← All tactics

Resource Development

50 techniques · out of scope

What it is

everything an attacker builds or acquires before an intrusion starts. Registering a lookalike domain, renting server space for command-and-control, buying or building malware, compromising a legitimate account or a third-party service to use as staging infrastructure, obtaining code-signing certificates. The intrusion's tooling and infrastructure exist before the first packet ever reaches the target.

Why it isn't covered here

this happens entirely on infrastructure the attacker owns or controls, before any contact with the target network. Every range on this platform is a captured victim environment, so it can only ever contain evidence of what happened inside that network. An attacker's own staging server, wherever it lives, was never part of what got captured, and never could be.

Where the visibility actually comes from, in a real SOC

almost entirely outside your own environment. Threat intelligence on newly registered or recently active domains, passive DNS correlating infrastructure across different campaigns, certificate-transparency logs flagging a certificate issued for a lookalike domain, and vendor or ISAC reporting that ties a piece of infrastructure to a known actor. None of it is something your own SIEM will ever show you directly, which is exactly why it's a separate discipline (threat intelligence) rather than something folded into SOC detection work.

The techniques below are indexed for reference so the matrix stays complete. They are not pending write-ups.