PostureProof
Attacks Methodology Pricing Sign In

Attack breakdowns

We build checks by starting from how attacks actually run. Each breakdown walks a real incident stage by stage, marks which control breaks which stage, and shows exactly how we verify that control exists in your environment.

Where nothing we verify would have stopped a stage, the page says so. That's the point — a defense map is only useful if it shows the gaps too.

Supply chain Latest wave: 4 August 2026

Shai-Hulud

CHAINDROP

A self-replicating npm worm that turned maintainers into distribution

~440 packages · 2,200+ versions · under one hour 4 of 5 stages broken by verified controls

Read the breakdown →

Identity Active and ongoing

Scattered Spider

UNC3944 · Octo Tempest · Storm-0875

No malware, no exploit — they phone your help desk and ask for access

Help desk call to domain admin in under 40 minutes 3 of 5 stages broken by verified controls

Read the breakdown →

CI/CD March 2025 – March 2026

Poisoned GitHub Actions

tj-actions · TeamPCP / trivy-action · Axios

Rewrite one tag and every pipeline that trusts it runs your code

75 of 76 version tags force-pushed in a single incident 5 of 5 stages broken by verified controls

Read the breakdown →

See where you'd stand

Connect read-only. Find your gaps against these exact controls in 60 seconds.

Check my posture — free

© 2026 PostureProof. All rights reserved.

Attacks Methodology Terms Privacy