> For the complete documentation index, see [llms.txt](https://106-sam.gitbook.io/ejptv2-notes/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://106-sam.gitbook.io/ejptv2-notes/crto/getting-started/attack-lifecycle/microsoft-attack-lifecycle.md).

# Microsoft Attack LifeCycle

<figure><img src="https://lwfiles.mycourse.app/66e95234fe489daea7060790-public/9e1893d4cdd86b6e6226204ef9a378b2.jpg" alt=""><figcaption></figcaption></figure>

\
It shows the cyclical nature of some of the phases. <br>

* An advesary may have to compromise and move laterally to multiple machines before obtianing the level of privilege they reqiure.
