Threat Intelligence & Adversary BehaviorBeginnerAttack Technique4 validated evidence records

Initial Access

30 sec

The tactics and techniques adversaries use to gain their first foothold in an environment.

Know

What is Initial Access?

The tactics and techniques adversaries use to gain their first foothold in an environment. In practice, initial access should be understood in the context of the identities, systems, applications, data, trust relationships, and business processes it affects. The useful question is not only what the term means, but how it changes attacker capability or defensive control.

Why it matters

The tactics and techniques adversaries use to gain their first foothold in an environment. Attackers can use this behavior to turn a single weakness, identity, or interaction into broader compromise, so defenders need to recognize both the mechanism and the business consequence.

Evidence, not hype

Validated in the real world

Every record is labeled by evidence type and source strength so an incident, a standard, and emerging research are never presented as if they are the same thing.

Technical ValidationOperational validation

Fake IT-support contacts use Teams to obtain user-approved remote access

2026-09-02Microsoft Threat Intelligence

Microsoft describes external Teams contacts impersonating support staff and persuading users to grant remote access. The documented chain includes implant deployment, discovery, and lateral movement, following user authorization through legitimate support tools.

Why this is evidence

This is evidence of support-workflow abuse and social engineering. It does not establish a Teams software vulnerability or suggest that merely receiving a chat compromises a device.

See the source — Microsoft Threat Intelligence: Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Technical ValidationOperational validation

TerminalFix uses a fake verification prompt to establish a reverse tunnel

2026-08-28Microsoft Threat Intelligence

Microsoft's TerminalFix analysis describes a fake CAPTCHA prompt that persuades a user to execute a command, followed by a multistage intrusion and a reverse tunnel.

Why this is evidence

The case connects a human verification pretext with malware execution and network access. Microsoft distinguishes observed activity from possible downstream actions; it did not observe the suggested ransomware or data-theft outcomes in this analyzed chain.

See the source — Microsoft Threat Intelligence: TerminalFix campaign deploys a reverse tunnel through multistage intrusion
Technical ValidationOperational validation

Counterfeit vendor pages deliver changing malicious installers

2026-09-01Microsoft Threat Intelligence

Microsoft describes look-alike software download pages distributing malicious installers whose contents change between downloads. Observed affected devices were predominantly associated with China-based operations and Chinese-speaking users across several industries.

Why this is evidence

The campaign illustrates brand impersonation leading to malware delivery. Impersonating a vendor's download page does not establish compromise of its official distribution. The observed geography is not a measured global scope.

See the source — Microsoft Threat Intelligence: Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Government / AuthoritativeGovernment advisory

Government and ATT&CK guidance validate core adversary lifecycle behaviors

2025-03CISA and international partnersCross-sector

CISA and partner guidance describes threat actors abusing native tools and trusted processes for execution, persistence, lateral movement, discovery, and credential access. MITRE ATT&CK organizes initial access, privilege escalation, persistence, and command-and-control as core adversary objectives.

Why this is evidence

These concepts explain how attackers progress after an initial foothold and why behavior-based telemetry matters even when no obvious malware is present.

See the source — CISA and Partners: Identifying and Mitigating Living Off the Land Techniques

Understand the mechanics

How it works

  1. 1

    An adversary identifies a condition where initial access can provide access, control, information, or evasion.

  2. 2

    The attacker executes the technique directly or combines it with credentials, social engineering, exploitation, or trusted tools.

  3. 3

    Successful activity creates a new capability such as access, execution, persistence, privilege, movement, collection, or impact.

  4. 4

    Defenders investigate the surrounding identity, host, application, network, and cloud telemetry to determine scope and interrupt the attack chain.

Practice

What to watch for

  • Activity consistent with initial access in identity, endpoint, email, application, cloud, or network telemetry
  • Unexpected authentication, privilege, execution, or data-access behavior
  • New or unusual infrastructure, domains, processes, tokens, or administrative actions
  • A sequence of events that matches a known adversary technique rather than normal business activity

Perform

What to do

  1. 1

    Stop or contain the risky activity without destroying useful evidence.

  2. 2

    Determine which identities, systems, applications, data, and sessions are affected.

  3. 3

    Revoke exposed access, isolate compromised assets, and block malicious infrastructure as appropriate.

  4. 4

    Hunt for related initial access activity and adjacent attacker behaviors before declaring the incident contained.

How to reduce the risk

  • Collect endpoint, identity, network, and cloud telemetry.
  • Map observed behavior to ATT&CK techniques.
  • Detect unusual administrative behavior rather than relying only on malware signatures.
  • Harden credentials, remote administration, and common lateral-movement paths.

Business impact

  • Broader compromise
  • Longer attacker dwell time
  • Loss of detection coverage
  • Operational disruption

What different roles should do

Employee / Operator

  • Pause when an interaction or system behavior is unexpected.
  • Use approved verification and reporting paths rather than improvising.

Security

  • Correlate identity, endpoint, network, application, and cloud evidence.
  • Contain the attack path and hunt for follow-on activity.

Framework & standards context

  • MITRE ATT&CK TA0001

Keep learning

Source transparency

Authoritative sources

Last reviewed: 2026-09-02