Entrada de Pandipedia
ATT&CK mapping decisions for detection engineering
How do the attached sources describe ATT&CK at a high level?
Dificultad: FácilAccording to the attached sources, what does an ATT&CK technique represent?
Dificultad: MedioFor detection engineering, what mapping approach do the sources support when an observed behavior could fit more than one ATT&CK entry?
Dificultad: DifícilWhich statement best reflects the limitation noted in the attached sources about recurring behaviors such as privilege escalation, persistence, active scanning, account manipulation, and exfiltration-related activity?
Dificultad: MedioGuarda esta respuesta
Crea tu cuenta para conservar esta respuesta y continuar desde aquí más tarde.
Lo sentimos, Pandi no pudo encontrar una respuesta.
Veamos alternativas:
- Modifica la consulta.
- Inicia un nuevo hilo.
- Eliminar fuentes (si se han agregado manualmente).