Exploitation of Edge Network Devices (e.g., VPNs, Firewalls, Routers)
Living-off-the-Land (LotL)
Web Shell Deployment
Credential Access via Memory Injection
Spearphishing
Command and Control (C2) via Legitimate Cloud Services
Lateral Movement using Valid Accounts