risk
Coordinated multi-stage / APT campaigns
Adversary coordinates continuous, adaptive, multi-staged campaigns (hopping across systems, combining insider/outsider/supply-chain vectors, spreading from existing presence) to persist and progressively undermine mission/business functions.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- cyber_security
- domain
- Logging, Monitoring & Detection
- Incident Management & Response
- Network & Communications Security
- taxonomy
- nist-800-30-threat-event
- inherent_rating
- high
Details
- risk_id
- cyber-coordinated-campaign
- category
- cyber_security
- likelihood
- medium
- impact
- critical
- inherent_rating
- high
- treatment
- mitigate
- taxonomies
- nist-800-30-threat-event
Source
No record-specific source URL is provided.
Connections
- UC-IR-09 — Recover from incidents using defined initiation criteria mitigates Coordinated multi-stage / APT campaigns
- strength
- related
- rationale
- Gating recovery on confirmed eradication and forensic preservation before restoration prevents re-compromise by a persistent adversary during return to production.
- UC-NET-06 — Enforce separation with hardware and software mechanisms mitigates Coordinated multi-stage / APT campaigns
- strength
- related
- rationale
- Hardware/software-enforced separation of critical security functions resists implant persistence and tampering during a campaign.
- UC-BCDR-13 — Operate continuous security protection services mitigates Coordinated multi-stage / APT campaigns
- strength
- primary
- rationale
- Endpoint/network protection plus security monitoring block malware and lateral movement across multi-stage campaigns.
- UC-NET-01 — Segment networks and defend the external boundary mitigates Coordinated multi-stage / APT campaigns
- strength
- related
- rationale
- Internal segmentation with deny-by-default limits an intruder's lateral hopping between systems, containing campaign spread.
- UC-NET-04 — Isolate system, user, and security functions mitigates Coordinated multi-stage / APT campaigns
- strength
- related
- rationale
- Isolating functions and partitioning domains limits an adversary's lateral movement and progression across systems.
- UC-IR-05 — Assess and validate incident scope, impact, and magnitude mitigates Coordinated multi-stage / APT campaigns
- strength
- related
- rationale
- Estimating the scope of affected systems (DE.AE-04) reveals the spread and extent of a multi-stage campaign to inform containment.
- UC-IR-06 — Respond to, contain, and eradicate declared incidents mitigates Coordinated multi-stage / APT campaigns
- strength
- primary
- rationale
- Containment stops lateral movement/spread and eradication removes artifacts and closes exploited weaknesses — the direct defense against a persisting multi-stage campaign (RS.MI-01/02).
- UC-LOG-09 — Monitor providers and exchange audit data across organizations mitigates Coordinated multi-stage / APT campaigns
- strength
- related
- rationale
- Monitoring provider activity against contractual obligations detects the supply-chain vector campaigns exploit to enter.
- UC-LOG-05 — Correlate and analyze events centrally with threat intel mitigates Coordinated multi-stage / APT campaigns
- strength
- primary
- rationale
- Central correlation across multiple sources enriched with threat intel connects dispersed signals to detect multi-stage APT campaigns.
- UC-IR-07 — Investigate incidents and preserve evidence and records mitigates Coordinated multi-stage / APT campaigns
- strength
- related
- rationale
- Root-cause analysis establishes the full extent and method of a multi-stage intrusion so eradication can be made complete.
- UC-LOG-04 — Continuously monitor systems for anomalous activity mitigates Coordinated multi-stage / APT campaigns
- strength
- primary
- rationale
- Perimeter-and-interior monitoring for IOCs and anomalous behavior detects lateral movement and persistence of multi-stage campaigns.
- UC-LOG-03 — Protect audit logs and retain them for required periods mitigates Coordinated multi-stage / APT campaigns
- strength
- related
- rationale
- Immutable log storage and tamper alerts counter the anti-forensic log-deletion tactic APT campaigns use to hide persistence.