Why a Single Test Case is Insufficient | by Jared Atkinson | May, 2024 | Posts By SpecterOps Team Members
In my previous post, I explored the idea that different tools can implement the same operation chain (behavior) in various ways. I referred to these various ways as execution modalities. In that post, we explored five tools that allowed us to understand some of the most common modalities that one would expect to encounter and concluded with an image of a function call stack that represented the Session Enumeration operation with overlaid tools. In this post, I want to explore the implications of execution modalities on detection engineering. I’m particularly interested in how diverse modalities affect our ability to evaluate detection coverage. Evaluating detection coverage is a problem we’ve seen rise to industry attention with the ATT&CK EDR Evaluations. While the objective of the evaluations is not necessarily to assess detection coverage, that is undoubtedly a question that industry consumers are interested in, and rightfully so. This post will explore why a test not specifically d
Back to Blog Research & Tradecraft Part 13: Why a Single Test Case is Insufficient Author Jared Atkinson Read Time 24 mins Published May 31, 2024 Share Put Insights Into Action Explore our Platform Explore Services [ RS - Classic Editor Block ] Introduction In my previous post , I explored the idea that different tools can implement the same operation chain (behavior) in various ways. I referred to these various ways as execution modalities. In that post, we explored five tools that allowed us to understand some of the most common modalities that one would expect to encounter and concluded wit
Explore this link on the map →related reading
- Security incident disclosure — July 2026huggingface.co
- 2312.06942arxiv.org
- Focus Threat Intel Capabilities at Detection Engineering (Part 4) | by Anton Chuvakin | Anton on Security | Mediummedium.com
- Capability Abstraction - SpecterOpsposts.specterops.io
- Table stakes for Detection Engineering - by Zack Allendetectionengineering.net
- Agent Observability and Tracingarize.com
- Detection Spectrum - SpecterOpsposts.specterops.io
- GitHub - konst-int-i/lucid-rules: Rule Extraction Methods for Interactive eXplainability · GitHubgithub.com
- Dealing with Noisy Behavioral Analytics in Detection Engineering | CMU Software Engineering Instituteinsights.sei.cmu.edu
- Tuning YARA-L Rules in Chronicle SIEM | by Chris Martin (@thatsiemguy) | Mediummedium.com
- detection-engineering-maturity-matrixdetectionengineering.io
- Mediumdetect.fyi