Not part of a guided workflow —
Next best move:Open the platform atlas Atlas

Public threat intelligence · replay comparison

Known actors. Exact technique overlap. No attribution leap.

Public ATT&CK identities compared with the fictional Northstar replay by exact technique ID. A match is an instructional lead—not evidence that an actor targeted Northstar, a customer, or a vehicle.

Public context does not establish attributionSIMULATION — NO LIVE ACTIONS
Public identities
08
Shared techniques
09
Replay events
17
Official sources
08

8 OF 8 PUBLIC IDENTITIES · FIXTURE AL-BUILD-TRUST-1.1.0

  1. G0096

    APT41

    ATT&CK group

    ATT&CK describes a group assessed in public reporting as conducting espionage and financially motivated operations across multiple sectors.

    Public-source group identity. No relationship to Northstar, a customer, or a selected VIN is asserted.

    Also tracked as: Wicked Panda · Brass Typhoon · BARIUM

    MITRE ATT&CK · G0096

    Attack Lab relationship

    Exact technique IDs only · fixture evidence remains gated by replay position

    4 MATCHES

    T1195.002

    Compromise Software Supply Chain

    Initial Access · Exact ATT&CK technique overlap

    Replay mapping

    E08 · Build access

    The adversary waits for a legitimate build

    CI orchestrator

    E11 · Build interposition

    The helper observes the compiler invocation

    Endpoint telemetry · BLD-WIN-03

    E11A · Build interposition

    Selectivity check — correct product and expected source version

    CI orchestrator · BLD-WIN-03

    E15 · Build interposition

    Produced binary hash differs from the reproducible reference

    CI orchestrator · BLD-WIN-03

    E17 · Trusted release

    Trusted release — the ordinary workflow accepts the artifact

    CI orchestrator

    E20 · Trusted release

    Provenance record lacks the compile-input attestation

    Release system

    E24 · Downstream signal

    Marker string observed in the released artifact inventory

    Endpoint telemetry

    E29 · Investigation

    Provenance gap documented as the failed boundary

    Release system

    Evidence gates

    EV-BASE · E01EV-PROCTREE · E07EV-CI-JOB · E08EV-GIT · E09EV-FILEDIFF · E12EV-FIM · E12EV-BUILDLOG · E13EV-HASH · E15EV-SIGN · E19EV-PROVENANCE · E15EV-RELEASE · E22EV-CASE · E29

    Defensive tools: CI job ledger · Endpoint process telemetry · SLSA provenance verifier

    T1071.001

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Replay mapping

    E23 · Downstream signal

    Egress proxy records a first-seen destination from the build tier

    Egress proxy · BLD-WIN-03

    Evidence gates

    EV-RECON · E02EV-DNS · E04EV-PROCTREE · E07EV-CI-JOB · E08EV-FILEDIFF · E12EV-HASH · E15EV-NET · E23

    Defensive tool: Egress proxy telemetry

    T1071.004

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Replay mapping

    E04 · Reconnaissance

    Resolver log — reserved example domain queried

    DNS resolver · DEV-JUMP-07

    Evidence gates

    EV-BASE · E01EV-DNS · E04EV-PROCTREE · E07EV-CI-JOB · E08EV-GIT · E09EV-FILEDIFF · E12EV-BUILDLOG · E13EV-HASH · E15EV-PROVENANCE · E15EV-CASE · E29

    Defensive tool: DNS resolver telemetry

    T1070.004

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Replay mapping

    E14 · Build interposition

    Workspace restored to the committed state

    File integrity · BLD-WIN-03

    E16 · Build interposition

    Short-lived file mutation recorded, not alerted

    File integrity · BLD-WIN-03

    E28 · Investigation

    Transient workspace mutation recovered from raw records

    File integrity · BLD-WIN-03

    Evidence gates

    EV-BASE · E01EV-CI-JOB · E08EV-GIT · E09EV-FILEDIFF · E12EV-FIM · E12EV-BUILDLOG · E13EV-HASH · E15EV-PROVENANCE · E15EV-CASE · E29

    Defensive tool: File-integrity monitor

  2. G0035

    Dragonfly

    ATT&CK group

    ATT&CK documents a cyber-espionage group associated in public reporting with critical-infrastructure and supply-chain targeting.

    Public attribution is retained as ATT&CK context only; it does not attribute the replay or any vehicle state.

    Also tracked as: Energetic Bear · Crouching Yeti · Ghost Blizzard

    MITRE ATT&CK · G0035

    Attack Lab relationship

    Exact technique IDs only · fixture evidence remains gated by replay position

    3 MATCHES

    T1591.002

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Replay mapping

    E03 · Reconnaissance

    Release cadence is public

    Egress proxy

    Evidence gates

    EV-RECON · E02EV-DNS · E04EV-NET · E23

    Defensive tool: Egress proxy telemetry

    T1195.002

    Compromise Software Supply Chain

    Initial Access · Exact ATT&CK technique overlap

    Replay mapping

    E08 · Build access

    The adversary waits for a legitimate build

    CI orchestrator

    E11 · Build interposition

    The helper observes the compiler invocation

    Endpoint telemetry · BLD-WIN-03

    E11A · Build interposition

    Selectivity check — correct product and expected source version

    CI orchestrator · BLD-WIN-03

    E15 · Build interposition

    Produced binary hash differs from the reproducible reference

    CI orchestrator · BLD-WIN-03

    E17 · Trusted release

    Trusted release — the ordinary workflow accepts the artifact

    CI orchestrator

    E20 · Trusted release

    Provenance record lacks the compile-input attestation

    Release system

    E24 · Downstream signal

    Marker string observed in the released artifact inventory

    Endpoint telemetry

    E29 · Investigation

    Provenance gap documented as the failed boundary

    Release system

    Evidence gates

    EV-BASE · E01EV-PROCTREE · E07EV-CI-JOB · E08EV-GIT · E09EV-FILEDIFF · E12EV-FIM · E12EV-BUILDLOG · E13EV-HASH · E15EV-SIGN · E19EV-PROVENANCE · E15EV-RELEASE · E22EV-CASE · E29

    Defensive tools: CI job ledger · Endpoint process telemetry · SLSA provenance verifier

    T1070.004

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Replay mapping

    E14 · Build interposition

    Workspace restored to the committed state

    File integrity · BLD-WIN-03

    E16 · Build interposition

    Short-lived file mutation recorded, not alerted

    File integrity · BLD-WIN-03

    E28 · Investigation

    Transient workspace mutation recovered from raw records

    File integrity · BLD-WIN-03

    Evidence gates

    EV-BASE · E01EV-CI-JOB · E08EV-GIT · E09EV-FILEDIFF · E12EV-FIM · E12EV-BUILDLOG · E13EV-HASH · E15EV-PROVENANCE · E15EV-CASE · E29

    Defensive tool: File-integrity monitor

  3. G0046

    FIN7

    ATT&CK group

    ATT&CK describes a financially motivated group with public reporting across retail, hospitality, software, transportation, and other sectors.

    Technique overlap is a behavioral comparison, not a finding that FIN7 targeted this fixture or an automotive organization.

    Also tracked as: Carbon Spider · Sangria Tempest · GOLD NIAGARA

    MITRE ATT&CK · G0046

    Attack Lab relationship

    Exact technique IDs only · fixture evidence remains gated by replay position

    3 MATCHES

    T1591

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Replay mapping

    E02 · Reconnaissance

    Reconnaissance — reasoning about the environment, no intrusion

    Egress proxy

    Evidence gates

    EV-RECON · E02

    Defensive tool: Egress proxy telemetry

    T1195.002

    Compromise Software Supply Chain

    Initial Access · Exact ATT&CK technique overlap

    Replay mapping

    E08 · Build access

    The adversary waits for a legitimate build

    CI orchestrator

    E11 · Build interposition

    The helper observes the compiler invocation

    Endpoint telemetry · BLD-WIN-03

    E11A · Build interposition

    Selectivity check — correct product and expected source version

    CI orchestrator · BLD-WIN-03

    E15 · Build interposition

    Produced binary hash differs from the reproducible reference

    CI orchestrator · BLD-WIN-03

    E17 · Trusted release

    Trusted release — the ordinary workflow accepts the artifact

    CI orchestrator

    E20 · Trusted release

    Provenance record lacks the compile-input attestation

    Release system

    E24 · Downstream signal

    Marker string observed in the released artifact inventory

    Endpoint telemetry

    E29 · Investigation

    Provenance gap documented as the failed boundary

    Release system

    Evidence gates

    EV-BASE · E01EV-PROCTREE · E07EV-CI-JOB · E08EV-GIT · E09EV-FILEDIFF · E12EV-FIM · E12EV-BUILDLOG · E13EV-HASH · E15EV-SIGN · E19EV-PROVENANCE · E15EV-RELEASE · E22EV-CASE · E29

    Defensive tools: CI job ledger · Endpoint process telemetry · SLSA provenance verifier

    T1071.004

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Replay mapping

    E04 · Reconnaissance

    Resolver log — reserved example domain queried

    DNS resolver · DEV-JUMP-07

    Evidence gates

    EV-BASE · E01EV-DNS · E04EV-PROCTREE · E07EV-CI-JOB · E08EV-GIT · E09EV-FILEDIFF · E12EV-BUILDLOG · E13EV-HASH · E15EV-PROVENANCE · E15EV-CASE · E29

    Defensive tool: DNS resolver telemetry

  4. G0034

    Sandworm Team

    ATT&CK group

    ATT&CK records a destructive threat group attributed in cited government reporting to Russia's GRU unit 74455.

    Historical public attribution only. The Northstar exercise contains no actor-attribution evidence.

    Also tracked as: APT44 · Voodoo Bear · Seashell Blizzard

    MITRE ATT&CK · G0034

    Attack Lab relationship

    Exact technique IDs only · fixture evidence remains gated by replay position

    4 MATCHES

    T1591.002

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Replay mapping

    E03 · Reconnaissance

    Release cadence is public

    Egress proxy

    Evidence gates

    EV-RECON · E02EV-DNS · E04EV-NET · E23

    Defensive tool: Egress proxy telemetry

    T1195.002

    Compromise Software Supply Chain

    Initial Access · Exact ATT&CK technique overlap

    Replay mapping

    E08 · Build access

    The adversary waits for a legitimate build

    CI orchestrator

    E11 · Build interposition

    The helper observes the compiler invocation

    Endpoint telemetry · BLD-WIN-03

    E11A · Build interposition

    Selectivity check — correct product and expected source version

    CI orchestrator · BLD-WIN-03

    E15 · Build interposition

    Produced binary hash differs from the reproducible reference

    CI orchestrator · BLD-WIN-03

    E17 · Trusted release

    Trusted release — the ordinary workflow accepts the artifact

    CI orchestrator

    E20 · Trusted release

    Provenance record lacks the compile-input attestation

    Release system

    E24 · Downstream signal

    Marker string observed in the released artifact inventory

    Endpoint telemetry

    E29 · Investigation

    Provenance gap documented as the failed boundary

    Release system

    Evidence gates

    EV-BASE · E01EV-PROCTREE · E07EV-CI-JOB · E08EV-GIT · E09EV-FILEDIFF · E12EV-FIM · E12EV-BUILDLOG · E13EV-HASH · E15EV-SIGN · E19EV-PROVENANCE · E15EV-RELEASE · E22EV-CASE · E29

    Defensive tools: CI job ledger · Endpoint process telemetry · SLSA provenance verifier

    T1071.001

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Replay mapping

    E23 · Downstream signal

    Egress proxy records a first-seen destination from the build tier

    Egress proxy · BLD-WIN-03

    Evidence gates

    EV-RECON · E02EV-DNS · E04EV-PROCTREE · E07EV-CI-JOB · E08EV-FILEDIFF · E12EV-HASH · E15EV-NET · E23

    Defensive tool: Egress proxy telemetry

    T1070.004

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Replay mapping

    E14 · Build interposition

    Workspace restored to the committed state

    File integrity · BLD-WIN-03

    E16 · Build interposition

    Short-lived file mutation recorded, not alerted

    File integrity · BLD-WIN-03

    E28 · Investigation

    Transient workspace mutation recovered from raw records

    File integrity · BLD-WIN-03

    Evidence gates

    EV-BASE · E01EV-CI-JOB · E08EV-GIT · E09EV-FILEDIFF · E12EV-FIM · E12EV-BUILDLOG · E13EV-HASH · E15EV-PROVENANCE · E15EV-CASE · E29

    Defensive tool: File-integrity monitor

  5. G1023

    APT5

    ATT&CK group

    ATT&CK describes a China-based espionage actor with public reporting focused on telecommunications, aerospace, defense, and networking devices.

    Public-source identity only; shared techniques do not establish presence or targeting in the replay.

    Also tracked as: Mulberry Typhoon · Keyhole Panda · UNC2630

    MITRE ATT&CK · G1023

    Attack Lab relationship

    Exact technique IDs only · fixture evidence remains gated by replay position

    3 MATCHES

    T1554

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Replay mapping

    E11 · Build interposition

    The helper observes the compiler invocation

    Endpoint telemetry · BLD-WIN-03

    Evidence gates

    EV-BASE · E01EV-PROCTREE · E07EV-CI-JOB · E08EV-GIT · E09EV-FILEDIFF · E12EV-FIM · E12EV-BUILDLOG · E13EV-HASH · E15EV-PROVENANCE · E15EV-CASE · E29

    Defensive tool: Endpoint process telemetry

    T1078.004

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Replay mapping

    E05 · Build access

    Build access — an existing automation session is reused

    Identity · CI-ORCH-01

    E06 · Build access

    Automation identity used outside its schedule

    Identity · CI-ORCH-01

    Evidence gates

    EV-BASE · E01EV-IAM · E05EV-CI-JOB · E08EV-GIT · E09EV-BUILDLOG · E13EV-HASH · E15EV-PROVENANCE · E15EV-CASE · E29

    Defensive tool: Identity audit trail

    T1070.004

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Replay mapping

    E14 · Build interposition

    Workspace restored to the committed state

    File integrity · BLD-WIN-03

    E16 · Build interposition

    Short-lived file mutation recorded, not alerted

    File integrity · BLD-WIN-03

    E28 · Investigation

    Transient workspace mutation recovered from raw records

    File integrity · BLD-WIN-03

    Evidence gates

    EV-BASE · E01EV-CI-JOB · E08EV-GIT · E09EV-FILEDIFF · E12EV-FIM · E12EV-BUILDLOG · E13EV-HASH · E15EV-PROVENANCE · E15EV-CASE · E29

    Defensive tool: File-integrity monitor

  6. G0016

    APT29

    ATT&CK group

    ATT&CK describes a group attributed by cited US and UK government reporting to Russia's Foreign Intelligence Service.

    The SolarWinds precedent informs the lab theme, but this exact-ID join includes only current reviewed group relationships shared with the fixture.

    Also tracked as: NOBELIUM · Cozy Bear · Midnight Blizzard · UNC2452

    MITRE ATT&CK · G0016

    Attack Lab relationship

    Exact technique IDs only · fixture evidence remains gated by replay position

    2 MATCHES

    T1078.004

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Replay mapping

    E05 · Build access

    Build access — an existing automation session is reused

    Identity · CI-ORCH-01

    E06 · Build access

    Automation identity used outside its schedule

    Identity · CI-ORCH-01

    Evidence gates

    EV-BASE · E01EV-IAM · E05EV-CI-JOB · E08EV-GIT · E09EV-BUILDLOG · E13EV-HASH · E15EV-PROVENANCE · E15EV-CASE · E29

    Defensive tool: Identity audit trail

    T1070.004

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Replay mapping

    E14 · Build interposition

    Workspace restored to the committed state

    File integrity · BLD-WIN-03

    E16 · Build interposition

    Short-lived file mutation recorded, not alerted

    File integrity · BLD-WIN-03

    E28 · Investigation

    Transient workspace mutation recovered from raw records

    File integrity · BLD-WIN-03

    Evidence gates

    EV-BASE · E01EV-CI-JOB · E08EV-GIT · E09EV-FILEDIFF · E12EV-FIM · E12EV-BUILDLOG · E13EV-HASH · E15EV-PROVENANCE · E15EV-CASE · E29

    Defensive tool: File-integrity monitor

  7. G0007

    APT28

    ATT&CK group

    ATT&CK describes a long-running group attributed in cited public reporting to Russia's GRU unit 26165.

    This identity and its procedures are public-source context only; they do not attribute Northstar replay activity or VIN state.

    Also tracked as: Sofacy · Pawn Storm · Fancy Bear · Forest Blizzard

    MITRE ATT&CK · G0007

    Attack Lab relationship

    Exact technique IDs only · fixture evidence remains gated by replay position

    5 MATCHES

    T1591

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Replay mapping

    E02 · Reconnaissance

    Reconnaissance — reasoning about the environment, no intrusion

    Egress proxy

    Evidence gates

    EV-RECON · E02

    Defensive tool: Egress proxy telemetry

    T1596

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Replay mapping

    E02 · Reconnaissance

    Reconnaissance — reasoning about the environment, no intrusion

    Egress proxy

    Evidence gates

    EV-RECON · E02

    Defensive tool: Egress proxy telemetry

    T1078.004

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Replay mapping

    E05 · Build access

    Build access — an existing automation session is reused

    Identity · CI-ORCH-01

    E06 · Build access

    Automation identity used outside its schedule

    Identity · CI-ORCH-01

    Evidence gates

    EV-BASE · E01EV-IAM · E05EV-CI-JOB · E08EV-GIT · E09EV-BUILDLOG · E13EV-HASH · E15EV-PROVENANCE · E15EV-CASE · E29

    Defensive tool: Identity audit trail

    T1071.001

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Replay mapping

    E23 · Downstream signal

    Egress proxy records a first-seen destination from the build tier

    Egress proxy · BLD-WIN-03

    Evidence gates

    EV-RECON · E02EV-DNS · E04EV-PROCTREE · E07EV-CI-JOB · E08EV-FILEDIFF · E12EV-HASH · E15EV-NET · E23

    Defensive tool: Egress proxy telemetry

    T1070.004

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Replay mapping

    E14 · Build interposition

    Workspace restored to the committed state

    File integrity · BLD-WIN-03

    E16 · Build interposition

    Short-lived file mutation recorded, not alerted

    File integrity · BLD-WIN-03

    E28 · Investigation

    Transient workspace mutation recovered from raw records

    File integrity · BLD-WIN-03

    Evidence gates

    EV-BASE · E01EV-CI-JOB · E08EV-GIT · E09EV-FILEDIFF · E12EV-FIM · E12EV-BUILDLOG · E13EV-HASH · E15EV-PROVENANCE · E15EV-CASE · E29

    Defensive tool: File-integrity monitor

  8. G0032

    Lazarus Group

    ATT&CK group

    ATT&CK describes a North Korean state-sponsored group attributed in cited public reporting to the Reconnaissance General Bureau.

    Historical public attribution only. Technique overlap does not establish presence, targeting, or impact in the synthetic replay.

    Also tracked as: Labyrinth Chollima · HIDDEN COBRA · Guardians of Peace · Diamond Sleet

    MITRE ATT&CK · G0032

    Attack Lab relationship

    Exact technique IDs only · fixture evidence remains gated by replay position

    3 MATCHES

    T1591

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Replay mapping

    E02 · Reconnaissance

    Reconnaissance — reasoning about the environment, no intrusion

    Egress proxy

    Evidence gates

    EV-RECON · E02

    Defensive tool: Egress proxy telemetry

    T1071.001

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Replay mapping

    E23 · Downstream signal

    Egress proxy records a first-seen destination from the build tier

    Egress proxy · BLD-WIN-03

    Evidence gates

    EV-RECON · E02EV-DNS · E04EV-PROCTREE · E07EV-CI-JOB · E08EV-FILEDIFF · E12EV-HASH · E15EV-NET · E23

    Defensive tool: Egress proxy telemetry

    T1070.004

    Reviewed ATT&CK technique

    Instructional lead · Exact ATT&CK technique overlap

    Replay mapping

    E14 · Build interposition

    Workspace restored to the committed state

    File integrity · BLD-WIN-03

    E16 · Build interposition

    Short-lived file mutation recorded, not alerted

    File integrity · BLD-WIN-03

    E28 · Investigation

    Transient workspace mutation recovered from raw records

    File integrity · BLD-WIN-03

    Evidence gates

    EV-BASE · E01EV-CI-JOB · E08EV-GIT · E09EV-FILEDIFF · E12EV-FIM · E12EV-BUILDLOG · E13EV-HASH · E15EV-PROVENANCE · E15EV-CASE · E29

    Defensive tool: File-integrity monitor