--- layout: default ---
Attack Chains {% if page.last_updated %} Updated {{ page.last_updated }} {% endif %}

{{ page.title }}

{% if page.subtitle %}

{{ page.subtitle }}

{% endif %}
The Chokepoint Convergence Principle

Same stages, different tools. Each stage is an unavoidable prerequisite - the underlying chokepoints don't change. Detect the prerequisite; catch any actor.

{% if page.stages %} {% if page.show_ttp_overlap %}

TTP Overlap Across Groups

{% include ttp-graph.html %}
{% include ttp-vertical-diagram.html %}
{% endif %} {% if page.chokepoints %}

Chokepoint Opportunities by Stage

Invariant prerequisite per stage, top signals, and links to the full chokepoint analysis.

{% for stage in page.stages %}{% if page.chokepoints[stage.id] %}
{{ forloop.index }} {{ stage.label }}
Chokepoint

{{ page.chokepoints[stage.id] }}

{% if stage.detection_signals %}
Detection Signals
    {% for signal in stage.detection_signals %}
  • {{ signal }}
  • {% endfor %}
{% endif %} {% if stage.chokepoint_links %} {% endif %}
{% endif %}{% endfor %}
{% endif %} {% if page.actors %}

Actor Convergence Matrix {{ page.actors | size }} actors tracked

Different tools, different operators - same chokepoints. Bottom row: the invariant your detections must cover.

{% for stage in page.stages %} {% endfor %} {% for actor in page.actors %} {% for stage in page.stages %} {% endfor %} {% endfor %} {% if page.chokepoints %} {% for stage in page.stages %} {% endfor %} {% endif %}
Actor{{ stage.label }}
{{ actor.name }}{% if actor.status %}
{{ actor.status }}{% endif %}
{{ actor[stage.id] }}
The Chokepoint {{ page.chokepoints[stage.id] }}
{% endif %} {% endif %}

Analysis & References

{{ content }}
{% if page.stages %} {% if page.show_ttp_overlap %} {% endif %} {% endif %}