APT
APT tradecraft: how state-grade intrusions actually unfold
The NCSC and CISA describe APT campaigns as staged intrusions, not single exploits - with living-off-the-land techniques.
An APT rarely 'hacks' a box; it compromises it step by step. Initial access via phishing or an exposed edge device, privilege escalation, lateral movement through Active Directory, then persistence and exfiltration. Detection wins by instrumenting the high-value steps: anomalous auth, service accounts, odd DNS/HTTPS egress. A Virtual CISO prioritises attack-surface reduction (MFA, segmentation, patching) and a response plan mapped to NCSC guidance.
The MiliSec method
What we run for our Virtual CISO clients:
- Log authentications and service accounts.
- Hunt lateral movement, not just malware.
- Map crown-jewel access paths.
Going further
APTs do not hunt rare bugs, they hunt default configs and forgotten accounts.
Detection wins by instrumenting the high-value steps: odd authentications and lateral movement.
Besoin d'un RSSI Virtuel ?
Notre veille alimente nos recommandations de conformité. Contactez-nous pour un diagnostic.
Demander un audit