Purim NetGo
Attack Lifecycle · Stage 2 of 7

Stage 2: Internal Reconnaissance

May 2026  ·  8 min read  ·  MITRE ATT&CK  ·  Network Mapping · Asset Discovery · User Enumeration

Stage 2 of the cyberattack lifecycle: Internal Reconnaissance. After gaining initial access, the attacker silently maps your internal network — identifying systems, users, services, and high-value targets before making their next move.

Stage 2: Internal Reconnaissance - Purim NetGo

Attacker Goal

Understand the internal network layout, identify high-value targets, and plan the path to objectives without triggering alerts.

MITRE ATT&CK Techniques

T1046T1083T1087T1135T1018T1069

Stage Description

After gaining initial access, the attacker silently maps your internal network — identifying systems, users, services, and high-value targets before making their next move.

Common Entry Vectors

Typical Attacker Actions

✓ Purim NetGo Detection & Response

What Purim NetGo Delivers at This Stage

See It In Action

Get a real simulated attack alert sent to your inbox — experience deception security firsthand.

Launch Free Test Drive