Layer 1
Layer 1 – Endpoint Compromise
Malware, phishing, or physical theft gives attackers full control of the device.
- Persistence mechanisms (bootkits, rootkits)
- Local data harvest (documents, cached credentials)
- Remote admin tools installed
Layer 2
Layer 2 – Identity Leverage
Credentials stored on the laptop become the attacker’s passport across the environment.
- Cached Windows/Kerberos tickets
- Saved passwords in browsers or password managers
- Privileged tokens for VPN, SSO, or cloud services
Layer 3
Layer 3 – Network & Application Reach
Using stolen identities, threat actors move laterally to critical systems.
- Pass‑the‑hash / Pass‑the‑ticket attacks
- Exploitation of trust relationships (file shares, service accounts)
- Access to SaaS platforms via SSO tokens
Layer 4
Layer 4 – Data Exfiltration & Business Impact
Once inside, attackers can steal, encrypt, or destroy high‑value data, disrupting operations.
- Intellectual property theft
- Ransomware deployment on production servers
- Regulatory breach notifications and reputational damage
Layer 5
Layer 5 – Resilience & Recovery
The speed of detection and containment determines the overall fallout.
- Incident response time < 24 h reduces breach cost by 30 %
- Segmentation limits lateral spread to < 10 % of assets
- Zero‑trust verification at each hop curtails credential abuse