Categorize penetration-test evidence by ATT&CK tactic to improve attack-path reporting.
Place each internal-test note in the ATT&CK-style tactic bucket it best supports. Discovery Credential Access Lateral Movement Collection Approved subnet scan identifies SMB and WinRM on three in-scope servers. Readable deployment config contains a redacted service account password. Approved test credential authenticates to the lab file server over SMB. Finance export share is readable by the compromised service account. Local group enumeration shows the service account is in Backup Operators. Password hash is captured from a misconfigured internal service banner. One-hop remote command execution succeeds on an approved validation host. Database backup directory lists customer export filenames but files are…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in