How attackers turn ordinary permissions, APIs, processes, and trust relationships into attack chains