Kill Chain & Diamond Model Analysis
Map a threat actor or campaign across the Cyber Kill Chain and Diamond Model of Intrusion.
ta2730
(threat actor)
7 techniques
35 tools/malware
0 vulnerabilities
39 IOCs
1/7 stages covered
Deepest: Actions on Objectives
›
›
›
›
›
›
7
Actions on Objectives
7
T1005 - Data from Local System
T1059.003 - Command and Scripting Interpreter: PowerShell
T1078.004 - Valid Accounts: Default Accounts
T1110.001 - Brute Force: Password Guessing
T1204.002 - User Execution: Malicious File
T1566.001 - Phishing (Spearphishing Link)
Stage risk:
Critical
High
Medium
None
Indicators of Compromise (39)
ATT&CK Tactic Coverage
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command & Control
Exfiltration
Impact
Diamond Model of Intrusion
Adversary · Capability · Infrastructure · Victim
ta2730
Type: Unknown Active
tracked as
7 technique(s) 35 tool(s)/malware
Targeted Sectors
financial-services
government
defense
energy
hospitality
Targeted Countries
JP
CA
AU
SG
US
TR
MX
ES
CN
KP
IN
TW
IT
Diamond Model Meta-Features
Phase
Actions on Objectives
Direction
Adversary → Infrastructure → Victim
Adversary → Capability
Adversary → Infrastructure
Capability → Victim
Infrastructure → Victim
Diamond Model edges