Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Kill Chain & Diamond Model Analysis

Map a threat actor or campaign across the Cyber Kill Chain and Diamond Model of Intrusion.

jinx-0164 (threat actor)
Risk
86
Critical
56 techniques 48 tools/malware 5 vulnerabilities 18 IOCs 4/7 stages covered Deepest: Actions on Objectives
1 Reconnaissance
No data
2 Weaponization
No data
3 Delivery
No data
4 Exploitation
13
5 Installation
10
T1558
T1558.001
Golden Ticket credential access
T1558.002
Silver Ticket credential access
T1558.003
Kerberoasting credential access
T1558.004
AS-REP Roasting credential access
T1558.005
Ccache Files credential access
T1124
T1518.002
T1133
6 Command & Control
10
T1123
Audio Capture collection
T1125
Video Capture collection
T1560
T1560.001
T1560.002
T1560.003
T1132.001
Standard Encoding command and control
T1132.002
Non-Standard Encoding command and control
T1550.001
7 Actions on Objectives
28
T1127.001
MSBuild stealth
T1127.002
ClickOnce stealth
T1127.003
JamPlus stealth
T1134.001
T1134.002
T1134.004
T1134.005
T1030 – Data Transfer Size Limits
T1055 – Process Injection
T1059.013 – Container CLI/API
T1060 – Registry Run Keys / Startup Folder
T1078 – Valid Accounts
T1086 – PowerShell
T1105 – Ingress Tool Transfer
T1123 – Audio Capture
T1132.001 – Standard Encoding
T1134.003 – Make/Impersonate Token
T1134.004 – Parent PID Spoofing
T1195 – Supply Chain Compromise
T1557 – Steal or Forge Kerberos Ticket (AS-REP, Silver Ticket)
T1560.001 – Archive via Utility
T1566.001 – Phishing: Spear‑phishing attachment
T1566.002 – Phishing: Spear‑phishing link
Stage risk: Critical High Medium None

ATT&CK Tactic Coverage

Reconnaissance Resource Development Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command & Control Exfiltration Impact

Diamond Model of Intrusion

Adversary · Capability · Infrastructure · Victim

Completeness
4/4
Adversary
Confidence
55%

jinx-0164

Type: Unknown Active
tracked as Sleet
Victim
70%

Targeted Sectors

financial-services critical-infrastructure telecommunications manufacturing government gaming hospitality

Targeted Countries

US RU IR MX ES

Diamond Model Meta-Features

Phase

Actions on Objectives

Result

Active

Direction

Adversary → Infrastructure → Victim

Methodology

Unknown

Adversary → Capability
Adversary → Infrastructure
Capability → Victim
Infrastructure → Victim
Diamond Model edges

Activity Threads Kill chain phase → Diamond Model event mapping

Leaving Threaticon

This link opens an external site that isn't part of the platform.