Resource Development
Think of this as the 'prep work' phase. Before an attacker can launch a cyberattack, they need to gather their tools and supplies—like buying fake IDs, renting servers, or stealing login credentials—so they have everything ready to carry out their plan.
Resource Development encompasses the tactical phase where an adversary acquires, creates, or compromises the necessary assets to facilitate their operations. This includes procuring infrastructure, establishing accounts, or obtaining AI-specific artifacts that provide the foundational support required to execute subsequent stages of an attack lifecycle.
The adversary is trying to establish resources they can use to support operations. Resource Development consists of techniques that involve adversaries creating, purchasing, or compromising/stealing resources that can be used to support targeting. Such resources include AI artifacts, infrastructure, accounts, or capabilities. These resources can be leveraged by the adversary to aid in other phases of the adversary lifecycle, such as [AI Attack Staging](/tactics/AML.TA0001).
evolution
- 2013 · historyEmergence of Infrastructure-as-a-Service (IaaS) Abuse
Adversaries began systematically leveraging cloud platforms to host command-and-control infrastructure, shifting away from compromised personal servers.
- 2017 · historyRise of Automated Account Creation
The proliferation of sophisticated botnets enabled adversaries to automate the mass registration of social media and email accounts for large-scale influence operations.
- 2020 · historyFormalization in MITRE ATT&CK
MITRE officially introduced the 'Resource Development' tactic as a standalone category to categorize adversary efforts in acquiring, compromising, or establishing operational infrastructure.
- 2023 · historyAI-Driven Synthetic Identity Generation
Adversaries began utilizing generative AI to create realistic synthetic identities and deepfake assets to bypass automated identity verification and trust-based security controls.