Kill Chain & Diamond Model Analysis
Map a threat actor or campaign across the Cyber Kill Chain and Diamond Model of Intrusion.
Shahid Hemmat
(threat actor)
10 techniques
40 tools/malware
0 vulnerabilities
35 IOCs
1/7 stages covered
Deepest: Actions on Objectives
›
›
›
›
›
›
7
Actions on Objectives
10
T1003.001 - Credential Dumping: Mimikatz
T1041 - Exfiltration Over Command and Control Channel
T1059.001 - Command & Scripting Interpreter: PowerShell
T1059.003 - Windows Command Shell
T1070.003 - Indicator Removal on Host
T1077 - Windows Admin Shares (Remote Services)
T1105 - Ingress Tool Transfer
T1115 - Clipboard Data Manipulation
T1193 - Spearphishing Attachment
Stage risk:
Critical
High
Medium
None
Indicators of Compromise (35)
ATT&CK Tactic Coverage
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command & Control
Exfiltration
Impact
Diamond Model of Intrusion
Adversary · Capability · Infrastructure · Victim
Shahid Hemmat
Type: Unknown Active
Yellow Liderc
the BM-120
Al
Beijing Tianhua International Co
Ltd
+3 more
10 technique(s) 40 tool(s)/malware
Targeted Sectors
defense
nuclear
aerospace
chemical
financial-services
education
government
transportation
aviation
information-technology
non-profit
energy
food-agriculture
Targeted Countries
IR
CN
US
Diamond Model Meta-Features
Phase
Actions on Objectives
Direction
Adversary → Infrastructure → Victim
Adversary → Capability
Adversary → Infrastructure
Capability → Victim
Infrastructure → Victim
Diamond Model edges