1/14
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Reconnaissance
Attacker gathers information about the target environment (org, users, tech stack) to plan operations and identify weaknesses
Resource Development
Attacker acquires, builds, or compromises infrastructure (domains, hosting, VPS, malware, tooling, accounts) that will be used in later stages of the attack
Initial Access
Attacker gains a foothold in the environment (phishing, exploiting public‑facing apps, abusing valid accounts, supply chain, drive‑by compromise)
Execution
Attacker runs malicious code or commands (scripts, binaries, macros, LOLBins) on a system to perform actions or deploy payloads
Persistence
Attacker sets up mechanisms to keep access across reboots, logoffs, and password changes (scheduled tasks, services, startup items, accounts)
Privilege Escalation
Attacker obtains higher‑level permissions (local admin, domain admin, system) by exploiting vulnerabilities, misconfigurations, or credentials
Stealth
Attacker evades detection by hiding activity, blending with normal behavior, and minimizing noise (living off the land, timestomping, log evasion)
Defense Impairment
Attacker disables, bypasses, or tampers with security controls and telemetry (EDR, AV, logging, SIEM, mail security, policies)
Credential Access
Attacker steals or harvests credentials and tokens (keylogging, LSASS dump, password spraying, brute force, phishing, token theft)
Discovery
Attacker maps systems, users, groups, shares, network paths, and directory structure to understand where valuable assets and paths exist
Lateral Movement
Attacker uses existing access and credentials to move to additional hosts, accounts, or segments (RDP, SMB, WinRM, remote services)
Collection
Attacker gathers and stages data of interest (files, emails, databases, screenshots, keylogs) in preparation for exfiltration or impact
Command and Control
Attacker maintains communication with compromised systems using C2 channels (HTTP/S, DNS, TLS, cloud services, custom protocols)
Exfiltration
Attacker moves collected data out of the environment (direct to attacker infrastructure, cloud storage, staged archives, covert channels)
Impact
Attacker disrupts, encrypts, corrupts, or destroys systems and data (ransomware, data wiping, service disruption, business operations damage