M ManySignal
TA0042 ATT&CK Tactic

Resource Development

Before an attack begins, adversaries acquire infrastructure, develop capabilities, and establish the tools they will use. ManySignal's threat intelligence integration surfaces newly created attack infrastructure before it reaches your environment.

TI Coverage

TI sources supported
12+
Infra IOC enrichments
Real-time
Actor tracking feeds
8+

Context

How adversaries prepare before attacking

Sophisticated threat actors invest significant time in resource development before launching targeted attacks. Domain registrations that mimic the victim organisation, VPS provisioning in unusual geographies, and acquisition of valid code signing certificates are all preparatory steps that threat intelligence platforms track and correlate with known threat actors.

ManySignal's threat intelligence integrations (Recorded Future, MISP, VirusTotal) provide real-time enrichment: when any log event touches a domain or IP associated with known threat actor infrastructure, ManySignal surfaces the attribution immediately — transforming a routine DNS lookup into an early warning of a targeted attack.

Resource Development techniques and TI coverage

T1583 Low

Acquire Infrastructure

Registering domains, acquiring hosting, and provisioning cloud accounts for attack infrastructure.

T1584 Low

Compromise Infrastructure

Hijacking legitimate web servers, VPS hosts, or cloud accounts to use as attack infrastructure.

T1587 Low

Develop Capabilities

Building malware, exploits, and tooling customised for the target environment.

T1588 Low

Obtain Capabilities

Purchasing or downloading existing malware, exploit frameworks, and tools from criminal markets.

Resource Development: frequently asked questions

What is ATT&CK Resource Development (TA0042)?

Resource Development covers the preparations adversaries make before launching an attack — acquiring attack infrastructure, developing or purchasing malware, and establishing capabilities. Like Reconnaissance, it occurs before Initial Access and is largely undetectable through internal telemetry alone.

How does ManySignal help with Resource Development awareness?

ManySignal integrates with threat intelligence platforms (Recorded Future, MISP) that track adversary infrastructure. When a newly registered domain or VPS IP associated with a known threat actor appears in your logs, ManySignal surfaces this correlation immediately — even for what appear to be benign DNS queries.

Surface attacker infrastructure before it reaches your environment

ManySignal's threat intelligence integrations identify known attack infrastructure in your logs — giving you early warning of targeted campaigns.