#
Scattered Spider
Based on open-source intelligence, the MITRE ATT&CK® Evaluations team created the Scattered Spider scenario leveraging techniques seen in operations in the wild. The scenario was designed based on tools, resources, and intelligence available at the time.
#
Adversary Overview
#
Quick Links
#
Resources
The Resources Folder contains the emulated software source code.
All other pre-built executables have been removed. To rebuild the binaries, follow the documentation for the respective binary.
#
Emulation Key Software 💻
#
Scenario Walkthrough
Scattered Spider Scenario Overview: Overview of the Scattered Spider scenario
Scattered Spider Emulation Plan: Step by step walkthrough of the Scattered Spider red team emulation plan
#
Acknowledgements
We would like to formally thank the people that contributed to the content, review, and format of this document. This includes the MITRE ATT&CK and MITRE ATT&CK Evaluations teams, the organizations and people that provided public intelligence and resources, as well as the following organizations that participated in the community cyber threat intelligence contribution process:
-
#
Connect with us 🗨️
We 💖 feedback! Let us know how using ATT&CK Evaluation results has helped you and what we can do better.
- Email: evals@mitre.org
- LinkedIn: https://www.linkedin.com/showcase/attack-evaluations/
#
Liability / Responsible Usage
This content is only to be used with appropriate prior, explicit authorization for the purposes of assessing security posture and/or research.
#
Notice
© 2025 The MITRE Corporation. All rights reserved. Approved for Public Release. Document number 25-2821.
Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
This project makes use of ATT&CK®