Sourced from leak-site trackers — reflects the group's claim of a victim, not a confirmed breach.
Rows marked inferred are OSINT-extracted enrichment for actors without a MITRE Group ID — treat as analyst assessment, not authoritative ATT&CK attribution.
| Technique | Name | Tactic | Observed use |
|---|---|---|---|
| T1071.001 ↗inferred | Application Layer Protocol: Web Protocols | Command and Control | MITRE-attributed to LockBit 3.0 (S1202) |
| T1573.001 ↗inferred | Encrypted Channel: Symmetric Cryptography | Command and Control | MITRE-attributed to LockBit 3.0 (S1202) |
| T1132.001 ↗inferred | Data Encoding: Standard Encoding | Command and Control | MITRE-attributed to LockBit 3.0 (S1202) |
| T1622 ↗inferred | Debugger Evasion | Defense Evasion | MITRE-attributed to LockBit 3.0 (S1202) |
| T1070.004 ↗inferred | Indicator Removal: File Deletion | Defense Evasion | MITRE-attributed to LockBit 3.0 (S1202) |
| T1078.003 ↗inferred | Valid Accounts: Local Accounts | Defense Evasion | MITRE-attributed to LockBit 3.0 (S1202) |
+41 more relationships — see the relationships browser.
| T1480.002 ↗inferred |
| Execution Guardrails: Mutual Exclusion |
| Defense Evasion |
| MITRE-attributed to LockBit 3.0 (S1202) |
| T1484.001 ↗inferred | Domain or Tenant Policy Modification: Group Policy Modification | Defense Evasion | MITRE-attributed to LockBit 3.0 (S1202) |
| T1688 ↗inferred | Safe Mode Boot | Defense Evasion | MITRE-attributed to LockBit 3.0 (S1202) |
| T1685.005 ↗inferred | Disable or Modify Tools: Clear Windows Event Logs | Defense Evasion | MITRE-attributed to LockBit 3.0 (S1202) |
| T1685 ↗inferred | Disable or Modify Tools | Defense Evasion | MITRE-attributed to LockBit 3.0 (S1202) |
| T1027.002 ↗inferred | Obfuscated Files or Information: Software Packing | Defense Evasion | MITRE-attributed to LockBit 3.0 (S1202) |
| T1027.013 ↗inferred | Obfuscated Files or Information: Encrypted/Encoded File | Defense Evasion | MITRE-attributed to LockBit 3.0 (S1202) |
| T1112 ↗inferred | Modify Registry | Defense Evasion | MITRE-attributed to LockBit 3.0 (S1202) |
| T1140 ↗inferred | Deobfuscate/Decode Files or Information | Defense Evasion | MITRE-attributed to LockBit 3.0 (S1202) |
| T1218.003 ↗inferred | System Binary Proxy Execution: CMSTP | Defense Evasion | MITRE-attributed to LockBit 3.0 (S1202) |
| T1480 ↗inferred | Execution Guardrails | Defense Evasion | MITRE-attributed to LockBit 3.0 (S1202) |
| T1083 ↗inferred | File and Directory Discovery | Discovery | MITRE-attributed to LockBit 3.0 (S1202) |
| T1680 ↗inferred | Local Storage Discovery | Discovery | MITRE-attributed to LockBit 3.0 (S1202) |
| T1120 ↗inferred | Peripheral Device Discovery | Discovery | MITRE-attributed to LockBit 3.0 (S1202) |
| T1082 ↗inferred | System Information Discovery | Discovery | MITRE-attributed to LockBit 3.0 (S1202) |
| T1135 ↗inferred | Network Share Discovery | Discovery | MITRE-attributed to LockBit 3.0 (S1202) |
| T1614.001 ↗inferred | System Location Discovery: System Language Discovery | Discovery | MITRE-attributed to LockBit 3.0 (S1202) |
| T1057 ↗inferred | Process Discovery | Discovery | MITRE-attributed to LockBit 3.0 (S1202) |
| T1106 ↗inferred | Native API | Execution | MITRE-attributed to LockBit 3.0 (S1202) |
| T1059.001 ↗inferred | Command and Scripting Interpreter: PowerShell | Execution | MITRE-attributed to LockBit 3.0 (S1202) |
| T1569.002 ↗inferred | System Services: Service Execution | Execution | MITRE-attributed to LockBit 3.0 (S1202) |
| T1490 ↗inferred | Inhibit System Recovery | Impact | MITRE-attributed to LockBit 3.0 (S1202) |
| T1489 ↗inferred | Service Stop | Impact | MITRE-attributed to LockBit 3.0 (S1202) |
| T1486 ↗inferred | Data Encrypted for Impact | Impact | MITRE-attributed to LockBit 3.0 (S1202) |
| T1021.002 ↗inferred | Remote Services: SMB/Windows Admin Shares | Lateral Movement | MITRE-attributed to LockBit 3.0 (S1202) |
| T1547.004 ↗inferred | Boot or Logon Autostart Execution: Winlogon Helper DLL | Persistence | MITRE-attributed to LockBit 3.0 (S1202) |
| T1543.003 ↗inferred | Create or Modify System Process: Windows Service | Persistence | MITRE-attributed to LockBit 3.0 (S1202) |
| T1548.002 ↗inferred | Abuse Elevation Control Mechanism: Bypass User Account Control | Privilege Escalation | MITRE-attributed to LockBit 3.0 (S1202) |
Regional co-occurrence is association, not prediction. These techniques appeared alongside LockBit / LockBit 3.0's activity across the tracked MENA roster — a TIE-style association computed on our corpus (not CTID's model), not a prediction of the next move. Ranked by support-adjusted lift (over-representation among actors like this one vs. the roster base rate, damped when few actors back it), so neither a merely-common technique nor a tiny-sample coincidence floats to the top. A hunting lead only; never recorded as observed. ICS techniques are excluded.
Which Microsoft 365 controls protect, detect, or respond to this actor's techniques — from the CTID Mappings Explorer (technique-level). Strength: significant / partial / minimal.
Defensive techniques that counter LockBit / LockBit 3.0's TTPs, from MITRE D3FEND. The ATT&CK↔D3FEND link is mitigation-mediated — treat these as candidate countermeasures, not prescriptions.