Detection strategies define high-level approaches for detecting specific adversary techniques. They serve as containers that organize multiple platform-specific analytics into cohesive detection methodologies.

Linked Issues

Issuelinks
Linktyp Issue
is related to Detection of Block Operational Technology Message
is related to Detection of Exploitation for Privilege Escalation
is related to Detection of Default Credentials
is related to Detection of Data from Information Repositories
is related to Detection of Program Download All
is related to Detection of Data Destruction
is related to Detection of Replication Through Removable Media
is related to Detection of Block Reporting Message
is related to Detection of Program Append
is related to Detection of Block Command Message
is related to Detection of Program Download
is related to Detection of Remote System Discovery
is related to Detection of Spearphishing Attachment
is related to Detection of Wireless Compromise
is related to Detection of Loss of Control
is related to Detection of Standard Application Layer Protocol
is related to Detection of User Execution
is related to Detection of Commonly Used Port
is related to Detection of Rootkit
is related to Detection of Manipulation of Control
is related to Detection of Screen Capture
is related to Detection of Denial of Service
is related to Detection of Block Wi-Fi
is related to Detection of Manipulation of View
is related to Detection of Block Serial COM
is related to Detection of Valid Accounts
is related to Detection of Change Credential
is related to Detection of Firmware Modification
is related to Detection of I/O Image
is related to Detection of Manipulate I/O Image
is related to Detection of Adversary-in-the-Middle
is related to Detection of Exploitation of Remote Services
is related to Detection of System Firmware
is related to Detection of Denial of View
is related to Detection of Loss of View
is related to Detection of Program Upload
is related to Detection of Wireless Sniffing
is related to Detection of Unauthorized Command Message
is related to Detection of Block Communications
is related to Detection of Point & Tag Identification
is related to Detection of Damage to Property
is related to Detection of Insecure Credentials
is related to Detection of Hardcoded Credentials
is related to Detection of Rogue Master
is related to Detection of External Remote Services
is related to Detection of Scripting
is related to Detection of Module Firmware
is related to Detection of Unauthorized Message
is related to Detection of Network Sniffing
is related to Detection of Remote System Information Discovery
is related to Detection of Spoof Reporting Message
is related to Detection of Modify Alarm Settings
is related to Detection of Change Operating Mode
is related to Detection of Remote Services
is related to Detection of Project File Infection
is related to Detection of Theft of Operational Information
is related to Detection of Drive-by Compromise
is related to Detection of System Binary Proxy Execution
is related to Detection of Automated Collection
is related to Detection of Supply Chain Compromise
is related to Detection of Execution through API
is related to Detection of Autorun Image
is related to Detection of Multicast Discovery
is related to Detection of Network Connection Enumeration
is related to Detection of Service Stop
is related to Detection of Connection Proxy
is related to Detection of Loss of Availability
is related to Detection of Modify Parameter
is related to Detection of Loss of Safety
is related to Detection of Internet Accessible Device
is related to Detection of Device Restart/Shutdown
is related to Detection of Port Scan
is related to Detection of Masquerading
is related to Detection of Loss of Productivity and Revenue
is related to Detection of Native API
is related to Detection of Command-Line Interface
is related to Detection of Lateral Tool Transfer
is related to Detection of Detect Operating Mode
is related to Detection of Monitor Process State
is related to Detection of Exploitation for Evasion
is related to Detection of Siemens Project File Format Infection
is related to Detection of Hooking
is related to Detection of Transient Cyber Asset
is related to Detection of Online Edit
is related to Detection of Modify Controller Tasking
is related to Detection of Activate Firmware Update Mode
is related to Detection of Denial of Control
is related to Detection of Indicator Removal on Host
is related to Detection of Data from Local System
is related to Detection of Alarm Suppression
is related to Detection of Block Ethernet
is related to Detection of Brute Force I/O
is related to Detection of Loss of Protection
is related to Detection of Exploit Public-Facing Application
is related to Detection of Modify Program
is related to Detection of Graphical User Interface
is related to Detection of Broadcast Discovery
is related to Detection Strategy for Boot or Logon Initialization Scripts: RC Scripts
is related to Detect Abuse of vSphere Installation Bundles (VIBs) for Persistent Access
is related to Detection of Network Topology
is related to Detection of Server
is related to Detection of Gather Victim Host Information
is related to Detection Strategy for Modify System Image on Network Devices
is related to Internal Website and System Content Defacement via UI or Messaging Modifications
is related to Abuse of PowerShell for Arbitrary Execution
is related to Detection Strategy for Junk Code Obfuscation with Suspicious Execution Patterns
is related to Detection of Active Scanning
is related to Detection of Systemd Service Creation or Modification on Linux
is related to Behavioral Detection Strategy for Abuse of Sudo and Sudo Caching
is related to Suspicious Addition to Local or Domain Groups
is related to Detect Persistence via Office Template Macro Injection or Registry Hijack
is related to Detection Strategy for Modify Cloud Resource Hierarchy
is related to Suspicious Database Access and Dump Activity Across Environments (T1213.006)
is related to Detection Strategy for Weaken Encryption: Reduce Key Space on Network Devices
is related to Detection Strategy for ListPlanting Injection on Windows
is related to Cross-Platform Detection of JavaScript Execution Abuse
is related to Behavior-chain detection for T1132.001 Data Encoding: Standard Encoding (Base64/Hex/MIME) across Windows, Linux, macOS, ESXi
is related to Detection of Domain Properties
is related to Behavioral Detection of Visual Basic Execution (VBS/VBA/VBScript)
is related to Exploitation of Remote Services – multi-platform lateral movement detection
is related to Detection of Web Services
is related to Detection of Search Open Websites/Domains
is related to Detection Strategy for Impair Defenses Indicator Blocking
is related to Behavioral Detection for Service Stop across Platforms
is related to Detect abuse of Windows BITS Jobs for download, execution and persistence
is related to Email Forwarding Rule Abuse Detection Across Platforms
is related to Detection Strategy for Hijack Execution Flow through Service Registry Premission Weakness.
is related to Detection Strategy for Temporary Elevated Cloud Access Abuse (T1548.005)
is related to Detect Access to Cloud Instance Metadata API (IaaS)
is related to Detection Strategy for T1525 – Implant Internal Image
is related to Detection Strategy for Dynamic Resolution using Domain Generation Algorithms.
is related to Detection Strategy for Dynamic Resolution using Fast Flux DNS
is related to Behavior-chain detection for T1133 External Remote Services across Windows, Linux, macOS, Containers
is related to Detect Abuse of Windows Time Providers for Persistence
is related to Behavioral Detection Strategy for Exfiltration Over Alternative Protocol
is related to Detection strategy for Group Policy Discovery on Windows
is related to Detection of Establish Accounts
is related to Detect MFA Modification or Disabling Across Platforms
is related to Detection Strategy for Disable or Modify Cloud Firewall
is related to Detection of Business Relationships
is related to Detection Strategy for Network Sniffing Across Platforms
is related to Detection of Social Media
is related to Detection Strategy for Hijack Execution Flow using Path Interception by Search Order Hijacking
is related to Domain Account Enumeration Across Platforms
is related to Detection Strategy for LNK Icon Smuggling
is related to Detect User Activity Based Sandbox Evasion via Input & Artifact Probing
is related to Behavioral Detection Strategy for Use Alternate Authentication Material: Application Access Token (T1550.001)
is related to Behavior-chain detection for T1134.001 Access Token Manipulation: Token Impersonation/Theft on Windows
is related to Detection of Malware
is related to Detection Strategy for Device Driver Discovery
is related to Detection of Launch Agent Creation or Modification on macOS
is related to Suspicious RoleBinding or ClusterRoleBinding Assignment in Kubernetes
is related to Detection Strategy for Kernel Modules and Extensions Autostart Execution
is related to Detect Office Startup-Based Persistence via Macros, Forms, and Registry Hooks
is related to Domain Fronting Behavior via Mismatched TLS SNI and HTTP Host Headers
is related to Detection of Cloud Accounts
is related to TCC Database Manipulation via Launchctl and Unprotected SIP
is related to Behavioral Detection of Publish/Subscribe Protocol Misuse for C2
is related to Behavior-chain detection for T1135 Network Share Discovery across Windows, Linux, and macOS
is related to Detection of Network Devices
is related to Clipboard Data Access with Anomalous Context
is related to Detection Strategy for Steal or Forge Authentication Certificates
is related to Detection Strategy for Obfuscated Files or Information: Binary Padding
is related to Detection Strategy for File Creation or Modification of Boot Files
is related to Detection of Kernel/User-Level Rootkit Behavior Across Platforms
is related to T1136.002 Detection Strategy - Domain Account Creation Across Platforms
is related to Backup Software Discovery via CLI, Registry, and Process Inspection (T1518.002)
is related to Detection of Unauthorized Network Firewall Rule Modification
is related to Detection Strategy for Subvert Trust Controls using SIP and Trust Provider Hijacking.
is related to Behavior-Chain Detection for Remote Access Tools (Tool-Agnostic)
is related to Detection Strategy for Hidden User Accounts
is related to Detection Strategy for Lua Scripting Abuse
is related to Detection Strategy for VBA Stomping
is related to Detect Archiving and Encryption of Collected Data (T1560)
is related to Detection Strategy for MFA Interception via Input Capture and Smart Card Proxying
is related to Detection of Adversary Use of Unused or Unsupported Cloud Regions (IaaS)
is related to Detection Strategy for Impersonation
is related to Detection Strategy for T1505 - Server Software Component
is related to Detection of Software
is related to Detection of Search Engines
is related to Detection Strategy for Remote System Enumeration Behavior
is related to Detection of Defense Impairment
is related to Windows Detection Strategy for T1547.012 - Print Processor DLL Persistence
is related to Detection Strategy for Indicator Removal from Tools - Post-AV Evasion Modification
is related to Detection Strategy for T1505.005 – Terminal Services DLL Modification (Windows)
is related to Detection of SEO Poisoning
is related to Detect Abuse of Inter-Process Communication (T1559)
is related to Detection Strategy for Spearphishing Attachment across OS Platforms
is related to Detection of Valid Account Abuse Across Platforms
is related to Detection of Malware
is related to Detection Strategy for Hidden Files and Directories
is related to Detection Strategy for NTFS File Attribute Abuse (ADS/EAs)
is related to IDE Tunneling Detection via Process, File, and Network Behaviors
is related to Detection of Msiexec Abuse for Local, Network, and DLL Execution
is related to Detect Winlogon Helper DLL Abuse via Registry and Process Artifacts on Windows
is related to Detect Abuse of Dynamic Data Exchange (T1559.002)
is related to Detection Strategy for Power Settings Abuse
is related to Detection of NTDS.dit Credential Dumping from Domain Controllers
is related to Detection Strategy for ESXi Administration Command
is related to Endpoint DoS via OS Exhaustion Flood Detection Strategy
is related to Detection of Proxy Infrastructure Setup and Traffic Bridging
is related to Detection Strategy for System Services across OS platforms.
is related to Behavior-chain, platform-aware detection strategy for T1129 Shared Modules
is related to Detect Modification of Network Device Authentication via Patched System Images
is related to Detection Strategy for Hijack Execution Flow for DLLs
is related to Behavioral Detection of System Network Configuration Discovery
is related to Detection of Cached Domain Credential Dumping via Local Hash Cache Access
is related to Detection Strategy for LC_LOAD_DYLIB Modification in Mach-O Binaries on macOS
is related to Detecting .NET COM Registration Abuse via Regsvcs/Regasm
is related to Detection of Multi-Platform File Encryption for Impact
is related to Detecting Downgrade Attacks
is related to Programmatic and Excessive Access to Confluence Documentation
is related to Detection of Malvertising
is related to Detection Strategy for Hijack Execution Flow using Path Interception by PATH Environment Variable.
is related to Detection Strategy for System Services: Systemctl
is related to Detection Strategy for T1542.002 Pre-OS Boot: Component Firmware
is related to Detect Ingress Tool Transfers via Behavioral Chain
is related to Detection of Acquire Access
is related to Detection Strategy for Cloud Storage Object Discovery
is related to Detection of Server
is related to Detect Gatekeeper Bypass via Quarantine Flag and Trust Control Manipulation
is related to Detection of Remote Service Session Hijacking for RDP.
is related to Detection Strategy for T1547.009 – Shortcut Modification (Windows)
is related to Detection Strategy for Command Obfuscation
is related to Cross-host C2 via Removable Media Relay
is related to Detection Strategy for System Location Discovery
is related to Behavior-chain, platform-aware detection strategy for T1125 Video Capture
is related to Detection Strategy for Spearphishing Voice across OS platforms
is related to Detection Strategy for Encrypted Channel across OS Platforms
is related to Detection Strategy for /proc Memory Injection on Linux
is related to Detection Strategy for Event Triggered Execution via Trap (T1546.005)
is related to Detect Access to macOS Keychain for Credential Theft
is related to Behavioral Detection of Network History and Configuration Tampering
is related to Detection Strategy for Disable or Modify Linux Audit System Log
is related to Detection of Install Digital Certificate
is related to macOS AuthorizationExecuteWithPrivileges Elevation Prompt Detection
is related to Detection Strategy for Exfiltration Over Web Service
is related to Detecting Electron Application Abuse for Proxy Execution
is related to Detection of Local Data Staging Prior to Exfiltration
is related to Detection Strategy for Web Service: Dead Drop Resolver
is related to Detect Screen Capture via Commands and API Calls
is related to Detection of Command and Control Over Application Layer Protocols
is related to Detection Strategy for Modify Cloud Compute Infrastructure: Create Snapshot
is related to Detection of Local Account Abuse for Initial Access and Persistence
is related to Detection Strategy for Email Hiding Rules
is related to Detection Strategy for AutoHotKey & AutoIT Abuse
is related to Detecting Odbcconf Proxy Execution of Malicious DLLs
is related to Detection of Malware Relocation via Suspicious File Movement
is related to Detection Strategy for Exclusive Control
is related to Detection Strategy for Disk Wipe via Direct Disk Access and Destructive Commands
is related to Detection Strategy for Multi-Factor Authentication Request Generation (T1621)
is related to Credential Dumping from SAM via Registry Dump and Local File Access
is related to Detection Strategy for T1542 Pre-OS Boot
is related to Detection of Data Destruction Across Platforms via Mass Overwrite and Deletion Patterns
is related to Detection Strategy for Spearphishing Links
is related to Detection Strategy for Endpoint DoS via Service Exhaustion Flood
is related to Detection of Defense Impairment through Disabled or Modified Tools across OS Platforms.
is related to Virtualization/Sandbox Evasion via System Checks across Windows, Linux, macOS
is related to Detection Strategy for Hijack Execution Flow through the KernelCallbackTable on Windows.
is related to Detection Strategy for Spearphishing via a Service across OS Platforms
is related to Detection Strategy for Build Image on Host
is related to Detection of Botnet
is related to Behavioral Detection of Cloud Group Enumeration via API and CLI Access
is related to Renamed Legitimate Utility Execution with Metadata Mismatch and Suspicious Path
is related to Detection of Virtual Private Server
is related to Detection Strategy for Hijack Execution Flow using Executable Installer File Permissions Weakness
is related to Detection Strategy for File/Path Exclusions
is related to Detection Strategy for Network Device Configuration Dump via Config Repositories
is related to Behavioral Detection of Permission Groups Discovery
is related to Behavioral Detection of Mailbox Data and Log Deletion for Anti-Forensics
is related to Password Guessing via Multi-Source Authentication Failure Correlation
is related to Behavioral Detection of T1498 – Network Denial of Service Across Platforms
is related to Detection of Default Account Abuse Across Platforms
is related to Behavioral Detection of DLL Injection via Windows API
is related to Detection of Cloud Service Dashboard Usage via GUI-Based Cloud Access
is related to Hardware Supply Chain Compromise Detection via Host Status & Boot Integrity Checks
is related to Detect Unsecured Credentials Shared in Chat Messages
is related to Detection Strategy for Modify Cloud Compute Infrastructure: Delete Cloud Instance
is related to Automated Exfiltration Detection Strategy
is related to Multi-hop Proxy Behavior via Relay Node Chaining, Onion Routing, and Network Tunneling
is related to Detection of Email Accounts
is related to Detection Strategy for Login Hook Persistence on macOS
is related to Detection Strategy for TLS Callback Injection via PE Memory Modification and Hollowing
is related to Detection Strategy for T1497 Virtualization/Sandbox Evasion
is related to Detection Strategy for Safe Mode Boot Abuse
is related to Detection Strategy for T1218.011 Rundll32 Abuse
is related to Detect Suspicious Access to Browser Credential Stores
is related to Detect unauthorized LSASS driver persistence via LSA plugin abuse (Windows)
is related to Detect One-Way Web Service Command Channels
is related to Detection Strategy for Resource Hijacking: SMS Pumping via SaaS Application Logs
is related to User Execution – Malicious Image (containers & IaaS) – pull/run → start → anomalous behavior (T1204.003)
is related to Right-to-Left Override Masquerading Detection via Filename and Execution Context
is related to Detection of Credential Harvesting via API Hooking
is related to Detecting Abnormal SharePoint Data Mining by Privileged or Rare Users
is related to Local Storage Discovery via Drive Enumeration and Filesystem Probing
is related to Detect Windows Firewall
is related to Detection of Scan Databases
is related to Detection of Develop Capabilities
is related to Detect Disabled Windows Event Log
is related to Detection Strategy for Ignore Process Interrupts
is related to Detect Compromise of Host Software Binaries
is related to Detection Strategy for Hidden Virtual Instance Execution
is related to Detection of Audio-Visual Content
is related to Detecting Protocol or Service Impersonation via Anomalous TLS, HTTP Header, and Port Mismatch Correlation
is related to Multi-Platform File and Directory Permissions Modification Detection Strategy
is related to Detection Strategy for Email Spoofing
is related to Registry and LSASS Monitoring for Security Support Provider Abuse
is related to User Execution – Malicious File via download/open → spawn chain (T1204.002)
is related to Detecting Malicious Browser Extensions Across Platforms
is related to Detection Strategy for Compressed Payload Creation and Execution
is related to Credential Access via /etc/passwd and /etc/shadow Parsing
is related to Detection of Suspicious Scheduled Task Creation and Execution on Windows
is related to Detection of Threat Intel Vendors
is related to Detection of Hardware
is related to Detection of Spearphishing Link
is related to Detection Strategy for T1542.001 Pre-OS Boot: System Firmware
is related to Post-Credential Dump Password Cracking Detection via Suspicious File Access and Hash Analysis Tools
is related to Detection Strategy for Fileless Storage via Registry, WMI, and Shared Memory
is related to Detection Strategy for Polymorphic Code Mutation and Execution
is related to Cloud Account Enumeration via API, CLI, and Scripting Interfaces
is related to Detection of Local Browser Artifact Access for Reconnaissance
is related to Behavior-chain detection for T1132.002 Data Encoding: Non-Standard Encoding across Windows, Linux, macOS, ESXi
is related to Detect Persistence via Outlook Home Page Exploitation
is related to Email Collection via Local Email Access and Auto-Forwarding Behavior
is related to Cross-Platform Detection of Scheduled Task/Job Abuse via `at` Utility
is related to Detect Multi-Stage Command and Control Channels
is related to Detection Strategy for Forged SAML Tokens
is related to Detection Strategy for Steganographic Abuse in File & Script Execution
is related to Detection Strategy for Accessibility Feature Hijacking via Binary Replacement or Registry Modification
is related to Behavioral Detection of Wi-Fi Discovery Activity
is related to Detection of Adversarial Process Discovery Behavior
is related to Detect Persistence via Malicious Outlook Rules
is related to Detection Strategy for Bind Mounts on Linux
is related to Behavioral Detection of Keylogging Activity Across Platforms
is related to Suspicious Use of Web Services for C2
is related to Detection of Spoofed User-Agent
is related to Behavioral Detection of Log File Clearing on Linux and macOS
is related to Detect Kerberos Ccache File Theft or Abuse (T1558.005)
is related to Unix-like File Permission Manipulation Behavioral Chain Detection Strategy
is related to Behavior-chain detection for T1610 Deploy Container across Docker & Kubernetes control/node planes
is related to Behavioral Detection of Command and Scripting Interpreter Abuse
is related to Detect Screensaver-Based Persistence via Registry and Execution Chains
is related to Detection Strategy for Hijack Execution Flow through Services File Permissions Weakness.
is related to Detection Strategy for T1505.004 - Malicious IIS Components
is related to Detection Strategy for Modify Cloud Compute Infrastructure
is related to Local Account Enumeration Across Host Platforms
is related to Detection Strategy for Container and Resource Discovery
is related to Behavioral Detection Strategy for Exfiltration Over Symmetric Encrypted Non-C2 Protocol
is related to Behavioral Detection Strategy for Network Service Discovery Across Platforms
is related to Detect Excessive or Unauthorized Bandwidth Usage for Botnet, Proxyjacking, or Scanning Purposes
is related to Detection of Link Target
is related to Encrypted or Encoded File Payload Detection Strategy
is related to Detect Persistence via Office Test Registry DLL Injection
is related to Internal Proxy Behavior via Lateral Host-to-Host C2 Relay
is related to Detect Adversary-in-the-Middle via Network and Configuration Anomalies
is related to Detection for Spoofing Tool UI across OS Platforms
is related to Detection of Exfiltration Over Unencrypted Non-C2 Protocol
is related to Detection Strategy for Downgrade System Image on Network Devices
is related to Linux Python Startup Hook Persistence via .pth and Customize Files (T1546.018)
is related to Multi-Platform Cloud Storage Exfiltration Behavior Chain
is related to Boot or Logon Autostart Execution Detection Strategy
is related to Enumeration of Global Address Lists via Email Account Discovery
is related to Detection of Direct VM Console Access via Cloud-Native Methods
is related to Obfuscated Binary Unpacking Detection via Behavioral Patterns
is related to Detecting OS Credential Dumping via /proc Filesystem Access on Linux
is related to Detection Strategy for Encrypted Channel via Symmetric Cryptography across OS Platforms
is related to Detection Strategy for Modify Cloud Compute Infrastructure: Create Cloud Instance
is related to Detection of Spearphishing Service
is related to Brute Force Authentication Failures with Multi-Platform Log Correlation
is related to Detection Strategy for Extended Attributes Abuse
is related to Behavioral Detection of Systemd Timer Abuse for Scheduled Execution
is related to Detection of Application Window Enumeration via API or Scripting
is related to Detection Strategy for SVG Smuggling with Script Execution and Delivery Behavior
is related to T1136.001 Detection Strategy - Local Account Creation Across Platforms
is related to Account Access Removal via Multi-Platform Audit Correlation
is related to Behavioral detection for Supply Chain Compromise (package/update tamper → install → first-run)
is related to Detect Abuse of Container APIs for Credential Access
is related to Detection of Gather Victim Identity Information
is related to Detection Strategy for Extra Window Memory (EWM) Injection on Windows
is related to Detecting Remote Script Proxy Execution via PubPrn.vbs
is related to Password Policy Discovery – cross-platform behavior-chain analytics
is related to Detect Archiving via Library (T1560.002)
is related to Detection Strategy for Content Injection
is related to Firmware Modification via Flash Tool or Corrupted Firmware Upload
is related to Detection of File Transfer Protocol-Based C2 (FTP, FTPS, SMB, TFTP)
is related to Detection Strategy for T1546.016 - Event Triggered Execution via Installer Packages
is related to Cross-Platform Detection of Cron Job Abuse for Persistence and Execution
is related to Detection of Cloud Accounts
is related to Behavioral Detection of Local Group Enumeration Across OS Platforms
is related to Detection of Search Threat Vendor Data
is related to Detection Strategy for Embedded Payloads
is related to Detection Strategy for Container Administration Command Abuse
is related to Drive-by Compromise — Behavior-based, Multi-platform Detection Strategy (T1189)
is related to Behavior‑chain detection for T1134.003 Make and Impersonate Token (Windows)
is related to Detect Shell Configuration Modification for Persistence via Event-Triggered Execution
is related to Behavioral Detection of Input Capture Across Platforms
is related to Detection Strategy for Hijack Execution Flow through the AppDomainManager on Windows.
is related to Detection of Determine Physical Locations
is related to Detection of Direct Volume Access for File System Evasion
is related to Detection of Windows Service Creation or Modification
is related to Detection Strategy for Data from Configuration Repository on Network Devices
is related to Detection of Generate Content
is related to Detection of Script-Based Proxy Execution via Signed Microsoft Utilities
is related to Detection Strategy for Network Address Translation Traversal
is related to Enumeration of User or Account Information Across Platforms
is related to Detecting Steganographic Command and Control via File + Network Correlation
is related to Exploit Public-Facing Application – multi-signal correlation (request → error → post-exploit process/egress)
is related to Detection Strategy for Plist File Modification (T1647)
is related to Detection Strategy for System Binary Proxy Execution: Regsvr32
is related to Detect Unauthorized Access to Password Managers
is related to Detection Strategy for Resource Forking on macOS
is related to Web Shell Detection via Server Behavior and File Execution Chains
is related to Detection Strategy for Abuse Elevation Control Mechanism (T1548)
is related to Detect Network Logon Script Abuse via Multi-Event Correlation on Windows
is related to Detection Strategy for Exfiltration to Cloud Storage
is related to Detection of Phishing for Information
is related to Internal Spearphishing via Trusted Accounts
is related to Detect Remote Access via USB Hardware (TinyPilot, PiKVM)
is related to Windows DACL Manipulation Behavioral Chain Detection Strategy
is related to Detection Strategy for Data from Network Shared Drive
is related to Container CLI and API Abuse via Docker/Kubernetes (T1059.013)
is related to User Execution – Malicious Copy & Paste (browser/email → shell with obfuscated one-liner) – T1204.004
is related to Detection of Domains
is related to Detect Modification of Authentication Process via Reversible Encryption
is related to Detection Strategy for Exfiltration to Text Storage Sites
is related to Detection of Lifecycle Policy Modifications for Triggered Deletion in IaaS Cloud Storage
is related to Behavior-chain detection for T1134.002 Create Process with Token (Windows)
is related to Detection of Credential Dumping from LSASS Memory via Access and Dump Sequence
is related to Detect Time-Based Evasion via Sleep, Timer Loops, and Delayed Execution
is related to Detect Malicious Modification of Pluggable Authentication Modules (PAM)
is related to Detect Registry and Startup Folder Persistence (Windows)
is related to Behavioral Detection of PE Injection via Remote Memory Mapping
is related to User Execution – multi-surface behavior chain (documents/links → helper/unpacker → LOLBIN/child → egress)
is related to Detect AS-REP Roasting Attempts (T1558.004)
is related to Detection Strategy for Hijack Execution Flow: Dynamic Linker Hijacking
is related to Detect Abuse of XPC Services (T1559.003)
is related to Detect Forged Kerberos Silver Tickets (T1558.002)
is related to Detect Mark-of-the-Web (MOTW) Bypass via Container and Disk Image Files
is related to Detection Strategy for Scheduled Transfer and Recurrent Exfiltration Patterns
is related to Detect Obfuscated C2 via Network Traffic Analysis
is related to Detection of Bluetooth-Based Data Exfiltration
is related to Detection Strategy for Cloud Application Integration
is related to Detection of Firmware
is related to Detection of Artificial Intelligence
is related to Detection of Code Repositories
is related to Detect Hybrid Identity Authentication Process Modification
is related to Detection Strategy of Transmitted Data Manipulation
is related to Behavioral Detection of Remote SSH Logins Followed by Post-Login Execution
is related to Detection Strategy for Traffic Duplication via Mirroring in IaaS and Network Devices
is related to Detection Strategy for Exfiltration Over Webhook
is related to Detection Strategy for Netsh Helper DLL Persistence via Registry and Child Process Monitoring (Windows)
is related to Detection of Social Media Accounts
is related to Socket-filter trigger → on-host raw-socket activity → reverse connection (T1205.002)
is related to Detection of Malicious Control Panel Item Execution via control.exe or Rundll32
is related to Detection Strategy for Weaken Encryption: Disable Crypto Hardware on Network Devices
is related to Detection Strategy for Modify Cloud Compute Infrastructure: Modify Cloud Compute Configurations
is related to Behavioral Detection of Malicious File Deletion
is related to Detect Bidirectional Web Service C2 Channels via Process & Network Correlation
is related to Detect Local Email Collection via Outlook Data File Access and Command Line Tooling
is related to Suspicious Device Registration via Entra ID or MFA Platform
is related to Detection of Malicious Kubernetes CronJob Scheduling
is related to Defacement via File and Web Content Modification Across Platforms
is related to Behavioral Detection Strategy for Remote Service Logins and Post-Access Activity
is related to Detection Strategy for Stripped Payloads Across Platforms
is related to Detection Strategy for Additional Cloud Credentials in IaaS/IdP/SaaS
is related to Detection of Exploits
is related to Detection of Search Open Technical Databases
is related to External Proxy Behavior via Outbound Relay to Intermediate Infrastructure
is related to Behavioral Detection of Fallback or Alternate C2 Channels
is related to Detection Strategy for Cloud Infrastructure Discovery
is related to Detect Suspicious Access to Private Key Files and Export Attempts Across Platforms
is related to Detect Social Engineering
is related to Detect browser session hijacking via privilege, handle access, and remote thread into browsers
is related to Detection of Domains
is related to Detection of Event Log Clearing on Windows via Behavioral Chain
is related to Detection Strategy for Hijack Execution Flow: Dylib Hijacking
is related to Detection Strategy for Masquerading via Account Name Similarity
is related to Detection of Network Security Appliances
is related to Detect LSA Authentication Package Persistence via Registry and LSASS DLL Load
is related to Detecting Bulk or Anomalous Access to Private Code Repositories via SaaS Platforms
is related to Detection of Disabled or Modified System Firewalls across OS Platforms.
is related to Detection Strategy for SNMP (MIB Dump) on Network Devices
is related to Indirect Command Execution – Windows utility abuse behavior chain
is related to Detection of Botnet
is related to Credential Stuffing Detection via Reused Breached Credentials Across Services
is related to Detection Strategy for T1550.003 - Pass the Ticket (Windows)
is related to Multi-Platform Detection Strategy for T1678 - Delay Execution
is related to Detection of Compromise Infrastructure
is related to Detect abuse of Trusted Relationships (third-party and delegated admin access)
is related to Detect Domain Controller Authentication Process Modification (Skeleton Key)
is related to Detect persistence via reopened application plist modification (macOS)
is related to Detecting Mshta-based Proxy Execution via Suspicious HTA or Script Invocation
is related to User Execution – Malicious Link (click → suspicious egress → download/write → follow-on activity)
is related to Detection Strategy for Forged Web Credentials
is related to Behavioral Detection of User Discovery via Local and Remote Enumeration
is related to Detection Strategy for Phishing across platforms.
is related to Linux Detection Strategy for T1547.013 - XDG Autostart Entries
is related to Detection Strategy for T1505.002 - Transport Agent Abuse (Windows/Linux)
is related to Detection Strategy for T1542.005 Pre-OS Boot: TFTP Boot
is related to Multi-Platform Behavioral Detection for Compute Hijacking
is related to Detection of Remote Service Session Hijacking
is related to Detection of DNS Server
is related to Compromised software/update chain (installer/write → first-run/child → egress/signature anomaly)
is related to Detection of Credentials
is related to Detection of Malicious Profile Installation via CMSTP.exe
is related to Detect Kerberoasting Attempts (T1558.003)
is related to Detection of Exploits
is related to Detect WMI Event Subscription for Persistence via WmiPrvSE Process and MOF Compilation
is related to Removable Media Execution Chain Detection via File and Process Activity
is related to Account Manipulation Behavior Chain Detection
is related to Setuid/Setgid Privilege Abuse Detection (Linux/macOS)
is related to Detection Strategy for Addition of Email Delegate Permissions
is related to Cross-Platform Detection of Data Transfer to Cloud Account
is related to Detection of Spearphishing Voice
is related to Behavior-Based Registry Modification Detection on Windows
is related to Security Software Discovery Across Platforms
is related to Detection of Adversary Abuse of Software Deployment Tools
is related to Detection Strategy for Hijack Execution Flow across OS platforms.
is related to Detection Strategy for Defense Impairment via Prevent Command History Logging across OS platforms.
is related to Detection of Digital Certificates
is related to Detection Strategy for VDSO Hijacking on Linux
is related to Detection of AppleScript-Based Execution on macOS
is related to Detection Strategy for T1542.004 Pre-OS Boot: ROMMONkit
is related to Detect Access or Search for Unsecured Credentials Across Platforms
is related to Detection Strategy for Financial Theft
is related to Behavioral Detection of Indicator Removal Across Platforms
is related to Detect ARP Cache Poisoning Across Linux, Windows, and macOS
is related to Detection Strategy for System Services Service Execution
is related to Detection of Trust Relationship Modifications in Domain or Tenant Policies
is related to Detect Adversary Deobfuscation or Decoding of Files and Payloads
is related to Detection of Purchase Technical Data
is related to Detection of Exfiltration Over Alternate Network Interfaces
is related to Detection of Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
is related to Behavior-chain detection strategy for T1127.001 Trusted Developer Utilities Proxy Execution: MSBuild (Windows)
is related to Detection Strategy for Endpoint DoS via Application or System Exploitation
is related to Detect LLMNR/NBT-NS Poisoning and SMB Relay on Windows
is related to Detection Strategy for T1547.015 – Login Items on macOS
is related to Behavioral Detection of Process Injection Across Platforms
is related to Detect Subversion of Trust Controls via Certificate, Registry, and Attribute Manipulation
is related to Detecting Unauthorized Collection from Messaging Applications in SaaS and Office Environments
is related to Detection Strategy for Encrypted Channel via Asymmetric Cryptography across OS Platforms
is related to Detect Forced SMB/WebDAV Authentication via lure files and outbound NTLM
is related to Abuse of Information Repositories for Data Collection
is related to Cross-Platform Behavioral Detection of Scheduled Task/Job Abuse
is related to Behavior-chain detection strategy for T1127.002 Trusted Developer Utilities Proxy Execution: ClickOnce (Windows)
is related to Detect persistent or elevated container services via container runtime or cluster manipulation
is related to Detection Strategy for HTML Smuggling via JavaScript Blob + Dynamic File Drop
is related to Behavioral Detection Strategy for Use Alternate Authentication Material (T1550)
is related to Detect Malicious Password Filter DLL Registration
is related to Behavioral Detection Strategy for WMI Execution Abuse on Windows
is related to Detection of Scanning IP Blocks
is related to Detect Forged Kerberos Golden Tickets (T1558.001)
is related to Behavioral Detection of Malicious Cloud API Scripting
is related to Detection of Unauthorized DCSync Operations via Replication API Abuse
is related to Detection of Group Policy Modifications via AD Object Changes and File Activity
is related to Detection Strategy for Cloud Service Discovery
is related to Detection of Search Victim-Owned Websites
is related to Behavior-chain, platform-aware detection strategy for T1124 System Time Discovery
is related to Multi-Platform Shutdown or Reboot Detection via Execution and Host Status Events
is related to Detection of Remote Data Staging Prior to Exfiltration
is related to Detection Strategy for Forged Web Cookies
is related to Detection Strategy for Rogue Domain Controller (DCShadow) Registration and Replication Abuse
is related to Recursive Enumeration of Files and Directories Across Privilege Contexts
is related to Behavioral Detection of Spoofed GUI Credential Prompts
is related to Detection Strategy for Escape to Host
is related to Detection of Malicious Code Execution via InstallUtil.exe
is related to Environmental Keying Discovery-to-Decryption Behavioral Chain Detection Strategy
is related to Detection of Credential Harvesting via Web Portal Modification
is related to Detection of Web Services
is related to Detection Strategy for Event Triggered Execution via emond on macOS
is related to Detection of Written Content
is related to Behavioral Detection Strategy for T1123 Audio Capture Across Windows, Linux, macOS
is related to Behavioral Detection of CLI Abuse on Network Devices
is related to Detect unauthorized or suspicious Hardware Additions (USB/Thunderbolt/Network)
is related to Behavioral Detection of Unix Shell Execution
is related to Credential Dumping via Sensitive Memory and Registry Access Correlation
is related to Detect Logon Script Modifications and Execution
is related to Detection Strategy for IFEO Injection on Windows
is related to Detection of Tool
is related to Detection Strategy for Subvert Trust Controls via Install Root Certificate.
is related to Detection of USB-Based Data Exfiltration
is related to Detection Strategy for SSH Key Injection in Authorized Keys
is related to Detect Modification of macOS Startup Items
is related to Detection Strategy for Weaken Encryption on Network Devices
is related to Detection of Compromise Accounts
is related to Behavioral Detection of Asynchronous Procedure Call (APC) Injection via Remote Thread Queuing
is related to Detection of Mail Protocol-Based C2 Activity (SMTP, IMAP, POP3)
is related to Multi-Event Behavioral Detection for DCOM-Based Remote Code Execution
is related to Detect Active Setup Persistence via StubPath Execution
is related to Distributed Password Spraying via Authentication Failures Across Multiple Accounts
is related to Traffic Signaling (Port-knock / magic-packet → firewall or service activation) – T1205
is related to Detection Strategy for Disable or Modify Cloud Log
is related to Detection of Local Data Collection Prior to Exfiltration
is related to Cross-Platform Behavioral Detection of File Timestomping via Metadata Tampering
is related to Detection of Wordlist Scanning
is related to Detection of Persistence Artifact Removal Across Host Platforms
is related to Detection Strategy for Network Boundary Bridging
is related to Detection of Gather Victim Org Information
is related to Detection of Data Access and Collection from Removable Media
is related to User-Initiated Malicious Library Installation via Package Manager (T1204.005)
is related to Behavioral Detection of Network Share Connection Removal via CLI and SMB Disconnects
is related to Detection of Non-Application Layer Protocols for C2
is related to Detection of DNS
is related to Detection Strategy for Compile After Delivery - Source Code to Executable Transformation
is related to Detection Strategy for Hijack Execution Flow through Path Interception by Unquoted Path
is related to Detecting Suspicious Access to CRM Data in SaaS Environments
is related to Detection Strategy for System Services: Launchctl
is related to Detect DHCP Spoofing Across Linux, Windows, and macOS
is related to Behavior-chain detection for T1134.004 Access Token Manipulation: Parent PID Spoofing (Windows)
is related to Detection Strategy for T1528 - Steal Application Access Token
is related to System Discovery via Native and Remote Utilities
is related to Detection of Employee Names
is related to Detection of Social Media Accounts
is related to Detection Strategy for ESXi Hypervisor CLI Abuse
is related to Behavioral Detection of Thread Execution Hijacking via Thread Suspension and Context Switching
is related to Detection Strategy for Disk Content Wipe via Direct Access and Overwrite
is related to Detection Strategy for T1136 - Create Account across platforms
is related to Detect Credential Discovery via Windows Registry Enumeration
is related to Detection Strategy for PowerShell Profile Persistence via profile.ps1 Modification
is related to Detection Strategy for Dynamic API Resolution via Hash-Based Function Lookups
is related to Detection Strategy for Data Manipulation
is related to Remote Desktop Software Execution and Beaconing Detection
is related to Detection Strategy for Double File Extension Masquerading
is related to Application Exhaustion Flood Detection Across Platforms
is related to Cross-Platform Behavioral Detection of Python Execution
is related to Detection of Acquire Infrastructure
is related to Detection Strategy for Event Triggered Execution: AppInit DLLs (Windows)
is related to Peripheral Device Enumeration via System Utilities and API Calls
is related to Resource Hijacking Detection Strategy
is related to Detection Strategy for T1547.010 – Port Monitor DLL Persistence via spoolsv.exe (Windows)
is related to Detecting Code Injection via mavinject.exe (App-V Injector)
is related to Detection of Gather Victim Network Information
is related to Detection Strategy for Cloud Service Hijacking via SaaS Abuse
is related to Behavior-chain detection for T1134.005 Access Token Manipulation: SID-History Injection (Windows)
is related to Detection of Web Protocol-Based C2 Over HTTP, HTTPS, or WebSockets
is related to Detection Strategy for Runtime Data Manipulation.
is related to Multi-Platform Software Discovery Behavior Chain
is related to Detection of Data Exfiltration via Removable Media
is related to Detection of Abused or Compromised Cloud Accounts for Access and Persistence
is related to Detection of Code Signing Certificates
is related to Detect Archiving via Utility (T1560.001)
is related to Detection Strategy for Disk Structure Wipe via Boot/Partition Overwrite
is related to Detecting PowerShell Execution via SyncAppvPublishingServer.vbs Proxy Abuse
is related to Detect Suspicious Access to securityd Memory for Credential Extraction
is related to Detect malicious IDE extension install/usage and IDE tunneling
is related to Detection of Upload Tool
is related to Detection Strategy for Overwritten Process Arguments Masquerading
is related to Detect Use of Stolen Web Session Cookies Across Platforms
is related to Detection Strategy for Exfiltration to Code Repository
is related to Detection of Vulnerability Scanning
is related to Masquerading via Space After Filename - Behavioral Detection Strategy
is related to Endpoint Resource Saturation and Crash Pattern Detection Across Platforms
is related to Detection Strategy for Data Transfer Size Limits and Chunked Exfiltration
is related to Detection Strategy for Hidden Artifacts Across Platforms
is related to Abuse of Domain Accounts
is related to Detect Persistence via Malicious Office Add-ins
is related to Detection Strategy for Process Doppelgänging on Windows
is related to Detection Strategy for Poisoned Pipeline Execution via SaaS CI/CD Workflows
is related to Detection Strategy for Patch System Image on Network Devices
is related to Behavioral Detection of Domain Group Discovery
is related to Detection Strategy for Masquerading via Breaking Process Trees
is related to Detect Suspicious Access to Windows Credential Manager
is related to Behavior-chain detection strategy for T1127.003 Trusted Developer Utilities Proxy Execution: JamPlus (Windows)
is related to Detect Code Signing Policy Modification (Windows & macOS)
is related to Behavioral Detection of DNS Tunneling and Application Layer Abuse
is related to Detect Modification of Authentication Processes Across Platforms
is related to Detection Strategy for Exploitation for Privilege Escalation
is related to Detection Strategy for Hidden Windows
is related to Detect Abuse of Component Object Model (T1559.001)
is related to Detection Strategy for SQL Stored Procedures Abuse via T1505.001
is related to Detect Kerberos Ticket Theft or Forgery (T1558)
is related to Detection of WHOIS
is related to Multi-Platform Execution Guardrails Environmental Validation Detection Strategy
is related to Detect Access and Decryption of Group Policy Preference (GPP) Credentials in SYSVOL
is related to Detection Strategy for Application Shimming via sdbinst.exe and Registry Artifacts (Windows)
is related to Detection Strategy for Hidden File System Abuse
is related to Detection Strategy for Dynamic Resolution across OS Platforms
is related to Detection Strategy for Log Enumeration
is related to Detection Strategy for Launch Daemon Creation or Modification (macOS)
is related to Behavior-chain detection for T1134 Access Token Manipulation on Windows
is related to Behavioral Detection of External Website Defacement across Platforms
is related to Detection of Drive-by Target
is related to Detect Remote Email Collection via Abnormal Login and Programmatic Access
is related to Detection of Stage Capabilities
is related to Invalid Code Signature Execution Detection via Metadata and Behavioral Context
is related to Detection Strategy for Ptrace-Based Process Injection on Linux
is related to Detect Credentials Access from Password Stores
is related to Detect Persistence via Outlook Custom Forms Triggered by Malicious Email
is related to Detection Strategy for Hijack Execution Flow using the Windows COR_PROFILER.
is related to Detection of Email Accounts
is related to Detection Strategy for Invisible Unicode
is related to Detection Strategy for SSH Session Hijacking
is related to Detection Strategy for Impair Defenses Across Platforms
is related to Detection Strategy for Process Hollowing on Windows
is related to Detection Strategy for Input Injection
is related to Detection of CDNs
is related to Boot or Logon Initialization Scripts Detection Strategy
is related to Detection Strategy for Non-Standard Ports
is related to Detection of Spearphishing Attachment
is related to Detection Strategy for Reflection Amplification DoS (T1498.002)
is related to Multi-Event Detection for SMB Admin Share Lateral Movement
is related to Behavioral Detection of Native API Invocation via Unusual DLL Loads and Direct Syscalls
is related to Detection Strategy for Exploitation for Credential Access
is related to Detection Strategy for Stored Data Manipulation across OS Platforms.
is related to Port-knock → rule/daemon change → first successful connect (T1205.001)
is related to Behavioral Detection of Remote Cloud Logins via Valid Accounts
is related to Detection of System Network Connections Discovery Across Platforms
is related to Detecting Junk Data in C2 Channels via Behavioral Analysis
is related to Automated File and API Collection Detection Across Platforms
is related to Detection of Client Configurations
is related to Behavioral Detection for T1490 - Inhibit System Recovery
is related to Detect Access and Parsing of .bash_history Files for Credential Harvesting
is related to Detect Unauthorized Access to Cloud Secrets Management Stores
is related to Detection of System Service Discovery Commands Across OS Platforms
is related to Detection Strategy for T1136.003 - Cloud Account Creation across IaaS, IdP, SaaS, Office
is related to Detection Strategy for Masquerading via Legitimate Resource Name or Location
is related to Detection Strategy for Role Addition to Cloud Accounts
is related to Detection Strategy for Modify Cloud Compute Infrastructure: Revert Cloud Instance
is related to Detection Strategy for AppCert DLLs Persistence via Registry Injection
is related to Detection of Registry Query for Environmental Discovery
is related to Detection of Web Session Cookie Theft via File, Memory, and Network Artifacts
is related to Behavioral Detection of Event Triggered Execution Across Platforms
is related to Detection Strategy for Debugger Evasion (T1622)
is related to Detection Strategy for Serverless Execution (T1648)
is related to Detection Strategy for Virtual Machine Discovery
is related to Detection of Selective Exclusion
is related to Detecting MMC (.msc) Proxy Execution and Malicious COM Activation
is related to Behavioral Detection of WinRM-Based Remote Access
is related to Detect Evil Twin Wi-Fi Access Points on Network Devices
is related to Detection of Serverless
is related to Detection of Proxy Execution via Trusted Signed Binaries Across Platforms
is related to Detection of Domain or Tenant Policy Modifications via AD and Identity Provider
is related to Detect Suspicious or Malicious Code Signing Abuse
is related to Behavior-chain, platform-aware detection strategy for T1127 Trusted Developer Utilities Proxy Execution (Windows)
is related to Detection Strategy for T1546.017 - Udev Rules (Linux)
is related to Detection of Identify Roles
is related to Detect Access to Unsecured Credential Files Across Platforms
is related to Detection Strategy for Data Encoding in C2 Channels
is related to Behavioral Detection of Windows Command Shell Execution
is related to Detection Strategy for Hide Infrastructure
is related to Detection of Virtual Private Server
is related to Behavioral Detection of Command History Clearing
is related to Detection of Network Trust Dependencies
is related to Detection Strategy for Exploitation for Stealth
is related to Detection of Digital Certificates
is related to Multi-event Detection Strategy for RDP-Based Remote Logins and Post-Access Activity
is related to Behavioral Detection of Unauthorized VNC Remote Control Sessions
is related to Template Injection Detection - Windows
is related to Detection Strategy for T1548.002 – Bypass User Account Control (UAC)
is related to Detection of Code Signing Certificates
is related to Exploitation for Client Execution – cross-platform behavior chain (browser/Office/3rd-party apps)
is related to Detection of LSA Secrets Dumping via Registry and Memory Extraction
is related to Detection of Digital Certificates
is related to Detection of Masqueraded Tasks or Services with Suspicious Naming and Execution
is related to Detection of Upload Malware
is related to Behavioral Detection of Obfuscated Files or Information
is related to Supply-chain tamper in dependencies/dev-tools (manager→write/install→first-run→egress)
is related to Detection of System Process Creation or Modification Across Platforms
is related to Detection Strategy for Reflective Code Loading
is related to Detection of Tainted Content Written to Shared Storage
is related to Detection of Email Addresses
is related to Detection Strategy for Email Bombing
is related to Detection of Identify Business Tempo
is related to Detection Strategy for System Language Discovery
is related to Detection Strategy for Wi-Fi Networks
is related to Detection Strategy for Process Argument Spoofing on Windows
is related to Detection Strategy for Lateral Tool Transfer across OS platforms
is related to Detection of Data Staging Prior to Exfiltration
is related to Detection of Suspicious Compiled HTML File Execution via hh.exe
is related to Behavioral Detection of Masquerading Across Platforms via Metadata and Execution Discrepancy
is related to Detect XSL Script Abuse via msxsl and wmic
is related to Windows COM Hijacking Detection via Registry and DLL Load Correlation
is related to Behavioral Detection of Internet Connection Discovery
is related to Detect Network Provider DLL Registration and Credential Capture
is related to Detection of DNS/Passive DNS
is related to Detect Conditional Access Policy Modification in Identity and Cloud Platforms
is related to Detection Strategy for Exfiltration Over C2 Channel
is related to Detection of DNS Server
is related to Detection of IP Addresses
is related to Detect Default File Association Hijack via Registry & Execution Correlation on Windows
is related to Detection Strategy for T1550.002 - Pass the Hash (Windows)
is related to Detection of Serverless
is related to Detect Archiving via Custom Method (T1560.003)
is related to Detection Strategy for Protocol Tunneling accross OS platforms.
is related to Detection Strategy for T1218.012 Verclsid Abuse
is related to Detection of Query Public AI Services
is related to Detection of Vulnerabilities
is related to Detection of Malicious or Unauthorized Software Extensions
is related to Detection Strategy for Cloud Administration Command
is related to Direct Network Flood Detection across IaaS, Linux, Windows, and macOS
is related to Detection Strategy for Dynamic Resolution through DNS Calculation
is related to Detection Strategy for Masquerading via File Type Modification
is related to Detection of Mutex-Based Execution Guardrails Across Platforms
is related to Detection of Domain Trust Discovery via API, Script, and CLI Enumeration
is related to Detection of Search Closed Sources
is related to Detection of Obtain Capabilities
Impressum Deutsch Englisch