Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
Duqu 2.0 exploited zero-days for lateral movement (Kaspersky)
Regional co-occurrence · associated techniques
Honesty note
Regional co-occurrence is association, not prediction. These techniques appeared alongside Duqu (Duqu 2.0)'s activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
Adaptive Application Control IntegrationT1553minimalAdaptive Application Control IntegrationT1553.002partialAdvanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.001significantApp GovernanceT1566significantAdvanced Threat HuntingT1566significantMicrosoft Defender for IdentityT1210minimalLateral MovementsT1210partialPreset Security PoliciesT1566significantPreset Security PoliciesT1566.001significantSafe AttachmentsT1566significantSafe AttachmentsT1566.001significantSecurity AlertsT1210significant
respond · 2 techniques
Advanced Anti-Phishing T1566partialAdvanced Anti-Phishing T1566.001partialAutomated Investigation and ResponseT1566significantAutomated Investigation and ResponseT1566.001significantIncident ResponseT1566minimalQuarantine PoliciesT1566significantQuarantine PoliciesT1566.001significantSafe AttachmentsT1566significantSafe AttachmentsT1566.001significantATT&CK Simulation TrainingT1566partialATT&CK Simulation TrainingT1566.001partialZero Hour Auto PurgeT1566significantZero Hour Auto PurgeT1566.001significant
Countermeasures · D3FEND
Defensive techniques that counter Duqu (Duqu 2.0)'s TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.