AdversaryGraph public intelligence page
This page is part of Threat Matrix, the public browser workspace for the main AdversaryGraph platform. Use it for ATT&CK pivots, actor and technique context, similarity leads, detection coverage review, and analyst-ready investigation paths.
Validation disclaimer: TTP overlap, actor similarity, generated summaries, and coverage findings are investigation leads, not attribution proof or operational validation without analyst review.
Main AdversaryGraph project Documentation Malware Analysis GitHub
Windshift
Aliases: Bahamut
Windshift is a threat group that has been active since at least 2017, targeting specific individuals for surveillance in government departments and critical infrastructure across the Middle East.
Open interactive actor investigation
ATT&CK techniques
Process DiscoveryT1189
Drive-by CompromiseT1059.005
Visual BasicT1518.001
Security Software DiscoveryT1566.001
Spearphishing AttachmentT1204.001
Malicious LinkT1566.003
Spearphishing via ServiceT1547.001
Registry Run Keys / Startup FolderT1518
Software DiscoveryT1566.002
Spearphishing LinkT1036.001
Invalid Code SignatureT1027
Obfuscated Files or InformationT1071.001
Web ProtocolsT1036
MasqueradingT1105
Ingress Tool TransferT1047
Windows Management InstrumentationT1033
System Owner/User DiscoveryT1082
System Information DiscoveryT1204.002
Malicious File
Correlated CTI and IR reports
Continue the investigation
Cyber Knowledge routes
These contextual routes explain behaviors associated with this ATT&CK group record. They support learning and investigation planning; they do not add attribution evidence.
Red Team & Offensive Security · topic-matchModule 6 — Alert triage, investigation, and escalation
Blue Team & Defensive Security · topic-matchModule 10 — Cloud, containers, Kubernetes, and SaaS defense
Blue Team & Defensive Security · topic-matchPublic code, packages, cloud artifacts, documents, and exposed secrets
OSINT & Reconnaissance · topic-matchSecure AI development lifecycle and production release gate
AI Security · topic-matchModule 2 — The Intelligence Cycle Intelligence Types
Cyber Threat Intelligence (CTI) · topic-matchModule 8 — Operationalizing CTI (CTI → Detection)
Cyber Threat Intelligence (CTI) · topic-matchWeakness taxonomy and vulnerability identity
Vulnerability Research & Exploit Development · topic-matchModule 2 — Asset, service, identity, and exposure context
Blue Team & Defensive Security · topic-matchModule 7 — Endpoint defense and EDR
Blue Team & Defensive Security · topic-matchModule 9 — Identity defense and ITDR
Blue Team & Defensive Security · topic-matchWeb, API, mobile, and application reconnaissance
OSINT & Reconnaissance · topic-match