Get fresh insights, pro tips, and thought starters–only the best of posts for you.
MITRE ATT&CK Resource Development is the tactic that describes how adversaries establish, acquire, or prepare the resources needed to support a cyberattack before they compromise a target. In the MITRE ATT&CK Enterprise framework, it is identified as Tactic TA0042 and represents activities that typically occur before the Initial Access stage of an attack.
Rather than interacting directly with a victim’s environment, attackers use the Resource Development phase to build the infrastructure, identities, capabilities, and content required to conduct future operations. These preparations help adversaries launch phishing campaigns, host malware, manage command-and-control infrastructure, or impersonate legitimate organizations once an attack begins.
Understanding this tactic enables defenders to recognize early indicators of malicious activity and strengthen security controls before an attacker gains a foothold.
Cyberattacks rarely begin with exploitation alone. Most threat actors spend time preparing the tools and infrastructure needed to increase the success of their campaigns.
MITRE ATT&CK Resource Development helps organizations:
Recognizing these activities allows security teams to disrupt attacks before they reach the Initial Access stage.
MITRE ATT&CK includes several techniques under the Resource Development tactic.
| Technique | Purpose |
|---|---|
| Acquire Infrastructure | Obtain domains, servers, cloud resources, or other infrastructure used during attacks |
| Develop Capabilities | Create malware, exploits, phishing kits, or malicious tools |
| Establish Accounts | Create email, cloud, or social media accounts to support operations |
| Obtain Capabilities | Acquire malware, exploits, certificates, or other offensive tools from third parties |
| Stage Capabilities | Prepare malware or infrastructure for later deployment |
| Generate Content | Create phishing emails, fake documents, websites, images, or other social engineering content |
These techniques help adversaries prepare the resources they need before targeting victims.
Resource Development occurs before attackers attempt to compromise a target. Once preparations are complete, adversaries typically move to tactics such as Initial Access, Execution, Persistence, and Privilege Escalation.
By mapping attacker behavior to MITRE ATT&CK, organizations can better understand the full attack lifecycle and identify opportunities to detect or disrupt malicious activity at earlier stages.
Hexnode XDR helps security teams monitor managed Windows endpoints for suspicious activity associated with attacker preparation and follow-on attack stages. It provides centralized visibility into endpoint telemetry, threat detections, incidents, and MITRE ATT&CK mappings, helping analysts investigate malicious behaviors that may indicate an emerging attack.
Hexnode XDR also supports incident investigation and response actions such as endpoint isolation. While it does not detect every off-network Resource Development activity, it helps security teams identify attacker behavior once malicious infrastructure, tools, or techniques begin interacting with managed endpoints.
Yes. Organizations may detect indicators such as newly registered lookalike domains, phishing infrastructure, fake social media accounts, malicious cloud resources, or threat intelligence linking attacker-controlled infrastructure to future campaigns.
Nearly all sophisticated threat actors, including ransomware groups, advanced persistent threat (APT) groups, and cybercriminal organizations, perform some form of Resource Development to improve the effectiveness of their operations before launching an attack.