Host and process inventory
One long-lived process produced host inventory with recurring process and connection-owner inventories.
Research coverage · Availability not listed
This record covers one publicly reported 64-bit Windows sample. Proofmetry reached 25 intended paths in a fixed research matrix, but current customer availability for Abyssos is not publicly listed.
Research and product are different scopes: the 25 research scenarios are not 25 product-supported workflows.
Record metadata
Evidence vocabulary
The 23 corroborated outcomes combine different evidence levels. They must not be restated as 23 endpoint effects.
A behavior or handler was identified through analysis.
Execution entered the intended code path.
A meaningful intermediate or returned result was observed.
The workflow reached a defined completion or stop condition.
The intended native endpoint or network effect was corroborated.
Research evidence
The matrix preserves the difference between task delivery, path reach, returned result, terminal state, and endpoint effect.
| Research item | Public evidence | Claim boundary |
|---|---|---|
| Fixed scenario matrix | Path reached: all 25 intended paths were reached through the native v2.1F client. | Research scenarios are not identical to current product workflows. |
| Corroborated outcomes | Result, terminal state, or endpoint effect: 23 scenarios produced at least one of these evidence forms. | The public aggregate does not state that all 23 reached endpoint-effect confirmation. |
| Remote-desktop quality | Path reached: the task arrived in the intended sequence. | A perceptual image-quality change was not independently measured and is not claimed. |
| Hidden-desktop input | Path reached / terminal state observed: input reached dispatch and orderly teardown. | Cursor movement was not independently observed and is not claimed. |
| Lifecycle stops | Terminal state observed: some stops ended a worker without an ordinary command result. | Absence of an ordinary result does not erase the terminal-state evidence. |
| Disconnect | Terminal state observed: the process ended and the session reset. | A completed network exchange alone would not establish that endpoint outcome. |
| Additional static paths | Mapped: power control, elevation, injection, recovery, module loading, and arbitrary file, URL, or payload execution were identified. | They were not executed in this research and are not presented as observed behavior. |
Behavior categories
The original Abyssos v2.1F client produced the observed behavior in the isolated environment.
One long-lived process produced host inventory with recurring process and connection-owner inventories.
The sample returned file contents, wrote C2-supplied bytes, copied and deleted files, and built memory-only and on-disk archives.
The exercised paths included shell activity, socket-owner inventory, and a related process termination action keyed by PID.
Desktop creation, capture, image encoding, input dispatch, and lifecycle behavior were exercised, with two effect-specific claims withheld.
Worker stops and process disconnect produced distinct result and terminal-state patterns.
The sample file remained unmodified, but a standard Windows cryptography module had to be loaded into the process before native transport initialized.
Availability boundary: These are researched categories, not a published product test catalog. Abyssos customer availability is not currently listed.
Known limitations
Revision history
| Date | Record | Change |
|---|---|---|
| August 30, 2026 | Website coverage record 1.0 | Initial public coverage record separating Research Brief 002, revision 1.1, from unlisted product availability. This record number is not a Threat Pack version. |
Research coverage
Current preview availability is not publicly listed. We can confirm variant and behavior-test fit during the demo process.
Get a demo