Incidents

Anatomy of modern intrusion

Confirmed incidents from public disclosures, and the pattern most of them share.

01 / Pattern

A representative sequence

  1. Stage 01

    Initial access: stolen credentials, a phished help desk, or an unpatched edge device

    Access

  2. Stage 02

    Quiet reconnaissance and privilege escalation using legitimate admin tools

    Discovery

  3. Stage 03

    Backups located and disabled or deleted

    Impact prep

  4. Stage 04

    Data staged and exfiltrated to attacker-controlled storage

    Theft

  5. Stage 05

    Encryption deployed — or skipped entirely in favour of pure data extortion

    Extortion

02 / Index

Incident record