AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
APT1
Aliases: Comment Crew, Comment Group, Comment Panda
APT1 is a Chinese threat group that has been attributed to the 2nd Bureau of the People’s Liberation Army (PLA) General Staff Department’s (GSD) 3rd Department, commonly known by its Military Unit Cover Designator (MUCD) as Unit 61398.
Open interactive actor investigation
ATT&CK techniques
LSASS MemoryT1057
Process DiscoveryT1005
Data from Local SystemT1550.002
Pass the HashT1583.001
DomainsT1560.001
Archive via UtilityT1119
Automated CollectionT1114.002
Remote Email CollectionT1566.002
Spearphishing LinkT1016
System Network Configuration DiscoveryT1114.001
Local Email CollectionT1588.001
MalwareT1049
System Network Connections DiscoveryT1585.002
Email AccountsT1584.001
DomainsT1036.005
Match Legitimate Name or LocationT1087.001
Local AccountT1566.001
Spearphishing AttachmentT1135
Network Share DiscoveryT1059.003
Windows Command ShellT1588.002
ToolT1007
System Service DiscoveryT1021.001
Remote Desktop ProtocolT1059
Command and Scripting Interpreter
Correlated CTI and IR reports
Continue the investigation
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Cyber Threat Intelligence (CTI) · explicit-idModule 3 — Core Frameworks Models
Cyber Threat Intelligence (CTI) · explicit-idModule 8 — Operationalizing CTI (CTI → Detection)
Cyber Threat Intelligence (CTI) · explicit-idModule 4 — Collection Sources
Cyber Threat Intelligence (CTI) · explicit-nameModule 5 — Analysis Techniques Tradecraft
Cyber Threat Intelligence (CTI) · explicit-nameModule 7 — Intelligence Products Sharing
Cyber Threat Intelligence (CTI) · explicit-nameModule 9 — Tools of the Trade
Cyber Threat Intelligence (CTI) · explicit-nameModule 2 — Reconnaissance and attack-surface mapping
Red Team & Offensive Security · explicit-nameModule 6 — Active Directory and identity attack paths
Red Team & Offensive Security · explicit-nameModule 13 — Red-team infrastructure and operations
Red Team & Offensive Security · explicit-nameNetwork behavior, protocols, and configuration recovery
Malware Analysis & Reverse Engineering · explicit-nameShared responsibility, governance, and service ownership
Cloud Security · explicit-name