Resource Development
Before an attack begins, adversaries acquire infrastructure, develop capabilities, and establish the tools they will use. ManySignal's threat intelligence integration surfaces newly created attack infrastructure before it reaches your environment.
TI Coverage
- TI sources supported
- 12+
- Infra IOC enrichments
- Real-time
- Actor tracking feeds
- 8+
Context
How adversaries prepare before attacking
Sophisticated threat actors invest significant time in resource development before launching targeted attacks. Domain registrations that mimic the victim organisation, VPS provisioning in unusual geographies, and acquisition of valid code signing certificates are all preparatory steps that threat intelligence platforms track and correlate with known threat actors.
ManySignal's threat intelligence integrations (Recorded Future, MISP, VirusTotal) provide real-time enrichment: when any log event touches a domain or IP associated with known threat actor infrastructure, ManySignal surfaces the attribution immediately — transforming a routine DNS lookup into an early warning of a targeted attack.
Resource Development techniques and TI coverage
Acquire Infrastructure
Registering domains, acquiring hosting, and provisioning cloud accounts for attack infrastructure.
Compromise Infrastructure
Hijacking legitimate web servers, VPS hosts, or cloud accounts to use as attack infrastructure.
Develop Capabilities
Building malware, exploits, and tooling customised for the target environment.
Obtain Capabilities
Purchasing or downloading existing malware, exploit frameworks, and tools from criminal markets.
Resource Development: frequently asked questions
What is ATT&CK Resource Development (TA0042)?
Resource Development covers the preparations adversaries make before launching an attack — acquiring attack infrastructure, developing or purchasing malware, and establishing capabilities. Like Reconnaissance, it occurs before Initial Access and is largely undetectable through internal telemetry alone.
How does ManySignal help with Resource Development awareness?
ManySignal integrates with threat intelligence platforms (Recorded Future, MISP) that track adversary infrastructure. When a newly registered domain or VPS IP associated with a known threat actor appears in your logs, ManySignal surfaces this correlation immediately — even for what appear to be benign DNS queries.
Surface attacker infrastructure before it reaches your environment
ManySignal's threat intelligence integrations identify known attack infrastructure in your logs — giving you early warning of targeted campaigns.