SIGNAL//DESK
AI securitysrc: MITRE ATLAS

Resource Development

Think of this as the 'prep work' phase. Before an attacker can launch a cyberattack, they need to gather their tools and supplies—like buying fake IDs, renting servers, or stealing login credentials—so they have everything ready to carry out their plan.

Resource Development encompasses the tactical phase where an adversary acquires, creates, or compromises the necessary assets to facilitate their operations. This includes procuring infrastructure, establishing accounts, or obtaining AI-specific artifacts that provide the foundational support required to execute subsequent stages of an attack lifecycle.

The adversary is trying to establish resources they can use to support operations. Resource Development consists of techniques that involve adversaries creating, purchasing, or compromising/stealing resources that can be used to support targeting. Such resources include AI artifacts, infrastructure, accounts, or capabilities. These resources can be leveraged by the adversary to aid in other phases of the adversary lifecycle, such as [AI Attack Staging](/tactics/AML.TA0001).

evolution

  1. 2013 · history
    Emergence of Infrastructure-as-a-Service (IaaS) Abuse

    Adversaries began systematically leveraging cloud platforms to host command-and-control infrastructure, shifting away from compromised personal servers.

  2. 2017 · history
    Rise of Automated Account Creation

    The proliferation of sophisticated botnets enabled adversaries to automate the mass registration of social media and email accounts for large-scale influence operations.

  3. 2020 · history
    Formalization in MITRE ATT&CK

    MITRE officially introduced the 'Resource Development' tactic as a standalone category to categorize adversary efforts in acquiring, compromising, or establishing operational infrastructure.

  4. 2023 · history
    AI-Driven Synthetic Identity Generation

    Adversaries began utilizing generative AI to create realistic synthetic identities and deepfake assets to bypass automated identity verification and trust-based security controls.


← all terms