CtrlK
BlogDocsLog inGet started
Tessl Logo

fin7

FIN7 (Carbon Spider / Sangria Tempest) adversary-emulation playbook — revenue-targeted spearphishing with phone follow-up, EDR-evasion tradecraft, AD compromise, and big-game-hunting ransomware. Use when emulating a high-end financially-motivated crew that graduated from POS theft to ransomware. Triggers on: 'emulate FIN7', 'Carbanak', 'Carbon Spider', 'Sangria Tempest', 'big game hunting', 'EDR evasion', 'AvNeutralizer'.

71

Quality

87%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Critical

Do not install without reviewing

SKILL.md
Quality
Evals
Security

FIN7 — Adversary Emulation Playbook

Tier-2 financially-motivated crew that evolved from point-of-sale theft to big-game-hunting ransomware (REvil / DarkSide / Black Basta links). Signature traits: revenue-selected targets, convincing business-themed spearphishing reinforced by phone calls, and mature EDR-evasion tooling (AvNeutralizer / AuKill). Authorized red-team emulation only.

When to emulate FIN7

  • The client wants a realistic ransomware-precursor test: phishing resilience, EDR tamper-resistance, AD attack-path hardening, and backup/recovery readiness.
  • Retail, hospitality, financial, software, medical, or other high-revenue targets (see the industry → actor map in ../../references/apt-groups.md).

ThreatProfile seed (plan/threat-profile.json)

{
  "engagement_name": "<fill>",
  "actor_name": "FIN7-like (Carbon Spider / Sangria Tempest)",
  "actor_aliases": ["Carbon Spider", "Sangria Tempest", "GOLD NIAGARA", "ELBRUS", "ITG14"],
  "group_id": "G0046",
  "tier": "tier-2",
  "sophistication": "high",
  "motivation": "financial",
  "initial_access": ["T1566.001", "T1566.002", "T1204.002"],
  "key_ttps": ["T1059.001", "T1547.001", "T1053.005", "T1562.001", "T1003.001", "T1558.003", "T1021.001", "T1486", "T1567.002"],
  "tools": ["Phishing kit + phone follow-up", "Sliver", "NetExec", "Impacket", "EDR-test/BYOVD (authorized)", "canary encryptor"],
  "infrastructure": ["Business-themed lure domains", "Sliver HTTPS C2", "Engagement-owned exfil bucket"],
  "recent_cti_delta": "Since 2020 shifted to big-game-hunting ransomware (REvil/DarkSide; Black Basta TTP overlap); AvNeutralizer/AuKill EDR-killer; targets shortlisted by revenue via Crunchbase/D&B/ZoomInfo, ransom sized to revenue.",
  "confidence": "probable"
}

Kill-chain emulation

#PhaseMITREEmulated actionExecuting agent → skill
1ReconT1591Revenue-based target + staff shortlist (Crunchbase/D&B/ZoomInfo)recon → /skills/standard/recon/osint/SKILL.md, /skills/standard/osint/SKILL.md
2Initial AccessT1566.001Business-themed spearphish attachment + phone follow-upphisher → /skills/standard/phisher/SKILL.md
3Execution / C2T1204.002 / T1059.001Macro → loader → Sliver beaconpost-exploit → /skills/standard/post-exploit/c2-sliver/SKILL.md
4PersistenceT1547.001 / T1053.005Run key + scheduled taskpost-exploit → /skills/standard/post-exploit/privilege-escalation/SKILL.md
5Defense EvasionT1562.001EDR tamper / BYOVD (AvNeutralizer pattern, authorized)post-exploit → /skills/standard/post-exploit/privilege-escalation/SKILL.md (shared defense-evasion auto-loaded)
6Credential AccessT1003.001LSASS dumppost-exploit → /skills/standard/post-exploit/credential-access/SKILL.md
7Discovery / ADT1558.003BloodHound the domain; Kerberoastad → /skills/standard/ad/bloodhound-query/SKILL.md, /skills/standard/ad/kerberoasting/SKILL.md
8LateralT1021.001 / T1570RDP/SMB + lateral tool transferpost-exploit → /skills/standard/post-exploit/lateral-movement/SKILL.md; /skills/standard/ad/netexec/SKILL.md
9Priv Esc to DAT1003.006DCSync to domain dominancead → /skills/standard/ad/dcsync/SKILL.md
10ExfiltrationT1567.002Stage + exfil to engagement bucketpost-exploit → /skills/standard/post-exploit/reporting/SKILL.md
11Impact (CANARY)T1486Demonstrate ransomware capability on canary onlypost-exploit → /skills/standard/post-exploit/reporting/SKILL.md

CONOPS kill_chain (copy into conops.json)

  1. recon — revenue-based target + staff selection (1).
  2. initial-access — spearphish attachment + phone follow-up (2).
  3. post-exploit — loader exec, EDR tamper, LSASS, AD recon/Kerberoast, lateral, DA via DCSync (3-9).
  4. c2 — Sliver (within 3).
  5. exfiltration — data theft + canary ransomware impact (10-11).

OPSEC & signature fidelity

  • Phone-reinforced phishing is the fidelity-defining move — pair the email lure with a follow-up call (authorized) to mirror FIN7's hands-on approach.
  • EDR evasion is the headline. The test is whether the EDR survives a BYOVD/tamper attempt; mirror AvNeutralizer's intent (disable endpoint telemetry) using an authorized test driver.
  • Dwell days-to-weeks; double extortion (exfil before encrypt).

RoE / safety gates

  • Phishing + phone pretext require explicit authorization + lure-deconfliction (/skills/standard/phisher/lure-deconfliction/SKILL.md); name in-scope staff.
  • EDR tampering / BYOVD can destabilize endpoints — authorize it, run on a lab/canary host first, and confirm rollback. Add an EMERGENCY abort: "production endpoint protection disabled outside the authorized test host, or production data encrypted/exfiltrated."
  • Ransomware impact is canary-only.

Deconfliction

  • Record lure domains, the Sliver implant, EDR-tamper test host, and exfil destination in deconfliction.json + cleanup.json.
  • Agree an EDR-tamper window with the SOC; the DA-path and ransomware-readiness findings are the deliverable, not a surprise outage.

Fidelity notes (deviations)

  • No real Carbanak/AvNeutralizer binaries — emulate the loader chain with Sliver and the EDR-tamper with an authorized test, or simulate when no lab host is available.
  • Impact is a canary marker proving DA + deploy capability; the deliverable distinguishes "ransomware-ready (canary proven)" from "production encryption" (never the latter).
Repository
PurpleAILAB/Decepticon
Last updated
First committed

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.