Kill Chain & Diamond Model Analysis
Map a threat actor or campaign across the Cyber Kill Chain and Diamond Model of Intrusion.
Operation Emmental
(threat actor)
40 techniques
40 tools/malware
18 vulnerabilities
37 IOCs
3/7 stages covered
Deepest: Actions on Objectives
›
›
›
›
›
›
7
Actions on Objectives
18
Stage risk:
Critical
High
Medium
None
Indicators of Compromise (37)
ATT&CK Tactic Coverage
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command & Control
Exfiltration
Impact
Recommended Mitigations
21 MITRE ATT&CK mitigations cover detected techniques
Browse all →
Actions on Objectives
(10)
Detection Coverage
40 strategies
3/7 stages covered
Actions on Objectives
(18)
Diamond Model of Intrusion
Adversary · Capability · Infrastructure · Victim
Operation Emmental
Type: Unknown Active
Retefe Gang
Retefe Group
binary planting
slack space
header
+6 more
40 technique(s) 40 tool(s)/malware 18 CVE(s)
Targeted Sectors
government
financial-services
defense
energy
non-profit
media
telecommunications
critical-infrastructure
aerospace
oil-gas
healthcare
manufacturing
education
hospitality
think-tank
gaming
retail
utilities
transportation
pharmaceutical
information-technology
maritime
chemical
Targeted Countries
US
CN
JP
RU
IN
UA
KP
IL
KR
VN
PK
TW
KZ
BY
IR
SA
GB
AE
MX
LB
IT
SY
FR
PL
Diamond Model Meta-Features
Phase
Actions on Objectives
Direction
Adversary → Infrastructure → Victim
Adversary → Capability
Adversary → Infrastructure
Capability → Victim
Infrastructure → Victim
Diamond Model edges
Activity Threads
Kill chain phase → Diamond Model event mapping