GreyNoise has spent years observing the earliest stages of an attack. Our Global Observation Grid sees adversaries as they scan the internet, probe exposed systems, and attempt to exploit vulnerabilities at the edge. That visibility has traditionally focused on the left side of the MITRE ATT&CK framework, from Reconnaissance through Initial Access and it’s where we built our primary-source intelligence brand.
But we’ve known that is only half the equation.
Moving Further Right on MITRE ATT&CK
Earlier this year, we launched our C2 Detection Module, expanding our visibility beyond inbound scanning to the attacker-controlled infrastructure used after exploitation. GreyNoise reads the callback destinations embedded in exploit payloads to identify where a compromised device would call home, from malware-hosting servers to suspected C2 infrastructure.
This marked our first move right of Initial Access on MITRE ATT&CK, extending visibility beyond the exploit itself to the infrastructure supporting what happens next. Defenders can match outbound traffic from their edge devices against GreyNoise callback intelligence to identify connections to confirmed malware-serving infrastructure or suspected C2 servers.
See Host Telemetry from GreyNoise Deception Sensors on Your Network
When we launched Project Swarm, we opened our deception platform to the global security community. Participants could deploy GreyNoise Deception Sensors across their own infrastructure that looked like the firewalls, routers, VPN gateways, and other internet-facing systems that adversaries target.
Project Swarm users gained full visibility into the sessions reaching their sensors, including raw payloads, HTTP headers, TLS metadata, and other behavioral artifacts.
But a common ask from them was deeper visibility into what happened after an exploit succeeded. What shell commands did the adversary run? What files did they touch? What did they try to do next?
Introducing GreyNoise Tactics
Today, we are launching Tactics, giving anyone deploying a GreyNoise Deception Sensor deeper visibility into what attackers do after initial compromise.
Tactics automatically maps qualifying attacker sessions captured by sensors in your workspace to the MITRE ATT&CK framework. Each detection represents one session and shows the tactics and techniques observed, along with the activity behind the mapping.
You can find Tactics under Observe → Tactics in the GreyNoise Visualizer. Open a detection to:
- Follow the attacker’s complete command sequence
- See the commands, scripts, and binaries the adversary executed
- Inspect files created or modified, including their SHA256 hashes
- Review outbound connections to internet destinations
- Identify attempts to move laterally within your address space
Tactics begin populating when your workspace has a sensor running a vulnerable profile. Once an attacker compromises that profile and performs activity mapped to a MITRE ATT&CK technique, the session will appear as a detection.
Routine and unclassified sessions are filtered out, so the view focuses on meaningful adversary behavior rather than every connection your sensor receives.
See What Happens After the Shell
Because GreyNoise captures the attacker’s interaction with the host, Tactics can identify behavior across the post-compromise stages of MITRE ATT&CK.
That includes:
- Execution: Commands, scripts, and binaries run after gaining access
- Persistence: Scheduled jobs, new accounts, and other attempts to maintain access
- Privilege Escalation: Attempts to gain greater control of the host
- Defense Evasion: Actions intended to hide activity or interfere with protections
- Credential Access: Searches for cloud credentials, private keys, service account tokens, and other secrets
- Discovery: Commands used to inspect the operating system, processes, files, and surrounding environment
- Lateral Movement: Attempts to reach other systems from the initial foothold, a view that keeps expanding as our deception network grows
- Collection: Files and data gathered from a system they think they’ve compromised
- Command and Control: Connections used to retrieve payloads or maintain access
- Exfiltration: Attempts to move credentials, files, or other data off the sensor
- Impact: Activity intended to disrupt the host, consume resources, or interfere with processes
With Tactics, GreyNoise now shows what adversaries do with access, not just how they find and exploit exposed systems.
Turn Observed Behavior Into Action
Every command, file, hash, path, and network connection captured by a sensor gives defenders a lead they can investigate inside their own environment.
- SOC analysts and detection engineers can build and tune detections around the commands and techniques adversaries are using now.
- Threat hunters can search production environments for observed hashes, file paths, binaries, and command patterns.
- Threat intelligence teams can track which tactics and techniques are appearing across infrastructure relevant to their organization.
Because this intelligence comes directly from observed session activity, defenders can work from what the adversary actually did after gaining access. Mapping that activity to MITRE ATT&CK makes it easier to understand and use across existing security workflows.
What We Found After the Shell
Before launching Tactics, we analyzed weeks of post-compromise activity across our own Deception Sensor network in the Global Observation Grid.
Much of what we observed was commodity cryptomining, with adversaries treating each new foothold as more infrastructure to consume. A smaller set of sessions showed more serious behavior, going after cloud credentials, attempting container escapes, or creating backdoor accounts.
We break down these findings in After the Shell, a new GreyNoise research report published today. It examines what adversaries did after gaining access, which behaviors appeared most often, and what those observations mean for defenders.
Join the Swarm
Tactics is available for all users who have deployed a GreyNoise sensor. If you already have a sensor deployed, open Tactics under Observe in the GreyNoise Visualizer to see what it has captured.
If you’re new to Project Swarm, deploy a Greynoise Deception Sensor to start observing what attackers do after compromise.
