Field kit

Kill chain

Engagement plans

A plan is the mix: phase, why, tools, and ATT&CK ids in one ordered path. Pin it to the case file so findings and detection notes hang off the same job.

Authorized testing only. Practice on systems you own, isolated labs, or targets with written permission. Unauthorized access is illegal.

Owned home network

Inventory, light enum, exposure check, then harden. Mixes coach, recipes, and defense.

Only networks and devices you administer. No neighbor scans.

1. Recon
T1595T1046

Asset inventory

DHCP leases plus ARP/ping discovery. Name every host before ports.

2. Enum
T1046

Services, shares, cameras

Top ports, SMB/NFS, RTSP/mDNS. Fragile IoT stays slow.

3. Exposure
T1592

WAN and UPnP

Public IP view plus router maps. Every forward needs an owner.

4. Defense

Segment and close

Guest/IoT isolation, kill WPS and WAN admin, VPN instead of port forwards.

5. Report

Write the case

Save findings with impact and fix. Note what logs would have shown.