Kill Chain & Diamond Model Analysis
Map a threat actor or campaign across the Cyber Kill Chain and Diamond Model of Intrusion.
ghost stadium
(threat actor)
2 techniques
48 tools/malware
10 vulnerabilities
40 IOCs
3/7 stages covered
Deepest: Command & Control
Stage risk:
Critical
High
Medium
None
Indicators of Compromise (40)
ATT&CK Tactic Coverage
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command & Control
Exfiltration
Impact
Recommended Mitigations
8 MITRE ATT&CK mitigations cover detected techniques
Browse all →
Detection Coverage
2 strategies
2/7 stages covered
Diamond Model of Intrusion
Adversary · Capability · Infrastructure · Victim
ghost stadium
Type: Unknown Active
tracked as
YoroTrooper
Mustang Panda
T-APT-04
RattleSnake
+23 more
2 technique(s) 48 tool(s)/malware 10 CVE(s)
Targeted Sectors
information-technology
entertainment
financial-services
government
defense
healthcare
media
telecommunications
aviation
manufacturing
hospitality
maritime
retail
gaming
critical-infrastructure
education
transportation
energy
nuclear
Targeted Countries
United States of America
Argentina
Brazil
Canada
Colombia
Mexico
US
CN
MX
IN
UA
SG
EG
RU
BR
AU
VN
PK
CA
FR
IT
RO
NL
SA
JP
IL
IR
GB
Diamond Model Meta-Features
Direction
Adversary → Infrastructure → Victim
Adversary → Capability
Adversary → Infrastructure
Capability → Victim
Infrastructure → Victim
Diamond Model edges
Activity Threads
Kill chain phase → Diamond Model event mapping