Pandipedia entry
ATT&CK mapping decisions for detection engineering
How do the attached sources describe ATT&CK at a high level?
Difficulty: EasyAccording to the attached sources, what does an ATT&CK technique represent?
Difficulty: MediumFor detection engineering, what mapping approach do the sources support when an observed behavior could fit more than one ATT&CK entry?
Difficulty: HardWhich statement best reflects the limitation noted in the attached sources about recurring behaviors such as privilege escalation, persistence, active scanning, account manipulation, and exfiltration-related activity?
Difficulty: MediumSave this answer
Create your account to keep this answer and continue from it later.
Sorry, Pandi could not find an answer.
Let's look at alternatives:
- Modify the query.
- Start a new thread.
- Remove sources (if manually added).