APT Lifecycle: Initial Access to Exfiltration
Trace a full APT campaign through the cyber kill chain from spear phishing to data theft.
What is an APT?
Advanced Persistent Threat (APT) refers to sophisticated, nation-state or well-funded adversaries who conduct long-duration, targeted campaigns. Unlike opportunistic attackers, APTs invest significant resources in specific high-value targets: defense contractors, financial institutions, government agencies.
The Cyber Kill Chain
Lockheed Martin's Cyber Kill Chain describes APT operations in seven phases: Reconnaissance, Weaponization, Delivery, Exploitation, Installation, Command and Control (C2), and Actions on Objectives. Defenders can disrupt the campaign by breaking any link in the chain.
All lessons in this course
- APT Lifecycle: Initial Access to Exfiltration
- Fileless Malware and Living-in-Memory Techniques
- C2 Over HTTPS and DNS Tunneling
- Threat Attribution and Campaign Tracking