THE SAFEHOUSE / JOURNAL
MITRE ATT&CK Cyber Incident Matrix · Part 2 of 2

MITRE ATT&CK Cyber Incident Matrix (2026) — Part 2: Initial Access & Execution

25 February 2026· 2 min read

Every cyberattack begins with an entry point. Initial Access and Execution are the most critical stages, as they determine whether attackers succeed or fail early — before they ever get the chance to move laterally or achieve their objective.

Common Initial Access Techniques

T1566 — Phishing. Still the single most common entry point for attackers. Malicious links or attachments trick a user into executing code or handing over credentials — spear-phishing in particular remains highly effective against even well-trained staff.

T1190 — Exploit Public-Facing Application. Attackers scan for and exploit vulnerabilities in internet-facing web apps, VPN gateways, and APIs. This is why external attack surface management and timely patching matter so much.

T1133 — External Remote Services. Weakly secured VPNs, RDP, or remote access tools without MFA are a favorite target — the Colonial Pipeline attack is a well-known example of this technique in action.

T1078 — Valid Accounts. Rather than "breaking in," attackers simply log in — using credentials obtained through phishing, credential stuffing, or prior breaches. This is why MFA and anomalous login detection are so critical.

From Access to Execution

Getting in is only half the equation. Once inside, attackers need to execute code to establish a foothold:

T1059 — Command and Scripting Interpreter. PowerShell, Bash, and Python scripts are frequently abused to run malicious payloads while blending in with legitimate administrative activity.

T1204 — User Execution. Relies on a user opening a malicious file or clicking a link — often the final step of a phishing chain.

T1203 — Exploitation for Client Execution. Exploits vulnerabilities in client applications (browsers, document readers) to execute code without obvious user interaction.

Why These Stages Matter Most for SOC Teams

The earlier in the attack chain a SOC can detect and respond, the less damage an attacker can do. Initial Access and Execution are the highest-leverage stages to focus detection engineering on, because:

Practical SOC Takeaways

Mapping real detections back to these specific technique IDs turns a vague "suspicious activity" alert into an actionable, documented incident — which is the whole point of using ATT&CK as a working framework, not just a reference chart.

Related reading