Mandiant experts use their deep knowledge of attackers and the targeted attack life cycle, combined with an understanding of your unique environment, to determine the preventative measures you need to take throughout the various stages described below.
Mandiant’s depiction of the targeted attack life cycle illustrates the major phases of a typical intrusion. While not all attacks follow the exact flow of this model, the chart below provides a visual representation of the common attack life cycle.
- Initial reconnaissance: In this stage, the attacker researches the targeted company’s systems and employees and outlines a methodology for the intrusion. The attacker may also search for infrastructure that provides remote access to an environment or look for employees to target for social engineering attacks.
- Initial compromise: Here, the attacker successfully executes malicious code on one or more corporate systems. This usually occurs as the result of a social engineering attack or exploitation of a vulnerability on an internet-facing system.
- Establish foothold: Immediately following the initial compromise, the attacker maintains continued control over a recently compromised system. Typically, the attacker establishes a foothold by installing a persistent backdoor or downloading additional utilities to the compromised system.
- Escalate privileges: At this stage, the attacker obtains further access to corporate systems and data within the environment. Attackers often escalate their privileges through credential harvesting, keystroke logging, or subversion of authentication systems.
- Internal reconnaissance: Next, the attacker explores the organization’s environment to gain a better understanding of infrastructure, storage of information of interest, and the roles and responsibilities of key individuals.
- Move laterally: The attacker uses accounts obtained from the “escalate privileges” phase and moves laterally to additional systems within the compromised environment. Common lateral movement techniques include accessing network file shares, remote execution of commands, or accessing systems through remote login protocols such as remote desktop services (RDS) or secure shell (SSH).
- Maintain presence: The attacker ensures continued access to the environment by installing multiple variants of backdoors or by accessing remote access services such as the corporate virtual private network (VPN).
- Complete mission: The attacker accomplishes the objectives of the intrusion such as stealing intellectual property, financial data, mergers and acquisition information, or personally identifiable information (PII). In other cases, the objective of the mission might be a disruption of systems or services or destruction of data within the environment.
Understanding the steps attackers take is important to establish a plan to prevent such attacks and mitigate risks. Understanding the stages of a targeted attack life cycle is the first step. To help ensure your organization is prepared and able to prevent attacks, turn to Mandiant’s team of experts as your partner in cyber-readiness.