Custodian of Private Histories | Keynote Speaker | Creator of https://t.co/sgaC8FxjAE | Author of Diving In: An Incident Responder’s Journey 📖
Aug 15, 2021 • 8 tweets • 2 min read
The modern intrusion life cycle.
[0] External Victim Scouting: Collect basic information about victim, external facing infrastructure, email accounts, public profiles.
[1] Initial Exploit/Actor Foothold: Wide pendulum swing, from zero-day and unpatched CVE exploits to phishing for credentials, to obtaining credentials for matching domain accounts to supply chain attacks, etc. Regardless of the chosen Initial Intrusion Vector (IIV)...