A ten-stage intrusion, mapped to the ATT&CK framework. Each stage shows the command an operator would run, the technique ID, and the specific defensive control that would have caught it.
Adversary performs active network scanning to identify live hosts and exposed services. This phase maps the attack surface and identifies potential ingress points.
View T1595 on MITRE ATT&CK →External attack surface monitoring. If you do not know what you expose, you cannot close it.
An external assessment identifies which of these stages are reachable in your environment, and what to fix first.