flâneur — a map of the web's best reading

Why a Single Test Case is Insufficient | by Jared Atkinson | May, 2024 | Posts By SpecterOps Team Members

posts.specterops.io · 4,670 words · saved by 1 readers

In my previous post, I explored the idea that different tools can implement the same operation chain (behavior) in various ways. I referred to these various ways as execution modalities. In that post, we explored five tools that allowed us to understand some of the most common modalities that one would expect to encounter and concluded with an image of a function call stack that represented the Session Enumeration operation with overlaid tools. In this post, I want to explore the implications of execution modalities on detection engineering. I’m particularly interested in how diverse modalities affect our ability to evaluate detection coverage. Evaluating detection coverage is a problem we’ve seen rise to industry attention with the ATT&CK EDR Evaluations. While the objective of the evaluations is not necessarily to assess detection coverage, that is undoubtedly a question that industry consumers are interested in, and rightfully so. This post will explore why a test not specifically d

Back to Blog Research & Tradecraft Part 13: Why a Single Test Case is Insufficient Author Jared Atkinson Read Time 24 mins Published May 31, 2024 Share Put Insights Into Action Explore our Platform Explore Services [ RS - Classic Editor Block ] Introduction In my previous post , I explored the idea that different tools can implement the same operation chain (behavior) in various ways. I referred to these various ways as execution modalities. In that post, we explored five tools that allowed us to understand some of the most common modalities that one would expect to encounter and concluded wit

Explore this link on the map →

related reading