. Make Defender tampering a high-severity event

An adversary disabling real-time monitoring (Set-MpPreference) or adding exclusions (Add-MpPreference -ExclusionPath) is a pre-attack tell, not a configuration note. Watch the policy registry keys as well — turning the control off and carving an exclusion are the two halves of the same move.

4. Correlate discovery by lineage, not by command

A single net, nltest or whoami is noise. The same parent spawning all of them — plus systeminfo and a reg query — within seconds is the reconnaissance signature. Group alerts by process ancestry before deciding severity, which is exactly what let THRONE collapse fourteen alerts into three incidents an analyst can actually work.