logo

Threat Analytics and Activity Groups

ID: c80a1f42-2efb-5b0e-98a2-b7ffc70459c4

STIX ID: report--c80a1f42-2efb-5b0e-98a2-b7ffc70459c4

Feed Name: Dragos Blog

Date Published: 2018-02-27

Date Updated: 2026-04-27

...
...

This report argues for shifting from IOC-centric detection to behavioral analytics that track adversary TTPs, leveraging models like the Diamond Model to define activity groups by observable capabilities, infrastructure, and targeting. Using ICS-focused examples—such as DYMALLOY’s screenshot exfiltration and ELECTRUM’s use of PSExec and net use for lateral movement—it demonstrates how general behavior analytics can provide broader, forward-leaning detection while more specific, group-tuned variants enable higher-confidence, context-rich investigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.