MITRE ATT&CK, extended to the perimeter no one is defending
Security teams already think in kill chains. Ask any practitioner to describe how an intrusion unfolds and they'll reach for a sequence: reconnaissance, weaponization, delivery, exploitation. That instinct is correct, but it is also incomplete, and the gap is costing teams more each year.
The threat landscape has changed faster than the frameworks describing it
None of the numbers above describe a network intrusion. They describe attacks on trust: a fake executive profile, a cloned brand account, a lookalike domain built to catch a customer mid-click. The infrastructure being attacked is not yours, it is the open internet, and your security stack was never built to watch it.
Generative AI is what changed the economics. Building a convincing fake used to require real skill, including passable writing, a decent eye for design, and patience. Today it takes a prompt. Voice cloning, deepfake video, and fluent copy in any language are available at near-zero marginal cost, so the volume of attacks scaled the moment the cost of producing one collapsed.
Why the perimeter you're defending has already moved
For twenty years, "the perimeter" meant your network edge. That's where Lockheed Martin's Cyber Kill Chain and MITRE ATT&CK live, and for infrastructure attacks, they're still the right tools. Practitioners trust them because they're rigorous: MITRE ATT&CK documents hundreds of techniques, each with real-world procedure examples, sourced and citable. That rigor is exactly why it's worth being precise about what it does and doesn't cover.
To be precise, we mapped roughly fifty techniques used in brand, executive, location, and product-based attacks against the current MITRE ATT&CK matrix.
Twenty-four did not, because MITRE models attacks against infrastructure you own, and these attacks never touch it. Brand impersonation, executive spoofing, fake endorsements, counterfeit sales, and credential resale are not yet represented in a framework built for network intrusion, which is where there is room for the matrix to grow.
This is not a criticism of MITRE, it is a description of scope, and the reason the two frameworks fit together rather than compete. Reconnaissance and Infrastructure Setup map cleanly, but Trust Exploitation and Monetization are two full stages of the attack lifecycle with no dedicated tactic in ATT&CK at all. That is the opportunity. The kill chain your team already trusts covers the intrusion path thoroughly, and the Digital Trust Kill Chain extends the same structure across the stages that play out beyond your infrastructure.
The Digital Trust Kill Chain
Eight stages, grouped into four phases, mapped to MITRE ATT&CK where it reaches and defined by Outtake where it does not.
Why the current tooling misses this, structurally rather than by accident
Legacy DRP tools work one impersonation URL at a time. Take down a single lookalike domain and, if it shares infrastructure with nine others as one recent investigation found, the other nine keep running untouched. Speed compounds the problem.
A recent law enforcement case makes the structural point at industry scale. A phishing- as-a-service platform ran for three years before a coordinated, nineteen-country operation took down the platform itself rather than chasing its individual phishing pages one at a time.
The lesson is that the choke point was never the domain the victim happened to land on, it was the shared hosting account and template library behind all of them. Point tools that alert on individual artifacts will always be a step behind an attacker who builds once and deploys everywhere.
What a platform built for this actually needs to do
Closing this gap requires five capabilities working together in one platform rather than five separate vendors.
That is what Outtake was built to do: the Next-Generation Digital Risk Protection Platform, mapped explicitly to the stages above, dismantling the whole operation at machine speed rather than the one artifact you happened to see first.
Extending a framework your team already trusts
This framework is not a replacement for the kill chain your team already trusts. It is an extension of it. Your network perimeter has a name for every stage of an attack against it, and your brand, your executives, your locations, and your products deserve the same rigor. We built it in the open, cross-referenced against MITRE ATT&CK technique by technique, and clear about where the existing mapping already holds and where the matrix has room to grow.
The full framework is live now rather than only described here. Filter the matrix by brand, people, location, or product and watch the relevant techniques highlight in place. Click any MITRE badge and it opens the real technique page on attack.mitre.org, not a screenshot standing in for one. You can also walk through one real investigation end to end, following a single lookalike domain that resolved into a nine-domain pig butchering operation, mapped stage by stage with the case video.
Outtake Labs publishes original research on the Digital Trust Kill Chain, real-world case investigations, and quarterly threat data. See more at outtake.ai/labs
