BushidoUK ToolMatrix Tools: DiscoveryEnum

Fecha
18 Jun 2026
Actor
bushidouk
Tipo
Report
Pais
United States
Sector
-
Confianza
high
55
Prioridad analitica
Media

Basado en actor, pais, IOCs, TTPs, filtracion y calidad de contexto.

1IOCs
0TTPs
bushidoukActor
United StatesPais
Executive Summary
Recurso del BushidoUK Ransomware Tool Matrix - Tools.

Key Points

  • |
  • |
  • |
  • |
  • |

Tools: DiscoveryEnum.md

Recurso del BushidoUK Ransomware Tool Matrix - Tools.

Discovery and Enumeration Tools

> [!TIP]

> There are a number of network scanning and profiling tools available online that are designed to help administrators and IT professionals with tasks such as discovering and mapping network devices, performing detailed scans of IP addresses and open ports, and querying network services like Active Directory.

> [!IMPORTANT]

> Malicious adversaries leverage these network management tools to perform reconnaissance and gather detailed information about a target network. They can use these tools to identify active devices, open ports, and vulnerabilities, which could then be exploited to gain entry. Additionally, querying tools for active directory services could allow them to harvest sensitive information about users, groups, and permissions, facilitating targeted attacks or insider threats. Essentially, these tools, while valuable for legitimate network management, can be misused to map out and exploit network infrastructures for nefarious purposes.

| Tool Name | Threat Group Usage |

|---|---|

| ADExplorer | Lapsus$, Scattered Spider

  • |
  • | ADRecon | Scattered Spider*, DarkSide, PYSA, BlackCat, Cicada3301, Storm-0501 |

    | AdFind | MAZE, BlackSuit, Royal, PLAY, LockBit, Conti, Dagon Locker, Nokoyawa, Quantum, Diavol, XingLocker, REvil, Ryuk, NetWalker, INC Ransom, Black Basta, Yanluowang, DarkSide, Lockean*, FiveHands, DragonForce |

    | Advanced IP Scanner | MAZE, BlackSuit, Royal, Akira, LockBit, Diavol, GoGoogle, INC Ransom, Hive, Zola, DarkSide, PYSA, Vice Society, FiveHands, Sarcoma, DragonForce, MedusaLocker, Mimic, Loki, Medusa, Hunters International, BianLian, Beast, TheGentlemen |

    | Advanced Port Scanner | LockBit, BianLian, PYSA, Trigona, EvilCorp, Fog, Scattered Spider, RagnarLocker, Vice Society, Medusa Locker, Hunters International, Helldown, Interlock, Beast |

    | Angry IP Scanner | Phobos, RansomHub |

    | AWS Systems Manager Inventory | Scattered Spider

  • |
  • | Azure Storage Explorer | Interlock |

    | AzureHound | Storm-0501

  • |
  • | Bloodhound | MAZE, LockBit, Conti, XingLocker, REvil, Hive, Black Basta, Lockean*, FiveHands, Akira |

    | API-C99-NL | TheGentlemen |

    | Cent Browser | Yanluowang |

    | Censys | TheGentlemen |

    | CertiHound | TheGentlemen |

    | Dsquery | RagnarLocker |

    | Everything.exe | NightSpire, Beast, Yurei, Warlock |

    | Get-ADUser | Scattered Spider

  • |
  • | Gogo | TheGentlemen |

    | Lansweeper | EvilCorp

  • |
  • | ldapdomaindump | Akira |

    | Navicat | Medusa |

    | Nbtscan | Dagon Locker |

    | NirSoft WinLister | AvosLocker |

    | Nmap | Qilin, Cactus, AvosLocker, RansomHub, TheGentlemen |

    | Nping | Qilin |

    | ManageEngine LANDESK | Scattered Spider

  • |
  • | MANSPIDER | TheGentlemen |

    | Masscan | Akira, BlackCat |

    | ossec-win32 | Storm-0501 |

    | OSQuery | Storm-0501 |

    | PDQ Inventory | Scattered Spider*, Medusa |

    | PingCastle | MAZE, BianLian, Scattered Spider*, DragonForce |

    | PowerView | MAZE, Conti, XingLocker, Rhysida, BlackByte, Black Basta, Cicada3301 |

    | PrivHound | TheGentlemen |

    | PsInfo | RagnarLocker |

    | PSNmap | Black Basta |

    | ReconFTW | Akira |

    | RelayKing-Depth | TheGentlemen |

    | RoboCopy | Medusa |

    | RustScan | Scattered Spider

  • |
  • | RVTools | Scattered Spider

  • |
  • | S3 Browser | FiveHands, Yanluowang |

    | Seatbelt | LockBit, Conti, Dagon Locker |

    | SecurityCheck | Warlock |

    | SharpNBTScan | Ghost/Cring |

    | SharpHound | Scattered Spider*, Akira, BlackSuit |

    | ShareFinder | MAZE, Conti, Dagon Locker, Diavol, XingLocker |

    | SharpShares | BlackSuit, Royal, BianLian, Fog, Ghost/Cring, Akira |

    | SharpView | Conti |

    | Shodan | TheGentlemen |

    | SoftPerfect LanSearchPro | RagnarLocker |

    | SoftPerfect NetScan | BlackSuit, Royal, Black Basta, Akira, LockBit, BianLian, Conti, BlackCat, Dagon Locker, Nokoyawa, Trigona, Hive, BlackByte, RansomHub, Cactus, Fog, Medusa, Avaddon, AvosLocker, FiveHands, Yanluowang, MONTI, DarkSide, Everest, Cicada3301, MedusaLocker, DragonForce, Phobos, Lynx, Medusa, Beast, Yurei, DragonForce |

    | TaskHound | TheGentlemen |

    | TXPortMap | *Prophet Spider |

    | VMware PowerCLI | Scattered Spider

  • |
  • | WKTools | RansomHub, PLAY, BianLian |

    Referencias

    Diamond Model

    Adversary
    bushidouk
    Ver perfil →
    Victim
    BushidoUK ToolMatrix Tools: DiscoveryEnum
    United States
    Capability
    Report
    Infrastructure
    Sin infraestructura confirmada

    Indicadores de Compromiso (IOCs)

    TipoValorContextoOSINT
    File Everything.exe Artefacto observado VT OffSec SOCRadar

    Referencias y enlaces

    → Perfil del actor bushidouk en el blog → Ver bushidouk en IntelTracker → Fuente OSINT: github.com→ Fuente OSINT: github.com → Buscar bushidouk en APTTrail → Repositorio APTTrail → Mas incidentes en United States → Buscar en Google News → Analizar en VirusTotal → Feed RSS del blog
    ← Volver al panel de inteligencia

    Incidentes recientes