Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Kill Chain & Diamond Model Analysis

Map a threat actor or campaign across the Cyber Kill Chain and Diamond Model of Intrusion.

LongNosedGoblin (threat actor)
Risk
90
Critical
37 techniques 64 tools/malware 3 vulnerabilities 40 IOCs 6/7 stages covered Deepest: Actions on Objectives
1 Reconnaissance
No data
2 Weaponization
2
T1585.003
Cloud Accounts resource development
T1588.001
Malware resource development
3 Delivery
1
T1566
Phishing initial access
4 Exploitation
8
T1053.005
T1059.001
PowerShell execution
T1059.003
T1106
Native API execution
5 Installation
3
6 Command & Control
12
T1056
Input Capture collection
T1056.001
Keylogging collection
T1074.001
T1113
Screen Capture collection
T1125
Video Capture collection
T1560
T1071
Application Layer Protocol command and control
T1071.001
Web Protocols command and control
T1102.002
Bidirectional Communication command and control
T1105
Ingress Tool Transfer command and control
T1573.001
Symmetric Cryptography command and control
T1573.002
Asymmetric Cryptography command and control
7 Actions on Objectives
14
T1484.001
Group Policy Modification defense impairment
T1567.002
T1027.013
T1027.015
T1055
T1564.003
T1574.014
T1622
T1562.001
Stage risk: Critical High Medium None

ATT&CK Tactic Coverage

Reconnaissance Resource Development Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command & Control Exfiltration Impact

Diamond Model of Intrusion

Adversary · Capability · Infrastructure · Victim

Completeness
4/4
Adversary
Confidence
60%

LongNosedGoblin

Type: Unknown Active
APT34 Earth Preta Stately Taurus tracked as Midnight Blizzard has +85 more
Capability
56%
37 technique(s) 64 tool(s)/malware 3 CVE(s)
collection
command and control
defense impairment
Victim
70%

Targeted Sectors

government defense telecommunications financial-services non-profit education think-tank energy healthcare media maritime hospitality critical-infrastructure manufacturing aerospace pharmaceutical transportation legal-services nuclear entertainment aviation chemical utilities information-technology

Targeted Countries

CN RU UA US JP IL AE PK BY IN IR VN PL KR KP LB TR TW KZ IQ DE IT SA FR

Diamond Model Meta-Features

Phase

Actions on Objectives

Result

Active

Direction

Adversary → Infrastructure → Victim

Methodology

Unknown

Resources

government

Adversary → Capability
Adversary → Infrastructure
Capability → Victim
Infrastructure → Victim
Diamond Model edges

Activity Threads Kill chain phase → Diamond Model event mapping

2 Weaponization

Capability (Techniques)

Capability (Malware)

3 Delivery

Capability (Techniques)

Capability (Malware)

4 Exploitation
5 Installation

Capability (Techniques)

Capability (Malware)

6 Command & Control
7 Actions on Objectives

Capability (Techniques)

Capability (Malware)

Leaving Threaticon

This link opens an external site that isn't part of the platform.