All Atomic Rules by ATT&CK Tactic & Technique persistence T1137 Office Application Startup defense-evasion privilege-escalation discovery credential-access execution T1086 PowerShell lateral-movement collection exfiltration command-and-control initial-access