Kill Chain & Diamond Model Analysis
Map a threat actor or campaign across the Cyber Kill Chain and Diamond Model of Intrusion.
Winnti Group
(threat actor)
43 techniques
52 tools/malware
11 vulnerabilities
40 IOCs
7/7 stages covered
Deepest: Actions on Objectives
›
›
›
›
›
›
7
Actions on Objectives
13
Stage risk:
Critical
High
Medium
None
Indicators of Compromise (40)
ATT&CK Tactic Coverage
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command & Control
Exfiltration
Impact
Recommended Mitigations
34 MITRE ATT&CK mitigations cover detected techniques
Browse all →
Actions on Objectives
(17)
Detection Coverage
43 strategies
7/7 stages covered
Actions on Objectives
(13)
Diamond Model of Intrusion
Adversary · Capability · Infrastructure · Victim
Winnti Group
Type: Unknown Active
Blackfly
Wicked Panda
APT41
Winnti Umbrella
BARIUM
+47 more
43 technique(s) 52 tool(s)/malware 11 CVE(s)
Targeted Sectors
healthcare
manufacturing
critical infrastructure
technology
media
gaming
government
financial-services
telecommunications
defense
education
pharmaceutical
energy
non-profit
aerospace
critical-infrastructure
aviation
transportation
hospitality
retail
information-technology
chemical
mining
think-tank
utilities
oil-gas
construction
maritime
legal-services
nuclear
entertainment
Targeted Countries
CN
US
TW
RU
IR
IL
IN
JP
SA
AE
KR
GB
VN
AU
PK
UA
SG
DE
MX
PL
CA
IT
BY
TR
FR
ES
AZ
RO
NG
KP
LB
KZ
Diamond Model Meta-Features
Phase
Actions on Objectives
Direction
Adversary → Infrastructure → Victim
Adversary → Capability
Adversary → Infrastructure
Capability → Victim
Infrastructure → Victim
Diamond Model edges
Activity Threads
Kill chain phase → Diamond Model event mapping