01
External perimeter
Internet-facing services, applications, and misconfigurations an outside attacker would target.
02
Internal movement
How far an attacker who already has a foothold can move across the network.
03
Privilege escalation
Paths from a low-privilege position toward domain or system control.
04
Segmentation
Whether network boundaries actually contain an attacker, or let them spread freely.
05
Exposed services and credentials
Weak, default, or exposed services and credentials that open the door.