Companion-course connectionLiving Off the Land
Living off the land describes adversary use of legitimate system tools, interpreters, services, and administration features to blend malicious actions into ordinary operations.
Open article →Companion-course connectionCommand and Control Detection
Command and control detection identifies the channels, timing patterns, protocol misuse, infrastructure, and host behavior used to direct compromised systems.
Open article →Companion-course connectionInitial Access Techniques
Initial access techniques are the phishing, exploitation, credential, supply-chain, and trusted-relationship methods adversaries use to obtain a first foothold.
Open article →Companion-course connectionIP Addressing and Routing
IP addressing and routing explain how hosts identify network locations and how routers select paths that move packets between local and remote networks.
Open article →Companion-course connectionInitial Access — MITRE ATT&CK® Tactic TA0001
Adversaries obtain the first foothold through people, internet-facing services, remote access, trusted relationships, removable media, or other entry paths.
Open article →Companion-course connectionCybersecurity Risk Management
Cybersecurity risk management connects assets, threats, vulnerabilities, controls, consequences, uncertainty, priorities, and accountable decisions.
Open article →Companion-course connectionAI-Assisted Audit Governance
AI-assisted audit governance establishes approved uses, boundaries, validation, confidentiality, accountability, and documentation when auditors use AI tools.
Open article →Companion-course connectionCloud Threat Detection
Cloud threat detection identifies suspicious behavior across identities, control planes, workloads, networks, storage, and managed services.
Open article →Companion-course connectionCyber Kill Chain Analysis
Cyber Kill Chain analysis organizes adversary activity into stages so defenders can identify opportunities to disrupt an operation before its objective is achieved.
Open article →Companion-course connectionPenetration Testing Lifecycle
A penetration test moves through authorization, planning, reconnaissance, analysis, controlled exploitation, post-exploitation, evidence handling, reporting, cleanup, and retesting.
Open article →Companion-course connectionAI Risk Treatment Tracking
AI risk treatment tracking follows mitigation, transfer, avoidance, acceptance, or pursuit decisions from approval through implementation and validation.
Open article →Companion-course connectionAlert Triage
Alert triage is the rapid, evidence-based process of validating a security alert, estimating urgency and impact, and deciding the correct next action.
Open article →