Human-Operated Intrusions

This category tracks "hands-on-keyboard" attacks where live threat actors — rather than automated scripts — maneuver through a network in real-time. Unlike traditional malware campaigns, these intrusions rely on interactive social engineering, lateral movement, and the abuse of legitimate administrative tools. We focus on the shift toward platform-based deception (e.g., Microsoft Teams) and the deployment of custom toolkits used for credential theft and domain takeover.