Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Kill Chain & Diamond Model Analysis

Map a threat actor or campaign across the Cyber Kill Chain and Diamond Model of Intrusion.

DieNet (threat actor)
Risk
84
Critical
74 techniques 53 tools/malware 1 vulnerabilities 40 IOCs 6/7 stages covered Deepest: Actions on Objectives
1 Reconnaissance
2
2 Weaponization
No data
3 Delivery
1
T1189
Drive-by Compromise initial access
4 Exploitation
14
T1059.013
T1129
T1559.001
T1559.002
T1559.003
XPC Services execution
T1610
T1648
T1546.005
Trap privilege escalation
T1546.016
Installer Packages privilege escalation
T1548
T1548.002
Bypass User Account Control privilege escalation
T1548.005
5 Installation
22
T1528
T1558
T1558.001
Golden Ticket credential access
T1558.002
Silver Ticket credential access
T1558.004
AS-REP Roasting credential access
T1124
T1518.002
T1133
T1136
Create Account persistence
T1136.003
Cloud Account persistence
T1505
T1505.001
T1505.002
Transport Agent persistence
T1505.004
IIS Components persistence
T1505.005
T1525
T1546.017
Udev Rules persistence
T1547.009
T1547.010
Port Monitors persistence
T1547.015
Login Items persistence
6 Command & Control
12
T1123
Audio Capture collection
T1125
Video Capture collection
T1560
T1560.001
T1560.002
T1560.003
T1132.001
Standard Encoding command and control
T1132.002
Non-Standard Encoding command and control
T1550.001
T1550.002
Pass the Hash lateral movement
T1550.003
Pass the Ticket lateral movement
7 Actions on Objectives
24
T1556.003
T1647
Plist File Modification defense impairment
T1127.001
MSBuild stealth
T1127.002
ClickOnce stealth
T1127.003
JamPlus stealth
T1134.001
T1134.002
T1134.004
T1134.005
T1218.011
Rundll32 stealth
T1218.012
Verclsid stealth
T1542
T1542.001
T1542.002
T1542.004
ROMMONkit stealth
T1542.005
TFTP Boot stealth
T1622
T0835
Stage risk: Critical High Medium None

ATT&CK Tactic Coverage

Reconnaissance Resource Development Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command & Control Exfiltration Impact

Diamond Model of Intrusion

Adversary · Capability · Infrastructure · Victim

Completeness
4/4
Adversary
Confidence
60%

DieNet

Type: Unknown Active
Shiite_Harvest MuddyWater tracked as Cyber Av3ngers Storm-0784 +4 more
Victim
70%

Targeted Sectors

financial-services government critical-infrastructure education telecommunications defense energy healthcare manufacturing media retail aviation non-profit transportation maritime

Targeted Countries

IL IR US AU AE TR SA EG RU IN NG PL

Diamond Model Meta-Features

Phase

Actions on Objectives

Result

Active

Direction

Adversary → Infrastructure → Victim

Methodology

Unknown

Adversary → Capability
Adversary → Infrastructure
Capability → Victim
Infrastructure → Victim
Diamond Model edges

Activity Threads Kill chain phase → Diamond Model event mapping

1 Reconnaissance

Capability (Techniques)

Capability (Malware)

3 Delivery

Capability (Techniques)

Capability (Malware)

4 Exploitation
5 Installation
6 Command & Control
7 Actions on Objectives

Capability (Techniques)

Capability (Malware)

Leaving Threaticon

This link opens an external site that isn't part of the platform.