Adversary Simulation

Scattered Spider Adversary Emulation

A collaborative purple team exercise running around 70 test cases drawn from Scattered Spider's published tactics, across the full lifecycle of their attacks.

Discuss an engagement
Objective
Test controls against one actor
Maturity
A security team to work alongside
Approach
Collaborative purple team
Result
Prevented, detected or neither

Scattered Spider (also tracked as Octo Tempest, UNC3944, Starfraud, Scatter Swine and Muddled Libra) is a financially motivated group whose methods are unusually well documented. That makes them a practical benchmark: the tactics are published, so your controls can be measured against them one technique at a time.

This is a collaborative exercise, not a covert one. SilentGrid operators work alongside your security team to execute scenarios covering the full lifecycle of a typical Scattered Spider attack, assessing for each test case whether your current controls prevent it, detect it, or neither.

Your team uses their own tooling throughout, in a safe and controlled setting. The result is a clear picture of where controls hold, where telemetry exists but no alert fires, and where nothing is seen at all.

Where the scenarios come from

Scenarios and test cases are derived from published threat intelligence rather than from assumptions about how the group operates. The sources are named in the report so findings can be traced back to them.

Microsoft

Octo Tempest analysis covering extortion, encryption and destruction activity.

CISA

Advisory AA23-320A on Scattered Spider tactics, techniques and procedures.

Google Cloud

UNC3944 hardening recommendations, and reporting on SMS phishing, SIM swapping and ransomware.

Permiso

LUCR-3 research on the group's activity across SaaS and cloud environments.

Is a Scattered Spider emulation the right fit?

It suits organisations with a security team able to take part, who want technique-level evidence of what their controls cover.

A Scattered Spider emulation fits when

  • A security team is in place and able to take part day to day
  • Identity, endpoint and cloud controls are deployed and you want them measured
  • Help desk processes handle account and MFA changes
  • You want to know which specific techniques are covered, not a general assurance

The scenarios

Six scenarios covering the full lifecycle of a typical attack, from reconnaissance to an administrator account.

  1. 01

    Discovery and resource development

    • Reconnaissance to build a picture of the organisation's external attack surface
    • Registration of a look-alike domain for use in later phishing test cases
  2. 02

    Compromised user credentials

    • Techniques used after obtaining the username and password of a business-as-usual account
    • Attempts to reach internet-facing systems and services
    • Multi-factor authentication bypasses, and discovery where possible
  3. 03

    Compromised credentials and SIM swap

    • A consultant's phone number is assigned to the account to simulate a SIM swap
    • Test cases probe whether phone-based authentication can be used to authenticate or reset credentials
  4. 04

    Compromised credentials, device and MFA

    • Assumes the account, end-user device and a factor of authentication are all under the actor's control
    • Focuses on discovery of cloud and on-premises assets, credential access and persistence
  5. 05

    Compromised help desk credentials

    • Scattered Spider frequently target help desk staff after an initial compromise
    • Test cases cover further discovery, credential access, persistence and privilege escalation from a help desk profile
  6. 06

    Compromised IT administrator account

    • The later stages of the group's attacks, spanning cloud and on-premises assets
    • Techniques requiring higher privileges, including hypervisor access, credential dumping on domain controllers and simulated exfiltration

What we need from you

A purple team exercise depends on your side taking part. A nominated point of contact should expect to give it roughly an hour a day.

Representative accounts

A business-as-usual account, a help desk account, and an account representative of a privileged systems administrator.

Representative access

A corporate end-user device, and network access matching what each of those three roles would normally have.

Daily stand-up

Someone available each day to keep the exercise moving, whether or not the nominated contact is free.

Detection evidence

Evidence relating to detections uploaded promptly. Where evidence is not provided in time, a technique may default to undetected.

Retrospective review

Reviewing tooling and telemetry to establish whether an undetected technique was nonetheless captured somewhere.

A channel to work in

A shared chat for the duration, provisioned by SilentGrid or an equivalent you prefer.

What an emulation cannot tell you

An emulation measures logging, detection and prevention for specific techniques in isolation. It is worth being clear about what that does not tell you.

Your team knows it is happening

Because the exercise is collaborative, it cannot show how the organisation would respond under the pressure of a real incident. Red teaming answers that question.

Actors change

Coverage reflects the techniques the group has used to date. A future campaign may not look like the published record.

Techniques, not campaigns

Each test case is assessed on its own. Strong coverage across individual techniques is not the same as stopping a full attack chain.

Scheduling shapes coverage

Where account provisioning or environment constraints delay the work, SilentGrid agrees with you which test cases to prioritise.

Run it continuously

Emulate them once, or keep testing all year.

A single emulation shows which Scattered Spider techniques your controls prevent, detect or miss. Where identity and help desk processes keep changing, CAOS (Continuous Adversary Operations Service) can run intelligence-led cycles through the year and replay earlier test cases to show whether detection has improved.

Explore CAOS

Deliverables and reporting

Every test case is reported with its technical detail and result, so coverage can be audited rather than taken on trust.

Executive summary

A high-level overview of the exercise, its objective, the results and the recommendations.

Technical summary

Threat intelligence summary, the scenarios run, concessions applied, positive observations and a recommendations summary.

Findings

Detailed findings describing each security issue, the risk it presents and how to remediate it.

Test case results

The technical detail and result of every executed test case, so coverage is auditable rather than asserted.

Technical debrief

A 60 to 90 minute report walkthrough for technical stakeholders, with time for questions.

Why SilentGrid

SilentGrid's consultants are hand-picked, and between them they have delivered red team engagements globally over decades, including CBEST for UK financial institutions and CORIE engagements in Australia. Their sector experience covers banking and financial services, insurance, government, critical infrastructure and healthcare.

Consultants find 0-day vulnerabilities in commercial software and speak or teach at security conferences. That research produces the custom tooling used to bypass EDR and network controls, and keeps techniques current with the threat actor being simulated. The methodology follows concepts set out in NIST, OWASP, PTES and OSSTMM.

CREST ANZApproved company

Individual credentials across our team include

  • OSEE
  • OSCE3
  • OSED
  • OSEP
  • OSWE
  • GXPN
  • CRTO
  • CRTE
  • CRTP
  • OSCP
Meet the team

Common questions

What is a Scattered Spider adversary emulation?

A Scattered Spider adversary emulation tests an organisation's controls the way that group attacks: around 70 test cases drawn from published threat intelligence, run across six scenarios from reconnaissance and a simulated SIM swap to compromised help desk and administrator accounts. It is a collaborative purple team exercise, and each technique is recorded as prevented, detected or neither.

Is this a red team exercise?

No. It is a collaborative purple team exercise. Your security team knows it is running and takes part throughout, using their own tooling to detect and prevent the techniques as they are executed. If you want to know how the organisation responds without warning, red teaming is the engagement for that.

How many test cases are run?

Around 70, derived from individual tactics, techniques and procedures the group has used. Together the scenarios span the full lifecycle of a typical attack, from reconnaissance through to exfiltration.

How long does it take?

Typically four to five weeks. Where the environment, account provisioning or unexpected delays mean not every test case can be executed in that window, SilentGrid works with you to decide which ones matter most.

Where do the scenarios come from?

Published threat intelligence on the group, including Microsoft's Octo Tempest analysis, CISA advisory AA23-320A, Google Cloud's UNC3944 reporting and Permiso's LUCR-3 research. The sources are cited so findings can be traced back to them.

What does our team need to do?

Nominate a point of contact who can give the exercise about an hour a day, attend a regular stand-up, upload evidence of detections promptly, and retrospectively review tooling to establish whether an undetected technique was captured somewhere. Where evidence is not supplied in time, a technique may be recorded as undetected.

Do you actually perform a SIM swap?

No. A SilentGrid consultant's phone number is assigned to the test account with your agreement, which reproduces the effect of a SIM swap without involving a carrier or a real person's service.

What do we receive at the end?

A report covering an executive summary, a technical summary with the threat intelligence behind the scenarios, detailed findings, and the technical result of every test case. A 60 to 90 minute technical debrief walks your team through it.

Ready to measure your coverage?

Get started with a Scattered Spider emulation

Agree the accounts and access needed, confirm the scenarios that matter for your environment, and plan the exercise around your security team.