Kill Chain & Diamond Model Analysis
Map a threat actor or campaign across the Cyber Kill Chain and Diamond Model of Intrusion.
Cyber Alliance
(threat actor)
24 techniques
44 tools/malware
12 vulnerabilities
19 IOCs
4/7 stages covered
Deepest: Actions on Objectives
›
›
›
›
›
›
7
Actions on Objectives
19
T1033: System Owner/User Discovery
T1059.001: Command‑line Interface
T1083: File and Directory Discovery
T1135: Network Share Discovery
T1140: Deobfuscate/Decode Files or Information
T1190: Exploit Public-Facing Application
T1486: Data Encrypted for Impact
T1497.003: Time Based Checks
T1529: System Shutdown/Reboot
T1547.001: Registry Run Keys / Startup Folder
Stage risk:
Critical
High
Medium
None
Indicators of Compromise (19)
ATT&CK Tactic Coverage
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command & Control
Exfiltration
Impact
Recommended Mitigations
17 MITRE ATT&CK mitigations cover detected techniques
Browse all →
Actions on Objectives
(8)
Detection Coverage
12 strategies
3/7 stages covered
Actions on Objectives
(7)
Diamond Model of Intrusion
Adversary · Capability · Infrastructure · Victim
Cyber Alliance
Type: Unknown Active
AlphaVM
AlphaV
Secret Blizzard
tracked as
the Newscaster Team
+5 more
24 technique(s) 44 tool(s)/malware 12 CVE(s)
Targeted Sectors
telecommunications
government
financial-services
energy
defense
critical-infrastructure
information-technology
manufacturing
healthcare
education
non-profit
retail
transportation
Targeted Countries
US
RU
RO
CN
BR
DE
GB
UA
IR
NL
FR
KP
CA
TR
ES
IT
JP
Diamond Model Meta-Features
Phase
Actions on Objectives
Direction
Adversary → Infrastructure → Victim
Adversary → Capability
Adversary → Infrastructure
Capability → Victim
Infrastructure → Victim
Diamond Model edges
Activity Threads
Kill chain phase → Diamond Model event mapping