•
recon, weaponize, deliver, exploit, install, command and control, act on objectives
•
ATT&CK catalogs observed tactics and techniques, so you can map detection coverage
•
phishing, exposed services, valid accounts and trusted third parties dominate
•
after access, the attacker's next goal is surviving a reboot and a password reset
•
reused local administrator credentials are how one host becomes the whole estate
•
unusual volume, destination and timing over egress, not suspicious file names
•
SP 800-61r3 (April 2025) rebuilt the life cycle on the six CSF 2.0 Functions — Govern, Identify, Protect, Detect, Respond, Recover — and maps the older preparation / detection & analysis / containment-eradication-recovery / post-incident phases onto them
•
containment prevents an incident expanding and comes first; deliberately delaying it to watch an attacker and gather evidence is a legal-sign-off decision, not a default, because the delay lets them escalate
•
three copies, two media, one offline; a mounted backup gets encrypted too