Entrée Pandipedia
ATT&CK mapping decisions for detection engineering
How do the attached sources describe ATT&CK at a high level?
Difficulté: FacileAccording to the attached sources, what does an ATT&CK technique represent?
Difficulté: MoyenFor detection engineering, what mapping approach do the sources support when an observed behavior could fit more than one ATT&CK entry?
Difficulté: DifficileWhich statement best reflects the limitation noted in the attached sources about recurring behaviors such as privilege escalation, persistence, active scanning, account manipulation, and exfiltration-related activity?
Difficulté: MoyenEnregistrez cette réponse
Créez votre compte pour conserver cette réponse et la reprendre plus tard.
Désolé, Pandi n'a pas trouvé de réponse.
Examinons les alternatives :
- Modifier la requête.
- Démarrer une nouvelle conversation.
- Supprimer des sources (si elles ont été ajoutées manuellement).