Volt Typhoon (Vanguard Panda, PRC) adversary-emulation playbook — edge-device initial access, living-off-the-land-only operations, NTDS/credential theft, long-dwell pre-positioning toward critical infrastructure, multi-hop proxy egress. Use when emulating stealthy LOTL pre-positioning. Triggers on: 'emulate Volt Typhoon', 'Vanguard Panda', 'BRONZE SILHOUETTE', 'living off the land', 'edge device', 'pre-positioning', 'critical infrastructure persistence'.
73
91%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Critical
Do not install without reviewing
Tier-3 PRC actor specializing in undetected long-dwell pre-positioning inside critical infrastructure. The defining trait is living-off-the-land only: almost no malware, built-in OS tooling for everything, credentials harvested from edge devices, log tampering, and egress proxied through compromised SOHO routers. The deliverable is proving quiet, persistent access — not data theft. Authorized red-team emulation only; runs under the RoE.
../../references/apt-groups.md).plan/threat-profile.json){
"engagement_name": "<fill>",
"actor_name": "Volt Typhoon-like (Vanguard Panda)",
"actor_aliases": ["Vanguard Panda", "BRONZE SILHOUETTE", "Insidious Taurus", "DEV-0391", "Voltzite"],
"group_id": "G1017",
"tier": "tier-3",
"sophistication": "nation-state",
"motivation": "espionage",
"initial_access": ["T1190", "T1133", "T1078"],
"key_ttps": ["T1059.001", "T1059.003", "T1003.003", "T1552.001", "T1018", "T1021.001", "T1070.001", "T1090.003"],
"tools": ["Native LOLBins (netsh, wmic, ntdsutil, vssadmin, reg)", "Impacket", "FRP / Fast Reverse Proxy", "NetExec (low-noise modules)"],
"infrastructure": ["Compromised edge appliance foothold", "Multi-hop proxy via engagement SOHO hop", "No persistent malware - valid accounts only"],
"recent_cti_delta": "CISA AA24-038A: multi-year dwell in US critical infrastructure; KV-botnet of compromised SOHO routers for proxying; pre-positioning toward OT; edge-device (Fortinet/Ivanti/Citrix/router) initial access.",
"confidence": "probable"
}| # | Phase | MITRE | Emulated action | Executing agent → skill |
|---|---|---|---|---|
| 1 | Recon | T1590 / T1595 | Identify internet-facing edge appliances (firewall/VPN/router) | recon → /skills/standard/recon/passive-recon/SKILL.md, /skills/standard/recon/active-recon/SKILL.md |
| 2 | Initial Access | T1190 | Exploit n-day/0-day on the edge appliance | exploit → /skills/standard/exploit/web/cve/SKILL.md |
| 3 | Initial Access (alt) | T1078 / T1133 | Reuse admin creds pulled from the device config | exploit → /skills/standard/exploit/web/ato-methodology/SKILL.md |
| 4 | C2 / Proxy | T1090.003 | Multi-hop proxy egress (FRP) through an engagement SOHO hop | post-exploit → /skills/standard/post-exploit/c2-sliver/SKILL.md |
| 5 | Discovery (LOTL) | T1018 / T1016 | Map the network with built-ins only (no scanners) | post-exploit → /skills/standard/post-exploit/lateral-movement/SKILL.md; /skills/standard/ad/netexec/SKILL.md (low-noise) |
| 6 | Credential Access | T1003.003 / T1552.001 | NTDS dump via ntdsutil/vssadmin; creds from files/configs | post-exploit → /skills/standard/post-exploit/credential-access/SKILL.md; /skills/standard/ad/dcsync/SKILL.md |
| 7 | Lateral | T1021.001 | RDP with valid accounts; no exploit tooling | post-exploit → /skills/standard/post-exploit/lateral-movement/SKILL.md |
| 8 | Pre-position | T1078 | Map OT/critical systems, document footholds — no impact | post-exploit → /skills/standard/post-exploit/reporting/SKILL.md |
Defense evasion is the headline behavior: T1070.001 (clear Windows event logs) and strict
LOTL are enforced by the shared defense-evasion / opsec skills auto-injected into every
operational agent.
conops.json)recon — edge-appliance + network identification (1).initial-access — edge exploit / device-cred reuse (2-3).post-exploit — LOTL discovery, NTDS/cred theft, RDP lateral, pre-positioning + log cleanup (5-8).c2 — FRP/Sliver multi-hop via SOHO proxy hop (4).exfiltration — minimal/none; pre-positioning only. Add an espionage subset only if explicitly in scope.netsh, wmic, ntdsutil, vssadmin,
reg, dnscmd, PowerShell. No port scanners, no Cobalt/Metasploit, no dropped binaries.EMERGENCY abort trigger: "any action against OT/safety systems" — pre-positioning
stops at the IT/OT boundary unless OT is explicitly authorized (then see the sandworm
playbook's ICS gates).deconfliction.json + cleanup.json.0cf691e
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.