Field kit

Coverage

ATT&CK board

The techniques OpsField actually teaches, grouped by tactic. Amber means you already logged a detection note in the case file.

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

Reconnaissance

Discovery

Execution

Initial Access

Credential Access

Lateral Movement

Privilege Escalation

Defense Evasion

Collection

Exfiltration

Command and Control

Persistence

T1595
Reconnaissance

Active Scanning

Adversaries probe victim infrastructure for reachable hosts, ports, and services. In ethical assessments this maps to authorized discovery scans.

Detection: IDS/IPS volume spikes, connection attempts across many ports from one source, and unusual ARP traffic. Baseline internal scanners so SOC can distinguish authorized jobs.