Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Kill Chain & Diamond Model Analysis

Map a threat actor or campaign across the Cyber Kill Chain and Diamond Model of Intrusion.

PassCV (threat actor)
Risk
84
Critical
55 techniques 68 tools/malware 1 vulnerabilities 39 IOCs 6/7 stages covered Deepest: Actions on Objectives
1 Reconnaissance
No data
2 Weaponization
1
T1588.002
Tool resource development
3 Delivery
3
T1195.002
T1566.001
4 Exploitation
9
T1053.005
T1059.001
PowerShell execution
T1059.003
T1059.004
Unix Shell execution
T1569.002
T1546.008
Accessibility Features privilege escalation
5 Installation
13
T1003.001
LSASS Memory credential access
T1110.002
Password Cracking credential access
T1133
T1136.001
Local Account persistence
T1543.003
Windows Service persistence
6 Command & Control
12
T1005
T1056.001
Keylogging collection
T1008
Fallback Channels command and control
T1071.001
Web Protocols command and control
T1071.002
File Transfer Protocols command and control
T1071.004
DNS command and control
T1090
Proxy command and control
T1102.001
Dead Drop Resolver command and control
T1104
Multi-Stage Channels command and control
T1105
Ingress Tool Transfer command and control
T1568.002
Domain Generation Algorithms command and control
T1021.001
Remote Desktop Protocol lateral movement
7 Actions on Objectives
18
T1553.002
Code Signing defense impairment
T1055
T1070.003
T1070.004
T1078
T1197
BITS Jobs stealth
T1218.001
T1218.011
Rundll32 stealth
T1480.001
T1542.003
Bootkit stealth
T1574.001
DLL stealth
T1574.006
T1070.001
T1100
T1574.002
Stage risk: Critical High Medium None

ATT&CK Tactic Coverage

Reconnaissance Resource Development Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command & Control Exfiltration Impact

Diamond Model of Intrusion

Adversary · Capability · Infrastructure · Victim

Completeness
4/4
Adversary
Confidence
50%

PassCV

Type: Unknown Active
TG-3279 Winnti Umbrella China Cracking Group tracked as indicating active exploitation +4 more
Victim
70%

Targeted Sectors

gaming financial-services government energy pharmaceutical telecommunications media manufacturing healthcare defense retail utilities aerospace construction aviation education

Targeted Countries

CN US IN FR IT JP KR PK TW TR NG GB RU DE BR SG KZ NL

Diamond Model Meta-Features

Phase

Actions on Objectives

Result

Active

Direction

Adversary → Infrastructure → Victim

Methodology

Unknown

Resources

government

Adversary → Capability
Adversary → Infrastructure
Capability → Victim
Infrastructure → Victim
Diamond Model edges

Activity Threads Kill chain phase → Diamond Model event mapping

Leaving Threaticon

This link opens an external site that isn't part of the platform.