THEGENTLEMEN
Predicted CVEs (7) CORRELATION
How does prediction work?
Predicted CVEs are identified through automated correlation using multiple sources: vendor/product profiles historically targeted by the group (MITRE ATT&CK), attack chain patterns (KEV + TTPs), threat intelligence (MISP, STIX), and AI analysis. These CVEs have not been confirmed as exploited by this specific group, but have a high probability of being targets based on the actor's operational profile.
ATT&CK Techniques (56)
T1078
Valid Accounts
Initial Access
T1078.002
Valid Accounts: Domain Accounts
Initial Access
T1133
External Remote Services
Initial Access
T1190
Exploit Public-Facing Application
Initial Access
T1566
Phishing
Initial Access
T1047
Windows Management Instrumentation
Execution
T1059
Command and Scripting Interpreter
Execution
T1059.001
Command and Scripting Interpreter: PowerShell
Execution
T1059.003
Command and Scripting Interpreter: Windows Command Shell
Execution
T1072
Software Deployment Tools
Execution
T1136
Create Account
Persistence
T1543
Create or Modify System Process
Persistence
T1547
Boot or Logon Autostart Execution
Persistence
T1068
Exploitation for Privilege Escalation
Privilege Escalation
T1187
Forced Authentication
Privilege Escalation
T1557
Adversary-in-the-Middle
Privilege Escalation
T1027
Obfuscated Files or Information
Defense Evasion
T1070
Indicator Removal
Defense Evasion
T1090
Proxy
Defense Evasion
T1112
Modify Registry
Defense Evasion
T1484.001
Domain Policy Modification: Group Policy Modification
Defense Evasion
T1562
Impair Defenses
Defense Evasion
T1562.001
Impair Defenses: Disable or Modify Tools
Defense Evasion
T1003
OS Credential Dumping
Credential Access
T1110
Brute Force
Credential Access
T1552
Unsecured Credentials
Credential Access
T1555
Credentials from Password Stores
Credential Access
T1018
Remote System Discovery
Discovery
T1046
Network Service Discovery
Discovery
T1069
Permission Groups Discovery
Discovery
T1087
Account Discovery
Discovery
T1087.002
Account Discovery: Domain Account
Discovery
T1482
Domain Trust Discovery
Discovery
T1526
Cloud Service Discovery
Discovery
T1021
Remote Services
Lateral Movement
T1021.001
Remote Services: Remote Desktop Protocol
Lateral Movement
T1021.002
Remote Services: SMB/Windows Admin Shares
Lateral Movement
T1021.004
Remote Services: SSH
Lateral Movement
T1563
Remote Service Session Hijacking
Lateral Movement
T1005
Data from Local System
Collection
T1039
Data from Network Shared Drive
Collection
T1074
Data Staged
Collection
T1074.001
Data Staged: Local Data Staging
Collection
T1114
Email Collection
Collection
T1048
Exfiltration Over Alternative Protocol
Exfiltration
T1048.001
Exfiltration Over Alternative Protocol: Exfiltration Over Symmetric Encrypted Non-C2 Protocol
Exfiltration
T1537
Transfer Data to Cloud Account
Exfiltration
T1071
Application Layer Protocol
Command and Control
T1071.001
Application Layer Protocol: Web Protocols
Command and Control
T1219
Remote Access Software
Command and Control
T1572
Protocol Tunneling
Command and Control
T1573
Encrypted Channel
Command and Control
T1486
Data Encrypted for Impact
Impact
T1489
Service Stop
Impact
T1490
Inhibit System Recovery
Impact
T1491
Defacement
Impact