Every cyberattack begins with an entry point. Initial Access and Execution are the most critical stages, as they determine whether attackers succeed or fail early — before they ever get the chance to move laterally or achieve their objective.
Common Initial Access Techniques
T1566 — Phishing. Still the single most common entry point for attackers. Malicious links or attachments trick a user into executing code or handing over credentials — spear-phishing in particular remains highly effective against even well-trained staff.
T1190 — Exploit Public-Facing Application. Attackers scan for and exploit vulnerabilities in internet-facing web apps, VPN gateways, and APIs. This is why external attack surface management and timely patching matter so much.
T1133 — External Remote Services. Weakly secured VPNs, RDP, or remote access tools without MFA are a favorite target — the Colonial Pipeline attack is a well-known example of this technique in action.
T1078 — Valid Accounts. Rather than "breaking in," attackers simply log in — using credentials obtained through phishing, credential stuffing, or prior breaches. This is why MFA and anomalous login detection are so critical.
From Access to Execution
Getting in is only half the equation. Once inside, attackers need to execute code to establish a foothold:
T1059 — Command and Scripting Interpreter. PowerShell, Bash, and Python scripts are frequently abused to run malicious payloads while blending in with legitimate administrative activity.
T1204 — User Execution. Relies on a user opening a malicious file or clicking a link — often the final step of a phishing chain.
T1203 — Exploitation for Client Execution. Exploits vulnerabilities in client applications (browsers, document readers) to execute code without obvious user interaction.
Why These Stages Matter Most for SOC Teams
The earlier in the attack chain a SOC can detect and respond, the less damage an attacker can do. Initial Access and Execution are the highest-leverage stages to focus detection engineering on, because:
- They generate observable signals (unusual logins, new processes, script execution) before an attacker has established persistence
- Blocking here prevents everything downstream — lateral movement, privilege escalation, exfiltration
- Many of these techniques map cleanly to log sources SOCs already collect: email gateways, EDR, authentication logs, and web/proxy logs
Practical SOC Takeaways
- Correlate phishing-reported emails with authentication anomalies to catch credential harvesting early
- Alert on script interpreters (PowerShell, wscript) spawning from Office applications — a classic initial-execution pattern
- Monitor external-facing services for unpatched CVEs and unusual authentication patterns
- Treat MFA bypass or absence on remote access services as a standing high-priority finding, not a background risk
Mapping real detections back to these specific technique IDs turns a vague "suspicious activity" alert into an actionable, documented incident — which is the whole point of using ATT&CK as a working framework, not just a reference chart.