Attack breakdowns
We build checks by starting from how attacks actually run. Each breakdown walks a real incident stage by stage, marks which control breaks which stage, and shows exactly how we verify that control exists in your environment.
Where nothing we verify would have stopped a stage, the page says so. That's the point — a defense map is only useful if it shows the gaps too.
Shai-Hulud
CHAINDROP
A self-replicating npm worm that turned maintainers into distribution
Read the breakdown →
Scattered Spider
UNC3944 · Octo Tempest · Storm-0875
No malware, no exploit — they phone your help desk and ask for access
Read the breakdown →
Poisoned GitHub Actions
tj-actions · TeamPCP / trivy-action · Axios
Rewrite one tag and every pipeline that trusts it runs your code
Read the breakdown →
See where you'd stand
Connect read-only. Find your gaps against these exact controls in 60 seconds.
Check my posture — free