Attack Chain Analysis

How modern attacks actually work

AI accelerates every stage of an intrusion, not by inventing new attack techniques, but by making legitimate activity faster, more adaptive, and harder to distinguish from normal operations.

Continuous behavioral change
Behavior changes at every stage of an intrusion
Stage names describe behavioral change. MITRE ATT&CK tactics are shown for reference, not as a classification model.
01
Initial Access
Uses stolen credentials, trusted identities, or compromised third parties.
MITRE ATT&CK Initial Access
02
Environment Understanding
Maps users, systems, applications, and business relationships.
MITRE ATT&CK Reconnaissance · Discovery
03
Trusted Activity
Uses approved tools, administrative interfaces, automation, and APIs.
MITRE ATT&CK Execution · Defense Evasion
04
Behavioral Expansion
Expands across people, devices, applications, and cloud services.
MITRE ATT&CK Lateral Movement · Command & Control
05
Mission Execution
Data theft, fraud, ransomware, disruption, or quiet persistence.
MITRE ATT&CK Collection · Exfiltration · Impact
Traditional security asks
“Did something malicious execute?”
The better question is
Did a user, device, application,
or service begin behaving
outside its normal pattern?

Modern intrusions increasingly use valid identities and trusted tools. The meaningful signal is often not the artifact. It is the change in behavior.

Where Personam detects the behavior change

At every stage, traditional tools struggle when the credential is valid and the tool is approved. Personam watches behavior, not artifacts. These are the specific signals it surfaces.

01
Stage

Initial Access

Phishing or credential theft. The account credentials are real, nothing about the login itself looks wrong. A traditional tool sees an authorized user.

What Personam detects
  • First login from an unusual network segment or time window
  • Login-to-access pattern inconsistent with this user's historical baseline
  • Credential used across peer-family in an unusual sequence
02
Stage

Environment Understanding

The attacker enumerates shares, maps admin paths, and identifies high-value systems. This looks like a network scan, except using a legitimate account.

What Personam detects
  • Unusual breadth of internal DNS lookups or SMB queries
  • Access to file shares outside this user's historical scope
  • Enumeration pattern inconsistent with any peer in the group
03
Stage

Trusted Activity

PowerShell, RDP, WMI, sanctioned cloud services, used in ways that technically comply with policy but are behaviorally out of character.

What Personam detects
  • PowerShell or RDP sessions outside the normal operating hours for this entity
  • Admin tool used from a host that has never used it before
  • Outbound connection to a service account's peer group that doesn't fit its baseline
04
Stage

Behavioral Expansion

The attacker pivots using valid credentials or service accounts. To a signature-based tool, this is indistinguishable from a legitimate IT operation.

What Personam detects
  • Device communicating with a new peer group, first contact with hosts outside its historical cohort
  • Service account touching systems it has never reached before
  • East-west traffic pattern 4–7σ outside the device's established baseline
  • A server sending its backup somewhere the rest of its family never does
05
Stage

Mission Execution

Data staged for exfiltration, or ransomware pre-positioned. By now the attacker has been inside for hours or days. Every minute of dwell time increases the damage.

What Personam detects
  • Large internal data transfers to a staging host, volume and velocity outside any peer baseline
  • Outbound connection to external storage inconsistent with this user's historical behavior
  • A senior insider staging client material over several nights, weeks off-baseline before staging
Real Detections, Anonymized

These weren't found by a rule.

Both were caught because behavior changed, not because a signature matched.

Misconfiguration · Data Leaving the Network

One member of a server family, behaving differently

Several servers sharing a role, a schedule, and a behavioral family
All but one write their nightly backup to storage inside the network
The remaining server sends its backup to an external destination instead
No malware, no attacker, and no rule that any tool was watching for
Traditional security sees

An authorized server performing an authorized backup over an approved protocol. The credential is valid. The destination is a legitimate provider. Nothing matches a signature and no threshold is crossed. No alert fires.

Personam detects

One member of a behavioral family behaving unlike the rest of it. Because Personam had learned that these systems belong together, a destination that is unremarkable on the open internet was clearly wrong for this family. Surfaced as a deviation and traced back to a configuration error that had been quietly sending data outside the network.

Insider Threat · Data Exfiltration

A senior insider, entirely within their access

A senior professional with valid credentials and fully authorized access
Begins reaching client material outside the scope of their own established work
Three weeks of gradual behavioral drift, below any threshold-based alert
Sensitive client material staged quietly across several nights
Traditional security sees

An authorized person doing their job. Valid login, approved access paths, normal-looking file transfers. Three weeks pass. Nothing fires.

Personam detects

Behavioral deviation: file access scope expanding outside peer group norm. Exfiltration velocity well above this user's established baseline. This is an HR case before an IT case.

See what's moving in your network.

Personam builds a behavioral map of your entire environment and flags the deviations that no rule could anticipate. Live demo in 30 minutes.

Schedule a Demo See How It Works →