Initial access

Every intrusion starts somewhere, and the routes are a short and stable list.

Phishing, stolen credentials, an unpatched internet-facing service, a supplier, or something exposed that should not have been. The list barely changes year to year, which is unusually useful: a small number of defences cover most of the ways anybody gets in at all.

Checked against the primary source.

More on Threat actors & ATT&CK