flâneur — a map of the web's best reading

Mistaken Identification: When an Attack Technique isn’t a Technique | by VanVleet | Jul, 2024 | Medium

medium.com · saved by 1 readers

This article is part of a series on Threat Detection. In this post, I’m going to talk about one of the challenges Detection Engineers face: sometimes a Mitre ATT&CK technique isn’t really a technique at all, which really complicates trying to detect it! I’m going to use T1059.001 PowerShell as my example in this article, but the concept applies to a lot of other techniques (too many!). Ultimately, we’ll demonstrate why T1059.001 (and many others) shouldn’t even exist. If you haven’t already read my articles on Identifying and Classifying and Detection Data Models, you might want to start there so it’s easier to follow along. Let’s imagine that you were looking over the top attack techniques used in 2023. Red Canary has an excellent site called “Threat Detection Report” that gives lots of great insights into the top attack techniques they’re seeing. Directly from their site, “The following chart represents the most prevalent MITRE ATT&CK® techniques observed in confirmed threats across

This article is part of a series on Threat Detection. In this post, I’m going to talk about one of the challenges Detection Engineers face: sometimes a Mitre ATT&CK technique isn’t really a technique at all, which really complicates trying to detect it! I’m going to use T1059.001 PowerShell as my example in this article, but the concept applies to a lot of other techniques (too many!). Ultimately, we’ll demonstrate why T1059.001 (and many others) shouldn’t even exist. If you haven’t already read my articles on Identifying and Classifying and Detection Data Models, you might want to start there

Explore this link on the map →