Kill Chain & Diamond Model Analysis
Map a threat actor or campaign across the Cyber Kill Chain and Diamond Model of Intrusion.
BreachLaboratory
(threat actor)
5 techniques
46 tools/malware
4 vulnerabilities
40 IOCs
2/7 stages covered
Deepest: Actions on Objectives
›
›
›
›
›
›
7
Actions on Objectives
5
T1041 - Exfiltration Over Command and Control Channel
T1049 - System Network Connections Discovery
T1078.004 - Valid Accounts: Remote Services via stolen credentials
T1518.002 - Credentials from Non‑Local System Data Sources
T1566.001 - Spear‑phishing via Email
Stage risk:
Critical
High
Medium
None
Indicators of Compromise (40)
ATT&CK Tactic Coverage
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command & Control
Exfiltration
Impact
Diamond Model of Intrusion
Adversary · Capability · Infrastructure · Victim
BreachLaboratory
Type: Unknown Active
other aliases
several other aliases
Turla
network
software application
+75 more
5 technique(s) 46 tool(s)/malware 4 CVE(s)
Targeted Sectors
financial-services
government
defense
healthcare
telecommunications
critical-infrastructure
manufacturing
media
education
energy
aviation
aerospace
think-tank
non-profit
transportation
hospitality
maritime
retail
gaming
legal-services
utilities
nuclear
Targeted Countries
RU
CN
US
IN
IR
GB
BR
KP
TW
KR
UA
DE
CA
AU
TR
VN
FR
PK
Diamond Model Meta-Features
Phase
Actions on Objectives
Direction
Adversary → Infrastructure → Victim
Adversary → Capability
Adversary → Infrastructure
Capability → Victim
Infrastructure → Victim
Diamond Model edges