Kill Chain & Diamond Model Analysis
Map a threat actor or campaign across the Cyber Kill Chain and Diamond Model of Intrusion.
TIDRONE
(threat actor)
40 techniques
40 tools/malware
29 vulnerabilities
39 IOCs
7/7 stages covered
Deepest: Actions on Objectives
›
›
›
›
›
›
7
Actions on Objectives
5
Stage risk:
Critical
High
Medium
None
Indicators of Compromise (39)
ATT&CK Tactic Coverage
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command & Control
Exfiltration
Impact
Recommended Mitigations
27 MITRE ATT&CK mitigations cover detected techniques
Browse all →
Actions on Objectives
(7)
Detection Coverage
40 strategies
7/7 stages covered
Actions on Objectives
(5)
Diamond Model of Intrusion
Adversary · Capability · Infrastructure · Victim
TIDRONE
Type: Unknown Active
Earth Ammit
VENOM
APT28
Fancy Bear
Asylum Ambuscade
+39 more
40 technique(s) 40 tool(s)/malware 29 CVE(s)
Targeted Sectors
defense
financial-services
manufacturing
government
aerospace
telecommunications
energy
transportation
media
healthcare
education
construction
critical-infrastructure
pharmaceutical
retail
utilities
non-profit
information-technology
food-agriculture
chemical
aviation
maritime
mining
nuclear
oil-gas
Targeted Countries
TW
RU
KR
CN
UA
IN
TR
US
CA
PK
DE
JP
AE
VN
BR
IR
IT
SA
AU
IL
FR
Diamond Model Meta-Features
Phase
Actions on Objectives
Direction
Adversary → Infrastructure → Victim
Adversary → Capability
Adversary → Infrastructure
Capability → Victim
Infrastructure → Victim
Diamond Model edges
Activity Threads
Kill chain phase → Diamond Model event mapping