I hate when security folks say "attackers only have to win once, defenders have to win every time" because it's flawed thinking.
Thanks @haroonmeer for this: "Actually, an attacker can win everywhere and as a defender you only have to find them once"https://youtu.be/Wqww0BRIX5U
"defenders have to defend the whole castle and attackers only have to find one entrypoint to gain access" - true. but it gets turned on its head soon as the attackers get a shell: "attackers make ONE MISTAKE, and their entire c2 infra is burned and they have to rebuild"