Personal ATT&CK heatmap

The 14 tactics of MITRE ATT&CK Enterprise, with the techniques I cover defensively lit up. My CV in the industry's native language — hover (or focus) a technique to see what covers it.

Control in productionOccasional experience / labOutside my scope40 techniques mapped · 23 prod · 17 lab

Reconnaissance

T1595Active Scanningcovered by: FortiGate NGFW + IPS · edge scan detection · Ascendi
T1592Gather Victim Host Infocovered by: Enumeration during internal pentests · Hardsecure
T1589Gather Victim Identity Infocovered by: OSINT in red-team exercises · CTFs

Resource Development

T1583Acquire Infrastructurecovered by: Standing up attack infra in lab · k3s homelab
T1587Develop Capabilitiescovered by: Own scanning/scripting tooling · Python/Go

Initial Access

T1190Exploit Public-Facing Appcovered by: FortiWeb WAF + vulnerability assessment (Rapid7 InsightVM) · Ascendi
T1566Phishingcovered by: FortiMail Security Email Gateway · attachment sandboxing · Ascendi
T1133External Remote Servicescovered by: NGFW + Secure Access (NSE 7) · VPN and ZTNA · Ascendi
T1078Valid Accountscovered by: IAM + Active Directory · MFA and access reviews · Ascendi

Execution

T1059Command & Scripting Interpretercovered by: FortiEDR · behavioural script detection · Ascendi
T1204User Executioncovered by: SEG + EDR + awareness · Ascendi
T1053Scheduled Task/Jobcovered by: SIEM detection via baseline rules · FortiSIEM

Persistence

T1098Account Manipulationcovered by: IAM/AD + privilege-change alerts in SIEM · Ascendi
T1547Boot/Logon Autostartcovered by: FortiEDR telemetry · ad-hoc investigation
T1136Create Accountcovered by: Account-creation monitoring · FortiSIEM · Ascendi

Privilege Escalation

T1068Exploit for Privilege Escalationcovered by: Patch management + VA (Rapid7 InsightVM) · Ascendi
T1548Abuse Elevation Controlcovered by: Windows Privilege Escalation (training) · lab
T1078Valid Accountscovered by: Least-privilege in AD · access reviews · Ascendi

Defense Evasion

T1562Impair Defensescovered by: EDR/SIEM tamper and health alerts · Ascendi
T1070Indicator Removalcovered by: Log forwarding to SIEM (off-host) · FortiSIEM
T1027Obfuscated Files/Infocovered by: Obfuscation detection in sandbox · SEG/EDR
T1036Masqueradingcovered by: SIEM correlation rules · FortiSIEM

Credential Access

T1110Brute Forcecovered by: AD lockout + SIEM brute-force detection · Ascendi
T1003OS Credential Dumpingcovered by: FortiEDR · LSASS-access detection · Ascendi
T1555Credentials from Storescovered by: Ethical hacking (training) · lab

Discovery

T1046Network Service Discoverycovered by: NGFW segmentation + internal-scan detection · Ascendi
T1087Account Discoverycovered by: SIEM baseline of AD queries · FortiSIEM
T1018Remote System Discoverycovered by: Enumeration in pentests · Hardsecure

Lateral Movement

T1021Remote Servicescovered by: NGFW micro-segmentation + east-west rules · Ascendi
T1570Lateral Tool Transfercovered by: Anomalous-transfer detection · FortiEDR/SIEM

Collection

T1005Data from Local Systemcovered by: File-access telemetry · FortiEDR
T1114Email Collectioncovered by: SEG controls and auditing · FortiMail · Ascendi

Command & Control

T1071Application Layer Protocolcovered by: NGFW + TLS inspection + DNS filtering · Ascendi
T1573Encrypted Channelcovered by: SSL/TLS inspection at the edge · FortiGate · Ascendi
T1090Proxycovered by: Anonymizer/Tor detection · threat-intel feeds

Exfiltration

T1041Exfiltration Over C2 Channelcovered by: Egress-traffic analysis in NGFW + SIEM · Ascendi
T1048Exfil Over Alternative Protocolcovered by: DNS/ICMP anomaly rules · FortiSIEM

Impact

T1486Data Encrypted for Impactcovered by: EDR anti-ransomware + backups/BCP · SANS Ransomware '22 · Ascendi
T1490Inhibit System Recoverycovered by: Shadow-copy deletion detection · FortiEDR
T1498Network Denial of Servicecovered by: Cloudflare DDoS protection + NGFW · infrastructure