> For the complete documentation index, see [llms.txt](https://106-sam.gitbook.io/ejptv2-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://106-sam.gitbook.io/ejptv2-notes/crto/getting-started/attack-lifecycle/mandiants-targeted-attack-lifecycle.md).

# Mandiant's Targeted Attack LifeCycle

These have 8 phases:

* **Initial Reconnaissance -** *Research the target's systems and employees to develop a methodology  for intrusion.*&#x20;
* **Initial Compromise -** *execute malicious code on one or more targets via the attack vector planned during phase 1.*
* **Establish Foothold** - *maintain continued control over a compromised system by installing persistent backdoors.*
* **Escalated Privileges** - *exploit system vulnerabilities or misconfigurations to obtain local admin access to compromised systems.*
* **Internal Reconnaissance** - *explore the target's internal infrastructure and environment.*
* **Move Laterally -** use credentials obtained from phase 4 to compromise additional systems.
* **Maintain Presence -** *maintain highly privileged access to domains and systems.*
* **Complete Mission -** acomplish the operational objective.
