Exploitation of Edge Vulnerabilities (VPNs, Firewalls)
Living-off-the-Land (LotL) using PowerShell and WMI
Custom Web Shell deployment
Spear-phishing with specialized malware attachments
Credential Harvesting via LSASS memory dumping
Data Exfiltration via encrypted protocols (HTTPS/DNS)
Lateral Movement using SMB and RDP