Kill Chain & Diamond Model Analysis
Map a threat actor or campaign across the Cyber Kill Chain and Diamond Model of Intrusion.
TRIPLESTRENGTH
(threat actor)
11 techniques
47 tools/malware
40 vulnerabilities
22 IOCs
5/7 stages covered
Deepest: Actions on Objectives
›
›
›
›
›
›
7
Actions on Objectives
5
Stage risk:
Critical
High
Medium
None
Indicators of Compromise (22)
ATT&CK Tactic Coverage
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command & Control
Exfiltration
Impact
Recommended Mitigations
25 MITRE ATT&CK mitigations cover detected techniques
Browse all →
Actions on Objectives
(16)
Detection Coverage
11 strategies
5/7 stages covered
Actions on Objectives
(5)
Diamond Model of Intrusion
Adversary · Capability · Infrastructure · Victim
TRIPLESTRENGTH
Type: Unknown Active
tracked as
Antis
kanna
alprostadil
APT28
+11 more
11 technique(s) 47 tool(s)/malware 40 CVE(s)
Targeted Sectors
financial-services
government
healthcare
education
telecommunications
defense
critical-infrastructure
hospitality
energy
media
retail
manufacturing
non-profit
nuclear
gaming
pharmaceutical
mining
aerospace
maritime
information-technology
aviation
entertainment
food-agriculture
construction
transportation
legal-services
utilities
Targeted Countries
CN
IR
UA
GB
IN
RU
PL
KP
CA
JP
DE
TW
IT
KR
SG
RO
PK
BY
AU
TR
ES
MX
FR
US
BR
Diamond Model Meta-Features
Phase
Actions on Objectives
Direction
Adversary → Infrastructure → Victim
Adversary → Capability
Adversary → Infrastructure
Capability → Victim
Infrastructure → Victim
Diamond Model edges
Activity Threads
Kill chain phase → Diamond Model event mapping