Kill Chain & Diamond Model Analysis
Map a threat actor or campaign across the Cyber Kill Chain and Diamond Model of Intrusion.
EC2 Grouper
(threat actor)
1 techniques
47 tools/malware
40 vulnerabilities
43 IOCs
1/7 stages covered
Deepest: Exploitation
Stage risk:
Critical
High
Medium
None
Indicators of Compromise (43)
ATT&CK Tactic Coverage
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command & Control
Exfiltration
Impact
Recommended Mitigations
3 MITRE ATT&CK mitigations cover detected techniques
Browse all →
Detection Coverage
1 strategies
1/7 stages covered
Diamond Model of Intrusion
Adversary · Capability · Infrastructure · Victim
EC2 Grouper
Type: Unknown Active
tracked as
cpyy
APT3
Gothic Panda
UPS Team
+16 more
1 technique(s) 47 tool(s)/malware 40 CVE(s)
Targeted Sectors
government
financial-services
defense
telecommunications
healthcare
non-profit
energy
education
hospitality
critical-infrastructure
media
aerospace
mining
pharmaceutical
maritime
gaming
nuclear
information-technology
retail
aviation
manufacturing
think-tank
legal-services
transportation
utilities
chemical
entertainment
Targeted Countries
CN
US
IR
GB
IN
JP
KR
TW
UA
DE
CA
RU
PL
FR
SA
TR
AU
AE
SG
IL
BR
IT
RO
KZ
PK
KP
ES
VN
MX
NL
IQ
BY
SY
EG
AZ
Diamond Model Meta-Features
Direction
Adversary → Infrastructure → Victim
Adversary → Capability
Adversary → Infrastructure
Capability → Victim
Infrastructure → Victim
Diamond Model edges
Activity Threads
Kill chain phase → Diamond Model event mapping