Reference · Attack Chain Walkthrough

MITRE ATT&CK, stage by stage.

A ten-stage intrusion, mapped to the ATT&CK framework. Each stage shows the command an operator would run, the technique ID, and the specific defensive control that would have caught it.

Stage 1 of 10 Reconnaissance
Reconnaissance
T1595

Adversary performs active network scanning to identify live hosts and exposed services. This phase maps the attack surface and identifies potential ingress points.

View T1595 on MITRE ATT&CK →
Defensive control

External attack surface monitoring. If you do not know what you expose, you cannot close it.

See this run against your own perimeter.

An external assessment identifies which of these stages are reachable in your environment, and what to fix first.

View the assessment