Microsoft
Octo Tempest analysis covering extortion, encryption and destruction activity.
Adversary Simulation
A collaborative purple team exercise running around 70 test cases drawn from Scattered Spider's published tactics, across the full lifecycle of their attacks.
Discuss an engagementScattered Spider (also tracked as Octo Tempest, UNC3944, Starfraud, Scatter Swine and Muddled Libra) is a financially motivated group whose methods are unusually well documented. That makes them a practical benchmark: the tactics are published, so your controls can be measured against them one technique at a time.
This is a collaborative exercise, not a covert one. SilentGrid operators work alongside your security team to execute scenarios covering the full lifecycle of a typical Scattered Spider attack, assessing for each test case whether your current controls prevent it, detect it, or neither.
Your team uses their own tooling throughout, in a safe and controlled setting. The result is a clear picture of where controls hold, where telemetry exists but no alert fires, and where nothing is seen at all.
Scenarios and test cases are derived from published threat intelligence rather than from assumptions about how the group operates. The sources are named in the report so findings can be traced back to them.
Octo Tempest analysis covering extortion, encryption and destruction activity.
Advisory AA23-320A on Scattered Spider tactics, techniques and procedures.
UNC3944 hardening recommendations, and reporting on SMS phishing, SIM swapping and ransomware.
LUCR-3 research on the group's activity across SaaS and cloud environments.
It suits organisations with a security team able to take part, who want technique-level evidence of what their controls cover.
A Scattered Spider emulation fits when
Six scenarios covering the full lifecycle of a typical attack, from reconnaissance to an administrator account.
A purple team exercise depends on your side taking part. A nominated point of contact should expect to give it roughly an hour a day.
A business-as-usual account, a help desk account, and an account representative of a privileged systems administrator.
A corporate end-user device, and network access matching what each of those three roles would normally have.
Someone available each day to keep the exercise moving, whether or not the nominated contact is free.
Evidence relating to detections uploaded promptly. Where evidence is not provided in time, a technique may default to undetected.
Reviewing tooling and telemetry to establish whether an undetected technique was nonetheless captured somewhere.
A shared chat for the duration, provisioned by SilentGrid or an equivalent you prefer.
An emulation measures logging, detection and prevention for specific techniques in isolation. It is worth being clear about what that does not tell you.
Because the exercise is collaborative, it cannot show how the organisation would respond under the pressure of a real incident. Red teaming answers that question.
Coverage reflects the techniques the group has used to date. A future campaign may not look like the published record.
Each test case is assessed on its own. Strong coverage across individual techniques is not the same as stopping a full attack chain.
Where account provisioning or environment constraints delay the work, SilentGrid agrees with you which test cases to prioritise.
Run it continuously
A single emulation shows which Scattered Spider techniques your controls prevent, detect or miss. Where identity and help desk processes keep changing, CAOS (Continuous Adversary Operations Service) can run intelligence-led cycles through the year and replay earlier test cases to show whether detection has improved.
Explore CAOSEvery test case is reported with its technical detail and result, so coverage can be audited rather than taken on trust.
A high-level overview of the exercise, its objective, the results and the recommendations.
Threat intelligence summary, the scenarios run, concessions applied, positive observations and a recommendations summary.
Detailed findings describing each security issue, the risk it presents and how to remediate it.
The technical detail and result of every executed test case, so coverage is auditable rather than asserted.
A 60 to 90 minute report walkthrough for technical stakeholders, with time for questions.
SilentGrid's consultants are hand-picked, and between them they have delivered red team engagements globally over decades, including CBEST for UK financial institutions and CORIE engagements in Australia. Their sector experience covers banking and financial services, insurance, government, critical infrastructure and healthcare.
Consultants find 0-day vulnerabilities in commercial software and speak or teach at security conferences. That research produces the custom tooling used to bypass EDR and network controls, and keeps techniques current with the threat actor being simulated. The methodology follows concepts set out in NIST, OWASP, PTES and OSSTMM.
CREST ANZApproved company Individual credentials across our team include
A Scattered Spider adversary emulation tests an organisation's controls the way that group attacks: around 70 test cases drawn from published threat intelligence, run across six scenarios from reconnaissance and a simulated SIM swap to compromised help desk and administrator accounts. It is a collaborative purple team exercise, and each technique is recorded as prevented, detected or neither.
No. It is a collaborative purple team exercise. Your security team knows it is running and takes part throughout, using their own tooling to detect and prevent the techniques as they are executed. If you want to know how the organisation responds without warning, red teaming is the engagement for that.
Around 70, derived from individual tactics, techniques and procedures the group has used. Together the scenarios span the full lifecycle of a typical attack, from reconnaissance through to exfiltration.
Typically four to five weeks. Where the environment, account provisioning or unexpected delays mean not every test case can be executed in that window, SilentGrid works with you to decide which ones matter most.
Published threat intelligence on the group, including Microsoft's Octo Tempest analysis, CISA advisory AA23-320A, Google Cloud's UNC3944 reporting and Permiso's LUCR-3 research. The sources are cited so findings can be traced back to them.
Nominate a point of contact who can give the exercise about an hour a day, attend a regular stand-up, upload evidence of detections promptly, and retrospectively review tooling to establish whether an undetected technique was captured somewhere. Where evidence is not supplied in time, a technique may be recorded as undetected.
No. A SilentGrid consultant's phone number is assigned to the test account with your agreement, which reproduces the effect of a SIM swap without involving a carrier or a real person's service.
A report covering an executive summary, a technical summary with the threat intelligence behind the scenarios, detailed findings, and the technical result of every test case. A 60 to 90 minute technical debrief walks your team through it.
Ready to measure your coverage?
Agree the accounts and access needed, confirm the scenarios that matter for your environment, and plan the exercise around your security team.