1200KM / simulation
T1570 Lateral Tool Transfer — Attack Simulation
Adversaries may transfer tools or other files between systems in a compromised environment. Once brought into the victim environment (i.e., Ingress Tool Transfer) files may then be copied from one system to another to stage adversary tools or other files over the course of an operation. Adversaries may copy files between internal victim systems to support lateral movement using inherent file sharing protocols such as file sharing over…
Technique description
Adversaries may transfer tools or other files between systems in a compromised environment. Once brought into the victim environment (i.e., Ingress Tool Transfer) files may then be copied from one system to another to stage adversary tools or other files over the course of an operation. Adversaries may copy files between internal victim systems to support lateral movement using inherent file sharing protocols such as file sharing over…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Exfiltration Over SMB over QUIC (NET USE)
Procedure 183235ca-8e6c-422c-88c2-3aa28c4825d9; elevation required; cleanup not declared. Not executed or individually validated.
- Exfiltration Over SMB over QUIC (New-SmbMapping)
Procedure d8d13303-159e-4f33-89f4-9f07812d016f; elevation required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Turla · G0010
- Sandworm Team · G0034
- APT32 · G0050
- FIN10 · G0051
- Magic Hound · G0059
- GALLIUM · G0093
- APT41 · G0096
- Wizard Spider · G0102
- Chimera · G0114
- Ember Bear · G1003
- Aoqin Dragon · G1007
- Volt Typhoon · G1017
- Agrius · G1030
- INC Ransom · G1032
- BlackByte · G1043
- Storm-1811 · G1046
- Velvet Ant · G1047
- UNC3886 · G1048
- Medusa Group · G1051
Existing research
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.