Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Kill Chain & Diamond Model Analysis

Map a threat actor or campaign across the Cyber Kill Chain and Diamond Model of Intrusion.

4bid (threat actor)
Risk
91
Critical
62 techniques 164 tools/malware 13 vulnerabilities 34 IOCs 5/7 stages covered Deepest: Actions on Objectives
1 Reconnaissance
No data
2 Weaponization
No data
3 Delivery
5
T1195
T1566
Phishing initial access
T1566.001
T1566.002
Spearphishing Link initial access
5 Installation
12
T1003
OS Credential Dumping credential access
T1003.001
LSASS Memory credential access
T1003.002
Security Account Manager credential access
T1003.006
DCSync credential access
T1040
Network Sniffing credential access
T1110
Brute Force credential access
T1552
Unsecured Credentials credential access
T1098
T1136.001
Local Account persistence
6 Command & Control
9
T1074
Data Staged collection
T1113
Screen Capture collection
T1071.001
Web Protocols command and control
T1071.004
DNS command and control
T1090
Proxy command and control
T1104
Multi-Stage Channels command and control
T1105
Ingress Tool Transfer command and control
T1021
Remote Services lateral movement
T1021.004
SSH lateral movement
7 Actions on Objectives
24
T1484.002
Trust Modification defense impairment
T1578.001
Create Snapshot defense impairment
T1498.001
T1036
T1055
T1070
T1078
T1574.001
DLL stealth
T1574.004
T1036.015
T1043
T1064
T1070.002
T1076
T1081
T1086
T1498.004
T1515
T1574.003
Stage risk: Critical High Medium None

Tools & Malware (164)

ADRecon Advanced IP Scanner Agenda ransomware binary Akira Akira ransomware Anthropic Claude LLM AnyDesk AsyncRAT Atera RMM platform BADAUDIO BLOODALCHEMY BRICKSTORM Babuk Backdoors BadAudio BlackReaperRAT Blackout Locker BloodHound Broadside (Mirai variant) Broadside Botnet C5 backdoor COROXY backdoor CalaRat Chaos Chisel ClearWater ClearWater ransomware CloudAtlas backdoor CloudFlared Cloudflare Workers Cobalt Cobalt Strike Cobint Comebacker ConfuserEx CrackMapExec Custom Python credential extraction script Custom scripts DCRat DCSYNCER.SLICK DCSyncer DEEPROOT DaemonicLogistics Dark Dev Tunnels EchoGather EdgeStepper Endurance-Wiper Explorer Export-Alias FaceFish FileGrabber Fleetdeck Fooder FormBook Fscan GHOSTLINE GOST GTG-1002 Malware GalaxyGato Global GoRed GoRed (Bulldog) GuestConduit Impacket Impacket wmiexec.py Imperial Kitten InfoCollector JavaScript payloads Junction Katz Stealer Kimsuky LittleDaemon LockBit LockBit 3.0 LogMeIn Resolve Malicious downloaders Megazord Mimikatz MuPDF MuddyViper MuddyWater Mythic agent NSSM NeuralExecutor Neursite Nmap Notepad++ N‑able OPENVAS OceanLotus PDQ Connect PEASS PEBBLEDASH POLLBLEND Panorama9 Panorama9 RMM PasswordStealer Pay2Key Payload Payload PhantomVAI PhantomVAI loader Phishing emails PowerShell PowerShell scripts PowerShower PS script PowerView ProcDump PsExec PuTTY PuTTY SSH client PureCrypter PureHVNC/PureRAT PureLogs Stealer RClone Red Likho RemCom Revsocks Rust dropper RustVoralix SQLMap ScoringMathTea ScreenConnect Set-Alias Sharp7Extend SimpleHelp SlowStepper SocGholish Spear-phishing Splashtop Remote (SRManager.exe) SpyDealer Sting TWOSTROKE Telegram TightVNC Viewer Tuoni UNC1549 Unknown VAX‑One VBCloud VBS files VBScript VBShower VIPERTUNNEL Velociraptor Visual Studio Code Void Warlock Warp Warp RAT WinDealer WinMerge Windows Subsystem for Linux (WSL) XWorm XenAllPasswordPro YARA ZEROLOT ZeronetKit grabff kidsRAT ngrok nltest patched Process Explorer phishing

ATT&CK Tactic Coverage

Reconnaissance Resource Development Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command & Control Exfiltration Impact

Diamond Model of Intrusion

Adversary · Capability · Infrastructure · Victim

Completeness
4/4
Adversary
Confidence
55%

4bid

Type: Unknown Active
SHADOW-VOID-042 Storm-0978 Tropical Scorpius APT44 Seashell Blizzard +25 more
Victim
70%

Targeted Sectors

healthcare government manufacturing aerospace financial-services transportation defense energy critical-infrastructure food-agriculture pharmaceutical chemical retail education construction telecommunications media utilities aviation maritime oil-gas information-technology entertainment

Targeted Countries

Belarus Egypt Kazakhstan Russian Federation Syrian Arab Republic United Arab Emirates RU CN US AE BR EG SY KZ BY UA IL IR TW FR CA GB DE IN MX SA

Diamond Model Meta-Features

Phase

Actions on Objectives

Result

Active

Direction

Adversary → Infrastructure → Victim

Methodology

Unknown

Resources

government

Adversary → Capability
Adversary → Infrastructure
Capability → Victim
Infrastructure → Victim
Diamond Model edges

Activity Threads Kill chain phase → Diamond Model event mapping

Leaving Threaticon

This link opens an external site that isn't part of the platform.