Sample scenario sheets from the BlackNoise CTI library, including two compliance
tests mapped to the Qatar National Incident Management Framework. Free to download, TLP:GREEN.
Averages shown are observed on customer environments, not contractual commitments.
Compliance test · NIMF v1.0
NIMF Qatar — APT on Linux
Exposed Linux infrastructure server — Critical National Organisation
A state-sponsored operator working post-compromise with the tools already
installed: rsyslog silenced, credentials dumped, passwordless root path opened, data shipped
out over ordinary HTTPS. Validates detection, notification to the NCSA, containment,
forensic readiness and egress control.
14Events
6MITRE tactics
58Baseline score
↓ Download PDF
Compliance test · NIMF v1.0
NIMF Qatar — Insider Threat
Windows endpoint & member server — Critical National Organisation
No phishing, no exploit, no external infrastructure: legitimate credentials
performing illegitimate actions. Defender telemetry and the Windows event log are silenced
before credentials are touched, putting the audit trail itself under test up to recovery
inhibition on a critical asset.
13Events
8MITRE tactics
66Baseline score
↓ Download PDF
Full simulation · Regional actor
Handala Hack
Windows destructive operation — Void Manticore (MOIS-affiliated)
Destructive intrusion pattern replayed post-initial-access on a Windows
domain: Defender and AMSI neutralised, credentials extracted from LSASS and registry hives,
Active Directory reconnaissance, persistence, then a safe destructive phase — recovery
inhibition and file content overwrite on a controlled scope.
19Events
8MITRE tactics
73Baseline score
↓ Download PDF
Scenarios built and maintained by the BlackNoise CTI team. Impact
categorisations are indicative and remain the responsibility of the reporting organisation.
Over 200 scenario templates and 2,000 adversary behaviours are available in the platform.