Detect Volt Typhoon TTPs that Evade EDR


Over the past year, several sophisticated cyber-espionage campaigns have grabbed the attention of the IT industry and challenged defenders and vendors with advanced tactics, techniques, and procedures (TTPs). One of the most visible is Volt Typhoon, named by the Microsoft threat intelligence team in May 2023 and attributed to Chinese state-sponsored threat actors. It primarily targets critical infrastructure organizations in the US, using legitimate network administration tools to avoid detection—and is believed to be part of a broader effort to establish footholds in critical infrastructure for politically driven future disruptions. Download this guide to discover a SOC analyst’s perspective on combating Volt Typhoon attacks.

Report Snapshot

  • How Volt Typhoon and other advanced attacks use living-off-the-land (LOTL) techniques for persistence and lateral movement
  • CISA’s recommendation about implementing strong network monitoring and visibility to combat advanced TTPs such as these
  • How NDR delivers on these recommendations to identify and neutralize attacks