| Technique | Name | Tactic | Observed use |
|---|---|---|---|
| T1120 ↗ | Peripheral Device Discovery | Discovery | [Equation](https://attack.mitre.org/groups/G0020) has used tools with the functionality to search for specific information about the attached hard drive that could be used to identify and overwrite the firmware.(Citation: Kaspersky Equation QA) |
| T1480.001 ↗ | Environmental Keying | Stealth | [Equation](https://attack.mitre.org/groups/G0020) has been observed utilizing environmental keying in payload delivery.(Citation: Kaspersky Gauss Whitepaper)(Citation: Kaspersky Equation QA) |
| T1564.005 ↗ | Hidden File System | Stealth | [Equation](https://attack.mitre.org/groups/G0020) has used an encrypted virtual file system stored in the Windows Registry.(Citation: Kaspersky Equation QA) |
| T1542.002 ↗ | Component Firmware | Stealth | [Equation](https://attack.mitre.org/groups/G0020) is known to have the capability to overwrite the firmware on hard drives from some manufacturers.(Citation: Kaspersky Equation QA) |
Regional co-occurrence is association, not prediction. These techniques appeared alongside Equation Group's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
Defensive techniques that counter Equation Group's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.