Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started

Kill Chain & Diamond Model Analysis

Map a threat actor or campaign across the Cyber Kill Chain and Diamond Model of Intrusion.

Mustang Panda (threat actor)
Risk
88
Critical
107 techniques 60 tools/malware 1 vulnerabilities 40 IOCs 7/7 stages covered Deepest: Actions on Objectives
1 Reconnaissance
2
T1593
T1598.003
Spearphishing Link reconnaissance
2 Weaponization
15
T1583
Acquire Infrastructure resource development
T1583.001
Domains resource development
T1583.006
Web Services resource development
T1585
Establish Accounts resource development
T1585.002
Email Accounts resource development
T1586
Compromise Accounts resource development
T1586.002
Email Accounts resource development
T1587
Develop Capabilities resource development
T1587.001
Malware resource development
T1588
Obtain Capabilities resource development
T1588.002
Tool resource development
T1588.003
Code Signing Certificates resource development
T1588.004
Digital Certificates resource development
T1608
Stage Capabilities resource development
T1608.001
Upload Malware resource development
3 Delivery
3
T1566
Phishing initial access
T1566.001
T1566.002
Spearphishing Link initial access
4 Exploitation
16
T1053.005
T1059.001
PowerShell execution
T1059.003
T1059.005
Visual Basic execution
T1059.007
JavaScript execution
T1106
Native API execution
T1129
T1204.001
T1204.002
T1546
Event Triggered Execution privilege escalation
5 Installation
22
T1003
OS Credential Dumping credential access
T1003.001
LSASS Memory credential access
T1003.003
NTDS credential access
T1003.006
DCSync credential access
T1557
Adversary-in-the-Middle credential access
T1057
T1069.002
Domain Groups discovery
T1087
T1087.002
T1518
T1654
T1176.002
IDE Extensions persistence
T1505.003
Web Shell persistence
6 Command & Control
19
T1074
Data Staged collection
T1074.001
T1119
T1560
T1560.001
T1560.003
T1001
Data Obfuscation command and control
T1001.003
T1071
Application Layer Protocol command and control
T1071.001
Web Protocols command and control
T1095
T1102
Web Service command and control
T1105
Ingress Tool Transfer command and control
T1219.001
IDE Tunneling command and control
T1219.002
Remote Desktop Software command and control
T1572
Protocol Tunneling command and control
T1573
Encrypted Channel command and control
T1573.001
Symmetric Cryptography command and control
7 Actions on Objectives
31
T1553.002
Code Signing defense impairment
T1052.001
T1567.002
T1027.007
T1027.012
T1027.016
T1036
T1036.007
T1036.008
T1070
T1070.004
T1070.006
Timestomp stealth
T1205
T1218.004
T1218.005
Mshta stealth
T1564
T1574.001
DLL stealth
T1622
T1678
Stage risk: Critical High Medium None

ATT&CK Tactic Coverage

Reconnaissance Resource Development Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command & Control Exfiltration Impact

Detection Coverage

107 strategies
7/7 stages covered

Diamond Model of Intrusion

Adversary · Capability · Infrastructure · Victim

Completeness
4/4
Adversary
Confidence
70%

Mustang Panda

Type: Nation-State Active
HoneyMyte Temp.Hex BRONZE PRESIDENT Red Lich BASIN +103 more
Capability
82%
107 technique(s) 60 tool(s)/malware 1 CVE(s)
collection
command and control
credential access
defense impairment
Victim
70%

Targeted Sectors

government ngo financial-services defense telecommunications healthcare critical-infrastructure education manufacturing non-profit energy media aviation think-tank hospitality aerospace pharmaceutical maritime retail gaming transportation utilities information-technology legal-services mining chemical nuclear entertainment oil-gas construction

Targeted Countries

British Indian Ocean Territory India CN US RU IN IR VN TW AU PK UA JP IL GB KR SA AE KP SG DE TR BY BR MX ES PL CA RO FR NG IT LB AZ KZ

Diamond Model Meta-Features

Phase

Actions on Objectives

Result

Active

Direction

Adversary → Infrastructure → Victim

Methodology

Nation-State

Resources

government

Adversary → Capability
Adversary → Infrastructure
Capability → Victim
Infrastructure → Victim
Diamond Model edges

Activity Threads Kill chain phase → Diamond Model event mapping

1 Reconnaissance

Capability (Techniques)

Capability (Malware)

Infrastructure

2 Weaponization

Capability (Malware)

Infrastructure

3 Delivery

Capability (Techniques)

Capability (Malware)

Infrastructure

4 Exploitation

Capability (Malware)

Infrastructure

5 Installation

Capability (Malware)

Infrastructure

6 Command & Control

Capability (Malware)

Infrastructure

7 Actions on Objectives

Capability (Malware)

Infrastructure

Leaving Threaticon

This link opens an external site that isn't part of the platform.