This is a live map of the Windows attack surface for incident triage.
The 8 hubs are the domains an Incident Commander reasons about. Click a hub to fan out its components, then click any component to see:
› How it's abused — with MITRE ATT&CK IDs
› Blast radius — the escalation chain it opens
› What it reaches — downstream assets
The red spine in each blast section is the signature: it traces how one compromised component becomes domain- or tenant-wide.